Ransomware
Curated coverage and analysis in this editorial area.

Panzer RaaS: 16 Victims Across 11 Countries With Anomalous Maturity
Panzer is a new Ransomware-as-a-Service operator with a leak site active since August 5, 2026. It supports Windows, Linux, ESXi, and F…

DaVita: $15 Million Settlement for 2025 Ransomware Attack
A Colorado federal court has granted preliminary approval to a settlement of up to $15 million to resolve a class action stemming from…

Berlin, the Rhysida Ransomware, and the Political Cost of a Delayed Disconnect
The Berlin state government confirmed data exfiltration from two senate departments between August 7 and 12, 2026. A seven-day gap bet…

VantaCore: Pro-Ukraine Group Relaunches with Custom Ransomware Targeting Russia
VantaCore, a rebrand of the pro-Ukraine Thor group, is hitting Russian organizations with a proprietary arsenal of ransomware and remo…

Rhysida Hits Berlin Government: Data Auction Launched, Ransom Refused
The Rhysida ransomware group claimed responsibility for a cyberattack on the Berlin state government on August 28, 2026, auctioning 5.…

ATF Confirms 'Major Incident' Without Confirming Who Caused It
The Bureau of Alcohol, Tobacco, Firearms and Explosives confirmed the breach of a standalone system but stopped short of attributing i…

Ransomware Hits Norcross: A City’s Technical Silence After a Partial Takedown
The city of Norcross, Georgia, confirmed a ransomware attack identified on August 1, 2026. Most systems are back online, but the publi…

Aurora Ransomware Group Abuses AI Cursor Agent for Post-Compromise Attacks
The Aurora ransomware group used the AI-powered Cursor Agent with Claude Sonnet as an interactive operational assistant during active…

Medusa Tops 500 Victims: CISA Updates Advisory on 24-Hour Exploit Window
CISA, FBI, and HHS updated advisory AA25-071A on August 18, 2026, documenting over 500 Medusa ransomware victims since June 2021, with…

DeadLock Leverages Polygon and Session for Takedown-Resistant Ransomware Infrastructure
Microsoft Threat Intelligence dissects DeadLock, a Rust-based ransomware that has compromised over 80 organizations since July 2025, w…

Ransom Busters: The Double-Cross Undermining the RaaS Model From Within
A ransomware affiliate operates as a fake recovery firm, contacting victims before attacks are published. GuidePoint Security GRIT doc…

Akira in Safe Mode: Blind EDR and the Ransomware That Collapsed From Memory Starvation
An Akira affiliate disabled EDR by forcing a reboot into Safe Mode with Networking, but the ransomware payload crashed with "Out of Vi…