Companion HTML report: Download HTML report
CRITICAL SECTION
[12] CISA orders urgent action on actively exploited Langflow RCE flaw (BleepingComputer)
The Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday ordered U.S. government agencies to prioritize patching an actively exploited vulnerability in the Langflow visual framework for building AI agents. […]
CISA KEV (Known Exploited Vulnerabilities)
| CVE | Vendor/Product | Score | Required Action |
|---|---|---|---|
| CVE-2026-16232 | CISA KEV | 6 | Assess and patch immediately |
| CVE-2026-50522 | CISA KEV | 6 | Assess and patch immediately |
RANSOMWARE VICTIMS (DLS Monitoring)
[RANSOMWARE] dragonforce leaked Koshkaryan Law Group: [RANSOMWARE] dragonforce leaked Koshkaryan Law Group
[RANSOMWARE] kairos leaked LR Reed: [RANSOMWARE] kairos leaked LR Reed
[RANSOMWARE] nova leaked VNSO: [RANSOMWARE] nova leaked VNSO
[RANSOMWARE] blacknevas leaked Zuni Shopping Center, Inc.: [RANSOMWARE] blacknevas leaked Zuni Shopping Center, Inc.
[RANSOMWARE] qilin leaked P & A Construction: [RANSOMWARE] qilin leaked P & A Construction
[RANSOMWARE] BrainCipher leaked windiam.com: [RANSOMWARE] BrainCipher leaked windiam.com
[RANSOMWARE] qilin leaked Primeline Logistics: [RANSOMWARE] qilin leaked Primeline Logistics
[RANSOMWARE] qilin leaked Recsa: [RANSOMWARE] qilin leaked Recsa
[RANSOMWARE] qilin leaked Salida Union School District: [RANSOMWARE] qilin leaked Salida Union School District
[RANSOMWARE] chaos leaked neopharmlabs.com: [RANSOMWARE] chaos leaked neopharmlabs.com
[RANSOMWARE] qilin leaked Cpcg: [RANSOMWARE] qilin leaked Cpcg
[RANSOMWARE] qilin leaked EFU Life Assurance: [RANSOMWARE] qilin leaked EFU Life Assurance
[RANSOMWARE] qilin leaked Infina Health: [RANSOMWARE] qilin leaked Infina Health
[RANSOMWARE] m3rx leaked ubfreight.com: [RANSOMWARE] m3rx leaked ubfreight.com
[RANSOMWARE] krybit leaked dhli.in: [RANSOMWARE] krybit leaked dhli.in
[RANSOMWARE] krybit leaked Vibonum Technologies Private Limited: [RANSOMWARE] krybit leaked Vibonum Technologies Private Limited
[RANSOMWARE] akira leaked Kruse Construction: [RANSOMWARE] akira leaked Kruse Construction
[RANSOMWARE] akira leaked University Sprinkler Systems: [RANSOMWARE] akira leaked University Sprinkler Systems
[RANSOMWARE] Booba Project leaked Pelli Clarke Pelli Architects: [RANSOMWARE] Booba Project leaked Pelli Clarke Pelli Architects
[RANSOMWARE] chaos leaked issvc.com: [RANSOMWARE] chaos leaked issvc.com
NEWS
[8] Ubuntu snap-confine Flaw Could Give Local Users Root on Default Desktop Installs (TheHackerNews)
Cybersecurity researchers have disclosed details of a new local privilege escalation (LPE) vulnerability in snap-confine that an unprivileged user can trigger to obtain root access and gain complete control of a target environment.
The high-severity flaw, tracked as CVE-2026-8933 (CVSS score: 7.8), impacts default installations of Ubuntu Desktop 24.04, 25.10, and 26.04. The disclosure comes as
[8] Another SharePoint RCE exploited: Patch, then rotate your machine keys (CVE-2026-50522) (HelpNetSecurity)
<p>Attackers are exploiting a critical SharePoint remote code execution (RCE) vulnerability (CVE-2026-50522) to extract the servers’ IIS machine keys. “WatchTowr is observing active exploitation of CVE-2026-50522 against on-premise Microsoft SharePoint deployments following the release of public exploit code, with attackers stealing machine keys to retain long-term access,” the offensive security company warned on Tuesday. WatchTowr’s global honeypot network registered su
[7] [RANSOMWARE] dragonforce leaked Koshkaryan Law Group (ransomware.live/dragonforce)
Victim: Koshkaryan Law Group | Group: dragonforce | Website: koshlaw.com | Country: US | Details: Koshkaryan Law Group is a legal firm specializing in personal injury and criminal defense cases. They prioritize client service and provide personalized attention to ensure favorable outcomes for their clients. The firm offers free initial consultations and is dedicated to keeping clients informed a
[5] Swiss rail giant Stadler rejects $12.3M ransom demand after cyberattack (BleepingComputer)
Swiss rail vehicle manufacturer Stadler Rail says the Everest ransomware gang demanded about $12.3 million after breaching a data exchange platform shared with one of its suppliers. […]
[5] How enterprise GenAI can amplify ransomware risk — and how to contain it (BleepingComputer)
Enterprise AI can accelerate ransomware attacks when AI assistants and agents inherit excessive permissions or compromised identities. Acronis explains how identity controls, governance, and least-privilege access help reduce AI-enabled ransomware risk while supporting secure AI adoption. […]
[5] Hackers Exploit Windmill Flaw to Read Arbitrary Server Files Without Authentication (TheHackerNews)
A high-severity security flaw impacting open-source developer platform Windmill has come under active exploitation in the wild, per VulnCheck.
The vulnerability in question is CVE-2026-29059 (CVSS score: 7.5), a case of unauthenticated path traversal impacting Windmill’s “get_log_file” endpoint (“/api/w/{workspace}/jobs_u/get_log_file/{filename}”).
“The filename parameter is concatenated into
[5] Lookout identifies exploitable vulnerabilities in mobile apps (HelpNetSecurity)
<p>Lookout has announced the launch of the Lookout Mobile Software Exposure Center (MSEC). Integrated natively into the Lookout Mobile Endpoint Security platform, MSEC enables organizations to continuously detect, validate, prioritize, and remediate exploitable vulnerabilities across their mobile software ecosystem. The advancement of frontier AI models, such as Anthropic’s Claude Mythos, marks a fundamental shift in the cybersecurity landscape. By reducing the cost and time required to di
[5] [RANSOMWARE] kairos leaked LR Reed (ransomware.live/kairos)
Victim: LR Reed | Group: kairos | Country: AU | Details: LR Reed is a family-owned business with over 30 years of experience, specializing in Owners Corporation management and developer services. They provide a comprehensive range of management services, including asset management, legislative compliance, and financial accounting, ensuring a transparent a
[5] [RANSOMWARE] nova leaked VNSO (ransomware.live/nova)
Victim: VNSO | Group: nova | Details: Công nghệ VNSO is a leading provider of cloud and server solutions in Vietnam, offering a wide range of services including hosting, VPS, cloud storage, private cloud, anti-DDoS, and CDN. Their products cater to various needs, from high-performance cloud servers to dedicated servers for gaming and AI
[5] [RANSOMWARE] blacknevas leaked Zuni Shopping Center, Inc. (ransomware.live/blacknevas)
Victim: Zuni Shopping Center, Inc. | Group: blacknevas | Country: US | Details: A family-owned commercial corporation incorporated in New Mexico, USA, that owns and operates Halona Plaza, a multi-purpose retail and tourism hub in the heart of the Zuni Pueblo reservation.The business dates back to 1910 and was formally incorporated as Zuni Shopping Center, Inc. in 1961. Over the
[5] [RANSOMWARE] qilin leaked P & A Construction (ransomware.live/qilin)
Victim: P & A Construction | Group: qilin | Website: www.paconst.com | Country: US | Details: N/A
[5] [RANSOMWARE] BrainCipher leaked windiam.com (ransomware.live/BrainCipher)
Victim: windiam.com | Group: BrainCipher | Website: windiam.com | Details: [AI generated] N/A
[5] [RANSOMWARE] qilin leaked Primeline Logistics (ransomware.live/qilin)
Victim: Primeline Logistics | Group: qilin | Website: www.primeline.ie | Country: IE | Details: N/A
[5] [RANSOMWARE] qilin leaked Recsa (ransomware.live/qilin)
Victim: Recsa | Group: qilin | Website: www.recsa.com | Country: CR | Details: N/A
[5] [RANSOMWARE] qilin leaked Salida Union School District (ransomware.live/qilin)
Victim: Salida Union School District | Group: qilin | Website: www.salida.k12.ca.us | Country: US | Details: N/A
[5] [RANSOMWARE] chaos leaked neopharmlabs.com (ransomware.live/chaos)
Victim: neopharmlabs.com | Group: chaos | Website: neopharmlabs.com | Country: US | Details: Notice of Data Escalation: 3% Proof Publication
Management is ignoring the seriousness of the situation and refusing to engage in dialogue. We are publishing a 3% sample of our 627 GB archive right now.
We are giving management 48 hours to reach out to us. If they fail to contact us within this ti
[5] [RANSOMWARE] qilin leaked Cpcg (ransomware.live/qilin)
Victim: Cpcg | Group: qilin | Website: www.cpcgr.com | Country: BR | Details: N/A
[5] [RANSOMWARE] qilin leaked EFU Life Assurance (ransomware.live/qilin)
Victim: EFU Life Assurance | Group: qilin | Website: www.efulife.com | Country: PK | Details: N/A
[5] [RANSOMWARE] qilin leaked Infina Health (ransomware.live/qilin)
Victim: Infina Health | Group: qilin | Website: www.infinahealth.com | Details: N/A
[5] [RANSOMWARE] m3rx leaked ubfreight.com (ransomware.live/m3rx)
Victim: ubfreight.com | Group: m3rx | Website: ubfreight.com | Details: UB Freight is a leading provider of worldwide freight services, specializing in air and sea freight, customs clearance, and warehousing solutions. They cater to a diverse clientele, including large companies with complex shipping needs and individuals looking to send personal items overseas. With IA
[5] [RANSOMWARE] krybit leaked dhli.in (ransomware.live/krybit)
Victim: dhli.in | Group: krybit | Website: dhli.in | Country: IN | Details: Delhi Heart & Lung Institute (DHLI) is a tertiary care 100-bedded super specialty hospital established in 2003 in New De…
[5] [RANSOMWARE] krybit leaked Vibonum Technologies Private Limited (ransomware.live/krybit)
Victim: Vibonum Technologies Private Limited | Group: krybit | Website: Vibonum Technologies Private Limited | Country: IN | Details: *** is a recently incorporated Indian private limited company established on March 27, …
[5] [RANSOMWARE] akira leaked Kruse Construction (ransomware.live/akira)
Victim: Kruse Construction | Group: akira | Details: Kruse Construction is a mechanical contractor with over 50 years of experience in the petroleum
and petrochemical industry, specializing in the construction and maintenance of liquid petrole
um truck, rail, and pipeline terminals. The company also provides services for bulk plants, pip
eline pump st
[5] [RANSOMWARE] akira leaked University Sprinkler Systems (ransomware.live/akira)
Victim: University Sprinkler Systems | Group: akira | Details: University Sprinklers is BC’s largest irrigation company, specializing in the installation of i
rrigation sprinkler systems and landscape lighting for both residential and commercial clients.
With over 40 years of experience, they provide tailored irrigation solutions that ensure healt
hy lawns and
[5] [RANSOMWARE] Booba Project leaked Pelli Clarke Pelli Architects (ransomware.live/Booba Project)
Victim: Pelli Clarke Pelli Architects | Group: Booba Project | Website: www.pcparch.com | Country: US | Details: Architecture and Planning Stolen data: 45 GB.
[5] [RANSOMWARE] chaos leaked issvc.com (ransomware.live/chaos)
Victim: issvc.com | Group: chaos | Website: issvc.com | Country: SG | Details: issvc.com
Official Notice to Management and Stakeholders
The time window has expired. Exactly 24 hours remain until the final deadline. If an agreement is not reached by the end of this period, the complete confidential dataset totaling 262 GB will be published into the public domain.
Compromised
SUMMARY
Total new items: 63, critical: 1, ransomware victims today: 20.
Top CVEs to patch urgently: CVE-2026-50522, CVE-2026-8933, CVE-2026-16232, CVE-2026-29059, CVE-2026-48294.
Sources: BleepingComputer, TheHackerNews, SecurityWeek, HelpNetSecurity, KrebsOnSecurity, CISA KEV, ransomware.live
Leave a Reply