Tracking the criminal infrastructure of the internet.
Ransomware operators, breach economics, threat-actor profiles, and the open-source investigation toolkit that makes it all visible. Updated daily.
Latest stories
- Love Electric driver data for sale: NI, licence numbersA seller is offering 877,000 driver records from UK EV salary sacrifice broker Love Electric, including National Insurance and driving licence numbers. We checked the sample.
- Bashe interview: a ransomware group on why it wants the coverageBashe, also known as APT73, tells Dancho Danchev that interviews raise the price of silence. Then the public record shows how much of that reputation is manufactured.
- “Delve” is dead: AI writing tells expire in 18 monthsThe word delve fell 94% from its 2024 peak while dash use doubled. We measured 21,442 arXiv abstracts: AI writing tells expire in about 18 months.
- RTM Locker interview: a ransomware actor on the RaaS marketThe group behind RTM Locker speaks to Dancho Danchev about ransomware-as-a-service, why companies really pay, and where the market goes next.
// FOCUS
Ransomware
The defining cybercrime of the decade. How it works, who runs it, and where the money goes.
- Ransomware statistics 2026: confirmed attacks by monthConfirmed ransomware attack statistics, updated monthly: attacks per year, month, country, industry and group, from a human-verified dataset going back to 2018.
- ESXi ransomware in 2026: one host, the whole datacenterESXi ransomware encrypts every VM on a hypervisor at once. Here is why VMware ESXi became ransomware’s highest-value target in 2026, and how to defend it.
- MSPs: ransomware’s #1 target of 2026 [Field Report]Managed service providers entered 2026 as the single highest-leverage target class in the ransomware economy. Why the channel is now the front line, which TTPs operators are running against MSPs specifically, and what the better-run shops have already changed.
// PROFILES
Threat Groups
From LockBit and Conti to Akira and Cl0p, anatomies of the operations behind the headlines.
- Interlock: the drive-by ransomware crew CISA flaggedInterlock breaks the ransomware playbook, entering through compromised websites and fake CAPTCHAs. A joint CISA-FBI advisory mapped its TTPs. Here is the profile.
- SafePay: the centralised crew that skipped affiliatesSafePay went from unknown to one of the busiest ransomware crews in under a year by ditching affiliates and hammering RDP and VPN gateways. Here is how it works.
- INC Ransom: the RaaS that wins by mastering the basicsINC Ransom has claimed 800-plus victims since 2023 using stolen credentials, edge-device flaws and double extortion. Here is how the RaaS operates in 2026.
// DEFENCE
Security
EDR, Zero Trust, MFA, patching, IR, what actually works against modern threats.
- Best VirusTotal alternatives 2026: what threat hunters runThe VirusTotal alternatives threat hunters run in 2026: MetaDefender, ANY.RUN, CAPE, Intezer and MalwareBazaar, compared by job, upload privacy and API.
- SOAR vs SIEM 2026: tune before you automateSOAR vs SIEM in 2026: they were never alternatives. Gartner marked standalone SOAR obsolete, and the automation now ships inside your SIEM or XDR.
- SIEM vs XDR 2026: retention is the deciding factorSIEM vs XDR in 2026: XDR wins on detection speed, SIEM wins on retention and audit. Which one you can drop comes down to your compliance obligations.
// SURVEILLANCE
Privacy
GDPR, data brokers, encryption, fingerprinting, VPNs, the surveillance economy and its limits.
- Codename Morgan: inside Morocco’s Pegasus machineForbidden Stories names Morocco as NSO’s client “Morgan”: a 2017 Rabat demo, an Emirati broker, roughly 12,000 targets, and Pegasus traces on seven French ministers’ phones.
- Inside Pegasus: NSO’s own files reveal the machineUnsealed NSO Group court files, analysed by Amnesty’s Security Lab and Forbidden Stories, expose how Pegasus really works: a vendor-run spyware service, not a weapon sold and forgotten.
- Stealer logs bypassing MFA in 2026 [Field Guide]Multi-factor authentication was supposed to end the credential-theft era. In 2026, it hasn’t — because adversaries skip the credential entirely and steal the session cookie that the authentication produced. Here’s how the attack works, why MFA doesn’t stop it, and the four controls that do.
// MACHINE LEARNING
AI
Prompt injection, deepfakes, model theft, the EU AI Act, security and policy at the frontier.
- “Delve” is dead: AI writing tells expire in 18 monthsThe word delve fell 94% from its 2024 peak while dash use doubled. We measured 21,442 arXiv abstracts: AI writing tells expire in about 18 months.
- Vibe coding is shipping vulnerabilities at scale in 2026AI-generated code is fast and insecure. Veracode found 45% of samples carry OWASP Top 10 flaws, roughly a fifth of AI-suggested packages are hallucinated, and vibe-coded apps are already leaking real data.
- Prompt injection left the lab in 2026. It is in the wild nowPrompt injection stopped being a lab demo in 2026. A one-click Claude Desktop flaw, AI browsers leaking credentials, and agents tricked into crypto payments show the attack is now operational, not theoretical.
// INVESTIGATIONS
OSINT
Tools, methods, and case studies from the open-source investigation discipline.
- Best OSINT tools 2026: what analysts actually runThe OSINT tools worth your time in 2026: Maltego, Shodan, SecurityTrails, DarkOwl, theHarvester and more, ranked by what they do and what they leak.
- Maltego tutorial: OSINT link analysis in 2026A hands-on 2026 guide to Maltego for OSINT: entities, transforms, machines and how to build a corroborated link chart from a single selector using the free Community Edition.
- GraphSense tutorial: open-source crypto tracing in 2026A hands-on 2026 guide to GraphSense, the open-source cryptoasset forensics platform: address clustering, TagPacks and how to trace ransom funds without a paid licence.
// PRIMERS
Explainers
Long-form primers on the underlying concepts. Built to be referenced, not skimmed.
- What is intermittent encryption? A 2026 guideIntermittent encryption locks only parts of each file so ransomware runs faster and hides from detection. Here is how partial encryption works and how to catch it.
- What is RaaS? Ransomware-as-a-service, explainedRansomware-as-a-service splits ransomware into a rented product and an affiliate workforce. Here is how the RaaS model works and why it made attacks scale in 2026.
- What is BYOVD? Bring your own vulnerable driver, explainedBYOVD lets attackers load a legitimate but vulnerable signed driver to kill EDR from the kernel. Here is how it works and why ransomware crews rely on it in 2026.























