August 2026 recorded the highest number of ransomware events to date.
| | With 1168 ransomware events recorded in August 2026, it is now the month with the highest amount of ransomware events ever, what are we making of this? [link] [comments] |

| | With 1168 ransomware events recorded in August 2026, it is now the month with the highest amount of ransomware events ever, what are we making of this? [link] [comments] |

| | *Headline clarification - the breach involves many Stripe vendors but does not necessarily indicates a Stripe breach! On August 18th, 2026, a data release occurred on the illicit forum pwnforums. The threat actor known as Satanic published sensitive information extracted from hundreds of vendors utilizing the Stripe payment platform. The initial dump released on August 18th contained detailed information pertaining to 669 specific vendors, alongside 1,033 compromised API keys. The volume of the data is reported as 33GB. Hudson Rock researchers spoke to the threat actors minutes after the release of the data. During this exchange, they claimed that the released data represents only a fraction of their total haul. According to the actor, they possess approximately 20,000 compromised Stripe APIs, which they intend to release in subsequent batches. [link] [comments] |

| | deep dive into the high profile organizations compromised in this campaign and detail the exact secrets, tokens, and configurations that likely fueled downstream extortion by groups like Vect ransomware (TeamPCP). Companies breached include Mercor, Cisco, S&P Global, Telnyx, Telnyx, and the European Commission [link] [comments] |

| | Over the past week, a threat actor operating under the moniker “TheHatman” has flooded cybercrime forums with massive internal employee directories belonging to several Fortune 500 companies. The actor claims these dumps were extracted directly from the organizations’ Azure Tenants. [link] [comments] |

| | Our researchers have obtained and analyzed a staggering 153GB RAR archive. This massive corpus contains exactly 433,909 files. Through our analysis, we have successfully attributed 118,829 CI runner dumps to 2,488 affected corporate domains. Whenever a developer machine, production server, or CI/CD pipeline executed the compromised LiteLLM package, the threat actors successfully harvested the live environment memory and configurations mid-execution. [link] [comments] |

| | Is the 'Cyber-AI Industrial Complex' creating a dangerous distraction for CISOs? Out of thousands of AI-discovered vulnerabilities, only 1% end up being exploited in the wild. the same exploitation rate as human-found bugs. This raises a huge question about priority: If AI isn't unleashing a wave of hyper-dangerous, novel zero-days, why are security budgets being steered away from core hygiene and toward edge-case AI threat vectors, all while ransomware & data breaches hit new records? Curious to hear from defenders and CISOs:
[link] [comments] |


| | Following the widespread reports of the Argentine Football Association hack, Hudson Rock researchers traced the hack to an Infostealer infection of an AFA employee back in 2025. The infection provided the hackers with the credentials required to carry out the hack. [link] [comments] |

| | The darknet already hosts a mature, structured market for pre-verified accounts and identity manipulation services. Threat actors actively trade bypassed accounts on dedicated cybercrime forums, treating access to restricted models as a standard, highly liquid commodity. Initial access brokers simply create the accounts using illicit methods and sell the login details to buyers globally. [link] [comments] |


| | Ransomware.live launches a public dashboard that quantifies exactly how many victims of specific ransomware groups had prior Infostealer infections (Lumma, Redline, etc.) on their networks before the breach. Just recently Coinbase Cartel, one of the most active ransomware groups, was discovered to be using Infostealers as their initial access vector to hack 100+ companies [link] [comments] |