Log4Shell attacks began two weeks ago, Cisco and Cloudflare sayThe Record·Jan 18, 00:00 UTC · Jan 18, 2023Ransomware in the wild60
FireEye's new software releases allow for detection and investigation of attacks against serversHelp Net Security·Aug 5, 00:00 UTC · Aug 5, 2019Ransomware60
Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCEThe Hacker News·Aug 3, 16:06 UTC · Aug 3, 2026Ransomware in the wildCVE-2026-1256960
Legit tools, illicit uses: Velociraptor, Nezha turned against victimsHelp Net Security·Oct 15, 11:50 UTC · Oct 15, 2025RansomwareCVE-2025-626460
August 2025 CVE LandscapeRecorded Future·Nov 21, 00:00 UTC · Nov 21, 2025Ransomware in the wildCVE-2025-8088CVE-2025-7775CVE-2025-57819+5 CVEs60
CLR SqlShell Malware Targets MS SQL Servers for Crypto Mining and RansomwareThe Hacker News·May 15, 00:00 UTC · May 15, 2023Ransomware57
⚡ Weekly Recap: Chrome 0-Day, IngressNightmare, Solar Bugs, DNS Tactics, and MoreThe Hacker News·Aug 19, 13:08 UTC · Aug 19, 2025Ransomware in the wildCVE-2025-2783CVE-2025-2857CVE-2025-1974+11 CVEs60
⚡ Weekly Recap: Chrome 0-Day, IngressNightmare, Solar Bugs, DNS Tactics, and MoreThe Hacker News·May 17, 13:56 UTC · May 17, 2025Ransomware in the wildCVE-2025-2783CVE-2025-2857CVE-2025-1974+11 CVEs60
China-linked hackers target gov agencies by exploiting known flawsSecurity Affairs·Sep 15, 09:16 UTC · Sep 15, 2020RansomwareCVE-2020-5902CVE-2019-19781CVE-2019-11510+1 CVEs60
Iranian Agrius Hackers Targeting Israeli Organizations with Moneybird RansomwareThe Hacker News·May 25, 06:03 UTC · May 25, 2023Ransomware57
Microsoft Exchange vulnerabilities exploited once again for ransomware, this time with BabukCisco Talos·Nov 3, 12:00 UTC · Nov 3, 2021RansomwareCVE-2021-3694260
Database Breaches Remain the Top Cyber Threat for OrganizationsRecorded Future·Aug 21, 00:00 UTC · Aug 21, 2025Ransomware57
Cyber intrusion activity volume jumped 125% in H1 2021Help Net Security·Aug 10, 00:00 UTC · Aug 10, 2021Ransomware60
From the field to the report and back again: How incident responders can use the Year in ReviewCisco Talos·Apr 9, 10:00 UTC · Apr 9, 2026Ransomware60
Linux variant of Cerber ransomware targets Atlassian serversSecurity Affairs·Apr 17, 18:01 UTC · Apr 17, 2024RansomwareCVE-2023-2251860
Critical Atlassian Flaw Exploited to Deploy Linux Variant of Cerber RansomwareThe Hacker News·Apr 18, 03:38 UTC · Apr 18, 2024RansomwareCVE-2023-2251860
Quarterly Report: Incident Response trends in Summer 2020Cisco Talos·Sep 1, 15:00 UTC · Sep 1, 2020RansomwareCVE-2019-1893560
New LockFile gang uses ProxyShell and PetitPotam exploitsSecurity Affairs·Aug 23, 20:02 UTC · Aug 23, 2021RansomwareCVE-2021-34473CVE-2021-34523CVE-2021-3120760
Initial Access Broker Involved in Log4Shell Attacks Against VMware Horizon ServersThe Hacker News·Jan 29, 06:06 UTC · Jan 29, 2022Ransomware in the wild160
Researchers Uncover Hacker Group Behind Organized FinancialThe Hacker News·Jan 6, 04:15 UTC · Jan 6, 2022RansomwareCVE-2017-1000486CVE-2015-7450CVE-2010-532660
Hackers Are Targeting Microsoft Exchange Servers With RansomwareThe Hacker News·Mar 15, 00:00 UTC · Mar 15, 2021Ransomware in the wild60
New Incident Report Reveals How Hive Ransomware Targets OrganizationsThe Hacker News·Apr 21, 10:00 UTC · Apr 21, 2022RansomwareCVE-2021-31207CVE-2021-34523CVE-2021-3447360
Mass Exploitation of Exchange Server ProxShell BugsInfosecurity Magazine·Aug 24, 10:27 UTC · Aug 24, 2021Ransomware in the wildCVE-2021-34473CVE-2021-34523CVE-2021-3120760
A Basic Timeline of the Exchange Mass-HackKrebs on Security·Mar 8, 16:45 UTC · Mar 8, 2021Ransomware60
Hackers Exploit IT Monitoring Tool Centreon to Target Several French EntitiesThe Hacker News·Feb 17, 05:47 UTC · Feb 17, 2021Ransomware57
Black Kingdom Ransomware Hunting Unpatched Microsoft Exchange ServersThe Hacker News·Mar 25, 12:05 UTC · Mar 25, 2021Ransomware57
Clop ransomware gang leaks data allegedly stolen from cybersecurity firm QualysSecurity Affairs·Mar 3, 23:14 UTC · Mar 3, 2021Ransomware60
FIN11 cybercrime group is behind recent wave of attacks on FTA serversSecurity Affairs·Feb 23, 09:36 UTC · Feb 23, 2021Ransomware60
FireEye Links Accellion Attacks to FIN11Infosecurity Magazine·Feb 23, 11:15 UTC · Feb 23, 2021Ransomware60
Microsoft Links Ongoing SharePoint Exploits to Three Chinese Hacker GroupsThe Hacker News·Jul 22, 16:43 UTC · Jul 22, 2025RansomwareCVE-2025-49706CVE-2025-49704CVE-2025-53771+1 CVEs60
Iranian APT UNC1860 Linked to MOIS Facilitates Cyber Intrusions in Middle EastThe Hacker News·Sep 20, 12:44 UTC · Sep 20, 2024RansomwareCVE-2019-060460
Cyber Group 'Gold Melody' Selling Compromised Access to Ransomware AttackersThe Hacker News·Sep 21, 09:11 UTC · Sep 21, 2023RansomwareCVE-2017-7504CVE-2019-19781CVE-2020-14750+10 CVEs60
Storm-2603 spotted deploying ransomware on exploited SharePoint serversHelp Net Security·Aug 4, 12:44 UTC · Aug 4, 2025Ransomware in the wildCVE-2025-53770CVE-2025-49706CVE-2025-49704+2 CVEs160
Microsoft: Lace Tempest Hackers Behind Active Exploitation of MOVEit Transfer AppThe Hacker News·Jun 6, 03:48 UTC · Jun 6, 2023Ransomware in the wildCVE-2023-3436260
Hackers Exploit Accellion Zero-Days in Recent Data Theft and Extortion AttacksThe Hacker News·Feb 23, 08:26 UTC · Feb 23, 2021RansomwareCVE-2021-27101CVE-2021-27102CVE-2021-27103+1 CVEs60