Close Menu
  • Home
  • News
  • Security
  • Privacy
  • Cybercrime
    • Threat Groups
    • Ransomware
    • Explainers
    • Stealer Logs
  • AI
  • OSINT
  • Tools
    • Ransomtracker
    • Stealercheck
    • FortiBleed Checker
  • Newsletter
  • About Us
Facebook X (Twitter) Instagram Threads
Ransomnews
  • Home
  • News
  • Security
  • Privacy
  • Cybercrime
    • Threat Groups
    • Ransomware
    • Explainers
    • Stealer Logs
  • AI
  • OSINT
  • Tools
    • Ransomtracker
    • Stealercheck
    • FortiBleed Checker
  • Newsletter
  • About Us
Facebook X (Twitter) LinkedIn
Ransomnews

macOS.Gaslight: malware that prompt-injects your SOC

Martynas VareikisJuly 16, 20260

SentinelLABS found macOS.Gaslight, a DPRK-linked Rust backdoor that embeds 38 fake system messages to make AI malware-triage agents abort. It is the first implant built to attack the analyst’s LLM, not the sandbox.

Akira: the edge-VPN ransomware that never slowed down

Jesse William McGrawJuly 16, 20260

Akira has stayed a top-tier ransomware operation into 2026 by hammering SonicWall SSL-VPNs via CVE-2024-40766, deploying within an hour and using BYOVD to bypass EDR.

Coca-Cola’s Fairlife halts US production after ransomware

Ransomnews Research TeamJuly 16, 20260

Coca-Cola disclosed a ransomware attack on its Fairlife dairy subsidiary in a July 16 SEC filing, suspending all US production. No group has claimed it.

292 fake GitHub repos push a hash-dodging infostealer

Ransomnews Research TeamJuly 15, 20260

Arctic Wolf found 292+ fake GitHub repositories impersonating security and fintech brands to deliver a BoryptGrab-lineage infostealer, with payloads that rotate every 60 seconds.

570 flaws, 2 exploited: July Patch Tuesday hits identity

Jesse William McGrawJuly 15, 20260

Microsoft’s July 2026 Patch Tuesday fixed a record 570 flaws and three zero-days, two already exploited in AD FS and SharePoint identity infrastructure.

Qilin: the RaaS that ran H1 2026 ransomware

Jesse William McGrawJuly 15, 20260

Qilin, formerly Agenda, was the most prolific ransomware-as-a-service of H1 2026 with 641 claimed victims, including the Asahi brewery attack.

The week the West went after ransomware’s plumbing

Ransomnews Research TeamJuly 15, 20260

In 48 hours the US, UK and EU indicted a bulletproof host and sanctioned VPN and cryptor sellers behind LockBit, Play and BlackSuit ransomware.

The Gentlemen weaponised a Kontron driver to kill EDR

Jesse William McGrawJuly 10, 20260

The Gentlemen ransomware weaponised a zero-day in Kontron’s ktapi.sys driver to gain kernel access and kill EDR from Microsoft, ESET, Palo Alto, and SentinelOne, researchers found.

Anubis ransomware is exploiting Citrix Bleed 2 for access

Ransomnews Research TeamJuly 10, 20260

Arctic Wolf says Anubis ransomware affiliates are exploiting Citrix Bleed 2 (CVE-2025-5777) and abusing legitimate RMM tools to breach networks, then deploying an irreversible data wiper.

Kairos took $1M from a US government body and encrypted nothing

Ransomnews Research TeamJuly 10, 20260

A US government entity paid Kairos about $1 million to keep stolen files offline, a Ransom-ISAC case study shows. Kairos never encrypted a machine, it just threatened to publish.

Previous 1 … 3 4 5 6 7 … 22 Next

// The Ransomnews Monthly

What leaked, what held up

One email a month: the datasets we verified, and the ones that fell apart under scrutiny.

Double opt-in. We store your email, signup time, and IP for consent records (GDPR Art. 7). See our privacy policy.

// Free tool

Were you in a leak?

Check whether an email address has surfaced in infostealer logs. No signup, no data stored.

Run StealerCheck

// Live data

Ransomtracker

Victims as they are posted to ransomware leak sites, tracked continuously and checked against the claims.

Open the tracker

9,459 confirmed attacks tracked

Facebook X (Twitter) LinkedIn
© 2026 Ransomnews.com

Type above and press Enter to search. Press Esc to cancel.

Cookies on Ransomnews

We use strictly-necessary cookies to run the site and may use first-party analytics to understand which articles are read. Some pages contain affiliate links — when you click one, the affiliate network sets cookies on the merchant's domain to attribute the referral. See the Cookie Policy and Affiliate Disclosure for detail.

RANSOMNEWS.COM

Tracking the criminal infrastructure of the internet.

Independent coverage of ransomware, breach economics, threat actors, privacy, AI security, and the open-source investigation toolkit.

// Topics

  • News
  • Security
  • Privacy
  • Cybercrime
  • AI
  • OSINT
  • Threat Groups
  • Stealer Logs
  • Ransomtracker
  • Stealercheck
  • FortiBleed Checker

// Site

  • About Us
  • Editorial Team
  • Contact
  • Tip Line
  • Editorial

// Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Funding & Independence
  • RSS Feed
© 2026 Ransomnews.com · Tracking the criminal infrastructure of the internet.