Attacker Uses Suspected AI-Generated PowerShell Script to Map Active Directory
Cybersecurity researchers at Huntress have identified an intrusion where an unknown threat actor used a suspected AI-generated PowerShell script to enumerate Active…
Cybersecurity researchers at Huntress have identified an intrusion where an unknown threat actor used a suspected AI-generated PowerShell script to enumerate Active…
LAPSUS$ is a cyber extortion group that has targeted major corporations. As part of The Com collective, they have been associated with…
A 41-year-old former ransomware negotiator, Angelo Martino, has been sentenced to 70 months in prison for conspiring with the now-defunct BlackCat ransomware…
The extortion contact email e78393397@proton.me was used in both the prior JADEPUFFER campaign and the ENCFORGE ransomware campaign.
The first known case of agentic ransomware, codenamed JADEPUFFER, where a human operator deployed an artificial agent to handle the entire extortion…
Octo Tempest is an alternative tracking name for the Scattered Spider extortion crew, used by threat intelligence firms to identify the group's…
UNC3944 is Mandiant's designation for the threat actor group known as Scattered Spider. The group has been involved in numerous high-profile extortion…
Transport for London (TfL) suffered a significant cyberattack in September 2024, attributed to Scattered Spider hackers. The attack disrupted services, compromised customer…
The ShinyHunters extortion crew exploited an unpatched remote code execution vulnerability in Oracle PeopleSoft (CVE-2026-35273) to breach enterprise systems, primarily targeting universities.…
Scattered Spider, also tracked as Octo Tempest, UNC3944, and 0ktapus, is an extortion crew known for data extortion, SIM swapping, and social…