Security News

New VanHelsing ransomware targets Windows, ARM, ESXi systems
2025-03-24 19:43

A new multi-platform ransomware-as-a-service (RaaS) operation named VanHelsing has emerged, targeting Windows, Linux, BSD, ARM, and ESXi systems. [...]

VSCode Marketplace Removes Two Extensions Deploying Early-Stage Ransomware
2025-03-24 11:10

Cybersecurity researchers have uncovered two malicious extensions in the Visual Studio Code (VSCode) Marketplace that are designed to deploy ransomware that's under development to its users. The...

Medusa Ransomware Uses Malicious Driver to Disable Anti-Malware with Stolen Certificates
2025-03-21 12:58

The threat actors behind the Medusa ransomware-as-a-service (RaaS) operation have been observed using a malicious driver dubbed ABYSSWORKER as part of a bring your own vulnerable driver (BYOVD)...

AI will make ransomware even more dangerous
2025-03-21 06:00

Ransomware is the top predicted threat for 2025, which is especially concerning given 38% of security professionals say ransomware will become even more dangerous when powered by AI, according to...

VSCode extensions found downloading early-stage ransomware
2025-03-20 19:54

Two malicious VSCode Marketplace extensions were found deploying in-development ransomware from a remote server, exposing critical gaps in Microsoft's review process. [...]

RansomHub ransomware uses new Betruger ‘multi-function’ backdoor
2025-03-20 16:31

Security researchers have linked a new backdoor dubbed Betruger, deployed in several recent ransomware attacks, to an affiliate of the RansomHub operation. [...]

TechRepublic EXCLUSIVE: New Ransomware Attacks are Getting More Personal as Hackers ‘Apply Psychological Pressure”
2025-03-19 21:28

Ransomware attackers know where your kids go to school and they want you to know it, according to professional negotiators at Sygnia.

Medusa Ransomware Strikes 300+ Targets: FBI & CISA Urge Immediate Action to #StopRansomware
2025-03-17 21:01

Medusa ransomware now operates as a RaaS model, recruiting affiliates from criminal forums to launch attacks, encrypt data, and extort victims worldwide.

BlackLock ransomware claims nearly 50 attacks in two months
2025-03-17 20:40

A ransomware-as-a-service (RaaS) operation called 'BlackLock' has emerged as one of the more active ransomware operations of 2025. [...]

⚡ THN Weekly Recap: Router Hacks, PyPI Attacks, New Ransomware Decryptor, and More
2025-03-17 11:25

From sophisticated nation-state campaigns to stealthy malware lurking in unexpected places, this week’s cybersecurity landscape is a reminder that attackers are always evolving. Advanced threat...