German authorities identify REvil and GandCrab ransomware bosses

2026-04-07T13:23:29Za57291d79356b97648837b5cab5f18d93e511d17eae02d0266bbe86819a5a213
AxiosBlueHammerCISADrift ProtocolFortiClient EMSFortinetGPU RowhammerGPUBreachGandCrabLinkedIn BrowserGateMedusaQR phishingREvilReact2Shellactive exploitationcredential theftcrypto-theftdevice-code-phishingemergency patchnpm compromiseransomwaresupply-chainzero-day

What happened

Multiple high-impact security stories: German BKA identified two Russian nationals as leaders of GandCrab and REvil ransomware operations (2019–2021). Active and emergent exploitation observed — Fortinet FortiClient EMS vulnerability (CVE-2026-35616) is being actively exploited, prompting emergency patches and a CISA order for federal remediation; React2Shell (CVE-2025-55182) is being abused in large-scale automated credential-theft campaigns; a leaked unpatched Windows privilege-escalation exploit dubbed “BlueHammer” enables SYSTEM elevation; and a new GPU Rowhammer technique (“GPUBreach”) on

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
a57291d79356b97648837b5cab5f18d93e511d17eae02d0266bbe86819a5a213
Enrichment time
2026-04-07T13:23:29Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.