Microsoft Takes Down Fox Tempest for Providing Ransomware-Enabling Signing Tool

2026-05-19T20:52:16Z8bb5f174462ebd4cfbf883b5e8b77b6be759165f97c9e9144005cb6a40e3ffe5
agentic-aiai-powered-attacksavada-builderdigital-crimes-unitdirty-fragexchange-zero-dayfox-tempestfragnesiagrafanagremlin-stealerlaw-enforcementlinux-kernellocal-privilege-escalationpwn2ownransomwaresbomshinyhunterssource-code-theftsupply-chainwordpress

What happened

A wide range of high-impact cyber incidents and trends: Microsoft’s Digital Crimes Unit dismantled Fox Tempest — a group offering a signing tool that enabled ransomware — while Microsoft also disclosed a severe zero-day affecting on‑prem Exchange Server. Multiple large-scale breaches and thefts were reported (Grafana source‑code theft, Zara/Canvas data extortion by ShinyHunters), and critical vulnerabilities surfaced across Linux (Fragnesia LPE, “Dirty Frag” kernel issues) and widely used software (Avada Builder affecting ~1M WordPress sites). Malware families and campaigns evolved (Gremlinste

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
infosecurity_magazine
Record identifier
8bb5f174462ebd4cfbf883b5e8b77b6be759165f97c9e9144005cb6a40e3ffe5
Enrichment time
2026-05-19T20:52:16Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.