INTERPOL Operation Ramz Disrupts MENA Cybercrime Networks with 201 Arrests
2026-05-19T01:24:11Z•d3d11274a54c98e7b785041af24c4f047a1ad85eb53df8f99031fdcf0138fa0c
INTERPOLMENAactive_exploitationarrestscisco_sd-wancredential_theftfragnesiafunnel_builder_skimmingghostwritergrafana_token_breachivantimicrosoft_exchangeminiPlasmanginxnode-ipcnpm_malwareopenclawoperation_ramzpraisonaisupply_chainsupply_chain_attacktanstackturlawindows_zero-day
What happened
A large, multi-topic security roundup: INTERPOL's Operation Ramz disrupted MENA cybercrime networks with 201 arrests and 382 additional suspects identified. Numerous high- and critical-severity vulnerabilities were disclosed and actively exploited (notably Cisco Catalyst SD‑WAN auth bypass, NGINX heap overflow, Ivanti Xtraction critical flaw, and on‑prem Exchange spoofing), alongside public zero-days and privilege‑escalation bugs (MiniPlasma for Windows, Fragnesia Linux LPE). Multiple supply‑chain and credential incidents were reported — malicious npm packages and node-ipc backdoors, TanStack/
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- d3d11274a54c98e7b785041af24c4f047a1ad85eb53df8f99031fdcf0138fa0c
- Enrichment time
- 2026-05-19T01:24:11Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.