Akira Ransomware: Defense Evasion Tactics and Safe Mode Reboot Incident
Akira ransomware continues to use defense evasion tactics, such as rebooting victim hosts into Safe Mode with Networking to disable security tools.…
MITRE ATT&CK groups, threat actors, intrusion sets and activity clusters.
Akira ransomware continues to use defense evasion tactics, such as rebooting victim hosts into Safe Mode with Networking to disable security tools.…
Lynx is a ransomware affiliate program that has been observed deploying DeadLock ransomware. This indicates a growing trend of affiliates using multiple…
Sinobi was identified as a relevant cybersecurity entity in recently ingested reporting. This profile is generated so related cyber news, CVEs, malware,…
Cybersecurity researchers have charted the evolution of INC from a nascent ransomware-as-a-service (RaaS) operation to one of the most prolific cybercrime groups…
INC Ransomware is another affiliate program that has been linked to the deployment of DeadLock ransomware. The collaboration between different ransomware groups…
Icarus is an extortion group active since April 28, 2026, responsible for compromising Klue's integration infrastructure and exfiltrating customer data via OAuth…
ShinyHunters is a well-known threat actor group infamous for large-scale data breaches and selling stolen data. They have previously exploited Salesforce guest…
UNC6395 is a threat actor group associated with prior OAuth abuse campaigns targeting Salesforce environments. The Klue incident shares similarities with their…
Suspected Russian-speaking threat actors compromised over 30,000 Fortinet firewalls across 194 countries in a large-scale credential harvesting campaign dubbed FortiBleed. They used…
Warlock was identified as a relevant cybersecurity entity in recently ingested reporting. This profile is generated so related cyber news, CVEs, malware,…