A Huntress employee informed the Devman ransomware operator of FBI investigations against him, which CEO Hanslovan characterizes as poor judgment but not as illegal or deliberate insider activity.
Ransomware extortionists are exploiting insufficient access controls in Microsoft Defender (CVE-2026-33825) to obtain SYSTEM privileges and fully compromise systems.
Ransomware gangs exploit a vulnerability in Microsoft Defender to gain access to the SAM database through insufficient access controls and obtain SYSTEM privileges.
Ransomware gangs are exploiting the BlueHammer vulnerability in Microsoft Defender for privilege escalation, putting Windows systems at widespread risk.
Cyberattacks on midmarket companies unfold in five phases and often reach administrator privileges within 48 hours, with data exfiltration following by day five—early detection is critical to preventing escalation.
The parallel activity of two independent ransomware groups on the same SharePoint servers demonstrates that attackers are increasingly conducting overlapping campaigns, requiring centralized visibility across all layers.
Summer holiday absences lead to 69 percent email fraud between June and August, but ransomware remains undetected an average of nine days longer, with damages becoming visible only in autumn.
Following a period of lower activity, ransomware groups are increasingly concentrating on European organizations and their suppliers as primary attack targets.
A malicious Edge extension exploits the native messaging protocol to bypass browser sandbox and establish full remote access backdoor at operating system level.