ransomware

Gentlemen Ransomware Affiliate Uses MCP as C2 Channel in Live Cyberattacks

A Russian-speaking Gentlemen ransomware affiliate used the Model Context Protocol (MCP) to execute commands during live intrusions, turning an AI…

2 days ago

Aembit Launches Support for Okta Cross App Access, Extending Enterprise Identity Controls to AI Agents

Silver Spring, Maryland, USA, September 22nd, 2026, CyberNewswire Aembit, the identity and access management (IAM) company for AI agents, today…

2 weeks ago

JADEPUFFER Evolves Agentic Ransomware to Target AI Models and Training Data

JADEPUFFER, the agentic threat actor first linked to an autonomous ransomware operation against exposed Langflow infrastructure, has evolved its tooling…

3 weeks ago

Mantax OTAX Android Ransomware Spies on Users, Steals OTPs and Encrypts Files

Mantax OTAX is aggressive Android malware family combines ransomware, spyware, credential theft, and remote device-control features in a single infection…

4 weeks ago

Hackers Deploy New SloppyRAT via ClickFix to Enable Ransomware Lateral Movement

A new Windows remote-access trojan dubbed SloppyRAT, which appears to be positioned as an intrusion-enablement tool for ransomware operations. First…

4 weeks ago

Panzer Ransomware Emerges With Windows, Linux, ESXi and FreeBSD Attack Support

A newly identified ransomware-as-a-service operation, Panzer, has surfaced with advertised payload support for Windows, Linux, VMware ESXi and FreeBSD, positioning…

1 month ago

Ransomware Hackers Can Go From Network Access to Encryption in Less Than 24 Hours

The Gentlemen ransomware-as-a-service operation can move from confirmed access inside a victim network to encryption in under 24 hours. Demonstrating…

1 month ago

The Gentlemen Ransomware Hackers Use TukTuk C2 to Steal Credentials and Disable EDR Security

The Gentlemen ransomware operation has been linked to a previously undocumented, cross-platform command-and-control framework named TukTuk, alongside EDR-disabling tooling, DLL sideloading…

1 month ago

Aurora Ransomware Hackers Use Cursor AI Agent for Hands-On Exploitation and ESXi Attacks

Aurora ransomware operators have been observed using Cursor Agent, powered by Claude Sonnet, to support hands-on intrusion activity across ten…

1 month ago

TITAN RaaS Uses AI for Data Classification, Regulatory Analysis and Automated Ransom Calculation

A newly emerged ransomware-as-a-service operation named TITAN is advertising an AI-driven extortion platform that it claims can autonomously classify stolen…

1 month ago