T9000: Advanced Modular Backdoor Uses Complex AntiPalo Alto Unit 42·Nov 1, 10:04 UTC · Nov 1, 2018MalwareCVE-2012-1856CVE-2015-164160
THOR: Previously Unseen PlugX Variant Deployed During Microsoft Exchange Server Attacks by PKPLUG GroupPalo Alto Unit 42·Jun 6, 12:19 UTC · Jun 6, 2024VulnerabilityCVE-2021-26855CVE-2021-2706560
Dutch Police obtain 155 decryption keys for Deadbolt ransomware victimsThe Record·Jan 9, 00:00 UTC · Jan 9, 2023Ransomware60
ExtraHop expands decryption support for Microsoft authentication and application protocolsHelp Net Security·Nov 4, 00:00 UTC · Nov 4, 2021Ransomware60
Researchers found flaws in MEGA that allowed to decrypt of user dataSecurity Affairs·Jun 23, 07:53 UTC · Jun 23, 2022Vulnerability55
Keenadu the tablet conqueror and the links between major Android botnetsKaspersky Securelist·Feb 17, 09:00 UTC · Feb 17, 2026Malware55
FBI obtained 7,000 LockBit decryption keys, victims should contact feds to get supportSecurity Affairs·Jun 6, 10:04 UTC · Jun 6, 2024Ransomware60
Spear Phishing Attacks Target Organizations in Ukraine, Payloads Include the Document Stealer OutSteel and the Downloader SaintBotPalo Alto Unit 42·Jun 5, 23:28 UTC · Jun 5, 2024MalwareCVE-2017-1188260
Authorities shut down HIVE ransomware infrastructure, provide decryption toolsHelp Net Security·May 7, 10:18 UTC · May 7, 2024Ransomware60
CloudZ RAT potentially steals OTP messages using Pheno pluginCisco Talos·May 5, 10:00 UTC · May 5, 2026Malware55
QNAP urges users to update after new Deadbolt ransomware attacks discoveredThe Record·Jan 12, 00:00 UTC · Jan 12, 2023Ransomware60
Ragnarok ransomware operation shuts down and releases free decrypterThe Record·Dec 15, 00:00 UTC · Dec 15, 2022Ransomware60
Kaseya says it didn't pay ransomware gang for decryption key after hacks affected hundredsCyberScoop·Jul 26, 18:50 UTC · Jul 26, 2021Ransomware in the wild60
Accedian launches TLS 1.3 decryption capabilities for Skylight platformHelp Net Security·Mar 11, 00:00 UTC · Mar 11, 2021Policy & legal55
Using Firepower to defend against encrypted RDP attacks like BlueKeepCisco Talos·May 31, 20:23 UTC · May 31, 2019VulnerabilityCVE-2019-070860
A cascade of compromise: unveiling Lazarus' new campaignKaspersky Securelist·Oct 27, 05:41 UTC · Oct 27, 2023Threat actor60
Gigamon Precryption technology reveals concealed threat activity in the cloudHelp Net Security·Sep 12, 00:00 UTC · Sep 12, 2023Vulnerability55
Researchers Uncover Ways to Break the Encryption of 'MEGA' Cloud Storage ServiceThe Hacker News·Jun 22, 15:05 UTC · Jun 22, 2022Vulnerability55
Law Enforcement Confirms BlackCat Take Down, Decryption Key Offered toInfosecurity Magazine·Dec 19, 17:00 UTC · Dec 19, 2023Ransomware60
Irish officials analyze decryption tool as long recovery process from ransomware continuesCyberScoop·May 23, 01:20 UTC · May 23, 2021Ransomware in the wild60
Flaws in several self-encrypting SSDs allows hackers to decrypt dataSecurity Affairs·Nov 6, 15:51 UTC · Nov 6, 2018Vulnerability55
OneLogin: Breach Exposed Ability to Decrypt DataKrebs on Security·Jun 8, 05:15 UTC · Jun 8, 2017Threat actor60
Hunters International ransomware gang shuts down and offers free decryption keys to all victimsSecurity Affairs·Jul 6, 13:28 UTC · Jul 6, 2025Ransomware60
Most interesting IR cases in 2023: insider threats and moreKaspersky Securelist·Sep 3, 11:01 UTC · Sep 3, 2024Ransomware60
Feds Seize LockBit Ransomware Websites, Offer Decryption Tools, Troll AffiliatesKrebs on Security·Feb 20, 20:21 UTC · Feb 20, 2024Ransomware60
New decryptor for Babuk Tortilla ransomware variant releasedCisco Talos·Jan 9, 09:00 UTC · Jan 9, 2024Ransomware60
Kaseya obtains decryption key for victims of massive ransomware attackCyberScoop·Jul 22, 21:22 UTC · Jul 22, 2021Ransomware in the wild60
The latest on BlueKeep and DejaBlue vulnerabilities — Using Firepower to defend against encrypted DejaBlueCisco Talos·Nov 4, 15:43 UTC · Nov 4, 2019Vulnerability in the wildCVE-2019-0708CVE-2019-1181CVE-2019-118260
Let It Ride: The Sofacy Group’s DealersChoice Attacks ContinuePalo Alto Unit 42·Nov 1, 10:41 UTC · Nov 1, 2018Exploit / PoC in the wildCVE-2016-7855CVE-2016-7255CVE-2015-7645160
Notpetya - The Petya variant used in the massive attack is a wiper disguised by a ransomwareSecurity Affairs·Oct 14, 15:09 UTC · Oct 14, 2017Ransomware60
Researchers build WannaCry decryption tools for Windows XPCyberScoop·May 18, 18:33 UTC · May 18, 2017Ransomware in the wild60
2016 Updates to Shifu Banking TrojanPalo Alto Unit 42·Jan 6, 20:00 UTC · Jan 6, 2017MalwareCVE-2016-0167CVE-2015-0003160
macOS vulnerability allowed Keychain and iOS app decryption without a passwordHelp Net Security·Sep 4, 00:00 UTC · Sep 4, 2025Vulnerability in the wildCVE-2025-2420460
Chinese State-Sponsored Group TA413 Adopts New Capabilities in Pursuit of Tibetan TargetsRecorded Future·Aug 21, 00:00 UTC · Aug 21, 2025Threat actorCVE-2022-1040CVE-2022-3019060
New malicious web shell from the Tropic Trooper group is found in the Middle EastKaspersky Securelist·Sep 5, 08:02 UTC · Sep 5, 2024Vulnerability in the wildCVE-2021-34473CVE-2021-34523CVE-2021-31207+1 CVEs60