Browsing: Ransomware

Microsoft says China-linked, financially motivated threat actor Storm-1175 has begun using a new ransomware strain called StormEncryptor. The group previously relied on Medusa ransomware. StormEncryptor is written in C++ and encrypts files and adds the .encrypted extension, then leaves a !!!README_FIRST!!!.txt ransom note in each scanned directory. The change suggests an evolution in the group’s…

Ransomware protection is a coordinated set of controls that reduces the likelihood of compromise, detects and contains malicious activity, protects recovery infrastructure and restores operations when an attack succeeds. It spans identity security, vulnerability and patch management, endpoint protection, EDR or XDR, incident response, targeted rollback, immutable backup and disaster recovery. No single control covers…

For the past year, the ransomware conversation has centered on concentration: a handful of dominant RaaS operations controlling most of the damage, and a shrinking pool of active groups fighting over the same territory. The State of Ransomware Q2 2026 report from Check Point Research shows that picture starting to shift. The leaders are still winning, but…

A high-severity bug in Microsoft SharePoint that’s been exploited since early July has been abused by ransomware, according to an Aug. 10 update to the Cybersecurity and Infrastructure Security Agency’s Known Exploited Vulnerabilities (KEV) catalog.CISA offered no more information on the nature of the ransomware attack, but the CVSS 8.8 flaw — CVE-2026-45659 — was…

U.S. and international agencies released a joint cybersecurity advisory Aug. 10 warning of actions by Gunra ransomware. Gunra is a ransomware-as-a-service program that has been used to target government, critical infrastructure — including healthcare — and other organizations in the U.S. and abroad. Gunra actors leverage a double-extortion model, both encrypting data and threatening to publish stolen data to a dedicated leak…