WantToCry ransomware remotely encrypts files
2026-05-27T20:51:36Z•ed30b7c4efeaca866096b82b4ad665e4ad03d989fd096b4ca0348b78972785e8
AIAMOSGPT-5.5GitHubMicrosoftPatch TuesdaySMBVS Code extensionWantToCryendpoint securityinfostealermacOSransomwaresupply-chainsupply-chain attack
What happened
Sophos blog feed (May 11–20, 2026) highlights multiple active threats and defensive guidance: WantToCry ransomware conducting remote encryption after SMB brute-force attempts; a malicious VS Code extension that led to cloning/exfiltration of private GitHub repositories (supply-chain/IDE-extension risk); AMOS (Atomic macOS Stealer) described as a large-scale macOS infostealer; May Patch Tuesday addressing ~132 CVEs (advisories push the monthly total toward ~300); and AI-related guidance including blast-radius reduction for agent deployments and use of GPT-5.5-Cyber by defenders. The feed does’t
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sophos_news
- Record identifier
- ed30b7c4efeaca866096b82b4ad665e4ad03d989fd096b4ca0348b78972785e8
- Enrichment time
- 2026-05-27T20:51:36Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.