Advantest, a major semiconductor chip-testing company, was reported as being hit by ransomware, indicating a disruptive cyber incident affecting a critical supplier in the semiconductor manufacturing ecosystem. Public reporting did not provide detailed technical indicators, the initial access vector, or the scope of impacted systems, but the incident aligns with ongoing ransomware targeting of large enterprises and operationally critical technology providers.
Separate reporting during the same period emphasized that ransomware operators and initial access brokers frequently gain entry via network edge devices, particularly firewalls exploited through known vulnerabilities or compromised accounts, and that legacy exposures can remain in active use for years. This broader trend context is consistent with ransomware tradecraft but is not specific attribution or confirmation of the intrusion method used against Advantest.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
SC Media, citing a TechRadar summary of Barracuda’s Managed XDR Global Threat Report, reported the findings that firewalls were exploited in 90% of ransomware incidents and referenced examples involving SonicWall appliances and Akira ransomware. This marks the public reporting of the report’s conclusions.
Barracuda's report identified CVE-2013-2566 as the most prevalent vulnerability observed in its 2025 data, indicating attackers continued exploiting long-known flaws in legacy systems. The report also said 1 in 10 detected vulnerabilities already had an exploit available.
During 2025, Barracuda says it analyzed more than two trillion IT events and 600,000 security alerts for its Managed XDR Global Threat Report. The analysis found that 90% of ransomware incidents in 2025 began with compromised firewall instances, often through known vulnerabilities or compromised accounts.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.