State of ransomware in 2026
2026-05-13T08:51:56Z•54f9c5600e77078794667911f4ef0f3839dd489fe8d0d914f99b0d8a112790ca
abcdooramazon-sesbeccrypto-stealercve-2025-68670data-leak-extortionedr-killerexploitsfakewalletics-report','aptindustrial-automationiosoceanlotusphantomrpcphishingprivilege-escalationpypiransomwarercesilver-foxsupply-chainvalleyratvulnerabilitiesxrdpzichatbot
What happened
Kaspersky Securelist RSS feed (May 2026) summarizing multiple research posts: ransomware trends for 2026 (rise of EDR-killers and shift from encryption to data leaks), discovery and patch of CVE-2025-68670 (pre-auth RCE in xrdp), Q1 2026 vulnerability/exploit statistics and C2 usage in APTs, OceanLotus PyPI supply‑chain campaign delivering ZiChatBot, phishing campaigns abusing Amazon SES (BEC), Silver Fox targeting Russia/India with ValleyRAT and new ABCDoor backdoor, PhantomRPC Windows RPC privilege escalation technique, FakeWallet iOS crypto-stealer apps in the App Store, and an industrial/
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- kaspersky_securelist
- Record identifier
- 54f9c5600e77078794667911f4ef0f3839dd489fe8d0d914f99b0d8a112790ca
- Enrichment time
- 2026-05-13T08:51:56Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.