Cybersecurity Intelligence Report — 16 July 2026
CRITICAL SECTION
-
[12] CISA Urges Immediate Patching of Exploited SharePoint Vulnerabilities (SecurityWeek)
<p>Three vulnerabilities are actively exploited in attacks, including two that have been targeted as zero-days.</p>
<p>The post <a href=”https://www.securityweek.com/cisa-urges-immediate-patching-of-exploited-sharepoint-vulnerabilities/”>CISA Urges Immediate Patching of Exploited SharePoint Vulnerabilities</a> appeared first on <a href=”https://www.securityweek.com”>SecurityWeek</a>.</p>
CISA KEV (last 14 days)
No KEV items in the last 14 days.
RANSOMWARE VICTIMS (DLS Monitoring)
No new ransomware victims recorded today.
NEWS
-
[9] Google Gemini CLI abused as a hacking agent, malware botnet operator (BleepingComputer)
A Russian-speaking threat actor known as “bandcampro” used Google’s open-source Gemini CLI AI tool as a hacking agent and to operate a small-scale botnet. […]
-
[9] Researcher Drops New Windows Zero-Day PoC Hours After Microsoft Patch Tuesday (TheHackerNews)
Security researcher Chaotic Eclipse (aka Nightmare-Eclipse) has released a new proof-of-concept (PoC) exploit called LegacyHive.
It has been described as a Windows User Profile Service arbitrary hive load elevation of privileges vulnerability. The Windows User Profile Service, also referred to as ProfSvc, is a core system component that manages user accounts and environments.
“The PoC requires
-
[9] Critical Vulnerabilities Patched With Fresh Chrome 150, Firefox 152 Updates (SecurityWeek)
<p>Public exploit code targeting the Firefox flaws exists, but no in-the-wild exploitation has been observed.</p>
<p>The post <a href=”https://www.securityweek.com/critical-vulnerabilities-patched-with-fresh-chrome-150-firefox-152-updates/”>Critical Vulnerabilities Patched With Fresh Chrome 150, Firefox 152 Updates</a> appeared first on <a href=”https://www.securityweek.com”>SecurityWeek</a>.</p> -
[8] CISA warns admins to patch actively exploited SharePoint flaws (BleepingComputer)
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned Tuesday that attackers are actively exploiting three vulnerabilities to hack Internet-exposed on-premises SharePoint Server instances. […]
-
[7] Two SonicWall SMA 1000 Zero-Days Exploited, One Could Enable Admin Commands (TheHackerNews)
SonicWall has warned of active exploitation of two zero-day vulnerabilities impacting Secure Mobile Access (SMA) 1000 series appliances, one of which could be exploited to achieve arbitrary command execution.
The vulnerabilities are listed below –
CVE-2026-15409 (CVSS score: 10.0) – A Server-side request forgery (SSRF) vulnerability that a remote unauthenticated attacker could exploit to
-
[7] Vulnerabilities Patched by Fortinet, Ivanti, ServiceNow (SecurityWeek)
<p>A critical security defect in the ServiceNow AI platform could allow remote attackers to execute arbitrary code.</p>
<p>The post <a href=”https://www.securityweek.com/vulnerabilities-patched-by-fortinet-ivanti-servicenow/”>Vulnerabilities Patched by Fortinet, Ivanti, ServiceNow</a> appeared first on <a href=”https://www.securityweek.com”>SecurityWeek</a>.</p> -
[7] [RANSOMWARE] dragonforce leaked Heritage Mechanical LLC (ransomware.live/dragonforce)
Victim: Heritage Mechanical LLC | Group: dragonforce | Website: heritagemechanical-llc.com | Country: US | Details: Built on a family legacy of proud steamfitters dating back to over 100 years, Heritage Mechanical was established in 2012 to provide quality mechanical service to the commercial construction industry. Opening its doors with only three employees and a master plan, the company has since grown rapidly
-
[7] [RANSOMWARE] dragonforce leaked Isegen South Africa (Pty) Ltd (ransomware.live/dragonforce)
Victim: Isegen South Africa (Pty) Ltd | Group: dragonforce | Website: www.isegen.co.za | Country: ZA | Details: Isegen South Africa (Pty) Ltd is a South African chemical company founded in 1974. It is the sole producer of certain chemical products in South Africa.
Data that will be published:
Corporate correspondence
Passport / personal identification data
Contracts
Certificates
Intellectu -
[7] [RANSOMWARE] dragonforce leaked Hughes Atwood & Mullaly pllc (ransomware.live/dragonforce)
Victim: Hughes Atwood & Mullaly pllc | Group: dragonforce | Website: hsh-law.com | Country: US | Details: Hughes Atwood & Mullaly PLLC is a full-service law firm that offers professional legal services to individuals, businesses, and institutions in the Upper Valley Region of New Hampshire and Vermont. The firm specializes in various practice areas including Business Law, Civil Litigation, Criminal Law,
-
[7] [RANSOMWARE] dragonforce leaked Shillen Mackall & Seldon (ransomware.live/dragonforce)
Victim: Shillen Mackall & Seldon | Group: dragonforce | Website: promotingjustice.com | Country: US | Details: Shillen Mackall Seldon Spicer & Fraas is a law firm dedicated to representing personal injury victims primarily in Vermont, New Hampshire, and Florida since 1980. They offer legal services for a wide range of personal injury cases, including car accidents, medical malpractice, and workers’ compensat
-
[7] [RANSOMWARE] dragonforce leaked Stephens Precision (ransomware.live/dragonforce)
Victim: Stephens Precision | Group: dragonforce | Website: stephensprecision.com | Country: US | Details: Stephens Precision, Inc. is a versatile HUBZone manufacturing facility in Vermont, specializing in the machining of mechanical assemblies, components, and tooling for aerospace, defense, commercial, and research sectors. As a Woman-Owned Small Business, they offer solutions from prototype to volume
-
[7] [RANSOMWARE] pear leaked Carient Heart & Vascular (ransomware.live/pear)
Victim: Carient Heart & Vascular | Group: pear | Website: carient.com | Country: US | Details: Expert resource for heart and vascular care in Northern Virginia
-
[6] We built a vulnerability vending machine: AI tokens in, zero-days out (BleepingComputer)
Intruder built an AI-powered “vulnerability vending machine” that combines code slicing with LLMs to automatically discover complex software vulnerabilities. The company explains how the system found and exploited a previously unknown WordPress plugin zero-day, with additional discoveries already under responsible disclosure. […]
-
[6] US charges alleged operators of Russian bulletproof hosting service (BleepingComputer)
U.S. federal prosecutors have unsealed charges against three Russian nationals, accusing them of providing bulletproof hosting (BPH) services to ransomware gangs that caused over $62 million in damages to victims worldwide. […]
-
[6] Progress Confirms Zero-Day Vulnerability Behind ShareFile Disruption (SecurityWeek)
<p>The company has rolled out a fix and is restoring access for Storage Zones Controller customers who apply it.</p>
<p>The post <a href=”https://www.securityweek.com/progress-confirms-zero-day-vulnerability-behind-sharefile-disruption/”>Progress Confirms Zero-Day Vulnerability Behind ShareFile Disruption</a> appeared first on <a href=”https://www.securityweek.com”>SecurityWeek</a>.</p> -
[6] LatticeFlow AI connects governance frameworks with continuous AI risk monitoring (HelpNetSecurity)
<p>LatticeFlow AI has announced a platform for managing AI risk across agentic systems. Organizations are deploying autonomous AI in critical business processes, while governance approaches based on documentation and point-in-time assessments struggle to keep up with evolving risks. The LatticeFlow AI Platform links AI governance frameworks with technical controls to continuously generate evidence and translate evaluation results into risk insights, helping organizations assess AI systems and su
-
[6] [CISA KEV] CVE-2026-46817: Oracle E-Business Suite Improper Privilege Management Vulnerability – Oracle E-Business Suite (CISA KEV)
Oracle E-Business Suite Improper Privilege Management Vulnerability – Oracle E-Business Suite. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset’s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.. Due: 2026-07-18
-
[6] [CISA KEV] CVE-2023-4346: KNX Association KNX Protocol Connection Authorization Option 1 Overly Restrictive Account Lockout Mechanism Vulnerability – KNX Association KNX Protocol Connection Authorization Option 1 (CISA KEV)
KNX Association KNX Protocol Connection Authorization Option 1 Overly Restrictive Account Lockout Mechanism Vulnerability – KNX Association KNX Protocol Connection Authorization Option 1. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset’s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.. Due: 2026-07-29
-
[5] Firefox, Chrome, Adobe, and VMware Updates Fix Multiple Critical Security Flaws (TheHackerNews)
Mozilla has released updates to address two critical flaws in Firefox for which it warned that exploit code has been published.
The vulnerabilities are listed below –
CVE-2026-15718, an invalid pointer in the JavaScript: WebAssembly component
CVE-2026-15719, a site isolation in the DOM: Navigation component“We are aware that exploit code for this is public, however we are not aware of
-
[5] [RANSOMWARE] qilin leaked International Delights (ransomware.live/qilin)
Victim: International Delights | Group: qilin | Website: intdelights.com | Country: US | Details: N/A
-
[5] [RANSOMWARE] ransomhouse leaked Fidelity Services Group (ransomware.live/ransomhouse)
Victim: Fidelity Services Group | Group: ransomhouse | Website: www.fidelity-services.com | Country: GB | Details: Fidelity Services Group is Southern Africa’s largest integrated security solutions provider, specializing in innovative protection services. With over 60 years of experience, they offer a range of services including security guarding, cash management, and fire protection solutions tailored for corpo
-
[5] [RANSOMWARE] coinbasecartel leaked PanasonicAero (ransomware.live/coinbasecartel)
Victim: PanasonicAero | Group: coinbasecartel | Website: panasonic.aero | Country: JP | Details: [AI generated] Panasonic Avionics Corporation, commonly known as Panasonic Aero, is a US-based subsidiary of Panasonic Corporation specializing in in-flight entertainment and connectivity systems for commercial airlines. The company designs and supplies seatback screens, Wi-Fi connectivity, and cabi
-
[5] [RANSOMWARE] akira leaked Pioneer Construction (ransomware.live/akira)
Victim: Pioneer Construction | Group: akira | Details: Established in 1933, Pioneer Construction is headquartered in Grand Rapids, Michigan. They prov
ide construction solutions throughout the United States including general contracting, crane se
rvices, program management, and more.We will upload 168gb of corporate data soon. Scanned employee persona
-
[5] [RANSOMWARE] Booba Project leaked Jani-King (ransomware.live/Booba Project)
Victim: Jani-King | Group: Booba Project | Website: www.janiking.com | Country: US | Details: Facilities Services Stolen data: 12 GB.
-
[5] [RANSOMWARE] pear leaked South Plains Rural Health Services, Inc. (ransomware.live/pear)
Victim: South Plains Rural Health Services, Inc. | Group: pear | Website: sprhs.org | Country: US | Details: Comprehensive and family care in West Texas
-
[5] [RANSOMWARE] AiLock leaked Nihon Kotsu Co., Ltd. (ransomware.live/AiLock)
Victim: Nihon Kotsu Co., Ltd. | Group: AiLock | Website: nihon-kotsu.co.jp | Country: JP | Details: Nihon Kotsu Co., Ltd. is the largest taxi and limousine operator in Japan. For the fiscal year ending May 2025, the company reported an annual consolidated revenue of ¥103.445 billion, with group and partner company sales reaching ¥155.457 billion.
-
[5] [RANSOMWARE] AiLock leaked Solid Advance Inc. (ransomware.live/AiLock)
Victim: Solid Advance Inc. | Group: AiLock | Website: solid-adv.co.jp | Country: JP | Details: Solid Advance Inc. is a Japanese software company, founded in 2004, based in Tokyo and Aomori. It develops and sells All Gather CRM, a fully in-house-built, integrated CRM package covering customer management, sales support (SFA), marketing, and call centers, available both in the cloud and on-premi
-
[5] [RANSOMWARE] AiLock leaked Ferrovial (ransomware.live/AiLock)
Victim: Ferrovial | Group: AiLock | Website: ferrovial.com | Country: ES | Details: Headquartered in Ferrovial operates as a global infrastructure and mobility operator. The company’s services include the design and construction of public and private projects, and development, finance, and operation of toll road concessions.
-
[5] [RANSOMWARE] qilin leaked Feliubadaló (ransomware.live/qilin)
Victim: Feliubadaló | Group: qilin | Website: www.feliubadalo.com | Country: ES | Details: N/A
-
[5] [RANSOMWARE] qilin leaked Levin Furniture (ransomware.live/qilin)
Victim: Levin Furniture | Group: qilin | Website: www.levinfurniture.com | Country: US | Details: N/A
SUMMARY
Total new items: 56, critical: 1, ransomware groups active today: 0.
Top CVEs to patch urgently: CVE-2026-15409, CVE-2026-46817, CVE-2023-4346, CVE-2026-15718, CVE-2026-15719.
Sources: BleepingComputer, TheHackerNews, SecurityWeek, HelpNetSecurity, KrebsOnSecurity, CISA KEV, ransomware.live
Companion HTML report attached.
Leave a Reply