FBI, British authorities seize infrastructure of LockBit ransomware groupCyberScoop·Feb 21, 15:54 UTC · Feb 21, 2024Ransomware in the wild60
After Hive takedown, could the LockBit ransomware crew be the next to fall?CyberScoop·Feb 7, 21:44 UTC · Feb 7, 2023Ransomware in the wild60
LockBit claims a comeback less than a week after major disruptionCyberScoop·Feb 27, 16:09 UTC · Feb 27, 2024Ransomware in the wild60
Multinational police effort hits sections of Lockbit ransomware operationCyberScoop·Oct 1, 14:52 UTC · Oct 1, 2024Ransomware in the wild60
Copycat Criminals mimicking Lockbit gang in northern EuropeSecurity Affairs·Jan 28, 21:58 UTC · Jan 28, 2023Ransomware in the wild60
After LockBit takedown, police try to sow doubt in cybercrime communityCyberScoop·Feb 23, 22:31 UTC · Feb 23, 2024Ransomware in the wild60
US, UK authorities unmask Russian national as LockBit administratorCyberScoop·May 7, 19:04 UTC · May 7, 2024Ransomware in the wild60
Australian Cyber Security Centre warns of a surge of LockBit 2.0 ransomware attacksSecurity Affairs·Aug 9, 11:41 UTC · Aug 9, 2021Ransomware in the wildCVE-2018-1337960
Justice Department unveils charges against alleged LockBit developerCyberScoop·Dec 20, 18:57 UTC · Dec 20, 2024Ransomware in the wild60
Israeli court to hear U.S. extradition request for alleged LockBit developerCyberScoop·Dec 19, 21:14 UTC · Dec 19, 2024Ransomware in the wild60
Russian national arrested in Arizona, charged for alleged role in LockBit ransomware attacksCyberScoop·Jun 15, 18:41 UTC · Jun 15, 2023Ransomware in the wild60
LockBit 2.0 gang claims Mandiant as latest victim; Mandiant sees no evidence of itCyberScoop·Jun 7, 01:27 UTC · Jun 7, 2022Ransomware in the wild60
LockBit ransomware crew claims attack on California Department of FinanceCyberScoop·Dec 13, 01:16 UTC · Dec 13, 2022Ransomware in the wild60
How LockBit used Citrix Bleed to breach Boeing and other targetsHelp Net Security·Nov 22, 00:00 UTC · Nov 22, 2023Ransomware in the wildCVE-2023-496660
⚡ Weekly Recap: WSUS Exploited, LockBit 5.0 Returns, Telegram Backdoor, F5 Breach WidensThe Hacker News·Oct 27, 14:16 UTC · Oct 27, 2025Ransomware in the wildCVE-2025-59287CVE-2025-54957CVE-2025-6950+21 CVEs60
'Mora_001' ransomware gang exploiting Fortinet bug spotlighted by CISA in JanuaryThe Record·Mar 17, 14:17 UTC · Mar 17, 2025Ransomware in the wildCVE-2024-55591CVE-2025-2447260
U.S. sanctions bulletproof hosting provider for supplying LockBit infrastructureCyberScoop·Feb 11, 16:30 UTC · Feb 11, 2025Ransomware in the wild60
LockBit ransomware gang leaked data stolen from BoeingSecurity Affairs·Nov 13, 14:02 UTC · Nov 13, 2023Ransomware in the wildCVE-2023-496660
‘Citrix Bleed’ vulnerability targeted by nationThe Record·Nov 21, 19:18 UTC · Nov 21, 2023Vulnerability in the wildCVE-2023-4966CVE-2023-491160
Boeing confirms attempted $200 million ransomware extortion attemptCyberScoop·May 8, 23:22 UTC · May 8, 2024Ransomware in the wild60
Ransomware groups rack up victims among corporate AmericaCyberScoop·Nov 21, 22:06 UTC · Nov 21, 2023Ransomware in the wildCVE-2023-496660
Microsoft Confirms PaperCut Servers Used to Deliver LockBit and Cl0p RansomwareThe Hacker News·Apr 29, 04:05 UTC · Apr 29, 2023Ransomware in the wildCVE-2023-27351CVE-2023-27532CVE-2023-138960
LockBit ransomware suspect arrested in Canada, faces charges in USCyberScoop·Nov 10, 22:37 UTC · Nov 10, 2022Ransomware in the wild60
Russian ransomware group claims attack on Bulgarian refugee agencyCyberScoop·May 4, 16:48 UTC · May 4, 2022Ransomware in the wild60
Week in review: LockBit exploits Citrix Bleed, Apache ActiveMQ bug exploited for cryptojackingHelp Net Security·Nov 26, 00:00 UTC · Nov 26, 2023Ransomware in the wildCVE-2023-4966CVE-2023-1671CVE-2023-4660460
LockBit Dominates Ransomware Campaigns in 2022: Deep InstinctInfosecurity Magazine·Nov 1, 15:00 UTC · Nov 1, 2022Ransomware in the wild60
CL0P's Ransomware RampageThe Hacker News·May 13, 09:30 UTC · May 13, 2024Ransomware in the wildCVE-2023-0669CVE-2023-27350CVE-2023-27351+2 CVEs60
Microsoft investigating alleged Exchange zeroThe Record·Jan 10, 00:00 UTC · Jan 10, 2023Ransomware in the wildCVE-2022-41040CVE-2022-4108260
Ransomware attacks jump as new malware strains proliferate, research findsCyberScoop·Aug 25, 13:13 UTC · Aug 25, 2022Ransomware in the wild60
Ransomware group targets Italian tax agencyCyberScoop·Jul 25, 16:09 UTC · Jul 25, 2022Ransomware in the wild60
Ransomware group says it took files from French Ministry of JusticeCyberScoop·Jan 27, 19:39 UTC · Jan 27, 2022Ransomware in the wild60
IR Trends Q3 2025: ToolShell attacks dominate, highlighting criticality of segmentation and rapid responseCisco Talos·Oct 23, 10:00 UTC · Oct 23, 2025Ransomware in the wildCVE-2025-53770CVE-2025-53771CVE-2025-49704+1 CVEs160
Attackers exploit Fortinet flaws to deploy Qilin ransomwareSecurity Affairs·Jun 6, 22:09 UTC · Jun 6, 2025Ransomware in the wildCVE-2024-21762CVE-2024-55591CVE-2025-2447260
U.S. CISA adds Fortinet FortiOS/FortiProxy and GitHub Action flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Mar 20, 14:17 UTC · Mar 20, 2025Exploit / PoC in the wildCVE-2025-24472CVE-2025-30066CVE-2024-5559160
A new alert system from CISA seems to be effective — now we just need companies to sign upCisco Talos·May 9, 18:00 UTC · May 9, 2024Ransomware in the wildCVE-2023-4960660
Ransomware groups continue to increase their operational tempoHelp Net Security·Oct 26, 00:00 UTC · Oct 26, 2023Ransomware in the wild60
Hackers stole client info, work materials in Accenture ransomware attackCyberScoop·Aug 12, 18:49 UTC · Aug 12, 2021Ransomware in the wild60
Week in review: Firmware-level Android backdoor found on tablets, Dell zero-day exploited since 2024Help Net Security·Feb 22, 00:00 UTC · Feb 22, 2026Exploit / PoC in the wildCVE-2026-2441CVE-2026-22769CVE-2026-2329+1 CVEs60
⚡ Weekly Recap: WhatsApp Worm, Critical CVEs, Oracle 0The Hacker News·Oct 15, 00:00 UTC · Oct 15, 2025Ransomware in the wildCVE-2025-61882CVE-2025-61884CVE-2025-10035+12 CVEs160
Week in review: Microsoft fixes exploited zero-day, Mirai botnets target unpatched Wazuh serversHelp Net Security·Jun 15, 00:00 UTC · Jun 15, 2025Exploit / PoC in the wildCVE-2025-33053CVE-2025-24016CVE-2025-43200+1 CVEs60