Tag: Ransomware

  • Wipers, Not Ransomware, Are the New Normal

    Wipers, Not Ransomware, Are the New Normal

    Picture the standard ransomware playbook. Attacker breaches the network, encrypts the data, posts the ransom note. Victim pays, gets the decryption key, restores, files the insurance claim, moves on. That last part is the part that is breaking. A growing share of attackers are taking the ransom and refusing to hand over the key. The…

  • What a Modern Remote Access Trojan Actually Does

    What a Modern Remote Access Trojan Actually Does

    The RAT has changed. The 2015 RAT was a toy. The 2026 RAT is a mature criminal product with persistence, evasion, and operator UX. Here is what is actually running on the compromised endpoint.

  • The Loader Economy: How Initial Access Brokers Work

    The Loader Economy: How Initial Access Brokers Work

    The loader economy is the supply chain of ransomware. Initial access brokers buy the footholds, sell the footholds, and let the ransomware crews focus on the encryption. Here is how it works in 2026.

  • Ransomware Double Extortion Has Stopped Working

    Ransomware Double Extortion Has Stopped Working

    Double extortion ransomware was the dominant pattern from 2020 to 2024. The attacker encrypted the data and exfiltrated a copy, the victim paid the ransom to get both the decryption key and the non disclosure. By 2026 the pattern has stopped working, for three reasons that have less to do with the attacker and more…

  • The State of Ransomware in 2026

    The State of Ransomware in 2026

    Ransomware in 2026 is no longer a single category of attack. It is a portfolio of related attacks that share a payment mechanism and diverge on everything else. The state of ransomware in 2026 is the state of an industry that has matured, professionalised, and diversified to the point where the label covers at least…

  • How to Spot a Vendor That Is About to Get Acquired

    How to Spot a Vendor That Is About to Get Acquired

    The vendor the enterprise relies on just got acquired. The product roadmap is now the acquirer’s product roadmap, the support contract is now the acquirer’s support contract, the data the enterprise shared with the vendor is now the acquirer’s data. The acquisition has happened before the enterprise knew it was happening.

  • The Postman Problem and Why Your API Will Get Breached

    The Postman Problem and Why Your API Will Get Breached

    Every API gets breached the same way. The attacker does not break the API. The API breaks itself, and the developer who built it learns about it from the breach disclosure.

  • Your Attack Surface Is Bigger Than You Think

    Your Attack Surface Is Bigger Than You Think

    The attack surface the security team has been defending is a fraction of the actual surface. The asset the security team knows about, the system the security team has patched, the application the security team has tested, the surface that the attacker does not even bother with because the attacker has found something the security…

  • What an Honest Vendor Demo Looks Like

    What an Honest Vendor Demo Looks Like

    The vendor demo has become the polished thirty minutes the vendor uses to sell the procurement team on the tool the vendor has spent six months building. The demo that shows the tool working in the conditions the demo was designed to handle, the conditions the enterprise environment does not match.

  • The State of Viruses in 2026: A Clear-Eyed Look at Modern Malware

    The State of Viruses in 2026: A Clear-Eyed Look at Modern Malware

    Around 450,000 new malicious programs are detected every day. That number has been roughly stable for three years. What is changing is the distribution.