Security Affairs newsletter Round 492 by Pierluigi PaganiniSecurity Affairs·Oct 6, 12:05 UTC · Oct 6, 2024Ransomware in the wildCVE-2024-4551960
Cybercriminals Are Leveraging Autonomous AI Offensive Security AgentsSecurity Affairs·Jul 30, 17:19 UTC · Jul 30, 2026Ransomware57
AWS Warns Hackers Have Abused Cisco Firewall ZeroInfosecurity Magazine·Mar 19, 09:50 UTC · Mar 19, 2026RansomwareCVE-2026-2013160
Dark web threats and dark market predictions for 2024Kaspersky Securelist·Jan 17, 10:00 UTC · Jan 17, 2024Ransomware57
Ransom Cartel Ransomware: A Possible Connection With REvilPalo Alto Unit 42·Jun 5, 17:50 UTC · Jun 5, 2024Ransomware57
Storm-2603 Exploits SharePoint Flaws to Deploy Warlock Ransomware on Unpatched SystemsThe Hacker News·Jul 28, 15:57 UTC · Jul 28, 2025Ransomware in the wildCVE-2025-49706CVE-2025-4970460
Everyday tools, extraordinary crimes: the ransomware exfiltration playbookCisco Talos·Mar 19, 10:00 UTC · Mar 19, 2026Ransomware57
Why vaporworms might be the scourge of 2019Help Net Security·Mar 10, 14:44 UTC · Mar 10, 2019Ransomware60
The 3 most common post-compromise tactics on network infrastructureCisco Talos·Mar 7, 15:00 UTC · Mar 7, 2024Ransomware60
Ransomware Attackers Target Industries with Low Downtime ToleranceInfosecurity Magazine·Dec 20, 09:15 UTC · Dec 20, 2024Ransomware60
Researchers Reveal Reprompt Attack Allowing Single-Click Data Exfiltration From Microsoft CopilotThe Hacker News·Jan 15, 00:00 UTC · Jan 15, 2026Ransomware160
New Variant of Russian Cyclops Blink Botnet Targeting ASUS RoutersThe Hacker News·Mar 19, 05:12 UTC · Mar 19, 2022Ransomware60
Modified Zyklon and plugins from IndiaCisco Talos·May 23, 13:05 UTC · May 23, 2017RansomwareCVE-2013-3906CVE-2012-185660
Microsoft Warns Developers of Fake Next.js Job Repos Delivering InThe Hacker News·Mar 10, 05:53 UTC · Mar 10, 2026Ransomware57
Inside Mistic, the New Stealth Backdoor in Ransomware IntrusionsSecurity Affairs·Jun 25, 15:07 UTC · Jun 25, 2026Ransomware57
What happened in Vegas (that you actually want to know about)Cisco Talos·Aug 14, 18:00 UTC · Aug 14, 2025RansomwareCVE-2025-654360
Play ransomware affiliate leveraged zeroSecurity Affairs·May 7, 18:44 UTC · May 7, 2025Ransomware in the wildCVE-2025-2982460
⚡ Weekly Recap: WSUS Exploited, LockBit 5.0 Returns, Telegram Backdoor, F5 Breach WidensThe Hacker News·Oct 27, 14:16 UTC · Oct 27, 2025Ransomware in the wildCVE-2025-59287CVE-2025-54957CVE-2025-6950+21 CVEs60
200,000 Linux systems from Framework are shipped with signed UEFI components vulnerable to Secure Boot bypassSecurity Affairs·Oct 15, 14:22 UTC · Oct 15, 2025RansomwareCVE-2022-34302CVE-2023-48733CVE-2024-734460
Cyber extortionists target North American companiesHelp Net Security·Jun 16, 00:00 UTC · Jun 16, 2017Ransomware60
Interlock Ransomware Exploits Cisco FMC Zero-Day CVE-2026The Hacker News·Mar 21, 07:03 UTC · Mar 21, 2026Ransomware in the wildCVE-2026-2013160
China-Linked Hackers Exploit VMware ESXi ZeroThe Hacker News·Jan 12, 16:25 UTC · Jan 12, 2026Ransomware in the wildCVE-2025-22224CVE-2025-22225CVE-2025-2222660
Chinese-speaking hackers exploited ESXi zeroSecurity Affairs·Jan 9, 00:06 UTC · Jan 9, 2026Ransomware in the wildCVE-2025-22226CVE-2025-22224CVE-2025-2222560
CISA and FBI warn of Truebot infecting US and Canada based orgsSecurity Affairs·Jul 7, 05:58 UTC · Jul 7, 2023RansomwareCVE-2022-3119960
IR Q4 2023 trends: Significant increase in ransomware activity found in engagements, while education remains one of the mostCisco Talos·Jan 24, 13:00 UTC · Jan 24, 2024RansomwareCVE-2020-147260
Akira Ransomware Group Rakes in $42m, 250 Organizations ImpactedInfosecurity Magazine·Apr 19, 11:17 UTC · Apr 19, 2024Ransomware60
Exploring vulnerable Windows driversCisco Talos·Dec 19, 11:04 UTC · Dec 19, 2024RansomwareCVE-2022-369960
Introducing ToyMaker, an initial access broker working in cahoots with double extortion gangsCisco Talos·Apr 23, 10:00 UTC · Apr 23, 2025Ransomware60
ThreatsDay: Game Cheat Spyware, 24-Hour Ransomware, Chrome Sync Stalking + 12 More StoriesThe Hacker News·Jul 15, 00:00 UTC · Jul 15, 2026Ransomware in the wildCVE-2026-46817CVE-2023-434660
Interlock group exploiting the CISCO FMC flaw CVE-2026Security Affairs·Mar 19, 09:22 UTC · Mar 19, 2026RansomwareCVE-2026-2013160
Qilin Ransomware Affiliates Abuse CVE-2026Security Affairs·Jul 21, 16:08 UTC · Jul 21, 2026Ransomware in the wildCVE-2026-025760
Medusa Ransomware Uses Malicious Driver to Disable AntiThe Hacker News·Mar 22, 04:07 UTC · Mar 22, 2025Ransomware57
New propagation module makes Trickbot more stealthyHelp Net Security·Jun 1, 00:00 UTC · Jun 1, 2020Ransomware57
More Hacking Groups Found Exploiting SMB Flaw Weeks Before WannaCryThe Hacker News·May 19, 15:00 UTC · May 19, 2017RansomwareCVE-2017-014360
Kaspersky IT threat report for Q1 2022Kaspersky Securelist·May 27, 08:00 UTC · May 27, 2022Ransomware57
Ransomware gang targets IT workers with new RAT masquerading as IP scannerHelp Net Security·Aug 6, 00:00 UTC · Aug 6, 2024Ransomware57
New MortalKombat ransomware and Laplas Clipper malware threats deployed in financially motivated campaignCisco Talos·Feb 14, 13:00 UTC · Feb 14, 2023Ransomware57
PwnedPiper PTS Security Flaws Threaten 80% of Hospitals in the U.S.The Hacker News·Aug 12, 13:04 UTC · Aug 12, 2021RansomwareCVE-2021-37161CVE-2021-37162CVE-2021-37163+5 CVEs60