Babuk Ransomware Deployed in vCenter Attacks
In at least one case, the vCenter exploitation campaign led to the deployment of Babuk-derived ransomware, compromising 361 victim IPs across 47…
In at least one case, the vCenter exploitation campaign led to the deployment of Babuk-derived ransomware, compromising 361 victim IPs across 47…
vSphere, VMware's virtualization platform, was targeted in ransomware attacks. Attackers created administrative accounts and deployed Babuk-derived ransomware on ESXi hosts.
Cybersecurity researchers have attributed the exploitation of a newly patched security flaw in Broadcom VMware vCenter to a suspected China-nexus advanced persistent…
BianLian is a cybercrime group that has been observed exploiting SAP vulnerabilities, including CVE-2025-31324, for ransomware and other malicious activities.
RansomExx is a ransomware group that has exploited SAP vulnerabilities such as CVE-2025-31324 to gain access to victim networks.
HiddenTear is a ransomware family whose signatures have been found in artifacts communicating with Sable Squirrel's infrastructure, indicating potential ransomware activity within…
A new White House memo signed by U.S. President Donald Trump directs the National Coordination Center (NCC) to establish a program allowing…
Transnational Criminal Organizations (TCOs) are foreign groups that conduct cyber-enabled crimes such as ransomware, phishing, financial fraud, sextortion, and pig butchering scams…
Ransomware is a type of malware deployed by Transnational Criminal Organizations to extort victims. The White House memo highlights ransomware as one…
This week's ThreatsDay Bulletin covers a wide range of cybersecurity developments, including new attack techniques, data breaches, and product updates. Key highlights…