Readiness beats prevention alone Prevention still matters, but the organizations that recover well from ransomware are the ones that planned for the bad day before it […]
Throughout 2025, the fallout from Salt Typhoon, a China-linked espionage campaign against telecommunications providers, continued to shape how governments think about critical-infrastructure security. The campaign compromised […]
In October 2025, the Cl0p extortion group launched another mass data-theft campaign, this time exploiting a zero-day in Oracle E-Business Suite tracked as CVE-2025-61882. The pattern […]
Through the first half of 2025, a loose collective often tracked as Scattered Spider ran a highly effective campaign against retail, aviation, insurance, and hospitality organizations. […]
In March 2025, US authorities issued a joint advisory on the Medusa ransomware operation, detailing its tactics against organizations across multiple sectors. The advisory is a […]
On February 21, 2025, cryptocurrency exchange Bybit disclosed the theft of roughly 1.5 billion US dollars in Ethereum, the largest digital-asset heist on record. Investigators attributed […]
In early January 2025, a breach at PowerSchool, a widely used student information system, exposed data belonging to students, families, and staff across North America. Several […]
In December 2024, attackers began exploiting vulnerabilities in Cleo’s managed file transfer products, and the Clop extortion group claimed responsibility for the resulting data theft. It […]
In mid-June 2024, a ransomware attack against CDK Global, the dealer management platform used by thousands of car dealerships across North America, forced the company to […]