The Gentlemen RaaS: rapid growth and a new ransomware variantKaspersky Securelist·Jun 30, 10:06 UTC · Jun 30, 2026Ransomware160
EDR killers are now standard equipment in ransomware attacksHelp Net Security·Apr 23, 13:28 UTC · Apr 23, 2026Ransomware57
H1 2023: Ransomware's Pivot to Linux and Vulnerable DriversRecorded Future·Jun 29, 00:00 UTC · Jun 29, 2026Ransomware60
The Gentlemen RaaS Uses GentleKiller EDR Framework Targeting 400 Security ProcessesThe Hacker News·Jun 23, 17:43 UTC · Jun 23, 2026Ransomware57
Windows CLFS and five exploits used by ransomware operatorsKaspersky Securelist·Dec 21, 09:53 UTC · Dec 21, 2023RansomwareCVE-2023-28252CVE-2022-24521CVE-2022-37969+1 CVEs60
Ransomware Hackers Using AuKill Tool to Disable EDR Software Using BYOVD AttackThe Hacker News·Apr 28, 03:18 UTC · Apr 28, 2023Ransomware57
Ransomware Attackers Abuse Genshin Impact AntiThe Hacker News·Sep 5, 12:26 UTC · Sep 5, 2022Ransomware57
Insurer unveils policy covering drivers from connected car hacks and data leaksThe Record·Mar 27, 15:25 UTC · Mar 27, 2024Ransomware57
DragonForce Hid Inside Microsoft Teams and Nobody Noticed for Two MonthsSecurity Affairs·Jun 17, 15:55 UTC · Jun 17, 2026Ransomware57
FIN7 group advertises new EDR bypass tool on hacking forumsSecurity Affairs·Jul 18, 11:04 UTC · Jul 18, 2024Ransomware57
Friday Squid Blogging: 14-foot Giant Squid Washes Ashore in Cape TownSchneier on Security·Aug 26, 21:08 UTC · Aug 26, 2022Ransomware57
GentleKiller Framework Disables Victims' Security SoftwareInfosecurity Magazine·Jun 22, 15:00 UTC · Jun 22, 2026Ransomware57
Chinese-speaking hackers exploited ESXi zeroSecurity Affairs·Jan 9, 00:06 UTC · Jan 9, 2026Ransomware in the wildCVE-2025-22226CVE-2025-22224CVE-2025-2222560
Linux variant of Qilin Ransomware targets Windows via remote management tools and BYOVDSecurity Affairs·Oct 27, 10:45 UTC · Oct 27, 2025Ransomware60
SonicWall Investigating Potential SSL VPN ZeroThe Hacker News·Aug 7, 05:27 UTC · Aug 7, 2025Ransomware in the wild60
CosmicBeetle Deploys Custom ScRansom Ransomware, Partnering with RansomHubThe Hacker News·Sep 11, 06:02 UTC · Sep 11, 2024RansomwareCVE-2017-0144CVE-2020-1472CVE-2021-42278+3 CVEs160
BlackByte Ransomware Exploits VMware ESXi Flaw in Latest Attack WaveThe Hacker News·Aug 29, 15:41 UTC · Aug 29, 2024RansomwareCVE-2024-3708560
A group linked to RansomHub operation employs EDRSecurity Affairs·Aug 15, 20:12 UTC · Aug 15, 2024Ransomware57
Mamba: The new Full Disk Encryption Ransomware Family MemberSecurity Affairs·Oct 1, 09:41 UTC · Oct 1, 2017Ransomware57
Puerto Rico government agency cancels driver’s license appointments after cyberattackThe Record·Mar 25, 15:34 UTC · Mar 25, 2026Ransomware57
CVE-2025-22225 in VMware ESXi now used in active ransomware attacksSecurity Affairs·Feb 4, 22:02 UTC · Feb 4, 2026Ransomware in the wildCVE-2025-22225CVE-2025-22226CVE-2025-2222460
ThreatsDay Bulletin: $176M Crypto Fine, Hacking Formula 1, Chromium Vulns, AI Hijack & MoreThe Hacker News·Oct 23, 14:22 UTC · Oct 23, 2025Ransomware57
⚡ THN Weekly Recap: Router Hacks, PyPI Attacks, New Ransomware Decryptor, and MoreThe Hacker News·May 6, 07:05 UTC · May 6, 2025RansomwareCVE-2025-21590CVE-2025-24983CVE-2025-24984+27 CVEs160
BYOVD Attacks Exploit ZeroInfosecurity Magazine·Mar 3, 09:35 UTC · Mar 3, 2025RansomwareCVE-2025-0289CVE-2025-0288CVE-2025-0287+2 CVEs60
BlackByte Ransomware group targets recently patched VMware ESXi flaw CVE-2024Security Affairs·Aug 28, 14:39 UTC · Aug 28, 2024RansomwareCVE-2024-3708560
Cybercriminals mask malicious communications through Microsoft Teams relaysHelp Net Security·Jun 16, 00:00 UTC · Jun 16, 2026RansomwareCVE-2023-52271CVE-2025-61155CVE-2025-1055160
Reviewing the trends in ransomware attacks in 2026Kaspersky Securelist·May 12, 07:00 UTC · May 12, 2026Ransomware60
China-Linked Hackers Exploit VMware ESXi ZeroThe Hacker News·Jan 12, 16:25 UTC · Jan 12, 2026Ransomware in the wildCVE-2025-22224CVE-2025-22225CVE-2025-2222660
⚡ Weekly Recap: BadCam Attack, WinRAR 0-Day, EDR Killer, NVIDIA Flaws, Ransomware Attacks & MoreThe Hacker News·Aug 12, 04:40 UTC · Aug 12, 2025Ransomware in the wildCVE-2025-54948CVE-2025-54987CVE-2025-8088+30 CVEs60
Third Parties and Machine Credentials: The Silent Drivers Behind 2025's Worst BreachesThe Hacker News·May 6, 15:39 UTC · May 6, 2025Ransomware60
Kasseika Ransomware Using BYOVD Trick to Disarm Security PreThe Hacker News·Jan 25, 04:20 UTC · Jan 25, 2024Ransomware57
Microsoft Fixes Six ZeroInfosecurity Magazine·Jul 12, 09:30 UTC · Jul 12, 2023Ransomware in the wildCVE-2023-36884CVE-2023-35311CVE-2023-32046+2 CVEs60
Nokoyawa ransomware attacks with Windows zeroKaspersky Securelist·Apr 11, 17:36 UTC · Apr 11, 2023RansomwareCVE-2023-28252CVE-2022-24521CVE-2022-37969+1 CVEs60