Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Atlanta's $17M Ransomware Attack: What Could Have Stopped It

In March 2018, the SamSam ransomware attack on the city of Atlanta became one of the most expensive ransomware incidents ever to hit a US local government. It remains a useful case study in what happens when an organization has no way to detect, stop or recover from ransomware in real time.

SparkKitty Malware: An Emerging Threat to Mobile Users

SparkKitty is a newly uncovered cross-platform information stealer, designed to exfiltrate sensitive data—particularly cryptocurrency wallet seed phrases—by leveraging advanced optical character recognition (OCR) techniques on both Android and iOS devices. The malware, discovered by Kaspersky in early 2024 and publicly detailed in June 2025, appears to be a direct evolution of a previous stealer known as SparkCat.

Why Flipping Cyber Defense Backwards Works

Standard incident response is failing to keep pace with long-term threat campaigns. Adam Karcher from the FBI explains why the most effective security teams run their operations as an inverted offensive strategy, leveraging continuous adversary emulation to stop intrusions before they begin. Watch the full video on our channel.

From Inbox to Encryption: How Ransomware Delivery Has Evolved

Ransomware and phishing have always been linked, but the old model was blunt: a phishing email carried the payload, the recipient opened it, encryption followed within hours. What the threat looks like in 2026 is fundamentally different. The email that starts the chain carries nothing dangerous. Instead, the ransomware arrives weeks later, launched by a completely different attacker. So, what can organizations do to protect themselves from these new threats?

The Perfect Heist: NuGet Typosquat Targets Betting Platform to Rig Results

The JFrog Security Research team has discovered and disclosed a typosquatted NuGet package named Newtonsoftt.Json.Net. Note the double t and the.Net suffix. This package has been masquerading as the popular Newtonsoft.Json library while quietly shipping a trojanized fork. The trojan rigs Digitain, an online betting platform, and in later generations, exfiltrates rigged round results to an attacker-controlled server, utilizing the header X-Seq-ApiKey: theperfectheist2025.

Cookie Crumbles: How Exploitation of CVE-2026-0257 Leads to Qilin Ransomware

During June 2026, Arctic Wolf Labs investigated multiple intrusions during which threat actors exploited CVE-2026-0257 as a consistent initial access vector, rapidly transitioning from perimeter compromise to domain-wide Qilin ransomware encryption across distinct victim environments.

WannaCry Ransomware: Infection, Impact, and Prevention

WannaCry, also known as WannaCrypt, is a notorious ransomware strain that gained global attention in May 2017 due to its widespread and damaging impact. It belongs to the category of malware known as ransomware, which encrypts a victim’s files and demands a ransom payment, usually in cryptocurrency, in exchange for a decryption key that can unlock the files.

Building a More Secure Workplace Technology Environment

One weak password. One rushed click. One laptop left in a rideshare. That's all it can take to create a very real problem for your business. Strong workplace technology security is no longer just about locking down computers. It protects payroll, customer records, employee privacy, contracts, financial data, and the trust you've worked hard to earn.

How Aikido Intel detects malware and vulnerabilities first

TL;DR: Aikido Intel is a real-time supply chain intelligence feed. It detects both malware and vulnerabilities in open-source ecosystems. Aikido's world-class researchers maintain our LLM-powered pipeline to find malware and validate the most malicious cases by hand. The vulnerability detection system monitors package changes across ecosystems to catch and document vulnerabilities that don’t have CVEs assigned.