Cyberpress Cephalus Ransomware Targets Windows via Exposed RDP in Double-Extortion Scheme
Article Content
Browse articles
Cephalus ransomware has been actively exploiting exposed Remote Desktop Protocol (RDP) vulnerabilities since mid-2025, primarily targeting Windows systems. The attacks utilize a double-extortion tactic, where victims are not only encrypted but also threatened with data leaks unless a ransom is paid.
Ask AI about this cluster
Answers cite the sources they use
Updated 203d ago How this analysis works
Timeline
2025-06-15
Cephalus ransomware first identified in attacks
2025-07-20
Double-extortion tactics reported
2026-02-11
Latest report on Cephalus ransomware published
More articles in this cluster (1)
Following this threat?
Track Cephalus in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Citrix NetScaler Critical Vulnerabilities Exploited: Urgent Patching Required Citrix NetScaler ADC and Gateway products are affected by critical vulnerabilities CVE-2026-88771 and CVE-2026-88772, both assigned a CVSS score of 9.5. The Cybersecurity and Infrastructure Security Agency (CISA) added these CVEs to its Known Exploited Vulnerabilities catalog on September 27, 2026, and mandated…
Critical Zero-Day Exploits Target F5 and Check Point Products F5 Networks released emergency hotfixes for a critical zero-day vulnerability, CVE-2026-94127, in its BIG-IP Access Policy Manager on September 22, 2026, after confirming active exploitation. This flaw allows unauthenticated remote code execution (RCE) and has a CVSS score of 9.8. Concurrently, Check Point disclosed…