โ ๏ธ Fake CleanMyMac download spreads Shub stealer malware
A counterfeit CleanMyMac site distributes the #Shub Stealer, which harvests browser credentials, Telegram data, and cryptocurrency wallets from macOS systems before exfiltrating them to attacker-controlled servers.
#ransomNews #macOS
11.03.2026 08:37
๐ 5
๐ 1
๐ฌ 0
๐ 1
*all data arise checked, verified and validated by human beings, no Molts.
Weโve always been on the hard-work side of the page and automations are not a replacement. Paid platforms not able to localize a claim, and free platforms unable to catch the latest claims.
The rest is #fuffa.
10.03.2026 14:37
๐ 2
๐ 0
๐ฌ 0
๐ 0
ransomNews โข your go-to source for ransomware news, insights, and analysis, also home of RedACT monthly threat report
ransomNews, your go-to source for ransomware news, insights, and analysis, also home of RedACT monthly threat report
This is verified data. Not estimates. Not noise.
And this is just the beginning, more features and insights are coming soon ๐
If you work in cybersecurity, risk management, or just want to understand the real threat landscape affecting businesses today, this is your bookmark.
#ransomNews
10.03.2026 14:37
๐ 3
๐ 0
๐ฌ 1
๐ 0
๐ฎ๐น Italy is not immune:
โ February alone recorded 26 confirmed incidents
โ Lombardia, Emilia-Romagna, Liguria leading the regional impact
โ over 3.600 GB of data already exfiltrated and published in early 2026
10.03.2026 14:37
๐ 3
๐ 0
๐ฌ 1
๐ 0
in the ransomware ecosystem:
๐ Global snapshot (2026 so far*):
โ 1.504 ransomware victims worldwide
โ 62 active threat groups
โ 26 countries impacted
โ 13 new threat actors already emerged
10.03.2026 14:37
๐ 4
๐ 1
๐ฌ 1
๐ 0
ransomNews โข your go-to source for ransomware news, insights, and analysis, also home of RedACT monthly threat report
ransomNews, your go-to source for ransomware news, insights, and analysis, also home of RedACT monthly threat report
๐จ We just upgraded ransomNews - and the numbers speak for themselves!
Our website ransomnews.online got a serious update, and we're not just talking about a new coat of paint ๐
We've introduced threat landscape statistics, both globally and for Italy, giving you a quick pulse on what's happening
10.03.2026 14:37
๐ 8
๐ 3
๐ฌ 1
๐ 2
๐จ nuova rivendicazione #ransomware Italia ๐จ
๐ดโโ ๏ธ gruppo #DragonForce
๐งฌ Tazzetti SPA | Volpiano (TO)
๐ฏ settore: trattamento e smaltimento rifiuti
๐ tazzetti.com
๐๏ธ 10 marzo 2026
๐ sample: -
โช๏ธ dati esfiltrati dichiarati: 14.94GB
โช๏ธ dati esfiltrati pubblicati: -
โฒ๏ธ scadenza: 21 marzo 2026
#ransomNews
10.03.2026 14:04
๐ 2
๐ 0
๐ฌ 0
๐ 1
โ ๏ธ Fake Signal security alerts steal accounts via phishing pages
Attackers sent fake #Signal security alert messages linking to credential-harvesting pages designed to capture account details and enable session hijacking of victimsโ messaging accounts.
#Phishing #CyberSecurity
10.03.2026 13:37
๐ 3
๐ 0
๐ฌ 0
๐ 0
โ ๏ธ Hospital forced offline after medical records system collapse
The #cyberattack disabled the hospitalโs electronic medical records, forcing staff to switch to paper workflows while emergency admissions were reduced and patients redirected to nearby facilities.
#ransomNews #HealthcareCyber
10.03.2026 12:37
๐ 2
๐ 0
๐ฌ 0
๐ 0
โ ๏ธ Commercial iPhone hacking kit traces back to US vendor
Security researchers link the #iPhone exploitation toolkit #Reign to US firm #QuaDream infrastructure, showing it leveraged zero-click iMessage exploits and was marketed to governments for covert device surveillance operations.
#iOS #Spyware
10.03.2026 11:37
๐ 2
๐ 1
๐ฌ 0
๐ 0
๐จย Custom tool turns Salesforce scanning into data theft
Attackers modified the open-source #AuraInspector tool to mass-scan public #Salesforce Experience Cloud sites and extract data directly via the `/s/sfsites/aura` API when guest user permissions are overly permissive.
#ransomNews
10.03.2026 10:37
๐ 1
๐ 0
๐ฌ 0
๐ 0
๐จ nuova rivendicazione #ransomware Italia ๐จ
๐ดโโ ๏ธ gruppo #LockBit5
๐งฌ Commerfrutta Di Stancari | Cerlongo (MN)
๐ฏ settore: ingrosso alimentare
๐ commerfrutta.com
๐๏ธ 09 marzo 2026
๐ sample: -
โช๏ธ dati esfiltrati dichiarati: -
โช๏ธ dati esfiltrati pubblicati: -
โฒ๏ธ scadenza: 25 marzo 2026
#ransomNews
10.03.2026 09:14
๐ 2
๐ 0
๐ฌ 0
๐ 1
๐จ nuova rivendicazione #ransomware Italia ๐จ
๐ดโโ ๏ธ gruppo #LockBit5
๐งฌ FAC SRL | Augusta (SR)
๐ฏ settore: noleggio attrezzature pesanti
๐ fac-srl.net
๐๏ธ 09 marzo 2026
๐ sample: -
โช๏ธ dati esfiltrati dichiarati: -
โช๏ธ dati esfiltrati pubblicati: -
โฒ๏ธ scadenza: 25 marzo 2026
#ransomNews #cybersecurity
10.03.2026 09:11
๐ 2
๐ 0
๐ฌ 0
๐ 1
๐จ nuova rivendicazione #ransomware Italia ๐จ
๐ดโโ ๏ธ gruppo #LockBit5
๐งฌ S.I.A. Societร Italiana Alimenti SPA | Offida (AP)
๐ฏ settore: alimentare
๐ societaitalianaalimenti.it
๐๏ธ 07 marzo 2026
๐ sample: -
โช๏ธ dati esfiltrati dichiarati: -
โช๏ธ dati esfiltrati pubblicati: -
โฒ๏ธ scadenza: 21 marzo 2026
07.03.2026 15:03
๐ 3
๐ 0
๐ฌ 0
๐ 1
โ ๏ธ Surveillance spyware hides inside fake meeting update
A fake #Google Meet update installs #Teramind surveillance software; the same MSI payload (SHA-256: 644ef9f..) is reused across campaigns and runs in hidden-agent mode with two auto-restarting services for persistent monitoring.
07.03.2026 13:37
๐ 4
๐ 1
๐ฌ 1
๐ 0
๐ Five-page cyber strategy signals major policy shift
The new US cyber strategy is just 5 pages -far shorter than prior plans- and pivots toward offensive cyber operations, deregulation for industry, and AI-driven defense while leaving implementation details largely undefined.
07.03.2026 12:37
๐ 6
๐ 3
๐ฌ 1
๐ 0
Partnering with Mozilla to improve Firefoxโs security
Anthropic is an AI safety and research company that's working to build reliable, interpretable, and steerable AI systems.
โ ๏ธ AI-generated bug reports flood Firefox maintainers
#Claude Opus 4.6 scanned 6k C++ files and sent 112 bug reports in two weeks. 22 confirmed vulnerabilities (14 high severity), nearly 20% of all Firefox high-severity bugs fixed in 2025.
#AIsecurity #Firefox #Vulnerabilities
07.03.2026 11:10
๐ 2
๐ 0
๐ฌ 0
๐ 0
๐จ nuova rivendicazione #ransomware Italia ๐จ
๐ดโโ ๏ธ gruppo #LockBit5
๐งฌ Barbero Pietro SPA | Torino
๐ฏ settore: imballaggi e forniture per ufficio
๐ barberopietro.it
๐๏ธ 05 marzo 2026
๐ sample: -
โช๏ธ dati esfiltrati dichiarati: -
โช๏ธ dati esfiltrati pubblicati: -
โฒ๏ธ scadenza: 19 marzo 2026
#ransomNews
05.03.2026 15:54
๐ 4
๐ 0
๐ฌ 0
๐ 1
๐จ nuova rivendicazione #ransomware Italia ๐จ
๐ดโโ ๏ธ gruppo #Tengu
๐งฌ Eos Technology SRL | Roma
๐ฏ settore: riparazione computer e periferiche
๐ eostechnology.net
๐๏ธ 04 marzo 2026
๐ sample: sรฌ
โช๏ธ dati esfiltrati dichiarati: 20.78GB
โช๏ธ dati esfiltrati pubblicati: -
โฒ๏ธ scadenza: 11 marzo 2026
#ransomNews
04.03.2026 18:10
๐ 6
๐ 1
๐ฌ 0
๐ 1
๐จ nuova rivendicazione #ransomware Italia ๐จ
๐ดโโ ๏ธ gruppo #LockBit5
๐งฌ Paoli Dental Center | Mestre (VE)
๐ฏ settore: sanitario
๐ paolidental.org
๐๏ธ 04 marzo 2026
๐ sample: -
โช๏ธ dati esfiltrati dichiarati: -
โช๏ธ dati esfiltrati pubblicati: -
โฒ๏ธ scadenza: 19 marzo 2026
#ransomNews #cybersecurity
04.03.2026 18:09
๐ 5
๐ 1
๐ฌ 0
๐ 1
โ ๏ธ North Korean StegaBin campaign targets developers
Researchers uncovered a North Korean #StegaBin operation using steganographic malware hidden in images to target developers, blending social engineering and covert payload delivery to evade traditional detection.
#ransomNews #APT #Steganography
04.03.2026 09:37
๐ 1
๐ 0
๐ฌ 0
๐ 0
๐จ nuova rivendicazione #ransomware Italia ๐จ
๐ดโโ ๏ธ gruppo #LockBit5
๐งฌ Formula50 | Anagni (FR)
๐ฏ settore: sviluppo IT
๐ formula50.it
๐๏ธ 04 marzo 2026
๐ sample: -
โช๏ธ dati esfiltrati dichiarati: -
โช๏ธ dati esfiltrati pubblicati: -
โฒ๏ธ scadenza: 18 marzo 2026
#ransomNews #cybersecurity #cyberthreats
04.03.2026 09:34
๐ 3
๐ 1
๐ฌ 0
๐ 1
Hacktivists claim to have hacked Homeland Security to release ICE contract data | TechCrunch
A hacking group called Department of Peace said they hacked a specific office within Homeland Security to protest ICEโs mass deportation campaign, and the companies aiding it.
๐ย Hacktivists claim DHS breach exposing ICE contracts
Hacktivists allege they accessed US Homeland Security systems to leak sensitive ICE contract data, raising concerns over federal network security and the potential exposure of vendor and operational information.
#ransomNews #DataBreach
04.03.2026 08:37
๐ 1
๐ 0
๐ฌ 1
๐ 0
However, some victim claims are unverified, indicating possible fabrications to inflate reputation.
#ransomNews #cybersecurity #newthreatactor
03.03.2026 18:01
๐ 1
๐ 0
๐ฌ 0
๐ 0
The group's activity pattern suggests it is still establishing its operational tempo.
#Security teams should prioritize behavior-based detection and assume zero-trust principles, as traditional IOCs may be insufficient against an AI-augmented and state-aligned adversary.
03.03.2026 18:01
๐ 1
๐ 0
๐ฌ 1
๐ 0
as this is an evolving pressure tactic
๐ค Analyst take (confidence: low)
While AiLock's re-emergence and ties to sophisticated state actors are concerning, its public embrace of AI may be as much a marketing ploy as a technical reality.
03.03.2026 18:01
๐ 1
๐ 0
๐ฌ 1
๐ 0
- enhance detection for AI-assisted behaviors, focusing on anomalous user interaction patterns and rapid, large-scale encryption
- track blockchain transactions involving Wasabi mixer and FixedFloat exchange, especially conversions to Monero
- scrutinize threats of regulatory reporting,
03.03.2026 18:01
๐ 1
๐ 0
๐ฌ 1
๐ 0
โข exfiltration (T1567): exfiltration over web service
โข financial Motivation (T1657): the primary objective is financial gain through extortion, with potential secondary strategic disruption
๐๐ป What to watch next (#SOCPlaybook cues)
- monitor their DLS for re-emergence and new victim postings
03.03.2026 18:01
๐ 1
๐ 0
๐ฌ 1
๐ 0