CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Risky Bulletin: Two law firms pay giant ransoms

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 6091

As cited

Copy frozen at (site build).

Risky Bulletin: Two law firms pay giant ransoms

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

ransomware

Risky Bulletin: Two law firms pay giant ransoms

Two U.S. law firms paid multi-million dollar ransoms following attacks. A zero-day vulnerability in Metabase is actively exploited in data theft campaigns, and Russian-linked attackers disrupted a second power generation facility in Poland. A remote code execution (RCE) vulnerability was discovered in WordPress.

Why it matters: Law firms and their clients face escalating ransom demands and operational disruption; organizations running Metabase must patch or isolate the affected system immediately; power utilities and critical infrastructure operators need to assess exposure to Russian threat actors; WordPress site administrators must apply security updates to prevent RCE attacks.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

ransomware

Risky Bulletin: Two law firms pay giant ransoms

Two U.S. law firms paid multi-million dollar ransoms following attacks. A zero-day vulnerability in Metabase is actively exploited in data theft campaigns, and Russian-linked attackers disrupted a second power generation facility in Poland. A remote code execution (RCE) vulnerability was discovered in WordPress.

Why it matters: Law firms and their clients face escalating ransom demands and operational disruption; organizations running Metabase must patch or isolate the affected system immediately; power utilities and critical infrastructure operators need to assess exposure to Russian threat actors; WordPress site administrators must apply security updates to prevent RCE attacks.

VendorsWordPress
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary