First VPN Dismantled in Global Takedown Over Use by 25 Ransomware Groups
2026-05-23T07:24:10Z•b089c88f74dbef6ca4f93c417aa54debd225ca2f63ae395d49b53156a977acde
CI/CD compromiseCISA KEVCiscoDefenderDirtyDecryptGitHubGrafanaKnown Exploited Vulnerabilities (KEV) list","Trend Micro","LangflLinux kernelMSaaSMegalodonMicrosoftNx ConsoleOperation SaffronSecure WorkloadTanStackVPN takedownmalicious workflowsmalware-signing-as-a-servicepoisoned extensionprivilege escalationransomwaresoftware supply chainsupply-chainvulnerability
What happened
A large set of active and high-impact cyber incidents and research was reported: law enforcement dismantled a criminal VPN (Operation Saffron) used by ~25 ransomware groups; multiple large-scale supply-chain and source-code compromises hit developer ecosystems (Megalodon malicious CI/CD commits to 5,561 GitHub repos, GitHub internal repo exfiltration via a poisoned Nx Console VS Code extension, Grafana breach via a TanStack npm compromise). Microsoft disrupted a malware‑signing‑as‑a‑service operation and warned of actively exploited Defender flaws; Cisco patched a CVSS 10.0 Secure Workload API
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- b089c88f74dbef6ca4f93c417aa54debd225ca2f63ae395d49b53156a977acde
- Enrichment time
- 2026-05-23T07:24:10Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.