Feuding Ransomware Groups Leak Each Other's Data

2026-04-28T20:52:06Z0f5371e6aeec6f5025c5166e06dd3afb739eb75285ed2e7a6d765a5b36ec27c8
AI-phishingAWS S3Bomgar RMMCVE-2026-1731Chinese APTClickFixGlassWormLazarusMicrosoft TeamsPhantomRPCSnow malwareUNC6692VS Code extensionsVidarWindowsWindows Defender exploitsantigravity (agentic AI)botnetscloud-abuseinfostealermacOSprivilege-escalationransomwareremote-code-executionsupply-chain

What happened

A batch of DarkReading reports highlights a spike in active, diverse threats: ransomware groups leaking operational data; Vidar emerging at the top of the infostealer market; a large supply-chain campaign (GlassWorm) seeding malicious VS Code/Open VSX extensions; cloud-enabled campaigns (UNC6692) abusing Microsoft Teams, AWS S3 and custom malware; and multiple serious vulnerabilities being exploited in the wild (including critical RCE in Bomgar RMM). Other notable items: an unpatched Windows 'PhantomRPC' architectural privilege‑escalation issue, proof‑of‑concept exploits against Windows Defend

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
darkreading
Record identifier
0f5371e6aeec6f5025c5166e06dd3afb739eb75285ed2e7a6d765a5b36ec27c8
Enrichment time
2026-04-28T20:52:06Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.