Linux variant of Qilin Ransomware targets Windows via remote management tools and BYOVDSecurity Affairs·Oct 27, 10:45 UTC · Oct 27, 2025Ransomware60
Your best defense against ransomware: Find the early warning signsHelp Net Security·Sep 23, 00:00 UTC · Sep 23, 2020Ransomware57
Red Alert as US Hospitals Are Flooded with Ryuk RansomwareInfosecurity Magazine·Oct 29, 10:15 UTC · Oct 29, 2020Ransomware60
Threat Source newsletter (May 27, 2021)Cisco Talos·May 27, 17:56 UTC · May 27, 2021RansomwareCVE-2021-2116060
Private Equity Firms Exposed by CyberInfosecurity Magazine·Nov 21, 11:00 UTC · Nov 21, 2022Ransomware60
Ransomware attackers are "vishing" organizations via Microsoft TeamsHelp Net Security·Jan 21, 00:00 UTC · Jan 21, 2025Ransomware60
Two ransomware groups abuse Microsoft’s Office 365 platform to gain access to target organizationsSecurity Affairs·Jan 22, 20:49 UTC · Jan 22, 2025Ransomware57
Russian Ransomware Groups Deploy Email Bombing and Teams VishingInfosecurity Magazine·Jan 21, 11:30 UTC · Jan 21, 2025Ransomware57
Patching is trucking along on Microsoft flaws, but hackers are still meddlingCyberScoop·Mar 26, 14:01 UTC · Mar 26, 2021RansomwareCVE-2021-2685560
Threat Assessment: Black Basta RansomwarePalo Alto Unit 42·Jun 5, 17:55 UTC · Jun 5, 2024Ransomware60
Hackers Could Exploit Google Workspace and Cloud Platform for Ransomware AttacksThe Hacker News·Nov 15, 00:00 UTC · Nov 15, 2023Ransomware57
Qilin Ransomware Combines Linux Payload With BYOVD Exploit in Hybrid AttackThe Hacker News·Oct 28, 03:54 UTC · Oct 28, 2025Ransomware57
A mining multitoolKaspersky Securelist·Jul 26, 10:00 UTC · Jul 26, 2018RansomwareCVE-2017-0144CVE-2018-812060
Adaptive protection against invisible threatsKaspersky Securelist·Dec 14, 12:00 UTC · Dec 14, 2020Ransomware57
Introducing ToyMaker, an initial access broker working in cahoots with double extortion gangsCisco Talos·Apr 23, 10:00 UTC · Apr 23, 2025Ransomware60
TROJ_POSHCODER A ransomware uses Windows PowerShell featuresSecurity Affairs·Nov 14, 23:12 UTC · Nov 14, 2017Ransomware57
Product showcase: Cross-platform and third-party endpoint patching with Action1Help Net Security·Mar 24, 00:00 UTC · Mar 24, 2026Ransomware in the wild60
Kaspersky releases free decryptor for Yanluowang ransomwareSecurity Affairs·Apr 19, 12:29 UTC · Apr 19, 2022Ransomware57
Yanluowang ransomware used in highly targeted attacks on large orgsSecurity Affairs·Oct 14, 11:15 UTC · Oct 14, 2021Ransomware57
Bumblebee attacks, from initial access to the compromise of Active Directory ServicesSecurity Affairs·Aug 19, 08:33 UTC · Aug 19, 2022Ransomware60
New BYOVD loader behind DeadLock ransomware attackCisco Talos·Dec 9, 11:00 UTC · Dec 9, 2025RansomwareCVE-2024-5132460
N-able N-sight RMM enables MSPs to manage and secure their small to medium enterprise customersHelp Net Security·Jul 13, 00:00 UTC · Jul 13, 2022Ransomware60
NotPetya successor Bad Rabbit hits orgs in Russia, UkraineHelp Net Security·Feb 24, 11:59 UTC · Feb 24, 2022Ransomware57
Microsoft Warns of New INC Ransomware Targeting U.S. Healthcare SectorThe Hacker News·Sep 19, 10:12 UTC · Sep 19, 2024Ransomware57
IR Trends: Ransomware on the rise, while technology becomes most targeted sectorCisco Talos·Jul 25, 10:00 UTC · Jul 25, 2024Ransomware60
⚡ Weekly Recap: Chrome 0-Day, AI Hacking Tools, DDR5 BitThe Hacker News·Sep 22, 15:16 UTC · Sep 22, 2025Ransomware in the wildCVE-2025-10585CVE-2025-55241CVE-2025-10035+14 CVEs160
Windows Quick Assist Exploited in Ransomware AttacksInfosecurity Magazine·May 16, 17:15 UTC · May 16, 2024Ransomware57
Researchers Warn of New “Vect” RaaS VariantInfosecurity Magazine·Feb 3, 14:00 UTC · Feb 3, 2026Ransomware57
Attackers keep finding the same gaps in security programsHelp Net Security·Feb 19, 00:00 UTC · Feb 19, 2026RansomwareCVE-2013-2566CVE-2019-11072CVE-2024-638760
Adversaries are leveraging remote access tools now more than ever — here’s how to stop themCisco Talos·Apr 2, 12:00 UTC · Apr 2, 2024Ransomware57
Quarterly Report: Incident Response trends from Spring 2021Cisco Talos·Jun 10, 12:00 UTC · Jun 10, 2021RansomwareCVE-2021-26855CVE-2021-26857CVE-2021-26858+4 CVEs60
Increasing security measures are driving cybercriminals to alter their techniquesHelp Net Security·Feb 27, 00:00 UTC · Feb 27, 2019Ransomware60
The Vanilla Tempest cybercrime gang used INC ransomware for the first time in attacks on the healthcare sectorSecurity Affairs·Sep 20, 08:36 UTC · Sep 20, 2024Ransomware57
⚡ Weekly Recap: Exchange 0-Day, npm Worm, Fake AI Repo, Cisco Exploit and MoreThe Hacker News·May 19, 04:33 UTC · May 19, 2026Ransomware in the wildCVE-2026-42897CVE-2026-20182CVE-2026-2012760