Tracking the criminal infrastructure of the internet.
Ransomware operators, breach economics, threat-actor profiles, and the open-source investigation toolkit that makes it all visible. Updated daily.
Latest stories
- Quake3 and morgot: tracing REvil’s source-code developerQuake3, a moderator on the XSS.is cybercrime forum, is the persona DEF CON 33 research placed at REvil’s source-code development, and the man the German BKA named in April 2026. We trace the forum record that ties the handles together.
- Pokémon Center vending ‘breach’ is old 2016 dataA seller is marketing a ‘live’ breach of automated-retail vendor SwyftStore across 28 brands including Pokémon Center. The sample is genuine Zoom/Swyft data, but every record dates from 2016.
- Israeli population registry for sale, but the data is oldA vendor is selling what they call Israel’s current 9.22M-record population registry. Our analysis of the 100k sample says the data is genuine, but every date in it stops in 2005.
- Best VirusTotal alternatives 2026: what threat hunters runThe VirusTotal alternatives threat hunters run in 2026: MetaDefender, ANY.RUN, CAPE, Intezer and MalwareBazaar, compared by job, upload privacy and API.
// FOCUS
Ransomware
The defining cybercrime of the decade. How it works, who runs it, and where the money goes.
- Ransomware statistics 2026: confirmed attacks by monthConfirmed ransomware attack statistics, updated monthly: attacks per year, month, country, industry and group, from a human-verified dataset going back to 2018.
- ESXi ransomware in 2026: one host, the whole datacenterESXi ransomware encrypts every VM on a hypervisor at once. Here is why VMware ESXi became ransomware’s highest-value target in 2026, and how to defend it.
- MSPs: ransomware’s #1 target of 2026 [Field Report]Managed service providers entered 2026 as the single highest-leverage target class in the ransomware economy. Why the channel is now the front line, which TTPs operators are running against MSPs specifically, and what the better-run shops have already changed.
// PROFILES
Threat Groups
From LockBit and Conti to Akira and Cl0p, anatomies of the operations behind the headlines.
- Interlock: the drive-by ransomware crew CISA flaggedInterlock breaks the ransomware playbook, entering through compromised websites and fake CAPTCHAs. A joint CISA-FBI advisory mapped its TTPs. Here is the profile.
- SafePay: the centralised crew that skipped affiliatesSafePay went from unknown to one of the busiest ransomware crews in under a year by ditching affiliates and hammering RDP and VPN gateways. Here is how it works.
- INC Ransom: the RaaS that wins by mastering the basicsINC Ransom has claimed 800-plus victims since 2023 using stolen credentials, edge-device flaws and double extortion. Here is how the RaaS operates in 2026.
// DEFENCE
Security
EDR, Zero Trust, MFA, patching, IR, what actually works against modern threats.
- Best VirusTotal alternatives 2026: what threat hunters runThe VirusTotal alternatives threat hunters run in 2026: MetaDefender, ANY.RUN, CAPE, Intezer and MalwareBazaar, compared by job, upload privacy and API.
- SOAR vs SIEM 2026: tune before you automateSOAR vs SIEM in 2026: they were never alternatives. Gartner marked standalone SOAR obsolete, and the automation now ships inside your SIEM or XDR.
- SIEM vs XDR 2026: retention is the deciding factorSIEM vs XDR in 2026: XDR wins on detection speed, SIEM wins on retention and audit. Which one you can drop comes down to your compliance obligations.
// SURVEILLANCE
Privacy
GDPR, data brokers, encryption, fingerprinting, VPNs, the surveillance economy and its limits.
- Codename Morgan: inside Morocco’s Pegasus machineForbidden Stories names Morocco as NSO’s client “Morgan”: a 2017 Rabat demo, an Emirati broker, roughly 12,000 targets, and Pegasus traces on seven French ministers’ phones.
- Inside Pegasus: NSO’s own files reveal the machineUnsealed NSO Group court files, analysed by Amnesty’s Security Lab and Forbidden Stories, expose how Pegasus really works: a vendor-run spyware service, not a weapon sold and forgotten.
- Stealer logs bypassing MFA in 2026 [Field Guide]Multi-factor authentication was supposed to end the credential-theft era. In 2026, it hasn’t — because adversaries skip the credential entirely and steal the session cookie that the authentication produced. Here’s how the attack works, why MFA doesn’t stop it, and the four controls that do.
// MACHINE LEARNING
AI
Prompt injection, deepfakes, model theft, the EU AI Act, security and policy at the frontier.
- Vibe coding is shipping vulnerabilities at scale in 2026AI-generated code is fast and insecure. Veracode found 45% of samples carry OWASP Top 10 flaws, roughly a fifth of AI-suggested packages are hallucinated, and vibe-coded apps are already leaking real data.
- Prompt injection left the lab in 2026. It is in the wild nowPrompt injection stopped being a lab demo in 2026. A one-click Claude Desktop flaw, AI browsers leaking credentials, and agents tricked into crypto payments show the attack is now operational, not theoretical.
- Shadow AI is the new stealer-log jackpot in 2026Shadow AI is now a top insider threat: 45% of staff use AI on corporate devices, most via personal accounts. When those sessions land in stealer logs, attackers inherit the AI and everything typed into it.
// INVESTIGATIONS
OSINT
Tools, methods, and case studies from the open-source investigation discipline.
- Best OSINT tools 2026: what analysts actually runThe OSINT tools worth your time in 2026: Maltego, Shodan, SecurityTrails, DarkOwl, theHarvester and more, ranked by what they do and what they leak.
- Maltego tutorial: OSINT link analysis in 2026A hands-on 2026 guide to Maltego for OSINT: entities, transforms, machines and how to build a corroborated link chart from a single selector using the free Community Edition.
- GraphSense tutorial: open-source crypto tracing in 2026A hands-on 2026 guide to GraphSense, the open-source cryptoasset forensics platform: address clustering, TagPacks and how to trace ransom funds without a paid licence.
// PRIMERS
Explainers
Long-form primers on the underlying concepts. Built to be referenced, not skimmed.
- What is intermittent encryption? A 2026 guideIntermittent encryption locks only parts of each file so ransomware runs faster and hides from detection. Here is how partial encryption works and how to catch it.
- What is RaaS? Ransomware-as-a-service, explainedRansomware-as-a-service splits ransomware into a rented product and an affiliate workforce. Here is how the RaaS model works and why it made attacks scale in 2026.
- What is BYOVD? Bring your own vulnerable driver, explainedBYOVD lets attackers load a legitimate but vulnerable signed driver to kill EDR from the kernel. Here is how it works and why ransomware crews rely on it in 2026.























