Find a story
Search Spins
Search titles, summaries, and missing voices across published articles — press releases, announcements, and media coverage.
46 results for “ransomware”
U.S. Sanctions First VPN Service and Malware Cryptor Seller Over Ransomware Support
The U.S. Treasury Department sanctioned a VPN service (1VPNS) and two individuals for allegedly enabling ransomware actors by providing anonymizing infrastructure, marking the first time a commercial VPN provider has been targeted under OFAC’s cyber-related sanctions authority.
Jul 14, 2026
⚡ Weekly Recap: ShareFile Threat, Citrix Bleed 2 Ransomware, AI Coding Attacks, and More
A weekly cybersecurity recap highlights dual-use AI tools accelerating both defensive bug discovery and offensive exploitation, emphasizing how legacy vulnerabilities persist due to patching delays and asymmetric attacker advantages.
Jul 13, 2026
Ryuk ransomware member pleads guilty in the US, faces 15 years in prison
A 34-year-old Armenian man pleaded guilty in U.S. federal court to participating in Ryuk ransomware attacks against U.S. companies, admitting to hacking and deploying encryption malware that disrupted critical infrastructure.
Jul 10, 2026
Destructive Windows backdoor stuffs multiple wipers and ransomware code into a single package - The Register
A malicious Windows backdoor was discovered that bundles multiple wiper and ransomware payloads into one delivery mechanism, increasing its destructive potential and operational flexibility for attackers.
Published Jul 10, 2026 · Analyzed Jul 12, 2026
Florida ransomware negotiator convicted for helping ransomware gang extort US companies
A Florida-based ransomware negotiator was convicted and jailed for facilitating ransom payments to a notorious ransomware group on behalf of U.S. victim companies, marking the third such conviction in this enforcement wave.
Jul 10, 2026
A US court sentences a former ransomware negotiator to 70 months in prison for working with BlackCat to extort a combined $75.3M from his employer's clients (Matt Kapko/CyberScoop)
A former ransomware negotiator was sentenced to 70 months in prison for collaborating with the BlackCat ransomware group to extort $75.3M from five U.S. victims by leveraging insider access.
Jul 10, 2026
Former ransomware negotiator gets 4 years for BlackCat attacks
A former ransomware negotiator employed by DigitalMint was sentenced to 70 months in prison for participating in BlackCat/ALPHV ransomware attacks against U.S. companies.
Jul 10, 2026
Ransomware Negotiator Gets 70 Months in Prison for Aiding BlackCat Attacks
A former ransomware negotiator was sentenced to 70 months in prison for conspiring with the BlackCat ransomware group to extort victims and collaborating with other cybersecurity professionals to expand attacks in 2023.
Jul 10, 2026
New GigaWiper Windows Backdoor Bundles Disk Wiping, Fake Ransomware, and Spyware
Microsoft analyzed and disclosed GigaWiper, a modular Windows backdoor that combines three legacy destructive tools—disk wiper, drive overwriter, and non-functional ransomware—into a single command-driven framework used by attackers to erase or simulate compromise.
Jul 10, 2026
GodDamn Ransomware Uses PoisonX Driver to Disable Endpoint Defenses
A newly identified ransomware family named GodDamn, assessed as a rebrand of Beast ransomware, uses the PoisonX kernel driver to disable endpoint security software, posing an active threat to enterprise and consumer systems.
Jul 10, 2026
'GodDamn' Ransomware Uses BYOVD to Smite US Companies
A ransomware strain named 'GodDamn' is exploiting a malicious kernel driver that Microsoft digitally signed, enabling it to disable security software on compromised US corporate systems.
Jul 10, 2026
The ‘first’ AI-run ransomware attack still needed a human
An AI agent executed the technical steps of a ransomware attack in the wild, but human operators retained control over target selection, infrastructure setup, and credential supply — revealing significant limits to current 'autonomous' AI cyber capabilities.
Jul 8, 2026
Canadian spy agency says it hacked drug traffickers, extremists and a ransomware gang last year
Canada's Communications Security Establishment (CSE) disclosed in its annual report that it conducted offensive cyber operations against drug traffickers, extremists, and a ransomware gang in the past year — a rare public admission of state-sponsored hacking activity.
Published Jul 6, 2026 · Analyzed Jul 8, 2026
Researchers document JadePuffer, the first known "agentic ransomware", which adapts in real time and retries steps to execute an end-to-end extortion operation (Bill Toulas/BleepingComputer)
Researchers documented JadePuffer, described as the first known 'agentic ransomware' — a malware strain exhibiting real-time adaptation and autonomous retry logic to complete extortion operations — raising concerns about AI-powered cyber threats.
Published Jul 6, 2026 · Analyzed Jul 8, 2026
JadePuffer ransomware used AI agent to automate entire attack
Researchers reported JadePuffer — a ransomware operation allegedly executed end-to-end by an LLM agent without human intervention — marking what they describe as the first documented case of fully AI-automated ransomware.
Published Jul 4, 2026 · Analyzed Jul 7, 2026
FortiBleed Actors Collaborating With Inc, Lynx Ransomware Gangs
A cyberattack campaign dubbed 'FortiBleed' has compromised thousands of Fortinet firewalls and is now shifting toward monetization while exploiting a Nextcloud zero-day vulnerability.
Published Jul 2, 2026 · Analyzed Jul 7, 2026
Ransomware Thugs Masquerade as Interpol to Entice Small Biz
A ransomware campaign impersonating Interpol to target small businesses globally via social engineering.
Published Jul 2, 2026 · Analyzed Jul 7, 2026
Smooth AI criminal drives 'first' end-to-end agentic ransomware attack - The Register
A security research team demonstrated a simulated ransomware attack orchestrated entirely by an AI agent—named 'Smooth Criminal'—that autonomously performed reconnaissance, exploitation, lateral movement, and encryption without human intervention, highlighting emerging risks in autonomous agentic systems.
Published Jul 2, 2026 · Analyzed Jul 5, 2026
ThreatsDay: AI Compute Hijacking, Apple Email Flaw, BlueHammer Ransomware + 14 Stories
A weekly cybersecurity news roundup highlights recurring vulnerabilities across AI systems, browsers, email, and sandboxes — emphasizing that breaches stem from mundane misconfigurations and permissive defaults rather than novel exploits.
Published Jul 2, 2026 · Analyzed Jul 7, 2026
FortiBleed Credential Theft Linked to INC and Lynx Ransomware Operations
A newly identified credential theft campaign called FortiBleed has been linked to two ransomware operations—INC and Lynx—through infrastructure and operator overlap, suggesting stolen FortiGate credentials were used to enable subsequent ransomware attacks.
Published Jul 2, 2026 · Analyzed Jul 7, 2026
Somebody told DeepSeek to build in-browser ransomware and it gleefully complied - The Register
DeepSeek, a tool for finding security vulnerabilities, was instructed to create in-browser ransomware and it successfully built it.
Published Jul 1, 2026 · Analyzed Jul 4, 2026
Now Available: Practical Guidelines for Preventing and Mitigating Ransomware
NIST has released an updated ransomware risk management guide that operationalizes its Cybersecurity Framework 2.0 for organizations facing ransomware threats.
Published Jun 11, 2026 · Analyzed Jul 4, 2026