BTC$85,190+0.77% LTC$69.87+3.93% XMR$543.25+0.03%
TorPortal TorPortalMarkets, mirrors, dark web news
News › Topic

News tagged Ransomware

Every TorPortal story that mentions Ransomware. 60 stories, newest first. Category: topic.

Latest coverage of Ransomware

Click a headline for the full story or jump to the original.

GitLab warns of critical RCE vulnerability in AI Gateway service
BleepingComputer · Oct 2, 2026 · 2 min read

GitLab warns of critical RCE vulnerability in AI Gateway service

GitLab warned customers today to immediately patch a critical AI Gateway vulnerability that could let attackers run arbitrary commands on vulnerable instances.
Mississippi mayor says ransomware incident led city to shut down systems
The Record · Oct 2, 2026 · 2 min read

Mississippi mayor says ransomware incident led city to shut down systems

Government services were temporarily disrupted by ransomware in Vicksburg, Mississippi. Mayor Willis Thompson said the FBI and other authorities are investigating.
'Warlock' ransomware used in attacks on critical infrastructure in Portuguese, Spanish-speaking…
The Record · Oct 2, 2026 · 2 min read

'Warlock' ransomware used in attacks on critical infrastructure in Portuguese, Spanish-speaking countries

The group is exploiting a variety of vulnerabilities impacting Microsoft SharePoint, according to a new report from Symantec Threat Hunter Team.
Police disrupt KillSec ransomware, arrest suspected teenage leader
The Record · Oct 1, 2026 · 2 min read

Police disrupt KillSec ransomware, arrest suspected teenage leader

European police said raids against the KillSec ransomware-as-a-service operation included the arrest of a high-profile teen suspect.
Police dismantle KillSec ransomware gang allegedly led by 16-year-old
BleepingComputer · Oct 1, 2026 · 3 min read

Police dismantle KillSec ransomware gang allegedly led by 16-year-old

An international law enforcement operation dubbed "Operation KillSwitch" seized the KillSec ransomware gang's data leak site and servers, led to three arrests, and identified a 16-year-old as the group's alleged administrator.
Cisco warns of new SD-WAN zero-day exploited in attacks
BleepingComputer · Sep 30, 2026 · 2 min read

Cisco warns of new SD-WAN zero-day exploited in attacks

Cisco released security updates to address a critical zero-day in the Catalyst SD-WAN Manager (tracked as CVE-2026-76504) that attackers are actively exploiting to escalate to admin privileges.
TeamViewer urges users to patch severe flaws “as soon as possible”
BleepingComputer · Sep 30, 2026 · 2 min read

TeamViewer urges users to patch severe flaws “as soon as possible”

Remote access software company TeamViewer warned customers on Tuesday to immediately patch a set of high-severity vulnerabilities affecting its client and host software.
Arizona Supreme Court says hackers stole residents’ personal data
The Record · Sep 29, 2026 · 2 min read

Arizona Supreme Court says hackers stole residents’ personal data

A spokesperson for the court system told Recorded Future News that the incident did not involve ransomware and the hackers have not issued ransom demands for the stolen data as of Monday.
Japan's Keio confirms ransomware attack disrupted business systems
BleepingComputer · Sep 28, 2026 · 2 min read

Japan's Keio confirms ransomware attack disrupted business systems

Keio Corporation (Keio), a major private railway operator in Japan, said its network was hit by a ransomware attack over the weekend, disrupting some of its business systems.
Dutch police confirm arrest in ShinyHunters hacking investigation
BleepingComputer · Sep 28, 2026 · 2 min read

Dutch police confirm arrest in ShinyHunters hacking investigation

Dutch police have confirmed that a 24-year-old Amsterdam man arrested earlier this month was detained as part of an investigation into the ShinyHunters hacking group.
JadePuffer agentic AI attacks target Azure, destroy cloud resources
BleepingComputer · Sep 28, 2026 · 2 min read

JadePuffer agentic AI attacks target Azure, destroy cloud resources

The JadePuffer ransomware operator is targeting Azure tenants with agent-driven attacks that conduct reconnaissance, steal credentials, and destroy core components.
Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation
Krebs on Security · Sep 28, 2026 · 10 min read

Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation

Authorities in the Netherlands have arrested a 23-year-old convicted cybercriminal on suspicion of aiding in data thefts and extortions by the prolific hacker group ShinyHunters. In the days immediately following the suspect's arrest…
CISA orders feds to patch exploited Citrix flaws by Wednesday
BleepingComputer · Sep 28, 2026 · 3 min read

CISA orders feds to patch exploited Citrix flaws by Wednesday

The Cybersecurity and Infrastructure Security Agency (CISA) has ordered U.S. government agencies over the weekend to secure their systems against attacks exploiting two critical Citrix NetScaler vulnerabilities.
ShinyHunters hacked Clop leak site using Grav CMS path traversal flaw
BleepingComputer · Sep 25, 2026 · 4 min read

ShinyHunters hacked Clop leak site using Grav CMS path traversal flaw

The Clop ransomware gang has moved its data leak site to a new Tor address after confirming its previous server was compromised and defaced through an unpatched Grav CMS flaw that BleepingComputer has learned is an unauthenticated path…
Astrana latest healthcare tech firm to report data breach to SEC
The Record · Sep 24, 2026 · 2 min read

Astrana latest healthcare tech firm to report data breach to SEC

The healthcare firm Astrana warned regulators that hackers accessed confidential information by impersonating company personnel.
CISA: Ransomware gangs now exploiting critical TeamCity flaw
BleepingComputer · Sep 24, 2026 · 2 min read

CISA: Ransomware gangs now exploiting critical TeamCity flaw

​The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned federal agencies on Wednesday that ransomware gangs are now also exploiting a critical JetBrains TeamCity vulnerability patched in July.
Ryuk ransomware operator gets 2-year sentence after extorting victims for $1.2 million
The Record · Sep 23, 2026 · 2 min read

Ryuk ransomware operator gets 2-year sentence after extorting victims for $1.2 million

An Armenian national and member of the Ryuk ransomware gang was sentenced to two years in federal prison for his role in launching attacks.
InfraTrust report warns network management systems under attack
BleepingComputer · Sep 23, 2026 · 6 min read

InfraTrust report warns network management systems under attack

Attackers are increasingly targeting the management systems used to control enterprise infrastructure, with several critical vulnerabilities actively exploited before or shortly after vendors disclosed them.
Ryuk ransomware member sentenced to 24 months in prison
BleepingComputer · Sep 23, 2026 · 1 min read

Ryuk ransomware member sentenced to 24 months in prison

An Armenian man was sentenced to 24 months in prison and 3 years of supervised release for hacking U.S. companies and encrypting their systems in Ryuk ransomware attacks.
F5 patches BIG-IP APM zero-day flaw exploited in RCE attacks
BleepingComputer · Sep 23, 2026 · 2 min read

F5 patches BIG-IP APM zero-day flaw exploited in RCE attacks

F5 has released security updates to address a critical BIG-IP APM zero-day vulnerability being exploited in remote code execution attacks.
ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach
BleepingComputer · Sep 22, 2026 · 5 min read

ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach

The ShinyHunters extortion gang claims it breached FBI systems using a new Oracle PeopleSoft zero-day vulnerability, gaining access to internal services and stealing sensitive data on employees and job applicants.
Check Point warns of Management Server zero-day exploited in attacks
BleepingComputer · Sep 22, 2026 · 2 min read

Check Point warns of Management Server zero-day exploited in attacks

Check Point Software released emergency hotfixes to address a critical Security Management Server vulnerability that could let attackers run arbitrary scripts.
D-Link warns of max severity zero-day bug in DIR-822A routers
BleepingComputer · Sep 22, 2026 · 2 min read

D-Link warns of max severity zero-day bug in DIR-822A routers

D-Link warned customers of a maximum-severity vulnerability (CVE-2026-86296) with public proof-of-concept (PoC) exploit code and no patch, affecting legacy DIR-822A dual-band Wi-Fi routers.
ShinyHunters Hijacks Clop Dark Web Leak Site
DarkDotWeb · Sep 22, 2026 · 3 min read

ShinyHunters Hijacks Clop Dark Web Leak Site

ShinyHunters defaced Clop's dark web leak site and demanded an eight-figure payment while threatening to expose the ransomware group.
CISA alerts of active exploitation of three Linux kernel flaws
BleepingComputer · Sep 21, 2026 · 2 min read

CISA alerts of active exploitation of three Linux kernel flaws

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning that hackers are exploiting three Linux kernel vulnerabilities, one of them rated critical.
Cyberattack hits University of Munich, potentially exposing student financial data
The Record · Sep 21, 2026 · 3 min read

Cyberattack hits University of Munich, potentially exposing student financial data

The university, commonly known as LMU Munich, said Saturday that an attacker accessed enrollment data stored on one of its IT systems.
ShinyHunters cybercrime gang takes over Cl0p ransomware site, demands extortion payment
The Record · Sep 21, 2026 · 3 min read

ShinyHunters cybercrime gang takes over Cl0p ransomware site, demands extortion payment

The ShinyHunters extortion group hijacked the dark web leak site of the prolific Cl0p ransomware gang, according to material posted on the site over the weekend.
ShinyHunters hacks Clop leak site, threatens to extort ransomware gang
BleepingComputer · Sep 19, 2026 · 5 min read

ShinyHunters hacks Clop leak site, threatens to extort ransomware gang

The ShinyHunters extortion gang breached the Clop (aka Cl0p) ransomware operation's data leak site, defacing the Tor site and allegedly stealing server data and the private keys for its onion service.
Microsoft Teams will let admins block custom file extensions
BleepingComputer · Sep 18, 2026 · 1 min read

Microsoft Teams will let admins block custom file extensions

Microsoft Teams will soon let administrators tweak the list of file extensions commonly associated with security threats to meet their company's security requirements.
New Check Point flaw lets hackers execute code with root privileges
BleepingComputer · Sep 18, 2026 · 2 min read

New Check Point flaw lets hackers execute code with root privileges

Check Point Software has released security updates to address a critical vulnerability that can let attackers execute code with root privileges on management systems.
Cisco warns of max severity ISE zero-day exploited in attacks
BleepingComputer · Sep 17, 2026 · 1 min read

Cisco warns of max severity ISE zero-day exploited in attacks

Cisco has released security updates to address a maximum-severity Identity Services Engine vulnerability that attackers are actively exploiting in the wild.
Coast Guard, FBI boarded tanker after attack by ‘foreign cyber actors’
The Record · Sep 16, 2026 · 3 min read

Coast Guard, FBI boarded tanker after attack by ‘foreign cyber actors’

U.S. personnel boarded an oil tanker in the Gulf of Mexico to “ensure integrity of the vessel’s operational and information technology systems," after an apparent cyberattack, the U.S. Coast Guard said.
International Meteor Organization says cyberattack dealt ‘critical blow’ to website
The Record · Sep 16, 2026 · 1 min read

International Meteor Organization says cyberattack dealt ‘critical blow’ to website

A website used around the world for reporting meteors faces weeks of downtime as the organization moves away from systems that were hacked recently.
The true cost of a ransomware attack, with and without BCDR
BleepingComputer · Sep 16, 2026 · 5 min read

The true cost of a ransomware attack, with and without BCDR

The ransom itself can be only a fraction of the total cost of a ransomware attack, with downtime, recovery, remediation, and legal obligations adding millions to the bill. Datto explains how a mature BCDR strategy can reduce downtime and…
Critical ScreenConnect flaw now actively exploited in attacks
BleepingComputer · Sep 16, 2026 · 1 min read

Critical ScreenConnect flaw now actively exploited in attacks

Attackers now exploit a critical-severity ConnectWise ScreenConnect vulnerability in the wild, according to the U.S. Cybersecurity and Infrastructure Security Agency (CISA).
CISA: Critical VMware RCE flaw now exploited by ransomware gangs
BleepingComputer · Sep 15, 2026 · 1 min read

CISA: Critical VMware RCE flaw now exploited by ransomware gangs

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned security teams that ransomware gangs have now joined ongoing attacks exploiting a critical VMware vCenter vulnerability patched in July.
Cisco patches Secure Email Gateway zero-day exploited in attacks
BleepingComputer · Sep 15, 2026 · 1 min read

Cisco patches Secure Email Gateway zero-day exploited in attacks

Cisco warned customers to patch a critical Secure Email Gateway zero-day security flaw that threat actors have been exploiting in attacks.
Pro-Ukraine Hacking Cat group deploying new malware against Russian targets
The Record · Sep 14, 2026 · 2 min read

Pro-Ukraine Hacking Cat group deploying new malware against Russian targets

The pro-Ukraine hacktivist group Hacking Cat has evolved from carrying out website defacements and data leaks to more sophisticated and destructive attacks on Russian targets, researchers said.
How Threat Actors Are Turning Trusted AI Platforms Into an Attack Surface
BleepingComputer · Sep 11, 2026 · 1 min read

How Threat Actors Are Turning Trusted AI Platforms Into an Attack Surface

Threat actors are abusing trusted AI platforms to host malicious content, poison search results, and trick users into installing malware. Huntress examines campaigns targeting AI users through weaponized Claude Artifacts, shared AI…
Ukrainian hacker gets four years in US prison over Conti ransomware attacks
The Record · Sep 11, 2026 · 2 min read

Ukrainian hacker gets four years in US prison over Conti ransomware attacks

A Ukrainian national was sentenced to four years in a U.S. prison for his role in the notorious Conti ransomware operation, which targeted more than 1,000 victims worldwide before shutting down in 2022.
Conti ransomware gang member sentenced to 4 years in prison
BleepingComputer · Sep 11, 2026 · 2 min read

Conti ransomware gang member sentenced to 4 years in prison

A Ukrainian national has been sentenced to four years in prison for his role in Conti ransomware attacks between 2021 and 2022.
New Android malware encrypts files, steals data, and harasses victims
BleepingComputer · Sep 10, 2026 · 3 min read

New Android malware encrypts files, steals data, and harasses victims

A new Android malware strain called Mantax Otax combines ransomware and spyware capabilities to encrypt files, steal sensitive data, and spam and harass victims.
AI-powered attack exploited PaperCut flaws to hack 395 organizations
BleepingComputer · Sep 10, 2026 · 2 min read

AI-powered attack exploited PaperCut flaws to hack 395 organizations

A threat actor, likely Russian-speaking, used hundreds of AI agents to develop and launch a global exploitation campaign targeting vulnerable PaperCut NG/MF servers.
Cisco FMC flaws exploited by ransomware gang, state-sponsored hackers
BleepingComputer · Sep 10, 2026 · 1 min read

Cisco FMC flaws exploited by ransomware gang, state-sponsored hackers

Cisco Talos says two recently patched Secure Firewall Management Center (FMC) vulnerabilities have been exploited by three separate threat clusters linked to ransomware and state-sponsored attacks.
The Top 4 Threats We Found by Investigating Every Alert for a Quarter
BleepingComputer · Sep 10, 2026 · 1 min read

The Top 4 Threats We Found by Investigating Every Alert for a Quarter

Identity was the target in roughly half of all confirmed malicious activity. Prophet Security breaks down the four main attack patterns seen across customer environments between May and July 2026, and explains why some attacks succeeded…
CISA: WatchGuard RCE flaw now exploited in ransomware attacks
BleepingComputer · Sep 10, 2026 · 1 min read

CISA: WatchGuard RCE flaw now exploited in ransomware attacks

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that ransomware gangs are also exploiting a critical WatchGuard Firebox firewall vulnerability, which it flagged as actively exploited in December.
Electronic health record company says customer data stolen in breach
The Record · Sep 9, 2026 · 3 min read

Electronic health record company says customer data stolen in breach

Veradigm said access was limited to a specific interface, and did not impact the company’s broader environment such as its networks, servers or databases. The incident did not result in operational disruptions, the company added.
FBI puts its cyber strategy on paper
The Record · Sep 9, 2026 · 3 min read

FBI puts its cyber strategy on paper

The first public cybersecurity strategy issued by the FBI "directs our teams, our field offices, our global presence" to align their efforts on countering malicious hackers and cybercrime groups, senior official Brett Leatherman says.
Veradigm warns of patient data breach after ransomware gang claims attack
BleepingComputer · Sep 9, 2026 · 1 min read

Veradigm warns of patient data breach after ransomware gang claims attack

Healthcare technology company Veradigm disclosed a data breach after a cybersecurity incident at one of its third-party vendors exposed patients' personal data.
MFA's Weakest Link: Account Recovery Is the New Attack Path
BleepingComputer · Sep 9, 2026 · 5 min read

MFA's Weakest Link: Account Recovery Is the New Attack Path

MFA makes account takeover harder, but attackers are increasingly targeting the recovery processes used to reset passwords and authentication methods. Specops explains why stronger identity verification at the service desk is critical to…
Microsoft posts nearly 1,000 bugs for Patch Tuesday as CISA warns two being exploited
The Record · Sep 8, 2026 · 1 min read

Microsoft posts nearly 1,000 bugs for Patch Tuesday as CISA warns two being exploited

The new record total for Patch Tuesday is 973 vulnerabilities.
SAP warns of maximum severity 'OVERPASS' kernel vulnerability
BleepingComputer · Sep 8, 2026 · 1 min read

SAP warns of maximum severity 'OVERPASS' kernel vulnerability

SAP has addressed 20 vulnerabilities across multiple products in its September 2026 security updates, including a maximum-severity memory corruption flaw in the SAP Kernel code.
Cyberattack encrypts systems at Bavarian municipal utility
The Record · Sep 8, 2026 · 3 min read

Cyberattack encrypts systems at Bavarian municipal utility

A municipal utility in Bavaria is recovering from a cyberattack that encrypted its internal IT systems but did not affect water and electricity services.
220 million traveler records exposed in Vietnam-linked APIS leak
BleepingComputer · Sep 8, 2026 · 3 min read

220 million traveler records exposed in Vietnam-linked APIS leak

Exclusive: An exposed Advance Passenger Information System (APIS) database held 220 million passenger and crew records containing names, passport numbers, dates of birth, nationalities, and flight details spanning 2017 to 2026. Researchers…
Berlin investigates new data leak after hackers publish stolen login credentials
The Record · Sep 7, 2026 · 4 min read

Berlin investigates new data leak after hackers publish stolen login credentials

Another trove of data from Berlin's government has appeared online, authorities said. Germany's information security agency separately warned about the Rhysida cybercrime group.
ConnectWise warns of new ScreenConnect flaw without patch
BleepingComputer · Sep 7, 2026 · 1 min read

ConnectWise warns of new ScreenConnect flaw without patch

ConnectWise has shared temporary mitigation measures for a new ScreenConnect Remote Access vulnerability that it plans to patch later this week.
Critical Citrix NetScaler auth bypass now leveraged in attacks
BleepingComputer · Sep 4, 2026 · 2 min read

Critical Citrix NetScaler auth bypass now leveraged in attacks

Attackers have begun targeting a critical-severity Citrix NetScaler auth bypass flaw (CVE-2026-19490) in the wild, according to vulnerability intelligence company Previdian.
UK account-hack losses surge as new reporting system exposes hidden cases
The Record · Sep 4, 2026 · 4 min read

UK account-hack losses surge as new reporting system exposes hidden cases

In its first annual assessment, published Friday, the City of London Police said victims reported losing £6.3 million ($8.5 million) to account hacks in the year ending March 31, up from £1.2 million ($1.6 million) a year earlier.
Your Employee’s Password Appeared in an Infostealer Log. Now What?
BleepingComputer · Sep 3, 2026 · 1 min read

Your Employee’s Password Appeared in an Infostealer Log. Now What?

Infostealers can expose far more than passwords, including authenticated sessions that may let attackers bypass MFA. Flare explains how defenders can prioritize compromised identities, determine whether stolen access is still usable, and…
New pro-Ukraine hacker group targets Russian companies with custom ransomware
The Record · Sep 2, 2026 · 2 min read

New pro-Ukraine hacker group targets Russian companies with custom ransomware

The group, which calls itself VantaCore, has targeted at least seven known victims, Russian cybersecurity firm F6 said in a report published this week.

← All news