German authorities identify REvil and GandCrab ransomware bosses
2026-04-07T13:23:29Z•a57291d79356b97648837b5cab5f18d93e511d17eae02d0266bbe86819a5a213
AxiosBlueHammerCISADrift ProtocolFortiClient EMSFortinetGPU RowhammerGPUBreachGandCrabLinkedIn BrowserGateMedusaQR phishingREvilReact2Shellactive exploitationcredential theftcrypto-theftdevice-code-phishingemergency patchnpm compromiseransomwaresupply-chainzero-day
What happened
Multiple high-impact security stories: German BKA identified two Russian nationals as leaders of GandCrab and REvil ransomware operations (2019–2021). Active and emergent exploitation observed — Fortinet FortiClient EMS vulnerability (CVE-2026-35616) is being actively exploited, prompting emergency patches and a CISA order for federal remediation; React2Shell (CVE-2025-55182) is being abused in large-scale automated credential-theft campaigns; a leaked unpatched Windows privilege-escalation exploit dubbed “BlueHammer” enables SYSTEM elevation; and a new GPU Rowhammer technique (“GPUBreach”) on
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- a57291d79356b97648837b5cab5f18d93e511d17eae02d0266bbe86819a5a213
- Enrichment time
- 2026-04-07T13:23:29Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.