Companion report attempted upload failed; local path: https://liberpulse.com/wp-content/uploads/cyber_report_latest.html
CRITICAL SECTION
[10] [RANSOMWARE] nightspire leaked Grupo Riquelme (ransomware.live/nightspire)
Victim: Grupo Riquelme | Group: nightspire | Website: www.gruporiquelme.com | Country: PY | Details: – Full Database Backup- Banking & Financial Data- Accounting & Ledger Records- Customer Databases- HR / Workforce Data- User, Role & Permission data- ERP & Critical Business Application Data
CISA KEV (last 14 days)
| CVE |
Vendor/Product |
Score |
Required Action |
| CVE-2026-12569 |
See CISA |
— |
Apply vendor patch / mitigations |
| CVE-2026-20230 |
See CISA |
— |
Apply vendor patch / mitigations |
RANSOMWARE VICTIMS (DLS Monitoring)
nightspire: Grupo Riquelme
AuditTeam: I-SYS
incransom: Life Bridges, GSP Crop Science Pvt
krybit: politur.gob.do, sansilvestre.edu.pe
anubis: Nachlass Nord
interlock: Clearview Eye Centre
chaos: roofdepot.com
insomnia: *************
akira: JMS Southeast, Padget Technologies
morpheus: Delegal Poindexter & Underkofler, P.A.
qilin: ISOPLUS
NEWS
[7] Cisco Catalyst SD-WAN Zero-Day CVE-2026-20245 Exploited to Gain Root Access — TheHackerNews
An unknown threat actor exploited a recently disclosed high-severity security flaw impacting Cisco Catalyst SD-WAN as a zero-day at least two months before it was publicly disclosed, according to new findings from Google-owned Mandiant.
The vulnerability, tracked as CVE-2026-20245 (CVSS score: 7.8), allows an authenticated, local attacker to execute arbitrary commands with elevated privileges
[7] Cisco SD-WAN Zero-Day Exploited Months Before Patching — SecurityWeek
CVE-2026-20245, the 7th Cisco SD-WAN vulnerability exploited in 2026, was used for months prior to its disclosure and patching.
The post Cisco SD-WAN Zero-Day Exploited Months Before Patching appeared first on SecurityWeek.
[7] ControlMonkey connects backup visibility with cloud recovery readiness — HelpNetSecurity
ControlMonkey announced its Data Backup Correlation, a new capability that extends its Cyber Resilience Platform by connecting data backup posture with cloud configuration recovery. The first release supports AWS Backup and Azure Backup. CISOs and cloud teams often lack full visibility into data backup coverage and available recovery points across critical data sources, including databases, storage accounts, and cloud data services, making it harder to understand what data assets are actually
[5] Webinar: Why account takeovers remain one of the hardest threats to stop — BleepingComputer
Account takeover attacks continue to challenge security teams because attackers often operate through legitimate accounts and trusted services. This webinar explores how behavioral AI can help organizations identify compromised accounts faster and automate response workflows. […]
[5] Cal Water Says No OT Systems Breached in Iranian Handala Cyberattack — SecurityWeek
Mandiant has helped the California water utility investigate the cyberattack launched by Iranian hacker group Handala.
The post Cal Water Says No OT Systems Breached in Iranian Handala Cyberattack appeared first on SecurityWeek.
[5] runZero 5.0 unifies exposure management to accelerate risk reduction — HelpNetSecurity
runZero has announced runZero 5.0, a major platform evolution designed to help organizations defend their expanding attack surfaces against high-velocity, AI-fueled threats. The new release unifies the exposure management lifecycle into an automated workflow that enables security teams to seamlessly discover assets and network connections, identify and prioritize critical risks, and initiate and validate remediation to proactively reduce exposure and achieve operational resilience. For years,
SUMMARY
Total new items: 50. Critical count: 1. Ransomware groups active: 11. Top CVEs to patch: CVE-2026-12569, CVE-2026-20230.
Sources: BleepingComputer, TheHackerNews, SecurityWeek, HelpNetSecurity, KrebsOnSecurity, CISA KEV, ransomware.live