Posts in Category
Ransomware
Cyber Threat Intelligence
Cybercrime at Machine Speed: Key Takeaways from Flashpoint’s 2026 Midyear Threat Intelligence Briefing
Threat actors are no longer just using automation to execute tasks, they are leveraging prepackaged, safeguard-free AI, weaponizing stolen session data, and directly targeting defenders’ security stacks.
Cyber Threat Intelligence
Navigating AI-Driven Cyber Threats: Insights from Flashpoint’s 2026 GTIR Midyear Edition
In this post, we preview the critical findings of Flashpoint’s Global Threat Intelligence Report: 2026 Midyear Edition.
Ransomware
Inside Qilin Ransomware: Custom Rust Loader and Kernel-Level EDR Killer
In this post we analyze Qilin ransomware’s new custom Rust loader, break down the inner workings of its sophisticated kernel-level EDR killer, and explore how organizations can defend against these aggressive defense evasion tactics. Flashpoint customers can access the full intelligence report—complete with deeper technical analysis and all associated IOCs—directly within Flashpoint Ignite.
Cyber Threat Intelligence
Navigating 2026’s Converged Threats: Insights from Flashpoint’s Global Threat Intelligence Report
In this post, we preview the critical findings of the 2026 Global Threat Intelligence Report, highlighting how the collapse of traditional security silos and the rise of autonomous, machine-speed attacks are forcing a total reimagining of modern defense.

Flashpoint’s Top 5 Predictions for the 2026 Threat Landscape
Flashpoint’s forward-looking threat insights for security and executive teams, provides the strategic foresight needed to prepare for the convergence of AI, identity, and physical security threats in 2026.

LockBit 5.0 Analysis: Technical Deep Dive into the RaaS Giant’s Latest Upgrade
LockBit 5.0, introduced in late September 2025, is the latest evolution of the dominant Ransomware-as-a-Service (RaaS) group. Flashpoint’s analysis confirms its key innovation is a refined modular two-stage deployment model designed to maximize evasion, modularity, and EDR bypass.

The Evolution of Data Extortion TTPs: From Exploiting Code to Exploiting People
In this post we break down four eras of data extortion TTPs, tracing the strategic pivot from technical code exploits (SQL injection) to vishing and MFA fatigue, so security teams can harden human and cloud defenses against modern threat actors.

FUSE 2025: How Security Leaders Are Operationalizing Flashpoint Intelligence to Thwart Rising Threats
In this post, we summarize the critical themes that emerged at FUSE 2025, detailing how security professionals are operationalizing threat intelligence and leveraging AI to gain a decisive advantage over adversaries.

New Ransomware-as-a-Service (RaaS) Groups to Watch in 2025
In this post we take a deep dive into the ransomware-as-a-service (RaaS) landscape, highlighting new emerging threats, and analyzing the notable decline of once-dominant groups like LockBit and BlackCat.

Inside the LockBit Leak: Rare Insights Into Their Operations
In this post, we delve into the significant data breach affecting the LockBit ransomware group. This leak provides a rare opportunity for security defenders to gain critical insights into LockBit's operations.

The Top Ransomware Groups Targeting the Healthcare Sector
In this post, we identify and analyze the top ransomware groups that have been actively targeting the healthcare sector between January and April 2025.

Key Trends in Vulnerability Exploitation and Ransomware: Insights from the 2025 Verizon DBIR
Flashpoint, an official contributor to the 2025 Verizon Data Breach Investigations Report (DBIR), breaks down the key findings that Verizon finds are shaping the threat landscape.