The Gentlemen ransomware weaponised a zero-day in Kontron’s ktapi.sys driver to gain kernel access and kill EDR from Microsoft, ESET, Palo Alto, and SentinelOne, researchers found.
Arctic Wolf says Anubis ransomware affiliates are exploiting Citrix Bleed 2 (CVE-2025-5777) and abusing legitimate RMM tools to breach networks, then deploying an irreversible data wiper.
A US government entity paid Kairos about $1 million to keep stolen files offline, a Ransom-ISAC case study shows. Kairos never encrypted a machine, it just threatened to publish.
Sysdig documented JADEPUFFER, the first ransomware operation run end to end by an AI agent: it breached a server, moved laterally, and encrypted a database with no human at the keyboard.
Confirmed ransomware attack statistics, updated monthly: attacks per year, month, country, industry and group, from a human-verified dataset going back to 2018.
Inside XSS.is, the Russian cybercrime forum seized in 2025. A data-led profile from 123,241 leaked messages: what it traded, who ran it, its place in the ransomware kill chain, and a searchable country IoC table.
Agentic AI moves the threat from what a model says to what it does. We map how MCP turns goal hijacking, tool misuse, and privilege abuse into a working attack chain, and the controls that contain it.
A technical map of the Model Context Protocol attack surface in 2026: tool poisoning, line jumping, rug pulls, tool-chaining exfiltration, token sprawl, and the RCE flaws that turned MCP servers into entry points.
A practitioner’s hardening guide for MCP servers in 2026: OAuth 2.1 auth, least-privilege tool scopes, sandboxing, egress control, and the tool-definition pinning that blocks poisoning and rug pulls.
ESXi ransomware encrypts every VM on a hypervisor at once. Here is why VMware ESXi became ransomware’s highest-value target in 2026, and how to defend it.