Related Threat Clusters
-
Microsoft Disrupts Fox Tempest Malware-Signing Service for Ransomware Gangs
On May 19, 2026, Microsoft disrupted Fox Tempest, a malware-signing-as-a-service (MSaaS) operation that provided over 1,000 fraudulent code-signing certificates to cybercriminals, enabling them to disguise malware as…
33 articles · Updated May 19, 2026 -
Node.js Exploited in Ransomware Attacks Using EtherHiding Technique
Since February 2026, threat actors have been exploiting the trusted Node.js runtime to deploy malicious payloads in targeted attacks against government departments, technology companies, and hotels. The technique…
8 articles · Updated September 3, 2026 -
New Mistic Backdoor Linked to Ransomware Access Broker Activity
A new backdoor known as Mistic has been identified in cyberattacks targeting various sectors since April 2026. It is associated with the initial access broker KongTuke, also known as Woodgnat, which sells access to…
21 articles · Updated June 24, 2026 -
Cookeville Medical Center Data Breach Affects Over 337,000 Patients
Cookeville Regional Medical Center (CRMC) in Tennessee reported a ransomware attack that compromised the personal and medical data of 337,917 patients. The attack occurred between July 11 and July 14, 2025, and was…
5 articles · Updated April 16, 2026 -
Ransomware Attack on Berlin Senate: Data Exfiltration and Phishing Vector
In August 2026, the Berlin Senate Administration suffered a significant ransomware attack attributed to the group Rhysida, initiated by a phishing email that led to a fake CAPTCHA prompt. The attack exploited a method…
2 articles · Updated September 9, 2026 -
Ransomware Fuels Surge in Global Cyberattacks
As of February 12, 2026, organizations worldwide are experiencing an average of 2,090 cyber-attacks per week, largely driven by ransomware incidents. This increase highlights the ongoing challenges faced by businesses…
1922 articles · Updated February 12, 2026 -
Baltic Nations Enhance Security Against Hybrid Threats
On August 28, 2026, leaders from Baltic nations, including Germany, Denmark, and Poland, convened to address rising hybrid threats in the Baltic Sea region. German Interior Minister Alexander Dobrindt highlighted the…
2 articles · Updated August 29, 2026 -
Rhysida Ransomware Group Targets Berlin Ahead of Elections
The Rhysida ransomware group has claimed responsibility for a cyberattack on Berlin's state agencies, stealing 5.79 terabytes of data, including sensitive contracts and personal information. The group is auctioning the…
74 articles · Updated August 28, 2026 -
Rise of AI-Driven Scams Targeting UK SMEs
UK small and medium-sized enterprises (SMEs) are increasingly vulnerable to sophisticated AI-driven scams, as highlighted by recent reports. The emergence of 'AI scams 2.0' combines traditional social engineering…
860 articles · Updated March 12, 2026 -
Gootloader Malware Resurgence Leads to Domain Controller Compromise
Recent Gootloader attacks have resulted in a Domain Controller compromise within 17 hours, as reported by Huntress. The Gootloader malware, which has been active since 2020, was previously inactive but saw a resurgence…
2 articles · Updated November 6, 2025
Recent Intelligence Reports
- Hack of the Berlin Senate Administration Will Have Consequences for Decades — Feeds.Feedburner · September 9, 2026
- Rhysida Ransomware Attack: Berlin Government Data Published After €2m Demand Rejected — Redpacketsecurity · September 8, 2026
- BSI explains first attack vector on Berlin authorities — Heise.De · September 7, 2026
- [RHYSIDA] – Ransomware Victim: Rug & Home — Redpacketsecurity · September 7, 2026
- Node Js Returns Ransomware — www.security.com · September 3, 2026
- Node.js: Old Technique Makes a Comeback — Security · September 3, 2026
- Berlin being 'blackmailed' after cyberattack — www.thelocal.de · August 29, 2026
- Germany news: Baltic summit plans hybrid-threat task force — Dw · August 29, 2026