Threat actors are increasingly turning massive infostealer-derived credential collections into searchable underground services, allowing buyers to request credentials for a specific company, platform, domain, geography, or account type.
Flare researchers analyzed 470 underground forum posts published between January 2025 and June 2026, across different sources, related to actors offering to search for and extract stolen credentials from their databases. The dataset included advertisements, reposts, buyer feedback, pricing references, and disputes around quality and validity.
The findings show a dedicated service layer sitting between infostealer infections, raw logs trading and account takeover activity. The profile of the threat actors who offer these services is divided between the Malware-as-a-Service (MaaS) providers and the MaaS consumers.
In many cases, they function as credential brokers or data processors, monetizing the vast number of logs and their ability to search, filter, format, and deliver targeted results from large stolen credential collections.
Advertisement
Key Points
Analysis of 470 underground posts illustrates a pinpointed service that offers targeted extraction, filtering, deduplication, formatting, and freshness, from large infostealers databases containing tens of billions of lines. It is functioning as an alternative to combo lists, where instead of purchasing a bulk dump, buyers query a seller’s existing data and receive only the results that match their target.
The market overlaps with the Initial Access Broker (IAB) ecosystem, but is not identical to it, when the common output formats included URL:LOGIN:PASS, MAIL:PASS, LOGIN:PASS, PHONE:PASS, MAIL:PHONE, and MAIL:LOGIN.
Interestingly buyer feedback showed there’s a gap between what is advertised and the actual results in terms of in reality the volume is lower, the credentials are often invalid, duplicated and generally usable.
How Does the “Search Your Target” Service Work
The “search your target” market sits in the middle of the account takeover chain.
First, infostealers infect devices and collect credentials, cookies, autofill data, and browser artifacts. Then logs are aggregated and inserted into private clouds, ULP databases, public dumps, or exchange-based collections. Next, the “search-service” threat actors extract rows based on buyers’ requests. Buyers then validate the credentials and use them for account takeover, fraud, spam, phishing, crypto theft, or corporate intrusion.
Advertisement
This means the sellers in this dataset are often neither the first nor final step. They are the processing layer that turns stolen credential noise into targeted attack material.
Figure 1 – the “search your target” flow
From a threat intelligence framework perspective, this service model represents a practical example of T1589.001 (Gather Victim Identity Information: Credentials), where adversaries actively research and acquire credentials prior to exploitation, and potentially T1650 (Acquire Access), given that some sellers deliver results indistinguishable from direct access provisioning.
From GitHub access sales to leaked vendor repositories, the warning signs exist — they’re just buried in forums and marketplaces most teams aren’t watching.
Much like in the DDoS market, where the buyer submits a domain and the service provider attacks it, the service is duplicated and offers the same pipeline.
Advertisement
A buyer sends a target
The seller returns matching credentials
That target can be a company domain, login URL, ecommerce site, gaming platform, application, geographic market, or a list of emails. The output is usually delivered in formats such as URL:LOGIN, URL:LOG, MAIL, LOGIN, PHONE, or other combinations depending on the request.
Several sellers in the underground specify the size of their database as a selling point. One actor advertised an “ULP 5kkk+ lines” database (5,000,000,000), quick access within 10–15 minutes, daily updates, and sources that allegedly included private logs, private clouds, personal streams, and public data. Another actor promoted a 10kkk+ line, 1TB+ URL:LOG database, while others claimed access to collections ranging from hundreds of millions to tens of billions of records.
Screenshot taken from Flare’s platform. Sign up for the free trial to access if you aren’t already a customer.
The size of the database isn’t the only selling point. Threat actors also indicate other capabilities, as part of their sales pitch. The sellers are also advertising their search capabilities, freshness, formatting, and relevance.
Some offer simple domain extraction, while others offer more customized services, such as extracting email accounts for a requested shop, website, app, or game. De-facto, attackers are advertising their technical capabilities of indexing data inside databases, updating and enabling quick and convenient search on it.
Advertisement
As an example, one of the sellers advertised that customers could submit a request for only $20 per request, and add additional payment based on the returned results.
Screenshot taken from the forum of one of the posts in the dataset
The dataset also showed more advanced forms of credential enrichment. One actor claimed access to separate email, password, login, phone, and URL:Login collections, and described how those records could be combined.
For example, a buyer with only an email list could request matching login pairs, or a buyer looking for a specific geography could receive results built from country codes, domains, URLs, cities, and password patterns.
This further indicates that threat actors are using data best practices (e.g. labeling, slicing), much like ordinary legitimate businesses around the world.
Customers Feedback Shows a Gap Between Ads and Reality
Customer feedback indicates that the sellers are over-promising and under-delivering. They claim that some sellers aren’t credible. Some claim that the credentials are invalid, and sellers answer in return that they didn’t ever check if the credentials were valid. Some said that this is the same data that appears in large combo lists published for free across the underground.
Advertisement
Others claim that these databases contain many duplications (one even claimed that out of 3,000 records only 200 were unique).
While the concept of large combo lists or aggregated credential files, isn’t new. This service is still something unique that can eventually, if operated correctly, put a lot of businesses and organizations at risk.
Developed Alongside the Infostealers Market
Over the past several years, infostealer families and log marketplaces produced enormous quantities of records that include browser-stored credentials, cookies, autofill data, and device information. These collections are constantly growing and create a challenge for buyers to sort it out for profit.
The operation to more easily extract value was an opportunity for commercialization. Therefore, a buyer who usually has a specific pinpointed goal can save time and money with this service.
Advertisement
Comparison Between the “Search Your Target” Market and the IAB Market
The “search your target” market is often tied to a general search for an email or business or person, the validity and “freshness” of access isn’t guaranteed, and you are basically paying for search, find, and results. This market partially overlaps with the initial access broker’s (IAB) market.
When buyers are looking for access to corporate VPNs, SaaS platforms, email accounts, cloud environments, admin panels, or remote access systems, the output can become initial access if these markets overlap.
Nevertheless, the IAB market is often more expensive, prestigious and serves as a “white glove service” when they sell validated access, which often can bypass MFA, and ultimately get into an organization.
What Defenders Should Learn
The “search your target” market shows that attackers no longer need to manually process massive dumps to find what matters. They can outsource that work to sellers who specialize in turning noisy credential collections into focused target lists. For defenders, the challenge is to identify and close those exposed paths before a buyer turns them into access.
Advertisement
Flare helps by giving security teams visibility into these underground markets and by monitoring exposed employee credentials, corporate domains, login portals, SaaS applications, and related indicators across deep and dark web sources.
This allows organizations to detect when their access points appear in credential collections or search-service advertisements, prioritize the most relevant exposures, and respond faster with password resets, session revocation, MFA enforcement, and investigation of possible account misuse.
Brendan Carr and the Trump FCC are finalizing plans to illegally eliminate what’s left of the country’s already barely functional media consolidation limits; a specific gift to Trump-friendly right wing broadcasters that are hoping to monopolize what’s left of local U.S. broadcast news so they can more efficiently spread propaganda and kiss the president’s ass.
Current laws (remember those?) prohibit any single local broadcast news company from serving more than 39 percent of all TV households in the US. The original (good) idea was that this helped protect opinion diversity and competition in the local broadcast news space. Republicans don’t like that, because they want to replace all journalism with right-wing and oligarch friendly propaganda.
Brendan Carr last March had already made it clear he viewed the law as optional when he granted Nexstar Media Group a waiver for its $6.2 billion acquisition of Tegna. That deal would let the company reach more than half of all U.S. households with what passes as “local news.” Now he’s trying to replace a congressionally-approved law with a “case by case review” dictated by Republican whims:
“Carr now plans to repeal the 39 percent limit and replace it with a “case-by-case review” of each proposed merger, the chairman announced today in an op-ed published on Breitbart. The change would make it easier for the FCC to pick and choose which station groups get to surpass the limit. Under Carr, this would likely benefit news companies that provide favorable coverage for President Trump.”
This is, to be clear, illegal. Something the FCC’s lone Democrat, Anna Gomez, made clear in her own statement:
Advertisement
“This unlawful effort to hand control of the public airwaves to billionaire buddies of this administration will destroy local newsrooms, silence community reporting, and drive-up costs for the American families who depend on local stations for news and emergency alerts. A free and diverse media landscape depends on real limits on how much of the public airwaves any one company can control, and this FCC is now poised to allow local broadcasters to sell those airwaves off to the highest bidder. Congress set the 39 percent national ownership cap in federal law, and only Congress has the authority to raise or eliminate it. The Commission cannot waive away that limit simply because these corporate behemoths want to get out from under it.”
Clearly there will be lawsuits, though they’re likely to drag on until long after Nexstar and Tegna have merged, with future regulators being very unlikely to unwind the transaction. I’d then expect to see Sinclair Broadcasting to merge with the remaining company, creating a monopoly over local broadcast TV.
While people are quick to insist that “who cares, nobody watches this stuff,” they don’t seem to realize that somewhere around 80 million households still watch local broadcast TV channels via antenna, cable TV, streaming providers, or satellite.
As I’ve frequently discussed, most of these local broadcasters deliver a sloppy combination of lazy infotainment and right-wing agitprop, as that viral video about Sinclair Broadcasting made clear a few years back:
Advertisement
Carr’s very unsubtle goal here is to turn the entirety of U.S. local broadcast television into propaganda arms of the U.S. right wing. That’s not an opinion or hyperbole, and he’s well on his way already. It might help if there was a functional opposition party that had made meaningful media reforms a centerpiece of their political platform anytime in the last quarter century.
And this is, of course, just local broadcast TV. We’ve also got Carr’s FCC helping Larry Ellison do the same thing to CBS and CNN. Ellison’s also steadily doing the same thing to TikTok while Elon Musk does the same thing to what used to be Twitter. If you stand back, tilt you head, and squint just right, you might begin to notice a consistent theme.
These days, it is easy to think you always have access to the Internet. But some wonder if — in spite of its ARPANET, nuclear-war-planning heritage — you can actually count on it to be there when things go pear-shaped. [The Tech Prepper], as you might imagine, is quite concerned with that last question, and is flogging Reticulum over high-frequency radio as a post-internet network in a video embedded below.
Reticulum is a cryptographic network stack, fully decentralized and amazing from a cyberpunk/hacker/survivalist perspective. Unfortunately for [The Tech Prepper], until the you-know-what hits the ventilation unit and the FCC and its counterparts in other countries are too busy to be concerned with such trifles, encrypted signals are banned on ham radio bands just about everywhere. That’s why his demo is using a dummy load on the Mercury HF modem instead of an antenna: the feds don’t care if the signal doesn’t leave the building. The video shows how to replicate the setup using his EmComm Tools suite on Ubuntu.
Perhaps more interesting is his vision of a Post-Internet network, be it in a disaster scenario, as he envisions, or simply because we get sick of what the internet has become. The idea of easily hooking an open-source radio modem to a PC running modem73, open-source SDR software, has a certain appeal. Reticulum isn’t your only option there: modem73 will let you run a BBS in the clear — that is, unencrypted and legal to transmit — and let’s face it, wasn’t life online more fun in BBS days?
Advertisement
This isn’t the first time we’ve seen the Reticulum network stack, but last time it was operating at considerably shorter ranges over LoRA.
Finding another planet outside of our solar system that can comfortably be called ‘Earth-like’ is one of those discoveries that — if confirmed — would be a major event. The complication here is that with every exoplanet that we discover through observations, determining the type of planet is hard enough, never mind figuring out whether it has an atmosphere, much less what’s in that atmosphere. This makes a recent report on LHS 1140 b rather exciting, as it strongly suggests that this super-Earth may have something close to an Earth-like atmosphere.
In the paper by [Collin Cherubim] and others in Science, the findings of helium occasionally escaping from its atmosphere have led to considerable excitement, as this time-variable atmospheric escape of helium suggests a helium-rich upper atmosphere that’s further depleted in hydrogen.
It should be noted, of course, that these assumptions are based on observations from roughly 49 light-years away, so there’s always some room for later adjustments. Even if confirmed, the star that LHS 1140b orbits is a red dwarf, with a nearly 25-day orbital period and light levels less than half of what Earth receives from the Sun. This would make the surface of LHS 1140b with its proposed oceans rather dim, even if it’s conceivably at temperatures well within the comfort range of us Earth-based mammals.
Advertisement
At 49 light-years distance, it’s also not close enough that — barring an FTL drive — we could do direct observations or visitations, but if these results hold, it’d be on the short list along with a number of other plausibly habitable exoplanets to check out once we build that first warp drive-powered starship.
Research from ServiceNow indicates an 18-point gap between AI strategy and execution in EMEA.
Despite massive artificial intelligence spending, European businesses are struggling to turn their investments into measurable results, a new ServiceNow index has found.
Organisations across Europe, the Middle East and Africa (EMEA) scored 51 out of 100 for their overall AI maturity – up 34pc since last year – but only managed to hit 40 points when it comes to actual AI-enabled workflows.
Leadership, vision and strategy scores reached 58, according to the report, which surveyed more than 4,700 senior executives across 16 countries. 1,700 were based across EMEA.
Advertisement
Business are paying for AI capability that they haven’t yet unlocked, the report found, with only 16pc of those surveyed saying they replaced fragmented legacy systems with an integrated platform.
And while 59pc of the surveyed professionals said their organisations had moved beyond piloting agentic AI, only 9pc said they have made “meaningful progress” towards building autonomous, multistep workflows.
This comes as global corporate AI spending hit $581bn in 2025, with projections estimating that AI will represent more than 20pc of an organisation’s IT budget by 2027. Government AI spend, meanwhile, rose 140pc year over year, more than any other industry surveyed.
ServiceNow pointed to data quality, governance and workflow foundations as “critical barrier[s]” to scaling AI across the enterprise sector.
Advertisement
It also found that businesses based in Ireland that already operate against rising costs and tighter margins are facing added pressures.
“Organisations in Ireland are among the most ambitious on AI in Europe. The challenge isn’t commitment. It’s connecting that commitment to the operational infrastructure that makes AI work across the enterprise and, more importantly, getting it live with the right guardrails and governance,” explained Paul Turley, senior director at ServiceNow Ireland.
“The organisations that have closed that gap are already seeing returns the rest have yet to match. The contrast is stark – those bridging the gap aren’t just using AI more, they’re using it differently, running autonomous, multi-step workflows at roughly 18 times the rate of the rest of the market.”
Advertisement
ServiceNow’s survey found data to be the biggest barrier to AI execution, with 73pc of EMEA executives citing inadequate data accuracy, access and management as a major barrier.
Only 57pc of surveyed organisations in the region use agentic AI, of which only 9pc use the technology to create autonomous workflows, according to ServiceNow, meaning AI is merely assisting employees without a significant change in how an organisation works.
Meanwhile, only 19pc of EMEA organisations said they have implemented AI testing, auditing and risk processes, despite the bloc’s strict rules.
ServiceNow finds governance maturity as the defining factor between organisations succeeding in the AI race and those lagging behind.
Advertisement
These organisations combine strong data management, testing and risk controls with integrated workflows, enabling them to scale AI confidently, according to the report, and as a result, managed to deliver a 164pc return on investment and expect 199pc ROI within two years.
“Mature governance enables these organisations to scale confidently and move faster than their peers. For Irish businesses, the EU AI Act makes governance unavoidable, but the Index shows it should be welcomed rather than resisted,” said ServiceNow.
Don’t miss out on the knowledge you need to succeed. Sign up for the Daily Brief, Silicon Republic’s digest of need-to-know sci-tech news.
China’s passenger car sales fell 20.2% in H1 2026 to 8.7M units. ICE vehicles down 39% in June. Exports up 82%. Industry margins at 3.4%. A shakeout is coming.
China’s passenger car sales fell 20.2% in the first half of 2026 to 8.7 million units, and the China Passenger Car Association has lowered its full-year forecast to a 14% decline, projecting 20.4 million deliveries, down from a record 23.7 million in 2025. Citic CLSA’s Xiao Feng expects a 20% full-year drop. “This is going to continue to be a brutal year,” said Tu Le, founder of Sino Auto Insights.
The collapse is concentrated in petrol cars. Retail sales of internal combustion engine vehicles fell 39% year-on-year in June, with pure gasoline models down 42%, accounting for 78% of the total decline that month. Transportation energy costs soared 15.3% year-on-year in June, crushing demand for cars that burn fuel. On the electric side, Beijing’s pullback of NEV subsidies that had stimulated record 2025 sales is now pulling demand forward in reverse. “Policy only moves demand around,” Feng told CNBC. Even new energy vehicle sales are expected to fall 5-6%.
Automakers are being squeezed from both ends. Battery input costs, including lithium and memory chips, are rising. Industry profit margins fell to 3.4% in January-May, while industry profits dropped 20% year-on-year. Passenger vehicle prices fell more than 1% in June, further thinning already razor margins. Feng estimates a Chinese automaker needs 500,000 annual sales to break even, 1 million for sustainable profits, and 2 million for full economies of scale. He expects the market to consolidate to seven or eight players by 2030, with BYD (1.8 million H1 sales), Geely (1.4 million), and Leapmotor (356,000) among the survivors alongside Volkswagen and Toyota. Chinese automakers are opening new markets, from Canada to the UK, precisely because the domestic market can no longer absorb their output.
Exports are the lifeline. Total passenger vehicle exports surged 82.3% year-on-year to 877,000 units in June. Chinese EV content is flooding American social media even though 100% tariffs block the cars themselves. The Middle East conflict has driven fuel costs higher worldwide, pushing overseas consumers toward cheaper Chinese EVs. Feng expects a rebound in 2027 as vehicle fleets age and replacement cycles kick in. But between now and then, the shakeout will decide which companies are still around to benefit.
Days after a rival Chinese lab shook Silicon Valley, Alibaba has fired back. The company previewed Qwen3.8, its most powerful model yet, and made a bold claim: it trails only one model on Earth.
Alibaba unveiled the model at the World Artificial Intelligence Conference in Shanghai. Its Qwen team said on X that Qwen3.8 is “second only to Fable 5,” a nod to Anthropic’s latest release. Alibaba shares rose as much as 5.4% on Monday.
What Qwen3.8 is
The model holds 2.4 trillion parameters. That makes it the first in the Qwen family above a trillion to be multimodal, meaning it handles images, video and documents as well as text.
Alibaba says Qwen3.8 should beat its own previous flagship, especially at coding and office work such as full-stack development and data analysis. Lead developer Shuai Bai called it the team’s first trillion-parameter multimodal model, with understanding that he said matches or beats leading proprietary systems.
Advertisement
The 💜 of EU tech
The latest rumblings from the EU tech scene, a story from our wise ol’ founder Boris, and some questionable AI art. It’s free, every week, in your inbox. Sign up now!
The preview is available now. It runs through Alibaba’s Token Plan subscription and its Qoder developer tools, priced at 10% of the standard rate during the trial. Full open weights are promised “soon,” with no date and no licence terms yet.
A claim without the receipts
Here is the catch. Alibaba offered no benchmark scores, no model card, and no independent test to back the “second only to Fable 5” billing, SiliconANGLE reported.
Advertisement
That is a shift for the company. Its last flagship, Qwen3.7-Max, shipped in May with a full set of published results. This one arrived with none.
The gap matters because the comparison is Alibaba’s own. No public leaderboard has scored Qwen3.8. On LMArena, where Fable 5 sits at number one, the older Qwen3.7-Max ranks well down the list. The weights, once released, would let outside researchers check the claim. For now, they cannot.
The open-weight arms race
The timing is no accident. The launch came three days after Moonshot released Kimi K3, a 2.8-trillion-parameter open model that topped a major coding leaderboard and rattled US chip stocks. Alibaba’s move reads as a direct answer, The Decoder noted.
A cluster of Chinese labs is now shipping models at a scale once reserved for the biggest US labs. Moonshot has Kimi K3. Zhipu has GLM-5.2. All are chasing the frontier, and most are handing out their weights for free.
Advertisement
There is a strategic wrinkle. Alibaba, like Moonshot, is putting the model in paid products first and releasing the weights later. It turns the launch buzz into customers before anyone can run the model for nothing.
The bigger signal is what Alibaba is promising to open up at all. Its largest models have not usually been open-weight, a point several analysts flagged. “Something is changing,” the AI researcher Nathan Lambert wrote, reading the shift as a new phase of competition among Chinese labs.
Handing over a claimed number-two system, if the weights match the hype, would push the open-weight field deeper into frontier territory. That is the ground US labs have guarded most closely. The proof, though, lands only when the download does. Until then, Alibaba is asking the market to take its word for it.
Samsung is expected to announce the Galaxy Watch Ultra 2 on Wednesday.
Holgs/Getty Images
We’re just two days out from Samsung’s Galaxy Unpacked event, but that’s still enough time for more leaks. This time it’s the Galaxy Watch Ultra 2, which is set to be announced at the event. Evan Blass, who runs the Substack Leakmail, has published a slew of renderings depicting the new smartwatch.
We got a first look at the Galaxy Watch Ultra 2 design earlier this month thanks to Android Headlines, but Leakmail’s post includes new perspectives and specs. For instance, the leaked photos show an upgrade to an IP69K dust- and water-resistance rating, compared to the 2025 Galaxy Watch Ultra’s IP68 rating. They also state that the new model is 12% thinner than its predecessor.
If the leak is accurate, the Galaxy Watch Ultra 2 will come with an 800 mAh battery, up from 590 mAh on the 2025 model. The latest watch should also offer a much brighter display with up to 5,000 nits, a significant boost from 3,000 nits.
Advertisement
As for performance, Blass claims the watch will use the Snapdragon Wear Elite chip, corroborating another leak from last week. According to a separate leak from Blass, the upcoming Galaxy Watch 9 will be powered by the same chip.
We’ll have to wait until Wednesday to get confirmation — and price points — for Samsung’s new flagship wearable.
The Hugging Face artificial intelligence repository disclosed that attackers gained access to internal datasets and credentials after breaching its production infrastructure using an autonomous AI agent system.
Hugging Face is an open-source AI and machine learning platform that provides access to over 45,000 models from leading AI providers and is used by more than 50,000 organizations.
The company is still investigating whether partner or customer data was affected and said it would contact any affected parties directly. Hugging Face said it has found no evidence of tampering with public-facing models, datasets, or Spaces to date, and that its software supply chain has been “verified clean.”
The intrusion began in Hugging Face’s data-processing pipeline, with the attackers using a malicious dataset to exploit two code-execution vulnerabilities and run code on a processing worker. This allowed them to steal cloud and cluster credentials and move laterally across several internal clusters.
“The campaign was run by an autonomous agent framework (appearing to be built on an agentic security-research harness – used LLM still not known) executing many thousands of individual actions across a swarm of short-lived sandboxes, with self-migrating command-and-control staged on public services,” Hugging Face said in an incident disclosure published Thursday. “This matches the ‘agentic attacker’ scenario the industry has been forecasting.”
Advertisement
In response to the breach, Hugging Face has closed the vulnerable code execution paths (a template injection in a dataset configuration and a remote code dataset loader), evicted the attacker, rebuilt the compromised nodes, and revoked and rotated all affected credentials.
It also deployed improved malicious activity detection systems, reported the incident to law enforcement, and is now working with external forensic experts to assess the breach’s impact.
“We do not know which model powered the attacker’s agents, whether a jailbroken hosted model or an unrestricted open-weight one; either way, the attacker was bound by no usage policy, while our own forensic work was blocked by the guardrails of the hosted models we first tried,” Hugging Face added.
“The practical lesson for defenders: have a capable model you can run on your own infrastructure vetted and ready before an incident, both to avoid guardrail lockout and to keep attacker data and credentials from leaving your environment.”
Advertisement
Hugging Face advised users to rotate access tokens and review recent account activity for signs of suspicious behavior and said it would continue sharing findings on defending against AI-driven attacks.
While this is the first security incident affecting the platform that has been linked to an AI agent, it’s not the first breach disclosed by Hugging Face in recent years.
The company also revoked some members’ authentication secrets and advised them to switch to fine-grained access tokens two years ago after hackers breached its Spaces platform.
NordStellar reports 2,581 ransomware attacks in Q2 2026, with Qilin (299) and The Gentlemen (284) leading activity, far ahead of DragonForce (147)
US SMBs were hit hardest, suffering 769 incidents; Canada (97), Germany (83), and the UK (74) followed, while attacks on billion‑dollar enterprises surged 74%
Experts say rivalry between Qilin and The Gentlemen is driving the spike, with major corporate hits seen as reputation‑boosting trophies in the cybercriminal underground
Two ransomware gangs are battling for dominance, and US-based SMBs are the ones suffering most for it, experts have claimed.
Fresh data about the state of ransomware in 2026, compiled by security experts from NordStellar, shows two groups – Qilin and The Gentlemen – being by far the most active ones.
After analyzing more than 200 threat actor blogs, NordStellar concluded that there were 2,581 ransomware attacks in the second quarter of the year – and of that number, 299 belong to Qilin, the most active threat actor out there. Close second are The Gentlemen, with 284 attacks. The third most active group – DragonForce – doesn’t even come close with “just” 147 attacks.
Latest Videos From
SMBs and enterprises under assault
While it seems like a close race, it’s actually The Gentlemen who have been doing the heavy lifting between April and June 2026. This group experienced a 39% increase in attacks, while Qilin’s activity actually declined somewhat, compared to Q1.
Advertisement
In this morbid race to the bottom, the biggest victims are US-based small and medium-sized businesses (SMB). These companies, with up to 200 employees and revenues under $25 million, experienced 769 attacks in Q2 2026, followed by Canada (97), Germany (83), and the UK (74).
NordStellar also mentioned US enterprises, who are now increasingly being targeted. Attacks against organizations with revenues north of $1 billion surged by 74%, going from 23 incidents in Q1, to 40 in Q2.
“Ransomware actors historically target SMBs because these organizations often lack comprehensive defenses, which can increase the likelihood of a successful attack,” commented Vakaris Noreika, cybersecurity expert at NordStellar.
Advertisement
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
“This recent spike in enterprise targeting is unusual and may be a temporary fluctuation. This shift likely stems from the rivalry between dominant threat actors — a successful hit on a major corporation is a badge of honor that boosts a group’s reputation within the cybercriminal underground.”
In Obsession, an awkward young man gets more than he bargained for when he wishes for his crush to love him back with the help of a gag gift from a novelty store. After a rocky start, Bear gets what he wanted… sort of… before his relationship with Nikki takes a series of increasingly bizarre turns and goes completely off the rails.
In his feature film debut, writer, director, and editor Curry Barker demonstrates one of those uniquely original voices that makes us rethink what a horror movie can be, shocking even genre buffs and video reviewers who think they have seen it all. With tips of the cap to The Twilight Zone and Get Out, the script takes us places we have never been, growing deeper and darker while maintaining a surprising amount of humor in perfect balance.
The performances help tremendously, with the lead actors bringing a naturalistic edginess that ensures we never quite know what to expect next. Props to newcomer Inde Navarrette as Nikki, who is so terrifying that she reportedly made her costars, and herself, quite uncomfortable.
The movie is presented in the unusual 1.5:1 aspect ratio, with vertical black bars on the left and right and occasional elements within the frame that add to the sense of claustrophobia, as though the characters are trapped in their predicament. Director of photography Taylor Clemons often backlights the actors to creepy effect, but the high dynamic range preserves ample facial detail, while the precise image reveals haphazard shaving stubble, the fine fibers of a sweater, and the uneven degrees of focus within the frame.
You could call the sonic jolts in Obsession’s Dolby Atmos mix “jump scares,” but not in the same way as in, say, a Freddy or Jason style slasher. Instead, an abrupt beat might trigger the question, “What the hell is she going to do next?” The answer: Nothing good. Hard offscreen cues do a good job of establishing three-dimensional space, while Rock Burwell’s musical score envelops us but also bludgeons us from time to time, leaving us exhausted by the end credits.
Advertisement
Barker’s audio commentary track is definitely worth a listen for the infectious energy of a filmmaker at the top of his game. In a hurry? Check out the 19-minute “Obsession Unleashed” featurette, which also brings in the principal actors to share their own behind-the-scenes tidbits. The two-disc set includes an HD Blu-ray of the movie with the same extras, plus a 4K Movies Anywhere digital copy code.
This is definitely one I’ll be watching again, which is another reason physical media rocks. There are plenty of clues and little Easter eggs waiting to be discovered and dissected, a testament to the thoroughly smart script and the clever way Barker executes his twisty vision.
Movie Details
STUDIO: Universal Pictures Home Entertainment
FORMAT: Ultra HD 4K Blu-ray (July 14, 2026)
THEATRICAL RELEASE YEAR: 2026
ASPECT RATIO: 1.50:1
HDR FORMATS: Dolby Vision, HDR10
AUDIO FORMAT: Dolby Atmos with TrueHD 7.1 core
LENGTH: 109 mins.
MPAA RATING: R
DIRECTOR: Curry Barker
STARRING: Inde Navarrette, Michael Johnston, Cooper Tomlinson, Megan Lawless, Andy Richter, Darin Toonder
You must be logged in to post a comment Login