WantToCry ransomware remotely encrypts files
2026-05-21T20:51:34Z•4d67f007244645415b64cf6c52e84d3da6075c63f3459c9ceaea02db23cec939
AIAI agentsAMOSCVEEDRFirewallGitHub breachMicrosoftPatch TuesdaySMBSophos EndpointState of Identity SecuritySynchronized SecurityVS Code extensionWantToCryanti‑exploitationblast radiusbrute‑forceidentity securityinfostealermacOSransomwaresupply chain
What happened
Feed of Sophos research and blog posts (May 2026) highlighting multiple active threats and defensive guidance: WantToCry ransomware performing remote file encryption following brute‑force against SMB; a GitHub compromise where a malicious VS Code extension cloned private/internal repositories (supply‑chain/exposure of private code); AMOS (Atomic macOS Stealer) actively stealing data at scale; Microsoft May Patch Tuesday addressing 132 CVEs; a documented supply‑chain attack blocked by Sophos Endpoint anti‑exploitation; advice on reducing blast radius for AI agent deployments; and a 2026 StateOf
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sophos_news
- Record identifier
- 4d67f007244645415b64cf6c52e84d3da6075c63f3459c9ceaea02db23cec939
- Enrichment time
- 2026-05-21T20:51:34Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.