Ransomware Security News

Ransomware attacks, extortion group activity, victim disclosures and decryptor releases tracked as they are reported.

Ransomware encrypts — or threatens to leak — an organization's data until a ransom is paid, and has grown into an industrialized criminal ecosystem with named extortion groups, leak sites and affiliate programs. This feed follows new attack claims, victim disclosures, law-enforcement takedowns and the occasional free decryptor release. It is a fast-moving space: the same group often rebrands or splinters within months.

Recent Ransomware items

Shell investigates 'potential incident' after Clop data theft claimshttps://ift.tt/13ABYJg
@ctinow · Aug 14, 2026
When You Pay the Ransom - Taking Apart an Interlock ESXi Decryptor | Maldbg - Malware Analysis BlogTaking apart a freshly compiled Interlock ESXi decryptor, and what it reveals about how the encryptor…
@malwr · Aug 14, 2026
Akira hackers disable EDR with Safe Mode, steal data but fail to encrypthttps://ift.tt/GSmFypP
@ctinow · Aug 13, 2026
The State of Ransomware Q2 2026https://ift.tt/ybcXJ04
@ctinow · Aug 13, 2026
Akira Ransomware Affiliate Rebooted Into Safe Mode to Dodge EDR and Broke Its Own Attackhttps://ift.tt/kwu3eI2
@ctinow · Aug 13, 2026
UK Cyber Attacks Jump 26% Year-on-Year as Ransomware Activity Doubles Globallyhttps://ift.tt/lbEeQni
@ctinow · Aug 13, 2026
Storm-1175 Replaces Medusa With New StormEncryptor Ransomwarehttps://securityaffairs.com/197119/malware/storm-1175-replaces-medusa-with-new-stormencryptor-ransomware.html
@PentestingNews · Aug 13, 2026
Storm-1175 Replaces Medusa With New StormEncryptor Ransomwarehttps://ift.tt/YcEXZRm
@ctinow · Aug 13, 2026
Ransomware Hits Colombian Justice Ministry Days Before Presidential Transitionhttps://ift.tt/9eJmlut
@ctinow · Aug 12, 2026
DeadLock ransomware uses blockchain to resist infrastructure takedownhttps://ift.tt/1BWzvD9
@ctinow · Aug 11, 2026
Gunra Ransomware Gang Exploits Fortinet Flaws, Bypasses MFAhttps://ift.tt/A2bCJet
@ctinow · Aug 11, 2026
DeadLock Ransomware Uses Polygon Smart Contracts to Make Extortion Infra Harder to Disrupthttps://ift.tt/wX0edji
@ctinow · Aug 11, 2026
DeadLock ransomware is making its extortion infrastructure harder to disrupt.It uses Polygon smart contracts to rotate victim-chat proxies, Session for encrypted communications, and blockchain-hosted…
@thehackernews · Aug 11, 2026
Q&A: Ransomware is now a ‘fully fledged industry’, says cybercrime journalist Geoff Whitehttps://ift.tt/8FWh9oY
@ctinow · Aug 11, 2026
CISA: Microsoft SharePoint flaw now exploited in ransomware attackshttps://ift.tt/5sigPxd
@ctinow · Aug 11, 2026
Gunra Ransomware Builds a New Attack Network Through RaaShttps://thecyberexpress.com/gunra-ransomware-expands-raas-operations/
@PentestingNews · Aug 11, 2026
Gunra Ransomware Exploits Fortinet and Schneider Electric Flaws to Breach Networkshttps://ift.tt/TwgobMc
@ctinow · Aug 11, 2026
US and South Korea warn of Gunra ransomware targeting govt agencieshttps://ift.tt/C5BVioq
@ctinow · Aug 11, 2026
Gunra ransomware breaches networks, steals data, and destroys backups.Attacks have exploited Fortinet FortiOS/FortiProxy and Schneider Electric PowerLogic P5 flaws for initial access, before encryptin…
@thehackernews · Aug 11, 2026
DeadLock Ransomware Disables Windows Defender, Backups and Event Logs Before Encrypting Fileshttps://gbhackers.com/deadlock-ransomware-attack/
@PentestingNews · Aug 11, 2026
CISA Urges Organizations to Patch Exposed VPNs and Segment Networks Against Gunra Ransomwarehttps://gbhackers.com/gunra-ransomware-attack/
@PentestingNews · Aug 11, 2026
U.S., South Korean government agencies caution to be on lookout for Gunra ransomware ganghttps://cyberscoop.com/us-south-korea-gunra-ransomware-warning/
@PentestingNews · Aug 11, 2026
U.S., South Korean government agencies caution to be on lookout for Gunra ransomware ganghttps://ift.tt/3BKupib
@ctinow · Aug 10, 2026
DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructurehttps://www.microsoft.com/en-us/security/blog/2026/08/10/deadlock-ransomware-breaking-down-a-rust-ba…
@PentestingNews · Aug 10, 2026
China-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flawhttps://ift.tt/2GimnXb
@ctinow · Aug 10, 2026
New StormEncryptor ransomware used by former Medusa affiliatehttps://ift.tt/ghtOuaS
@ctinow · Aug 10, 2026
China-linked Storm-1175 deploys previously undocumented StormEncryptor ransomware.Microsoft says the group has shifted from Medusa and likely used N-able N-central CVE-2026-18577 for initial access. S…
@thehackernews · Aug 10, 2026
StopRansomware: Gunra Ransomwarehttps://ift.tt/DHLkThp
@ctinow · Aug 10, 2026
DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructurehttps://ift.tt/FX7AwJr
@ctinow · Aug 10, 2026
Rogue AI • Metabase 0-day • Spectre bypass • Webmail attacks • Router backdoors • MCP supply-chain malware • 440 poisoned packages • AI token jacking • Device-code phishing • $30M crypto attacks • 26…
@thehackernews · Aug 10, 2026

Other topics

CVE
Recent CVE identifiers and vulnerability disclosures aggregated from security feeds — new CVE IDs, published advisories, and the vendors and products they affect.
Phishing
Phishing campaigns, credential-harvesting kits, and social-engineering techniques used to compromise users and organizations.
Zero-Day
Zero-day vulnerabilities being actively exploited before a patch exists, and the fixes that follow.
Data Breach
Confirmed and reported data breaches — what was exposed, which organizations were affected, and how the incident came to light.
Exploit
Public exploit code, proof-of-concept releases, and technical exploitation write-ups for known vulnerabilities.
Patch
Vendor patches, security updates and fix releases for previously disclosed vulnerabilities.