Over 200 Japanese firms paid ransomware attackers, 60% fail to recover data

A survey found that at least 222 Japanese companies paid ransom demands but roughly 60% still failed to recover their data. Of 1,107 respondents, 507 reported ransomware attacks, and experts warn that paying ransoms does not guarantee recovery while urging updated security and regular backups. #JapanInstituteForPromotionOfDigitalEconomyAndCommunity #Proofpoint

Read More
The Price of Privacy: Atlassian to Train AI on Jira and Confluence Data Starting August 2026

Atlassian has revised its data contribution policy so that, effective August 17, 2026, it will use customer metadata and in‑app content from Jira, Confluence, and related cloud offerings to train its AI models, affecting roughly 300,000 customers. Data will be classified into de‑identified metadata (readability, complexity, task taxonomies, semantic similarity, iteration…

Read More
Anubis Ransomware Attack Hits ViaQuest and Samuel I White PC

Anubis group claims to have breached multiple organizations, exposing over five terabytes of sensitive information across the healthcare and legal sectors. The alleged victims include ViaQuest and Samuel I. White, PC, with stolen files spanning patient medical records, internal emails, financial documents, court filings, client databases, and network passwords. #Anubis #ViaQuest…

Read More
The Ghost in the Browser: Is Claude Desktop Clandestinely Installing a Surveillance Bridge?

Alexander Hanff found that Claude Desktop silently installs a native messaging bridge that pre-authorizes browser extensions to communicate with local executables, enabling browser automation, DOM access, session sharing, and other elevated actions without user consent. The manifest is autonomously generated across multiple Chromium browsers, persists and is rewritten on launch with…

Read More
IT Forensics Team Investigates Ransomware Attack on Sprendlingen-Gensingen Municipal Administration

Threat actor Rabid is advertising a complete 250GB+ database from the Chartered Institute of Bankers of Nigeria (CIBN), claiming it contains the institute’s full records and platform source code. The archive includes member personal data, scanned ID and academic documents, and internal code that could enable identity theft, synthetic identity fraud,…

Read More
IT Forensics Team Investigates Ransomware Attack on Sprendlingen-Gensingen Municipal Administration

A threat actor known as Sorb is selling a database attributed to Taiseer (taiseer.co) containing 71,000 user records, including bcrypt password hashes, 27,000 national ID scans, emails, phone numbers, FCM push tokens, and per-user gold balances. The listing is priced at $400 with escrow and claims ongoing access, creating high risk…

Read More
DFIR Report – The Gentlemen & SystemBC: A Sneak Peek Behind the Proxy

The Gentlemen RaaS has rapidly expanded in early 2026, claiming over 320 victims and offering multi‑platform lockers written in Go for Windows, Linux, NAS and BSD plus a C‑based ESXi variant. Incident response telemetry shows affiliates deploying SystemBC and Cobalt Strike, revealing a botnet of over 1,570 likely corporate victims and demonstrating GPO‑based mass deployment, robust lateral movement, and aggressive defense‑evasion. #TheGentlemen #SystemBC

Read More
Everest Group Breaches Frost Bank, Citizens Bank, Tokoparts, Complete Aircraft Group, Umiles, Nutrabio

The Everest ransomware group claims to have breached multiple organizations across the financial, aviation, automotive, and retail sectors and has posted large troves of highly sensitive corporate and customer data on its extortion portal with active countdowns to public release. Alleged victims include Frost Bank, Citizens Bank, Tokoparts, Complete Aircraft Group,…

Read More