The Hidden Ransomware Economy Running on Exposed Databases
2026-05-27T02:51:52Z•78910a8874a1d873ff78dca9749f66c64c816c0236afad561a51ca1df70ae4c4
APTai-assisted-malwareclickfixcomposerdata-breachdatabase-extortionexposed-databasesfake-installerfileless-ratghost-cmsgit-tag-poisoninghealthcareios16 compromise? (reported)lazarusmalwarememory-onlynimbus-manticorepackage-poisoningransomwareremote-access-trojanseo-poisoningsupply-chainthird-party-riskwhatsappzero-click
What happened
A mixed-security feed describing a range of active threats and incidents: a 5‑year study shows a large ransomware/ database‑extortion economy abusing 30,515 exposed databases; Laravel‑Lang Composer packages were poisoned via mass Git tag rewriting, delivering malware to downstream Laravel apps; Nimbus Manticore expanded wartime operations with AI‑assisted malware, fake Zoom installers and SEO poisoning; Lazarus is deploying a stealthy memory‑only (fileless) RAT to evade forensics; Ghost CMS sites remain widely unpatched and are being exploited in ClickFix campaigns (CVE‑2026‑26980) affecting 7
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- 78910a8874a1d873ff78dca9749f66c64c816c0236afad561a51ca1df70ae4c4
- Enrichment time
- 2026-05-27T02:51:52Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.