Ransomware Security News

Ransomware attacks, extortion group activity, victim disclosures and decryptor releases tracked as they are reported.

Ransomware encrypts — or threatens to leak — an organization's data until a ransom is paid, and has grown into an industrialized criminal ecosystem with named extortion groups, leak sites and affiliate programs. This feed follows new attack claims, victim disclosures, law-enforcement takedowns and the occasional free decryptor release. It is a fast-moving space: the same group often rebrands or splinters within months.

Recent Ransomware items

New Panzer Ransomware Hits 16 Victims Across 11 Countries With Data Theft and Encryption https://gbhackers.com/new-panzer-ransomware-hits-16-victim/
@PentestingNews · Sep 5, 2026
Attackers are exploiting a PaperCut authentication bypass and RCE chain against schools and universities in the U.S. and Europe.The attacks enable credential theft, privileged account creation, regist…
@thehackernews · Sep 5, 2026
CVE-2026-52691 ** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Griffin Hive Metastore Module. This issue af…
@cveNotify · Sep 4, 2026
This week’s ThreatsDay... 🧰 Real tools, wrong hands 🎣 Phishing for sale 🔗 Old access stays open 🤖 AI points to bad packages ⌨️ Typos open doors 🪪 ID data stolen 💥 Access becomes ransomware ⚙️ Weak set…
@thehackernews · Sep 3, 2026
Manchester Airports Group Data on 8.8 Million People Leaked After Ransom Refusal https://ift.tt/Fas43Sq
@ctinow · Sep 3, 2026
Ransomware protection for MSPs: A 6-point checklist for faster recovery https://ift.tt/cIGUEij
@ctinow · Sep 2, 2026
The Gentlemen Ransomware Hackers Use TukTuk C2 to Steal Credentials and Disable EDR Security https://gbhackers.com/tuktuk-c2-framework/
@PentestingNews · Sep 2, 2026
Stronger Security Drives Ransomware Groups to Recruit From Within https://ift.tt/UKGLsou
@ctinow · Sep 1, 2026
CVE-2026-74888 openssl_encrypt versions before 1.4.0 use a non-standard PBKDF2 key derivation construction with iterations=1 per call in an outer loop, creating a KDF whose security properties have no…
@cveNotify · Sep 1, 2026
Ransomware Gang Claims Nutex Health Data Breach https://ift.tt/WD6Ej51
@ctinow · Sep 1, 2026
CVE-2026-81704 openssl_encrypt versions before 1.4.9 contain a weak key derivation vulnerability in the D-Bus CryptoService.EncryptFile handler that uses unstretched SHA-256 instead of Argon2id. Attac…
@cveNotify · Aug 31, 2026
CVE-2026-74888 openssl_encrypt versions before 1.4.0 use a non-standard PBKDF2 key derivation construction with iterations=1 per call in an outer loop, creating a KDF whose security properties have no…
@cveNotify · Aug 31, 2026
Aurora Ransomware Hackers Use Cursor AI Agent for Hands-On Exploitation and ESXi Attacks https://gbhackers.com/cursor-ai-powered-ransomware/
@PentestingNews · Aug 31, 2026
Berlin confirms data theft after Rhysida ransomware attack claims https://www.bleepingcomputer.com/news/security/berlin-confirms-data-theft-after-rhysida-ransomware-attack-claims/
@PentestingNews · Aug 31, 2026
Trust did the damage this week.• AI agents breached Hugging Face• FBI disrupted Chinese spy proxies• Backdoors shipped in routers• PaperCut flaws came under attack• Fake IT support pushed ransomware•…
@thehackernews · Aug 31, 2026
Berlin confirms data theft after Rhysida ransomware attack claims https://ift.tt/tvjAVLZ
@ctinow · Aug 31, 2026
Aurora Ransomware Operators Use Cursor AI in Attacks Against 10 Targets https://ift.tt/8hJs2NC
@ctinow · Aug 31, 2026
Aurora ransomware operators gave Cursor AI credentials or an existing route into victim networks.The agent handled exploitation tasks against 10 targets, including network scanning, privilege checks,…
@thehackernews · Aug 31, 2026
Rhysida Ransomware Group Targets Berlin Government Ahead of Vote https://securityaffairs.com/198064/cyber-crime/rhysida-ransomware-group-targets-berlin-government-ahead-of-vote.html
@PentestingNews · Aug 29, 2026
Rhysida Ransomware Group Targets Berlin Government Ahead of Vote https://ift.tt/gsHN2JL
@ctinow · Aug 29, 2026
Berlin refuses to pay hackers after data was stolen from the city’s state network.Rhysida ransomware crew claims 5.79 TB of data and personal information on 12,076 people on its leak site, while Berli…
@thehackernews · Aug 28, 2026
CVE-2026-81704 openssl_encrypt versions before 1.4.9 contain a weak key derivation vulnerability in the D-Bus CryptoService.EncryptFile handler that uses unstretched SHA-256 instead of Argon2id. Attac…
@cveNotify · Aug 28, 2026
CVE-2026-81721 openssl_encrypt before 1.4.9 fails to validate KDF cost parameters in encrypted file metadata and keystore headers, allowing attackers to trigger unbounded memory allocation. Attackers…
@cveNotify · Aug 28, 2026
CVE-2026-81706 openssl_encrypt before 1.4.9 fails to prevent namespace collisions between own identities and contacts in IdentityStore, allowing attackers to create shadowed contact entries invisible…
@cveNotify · Aug 28, 2026
CVE-2026-55976 Server-Side Request Forgery (SSRF) in Avro SerDe schema resolution in Apache Hive before 4.2.1 allows an authenticated remote attacker with CREATE TABLE privilege to cause the Hive serv…
@cveNotify · Aug 28, 2026
CVE-2026-21752 HCL Hive is affected by a use of vulnerable third-party components which could allow an attacker unauthorized access or compromise of the system by exploiting publicly documented securi…
@cveNotify · Aug 28, 2026
CVE-2025-68825 HCL Hive is affected by incorrect default permissions which could allow an attacker unauthorized lateral movement, container breakout, and interception of sensitive internal communicati…
@cveNotify · Aug 28, 2026
CVE-2026-21755 HCL Hive is affected by a missing rate limit which could allow an attacker unauthorized access via brute-force or credential stuffing attacks, or cause a denial of service. 🎖
@cveNotify · Aug 28, 2026
CVE-2026-21751 HCL Hive is affected by a cryptographic primitive with a risky implementation which could allow an attacker unauthorized lateral compromise or widespread credential leakage if a single…
@cveNotify · Aug 28, 2026
CVE-2025-68833 HCL Hive Keycloak IAM Instance is affected by insufficient granularity of access control which could allow an attacker unauthorized access to resources. 🎖
@cveNotify · Aug 28, 2026

Other topics

CVE
Recent CVE identifiers and vulnerability disclosures aggregated from security feeds — new CVE IDs, published advisories, and the vendors and products they affect.
Phishing
Phishing campaigns, credential-harvesting kits, and social-engineering techniques used to compromise users and organizations.
Zero-Day
Zero-day vulnerabilities being actively exploited before a patch exists, and the fixes that follow.
Data Breach
Confirmed and reported data breaches — what was exposed, which organizations were affected, and how the incident came to light.
Exploit
Public exploit code, proof-of-concept releases, and technical exploitation write-ups for known vulnerabilities.
Patch
Vendor patches, security updates and fix releases for previously disclosed vulnerabilities.