Allan “Ransomware Sommelier” Liska
banner
ransomwaresommelier.com
Allan “Ransomware Sommelier” Liska
@ransomwaresommelier.com
Recorded Future - Ransomware Researcher

Owner @greenarcher.io - Yours Truly, Johnny Dollar | The Press Guardian | The Clock | The Green Archer

Weird mix of security, comics, photography and wine!

www.greenarcher.io
Flying from SFO to IAD during Sunday Night Football and the plane does not have a scream room. @amandagodsey.bsky.social I think you should report on this travesty.
a young boy wearing a soccer jersey is screaming in a crowd of people .
ALT: a young boy wearing a soccer jersey is screaming in a crowd of people .
media.tenor.com
November 10, 2025 at 12:20 AM
Looks like Manassas City in Virginia was hit with a ransomware attack.

cc @andyjabbour.bsky.social
Manassas city schools closed Monday due to cybersecurity incident
Manassas City Public Schools will be closed on Monday after the school system experienced a cybersecurity incident over the weekend, Superintendent Kevin Newman announced Sunday.
www.insidenova.com
November 9, 2025 at 11:34 PM
Monterey airport has a lovely outdoor seating area where you can have a drink and watch the planes take off…
November 9, 2025 at 9:23 PM
Reposted by Allan “Ransomware Sommelier” Liska
Editor: We need more clock puns!

Writer: What if I fit FIVE into one panel?

Editor: kid! You got moxie, I’ll give you that! If you fit five in one panel there’ll be an extra $2 in your paycheck!

Writer: A whole deuce? Watch me work!
November 9, 2025 at 8:14 PM
Normally, I read through @zackwhittaker.com newsletter on Sunday and find a couple of things I missed, but with my travel schedule this week I missed a lot...thanks for catching me up Zack!

And, hopefully, you all are reading and subscribing to his newsletter as well!
this week in security — november 9 2025 edition
SonicWall blames nation-state for theft of firewall backups, CBO hacked, Korea Telecom covered up hacks, North Korea's remote IT workers' scheme, and more.
this.weekinsecurity.com
November 9, 2025 at 4:28 PM
Folks! This is big!

We have a full blown trilogy in our BAFTA-nominated series: Today’s interesting newly registered ransomware-themed domain name:

ransomware-response-team[.]com

Critics will be debating for years which one of these is the best, but I think we all know the answer…
November 9, 2025 at 3:29 PM
I hope someone makes a statue of me just like this one day…sitting on a corner, playing my according, being happy.
November 9, 2025 at 3:18 AM
This is all terrible.

But, if we get a sequel to Planes, Trains and Automobiles out of it that would be pretty amazing!
November 7, 2025 at 7:40 PM
Nevada ransomware attack traced back to malware download by employee
Nevada ransomware attack traced back to malware download by employee
The state refused to pay a ransom and recovered 90% of the impacted data.
www.cybersecuritydive.com
November 7, 2025 at 7:37 PM
For a minute I thought @theonion.com was talking about ransomware.
November 7, 2025 at 7:06 PM
In a first for this series, WE HAVE A SEQUEL!

Today’s interesting newly registered ransomware-themed domain is:

ransomware-response-team[.]info

Remember, with few exceptions, the sequel is never as good as the original. And the original wasn’t great in the first time place.
November 6, 2025 at 2:56 PM
Uhhh..no dear, I didn't subscribe to that porn site, the hackers did!

"...stolen credit card data from over 4.3 million cardholders worldwide to set up about 19 million fake online subscriptions to pornography, dating and streaming websites."

via @darynant.bsky.social & @therecordmedia.bsky.social
Europe police bust global fraud ring that used German payment firms to launder millions
The cross-border investigation led to more than 60 house searches and 18 arrests across Germany, the U.S., Canada, Singapore, Luxembourg, Cyprus, Spain, Italy and the Netherlands.
therecord.media
November 5, 2025 at 8:22 PM
Reposted by Allan “Ransomware Sommelier” Liska
State-backed hackers are for the first time deploying malware that uses large language models during execution, allowing them to dynamically generate malicious scripts and evade detection, according to new research from Google Threat Intelligence Group

therecord.media/new-malware-...
New malware uses AI to adapt during attacks, report finds
Researchers at Google said Wednesday that they recently observed malware "that employed AI capabilities mid-execution to dynamically alter the malware's behavior."
therecord.media
November 5, 2025 at 2:07 PM
Today's interesting newly registered ransomware-themed domain name is:

ransomware-response-team[.]store

Honestly, my only thought when I saw this was...
a man in a suit and tie says well the jerk store called and they 're running out of you .
ALT: a man in a suit and tie says well the jerk store called and they 're running out of you .
media.tenor.com
November 5, 2025 at 3:39 PM
F me…

This is really good, and sad, reporting from @schuba.bsky.social

Justice like the hackers have access too all our red team tools, most of us have access to the attackers tools. I guess, for some, the lure is too great - no matter how many people get hurt.
Chicago firm that resolves ransomware attacks had rogue workers carrying out their own hacks, FBI says
Employees of DigitalMint, a company that specializes in negotiating ransoms in cyber attacks, were part of a small crew the feds say conducted five hacks that scored more than $1 million.
chicago.suntimes.com
November 3, 2025 at 3:22 PM
There’s a Chuck E Cheese in the parking lot next to my hotel…sadly it’s already closed.
November 3, 2025 at 4:54 AM
I guess I need to not watch games more often 🤷!

Great win #HereWeGo!

Aaron Rodgers still sucks.
The Steelers take down the Colts with an absolutely incredible defensive performance.

Final:

Steelers 27
Colts 20
November 3, 2025 at 12:15 AM
CIA cyberattacks targeting the Maduro regime didn’t satisfy Trump in his first term. Now the US is [ILLEGALLY] flexing its military might

via @snlyngaas.bsky.social, Katie Bo Lillis and Kylie Atwood
CIA cyberattacks targeting the Maduro regime didn’t satisfy Trump in his first term. Now the US is flexing its military might | CNN Politics
In the final year of President Donald Trump’s first administration, the CIA carried out a clandestine cyberattack against the Venezuelan government, disabling the computer network used by Venezuelan l...
www.cnn.com
November 2, 2025 at 8:53 PM
Sadly, because of flight delays I didn't get to spend too much time touring Old Town Riga, but what I saw was really beautiful, especially in the fall.
Old Town Riga - Fall 2025 - allan
This gallery hosted by SmugMug; your photos look better here.
www.allan.photo
November 2, 2025 at 3:21 PM