Skip to content
October 1, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Free Tools
    • CVSS 3.1 Calculator
    • Certificate Viewer
    • DNS Lookup
    • Encoder & Hash Generator
    • IP / Subnet Calculator
    • Whois Lookup
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
  • Home
  • Technique
  • Ransomware Cipher Crime: Encryption Used Maliciously
  • Technique

Ransomware Cipher Crime: Encryption Used Maliciously

Do Son November 8, 2021 4 minutes read
Img_2021_11_03_21_05_40

Credit: mantejmo via Canva

Credit: gregorly via Canva

Ransomware from Several Perspectives

Ransomware has many facets and angles to explore. Let’s explore it from a general, technical, personal and monetary perspective. Then let’s perhaps dive into how some of these different angles interrelate.

Generally Speaking

Ransomware is a malicious application that renders user or business data inaccessible with the ultimate goal of receiving ransom payments from its unsuspecting cyber victims.

Encryption in History

Encryption was used 2000 years ago by the Romans on the battlefield used an encryption algorithm called substitution cipher developed by Caesar. Caesar needed a way to send documents to his troops in remote locations while ensuring only its intended recipients would be able to understand the text.

Digital encryption has been in existence for several decades, going back to the 1970s. At that time, IBM started protecting their customers’ data using encryption.

Encryption used for Cybercrime

Cybercriminals are just using something that is generally a valid solution to protect the privacy and sensitivity of digital information and turn it into a tool to commit a malicious cybercrime/cyber theft.

Root Cause: Complacency

We could safely assume that most ransomware victims did not use anti ransomware or other cybersecurity-related products such as antivirus and malware protection solutions. Once a ransomware attack occurs, many cyber victims have no other choice but to give in and pay ransom to regain access to their data.

Cyber ransomware will typically encrypt personal and enterprise-grade data. Once the encryption is complete and verified, a ransom for that data depends on the value deemed. A high-pressure ultimatum often comes attached with the ransom request.

In the next section, we will take a deeper dive into the technical side of encryption which is at the core of a ransomware attack. Cryptocurrencies have made it even easier for cyber gangs to remain elusive and evade the law. Crypto ransom has made it much more challenging and often near impossible to track by law enforcement.

Technically Speaking

Encryption, which is at the heart of a ransomware cyberattack, is a process of encoding data into a series of letters, numbers and other characters, which essentially renders a coherent piece of data into gibberish.

Data at Rest and Data in Transit

Encryption protects sensitive documents by organizations and regular end-users, and it falls under two different categories, data at rest and data in transit. Data at rest could be data in a hard drive, and data in transit is any data that travels over digital communication channels, such as a peer-to-peer chat. 

Another example of data at rest encryption is when a password is on a Microsoft Word document. What happens is that the file becomes scrambled with indiscernible ciphertext or a series of random characters. 

Essentially the password, in this case, is the key that can unlock the data. Encryption can take place for a much larger batch of data, including encrypting an entire physical hard drive at the hardware level.

This process converts the original representation of the information, known as plaintext, into an alternative form known as ciphertext. Ideally, only authorized parties can decipher a ciphertext back to plaintext and access the original information.

Encryption Protocols and Keys

Encryption protocols use encryption algorithms to scramble the text into set-sized blocks, which can be 56 bits, 128 bits and more in size. These algorithms used advanced mathematical functions to perform their operations and then create a key. The same key is generally needed to decrypt the data with a symmetric encryption protocol, and Asymmetrical protocols require public and private keys.

Some of the most popular encryption protocols are DES and AES, which stand for Data Encryption Standard and Advanced Encryption Standard.

Credit: mantejmo via Canva

The Key is in the Key Size

Theoretically, a brute force attack could guess a given algorithm key by guessing all of its possible respective keys. This is why the key length of a given encryption algorithm makes a massive difference.

For example, a 56 bit DES cipher encryption algorithm could be hacked in 1 hour with a supercomputer, and 128 bit AES cipher encryption algorithm could take 5.3 x 1017, which is 5.3 times almost a QUINTILION YEARS or 5.3 x 100000000000000000 YEARS for a supercomputer to hack. This is not even close to other bigger key lengths out there. 

Imagine how much time it would take for an organization to guess the key to deciphering their data. Actually, don’t bother, it is UNIMAGINABLE.

Monetarily Speaking

In 2020, an estimated $18 billion was paid out as a result of ransomware cyber-attacks by businesses and home users, and this number is expected to grow.

SHARE
Share on FacebookShare on XShare on LinkedInShare on TelegramShare on BlueskyShare on Mastodon

Search

Translation

CVE ALERTS
📈

EPSS Spike Alerts
Catch risk spikes before they make headlines.

🎯

Custom EPSS/CVSS
Set score thresholds to effectively filter noise.

🛡️

Exploit Intel
Real-world exploit signals beyond the KEV catalog.

🐙

GitHub Issues
Auto-create alert tickets without duplication.

📬

Weekly Digest
Clean summaries, eliminating email spam.

🏷️

Watchlist Groups
Tag vulnerabilities by team (Infra/AppSec/SOC).

🔀

Smart Routing
Route chat channels based on severity levels.

🚨

RBP Tracker
Early warning detection and tracking system.

Subscribe – $7/mo or try free for 14 days →

🚨 Active Exploits in the Wild

  • CVE-2026-100382CVSS 10.0
    Improper Neutralization of Special Elements used in an OS Command (\'OS Command Injection\') vulnerability in Wikimedia Foundation Mediawiki...
    Admin intel📅 Updated: Oct 1, 2026
  • CVE-2026-76504CVSS 9.8
    A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote...
    Admin intelCISA KEV📅 Added to KEV: Sep 30, 2026📅 Updated: Sep 30, 2026
  • CVE-2026-86950CVSS 8.8
    An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and...
    Admin intelCISA KEV📅 Added to KEV: Sep 29, 2026📅 Updated: Sep 29, 2026
  • CVE-2026-88772
    Memory overflow vulnerability leading to remote code execution or denial of service.
    Admin intelCISA KEV📅 Added to KEV: Sep 27, 2026📅 Updated: Sep 27, 2026
  • CVE-2026-88771
    Remote code execution due to improper input validation that can allow an unauthenticated attacker to execute arbitrary commands.
    Admin intelCISA KEV📅 Added to KEV: Sep 27, 2026📅 Updated: Sep 27, 2026
  • CVE-2026-65660CVSS 8.8
    Improper control of generation of code (\'code injection\') in Microsoft Office SharePoint allows an authorized attacker to execute...
    Admin intelCISA KEV📅 Added to KEV: Sep 25, 2026📅 Updated: Sep 25, 2026
  • CVE-2026-5430CVSS 10.0
    The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows...
    CISA KEV📅 Added to KEV: Sep 24, 2026
  • CVE-2026-71362CVSS 9.1
    Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could...
    CISA KEV📅 Added to KEV: Sep 24, 2026
Powered by CVE Watchtower

Critical Vulnerabilities

  • CVE-2026-75957CVSS 9.8
    The Ultimate Multisite – WordPress Multisite SaaS & WaaS Platform plugin for WordPress is vulnerable to Authentication Bypass...
    📅 Updated: Oct 1, 2026
  • CVE-2026-15989CVSS 9.8
    The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Privilege Escalation in...
    📅 Updated: Oct 1, 2026
  • CVE-2026-92966CVSS 9.1
    The The Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress plugin for WordPress is vulnerable...
    📅 Updated: Oct 1, 2026
  • CVE-2026-101148CVSS 10.0
    The BackupSheep WordPress Backup Plugin WordPress plugin through 1.8 does not properly validate its integration key, treating an...
    📅 Updated: Oct 1, 2026
  • CVE-2026-62329CVSS 9.8
    Vulnerability Type: CWE-1392: Use of Default Credentials Attack type: Unauthenticated remote Impact: Unauthenticated users can access the default...
    📅 Updated: Oct 1, 2026
  • CVE-2026-103264CVSS 9.3
    Fleet versions before 4.87.0 contain an authentication bypass vulnerability in the device API that accepts hostnames and hardware...
    📅 Updated: Oct 1, 2026
  • CVE-2026-103244CVSS 9.3
    ground-station versions before 0.8.0 contain an authentication bypass vulnerability in the setup.restore command that allows unauthenticated attackers to...
    📅 Updated: Oct 1, 2026
  • CVE-2026-57496CVSS 9.6
    ## REST Path Traversal Bypasses Token Redaction in netlicensing-mcp ### Summary The `netlicensing_get_product` MCP tool in `netlicensing-mcp` interpolates...
    📅 Updated: Oct 1, 2026
Powered by CVE Watchtower

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.