Subscribe to Updates
Get the latest business software news from BitComme.
Browsing: Ransomware
Shutting down endpoint detection and response (EDR) tools before encryption begins has become standard operating procedure across the ransomware ecosystem, analysis of attacks by researchers at Halcyon has warned.
Microsoft says China-linked, financially motivated threat actor Storm-1175 has begun using a new ransomware strain called StormEncryptor. The group previously relied on Medusa ransomware. StormEncryptor is written in C++ and encrypts files and adds the .encrypted extension, then leaves a !!!README_FIRST!!!.txt ransom note in each scanned directory. The change suggests an evolution in the group’s…
Ransomware protection is a coordinated set of controls that reduces the likelihood of compromise, detects and contains malicious activity, protects recovery infrastructure and restores operations when an attack succeeds. It spans identity security, vulnerability and patch management, endpoint protection, EDR or XDR, incident response, targeted rollback, immutable backup and disaster recovery. No single control covers…
For the past year, the ransomware conversation has centered on concentration: a handful of dominant RaaS operations controlling most of the damage, and a shrinking pool of active groups fighting over the same territory. The State of Ransomware Q2 2026 report from Check Point Research shows that picture starting to shift. The leaders are still winning, but…
A ransomware affiliate’s attempt to disable security tools by rebooting a victim’s system into Safe Mode backfired, with the tactic apparently preventing the malware from successfully encrypting the target’s file, according to recent research by Huntress.
Threat actors such as Punk Spider, the group behind Akira ransomware, have significantly increased their activity and are targeting SMBs, according to CrowdStrike’s Justin Bradley.
A ransomware attack against one of Canada’s largest healthcare facilities has demonstrated how cyber incidents can extend beyond data and computer networks to disrupt the physical infrastructure that keeps a hospital operational.
A high-severity bug in Microsoft SharePoint that’s been exploited since early July has been abused by ransomware, according to an Aug. 10 update to the Cybersecurity and Infrastructure Security Agency’s Known Exploited Vulnerabilities (KEV) catalog.CISA offered no more information on the nature of the ransomware attack, but the CVSS 8.8 flaw — CVE-2026-45659 — was…
U.S. and international agencies released a joint cybersecurity advisory Aug. 10 warning of actions by Gunra ransomware. Gunra is a ransomware-as-a-service program that has been used to target government, critical infrastructure — including healthcare — and other organizations in the U.S. and abroad. Gunra actors leverage a double-extortion model, both encrypting data and threatening to publish stolen data to a dedicated leak…
Disrupting IT systems that support industrial environments can be enough to interrupt production, even when ransomware operators do not gain direct access to industrial control systems (ICS)