First VPN Dismantled in Global Takedown Over Use by 25 Ransomware Groups

2026-05-23T07:24:10Zb089c88f74dbef6ca4f93c417aa54debd225ca2f63ae395d49b53156a977acde
CI/CD compromiseCISA KEVCiscoDefenderDirtyDecryptGitHubGrafanaKnown Exploited Vulnerabilities (KEV) list","Trend Micro","LangflLinux kernelMSaaSMegalodonMicrosoftNx ConsoleOperation SaffronSecure WorkloadTanStackVPN takedownmalicious workflowsmalware-signing-as-a-servicepoisoned extensionprivilege escalationransomwaresoftware supply chainsupply-chainvulnerability

What happened

A large set of active and high-impact cyber incidents and research was reported: law enforcement dismantled a criminal VPN (Operation Saffron) used by ~25 ransomware groups; multiple large-scale supply-chain and source-code compromises hit developer ecosystems (Megalodon malicious CI/CD commits to 5,561 GitHub repos, GitHub internal repo exfiltration via a poisoned Nx Console VS Code extension, Grafana breach via a TanStack npm compromise). Microsoft disrupted a malware‑signing‑as‑a‑service operation and warned of actively exploited Defender flaws; Cisco patched a CVSS 10.0 Secure Workload API

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
b089c88f74dbef6ca4f93c417aa54debd225ca2f63ae395d49b53156a977acde
Enrichment time
2026-05-23T07:24:10Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · First VPN Dismantled in Global Takedown Over Use by 25 Ransomware Groups · Baitaphish