Ransomware News: Noticis kiberuzbrukums Latvijas Valsts mežiem; drošības apsvērumu dēļ slēgts LVM GEO, karšu sistēma un "Mednis" [papildināts]2026-06-25
anggipradanareportUnited Kingdom
Noticis kiberuzbrukums Latvijas Valsts mežiem; drošības apsvērumu dēļ slēgts LVM GEO, karšu sistēma un "Mednis" [papildināts] Noticia sobre ransomware publicada en . Extracto Sin e...
Clearview Eye Centre2026-06-25
interlockransomwareCanada
Un incidente de ciberseguridad ha afectado a Clearview Eye Centre, una clínica oftalmológica en Calgary, Alberta. Según informaciones recientes, el grupo malicioso "interlock" ha comprometid...
Delegal Poindexter & Underkofler, P.A.2026-06-25
morpheusransomwareUnited States
Se ha reportado un incidente de ciberataque relacionado con ransomware afectando a Delegal Poindexter & Underkofler, P.A., una organización especializada en servicios legales. El grupo Morph...
StealthMole: 𝗗𝗮𝘆 𝟮 𝗶𝘀 𝗶𝗻 𝗳𝘂𝗹𝗹 𝘀𝘄𝗶𝗻𝗴 𝗮𝘁 𝗜𝗻𝘁𝗲𝗿𝗻𝗮𝘁𝗶𝗼𝗻𝗮𝗹 𝗣𝗼𝗹𝗶𝗰𝗲 𝗘𝘅𝗽𝗼 𝟮𝟬𝟮𝟲! The best part of an event isn't the presentations. It's the conversations happening in between. Day 2 has been full of great discussions, new connections, and live demos at the StealthMole booth. Thank you to everyone who's stopped by so far! If you're at the expo today, come visit us at 𝗕𝗼𝗼𝘁𝗵 𝗔𝟮𝟯. There's still plenty of time to connect, exchange ideas, and see StealthMole in action.2026-06-25
stealthmole_intcampaignUnited States
StealthMole cyber threat intelligence on ransomware, data leaks and criminal underground ecosystems.
StealthMole: One thing we've learned from 𝗗𝗮𝘆 𝟭 𝗮𝘁 𝗜𝗻𝘁𝗲𝗿𝗻𝗮𝘁𝗶𝗼𝗻𝗮𝗹 𝗣𝗼𝗹𝗶𝗰𝗲 𝗘𝘅𝗽𝗼 𝟮𝟬𝟮𝟲 The best part of any event isn't the booth. It's the people you meet. Today was filled with conversations, new perspectives, and plenty of great moments with visitors, partners, and friends from across the industry. Thank you to everyone who spent time with us at 𝗕𝗼𝗼𝘁𝗵 𝗔𝟮𝟯.2026-06-25
stealthmole_intcampaignUnited States
StealthMole cyber threat intelligence on ransomware, data leaks and criminal underground ecosystems.
Ido Cohen: Stormous is back with increased activity. Recent victims have had their public websites defaced with a ransomware message displayed directly on the homepage—a pressure tactic sometimes used by ransomware groups to increase urgency and force negotiations. DarkFeed makes it easy to compare a ransomware group's leak site with the victim's public website in one place, helping analysts quickly identify attacks like these.2026-06-25
ido_cohen2ransomwareUnited StatesT1566
Independent cyber threat research covering malware campaigns, phishing infrastructure and vulnerability exploitation.
Ido Cohen: Country Spotlight: Canada Over the past 7 days, our AI-powered platform tracked ransomware and cyber extortion attacks targeting Canada.2026-06-25
ido_cohen2ransomwareCanadaT1566
Independent cyber threat research covering malware campaigns, phishing infrastructure and vulnerability exploitation.
Ido Cohen: Sector Spotlight: HealthCare Over the past 7 days, our AI-powered platform tracked ransomware and cyber extortion groups actively targeting the HealthCare sector.2026-06-25
ido_cohen2ransomwareUnited StatesT1566
Independent cyber threat research covering malware campaigns, phishing infrastructure and vulnerability exploitation.
Group-IB Threat Intelligence: The Y2K Operators threat actor is using sophisticated #socialengineering lures, disguising payloads as legitimate software, cracked applications, gaming cheat tools (e.g., Roblox), and used PDF decoy documents.2026-06-25
GroupIB_TIcampaignUnknown
Group-IB Threat Intelligence feed featuring APT research, ransomware analysis and cybercrime investigations.
Group-IB Threat Intelligence: Group-IB telemetry has identified over 62,000 compromised endpoints across more than 160 countries infected with #MilleniumRAT (4.x). The infection velocity is alarming, with over 39,000 of these detections occurring in Q1 2026 alone, representing 64% of all infections. This demonstrates a rapidly accelerating global campaign.2026-06-25
GroupIB_TIcampaignUnknown
Group-IB Threat Intelligence feed featuring APT research, ransomware analysis and cybercrime investigations.
Group-IB Threat Intelligence: Pinned: #MilleniumRAT (v4.x) marks a significant evolution in the threat landscape. The #malware has been completely rewritten from .NET to a native C++ application, removing .NET dependencies. This architectural shift enables greater stealth and resilience, making detection more challenging. The #Telegram Bot API remains the core C2 mechanism.2026-06-25
GroupIB_TImalwareUnknown
Group-IB Threat Intelligence feed featuring APT research, ransomware analysis and cybercrime investigations.
Ransomware News: «Ðобилизовали веÑÑ ÐºÐ¾Ð»Ð»ÐµÐºÑив»: «УÑагоÑмолзавод» пеÑевели в «ÑÑÑной Ñежим» из-за кибеÑаÑаки2026-06-24
anggipradanareportUnknown
«Ðобилизовали веÑÑ ÐºÐ¾Ð»Ð»ÐµÐºÑив»: «УÑагоÑмолзавод» пеÑевели в «ÑÑÑной Ñежим» из-за кибеÑаÑаки Noticia sobre ransomware publicad...