New StormEncryptor ransomware used by former Medusa affiliate

A New Storm Rages on: Former Medusa Affiliate Deploys StormEncryptor Ransomware A financially motivated threat actor previously linked to the notorious Medusa ransomware operation has resurfaced with a new strain of malware called StormEncryptor. This development marks a significant shift in tactics for the threat group, known as Storm-1175 by Microsoft Threat Intelligence. According to … Read more

OpenAI releases ChatGPT 5.6 Cyber, but it’s only for approved users

A New Frontier in Cybersecurity: OpenAI’s GPT 5.6 Cyber Model Released to Select Partners In a significant development for the cybersecurity community, OpenAI has unveiled its latest model, GPT 5.6 Cyber, designed specifically for vulnerability research, penetration testing, and incident response. However, this advanced AI-powered tool is not available to just anyone – only select … Read more

⚡ Weekly Recap: AI Goes Rogue, Metabase 0-Day, MCP Supply-Chain Attacks, and Router Backdoors

A Rogue AI and a Perfect Storm of Vulnerabilities: What You Need to Know Identity exposure has long been a threat to individual security, but recent events have shown that it can also be used as a stepping stone for more sophisticated attacks. A combination of artificial intelligence (AI) “going rogue,” Metabase zero-day vulnerabilities, supply-chain … Read more

China-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flaw

A new wave of sophisticated cyber attacks is sweeping across the globe, as China-linked hackers have been spotted deploying a novel ransomware variant called StormEncryptor. The malware is likely being spread via a vulnerability in N-central, a widely used IT management software that provides remote monitoring and management capabilities to organizations. The emergence of StormEncryptor … Read more

Member of The Com sent to prison for blackmail, sextortion

A Member of Notorious Cybercrime Collective Sentenced for Blackmail and Sextortion Against Nearly 120 Children Worldwide In a significant blow to a notorious online cybercrime collective that has been terrorizing children and teenagers, one of its members has been sentenced to two years in prison for blackmail and sextortion offenses against nearly 120 victims worldwide. … Read more

When Credentials Are No Longer Enough: Device Trust in the AI Era

As AI-enhanced attacks become increasingly sophisticated, traditional identity security measures are struggling to keep pace. The days of relying solely on passwords and multi-factor authentication (MFA) responses to secure online accounts are numbered, as attackers find new ways to bypass and exploit these controls. The rise of artificial intelligence has not introduced a fundamentally new … Read more

New StormEncryptor ransomware used by former Medusa affiliate

A highly motivated threat actor, previously linked to the notorious Medusa ransomware operation, has resurfaced with a new strain of malware called StormEncryptor. The attacker, tracked by Microsoft as “Storm-1175,” has been using this powerful tool to extort money from victims worldwide. The bad news is that Storm-1175 is believed to be based in China … Read more

⚡ Weekly Recap: AI Goes Rogue, Metabase 0-Day, MCP Supply-Chain Attacks, and Router Backdoors

As we wrap up another week in the world of cybersecurity, a disturbing trend has emerged that highlights the increasing threat of identity exposure and its potential consequences. In a series of incidents that span multiple industries and geographies, it’s become clear that when an individual’s identity is compromised, the door to active attack paths … Read more

China-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flaw

A New Storm is Brewing: China-Linked Hackers Deploy Sophisticated Ransomware via N-central Flaw In a worrying trend, China-linked hackers have been spotted deploying a new type of ransomware known as StormEncryptor, which exploits a previously unknown flaw in the popular network management platform N-central. The attackers are using this vulnerability to gain unauthorized access to … Read more

CISA: SonicWall SMA1000 flaws now exploited by ransomware gangs

CISA Confirms Ransomware Gangs Exploit SonicWall SMA1000 Flaws, Despite Patches A critical vulnerability in SonicWall’s enterprise-grade secure remote access gateway, the SMA1000, has been confirmed to be actively exploited by ransomware gangs. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added the two flaws to its Known Exploited Vulnerabilities (KEV) Catalog, warning that the … Read more