Security Affairs newsletter Round 479 by Pierluigi PaganiniSecurity Affairs·Jul 7, 09:14 UTC · Jul 7, 2024RansomwareCVE-2021-40444CVE-2024-0769CVE-2024-23692+1 CVEs60
IT threat evolution Q3 2022Kaspersky Securelist·Nov 18, 08:00 UTC · Nov 18, 2022RansomwareCVE-2017-1027160
Ransomware Gang Exploits SimpleHelp RMM to Compromise Utility BillingInfosecurity Magazine·Jun 13, 11:00 UTC · Jun 13, 2025Ransomware in the wildCVE-2024-57727CVE-2024-57728CVE-2024-5772660
CLOP targets Gladinet CentreStack servers in largeSecurity Affairs·Dec 19, 11:48 UTC · Dec 19, 2025Ransomware in the wildCVE-2025-11371CVE-2025-30406CVE-2025-61882+2 CVEs60
Analysis of Cuba ransomware gang activity and toolingKaspersky Securelist·Sep 11, 10:00 UTC · Sep 11, 2023RansomwareCVE-2021-31207CVE-2021-34473CVE-2021-34523+8 CVEs60
Andariel deploys DTrack and Maui ransomwareKaspersky Securelist·Aug 9, 14:25 UTC · Aug 9, 2022RansomwareCVE-2017-1027160
Healthcare organizations implementing zero trust to tackle cyberattacksHelp Net Security·Feb 5, 13:47 UTC · Feb 5, 2024Ransomware60
GhostSec’s joint ransomware operation and evolution of their arsenalCisco Talos·Mar 5, 13:00 UTC · Mar 5, 2024Ransomware60
Threat Brief: Office Documents Can Be Dangerous (But We’ll Continue to Use Them Anyway)Palo Alto Unit 42·Sep 21, 18:41 UTC · Sep 21, 2020Ransomware in the wildCVE-2018-4878CVE-2017-11882CVE-2018-0802+4 CVEs160
Oracle EBS Under Fire as Cl0p Exploits CVE-2025-61882 in RealThe Hacker News·Oct 8, 04:30 UTC · Oct 8, 2025Ransomware in the wildCVE-2025-6188260
Head Mare and Twelve: Joint attacks on Russian entitiesKaspersky Securelist·Mar 13, 10:07 UTC · Mar 13, 2025RansomwareCVE-2023-38831CVE-2021-2685560
U.S., U.K. and Australia Warn of Iranian Hackers Exploiting Microsoft, Fortinet FlawsThe Hacker News·Nov 22, 07:14 UTC · Nov 22, 2021Ransomware in the wildCVE-2021-34473CVE-2020-12812CVE-2019-5591+1 CVEs60
Attackers exploited a Mitel VOIP zeroSecurity Affairs·Jun 25, 11:59 UTC · Jun 25, 2022RansomwareCVE-2022-2949960
Threat Source newsletter (Oct. 28, 2021)Cisco Talos·Oct 28, 18:00 UTC · Oct 28, 2021Ransomware in the wildCVE-2021-41733CVE-2021-4201360
Threat Source newsletter (Oct. 14, 2021)Cisco Talos·Oct 14, 18:00 UTC · Oct 14, 2021Ransomware in the wildCVE-2021-40461CVE-2021-38672CVE-2021-41733+1 CVEs60
Hackers Targeting Critical Healthcare Facilities With Ransomware During Coronavirus PandemicThe Hacker News·Apr 15, 00:00 UTC · Apr 15, 2020RansomwareCVE-2012-015860
Interlock Ransomware Exploits Cisco FMC Zero-Day CVE-2026The Hacker News·Mar 21, 07:03 UTC · Mar 21, 2026Ransomware in the wildCVE-2026-2013160
Iranian APT UNC1860 Linked to MOIS Facilitates Cyber Intrusions in Middle EastThe Hacker News·Sep 20, 12:44 UTC · Sep 20, 2024RansomwareCVE-2019-060460
GHOSTENGINE Exploits Vulnerable Drivers to Disable EDRs in Cryptojacking AttackThe Hacker News·May 29, 05:25 UTC · May 29, 2024RansomwareCVE-2021-44228CVE-2023-24860CVE-2023-3601060
Cisco Talos shares insights related to recent cyber attack on CiscoCisco Talos·Aug 10, 19:30 UTC · Aug 10, 2022Ransomware60
Interlock group exploiting the CISCO FMC flaw CVE-2026Security Affairs·Mar 19, 09:22 UTC · Mar 19, 2026RansomwareCVE-2026-2013160
Threat Source newsletter (Aug. 1, 2019)Cisco Talos·Aug 1, 18:00 UTC · Aug 1, 2019Ransomware in the wild60
Ransomware Groups Prioritize Defense Evasion for Data ExfiltrationInfosecurity Magazine·Jul 10, 13:00 UTC · Jul 10, 2024RansomwareCVE-2020-1472CVE-2018-13379CVE-2023-066960
FBI warns of Iran-linked hackers attempting to exploit F5 BIGSecurity Affairs·Aug 8, 15:53 UTC · Aug 8, 2020RansomwareCVE-2020-590260
Sodinokibi ransomware exploits WebLogic Server vulnerabilityCisco Talos·Apr 30, 18:00 UTC · Apr 30, 2019RansomwareCVE-2019-272560
XBash combines features from ransomware, miners, botnets, and wormsSecurity Affairs·Sep 18, 06:40 UTC · Sep 18, 2018RansomwareCVE-2016-308860
North Korean Hackers Target Critical Infrastructure for Military GainInfosecurity Magazine·Jul 26, 11:02 UTC · Jul 26, 2024Ransomware60
Quarterly Report: Incident Response trends from Spring 2021Cisco Talos·Jun 10, 12:00 UTC · Jun 10, 2021RansomwareCVE-2021-26855CVE-2021-26857CVE-2021-26858+4 CVEs60
⚡ Weekly Recap: BadCam Attack, WinRAR 0-Day, EDR Killer, NVIDIA Flaws, Ransomware Attacks & MoreThe Hacker News·Aug 12, 04:40 UTC · Aug 12, 2025Ransomware in the wildCVE-2025-54948CVE-2025-54987CVE-2025-8088+30 CVEs60
Researchers warn of a surge in cyber attacks against Microsoft ExchangeSecurity Affairs·Mar 12, 22:51 UTC · Mar 12, 2021Ransomware in the wildCVE-2021-26855CVE-2021-26857CVE-2021-26858+1 CVEs60
Canary Exploit tool allows to find servers affected by Apache Parquet flawSecurity Affairs·May 7, 14:08 UTC · May 7, 2025RansomwareCVE-2025-3006560
Inside the ransomware playbook: Analyzing attack chains and mapping common TTPsCisco Talos·Jul 10, 10:00 UTC · Jul 10, 2024Ransomware60
Microsoft blames Clop gang for 'MOVEit Transfer' attacksSecurity Affairs·Jun 5, 15:07 UTC · Jun 5, 2023Ransomware in the wildCVE-2023-3436260
Over 100 VS Code Extensions Exposed Developers to Hidden Supply Chain RisksThe Hacker News·Oct 31, 07:59 UTC · Oct 31, 2025Ransomware60
Crooks target Healthcare facilities involved in Coronavirus containment with RansomwareSecurity Affairs·Apr 14, 15:29 UTC · Apr 14, 2020RansomwareCVE-2012-015860
Clop ransomware gang claims the hack of hundreds of victimsSecurity Affairs·Jun 7, 18:20 UTC · Jun 7, 2023RansomwareCVE-2023-34362CVE-2023-066960
Head Mare hacktivists: attacks on companies in Russia and BelarusKaspersky Securelist·Sep 2, 10:00 UTC · Sep 2, 2024RansomwareCVE-2023-3883160