Rhysida is a ransomware_group tracked across 19 threat clusters and 39 intelligence report mentions on ThreatCluster. First observed October 31, 2025; most recent activity June 25, 2026.
On May 19, 2026, Microsoft disrupted Fox Tempest, a malware-signing-as-a-service (MSaaS) operation that provided over 1,000 fraudulent code-signing certificates to cybercriminals, enabling them to disguise malware as…
A new backdoor known as Mistic has been identified in cyberattacks targeting various sectors since April 2026. It is associated with the initial access broker KongTuke, also known as Woodgnat, which sells access to…
Cookeville Regional Medical Center (CRMC) in Tennessee reported a ransomware attack that compromised the personal and medical data of 337,917 patients. The attack occurred between July 11 and July 14, 2025, and was…
As of February 12, 2026, organizations worldwide are experiencing an average of 2,090 cyber-attacks per week, largely driven by ransomware incidents. This increase highlights the ongoing challenges faced by businesses…
UK small and medium-sized enterprises (SMEs) are increasingly vulnerable to sophisticated AI-driven scams, as highlighted by recent reports. The emergence of 'AI scams 2.0' combines traditional social engineering…
Recent Gootloader attacks have resulted in a Domain Controller compromise within 17 hours, as reported by Huntress. The Gootloader malware, which has been active since 2020, was previously inactive but saw a resurgence…
The Public Accounts Committee (PAC) has reported that UK national museums and galleries are highly vulnerable to cyber threats and theft, following significant incidents like the British Library ransomware attack and…
Recent analysis reveals that Rhysida and Interlock ransomware groups are interconnected through a shared ecosystem of malware tools, including the Supper backdoor. Both groups utilize initial access brokers and a…
A dataset containing subscriber information from SUCCESS Magazine has reportedly been leaked on a hacker forum. The data includes full names, physical and email addresses, phone numbers, and subscription details. This…
Cybercriminals are distributing the Oyster backdoor malware disguised as popular office tools, including Microsoft Teams and Google Meet. This campaign, targeting individuals in the financial sector, has been active…