Close Menu
  • Home
  • News
  • Security
  • Privacy
  • Cybercrime
    • Threat Groups
    • Ransomware
    • Explainers
    • Stealer Logs
  • AI
  • OSINT
  • Tools
    • Ransomtracker
    • Stealercheck
    • FortiBleed Checker
  • About Us
Facebook X (Twitter) Instagram Threads

Ransomnews

  • Home
  • News
  • Security
  • Privacy
  • Cybercrime
    • Threat Groups
    • Ransomware
    • Explainers
    • Stealer Logs
  • AI
  • OSINT
  • Tools
    • Ransomtracker
    • Stealercheck
    • FortiBleed Checker
  • About Us
Facebook X (Twitter) LinkedIn
Ransomnews

Home

RANSOMNEWS // 2026

Tracking the criminal infrastructure of the internet.

Ransomware operators, breach economics, threat-actor profiles, and the open-source investigation toolkit that makes it all visible. Updated daily.

Latest stories

  • Codename Morgan: how Morocco ran Pegasus, a Forbidden Stories investigation, ransomnews.com
    Codename Morgan: inside Morocco’s Pegasus machineJuly 22, 2026
    Forbidden Stories names Morocco as NSO’s client “Morgan”: a 2017 Rabat demo, an Emirati broker, roughly 12,000 targets, and Pegasus traces on seven French ministers’ phones.
  • Inside Pegasus: how NSO Group's own court files expose the spyware system, ransomnews.com
    Inside Pegasus: NSO’s own files reveal the machineJuly 22, 2026
    Unsealed NSO Group court files, analysed by Amnesty’s Security Lab and Forbidden Stories, expose how Pegasus really works: a vendor-run spyware service, not a weapon sold and forgotten.
  • Maltego tutorial: OSINT link analysis in 2026, ransomnews.com
    Maltego tutorial: OSINT link analysis in 2026July 20, 2026
    A hands-on 2026 guide to Maltego for OSINT: entities, transforms, machines and how to build a corroborated link chart from a single selector using the free Community Edition.
  • GraphSense tutorial: open-source crypto tracing in 2026, ransomnews.com
    GraphSense tutorial: open-source crypto tracing in 2026July 20, 2026
    A hands-on 2026 guide to GraphSense, the open-source cryptoasset forensics platform: address clustering, TagPacks and how to trace ransom funds without a paid licence.
Most Popular
  1. FortiBleed: 1.16 billion attacks on FortiGate, neon investigation cover1.16 billion attacks: how the FortiBleed crew broke FortiGate
  2. Database ransom census dashboard: 62% of 514 traced wallets received zero BTC, 30,515 databases ransomed, 9.78 BTC moved ($753K), top 10 wallets captured 43% - Ransomnews Research62% of database ransom wallets were never paid
  3. Ransomware office hours: 16,699 leak posts, 200 groups, 84 percent weekday, peak hour 16:00 UTCRansomware runs office hours: what 16,699 leak posts reveal
  4. Neon poster of the Novo Nordisk charging bull logo cracked and leaking data, title Novo Nordisk Breached, 1.3 TB stolen by FulcrumSec, 25M refusedNovo Nordisk hit by FulcrumSec: the stealer logs saw it coming
  5. Ransomware encryption-less extortion shift May 2026Ransomware ditched encryption in May 2026 — here’s why
  6. Neon world map of exposed FortiGate firewalls with a cracked firewall shield leaking dataFortiBleed: exposed firewalls are a ransomware early warning
  7. Synthwave cover for the Registrų centras 2026 breach: 600,000 records exposed from two state registers, neon perspective grid, floating registry document and broken padlockRegistrų centras breach: 600,000 records exposed
  8. The Gentlemen ransomware 2026: 483 victims, infostealer-fed RaaS access pipelineThe Gentlemen ransomware: 483 victims and a leaked playbook

// FOCUS

Ransomware

The defining cybercrime of the decade. How it works, who runs it, and where the money goes.

  • Ransomware statistics 2026: confirmed attacks by month, ransomnews.com
    Ransomware statistics 2026: confirmed attacks by monthJuly 8, 2026
    Confirmed ransomware attack statistics, updated monthly: attacks per year, month, country, industry and group, from a human-verified dataset going back to 2018.
  • ESXi ransomware synthwave cover, one hypervisor one datacenter, ransomnews.com
    ESXi ransomware in 2026: one host, the whole datacenterJune 24, 2026
    ESXi ransomware encrypts every VM on a hypervisor at once. Here is why VMware ESXi became ransomware’s highest-value target in 2026, and how to defend it.
  • Central control hub with thin connection lines radiating to many small building silhouettes, dark editorial illustration
    MSPs: ransomware’s #1 target of 2026 [Field Report]May 11, 2026
    Managed service providers entered 2026 as the single highest-leverage target class in the ransomware economy. Why the channel is now the front line, which TTPs operators are running against MSPs specifically, and what the better-run shops have already changed.

// PROFILES

Threat Groups

From LockBit and Conti to Akira and Cl0p, anatomies of the operations behind the headlines.

  • Interlock: the drive-by ransomware crew CISA flagged, ransomnews.com
    Interlock: the drive-by ransomware crew CISA flaggedJuly 20, 2026
    Interlock breaks the ransomware playbook, entering through compromised websites and fake CAPTCHAs. A joint CISA-FBI advisory mapped its TTPs. Here is the profile.
  • SafePay: the centralised crew that skipped affiliates, ransomnews.com
    SafePay: the centralised crew that skipped affiliatesJuly 20, 2026
    SafePay went from unknown to one of the busiest ransomware crews in under a year by ditching affiliates and hammering RDP and VPN gateways. Here is how it works.
  • INC Ransom: the RaaS that wins by mastering the basics, ransomnews.com
    INC Ransom: the RaaS that wins by mastering the basicsJuly 20, 2026
    INC Ransom has claimed 800-plus victims since 2023 using stolen credentials, edge-device flaws and double extortion. Here is how the RaaS operates in 2026.

// DEFENCE

Security

EDR, Zero Trust, MFA, patching, IR, what actually works against modern threats.

  • wp2shell pre-authentication RCE in WordPress core, CVE-2026-63030 chained with CVE-2026-60137, patched in WordPress 7.0.2, ransomnews.com
    wp2shell: pre-auth RCE in WordPress core (CVE-2026-63030)July 18, 2026
    wp2shell chains a REST batch-route bypass and a SQL injection into pre-auth RCE on WordPress core. WordPress shipped forced auto-updates in 7.0.2, 6.9.5 and 6.8.6.
  • GodDamn ransomware blinds EDR with a Microsoft-signed driver, ransomnews.com
    GodDamn ransomware blinds EDR with a Microsoft-signed driverJuly 18, 2026
    Symantec detailed GodDamn ransomware using PoisonX, a kernel driver with a valid Microsoft signature, to terminate EDR before it encrypts.
  • macOS.Gaslight: malware that prompt-injects your SOC, ransomnews.com
    macOS.Gaslight: malware that prompt-injects your SOCJuly 16, 2026
    SentinelLABS found macOS.Gaslight, a DPRK-linked Rust backdoor that embeds 38 fake system messages to make AI malware-triage agents abort. It is the first implant built to attack the analyst’s LLM, not the sandbox.

// SURVEILLANCE

Privacy

GDPR, data brokers, encryption, fingerprinting, VPNs, the surveillance economy and its limits.

  • Codename Morgan: how Morocco ran Pegasus, a Forbidden Stories investigation, ransomnews.com
    Codename Morgan: inside Morocco’s Pegasus machineJuly 22, 2026
    Forbidden Stories names Morocco as NSO’s client “Morgan”: a 2017 Rabat demo, an Emirati broker, roughly 12,000 targets, and Pegasus traces on seven French ministers’ phones.
  • Inside Pegasus: how NSO Group's own court files expose the spyware system, ransomnews.com
    Inside Pegasus: NSO’s own files reveal the machineJuly 22, 2026
    Unsealed NSO Group court files, analysed by Amnesty’s Security Lab and Forbidden Stories, expose how Pegasus really works: a vendor-run spyware service, not a weapon sold and forgotten.
  • Session Cookie Theft and MFA Bypass 2026 — Ransomnews cover
    Stealer logs bypassing MFA in 2026 [Field Guide]May 16, 2026
    Multi-factor authentication was supposed to end the credential-theft era. In 2026, it hasn’t — because adversaries skip the credential entirely and steal the session cookie that the authentication produced. Here’s how the attack works, why MFA doesn’t stop it, and the four controls that do.

// MACHINE LEARNING

AI

Prompt injection, deepfakes, model theft, the EU AI Act, security and policy at the frontier.

  • Vibe coding is shipping vulnerabilities at scale in 2026, ransomnews.com
    Vibe coding is shipping vulnerabilities at scale in 2026July 16, 2026
    AI-generated code is fast and insecure. Veracode found 45% of samples carry OWASP Top 10 flaws, roughly a fifth of AI-suggested packages are hallucinated, and vibe-coded apps are already leaking real data.
  • Prompt injection left the lab in 2026, it is in the wild now, ransomnews.com
    Prompt injection left the lab in 2026. It is in the wild nowJuly 16, 2026
    Prompt injection stopped being a lab demo in 2026. A one-click Claude Desktop flaw, AI browsers leaking credentials, and agents tricked into crypto payments show the attack is now operational, not theoretical.
  • Shadow AI is the new stealer-log jackpot in 2026, ransomnews.com
    Shadow AI is the new stealer-log jackpot in 2026July 16, 2026
    Shadow AI is now a top insider threat: 45% of staff use AI on corporate devices, most via personal accounts. When those sessions land in stealer logs, attackers inherit the AI and everything typed into it.

// INVESTIGATIONS

OSINT

Tools, methods, and case studies from the open-source investigation discipline.

  • Maltego tutorial: OSINT link analysis in 2026, ransomnews.com
    Maltego tutorial: OSINT link analysis in 2026July 20, 2026
    A hands-on 2026 guide to Maltego for OSINT: entities, transforms, machines and how to build a corroborated link chart from a single selector using the free Community Edition.
  • GraphSense tutorial: open-source crypto tracing in 2026, ransomnews.com
    GraphSense tutorial: open-source crypto tracing in 2026July 20, 2026
    A hands-on 2026 guide to GraphSense, the open-source cryptoasset forensics platform: address clustering, TagPacks and how to trace ransom funds without a paid licence.
  • Pivoting on threat-actor handles: a 2026 OSINT method, ransomnews.com
    Pivoting on threat-actor handles: a 2026 OSINT methodJuly 20, 2026
    How to pivot from a single ransomware forum handle to a corroborated actor profile using usernames, PGP keys, emails and crypto selectors. A 2026 OSINT walkthrough.

// PRIMERS

Explainers

Long-form primers on the underlying concepts. Built to be referenced, not skimmed.

  • What is intermittent encryption? A 2026 guide, ransomnews.com
    What is intermittent encryption? A 2026 guideJuly 20, 2026
    Intermittent encryption locks only parts of each file so ransomware runs faster and hides from detection. Here is how partial encryption works and how to catch it.
  • What is RaaS? Ransomware-as-a-service explained, ransomnews.com
    What is RaaS? Ransomware-as-a-service, explainedJuly 20, 2026
    Ransomware-as-a-service splits ransomware into a rented product and an affiliate workforce. Here is how the RaaS model works and why it made attacks scale in 2026.
  • What is BYOVD? Bring your own vulnerable driver explained, ransomnews.com
    What is BYOVD? Bring your own vulnerable driver, explainedJuly 20, 2026
    BYOVD lets attackers load a legitimate but vulnerable signed driver to kill EDR from the kernel. Here is how it works and why ransomware crews rely on it in 2026.
Facebook X (Twitter) LinkedIn
© 2026 Ransomnews.com

Type above and press Enter to search. Press Esc to cancel.

Cookies on Ransomnews

We use strictly-necessary cookies to run the site and may use first-party analytics to understand which articles are read. Some pages contain affiliate links — when you click one, the affiliate network sets cookies on the merchant's domain to attribute the referral. See the Cookie Policy and Affiliate Disclosure for detail.

RANSOMNEWS.COM

Tracking the criminal infrastructure of the internet.

Independent coverage of ransomware, breach economics, threat actors, privacy, AI security, and the open-source investigation toolkit.

// Topics

  • News
  • Security
  • Privacy
  • Cybercrime
  • AI
  • OSINT
  • Threat Groups
  • Stealer Logs
  • Ransomtracker
  • Stealercheck
  • FortiBleed Checker

// Site

  • About Us
  • Editorial Team
  • Contact
  • Tip Line
  • Editorial

// Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Funding & Independence
  • RSS Feed
© 2026 Ransomnews.com · Tracking the criminal infrastructure of the internet.