Close Menu
  • Home
  • News
  • Security
  • Privacy
  • Cybercrime
    • Threat Groups
    • Ransomware
    • Explainers
    • Stealer Logs
  • AI
  • OSINT
  • Tools
    • Ransomtracker
    • Stealercheck
    • FortiBleed Checker
  • About Us
Facebook X (Twitter) Instagram Threads

Ransomnews

  • Home
  • News
  • Security
  • Privacy
  • Cybercrime
    • Threat Groups
    • Ransomware
    • Explainers
    • Stealer Logs
  • AI
  • OSINT
  • Tools
    • Ransomtracker
    • Stealercheck
    • FortiBleed Checker
  • About Us
Facebook X (Twitter) LinkedIn
Ransomnews

Home

RANSOMNEWS // 2026

Tracking the criminal infrastructure of the internet.

Ransomware operators, breach economics, threat-actor profiles, and the open-source investigation toolkit that makes it all visible. Updated daily.

Latest stories

  • The Gentlemen weaponised a Kontron driver to kill EDR, ransomnews.com
    The Gentlemen weaponised a Kontron driver to kill EDRJuly 10, 2026
    The Gentlemen ransomware weaponised a zero-day in Kontron’s ktapi.sys driver to gain kernel access and kill EDR from Microsoft, ESET, Palo Alto, and SentinelOne, researchers found.
  • Anubis ransomware is exploiting Citrix Bleed 2 for access, ransomnews.com
    Anubis ransomware is exploiting Citrix Bleed 2 for accessJuly 10, 2026
    Arctic Wolf says Anubis ransomware affiliates are exploiting Citrix Bleed 2 (CVE-2025-5777) and abusing legitimate RMM tools to breach networks, then deploying an irreversible data wiper.
  • Kairos took $1M from a US government body and encrypted nothing, ransomnews.com
    Kairos took $1M from a US government body and encrypted nothingJuly 10, 2026
    A US government entity paid Kairos about $1 million to keep stolen files offline, a Ransom-ISAC case study shows. Kairos never encrypted a machine, it just threatened to publish.
  • JadePuffer: the first AI agent to run a ransomware attack, ransomnews.com
    JadePuffer: the first AI agent to run a ransomware attackJuly 10, 2026
    Sysdig documented JADEPUFFER, the first ransomware operation run end to end by an AI agent: it breached a server, moved laterally, and encrypted a database with no human at the keyboard.
Most Popular
  1. FortiBleed: 1.16 billion attacks on FortiGate, neon investigation cover1.16 billion attacks: how the FortiBleed crew broke FortiGate
  2. Database ransom census dashboard: 62% of 514 traced wallets received zero BTC, 30,515 databases ransomed, 9.78 BTC moved ($753K), top 10 wallets captured 43% - Ransomnews Research62% of database ransom wallets were never paid
  3. Ransomware office hours: 16,699 leak posts, 200 groups, 84 percent weekday, peak hour 16:00 UTCRansomware runs office hours: what 16,699 leak posts reveal
  4. Neon poster of the Novo Nordisk charging bull logo cracked and leaking data, title Novo Nordisk Breached, 1.3 TB stolen by FulcrumSec, 25M refusedNovo Nordisk hit by FulcrumSec: the stealer logs saw it coming
  5. Ransomware encryption-less extortion shift May 2026Ransomware ditched encryption in May 2026 — here’s why
  6. Neon world map of exposed FortiGate firewalls with a cracked firewall shield leaking dataFortiBleed: exposed firewalls are a ransomware early warning
  7. Synthwave cover for the Registrų centras 2026 breach: 600,000 records exposed from two state registers, neon perspective grid, floating registry document and broken padlockRegistrų centras breach: 600,000 records exposed
  8. Leak Site OSINT Walkthrough 2026 — Ransomnews coverRansomware leak-site OSINT: 2026 investigation walkthrough

// FOCUS

Ransomware

The defining cybercrime of the decade. How it works, who runs it, and where the money goes.

  • Ransomware statistics 2026: confirmed attacks by month, ransomnews.com
    Ransomware statistics 2026: confirmed attacks by monthJuly 8, 2026
    Confirmed ransomware attack statistics, updated monthly: attacks per year, month, country, industry and group, from a human-verified dataset going back to 2018.
  • ESXi ransomware synthwave cover, one hypervisor one datacenter, ransomnews.com
    ESXi ransomware in 2026: one host, the whole datacenterJune 24, 2026
    ESXi ransomware encrypts every VM on a hypervisor at once. Here is why VMware ESXi became ransomware’s highest-value target in 2026, and how to defend it.
  • Central control hub with thin connection lines radiating to many small building silhouettes, dark editorial illustration
    MSPs: ransomware’s #1 target of 2026 [Field Report]May 11, 2026
    Managed service providers entered 2026 as the single highest-leverage target class in the ransomware economy. Why the channel is now the front line, which TTPs operators are running against MSPs specifically, and what the better-run shops have already changed.

// PROFILES

Threat Groups

From LockBit and Conti to Akira and Cl0p, anatomies of the operations behind the headlines.

  • Fragmented padlock with shadow figures dispersing in different directions, dark editorial illustration
    LockBit, 2 years after Operation Cronos: where are they now?May 11, 2026
    A 2026 retrospective on the international takedown that displaced LockBit at the top of the ransomware ecosystem — what stuck, what reverted, where the affiliate workforce migrated, and what the next coordinated action should learn from the playbook.
  • Intersecting magnifying glasses over a stylised fingerprint pattern, dark editorial illustration
    Ransomware attribution 2026: TTPs, notes, fingerprintsMay 10, 2026
    A 2026 attribution playbook for ransomware investigations — combining TTP fingerprinting against MITRE ATT&CK, ransom-note artifact analysis, leak-site monitoring, and the open-source intelligence pivots that hold up under scrutiny.
  • Concentric defensive rings around a glowing core with server-rack outlines, dark editorial illustration
    Active Directory hardening 2026: Tier 0, DSRM, PRT theftMay 10, 2026
    A 2026 practitioner walkthrough of Active Directory hardening against the lateral-movement, credential-theft, and persistence techniques that modern ransomware operators rely on — Tier 0 isolation, DSRM rotation, PRT theft mitigation, and AD audit baselines.

// DEFENCE

Security

EDR, Zero Trust, MFA, patching, IR, what actually works against modern threats.

  • The Gentlemen weaponised a Kontron driver to kill EDR, ransomnews.com
    The Gentlemen weaponised a Kontron driver to kill EDRJuly 10, 2026
    The Gentlemen ransomware weaponised a zero-day in Kontron’s ktapi.sys driver to gain kernel access and kill EDR from Microsoft, ESET, Palo Alto, and SentinelOne, researchers found.
  • Neon poster of a cracked bleeding network firewall leaking passwords, title FortiBleed 75,000 firewalls, cracked admin passwords across 194 countries
    FortiBleed: 75,000 cracked Fortinet firewalls, no zero-day neededJune 18, 2026
    FortiBleed exposed cracked admin passwords for around 75,000 Fortinet firewalls across 194 countries, roughly half the internet-facing fleet. There is no new zero-day. It is config exports, weak hashing, and recycled credentials, packaged as a sales catalog.
  • Synthwave cover for the Registrų centras 2026 breach: 600,000 records exposed from two state registers, neon perspective grid, floating registry document and broken padlock
    Registrų centras breach: 600,000 records exposedMay 27, 2026
    Lithuania’s Centre of Registers (Registrų centras) disclosed a May 2026 breach exposing roughly 600,000 records. Attackers reused credentials of authorised institutions, queried from abroad. Alerts.bar data shows 117 stealer-log accounts tied to the agency and 60+ live infected staff endpoints across the wider Lithuanian institutional ecosystem.

// SURVEILLANCE

Privacy

GDPR, data brokers, encryption, fingerprinting, VPNs, the surveillance economy and its limits.

  • Session Cookie Theft and MFA Bypass 2026 — Ransomnews cover
    Stealer logs bypassing MFA in 2026 [Field Guide]May 16, 2026
    Multi-factor authentication was supposed to end the credential-theft era. In 2026, it hasn’t — because adversaries skip the credential entirely and steal the session cookie that the authentication produced. Here’s how the attack works, why MFA doesn’t stop it, and the four controls that do.
  • Stylised official document and glowing countdown timer, dark editorial illustration
    SEC 4-day cyber rule: 2.5 years in, what CISOs learnedMay 11, 2026
    A 2026 retrospective on Item 1.05 of Form 8-K — the SEC’s four-day cyber-incident disclosure rule. How filings have actually played out, what the enforcement signals look like, and the practical playbook the better-prepared CISOs now run.
  • Mirror reflecting a fragmented digital silhouette of circuit segments, dark editorial illustration
    Audit your digital footprint 2026: Sherlock, Holehe, WhoxyMay 10, 2026
    A 2026 self-doxxing tutorial — run the same OSINT tools attackers use, on yourself, to find every account, leaked credential, and broker entry tied to your identity. With remediation steps for each finding.

// MACHINE LEARNING

AI

Prompt injection, deepfakes, model theft, the EU AI Act, security and policy at the frontier.

  • JadePuffer: the first AI agent to run a ransomware attack, ransomnews.com
    JadePuffer: the first AI agent to run a ransomware attackJuly 10, 2026
    Sysdig documented JADEPUFFER, the first ransomware operation run end to end by an AI agent: it breached a server, moved laterally, and encrypted a database with no human at the keyboard.
  • Agentic AI threats: how MCP becomes an attack chain, ransomnews.com
    Agentic AI threats: how MCP becomes an attack chainJune 29, 2026
    Agentic AI moves the threat from what a model says to what it does. We map how MCP turns goal hijacking, tool misuse, and privilege abuse into a working attack chain, and the controls that contain it.
  • MCP security in 2026: the attack surface mapped, ransomnews.com
    MCP security in 2026: the attack surface mappedJune 28, 2026
    A technical map of the Model Context Protocol attack surface in 2026: tool poisoning, line jumping, rug pulls, tool-chaining exfiltration, token sprawl, and the RCE flaws that turned MCP servers into entry points.

// INVESTIGATIONS

OSINT

Tools, methods, and case studies from the open-source investigation discipline.

  • Hunting C2 infrastructure synthwave cover, favicon JARM cert logs, ransomnews.com
    Hunting C2 infrastructure: favicon, JARM, cert logsJune 24, 2026
    A 2026 OSINT methodology for pivoting from one malicious IP to a whole adversary cluster using favicon hashes, JARM fingerprints, and certificate transparency.
  • Leak Site OSINT Walkthrough 2026 — Ransomnews cover
    Ransomware leak-site OSINT: 2026 investigation walkthroughMay 16, 2026
    A practical OSINT walkthrough for investigating ransomware leak sites — workflow, sources, pitfalls, and how to verify victim claims without breaking operational security.
  • Mirror reflecting a fragmented digital silhouette of circuit segments, dark editorial illustration
    Audit your digital footprint 2026: Sherlock, Holehe, WhoxyMay 10, 2026
    A 2026 self-doxxing tutorial — run the same OSINT tools attackers use, on yourself, to find every account, leaked credential, and broker entry tied to your identity. With remediation steps for each finding.

// PRIMERS

Explainers

Long-form primers on the underlying concepts. Built to be referenced, not skimmed.

  • Stylised padlock split in two with abstract data streams spilling out, dark editorial illustration
    What is double extortion ransomware? An explainer for non-technical executives in 2026May 10, 2026
    An executive-level explainer of double extortion — the dominant ransomware playbook in 2026 — covering how it works, why backups don’t fully defeat it, and the policy choices boards now have to make in the first hour of an incident.
  • A five-stage workflow pipeline with glowing connected nodes representing intake, collection, verification, analysis, and report
    Building an OSINT investigation workflow: from intake to reportApril 30, 2026
    The five-stage workflow that separates an OSINT analyst from someone with a bookmarks bar full of tools.
  • A photograph overlaid on a grid map with triangulation lines connecting visual landmarks to coordinates
    Geolocating a photo from scratch: the Bellingcat workflow for normal humansApril 30, 2026
    A practitioner walkthrough of the photo-geolocation method used by Bellingcat and most newsroom verification teams. Worked example included.
Facebook X (Twitter) LinkedIn
© 2026 Ransomnews.com

Type above and press Enter to search. Press Esc to cancel.

Cookies on Ransomnews

We use strictly-necessary cookies to run the site and may use first-party analytics to understand which articles are read. Some pages contain affiliate links — when you click one, the affiliate network sets cookies on the merchant's domain to attribute the referral. See the Cookie Policy and Affiliate Disclosure for detail.

RANSOMNEWS.COM

Tracking the criminal infrastructure of the internet.

Independent coverage of ransomware, breach economics, threat actors, privacy, AI security, and the open-source investigation toolkit.

// Topics

  • News
  • Security
  • Privacy
  • Cybercrime
  • AI
  • OSINT
  • Threat Groups
  • Stealer Logs
  • Ransomtracker
  • Stealercheck
  • FortiBleed Checker

// Site

  • About Us
  • Editorial Team
  • Contact
  • Tip Line
  • Editorial

// Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Funding & Independence
  • RSS Feed
© 2026 Ransomnews.com · Tracking the criminal infrastructure of the internet.