Attackers actively exploiting Atlassian Confluence and Oracle WebLogic flawsHelp Net Security·May 2, 00:00 UTC · May 2, 2019RansomwareCVE-2019-2725CVE-2019-339660
Hackers Exploit Apache HTTP Server Flaw to Deploy Linuxsys Cryptocurrency MinerThe Hacker News·Jul 21, 06:31 UTC · Jul 21, 2025RansomwareCVE-2021-41773CVE-2024-36401CVE-2023-22527+5 CVEs60
Canary Exploit tool allows to find servers affected by Apache Parquet flawSecurity Affairs·May 7, 14:08 UTC · May 7, 2025RansomwareCVE-2025-3006560
Reverse RDP Attack - Rogue RDP Server can be used to hack RDP clientsSecurity Affairs·Feb 6, 08:40 UTC · Feb 6, 2019Ransomware60
Endpoint breach prevention by reducing attack surfacesHelp Net Security·Jan 17, 09:30 UTC · Jan 17, 2023Ransomware60
Zero Day in Cleo File Transfer Software Exploited En MasseInfosecurity Magazine·Dec 11, 09:30 UTC · Dec 11, 2024Ransomware in the wildCVE-2024-5062360
Attackers probing for vulnerable Microsoft Exchange Servers, is yours one of them?Help Net Security·Mar 1, 12:53 UTC · Mar 1, 2020RansomwareCVE-2020-068860
Threat Source newsletter (June 10, 2021)Cisco Talos·Jun 10, 18:00 UTC · Jun 10, 2021Ransomware in the wildCVE-2021-21985CVE-2021-3198560
U.S. CISA adds Google Chromium CSS, Microsoft Windows, TeamT5 ThreatSonar Anti-Ransomware, and Zimbra flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Feb 18, 10:55 UTC · Feb 18, 2026Ransomware in the wildCVE-2008-0015CVE-2020-7796CVE-2024-7694+1 CVEs60
Threat Source newsletter (July 15, 2021)Cisco Talos·Jul 15, 18:00 UTC · Jul 15, 2021Ransomware in the wildCVE-2021-3444860
Threat Source newsletter (Oct. 14, 2021)Cisco Talos·Oct 14, 18:00 UTC · Oct 14, 2021Ransomware in the wildCVE-2021-40461CVE-2021-38672CVE-2021-41733+1 CVEs60
Security Affairs newsletter Round 436 by Pierluigi PaganiniSecurity Affairs·Sep 10, 08:53 UTC · Sep 10, 2023Ransomware in the wildCVE-2023-34039CVE-2023-3324660
Questions mount as Ivanti tackles another round of zeroCyberScoop·May 28, 21:39 UTC · May 28, 2025Ransomware in the wildCVE-2025-4427CVE-2025-442860
Threat Source newsletter (March 2, 2023) — Little victories in the fight against ransomwareCisco Talos·Mar 2, 19:00 UTC · Mar 2, 2023RansomwareCVE-2022-3653760
Threat Source newsletter (Oct. 6, 2022) — Continuing down the Privacy Policy rabbit holeCisco Talos·Oct 6, 18:00 UTC · Oct 6, 2022RansomwareCVE-2022-41040CVE-2022-4108260
IT threat evolution Q2 2020. PC statisticsKaspersky Securelist·Sep 3, 10:30 UTC · Sep 3, 2020RansomwareCVE-2017-8570CVE-2017-11882CVE-2017-0199+4 CVEs60
A critical WatchGuard Fireware flaw could allow unauthenticated code executionSecurity Affairs·Oct 17, 14:09 UTC · Oct 17, 2025RansomwareCVE-2025-924260
Critical Flaws in AMI MegaRAC BMC Software Expose Servers to Remote AttacksThe Hacker News·Jul 26, 17:38 UTC · Jul 26, 2023Ransomware in the wildCVE-2022-40259CVE-2022-40242CVE-2022-2827+4 CVEs60
IT threat evolution in Q3 2021. PC statisticsKaspersky Securelist·Nov 26, 12:00 UTC · Nov 26, 2021RansomwareCVE-2019-7481CVE-2021-1675CVE-2021-34527+4 CVEs60
Nearly 1 Million Computers Still Vulnerable to "Wormable" BlueKeep RDP FlawThe Hacker News·May 28, 12:08 UTC · May 28, 2019RansomwareCVE-2019-070860
Security Affairs newsletter Round 479 by Pierluigi PaganiniSecurity Affairs·Jul 7, 09:14 UTC · Jul 7, 2024RansomwareCVE-2021-40444CVE-2024-0769CVE-2024-23692+1 CVEs60
New wave of ransomware attacks targeting VMware ESXi ServersSecurity Affairs·Feb 4, 13:11 UTC · Feb 4, 2023RansomwareCVE-2021-2197460
Interlock group exploiting the CISCO FMC flaw CVE-2026Security Affairs·Mar 19, 09:22 UTC · Mar 19, 2026RansomwareCVE-2026-2013160
Impact of Log4Shell Bug Was Overblown, Say ResearchersInfosecurity Magazine·Dec 19, 10:30 UTC · Dec 19, 2023Ransomware60
Cryptomining attacks against Apple devices increase sharplyHelp Net Security·Oct 16, 00:00 UTC · Oct 16, 2018RansomwareCVE-2017-7269CVE-2017-5638CVE-2016-630960
Week in review: AWS S3 data encrypted without ransomware, data of 15k Fortinet firewalls leakedHelp Net Security·Jan 19, 00:00 UTC · Jan 19, 2025Ransomware in the wildCVE-2024-55591CVE-2025-0282CVE-2024-734460
BlueKeep RDP flaw: Nearly a million Internet-facing systems are vulnerableHelp Net Security·Nov 15, 08:03 UTC · Nov 15, 2023Ransomware in the wildCVE-2019-070860
Expert publicly discloses Zoho ManageEngine zeroSecurity Affairs·Mar 9, 14:55 UTC · Mar 9, 2020RansomwareCVE-2020-1018960
IR Trends Q3 2025: ToolShell attacks dominate, highlighting criticality of segmentation and rapid responseCisco Talos·Oct 23, 10:00 UTC · Oct 23, 2025Ransomware in the wildCVE-2025-53770CVE-2025-53771CVE-2025-49704+1 CVEs160
March 2026 CVE Landscape: 31 High-Impact Vulnerabilities Identified, Interlock Ransomware Group Exploits Cisco FMC ZeroRecorded Future·Jun 3, 00:00 UTC · Jun 3, 2026Ransomware in the wildCVE-2017-7921CVE-2026-27483CVE-2026-27944+10 CVEs260
Darktrace Newsroom monitors open-source intelligence sourcesHelp Net Security·Feb 24, 00:00 UTC · Feb 24, 2023Ransomware60
New LockFile gang uses ProxyShell and PetitPotam exploitsSecurity Affairs·Aug 23, 20:02 UTC · Aug 23, 2021RansomwareCVE-2021-34473CVE-2021-34523CVE-2021-3120760
StorageCrypt Ransomware is the last malware in order of time exploiting SambaCry to target NAS DevicesSecurity Affairs·Dec 6, 21:49 UTC · Dec 6, 2017RansomwareCVE-2017-749460
U.S. Charges Chinese Hacker for Exploiting ZeroThe Hacker News·Jan 7, 09:22 UTC · Jan 7, 2025Ransomware in the wildCVE-2020-12271CVE-2022-1040CVE-2022-129260
The threat hunter’s gambitCisco Talos·Apr 9, 18:00 UTC · Apr 9, 2026Ransomware in the wildCVE-2026-173160
AWS Warns Hackers Have Abused Cisco Firewall ZeroInfosecurity Magazine·Mar 19, 09:50 UTC · Mar 19, 2026RansomwareCVE-2026-2013160