The Hidden Ransomware Economy Running on Exposed Databases

2026-05-26T20:51:47Z671a817879c001022e67d559185a6e1d1154fe1dc134399fd8ccdc17e0b6be53
AI-assisted-malwareAPTCVE-2026-26980ClickFixGhost-CMSLazarusNimbus ManticoreOnlyFans-leaks','hosting-takedown','disinformation','stark-indu‌WhatsAppcomposerdata-aggregationdatabase extortionexposed-databasesfake-installersfileless-ratgit-tag-poisoninghealthcare-breachiOS16malwarememory-resident-malwareransomwareseo-poisoningsupply-chainthird-party-breachzero-click

What happened

Multiple active threats and large-scale incidents were reported: a 5-year study found 30,515 exposed databases targeted by extortion-style ransomware operations; Laravel-Lang Composer packages were poisoned by attackers rewriting >700 Git tags to inject malware; Nimbus Manticore expanded wartime operations with AI-assisted malware, fake Zoom installers and SEO poisoning; Lazarus deployed a fileless, memory-only RAT to evade forensics; Ghost CMS sites (700+ victims) are being actively exploited via CVE-2026-26980 to push ClickFix malware; a zero-click WhatsApp iOS16 account-takeover campaign is

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
671a817879c001022e67d559185a6e1d1154fe1dc134399fd8ccdc17e0b6be53
Enrichment time
2026-05-26T20:51:47Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.