Cybersecuritynews Apache ActiveMQ Vulnerability Exploited for LockBit Ransomware Attack
Article Content
Browse articles
Threat actors exploited a critical vulnerability (CVE-2023-46604) in Apache ActiveMQ, leading to a LockBit ransomware deployment across an enterprise network. The attackers gained access through an exposed Windows server using Remote Desktop Protocol, resulting in significant system encryption. Despite efforts to evict the intruders, the ransomware spread rapidly within the network.
Ask AI about this cluster
Answers cite the sources they use
Updated 210d ago How this analysis works
Timeline
2023-10-26
First public PoC for CVE-2023-46604 released
2023-10-27
CVE-2023-46604 published
2023-11-02
CVE-2023-46604 added to CISA KEV for active exploitation
2026-02-23
Threat actor exploited CVE-2023-46604 on ActiveMQ server
2026-02-25
LockBit ransomware deployment reported across enterprise network
More articles in this cluster (3)
Following this threat?
Track Lockbit and CVE-2023-46604 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
PAYLOAD Ransomware Exploits Active Directory GPO for Disruption In April 2026, Kaspersky's Global Emergency Response Team (GERT) responded to a ransomware incident at a manufacturing organization in the Middle East. Attackers gained domain-admin-equivalent control via a compromised FortiGate SSL VPN account and created a malicious Group Policy Object (GPO) named PAYLOAD. This GPO…
Russian Gang Targets US Law Firms with Extortion Tactics Leaked chats from the Silent Ransom Group, a Russia-based cyberextortion gang, reveal plans to infiltrate U.S. law firms, kidnap executives, and recruit military personnel for espionage. The chats, spanning from August 2025 to September 2026, detail negotiations with law firms, including demands for…