Hackers extorted a cool $1 million from South Korean web hosting providerHelp Net Security·Jun 26, 21:22 UTC · Jun 26, 2018Ransomware57
NAYANA provider infected by Erebus ransomware,it paid $1M ransomSecurity Affairs·Jun 21, 12:49 UTC · Jun 21, 2017Ransomware57
WannaCry ransomware used in widespread attacks all over the worldKaspersky Securelist·May 12, 17:30 UTC · May 12, 2017Ransomware57
Who is offering the CradleCore Ransomware as source code?Security Affairs·Apr 18, 07:19 UTC · Apr 18, 2017Ransomware57
Who is Anna-Senpai, the Mirai Worm Author?Krebs on Security·Feb 11, 21:02 UTC · Feb 11, 2017Ransomware45
Angler EK: More Obfuscation, Fake Extensions, and Other NonsenseCisco Talos·Jun 5, 05:05 UTC · Jun 5, 2015Ransomware57
⚡ Weekly Recap: ShareFile Threat, Citrix Bleed 2 Ransomware, AI Coding Attacks, and MoreThe Hacker News·Aug 4, 12:16 UTC · Aug 4, 2026RansomwareCVE-2026-50746CVE-2026-50747CVE-2026-50748+45 CVEs60
Fake Notepad++ Plugin Delivers MATCHBOIL.V2 in UACThe Hacker News·Jul 24, 06:50 UTC · Jul 24, 2026RansomwareCVE-2025-66376CVE-2026-8496CVE-2025-4911360
Hackers Use Fake Microsoft Entra Passkey Enrollment to Gain Microsoft 365 AccessThe Hacker News·Jul 10, 10:30 UTC · Jul 10, 2026Ransomware145
Five defender priorities from the Talos Year in ReviewCisco Talos·Apr 28, 13:23 UTC · Apr 28, 2026Ransomware60
Ransomware Turf War as 0APT and KryBit Groups Trade BlowsInfosecurity Magazine·Apr 28, 13:00 UTC · Apr 28, 2026Ransomware57
Cybercriminals scale up, government sector hit hardestHelp Net Security·Apr 23, 13:50 UTC · Apr 23, 2026RansomwareCVE-2017-17215CVE-2023-1389CVE-2014-8361+2 CVEs60
ThreatsDay Bulletin: Defender 0-Day, SonicWall Brute-Force, 17-YearThe Hacker News·Apr 17, 14:47 UTC · Apr 17, 2026Ransomware in the wildCVE-2026-33825CVE-2009-0238160
Hive0163 Uses AI-Assisted Slopoly Malware for Persistent Access in Ransomware AttacksThe Hacker News·Mar 15, 00:00 UTC · Mar 15, 2026Ransomware57
AI-assisted Slopoly malware powers Hive0163’s ransomware campaignsSecurity Affairs·Mar 13, 11:36 UTC · Mar 13, 2026Ransomware60
ThreatsDay Bulletin: New RCEs, Darknet Busts, Kernel Bugs & 25+ More StoriesThe Hacker News·Jan 30, 08:37 UTC · Jan 30, 2026Ransomware in the wildCVE-2025-59090CVE-2025-5910960
Magniber ransomware: exclusively for South KoreansMalwarebytes Labs·Jan 13, 08:15 UTC · Jan 13, 2026Ransomware57
Velociraptor leveraged in ransomware attacksCisco Talos·Oct 9, 10:00 UTC · Oct 9, 2025RansomwareCVE-2025-626460
⚡ Weekly Recap: Cisco 0-Day, Record DDoS, LockBit 5.0, BMC Bugs, ShadowV2 Botnet & MoreThe Hacker News·Oct 6, 11:28 UTC · Oct 6, 2025RansomwareCVE-2025-20362CVE-2025-20333CVE-2025-20363+15 CVEs60
Charon Ransomware Hits Middle East Sectors Using APTThe Hacker News·Aug 15, 00:00 UTC · Aug 15, 2025Ransomware57
Security Affairs newsletter Round 527 by Pierluigi PaganiniSecurity Affairs·Jun 8, 11:20 UTC · Jun 8, 2025Ransomware in the wildCVE-2025-2018860
⚡ THN Weekly Recap: Router Hacks, PyPI Attacks, New Ransomware Decryptor, and MoreThe Hacker News·May 6, 07:05 UTC · May 6, 2025RansomwareCVE-2025-21590CVE-2025-24983CVE-2025-24984+27 CVEs160
Leaked Black Basta Chats Suggest Russian Officials Aided Leader's Escape from ArmeniaThe Hacker News·Mar 19, 15:41 UTC · Mar 19, 2025Ransomware57
Leaked Black Basta Ransomware Chat Logs Reveal Inner Workings and Internal ConflictsThe Hacker News·Feb 27, 05:08 UTC · Feb 27, 2025Ransomware in the wildCVE-2024-50623CVE-2009-3960CVE-2010-2861+8 CVEs60
Talos IR trends Q4 2024: Web shell usage and exploitation of publicCisco Talos·Jan 30, 11:00 UTC · Jan 30, 2025Ransomware57
Security Affairs newsletter Round 503 by Pierluigi PaganiniSecurity Affairs·Dec 22, 14:59 UTC · Dec 22, 2024RansomwareCVE-2024-53677CVE-2023-5016460
Hacktivist Group Twelve Targets Russian Entities with Destructive Cyber AttacksThe Hacker News·Oct 19, 07:30 UTC · Oct 19, 2024RansomwareCVE-2021-21972CVE-2021-2200560
Head Mare hacktivists: attacks on companies in Russia and BelarusKaspersky Securelist·Sep 2, 10:00 UTC · Sep 2, 2024RansomwareCVE-2023-3883160
Ransomware Surges Annually Despite Law Enforcement TakedownsInfosecurity Magazine·Jul 11, 10:45 UTC · Jul 11, 2024RansomwareCVE-2024-457760
New eCh0raix Ransomware Variant Targets QNAP and Synology NetworkPalo Alto Unit 42·Jun 6, 12:17 UTC · Jun 6, 2024RansomwareCVE-2021-28799160
LockBit claims a comeback less than a week after major disruptionCyberScoop·Feb 27, 16:09 UTC · Feb 27, 2024Ransomware in the wild60
LockBit ransomware gang attempts to relaunch its services following takedownThe Record·Feb 26, 13:15 UTC · Feb 26, 2024Ransomware57
LockBit Ransomware Takedown: What You Need to Know about Operation CroInfosecurity Magazine·Feb 26, 12:00 UTC · Feb 26, 2024RansomwareCVE-2023-382460
After years of losing, it’s finally feds’ turn to troll ransomware groupArs Technica · Security·Feb 20, 21:29 UTC · Feb 20, 2024Ransomware57
Police plan week of LockBit revelations after capturing ‘unprecedented’ intelligence from gang’s infrastructureThe Record·Feb 20, 15:49 UTC · Feb 20, 2024Ransomware57
LockBit Infrastructure Disrupted by Global Law EnforcersInfosecurity Magazine·Feb 20, 09:30 UTC · Feb 20, 2024RansomwareCVE-2023-382460
LockBit disrupted by international law enforcement task forceHelp Net Security·Feb 20, 00:00 UTC · Feb 20, 2024RansomwareCVE-2023-382460