Close Menu
  • Home
  • News
  • Security
  • Privacy
  • Cybercrime
    • Threat Groups
    • Ransomware
    • Explainers
    • Stealer Logs
  • AI
  • OSINT
  • Tools
    • Ransomtracker
    • Stealercheck
    • FortiBleed Checker
  • About Us
Facebook X (Twitter) Instagram Threads
Ransomnews
  • Home
  • News
  • Security
  • Privacy
  • Cybercrime
    • Threat Groups
    • Ransomware
    • Explainers
    • Stealer Logs
  • AI
  • OSINT
  • Tools
    • Ransomtracker
    • Stealercheck
    • FortiBleed Checker
  • About Us
Facebook X (Twitter) LinkedIn
Ransomnews

The Gentlemen weaponised a Kontron driver to kill EDR

Jesse William McGrawJuly 10, 20260

The Gentlemen ransomware weaponised a zero-day in Kontron’s ktapi.sys driver to gain kernel access and kill EDR from Microsoft, ESET, Palo Alto, and SentinelOne, researchers found.

Anubis ransomware is exploiting Citrix Bleed 2 for access

Ransomnews Research TeamJuly 10, 20260

Arctic Wolf says Anubis ransomware affiliates are exploiting Citrix Bleed 2 (CVE-2025-5777) and abusing legitimate RMM tools to breach networks, then deploying an irreversible data wiper.

Kairos took $1M from a US government body and encrypted nothing

Ransomnews Research TeamJuly 10, 20260

A US government entity paid Kairos about $1 million to keep stolen files offline, a Ransom-ISAC case study shows. Kairos never encrypted a machine, it just threatened to publish.

JadePuffer: the first AI agent to run a ransomware attack

Martynas VareikisJuly 10, 20260

Sysdig documented JADEPUFFER, the first ransomware operation run end to end by an AI agent: it breached a server, moved laterally, and encrypted a database with no human at the keyboard.

Ransomware statistics 2026: confirmed attacks by month

Ransomnews Research TeamJuly 8, 20260

Confirmed ransomware attack statistics, updated monthly: attacks per year, month, country, industry and group, from a human-verified dataset going back to 2018.

XSS forum: from DaMaGeLaB to the 2025 takedown

Ransomnews Research TeamJune 29, 20260

Inside XSS.is, the Russian cybercrime forum seized in 2025. A data-led profile from 123,241 leaked messages: what it traded, who ran it, its place in the ransomware kill chain, and a searchable country IoC table.

Agentic AI threats: how MCP becomes an attack chain

Martynas VareikisJune 29, 20260

Agentic AI moves the threat from what a model says to what it does. We map how MCP turns goal hijacking, tool misuse, and privilege abuse into a working attack chain, and the controls that contain it.

MCP security in 2026: the attack surface mapped

Martynas VareikisJune 28, 20260

A technical map of the Model Context Protocol attack surface in 2026: tool poisoning, line jumping, rug pulls, tool-chaining exfiltration, token sprawl, and the RCE flaws that turned MCP servers into entry points.

Build a secure MCP server in 2026: a hardening guide

Martynas VareikisJune 27, 20260

A practitioner’s hardening guide for MCP servers in 2026: OAuth 2.1 auth, least-privilege tool scopes, sandboxing, egress control, and the tool-definition pinning that blocks poisoning and rug pulls.

ESXi ransomware in 2026: one host, the whole datacenter

Ransomnews Research TeamJune 24, 20260

ESXi ransomware encrypts every VM on a hypervisor at once. Here is why VMware ESXi became ransomware’s highest-value target in 2026, and how to defend it.

1 2 3 … 18 Next
Facebook X (Twitter) LinkedIn
© 2026 Ransomnews.com

Type above and press Enter to search. Press Esc to cancel.

Cookies on Ransomnews

We use strictly-necessary cookies to run the site and may use first-party analytics to understand which articles are read. Some pages contain affiliate links — when you click one, the affiliate network sets cookies on the merchant's domain to attribute the referral. See the Cookie Policy and Affiliate Disclosure for detail.

RANSOMNEWS.COM

Tracking the criminal infrastructure of the internet.

Independent coverage of ransomware, breach economics, threat actors, privacy, AI security, and the open-source investigation toolkit.

// Topics

  • News
  • Security
  • Privacy
  • Cybercrime
  • AI
  • OSINT
  • Threat Groups
  • Stealer Logs
  • Ransomtracker
  • Stealercheck
  • FortiBleed Checker

// Site

  • About Us
  • Editorial Team
  • Contact
  • Tip Line
  • Editorial

// Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Funding & Independence
  • RSS Feed
© 2026 Ransomnews.com · Tracking the criminal infrastructure of the internet.