Ransomware Operators Keep Business Hours. The Data Proves It

2026-06-01T20:51:46Za381928318332eecac808cc384c5e63eea618c5ef8650d75e55f2f8748d300ed
authentication-bypasscifswitchclickfixdata-leakghost-cmsglobalprotectknown-exploited-vulnerabilitylazaruslinux-local-privilege-escalationlocation-data-surveillancepalo-altopan-osransomware-activity-patternsshinyhunterssignal-phishingsupply-chain-malwaretrapdoorwordpresswp-maps-pro

What happened

This batch highlights multiple high-risk incidents and research: CVE-2026-8732 in the WP Maps Pro WordPress plugin allows unauthenticated creation of admin accounts (over 15k installs; 2,858 attacks blocked in 24 hours). Palo Alto PAN-OS CVE-2026-0257 (CVSS 7.8) was added to CISA’s KEV after Rapid7 observed active exploitation via forged GlobalProtect cookies. A 19‑year‑old Linux logic bug dubbed CIFSwitch can be abused to escalate to root across several distributions. Other notable items: analysis of 16,699 ransomware leak posts shows operators largely follow European business hours with Oct.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
a381928318332eecac808cc384c5e63eea618c5ef8650d75e55f2f8748d300ed
Enrichment time
2026-06-01T20:51:46Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.