Skip to main content
FreeIntelHub
Feed Threat Feed Search Trending
Intelligence CVE Priority Vulnerability IOC Lookup IOC Feed YARA Rules Phishing Lookup Exploit Lookup Pastes Dark Web
Adversaries Threat Groups Software Campaigns
Explore Dashboard Geo Map Heatmap MITRE ATT&CK
Browse Sources Vendors Categories Sectors
RSS API
FreeIntelHub
/
Sign In

Ransomware

20 articles

Security Affairs Ransomware May 21

Global law enforcement operation takes First VPN offline

Police seized First VPN in a global crackdown, exposed its cybercrime users, and shut down infrastructure tied to ransomware and data theft. A major internat...

T1041 T1598

Security Affairs →

Infosecurity Magazine Ransomware May 21

Cybercriminal VPN Dismantled in Europol Crackdown

First VPN, a service used by ransomware actors and fraudsters, was dismantled by Europol

Infosecurity Magazine →

Help Net Security Ransomware May 21

Authorities dismantle First VPN, used by ransomware actors

First VPN, a virtual private network service marketed to cybercriminals, promising anonymity for its users, was taken offline on May 19 and 20 as part of Ope...

Help Net Security →

BleepingComputer Ransomware May 21

Police seize “First VPN” service used in ransomware, data theft attacks

A virtual private network service called 'First VPN,' used in ransomware and data theft attacks, has been taken offline in a joint international law enforcem...

T1041

BleepingComputer →

Rapid7 Blog Ransomware May 21

Q1 2026 Threat Landscape Report: Zero-clicks, geopolitical tensions, and some wins for law enforcement

The first quarter of 2026 reinforced that attackers are moving faster, operating with greater coordination, and exploiting weaknesses before most organizatio...

T1204 T1598

Rapid7 Blog →

HackRead Ransomware May 21

Europol Seizes First VPN Used by Ransomware Gangs, Arrests Administrator

Europol has seized First VPN, a service used by ransomware gangs, arrested its administrator and gained access to data linked to thousands of users.

HackRead →

GBHackers Ransomware May 21

WantToCry Ransomware Exploits SMB to Encrypt Remote Files

A new ransomware campaign named “WantToCry” that leverages exposed Server Message Block (SMB) services to gain access and encrypt victim data without deployi...

GBHackers →

The Record Ransomware May 20

Europe dismantles VPN service used by cybercriminals to hide ransomware attacks

The international operation targeted a service known as First VPN, which had been marketed for years on Russian-speaking cybercrime forums as a secure way fo...

The Record →

SC Media Ransomware May 20

WantToCry ransomware evades detection through SMB abuse, remote encryption

More than 1.5 million exposed SMB ports may be susceptible to brute force attacks.

T1110

SC Media →

BleepingComputer Ransomware SonicWall May 20

Hackers bypass SonicWall VPN MFA due to incomplete patching

Threat actors brute-forced VPN credentials and bypassed multi-factor authentication (MFA) on SonicWall Gen6 SSL-VPN appliances to deploy tools used in ransom...

BleepingComputer →

The Hacker News Ransomware Microsoft May 20

Microsoft Takes Down Malware-Signing Service Behind Ransomware Attacks

Microsoft on Tuesday said it disrupted a malware-signing-as-a-service (MSaaS) operation that weaponized the company's Artifact Signing system to deliver mali...

The Hacker News →

SC Media Ransomware May 20

Verizon DBIR 2026: Vulnerability exploits top initial access as patching coverage falls

The report also highlighted ransomware trends and the evolving role of AI in breaches.

SC Media →

GBHackers Ransomware Microsoft Intel May 20

Fox Tempest Linked to Malware-Signing Service Abusing Microsoft Artifact Signing

Fox Tempest, a financially motivated threat actor, has been linked to a large-scale malware-signing-as-a-service (MSaaS) operation that abused Microsoft’s Ar...

GBHackers →

CSO Online Ransomware Microsoft May 20

Microsoft disrupts malware code-signing service used by ransomware gangs

Microsoft has disrupted the infrastructure powering the largest malware code-signing service used to help ransomware groups and other cybercriminals make mal...

CSO Online →

BleepingComputer Ransomware Microsoft May 19

Cybercrime service disrupted for abusing Microsoft platform to sign malware

Microsoft says it has disrupted a malware-signing-as-a-service (MSaaS) operation that abused the company's Artifact Signing service to generate fraudulent co...

BleepingComputer →

The Record Ransomware Microsoft May 19

Microsoft disrupts Fox Tempest malware-signing-as-a-service platform tied to ransomware gangs

The company unsealed a legal case in U.S.

The Record →

SecurityWeek Ransomware Microsoft May 19

Microsoft Disrupts Malware-Signing Service Run by ‘Fox Tempest’ 

Fox Tempest provides a service that cybercriminals use to distribute ransomware and other malware disguised as legitimate software. The post Microsoft Disrup...

SecurityWeek →

Microsoft Security Blog Ransomware Microsoft May 19

Exposing Fox Tempest: A malware-signing service operation

Fox Tempest is a financially motivated threat actor operating a malware‑signing‑as‑a‑service (MSaaS) used by other cybercriminals, including Vanilla Tempest ...

Microsoft Security Blog →

Cyberscoop Ransomware Microsoft May 19

Microsoft disrupts cybercrime service that abused software verification systems en masse

Fox Tempest, a financially-motivated threat group, allowed ransomware operators and other cybercriminals to slip malware-laced software past security control...

Cyberscoop →

Infosecurity Magazine Ransomware Microsoft May 19

Microsoft Takes Down Fox Tempest for Providing Ransomware-Enabling Signing Tool

Microsoft’s Digital Crimes Unit has taken down the infrastructure of Fox Tempest, a prolific cybercrime-enabling threat group

Infosecurity Magazine →

«Previous page 1 2 3 4 5 ... 8 Next page»
FreeIntelHub · Open-source CTI platform

All articles belong to their respective owners. FreeIntelHub aggregates publicly available RSS feeds for informational purposes only. DMCA