Monday , August 24 2026
blacksuit

CISA, FBI released joint advisory for Blacksuit ransomware

The FBI and CISA updated their advisory to confirm that the Royal ransomware group now goes by the name “BlackSuit” and still demands very high ransom amounts, up to $60 million.

The advisory has new technical information to help defenders detect the activity of the group, known as Royal ransomware from September 2022 to July 2023 and now called BlackSuit.

After BDJobs, Directorate of Secondary and Higher Education 390k data surfaced online

A group of hackers named “Madarax” claims they have stolen and are offering to sell the personal information of about...
Read More
After BDJobs, Directorate of Secondary and Higher Education 390k data surfaced online

Researchers show new technique to bypass AI safety guardrails in Grok and Gemini

A new hacking technique has been demonstrated to steal data from Elon Musk's Grok AI. It uses a simple trick...
Read More
Researchers show new technique to bypass AI safety guardrails in Grok and Gemini

About thousands of leaked AWS keys Held Full Admin Rights

More than 9,300 AWS access keys that were made public from August 2022 to August 2026 are still active, says...
Read More
About thousands of leaked AWS keys Held Full Admin Rights

US Bank investigates LockBit’s Data Breach Claims

US Bank is looking into LockBit's claims about a breach and stolen data. The ransomware group says they will share...
Read More
US Bank investigates LockBit’s Data Breach Claims

Five new malware families actively targeting Asian Gov.t infra

Central Asian government agencies have been attacked in a cyber spy operation that used a small but different range of...
Read More
Five new malware families actively targeting Asian Gov.t infra

T-Mobile Cuts Cables to Remove Chiness Salt Typhoon Hackers from Network

T-Mobile’s cybersecurity team reportedly physically cut a network cable connecting compromised infrastructure to the outside world. According to Bloomberg, the move...
Read More
T-Mobile Cuts Cables to Remove Chiness Salt Typhoon Hackers from Network

Splunk, Zyxel Patch Multiple Flaws Enabling RCE and Root Command Execution

Splunk has issued security fixes for 17 weaknesses in different apps and add-ons, such as Splunk MCP Server, Splunk AI...
Read More
Splunk, Zyxel Patch Multiple Flaws Enabling RCE and Root Command Execution

“Zombie Card” attack revels expired Visa card may be used for contactless payments

Security experts have shown that expired credit cards can still be used. A study from the University of Massachusetts Amherst,...
Read More
“Zombie Card” attack revels expired Visa card may be used for contactless payments

Critical Zimbra RCE Flaw Actively Exploited in the Wild

CERT Polska has alerted that bad actors are actively exploiting a security flaw in Zimbra Collaboration Suite to execute code...
Read More
Critical Zimbra RCE Flaw Actively Exploited in the Wild

Operation CameraSwarm
A single hacker compromise 1400+ Dahua camera worldwide 

Operation CameraSwarm compromised 14,500+ Dahua IP cameras mostly in Ukraine and Russia. The operation lasted for at least 35 days...
Read More
Operation CameraSwarm  A single hacker compromise 1400+ Dahua camera worldwide 

The group got attention from the police last summer when they attacked Dallas, causing damage to the city’s emergency services, courts, and government. In November, the FBI and CISA warned that Royal was transitioning to the “BlackSuit” branding for attacks. The latest update confirms that all of the group’s new attacks, some as recent as July, are linked to the new name.

“Ransom demands have typically ranged from approximately $1 million to $10 million, with payment demanded in Bitcoin,” the agencies said. “BlackSuit actors have exhibited a willingness to negotiate payment amounts.”

The agencies linked the hackers behind the two groups based on “numerous coding similarities” but noted that BlackSuit has “exhibited improved capabilities.”

Hackers still rely on phishing emails to launch successful attacks. They use these emails to gain initial access, disable antivirus software, steal a lot of data, and deploy ransomware.

The agencies noted there has been a recent uptick in attacks where victims “received telephonic or email communications from BlackSuit actors regarding the compromise and ransom.”

A new report from Sophos, a cybersecurity company, revealed that several ransomware groups are using this tactic to pressure victims into paying ransoms. Ransomware gangs have been contacting patients and customers of multiple hospitals and businesses, threatening them with data stolen or accessed during attacks.

According to Chester Wisniewski, Sophos Field CTO, ransomware gangs used to rely on media coverage to scare victims. However, in recent times, these groups have started directly contacting customers and patients as a new way to apply pressure.

Wisniewski argued that the tactic has not been successful, as companies mostly base their decision to pay ransoms on practical factors such as business downtime and regulatory concerns.

Check Also

Anthropic

Anthropic’s Claude Code Source Code Reportedly Leaked

Anthropic’s special Claude Code CLI tool had its complete TypeScript source code inadvertently exposed due …