German authorities identify REvil and GandCrab ransomware bosses
2026-04-07T07:23:35Z•f8003eb6f152c8fa6fe2284cf746263c6f36c7d49e8c23e2896b90b5f64a2635
AxiosBlueHammerCISACVE-2025-55182CVE-2026-35616FortiClient EMSFortinetGPUGPUBreachGandCrabMedusaOAuth device flow phishing kits`,`QR-phishing`REvilReact2ShellRowhammerStorm-1175Windows zero-dayactive exploitationcredential theftdevice-code-phishinginfostealerlaw-enforcementnpm supply-chainprivilege escalationransomware
What happened
This feed reports multiple high-impact security developments: German police identified two Russian nationals as leaders of the GandCrab and REvil ransomware operations; a new GPUBreach GPU Rowhammer attack can induce bit-flips in GDDR6 to escalate privileges and enable full system compromise; a disgruntled researcher publicly released exploit code for an unpatched Windows privilege-escalation zero-day (“BlueHammer”); Microsoft linked a China-based affiliate (Storm-1175) to n-day and zero-day Medusa ransomware attacks; and a $280M Drift Protocol theft was tied to a six-month in-person operation
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- f8003eb6f152c8fa6fe2284cf746263c6f36c7d49e8c23e2896b90b5f64a2635
- Enrichment time
- 2026-04-07T07:23:35Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.