Close Menu
  • Home
  • News
  • Security
  • Privacy
  • Cybercrime
    • Threat Groups
    • Ransomware
    • Explainers
    • Stealer Logs
  • AI
  • OSINT
  • Tools
    • Ransomtracker
    • Stealercheck
    • FortiBleed Checker
    • Site Check
  • Data
    • Ransomware statistics
    • Ransom payment rate
    • Breach verification
  • Newsletter
  • About Us
Facebook X (Twitter) Instagram Threads
Ransomnews
  • Home
  • News
  • Security
  • Privacy
  • Cybercrime
    • Threat Groups
    • Ransomware
    • Explainers
    • Stealer Logs
  • AI
  • OSINT
  • Tools
    • Ransomtracker
    • Stealercheck
    • FortiBleed Checker
    • Site Check
  • Data
    • Ransomware statistics
    • Ransom payment rate
    • Breach verification
  • Newsletter
  • About Us
Facebook X (Twitter) LinkedIn
Ransomnews

What’s inside an infostealer log? A 2026 walkthrough

Ransomnews Research TeamMay 10, 20260

A 2026 walkthrough of the typical infostealer-log archive: what files it contains, what each one means, and how defenders parse them with Python and jq for downstream incident response.

Active Directory hardening 2026: Tier 0, DSRM, PRT theft

Jesse William McGrawMay 10, 20260

A 2026 practitioner walkthrough of Active Directory hardening against the lateral-movement, credential-theft, and persistence techniques that modern ransomware operators rely on: Tier 0 isolation, DSRM rotation, PRT theft mitigation, and AD audit baselines.

Ransomware IR runbook 2026: NIST 800-61 r3 + CISA templates

Ransomnews Research TeamMay 10, 20260

A practitioner walkthrough of building a ransomware-specific incident response runbook in 2026, combining NIST SP 800-61 r3, CISA’s #StopRansomware playbook, and the lessons from named incidents on the Ransomtracker leak feed.

Audit your digital footprint 2026: Sherlock, Holehe, Whoxy

Jesse William McGrawMay 10, 20260

A 2026 self-doxxing tutorial: run the same OSINT tools attackers use, on yourself, to find every account, leaked credential, and broker entry tied to your identity. With remediation steps for each finding.

Attack-surface mapping 2026: Shodan, Censys, FOFA, Nuclei

Ransomnews Research TeamMay 10, 20260

A 2026 OSINT workflow for mapping the external attack surface of any organisation using only public data: internet-scan engines, certificate transparency, and authenticated vulnerability templates.

What is double extortion ransomware? An explainer for non-technical executives in 2026

Jesse William McGrawMay 10, 20260

An executive-level explainer of double extortion (the dominant ransomware playbook in 2026) covering how it works, why backups don’t fully defeat it, and the policy choices boards now have to make in the first hour of an incident.

How initial access brokers price corporate access in 2026: an explainer for defenders

Ransomnews Research TeamMay 10, 20260

A field guide to the 2026 initial-access-broker market: how IABs source access, how they price it, who buys, and what the listings look like under the hood.

Detecting AI-generated phishing in 2026: a header-forensics, classifier, and DKIM workflow

Martynas VareikisMay 10, 20260

A 2026 workflow for telling AI-generated phishing apart from real correspondence, combining email-header forensics, public LLM-detection classifiers, and DKIM/SPF replay analysis.

How to set up YubiKey on every account that matters: a 2026 step-by-step tutorial

Jesse William McGrawMay 7, 20260

A practitioner’s step-by-step tutorial for hardware-key MFA in 2026. Which YubiKey to buy, how to enroll it on Google, Microsoft, GitHub, AWS, and your password manager, plus the recovery-key gotcha that locks people out.

Build a home SOC with Wazuh and Suricata: a 2026 indie security tutorial

Ransomnews Research TeamMay 7, 20260

A step-by-step tutorial for building a real home SOC with Wazuh, Suricata, and an OPNsense router on hardware that costs under $400. Endpoint EDR, network IDS, and log correlation, the same stack used by mid-market enterprises.

Previous 1 … 9 10 11 12 13 … 24 Next

The Ransomnews Monthly

What leaked, what held up

One email a month: the datasets we verified, and the ones that fell apart under scrutiny.

Double opt-in. We store your email, signup time, and IP for consent records (GDPR Art. 7). See our privacy policy.

Free tool

How does your own site score?

Forty passive checks on TLS, security headers, email spoofing and privacy. A grade out of 100 in about fifteen seconds.

No signup. Nothing installed. We only request what your site already serves publicly.

Free tool

Were you in a leak?

Check whether an email address has surfaced in infostealer logs. No signup, no data stored.

Run StealerCheck

Live data

Ransomtracker

Victims as they are posted to ransomware leak sites, tracked continuously and checked against the claims.

Open the tracker

9,715 confirmed attacks tracked

Facebook X (Twitter) LinkedIn
© 2026 Ransomnews.com

Type above and press Enter to search. Press Esc to cancel.

Cookies on Ransomnews

We use strictly-necessary cookies to run the site and may use first-party analytics to understand which articles are read. Some pages contain affiliate links; when you click one, the affiliate network sets cookies on the merchant's domain to attribute the referral. See the Cookie Policy and Affiliate Disclosure for detail.

RANSOMNEWS.COM

Tracking the criminal infrastructure of the internet.

Independent coverage of ransomware, breach economics, threat actors, privacy, AI security, and the open-source investigation toolkit.

Topics

  • News
  • Security
  • Privacy
  • Cybercrime
  • AI
  • OSINT
  • Threat Groups
  • Stealer Logs
  • Ransomtracker
  • Stealercheck
  • FortiBleed Checker
  • Site Check

Site

  • About Us
  • Editorial Team
  • Contact
  • Tip Line
  • Editorial

Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Funding & Independence
  • RSS Feed
© 2026 Ransomnews.com · Tracking the criminal infrastructure of the internet.