Mlex Massive Ransomware Attack Targets Critical Infrastructure in March 2026
Article Content
- •Over 50 organizations in critical infrastructure sectors were affected by the ransomware attack.
- •The attack exploited the zero-day vulnerability CVE-2026-0456 in industrial control systems.
- •Ransom demands exceed $10 million, with significant disruptions reported in energy and healthcare sectors.
In March 2026, a sophisticated ransomware attack impacted multiple critical infrastructure sectors across the United States, affecting at least 50 organizations. The attack utilized the 'DarkSide' ransomware variant, which is known for its double extortion tactics. Initial reports indicate that the attackers exploited a zero-day vulnerability in widely used industrial control systems, identified as CVE-2026-0456. The breach has led to the encryption of sensitive data and demands for ransom payments totaling over $10 million. Key sectors affected include energy, transportation, and healthcare, causing significant disruptions. The FBI has launched an investigation and issued an emergency advisory to organizations in these sectors. As of now, many affected organizations are still working to restore their systems and recover data. Security experts recommend immediate patching of the identified vulnerability and enhancing monitoring protocols.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (1)
Continue Reading
Critical Authentication Bypass in Rejetto HFS Exploited Within 24 Hours Anthropic's Mythos model identified a critical authentication bypass in Rejetto HTTP File Server (HFS), tracked as CVE-2026-61500, allowing remote code execution. Discovered by Horizon3 researcher Zach Hanley, the flaw was revealed on September 27, 2026, and exploitation began within 24 hours, with attacks traced to…
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited In late September 2026, two critical zero-day vulnerabilities (CVE-2026-88771 and CVE-2026-88772) in Citrix NetScaler ADC and Gateway were actively exploited, allowing remote code execution. The Cybersecurity and Infrastructure Security Agency (CISA) added these CVEs to its Known Exploited Vulnerabilities catalog on…