ransomware (426)

31222611894?profile=RESIZE_400xThe Federal Bureau of Investigation (FBI), Cybersecurity and Infrastructure Security Agency (CISA), and US Department of Health and Human Services (HHS) are releasing this updated joint advisory to disseminate known Medusa ransomware tactics, techniques, and procedures (TTPs) and indicators of compromise (IOCs) identified through FBI investigations as recently as April 2026.  Medusa is a ransomware-as-a-service (RaaS) variant first identified in June 2021.  Both Medusa developers and affiliates

31221012677?profile=RESIZE_400xGunra is a ransomware-as-a-service (RaaS) used by affiliates to target government, critical infrastructure, and other organizations.  The Gunra ransomware variant first appeared in 2025 and expanded to RaaS operations in 2026.  The actors leverage a double-extortion model, both encrypting data and threatening to publish exfiltrated data to a dedicated leak site (DLS) if the ransom is not paid.  This advisory provides technical details of the activity, as well as tailored detection and mitigation

31214612658?profile=RESIZE_400xRansomware attacks have increased dramatically during the second quarter of 2026, with undisclosed incidents surging 40% year-on-year, according to BlackFog's latest State of Ransomware Report.  The cybersecurity firm documented 2,027 undisclosed attacks in Q2 2026, compared with 1,446 during the same period in 2025.  The report, which provides comprehensive analysis of both publicly disclosed and undisclosed ransomware attacks worldwide, also recorded 306 publicly disclosed attacks during the q

31197852093?profile=RESIZE_400xFairlife has temporarily stopped producing its milk in the United States after a cyber attack, the company said.  A portion of Fairlife's systems were accessed by an unauthorized third party in a "ransomware event," parent company Coca-Cola said in a statement on 16 July.[1]

The milk brand said it notified law enforcement and is continuing to investigate the incident, but has suspended production in the United States.  Fairlife also said its product quality and safety have not been affected.  "T

31188979063?profile=RESIZE_400xThe maritime logistics sector is navigating turbulent waters.  As shipping routes become geopolitical focal points and port operations increasingly rely on digital execution, the maritime attack surface is expanding rapidly.  To help defense teams navigate this shifting environment, US Coast Guard Cyber Command (CGCYBER) released its fifth annual Cyber Trends and Insights in the Marine Environment (CTIME) report.  Grounded in data collected from 42 comprehensive operations conducted by Coast Gua

31175884483?profile=RESIZE_400xTelecom Italia warned ransomware attacks surged in 2025 as cybercriminals used AI and automation to scale campaigns, cautioning that rapidly evolving technology and geopolitical tensions are reshaping digital risk.  In the second edition of its Cyber Security Report produced alongside Italy-based non-profit Cyber Security Foundation, TIM said ransomware claims topped 7,400 globally in 2025, up 42% compared to 2024.[1]

The report pointed to malware campaigns affecting entities in around 200 count

31146432269?profile=RESIZE_400xA Florida man who worked as a ransomware negotiator at a US cyber incident response firm has pleaded guilty to conspiring with the BlackCat/ALPHV ransomware group, feeding the attackers confidential information about his own clients while simultaneously negotiating on their behalf.  Angelo Martino, 41, of Land O'Lakes, Florida, admitted to providing BlackCat operators with clients' insurance policy limits and internal negotiation strategies without his employer's or clients' knowledge.  The oper

31125805877?profile=RESIZE_400xGoogle has warned that ransomware gangs are reinventing their business models as traditional encryption-based attacks become less profitable and data-theft extortion surges.   According to new analysis, better cybersecurity controls, improved backup strategies, and stronger recovery capabilities mean more victims can restore their systems without paying, directly eroding criminal revenue. However, threat actors are not retreating; they are adapting their methods to make operations harder to disr

31101707463?profile=RESIZE_400xBlockchain analysis firm Chainalysis has released new data indicating that ransomware activity in 2025 featured reduced overall revenue alongside increased disruption and economic damage.  Globally, on-chain payments to attackers totaled approximately $820 million, an 8% decline from the previous year, yet the number of attacks claimed rose by 50%, and the UK emerged as one of the most targeted nations with severe impacts on major organizations.[1]

The use of blockchain technology in tracking ra

31101330670?profile=RESIZE_400xNorth Korea's state-sponsored Lazarus Group has added yet another ransomware strain to its arsenal. New research from the Symantec and Carbon Black Threat Hunter Team reveals that the group has been observed deploying Medusa ransomware in an attack against an unnamed entity in the Middle East and, separately, attempting an unsuccessful breach of a healthcare organization in the United States.  The findings represent a notable evolution in Lazarus's tactics. The group has previously been linked t

31101330670?profile=RESIZE_400xNorth Korea's state-sponsored Lazarus Group has added yet another ransomware strain to its arsenal. New research from the Symantec and Carbon Black Threat Hunter Team reveals that the group has been observed deploying Medusa ransomware in an attack against an unnamed entity in the Middle East and, separately, attempting an unsuccessful breach of a healthcare organization in the United States.  The findings represent a notable evolution in Lazarus's tactics. The group has previously been linked t

31101330670?profile=RESIZE_400xNorth Korea's state-sponsored Lazarus Group has added yet another ransomware strain to its arsenal. New research from the Symantec and Carbon Black Threat Hunter Team reveals that the group has been observed deploying Medusa ransomware in an attack against an unnamed entity in the Middle East and, separately, attempting an unsuccessful breach of a healthcare organization in the United States.  The findings represent a notable evolution in Lazarus's tactics. The group has previously been linked t

31101330670?profile=RESIZE_400xNorth Korea's state-sponsored Lazarus Group has added yet another ransomware strain to its arsenal. New research from the Symantec and Carbon Black Threat Hunter Team reveals that the group has been observed deploying Medusa ransomware in an attack against an unnamed entity in the Middle East and, separately, attempting an unsuccessful breach of a healthcare organization in the United States.  The findings represent a notable evolution in Lazarus's tactics. The group has previously been linked t

31101330670?profile=RESIZE_400xNorth Korea's state-sponsored Lazarus Group has added yet another ransomware strain to its arsenal. New research from the Symantec and Carbon Black Threat Hunter Team reveals that the group has been observed deploying Medusa ransomware in an attack against an unnamed entity in the Middle East and, separately, attempting an unsuccessful breach of a healthcare organization in the United States.  The findings represent a notable evolution in Lazarus's tactics. The group has previously been linked t

31101330670?profile=RESIZE_400xNorth Korea's state-sponsored Lazarus Group has added yet another ransomware strain to its arsenal. New research from the Symantec and Carbon Black Threat Hunter Team reveals that the group has been observed deploying Medusa ransomware in an attack against an unnamed entity in the Middle East and, separately, attempting an unsuccessful breach of a healthcare organization in the United States.  The findings represent a notable evolution in Lazarus's tactics. The group has previously been linked t

31101330670?profile=RESIZE_400xNorth Korea's state-sponsored Lazarus Group has added yet another ransomware strain to its arsenal. New research from the Symantec and Carbon Black Threat Hunter Team reveals that the group has been observed deploying Medusa ransomware in an attack against an unnamed entity in the Middle East and, separately, attempting an unsuccessful breach of a healthcare organization in the United States.  The findings represent a notable evolution in Lazarus's tactics. The group has previously been linked t

31101330670?profile=RESIZE_400xNorth Korea's state-sponsored Lazarus Group has added yet another ransomware strain to its arsenal. New research from the Symantec and Carbon Black Threat Hunter Team reveals that the group has been observed deploying Medusa ransomware in an attack against an unnamed entity in the Middle East and, separately, attempting an unsuccessful breach of a healthcare organization in the United States.  The findings represent a notable evolution in Lazarus's tactics. The group has previously been linked t

31101330670?profile=RESIZE_400xNorth Korea's state-sponsored Lazarus Group has added yet another ransomware strain to its arsenal. New research from the Symantec and Carbon Black Threat Hunter Team reveals that the group has been observed deploying Medusa ransomware in an attack against an unnamed entity in the Middle East and, separately, attempting an unsuccessful breach of a healthcare organization in the United States.  The findings represent a notable evolution in Lazarus's tactics. The group has previously been linked t

31101330670?profile=RESIZE_400xNorth Korea's state-sponsored Lazarus Group has added yet another ransomware strain to its arsenal. New research from the Symantec and Carbon Black Threat Hunter Team reveals that the group has been observed deploying Medusa ransomware in an attack against an unnamed entity in the Middle East and, separately, attempting an unsuccessful breach of a healthcare organization in the United States.  The findings represent a notable evolution in Lazarus's tactics. The group has previously been linked t

31101330670?profile=RESIZE_400xNorth Korea's state-sponsored Lazarus Group has added yet another ransomware strain to its arsenal. New research from the Symantec and Carbon Black Threat Hunter Team reveals that the group has been observed deploying Medusa ransomware in an attack against an unnamed entity in the Middle East and, separately, attempting an unsuccessful breach of a healthcare organization in the United States.  The findings represent a notable evolution in Lazarus's tactics. The group has previously been linked t