The Hidden Ransomware Economy Running on Exposed Databases
2026-05-26T20:51:47Z•671a817879c001022e67d559185a6e1d1154fe1dc134399fd8ccdc17e0b6be53
AI-assisted-malwareAPTCVE-2026-26980ClickFixGhost-CMSLazarusNimbus ManticoreOnlyFans-leaks','hosting-takedown','disinformation','stark-induWhatsAppcomposerdata-aggregationdatabase extortionexposed-databasesfake-installersfileless-ratgit-tag-poisoninghealthcare-breachiOS16malwarememory-resident-malwareransomwareseo-poisoningsupply-chainthird-party-breachzero-click
What happened
Multiple active threats and large-scale incidents were reported: a 5-year study found 30,515 exposed databases targeted by extortion-style ransomware operations; Laravel-Lang Composer packages were poisoned by attackers rewriting >700 Git tags to inject malware; Nimbus Manticore expanded wartime operations with AI-assisted malware, fake Zoom installers and SEO poisoning; Lazarus deployed a fileless, memory-only RAT to evade forensics; Ghost CMS sites (700+ victims) are being actively exploited via CVE-2026-26980 to push ClickFix malware; a zero-click WhatsApp iOS16 account-takeover campaign is
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- 671a817879c001022e67d559185a6e1d1154fe1dc134399fd8ccdc17e0b6be53
- Enrichment time
- 2026-05-26T20:51:47Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.