<?xml version='1.0' encoding='utf-8'?>
<rss version="2.0"><channel><title>Cybersecurity Tracker: Ransomware and Leak Sites</title><link>https://cybersecuritytracker.ai/?cats=ransomware</link><description>Curated cybersecurity news and vulnerability intelligence.</description><lastBuildDate>Sun, 26 Jul 2026 22:32:50 GMT</lastBuildDate><item><title>ShinyHunters data leaks fuel $2,000 sextortion email scam</title><link>https://bleepingcomputer.com/news/security/shinyhunters-data-leaks-fuel-2-000-sextortion-email-scam</link><guid isPermaLink="false">cst-3217</guid><description>Threat actors are leveraging email addresses from ShinyHunters data leaks to conduct sextortion campaigns demanding $2,000 in Bitcoin from recipients. The attackers are exploiting publicly available breach data to target victims with extortion threats.</description><pubDate>Sat, 25 Jul 2026 14:16:26 GMT</pubDate></item><item><title>Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE</title><link>https://thehackernews.com/2026/07/cl0p-affiliates-target-internet-exposed.html</link><guid isPermaLink="false">cst-3213</guid><description>Cl0p-affiliated threat actors are exploiting unauthenticated remote code execution (RCE) vulnerabilities in internet-exposed PTC Windchill and FlexPLM deployments. The attackers chain pre-authentication information disclosure in FlexPLM with server-side flaws in Windchill's login servlet to gain unauthorized access. This activity is part of an active data extortion campaign.</description><pubDate>Sat, 25 Jul 2026 10:14:03 GMT</pubDate></item><item><title>DevMan RaaS Portal Centralizes Payload Builds, Victim Management, and Affiliate Payouts</title><link>https://thehackernews.com/2026/07/devman-raas-portal-centralizes-payload.html</link><guid isPermaLink="false">cst-3214</guid><description>DevMan operators maintain a web portal that enables affiliates to build ransomware payloads, track earnings, and manage victim information. The Swiss cybersecurity firm PRODAFT tracks the operation under the threat actor name Funky Mantis and reports that the platform centralizes multiple ransomware-as-a-service functions in one location.</description><pubDate>Sat, 25 Jul 2026 09:53:41 GMT</pubDate></item><item><title>Clop ransomware targets Windchill, FlexPLM in data theft attacks</title><link>https://bleepingcomputer.com/news/security/clop-ransomware-targets-windchill-flexplm-in-data-theft-attacks</link><guid isPermaLink="false">cst-3151</guid><description>The Clop ransomware group is conducting data theft extortion attacks against publicly accessible instances of PTC Windchill and FlexPLM product lifecycle management platforms. These attacks represent an expansion of the group's targeting beyond previously observed patterns.</description><pubDate>Fri, 24 Jul 2026 07:36:39 GMT</pubDate></item><item><title>Ransomware gangs go after EMEA healthcare’s supply chain</title><link>https://helpnetsecurity.com/2026/07/24/emea-healthcare-ransomware-activity</link><guid isPermaLink="false">cst-3148</guid><description>A Flare researcher analyzed ransomware leak-site activity targeting healthcare organizations across the EMEA region from 2024 to 2026 and found that ransomware groups are systematically attacking the entire healthcare supply chain, not just hospitals. The attacks extend beyond hospitals and clinics to include telemedicine providers, diagnostic laboratories, pharmacies, and other ecosystem participants. While hospital breaches receive media attention, attacks on peripheral healthcare entities often remain unreported despite comparable damage.</description><pubDate>Fri, 24 Jul 2026 05:30:33 GMT</pubDate></item><item><title>Ransomware in 2026: More groups, more victims, no slowdown</title><link>https://helpnetsecurity.com/2026/07/24/ransomware-attack-trends-2026-report</link><guid isPermaLink="false">cst-3150</guid><description>Black Kite's 2026 Ransomware Report finds a fragmented ransomware landscape with 61 new groups entering the market between April 2025 and March 2026, averaging more than one new group per week. Unlike previous years defined by dominant actors or major incidents, 2026 shows multiple ransomware playbooks scaling simultaneously with no signs of slowdown.</description><pubDate>Fri, 24 Jul 2026 04:30:22 GMT</pubDate></item><item><title>Ransomware is the Scoreboard</title><link>https://recordedfuture.com/blog/ransomware-is-the-scoreboard</link><guid isPermaLink="false">cst-3190</guid><description>Recorded Future documented 13,000 ransomware victims over two years, with groups like Interlock and RansomHub continuing successful attacks despite existing defensive technologies such as attack path management tools. The article argues that defenders struggle because they focus on compliance checklists and vulnerability lists rather than modeling their environment as an interconnected graph of assets, configurations, and credentials that attackers actually traverse, and proposes that AI agents continuously recomputing attack paths at adversarial speed could improve defense.</description><pubDate>Fri, 24 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Chaos ransomware's msaRAT: Living off the browser to build a covert C2 channel</title><link>https://blog.talosintelligence.com/chaos-msarat-living-off-the-browser-to-build-covert-c2-channel</link><guid isPermaLink="false">cst-3081</guid><description>Cisco Talos discovered msaRAT, a Rust-based remote access trojan attributed to the Chaos ransomware group that establishes command-and-control communications exclusively through Chrome DevTools Protocol rather than direct network connections. The malware is delivered via a malicious MSI installer disguised as a Windows update and leverages the browser, Cloudflare Workers, and Twilio TURN relays to create a covert WebRTC DataChannel for C2 communications. Chaos is a ransomware-as-a-service group active since February 2025 that uses phishing, vishing, and legitimate tools for post-compromise activities before deploying encryption.</description><pubDate>Thu, 23 Jul 2026 10:00:38 GMT</pubDate></item><item><title>Ransomware Attack Puts a Chill On Japanese Frozen-Food Chain</title><link>https://darkreading.com/cyberattacks-data-breaches/ransomware-attack-japanese-frozen-food-chain</link><guid isPermaLink="false">cst-3055</guid><description>A cyberattack on a Japanese food and logistics company disrupted frozen food distribution to thousands of clients, including major restaurant chains such as Kentucky Fried Chicken. The incident affected supply chains across multiple food service operators dependent on the firm's distribution network.</description><pubDate>Thu, 23 Jul 2026 01:00:00 GMT</pubDate></item><item><title>Swiss train maker Stadler refuses Everest $12 million ransomware demand</title><link>https://therecord.media/stadler-refuses-everest-ransom-demand</link><guid isPermaLink="false">cst-3075</guid><description>Stadler Rail, a Swiss train manufacturer, declined to pay a $12.3 million ransom demand from cybercriminals who obtained technical data through a compromised supplier's file-sharing platform.</description><pubDate>Wed, 22 Jul 2026 23:00:00 GMT</pubDate></item><item><title>Swiss rail giant Stadler rejects $12.3M ransom demand after cyberattack</title><link>https://bleepingcomputer.com/news/security/swiss-rail-giant-stadler-rejects-123m-ransom-demand-after-cyberattack</link><guid isPermaLink="false">cst-3032</guid><description>Swiss rail manufacturer Stadler Rail was targeted by the Everest ransomware group, which demanded $12.3 million following a breach of a shared data exchange platform with a supplier. Stadler has rejected the ransom demand. The incident affected the company's IT systems and exposed sensitive business information.</description><pubDate>Wed, 22 Jul 2026 16:59:17 GMT</pubDate></item><item><title>Ransomware Does Not Pause While You Figure Out Who Is in Charge</title><link>https://halcyon.ai/blog/ransomware-response-authority-who-is-in-charge</link><guid isPermaLink="false">cst-3031</guid><description>Organizations face simultaneous decision-making pressures when ransomware incidents occur outside business hours, requiring clear cross-functional authority structures to respond effectively. The article outlines the need for defined ownership across multiple response tracks to avoid delays and coordination failures during critical incidents.</description><pubDate>Wed, 22 Jul 2026 15:45:20 GMT</pubDate></item><item><title>Japanese food logistics giant recovers as extortion group claims cyberattack</title><link>https://therecord.media/nichirei-japan-food-logistics-cyberattack-recovery</link><guid isPermaLink="false">cst-3020</guid><description>Nichirei Logistics Group, a major Japanese food distribution company, has restored warehouse operations and frozen food shipments following a disruption. A cybercriminal group claimed responsibility for causing the incident through a cyberattack.</description><pubDate>Wed, 22 Jul 2026 15:40:00 GMT</pubDate></item><item><title>How enterprise GenAI can amplify ransomware risk — and how to contain it</title><link>https://bleepingcomputer.com/news/security/how-enterprise-genai-can-amplify-ransomware-risk-and-how-to-contain-it</link><guid isPermaLink="false">cst-3011</guid><description>Enterprise generative AI systems can amplify ransomware risk when AI assistants inherit excessive permissions or operate with compromised identities. Organizations can mitigate this exposure through identity controls, governance frameworks, and least-privilege access models that balance security with AI adoption.</description><pubDate>Wed, 22 Jul 2026 15:30:00 GMT</pubDate></item><item><title>If you pay a hacker’s ransom, chances are that they’ll come back for more</title><link>https://techcrunch.com/2026/07/22/if-you-pay-a-hackers-ransom-chances-are-that-theyll-come-back-for-more</link><guid isPermaLink="false">cst-3028</guid><description>Security researchers observe that paying ransoms to attackers creates perverse incentives, as threat actors have no genuine reason to cease targeting an organization once payment is made. The dynamic mirrors traditional extortion, where capitulation signals vulnerability rather than resolution.</description><pubDate>Wed, 22 Jul 2026 15:29:41 GMT</pubDate></item><item><title>Greedy ransomware crews return for seconds after victims cough up first extortion payments</title><link>https://databreaches.net/2026/07/22/greedy-ransomware-crews-return-for-seconds-after-victims-cough-up-first-extortion-payments?pk_campaign=feed&amp;pk_kwd=greedy-ransomware-crews-return-for-seconds-after-victims-cough-up-first-extortion-payments</link><guid isPermaLink="false">cst-3027</guid><description>A Proofpoint survey of UK organizations found that 58 percent of those hit by ransomware paid the initial extortion demand. Among organizations that paid, 22 percent were targeted again by the same or different threat actors seeking additional payments.</description><pubDate>Wed, 22 Jul 2026 14:34:35 GMT</pubDate></item><item><title>Human-in-the-Loop vs Human-on-the-Loop: What's the Difference?</title><link>https://reliaquest.com/blog/human-in-the-loop-vs-human-on-the-loop</link><guid isPermaLink="false">cst-3203</guid><description>The article contrasts human-in-the-loop and human-on-the-loop oversight models for AI-driven security operations centers (SOCs). Human-in-the-loop, which requires analyst approval for every AI action, creates bottlenecks at scale when SOCs handle thousands of daily alerts. Human-on-the-loop, where AI acts autonomously while humans monitor and can intervene, offers better efficiency for mid-risk, reversible decisions while reserving human pre-approval for irreversible, high-consequence actions like system isolation.</description><pubDate>Wed, 22 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Police dismantle Kratos phishing platform, arrest developer</title><link>https://bleepingcomputer.com/news/security/police-dismantle-kratos-phishing-platform-arrest-developer</link><guid isPermaLink="false">cst-2969</guid><description>German and US authorities dismantled the Kratos phishing-as-a-service platform and arrested its developer in Indonesia. The operation targeted the infrastructure supporting a platform that enabled phishing campaigns globally. Law enforcement cooperation disrupted a significant threat delivery mechanism.</description><pubDate>Tue, 21 Jul 2026 23:07:33 GMT</pubDate></item><item><title>Ransomware Is Accelerating, But It's Not Because of AI</title><link>https://darkreading.com/cyberattacks-data-breaches/ransomware-is-accelerating-not-ai</link><guid isPermaLink="false">cst-2964</guid><description>Researchers attribute the acceleration of ransomware attacks to ecosystem fragmentation, new threat actors entering the market, and expanding targeting of organizations with weaker defenses, rather than artificial intelligence-driven acceleration.</description><pubDate>Tue, 21 Jul 2026 21:48:05 GMT</pubDate></item><item><title>Anubis ransomware claims Coca-Cola Fairlife attack, threatens data leak</title><link>https://bleepingcomputer.com/news/security/anubis-ransomware-claims-coca-cola-fairlife-attack-threatens-data-leak</link><guid isPermaLink="false">cst-2950</guid><description>The Anubis ransomware group has claimed responsibility for a cyberattack against Fairlife, a Coca-Cola subsidiary, and has threatened to leak allegedly stolen corporate data if a ransom is not paid.</description><pubDate>Tue, 21 Jul 2026 18:50:54 GMT</pubDate></item><item><title>Kenya probes hack of president's website after bitcoin ransom demand</title><link>https://therecord.media/kenya-probes-hack-of-presidents-website-after-ransom-demand</link><guid isPermaLink="false">cst-2908</guid><description>Kenya's presidential website was compromised on Saturday, with attackers replacing the homepage with a message demanding bitcoin and threatening to release unspecified information about President William Ruto. The incident prompted a government investigation into the unauthorized access.</description><pubDate>Tue, 21 Jul 2026 12:08:00 GMT</pubDate></item><item><title>Critical Palo Alto VPN bug now exploited by Qilin ransomware gang</title><link>https://bleepingcomputer.com/news/security/critical-globalprotect-vpn-bug-now-exploited-in-ransomware-attacks</link><guid isPermaLink="false">cst-2883</guid><description>The Qilin ransomware group is actively exploiting a critical authentication bypass vulnerability in Palo Alto Networks PAN-OS GlobalProtect to gain initial access to target networks. Arctic Wolf researchers documented this threat actor leveraging the flaw as part of their attack chain.</description><pubDate>Tue, 21 Jul 2026 10:12:24 GMT</pubDate></item><item><title>JadePuffer agentic attacks now target AI model data with ransomware</title><link>https://bleepingcomputer.com/news/security/jadepuffer-agentic-attacks-now-target-ai-model-data-with-ransomware</link><guid isPermaLink="false">cst-2870</guid><description>JadePuffer, an autonomous AI agent, has been updated with a custom malware tool named EncForge designed to encrypt AI-specific assets including training datasets, vector databases, and model checkpoints. This development represents an expansion of the threat beyond general systems to infrastructure critical to machine learning operations.</description><pubDate>Mon, 20 Jul 2026 21:08:02 GMT</pubDate></item><item><title>Pay up or not? Ransomware surge has victims facing tough choices</title><link>https://arstechnica.com/security/2026/07/pay-up-or-not-ransomware-surge-has-victims-facing-tough-choices</link><guid isPermaLink="false">cst-2850</guid><description>Sophos research shows that nearly half of targeted companies pay ransoms, with median demands increasing. The UK government is advancing legislation to prohibit public sector bodies and critical national infrastructure, including the NHS, councils, and schools, from making ransom payments as attackers grow more sophisticated in targeting vulnerable organizations.</description><pubDate>Mon, 20 Jul 2026 14:00:50 GMT</pubDate></item><item><title>Inc Ransomware Exploits SonicWall SMA Zero-Days</title><link>https://darkreading.com/vulnerabilities-threats/inc-ransomware-exploits-sonicwall-sma-zero-days</link><guid isPermaLink="false">cst-2785</guid><description>Two zero-day vulnerabilities in SonicWall Secure Mobile Access (SMA) appliances can be chained together to grant attackers root-level access. The Inc ransomware group is actively exploiting these flaws against targeted organizations.</description><pubDate>Fri, 17 Jul 2026 20:01:13 GMT</pubDate></item><item><title>Spirals ransomware locks down victim systems in under 24 hours</title><link>https://helpnetsecurity.com/2026/07/17/spirals-ransomware-south-asia</link><guid isPermaLink="false">cst-2763</guid><description>Symantec researchers discovered a previously unknown ransomware variant called Spirals used in an attack against an IT services company in South Asia last month. The attackers achieved data theft and network encryption in under 24 hours from initial access. Spirals is written in Rust and uses AES-128 encryption with per-file keys wrapped using ECDH.</description><pubDate>Fri, 17 Jul 2026 12:25:24 GMT</pubDate></item><item><title>Armenia Detains Russian Tourist on U.S. Warrant for REvil Hacker, Lawyers Say Wrong Man</title><link>https://thehackernews.com/2026/07/armenia-detains-russian-tourist-on-us.html</link><guid isPermaLink="false">cst-2754</guid><description>Armenia detained a Russian tourist named Aleksandr Ermakov at Yerevan airport on June 28 based on a U.S. extradition request for a REvil ransomware suspect also named Aleksandr Ermakov. His wife and legal representatives claim the detained individual is the wrong person, as the name match appears coincidental rather than evidence of identity.</description><pubDate>Fri, 17 Jul 2026 10:53:31 GMT</pubDate></item><item><title>Coca-Cola says Fairlife ransomware attack halts US dairy production</title><link>https://bleepingcomputer.com/news/security/coca-cola-says-fairlife-ransomware-attack-halts-us-dairy-production</link><guid isPermaLink="false">cst-2726</guid><description>Coca-Cola disclosed that a ransomware attack on its Fairlife dairy subsidiary has disrupted US operations and temporarily halted production of Fairlife products. The attack impacts supply chains for a major dairy brand sold nationwide.</description><pubDate>Thu, 16 Jul 2026 21:09:41 GMT</pubDate></item><item><title>Ransomware and Cyber Extortion in Q2 2026</title><link>https://reliaquest.com/blog/threat-spotlight-ransomware-and-cyber-extortion-in-q2-2026</link><guid isPermaLink="false">cst-2690</guid><description>A ransomware threat report covering Q2 2026 activity found that group rankings shifted significantly, with "The Gentlemen" claiming the top spot while previously dominant groups like Qilin and DragonForce declined. Notable developments include Deadlock's resurgence with blockchain-based command and control and kernel-level endpoint detection and response (EDR) evasion techniques, alongside steady targeting patterns favoring professional, scientific, and technical services sectors across 90 groups in 99 countries. Despite quarterly fluctuations in victim counts, underlying attack techniques remained consistent, with the US absorbing approximately 49 percent of victim activity.</description><pubDate>Thu, 16 Jul 2026 18:00:00 GMT</pubDate></item><item><title>The Real Cost of Ransomware Is What Cripples the Business</title><link>https://halcyon.ai/blog/ransomware-real-cost</link><guid isPermaLink="false">cst-2724</guid><description>A new analysis reveals that financial executives significantly underestimate ransomware expenses, typically by a factor of ten or more. The article examines the actual cost calculation methodology and explains why standard risk assessments fail to capture the true financial impact of ransomware incidents.</description><pubDate>Thu, 16 Jul 2026 16:54:36 GMT</pubDate></item><item><title>ThreatsDay: Game Cheat Spyware, 24-Hour Ransomware, Chrome Sync Stalking + 12 More Stories</title><link>https://thehackernews.com/2026/07/threatsday-game-cheat-spyware-24-hour.html</link><guid isPermaLink="false">cst-2694</guid><description>This week's security news covers multiple attack vectors including game cheat spyware, rapid ransomware deployment, and Chrome synchronization exploitation for surveillance. The stories highlight how attackers leverage seemingly legitimate tools, weak configurations, and straightforward attack paths to compromise systems and escalate damage.</description><pubDate>Thu, 16 Jul 2026 15:41:15 GMT</pubDate></item><item><title>Scattered Spider members behind TfL hack get five years in prison</title><link>https://bleepingcomputer.com/news/security/scattered-spider-members-behind-transport-for-london-hack-get-five-years-in-prison</link><guid isPermaLink="false">cst-2667</guid><description>Two prominent members of the Scattered Spider cybercrime group received sentences of five years and six months each for conducting a hack against Transport for London in 2024. The sentences represent judicial action against key figures in the criminal collective responsible for the intrusion.</description><pubDate>Thu, 16 Jul 2026 12:31:29 GMT</pubDate></item><item><title>New Spirals ransomware encrypts victim network in under 24 hours</title><link>https://bleepingcomputer.com/news/security/new-spirals-ransomware-encrypts-victim-network-in-under-24-hours</link><guid isPermaLink="false">cst-2651</guid><description>A previously unknown ransomware actor named Spirals has demonstrated the ability to compromise a corporate network and complete encryption within a single day. The speed of the attack, from initial access through data theft to full encryption, indicates a highly efficient operational capability.</description><pubDate>Thu, 16 Jul 2026 10:00:00 GMT</pubDate></item><item><title>Srsly Risky Biz: Ransomware Uses AI To Amp Up Negotiations</title><link>https://risky.biz/srsly-risky-biz-ransomware-uses-ai-to-amp-up-negotiations</link><guid isPermaLink="false">cst-2664</guid><description>Ransomware operators are leveraging AI not primarily to conduct breaches but to strengthen negotiation tactics with victims to demand higher ransoms. FulcrumSec, a data extortion group active since September 2025, exploits basic security gaps such as hardcoded credentials, unpatched software, and misconfigured storage to breach organizations, claiming over 25 victims and multiple terabytes of stolen data.</description><pubDate>Thu, 16 Jul 2026 07:32:27 GMT</pubDate></item><item><title>Identity Attacks Overtake Exploits as Top Ransomware Cause</title><link>https://darkreading.com/identity-access-management-security/identity-attacks-overtake-exploits-top-ransomware-cause</link><guid isPermaLink="false">cst-2635</guid><description>Email attacks became the leading ransomware entry vector in the past year, surpassing exploitation of software vulnerabilities. Multifactor authentication (MFA) was present in 97% of credential-based attacks but did not prevent successful compromises.</description><pubDate>Wed, 15 Jul 2026 20:16:13 GMT</pubDate></item><item><title>Spanish Police take down €140 million cyber fraud ring, arrest four</title><link>https://bleepingcomputer.com/news/security/spanish-police-take-down-140-million-cyber-fraud-ring-arrest-four</link><guid isPermaLink="false">cst-2528</guid><description>Spanish police dismantled a cybercrime organization responsible for approximately 140 million euros in losses through investment fraud and business email compromise attacks. The operation resulted in four arrests and targeted money-laundering infrastructure used to conceal criminal proceeds.</description><pubDate>Tue, 14 Jul 2026 20:23:09 GMT</pubDate></item><item><title>Synopsys Finds No Evidence of Data Breach Amid Bosch Hack Claims</title><link>https://securityweek.com/synopsys-finds-no-evidence-of-data-breach-following-bosch-hack-claims</link><guid isPermaLink="false">cst-2518</guid><description>The D1R cybercrime group claimed to have stolen data from Synopsys and Bosch and threatened to leak it unless paid a ransom. Synopsys investigated the claim and found no evidence supporting a data breach at the company.</description><pubDate>Tue, 14 Jul 2026 18:18:45 GMT</pubDate></item><item><title>VPN service favored by ransomware groups is sanctioned by US</title><link>https://therecord.media/first-vpn-administrator-us-sanctions-ransomware-groups</link><guid isPermaLink="false">cst-2436</guid><description>The U.S. Treasury Department sanctioned First VPN Service (1VPNS) and its Ukrainian administrator for facilitating ransomware operations. In a separate action, a Belarusian individual was also sanctioned for distributing malware encryption tools.</description><pubDate>Mon, 13 Jul 2026 18:50:00 GMT</pubDate></item><item><title>⚡ Weekly Recap: ShareFile Threat, Citrix Bleed 2 Ransomware, AI Coding Attacks, and More</title><link>https://thehackernews.com/2026/07/weekly-recap-sharefile-threat-citrix.html</link><guid isPermaLink="false">cst-2414</guid><description>A weekly security recap highlights multiple threats including ShareFile vulnerabilities, Citrix Bleed 2 ransomware activity, and AI-powered coding attacks. The piece emphasizes that while security tools automate vulnerability discovery, attackers similarly leverage automation to find and exploit weaknesses, and many organizations remain unpatched against known issues from prior years.</description><pubDate>Mon, 13 Jul 2026 15:05:57 GMT</pubDate></item><item><title>Ransomware negotiator who conspired with BlackCat threat actors sentenced to 70 months in prison</title><link>https://databreaches.net/2026/07/11/ransomware-negotiator-who-conspired-with-blackcat-threat-actors-sentenced-to-70-months-in-prison?pk_campaign=feed&amp;pk_kwd=ransomware-negotiator-who-conspired-with-blackcat-threat-actors-sentenced-to-70-months-in-prison</link><guid isPermaLink="false">cst-2365</guid><description>A former ransomware negotiator employed by DigitalMint has been sentenced to 70 months in prison for conspiring with BlackCat threat actors. The negotiator provided BlackCat with inside information about victims' defense strategies, enabling the group to extort the companies he was hired to protect. This represents the third co-conspirator in the scheme to face sentencing.</description><pubDate>Sat, 11 Jul 2026 13:06:25 GMT</pubDate></item><item><title>No Manners Here: The Ruthless Rise of The Gentlemen Ransomware</title><link>https://unit42.paloaltonetworks.com/the-gentlemen-ransomware</link><guid isPermaLink="false">cst-2355</guid><description>Unit 42 published analysis of The Gentlemen ransomware operations and its affiliate model structure that has enabled rapid expansion. The report examines how the group's business model has driven its growth in the threat landscape.</description><pubDate>Fri, 10 Jul 2026 22:00:39 GMT</pubDate></item><item><title>Ryuk ransomware member pleads guilty in the US, faces 15 years in prison</title><link>https://bleepingcomputer.com/news/security/ryuk-ransomware-member-pleads-guilty-in-the-us-faces-15-years-in-prison</link><guid isPermaLink="false">cst-2341</guid><description>A 34-year-old Armenian national pleaded guilty to hacking U.S. companies and deploying Ryuk ransomware to encrypt their systems. The defendant faces up to 15 years in prison as part of a U.S. prosecution. This case represents a law enforcement action against a member of the ransomware-as-a-service operation.</description><pubDate>Fri, 10 Jul 2026 17:46:10 GMT</pubDate></item><item><title>Ryuk operator pleads guilty; Blackcat/AlphV conspirator gets nearly 6-year sentence</title><link>https://therecord.media/ryuk-operator-pleads-guilty-alphv-conspirator-sentenced</link><guid isPermaLink="false">cst-2346</guid><description>A Ryuk ransomware operator pleaded guilty to conspiracy and computer fraud in Oregon federal court, while a separate defendant received a 70-month federal prison sentence in Florida for assisting the Blackcat/AlphV ransomware gang in extortion campaigns against multiple victims.</description><pubDate>Fri, 10 Jul 2026 17:01:00 GMT</pubDate></item><item><title>In Other News: DHS Database Hacked, Adobe Boosts Patch Cadence, Canada Disrupts Ransomware Ops</title><link>https://securityweek.com/in-other-news-dhs-database-hacked-adobe-boosts-patch-cadence-canada-disrupts-ransomware-ops</link><guid isPermaLink="false">cst-2335</guid><description>This news roundup mentions several security stories: a breach of a Department of Homeland Security database, Adobe increasing its patch release frequency, and Canadian authorities disrupting ransomware operations. The article also references a lawsuit between Abnormal AI and Anthropic, a data breach affecting 7 million AssuranceAmerica customers, and the NSA reactivating its Tailored Access Operations unit.</description><pubDate>Fri, 10 Jul 2026 15:01:19 GMT</pubDate></item><item><title>Former DigitalMint ransomware negotiator who duped clients sentenced to 70 months in jail</title><link>https://cyberscoop.com/digitalmint-ransomware-negotiator-angelo-martino-sentenced</link><guid isPermaLink="false">cst-2283</guid><description>Angelo John Martino III, a ransomware negotiator at DigitalMint, was sentenced to 70 months in prison for conspiring with BlackCat affiliates to extort $75.3 million from five U.S. companies he was hired to help during ransomware incidents. Martino shared confidential negotiating positions and insurance policy limits with his co-conspirators to maximize ransom demands, effectively playing both sides of negotiations between April and September 2023. His co-conspirators, including fellow DigitalMint negotiator Kevin Tyler Martin and Sygnia incident response manager Ryan Clifford Goldberg, received four-year sentences for their roles in deploying BlackCat ransomware against additional victims.</description><pubDate>Fri, 10 Jul 2026 00:16:13 GMT</pubDate></item><item><title>New GigaWiper Windows Backdoor Bundles Disk Wiping, Fake Ransomware, and Spyware</title><link>https://thehackernews.com/2026/07/new-gigawiper-windows-backdoor-bundles.html</link><guid isPermaLink="false">cst-2268</guid><description>Microsoft identified a Windows backdoor called GigaWiper that combines three destructive capabilities: disk wiping, Windows drive overwriting, and fake ransomware that scrambles files without saving decryption keys. The malware operates as a modular tool, allowing operators to select which destructive method to deploy on compromised machines.</description><pubDate>Thu, 09 Jul 2026 18:08:07 GMT</pubDate></item><item><title>Latvian forestry company still restoring systems weeks after ransomware attack</title><link>https://therecord.media/latvia-state-owned-foresty-company-lvm-ransomware</link><guid isPermaLink="false">cst-2256</guid><description>A financially motivated foreign group carried out a ransomware attack on Latvijas Valsts Mezi (LVM), Latvia's state-owned forestry company, and the organization was still in recovery weeks after the incident.</description><pubDate>Thu, 09 Jul 2026 14:20:00 GMT</pubDate></item><item><title>GodDamn Ransomware Uses PoisonX Driver to Disable Endpoint Defenses</title><link>https://thehackernews.com/2026/07/goddamn-ransomware-uses-poisonx-driver.html</link><guid isPermaLink="false">cst-2239</guid><description>Security researchers identified a new ransomware family called GodDamn that uses a kernel driver called PoisonX to disable endpoint security software. The ransomware was first observed in May 2026 and is believed to be a rebranded variant of Beast ransomware.</description><pubDate>Thu, 09 Jul 2026 10:43:09 GMT</pubDate></item><item><title>'GodDamn' Ransomware Uses BYOVD to Smite US Companies</title><link>https://darkreading.com/cyberattacks-data-breaches/goddamn-ransomware-byovd-smite-companies</link><guid isPermaLink="false">cst-2229</guid><description>A malicious kernel driver co-signed by Microsoft is being exploited in ransomware attacks targeting US companies to disable security software. The driver is associated with a ransomware variant named GodDamn. Attackers are leveraging this bring-your-own-vulnerable-driver (BYOVD) technique to gain kernel-level access and bypass endpoint protection.</description><pubDate>Thu, 09 Jul 2026 10:00:00 GMT</pubDate></item><item><title>Cybersecurity and the Gap Between Skill and Ability</title><link>https://schneier.com/blog/archives/2026/07/cybersecurity-and-the-gap-between-skill-and-ability.html</link><guid isPermaLink="false">cst-2165</guid><description>Five Eyes national security agencies warned of growing cyber risks from artificial intelligence models capable of autonomous system attacks and network compromise. The article argues that AI has widened the gap between skill and ability, enabling individuals without deep technical expertise to conduct sophisticated cyberattacks similar to how pre-written hacking tools once democratized attack capabilities. The author contends that guardrails and monitoring of AI systems will prove insufficient as open-source models proliferate beyond corporate control.</description><pubDate>Wed, 08 Jul 2026 11:03:04 GMT</pubDate></item></channel></rss>