The Belarusian creator and administrator of the Ransom Cartel ransomware was sentenced to 16 years in prison in the US. Maksim Silnikau, 40, built the ransomware operation and recruited other individuals through cybercrime forums, according to documents presented in court. Silnikau provided Ransom Cartel conspirators with stolen credentials and other information on compromised computers, as ..
Tag : Cybercrime
Una vulnerabilità critica nella piattaforma AI di ServiceNow consente a un attaccante non autenticato di eseguire codice da remoto e prendere il controllo dell’istanza. Identificata come CVE-2026-6875 , è passata dalla pubblicazione del proof of concept tecnico ai primi payload osservati in rete in circa 72 ore, e la finestra di esposizione per chi gestisce ..
Una vulnerabilità critica nel cuore di WordPress consente a un attaccante anonimo di eseguire codice da remoto su un’installazione standard, senza credenziali, senza plugin e senza interazione della vittima. La falla, battezzata wp2shell dai ricercatori di Searchlight Cyber (divisione Assetnote) che l’hanno scoperta, colpisce il core della piattaforma che, secondo la stessa società, sostiene oltre ..
Il team GReAT di Kaspersky ha documentato nel report di Securelist OkoBot, un framework malevolo composto da oltre venti moduli che colpisce gli utenti di criptovaluta su Windows. La catena di attacco è stata ridisegnata a fine aprile 2025; la telemetria sulle vittime copre il periodo aprile 2025-giugno 2026 e GReAT ne ha identificato gli ..
Two members of the Scattered Spider cybercrime group have been sentenced to jail in the United Kingdom, the country’s National Crime Agency (NCA) announced on Thursday. Thalha Jubair, 20, and Owen Flowers, 18, were charged over their role in a 2024 cyberattack targeting Transport for London (TfL), which caused significant disruptions and generated costs of ..
Una finta promozione, la promessa di 100 dollari e un bot Telegram: è la trappola con cui, in una campagna a tema italiano documentata dalla società italiana D3Lab, viene distribuito Albiriox, un banking trojan Android costruito per la frode on-device. Il marchio abusato è quello di UniCredit, ma conviene chiarirlo subito per non generare equivoci: ..
A government entity in the US reportedly paid a $1 million ransom to the Kairos cyber extortion group to prevent the public dissemination of information stolen in a May 2025 intrusion, Ransom-ISAC reports. A leaked negotiation transcript shows that the extortion group demanded $3 million in cryptocurrency from the victim organization, but eventually settled for ..
A recently discovered advanced persistent threat (APT) actor has been targeting government and electric power organizations in multiple countries, Kaspersky reports. Dubbed Armored Likho, the APT engages both in financially motivated attacks against individuals and in cyber-espionage operations against organizations in Russia, Brazil, and Kazakhstan. The threat actor’s arsenal includes modular remote access trojans (RATs) ..
Threat actors are using prompt injection attacks embedded in malicious websites and manipulated search results to trick AI agents into making payments or trusting fraudulent cryptocurrency platforms. Zscaler says it identified two campaigns relying on indirect prompt injection, including a payment scam hiding behind API documentation, and a typosquatting operation promoting a crypto platform that ..
SecurityWeek’s cybersecurity news weekly roundup offers a concise overview of important developments that may not receive full standalone coverage but remain relevant to the broader threat landscape. This curated summary highlights key stories across vulnerability disclosures, emerging attack methods, policy updates, industry reports, and other noteworthy events to help readers maintain a well-rounded awareness of ..


