MOVEit Transfer zero-day was exploited by Cl0p gang (CVE-2023-34362)Help Net Security·Jun 8, 10:36 UTC · Jun 8, 2026Ransomware in the wildCVE-2023-3436260
Microsoft blames Clop gang for 'MOVEit Transfer' attacksSecurity Affairs·Jun 5, 15:07 UTC · Jun 5, 2023Ransomware in the wildCVE-2023-3436260
CISA issues directive for exploited VMware bug after IR team deployed to ‘large’ orgThe Record·Jan 12, 00:00 UTC · Jan 12, 2023Ransomware in the wildCVE-2022-22954CVE-2022-22972CVE-2022-22973+1 CVEs60
Ransomware group exploits Citrix NetScaler systems for initial accessHelp Net Security·Aug 29, 00:00 UTC · Aug 29, 2023Ransomware in the wildCVE-2023-351960
WARNING: Microsoft Exchange Under Attack With ProxyShell FlawsThe Hacker News·Aug 23, 13:28 UTC · Aug 23, 2021Ransomware in the wildCVE-2021-34473CVE-2021-34523CVE-2021-3120760
As firms race to patch Microsoft Exchange flaws, security pros brace for ransomware outbreakCyberScoop·Mar 12, 19:28 UTC · Mar 12, 2021Ransomware in the wild60
Attackers exploit cPanel CVE-2026Security Affairs·May 12, 11:41 UTC · May 12, 2026Ransomware in the wildCVE-2026-41940160
Attackers hit React defect as researchers quibble over proofCyberScoop·Dec 6, 17:14 UTC · Dec 6, 2025Ransomware in the wildCVE-2025-55182CVE-2025-6647860
Storm-2603 spotted deploying ransomware on exploited SharePoint serversHelp Net Security·Aug 4, 12:44 UTC · Aug 4, 2025Ransomware in the wildCVE-2025-53770CVE-2025-49706CVE-2025-49704+2 CVEs160
Week in review: Critical SAP NetWeaver flaw exploited, RSAC 2025 ConferenceHelp Net Security·May 4, 00:00 UTC · May 4, 2025Ransomware in the wildCVE-2025-31324CVE-2025-3928CVE-2025-42599+1 CVEs60
Week in review: VPNs vulnerable to TunnelCrack attacks, Cybertech Africa 2023Help Net Security·Aug 20, 00:00 UTC · Aug 20, 2023Ransomware in the wildCVE-2023-32560CVE-2023-3519CVE-2023-2448960
Microsoft investigating alleged Exchange zeroThe Record·Jan 10, 00:00 UTC · Jan 10, 2023Ransomware in the wildCVE-2022-41040CVE-2022-4108260
Hackers with Chinese links breach defense, energy targets, including one in USCyberScoop·Nov 8, 15:11 UTC · Nov 8, 2021Ransomware in the wild60
ProxyShell vulnerabilities actively exploited to deliver web shells and ransomwareHelp Net Security·Aug 23, 00:00 UTC · Aug 23, 2021Ransomware in the wildCVE-2021-34473CVE-2021-34523CVE-2021-3120760
NCSC is not aware of ransomware attacks compromising UK orgs through Microsoft Exchange bugsSecurity Affairs·Mar 15, 08:54 UTC · Mar 15, 2021Ransomware in the wildCVE-2021-26855CVE-2021-26857CVE-2021-26858+1 CVEs60