Reddit Massive Ransomware Attack Targets Critical Infrastructure in March 2026
Article Content
- •A ransomware attack using CVE-2026-0456 has affected over 500 organizations.
- •Critical infrastructure sectors, including energy and transportation, are heavily impacted.
- •The ransomware, named 'DarkSky', is linked to a state-sponsored group.
In March 2026, a sophisticated ransomware attack impacted multiple critical infrastructure sectors, including energy and transportation. The attack utilized a zero-day exploit, CVE-2026-0456, which allowed attackers to bypass security measures and encrypt sensitive data. Initial reports indicate that over 500 organizations were affected, with significant disruptions reported in power distribution and public transit systems. The ransomware, identified as 'DarkSky', is believed to be operated by a state-sponsored group. Emergency response teams have been deployed to mitigate the damage and restore services. As of now, the attack is ongoing, with ransom demands exceeding $10 million for decryption keys. Authorities are urging affected organizations to isolate impacted systems and refrain from paying the ransom. Investigations are underway to trace the origins of the attack and identify the perpetrators.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
Critical Citrix NetScaler Vulnerabilities Actively Exploited in Finland The National Cyber Security Centre Finland (NCSC-FI) issued an alert regarding critical vulnerabilities in Citrix NetScaler ADC and Gateway products, specifically CVE-2026-88771 and CVE-2026-88772, which are being actively exploited in Finland. These vulnerabilities allow attackers to execute remote code without…