DragonForce Ransomware Exploited Microsoft Teams to Hide AttackInfosecurity Magazine·Jun 16, 11:30 UTC · Jun 16, 2026Ransomware57
DragonForce Hid Inside Microsoft Teams and Nobody Noticed for Two MonthsSecurity Affairs·Jun 17, 15:55 UTC · Jun 17, 2026Ransomware57
A Multi-Method Approach to Identifying Rogue Cobalt Strike ServersRecorded Future·Aug 21, 00:00 UTC · Aug 21, 2025Ransomware57
Rare Werewolf APT Uses Legitimate Software in Attacks on Hundreds of Russian EnterprisesThe Hacker News·Jun 25, 13:37 UTC · Jun 25, 2025Ransomware57
DDoS attacks in Q1 2021Kaspersky Securelist·May 10, 10:00 UTC · May 10, 2021RansomwareCVE-2021-300760
Microsoft Exchange vulnerabilities exploited once again for ransomware, this time with BabukCisco Talos·Nov 3, 12:00 UTC · Nov 3, 2021RansomwareCVE-2021-3694260
Attacks on Exchange servers expand from nationThe Record·Nov 17, 06:58 UTC · Nov 17, 2022Ransomware in the wild60
IR Trends: Ransomware on the rise, while technology becomes most targeted sectorCisco Talos·Jul 25, 10:00 UTC · Jul 25, 2024Ransomware160
Microsoft took down 120 of 128 Trickbot servers in recent takedownSecurity Affairs·Oct 21, 06:00 UTC · Oct 21, 2020Ransomware57
Microsoft linked attacks on SharePoint flaws to ChinaSecurity Affairs·Jul 23, 06:20 UTC · Jul 23, 2025RansomwareCVE-2025-5377060
Inside DragonForce, the Group Tied to M&S, CoInfosecurity Magazine·May 6, 13:25 UTC · May 6, 2025Ransomware60
UNRAVELING EternalBlue: inside the WannaCry’s enablerSecurity Affairs·Sep 1, 14:43 UTC · Sep 1, 2023Ransomware57
Ransomware world in 2021: who, how and whyKaspersky Securelist·May 12, 10:00 UTC · May 12, 2021Ransomware57
Storm-2603 Exploits SharePoint Flaws to Deploy Warlock Ransomware on Unpatched SystemsThe Hacker News·Jul 28, 15:57 UTC · Jul 28, 2025Ransomware in the wildCVE-2025-49706CVE-2025-4970460
Attacks on web applications spike in third quarter, new Talos IR data showsCisco Talos·Oct 24, 12:00 UTC · Oct 24, 2023Ransomware60
Linux Variant of Clop Ransomware Spotted, But Uses Faulty Encryption AlgorithmThe Hacker News·Feb 8, 05:32 UTC · Feb 8, 2023Ransomware57
New Linux variant of Clop Ransomware uses a flawed encryptionSecurity Affairs·Feb 7, 23:53 UTC · Feb 7, 2023Ransomware57
Released: Decryptor for Cl0p ransomware's Linux variantHelp Net Security·Feb 7, 00:00 UTC · Feb 7, 2023Ransomware57
ThreatsDay Bulletin: Defender 0-Day, SonicWall Brute-Force, 17-YearThe Hacker News·Apr 17, 14:47 UTC · Apr 17, 2026Ransomware in the wildCVE-2026-33825CVE-2009-0238160
LockBit Ransomware Abuses Windows Defender to Deploy Cobalt Strike PayloadThe Hacker News·Aug 2, 08:07 UTC · Aug 2, 2022Ransomware60
AI Agent Exploits Langflow RCE to Automate Database Ransomware AttackThe Hacker News·Jul 2, 09:13 UTC · Jul 2, 2026Ransomware in the wildCVE-2025-3248CVE-2021-29441160
Cybercriminals mask malicious communications through Microsoft Teams relaysHelp Net Security·Jun 16, 00:00 UTC · Jun 16, 2026RansomwareCVE-2023-52271CVE-2025-61155CVE-2025-1055160
Ransomware attacks on industrial infrastructure doubled in 2022: DragosThe Record·Feb 14, 00:00 UTC · Feb 14, 2023Ransomware57
New Ransomware Group Exploiting Veeam Backup Software VulnerabilityThe Hacker News·Jul 15, 00:00 UTC · Jul 15, 2024RansomwareCVE-2023-2753260
Threat Spotlight: Cisco Talos Thwarts Access to Massive International Exploit Kit Generating $60M Annually From Ransomware AloneCisco Talos·Oct 6, 12:00 UTC · Oct 6, 2015Ransomware57
Sophos XDR: Threat hunting through the entire security ecosystemHelp Net Security·Aug 9, 08:34 UTC · Aug 9, 2021Ransomware60
Week in review: AWS S3 data encrypted without ransomware, data of 15k Fortinet firewalls leakedHelp Net Security·Jan 19, 00:00 UTC · Jan 19, 2025Ransomware in the wildCVE-2024-55591CVE-2025-0282CVE-2024-734460
Warlock Ransomware Hitting Victims Globally Through SharePoint ToolSheInfosecurity Magazine·Aug 20, 12:00 UTC · Aug 20, 2025Ransomware60
Celerium Compromise Defender detects and disrupts cyber compromise activityHelp Net Security·Jun 23, 00:00 UTC · Jun 23, 2023Ransomware60
NSO Group partly disputes claim about use of U.S.CyberScoop·May 1, 17:22 UTC · May 1, 2020Ransomware in the wild60
Bl00dy Ransomware Gang actively targets the education sectorSecurity Affairs·May 12, 22:55 UTC · May 12, 2023RansomwareCVE-2023-2735060
Microsoft announces Microsoft Defender for Business (for SMBs)Help Net Security·May 2, 00:00 UTC · May 2, 2022Ransomware157
Microsoft Links Ongoing SharePoint Exploits to Three Chinese Hacker GroupsThe Hacker News·Jul 22, 16:43 UTC · Jul 22, 2025RansomwareCVE-2025-49706CVE-2025-49704CVE-2025-53771+1 CVEs60
Microsoft leads effort to disrupt illicit use of Cobalt Strike, a dangerous hacking tool in the wrong handsCyberScoop·Apr 6, 16:00 UTC · Apr 6, 2023Ransomware in the wild60
US, Australia, Canada warn of ‘fast flux’ scheme used by ransomware gangsThe Record·Apr 3, 18:20 UTC · Apr 3, 2025Ransomware57
Adversary Infrastructure Report 2020: A Defender’s ViewRecorded Future·Jan 2, 00:00 UTC · Jan 2, 2026Ransomware57
DeadLock Ransomware Uses Polygon Smart Contracts For Proxy RotationInfosecurity Magazine·Jan 14, 14:20 UTC · Jan 14, 2026Ransomware57
DoJ Seizes 145 Domains Tied to BidenCash Carding Marketplace in Global TakedownThe Hacker News·Jun 5, 10:19 UTC · Jun 5, 2025Ransomware57