WantToCry ransomware remotely encrypts files
2026-05-22T08:51:40Z•5a1f5519e0a59aaf524984c4f4de27e04f9d3a717b6c757f36f19faf76a95556
AI riskAMOSGitHubMicrosoftPatch TuesdaySMBVS Code extensionWantToCryanti-exploitationbrute‑forceendpoint protectionidentity securityinfostealermacOSpatchingransomwaresupply chainsupply-chain-attackvulnerabilities
What happened
Multiple Sophos posts in May 2026 describe active threats and defensive guidance: a WantToCry ransomware campaign is remotely encrypting files after brute‑forcing SMB credentials; a malicious VS Code extension led to cloning of private GitHub repositories (reported for sale) indicating a targeted supply‑chain/IDE compromise; the AMOS (Atomic macOS Stealer) family is scaling macOS data‑theft operations; and Microsoft’s May Patch Tuesday disclosed 132 CVEs (with advisories pushing the month’s total toward ~300). Sophos also highlights successful blocking of a novel supply‑chain attack by Sophos
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sophos_news
- Record identifier
- 5a1f5519e0a59aaf524984c4f4de27e04f9d3a717b6c757f36f19faf76a95556
- Enrichment time
- 2026-05-22T08:51:40Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.