German authorities identify REvil and GandCrab ransomware bosses

2026-04-07T07:23:35Zf8003eb6f152c8fa6fe2284cf746263c6f36c7d49e8c23e2896b90b5f64a2635
AxiosBlueHammerCISACVE-2025-55182CVE-2026-35616FortiClient EMSFortinetGPUGPUBreachGandCrabMedusaOAuth device flow phishing kits`,`QR-phishing`REvilReact2ShellRowhammerStorm-1175Windows zero-dayactive exploitationcredential theftdevice-code-phishinginfostealerlaw-enforcementnpm supply-chainprivilege escalationransomware

What happened

This feed reports multiple high-impact security developments: German police identified two Russian nationals as leaders of the GandCrab and REvil ransomware operations; a new GPUBreach GPU Rowhammer attack can induce bit-flips in GDDR6 to escalate privileges and enable full system compromise; a disgruntled researcher publicly released exploit code for an unpatched Windows privilege-escalation zero-day (“BlueHammer”); Microsoft linked a China-based affiliate (Storm-1175) to n-day and zero-day Medusa ransomware attacks; and a $280M Drift Protocol theft was tied to a six-month in-person operation

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
f8003eb6f152c8fa6fe2284cf746263c6f36c7d49e8c23e2896b90b5f64a2635
Enrichment time
2026-04-07T07:23:35Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.