Close Menu
  • Home
  • News
  • Security
  • Privacy
  • Cybercrime
    • Threat Groups
    • Ransomware
    • Explainers
    • Stealer Logs
  • AI
  • OSINT
  • Tools
    • Ransomtracker
    • Stealercheck
    • FortiBleed Checker
  • About Us
Facebook X (Twitter) Instagram Threads

Ransomnews

  • Home
  • News
  • Security
  • Privacy
  • Cybercrime
    • Threat Groups
    • Ransomware
    • Explainers
    • Stealer Logs
  • AI
  • OSINT
  • Tools
    • Ransomtracker
    • Stealercheck
    • FortiBleed Checker
  • About Us
Facebook X (Twitter) LinkedIn
Ransomnews

Home

Tracking the criminal infrastructure of the internet.

Ransomware operators, breach economics, threat-actor profiles, and the open-source investigation toolkit that makes it all visible. Updated daily.

Latest stories

  • Ransomnews cover: the persona chain Quake3, morgot, Rcode leading to REvil source-code development, named by the BKA in April 2026
    Quake3 and morgot: tracing REvil’s source-code developerAugust 10, 2026
    Quake3, a moderator on the XSS.is cybercrime forum, is the persona DEF CON 33 research placed at REvil’s source-code development, and the man the German BKA named in April 2026. We trace the forum record that ties the handles together.
  • Ransomnews cover: Swyft vending data marketed as a live 2026 breach, but every record in the sample dates from 2016
    Pokémon Center vending ‘breach’ is old 2016 dataAugust 10, 2026
    A seller is marketing a ‘live’ breach of automated-retail vendor SwyftStore across 28 brands including Pokémon Center. The sample is genuine Zoom/Swyft data, but every record dates from 2016.
  • Ransomnews cover: Israel population registry, 9.2 million records offered for sale, every date in the sample frozen at 2005
    Israeli population registry for sale, but the data is oldAugust 10, 2026
    A vendor is selling what they call Israel’s current 9.22M-record population registry. Our analysis of the 100k sample says the data is genuine, but every date in it stops in 2005.
  • Best VirusTotal alternatives 2026 for threat hunters, ransomnews.com
    Best VirusTotal alternatives 2026: what threat hunters runAugust 9, 2026
    The VirusTotal alternatives threat hunters run in 2026: MetaDefender, ANY.RUN, CAPE, Intezer and MalwareBazaar, compared by job, upload privacy and API.
Most Popular
  1. FortiBleed: 1.16 billion attacks on FortiGate, neon investigation cover1.16 billion attacks: how the FortiBleed crew broke FortiGate
  2. Database ransom census dashboard: 62% of 514 traced wallets received zero BTC, 30,515 databases ransomed, 9.78 BTC moved ($753K), top 10 wallets captured 43% - Ransomnews Research62% of database ransom wallets were never paid
  3. Ransomware office hours: 16,699 leak posts, 200 groups, 84 percent weekday, peak hour 16:00 UTCRansomware runs office hours: what 16,699 leak posts reveal
  4. Ransomnews cover: Żabka data up for sale, a leak forum listing offering 541,000 Jira tickets and 89 Git repositories for 5,000 euroŻabka confirms breach via supplier account, data for sale
  5. Neon poster of the Novo Nordisk charging bull logo cracked and leaking data, title Novo Nordisk Breached, 1.3 TB stolen by FulcrumSec, 25M refusedNovo Nordisk hit by FulcrumSec: the stealer logs saw it coming
  6. Ransomware encryption-less extortion shift May 2026Ransomware ditched encryption in May 2026 — here’s why
  7. Neon world map of exposed FortiGate firewalls with a cracked firewall shield leaking dataFortiBleed: exposed firewalls are a ransomware early warning
  8. Synthwave cover for the Registrų centras 2026 breach: 600,000 records exposed from two state registers, neon perspective grid, floating registry document and broken padlockRegistrų centras breach: 600,000 records exposed

// FOCUS

Ransomware

The defining cybercrime of the decade. How it works, who runs it, and where the money goes.

  • Ransomware statistics 2026: confirmed attacks by month, ransomnews.com
    Ransomware statistics 2026: confirmed attacks by monthJuly 8, 2026
    Confirmed ransomware attack statistics, updated monthly: attacks per year, month, country, industry and group, from a human-verified dataset going back to 2018.
  • ESXi ransomware synthwave cover, one hypervisor one datacenter, ransomnews.com
    ESXi ransomware in 2026: one host, the whole datacenterJune 24, 2026
    ESXi ransomware encrypts every VM on a hypervisor at once. Here is why VMware ESXi became ransomware’s highest-value target in 2026, and how to defend it.
  • Central control hub with thin connection lines radiating to many small building silhouettes, dark editorial illustration
    MSPs: ransomware’s #1 target of 2026 [Field Report]May 11, 2026
    Managed service providers entered 2026 as the single highest-leverage target class in the ransomware economy. Why the channel is now the front line, which TTPs operators are running against MSPs specifically, and what the better-run shops have already changed.

// PROFILES

Threat Groups

From LockBit and Conti to Akira and Cl0p, anatomies of the operations behind the headlines.

  • Interlock: the drive-by ransomware crew CISA flagged, ransomnews.com
    Interlock: the drive-by ransomware crew CISA flaggedJuly 20, 2026
    Interlock breaks the ransomware playbook, entering through compromised websites and fake CAPTCHAs. A joint CISA-FBI advisory mapped its TTPs. Here is the profile.
  • SafePay: the centralised crew that skipped affiliates, ransomnews.com
    SafePay: the centralised crew that skipped affiliatesJuly 20, 2026
    SafePay went from unknown to one of the busiest ransomware crews in under a year by ditching affiliates and hammering RDP and VPN gateways. Here is how it works.
  • INC Ransom: the RaaS that wins by mastering the basics, ransomnews.com
    INC Ransom: the RaaS that wins by mastering the basicsJuly 20, 2026
    INC Ransom has claimed 800-plus victims since 2023 using stolen credentials, edge-device flaws and double extortion. Here is how the RaaS operates in 2026.

// DEFENCE

Security

EDR, Zero Trust, MFA, patching, IR, what actually works against modern threats.

  • Best VirusTotal alternatives 2026 for threat hunters, ransomnews.com
    Best VirusTotal alternatives 2026: what threat hunters runAugust 9, 2026
    The VirusTotal alternatives threat hunters run in 2026: MetaDefender, ANY.RUN, CAPE, Intezer and MalwareBazaar, compared by job, upload privacy and API.
  • SOAR vs SIEM 2026: SIEM decides what is happening, SOAR decides what to do about it
    SOAR vs SIEM 2026: tune before you automateAugust 6, 2026
    SOAR vs SIEM in 2026: they were never alternatives. Gartner marked standalone SOAR obsolete, and the automation now ships inside your SIEM or XDR.
  • SIEM vs XDR 2026: which platform wins on detection speed, retention, audit reporting and custom analytics
    SIEM vs XDR 2026: retention is the deciding factorAugust 6, 2026
    SIEM vs XDR in 2026: XDR wins on detection speed, SIEM wins on retention and audit. Which one you can drop comes down to your compliance obligations.

// SURVEILLANCE

Privacy

GDPR, data brokers, encryption, fingerprinting, VPNs, the surveillance economy and its limits.

  • Codename Morgan: how Morocco ran Pegasus, a Forbidden Stories investigation, ransomnews.com
    Codename Morgan: inside Morocco’s Pegasus machineJuly 22, 2026
    Forbidden Stories names Morocco as NSO’s client “Morgan”: a 2017 Rabat demo, an Emirati broker, roughly 12,000 targets, and Pegasus traces on seven French ministers’ phones.
  • Inside Pegasus: how NSO Group's own court files expose the spyware system, ransomnews.com
    Inside Pegasus: NSO’s own files reveal the machineJuly 22, 2026
    Unsealed NSO Group court files, analysed by Amnesty’s Security Lab and Forbidden Stories, expose how Pegasus really works: a vendor-run spyware service, not a weapon sold and forgotten.
  • Session Cookie Theft and MFA Bypass 2026 — Ransomnews cover
    Stealer logs bypassing MFA in 2026 [Field Guide]May 16, 2026
    Multi-factor authentication was supposed to end the credential-theft era. In 2026, it hasn’t — because adversaries skip the credential entirely and steal the session cookie that the authentication produced. Here’s how the attack works, why MFA doesn’t stop it, and the four controls that do.

// MACHINE LEARNING

AI

Prompt injection, deepfakes, model theft, the EU AI Act, security and policy at the frontier.

  • Vibe coding is shipping vulnerabilities at scale in 2026, ransomnews.com
    Vibe coding is shipping vulnerabilities at scale in 2026July 16, 2026
    AI-generated code is fast and insecure. Veracode found 45% of samples carry OWASP Top 10 flaws, roughly a fifth of AI-suggested packages are hallucinated, and vibe-coded apps are already leaking real data.
  • Prompt injection left the lab in 2026, it is in the wild now, ransomnews.com
    Prompt injection left the lab in 2026. It is in the wild nowJuly 16, 2026
    Prompt injection stopped being a lab demo in 2026. A one-click Claude Desktop flaw, AI browsers leaking credentials, and agents tricked into crypto payments show the attack is now operational, not theoretical.
  • Shadow AI is the new stealer-log jackpot in 2026, ransomnews.com
    Shadow AI is the new stealer-log jackpot in 2026July 16, 2026
    Shadow AI is now a top insider threat: 45% of staff use AI on corporate devices, most via personal accounts. When those sessions land in stealer logs, attackers inherit the AI and everything typed into it.

// INVESTIGATIONS

OSINT

Tools, methods, and case studies from the open-source investigation discipline.

  • Best OSINT tools 2026: Maltego, Shodan, SecurityTrails, VirusTotal, theHarvester, DarkOwl, BGPView, Wayback Machine
    Best OSINT tools 2026: what analysts actually runAugust 4, 2026
    The OSINT tools worth your time in 2026: Maltego, Shodan, SecurityTrails, DarkOwl, theHarvester and more, ranked by what they do and what they leak.
  • Maltego tutorial: OSINT link analysis in 2026, ransomnews.com
    Maltego tutorial: OSINT link analysis in 2026July 20, 2026
    A hands-on 2026 guide to Maltego for OSINT: entities, transforms, machines and how to build a corroborated link chart from a single selector using the free Community Edition.
  • GraphSense tutorial: open-source crypto tracing in 2026, ransomnews.com
    GraphSense tutorial: open-source crypto tracing in 2026July 20, 2026
    A hands-on 2026 guide to GraphSense, the open-source cryptoasset forensics platform: address clustering, TagPacks and how to trace ransom funds without a paid licence.

// PRIMERS

Explainers

Long-form primers on the underlying concepts. Built to be referenced, not skimmed.

  • What is intermittent encryption? A 2026 guide, ransomnews.com
    What is intermittent encryption? A 2026 guideJuly 20, 2026
    Intermittent encryption locks only parts of each file so ransomware runs faster and hides from detection. Here is how partial encryption works and how to catch it.
  • What is RaaS? Ransomware-as-a-service explained, ransomnews.com
    What is RaaS? Ransomware-as-a-service, explainedJuly 20, 2026
    Ransomware-as-a-service splits ransomware into a rented product and an affiliate workforce. Here is how the RaaS model works and why it made attacks scale in 2026.
  • What is BYOVD? Bring your own vulnerable driver explained, ransomnews.com
    What is BYOVD? Bring your own vulnerable driver, explainedJuly 20, 2026
    BYOVD lets attackers load a legitimate but vulnerable signed driver to kill EDR from the kernel. Here is how it works and why ransomware crews rely on it in 2026.
Facebook X (Twitter) LinkedIn
© 2026 Ransomnews.com

Type above and press Enter to search. Press Esc to cancel.

Cookies on Ransomnews

We use strictly-necessary cookies to run the site and may use first-party analytics to understand which articles are read. Some pages contain affiliate links — when you click one, the affiliate network sets cookies on the merchant's domain to attribute the referral. See the Cookie Policy and Affiliate Disclosure for detail.

RANSOMNEWS.COM

Tracking the criminal infrastructure of the internet.

Independent coverage of ransomware, breach economics, threat actors, privacy, AI security, and the open-source investigation toolkit.

// Topics

  • News
  • Security
  • Privacy
  • Cybercrime
  • AI
  • OSINT
  • Threat Groups
  • Stealer Logs
  • Ransomtracker
  • Stealercheck
  • FortiBleed Checker

// Site

  • About Us
  • Editorial Team
  • Contact
  • Tip Line
  • Editorial

// Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Funding & Independence
  • RSS Feed
© 2026 Ransomnews.com · Tracking the criminal infrastructure of the internet.