Kyber ransomware gang toys with post-quantum encryption on Windows

2026-04-22T19:23:29Z9a307b077a922d7f0363bd7c725b5fed06a296f48a1dea5bbe4e29ac38501242
ASP.NET CoreApache ActiveMQCISACatalystGoGraKyberKyber1024Linux malwareLotus','data wiper','Venezuela','caller-as-a-service','fraud','sMicrosoftMicrosoft Graph APISD-WANSharePointVMware ESXiactive exploitationcode injectioncredential theftnpmout-of-band patchpost-quantumransomwareself-spreading malwarespoofingsupply-chainzero-day

What happened

Multiple high-impact security developments: a new Kyber ransomware campaign is targeting Windows and VMware ESXi systems, with one variant adopting Kyber1024 post-quantum encryption; a self-propagating npm supply-chain attack is stealing developer auth tokens and spreading via compromised packages; Microsoft issued out-of-band emergency patches for a critical ASP.NET Core privilege-escalation flaw while >1,300 SharePoint servers remain vulnerable to an actively abused spoofing zero-day. CISA flagged an actively exploited SD‑WAN Manager vulnerability, Shadowserver reported ~6,400 Apache ActiveQ

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
9a307b077a922d7f0363bd7c725b5fed06a296f48a1dea5bbe4e29ac38501242
Enrichment time
2026-04-22T19:23:29Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Kyber ransomware gang toys with post-quantum encryption on Windows · Baitaphish