Security Affairs newsletter Round 479 by Pierluigi PaganiniSecurity Affairs·Jul 7, 09:14 UTC · Jul 7, 2024RansomwareCVE-2021-40444CVE-2024-0769CVE-2024-23692+1 CVEs60
IT threat evolution Q3 2022Kaspersky Securelist·Nov 18, 08:00 UTC · Nov 18, 2022RansomwareCVE-2017-1027160
Ransomware Gang Exploits SimpleHelp RMM to Compromise Utility BillingInfosecurity Magazine·Jun 13, 11:00 UTC · Jun 13, 2025Ransomware in the wildCVE-2024-57727CVE-2024-57728CVE-2024-5772660
CLOP targets Gladinet CentreStack servers in largeSecurity Affairs·Dec 19, 11:48 UTC · Dec 19, 2025Ransomware in the wildCVE-2025-11371CVE-2025-30406CVE-2025-61882+2 CVEs60
Analysis of Cuba ransomware gang activity and toolingKaspersky Securelist·Sep 11, 10:00 UTC · Sep 11, 2023RansomwareCVE-2021-31207CVE-2021-34473CVE-2021-34523+8 CVEs60
Andariel deploys DTrack and Maui ransomwareKaspersky Securelist·Aug 9, 14:25 UTC · Aug 9, 2022RansomwareCVE-2017-1027160
Healthcare organizations implementing zero trust to tackle cyberattacksHelp Net Security·Feb 5, 13:47 UTC · Feb 5, 2024Ransomware60
Updated PClock Ransomware Still Comes Up ShortPalo Alto Unit 42·Jan 28, 22:09 UTC · Jan 28, 2022Ransomware57
GhostSec’s joint ransomware operation and evolution of their arsenalCisco Talos·Mar 5, 13:00 UTC · Mar 5, 2024Ransomware60
Threat Brief: Office Documents Can Be Dangerous (But We’ll Continue to Use Them Anyway)Palo Alto Unit 42·Sep 21, 18:41 UTC · Sep 21, 2020Ransomware in the wildCVE-2018-4878CVE-2017-11882CVE-2018-0802+4 CVEs160
North Korean Hackers Spotted Using New MultiThe Hacker News·Jul 23, 09:18 UTC · Jul 23, 2020Ransomware57
Oracle EBS Under Fire as Cl0p Exploits CVE-2025-61882 in RealThe Hacker News·Oct 8, 04:30 UTC · Oct 8, 2025Ransomware in the wildCVE-2025-6188260
Head Mare and Twelve: Joint attacks on Russian entitiesKaspersky Securelist·Mar 13, 10:07 UTC · Mar 13, 2025RansomwareCVE-2023-38831CVE-2021-2685560
U.S., U.K. and Australia Warn of Iranian Hackers Exploiting Microsoft, Fortinet FlawsThe Hacker News·Nov 22, 07:14 UTC · Nov 22, 2021Ransomware in the wildCVE-2021-34473CVE-2020-12812CVE-2019-5591+1 CVEs60
Chaos ransomware's msaRAT: Living off the browser to build a covert C2 channelCisco Talos·Jul 23, 10:00 UTC · Jul 23, 2026Ransomware57
Attackers exploited a Mitel VOIP zeroSecurity Affairs·Jun 25, 11:59 UTC · Jun 25, 2022RansomwareCVE-2022-2949960
Chaos ransomware deploys browser-based msaRAT to evade network detectionSecurity Affairs·Jul 23, 18:27 UTC · Jul 23, 2026Ransomware57
TrickBot targets Italy using fake WHO Coronavirus emails as baitSecurity Affairs·Mar 6, 13:23 UTC · Mar 6, 2020Ransomware57
Ransomware attackers quickly weaponize PHP vulnerability with 9.8 severity ratingArs Technica · Security·Jun 15, 00:00 UTC · Jun 15, 2024Ransomware57
French Transport Giant Exposes 57,000 Employees and Source CodeInfosecurity Magazine·Dec 8, 10:25 UTC · Dec 8, 2021Ransomware57
Threat Source newsletter (Oct. 28, 2021)Cisco Talos·Oct 28, 18:00 UTC · Oct 28, 2021Ransomware in the wildCVE-2021-41733CVE-2021-4201360
Threat Source newsletter (Oct. 14, 2021)Cisco Talos·Oct 14, 18:00 UTC · Oct 14, 2021Ransomware in the wildCVE-2021-40461CVE-2021-38672CVE-2021-41733+1 CVEs60
Evolution of Mallox: from private ransomware to RaaSKaspersky Securelist·Sep 4, 10:01 UTC · Sep 4, 2024Ransomware57
New Ransomware-as-a-Service Tool ‘Thanos’ Shows Connections to ‘Hakbit’Recorded Future·Jun 29, 00:00 UTC · Jun 29, 2026Ransomware57
Hackers Targeting Critical Healthcare Facilities With Ransomware During Coronavirus PandemicThe Hacker News·Apr 15, 00:00 UTC · Apr 15, 2020RansomwareCVE-2012-015860
Interlock Ransomware Exploits Cisco FMC Zero-Day CVE-2026The Hacker News·Mar 21, 07:03 UTC · Mar 21, 2026Ransomware in the wildCVE-2026-2013160
TeamPCP Targets Telnyx Package in Latest Software Supply Chain AttackInfosecurity Magazine·Mar 27, 15:06 UTC · Mar 27, 2026Ransomware57
Multi-Stage Phishing Campaign Targets Russia with Amnesia RAT and RansomwareThe Hacker News·Jan 24, 11:09 UTC · Jan 24, 2026Ransomware57
Blind Eagle Hacking Group Targets South America With New ToolsInfosecurity Magazine·Jan 6, 17:00 UTC · Jan 6, 2023Ransomware57
Attackers use domain fronting technique to target Myanmar with Cobalt StrikeCisco Talos·Nov 16, 12:00 UTC · Nov 16, 2021Ransomware57
Iranian APT UNC1860 Linked to MOIS Facilitates Cyber Intrusions in Middle EastThe Hacker News·Sep 20, 12:44 UTC · Sep 20, 2024RansomwareCVE-2019-060460
Here’s all the ways an abandoned cloud instance can cause security issuesCyberScoop·Feb 4, 15:42 UTC · Feb 4, 2025Ransomware57
GHOSTENGINE Exploits Vulnerable Drivers to Disable EDRs in Cryptojacking AttackThe Hacker News·May 29, 05:25 UTC · May 29, 2024RansomwareCVE-2021-44228CVE-2023-24860CVE-2023-3601060