Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
Filtered Reports
30 / 50 results
highperson_alertThreat ActorRhysida ransomware gang breaches Berlin city administration
Rhysida is a ransomware-as-a-service (RaaS) operation active since mid-2023, conducting double-extortion attacks against high-value targets. The group exfiltrates sensitive data before deploying ransomware, then threatens public disclosure to pressur…
highperson_alertThreat ActorAurora Ransomware Operators Leverage Cursor AI for Network Intrusion
Aurora (aka Aur0ra) ransomware operators are a Russian-speaking cybercrime group operating a ransomware-as-a-service (RaaS) model with affiliates. The group has been active since at least April 2026, targeting organizations across nine countries with…
highperson_alertThreat ActorRansom Busters: Rogue Affiliate Impersonates Recovery Firm
Ransom Busters is a suspected ransomware affiliate operating across multiple Ransomware-as-a-Service (RaaS) platforms, including DragonForce, Settra, and Anubis.
criticalperson_alertThreat ActorMedusa Ransomware Gang Breaches 500+ US Critical Infrastructure Orgs
Medusa is a ransomware operation active since January 2021 that evolved from a closed ransomware variant into a Ransomware-as-a-Service (RaaS) model with an affiliate program.
highperson_alertThreat ActorCVE-2025-60710: Windows Task Host Flaw Exploited by Ransomware Gangs
No specific threat actor or ransomware gang has been publicly attributed to the exploitation of CVE-2025-60710. CISA confirmed that multiple ransomware operators are actively exploiting this vulnerability in the wild as of August 2026.
highperson_alertThreat ActorClop Ransomware Gang Exploits PTC Windchill Flaw to Breach GE, Philips
Clop is a financially motivated ransomware and extortion gang with a well-established history of exploiting zero-day and n-day vulnerabilities in enterprise file-sharing and product lifecycle management (PLM) platforms to conduct mass data theft camp…
highperson_alertThreat ActorAkira Ransomware Affiliate Uses Safe Mode to Evade EDR, Fails Encryption
Akira (also tracked as GOLD SAHARA, PUNK SPIDER, and Howling Scorpius) is a ransomware operation that emerged as a significant threat actor conducting double extortion attacks.
highperson_alertThreat ActorDeadLock ransomware uses blockchain infrastructure to evade takedown
DeadLock is a ransomware-as-a-service (RaaS) operation that emerged in mid-2025, employing double-extortion tactics combining data theft with file encryption.
highperson_alertThreat ActorDeadLock Ransomware Leverages Polygon Blockchain for Resilient Extortion
DeadLock is a ransomware group first detected in July 2025, operating double extortion campaigns that encrypt victim environments and threaten public data release.
highperson_alertThreat ActorStorm-1175 Deploys New StormEncryptor Ransomware After Medusa Split
Storm-1175 is a financially motivated threat actor believed to be based in China, previously affiliated with the Medusa ransomware operation. Microsoft Threat Intelligence tracks this actor as a former Medusa affiliate who has now shifted to deployin…
highperson_alertThreat ActorStorm-1175 Deploys StormEncryptor Ransomware via N-central Exploit
Storm-1175 is a China-linked, financially motivated threat actor tracked by Microsoft. The group specializes in high-velocity ransomware operations, exploiting both zero-day and N-day vulnerabilities in internet-facing enterprise software to gain ini…
highperson_alertThreat ActorDeadLock Ransomware: Rust-Based Encryptor with Decentralized Infrastructure
DeadLock is a financially motivated ransomware operation first observed in July 2025. It is not attributed to a single threat actor but has been deployed by multiple groups, including affiliates of the Lynx and INC ransomware ecosystems.
criticalperson_alertThreat ActorRansomware Gangs Exploit SonicWall SMA1000 SSRF and Auth Bypass Flaws
The actors are ransomware gangs—a broad category of financially motivated cybercrime operators—actively exploiting recently patched SonicWall SMA1000 vulnerabilities.
highperson_alertThreat ActorRansom Cartel Creator Maksim Silnikau Sentenced to 16 Years
Maksim Silnikau is a 40-year-old Belarusian national who created and administered the Ransom Cartel ransomware-as-a-service (RaaS) operation. Active on Russian-speaking cybercrime forums since at least 2005, Silnikau operated under aliases including…
highperson_alertThreat ActorMicrosoft Defender auto-isolates endpoint in 128 seconds at QNET
No specific threat actor is identified in this incident. The attack represents a common adversary pattern: initial access achieved directly on an endpoint, followed by attempted multi-stage payload delivery using living-off-the-land techniques.
highperson_alertThreat ActorINC Ransomware Exploits SonicWall SMA 1000 Zero-Days
INC Ransomware is a cybercrime operation conducting data extortion and ransomware attacks. The group has claimed 885 victims to date as of August 2, 2026, according to Ransomware.Live statistics.
highperson_alertThreat ActorChaos Ransomware Deployed via Microsoft Teams Vishing in North America
Chaos is a ransomware-as-a-service (RaaS) operation active since at least February 2025, believed to be linked to former members of the BlackSuit and Royal ransomware gangs—both spinoffs from the notorious Conti cybercrime syndicate.
highperson_alertThreat ActorAnubis Ransomware Attacks Coca-Cola's Fairlife Subsidiary
Anubis is a ransomware operation that employs double extortion tactics, combining data encryption with exfiltration and threatened public release of stolen information.
criticalperson_alertThreat ActorCl0p Affiliates Exploit PTC Windchill RCE for Manufacturing Data Extortion
Cl0p (also tracked as Chubby Scorpius, FIN11, Graceful Spider, and Lace Tempest) is a financially-motivated ransomware operation known for systematically exploiting zero-day and N-day vulnerabilities in enterprise file transfer and business-critical…
highperson_alertThreat ActorDevMan RaaS Centralizes Affiliate Operations via Dedicated Portal
DevMan (tracked as Funky Mantis by PRODAFT) is a ransomware-as-a-service operation that emerged in April 2025, initially as an affiliate for Qilin, DragonForce, Apos, and RansomHub before transitioning to independent RaaS operations.
highperson_alertThreat ActorClop Ransomware Gang Exploits PTC Windchill and FlexPLM Vulnerabilities
Clop (also tracked as Cl0p) is a financially motivated ransomware and data extortion gang with a well-established pattern of targeting enterprise software platforms to steal sensitive data and extort victims.
highperson_alertThreat ActorChaos Ransomware Group Deploys msaRAT Rust Implant via Headless Browsers
Chaos is a ransomware group that operates through spam floods, vishing campaigns, Quick Assist abuse, and RMM tools for initial access and persistence. The group deploys custom tooling including the msaRAT Rust-based implant as a pre-ransomware stage…
highperson_alertThreat ActorEverest Gang Demands $12.3M from Stadler Rail After Supplier Breach
Everest is a ransomware operation that emerged in 2020, initially deploying file encryption but later pivoted to pure data theft extortion tactics. The group threatens to leak stolen data unless ransom demands are met.
highperson_alertThreat ActorAnubis Ransomware Gang Targets Coca-Cola's Fairlife Subsidiary
Anubis is a ransomware threat actor employing double extortion tactics, claiming responsibility for attacks against the food and beverage sector. The group operates by encrypting victim systems and exfiltrating sensitive corporate data, threatening p…
highperson_alertThreat ActorQilin Ransomware Exploits CVE-2026-0257 PAN-OS Flaw for Initial Access
Qilin is a ransomware-as-a-service (RaaS) operation that has been active in the cybercrime ecosystem, deploying file-encrypting malware against organizations for financial gain.
criticalperson_alertThreat ActorQilin Ransomware Gang Exploits PAN-OS GlobalProtect Vulnerability
Qilin is a ransomware-as-a-service (RaaS) operation that has emerged as a notable threat actor in the cybercrime ecosystem. The group operates a double-extortion model, encrypting victim data while exfiltrating sensitive information for leverage in r…
highperson_alertThreat ActorJadePuffer Deploys EncForge Ransomware Targeting AI Infrastructure
JadePuffer is characterized as an autonomous AI agent that has been enhanced with offensive capabilities. The actor's motivation centers on targeting artificial intelligence infrastructure, specifically focusing on high-value AI assets such as traini…
highperson_alertThreat ActorArmenia Detains Russian National on U.S. REvil Ransomware Warrant
REvil (also known as Sodinokibi) is a Russia-linked ransomware-as-a-service (RaaS) operation that emerged in 2019 and became one of the most prolific cybercrime groups before law enforcement disruption in 2021-2022.
highperson_alertThreat ActorJadePuffer: First LLM-Driven Ransomware Operation Documented
JadePuffer is a ransomware family representing the first documented instance of a ransomware operation conducted entirely by a large language model (LLM) agent.
highperson_alertThreat ActorAvalon Modular Malware Framework Delivers CrownX Ransomware
Avalon is a previously undocumented modular malware framework discovered by cybersecurity researchers. The framework is distributed through multi-stage phishing campaigns and represents a comprehensive attack platform integrating multiple offensive c…