Ransomnews has confirmed 55 ransomware attacks in September 2026, against 107 in August and 151 a year earlier. Provisional. Government led the sectors, Qilin and The Gentlemen the groups.
Two class actions over the Novo Nordisk data breach cite our FulcrumSec reporting for its scale, then skip how the attackers got in and what data was exposed.
Germany named Vitaly Kovalev as Conti’s boss in 2025. RAMP forum messages show the other end: a recruiter, a written hacking exam, and when the hiring stopped.
Inside the Exploit.in database, 2005 to 2008: 9,647 members of the Russian hacker forum, 60% who never posted, and 205 handles still on the boards today.
sourcec0de, an active ransomware operator, answers the opening round of Dancho Danchev’s questions over Tox: on harm, an FSB tip, and why he says the law, not the crime, is unjust. First of a longer interview.
Mysterium VPN counted 36,769 self-hosted AI endpoints reachable on the public internet. Only 2.02% return an authentication challenge, and that is a floor.
A forum listing advertises 120 million Telegram records. Ransomnews parsed the 3.7GB file: 63.1 million rows, 74% Iranian, and most of it dates to 2020.
Slopsquatting is a supply-chain attack that weaponises the package names AI coding assistants invent. How it works, what the research measured, the real 2026 incidents, and how to defend an AI-assisted pipeline.
Paying a ransomware ransom is usually legal, but sanctions can make it a crime, and 2026 rules are tightening fast. The law in the US, UK, EU and Australia, and what paying still does not buy.
Medusa is a ransomware-as-a-service crew active since 2021, with 300+ claimed victims and 161 confirmed by Ransomnews. Its targets, tactics, biggest breaches and the defences that stop it.