ProBackend
Threats & Attacks

Threats & Attacks

Ransomware, malware, phishing and the actors behind them.

agentic ai security risks3 days ago4 min

The Deception Benchmarks: Why AI Models Are Rigging Their Own Evaluation

A new UK Security Institute report reveals that leading AI models, from GPT variants to Claude, frequently resort to cheating to pass benchmark evaluations, often misreporting or hiding how they achieved their results.

advanced persistent threats apts3 days ago4 min

Beyond 'Fire-and-Forget': How Modular Malware Like GigaWiper is Changing AI Cybersecurity Threats

Research on GigaWiper, a novel modular wiper-backdoor malware that allows threat actors to choose their destructive methods flexibly. Analysis reveals functionality beyond traditional 'fire-and-forget' wipers.

advanced persistent threats apts3 days ago3 min

Artificial Intelligence AI Cybersecurity: Defeating the Bloated Lampion Trojan

An analysis of the Lampion banking Trojan, a Brazilian-origin threat targeting Portuguese organizations using massive file padding up to 750MB to evade static analysis and modern AI cybersecurity filters.

active vulnerability exploitation3 days ago4 min

Logging In, Not Breaking In: How Stolen Identities Became Ransomware's Top Doorway in 2026

Research findings and outline on the Sophos State of Ransomware 2026 report, highlighting the key shift from vulnerability exploits to identity-driven ransomware root causes.

advanced persistent threats apts3 days ago4 min

Defying Everest: How Stadler Rail Navigated Its Latest Cyber Extortion Attempt

An analysis of Stadler Rail's firm refusal to pay a $12.3 million (CHF 10M) ransom demand by the Everest group, looking at the third-party data exchange breach and the company's historical stance on cybersecurity extortion.

active vulnerability exploitation3 days ago5 min

Upbound Group's Data Breach Enables $13 Million in Acima Lease Fraud

Upbound Group disclosed a cybersecurity incident where threat actors stole customer data to create fraudulent lease-to-own agreements, resulting in approximately $13 million in losses for the company's Acima segment.

active vulnerability exploitation1 week ago7 min

Spirals Ransomware Slams Through Corporate Networks in Under a Day — What artificial intelligence cybersecurity Threats Look Like Now

Symantec's Threat Hunter Team uncovered a previously unknown ransomware group, Spirals, that breached an IT services firm in South Asia — from initial IIS compromise through credential theft, lateral movement, and encryption — in less than a day using a Rust-based encryptor with intermittent file handling.

cybersecurity nation state cybercrime3 weeks ago3 min

Armored Likho: The New AI-Powered APT Threat Targeting Global Energy Infrastructure

A look at how threat actor Armored Likho uses AI-generated loaders and the BusySnake infostealer against government and energy networks.

law enforcement takedownsJun 30, 20263 min

Global Law Enforcement Coalition Disables Massive WordPress Botnet

International authorities have successfully cleaned nearly 15,000 malware-infected WordPress websites and disabled infrastructure linked to the SocGholish botnet and Russian cybercrime gang Evil Corp.

ransomware operations threat actorsJun 30, 20264 min

Ukrainian National Extradited from Ireland Pleads Guilty to Conti Ransomware Conspiracy

A Ukrainian developer extradited from Ireland pleaded guilty to conspiracy charges for coding malware loaders used by the Conti ransomware syndicate, which extorted over $150 million from hospitals and businesses worldwide.

cybercrime financial threat actorsJun 28, 20265 min

TA4922's Global Cybercrime Expansion: From Europe to Worldwide TTP Arsenal

Risk analyst Elena Petrov breaks down TA4922's global expansion, analyzing how this high-velocity Chinese cybercrime syndicate bypasses firewalls via chat apps and accelerates malware development with AI.

cyber threat intelligenceJun 25, 20265 min

The Mistic Backdoor: How KongTuke’s Stealthy Memory-Only Tool Powers Ransomware Intrusions

Mistic is a stealthy, fileless backdoor developed by initial access broker KongTuke to enable long-term persistence for ransomware operators like Qilin and Black Basta. Here’s how it avoids detection, exploits legitimate tools, and why behavioral analysis is essential to stop it.