Skip to content
Tech News
clear
Topics: Today This Week This Month This Year

ShinyHunters breach Clop's dark web leak site, demand extortion payment

ShinyHunters, a data-theft and extortion group, defaced rival ransomware gang Clop's dark web leak portal over the weekend, claiming to have exploited an unpatched file-upload flaw in the site's Grav CMS. The attackers say they stole Clop's source code, plugins, system logs and private encryption keys, and are now demanding an unspecified eight-figure Bitcoin payment from Clop while threatening to expose details of victims who paid ransoms.

ShinyHunters breaches Clop ransomware's leak site, defaces it and claims stolen data

The extortion group ShinyHunters says it exploited an unauthenticated file upload flaw in Grav CMS to compromise the Tor-based data leak site run by the Clop ransomware operation. The attackers uploaded a taunting message, later fully defaced the site with Pokémon-themed ASCII art, and claim to have exfiltrated source code, CMS plugins, system logs and other server files. BleepingComputer confirmed the defacement was live on Clop's infrastructure and that the uploaded file could be downloaded from the site.

Ransomware's hidden costs dwarf ransom payments, new data shows

IBM's Cost of a Data Breach Report 2025 puts the average total cost of a ransomware incident at $5.08 million once downtime, remediation, legal work and business disruption are counted, while Verizon's 2026 DBIR pegs the median ransom payment at just $139,875. Datto's State of BCDR Report 2025 adds that while over 60% of organizations expect to recover within a day, only 35% actually do, and attackers increasingly target backup systems, forcing costly forensic and incident-response work when recovery options are compromised.

CISA confirms active exploitation of ConnectWise ScreenConnect flaw CVE-2026-84869

CISA has added a critical ScreenConnect vulnerability, now designated CVE-2026-84869, to its known exploited vulnerabilities catalog after confirming attackers are actively abusing it. The flaw stems from missing authorization checks that let low-privilege users transfer and execute files during active remote sessions without host confirmation, and it has been fixed in ScreenConnect 26.6.5. Federal agencies have been given three days to patch, while Shadowserver reports over 1,000 unpatched, internet-exposed ScreenConnect servers, mostly in North America and Europe.

2026's cybersecurity year in review: DOGE Social Security data exposure among worst breaches

A year-end review of 2026's major hacks highlights an unresolved controversy over the Department of Government Efficiency's access to Social Security Administration data. Ongoing federal lawsuits and a whistleblower's claims allege DOGE staff uploaded a live copy of the Social Security database to an unsecured third-party server, potentially exposing sensitive personal information tied to most living Americans. The broader roundup also notes a year marked by ransomware, nation-state attacks on infrastructure, and data weaponization by governments.

CISA confirms ransomware groups exploiting critical VMware vCenter flaw CVE-2026-59310

CISA has updated its Known Exploited Vulnerabilities catalog to flag ransomware gangs actively exploiting a critical VMware vCenter directory traversal flaw, CVE-2026-59310, patched by Broadcom in July. The bug had already been abused by a suspected APT group to compromise over 361 IP addresses across 47 countries, and Shadowserver now tracks more than 450 exposed vCenter servers online.

Ukrainian national gets 4-year sentence for role in Conti ransomware operation

Oleksii Oleksiyovych Lytvynenko, 44, was sentenced to four years in prison for participating in the Conti ransomware conspiracy as an intruder and malware developer. He pleaded guilty to conspiracy to commit wire fraud, admitting he controlled stolen data from 12 victim companies, sent extortion notes, and coded a loader tool used to launch attacks between 2020 and 2022. He was arrested in Ireland in 2023 and extradited to the U.S. to face charges.

Mantax Otax Android Malware Blends Ransomware and Spyware to Extort Indonesian Victims

Security firm Zimperium has identified a new Android malware called Mantax Otax that combines file encryption with data theft, distributed via malicious APKs outside Google Play through phishing lures aimed at Indonesian users. Once installed, it abuses Accessibility permissions to harvest device data, report to a GitHub-hosted command server, and on older Android versions (9 and below) encrypts files, replaces images with ransom notes, and opens a Firebase-hosted chat to negotiate payment. Researchers exploited a misconfigured Firebase server to expose the attackers' actual conversations with victims.

Cisco Talos: Ransomware and state hackers exploit FMC firewall flaws

Cisco Talos reported that three distinct threat groups—including Qilin ransomware affiliates and state-sponsored actors—have been exploiting two vulnerabilities in Cisco Secure Firewall Management Center. The flaws, a maximum-severity authentication bypass (CVE-2026-20079) and a static credential issue (CVE-2026-20316), let attackers gain root access, deploy web shells, steal credentials, and in some cases install Qilin ransomware or Cyclops Blink malware. Cisco has issued hot fixes and urges immediate patching, with broader hardening updates planned next week.

CISA confirms ransomware groups exploiting WatchGuard Firebox flaw CVE-2025-14733

CISA has updated its Known Exploited Vulnerabilities catalog to warn that ransomware operators are now actively abusing a critical remote-code-execution bug in WatchGuard Firebox firewalls, first flagged as exploited back in December. The flaw, an out-of-bounds write bug affecting multiple Fireware OS versions, lets unauthenticated attackers run code remotely, particularly on devices configured for IKEv2 VPN. Shadowserver data shows nearly 9,000 Firebox devices remain unpatched online nine months after fixes were released.

Veradigm confirms patient data breach tied to vendor credential theft

Veradigm, the Chicago-based healthcare technology firm formerly known as Allscripts, disclosed in an SEC filing that an attacker used stolen credentials from a third-party vendor to access a customer-service API and copy patient data. The exposed information includes personal details and Social Security numbers for a limited number of patients, though clinical records were not accessed. The Gentlemen ransomware group has claimed responsibility for the attack.

Today's top topics: openai apple anthropic artificial intelligence qualcomm claude opus 5.5 iphone 18 pro ai safety motorola signature 27 sam altman
View all today's topics →