Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsStudyTraining
ProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Study
Training
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

1310+ Articles
157+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
All tags
125 articles

#Ransomware

All CosmicBytez Labs articles tagged #Ransomware, across news, security advisories, how-to guides, and projects.

  • HOWTOOct 15, 2026

    Anatomy of a Ransomware Attack on a Canadian Ag Operation

    A composite case study of a typical 2026 ransomware incident hitting a Canadian agricultural business — from the first phishing email through full encryption, six days later. Names changed, sequence accurate.

  • HOWTOSep 15, 2026

    Why Your Accountant is a Ransomware Target

    Small accounting firms in rural Alberta have become primary ransomware targets in 2025–2026. The reasons are structural: high-value data, weak security budgets, and tax-deadline timing pressure. Here's what to ask your accountant before it's your data caught in the crossfire.

  • HOWTOJun 15, 2026

    What Rural Alberta Businesses Get Wrong About Ransomware

    The five most common things rural Alberta business owners believe about ransomware that are wrong, expensive, and entirely fixable.

  • NewsJun 2, 2026

    AI-Built Ransomware Toolkit Automates EDR Evasion and AD Discovery

    A threat actor has deployed an AI-generated ransomware attack toolkit that automates Active Directory discovery and helps evade endpoint detection and response solutions, marking a new escalation in AI-assisted cybercrime.

  • HOWTOJun 1, 2026

    Why Every Business Needs Cyber Insurance in 2026

    Cyber insurance stopped being optional for Canadian small businesses in 2024. By 2026 it's table-stakes — but most owners are walking into renewal without understanding what their carrier is actually asking. Here's what's changed.

  • NewsMay 27, 2026

    Ransomware Actors Show Up In Person to Steal Law Firm Data

    FBI warns the Silent Ransom Group is targeting law firms by physically arriving on-site and social-engineering access to sensitive client databases.

  • NewsletterMay 26, 2026

    May 26 Digest: SharePoint RCE, Megalodon CI/CD Blitz

    Microsoft patches a CVSS 8.8 SharePoint RCE; the Megalodon campaign poisons 5,561 GitHub repos in six hours; 7-Eleven's ShinyHunters breach hits 185,000; and a.

  • NewsMay 22, 2026

    ''First VPN'' Cybercrime Service Disrupted, Administrator

    The FBI and international partners have disrupted First VPN, a criminal VPN service used by dozens of ransomware groups for network reconnaissance and...

  • NewsMay 22, 2026

    First VPN Dismantled in Global Takedown Over Use by 25

    International authorities have disrupted a criminal VPN service called First VPN that was used by more than 25 ransomware groups to conceal network...

  • NewsMay 22, 2026

    Verizon DBIR 2026: Healthcare Fends Off Rising Social

    The 2026 Verizon Data Breach Investigations Report highlights how evolving social engineering tactics are making the healthcare sector more vulnerable,...

  • NewsMay 21, 2026

    Europe Dismantles VPN Service Used by Cybercriminals to

    European law enforcement has taken down First VPN, a privacy service that had been openly advertised on Russian-language cybercrime forums as a tool for...

  • NewsMay 21, 2026

    Police Seize 'First VPN' Service Used in Ransomware and

    International law enforcement has dismantled 'First VPN,' a criminal VPN service marketed on Russian-speaking cybercrime forums and used to facilitate...

  • NewsMay 20, 2026

    Hackers Bypass SonicWall VPN MFA Due to Incomplete Patching

    Threat actors brute-forced credentials and bypassed multi-factor authentication on SonicWall Gen6 SSL-VPN appliances to deploy ransomware tools,...

  • NewsletterMay 20, 2026

    May 20 Digest: Exchange Zero-Day, Verizon DBIR, GitHub

    A Microsoft Exchange zero-day is being exploited with no patch in sight; Verizon DBIR 2026 marks a landmark shift — vulnerability exploitation now...

  • NewsMay 19, 2026

    Cybercrime Service Disrupted for Abusing Microsoft Platform

    Microsoft has disrupted a malware-signing-as-a-service operation that exploited the company's Artifact Signing service to produce fraudulent code-signing...

  • NewsMay 19, 2026

    Verizon DBIR 2026: Vulnerability Exploitation Overtakes

    Verizon's 2026 Data Breach Investigations Report reveals a landmark shift: vulnerability exploitation has surpassed credential abuse as the leading breach...

  • NewsMay 18, 2026

    Millions Impacted Across Several US Healthcare Data Breaches

    Multiple healthcare data breaches impacting hundreds of thousands to millions of individuals have been added to the HHS breach tracker, continuing a...

  • NewsMay 17, 2026

    Foxconn Attack Highlights Manufacturing's Cyber Crisis

    A Nitrogen ransomware attack on Foxconn's North American facilities is one of more than 600 hits on manufacturers so far in 2026, as ransomware gangs...

  • NewsMay 15, 2026

    American Lending Center Data Breach Affects 123,000

    The non-bank lender discovered a ransomware attack nearly one year ago but only recently completed its investigation, notifying over 123,000 individuals...

  • NewsMay 13, 2026

    Foxconn Confirms Cyberattack Claimed by Nitrogen Ransomware

    Foxconn, the world's largest electronics manufacturer, confirmed a cyberattack on its North American factories claimed by the Nitrogen ransomware gang,...

  • NewsMay 13, 2026

    Foxconn Confirms North American Factories Hit by Cyberattack

    Electronics manufacturing giant Foxconn has confirmed a cyberattack on its North American operations after the Nitrogen ransomware group claimed...

  • NewsMay 13, 2026

    Government to Scrutinize Instructure Over Canvas

    The House Committee on Homeland Security has demanded a briefing from Instructure, the company behind the Canvas LMS platform, after a ransomware attack...

  • NewsMay 13, 2026

    Tables Turn on 'The Gentlemen' RaaS Gang With Data Leak

    An OPSEC failure provides a rare window into the inner workings of The Gentlemen ransomware-as-a-service group, exposing their affiliate model, TTPs, and...

  • NewsMay 12, 2026

    Instructure Reaches Ransom Agreement with ShinyHunters to

    Educational technology company Instructure, parent of Canvas LMS, has reached an undisclosed 'agreement' with the ShinyHunters extortion group after a...

  • NewsMay 12, 2026

    UK Fines Water Supplier $1.3M for Exposing Data of 664K

    The UK's Information Commissioner's Office has fined South Staffordshire Water Plc and its parent company £963,900 ($1.3 million) after a cyberattack...

  • NewsMay 12, 2026

    West Pharmaceutical Services Hit by Disruptive Ransomware

    West Pharmaceutical Services, a global manufacturer of drug delivery systems and packaging, has taken systems offline worldwide after hackers exfiltrated...

  • NewsMay 12, 2026

    West Pharmaceutical Warns of Ransomware Attack Impacting

    West Pharmaceutical Services filed an SEC disclosure warning that hackers breached the company on May 4, stole data, and encrypted systems — forcing a...

  • NewsletterMay 12, 2026

    May 12 Digest: AI-Generated Zero-Day, Shai-Hulud Worm

    Google confirms the first AI-generated zero-day in the wild; TeamPCP's Mini Shai-Hulud worm hits TanStack, Mistral AI, and Guardrails AI; Instructure pays...

  • NewsMay 11, 2026

    UK Water Utility Fined £963,900 After Cl0p Lurked

    The UK's Information Commissioner's Office fined South Staffordshire Water nearly £1 million after the Cl0p ransomware group maintained undetected access...

  • NewsMay 10, 2026

    Canvas Breach Disrupts Schools & Colleges Nationwide

    A data extortion attack against Canvas LMS defaced login pages with a ransom demand, disrupting classes and coursework at school districts and...

  • NewsMay 8, 2026

    Trellix Source Code Breach Claimed by RansomHouse Hackers

    The RansomHouse threat group has claimed responsibility for the Trellix source code repository breach disclosed last week, leaking a set of proof images...

  • NewsMay 2, 2026

    Critical cPanel Flaw Mass-Exploited in 'Sorry' Ransomware

    A newly disclosed critical vulnerability in cPanel and WHM tracked as CVE-2026-41940 is being mass-exploited by ransomware actors to breach web hosting...

  • NewsMay 1, 2026

    Cyber Incident Responders Sentenced to 4 Years for Carrying

    Two cybersecurity incident responders who abused their trusted positions to secretly carry out ransomware attacks against the organizations they were...

  • NewsMay 1, 2026

    US Ransomware Negotiators Get 4 Years in Prison Over

    Two former cybersecurity incident responders from Sygnia and DigitalMint were each sentenced to four years in federal prison for leveraging their trusted...

  • NewsApr 30, 2026

    Former Incident Responders Sentenced to 4 Years for

    Ryan Goldberg and Kevin Martin, who worked as incident responders, were sentenced to four years in federal prison after using their trusted access to...

  • NewsApr 30, 2026

    Sandhills Medical Says Ransomware Breach Affects 170,000

    Healthcare organization took nearly one year to publicly disclose a data breach after being targeted by Inc Ransom ransomware, with approximately 170,000...

  • NewsApr 29, 2026

    Vect 2.0 Ransomware Acts as Wiper Thanks to Design Error

    The emerging Vect 2.0 ransomware — deployed against TeamPCP supply chain attack victims — permanently destroys files larger than 131KB due to a critical...

  • NewsApr 29, 2026

    VECT 2.0 Ransomware Irreversibly Destroys Files Over 131KB

    Threat hunters warn that VECT 2.0 ransomware contains a critical flaw in its encryption implementation that acts more like a wiper for files over 131KB...

  • NewsApr 28, 2026

    Broken VECT 2.0 Ransomware Acts as a Data Wiper for Large

    Researchers have found that VECT 2.0 ransomware contains a critical flaw in its nonce handling that causes encryption to permanently destroy large files...

  • NewsApr 28, 2026

    Feuding Ransomware Groups Leak Each Other's Data

    When rival ransomware groups 0APT and KryBit turned on each other, they exposed infrastructure details, operational data, victim lists, and internal...

  • NewsletterApr 28, 2026

    Apr 28 Digest: Medtronic 9M Breach, GitHub RCE, LiteLLM

    ShinyHunters hits Medtronic and ADT in the same week, exposing millions of records; a critical one-push RCE lands in GitHub; LiteLLM's pre-auth SQL...

  • NewsApr 25, 2026

    CISA Adds 4 Exploited Flaws to KEV, Sets May 2026 Federal

    CISA has added four actively exploited vulnerabilities affecting SimpleHelp, Samsung MagicINFO 9 Server, and D-Link DIR-823X routers to its Known...

  • NewsApr 23, 2026

    Trigona Ransomware Deploys Custom CLI Exfiltration Tool in

    Recently observed Trigona ransomware attacks are using a bespoke command-line exfiltration tool to steal data from compromised environments faster and...

  • NewsApr 22, 2026

    Former Ransomware Negotiator Pleads Guilty to BlackCat

    Angelo Martino, 41, a former employee of cybersecurity incident response firm DigitalMint, has pleaded guilty to targeting U.S. companies with BlackCat...

  • NewsApr 22, 2026

    Kyber Ransomware Gang Uses Post-Quantum Encryption to

    A new ransomware operation called Kyber is targeting Windows systems and VMware ESXi endpoints, with one variant implementing Kyber1024 post-quantum...

  • NewsApr 21, 2026

    Former DigitalMint Ransomware Negotiator Pleads Guilty to

    Angelo Martino, a former ransomware payment negotiator for DigitalMint, has pleaded guilty to helping accomplish extort $75.3 million in ransom from five...

  • NewsApr 21, 2026

    Surge in Bomgar RMM Exploitation Demonstrates Supply Chain

    A critical RCE flaw in BeyondTrust Bomgar remote monitoring and management software is being actively exploited to spread ransomware and compromise...

  • NewsletterApr 21, 2026

    Apr 21 Digest: Vercel AI Tool Breach, DPRK $290M, ActiveMQ

    Vercel confirms breach through a compromised third-party AI coding tool; North Korean hackers attributed to a $290 million crypto theft; 6,400 Apache...

  • NewsApr 20, 2026

    The Backup Myth That Is Putting Businesses at Risk

    Backups protect your data, but they don't keep your business running during downtime. Understanding the difference between backup and BCDR is critical as...

  • NewsApr 20, 2026

    The Gentlemen Ransomware Now Uses SystemBC for Bot-Powered

    Researchers have discovered a SystemBC proxy botnet of over 1,570 compromised hosts linked to Gentlemen ransomware operations. The gang's affiliate is...

  • NewsApr 19, 2026

    6-Year Ransomware Campaign Targets Turkish Homes and SMBs

    A ransomware campaign operating since at least 2019 has persistently targeted Turkish home users and small-to-medium businesses, largely evading major...

  • NewsApr 18, 2026

    NAKIVO v11.2: Ransomware Defense, Faster Replication

    NAKIVO Backup & Replication v11.2 is generally available, bringing immutable backup enhancements for ransomware defense, faster replication performance,...

  • NewsApr 17, 2026

    Payouts King Ransomware Uses QEMU Virtual Machines to

    The Payouts King ransomware group is deploying the QEMU open-source emulator as a covert reverse SSH backdoor, spinning up hidden virtual machines on...

  • NewsApr 17, 2026

    Ransomware Attack Still Disrupting London Healthcare Nearly

    More than 18 months after a ransomware attack crippled hospitals in South East London, at least one NHS trust is still operating without fully restored...

  • NewsApr 11, 2026

    In Other News: Cyberattack Stings Stryker, Windows

    A weekly roundup of notable cybersecurity stories: Iran-linked hackers wipe 200,000 Stryker devices, the BlueHammer Windows zero-day PoC goes public,...

  • NewsApr 10, 2026

    Dutch Hospitals Disrupted After Ransomware Hits Healthcare

    A ransomware attack on Dutch healthcare software vendor ChipSoft has forced hospitals and patients across the Netherlands offline, disrupting the HiX...

  • NewsApr 9, 2026

    Healthcare IT Provider ChipSoft Hit by Ransomware Attack

    Dutch healthcare software vendor ChipSoft has been struck by a ransomware attack, forcing the company to take its website and digital patient services...

  • NewsApr 8, 2026

    FBI: Cybercrime Losses Neared $21 Billion in 2025

    The FBI received over 1 million complaints of malicious activity in 2025, with investment scams, business email compromise, and tech support fraud causing...

  • NewsApr 7, 2026

    China-Linked Storm-1175 Chains Zero-Days for High-Velocity

    A China-based threat cluster designated Storm-1175 has been linked to high-velocity ransomware attacks deploying Medusa payloads using chained zero-day...

  • NewsApr 7, 2026

    Medusa Ransomware Is Fast to Exploit Fresh Vulnerabilities

    SecurityWeek reports that the Medusa ransomware group has developed a dangerous capability: rapidly weaponizing newly disclosed vulnerabilities —...

  • NewsApr 7, 2026

    Medusa Ransomware Exploits Zero-Days to Deploy Ransomware

    Microsoft has raised the alarm over Medusa ransomware's unprecedented operational speed, with the group now exploiting zero-day vulnerabilities before...

  • NewsApr 7, 2026

    Storm-1175 Deploys Medusa Ransomware at 'High Velocity'

    Microsoft says the financially motivated cybercrime group Storm-1175, linked to China, has exploited N-day and zero-day vulnerabilities in high-velocity...

  • NewsletterApr 7, 2026

    Apr 7 Digest: Medusa Ransomware Surge, FBI $21B Record

    Storm-1175 runs sub-24-hour Medusa ransomware campaigns using zero-days; the FBI IC3 reports a record $21 billion in US cybercrime losses for 2025; North...

  • NewsApr 6, 2026

    BKA Identifies REvil Leaders Behind 130 German Ransomware

    Germany's Federal Criminal Police Office has publicly unmasked the real identity of "UNKN," the primary operator behind the now-defunct REvil and GandCrab...

  • NewsApr 6, 2026

    German Authorities Identify REvil and GandCrab Ransomware

    Germany's Federal Police have publicly named two Russian nationals as the leaders of the GandCrab and REvil ransomware operations, linking them to at...

  • NewsApr 6, 2026

    Medusa Ransomware Group Exploits Zero-Days to Strike Within

    Microsoft warns that Medusa ransomware operators are exploiting zero-day vulnerabilities approximately one week before public disclosure, enabling the...

  • NewsApr 6, 2026

    Microsoft Links Storm-1175 to Medusa Ransomware Zero-Day

    Microsoft has formally attributed Medusa ransomware zero-day attacks to Storm-1175, a China-based financially motivated cybercriminal group that has...

  • NewsApr 5, 2026

    Germany Doxes "UNKN," Head of RU Ransomware Gangs REvil

    German authorities have publicly identified the elusive "UNKN," the operator behind the GandCrab and REvil ransomware groups, as 31-year-old Russian...

  • NewsApr 4, 2026

    Evolution of Ransomware: Multi-Extortion Ransomware Attacks

    Modern ransomware has evolved far beyond simple file encryption. Multi-extortion tactics — combining encryption, data theft, and public leak threats —...

  • NewsApr 3, 2026

    Die Linke German Political Party Confirms Data Stolen by

    The Qilin ransomware group has claimed responsibility for an attack against German political party Die Linke, forcing an IT systems outage and threatening...

  • NewsApr 3, 2026

    In Other News: ChatGPT Data Leak, Android Rootkit, Water

    This week's security stories you may have missed: a ChatGPT conversation data leak, a new Android rootkit on Google Play, a municipal water facility taken...

  • NewsApr 1, 2026

    Google Drive Ransomware Detection Now On by Default for

    Google has announced that its AI-powered ransomware detection feature for Google Drive has reached general availability and is now enabled by default for...

  • NewsMar 31, 2026

    Iran Deploys 'Pseudo-Ransomware,' Revives Pay2Key Operations

    Iranian APT groups are increasingly blurring the lines between state-sponsored cyber espionage and financially motivated cybercrime, deploying destructive...

  • NewsMar 31, 2026

    Leak Bazaar: New Criminal Service Plans to Monetize Data

    A new underground platform called Leak Bazaar positions itself as a data-processing business, offering to monetize stolen records on behalf of ransomware...

  • NewsMar 31, 2026

    Stolen Logins Are Fueling Everything From Ransomware to

    A new report reveals how industrialized credential theft has become the common thread connecting ransomware campaigns, SaaS platform breaches, and...

  • NewsletterMar 31, 2026

    Mar 31 Digest: Axios npm RAT, Claude Code Source Leaked

    The Axios npm library was weaponized to deliver a cross-platform RAT; Anthropic accidentally leaked Claude Code's CLI source in an npm package; Google...

  • NewsMar 29, 2026

    Foster City Declares State of Emergency After Ransomware

    A ransomware attack on March 19 paralyzed Foster City's government systems for over six days, forcing officials to declare a state of emergency while...

  • NewsMar 28, 2026

    Bearlyfy Hits Russian Firms with Custom GenieLocker

    Pro-Ukrainian hacktivist group Bearlyfy has conducted over 70 cyberattacks against Russian companies since January 2025, recently deploying a custom...

  • NewsletterMar 27, 2026

    Mar 27 Digest: EU Commission AWS Breach, DarkSword iOS

    The European Commission confirms a 350 GB AWS breach; the DarkSword iOS exploit chain goes public on GitHub threatening hundreds of millions of iPhones;...

  • NewsMar 26, 2026

    Pro-Ukraine Hacker Group Bearlyfy Targets Russian Companies

    The pro-Ukrainian hacktivist group Bearlyfy has conducted over 70 cyberattacks against Russian businesses in the past year and is escalating operations...

  • NewsletterMar 26, 2026

    Mar 26 Digest: LeakBase Admin Arrested, WebRTC Skimmer

    This week: Russian authorities detain the alleged LeakBase admin weeks after the FBI-led global crackdown on the 147,000-subscriber stolen-data...

  • NewsMar 25, 2026

    Manager of Botnet Used in Ransomware Attacks Gets 2 Years

    Ilya Angelov, co-leader of the TA551/Mario Kart cybercrime group, was sentenced to two years in prison for operating a phishing botnet that sent 700,000...

  • NewsletterMar 25, 2026

    Mar 25 Digest: DarkSword Leaks iPhone Zero-Days

    This week: the DarkSword iOS exploit chain published on GitHub threatens to democratize nation-state-grade iPhone hacking; CanisterWorm turns the Trivy...

  • NewsMar 24, 2026

    Russian Hacker Who Helped Yanluowang Ransomware Gang Gets

    Aleksei Volkov, a Russian initial access broker who sold unauthorized access to U.S. companies for the Yanluowang ransomware group, has been sentenced to...

  • NewsMar 22, 2026

    Malaysia Airlines Listed by Qilin Ransomware Group

    The Qilin ransomware-as-a-service group has listed Malaysia Airlines on its leak site, claiming access to passenger records, personnel files, and...

  • NewsMar 21, 2026

    Two US Cybersecurity Professionals Plead Guilty to BlackCat

    Former incident responder Ryan Goldberg and ransomware negotiator Kevin Martin admitted to running ALPHV/BlackCat ransomware operations against five US...

  • NewsMar 21, 2026

    Interlock Ransomware Exploited Cisco FMC Zero-Day for 36

    CVE-2026-20131, a maximum-severity CVSS 10.0 insecure deserialization flaw in Cisco Firepower Management Center, was exploited by Interlock ransomware as...

  • NewsMar 21, 2026

    Marquis Fintech Breach Exposes 672,000 Banking Customers

    Plano-based fintech vendor Marquis disclosed that a ransomware attack exploiting a SonicWall firewall vulnerability compromised Social Security numbers,...

  • NewsMar 19, 2026

    CISA Adds Zimbra XSS and SharePoint RCE to KEV; Cisco FMC

    CISA added actively exploited Zimbra Collaboration Suite and Microsoft SharePoint vulnerabilities to its Known Exploited Vulnerabilities catalog on March...

  • NewsMar 18, 2026

    Marquis Ransomware Breach: 672K People Exposed as Attack

    Texas fintech Marquis Software Solutions has confirmed a ransomware attack in August 2025 exposed data of 672,000+ individuals and disrupted operations at...

  • NewsMar 18, 2026

    Interlock Ransomware Has Been Exploiting Cisco FMC Zero-Day

    The Interlock ransomware gang has been actively exploiting a CVSS 10.0 insecure deserialization flaw in Cisco Secure Firewall Management Center since late...

  • NewsMar 17, 2026

    LeakNet Ransomware Weaponizes ClickFix and Deno Runtime for

    The LeakNet ransomware gang is using ClickFix social engineering for initial access and a Deno-based malware loader to execute fileless payloads from...

  • NewsletterMar 17, 2026

    Mar 17 Digest: GlassWorm Poisons Python, n8n RCE Hits KEV

    This week: GlassWorm escalates with 72 malicious Open VSX extensions and a GitHub token force-push campaign poisoning hundreds of Python repos; CISA adds...

  • NewsMar 15, 2026

    Operation Synergia III: Police Sinkhole 45,000 IPs in

    An international law enforcement operation codenamed Operation Synergia III has sinkholed 45,000 IP addresses and seized servers linked to ransomware,...

  • NewsMar 13, 2026

    England Hockey Investigating Data Breach After AiLock

    England Hockey, the national governing body for field hockey in England, is investigating a potential data breach after the AiLock ransomware group listed...

  • NewsMar 13, 2026

    Telus Digital Confirms Massive Breach After ShinyHunters

    Canadian telecom giant Telus Digital has confirmed a security incident after the ShinyHunters hacking group claimed to have stolen nearly 1 petabyte of...

  • NewsletterMar 11, 2026

    Mar 11 Digest: npm Supply Chain Seizes AWS Admin, 3.4M

    This week: UNC6426 weaponizes a stale npm supply chain compromise to seize full AWS admin in 72 hours, Cognizant TriZetto leaks 3.4 million patient...

  • NewsMar 8, 2026

    Termite Ransomware Operator Velvet Tempest Chains ClickFix

    Microsoft-tracked threat actor Velvet Tempest is deploying Termite ransomware via a ClickFix social-engineering chain that loads DonutLoader and installs...

  • NewsMar 5, 2026

    Phobos Ransomware Admin Pleads Guilty — 1,000+ Victims

    Evgenii Ptitsyn, 43, a Russian national who administered the Phobos ransomware-as-a-service operation, pleaded guilty to wire fraud conspiracy in the U.S....

  • NewsMar 1, 2026

    Former Cybersecurity Incident Responders Plead Guilty to

    An incident response manager and a ransomware negotiator face up to 20 years after admitting to conducting BlackCat (ALPHV) ransomware attacks against...

  • NewsFeb 25, 2026

    Ransomware Forces University of Mississippi Medical Center

    A ransomware attack detected February 19 has taken down UMMC's EPIC EMR system and forced all 35 health clinics across Mississippi to close, canceling...

  • NewsletterFeb 25, 2026

    Feb 25 Digest: Ransomware Hits Healthcare & Semiconductors

    This week: UMMC closes 35 clinics after ransomware, Advantest semiconductor supplier hit, AT&T's 2024 breach resurfaces with 148M decrypted SSNs, Diesel...

  • NewsFeb 24, 2026

    Japanese Semiconductor Giant Advantest Hit by Ransomware

    Advantest Corporation, the world's leading manufacturer of semiconductor test equipment supplying companies like TSMC, Intel, and Samsung, disclosed a...

  • NewsFeb 23, 2026

    HellCat Ransomware Group Breaches Ascom, Exfiltrates 44GB

    The HellCat ransomware group has breached Swiss enterprise communications provider Ascom by exploiting Jira credentials harvested through infostealer...

  • NewsFeb 19, 2026

    Conduent Breach Balloons to Tens of Millions of Americans

    The January 2025 ransomware attack on government technology giant Conduent continues to expand in scope, now confirmed to affect 15.4 million in Texas and...

  • NewsFeb 17, 2026

    Nova (RALord) Ransomware Group Confirmed Active with 73

    The Nova ransomware group, formerly known as RALord, has been confirmed fully operational with 73 victims across nearly every continent, employing double...

  • NewsFeb 17, 2026

    Reynolds Ransomware Embeds BYOVD Driver to Disable EDR

    A new ransomware strain called Reynolds bundles a Bring Your Own Vulnerable Driver component directly in its payload, killing EDR processes from...

  • NewsFeb 17, 2026

    Warlock Ransomware Breaches SmarterTools via Its Own

    The Warlock ransomware group exploited CVE-2026-23760, an authentication bypass zero-day in SmarterMail, to breach SmarterTools itself, compromise 12...

  • NewsFeb 15, 2026

    Ransomware in 2026: Data-Only Extortion Replaces Encryption

    With 91 publicly disclosed ransomware attacks in January 2026 alone, the ransomware landscape is shifting toward data-only extortion while healthcare...

  • NewsFeb 12, 2026

    Romania's National Oil Pipeline Operator Conpet Hit by

    The Qilin ransomware group has compromised Romania's national oil pipeline operator Conpet, exfiltrating over 1 TB of data including passports, internal...

  • NewsFeb 12, 2026

    Ransomware Attacks Surge 49% Year-Over-Year: BlackFog 2026

    BlackFog's 2025 State of Ransomware Report reveals a 49% increase in ransomware attacks year-over-year, with evolving tactics shifting toward...

  • NewsFeb 11, 2026

    Ransomware Costs Projected to Hit $74 Billion in 2026, 30%

    Cybersecurity Ventures forecasts ransomware damage costs will surge to $74 billion globally in 2026, up from $57 billion in 2025, as attacks grow more...

  • NewsFeb 10, 2026

    BridgePay Payment Gateway Knocked Offline by Ransomware

    Major U.S. payment processor BridgePay remains completely offline after a ransomware attack, forcing merchants nationwide to revert to cash-only operations.

  • SecurityFeb 10, 2026

    WinRAR Path Traversal Flaw CVE-2025-8088 Actively Exploited

    Critical path traversal vulnerability in WinRAR enables ransomware and credential theft as Russian and Chinese threat actors weaponize phishing campaigns...

  • NewsletterFeb 8, 2026

    Global Threat Intelligence & New Tools - Issue #3

    This week: state-backed espionage campaigns across 155 countries, China-linked router hijacking, ransomware surge, new security tools, and site updates.

  • NewsFeb 5, 2026

    ShinyHunters Dumps 5.1 Million Panera Bread Customer

    The ShinyHunters hacking group published a 760 MB archive of 5.1 million Panera Bread customer records on the dark web after the company refused to pay a...

  • SecurityFeb 5, 2026

    Conduent Breach Expands: 15.4 Million Texans Affected, 8TB

    Government technology provider Conduent's January 2025 ransomware breach now confirmed to affect at least 15.4 million people in Texas alone, with 8TB of...

  • SecurityFeb 5, 2026

    Iron Mountain Responds to Everest Ransomware Breach Claims

    Information management giant Iron Mountain clarifies that alleged 1.4TB breach was limited to marketing materials after single credential compromise.

  • NewsFeb 4, 2026

    The Rise of Ransomware-as-a-Service: 14 Active Platforms

    Security researchers identify 14 active RaaS platforms operating sophisticated affiliate programs, with entry costs as low as $40 per month lowering the...

  • NewsFeb 4, 2026

    Ransomware Attacks Surge in Early 2026 with 26 Claims in

    Threat intelligence reports show 8 active ransomware groups claimed 26 victims on February 2nd alone, with major corporations including BASF and Honeywell...

  • HOWTOFeb 3, 2026

    Incident Response Playbook: Ransomware

    Complete ransomware incident response playbook following NIST framework. Covers detection, containment, eradication, recovery, and lessons learned.

  • NewsJan 27, 2026

    Healthcare Sector Faces Unprecedented Ransomware Surge in

    Ransomware attacks against healthcare organizations have increased 67% in the first month of 2026, with multiple hospital systems reporting service disruptions.

  • NewsJan 15, 2026

    Covenant Health Ransomware Attack Impacts 478,000 Patients

    Qilin ransomware group claims responsibility for massive healthcare breach, stealing 850GB of sensitive patient data across multiple states. Initial...

  • NewsJan 5, 2026

    Cybersecurity Predictions 2026: The Hype We Can Ignore and

    Industry experts separate signal from noise in 2026's threat landscape. AI-powered attacks, supply chain risks, and the evolution of ransomware top the...

  • NewsJan 5, 2026

    Sedgwick Government Solutions Hit by TridentLocker

    Claims administration firm Sedgwick confirms cybersecurity incident at government subsidiary after TridentLocker ransomware group claims theft of 3.4 GB...