BKA unmasks two REvil Ransomware operators behind 130+ German attacks

2026-04-06T14:51:54Z8d6072ef49ac1a31515896e71792462361ddf751809a6c0bfc34e5af4932a0c8
DriftEuropean-Commission-breachF5 BIG-IPFortiClient EMSFortinetNorth KoreaQilinRCEREvilTeamPCPTrueConfactive-exploitationcryptocurrency-heistknown-exploited-vulnerabilitiesmacOS-infostealernpm-supply-chainransomwaresupply-chain

What happened

Multiple high-impact incidents and active exploits reported: German BKA identified two alleged REvil operators linked to 130+ attacks; attackers are actively exploiting a critical F5 BIG‑IP APM RCE (CVE-2025-53521) with ~14,000 instances exposed; Fortinet issued emergency patches for an actively exploited FortiClient EMS flaw (CVE-2026-35616). CISA added TrueConf Client vulnerability CVE-2026-3502 to its KEV catalog. Other notable events include CERT-EU linking a European Commission cloud breach to TeamPCP (data from ~30 EU entities exposed), Qilin claiming a hit on German party Die Linke, a $

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
8d6072ef49ac1a31515896e71792462361ddf751809a6c0bfc34e5af4932a0c8
Enrichment time
2026-04-06T14:51:54Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.