Microsoft Takes Down Fox Tempest for Providing Ransomware-Enabling Signing Tool
2026-05-19T20:52:16Z•8bb5f174462ebd4cfbf883b5e8b77b6be759165f97c9e9144005cb6a40e3ffe5
agentic-aiai-powered-attacksavada-builderdigital-crimes-unitdirty-fragexchange-zero-dayfox-tempestfragnesiagrafanagremlin-stealerlaw-enforcementlinux-kernellocal-privilege-escalationpwn2ownransomwaresbomshinyhunterssource-code-theftsupply-chainwordpress
What happened
A wide range of high-impact cyber incidents and trends: Microsoft’s Digital Crimes Unit dismantled Fox Tempest — a group offering a signing tool that enabled ransomware — while Microsoft also disclosed a severe zero-day affecting on‑prem Exchange Server. Multiple large-scale breaches and thefts were reported (Grafana source‑code theft, Zara/Canvas data extortion by ShinyHunters), and critical vulnerabilities surfaced across Linux (Fragnesia LPE, “Dirty Frag” kernel issues) and widely used software (Avada Builder affecting ~1M WordPress sites). Malware families and campaigns evolved (Gremlinste
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- infosecurity_magazine
- Record identifier
- 8bb5f174462ebd4cfbf883b5e8b77b6be759165f97c9e9144005cb6a40e3ffe5
- Enrichment time
- 2026-05-19T20:52:16Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.