Close Menu
  • Home
  • News
  • Security
  • Privacy
  • Cybercrime
    • Threat Groups
    • Ransomware
    • Explainers
    • Stealer Logs
  • AI
  • OSINT
  • Tools
    • Ransomtracker
    • Stealercheck
  • Reviews
    • Best antivirus software for 2026: independent picks from Ransomnews
    • Best ransomware-resistant backup for 2026: cloud, hybrid, and immutable picks reviewed
    • Best ransomware protection for business 2026: ESET PROTECT and 5 alternatives reviewed
  • About Us
Facebook X (Twitter) Instagram Threads
Ransomnews
  • Home
  • News
  • Security
  • Privacy
  • Cybercrime
    • Threat Groups
    • Ransomware
    • Explainers
    • Stealer Logs
  • AI
  • OSINT
  • Tools
    • Ransomtracker
    • Stealercheck
  • Reviews
    • Best antivirus software for 2026: independent picks from Ransomnews
    • Best ransomware-resistant backup for 2026: cloud, hybrid, and immutable picks reviewed
    • Best ransomware protection for business 2026: ESET PROTECT and 5 alternatives reviewed
  • About Us
Facebook X (Twitter) LinkedIn
Ransomnews

Security

// DEFENCE

Security

EDR, Zero Trust, MFA, patching, IR, what actually works against modern threats.

  • Synthwave cover for the Registrų centras 2026 breach: 600,000 records exposed from two state registers, neon perspective grid, floating registry document and broken padlock
    Registrų centras breach: 600,000 records exposedMay 27, 2026
    Lithuania’s Centre of Registers (Registrų centras) disclosed a May 2026 breach exposing roughly 600,000 records. Attackers reused credentials of authorised institutions, queried from abroad. Alerts.bar data shows 117 stealer-log accounts tied to the agency and 60+ live infected staff endpoints across the wider Lithuanian institutional ecosystem.
  • RDP Attack Landscape 2026 — Ransomnews cover
    RDP attacks 2026: ransomware’s #1 entry vectorMay 16, 2026
    Remote Desktop Protocol remains the single most-abused initial-access vector for ransomware operators in 2026. We break down the current attack patterns — credential stuffing, broker-sold access, BlueKeep-era CVE echoes, and weaponised RDS misconfigurations — and the controls that actually move the needle.
  • Editorial cover image with large ALERTS.BAR REVIEW typography over an alert-beacon and credential-cards illustration
    Alerts.bar review 2026: dark-web monitoring testedMay 12, 2026
    Alerts.bar is a continuously-updated dark-web monitoring and stealer-log intelligence platform. We’ve used it in production to power Ransomnews’s free Stealercheck tool. Here’s our independent review — features, pricing, real-world testing, and how it stacks up against HIBP, SpyCloud, Constella, and Hudson Rock.
  • Stylised official document and glowing countdown timer, dark editorial illustration
    SEC 4-day cyber rule: 2.5 years in, what CISOs learnedMay 11, 2026
    A 2026 retrospective on Item 1.05 of Form 8-K — the SEC’s four-day cyber-incident disclosure rule. How filings have actually played out, what the enforcement signals look like, and the practical playbook the better-prepared CISOs now run.
  • Central control hub with thin connection lines radiating to many small building silhouettes, dark editorial illustration
    MSPs: ransomware’s #1 target of 2026 [Field Report]May 11, 2026
    Managed service providers entered 2026 as the single highest-leverage target class in the ransomware economy. Why the channel is now the front line, which TTPs operators are running against MSPs specifically, and what the better-run shops have already changed.
  • Fragmented padlock with shadow figures dispersing in different directions, dark editorial illustration
    LockBit, 2 years after Operation Cronos: where are they now?May 11, 2026
    A 2026 retrospective on the international takedown that displaced LockBit at the top of the ransomware ecosystem — what stuck, what reverted, where the affiliate workforce migrated, and what the next coordinated action should learn from the playbook.
  • Stylised cookie slipping past a glowing security barrier, dark editorial illustration
    MFA bypass via cookie theft: the #1 breach vector of 2026May 11, 2026
    Through 2024 and 2025 a quiet rebalancing happened: password-phishing fell, session-cookie theft via infostealers surged, and “we have MFA” stopped meaning what defenders thought it meant. A 2026 field guide to the technique and the controls that actually answer it.
  • Stylised dashboard with bar charts and world-map silhouette, dark editorial illustration
    2026 ransomware victim toll: countries, sectors, operatorsMay 11, 2026
    A data-led snapshot of who’s actually being ransomed in 2026 — which sectors are losing ground, which operators are pulling away from the pack, and which national-level patterns the leak-site economy reveals.
  • Opened archive box with abstract data cards spilling out, dark editorial illustration
    What’s inside an infostealer log? A 2026 walkthroughMay 10, 2026
    A 2026 walkthrough of the typical infostealer-log archive — what files it contains, what each one means, and how defenders parse them with Python and jq for downstream incident response.
  • Concentric defensive rings around a glowing core with server-rack outlines, dark editorial illustration
    Active Directory hardening 2026: Tier 0, DSRM, PRT theftMay 10, 2026
    A 2026 practitioner walkthrough of Active Directory hardening against the lateral-movement, credential-theft, and persistence techniques that modern ransomware operators rely on — Tier 0 isolation, DSRM rotation, PRT theft mitigation, and AD audit baselines.
  • Abstract emergency control console with phase indicators glowing in green, dark editorial illustration
    Ransomware IR runbook 2026: NIST 800-61 r3 + CISA templatesMay 10, 2026
    A practitioner walkthrough of building a ransomware-specific incident response runbook in 2026 — combining NIST SP 800-61 r3, CISA’s #StopRansomware playbook, and the lessons from named incidents on the Ransomtracker leak feed.
  • Network of nodes radiating from a central building outline, dark technical illustration
    Attack-surface mapping 2026: Shodan, Censys, FOFA, NucleiMay 10, 2026
    A 2026 OSINT workflow for mapping the external attack surface of any organisation using only public data — internet-scan engines, certificate transparency, and authenticated vulnerability templates.
  • Stylised email envelope being scanned by a green beam, abstract data flow on dark background
    Detecting AI-generated phishing in 2026: a header-forensics, classifier, and DKIM workflowMay 10, 2026
    A 2026 workflow for telling AI-generated phishing apart from real correspondence — combining email-header forensics, public LLM-detection classifiers, and DKIM/SPF replay analysis.
  • A hardware security key being inserted into a laptop with account icons flowing toward it
    How to set up YubiKey on every account that matters: a 2026 step-by-step tutorialMay 7, 2026
    A practitioner’s step-by-step tutorial for hardware-key MFA in 2026. Which YubiKey to buy, how to enroll it on Google, Microsoft, GitHub, AWS, and your password manager, plus the recovery-key gotcha that locks people out.
  • A home server rack with monitoring dashboards displaying alert graphs and network flow diagrams
    Build a home SOC with Wazuh and Suricata: a 2026 indie security tutorialMay 7, 2026
    A step-by-step tutorial for building a real home SOC with Wazuh, Suricata, and an OPNsense router on hardware that costs under $400. Endpoint EDR, network IDS, and log correlation — the same stack used by mid-market enterprises.
  • A desktop GPU tower with model weights flowing in and a green chat interface on a monitor
    How to host Llama 3 70B locally with Ollama and Open WebUI: a 2026 tutorialMay 7, 2026
    A practitioner’s tutorial for running Llama 3 70B locally with Ollama, Open WebUI, and the right hardware. Privacy-sensitive AI work without sending a byte to OpenAI or Anthropic.
  • An AI agent being probed by red attack arrows with a green shield evaluating each attack
    How to red-team your own LLM app: tutorial with Garak, PyRIT, and PromptfooMay 7, 2026
    A 2026 tutorial for running structured prompt-injection and jailbreak red-team tests against your own LLM application using NVIDIA Garak, Microsoft PyRIT, and Promptfoo. Open-source, repeatable, CI-friendly.
  • A magnifying glass scanning a fake login page with red warning indicators visible
    How to investigate a phishing kit: tutorial with urlscan.io, PhishTank, and Sublime SecurityMay 7, 2026
    A practitioner’s tutorial for investigating a suspicious URL safely — fingerprinting the kit, attributing it to a campaign, and reporting it to takedown services. Real tools, step-by-step, no enterprise budget required.
  • A glass-walled isolated room containing a VM analysing a malicious file with monitoring meters outside
    How to set up a malware analysis sandbox at home: FlareVM, REMnux, and Cuckoo tutorialMay 7, 2026
    A step-by-step tutorial for building a free malware analysis sandbox at home — Windows reverse-engineering with FlareVM, Linux analysis with REMnux, and automated detonation with Cuckoo.
  • A dossier folder with actor profile, network graph, and TTPs grid arranged on a desk
    How to build a threat actor profile from public sources: MITRE ATT&CK + Mandiant + Malpedia tutorialMay 7, 2026
    A practitioner’s tutorial for assembling a working threat-actor profile from public sources — MITRE ATT&CK for TTPs, Mandiant and CrowdStrike for attribution context, Malpedia for malware lineage, plus a clean note-taking template.
  • A laptop wrapped in multiple shield layers deflecting a malware icon
    Defending against infostealers: tutorial with Defender for Endpoint, CrowdStrike, and browser hardeningMay 7, 2026
    A 2026 tutorial on building a layered defence against infostealers — endpoint EDR settings that catch stealer behaviour, browser hardening that protects cookie stores, and the user-side training that closes the actual gap.
  • A session cookie icon being snatched by a hooded hand with a successful login authentication and a bypassed MFA token
    How session-cookie theft replaced password theft in 2026May 3, 2026
    Stealing your password used to be the goal. In 2026 it’s the consolation prize — modern infostealers go for session cookies, which let attackers impersonate authenticated users without needing to defeat MFA. Here’s how the model works.
  • A forensic examination scene with magnifying glass over a stealer log file and a chain-of-evidence trail to an infected user
    Stealer log forensics: tracing infections back to the userMay 3, 2026
    A practitioner’s forensic playbook for working backwards from a stealer log to the originating infection — what the log file structure tells you, where the malware sits, and how to clean it up properly.
  • A spider silhouette spread over a network diagram with telecom and SIM-card icons connected by red threads
    Scattered Spider in 2026: still the SIM-swap kingsMay 3, 2026
    Scattered Spider — UNC3944, Octo Tempest — survived the 2024 arrests and remains one of the most operationally aggressive English-speaking threat groups. Their 2026 playbook, capabilities, and how they keep getting in.
Facebook X (Twitter) LinkedIn
© 2026 Ransomnews.com

Type above and press Enter to search. Press Esc to cancel.

Cookies on Ransomnews

We use strictly-necessary cookies to run the site and may use first-party analytics to understand which articles are read. Some pages contain affiliate links — when you click one, the affiliate network sets cookies on the merchant's domain to attribute the referral. See the Cookie Policy and Affiliate Disclosure for detail.

RANSOMNEWS.COM

Tracking the criminal infrastructure of the internet.

Independent coverage of ransomware, breach economics, threat actors, privacy, AI security, and the open-source investigation toolkit.

// Topics

  • News
  • Security
  • Privacy
  • Cybercrime
  • AI
  • OSINT
  • Reviews
  • Threat Groups
  • Stealer Logs
  • Ransomtracker
  • Stealercheck

// Site

  • About Us
  • Editorial Team
  • Contact
  • Tip Line
  • Editorial

// Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Affiliate Disclosure
  • RSS Feed
© 2026 Ransomnews.com · Tracking the criminal infrastructure of the internet.