Security Affairs newsletter Round 492 by Pierluigi PaganiniSecurity Affairs·Oct 6, 12:05 UTC · Oct 6, 2024Ransomware in the wildCVE-2024-4551960
Storm-2603 Exploits SharePoint Flaws to Deploy Warlock Ransomware on Unpatched SystemsThe Hacker News·Jul 28, 15:57 UTC · Jul 28, 2025Ransomware in the wildCVE-2025-49706CVE-2025-4970460
Play ransomware affiliate leveraged zeroSecurity Affairs·May 7, 18:44 UTC · May 7, 2025Ransomware in the wildCVE-2025-2982460
⚡ Weekly Recap: WSUS Exploited, LockBit 5.0 Returns, Telegram Backdoor, F5 Breach WidensThe Hacker News·Oct 27, 14:16 UTC · Oct 27, 2025Ransomware in the wildCVE-2025-59287CVE-2025-54957CVE-2025-6950+21 CVEs60
Interlock Ransomware Exploits Cisco FMC Zero-Day CVE-2026The Hacker News·Mar 21, 07:03 UTC · Mar 21, 2026Ransomware in the wildCVE-2026-2013160
China-Linked Hackers Exploit VMware ESXi ZeroThe Hacker News·Jan 12, 16:25 UTC · Jan 12, 2026Ransomware in the wildCVE-2025-22224CVE-2025-22225CVE-2025-2222660
Chinese-speaking hackers exploited ESXi zeroSecurity Affairs·Jan 9, 00:06 UTC · Jan 9, 2026Ransomware in the wildCVE-2025-22226CVE-2025-22224CVE-2025-2222560
ThreatsDay: Game Cheat Spyware, 24-Hour Ransomware, Chrome Sync Stalking + 12 More StoriesThe Hacker News·Jul 15, 00:00 UTC · Jul 15, 2026Ransomware in the wildCVE-2026-46817CVE-2023-434660
Qilin Ransomware Affiliates Abuse CVE-2026Security Affairs·Jul 21, 16:08 UTC · Jul 21, 2026Ransomware in the wildCVE-2026-025760
Storm-2603 spotted deploying ransomware on exploited SharePoint serversHelp Net Security·Aug 4, 12:44 UTC · Aug 4, 2025Ransomware in the wildCVE-2025-53770CVE-2025-49706CVE-2025-49704+2 CVEs60
CVE-2025-22225 in VMware ESXi now used in active ransomware attacksSecurity Affairs·Feb 4, 22:02 UTC · Feb 4, 2026Ransomware in the wildCVE-2025-22225CVE-2025-22226CVE-2025-2222460
August 2025 CVE LandscapeRecorded Future·Nov 21, 00:00 UTC · Nov 21, 2025Ransomware in the wildCVE-2025-8088CVE-2025-7775CVE-2025-57819+5 CVEs60
⚡ Weekly Recap: Chrome 0-Day, AI Hacking Tools, DDR5 BitThe Hacker News·Sep 22, 15:16 UTC · Sep 22, 2025Ransomware in the wildCVE-2025-10585CVE-2025-55241CVE-2025-10035+14 CVEs160
AI-Enabled Adversaries Compress Time-toInfosecurity Magazine·Mar 18, 13:00 UTC · Mar 18, 2026Ransomware in the wild60
Cryptominers, ransomware among top malware in IR engagements in Q4Cisco Talos·Nov 20, 16:00 UTC · Nov 20, 2019Ransomware in the wild60
Quarterly Report: Incident Response trends in Q1 2022Cisco Talos·Apr 26, 13:11 UTC · Apr 26, 2022Ransomware in the wildCVE-2021-44228CVE-2021-45046CVE-2021-22204+1 CVEs60
Shifting from reactive to proactive: Cyber resilience amid nationCyberScoop·Oct 24, 12:00 UTC · Oct 24, 2025Ransomware in the wild60
ThreatsDay Bulletin: Defender 0-Day, SonicWall Brute-Force, 17-YearThe Hacker News·Apr 17, 14:47 UTC · Apr 17, 2026Ransomware in the wildCVE-2026-33825CVE-2009-0238160
Critical Flaw Exposes 60,000 Redis Servers to Remote ExploitationInfosecurity Magazine·Oct 7, 16:00 UTC · Oct 7, 2025Ransomware in the wildCVE-2025-4984460
SonicWall SSL VPN Flaw and Misconfigurations Actively Exploited by Akira Ransomware HackersThe Hacker News·Sep 15, 00:00 UTC · Sep 15, 2025Ransomware in the wildCVE-2024-4076660
⚡ Weekly Recap: Exchange 0-Day, npm Worm, Fake AI Repo, Cisco Exploit and MoreThe Hacker News·May 19, 04:33 UTC · May 19, 2026Ransomware in the wildCVE-2026-42897CVE-2026-20182CVE-2026-2012760
IR Trends Q3 2025: ToolShell attacks dominate, highlighting criticality of segmentation and rapid responseCisco Talos·Oct 23, 10:00 UTC · Oct 23, 2025Ransomware in the wildCVE-2025-53770CVE-2025-53771CVE-2025-49704+1 CVEs160
Security Affairs newsletter Round 537 by Pierluigi PaganiniSecurity Affairs·Aug 17, 00:26 UTC · Aug 17, 2025Ransomware in the wildCVE-2025-2525660
New bug in PC booting process could take years to fix, researchers sayCyberScoop·Jul 29, 18:01 UTC · Jul 29, 2020Ransomware in the wild60
'China Chopper' web shell makes a comeback in Lebanon, other Asian countriesCyberScoop·Aug 28, 13:36 UTC · Aug 28, 2019Ransomware in the wild60
VMware ESXi Flaw Exploited by Ransomware Groups for Admin AccessThe Hacker News·Jul 31, 04:04 UTC · Jul 31, 2024Ransomware in the wildCVE-2024-37085CVE-2023-28252160
Microsoft Confirms PaperCut Servers Used to Deliver LockBit and Cl0p RansomwareThe Hacker News·Apr 29, 04:05 UTC · Apr 29, 2023Ransomware in the wildCVE-2023-27351CVE-2023-27532CVE-2023-138960
Incident Response trends Q2 2023: Data theft extortion rises, while healthcare is still mostCisco Talos·Jul 26, 12:00 UTC · Jul 26, 2023Ransomware in the wildCVE-2023-0669CVE-2021-27101CVE-2021-27102+3 CVEs60
Cryptojacking on the rise in poorer countries where ransoms can't be paidCyberScoop·Nov 27, 16:24 UTC · Nov 27, 2017Ransomware in the wild60
⚡ Weekly Recap: AI Goes Rogue, Metabase 0-Day, MCP SupplyThe Hacker News·Aug 10, 15:03 UTC · Aug 10, 2026Ransomware in the wildCVE-2026-34348CVE-2026-18497CVE-2026-63508+43 CVEs160
Citrix NetScaler customers hit by third actively exploited zeroCyberScoop·Aug 26, 21:28 UTC · Aug 26, 2025Ransomware in the wildCVE-2025-7775CVE-2025-7776CVE-2025-8424+3 CVEs60
All gas, no brakes: Time to come to AI churchCisco Talos·Feb 5, 19:00 UTC · Feb 5, 2026Ransomware in the wild60
October 2025 CVE LandscapeRecorded Future·Dec 9, 00:00 UTC · Dec 9, 2025Ransomware in the wildCVE-2025-59287CVE-2025-61882CVE-2025-41244+29 CVEs60
DDoSecrets' mission is 'unchanged' in wake of 'BlueLeaks' Twitter banCyberScoop·Jun 24, 14:41 UTC · Jun 24, 2020Ransomware in the wild60
Week in review: Kali Linux 2020.2, sensor-based ransomware detection, 10 most exploited vulnsHelp Net Security·May 17, 00:00 UTC · May 17, 2020Ransomware in the wild60
IT threat evolution Q1 2021Kaspersky Securelist·May 31, 07:32 UTC · May 31, 2021Ransomware in the wildCVE-2021-26855CVE-2021-26857CVE-2021-26858+1 CVEs60
Week in review: Claude Mythos finds 271 Firefox flaws, Vercel breachHelp Net Security·Apr 26, 00:00 UTC · Apr 26, 2026Ransomware in the wildCVE-2026-20133CVE-2026-21876CVE-2026-2895060
Security Affairs newsletter Round 564 by Pierluigi PaganiniSecurity Affairs·Feb 22, 14:14 UTC · Feb 22, 2026Ransomware in the wildCVE-2026-1670CVE-2026-244160
Chinese Hackers Had Access to a U.S. Hacking Tool Years Before It Was Leaked OnlineThe Hacker News·Feb 26, 07:37 UTC · Feb 26, 2021Ransomware in the wildCVE-2017-000560
⚡ Weekly Recap: Password Manager Flaws, Apple 0-Day, Hidden AI Prompts, In-theThe Hacker News·Aug 27, 05:11 UTC · Aug 27, 2025Ransomware in the wildCVE-2018-0171CVE-2025-43300CVE-2025-7353+5 CVEs60