The Hidden Ransomware Economy Running on Exposed Databases

2026-05-27T02:51:52Z78910a8874a1d873ff78dca9749f66c64c816c0236afad561a51ca1df70ae4c4
APTai-assisted-malwareclickfixcomposerdata-breachdatabase-extortionexposed-databasesfake-installerfileless-ratghost-cmsgit-tag-poisoninghealthcareios16 compromise? (reported)lazarusmalwarememory-onlynimbus-manticorepackage-poisoningransomwareremote-access-trojanseo-poisoningsupply-chainthird-party-riskwhatsappzero-click

What happened

A mixed-security feed describing a range of active threats and incidents: a 5‑year study shows a large ransomware/ database‑extortion economy abusing 30,515 exposed databases; Laravel‑Lang Composer packages were poisoned via mass Git tag rewriting, delivering malware to downstream Laravel apps; Nimbus Manticore expanded wartime operations with AI‑assisted malware, fake Zoom installers and SEO poisoning; Lazarus is deploying a stealthy memory‑only (fileless) RAT to evade forensics; Ghost CMS sites remain widely unpatched and are being exploited in ClickFix campaigns (CVE‑2026‑26980) affecting 7

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
78910a8874a1d873ff78dca9749f66c64c816c0236afad561a51ca1df70ae4c4
Enrichment time
2026-05-27T02:51:52Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.