Category: Cybersecurity

  • Cybersecurity Intelligence Report — 2026-07-21

    Cybersecurity Intelligence Report — 2026-07-21

    CRITICAL SECTION

    • [14] ServiceNow pre-auth RCE exploited in the wild (CVE-2026-6875) (HelpNetSecurity) — CVEs: CVE-2026-6875
      <p>Attackers have begun exploiting CVE-2026-6875, a critical pre-authentication vulnerability in the ServiceNow AI Platform, according to threat intelligence firm Defused. About the vulnerability ServiceNow AI is a Platform-as-a-Service that lets organizations build and automate digital workflows. CVE-2026-6875 is a code injection vulnerability that lets unauthenticated attackers escape ServiceNow’s script sandbox and execute code remotely on a targeted instance. The vulnerability was unea
    • [12] ⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More (TheHackerNews)
      A single request should not be able to do this much. But this week, small inputs led to code execution, memory loss, stolen keys, and disabled security tools.

      The paths were often simple: exposed systems, weak checks, old drivers, fake prompts, and public code used for malware delivery. Some bugs were new. Others were already being used before defenders had time to patch.

      Here is the full

    CISA KEV

    No CISA KEV items in the last 14 days.

    RANSOMWARE VICTIMS (DLS MONITORING)

    Unknown: [RANSOMWARE] nova leaked Jrd logistics, [RANSOMWARE] akira leaked McKeever , Varga & Senko, [RANSOMWARE] safepay leaked wdk.de, [RANSOMWARE] safepay leaked jaecklin-industrial.de, [RANSOMWARE] safepay leaked lbb-treuhand.de, [RANSOMWARE] safepay leaked timetex.de, [RANSOMWARE] safepay leaked stroebel-gruppe.de, [RANSOMWARE] safepay leaked industriesjaro.com, [RANSOMWARE] safepay leaked cenesco.de, [RANSOMWARE] safepay leaked acsmallmaxwell.com.au, [RANSOMWARE] safepay leaked mende-grundbesitz.de, [RANSOMWARE] kairos leaked College O’Sullivan de Québec, [RANSOMWARE] kairos leaked Collge O’Sullivan de Québec, [RANSOMWARE] incransom leaked Ali-Monde, [RANSOMWARE] coinbasecartel leaked Caterpillar, [RANSOMWARE] anubis leaked Bath Fitter, [RANSOMWARE] anubis leaked Fairlife / Coca-Cola, [RANSOMWARE] nova leaked Rumah Sakit Universitas Indonesia (RSUI), [RANSOMWARE] nova leaked Universidad Nacional de Mar del Plata, [RANSOMWARE] coinbasecartel leaked Colliers Real Estate, [RANSOMWARE] akira leaked L&A Transport, [RANSOMWARE] nova leaked Koplarla, [RANSOMWARE] qilin leaked Bolt & Nut Manufacturing, [RANSOMWARE] chaos leaked wikoff.com

    NEWS

    [9] Russian-Speaking Hacker Uses Google Gemini CLI to Control Botnet of Eight Dental Clinic PCs (TheHackerNews) — A solo Russian-speaking threat actor known as “bandcampro” outsourced a chunk of their operations to Google’s open-source Gemini CLI artificial intelligence (AI) and commandeered a live botnet.

    The findings come from an analysis of 200 Gemini CLI session logs between March 19 and April 21, 2026, which found the threat actor using AI, among other things, to crack passwords, set up a residential

    [9] [RANSOMWARE] nova leaked Jrd logistics (ransomware.live/nova) — Victim: Jrd logistics | Group: nova | Details: Jrd logistics LTD is an India-based freight forwarding and supply chain company headquartered in Kolkata that provides international logistics, customs clearance, warehousing, and multimodal transport services – Nova Provide tree and samples from stolen data to the company when its get in touch with

    [8] Critical ServiceNow code execution flaw now exploited in attacks (BleepingComputer) — Attackers have begun exploiting a critical vulnerability (CVE-2026-6875) in the ServiceNow AI Platform, according to threat intelligence company Defused. […]

    [8] SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch (SecurityWeek) — <p>The zero-days CVE-2026-15409 and CVE-2026-15410 were exploited by a threat actor tracked by Volexity as UTA0533.</p>
    <p>The post <a href=”https://www.securityweek.com/sonicwall-zero-days-exploited-to-deliver-custom-malware-for-weeks-before-patch/”>SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch</a> appeared first on <a href=”https://www.securityweek.com”>SecurityWeek</a>.</p>

    [8] WP2Shell WordPress Vulnerabilities Exploited in the Wild (SecurityWeek) — <p>Exploitation of the new WordPress vulnerabilities tracked as CVE-2026-60137 and CVE-2026-63030 started soon after disclosure.</p>
    <p>The post <a href=”https://www.securityweek.com/wp2shell-wordpress-vulnerabilities-exploited-in-the-wild/”>WP2Shell WordPress Vulnerabilities Exploited in the Wild</a> appeared first on <a href=”https://www.securityweek.com”>SecurityWeek</a>.</p>

    [7] [RANSOMWARE] akira leaked McKeever , Varga & Senko (ransomware.live/akira) — Victim: McKeever , Varga & Senko | Group: akira | Details: McKeever Varga & Senko is a firm of Certified Public Accountants dedicated to providing superio
    r client service and professional guidance. They offer a range of services including informativ
    e articles, interactive financial calculators, and links to external resources to assist their
    clients.

    We

    [6] Estée Lauder discloses data breach via Oracle E-Business flaw (BleepingComputer) — Cosmetics giant Estée Lauder is notifying customers of a data breach after hackers exploited a flaw in Oracle E-Business Suite that the company used for human resources (HR) operations. […]

    [6] SonicWall SMA1000 flaws exploited as zero-days to push custom malware (BleepingComputer) — Two recently disclosed SonicWall SMA1000 vulnerabilities were exploited in zero-day attacks for weeks, allowing threat actors to install custom malware on vulnerable VPN appliances. […]

    [6] World’s Largest AI Model Repository Hugging Face Breached by Autonomous AI Agent (TheHackerNews) — In an ironic twist, open-source artificial intelligence (AI) platform Hugging Face revealed that it was the victim of a hack perpetrated by an autonomous AI agent system.

    The company said it detected and responded to the incident targeting its production infrastructure earlier last week.

    “We identified unauthorized access to a limited set of internal datasets and to several credentials used by

    [6] New Index Tracks Material Breaches — And Refuses to Add Up the Losses (SecurityWeek) — <p>Longtime cybersecurity executive Richard Bird built the resource for security experts, journalists, policymakers, and everyday citizens.</p>
    <p>The post <a href=”https://www.securityweek.com/new-index-tracks-material-breaches-and-refuses-to-add-up-the-losses/”>New Index Tracks Material Breaches — And Refuses to Add Up the Losses</a> appeared first on <a href=”https://www.securityweek.com”>SecurityWeek</a>.</p>

    [6] Hugging Face breached by autonomous AI agent (HelpNetSecurity) — <p>Hugging Face, the widely used platform for sharing open-source machine learning models and datasets, has disclosed a security breach it says was carried out by an autonomous AI agent system. How the attack unfolded In a blog post published Thursday (July 16), the company said that earlier that week, it identified unauthorized access to some internal datasets and to several credentials used by its services. The intrusion was executed via a malicious dataset that abused … <a href=”https:/

    [5] More alerts are making your team slower, and an outcome-based SOC fixes that (HelpNetSecurity) — <p>In this Help Net Security video, Thom Langford, EMEA CTO, Rapid7, explains why piling on more security alerts makes a SOC slower to respond. Attackers log in with stolen credentials and use trusted tools like PowerShell instead of custom malware. He shares a case where attackers called a help desk, reset a privileged cloud account, and exposed thousands of passwords in three minutes. Ransomware groups can go from access to payload in under three hours. … <a href=”https://www.helpnetsecu

    [5] [RANSOMWARE] safepay leaked wdk.de (ransomware.live/safepay) — Victim: wdk.de | Group: safepay | Website: wdk.de | Country: DE | Details: Founded in 1950 and headquartered in Frankfurt am Main, the organization serves as the central voice of German manufacturers of …

    [5] [RANSOMWARE] safepay leaked jaecklin-industrial.de (ransomware.live/safepay) — Victim: jaecklin-industrial.de | Group: safepay | Website: jaecklin-industrial.de | Country: DE | Details: Founded in 1935 by Julius Jäcklin, the company has developed from a regional machine repair workshop into a globally recognized …

    [5] [RANSOMWARE] safepay leaked lbb-treuhand.de (ransomware.live/safepay) — Victim: lbb-treuhand.de | Group: safepay | Website: lbb-treuhand.de | Country: DE | Details: The company specializes in tax consulting, auditing, accounting, payroll administration, financial reporting, and business advisory services for private individuals, self-employed …

    [5] [RANSOMWARE] safepay leaked timetex.de (ransomware.live/safepay) — Victim: timetex.de | Group: safepay | Website: timetex.de | Country: DE | Details: The company traces its origins to 1991, when the TimeTEX brand was acquired and expanded into a comprehensive supplier of …

    [5] [RANSOMWARE] safepay leaked stroebel-gruppe.de (ransomware.live/safepay) — Victim: stroebel-gruppe.de | Group: safepay | Website: stroebel-gruppe.de | Country: DE | Details: Headquartered in Langenzenn, Bavaria, the company was founded in 1978 by Gerlinde and Gerhard Ströbel and has grown from a …

    [5] [RANSOMWARE] safepay leaked industriesjaro.com (ransomware.live/safepay) — Victim: industriesjaro.com | Group: safepay | Website: industriesjaro.com | Country: CA | Details: Over several decades, Jaro has evolved from manufacturing telephone booths into a supplier of advanced outdoor enclosures, interactive kiosks, bus …

    [5] [RANSOMWARE] safepay leaked cenesco.de (ransomware.live/safepay) — Victim: cenesco.de | Group: safepay | Website: cenesco.de | Country: DE | Details: Founded in 1998, the company provides comprehensive information technology solutions for small and medium-sized enterprises (SMEs), helping organizations modernize their …

    [5] [RANSOMWARE] safepay leaked acsmallmaxwell.com.au (ransomware.live/safepay) — Victim: acsmallmaxwell.com.au | Group: safepay | Website: acsmallmaxwell.com.au | Country: AU | Details: Founded in 1916 by Ambrose Cecil Small, the firm has provided professional accounting and financial services to businesses and individuals …

    [5] [RANSOMWARE] safepay leaked mende-grundbesitz.de (ransomware.live/safepay) — Victim: mende-grundbesitz.de | Group: safepay | Website: mende-grundbesitz.de | Country: DE | Details: Founded in 1994, the company specializes in the professional administration of residential, commercial, and mixed-use real estate throughout the Berlin …

    [5] [RANSOMWARE] kairos leaked College O’Sullivan de Québec (ransomware.live/kairos) — Victim: College O’Sullivan de Québec | Group: kairos | Country: CA | Details: Collège O’Sullivan de Québec offers a variety of training programs both in-class and online, focusing on fields such as administration, insurance, office management, IT, web development, and marketing. The institution aims to equip students with the skills needed for the job market and higher educat

    [5] [RANSOMWARE] kairos leaked Collge O’Sullivan de Québec (ransomware.live/kairos) — Victim: Collge O’Sullivan de Québec | Group: kairos | Country: CA | Details: Collège O’Sullivan de Québec offers a variety of training programs both in-class and online, focusing on fields such as administration, insurance, office management, IT, web development, and marketing. The institution aims to equip students with the skills needed for the job market and higher educat

    [5] [RANSOMWARE] incransom leaked Ali-Monde (ransomware.live/incransom) — Victim: Ali-Monde | Group: incransom | Country: US | Details: Ali-Monde is a food production and distribution company that’s been around for over 50 years. They’ve got 5 of their own brands and an impressive lineup of 800+ dry, organic, and gluten-free products. Based just south of Montreal, they distribute food across Quebec, Ontario, New Brunswick, and parts

    [5] [RANSOMWARE] coinbasecartel leaked Caterpillar (ransomware.live/coinbasecartel) — Victim: Caterpillar | Group: coinbasecartel | Country: US | Details: [AI generated] Caterpillar Inc. is an American multinational corporation headquartered in Irving, Texas. It is the world’s leading manufacturer of construction and mining equipment, diesel and natural gas engines, industrial gas turbines, and diesel-electric locomotives. Operating in over 190 countr

    [5] [RANSOMWARE] anubis leaked Bath Fitter (ransomware.live/anubis) — Victim: Bath Fitter | Group: anubis | Country: US | Details: Employee data breach at a major manufacturing company.

    [5] [RANSOMWARE] anubis leaked Fairlife / Coca-Cola (ransomware.live/anubis) — Victim: Fairlife / Coca-Cola | Group: anubis | Country: US | Details: www.fairlife.com

    [5] [RANSOMWARE] nova leaked Rumah Sakit Universitas Indonesia (RSUI) (ransomware.live/nova) — Victim: Rumah Sakit Universitas Indonesia (RSUI) | Group: nova | Country: ID | Details: Rumah Sakit Universitas Indonesia (RSUI) is the teaching hospital of the University of Indonesia, providing advanced medical care, education, and clinical research in Indonesia – medical data from drive at risk, Nova Provide tree and samples from stolen data to the company when its get in touch with

    [5] [RANSOMWARE] nova leaked Universidad Nacional de Mar del Plata (ransomware.live/nova) — Victim: Universidad Nacional de Mar del Plata | Group: nova | Country: AR | Details: The Universidad Nacional de Mar del Plata offers a wide range of academic programs, including undergraduate and postgraduate degrees, vocational training, and distance education. It serves students, faculty, and the broader community by promoting research, innovation, and cultural activities. The un

    [5] [RANSOMWARE] coinbasecartel leaked Colliers Real Estate (ransomware.live/coinbasecartel) — Victim: Colliers Real Estate | Group: coinbasecartel | Country: US | Details: [AI generated] Colliers International is a global commercial real estate services company headquartered in Toronto, Canada. It operates across more than 60 countries, offering services including property management, investment sales, leasing, valuation, and advisory. The firm serves corporate, insti

    [5] [RANSOMWARE] akira leaked L&A Transport (ransomware.live/akira) — Victim: L&A Transport | Group: akira | Details: L & A Transport is a reputable trucking company with over 50 years of experience in providing a
    wide range of shipping services, including international shipping, white glove handling, and l
    ogistics solutions for businesses of all sizes. They specialize in truckloads, container loads,
    less than con

    [5] [RANSOMWARE] nova leaked Koplarla (ransomware.live/nova) — Victim: Koplarla | Group: nova | Website: kopkarla.com | Country: ID | Details: Koperasi Konsumen Karyawan PT Aplikanusa Lintasarta (KOPKARLA) was established in 1992 and at that time was focusing on saving and loan business. Since 1998, KOPKARLA has evolved and expanded its business to provide an installation services and solution of telecommunication network (datacomm)

    [5] [RANSOMWARE] qilin leaked Bolt & Nut Manufacturing (ransomware.live/qilin) — Victim: Bolt & Nut Manufacturing | Group: qilin | Website: www.bnml.co.uk | Country: GB | Details: N/A

    [5] [RANSOMWARE] chaos leaked wikoff.com (ransomware.live/chaos) — Victim: wikoff.com | Group: chaos | Website: wikoff.com | Country: US | Details: [PUBLIC DISCLOSURE]

    Target: Wikoff Color Corporation (wikoff.com)
    Data Volume: 650 GB
    Status: Full Compromise Confirmed

    We are officially confirming that the entire internal infrastructure of Wikoff Color Corporation—ranging from Board of Directors financial reports and proprietary R&D formulas…

    SUMMARY

    Total new items: 65. Critical: 2. Ransomware groups active today: 1.

    Top CVEs to patch urgently: CVE-2026-6875 (2), CVE-2026-15409 (1), CVE-2026-15410 (1), CVE-2026-63030 (1), CVE-2026-60137 (1).

    Sources: BleepingComputer, TheHackerNews, SecurityWeek, HelpNetSecurity, KrebsOnSecurity, CISA KEV, ransomware.live

    Companion HTML report: Full HTML report

  • Cybersecurity Daily  2026-07-20

    Companion HTML report: Download HTML report (zip)

    CRITICAL SECTION

    None today.

    CISA KEV (last 14 days)

    None listed in the collector output.

    RANSOMWARE VICTIMS (today)

    Doommageddon: Reni Farmácias Associadas

    unsafe: CCR Solutions

    qilin: PP+K, Eana, Synergy Products, Don Tortaco Mexican Grill, Associated Theatrical Contractors, City Ambulance Service, Famesa

    nova: meralmanisa, Dephub, Jota Joias Premium

    krybit: eurohold.bg

    payload: CKR Consulting Engineers

    blackout: yano.tokyo, www.miatech.net, bluebellgroup.com

    thegentlemen: Ecopetrol

    ULose: KyungRok, NRCapital, HanDok, HIZE Aero, MSICapital

    The Green Blood Group: DAF SENEGAL, ECOBAT EGYPT

    NEWS

    1. [9] Week in review: High severity WordPress vulnerabilities, fake OAuth IDs bypass sign-in logs (HelpNetSecurity) — Reports indicate WordPress-related flaws and OAuth client ID spoofing that may bypass sign-in logs; review authentication logs and apply patches.
  • [8] Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution (TheHackerNews) — A vulnerability reported in NGINX can crash worker processes and may allow remote code execution; administrators should apply vendor updates and restart affected services. CVE(s): CVE-2026-42533
  • [7] UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices wih Malware (TheHackerNews) — Russian state-sponsored threat actors have been observed leveraging the infamous ClickFix strategy to trick Ukrainian targets into infecting their own machines with data-stealing malware.

    According to the Computer Emergency Response Team of Ukraine (CERT-UA), the activity has been attributed to UAC-0145, a sub-cluster within Sandworm, an advanced hacking unit affiliated with GRU, Russia’s

  • [6] SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access (TheHackerNews) — Several zero-day flaws in SonicWall SMA appliances are reported to have been exploited before disclosure; isolate affected appliances and seek vendor mitigations.
  • SUMMARY

    Total new items: 30

    Critical count: 0

    Ransomware victims listed: 25

    Top CVEs to patch urgently: CVE-2026-42533

    Sources: BleepingComputer, TheHackerNews, SecurityWeek, HelpNetSecurity, KrebsOnSecurity, CISA KEV, ransomware.live

  • Cybersecurity Daily – TEST

    Companion HTML report uploaded: Cybersecurity report

  • Cybersecurity Intelligence Report  2026-07-19

    Companion HTML report (zip): Download ZIP

    Critical

    • [11] Two new high severity WordPress vulnerabilities, patch immediately! — CVEs: CVE-2026-60137, CVE-2026-63030
      <p>The 7.0.2 WordPress security release addresses one critical and one high severity security issue. The vulnerabilities reported to the WordPress security team include: CVE-2026-60137 &#8211; A facilitated SQL injection issue reported as a team by TF1T, dtro, and haongo CVE-2026-63030 &#8211; A REST API batch-route confusion and SQL injection issue leading to Remote Code Execution reported by Adam Kues at Assetnote / Searchlight Cyber Which versions of WordPress are vulnerable? WordPress 6.9 is
  • Cybersecurity Intelligence Report — 16 July 2026

    Cybersecurity Intelligence Report — 16 July 2026

    CRITICAL SECTION

    • [12] CISA Urges Immediate Patching of Exploited SharePoint Vulnerabilities (SecurityWeek)

      <p>Three vulnerabilities are actively exploited in attacks, including two that have been targeted as zero-days.</p>
      <p>The post <a href=”https://www.securityweek.com/cisa-urges-immediate-patching-of-exploited-sharepoint-vulnerabilities/”>CISA Urges Immediate Patching of Exploited SharePoint Vulnerabilities</a> appeared first on <a href=”https://www.securityweek.com”>SecurityWeek</a>.</p>

    CISA KEV (last 14 days)

    No KEV items in the last 14 days.

    RANSOMWARE VICTIMS (DLS Monitoring)

    No new ransomware victims recorded today.

    NEWS

    • [9] Google Gemini CLI abused as a hacking agent, malware botnet operator (BleepingComputer)

      A Russian-speaking threat actor known as “bandcampro” used Google’s open-source Gemini CLI AI tool as a hacking agent and to operate a small-scale botnet. […]

    • [9] Researcher Drops New Windows Zero-Day PoC Hours After Microsoft Patch Tuesday (TheHackerNews)

      Security researcher Chaotic Eclipse (aka Nightmare-Eclipse) has released a new proof-of-concept (PoC) exploit called LegacyHive.

      It has been described as a Windows User Profile Service arbitrary hive load elevation of privileges vulnerability. The Windows User Profile Service, also referred to as ProfSvc, is a core system component that manages user accounts and environments.

      “The PoC requires

    • [9] Critical Vulnerabilities Patched With Fresh Chrome 150, Firefox 152 Updates (SecurityWeek)

      <p>Public exploit code targeting the Firefox flaws exists, but no in-the-wild exploitation has been observed.</p>
      <p>The post <a href=”https://www.securityweek.com/critical-vulnerabilities-patched-with-fresh-chrome-150-firefox-152-updates/”>Critical Vulnerabilities Patched With Fresh Chrome 150, Firefox 152 Updates</a> appeared first on <a href=”https://www.securityweek.com”>SecurityWeek</a>.</p>

    • [8] CISA warns admins to patch actively exploited SharePoint flaws (BleepingComputer)

      The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned Tuesday that attackers are actively exploiting three vulnerabilities to hack Internet-exposed on-premises SharePoint Server instances. […]

    • [7] Two SonicWall SMA 1000 Zero-Days Exploited, One Could Enable Admin Commands (TheHackerNews)

      SonicWall has warned of active exploitation of two zero-day vulnerabilities impacting Secure Mobile Access (SMA) 1000 series appliances, one of which could be exploited to achieve arbitrary command execution.

      The vulnerabilities are listed below –

      CVE-2026-15409 (CVSS score: 10.0) – A Server-side request forgery (SSRF) vulnerability that a remote unauthenticated attacker could exploit to

    • [7] Vulnerabilities Patched by Fortinet, Ivanti, ServiceNow (SecurityWeek)

      <p>A critical security defect in the ServiceNow AI platform could allow remote attackers to execute arbitrary code.</p>
      <p>The post <a href=”https://www.securityweek.com/vulnerabilities-patched-by-fortinet-ivanti-servicenow/”>Vulnerabilities Patched by Fortinet, Ivanti, ServiceNow</a> appeared first on <a href=”https://www.securityweek.com”>SecurityWeek</a>.</p>

    • [7] [RANSOMWARE] dragonforce leaked Heritage Mechanical LLC (ransomware.live/dragonforce)

      Victim: Heritage Mechanical LLC | Group: dragonforce | Website: heritagemechanical-llc.com | Country: US | Details: Built on a family legacy of proud steamfitters dating back to over 100 years, Heritage Mechanical was established in 2012 to provide quality mechanical service to the commercial construction industry. Opening its doors with only three employees and a master plan, the company has since grown rapidly

    • [7] [RANSOMWARE] dragonforce leaked Isegen South Africa (Pty) Ltd (ransomware.live/dragonforce)

      Victim: Isegen South Africa (Pty) Ltd | Group: dragonforce | Website: www.isegen.co.za | Country: ZA | Details: Isegen South Africa (Pty) Ltd is a South African chemical company founded in 1974. It is the sole producer of certain chemical products in South Africa.
      Data that will be published:
      Corporate correspondence
      Passport / personal identification data
      Contracts
      Certificates
      Intellectu

    • [7] [RANSOMWARE] dragonforce leaked Hughes Atwood & Mullaly pllc (ransomware.live/dragonforce)

      Victim: Hughes Atwood & Mullaly pllc | Group: dragonforce | Website: hsh-law.com | Country: US | Details: Hughes Atwood & Mullaly PLLC is a full-service law firm that offers professional legal services to individuals, businesses, and institutions in the Upper Valley Region of New Hampshire and Vermont. The firm specializes in various practice areas including Business Law, Civil Litigation, Criminal Law,

    • [7] [RANSOMWARE] dragonforce leaked Shillen Mackall & Seldon (ransomware.live/dragonforce)

      Victim: Shillen Mackall & Seldon | Group: dragonforce | Website: promotingjustice.com | Country: US | Details: Shillen Mackall Seldon Spicer & Fraas is a law firm dedicated to representing personal injury victims primarily in Vermont, New Hampshire, and Florida since 1980. They offer legal services for a wide range of personal injury cases, including car accidents, medical malpractice, and workers’ compensat

    • [7] [RANSOMWARE] dragonforce leaked Stephens Precision (ransomware.live/dragonforce)

      Victim: Stephens Precision | Group: dragonforce | Website: stephensprecision.com | Country: US | Details: Stephens Precision, Inc. is a versatile HUBZone manufacturing facility in Vermont, specializing in the machining of mechanical assemblies, components, and tooling for aerospace, defense, commercial, and research sectors. As a Woman-Owned Small Business, they offer solutions from prototype to volume

    • [7] [RANSOMWARE] pear leaked Carient Heart & Vascular (ransomware.live/pear)

      Victim: Carient Heart & Vascular | Group: pear | Website: carient.com | Country: US | Details: Expert resource for heart and vascular care in Northern Virginia

    • [6] We built a vulnerability vending machine: AI tokens in, zero-days out (BleepingComputer)

      Intruder built an AI-powered “vulnerability vending machine” that combines code slicing with LLMs to automatically discover complex software vulnerabilities. The company explains how the system found and exploited a previously unknown WordPress plugin zero-day, with additional discoveries already under responsible disclosure. […]

    • [6] US charges alleged operators of Russian bulletproof hosting service (BleepingComputer)

      U.S. federal prosecutors have unsealed charges against three Russian nationals, accusing them of providing bulletproof hosting (BPH) services to ransomware gangs that caused over $62 million in damages to victims worldwide. […]

    • [6] Progress Confirms Zero-Day Vulnerability Behind ShareFile Disruption (SecurityWeek)

      <p>The company has rolled out a fix and is restoring access for Storage Zones Controller customers who apply it.</p>
      <p>The post <a href=”https://www.securityweek.com/progress-confirms-zero-day-vulnerability-behind-sharefile-disruption/”>Progress Confirms Zero-Day Vulnerability Behind ShareFile Disruption</a> appeared first on <a href=”https://www.securityweek.com”>SecurityWeek</a>.</p>

    • [6] LatticeFlow AI connects governance frameworks with continuous AI risk monitoring (HelpNetSecurity)

      <p>LatticeFlow AI has announced a platform for managing AI risk across agentic systems. Organizations are deploying autonomous AI in critical business processes, while governance approaches based on documentation and point-in-time assessments struggle to keep up with evolving risks. The LatticeFlow AI Platform links AI governance frameworks with technical controls to continuously generate evidence and translate evaluation results into risk insights, helping organizations assess AI systems and su

    • [6] [CISA KEV] CVE-2026-46817: Oracle E-Business Suite Improper Privilege Management Vulnerability – Oracle E-Business Suite (CISA KEV)

      Oracle E-Business Suite Improper Privilege Management Vulnerability – Oracle E-Business Suite. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset’s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.. Due: 2026-07-18

    • [6] [CISA KEV] CVE-2023-4346: KNX Association KNX Protocol Connection Authorization Option 1 Overly Restrictive Account Lockout Mechanism Vulnerability – KNX Association KNX Protocol Connection Authorization Option 1 (CISA KEV)

      KNX Association KNX Protocol Connection Authorization Option 1 Overly Restrictive Account Lockout Mechanism Vulnerability – KNX Association KNX Protocol Connection Authorization Option 1. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset’s internet exposure and ensuring adherence to BOD 26-04 patching guidelines.. Due: 2026-07-29

    • [5] Firefox, Chrome, Adobe, and VMware Updates Fix Multiple Critical Security Flaws (TheHackerNews)

      Mozilla has released updates to address two critical flaws in Firefox for which it warned that exploit code has been published.

      The vulnerabilities are listed below –

      CVE-2026-15718, an invalid pointer in the JavaScript: WebAssembly component
      CVE-2026-15719, a site isolation in the DOM: Navigation component

      “We are aware that exploit code for this is public, however we are not aware of

    • [5] [RANSOMWARE] qilin leaked International Delights (ransomware.live/qilin)

      Victim: International Delights | Group: qilin | Website: intdelights.com | Country: US | Details: N/A

    • [5] [RANSOMWARE] ransomhouse leaked Fidelity Services Group (ransomware.live/ransomhouse)

      Victim: Fidelity Services Group | Group: ransomhouse | Website: www.fidelity-services.com | Country: GB | Details: Fidelity Services Group is Southern Africa’s largest integrated security solutions provider, specializing in innovative protection services. With over 60 years of experience, they offer a range of services including security guarding, cash management, and fire protection solutions tailored for corpo

    • [5] [RANSOMWARE] coinbasecartel leaked PanasonicAero (ransomware.live/coinbasecartel)

      Victim: PanasonicAero | Group: coinbasecartel | Website: panasonic.aero | Country: JP | Details: [AI generated] Panasonic Avionics Corporation, commonly known as Panasonic Aero, is a US-based subsidiary of Panasonic Corporation specializing in in-flight entertainment and connectivity systems for commercial airlines. The company designs and supplies seatback screens, Wi-Fi connectivity, and cabi

    • [5] [RANSOMWARE] akira leaked Pioneer Construction (ransomware.live/akira)

      Victim: Pioneer Construction | Group: akira | Details: Established in 1933, Pioneer Construction is headquartered in Grand Rapids, Michigan. They prov
      ide construction solutions throughout the United States including general contracting, crane se
      rvices, program management, and more.

      We will upload 168gb of corporate data soon. Scanned employee persona

    • [5] [RANSOMWARE] Booba Project leaked Jani-King (ransomware.live/Booba Project)

      Victim: Jani-King | Group: Booba Project | Website: www.janiking.com | Country: US | Details: Facilities Services Stolen data: 12 GB.

    • [5] [RANSOMWARE] pear leaked South Plains Rural Health Services, Inc. (ransomware.live/pear)

      Victim: South Plains Rural Health Services, Inc. | Group: pear | Website: sprhs.org | Country: US | Details: Comprehensive and family care in West Texas

    • [5] [RANSOMWARE] AiLock leaked Nihon Kotsu Co., Ltd. (ransomware.live/AiLock)

      Victim: Nihon Kotsu Co., Ltd. | Group: AiLock | Website: nihon-kotsu.co.jp | Country: JP | Details: Nihon Kotsu Co., Ltd. is the largest taxi and limousine operator in Japan. For the fiscal year ending May 2025, the company reported an annual consolidated revenue of ¥103.445 billion, with group and partner company sales reaching ¥155.457 billion.

    • [5] [RANSOMWARE] AiLock leaked Solid Advance Inc. (ransomware.live/AiLock)

      Victim: Solid Advance Inc. | Group: AiLock | Website: solid-adv.co.jp | Country: JP | Details: Solid Advance Inc. is a Japanese software company, founded in 2004, based in Tokyo and Aomori. It develops and sells All Gather CRM, a fully in-house-built, integrated CRM package covering customer management, sales support (SFA), marketing, and call centers, available both in the cloud and on-premi

    • [5] [RANSOMWARE] AiLock leaked Ferrovial (ransomware.live/AiLock)

      Victim: Ferrovial | Group: AiLock | Website: ferrovial.com | Country: ES | Details: Headquartered in Ferrovial operates as a global infrastructure and mobility operator. The company’s services include the design and construction of public and private projects, and development, finance, and operation of toll road concessions.

    • [5] [RANSOMWARE] qilin leaked Feliubadaló (ransomware.live/qilin)

      Victim: Feliubadaló | Group: qilin | Website: www.feliubadalo.com | Country: ES | Details: N/A

    • [5] [RANSOMWARE] qilin leaked Levin Furniture (ransomware.live/qilin)

      Victim: Levin Furniture | Group: qilin | Website: www.levinfurniture.com | Country: US | Details: N/A

    SUMMARY

    Total new items: 56, critical: 1, ransomware groups active today: 0.

    Top CVEs to patch urgently: CVE-2026-15409, CVE-2026-46817, CVE-2023-4346, CVE-2026-15718, CVE-2026-15719.

    Sources: BleepingComputer, TheHackerNews, SecurityWeek, HelpNetSecurity, KrebsOnSecurity, CISA KEV, ransomware.live

    Companion HTML report attached.

  • Cybersecurity Intelligence Report — 2026-07-15

    Cybersecurity Intelligence Report — 2026-07-15

    CRITICAL SECTION

    • [16] SonicWall SMA appliances targeted in zero-day attacks (CVE-2026-15409, CVE-2026-15410) (HelpNetSecurity) CVE-2026-15410, CVE-2026-15409
      <p>SonicWall has fixed two actively exploited vulnerabilities (CVE-2026-15409, CVE-2026-15410) affecting its Secure Mobile Access (SMA) 1000 Series appliances, and is urging customer organizations to upgrade to a fixed firmare version and search for evidence of potential compromise. If the outlined indicators of compromise are present on the system, the company advises re-imaging (hardware) or re-deploying (virtual) appliances, changing user and administrator passwords, and resetting TOTP tokens
    • [10] SonicWall warns of SMA1000 flaws exploited in zero-day attacks, patch now (BleepingComputer) CVE-2026-15410, CVE-2026-15409
      SonicWall warns that threat actors have been exploiting two SMA1000 vulnerabilities, tracked as CVE-2026-15409 and CVE-2026-15410, in zero-day attacks and urges customers to install the newly released security updates. […]
    • [10] [RANSOMWARE] dragonforce leaked Intron Technology Holdings (ransomware.live/dragonforce)
      Victim: Intron Technology Holdings | Group: dragonforce | Website: www.intron-tech.com | Country: TW | Details: Intron Technology Holdings Limited is a fast-growing automotive electronics solutions provider in China focuses on providing solutions targeting critical automotive electronic components applied in New Energy, Body Control, Safety and Powertrain systems. The Group utilizes its research and developme

    CISA KEV SECTION (Known Exploited Vulnerabilities)

    CVE Vendor/Product Score Required Action
    CVE-2026-56164 [CISA KEV] CVE-2026-56164: Microsoft SharePoint Server Missing Authentication for Critical Function Vulnerability – Microsoft SharePoint Server 9 Microsoft SharePoint Server Missing Authentication for Critical Function Vulnerability – Microsoft SharePoint Server. Required action: Apply mitigations in accordance with vendor instructions, ensurin
    CVE-2026-56155 [CISA KEV] CVE-2026-56155: Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability – Microsoft Active Directory Federation Services 6 Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability – Microsoft Active Directory Federation Services. Required action: Apply mitigations in accorda
    CVE-2026-15409 [CISA KEV] CVE-2026-15409: SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability – SonicWall SMA1000 Appliances 6 SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability – SonicWall SMA1000 Appliances. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance wi
    CVE-2026-15410 [CISA KEV] CVE-2026-15410: SonicWall SMA1000 Appliances Code Injection Vulnerability – SonicWall SMA1000 Appliances 6 SonicWall SMA1000 Appliances Code Injection Vulnerability – SonicWall SMA1000 Appliances. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD

    RANSOMWARE VICTIMS (DLS Monitoring)

    dragonforce: [RANSOMWARE] dragonforce leaked Intron Technology Holdings, [RANSOMWARE] dragonforce leaked Edison Global Networks Limited, [RANSOMWARE] dragonforce leaked SITAV SpA, [RANSOMWARE] dragonforce leaked Graphic International Centre, [RANSOMWARE] dragonforce leaked Road Ahead Technologies Consultant, [RANSOMWARE] dragonforce leaked Atcom, [RANSOMWARE] dragonforce leaked Midal Cables, [RANSOMWARE] dragonforce leaked Omax Autos, [RANSOMWARE] dragonforce leaked Ifage, [RANSOMWARE] dragonforce leaked asimar.com

    chaos: [RANSOMWARE] chaos leaked aphenapharma.com, [RANSOMWARE] chaos leaked sleemanbreweries.ca, [RANSOMWARE] chaos leaked spectrumchemical.com

    blacknevas: [RANSOMWARE] blacknevas leaked Arkın Group, [RANSOMWARE] blacknevas leaked L'azurde

    incransom: [RANSOMWARE] incransom leaked VantagePoint Management & Autoclear, [RANSOMWARE] incransom leaked Golden Glasko & Associates

    securotrop: [RANSOMWARE] securotrop leaked ProDirectional Drilling

    shinyhunters: [RANSOMWARE] shinyhunters leaked Abbott owned Exact Sciences Corporation

    coinbasecartel: [RANSOMWARE] coinbasecartel leaked Axiom GlobalNEW

    arcusmedia: [RANSOMWARE] arcusmedia leaked Perpustam, [RANSOMWARE] arcusmedia leaked gemese.pt, [RANSOMWARE] arcusmedia leaked Distribox, [RANSOMWARE] arcusmedia leaked Be Travel, [RANSOMWARE] arcusmedia leaked COREBI(NowVertical), [RANSOMWARE] arcusmedia leaked I-FITNESS

    qilin: [RANSOMWARE] qilin leaked THL, [RANSOMWARE] qilin leaked Sedemi

    nightspire: [RANSOMWARE] nightspire leaked Cedar Crest College

    payoutsking: [RANSOMWARE] payoutsking leaked Casta Diva Group

    AiLock: [RANSOMWARE] AiLock leaked WBF Construction

    cmdorganization: [RANSOMWARE] cmdorganization leaked Target Energy Solutions

    NEWS SECTION

    • [8] Progress confirms ShareFile zero-day flaw behind Storage Zone shutdown (BleepingComputer) — Progress Software has confirmed that a high-severity zero-day vulnerability is behind the emergency shutdown of ShareFile Storage Zone Controllers last week and has released security updates to patch the flaw. […]
    • [8] 7 Severe Vulnerabilities Patched in VMware Avi Load Balancer (SecurityWeek) — <p>The flaws can be exploited for authentication bypass, remote code execution, privilege escalation, and directory traversal.</p>
      <p>The post <a href="https://www.securityweek.com/7-severe-vulnerabilities-patched-in-vmware-avi-load-balancer/">7 Severe Vulnerabilities Patched in VMware Avi Load Balancer</a> appeared first on <a href="https://www.securityweek.com">SecurityWeek</a>.</p>
    • [8] US, Allies Warn of Russian Cyberattacks Targeting Critical Infrastructure Routers (SecurityWeek) — <p>Multiple state-sponsored APTs are compromising poorly secured devices across critical infrastructure sector networks.</p>
      <p>The post <a href="https://www.securityweek.com/us-allies-warn-of-russian-cyberattacks-targeting-critical-infrastructure-routers/">US, Allies Warn of Russian Cyberattacks Targeting Critical Infrastructure Routers</a> appeared first on <a href="https://www.securityweek.com">SecurityWeek</a>.</p>
    • [7] SAP warns of critical flaws in NetWeaver and Commerce Cloud (BleepingComputer) — SAP has addressed 16 vulnerabilities across multiple products as part of its July 2026 security updates, including three critical flaws in NetWeaver, Commerce Cloud, and AppRouter. […]
    • [7] Adobe Patches Critical ColdFusion Vulnerabilities (SecurityWeek) — <p>The ColdFusion security defects could allow attackers to execute arbitrary code or elevate their privileges.</p>
      <p>The post <a href="https://www.securityweek.com/adobe-patches-critical-coldfusion-vulnerabilities/">Adobe Patches Critical ColdFusion Vulnerabilities</a> appeared first on <a href="https://www.securityweek.com">SecurityWeek</a>.</p>
    • [7] SAP Patches Critical Vulnerabilities in NetWeaver, Approuter, Commerce Cloud (SecurityWeek) — <p>The flaws could allow attackers to access and modify data, and cause system unavailability and request-response desynchronization.</p>
      <p>The post <a href="https://www.securityweek.com/sap-patches-critical-vulnerabilities-in-netweaver-approuter-commerce-cloud/">SAP Patches Critical Vulnerabilities in NetWeaver, Approuter, Commerce Cloud</a> appeared first on <a href="https://www.securityweek.com">SecurityWeek</a>.</p>
    • [6] Microsoft July 2026 Patch Tuesday fixes massive 570 flaws, 3 zero-days (BleepingComputer) — Today is Microsoft's July 2026 Patch Tuesday, and with it comes security updates for a record-breaking 570 flaws, including two zero-day vulnerabilities exploited in attacks and one publicly disclosed. […]
    • [6] Microsoft Patches Record 622 Flaws, Including Two Zero-Days Under Active Attack (TheHackerNews) — Microsoft shipped its largest Patch Tuesday on record today, and two of the fixes close holes that attackers are already exploiting. The release covers 622 of Microsoft's own CVEs by its&nbsp;Security Update Guide&nbsp;count, more than triple&nbsp;June's previous high of around 200.

      Those two live bugs are the ones to grab first. Microsoft credits incident responders for both. Both are

    • [6] Microsoft Patches Record 622 Vulnerabilities, Including Two Exploited Zero-Days (SecurityWeek) — <p>Two flaws in Active Directory and SharePoint Server have been exploited as zero-days, and a BitLocker bug was publicly disclosed.</p>
      <p>The post <a href="https://www.securityweek.com/microsoft-patches-record-622-vulnerabilities-including-two-exploited-zero-days/">Microsoft Patches Record 622 Vulnerabilities, Including Two Exploited Zero-Days</a> appeared first on <a href="https://www.securityweek.com">SecurityWeek</a>.</p>
    • [6] New macOS malware steals passwords by posing as Apple’s crash-reporting tool (HelpNetSecurity) — <p>Jamf Threat Labs has uncovered a new macOS infostealer named CrashStealer that disguises itself as Apple&#8217;s crash-reporting tool to steal passwords, Keychain data, and cryptocurrency wallets. The malware was first spotted in May while it was still under development. By early July, Jamf was seeing in-the-wild detections, indicating it had moved into active use. &#8220;Unlike much of the commodity stealer activity on macOS, which is built on AppleScript droppers or thin Objective-C wrapper
    • [6] “Context bombs” can frustrate AI-driven attacks, researchers found (HelpNetSecurity) — <p>A new approach tried out by Tracebit researchers has proven very effective at stopping AI agents from fully compromising targeted environments. What makes it notable isn&#8217;t the technique &#8211; prompt injection is old news &#8211; but the direction it&#8217;s pointed: not to hijack AI agents, but to defend against them. Canaries with context bombs Tracebit offers customers a range of canaries, i.e., decoy resources and credentials that, when targeted by attackers, provide early warning
    • [5] Synopsys Finds No Evidence of Data Breach Amid Bosch Hack Claims (SecurityWeek) — <p>The D1R cybercrime group claimed to have stolen valuable data from Synopsys and Bosch, threatening to leak it unless a ransom is paid. </p>
      <p>The post <a href="https://www.securityweek.com/synopsys-finds-no-evidence-of-data-breach-following-bosch-hack-claims/">Synopsys Finds No Evidence of Data Breach Amid Bosch Hack Claims</a> appeared first on <a href="https://www.securityweek.com">SecurityWeek</a>.</p>

    SUMMARY

    Total new items: 84. Critical count: 3. Ransomware groups active: 13. Top CVEs to patch urgently: CVE-2026-15410, CVE-2026-15409, CVE-2026-56164, CVE-2026-56155, CVE-2026-44747.

    Sources: BleepingComputer, TheHackerNews, SecurityWeek, HelpNetSecurity, KrebsOnSecurity, CISA KEV, ransomware.live

    Companion HTML report: HTML report

  • Cybersecurity Daily – 2026-07-13

    Daily cybersecurity intelligence brief. See the companion report: [Companion HTML report attached]

    Companion report

    Download full report (HTML)

  • Cybersecurity Intelligence Report — 2026-07-12

    CRITICAL SECTION

    No items meeting score >= 10 were collected today.

    CISA KEV (last 14 days)

    No CISA KEV items found in today’s collection.

    RANSOMWARE VICTIMS (DLS Monitoring)

    cmdorganization: Golden Star Resources

    qilin: Century Equities, Retelit SpA PIVA, Carolina Agri-Power, Allied Plumbing & Heating

    NEWS

    [7] Critical Zimbra Flaw Could Let Crafted Emails Run Malicious Code in User Sessions (source)

    [6] Hackers Weaponize Balochistan Police Portal in Multi-Group Espionage Campaigns (source)

    SUMMARY

    Total new items: 40
    Critical items: 0
    Ransomware victims (24h): 5
    CISA KEV items: 0

    Companion HTML report: Download full report

  • test post

    test body

  • Cybersecurity Daily — 2026-07-11

    Companion HTML report (ZIP): Download report (ZIP)

    Top items

    • Turning software supply chain security into a daily habit \u2014

      In this Help Net Security video, Anastasia Tikhonova, Global Threat Research Lead at Group-IB, explains how to operationalize software su

    • Researcher Details WhatsApp-to-Host Attack Chain Using Three OpenClaw Flaws \u2014 Details have emerged about three now-patched security flaws in the OpenClaw personal artificial intelligence (AI) assistant that, if success
    • Hackers exploit critical auth bypass in Gitea Docker image \u2014 Hackers are actively exploiting a critical vulnerability in the official Docker image for the Gitea self-hosted Git service that allows atta
    • [RANSOMWARE] dragonforce leaked The Schuett Companies \u2014 Victim: The Schuett Companies | Group: dragonforce | Website: www.schuettcares.com | Country: US | Details: The Schuett Companies, Inc. is a
    • [RANSOMWARE] Deadlock leaked BARCELONA URBAN PROPERTY CHAMBER \u2014 Victim: BARCELONA URBAN PROPERTY CHAMBER | Group: Deadlock | Website: cpubcn.com | Country: ES | Details: [AI generated] N/A