Results for: ransomware

Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Warlock (Storm-2603) exploits SmarterMail vulnerability

Cybersecurity Threat Advisory: Warlock (Storm-2603) exploits SmarterMail vulnerability

SmarterTools has confirmed that the Warlock ransomware group (Storm‑2603) breached its environment by exploiting an unpatched SmarterMail instance. Current intelligence indicates the same SmarterMail vulnerability is being actively used in the wild to gain initial access and deploy Warlock ransomware....

/ February 12, 2026
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Critical FortiClientEMS SQL injection vulnerability

Cybersecurity Threat Advisory: Critical FortiClientEMS SQL injection vulnerability

An improper neutralization of special elements used in SQL commands in Fortinet FortiClientEMS 7.4.4 may allow an unauthenticated attacker to execute unauthorized code or commands through specially crafted HTTP requests. This vulnerability, tracked as CVE‑2026‑21643 with a CVSS score of...

/ February 12, 2026
ransomware
Welcome to ‘Ranswomare 2.0’

Welcome to ‘Ranswomare 2.0’

Ransomware attacks have evolved from simple encryption schemes into sophisticated extortion operations that render traditional defenses obsolete. In recent years, data exfiltration has occurred in 87 percent of ransomware incidents, according to the 2024 Verizon Data Breach Investigations Report, while...

/ February 10, 2026
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Tsundere Bot malware loader

Cybersecurity Threat Advisory: Tsundere Bot malware loader

A new malware loader, Tsundere Bot, is increasingly used by criminal Initial Access Brokers (IABs) to compromise corporate environments and pave the way for ransomware attacks. Recent public reporting links Tsundere Bot to ClickFix‑style phishing, malicious loaders delivered through user...

/ February 3, 2026
Start the year strong: 10 essential questions every IT team should address

Start the year strong: 10 essential questions every IT team should address

It’s a new year (and also a day ending in Y), which means it’s an excellent time for you to review your security posture. Use your renewed energy to seriously analyze your vulnerabilities, detection methods and organizational procedures. Answer these...

/ February 2, 2026
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Critical VMware vCenter Server vulnerability

Cybersecurity Threat Advisory: Critical VMware vCenter Server vulnerability

CISA has added a critical VMware vCenter Server vulnerability to its Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. The flaw is tracked as CVE‑2024‑37079 with a CVSS score of 9.8. It was originally patched in June 2024...

/ January 27, 2026
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Malicious browser extension in ClickFix variant

Cybersecurity Threat Advisory: Malicious browser extension in ClickFix variant

Security researchers have uncovered an active malvertising campaign abusing a fake ad‑blocking extension that intentionally crashes Google Chrome and Microsoft Edge to trick users into executing malicious commands—a new evolution of the ClickFix technique known as “CrashFix.” Read the Cybersecurity...

/ January 21, 2026
Threat Spotlight: How phishing kits evolved in 2025

Threat Spotlight: How phishing kits evolved in 2025

In 2025, 90 percent of high-volume phishing campaigns leveraged Phishing-as-a-Service (PhaaS) kits. These kits have transformed the phishing landscape, enabling even less-skilled cybercriminals to access advanced tools and automation and launch large-scale, targeted phishing campaigns, often impersonating legitimate services and...

/ January 12, 2026
Cybersecurity in 2026: Experts predict what’s next

Cybersecurity in 2026: Experts predict what’s next

Over the past two weeks, we’ve reflected on 2025’s cybersecurity developments—with a few glimpses into 2026. Today, we turn our full attention to the year ahead, sharing predictions from leading experts on what’s next for cybersecurity. AI will elevate phishing...

/ January 8, 2026
Cybercrime in 2026: Faster, smarter and fully industrialized

Cybercrime in 2026: Faster, smarter and fully industrialized

Cybercrime is no longer a loose collection of hackers, tools and opportunistic attacks. As we move into 2026, it has matured into a highly industrialized ecosystem—complete with specialization, automation, affiliate networks, and even cartel-like business models. The result is a...

/ January 5, 2026