Ransomware attacks are surging massively and hitting Germany particularly hard; the SafePay group is responsible for approximately one quarter of them.
The Mistic backdoor is being deployed by ransomware access broker KongTuke in targeted attacks against insurance companies, educational institutions, and IT firms.
Germany is Europe’s ransomware hotspot with nearly double the growth rate of France; its infrastructure and inadequate security awareness make it particularly attractive to criminals based in Russia.
Identities and cloud services have become more lucrative for attackers than infrastructure vulnerabilities; many companies fail to close this gap technologically due to lack of people, processes, and clear accountability.
Two independent attack groups exploited the same unpatched SharePoint server simultaneously within the same victim network, causing their traces to overlap and complicating the investigation.
The Gentlemen has developed GentleKiller, an EDR killer framework that provides less experienced affiliate partners with ready-to-use tools for bypassing enterprise security systems.
Gentlemen gang uses at least eight variants of GentleKiller to disable EDR protection from 48 different security vendors before executing ransomware attacks.
Ransomware group DragonForce disguises its command-and-control traffic via Microsoft Teams’ TURN protocol and exploits multiple CVEs and kernel exploits to bypass security software.
One in six breaches involves third parties, and even rapid patches fail to prevent most incidents—therefore incident exercises must prioritize operational resilience and third-party scenarios.