Ransomware Operators Keep Business Hours. The Data Proves It
2026-06-01T20:51:46Z•a381928318332eecac808cc384c5e63eea618c5ef8650d75e55f2f8748d300ed
authentication-bypasscifswitchclickfixdata-leakghost-cmsglobalprotectknown-exploited-vulnerabilitylazaruslinux-local-privilege-escalationlocation-data-surveillancepalo-altopan-osransomware-activity-patternsshinyhunterssignal-phishingsupply-chain-malwaretrapdoorwordpresswp-maps-pro
What happened
This batch highlights multiple high-risk incidents and research: CVE-2026-8732 in the WP Maps Pro WordPress plugin allows unauthenticated creation of admin accounts (over 15k installs; 2,858 attacks blocked in 24 hours). Palo Alto PAN-OS CVE-2026-0257 (CVSS 7.8) was added to CISA’s KEV after Rapid7 observed active exploitation via forged GlobalProtect cookies. A 19‑year‑old Linux logic bug dubbed CIFSwitch can be abused to escalate to root across several distributions. Other notable items: analysis of 16,699 ransomware leak posts shows operators largely follow European business hours with Oct.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- a381928318332eecac808cc384c5e63eea618c5ef8650d75e55f2f8748d300ed
- Enrichment time
- 2026-06-01T20:51:46Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.