Close Menu
  • Home
  • News
  • Security
  • Privacy
  • Cybercrime
    • Threat Groups
    • Ransomware
    • Explainers
    • Stealer Logs
  • AI
  • OSINT
  • Tools
    • Ransomtracker
    • Stealercheck
    • FortiBleed Checker
    • Site Check
  • Data
    • Ransomware statistics
    • Ransom payment rate
    • Breach verification
  • Newsletter
  • About Us
Facebook X (Twitter) Instagram Threads
Ransomnews
  • Home
  • News
  • Security
  • Privacy
  • Cybercrime
    • Threat Groups
    • Ransomware
    • Explainers
    • Stealer Logs
  • AI
  • OSINT
  • Tools
    • Ransomtracker
    • Stealercheck
    • FortiBleed Checker
    • Site Check
  • Data
    • Ransomware statistics
    • Ransom payment rate
    • Breach verification
  • Newsletter
  • About Us
Facebook X (Twitter) LinkedIn
Ransomnews

Build a secure MCP server in 2026: a hardening guide

Martynas VareikisJune 27, 20260

A practitioner’s hardening guide for MCP servers in 2026: OAuth 2.1 auth, least-privilege tool scopes, sandboxing, egress control, and the tool-definition pinning that blocks poisoning and rug pulls.

ESXi ransomware in 2026: one host, the whole datacenter

Ransomnews Research TeamJune 24, 20260

ESXi ransomware encrypts every VM on a hypervisor at once. Here is why VMware ESXi became ransomware’s highest-value target in 2026, and how to defend it.

Hunting C2 infrastructure: favicon, JARM, cert logs

Jesse William McGrawJune 24, 20260

A 2026 OSINT methodology for pivoting from one malicious IP to a whole adversary cluster using favicon hashes, JARM fingerprints, and certificate transparency.

Deepfake vishing 2026: voice-clone fraud explained

Martynas VareikisJune 24, 20260

Deepfake vishing uses AI-cloned voices to defeat phone-based trust. Here is how voice-clone fraud works in 2026, what it costs, and how to stop it.

1.16 billion attacks: how the FortiBleed crew broke FortiGate

Ransomnews Research TeamJune 19, 20260

Inside the FortiBleed operation: 1.16 billion FortiGate brute-force attempts, a 45-GPU cracking cluster, and the full attack chain, mapped step by step.

FortiBleed: exposed firewalls are a ransomware early warning

Ransomnews Research TeamJune 18, 20260

We cross-checked 73,932 exposed FortiGate firewalls against stealer-log and ransomware-leak data. The overlap is a measurable early warning for breaches.

FortiBleed: 75,000 cracked Fortinet firewalls, no zero-day needed

Ransomnews Research TeamJune 18, 20260

FortiBleed exposed cracked admin passwords for around 75,000 Fortinet firewalls across 194 countries, roughly half the internet-facing fleet. There is no new zero-day. It is config exports, weak hashing, and recycled credentials, packaged as a sales catalog.

Novo Nordisk hit by FulcrumSec: the stealer logs saw it coming

Ransomnews Research TeamJune 17, 20260

FulcrumSec says it stole 1.3 TB from Novo Nordisk, including internal AI models and clinical-trial data, and wants $25M. We pulled the leak-site listing and the stealer logs. The credentials were leaking for months.

Fable 5 and Mythos 5: the US-only gate threat actors will beat

Martynas VareikisJune 15, 20260

Washington cut Fable 5 and Mythos 5 for every foreigner. Meanwhile 34,814 stolen Claude sessions and 74,114 ChatGPT cookies already sit in infostealer logs. A citizenship gate is just KYC, and KYC loses.

The Gentlemen ransomware: 483 victims and a leaked playbook

Ransomnews Research TeamJune 13, 20260

The Gentlemen RaaS has listed 483 victims across 66 countries since 2025. A leaked chat log, live tracker data, and infostealer records show how the crew scaled.

Previous 1 … 6 7 8 9 10 … 24 Next

The Ransomnews Monthly

What leaked, what held up

One email a month: the datasets we verified, and the ones that fell apart under scrutiny.

Double opt-in. We store your email, signup time, and IP for consent records (GDPR Art. 7). See our privacy policy.

Free tool

How does your own site score?

Forty passive checks on TLS, security headers, email spoofing and privacy. A grade out of 100 in about fifteen seconds.

No signup. Nothing installed. We only request what your site already serves publicly.

Free tool

Were you in a leak?

Check whether an email address has surfaced in infostealer logs. No signup, no data stored.

Run StealerCheck

Live data

Ransomtracker

Victims as they are posted to ransomware leak sites, tracked continuously and checked against the claims.

Open the tracker

9,714 confirmed attacks tracked

Facebook X (Twitter) LinkedIn
© 2026 Ransomnews.com

Type above and press Enter to search. Press Esc to cancel.

Cookies on Ransomnews

We use strictly-necessary cookies to run the site and may use first-party analytics to understand which articles are read. Some pages contain affiliate links; when you click one, the affiliate network sets cookies on the merchant's domain to attribute the referral. See the Cookie Policy and Affiliate Disclosure for detail.

RANSOMNEWS.COM

Tracking the criminal infrastructure of the internet.

Independent coverage of ransomware, breach economics, threat actors, privacy, AI security, and the open-source investigation toolkit.

Topics

  • News
  • Security
  • Privacy
  • Cybercrime
  • AI
  • OSINT
  • Threat Groups
  • Stealer Logs
  • Ransomtracker
  • Stealercheck
  • FortiBleed Checker
  • Site Check

Site

  • About Us
  • Editorial Team
  • Contact
  • Tip Line
  • Editorial

Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Funding & Independence
  • RSS Feed
© 2026 Ransomnews.com · Tracking the criminal infrastructure of the internet.