Stadler Rail Everest Ransomware: SFr10m Demand Refused

Stadler Rail Everest Ransomware: SFr10m Demand Refused

The Stadler Rail Everest ransomware incident shows what a mature extortion response looks like: the Swiss train manufacturer confirmed that the Everest group stole supplier technical data through a shared data-exchange platform and demanded roughly SFr10m (about $12.3M) — and Stadler refused outright, filing a criminal complaint instead of negotiating. What Happened Stadler Rail, an…

Read More

GodDamn Ransomware PoisonX Driver Kills EDR

GodDamn ransomware PoisonX driver

The GodDamn ransomware PoisonX driver is a Microsoft-signed kernel tool that ransomware operators use to silently kill EDR and antivirus processes before deploying encryption — and because the driver carries a legitimate Microsoft signature, standard driver-trust checks wave it straight through. What Happened Symantec disclosed on July 9, 2026 that a ransomware family called GodDamn…

Read More

DragonForce Ransomware Hides C2 Traffic Inside Microsoft Teams Relay Servers

Ransomware operators found a backdoor into your network. It looks exactly like a Teams meeting. Symantec and Carbon Black disclosed that DragonForce ransomware affiliates deployed Backdoor.Turn — a Go-based implant that tunnels its command-and-control traffic through Microsoft Teams TURN relay servers. The malware obtains an anonymous Teams visitor token, uses a legitimate Microsoft relay for…

Read More

Your password manager just had encrypted vaults stolen. That’s not a near-miss.

Your password manager just had encrypted vaults stolen. That’s not a near-miss. Dashlane disclosed this week that attackers successfully downloaded encrypted password vaults belonging to fewer than 20 users via a brute-force attack. Dashlane notes the vaults remain encrypted and there’s no evidence of successful decryption. Most organizations reading this will breathe a sigh of…

Read More