ATF Confirms Cyber Incident After Ransomware Group Claims Attack
The Bureau of Alcohol, Tobacco, Firearms and Explosives has confirmed a cyber incident classified as major, with the Department of Justice assisting in the ongoing investigation. A ransomware group has claimed responsibility for the attack against the federal agency.
Aurora ransomware operators are leveraging SpaceX's Cursor Agent AI tool to automate reconnaissance and exploitation tasks as part of their ransomware campaigns. This represents a notable shift in adversary tradecraft, with threat actors weaponizing legitimate AI development tools to enhance their operational capabilities.
Protect your Australia- and New Zealand-based retail business from cyber threats. Learn five key decisions to secure identities, manage dependencies and ensure trading continuity against ransomware
Boston Scientific disclosed a cyberattack detected Tuesday that disrupted its global order processing and shipping systems, with the medical device manufacturer unable to restore full service timelines as of the disclosure. The incident affected IT systems and business applications across the major producer of cardiac and neuromodulation devices, prompting the company to activate incident response protocols and engage external cybersecurity specialists, though Boston Scientific has not disclosed whether ransomware, data exfiltration, or patient impact occurred. The attack represents the third significant disruption to a major medical technology firm in six months and carries potential regulatory implications for the European Union given the company's Irish operations and applicability of GDPR and NIS2 Directive requirements.
Modern ransomware attacks are orchestrated through a specialized supply chain comprising five distinct business functions: harvesters operating infostealer malware, brokers verifying and reselling access, ransomware-as-a-service operators providing toolkits, affiliates executing intrusions, and launderers handling proceeds. This structured ecosystem has replaced the outdated model of lone attackers, with each stage commanding specific costs within the cybercrime marketplace. Understanding this supply chain is critical for security professionals developing comprehensive defense strategies against organized ransomware operations.