Magnitude exploit kitKaspersky Securelist·Jun 24, 10:00 UTC · Jun 24, 2020Ransomware in the wildCVE-2018-8174CVE-2018-8653CVE-2019-1367+3 CVEs60
Blowing Cobalt Strike Out of the Water With Memory AnalysisPalo Alto Unit 42·Jun 5, 17:24 UTC · Jun 5, 2024Ransomware57
The curious case of a CVE-2012Kaspersky Securelist·Aug 6, 13:11 UTC · Aug 6, 2013RansomwareCVE-2012-015860
Sodin ransomware exploits Windows vulnerability and processor architectureKaspersky Securelist·Jul 3, 10:00 UTC · Jul 3, 2019RansomwareCVE-2018-845360
Dtrack expands its operations to Europe and Latin AmericaKaspersky Securelist·Nov 15, 10:00 UTC · Nov 15, 2022Ransomware57
Modified Zyklon and plugins from IndiaCisco Talos·May 23, 13:05 UTC · May 23, 2017RansomwareCVE-2013-3906CVE-2012-185660
China-Linked Hackers Exploit VMware ESXi ZeroThe Hacker News·Jan 12, 16:25 UTC · Jan 12, 2026Ransomware in the wildCVE-2025-22224CVE-2025-22225CVE-2025-2222660
Most interesting IR cases in 2023: insider threats and moreKaspersky Securelist·Sep 3, 11:01 UTC · Sep 3, 2024Ransomware60
August 2025 CVE LandscapeRecorded Future·Nov 21, 00:00 UTC · Nov 21, 2025Ransomware in the wildCVE-2025-8088CVE-2025-7775CVE-2025-57819+5 CVEs60
FIN8 Group spotted delivering the BlackCat RansomwareSecurity Affairs·Jul 18, 19:45 UTC · Jul 18, 2023Ransomware57
First Cyber Attack 'Mass Exploiting' BlueKeep RDP Flaw Spotted in the WildThe Hacker News·Nov 3, 11:34 UTC · Nov 3, 2019RansomwareCVE-2019-070860
Lemon Duck brings cryptocurrency miners back into the spotlightCisco Talos·Oct 13, 14:59 UTC · Oct 13, 2020Ransomware57
Microsoft warns of more disruptive BlueKeep AttacksSecurity Affairs·Nov 8, 13:28 UTC · Nov 8, 2019Ransomware in the wildCVE-2019-070860
At least 3 different groups have been leveraging the NSA EternalBlue exploit, what's went wrong?Security Affairs·Aug 22, 08:11 UTC · Aug 22, 2017Ransomware57
Security leaders say the next two years are going to be 'insane'CyberScoop·Mar 27, 17:16 UTC · Mar 27, 2026Ransomware157
ThrottleStop driver abused to terminate AV processesKaspersky Securelist·Aug 6, 10:00 UTC · Aug 6, 2025RansomwareCVE-2025-777160
Introducing ToyMaker, an initial access broker working in cahoots with double extortion gangsCisco Talos·Apr 23, 10:00 UTC · Apr 23, 2025Ransomware60
Exploring vulnerable Windows driversCisco Talos·Dec 19, 11:04 UTC · Dec 19, 2024RansomwareCVE-2022-369960
Researchers Discover "Bootkitty" – First UEFI Bootkit Targeting Linux KernelsThe Hacker News·Dec 2, 16:30 UTC · Dec 2, 2024RansomwareCVE-2023-4023860
A deep dive into Phobos ransomware, recently deployed by 8Base groupCisco Talos·Nov 17, 13:01 UTC · Nov 17, 2023Ransomware57
Kaspersky crimeware report: GoPIX, Lumar, and Rhysida.Kaspersky Securelist·Oct 24, 10:00 UTC · Oct 24, 2023Ransomware57
Andariel deploys DTrack and Maui ransomwareKaspersky Securelist·Aug 9, 14:25 UTC · Aug 9, 2022RansomwareCVE-2017-1027160
Threat Brief: Office Documents Can Be Dangerous (But We’ll Continue to Use Them Anyway)Palo Alto Unit 42·Sep 21, 18:41 UTC · Sep 21, 2020Ransomware in the wildCVE-2018-4878CVE-2017-11882CVE-2018-0802+4 CVEs160
New Snort, ClamAV coverage strikes back against Cobalt StrikeCisco Talos·Sep 21, 04:01 UTC · Sep 21, 2020Ransomware157
FIN6 group starts using LockerGoga and Ryuk RansomwareSecurity Affairs·Apr 6, 19:56 UTC · Apr 6, 2019Ransomware57
Angler Exploit Kit is able to bypass Microsoft EMET defenseSecurity Affairs·Apr 14, 16:31 UTC · Apr 14, 2018Ransomware60
A Dissection of the “EsteemAudit” Windows Remote Desktop ExploitPalo Alto Unit 42·May 31, 12:00 UTC · May 31, 2017RansomwareCVE-2017-907360
⚡ Weekly Recap: AI Goes Rogue, Metabase 0-Day, MCP SupplyThe Hacker News·Aug 10, 15:03 UTC · Aug 10, 2026Ransomware in the wildCVE-2026-34348CVE-2026-18497CVE-2026-63508+43 CVEs160
ThreatsDay: AI-Powered Hacking, 370 Chrome Flaws, SonicWall Attacks, DNS Hijacking + 22 More StoriesThe Hacker News·Jul 30, 15:25 UTC · Jul 30, 2026RansomwareCVE-2026-33017CVE-2026-21858CVE-2025-68613+5 CVEs60
⚡ Weekly Recap: Proxy Botnets, Browser Ransomware, AI Agent Tricks, Fake PoC Malware and MoreThe Hacker News·Jul 6, 13:02 UTC · Jul 6, 2026RansomwareCVE-2026-48276CVE-2026-48283CVE-2026-48277+69 CVEs160
The Gentlemen RaaS Uses GentleKiller EDR Framework Targeting 400 Security ProcessesThe Hacker News·Jun 23, 17:43 UTC · Jun 23, 2026Ransomware57
Junior Hacker Used Tailscale and OpenSSH to Keep Access After His C2 Went OfflineThe Hacker News·Jun 17, 16:00 UTC · Jun 17, 2026Ransomware57
OpenAI Revokes macOS App Certificate After Malicious Axios Supply Chain IncidentThe Hacker News·Apr 15, 00:00 UTC · Apr 15, 2026RansomwareCVE-2026-3363460