Close Menu
  • Home
  • News
  • Security
  • Privacy
  • Cybercrime
    • Threat Groups
    • Ransomware
    • Explainers
    • Stealer Logs
  • AI
  • OSINT
  • Tools
    • Ransomtracker
    • Stealercheck
    • FortiBleed Checker
    • Site Check
  • Data
    • Ransomware statistics
    • Ransom payment rate
    • Breach verification
  • Newsletter
  • About Us
Facebook X (Twitter) Instagram Threads
Ransomnews
  • Home
  • News
  • Security
  • Privacy
  • Cybercrime
    • Threat Groups
    • Ransomware
    • Explainers
    • Stealer Logs
  • AI
  • OSINT
  • Tools
    • Ransomtracker
    • Stealercheck
    • FortiBleed Checker
    • Site Check
  • Data
    • Ransomware statistics
    • Ransom payment rate
    • Breach verification
  • Newsletter
  • About Us
Facebook X (Twitter) LinkedIn
Ransomnews

570 flaws, 2 exploited: July Patch Tuesday hits identity

Jesse William McGrawJuly 15, 20260

Microsoft’s July 2026 Patch Tuesday fixed a record 570 flaws and three zero-days, two already exploited in AD FS and SharePoint identity infrastructure.

Qilin: the RaaS that ran H1 2026 ransomware

Jesse William McGrawJuly 15, 20260

Qilin, formerly Agenda, was the most prolific ransomware-as-a-service of H1 2026 with 641 claimed victims, including the Asahi brewery attack.

The week the West went after ransomware’s plumbing

Ransomnews Research TeamJuly 15, 20260

In 48 hours the US, UK and EU indicted a bulletproof host and sanctioned VPN and cryptor sellers behind LockBit, Play and BlackSuit ransomware.

The Gentlemen weaponised a Kontron driver to kill EDR

Jesse William McGrawJuly 10, 20260

The Gentlemen ransomware weaponised a zero-day in Kontron’s ktapi.sys driver to gain kernel access and kill EDR from Microsoft, ESET, Palo Alto, and SentinelOne, researchers found.

Anubis ransomware is exploiting Citrix Bleed 2 for access

Ransomnews Research TeamJuly 10, 20260

Arctic Wolf says Anubis ransomware affiliates are exploiting Citrix Bleed 2 (CVE-2025-5777) and abusing legitimate RMM tools to breach networks, then deploying an irreversible data wiper.

Kairos took $1M from a US government body and encrypted nothing

Ransomnews Research TeamJuly 10, 20260

A US government entity paid Kairos about $1 million to keep stolen files offline, a Ransom-ISAC case study shows. Kairos never encrypted a machine, it just threatened to publish.

JadePuffer: the first AI agent to run a ransomware attack

Martynas VareikisJuly 10, 20260

Sysdig documented JADEPUFFER, the first ransomware attack whose technical execution was run end to end by an AI agent. A human handler still picked the target, built the infrastructure, and supplied credentials.

XSS forum: from DaMaGeLaB to the 2025 takedown

Ransomnews Research TeamJune 29, 20260

Inside XSS.is, the Russian cybercrime forum seized in 2025. A data-led profile from 123,241 leaked messages: what it traded, who ran it, its place in the ransomware kill chain, and a searchable country IoC table.

Agentic AI threats: how MCP becomes an attack chain

Martynas VareikisJune 29, 20260

Agentic AI moves the threat from what a model says to what it does. We map how MCP turns goal hijacking, tool misuse, and privilege abuse into a working attack chain, and the controls that contain it.

MCP security in 2026: the attack surface mapped

Martynas VareikisJune 28, 20260

A technical map of the Model Context Protocol attack surface in 2026: tool poisoning, line jumping, rug pulls, tool-chaining exfiltration, token sprawl, and the RCE flaws that turned MCP servers into entry points.

Previous 1 … 5 6 7 8 9 … 24 Next

The Ransomnews Monthly

What leaked, what held up

One email a month: the datasets we verified, and the ones that fell apart under scrutiny.

Double opt-in. We store your email, signup time, and IP for consent records (GDPR Art. 7). See our privacy policy.

Free tool

How does your own site score?

Forty passive checks on TLS, security headers, email spoofing and privacy. A grade out of 100 in about fifteen seconds.

No signup. Nothing installed. We only request what your site already serves publicly.

Free tool

Were you in a leak?

Check whether an email address has surfaced in infostealer logs. No signup, no data stored.

Run StealerCheck

Live data

Ransomtracker

Victims as they are posted to ransomware leak sites, tracked continuously and checked against the claims.

Open the tracker

9,714 confirmed attacks tracked

Facebook X (Twitter) LinkedIn
© 2026 Ransomnews.com

Type above and press Enter to search. Press Esc to cancel.

Cookies on Ransomnews

We use strictly-necessary cookies to run the site and may use first-party analytics to understand which articles are read. Some pages contain affiliate links; when you click one, the affiliate network sets cookies on the merchant's domain to attribute the referral. See the Cookie Policy and Affiliate Disclosure for detail.

RANSOMNEWS.COM

Tracking the criminal infrastructure of the internet.

Independent coverage of ransomware, breach economics, threat actors, privacy, AI security, and the open-source investigation toolkit.

Topics

  • News
  • Security
  • Privacy
  • Cybercrime
  • AI
  • OSINT
  • Threat Groups
  • Stealer Logs
  • Ransomtracker
  • Stealercheck
  • FortiBleed Checker
  • Site Check

Site

  • About Us
  • Editorial Team
  • Contact
  • Tip Line
  • Editorial

Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Funding & Independence
  • RSS Feed
© 2026 Ransomnews.com · Tracking the criminal infrastructure of the internet.