Cybersecurity Intelligence Report — 17 August 2026

Written by

in

> CRITICAL SECTION

[12] Week in review: Salesforce and ServiceNow portals exposed for 17 months, exploited Metabase 0-day (HelpNetSecurity)
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: GitHub Dependabot malware alerts now cover eight ecosystems GitHub has flagged npm malware since March 2026. Anyone pulling in a bad PyPI, Maven, RubyGems, NuGet, Go, crates.io, or PHP Composer package has had no such warning, because GitHub’s malware detection only ever watched one ecosystem. That changed this month. Dependabot malware alerts, which had run on npm data alone, now … <a href

> CISA KEV (last 14 days)

CVE Vendor/Product Score Required action
No newly collected KEV entries.

> RANSOMWARE VICTIMS (today)

No victims timestamped today were present in the collected feed.

> NEWS

[7] [RANSOMWARE] emperador leaked Albania's Official National Teacher Training Portal (ransomware.live/emperador)
Victim: Albania's Official National Teacher Training Portal | Group: emperador | Country: AL | Details: Albania’s official national teacher training portal provides centralized professional development resources and accredited programs for educators nationwide. This leak include data such as; Roughly ~100k Full national ID numbers, full names and teacher certificates in PDF. [Size: 5.9 GB | Sector: E

[7] [RANSOMWARE] emperador leaked Albania's official national teacher training portal. (ransomware.live/emperador)
Victim: Albania's official national teacher training portal. | Group: emperador | Country: AL | Details: Albania’s official national teacher training portal provides centralized professional development resources and accredited programs for educators nationwide. This leak include data such as; Roughly ~100k Full national ID numbers, full names and teacher certificates in PDF. [Size: 5.9 GB | Sector: E

[7] [RANSOMWARE] medusalocker leaked Twal Family IT Lab (ransomware.live/medusalocker)
Victim: Twal Family IT Lab | Group: medusalocker | Details: Personal IT home lab. AD domain: twalfamily.com. VMware vSphere, multiple AD domains. Daniel Al Twal works at Technology North Corp (Edmonton), former DND co-op. No corporate target. Previously misidentified as Forces/forces.gc.ca. | 4172 Wolfe Point Way, Ottawa, ON K1V 1P5, Canada

[5] [RANSOMWARE] qilin leaked Teikoku USA (ransomware.live/qilin)
Victim: Teikoku USA | Group: qilin | Website: www.teikokuusa.com | Country: US | Details: N/A

[5] [RANSOMWARE] qilin leaked AGUNSA (ransomware.live/qilin)
Victim: AGUNSA | Group: qilin | Website: www.agunsa.com | Country: CL | Details: N/A

[5] [RANSOMWARE] qilin leaked Coface (ransomware.live/qilin)
Victim: Coface | Group: qilin | Website: www.coface.it | Country: IT | Details: N/A

[5] [RANSOMWARE] qilin leaked Spoonful of Comfort (ransomware.live/qilin)
Victim: Spoonful of Comfort | Group: qilin | Website: www.spoonfulofcomfort.com | Country: US | Details: N/A

[5] [RANSOMWARE] Panzer leaked SAGASTA sro (ransomware.live/Panzer)
Victim: SAGASTA sro | Group: Panzer | Website: sagasta.cz | Country: CZ | Details: SAGASTA is a design and engineering company specializing in modern construction, offering comprehensive design, engineering, and consulting services in the fields of railway, road, bridge, and water management construction.

[5] [RANSOMWARE] Eclipse leaked Moscord (ransomware.live/Eclipse)
Victim: Moscord | Group: Eclipse | Website: moscord.com | Country: SG | Details: Moscord is a digital marketplace that connects buyers and sellers in the maritime industry, offering a platform for various suppliers to aggregate and present their products. The company aims to enhance business operations for its clients by providing innovative solutions in procurement, logistics,

[5] [RANSOMWARE] qilin leaked Mulino Padano (ransomware.live/qilin)
Victim: Mulino Padano | Group: qilin | Website: www.mulinopadano.it | Country: IT | Details: N/A

[5] [RANSOMWARE] qilin leaked WEBA Meubelen (ransomware.live/qilin)
Victim: WEBA Meubelen | Group: qilin | Website: www.weba.be | Country: BE | Details: N/A

[5] [RANSOMWARE] settra leaked galmack.com.ec (ransomware.live/settra)
Victim: galmack.com.ec | Group: settra | Website: galmack.com.ec | Country: EC | Details: GALMACK S.A.: Internal Documents of an Ecuadorian Auto Dealership Holding PROLOGUE Inside: monthly b…

[5] [RANSOMWARE] settra leaked airoyal.biz (ransomware.live/settra)
Victim: airoyal.biz | Group: settra | Website: airoyal.biz | Details: AIROYAL COMPANY: Internal Documents of an American Industrial Components Distributor PROLOGUE We hav…

[5] [RANSOMWARE] settra leaked tiltstudio.com (ransomware.live/settra)
Victim: tiltstudio.com | Group: settra | Website: tiltstudio.com | Country: DE | Details: The Tilt Studio Archives Investigation of a Corporate Archive Leak from an Entertainment Network PRO…

[5] [RANSOMWARE] medusalocker leaked All Parts Dry Cleaning (ransomware.live/medusalocker)
Victim: All Parts Dry Cleaning | Group: medusalocker | Website: allpartsdrycleaning.co.uk | Country: GB | Details: Dry cleaning & laundry. Domain: allpartsdrycleaning.co.uk. | United Kingdom

[5] [RANSOMWARE] medusalocker leaked Idex Group (ransomware.live/medusalocker)
Victim: Idex Group | Group: medusalocker | Website: idex-group.com | Country: DE | Details: Organization with 30 emails extracted. Domain: idex-group.com

[5] [RANSOMWARE] medusalocker leaked Bija Industrie (ransomware.live/medusalocker)
Victim: Bija Industrie | Group: medusalocker | Website: bija-industrie.com | Country: FR | Details: Organization with 693 emails extracted. Domain: bija-industrie.com

[5] [RANSOMWARE] medusalocker leaked Thecourierguy (ransomware.live/medusalocker)
Victim: Thecourierguy | Group: medusalocker | Website: thecourierguy.co.za | Country: ZA | Details: Organization with 2018 emails extracted. Domain: thecourierguy.co.za

[5] [RANSOMWARE] Helix leaked Kennedy Jenks (ransomware.live/Helix)
Victim: Kennedy Jenks | Group: Helix | Country: US | Details: Kennedy Jenks is live. T1 is unlocked. T2 in 24 hours, then one day each through T4.

[5] [RANSOMWARE] lockbit5 leaked actua.fr (ransomware.live/lockbit5)
Victim: actua.fr | Group: lockbit5 | Website: actua.fr | Country: FR | Details: Groupe Actua is a recruitment and temporary staffing agency headquartered in Strasbourg, founded in…

> SUMMARY

New items collected: 47. Critical items: 1. Active ransomware groups represented today: 0. CVEs to prioritise for review: none identified in the selected items.

Sources: BleepingComputer, TheHackerNews, SecurityWeek, HelpNetSecurity, KrebsOnSecurity, CISA KEV, ransomware.live

Open the companion interactive HTML intelligence report

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *