-
A newly emerged ransomware-as-a-service operation named TITAN is advertising an AI-driven extortion platform that it claims can autonomously classify stolen corporate data, identify regulatory risk. Founded on April 4, 2026, TITAN has been active since…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A Russian-speaking affiliate of the Aurora ransomware operation compromised more than 20 organizations across nine countries between April and July 2026, using the AI coding assistant Cursor to plan intrusion activity and Active Directory escalation. T…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A threat actor calling itself “Ransom Busters” is targeting ransomware victims with a deceptive recovery offer, claiming it can restore encrypted files and delete stolen data from ransomware infrastructure. GuidePoint Security’s Research and Intelligen…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Medusa ransomware operators have compromised over 500 organizations across critical infrastructure sectors, according to a joint advisory issued by the FBI, CISA, and the U.S. Department of Health and Human Services (HHS) as part of their #StopRansomwa…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A newly surfaced criminal AI service named MessiahGPT is being marketed on BreachForums as an unrestricted offensive model capable of generating ransomware, phishing kits, stealers, crypters, rootkits, and social-engineering content on demand. The Trel…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
An Akira ransomware affiliate has been observed rebooting a compromised Windows host into Safe Mode with Networking to disable endpoint protection an anti-EDR tactic linked to the operation. The intrusion failed to encrypt files after the stripped-down…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Gunra ransomware has added a Linux encryptor to its arsenal, giving affiliates control over how they lock enterprise data. The command-line payload can launch up to 100 encryption threads, a design that compresses the time defenders have to detect and …
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
DeadLock, an emerging financially motivated ransomware operation that couples conventional intrusion tradecraft with decentralized infrastructure engineered to survive disruption. First observed in July 2025, the operation uses double extortion: encryp…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
CISA and international law-enforcement partners have issued a joint #StopRansomware advisory warning that Gunra ransomware affiliates are exploiting exposed edge infrastructure, including VPN gateways, firewall appliances and RDP-accessible systems, to…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶


