ransomware Hackers Exploit Critical Everest Forms Pro WordPress Plugin Flaw to Take Over Sites A critical vulnerability (CVE-2026-3300) in the Everest Forms Pro WordPress plugin has been exploited by threat actors, allowing for remote code execution and potential site compromise. Attackers have been actively targe… The Hacker News · Jun 5, 2026 Critical CVE-2026-3300MDwordpressvulnerabilityremote code execution
ransomware The U.S. sanctions Nobitex crypto exchange used by ransomware The U.S. Treasury's Office of Foreign Assets Control (OFAC) has announced sanctions against Nobitex, Iran's largest cryptocurrency exchange, for facilitating payments related to terrorist activities. BleepingComputer · Jun 3, 2026 High
ransomware AI-built ransomware toolkit automates EDR evasion, AD discovery A threat actor is utilizing an AI-powered ransomware toolkit to automate Active Directory discovery and evade Endpoint Detection and Response (EDR) solutions. The toolkit, developed with assistance from AI agents like Cu… BleepingComputer · Jun 2, 2026 High RUaiedr evasionactive directory
ransomware Reconstructing an Akira Ransomware Kill Chain from Perimeter and Endpoint Logs, (Wed, May 27th) This report details the reconstruction of an Akira ransomware attack on a mid-sized organization, focusing on the critical early stages of the intrusion. The analysis, based solely on firewall and Windows event logs, rev… SANS Internet Storm Center · May 27, 2026 High USbrute-forcecredential-stuffinglateral-movement
ransomware Ghost CMS CVE-2026-26980 Exploited to Hijack 700+ Sites for ClickFix Attacks A critical vulnerability (CVE-2026-26980) in Ghost CMS is being exploited to hijack over 700 websites, primarily through ClickFix attacks. Threat actors are leveraging this SQL injection flaw to steal admin API keys and… The Hacker News · May 25, 2026 Critical CVE-2026-26980CNsql injectionclickfixjavascript
ransomware ‘First VPN’ Cybercrime Service Disrupted, Administrator Arrested The FBI says First VPN has been used by dozens of ransomware groups for network reconnaissance and intrusions. The post ‘First VPN’ Cybercrime Service Disrupted, Administrator Arrested appeared first on SecurityWeek . SecurityWeek · May 22, 2026 High
ransomware Inside a Crypto Drainer: How to Spot it Before it Empties Your Wallet This article details the evolving landscape of cryptocurrency drainer operations, specifically focusing on the rise of "Drainer-as-a-Service" (DaaS) platforms like "Lucifer." These operations, rather than relying on dire… BleepingComputer · May 21, 2026 High USdrainerdaascryptocurrency
ransomware FBI warns students and staff that ShinyHunters may come knocking after Canvas breach The FBI issued an advisory regarding the ShinyHunters extortion gang following a breach of an online Learning Management System used by educational institutions. Instructure, the provider of Canvas, quietly agreed to pay… Graham Cluley · May 20, 2026 High USransomwarelmseducation
ransomware IT threat evolution in Q1 2026. Non-mobile statistics In Q1 2026, Kaspersky products blocked over 343 million attacks, with significant ransomware activity including 2938 new ransomware variants and 77,000 ransomware attacks. Law enforcement actions disrupted the RAMP cyber… Securelist · May 18, 2026 High CVE-2026-20131POUNransomwarezero-dayraas
ransomware Congress Puts Heat on Instructure After Canvas Outage Following a high-profile cyberattack on its Canvas learning management system by the ShinyHunters group, Instructure is facing increased scrutiny from Congress. The House Committee on Homeland Security has requested a br… Dark Reading · May 15, 2026 High USedtechransomwaredata breach
ransomware When ransomware gets physical: cybercriminals turn to threats of violence Pay up, or we'll pay someone to pay you a visit. Cybercrime gangs are increasingly turning to real-world threats - and even hiring local muscle to deliver the message. Read more in my article on the Hot for Security blog… Graham Cluley · May 14, 2026 High
ransomware State of ransomware in 2026 Kaspersky’s 2026 ransomware threat report highlights a shift in the landscape, with ransomware attacks declining overall but becoming more sophisticated. Key trends include the emergence of post-quantum cryptography rans… Securelist · May 12, 2026 High USransomwarequantum cryptographyedr
ransomware ‘Scattered Spider’ Member ‘Tylerb’ Pleads Guilty A senior member of the Scattered Spider cybercrime group, Tyler Robert Buchanan, has pleaded guilty to wire fraud conspiracy and aggravated identity theft related to a series of text-message phishing attacks conducted in… Krebs on Security · Apr 21, 2026 High UKUSSPphishingsim-swapcryptocurrency
ransomware What the ransom note won’t say This article details the ongoing issues surrounding the BlackCat ransomware gang’s affiliate, who attempted to defraud the group after carrying out a significant attack on Change Healthcare. The incident highlights the i… WeLiveSecurity · Apr 20, 2026 High USransomwarefranchisesupply chain
ransomware Germany Doxes “UNKN,” Head of RU Ransomware Gangs REvil, GandCrab German authorities have identified ‘UNKN,’ the elusive figure behind the notorious GandCrab and REvil ransomware gangs, as 31-year-old Russian national Daniil Maksimovich Shchukin. Shchukin, alongside Anatoly Sergeevitsc… Krebs on Security · Apr 6, 2026 Critical DERUransomwareextortioncybercrime