Skip to content

Daily Threat Intel

Cyber threat intelligence for security leaders

Menu
  • Vulnerabilities
  • Malware
  • Breaches
  • Enterprise
  • Supply Chain
  • Emerging Threats
  • Cloud
  • About us
Menu

Tag: ransomware

Are Your Systems Patched Against Storm-1175 Attacks?

Posted on April 7, 2026

Image source: Antony McAulay, Shutterstock The threat actor is exploiting more than 17 flaws in high-velocity campaigns to distribute Medusa ransomware, according to Microsoft. A financially motivated threat actor whom Microsoft is…

Share

NSA, CISA, Others Warn About Fast Flux Threat: Here’s Why

Posted on April 8, 2025

Image source: Shutterstock Enterprise organizations, ISPs and security services providers are not adequately prepared to protect against attacks that leverage the technique, authoring agencies say. The NSA, CISA, and international partners have…

Share

Ransomware Actors Escalate Adversary-in-the-Middle Attacks

Posted on October 8, 2024

Image source: Shutterstock Many are also striking quickly after gaining initial access, a new report shows. Ransomware actors increasingly deployed adversary in the middle (AiTM) tactics to steal credentials and session cookies…

Share

New Vuln Enables Admin Access on Domain-Joined ESXi Hypervisors

Posted on July 30, 2024

Image Source: Shutterstock Ransomware attackers are leveraging CVE-2024-37085 to drop Black Basta, Akira on vulnerable systems, Microsoft says. Ransomware operators are exploiting an authentication bypass vulnerability in ESXi hypervisors to gain full…

Share

CVE-2024-0204 in GoAnywhere MFT is a Ticking Time Bomb

Posted on January 24, 2024

Image source: Shutterstock More than 96% of GoAnywhere MFT assets that security vendor Tenable observed on Jan 23 were vulnerable. Mass attacks could soon begin against a critical authentication bypass flaw in…

Share

LockBit Ransomware Operators Targeting CitrixBleed in Coordinated Attacks

Posted on November 14, 2023

Image source: Shutterstock China’s ICBC, Boeing, Australian logistics giant DP World, major law firm among known victims so far; More than 5,000 organizations worldwide remain unpatched and vulnerable to CVE-2023-4966 Multiple LockBit…

Share

Destructive “CryWiper” disk-wiping malware is on the loose

Posted on December 2, 2022

Tool masquerades as ransomware but overwrites and destroys data making it unrecoverable, Kaspersky warns Security researchers at Kaspersky have spotted a new disk wiping malware tool dubbed CryWiper landing on target systems,…

Share

Australian Federal Police say Russian threat actor behind Medibank breach

Posted on November 11, 2022

“We will be holding talks with Russian law enforcement about these individuals,” AFP Commissioner says [300 words]. What: The Australian Federal Police (AFP) has identified the threat actor behind the catastrophic attack…

Share

Russia’s Iridium group deploying new ransomware payload

Posted on November 10, 2022

Prestige ransomware marks dangerous shift in strategy for threat actor Microsoft says [299 words]. What: Security researchers at Microsoft have spotted Russia-based threat group Iridium dropping a new ransomware payload dubbed “Prestige”…

Share

Black Basta ransomware operators are exploiting “PrintNightMare”, “ZeroLogon” and “NoPac” Flaws

Posted on November 3, 2022

New data that researchers at SentinelOne uncovered show that the notorious, financially-motivated FIN7 threat group may be behind—or has strong ties—to the Black Basta ransomware operation [300 words]. Why that matters: FIN7…

Share

Posts pagination

1 2 Next
  • cPanel Auth Bypass: What You Need to Know
  • CISA Mandates Immediate Action on Cisco Firewall Backdoor
  • CISA Adds 3 Cisco SD-WAN Manager Flaws to Actively Exploited List
  • Exploits Turn Microsoft Defender Against Itself
  • Project Glasswing FAQ: A Look at Anthropic’s Bid to Secure the Internet
©2026 Daily Threat Intel | Design: Newspaperly WordPress Theme