WantToCry ransomware remotely encrypts files

2026-05-21T20:51:34Z4d67f007244645415b64cf6c52e84d3da6075c63f3459c9ceaea02db23cec939
AIAI agentsAMOSCVEEDRFirewallGitHub breachMicrosoftPatch TuesdaySMBSophos EndpointState of Identity SecuritySynchronized SecurityVS Code extensionWantToCryanti‑exploitationblast radiusbrute‑forceidentity securityinfostealermacOSransomwaresupply chain

What happened

Feed of Sophos research and blog posts (May 2026) highlighting multiple active threats and defensive guidance: WantToCry ransomware performing remote file encryption following brute‑force against SMB; a GitHub compromise where a malicious VS Code extension cloned private/internal repositories (supply‑chain/exposure of private code); AMOS (Atomic macOS Stealer) actively stealing data at scale; Microsoft May Patch Tuesday addressing 132 CVEs; a documented supply‑chain attack blocked by Sophos Endpoint anti‑exploitation; advice on reducing blast radius for AI agent deployments; and a 2026 StateOf

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sophos_news
Record identifier
4d67f007244645415b64cf6c52e84d3da6075c63f3459c9ceaea02db23cec939
Enrichment time
2026-05-21T20:51:34Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · WantToCry ransomware remotely encrypts files · Baitaphish