Attackers Abuse Velociraptor Forensic Tool to Deploy Visual Studio Code for C2 TunnelingThe Hacker News·Sep 3, 04:55 UTC · Sep 3, 2025Ransomware157
Researchers Find VS Code Flaw Allowing Attackers to Republish Deleted Extensions Under Same NamesThe Hacker News·Aug 29, 03:58 UTC · Aug 29, 2025Ransomware157
Microsoft Warns Developers of Fake Next.js Job Repos Delivering InThe Hacker News·Mar 10, 05:53 UTC · Mar 10, 2026Ransomware57
Vibe-Coded Malicious VS Code Extension Found with BuiltThe Hacker News·Nov 7, 09:00 UTC · Nov 7, 2025Ransomware157
Malicious VS Code Extensions Exploit Name Reuse LoopholeInfosecurity Magazine·Aug 28, 14:00 UTC · Aug 28, 2025Ransomware157
ThreatsDay Bulletin: $176M Crypto Fine, Hacking Formula 1, Chromium Vulns, AI Hijack & MoreThe Hacker News·Oct 23, 14:22 UTC · Oct 23, 2025Ransomware57
Red Hat removes tainted packages after software pipeline compromiseThe Record·Jun 18, 00:00 UTC · Jun 18, 2026Ransomware57
Velociraptor leveraged in ransomware attacksCisco Talos·Oct 9, 10:00 UTC · Oct 9, 2025RansomwareCVE-2025-626460
Qilin and Warlock Ransomware Use Vulnerable Drivers to Disable 300+ EDR ToolsThe Hacker News·Apr 6, 10:07 UTC · Apr 6, 2026Ransomware57
Matrix Push C2 Uses Browser Notifications for Fileless, CrossThe Hacker News·Dec 9, 08:03 UTC · Dec 9, 2025RansomwareCVE-2025-5928760
Legit tools, illicit uses: Velociraptor, Nezha turned against victimsHelp Net Security·Oct 15, 11:50 UTC · Oct 15, 2025RansomwareCVE-2025-626460
VSCode Marketplace Removes Two Extensions Deploying EarlyThe Hacker News·Mar 24, 11:10 UTC · Mar 24, 2025Ransomware57
Hackers Can Abuse Visual Studio Marketplace to Target Developers with Malicious ExtensionsThe Hacker News·Jan 15, 00:00 UTC · Jan 15, 2023Ransomware57
North Korea-linked Zinc APT posed as Samsung recruiters to target security firmsSecurity Affairs·Nov 28, 12:11 UTC · Nov 28, 2021RansomwareCVE-2017-1623860
The source code of the 2020 variant of HelloKitty ransomware was leaked on cybercrime forumSecurity Affairs·Oct 9, 13:46 UTC · Oct 9, 2023RansomwareCVE-2021-20016CVE-2021-20021CVE-2021-20022+1 CVEs60
Cybercriminals camouflaging threats as AI tool installersCisco Talos·May 29, 10:00 UTC · May 29, 2025Ransomware57
PetrWrap, a Petya-based ransomware, was used in targeted attacksSecurity Affairs·Jun 27, 15:59 UTC · Jun 27, 2017Ransomware57
PetrWrap: the new Petya-based ransomware used in targeted attacksKaspersky Securelist·Mar 14, 08:59 UTC · Mar 14, 2017Ransomware57
Exploiting stolen session cookies to bypass multi-factor authentication (MFA)Help Net Security·Aug 19, 00:00 UTC · Aug 19, 2022Ransomware57
Dridex banking Trojan and the FriedEx ransomware were developed by the same groupSecurity Affairs·Jan 29, 21:20 UTC · Jan 29, 2018Ransomware57
Locky: the encryptor taking the world by stormKaspersky Securelist·Apr 6, 08:59 UTC · Apr 6, 2016Ransomware57