Ransomware Security News

Ransomware attacks, extortion group activity, victim disclosures and decryptor releases.

Ransomware encrypts — or threatens to leak — an organization's data until a ransom is paid. It has grown into an industrialized criminal ecosystem with named extortion groups, leak sites and affiliate programs. Expect new attack claims, victim disclosures, law-enforcement takedowns, and the occasional free decryptor release: the same group often rebrands or splinters within months.

Recent Ransomware items

Japan's Keio confirms ransomware attack disrupted business systems Keio Corporation (Keio), a major private railway operator in Japan, said its network was hit by a ransomware attack over the weekend,…
@bleepingcomputer · Sep 28, 2026
Japan's Keio confirms ransomware attack disrupted business systems https://ift.tt/oKYRTap
@ctinow · Sep 28, 2026
Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation ♟️ Authorities in the Netherlands have arrested a 23yearold convicted cybercriminal on suspicion of aiding in data thefts and extor…
@cibsecurity · Sep 28, 2026
be me > get dm > "Smelly, you said you accidentally executed an information stealer on your PC. What happens if you accidentally executed ransomware on your PC?" p much this tbh (ive done it before wi…
@vxunderground · Sep 28, 2026
JadePuffer agentic AI attacks target Azure, destroy cloud resources The JadePuffer ransomware operator is targeting Azure tenants with agent-driven attacks that conduct reconnaissance, steal credentia…
@bleepingcomputer · Sep 28, 2026
THIS WEEK IN CYBER... > $387M crypto hack > Citrix flaws exploited > AI agents hacking sites > 1.7K-repo domain trap > 5.7K M365 accounts targeted > EvilTokens taken down > TeamCity abused in ransomwa…
@thehackernews · Sep 28, 2026
Cyber Alert ‼️ 🇯🇵 Japan - 𝗞𝗲𝗶𝗼 𝗖𝗼𝗿𝗽𝗼𝗿𝗮𝘁𝗶𝗼𝗻 (𝗞𝗲𝗶𝗼 𝗘𝗹𝗲𝗰𝘁𝗿𝗶𝗰 𝗥𝗮𝗶𝗹𝘄𝗮𝘆) Keio Corporation (Keio Electric Railway) disclosed that it detected a ransomware attack against servers belonging to the Keio Group i…
@hackmanac_cybernews · Sep 27, 2026
Exploit.in Database Reveals the Roots of Today’s Ransomware Ecosystem https://securityaffairs.com/199800/cyber-crime/exploit-in-database-reveals-the-roots-of-todays-ransomware-ecosystem.html
@PentestingNews · Sep 26, 2026
Exploit.in Database Reveals the Roots of Today’s Ransomware Ecosystem https://ift.tt/JlGxVQI
@ctinow · Sep 26, 2026
Cyber Alert ‼️ 🇮🇹 Italy - 𝗔.𝗣.𝗦.𝗣. 𝗦𝗮𝗻 𝗚𝗮𝗲𝘁𝗮𝗻𝗼 A.P.S.P. San Gaetano suffered a cyberattack involving a ransom demand that disrupted access to IT systems, medical records, treatment information and tel…
@hackmanac_cybernews · Sep 26, 2026
Using Threat Intelligence to Stop Ransomware Attacks https://ift.tt/NVjhoHp
@ctinow · Sep 25, 2026
ShinyHunters hacked Clop leak site using Grav CMS path traversal flaw The Clop ransomware gang has moved its data leak site to a new Tor address after confirming its previous server was compromised an…
@bleepingcomputer · Sep 25, 2026
ShinyHunters hacked Clop leak site using Grav CMS path traversal flaw https://ift.tt/y1X8U67
@ctinow · Sep 25, 2026
In Other News: Clop Leak Site Takeover, Docker Botnet Hunts AI Keys, Water Utility Exposure https://ift.tt/Au4PoFO
@ctinow · Sep 25, 2026
Cyber Alert ‼️ 🇲🇦 Morocco - 𝗣𝗵𝗮𝗿𝗺𝗮 𝟱 INC Ransom claims to have breached Pharma 5, allegedly exfiltrating 50 GB of data related to corporate and financial information, products and supply, quality cont…
@hackmanac_cybernews · Sep 25, 2026
Microsoft Finds Ransomware Group Using Same Attack Blueprint Across Multiple Malware Families https://ift.tt/KnUky2a
@ctinow · Sep 25, 2026
Ryuk Member Karen Vardanyan Sentenced to Two Years in U.S. Prison https://securityaffairs.com/199692/cyber-crime/ryuk-member-karen-vardanyan-sentenced-to-two-years-in-u-s-prison.html
@PentestingNews · Sep 25, 2026
Cyber Alert ‼️ 🇮🇹 Italy - 𝗡𝗘𝗔𝗗 𝗣𝗿𝗼 – 𝗣𝗿𝗼𝗳𝗲𝘀𝘀𝗶𝗼𝗻𝗶𝘀𝘁𝗶 𝗿𝗶𝘂𝗻𝗶𝘁𝗶 The Rhysida ransomware group claims to have breached NEAD Pro, a professional network based in Gorizia and Udine, Italy, providing legal, ac…
@hackmanac_cybernews · Sep 25, 2026
Ryuk Member Karen Vardanyan Sentenced to Two Years in U.S. Prison https://ift.tt/2gLqINC
@ctinow · Sep 24, 2026
Storm-2570 Uses Four Ransomware Brands—and the Same Access Tools Changing the ransomware name does not necessarily mean changing the attacker. Microsoft’s September 24 investigation links Storm-2570 t…
@topcybersecurity · Sep 24, 2026
Beyond the ransomware: Tracking Storm-2570’s consistent tradecraft across deployments https://ift.tt/kwsA82B
@ctinow · Sep 24, 2026
Ukrainian ransomware developer jailed for nearly 13 years https://ift.tt/WXYeSZt
@ctinow · Sep 24, 2026
CISA: Ransomware gangs now exploiting critical TeamCity flaw The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned federal agencies on Wednesday that ransomware gangs are now also ex…
@bleepingcomputer · Sep 24, 2026
CISA: Ransomware gangs now exploiting critical TeamCity flaw https://ift.tt/QkqUghL
@ctinow · Sep 24, 2026
New Galago Ransomware Operation Emerges With Links to Panzer Extortion Group https://gbhackers.com/galago-ransomware-operation/
@PentestingNews · Sep 24, 2026
US Court Sentences Armenian Man to Prison for Ryuk Ransomware Attacks https://ift.tt/zpsLSF1
@ctinow · Sep 24, 2026
Ryuk ransomware operator sentenced to 2 years in prison https://cyberscoop.com/ryuk-ransomware-operator-karen-vardanyan-sentenced/
@PentestingNews · Sep 24, 2026
CVE-2026-11744 An input validation vulnerability exists in the PaperCut Hive embedded application for Ricoh devices. The application fails to properly sanitize input received during the NFC card readi…
@cveNotify · Sep 24, 2026
Ryuk ransomware operator sentenced to 2 years in prison https://ift.tt/QtuglMz
@ctinow · Sep 23, 2026
Cyber Alert ‼️ 🇸🇮 Slovenia - 𝗛𝗜𝗧 𝗱.𝗱. 𝗡𝗼𝘃𝗮 𝗚𝗼𝗿𝗶𝗰𝗮 Akira hacking group claims to have breached HIT. According to the post, the group claims to have stolen 367 GB of corporate data, allegedly including…
@hackmanac_cybernews · Sep 23, 2026

Other topics

CVE
Recent CVE identifiers and vulnerability disclosures aggregated from security feeds: new IDs, published advisories, and the vendors and products they affect.
Phishing
Phishing campaigns, credential-harvesting kits, and social-engineering techniques used to compromise users and organizations.
Zero-Day
Zero-day vulnerabilities being actively exploited before a patch exists, and the fixes that follow.
Data Breach
Confirmed and reported data breaches: what was exposed, which organizations were affected, and how the incident came to light.
Exploit
Public exploit code, proof-of-concept releases, and technical exploitation write-ups for known vulnerabilities.
Patch
Vendor patches, security updates and fix releases for previously disclosed vulnerabilities.