Exploring vulnerable Windows driversCisco Talos·Dec 19, 11:04 UTC · Dec 19, 2024RansomwareCVE-2022-369960
XPAJ: Reversing a Windows x64 BootkitKaspersky Securelist·Jun 19, 18:16 UTC · Jun 19, 2012Ransomware60
Threat Brief: Understanding Kernel APC AttacksPalo Alto Unit 42·Jan 28, 22:06 UTC · Jan 28, 2022Ransomware57
ThrottleStop driver abused to terminate AV processesKaspersky Securelist·Aug 6, 10:00 UTC · Aug 6, 2025RansomwareCVE-2025-777160
Novel News on Cuba Ransomware: Greetings From Tropical ScorpiusPalo Alto Unit 42·Jun 5, 20:16 UTC · Jun 5, 2024Ransomware57
Delivering vulnerable signed kernel drivers remains popular among attackersHelp Net Security·Jan 13, 00:00 UTC · Jan 13, 2022Ransomware60
Windows CLFS and five exploits used by ransomware operators (Exploit #1 – CVE-2022Kaspersky Securelist·Dec 21, 10:28 UTC · Dec 21, 2023Ransomware in the wildCVE-2022-24521CVE-2023-23376CVE-2023-28252+2 CVEs60
Researchers Discover "Bootkitty" – First UEFI Bootkit Targeting Linux KernelsThe Hacker News·Dec 2, 16:30 UTC · Dec 2, 2024RansomwareCVE-2023-4023860
CrowdStrike Apologizes for IT Outage, Defends Microsoft Kernel AccessInfosecurity Magazine·Sep 25, 11:30 UTC · Sep 25, 2024Ransomware60
BlackCat Ransomware affiliate uses signed kernel driver to evade detectionSecurity Affairs·May 23, 06:51 UTC · May 23, 2023Ransomware57
Old Linux Kernel flaw CVE-2024Security Affairs·Oct 31, 18:17 UTC · Oct 31, 2025Ransomware in the wildCVE-2024-108660
Hackers Exploit Windows Policy Loophole to Forge KernelThe Hacker News·Jul 12, 03:37 UTC · Jul 12, 2023Ransomware57
New OS X Ransomware KeRanger Infected Transmission BitTorrent Client InstallerPalo Alto Unit 42·Jan 28, 22:01 UTC · Jan 28, 2022Ransomware57
Ransomware gangs exploit a Paragon Partition Manager BioNTdrv.sys driver zeroSecurity Affairs·Mar 1, 18:52 UTC · Mar 1, 2025Ransomware in the wildCVE-2025-0289CVE-2025-0288CVE-2025-0287+2 CVEs60
Windows CLFS and five exploits used by ransomware operatorsKaspersky Securelist·Dec 21, 09:53 UTC · Dec 21, 2023RansomwareCVE-2023-28252CVE-2022-24521CVE-2022-37969+1 CVEs60
Making Vulnerable Drivers Exploitable Without HardwareThe Hacker News·May 22, 11:38 UTC · May 22, 2026Ransomware57
Why a decade-old EnCase driver still works as an EDR killerHelp Net Security·Feb 5, 00:00 UTC · Feb 5, 2026Ransomware60
ThreatsDay Bulletin: New RCEs, Darknet Busts, Kernel Bugs & 25+ More StoriesThe Hacker News·Jan 30, 08:37 UTC · Jan 30, 2026Ransomware in the wildCVE-2025-59090CVE-2025-5910960
Hackers Exploit Paragon Partition Manager Driver Vulnerability in Ransomware AttacksThe Hacker News·Mar 3, 13:56 UTC · Mar 3, 2025RansomwareCVE-2025-0289CVE-2025-0285CVE-2025-0286+2 CVEs60
BYOVD Attacks Exploit ZeroInfosecurity Magazine·Mar 3, 09:35 UTC · Mar 3, 2025RansomwareCVE-2025-0289CVE-2025-0288CVE-2025-0287+2 CVEs60
RobbinHood ransomware exploit GIGABYTE driver flaw to kill security softwareSecurity Affairs·Feb 8, 00:20 UTC · Feb 8, 2020RansomwareCVE-2018-1932060
GodDamn Ransomware Uses PoisonX to Blind Security SoftwareSecurity Affairs·Jul 9, 18:11 UTC · Jul 9, 2026Ransomware57
Analysis of Cuba ransomware gang activity and toolingKaspersky Securelist·Sep 11, 10:00 UTC · Sep 11, 2023RansomwareCVE-2021-31207CVE-2021-34473CVE-2021-34523+8 CVEs60
Nokoyawa ransomware attacks with Windows zeroKaspersky Securelist·Apr 11, 17:36 UTC · Apr 11, 2023RansomwareCVE-2023-28252CVE-2022-24521CVE-2022-37969+1 CVEs60
Dynamic analysis of firmware components in IoT devicesKaspersky Securelist·Jul 6, 10:00 UTC · Jul 6, 2022Ransomware145
Cruciferra Crypter Uses Process Ghosting to Evade DetectionInfosecurity Magazine·Jul 20, 15:00 UTC · Jul 20, 2026Ransomware57
CVE-2025-22225 in VMware ESXi now used in active ransomware attacksSecurity Affairs·Feb 4, 22:02 UTC · Feb 4, 2026Ransomware in the wildCVE-2025-22225CVE-2025-22226CVE-2025-2222460
Bootkitty is the first UEFI Bootkit designed for Linux systemsSecurity Affairs·Nov 27, 21:01 UTC · Nov 27, 2024Ransomware45
A Dissection of the “EsteemAudit” Windows Remote Desktop ExploitPalo Alto Unit 42·May 31, 12:00 UTC · May 31, 2017RansomwareCVE-2017-907360
GentleKiller Framework Disables Victims' Security SoftwareInfosecurity Magazine·Jun 22, 15:00 UTC · Jun 22, 2026Ransomware57
⚡ Weekly Recap: Exchange 0-Day, npm Worm, Fake AI Repo, Cisco Exploit and MoreThe Hacker News·May 19, 04:33 UTC · May 19, 2026Ransomware in the wildCVE-2026-42897CVE-2026-20182CVE-2026-2012760
Qilin and Warlock Ransomware Use Vulnerable Drivers to Disable 300+ EDR ToolsThe Hacker News·Apr 6, 10:07 UTC · Apr 6, 2026Ransomware57
China-Linked Hackers Exploit VMware ESXi ZeroThe Hacker News·Jan 12, 16:25 UTC · Jan 12, 2026Ransomware in the wildCVE-2025-22224CVE-2025-22225CVE-2025-2222660
BlackByte Ransomware abuses driver to bypass security solutionsSecurity Affairs·Oct 8, 16:23 UTC · Oct 8, 2022RansomwareCVE-2018-19320CVE-2019-1609860
The future of macOS security: Baked-in protection and third-party toolsHelp Net Security·Jul 31, 21:33 UTC · Jul 31, 2018RansomwareCVE-2015-3673CVE-2015-7024CVE-2017-698760
GodDamn Ransomware Uses PoisonX Driver to Disable Endpoint DefensesThe Hacker News·Jul 10, 07:50 UTC · Jul 10, 2026Ransomware57
The Gentlemen RaaS Uses GentleKiller EDR Framework Targeting 400 Security ProcessesThe Hacker News·Jun 23, 17:43 UTC · Jun 23, 2026Ransomware57