CRITICAL SECTION
- [11] Adobe Patches 7 CVSS 10.0 Flaws in ColdFusion and Campaign Classic (TheHackerNews)
Adobe has released patches for multiple maximum-severity security flaws impacting Adobe ColdFusion and Adobe Campaign Classic.The ColdFusion updates “resolves critical and important vulnerabilities that could lead to arbitrary code execution, privilege escalation, arbitrary file system read, and s…
CISA KEV (Known Exploited Vulnerabilities)
| CVE | Vendor/Product | Score | Required Action |
|---|---|---|---|
| CVE-2026-45659 | Vendor/Product: see source | 6 | Microsoft SharePoint Server Deserialization of Untrusted Data Vulnerability – Microsoft SharePoint Server. Required action: Apply mitigations in accordance with vendor instructions, ensuring complianc |
RANSOMWARE VICTIMS (DLS Monitoring)
No new ransomware victims reported today.
NEWS SECTION
- [9] [RANSOMWARE] shinyhunters leaked Fluke Corporation
Victim: Fluke Corporation | Group: shinyhunters | Country: US | Details: Over 21 million Salesforce records containing some PII were compromised. The Company failed to reach an agreement with us despite our incredible patience, all the chances and of… - [8] Progress Kemp LoadMaster Pre-Auth RCE Flaw Faces Active Exploitation Attempts
A recently disclosed critical security flaw impacting Progress Kemp LoadMaster is seeing active exploitation attempts, according to an advisory from eSentire’s Threat Response Unit (TRU).The Canadian cybersecurity company said it identified exploit…
- [7] Adobe Patches Critical ColdFusion, Campaign Classic Vulnerabilities
<p>Seven of the security defects have a maximum severity rating of 10/10 and could lead to arbitrary code execution.</p>
<p>The post <a href=”https://www.securityweek.com/adobe-patches-critical-coldfusion-campaign-classic-vulnera… - [7] [RANSOMWARE] thegentlemen leaked International Freight Services
Victim: International Freight Services | Group: thegentlemen | Website: ifs-sfo.com | Country: US | Details: ***.com zoominfo.com/c/ifs-sfocom/348198952 IFS (International Freight Services, Inc.) is a logistics company headquartered at San Francisco … - [7] [RANSOMWARE] thegentlemen leaked CHIFENG GOLD SEPON
Victim: CHIFENG GOLD SEPON | Group: thegentlemen | Website: lxml.la | Country: LA | Details: ***.la zoominfo.com/c/lane-xang-minerals-ltd/1311794256 which operates the major Sepon open-pit and underground gold and copper mine in Savannakhet Province,… - [7] [RANSOMWARE] thegentlemen leaked Au Vieux Campeur
Victim: Au Vieux Campeur | Group: thegentlemen | Website: auvieuxcampeur.fr | Country: FR | Details: ***.fr Au Vieux Campeur is a premier French retailer and the leading independent outdoor and sports equipment company in Europe.Founded in Paris in 1… - [6] [CISA KEV] CVE-2026-45659: Microsoft SharePoint Server Deserialization of Untrusted Data Vulnerability – Microsoft SharePoint Server
Microsoft SharePoint Server Deserialization of Untrusted Data Vulnerability – Microsoft SharePoint Server. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Upda… - [6] [RANSOMWARE] thegentlemen leaked Meccanica Gn
Victim: Meccanica Gn | Group: thegentlemen | Website: meccanicagn.com | Country: IT | Details: ***.com zoominfo.com/c/meccanica-gn/368731563 Meccanica GN is an Italian precision manufacturing company based in Carpi, specializing in high-accuracy mach… - [5] Over 900 Oracle E-Business instances exposed to ongoing attacks
Over 900 Oracle E-Business Suite (EBS) instances have been found exposed online amid ongoing attacks exploiting a critical security flaw. […]… - [5] Critical Cursor Flaws Could Let Prompt Injection Escape Sandbox and Run Commands
Two flaws in Cursor, an AI code editor, could let a single, ordinary-looking prompt break out of the editor’s safety sandbox and run any command on a developer’s computer. There is no click to fall for and no approval box to ignore.Cato AI Labs&…
- [5] [RANSOMWARE] incransom leaked Colorado Rehabilitation and Occupational Medicine
Victim: Colorado Rehabilitation and Occupational Medicine | Group: incransom | Country: US | Details: Colorado Rehabilitation & Occupational Medicine (CROM) is a leading Denver-area physiatry practice specializing in non-surgical treatments for m… - [5] [RANSOMWARE] medusalocker leaked Estrela
Victim: Estrela | Group: medusalocker | Website: estrela.ind | Country: BR | Details: Organization with 11 emails extracted. Domain: estrela.ind… - [5] [RANSOMWARE] medusalocker leaked Karneslegal
Victim: Karneslegal | Group: medusalocker | Website: karneslegal.com | Details: Organization with 23 emails extracted. Domain: karneslegal.com… - [5] [RANSOMWARE] medusalocker leaked Sgs Gmbh
Victim: Sgs Gmbh | Group: medusalocker | Website: sgs-gmbh.com | Country: DE | Details: Organization with 933 emails extracted. Domain: sgs-gmbh.com… - [5] [RANSOMWARE] medusalocker leaked Dadolighting
Victim: Dadolighting | Group: medusalocker | Website: dadolighting.com | Details: Organization with 17 emails extracted. Domain: dadolighting.com… - [5] [RANSOMWARE] medusalocker leaked T Online
Victim: T Online | Group: medusalocker | Website: t-online.de | Country: DE | Details: Organization with 823 emails extracted. Domain: t-online.de… - [5] [RANSOMWARE] medusalocker leaked FunkeScheid
Victim: FunkeScheid | Group: medusalocker | Website: FunkeScheid.com | Country: DE | Details: Notarkanzlei FunkeScheid, Kanzlei im Ostend, Frankfurt. 9755 emails. AD: Kanzlei.FunkeScheid.com… - [5] [RANSOMWARE] medusalocker leaked Mairie Thiverval Grignon
Victim: Mairie Thiverval Grignon | Group: medusalocker | Website: mairie-thiverval-grignon.fr | Country: FR | Details: Organization with 162 emails extracted. Domain: mairie-thiverval-grignon.fr… - [5] [RANSOMWARE] medusalocker leaked Dolrad
Victim: Dolrad | Group: medusalocker | Website: dolrad.ae | Country: AE | Details: Organization with 69 emails extracted. Domain: dolrad.ae… - [5] [RANSOMWARE] medusalocker leaked Bd
Victim: Bd | Group: medusalocker | Website: bd.zh.ch | Country: CH | Details: Organization with 772 emails extracted. Domain: bd.zh.ch…
SUMMARY
Total new items: 117. Critical count: 1. Ransomware groups active: 12. Top CVEs to patch urgently: CVE-2026-8037, CVE-2026-45659, CVE-2026-50548, CVE-2026-50549, CVE-2026-8451.
Sources: BleepingComputer, TheHackerNews, SecurityWeek, HelpNetSecurity, KrebsOnSecurity, CISA KEV, ransomware.live
Companion HTML report: Download report (HTML)
Leave a Reply