Security Insights
Latest threat analysis, industry news, and security best practices from our expert team.
PLAY Ransomware Campaign: US & Spain Hospitality/Retail Hit — Detection Rules for ScreenConnect & Check Point Exploits
Threat Actor Profile — PLAY Aliases: Play, Crypt (historical association) Operational Model: PLAY operates as a closed-group Ransomware-as-a...
AKIRA Ransomware: Critical VPN & RMM Exploitation Alert — 4 New Victims
AKIRA Ransomware: Critical VPN & RMM Exploitation Alert — 4 New Victims Threat Actor Profile — AKIRA Aliases: None confirmed (acts primarily...
NOVA Ransomware: Global Tech Sector Surge & Critical Infrastructure Exploitation
Threat Actor Profile: NOVA Aliases & Affiliations: NOVA operates as a Ransomware-as-a-Service (RaaS) entity with ties to former affiliates o...
KRYBIT Ransomware Gang: 4 New Victims Posted — Sector Targeting Analysis & Detection Rules
KRYBIT Ransomware Gang: 4 New Victims Posted — Sector Targeting Analysis & Detection Rules Intelligence Briefing Date: 2026-07-23 Source: Se...
THEGENTLEMEN Ransomware Gang: Critical Infrastructure Targeted — Active Exploitation of Check Point & Cisco Vulnerabilities
Threat Actor Profile — THEGENTLEMEN Aliases: GentleCrew, TheGentlemanClub (unconfirmed) RaaS Model: Emerging RaaS operation with strict vett...
SPACEBEARS Ransomware: Global Surge in Tech & Business Services — CVE-Driven Attacks & Detection Engineering
SPACEBEARS Ransomware Gang: 3 New Victims Posted — Sector Targeting Analysis & Detection Rules Threat Actor Profile — SPACEBEARS SPACEBEARS ...
DRAGONFORCE Gang: 4 Victims Across Telecom & Finance — KEV-Driven Attacks & Detection Rules
Threat Actor Profile — DRAGONFORCE Aliases & Model: DRAGONFORCE operates as a closed-group operation, occasionally selling affiliate access ...
SAFEPAY Ransomware: German Manufacturing & Services Sector Targeted — Detection Rules for Active Exploits
Threat Actor Profile — SAFEPAY Aliases & Structure: SAFEPAY is a ransomware-as-a-service (RaaS) operation that surfaced in mid-2025. The gro...
BLACKOUT Ransomware: Global Tech Sector Assault & Critical Infrastructure CVEs
Executive Summary Security Arsenal is tracking a resurgence in activity from the BLACKOUT ransomware operation. As of July 19, 2026, the gro...