Recently, a new ransomware group, dubbed Anubis, emerged. KELA has observed representatives of Anubis on both RAMP (using the moniker ‘superSonic’) and XSS (using the moniker ‘Anubis__media’). Read more in our blog.
The State of Cybercrime 2024: Key Threats & What’s Coming in 2025
2024 was a defining year for cybercrime. Infostealers fueled credential leaks at an unprecedented scale, ransomware gangs shifted their tactics, and AI-powered threats emerged as a new battleground. Read KELA’s newly released report, The State of Cybercrime 2024, for an in-depth look.
Inside the Black Basta Leak: How Ransomware Operators Gain Access
A major data leak has exposed the internal workings of Black Basta, revealing how one of the most active ransomware groups infiltrates and exploits its victims. KELA analyzed the leaked data to uncover the top five initial access and lateral movement tactics used by the group—including how stolen credentials from infostealer malware logs are fueling attacks.
Could The Belsen Group Be Associated With ZeroSevenGroup?
KELA explores a possible link between the Belsen Group and ZeroSevenGroup, two cybercriminal entities with ties to Yemen. The Belsen Group surfaced in January 2025, leaking Fortinet data and selling network access, while ZeroSevenGroup had been active earlier, breaching companies and monetizing stolen data. Notably, both groups share similarities in writing style and post formatting. […]
Brevo supply-chain attack injected ClickFix scripts on customer sites
Brevo confirmed that attackers stole a Cloudflare API key and used it to inject malicious ClickFix scripts into its websites and JavaScript files embedded on customer sites to distribute malware.
Cyber resilience industriale: perché l’AI deve parlare il linguaggio della fabbrica
Negli ambienti OT la sfida non è soltanto individuare un attacco, ma comprenderne l'impatto sui processi produttivi. Il progetto Elipsis OT Resilience introduce un modello che integra dati di processo ed eventi cyber in un'unica vista, utilizzando l'AI per trasformare gli alert in priorità operative e supportare resilienza, governance e compliance
Cyber resilience nel manufacturing: perché semplificare la sicurezza è diventata una priorità
Nel manifatturiero la resilienza digitale non dipende solo dall'introduzione di nuove tecnologie, ma dalla capacità di governarle in modo integrato. Il progetto Fortinet per LAMPRE mostra come convergenza IT/OT, Zero Trust, AI e Continuous Threat Exposure Management possano ridurre la complessità operativa e rafforzare la postura di sicurezza
Hugging Face e il precedente di RubyGems: è l’ora di portare nell’AI i principi della cyber security
Per OpenAI l’attacco a RubyGems rappresenterebbe almeno il terzo caso rilevante in cui i suoi agenti hanno attaccato l’infrastruttura di un’altra azienda, dopo il caso Hugging Face. Anthropic ha contato finora quattro incidenti. Ecco cosa sappiamo del precedente di RubyGems
What Recent AI-Powered Attacks Mean for Your Identity Security
AI is making credential theft faster and easier to scale, giving attackers more opportunities to abuse valid identities. Specops explains why identity security must go beyond successful authentication by verifying that both the user and the device requesting access can be trusted.
Flashpoint Named A Customer Favorite in The Forrester Wave™
The Forrester Wave™: External Threat Intelligence Service Providers, Q3 2026 report has named Flashpoint a Customer Favorite, along with naming the organization a Strong Performer with the highest scores possible in the criteria of: Fraud Intelligence, Executive Protection, and Pricing Flexibility and Transparency.
Passkey e phishing, la nuova trappola per compromettere le identità cloud Microsoft
Le passkey resistono al phishing, ma possono anche diventare il pretesto per renderlo più credibile. Microsoft ha individuato campagne in cui falsi aggiornamenti di sicurezza portano alla compromissione delle identità cloud, consentendo agli attaccanti di ottenere persistenza e accedere alle risorse Microsoft 365