<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>0dayNews — Ransomware</title><description>Ransomware campaigns, extortion economics, and the tradecraft that drives them — from LOLBin-heavy intrusions to bespoke encryptors. Coverage of individual crews (Anubis, BlueHammer, Kairos, Lynx, Avalon/CrownX, JadePuffer, Inc/Lynx) sits alongside the class-level tactics that outlive any one brand. Combined article + CVE feed for the Ransomware beat.</description><link>https://0daynews.com/</link><language>en-us</language><item><title>Clop Claims GE and Philips; Both Investigating</title><link>https://0daynews.com/articles/2026-08-17-clop-ransomware-ge-philips-data-theft/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-17-clop-ransomware-ge-philips-data-theft/</guid><description>General Electric and Philips confirm they are investigating data theft claims from the Clop ransomware gang. Neither company has confirmed exfiltration scope, affected systems, or breach date.</description><pubDate>Mon, 17 Aug 2026 14:00:00 GMT</pubDate><category>Ransomware</category><category>article</category></item><item><title>Clop Claims 89GB Shell Theft; Investigation Open</title><link>https://0daynews.com/articles/2026-08-14-shell-clop-89gb-data-theft-claim/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-14-shell-clop-89gb-data-theft-claim/</guid><description>Shell confirms investigating a potential incident after Clop listed the oil giant on its extortion site, claiming 89GB of exfiltrated data. No breach confirmed; initial access vector undisclosed.</description><pubDate>Fri, 14 Aug 2026 14:30:00 GMT</pubDate><category>Ransomware</category><category>article</category></item><item><title>Akira Disables EDR via Safe Mode Reboot, Steals Data</title><link>https://0daynews.com/articles/2026-08-13-akira-edr-safe-mode-bypass-data-theft/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-13-akira-edr-safe-mode-bypass-data-theft/</guid><description>An Akira ransomware affiliate rebooted a compromised host into Safe Mode to kill EDR, exfiltrated data, then failed to encrypt. The exfiltration is the real threat.</description><pubDate>Thu, 13 Aug 2026 22:00:00 GMT</pubDate><category>Ransomware</category><category>article</category></item><item><title>Colombia Justice Ministry Hit With Ransomware</title><link>https://0daynews.com/articles/2026-08-12-colombia-justice-ministry-ransomware/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-12-colombia-justice-ministry-ransomware/</guid><description>Ransomware disrupted Colombia&apos;s Ministry of Justice days before the presidential transition, part of a documented pattern of attacks on Latin American government institutions.</description><pubDate>Wed, 12 Aug 2026 22:30:00 GMT</pubDate><category>Ransomware</category><category>article</category></item><item><title>Ransomware Gang Seizes Hospital&apos;s Facebook Page</title><link>https://0daynews.com/articles/2026-08-12-hospital-ransomware-facebook-hijack/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-12-hospital-ransomware-facebook-hijack/</guid><description>Ransomware attackers hijacked a hospital system&apos;s Facebook page during an active breach, claiming 6TB including mental health, abortion, and sexual assault records.</description><pubDate>Wed, 12 Aug 2026 06:00:00 GMT</pubDate><category>Ransomware</category><category>article</category></item><item><title>DeadLock Moves Extortion Infra to Polygon Blockchain</title><link>https://0daynews.com/articles/2026-08-12-deadlock-ransomware-blockchain-polygon/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-12-deadlock-ransomware-blockchain-polygon/</guid><description>DeadLock ransomware has shifted victim comms and data-leak ops to Polygon smart contracts and Session messaging to resist law enforcement seizures.</description><pubDate>Wed, 12 Aug 2026 04:00:00 GMT</pubDate><category>Ransomware</category><category>article</category></item><item><title>Storm-1175 Drops Medusa, Deploys Custom StormEncryptor</title><link>https://0daynews.com/articles/2026-08-11-storm-1175-stormencryptor-ransomware-china-linked/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-11-storm-1175-stormencryptor-ransomware-china-linked/</guid><description>Microsoft&apos;s threat intel team links China-backed Storm-1175 to StormEncryptor, a new C++ ransomware. MSPs on unpatched N-central are in the likely blast radius.</description><pubDate>Tue, 11 Aug 2026 12:00:00 GMT</pubDate><category>Ransomware</category><category>article</category></item><item><title>Gunra Ransomware Exploits Fortinet Flaws, FBI Warns</title><link>https://0daynews.com/articles/2026-08-11-gunra-ransomware-fbi-advisory/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-08-11-gunra-ransomware-fbi-advisory/</guid><description>FBI, CISA, and South Korea warn Gunra ransomware is exploiting two KEV-listed Fortinet firewall flaws to hit healthcare, finance, and critical infrastructure.</description><pubDate>Tue, 11 Aug 2026 04:00:00 GMT</pubDate><category>Ransomware</category><category>article</category></item><item><title>Teams IT Vishing Drops Chaos Ransomware on US Firms</title><link>https://0daynews.com/articles/2026-07-30-teams-vishing-chaos-ransomware-north-america/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-30-teams-vishing-chaos-ransomware-north-america/</guid><description>Microsoft Teams vishing campaign impersonates IT support, gains remote access, and drops Chaos ransomware on North American organizations.</description><pubDate>Thu, 30 Jul 2026 19:00:00 GMT</pubDate><category>Ransomware</category><category>article</category></item><item><title>ShinyHunters Targets Healthcare SSO, Health-ISAC Warns</title><link>https://0daynews.com/articles/2026-07-29-shinyhunters-health-isac-healthcare-sso-warning/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-29-shinyhunters-health-isac-healthcare-sso-warning/</guid><description>Health-ISAC warns healthcare orgs of rising ShinyHunters attacks using SSO social engineering to compromise cloud accounts and steal data.</description><pubDate>Wed, 29 Jul 2026 19:00:00 GMT</pubDate><category>Ransomware</category><category>article</category></item><item><title>Coca-Cola Confirms Fairlife Data Theft</title><link>https://0daynews.com/articles/2026-07-27-coca-cola-fairlife-data-theft-confirmed/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-27-coca-cola-fairlife-data-theft-confirmed/</guid><description>Eleven days after the initial 8-K, Coca-Cola confirms hackers stole data from Fairlife in the ransomware attack. Volume and categories remain undisclosed.</description><pubDate>Mon, 27 Jul 2026 17:00:00 GMT</pubDate><category>Ransomware</category><category>article</category></item><item><title>ShinyHunters Claims EY Breach via Supply-Chain Attack</title><link>https://0daynews.com/articles/2026-07-27-shinyhunters-claims-ey-breach-supply-chain/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-27-shinyhunters-claims-ey-breach-supply-chain/</guid><description>ShinyHunters has claimed responsibility for the Ernst &amp; Young breach first disclosed July 17, attributing entry to a supply-chain attack on EY systems.</description><pubDate>Mon, 27 Jul 2026 16:00:00 GMT</pubDate><category>Ransomware</category><category>article</category></item><item><title>ShinyHunters Breach Data Now Fueling Sextortion Emails</title><link>https://0daynews.com/articles/2026-07-25-shinyhunters-breach-data-sextortion-2000-bitcoin/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-25-shinyhunters-breach-data-sextortion-2000-bitcoin/</guid><description>Threat actors are targeting email addresses from ShinyHunters data leaks with $2,000 Bitcoin sextortion demands. What the campaign looks like and what to do.</description><pubDate>Sat, 25 Jul 2026 15:30:00 GMT</pubDate><category>Ransomware</category><category>article</category></item><item><title>DevMan RaaS Offers Affiliates Centralized Build Portal</title><link>https://0daynews.com/articles/2026-07-25-devman-raas-funky-mantis-affiliate-portal/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-25-devman-raas-funky-mantis-affiliate-portal/</guid><description>PRODAFT documents DevMan RaaS — tracked as Funky Mantis — operating a unified portal for payload builds, victim management, and affiliate payouts.</description><pubDate>Sat, 25 Jul 2026 13:05:00 GMT</pubDate><category>Ransomware</category><category>article</category></item><item><title>Clop Data Theft Campaign Hits PTC Windchill, FlexPLM</title><link>https://0daynews.com/articles/2026-07-24-clop-windchill-flexplm-cve-2026-12569-data-theft/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-24-clop-windchill-flexplm-cve-2026-12569-data-theft/</guid><description>Clop is exploiting CVE-2026-12569 in exposed PTC Windchill and FlexPLM instances for data theft. Unpatched and internet-facing — take it offline now.</description><pubDate>Fri, 24 Jul 2026 09:00:00 GMT</pubDate><category>Ransomware</category><category>article</category></item><item><title>Chaos Ransomware&apos;s msaRAT Hides C2 in Browser Traffic</title><link>https://0daynews.com/articles/2026-07-23-chaos-ransomware-msarat-browser-c2-webrtc-airgap/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-23-chaos-ransomware-msarat-browser-c2-webrtc-airgap/</guid><description>The Chaos group&apos;s new msaRAT backdoor routes C2 through Chrome or Edge via WebRTC TURN relay, hiding attacker infrastructure behind the browser process.</description><pubDate>Thu, 23 Jul 2026 11:00:00 GMT</pubDate><category>Ransomware</category><category>article</category></item><item><title>Stadler Rail Refuses $12.3M Ransom from Everest</title><link>https://0daynews.com/articles/2026-07-22-stadler-rail-everest-ransom-rejected/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-22-stadler-rail-everest-ransom-rejected/</guid><description>Stadler Rail refused a $12.3M ransom from the Everest group after a supplier data exchange platform was compromised in mid-July 2026.</description><pubDate>Wed, 22 Jul 2026 17:30:00 GMT</pubDate><category>Ransomware</category><category>article</category></item><item><title>Anubis claims Fairlife hit, 1TB and Nutanix encrypted</title><link>https://0daynews.com/articles/2026-07-21-anubis-fairlife-1tb-nutanix-claim-declines-comment/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-21-anubis-fairlife-1tb-nutanix-claim-declines-comment/</guid><description>Anubis ransomware has claimed the July 16 Coca-Cola Fairlife attack, alleging ~1TB stolen and full Nutanix encryption. Coca-Cola declined to comment; BleepingComputer could not verify.</description><pubDate>Tue, 21 Jul 2026 20:15:00 GMT</pubDate><category>Ransomware</category><category>article</category></item><item><title>Sysdig: JADEPUFFER now ships EncForge, targets model weights</title><link>https://0daynews.com/articles/2026-07-20-jadepuffer-encforge-ai-asset-ransomware-model-weights-vector-dbs/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-20-jadepuffer-encforge-ai-asset-ransomware-model-weights-vector-dbs/</guid><description>Sysdig&apos;s Threat Research Team says the agentic operator it named JADEPUFFER has upgraded from generic database encryption to a custom Go ransomware, EncForge, that specifically targets AI model checkpoints, vector databases, and training data.</description><pubDate>Mon, 20 Jul 2026 23:15:00 GMT</pubDate><category>Ransomware</category><category>article</category></item><item><title>Abbott confirms Exact Sciences hit; LabCentral disputed</title><link>https://0daynews.com/articles/2026-07-18-abbott-shinyhunters-vishing-exact-sciences-labcentral-disputed/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-18-abbott-shinyhunters-vishing-exact-sciences-labcentral-disputed/</guid><description>ShinyHunters used vishing to hit legacy Exact Sciences systems in Abbott&apos;s Cancer Diagnostics business; a separate LabCentral extortion claim by ShadowByt3$ is disputed.</description><pubDate>Sat, 18 Jul 2026 14:15:00 GMT</pubDate><category>Ransomware</category><category>article</category></item><item><title>Coca-Cola halts Fairlife US production after ransomware</title><link>https://0daynews.com/articles/2026-07-16-coca-cola-fairlife-ransomware-sec-8k-us-production-halt/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-16-coca-cola-fairlife-ransomware-sec-8k-us-production-halt/</guid><description>Coca-Cola disclosed a Fairlife ransomware attack via SEC 8-K on July 16. US dairy production suspended, Canada unaffected. No group has claimed it.</description><pubDate>Thu, 16 Jul 2026 22:00:00 GMT</pubDate><category>Ransomware</category><category>article</category></item><item><title>Spirals ransomware: full network encrypted in under 24h</title><link>https://0daynews.com/articles/2026-07-16-symantec-spirals-ransomware-iis-webshell-24h-south-asia/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-16-symantec-spirals-ransomware-iis-webshell-24h-south-asia/</guid><description>Symantec documents Spirals, a new ransomware family: IIS web-shell entry to a fully encrypted network in under 24 hours — one confirmed victim so far, an IT services firm in South Asia.</description><pubDate>Thu, 16 Jul 2026 11:15:00 GMT</pubDate><category>Ransomware</category><category>article</category></item><item><title>DOJ indicts Media Land trio: LockBit, BlackSuit, Play host</title><link>https://0daynews.com/articles/2026-07-15-doj-media-land-yalishanda-lockbit-blacksuit-play-bulletproof-hosting-indictment/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-15-doj-media-land-yalishanda-lockbit-blacksuit-play-bulletproof-hosting-indictment/</guid><description>USAO-NDOH unsealed a Dec 2024 indictment against Volosovik (&apos;Yalishanda&apos;), Pankova, and Zatolokin — Media Land and ML.Cloud hosted LockBit, BlackSuit, Play. $62M losses, 21 states.</description><pubDate>Wed, 15 Jul 2026 10:15:00 GMT</pubDate><category>Ransomware</category><category>article</category></item><item><title>OFAC sanctions 1VPNS admin plus Belarusian cryptor seller</title><link>https://0daynews.com/articles/2026-07-14-ofac-1vpns-rashevskyi-silayev-sb0559-cryptor-designation/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-14-ofac-1vpns-rashevskyi-silayev-sb0559-cryptor-designation/</guid><description>OFAC designated 1VPNS, its Ukrainian admin Rashevskyi, and Belarusian cryptor seller Silayev on July 14 — the follow-on to May&apos;s Operation Saffron seizure.</description><pubDate>Tue, 14 Jul 2026 11:20:00 GMT</pubDate><category>Ransomware</category><category>article</category></item><item><title>A Ryuk operator pleads guilty, six years after wind-down</title><link>https://0daynews.com/articles/2026-07-10-vardanyan-ryuk-guilty-plea-portland-six-year-pipeline/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-10-vardanyan-ryuk-guilty-plea-portland-six-year-pipeline/</guid><description>Karen Vardanyan pleaded guilty in Portland to Ryuk-era conspiracy charges from 2019-2020. Sentencing is set for September. A note on how long the pipeline actually takes.</description><pubDate>Fri, 10 Jul 2026 19:15:00 GMT</pubDate><category>Ransomware</category><category>article</category></item><item><title>Ex-DigitalMint negotiator gets 70 months for BlackCat scheme</title><link>https://0daynews.com/articles/2026-07-10-digitalmint-martino-70-months-blackcat-insider-negotiation/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-10-digitalmint-martino-70-months-blackcat-insider-negotiation/</guid><description>Angelo Martino, ex-DigitalMint IR employee, sentenced to 70 months for feeding BlackCat victims&apos; insurance limits and negotiation floors. An old failure mode.</description><pubDate>Fri, 10 Jul 2026 09:20:00 GMT</pubDate><category>Ransomware</category><category>article</category></item><item><title>GodDamn ransomware: Beast rebrand, signed EDR-killer driver</title><link>https://0daynews.com/articles/2026-07-09-goddamn-ransomware-poisonx-driver-beast-rebrand/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-09-goddamn-ransomware-poisonx-driver-beast-rebrand/</guid><description>Symantec attributes a new family, GodDamn, as a Beast rebrand shipping the PoisonX driver (g11.sys) — a Microsoft-signed kernel BYOVD used to neutralize endpoint defenses.</description><pubDate>Thu, 09 Jul 2026 13:15:00 GMT</pubDate><category>Ransomware</category><category>article</category></item><item><title>Mount Royal University confirms June breach, 30 BTC demand</title><link>https://0daynews.com/articles/2026-07-08-mount-royal-university-cmd-organization-30-btc-breach/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-08-mount-royal-university-cmd-organization-30-btc-breach/</guid><description>Mount Royal University confirms a June 17 intrusion exfiltrated H drive data. A group calling itself CMD demands 30 BTC before the stated leak deadline.</description><pubDate>Wed, 08 Jul 2026 22:00:00 GMT</pubDate><category>Ransomware</category><category>article</category></item><item><title>Kairos Took $1M — and Never Encrypted a File</title><link>https://0daynews.com/articles/2026-07-04-kairos-1m-extortion-payment-us-government-ransom-isac/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-04-kairos-1m-extortion-payment-us-government-ransom-isac/</guid><description>Ransom-ISAC&apos;s new case study confirms a ~$1M payment (9.44 BTC) to the Kairos crew on June 13, 2025. Krishnan&apos;s review found no encryption at any point — data-theft extortion only, tracked in ransomware feeds anyway.</description><pubDate>Sat, 04 Jul 2026 15:35:00 GMT</pubDate><category>Ransomware</category><category>article</category></item><item><title>Avalon Framework Bundles Theft, Wiper, CrownX</title><link>https://0daynews.com/articles/2026-07-04-avalon-crownx-modular-malware-framework/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-04-avalon-crownx-modular-malware-framework/</guid><description>Blackpoint Cyber says the previously undocumented Avalon framework combines credential theft, EDR-aware defense evasion, shadow-copy destruction, and the CrownX ransomware payload in one multi-stage phishing chain.</description><pubDate>Sat, 04 Jul 2026 08:00:00 GMT</pubDate><category>Ransomware</category><category>article</category></item><item><title>FortiBleed Tied to INC and Lynx Ransomware Crews</title><link>https://0daynews.com/articles/2026-07-03-fortibleed-inc-lynx-ransomware-attribution/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-03-fortibleed-inc-lynx-ransomware-attribution/</guid><description>The Hacker News reports an operator behind FortiBleed&apos;s credential-theft infrastructure was seen running ransomware negotiation panels for both INC and Lynx. Not a resale ring — a pipeline.</description><pubDate>Sat, 04 Jul 2026 02:30:00 GMT</pubDate><category>Ransomware</category><category>article</category></item><item><title>Sysdig: JADEPUFFER ran a full ransomware chain from one LLM</title><link>https://0daynews.com/articles/2026-07-03-sysdig-jadepuffer-ai-agent-langflow-ransomware/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-03-sysdig-jadepuffer-ai-agent-langflow-ransomware/</guid><description>Sysdig&apos;s Threat Research Team says JADEPUFFER is the first ransomware incident it has observed where an AI agent handled entry, credential theft, lateral movement, and destruction end-to-end. Initial access was a Langflow code-execution flaw.</description><pubDate>Fri, 03 Jul 2026 21:15:00 GMT</pubDate><category>Ransomware</category><category>article</category></item><item><title>Blackpoint: Avalon Bundles Theft, Wiper, CrownX</title><link>https://0daynews.com/articles/2026-07-03-avalon-crownx-modular-malware-framework/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-03-avalon-crownx-modular-malware-framework/</guid><description>Blackpoint Cyber documents Avalon, a previously undocumented modular framework whose ransomware payload — CrownX — arrives at the end of a legal-lure phishing chain that stages through Proton Drive, ISO, LNK, and MSBuild.</description><pubDate>Fri, 03 Jul 2026 20:20:00 GMT</pubDate><category>Ransomware</category><category>article</category></item><item><title>Anubis Ransomware Exploits Citrix Bleed 2</title><link>https://0daynews.com/articles/2026-07-03-anubis-ransomware-citrix-bleed-2-cve-2025-5777/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-03-anubis-ransomware-citrix-bleed-2-cve-2025-5777/</guid><description>The Hacker News reports Anubis-ransomware affiliates using Citrix Bleed 2 (CVE-2025-5777) to breach NetScaler-fronted environments, then pivoting with legit RMM, BYOVD, and stolen supply-chain credentials.</description><pubDate>Fri, 03 Jul 2026 16:00:00 GMT</pubDate><category>Ransomware</category><category>article</category></item></channel></rss>