INTERPOL Operation Ramz Disrupts MENA Cybercrime Networks with 201 Arrests

2026-05-19T01:24:11Zd3d11274a54c98e7b785041af24c4f047a1ad85eb53df8f99031fdcf0138fa0c
INTERPOLMENAactive_exploitationarrestscisco_sd-wancredential_theftfragnesiafunnel_builder_skimmingghostwritergrafana_token_breachivantimicrosoft_exchangeminiPlasmanginxnode-ipcnpm_malwareopenclawoperation_ramzpraisonaisupply_chainsupply_chain_attacktanstackturlawindows_zero-day

What happened

A large, multi-topic security roundup: INTERPOL's Operation Ramz disrupted MENA cybercrime networks with 201 arrests and 382 additional suspects identified. Numerous high- and critical-severity vulnerabilities were disclosed and actively exploited (notably Cisco Catalyst SD‑WAN auth bypass, NGINX heap overflow, Ivanti Xtraction critical flaw, and on‑prem Exchange spoofing), alongside public zero-days and privilege‑escalation bugs (MiniPlasma for Windows, Fragnesia Linux LPE). Multiple supply‑chain and credential incidents were reported — malicious npm packages and node-ipc backdoors, TanStack/

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
d3d11274a54c98e7b785041af24c4f047a1ad85eb53df8f99031fdcf0138fa0c
Enrichment time
2026-05-19T01:24:11Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.