# Cybercrime

Criminal activity that targets computers or networks, or for which online platforms or digital assets are central to the offense.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## OpenAI's malicious bot swarm attacked RubyGems

DevFeed: [OpenAI's malicious bot swarm attacked RubyGems](<https://devfeed.tech/articles/openai-s-malicious-bot-swarm-attacked-rubygems-21633.md>)

Original publisher: [Read original article](<https://www.theregister.com/security/2026/09/14/openais-malicious-bot-swarm-attacked-rubygems/5296356>)

Author: Jessica Lyons

Published: 2026-09-14T18:03:58Z

Content type: news

Language: en

Sources: [www.theregister.com - Articles](<https://devfeed.tech/sources/www-theregister-com-articles.md>)

Topics: [OpenAI](<https://devfeed.tech/topics/openai.md>), [Bot](<https://devfeed.tech/topics/bot.md>), [Ruby](<https://devfeed.tech/topics/ruby.md>), [Cybercrime](<https://devfeed.tech/topics/cybercrime.md>)

Tags: [ai-and-ml](<https://devfeed.tech/tags/ai-and-ml.md>), [malware](<https://devfeed.tech/tags/malware.md>), [openai](<https://devfeed.tech/tags/openai.md>), [ruby](<https://devfeed.tech/tags/ruby.md>), [rubygems](<https://devfeed.tech/tags/rubygems.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

The article reports that a malicious bot swarm associated with OpenAI attacked RubyGems.

### Source excerpt

Ruby are you ok? Ruby are you ok? Are you ok Ruby?

## Revolut falls for fake government requests, hands over customer data

DevFeed: [Revolut falls for fake government requests, hands over customer data](<https://devfeed.tech/articles/revolut-falls-for-fake-government-requests-hands-over-customer-data-17407.md>)

Original publisher: [Read original article](<https://www.theregister.com/cyber-crime/2026/09/14/revolut-falls-for-fake-government-requests-hands-over-customer-data/5296118>)

Author: Connor Jones

Published: 2026-09-14T11:26:00Z

Content type: news

Language: en

Sources: [www.theregister.com - Articles](<https://devfeed.tech/sources/www-theregister-com-articles.md>)

Topics: [Cybercrime](<https://devfeed.tech/topics/cybercrime.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [bitcoin](<https://devfeed.tech/tags/bitcoin.md>), [customer](<https://devfeed.tech/tags/customer.md>), [cyber-crime](<https://devfeed.tech/tags/cyber-crime.md>), [data](<https://devfeed.tech/tags/data.md>), [phishing](<https://devfeed.tech/tags/phishing.md>)

### AI overview

Revolut handed over passports, selfies, and transaction histories after attackers used fake government requests and claimed responsibility for a crime while demanding 10,000 Bitcoin.

### Source excerpt

Passports, selfies, transaction histories exposed as self-proclaimed culprits demand 10,000 Bitcoin

## Peer Pressure: Inside the Sality Botnet Disruption Operation

DevFeed: [Peer Pressure: Inside the Sality Botnet Disruption Operation](<https://devfeed.tech/articles/peer-pressure-inside-the-sality-botnet-disruption-operation-8308.md>)

Original publisher: [Read original article](<https://www.crowdstrike.com/en-us/blog/inside-sality-botnet-disruption-operation/>)

Author: CrowdStrike Counter Adversary Operations

Published: 2026-09-12T11:17:51.295154Z

Content type: article

Language: en

Sources: [Blog](<https://devfeed.tech/sources/blog.md>)

Topics: [P2P](<https://devfeed.tech/topics/p2p.md>), [Cybercrime](<https://devfeed.tech/topics/cybercrime.md>)

Tags: [2026](<https://devfeed.tech/tags/2026.md>), [collaboration](<https://devfeed.tech/tags/collaboration.md>), [department-of-justice](<https://devfeed.tech/tags/department-of-justice.md>), [industry](<https://devfeed.tech/tags/industry.md>), [operations](<https://devfeed.tech/tags/operations.md>), [partnership](<https://devfeed.tech/tags/partnership.md>), [support](<https://devfeed.tech/tags/support.md>), [threat-hunting-intel](<https://devfeed.tech/tags/threat-hunting-intel.md>)

### AI overview

CrowdStrike describes a coordinated operation that disrupted the Sality peer-to-peer botnet, which had distributed malicious payloads to more than 33,000 infected machines worldwide. The operation used peer-to-peer sinkholing to isolate infected machines and disable the criminal command channel, with support from international law enforcement and industry partners.

### Source excerpt

CrowdStrike collaborated with international law enforcement and industry partners to execute a coordinated disruption of the Sality peer-to-peer botnet.

## The aircraft might not be flying, but the certificate has gone on vacation

DevFeed: [The aircraft might not be flying, but the certificate has gone on vacation](<https://devfeed.tech/articles/the-aircraft-might-not-be-flying-but-the-certificate-has-gone-on-vacation-8547.md>)

Original publisher: [Read original article](<https://www.theregister.com/offbeat/2026/09/12/the-aircraft-might-not-be-flying-but-the-certificate-has-gone-on-vacation/5295622>)

Author: Richard Speed

Published: 2026-09-12T09:00:00Z

Content type: news

Language: en

Sources: [www.theregister.com - Articles](<https://devfeed.tech/sources/www-theregister-com-articles.md>)

Topics: [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [NVLink](<https://devfeed.tech/topics/nvlink.md>), [Vibe coding](<https://devfeed.tech/topics/vibe-coding.md>), [ARKTunnel](<https://devfeed.tech/topics/arktunnel.md>), [Cybercrime](<https://devfeed.tech/topics/cybercrime.md>), [.NET](<https://devfeed.tech/topics/net.md>), [how to create smooth CSS transitions](<https://devfeed.tech/topics/how-to-create-smooth-css-transitions.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [bork](<https://devfeed.tech/tags/bork.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [malware](<https://devfeed.tech/tags/malware.md>), [nvidia](<https://devfeed.tech/tags/nvidia.md>), [offbeat](<https://devfeed.tech/tags/offbeat.md>), [phishing](<https://devfeed.tech/tags/phishing.md>), [security](<https://devfeed.tech/tags/security.md>), [tailwind](<https://devfeed.tech/tags/tailwind.md>), [ubuntu](<https://devfeed.tech/tags/ubuntu.md>)

### AI overview

A news roundup covering security incidents, AI-related developments, semiconductor infrastructure, phishing, ransomware, open-source software, and web development. The supplied title concerns an aircraft certificate, while the body mainly contains unrelated headlines.

### Source excerpt

Information is not forthcoming from this screen

## Trezor, BitBox users targeted in newsletter phishing spree

DevFeed: [Trezor, BitBox users targeted in newsletter phishing spree](<https://devfeed.tech/articles/trezor-bitbox-users-targeted-in-newsletter-phishing-spree-8538.md>)

Original publisher: [Read original article](<https://www.theregister.com/cyber-crime/2026/09/10/trezor-bitbox-users-targeted-in-newsletter-phishing-spree/5295496>)

Author: Connor Jones

Published: 2026-09-10T11:30:00Z

Content type: news

Language: en

Sources: [www.theregister.com - Articles](<https://devfeed.tech/sources/www-theregister-com-articles.md>)

Topics: [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Social engineering](<https://devfeed.tech/topics/social-engineering.md>), [Cybercrime](<https://devfeed.tech/topics/cybercrime.md>)

Tags: [cyber-crime](<https://devfeed.tech/tags/cyber-crime.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [phishing](<https://devfeed.tech/tags/phishing.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

Attackers exploit legitimate mailing channels to demand crypto wallet backups from Trezor and BitBox users.

### Source excerpt

Attackers exploit legitimate mailing channels to demand crypto wallet backups

## Cryptocrook ringleader, 22, who met crew on Minecraft admits role in $245M heist

DevFeed: [Cryptocrook ringleader, 22, who met crew on Minecraft admits role in $245M heist](<https://devfeed.tech/articles/cryptocrook-ringleader-22-who-met-crew-on-minecraft-admits-role-in-245m-heist-8537.md>)

Original publisher: [Read original article](<https://www.theregister.com/cyber-crime/2026/09/09/cryptocrook-ringleader-22-who-met-crew-on-minecraft-admits-role-in-245m-heist/5295273>)

Author: Connor Jones

Published: 2026-09-09T13:39:00Z

Content type: news

Language: en

Sources: [www.theregister.com - Articles](<https://devfeed.tech/sources/www-theregister-com-articles.md>)

Topics: [Cybercrime](<https://devfeed.tech/topics/cybercrime.md>)

Tags: [cyber-crime](<https://devfeed.tech/tags/cyber-crime.md>)

### AI overview

A 22-year-old alleged cryptocrime ringleader admitted a role in a $245 million heist after meeting the crew through Minecraft.

### Source excerpt

Stolen funds bought mansions, private jets, and supercars - now he faces up to 20 years

## Loyalty points fraud is funding hacker holidays (Lock and Code S07E18)

DevFeed: [Loyalty points fraud is funding hacker holidays (Lock and Code S07E18)](<https://devfeed.tech/articles/loyalty-points-fraud-is-funding-hacker-holidays-lock-and-code-s07e18-8443.md>)

Original publisher: [Read original article](<https://www.malwarebytes.com/blog/podcast/2026/09/loyalty-points-fraud-is-funding-hacker-holidays-lock-and-code-s07e18>)

Author: Malwarebytes Labs

Published: 2026-09-07T18:23:18Z

Content type: article

Language: en

Sources: [Malwarebytes](<https://devfeed.tech/sources/malwarebytes.md>)

Topics: [Cybercrime](<https://devfeed.tech/topics/cybercrime.md>), [passwords](<https://devfeed.tech/topics/passwords.md>)

Tags: [account-takeover](<https://devfeed.tech/tags/account-takeover.md>), [airline](<https://devfeed.tech/tags/airline.md>), [airline-miles](<https://devfeed.tech/tags/airline-miles.md>), [credit-card-points](<https://devfeed.tech/tags/credit-card-points.md>), [cybercrime](<https://devfeed.tech/tags/cybercrime.md>), [fraud](<https://devfeed.tech/tags/fraud.md>), [hotel-rewards](<https://devfeed.tech/tags/hotel-rewards.md>), [loyalty-account](<https://devfeed.tech/tags/loyalty-account.md>), [loyalty-points](<https://devfeed.tech/tags/loyalty-points.md>), [loyalty-points-fraud](<https://devfeed.tech/tags/loyalty-points-fraud.md>), [podcast](<https://devfeed.tech/tags/podcast.md>), [points](<https://devfeed.tech/tags/points.md>), [rewards-account](<https://devfeed.tech/tags/rewards-account.md>), [rewards-points](<https://devfeed.tech/tags/rewards-points.md>)

### AI overview

A Lock and Code podcast episode examines loyalty-points theft, why criminals target points balances, and ways companies and consumers can protect against fraud.

### Source excerpt

This week on the Lock and Code podcast, we speak with Kim Sutherland about loyalty points fraud and how everyday people can stay safe.

## What part of 'No!' is so hard for the DNS understand?

DevFeed: [What part of 'No!' is so hard for the DNS understand?](<https://devfeed.tech/articles/what-part-of-no-is-so-hard-for-the-dns-understand-10859.md>)

Original publisher: [Read original article](<https://blog.apnic.net/2026/09/04/what-part-of-no-is-so-hard-for-the-dns-understand/>)

Author: Geoff Huston

Published: 2026-09-04T01:06:30Z

Content type: article

Language: en

Sources: [APNIC Blog](<https://devfeed.tech/sources/apnic-blog.md>)

Topics: [servers](<https://devfeed.tech/topics/servers.md>), [Caching](<https://devfeed.tech/topics/caching.md>), [DDoS](<https://devfeed.tech/topics/ddos.md>), [Cybercrime](<https://devfeed.tech/topics/cybercrime.md>), [Availability](<https://devfeed.tech/topics/availability.md>), [Bot](<https://devfeed.tech/topics/bot.md>), [Script](<https://devfeed.tech/topics/script.md>)

Tags: [apnic-labs](<https://devfeed.tech/tags/apnic-labs.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [availability](<https://devfeed.tech/tags/availability.md>), [bots](<https://devfeed.tech/tags/bots.md>), [caching](<https://devfeed.tech/tags/caching.md>), [ddos](<https://devfeed.tech/tags/ddos.md>), [dns](<https://devfeed.tech/tags/dns.md>), [generate](<https://devfeed.tech/tags/generate.md>), [measurement](<https://devfeed.tech/tags/measurement.md>), [random](<https://devfeed.tech/tags/random.md>), [server](<https://devfeed.tech/tags/server.md>), [servers](<https://devfeed.tech/tags/servers.md>), [tech-matters](<https://devfeed.tech/tags/tech-matters.md>)

### AI overview

The article explains how random name attacks overwhelm authoritative DNS servers by generating queries for nonexistent names, bypassing recursive resolver caches and potentially causing domain availability failures. It also describes APNIC Labs' measurement work on nonexistent-domain responses to improve DNS resilience.

### Source excerpt

At APNIC Labs we've been experimenting with understanding how the DNS handles requests to resolve nonexistent names to make the DNS more resilient to random name attacks.

## Black Hat USA 2026: AI is racing ahead of cybersecurity controls

DevFeed: [Black Hat USA 2026: AI is racing ahead of cybersecurity controls](<https://devfeed.tech/articles/black-hat-usa-2026-ai-is-racing-ahead-of-cybersecurity-controls-8323.md>)

Original publisher: [Read original article](<https://www.welivesecurity.com/en/business-security/black-hat-usa-2026-ai-racing-cybersecurity-controls/>)

Author: Tony Anscombe

Published: 2026-08-12T13:28:07Z

Content type: article

Language: en

Sources: [WeLiveSecurity](<https://devfeed.tech/sources/welivesecurity.md>)

Topics: [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Cybercrime](<https://devfeed.tech/topics/cybercrime.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [black-hat](<https://devfeed.tech/tags/black-hat.md>), [business-security](<https://devfeed.tech/tags/business-security.md>), [conference](<https://devfeed.tech/tags/conference.md>), [cybercrime](<https://devfeed.tech/tags/cybercrime.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [government](<https://devfeed.tech/tags/government.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

AI dominated Black Hat USA 2026, where speakers discussed regulation, national leadership, open-source infrastructure, cybercrime, and the rapid discovery of vulnerabilities by AI-powered systems. The article's central concern is accountability and the need for safer, more coordinated AI governance.

### Source excerpt

AI took center stage, but the clearest lesson was less about what AI can do than about who is accountable when something goes wrong

## Cloudflare DDoS Threat Report H1 2026: 1 Tbps attacks soar as DNS floods and geopolitical tensions drive a new wave

DevFeed: [Cloudflare DDoS Threat Report H1 2026: 1 Tbps attacks soar as DNS floods and geopolitical tensions drive a new wave](<https://devfeed.tech/articles/cloudflare-ddos-threat-report-h1-2026-1-tbps-attacks-soar-as-dns-floods-and-geopolitical-tensions-drive-a-new-wave-113.md>)

Original publisher: [Read original article](<https://blog.cloudflare.com/ddos-threat-report-2026-h1/>)

Author: Cloudforce One

Published: 2026-08-11T13:00:00Z

Content type: article

Language: en

Sources: [Cloudflare Blog](<https://devfeed.tech/sources/cloudflare-blog.md>)

Topics: [DDoS](<https://devfeed.tech/topics/ddos.md>), [Cloudflare](<https://devfeed.tech/topics/cloudflare.md>), [Threat Research](<https://devfeed.tech/topics/threat-research.md>), [Cloudforce One](<https://devfeed.tech/topics/cloudforce-one.md>), [Network](<https://devfeed.tech/topics/network.md>), [data](<https://devfeed.tech/topics/data.md>), [Cybercrime](<https://devfeed.tech/topics/cybercrime.md>), [High Profile Threats](<https://devfeed.tech/topics/high-profile-threats.md>)

Tags: [analysis](<https://devfeed.tech/tags/analysis.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [cloudflare](<https://devfeed.tech/tags/cloudflare.md>), [cloudforce-one](<https://devfeed.tech/tags/cloudforce-one.md>), [data](<https://devfeed.tech/tags/data.md>), [ddos](<https://devfeed.tech/tags/ddos.md>), [dns](<https://devfeed.tech/tags/dns.md>), [drive](<https://devfeed.tech/tags/drive.md>), [global](<https://devfeed.tech/tags/global.md>), [government](<https://devfeed.tech/tags/government.md>), [industry](<https://devfeed.tech/tags/industry.md>), [iran](<https://devfeed.tech/tags/iran.md>), [media](<https://devfeed.tech/tags/media.md>), [network](<https://devfeed.tech/tags/network.md>), [radar](<https://devfeed.tech/tags/radar.md>), [streaming](<https://devfeed.tech/tags/streaming.md>), [threat-report](<https://devfeed.tech/tags/threat-report.md>)

### AI overview

Cloudflare's H1 2026 DDoS Threat Report analyzes attacks from January through June 2026. It highlights a 519% quarter-over-quarter increase in attacks exceeding 1 Tbps, a shift toward DNS and CLDAP reflection and amplification vectors, and the influence of geopolitical events on attack patterns. The report also covers attack volumes, an April peak, and the possible impact of Operation PowerOFF.

### Source excerpt

In the first half of 2026, Cloudflare detected a 519% surge in hyper-volumetric DDos attacks across its network. These attacks were driven heavily by DNS and CLDAP reflection vectors. This report breaks down how major geopolitical conflicts reshaped the global cyber threat landscape.

## Kimwolf v7: An Evolution of the Kimwolf Botnet

DevFeed: [Kimwolf v7: An Evolution of the Kimwolf Botnet](<https://devfeed.tech/articles/kimwolf-v7-an-evolution-of-the-kimwolf-botnet-7752.md>)

Original publisher: [Read original article](<https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/>)

Author: Asher Davila, Chris Navarrete and Doel Santos

Published: 2026-08-11T10:00:16Z

Content type: article

Language: en

Sources: [Unit 42](<https://devfeed.tech/sources/unit-42.md>)

Topics: [Kimwolf v7](<https://devfeed.tech/topics/kimwolf-v7.md>), [Android](<https://devfeed.tech/topics/android.md>), [DDoS](<https://devfeed.tech/topics/ddos.md>), [Internet of things](<https://devfeed.tech/topics/iot.md>), [C2](<https://devfeed.tech/topics/c2.md>), [Ethereum Name Service (ENS)](<https://devfeed.tech/topics/ens.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [Cybercrime](<https://devfeed.tech/topics/cybercrime.md>), [Ethereum](<https://devfeed.tech/topics/ethereum.md>), [Blockchain](<https://devfeed.tech/topics/blockchain.md>), [Routing (disambiguation)](<https://devfeed.tech/topics/routing.md>), [Threat Hunting & Intel](<https://devfeed.tech/topics/threat-hunting-intel.md>)

Tags: [android](<https://devfeed.tech/tags/android.md>), [android-apk](<https://devfeed.tech/tags/android-apk.md>), [blockchain](<https://devfeed.tech/tags/blockchain.md>), [c2](<https://devfeed.tech/tags/c2.md>), [ddos](<https://devfeed.tech/tags/ddos.md>), [devices](<https://devfeed.tech/tags/devices.md>), [ethereum](<https://devfeed.tech/tags/ethereum.md>), [http](<https://devfeed.tech/tags/http.md>), [iot-botnets](<https://devfeed.tech/tags/iot-botnets.md>), [kimwolf-v7](<https://devfeed.tech/tags/kimwolf-v7.md>), [linux](<https://devfeed.tech/tags/linux.md>), [malware](<https://devfeed.tech/tags/malware.md>), [network](<https://devfeed.tech/tags/network.md>), [networks](<https://devfeed.tech/tags/networks.md>), [resilience](<https://devfeed.tech/tags/resilience.md>), [routing](<https://devfeed.tech/tags/routing.md>), [rpc](<https://devfeed.tech/tags/rpc.md>), [spoofing](<https://devfeed.tech/tags/spoofing.md>), [threat-research](<https://devfeed.tech/tags/threat-research.md>)

### AI overview

Kimwolf v7 is an Android and IoT botnet variant that adds HTTP/2-based DDoS flooding with browser fingerprinting, Ethereum Name Service resolution for C2 addresses, and Tor-backed routing to improve infrastructure resilience. The article also describes its targeting of Android TV devices and exploitation of unauthenticated ADB instances.

### Source excerpt

Discover how Kimwolf v7 targets Android IoT devices with HTTP/2 DDoS fingerprinting, Ethereum ENS C2 resolution and Tor backup routing. The post Kimwolf v7: An Evolution of the Kimwolf Botnet appeared first on Unit 42.

## ESET takes part in Operation Endgame to disrupt Amadey and Stealc

DevFeed: [ESET takes part in Operation Endgame to disrupt Amadey and Stealc](<https://devfeed.tech/articles/eset-takes-part-in-operation-endgame-to-disrupt-amadey-and-stealc-8364.md>)

Original publisher: [Read original article](<https://www.welivesecurity.com/en/eset-research/eset-takes-part-operation-endgame-disrupt-amadey-stealc/>)

Author: Jakub Tomanek Tomáš Procházka

Published: 2026-06-24T12:35:24Z

Content type: article

Language: en

Sources: [WeLiveSecurity](<https://devfeed.tech/sources/welivesecurity.md>)

Topics: [ESET research](<https://devfeed.tech/topics/eset-research.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [Threat Research](<https://devfeed.tech/topics/threat-research.md>), [Cybercrime](<https://devfeed.tech/topics/cybercrime.md>), [C2](<https://devfeed.tech/topics/c2.md>), [High Profile Threats](<https://devfeed.tech/topics/high-profile-threats.md>), [Encryption](<https://devfeed.tech/topics/encryption.md>), [data](<https://devfeed.tech/topics/data.md>), [Statistics](<https://devfeed.tech/topics/statistics.md>)

Tags: [analysis](<https://devfeed.tech/tags/analysis.md>), [data](<https://devfeed.tech/tags/data.md>), [encryption](<https://devfeed.tech/tags/encryption.md>), [eset-research](<https://devfeed.tech/tags/eset-research.md>), [maas](<https://devfeed.tech/tags/maas.md>), [malware](<https://devfeed.tech/tags/malware.md>), [network](<https://devfeed.tech/tags/network.md>), [research](<https://devfeed.tech/tags/research.md>)

### AI overview

ESET Research describes its contribution to Operation Endgame, a coordinated global effort that disrupted the Amadey botnet and Stealc infostealer. The article covers infrastructure tracking, technical and statistical analysis, malware configuration data, command-and-control servers, encryption keys, campaign identifiers, and affiliate-level activity within the malware-as-a-service ecosystem.

### Source excerpt

ESET researchers assisted in the global disruption of the Amadey botnet and Stealc infostealer, providing technical analysis, infrastructure tracking, and affiliate-level insights

## Killing me gently: Inside Gentlemen's EDR killer framework

DevFeed: [Killing me gently: Inside Gentlemen's EDR killer framework](<https://devfeed.tech/articles/killing-me-gently-inside-gentlemen-s-edr-killer-framework-8373.md>)

Original publisher: [Read original article](<https://www.welivesecurity.com/en/eset-research/killing-me-gently-inside-gentlemens-edr-killer-framework/>)

Author: Jakub Souček

Published: 2026-06-18T09:46:32Z

Content type: article

Language: en

Sources: [WeLiveSecurity](<https://devfeed.tech/sources/welivesecurity.md>)

Topics: [ESET research](<https://devfeed.tech/topics/eset-research.md>), [Endpoint Security & XDR](<https://devfeed.tech/topics/endpoint-security-xdr.md>), [ransomware](<https://devfeed.tech/topics/ransomware.md>), [Security](<https://devfeed.tech/topics/security.md>), [Cybercrime](<https://devfeed.tech/topics/cybercrime.md>), [Software](<https://devfeed.tech/topics/software.md>)

Tags: [analysis](<https://devfeed.tech/tags/analysis.md>), [eset-research](<https://devfeed.tech/tags/eset-research.md>), [europe](<https://devfeed.tech/tags/europe.md>), [insights](<https://devfeed.tech/tags/insights.md>), [ransomware](<https://devfeed.tech/tags/ransomware.md>), [research](<https://devfeed.tech/tags/research.md>), [security](<https://devfeed.tech/tags/security.md>), [software](<https://devfeed.tech/tags/software.md>), [southeast-asia](<https://devfeed.tech/tags/southeast-asia.md>), [techniques](<https://devfeed.tech/tags/techniques.md>)

### AI overview

ESET Research analyzes Gentlemen's ransomware-as-a-service operation and its portfolio of EDR-killing tools. The article examines the in-house GentleKiller framework, third-party tools, shared defense-evasion techniques, and the group's rapid adoption of BYOVD exploits, using incident-level visibility and leaked internal data.

### Source excerpt

ESET Research shares the results of a months-long investigation into the suite of EDR killers maintained by the RaaS gang Gentlemen

## The foundation of security compliance for financial services businesses

DevFeed: [The foundation of security compliance for financial services businesses](<https://devfeed.tech/articles/the-foundation-of-security-compliance-for-financial-services-businesses-1918.md>)

Original publisher: [Read original article](<https://1password.com/blog/foundation-of-security-compliance-for-financial-services>)

Author: info@1password.com (Rachel Sudbeck)

Published: 2026-06-16T00:00:00Z

Content type: article

Language: en

Sources: [Blog on 1Password Blog](<https://devfeed.tech/sources/blog-on-1password-blog.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Business Security](<https://devfeed.tech/topics/business-security.md>), [Software as a service](<https://devfeed.tech/topics/saas.md>), [Cybercrime](<https://devfeed.tech/topics/cybercrime.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>)

Tags: [2026](<https://devfeed.tech/tags/2026.md>), [ai](<https://devfeed.tech/tags/ai.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [business](<https://devfeed.tech/tags/business.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [financial-services](<https://devfeed.tech/tags/financial-services.md>), [ransomware](<https://devfeed.tech/tags/ransomware.md>), [saas](<https://devfeed.tech/tags/saas.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

This article explains why small and medium-sized financial services businesses need a strong security and compliance foundation. It highlights rising cyberattack and ransomware risks, limited security resources, credential management challenges, and the way AI adoption can increase SaaS sprawl, shadow IT, policy violations, and attack sophistication.

### Source excerpt

One of the less surprising findings of the 2026 Verizon Data Breach Incident Report (DBIR) is the fact that incidents targeting the Financial and Insurance sector are on the rise. As they put it, "This sector continues to be a favorite among attackers, which isn't surprising given that its core business is handling money." For small-to-medium businesses (SMBs) in the financial services sector, the DBIR paints an even more dire picture. The report notes that SMBs face the same threats and breach patterns of larger organizations, but are also disproportionately impacted by attacks; 96% of ransomware victims were SMBs. In short: businesses in the financial services industry who are still building their foundation, or who possess limited security resources, are caught between a rock and a hard place. They operate within one of the most heavily targeted sectors for cyberattack, and are held to enterprise-level security standards by regulators and clients alike, but they're operating with startup-level security resources. For lean security and IT teams to make the most of those limited resources, they need to focus on what they can afford. That means getting the fundamentals right for a strong and impactful security foundation. The highest-leverage fundamental is, of course, credential management. Top security challenges for financial services organizations Small IT and security teams in the financial services industry are faced with high expectations when it comes to security. Unfortunately, they also experience significant challenges when it comes to securing credentials. AI is accelerating SaaS and credential sprawl JP Morgan Chase's recent research report, Understanding the use of AI among small businesses, finds that not only are a growing number of small businesses adopting AI, when they do, they also tend to implement a greater number and variety of AI tools. It's not hard to understand why this is the case; AI's ability to automate processes and improve productivi

## The 2026 DBIR says the quiet part loud: fundamentals still win

DevFeed: [The 2026 DBIR says the quiet part loud: fundamentals still win](<https://devfeed.tech/articles/the-2026-dbir-says-the-quiet-part-loud-fundamentals-still-win-1964.md>)

Original publisher: [Read original article](<https://1password.com/blog/the-2026-verizon-dbir>)

Author: info@1password.com (Dave Lewis)

Published: 2026-06-11T00:00:00Z

Content type: article

Language: en

Sources: [Blog on 1Password Blog](<https://devfeed.tech/sources/blog-on-1password-blog.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [ransomware](<https://devfeed.tech/topics/ransomware.md>), [Cybercrime](<https://devfeed.tech/topics/cybercrime.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [breach](<https://devfeed.tech/tags/breach.md>), [exploits](<https://devfeed.tech/tags/exploits.md>), [ransomware](<https://devfeed.tech/tags/ransomware.md>), [security](<https://devfeed.tech/tags/security.md>), [statistics](<https://devfeed.tech/tags/statistics.md>), [tips-advice](<https://devfeed.tech/tags/tips-advice.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

The article reviews the 2026 Verizon Data Breach Investigations Report, arguing that basic security practices remain essential. It highlights rising vulnerability exploitation, slower remediation, ransomware prevalence, and the potential impact of AI on future vulnerabilities.

### Source excerpt

Every year, the Verizon Data Breach Investigations Report (DBIR) is one of the most hotly-anticipated and widely-read documents in security. And every year includes some surprising stats and reshuffles the top few threat vectors. But longtime readers will notice that the 2026 DBIR features some advice that ought to be familiar to everyone by now: get the basics right. The report's authors even say that the overarching theme this year is "keeping a strong foundation in the face of change." So what does a strong foundation look like? It looks like patching faster, reducing credential reuse, tightening third-party access, and making it harder for attackers to turn one weak login into a company-wide mess. Glamorous? No. Effective? Yes. Exploits, credentials, and AI: The stories that stood out in the 2026 DBIR This year's DBIR analyzes more than 31,000 incidents, including more than 22,000 confirmed breaches across 145 countries. It's not light reading, unless your idea of a beach read includes ransomware economics, exploit chains, and the occasional donut chart. But diving deep into these topics is worthwhile, because the numbers show both change and stubborn repetition. Vulnerability exploitation is surging In terms of eye-popping statistics, the big story this year is the explosion of vulnerability exploitation, which is now the leading initial access vector for breaches-far exceeding phishing and credential abuse. Only 26% of critical vulnerabilities in the CISA Known Exploited Vulnerabilities catalog were fully remediated in 2025, down from 38% the prior year. Median time to full remediation rose to 43 days, a huge jump from last year's 32 days. Maybe the scariest part of this whole scenario is that these are pre-Mythos numbers, and security experts are still bracing for an AI-powered hurricane of vulnerabilities. The report's authors attribute this escalation to the sheer volume of vulnerabilities organizations had to face, finding that there were roughly 50% more

## How Geopolitical Turmoil Enables Scams and How to Stay Safe

DevFeed: [How Geopolitical Turmoil Enables Scams and How to Stay Safe](<https://devfeed.tech/articles/why-geopolitical-turmoil-is-a-gift-for-scammers-and-how-to-stay-safe-8404.md>)

Original publisher: [Read original article](<https://www.welivesecurity.com/en/scams/geopolitical-turmoil-gift-scammers-how-stay-safe/>)

Author: Phil Muncaster

Published: 2026-05-15T08:50:00Z

Content type: article

Language: en

Sources: [WeLiveSecurity](<https://devfeed.tech/sources/welivesecurity.md>)

Topics: [Cybercrime](<https://devfeed.tech/topics/cybercrime.md>), [data](<https://devfeed.tech/topics/data.md>), [Internet](<https://devfeed.tech/topics/internet.md>)

Tags: [data](<https://devfeed.tech/tags/data.md>), [digital-security](<https://devfeed.tech/tags/digital-security.md>), [email](<https://devfeed.tech/tags/email.md>), [internet](<https://devfeed.tech/tags/internet.md>), [money](<https://devfeed.tech/tags/money.md>), [scams](<https://devfeed.tech/tags/scams.md>), [social-media](<https://devfeed.tech/tags/social-media.md>), [travel](<https://devfeed.tech/tags/travel.md>)

### AI overview

The article explains how geopolitical conflict creates opportunities for online scammers. It describes scams delivered through email, text, social media, or phone calls that seek credentials, personal or financial data, donations, or direct payments.

### Source excerpt

Conflict is a boon for opportunistic fraudsters. Look out for their ploys.

## Anthropic's Mythos and the acceleration of zero-day vulnerability discovery

DevFeed: [Anthropic's Mythos and the acceleration of zero-day vulnerability discovery](<https://devfeed.tech/articles/mythos-pulls-zero-days-forward-here-s-what-you-need-to-know-now-13167.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/mythos-pulls-zero-days-forward-heres-what-you-need-to-know-now>)

Published: 2026-04-27T00:00:00Z

Content type: opinion

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [anthropic](<https://devfeed.tech/topics/anthropic.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [ai-assisted attacks](<https://devfeed.tech/topics/ai-assisted-attacks.md>), [Exploit](<https://devfeed.tech/topics/exploit.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Security](<https://devfeed.tech/topics/security.md>), [Cybercrime](<https://devfeed.tech/topics/cybercrime.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [ai-assisted-attacks](<https://devfeed.tech/tags/ai-assisted-attacks.md>), [ai-containers](<https://devfeed.tech/tags/ai-containers.md>), [anthropic](<https://devfeed.tech/tags/anthropic.md>), [anthropic-mythos](<https://devfeed.tech/tags/anthropic-mythos.md>), [chainguard-ai](<https://devfeed.tech/tags/chainguard-ai.md>), [chainguard-containers](<https://devfeed.tech/tags/chainguard-containers.md>), [cybercrime](<https://devfeed.tech/tags/cybercrime.md>), [exploit](<https://devfeed.tech/tags/exploit.md>), [firefox](<https://devfeed.tech/tags/firefox.md>), [kernel](<https://devfeed.tech/tags/kernel.md>), [linux-kernel](<https://devfeed.tech/tags/linux-kernel.md>), [mythos](<https://devfeed.tech/tags/mythos.md>), [mythos-ai-model](<https://devfeed.tech/tags/mythos-ai-model.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>), [web](<https://devfeed.tech/tags/web.md>)

### AI overview

The article discusses Anthropic's Mythos Preview, an AI system described as capable of finding and exploiting previously undisclosed vulnerabilities. It presents examples involving OpenBSD, FFmpeg, the Linux kernel, and Firefox, and argues that such systems could shorten or bypass traditional vulnerability disclosure timelines.

### Source excerpt

Anthropic's Mythos is reshaping zero-day threats. Learn how Chainguard helps you stay ahead with source-built, continuously secure software supply chains.

## Worth Reading: Microsoft Cloud Security, Neuro-Symbolic AI, Linux 7.0, and AI-Driven Cybercrime

DevFeed: [Worth Reading: Microsoft Cloud Security, Neuro-Symbolic AI, Linux 7.0, and AI-Driven Cybercrime](<https://devfeed.tech/articles/worth-reading-042226-10912.md>)

Original publisher: [Read original article](<https://rule11.tech/wr-042226/>)

Author: Russ

Published: 2026-04-22T12:11:04Z

Content type: article

Language: en

Sources: [rule 11 reader](<https://devfeed.tech/sources/rule-11-reader.md>)

Topics: [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Cybercrime](<https://devfeed.tech/topics/cybercrime.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Linux](<https://devfeed.tech/topics/linux.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>), [Kernel](<https://devfeed.tech/topics/kernel.md>), [Microsoft](<https://devfeed.tech/topics/microsoft.md>), [networking](<https://devfeed.tech/topics/networking.md>), [Neural Network](<https://devfeed.tech/topics/neural-network.md>)

Tags: [artificial-intelligence](<https://devfeed.tech/tags/artificial-intelligence.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [cybercrime](<https://devfeed.tech/tags/cybercrime.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [kernel](<https://devfeed.tech/tags/kernel.md>), [linux](<https://devfeed.tech/tags/linux.md>), [machine](<https://devfeed.tech/tags/machine.md>), [microsoft](<https://devfeed.tech/tags/microsoft.md>), [networking](<https://devfeed.tech/tags/networking.md>), [neural](<https://devfeed.tech/tags/neural.md>), [worth-reading](<https://devfeed.tech/tags/worth-reading.md>)

### AI overview

This roundup covers a federal cybersecurity assessment of a major Microsoft cloud offering, the evolution of neuro-symbolic artificial intelligence, the Linux 7.0 kernel release, and the threat of AI-driven cybercrime to small businesses.

### Source excerpt

In late 2024, the federal government's cybersecurity evaluators rendered a troubling verdict on one of Microsoft's biggest cloud computing offerings. This report explores the evolution and current state of neuro- symbolic artificial intelligence, an approach that integrates neural network capabilities with symbolic reasoning. The Linux 7.0 kernel is now out, and it's one of the most impactful releases in years for networking professionals. The human-speed defense of small business is being obliterated by the machine-speed offense of AI-driven cybercrime. Today, what large companies treat as a manageable risk is a terminal expense for small enterprises, with 60% of small enterprises shutting down within six months of a major attack. The original frustration was familiar. You build on one provider, they change pricing, deprecate an API, or just aren't the right tool anymore, and migrating is brutal.

## What the ransom note won't say

DevFeed: [What the ransom note won't say](<https://devfeed.tech/articles/what-the-ransom-note-won-t-say-8399.md>)

Original publisher: [Read original article](<https://www.welivesecurity.com/en/ransomware/what-ransom-note-doesnt-say/>)

Author: Tomáš Foltýn

Published: 2026-04-20T09:00:00Z

Content type: article

Language: en

Sources: [WeLiveSecurity](<https://devfeed.tech/sources/welivesecurity.md>)

Topics: [ransomware](<https://devfeed.tech/topics/ransomware.md>), [Cybercrime](<https://devfeed.tech/topics/cybercrime.md>), [incident](<https://devfeed.tech/topics/incident.md>), [Network](<https://devfeed.tech/topics/network.md>), [Tooling](<https://devfeed.tech/topics/tooling.md>), [data](<https://devfeed.tech/topics/data.md>)

Tags: [cybercrime](<https://devfeed.tech/tags/cybercrime.md>), [data](<https://devfeed.tech/tags/data.md>), [incident](<https://devfeed.tech/tags/incident.md>), [network](<https://devfeed.tech/tags/network.md>), [ransomware](<https://devfeed.tech/tags/ransomware.md>), [tooling](<https://devfeed.tech/tags/tooling.md>)

### AI overview

The article explains that modern ransomware is an organized business operation involving developers, affiliates, initial access brokers, suppliers, partners, subscription services, and tooling markets. It argues that focusing only on the visible ransom note obscures the supply chains and coordinated infrastructure that enable successful attacks.

### Source excerpt

An attack is what you see, but a business operation is what you're up against

## 2026: The year of AI-assisted attacks

DevFeed: [2026: The year of AI-assisted attacks](<https://devfeed.tech/articles/2026-the-year-of-ai-assisted-attacks-12853.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/2026-the-year-of-ai-assisted-attacks>)

Published: 2026-04-14T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Cybercrime](<https://devfeed.tech/topics/cybercrime.md>), [Hacking](<https://devfeed.tech/topics/hacking.md>), [Large Language Model](<https://devfeed.tech/topics/llm.md>), [Claude Code](<https://devfeed.tech/topics/claude-code.md>), [ChatGPT](<https://devfeed.tech/topics/chatgpt.md>), [Malware](<https://devfeed.tech/topics/malware.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [ai-assisted-attacks](<https://devfeed.tech/tags/ai-assisted-attacks.md>), [ai-containers](<https://devfeed.tech/tags/ai-containers.md>), [axios](<https://devfeed.tech/tags/axios.md>), [breach](<https://devfeed.tech/tags/breach.md>), [chainguard-for-ai](<https://devfeed.tech/tags/chainguard-for-ai.md>), [chatgpt](<https://devfeed.tech/tags/chatgpt.md>), [claude-code](<https://devfeed.tech/tags/claude-code.md>), [code](<https://devfeed.tech/tags/code.md>), [cybercrime](<https://devfeed.tech/tags/cybercrime.md>), [llm](<https://devfeed.tech/tags/llm.md>), [malicious-packages](<https://devfeed.tech/tags/malicious-packages.md>), [malwhere](<https://devfeed.tech/tags/malwhere.md>), [mythos](<https://devfeed.tech/tags/mythos.md>), [phishing](<https://devfeed.tech/tags/phishing.md>), [telnyx](<https://devfeed.tech/tags/telnyx.md>), [trivy](<https://devfeed.tech/tags/trivy.md>)

### AI overview

The article argues that AI-assisted attacks became more capable and accessible in 2025. It describes how ChatGPT, Claude Code, and other LLM-backed systems enabled nontechnical individuals and lone actors to conduct attacks previously associated with skilled hackers or organized teams, while citing increases in malicious packages, cloud intrusions, and AI-generated phishing.

### Source excerpt

AI is lowering the barrier to cybercrime. Learn why attacks are rising fast, and how eliminating entire classes of supply chain risk is the only path forward.

## EDR killers explained: Beyond the drivers

DevFeed: [EDR killers explained: Beyond the drivers](<https://devfeed.tech/articles/edr-killers-explained-beyond-the-drivers-8361.md>)

Original publisher: [Read original article](<https://www.welivesecurity.com/en/eset-research/edr-killers-explained-beyond-the-drivers/>)

Author: Jakub Souček

Published: 2026-03-19T09:55:08Z

Content type: article

Language: en

Sources: [WeLiveSecurity](<https://devfeed.tech/sources/welivesecurity.md>)

Topics: [Endpoint Security & XDR](<https://devfeed.tech/topics/endpoint-security-xdr.md>), [ransomware](<https://devfeed.tech/topics/ransomware.md>), [Cybercrime](<https://devfeed.tech/topics/cybercrime.md>), [Encryption](<https://devfeed.tech/topics/encryption.md>), [telemetry](<https://devfeed.tech/topics/telemetry.md>), [1Password in the browser](<https://devfeed.tech/topics/1password-in-the-browser.md>)

Tags: [development](<https://devfeed.tech/tags/development.md>), [encryption](<https://devfeed.tech/tags/encryption.md>), [eset-research](<https://devfeed.tech/tags/eset-research.md>), [ransomware](<https://devfeed.tech/tags/ransomware.md>), [research](<https://devfeed.tech/tags/research.md>), [techniques](<https://devfeed.tech/tags/techniques.md>), [telemetry](<https://devfeed.tech/tags/telemetry.md>)

### AI overview

ESET researchers analyze nearly 90 EDR killers used in real ransomware intrusions, examining vulnerable-driver, anti-rootkit, script-based, and driverless approaches to disabling endpoint protection. The article explains how affiliates select and adapt these tools, why driver-based attribution can mislead, and how commercialized kits increase defense complexity.

### Source excerpt

ESET researchers dive deeper into the EDR killer ecosystem, disclosing how attackers abuse vulnerable drivers

## PromptSpy ushers in the era of Android threats using GenAI

DevFeed: [PromptSpy ushers in the era of Android threats using GenAI](<https://devfeed.tech/articles/promptspy-ushers-in-the-era-of-android-threats-using-genai-8379.md>)

Original publisher: [Read original article](<https://www.welivesecurity.com/en/eset-research/promptspy-ushers-in-era-android-threats-using-genai/>)

Author: Lukas Stefanko

Published: 2026-02-19T10:30:20Z

Content type: news

Language: en

Sources: [WeLiveSecurity](<https://devfeed.tech/sources/welivesecurity.md>)

Topics: [Android](<https://devfeed.tech/topics/android.md>), [Generative AI](<https://devfeed.tech/topics/generative-ai.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [genai](<https://devfeed.tech/topics/genai.md>), [Cybercrime](<https://devfeed.tech/topics/cybercrime.md>), [Persistence](<https://devfeed.tech/topics/persistence.md>), [Encryption](<https://devfeed.tech/topics/encryption.md>), [Google](<https://devfeed.tech/topics/google.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [android](<https://devfeed.tech/tags/android.md>), [encryption](<https://devfeed.tech/tags/encryption.md>), [eset-research](<https://devfeed.tech/tags/eset-research.md>), [genai](<https://devfeed.tech/tags/genai.md>), [generative-ai](<https://devfeed.tech/tags/generative-ai.md>), [google](<https://devfeed.tech/tags/google.md>), [malware](<https://devfeed.tech/tags/malware.md>), [persistence](<https://devfeed.tech/tags/persistence.md>), [server](<https://devfeed.tech/tags/server.md>), [video](<https://devfeed.tech/tags/video.md>)

### AI overview

ESET researchers report PromptSpy, an Android malware family that uses Google Gemini and generative AI to analyze the device screen and adapt malicious user-interface manipulation. The malware uses this capability to maintain persistence, while also providing remote access, blocking uninstallation, capturing lockscreen data, and recording video.

### Source excerpt

ESET researchers discover PromptSpy, the first known Android malware to abuse generative AI in its execution flow

## Naming and shaming: How ransomware groups tighten the screws on victims

DevFeed: [Naming and shaming: How ransomware groups tighten the screws on victims](<https://devfeed.tech/articles/naming-and-shaming-how-ransomware-groups-tighten-the-screws-on-victims-8398.md>)

Original publisher: [Read original article](<https://www.welivesecurity.com/en/ransomware/naming-shaming-ransomware-groups-tighten-screws-victims/>)

Author: Guilherme Arruda Tomáš Foltýn

Published: 2026-02-12T10:00:00Z

Content type: article

Language: en

Sources: [WeLiveSecurity](<https://devfeed.tech/sources/welivesecurity.md>)

Topics: [ransomware](<https://devfeed.tech/topics/ransomware.md>), [Cybercrime](<https://devfeed.tech/topics/cybercrime.md>), [data](<https://devfeed.tech/topics/data.md>), [Security](<https://devfeed.tech/topics/security.md>), [incident](<https://devfeed.tech/topics/incident.md>), [Encryption](<https://devfeed.tech/topics/encryption.md>)

Tags: [cybercrime](<https://devfeed.tech/tags/cybercrime.md>), [data](<https://devfeed.tech/tags/data.md>), [encryption](<https://devfeed.tech/tags/encryption.md>), [incident](<https://devfeed.tech/tags/incident.md>), [ransomware](<https://devfeed.tech/tags/ransomware.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

The article explains how ransomware groups use dedicated data leak sites as part of double-extortion campaigns. Attackers exfiltrate corporate data, encrypt systems, and publish samples or threaten full disclosure to pressure victims into paying.

### Source excerpt

When corporate data is exposed on a dedicated leak site, the consequences linger long after the attack fades from the news cycle

## This month in security with Tony Anscombe - January 2026 edition

DevFeed: [This month in security with Tony Anscombe - January 2026 edition](<https://devfeed.tech/articles/this-month-in-security-with-tony-anscombe-january-2026-edition-8423.md>)

Original publisher: [Read original article](<https://www.welivesecurity.com/en/videos/month-security-tony-anscombe-january-2026-edition/>)

Author: Editor

Published: 2026-01-30T15:20:16Z

Content type: news

Language: en

Sources: [WeLiveSecurity](<https://devfeed.tech/sources/welivesecurity.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [AI Platform](<https://devfeed.tech/topics/ai-platform.md>), [Cybercrime](<https://devfeed.tech/topics/cybercrime.md>), [ransomware](<https://devfeed.tech/topics/ransomware.md>), [incident](<https://devfeed.tech/topics/incident.md>), [data](<https://devfeed.tech/topics/data.md>)

Tags: [ai-platform](<https://devfeed.tech/tags/ai-platform.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [data](<https://devfeed.tech/tags/data.md>), [fraud](<https://devfeed.tech/tags/fraud.md>), [incident](<https://devfeed.tech/tags/incident.md>), [news](<https://devfeed.tech/tags/news.md>), [ransomware](<https://devfeed.tech/tags/ransomware.md>), [security](<https://devfeed.tech/tags/security.md>), [video](<https://devfeed.tech/tags/video.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

### AI overview

January's security roundup covers an AI-platform vulnerability in ServiceNow, abuse of unsecured Zendesk systems for spam, rising concern about cyber-fraud, and a ransomware group's alleged theft of Nike data.

### Source excerpt

The trends from January offer useful clues about the risks and priorities that security teams are likely to contend with throughout the year

[Next page](<https://devfeed.tech/topics/cybercrime.md?cursor=WyIyMDI2LTAxLTMwVDE1OjIwOjE2KzAwOjAwIiwgIjM5MDc3N2MwLWVkMWMtNGYxYi05ODRiLWZjODMxMjhjOGFhYyJd>)