Cyberveillecurated by Decio
Nuage de tags
Mur d'images
Quotidien
Flux RSS
  • Flux RSS
  • Daily Feed
  • Weekly Feed
  • Monthly Feed
Filtres

Liens par page

  • 20 links
  • 50 links
  • 100 links

Filtres

Untagged links
page 3 / 21
419 résultats taggé Ransomware  ✕
Cobalt Strike and a Pair of SOCKS Lead to LockBit Ransomware https://thedfirreport.com/2025/01/27/cobalt-strike-and-a-pair-of-socks-lead-to-lockbit-ransomware/
27/01/2025 21:05:23
QRCode
archive.org
thumbnail

Key Takeaways This intrusion began with the download and execution of a Cobalt Strike beacon that impersonated a Windows Media Configuration Utility. The threat actor used Rclone to exfiltrate data…

thedfirreport EN 2025 Cobalt Strike LockBit Ransomware Rclone mega.io DFIR
UnitedHealth updates number of data breach victims to 190 million https://therecord.media/unitedhealth-updates-change-healthcare-data-breach-190-million?ref=metacurity.com
27/01/2025 21:00:37
QRCode
archive.org
thumbnail

The 2024 ransomware attack on Change Healthcare exposed the data of about 190 million people, according to an update from parent company UnitedHealth Group.

therecord.media EN 2025 ransomware UnitedHealth Group Change Healthcare
RansomHub Affiliate leverages Python-based backdoor https://www.guidepointsecurity.com/blog/ransomhub-affiliate-leverage-python-based-backdoor/
19/01/2025 10:46:28
QRCode
archive.org
thumbnail

In an incident response in Q4 of 2024, GuidePoint Security identified evidence of a threat actor utilizing a Python-based backdoor to maintain access to compromised endpoints. The threat actor later leveraged this access to deploy RansomHub encryptors throughout the entire impacted network. ReliaQuest documented an earlier version of this malware on their website in February 2024.

guidepointsecurity EN 2025 incident-response Python-based backdoor ransomware RansomHub SocGholish FakeUpdate
Ransomware roundup: 2024 end-of-year report - Comparitech https://www.comparitech.com/news/ransomware-roundup-2024-end-of-year-report/
19/01/2025 09:06:31
QRCode
archive.org
thumbnail

In 2024, ransomware groups claimed responsibility for 5,461 successful ransomware attacks on organizations worldwide. 1,204 of these attacks were confirmed by the targeted organizations. The rest were claimed by ransomware groups on their data leak sites, but have not been acknowledged by the targets.

comparitech EN 2025 2024 report ransomware confirmed statistcs
Après l’attaque par rançongiciel, la PME bretonne fait condamner ... https://www.zdnet.fr/actualites/apres-lattaque-par-rancongiciel-la-pme-bretonne-fait-condamner-son-prestataire-informatique-404483.htm
19/01/2025 09:04:14
QRCode
archive.org
thumbnail

Elle estimait que la société chargée du renouvellement de ses serveurs informatiques avait failli dans sa mission.

zdnet.fr FR 2025 PME legal bretonne condamnation prestataire ransomware backup sauvegarde déconnecté
Ministers consider ban on all UK public bodies making ransomware payments | Cybercrime | The Guardian https://www.theguardian.com/technology/2025/jan/14/ministers-consider-ban-on-all-uk-public-bodies-making-ransomware-payments
15/01/2025 09:11:56
QRCode
archive.org
thumbnail

Prohibition would bring the NHS, schools and local councils into line with government departments

theguardian EN 2024 UK ransomware payment banned government
Telefonica Breach Exposes Jira Tickets, Customer Data https://www.darkreading.com/cyberattacks-data-breaches/telefonica-breach-exposes-jira-tickets-customer-data?is=e4f6b16c6de31130985364bb824bcb39ef6b2c4e902e4e553f0ec11bdbefc118
15/01/2025 07:39:06
QRCode
archive.org
thumbnail

The Hellcat ransomware group has stolen roughly 5,000 documents, potentially containing confidential information, from the telecom giant's internal database.

darkreading EN 2025 Data-Breaches Telefonica Hellcat ransomware
Victime d'une cyberattaque début décembre, VidyMed a restauré les données ciblées (update) https://www.ictjournal.ch/news/2025-01-14/victime-dune-cyberattaque-debut-decembre-vidymed-a-restaure-les-donnees-ciblees
14/01/2025 22:32:36
QRCode
archive.org
thumbnail

Ciblée par une cyberattaque début décembre, VidyMed avait directement coupé l’accès aux systèmes pour contenir l’im

ictjournal FR CH Suisse 2025 Vidymed ransomware cyberattaque restauration données
Ransomware abuses Amazon AWS feature to encrypt S3 buckets https://www.bleepingcomputer.com/news/security/ransomware-abuses-amazon-aws-feature-to-encrypt-s3-buckets/
13/01/2025 20:12:07
QRCode
archive.org
thumbnail

A new ransomware campaign encrypts Amazon S3 buckets using AWS's Server-Side Encryption with Customer Provided Keys (SSE-C) known only to the threat actor, demanding ransoms to receive the decryption key.

bleepingcomputer EN 2025 Encryption Ransomware Computer S3 Amazon AES Security AWS
FunkSec – Alleged Top Ransomware Group Powered by AI https://research.checkpoint.com/2025/funksec-alleged-top-ransomware-group-powered-by-ai/
10/01/2025 17:41:47
QRCode
archive.org
thumbnail
  • The FunkSec ransomware group emerged in late 2024 and published over 85 victims in December, surpassing every other ransomware group that month.
  • FunkSec operators appear to use AI-assisted malware development which can enable even inexperienced actors to quickly produce and refine advanced tools.
  • The group’s activities straddle the line between hacktivism and cybercrime, complicating efforts to understand their true motivations.
  • Many of the group’s leaked datasets are recycled from previous hacktivism campaigns, raising doubts about the authenticity of their disclosures.
  • Current methods of assessing ransomware group threats often rely on the actors’ own claims, highlighting the need for more objective evaluation techniques.
checkpoint EN 2024 FunkSec analysis ransomware
Casio says hackers stole personal data of 8,500 people during October ransomware attack https://techcrunch.com/2025/01/08/casio-says-hackers-stole-personal-data-of-8500-people-during-october-ransomware-attack/
08/01/2025 12:29:13
QRCode
archive.org
thumbnail

The Japanese electronics giant says it did not negotiate with the hackers responsible for the attack.

techcrunch EN 2025 Casio Ransomware data-leak
Rhode Island warns of cybercriminals leaking stolen state files as Deloitte works to restore system https://therecord.media/rhode-island-data-breach-deloitte
04/01/2025 12:14:37
QRCode
archive.org
thumbnail

Rhode Island officials said they're still analyzing the impact of a ransomware gang's breach of state health and social services systems. Some are still down.

therecord.media EN 2025 Rhode-Island data-leak stolen data ransomware
Clop ransomware is now extorting 66 Cleo data-theft victims https://www.bleepingcomputer.com/news/security/clop-ransomware-is-now-extorting-66-cleo-data-theft-victims/
28/12/2024 11:58:18
QRCode
archive.org
thumbnail

The Clop ransomware gang started to extort victims of its Cleo data theft attacks and announced on its dark web portal that 66 companies have 48 hours to respond to the demands.

bleepingcomputer EN 2024 Cleo Clop Double-Extortion Extortion Ransomware
LockBit Ransomware Group Plots Comeback With 4.0 Release https://thecyberexpress.com/lockbit-ransomware-comeback-lockbit-4-0/
27/12/2024 11:56:17
QRCode
archive.org
thumbnail

The LockBit ransomware group will soon launch a comeback with the planned release of LockBit 4.0 in February 2025, Cyble

thecyberexpress EN 2024 LockBit ransomware LockBit4.0 comeback announce RaaS
Inside Operation Destabilise: How a ransomware investigation linked Russian money laundering and street-level drug dealing https://therecord.media/operation-destabilise-money-laundering-investigation-uk-nca
23/12/2024 13:44:58
QRCode
archive.org
thumbnail

U.K. investigators tell the story of how examining a cybercrime group's extortion funds helped to unravel a money-laundering network reaching from the illegal drug trade to Moscow's elite.

therecord.media EN 2024 Operation-Destabilise ransomware Russia UK cybercrime money-laundering
Medion hack? BlackBasta ransomware has allegedly copied 1.5 TB of data | heise online https://www.heise.de/en/news/Medion-hack-BlackBasta-ransomware-has-allegedly-copied-1-5-TB-of-data-10216148.html
21/12/2024 00:00:48
QRCode
archive.org
thumbnail

Cyber criminals claim to have successfully attacked Medion, a distributor of electronic products.

heise EN 2024 BlackBasta Cyberangriff Hacking MEDION Ransomware
Ascension: Health data of 5.6 million stolen in ransomware attack https://www.bleepingcomputer.com/news/security/ascension-health-data-of-56-million-stolen-in-ransomware-attack/
20/12/2024 13:09:00
QRCode
archive.org
thumbnail

​Ascension, one of the largest private U.S. healthcare systems, is notifying over 5.6 million patients and employees that their personal and health data was stolen in a May cyberattack linked to the Black Basta ransomware operation.

bleepingcomputer EN 2024 Ascension Data-Breach Healthcare Ransomware Security InfoSec Computer-Security
NotLockBit: A Deep Dive Into the New Ransomware Threat | Qualys Security Blog https://blog.qualys.com/vulnerabilities-threat-research/2024/12/18/notlockbit-a-deep-dive-into-the-new-ransomware-threat
20/12/2024 09:34:29
QRCode
archive.org
thumbnail

NotLockBit is a new and emerging ransomware family that actively mimics the behavior and tactics of the well-known LockBit ransomware.

qualys EN 2024 NotLockBit Ransomware analysis
https://www.forescout.com/blog/draytek-routers-exploited-in-massive-ransomware-campaign-analysis-and-recommendations/ https://www.forescout.com/blog/draytek-routers-exploited-in-massive-ransomware-campaign-analysis-and-recommendations/
16/12/2024 09:24:00
QRCode
archive.org
  • Our 2024 Dray:Break report revealed 14 new vulnerabilities in DrayTek devices
    *See our upcoming presentation at Black Hat Europe for more details
  • PRODAFT shared threat intelligence from 2023 on a ransomware campaign exploiting DrayTek devices
  • This is the first time this campaign is discussed publicly
  • Our analysis shows sophisticated attack workflows to deploy ransomware including possible:
    • Zero-day vulnerabilities
    • Credential harvesting and password cracking
      VPN and tunneling abuse
forescout en 2024 draytek ALPHV ransomware
Ransomware hackers target NHS hospitals with new cyberattacks https://techcrunch.com/2024/12/04/ransomware-hackers-target-nhs-hospitals-with-new-cyberattacks/
09/12/2024 11:03:43
QRCode
archive.org
thumbnail

Two NHS trusts in England have been hacked in recent weeks, the latest attacks to hit the national health service.

techcrunch EN 2024 INCRansomware NHS UK health ransomware
page 3 / 21
4261 links
Shaarli - The personal, minimalist, super-fast, database free, bookmarking service par la communauté Shaarli - Theme by kalvn - Curated by Decio