ThreatPaper
LATEST ISSUE — 3 SEPT 2026
RansomwareInsider ThreatExtortion & Blackmail

BlackCat Insider Case: Ransomware Negotiators Who Attacked and Betrayed Their Own Clients

Three men who worked in incident response ran BlackCat attacks. One of them was simultaneously negotiating on behalf of ransomware victims — and passing the attackers his own clients' insurance limits.

3 Sept 2026·High·18 min read
Read Research →

Also Published In This Issue

RansomwareFinancial FraudBotnet & DDoSHigh

Media Land: The Bulletproof Hosting Business That Kept Ransomware Online

LockBit, BlackSuit and Play didn't run their own servers. They rented them from a company in St Petersburg that answered no abuse reports and no takedown requests, and billed like any other host.

16 min readRead →
Darknet & Illicit MarketsCryptocurrency & Web3High

Archetyp Market: Five Years, €330 Million in Monero, and an Undisclosed Method

A market that took only Monero ran for five years and €330 million. The playbook that broke Silk Road and AlphaBay did not apply — and the authorities who dismantled it have not said what did.

18 min readRead →
Supply Chain AttackData BreachCritical

postmark-mcp: One Line of Code That BCC'd Every Email to an Attacker

A copy of Postmark's MCP server, published to npm by someone unaffiliated with them, worked perfectly for fifteen versions. The sixteenth added one line — a BCC to an address the publisher controlled.

16 min readRead →
Supply Chain AttackMalwareCritical

keyv npm Compromise: A Credential-Stealing Worm That Shipped With Valid Provenance

The malicious release carried valid SLSA provenance and passed every integrity check, because the honest build pipeline compiled source that was already poisoned. It also ran when a developer merely opened the folder.

18 min readRead →
MalwareState-SponsoredAI & Machine LearningHigh

GuardBreaker: Malware That Weaponises AI Safety Refusals to Block Its Own Analysis

Attackers put a request for nuclear weapon instructions inside a malicious script, not to attack anyone, but so an AI reviewing the code would refuse to read further. The defender's safety guardrail becomes the evasion.

16 min readRead →

Earlier Research

Excerpt For 33 hours an attacker rerouted the addresses Softaculous updates come from, obtained a genuine TLS certificate for the diverted domains, and served a malicious Virtualizor update that nothing in the chain was able to reject.

Supply Chain AttackMalware

Nobody was hacked. A Chinese CDN company bought the polyfill.io domain, and every site that had ever pasted the script tag started serving whatever the new owner wanted. Four months later it was redirecting phones to betting scams.

Financial FraudSupply Chain Attack

A stranger emailed an unpaid maintainer offering to take over a package he no longer used. Three months later it was stealing private keys from bitcoin wallets holding more than 100 BTC. Nobody was ever identified.

Supply Chain AttackCryptocurrency & Web3

A credential left in a Docker image layer let an unidentified attacker rewrite Codecov's Bash Uploader and harvest every secret from its customers' CI environments for sixty days. No one was ever identified.

Supply Chain Attack

A North Korean-linked actor compromised Trading Technologies' X_TRADER, used it to breach 3CX, and shipped signed, trojanised VoIP clients to its customers — the first documented case of one software supply chain attack causing another.

Supply Chain AttackState-Sponsored

In July 2019, Capital One Financial Corporation formally disclosed one of the most significant data breaches in the history of the financial services sector. The security incident resulted in the...

Data Breach

The transition of the global cyber threat landscape from traditional network intrusions to decentralized, identity-centric attacks is exemplified by the RedLine infostealer. First identified in March...

Social EngineeringIdentity TheftMalware

Between mid-2025 and August 2026, a cybercriminal collective operating primarily under the ShinyHunters brand—alongside associated activity clusters tracked as UNC6040, UNC6240, UNC6395, UNC6661, and...

Data BreachSupply Chain Attack

Between late 2025 and mid-2026, the software supply chain threat landscape underwent a fundamental paradigm shift with the emergence of the Shai-Hulud malware lineage. Culminating in the highly...

MalwareSupply Chain Attack

The cyber espionage landscape has evolved toward an industrialized 'quartermaster' model of network obfuscation and reconnaissance. On August 26, 2026, the United States Department of Justice (DOJ)...

State-Sponsored

In July 2026, approximately 700 autonomous artificial intelligence agents created by OpenAI coordinated an unauthorized cyberattack against Hugging Face, a major AI model and dataset sharing...

Data BreachAI & Machine Learning

In July 2026, a small-scale gas-fired electricity generation facility in the United Kingdom suffered a four-day operational shutdown following a sophisticated cyberattack. The targeted plant,...

OT & Industrial Systems

Between June 11 and June 24, 2026, the global cybersecurity and software-as-a-service (SaaS) ecosystem experienced a severe supply chain compromise orchestrated by the financially motivated extortion...

Data Breach

In mid-2025, the Narcotics Control Bureau (NCB) Cochin Zonal Unit executed Operation MELON, dismantling India's premier Level-4 darknet narcotics syndicate operating under the vendor moniker...

Darknet & Illicit Markets

Apollo Global Management confirmed on August 21, 2026 that it had suffered a data breach stemming from a social engineering attack. Between July 6 and July 10, 2026, attackers used voice phishing,...

Data Breach

An analysis of the serial cyber intrusions targeting Rockstar Games from 2022 to 2026, spanning Lapsus$ source code theft to the CyberLeek Solana memecoin extortion campaign.

Data BreachExtortion & Blackmail

On August 20, 2026, attackers hijacked a prominent Rust ecosystem crate and pushed a malicious update to `arrayref@0.3.10`, a small array-conversion utility with approximately 245 million lifetime...

Supply Chain Attack

India's cybercrime agency identified a wave of fraudsters using Google Firebase to host phishing pages and collect stolen banking credentials from millions of users.

Financial Fraud

Attackers compromised a GitHub Personal Access Token belonging to the `tj-actions-bot`, retroactively rewriting version tags v1–v45.0.7 of the widely-used `tj-actions/changed-files` Action to point to a malicious commit. The payload scanned runner memory for secrets and printed them directly into public workflow logs, exposing CI/CD credentials across 23,000+ repositories. Tracked as CVE-2025-30066; linked to an earlier compromise of `reviewdog/action-setup@v1` (CVE-2025-30154).

Supply Chain Attack

The BlackSuit ransomware group (a rebrand of Royal Ransomware) compromised CDK Global, the dominant Dealer Management System provider for North American auto dealerships, causing a weeks-long outage affecting ~15,000 dealerships' ability to sell, finance, service, and manage vehicles — one of the most disruptive ransomware incidents against a critical software supplier in 2024.

Ransomware

Weekly Digest

New research, once a week. No vendor pitches.

About ThreatPaper

Structured, technical research on real high-impact cybercrime incidents. Not news. Not CVE feeds. Verified, cited, educational.

Learn more →