PROBABLYPWNED
Home/Ransomware News

Ransomware News

Track the latest ransomware attacks, malware campaigns, and threat actor activity. Analysis of ransomware gangs, decryption tools, and defense strategies.

264Malware Articles
Megalodon Attack Backdoors 5,561 GitHub Repos in Six Hours
Malware4 min read

Megalodon Attack Backdoors 5,561 GitHub Repos in Six Hours

Automated Megalodon campaign pushed 5,718 malicious commits to GitHub repos on May 18, injecting CI/CD workflows that exfiltrate cloud credentials, SSH keys, and secrets. SafeDep links it to TeamPCP.

James RiveraMay 23, 2026
Laravel-Lang Supply Chain Attack Deploys Credential Stealer
Malware4 min read

Laravel-Lang Supply Chain Attack Deploys Credential Stealer

Attackers compromised 700+ versions of Laravel-Lang PHP packages via tag poisoning, deploying a sophisticated stealer targeting cloud credentials, crypto wallets, and browser data. Packagist pulled affected versions.

James RiveraMay 23, 2026
DBIR 2026: Vulnerability Exploitation Now the Top Breach Cause
Threat Intelligence4 min read

DBIR 2026: Vulnerability Exploitation Now the Top Breach Cause

Verizon's 2026 Data Breach Investigations Report reveals vulnerability exploitation surpassed credential theft as the leading breach vector for the first time in 19 years. Only 26% of KEV flaws get patched.

Alex KowalskiMay 20, 2026
Microsoft Dismantles Fox Tempest Malware-Signing Operation
Threat Intelligence3 min read

Microsoft Dismantles Fox Tempest Malware-Signing Operation

Microsoft's Digital Crimes Unit seizes infrastructure behind Fox Tempest, a malware-signing service that helped Rhysida, Akira, and Qilin ransomware gangs disguise malicious code as legitimate software.

Alex KowalskiMay 20, 2026
Nx Console VS Code Extension Hijacked for 11 Minutes
Malware4 min read

Nx Console VS Code Extension Hijacked for 11 Minutes

Attackers published malicious Nx Console 18.95.0 to VS Code Marketplace, stealing developer credentials via triple-channel exfiltration and Sigstore-signed npm package poisoning.

James RiveraMay 19, 2026
DAEMON Tools Trojanized Since April—Backdoor Hit 100+ Countries
Malware4 min read

DAEMON Tools Trojanized Since April—Backdoor Hit 100+ Countries

Kaspersky uncovered a supply chain attack on DAEMON Tools official website. Trojanized installers deployed QUIC RAT backdoors to thousands of systems, with a dozen government and manufacturing targets receiving advanced payloads.

James RiveraMay 8, 2026

Related Data Breaches

Understanding the Ransomware Threat

Ransomware remains one of the most damaging cyber threats facing organizations today. Our coverage tracks active ransomware gangs, new malware variants, attack campaigns, and the evolving tactics used by threat actors.

We analyze ransomware-as-a-service (RaaS) operations, infostealer malware, banking trojans, and nation-state malware campaigns. Each article includes indicators of compromise (IOCs), MITRE ATT&CK mappings, and practical defense recommendations.

New to ransomware? Read our comprehensive guide: What is Ransomware? For broader malware education, see What is Malware?

Notable Ransomware Groups We Track

LockBitActive
ALPHV/BlackCatDisrupted
AkiraActive
PlayActive
Cl0pActive
Black BastaActive
RoyalRebranded
Scattered SpiderActive

All Hacking News

Browse all cybersecurity news including breaches, vulnerabilities, and threat intel.

What is Ransomware?

Complete guide to understanding ransomware attacks and how to prevent them.

Threat Intelligence

APT tracking, nation-state campaigns, and threat actor analysis.