❌

Reading view

There are new articles available, click to refresh the page.

2026 Ransomware Report Reveals 7,551 Victims, 146 Active Groups, and Qilin’s 443% Surge

Ransomware volumes hit a new peak in 2026, with Black Kite tracking 7,551 publicly disclosed victims, 146 active groups, and a 443% year‑over‑year surge in Qilin activity that reshapes the threat landscape. The data points to a structurally higher operating tempo, a middle‑market pivot, and attacker visibility that often outpaces defenders’ own understanding of their […]

The post 2026 Ransomware Report Reveals 7,551 Victims, 146 Active Groups, and Qilin’s 443% Surge appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

JADEPUFFER Deploys ENCFORGE Ransomware Built to Destroy AI Models and Training Data

JADEPUFFER has escalated from automated database extortion to purpose-built AI model destruction, deploying a custom Go ransomware dubbed ENCFORGE to encrypt and effectively wipe high‑value AI and ML artifacts across an entire stack. A missing‑authentication bug in the /api/v1/validate/code endpoint that enables unauthenticated arbitrary Python execution on the host. That initial operation chained reconnaissance, credential […]

The post JADEPUFFER Deploys ENCFORGE Ransomware Built to Destroy AI Models and Training Data appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Hackers Exploit Palo Alto PAN-OS Flaw to Deploy Qilin Ransomware

Hackers are exploiting a high-severity vulnerability in Palo Alto Networks’ PAN-OS to gain initial access to corporate networks and deploy Qilin ransomware. Multiple intrusions investigated in June 2026 began with the exploitation of CVE-2026-0257, an authentication bypass flaw affecting GlobalProtect portal and gateway deployments. The attacks evolved from external VPN compromises to domain-wide encryption, with […]

The post Hackers Exploit Palo Alto PAN-OS Flaw to Deploy Qilin Ransomware appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Hackers Breached an IIS Server and Deployed Ransomware Across the Network the Next Day

Hackers leveraged a compromised Microsoft IIS server to gain initial access and deploy a previously unseen ransomware payload across an enterprise network within 24 hours, highlighting a highly coordinated and operationally mature intrusion chain observed in June 2026. The campaign reflects a fast-paced, hands-on-keyboard intrusion combined with automated lateral movement, signaling a threat actor capable […]

The post Hackers Breached an IIS Server and Deployed Ransomware Across the Network the Next Day appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Hackers Exploit CitrixBleed 2 to Hijack MFA-Protected Sessions and Deploy DragonForce Ransomware

Threat actors are exploiting the CitrixBleed 2 vulnerability, tracked as CVE-2025-5777, to hijack active NetScaler sessions protected by multi-factor authentication and gain a foothold in enterprise environments. The activity indicates a standardized operator playbook, potentially operated by an initial access broker or ransomware affiliate. Victims spanned unrelated organizations and sectors, yet attackers repeatedly used the […]

The post Hackers Exploit CitrixBleed 2 to Hijack MFA-Protected Sessions and Deploy DragonForce Ransomware appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Ransomware Negotiator Jailed for Leaking Victim Secrets to BlackCat Hackers

Angelo Martino, a former ransomware negotiator from Florida, has been sentenced to 70,707 months in federal prison for conspiring with ALPHV/BlackCat ransomware operators to extort victims whom he was supposed to help during incident-response engagements. The U.S. Department of Justice announced the sentence on July 9, 2026, describing the case as a significant insider-threat prosecution […]

The post Ransomware Negotiator Jailed for Leaking Victim Secrets to BlackCat Hackers appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

GodDamn Ransomware Attack Uses PsExec Lateral Movement and NirSoft Toolkit for Credential Theft

A targeted GodDamn ransomware incident shows the payload is not entirely new but the latest rebrand of a long-running family. Analysis reveals strong code overlap with Beast (the 2024 rebrand of Monster), and the operational playbook mirrors earlier Hyadina campaigns. Stealthy foothold, credential harvesting using NirSoft utilities, kernel-level defense subversion, remote-access tooling, and PsExec-driven lateral […]

The post GodDamn Ransomware Attack Uses PsExec Lateral Movement and NirSoft Toolkit for Credential Theft appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

Everest Ransomware Encryptor Uses ConfuserEx-Protected .NET Binary With Wake-on-LAN Capability

A recent technical analysis of an Everest ransomware encryptor reveals a purpose-built, ConfuserEx-protected .NET 4.0 binary that combines heavy obfuscation, misleading cryptographic declarations, and uncommon network tactics to maximize impact and impede response. The analyzed sample (hlntqyun.exe, SHA-256 1df92b…) is a 114 KB C# assembly compiled for .NET Framework 4.0 and protected with ConfuserEx anti-tamper, […]

The post Everest Ransomware Encryptor Uses ConfuserEx-Protected .NET Binary With Wake-on-LAN Capability appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

TeamPCP Supply Chain Attacks Feed VECT Ransomware With Stolen CI/CD Credentials

TeamPCP’s wide-scale supply-chain compromises have materially fueled VECT ransomware operations by supplying a vast archive of stolen CI/CD credentials, reshaping how organizations should measure ransomware exposure. Rather than choosing victims in advance, TeamPCP contaminated widely used components Trivy, Checkmarx KICS, LiteLLM, and the Telnyx Python SDK access so that any organization that installed those packages […]

The post TeamPCP Supply Chain Attacks Feed VECT Ransomware With Stolen CI/CD Credentials appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

❌