:

RANSOMWARE NEGOTIATOR PLEADS GUILTY TO BLACKCAT ATTACKS

SECURITY DESK1 MIN READ
TUE, APR 21, 2026

■ AI-SUMMARIZED FROM 1 SOURCE BELOW

Angelo Martino, 41, a former cybersecurity incident response employee at DigitalMint, has pleaded guilty to participating in BlackCat (ALPHV) ransomware attacks targeting U.S. companies in 2023.

Martino's role at DigitalMint gave him insider knowledge of victim networks and negotiation strategies, which he leveraged to facilitate BlackCat operations. The guilty plea marks a significant development in the ongoing investigation into the ALPHV ransomware-as-a-service operation, one of the most active threat groups in recent years. BlackCat has been linked to hundreds of attacks on organizations across critical infrastructure, healthcare, finance, and manufacturing sectors. The group is known for its sophisticated double-extortion tactics and use of the Rust programming language in its malware. Martino's case underscores the insider threat risk in cybersecurity firms, where employees possess detailed knowledge of corporate security postures and incident response procedures. Federal prosecutors have not yet announced sentencing details or whether additional charges are pending. The investigation into BlackCat operations continues across multiple jurisdictions.

■ SOURCES

Bleeping Computer

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

The Cybersecurity and Infrastructure Security Agency has flagged a new Catalyst SD-WAN Manager vulnerability being actively exploited in attacks, demanding U.S. government agencies patch systems within four days.

1H AGOSecurity Desk

Quantum computers pose no practical threat to 128-bit symmetric encryption, according to cryptographic analysis. The computational resources required make such attacks infeasible even with advanced quantum systems.

1H AGOIndustry Desk

Shadowserver identified over 6,400 Apache ActiveMQ instances exposed online and currently targeted by attackers exploiting a high-severity code injection vulnerability.

2H AGOSecurity Desk

A new NGate malware variant is targeting Android users through a trojanized version of HandyPay, a legitimate mobile payments app. The malware steals NFC payment card data from infected devices.

3H AGOSecurity Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.