WantToCry ransomware remotely encrypts files

2026-05-22T08:51:40Z5a1f5519e0a59aaf524984c4f4de27e04f9d3a717b6c757f36f19faf76a95556
AI riskAMOSGitHubMicrosoftPatch TuesdaySMBVS Code extensionWantToCryanti-exploitationbrute‑forceendpoint protectionidentity securityinfostealermacOSpatchingransomwaresupply chainsupply-chain-attackvulnerabilities

What happened

Multiple Sophos posts in May 2026 describe active threats and defensive guidance: a WantToCry ransomware campaign is remotely encrypting files after brute‑forcing SMB credentials; a malicious VS Code extension led to cloning of private GitHub repositories (reported for sale) indicating a targeted supply‑chain/IDE compromise; the AMOS (Atomic macOS Stealer) family is scaling macOS data‑theft operations; and Microsoft’s May Patch Tuesday disclosed 132 CVEs (with advisories pushing the month’s total toward ~300). Sophos also highlights successful blocking of a novel supply‑chain attack by Sophos

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sophos_news
Record identifier
5a1f5519e0a59aaf524984c4f4de27e04f9d3a717b6c757f36f19faf76a95556
Enrichment time
2026-05-22T08:51:40Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.