Punchng Massive Ransomware Attack Targets Critical Infrastructure in March 2026
Article Content
- •Over 500 organizations affected by the ransomware attack targeting critical infrastructure.
- •Attack exploited CVE-2025-6789, allowing unauthorized access to systems.
- •Ransomware 'DarkLock' demands payment in cryptocurrency for file decryption.
In March 2026, a sophisticated ransomware attack impacted multiple sectors, primarily targeting critical infrastructure organizations across the United States. The attack exploited vulnerabilities in several widely-used software systems, including CVE-2025-6789, which allowed attackers to gain unauthorized access. Initial reports indicate that over 500 organizations were affected, leading to significant operational disruptions and data breaches. The ransomware, identified as 'DarkLock', encrypts files and demands a ransom in cryptocurrency. The attack is believed to be state-sponsored, with links to a known cybercriminal group operating from a foreign nation. As of now, emergency response teams are working to mitigate the damage and restore affected systems. Authorities have issued advisories for organizations to strengthen their cybersecurity measures and monitor for suspicious activity. Law enforcement agencies are investigating the incident, and a patch for the exploited vulnerability is expected to be released shortly.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Solar Spider in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
CISA Mandates Urgent Patching of Five Critical Flaws Exploited by Flax Typhoon The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch five critical vulnerabilities by October 11, 2026, following exploitation by the China-linked hacking group Flax Typhoon. The vulnerabilities, added to CISA's Known Exploited Vulnerabilities (KEV) catalog, include…