Mamona ransomware group compromised: DragonForce exploits OPSEC failures
The cybersecurity landscape is once again witnessing the fallout of poor operational security (OPSEC) among ransomware operators. In the latest turn of events, Mamona, a ransomware group rebranded...
Western Alliance Bank data breach: 21,899 customers impacted
The recent data breach at Western Alliance Bank underscores a growing concern in the cybersecurity landscape: the risks posed by third-party software vulnerabilities. This incident not only highlights...
Akira ransomware’s ingenious IoT gambit: when webcams become cyberweapons
Akira group demonstrated how unsecured IoT devices can bypass enterprise-grade defenses. In a case analyzed by S-RM, attackers weaponized a vulnerable webcam to execute an end-run around EDR...
The CrazyHunter ransomware attack on Makai Hospital
On February 9, 2025, Makai Memorial Hospital in Taiwan became the latest victim of a devastating ransomware campaign orchestrated by the Hunter Ransom Group. The attack, which leveraged...
Fog’s dubious GitLab claims: investigation on instances
One name that has been gaining traction since late January is Fog, a ransomware operation that has been particularly vocal about targeting GitLab instances. Fog has claimed responsibility...
Black Basta and CACTUS ransomware: shared BackConnect module signals affiliate transition
Recent analysis has revealed a significant overlap in the tactics, techniques, and procedures (TTPs) employed by the Black Basta and CACTUS ransomware groups. Specifically, researchers have uncovered that...
Anubis: new ransomware threat
A new player has emerged in the ransomware landscape: Anubis. This group, first observed in December 2024, is quickly making a name for itself through a multi-faceted extortion...
Ghost Ransomware: an analysis of tactics, targets, and techniques
A joint advisory from CISA, the FBI, and the MS-ISAC sheds light on the activities of the Ghost ransomware gang, a cybercriminal group that has been actively targeting...