US charges another ransomware negotiator linked to BlackCat attacks
2026-03-12T13:23:33Z•4955775fdbdae9f34faa83ad76ddda46ea33e7374de6d871978d0db56d7990e1
ALPHVAndroid malwareBeatBankerBlackSantaCISADOJEDR bypassElementorHandalaPatch TuesdayPhantomRavenRCESQLiStrykerWordPressZombie ZIPevasioninsider threatn8nnpmplugin vulnerabilityransomwaresupply-chainwiper malwarezero-day
What happened
A batch of BleepingComputer security reports highlights multiple high-risk incidents and actively exploited vulnerabilities. Notable items: DOJ charged a former ransomware negotiator involved in an insider scheme with BlackCat/ALPHV; CISA ordered federal agencies to patch an actively exploited n8n RCE; an unauthenticated SQL injection in Elementor Ally affects hundreds of thousands of WordPress sites; Microsoft’s March 2026 Patch Tuesday fixes 79 flaws including two zero-days; HPE patched a critical Aruba AOS-CX flaw allowing admin password resets; supply-chain campaigns (PhantomRaven) pushed
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 4955775fdbdae9f34faa83ad76ddda46ea33e7374de6d871978d0db56d7990e1
- Enrichment time
- 2026-03-12T13:23:33Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.