Category: Cybersecurity

  • Cybersecurity Intelligence Report — 20 August 2026

    > CRITICAL SECTION

    [13] Critical RCE flaw in Windows IKE Extension now actively exploited (BleepingComputer)
    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned that hackers are exploiting a critical-severity remote code execution (RCE) flaw in the Windows Internet Key Exchange (IKE) Service Extensions component. […]

    [10] Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active Exploitation (TheHackerNews)
    CVEs: CVE-2026-65400
    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added four critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, stating they are being exploited in the wild. The shortcomings added to the KEV catalog are listed below – CVE-2026-65400 (CVSS score: 9.8) – An improper authentication vulnerability impacting Apple macOS that could allow an

    > CISA KEV (last 14 days)

    CVE Vendor/Product Score Required action
    CVE-2026-64849 [CISA KEV] CVE-2026-64849: MLflow Server-Side Request Forgery Vulnerability – MLflow MLflow 6 MLflow Server-Side Request Forgery Vulnerability – MLflow MLflow. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholde

    > RANSOMWARE VICTIMS (today)

    • everest: Grupo DT, Capgemini Engineering
    • xpl0itrs: Target

    > NEWS

    [8] CISA: Medusa ransomware hit over 500 critical infrastructure orgs (BleepingComputer)
    The FBI said Tuesday that the Medusa ransomware gang has breached more than 500 critical infrastructure organizations in the United States since June 2021. […]

    [8] CISA Urges Immediate Patching of Exploited Microsoft, VMware, Apple Vulnerabilities (SecurityWeek)
    The flaws can be exploited for remote code execution, authentication bypass, and device takeover. The post CISA Urges Immediate Patching of Exploited Microsoft, VMware, Apple Vulnerabilities appeared first on SecurityWeek .

    [8] Chrome, Firefox Updates Patch Dozens of Vulnerabilities (SecurityWeek)
    The bugs could lead to code execution, privilege escalation, sandbox escape, and information disclosure. The post Chrome, Firefox Updates Patch Dozens of Vulnerabilities appeared first on SecurityWeek .

    [8] Medusa ransomware gang has hit over 500 organizations, CISA warns (HelpNetSecurity)
    Medusa ransomware has breached more than 500 organizations since it first appeared in June 2021, the FBI, CISA, and the Department of Health and Human Services (HHS) said in an updated joint advisory. The update builds on an advisory first issued in March 2025 and draws on FBI investigations conducted as late as April 2026. “Medusa developers and affiliates have impacted over 500 victims from a variety of critical infrastructure sectors,” the advisory reads, listing … <a hre

    [7] Google’s AI security agents found 100+ critical software vulnerabilities in just two days (HelpNetSecurity)
    Google’s Mandiant has disclosed the workings of an internal tool that uses chains of AI agents to hunt for vulnerabilities in source code, saying it found over 100 verified, high-severity flaws in just two days during a live investigation into stolen corporate repositories. The tool, called the Agentic Vulnerability Discovery Harness (AVDH), has been running inside Mandiant for ten months. In that time it has scanned tens of millions of lines of code and produced … <a href="https:

    [6] Hackers Compromised 14,500+ Dahua Devices Using Credential Attacks, Auth Bypasses, and P2P (TheHackerNews)
    Cybersecurity researchers at Hunt.io have disclosed details of a campaign that they say compromised more than 14,530 Dahua devices between June 17 and July 22, 2026, using credential attacks, two authentication-bypass flaws, and a peer-to-peer (P2P) relay technique. The activity, codenamed Operation CameraSwarm, was reconstructed from a 407 MB exposed working directory containing 2,616 files

    [6] Clop-Linked Windchill Web Shell Decrypts Credentials and Maps Engineering Data (TheHackerNews)
    A JavaServer Pages (JSP) web shell deployed following the exploitation of a critical security flaw in PTC Windchill and FlexPLM servers is specifically designed for the enterprise Product Lifecycle Management (PLM) software, according to new findings from ReliaQuest. The cybersecurity company characterized the web shell as a fully equipped extortion platform capable of mapping sensitive vault

    [6] [RANSOMWARE] thegentlemen leaked Babcock (ransomware.live/thegentlemen)
    Victim: Babcock | Group: thegentlemen | Website: babcock.co.za | Country: ZA | Details: babcock.co.za rocketreach.co/babcock-international-group-africa-profile_b5cda591f42e0b42 Babcock Africa is a leading engineering and asset management company specializing in critical infrastructure and heavy equipment across the African continent. With over 130 years of experience, it provides lifet

    [5] Rogue ransomware affiliate poses as recovery firm to steal payments (BleepingComputer)
    A suspected ransomware affiliate is posing as a ransomware recovery service called "Ransom Busters," contacting the victims before the attacks become public and claiming to be able to provide decryption keys and delete stolen data for a fee. […]

    [5] [RANSOMWARE] qilin leaked Semana (ransomware.live/qilin)
    Victim: Semana | Group: qilin | Website: www.semana.es | Country: ES | Details: N/A

    [5] [RANSOMWARE] Helix leaked Delek US (ransomware.live/Helix)
    Victim: Delek US | Group: Helix | Country: US | Details: Delek US is live. T1 unlocks in 12 hours, then 24 hours per remaining tier.

    [5] [RANSOMWARE] Deadlock leaked UFOC (ransomware.live/Deadlock)
    Victim: UFOC | Group: Deadlock | Website: www.ufoc.com.tw/en/company | Country: TW | Details: United Fiber Optic Communication Inc. (UFOC) is an established, publicly traded telecommunications company from Taiwan. The company acts as a total solution provider for communication networks and specializes in the manufacture of fiber optic cables and the provision of integrated technological syst

    [5] [RANSOMWARE] Deadlock leaked Global Terminal Services (ransomware.live/Deadlock)
    Victim: Global Terminal Services | Group: Deadlock | Website: globalterminal-tr.com | Country: TR | Details: GTS legally registered as Global Terminal Hizmetleri A.Ş. It is the largest independent storage terminal for liquid fuels and oil in the entire Mediterranean region. 470gb

    [5] [RANSOMWARE] settra leaked wcmanagement.info (ransomware.live/settra)
    Victim: wcmanagement.info | Group: settra | Website: wcmanagement.info | Details: Documents of West Coast Management and Realty PROLOGUE Over 1,000 debt collection records with names…

    [5] [RANSOMWARE] settra leaked alphanumeric.com (ransomware.live/settra)
    Victim: alphanumeric.com | Group: settra | Website: alphanumeric.com | Country: US | Details: ALPHANUMERIC SYSTEMS, INC.: Internal Documents of an American IT Company PROLOGUE Internal documents…

    [5] [RANSOMWARE] settra leaked am-bition.jp (ransomware.live/settra)
    Victim: am-bition.jp | Group: settra | Website: am-bition.jp | Country: JP | Details: Internal Documents of the AMBITION Group and Its Insurance Partner Hope SSI PROLOGUE AMBITION Co., L…

    [5] [RANSOMWARE] settra leaked grecosteel.com (ransomware.live/settra)
    Victim: grecosteel.com | Group: settra | Website: grecosteel.com | Country: GR | Details: How Greco Steel Products Lost Control of Finances and Payroll PROLOGUE: 19 document categories. A co…

    [5] [RANSOMWARE] settra leaked makfreight.com (ransomware.live/settra)
    Victim: makfreight.com | Group: settra | Website: makfreight.com | Country: MY | Details: M.A.K. Freight Systems: Seven Vulnerabilities of a Canadian Freight Broker PROLOGUE We have in our p…

    [5] [RANSOMWARE] xpl0itrs leaked Mihuru (ransomware.live/xpl0itrs)
    Victim: Mihuru | Group: xpl0itrs | Details: Consumer travel financing

    [5] [RANSOMWARE] krybit leaked sunsea.co.th (ransomware.live/krybit)
    Victim: sunsea.co.th | Group: krybit | Website: sunsea.co.th | Country: TH | Details: Sunsea Plastics P.S. Co., Ltd. is a Thai family-owned company established in 1988, headquartered in Bang Na, Bangkok, Th…

    > SUMMARY

    New items collected: 86. Critical items: 2. Active ransomware groups represented today: 2. CVEs to prioritise for review: CVE-2026-65400, CVE-2026-64849.

    Sources: BleepingComputer, TheHackerNews, SecurityWeek, HelpNetSecurity, KrebsOnSecurity, CISA KEV, ransomware.live

    Open the companion interactive HTML intelligence report

  • Cybersecurity Intelligence Report — 19 August 2026

    > CRITICAL SECTION

    [13] CISA Flags Actively Exploited Ray Flaw That Can Trigger Browser-Based RCE (TheHackerNews)
    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a critical flaw impacting Ray to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. Ray is an open-source, Python-native distributed computing framework designed to scale artificial intelligence and machine learning workloads. As of writing, the GitHub project has more than

    > CISA KEV (last 14 days)

    CVE Vendor/Product Score Required action
    CVE-2026-33824 [CISA KEV] CVE-2026-33824: Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability – Microsoft Internet Key Exchange (IKE) Service Extensions 6 Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability – Microsoft Internet Key Exchange (IKE) Service Extensions. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services
    CVE-2026-59310 [CISA KEV] CVE-2026-59310: Broadcom VMware vCenter Path Traversal Vulnerability – Broadcom VMware vCenter 6 Broadcom VMware vCenter Path Traversal Vulnerability – Broadcom VMware vCenter. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailab
    CVE-2026-55040 [CISA KEV] CVE-2026-55040: Microsoft SharePoint Weak Authentication Vulnerability – Microsoft SharePoint 6 Microsoft SharePoint Weak Authentication Vulnerability – Microsoft SharePoint. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailabl
    CVE-2026-65400 [CISA KEV] CVE-2026-65400: Apple macOS Improper Authentication Vulnerability – Apple macOS 6 Apple macOS Improper Authentication Vulnerability – Apple macOS. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholder

    > RANSOMWARE VICTIMS (today)

    • direwolf: Photon Health, Inc., InfoFlo CRM, PayUp, Lifesum

    > NEWS

    [9] CISA: Windows Task Host flaw now exploited by ransomware gangs (BleepingComputer)
    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that ransomware gangs are also exploiting a high-severity Windows Task Host vulnerability that was flagged as actively exploited in April. […]

    [8] 16 Typosquatted RubyGems Packages Steal Browser Credentials and Crypto Wallets (TheHackerNews)
    Cybersecurity researchers have flagged a new typosquatting campaign targeting RubyGems users with a Windows-based information stealer. OpenSourceMalware, which discovered the activity on August 15, 2026, is tracking the threat under the moniker StubMaker. The complete list of packages published as part of the campaign is below – ubnuler ubnlder ri18nr reaker rakier orakw joxn

    [7] Attackers Exploit MLflow SSRF Flaw to Steal Cloud Credentials and Secrets (TheHackerNews)
    Two critical vulnerabilities impacting MLflow, an open-source artificial intelligence (AI) platform, and FUXA, an open-source, web-based SCADA / HMI software built for operational technology (OT) and industrial automation, are witnessing malicious scanning and exploitation efforts. According to independent reports from watchTowr and VulnCheck, the vulnerabilities in question are as follows –

    [7] Ransom Busters Claims It Hacked Ransomware Servers, Asks Victims for Up to $60,000 (TheHackerNews)
    A ransomware affiliate calling itself Ransom Busters has been spotted proactively sending emails to victim organizations and claims to delete stolen data from ransomware groups' servers in exchange for a fee ranging from $20,000 to $60,000. "In these messages, the third-party offers to help the victim recover from ransomware attack. This immediately stands out as anomalous," GuidePoint Research

    [7] [RANSOMWARE] dragonforce leaked R & D Machine and Engineering (ransomware.live/dragonforce)
    Victim: R & D Machine and Engineering | Group: dragonforce | Website: rdmachine.com | Country: US | Details: &D Machine and Engineering, LLC specializes in CNC machining of precision metal components primarily for the aerospace, defense, and space industries. The company is known for its ability to maintain tight tolerances and produce complex geometries using advanced 5-axis milling and coordinate measuri

    [7] [RANSOMWARE] Storm leaked Standard Tool & Die (ransomware.live/Storm)
    Victim: Standard Tool & Die | Group: Storm | Website: standardtool.net | Country: US | Details: Standard Tool & Die specializes in designing and manufacturing die cast dies, plastic molds, and trim dies for various industries including automotive, appliance, furniture, and household goods. The company offers single source manufacturing solutions and focuses on precision machining for both dome

    [6] NETSCOUT expands Adaptive DDoS Protection with outbound attack mitigation (HelpNetSecurity)
    NETSCOUT has announced an extension of its Adaptive DDoS Protection (ADP) solution enabling service providers to automatically detect and mitigate outbound DDoS attack traffic. By extending protection from the attack target towards its source, NETSCOUT helps operators prevent compromised subscriber devices from disrupting their own networks, consuming costly capacity and attacking customers and organizations across the internet. Consumer broadband routers, cameras and other IoT devices are in

    [6] Google’s $10,000 refund test shows why AI agents need zero trust (HelpNetSecurity)
    Google’s open-source autonomous Customer Support & Returns Agent, built using the Agent Development Kit (ADK) and Gemini, demonstrates how developers can apply zero-trust security principles to AI agents that interact with sensitive systems and take real-world actions. The project tests an approach that assumes an AI agent could be manipulated or compromised and puts security controls around it to limit what the agent can do. The architecture uses safeguards outside the model to verify a

    [6] [RANSOMWARE] emperador leaked Prefeitura Municipal de Arcos (ransomware.live/emperador)
    Victim: Prefeitura Municipal de Arcos | Group: emperador | Website: arcos.mg.gov.br | Country: BR | Details: We hold complete, unrestricted access to your internal infrastructure. All servers, databases, emails, and admin credentials have been exfiltrated. Critical systems have been encrypted. We have your data. You do not. You have 14 days to respond. No response = data published + permanent loss. Cont

    [5] Download: 2026 Credential Risk Report (HelpNetSecurity)
    85% of cybersecurity professionals consider compromised credentials a primary attack path, yet only 19% continuously monitor active credentials and automatically remediate exposure. The 2026 Credential Risk Report examines where credential security programs fall short and what it takes to move toward Continuous Credential Defense. Learn: Where gaps remain across credential detection, monitoring, and response Why MFA and point-in-time password screening do not fully address credential exposure

    [5] [RANSOMWARE] SilentRansomGroup leaked Troutman Pepper Locke (ransomware.live/SilentRansomGroup)
    Victim: Troutman Pepper Locke | Group: SilentRansomGroup | Country: US | Details: 2nd time we attacked them in a year (first time through physical intrusion), will continue our attacks…

    [5] [RANSOMWARE] securotrop leaked ADL Embedded Solutions (ransomware.live/securotrop)
    Victim: ADL Embedded Solutions | Group: securotrop | Country: US | Details: Status: AWAITING Size: 925 GB

    [5] [RANSOMWARE] SilentRansomGroup leaked T… P… L… (ransomware.live/SilentRansomGroup)
    Victim: T… P… L… | Group: SilentRansomGroup | Details: Redacted entry – full company name pending disclosure (FULL DATA TIMER active).

    [5] [RANSOMWARE] play leaked Coltrane Systems (ransomware.live/play)
    Victim: Coltrane Systems | Group: play | Website: www.coltranesystems.com | Country: US | Details: United States

    [5] [RANSOMWARE] akira leaked Borchert & LaSpina (ransomware.live/akira)
    Victim: Borchert & LaSpina | Group: akira | Details: Borchert & LaSpina, P.C. is a respected law firm located in Queens, New York, with a team of si x experienced attorneys specializing in various areas of law including real estate, mortgage fo reclosure, commercial litigation, personal injury, and elder law. We will upload corporate data soon. Clien

    [5] [RANSOMWARE] shinyhunters leaked Logitech/ Streamlabs (ransomware.live/shinyhunters)
    Victim: Logitech/ Streamlabs | Group: shinyhunters | Website: logitech.com | Country: CH | Details: This is a final warning to reach out by 21 Aug 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 18 Aug 2026 | Warning: FINAL WARNING PAY OR LEAK

    [5] [RANSOMWARE] qilin leaked Berlin Brandenburgische Wohnungsbaugenossenschaft (ransomware.live/qilin)
    Victim: Berlin Brandenburgische Wohnungsbaugenossenschaft | Group: qilin | Website: www.bbwbg.de | Country: DE | Details: N/A

    [5] [RANSOMWARE] gunra leaked BOMOHSA (ransomware.live/gunra)
    Victim: BOMOHSA | Group: gunra | Website: bomohsa.com | Country: HN | Details: Sector: Service Contractor | Revenue: US$ 20,000,000

    [5] [RANSOMWARE] incransom leaked SpearFin Ltd (ransomware.live/incransom)
    Victim: SpearFin Ltd | Group: incransom | Country: MU | Details: SpearFin Ltd https://spearfin.net SpearFin offers a wide range of services including fund administration, corporate services, compliance support, and investor relations. Assets Under Administration US$10 billion. The leak occurred on June 26, 2026. Total leak: 416 GB Leak included: NDA,

    [5] [RANSOMWARE] incransom leaked ssf-int.com ssf-ing.de (ransomware.live/incransom)
    Victim: ssf-int.com ssf-ing.de | Group: incransom | Website: ssf-int.com | Country: DE | Details: SSF International GmbH is an engineering firm headquartered in Munich, Germany. A subsidiary of SSF Ingenieure AG, the company provides comprehensive engineering services in project management, supervision, consultancy, design, quality management, and special construction design worldwide. It specia

    > SUMMARY

    New items collected: 65. Critical items: 1. Active ransomware groups represented today: 1. CVEs to prioritise for review: CVE-2026-33824, CVE-2026-59310, CVE-2026-55040, CVE-2026-65400.

    Sources: BleepingComputer, TheHackerNews, SecurityWeek, HelpNetSecurity, KrebsOnSecurity, CISA KEV, ransomware.live

    Open the companion interactive HTML intelligence report

  • Cybersecurity Intelligence Report — 18 August 2026

    > CRITICAL SECTION

    [12] ⚡ Weekly Recap: VMware Exploits, Windows 0-Day, MCP Attacks, Browser Hijacks and More (TheHackerNews)
    The expensive attacks are not always the clever ones. This week had plenty of proof. Exposed services got hit, old bugs found fresh use, browser sessions became attack paths, and supply-chain problems kept spreading farther than the original compromise. A lot of it came down to access that was already there and defenses that assumed nobody would look too closely. So, nothing magical. Just a

    [11] Suspected China-Nexus Actor Exploits VMware vCenter Flaw, Deploys Babuk-Derived Ransomware (TheHackerNews)
    CVEs: CVE-2026-59310
    Cybersecurity researchers have attributed the exploitation of a newly patched security flaw in Broadcom VMware vCenter to a suspected China-nexus advanced persistent threat (APT). The attacks involve the exploitation of CVE-2026-59310 (CVSS score: 9.8), a severe directory-traversal vulnerability in the VMware vCenter server that could be weaponized by a malicious actor to execute arbitrary code

    [10] GeoServer Zero-Day Targeted in Active Exploitation Attempts, Can Lead to RCE (TheHackerNews)
    A newly disclosed zero-day flaw in GeoServer is seeing active exploitation efforts, per watchTowr. The vulnerability, which has yet to be assigned a CVE identifier, is an SQL injection vulnerability in the open-source platform that can lead to remote code execution (RCE). The security defect remains unpatched. It was first disclosed on August 12, 2026, at 10:46 UTC, by a researcher named @

    [10] Critical SAP Commerce Cloud Vulnerability Exploited 3 Days After Disclosure (SecurityWeek)
    CVEs: CVE-2026-58231
    The vulnerability tracked as CVE-2026-58231 can be exploited to execute arbitrary code and compromise internal components. The post Critical SAP Commerce Cloud Vulnerability Exploited 3 Days After Disclosure appeared first on SecurityWeek .

    > CISA KEV (last 14 days)

    CVE Vendor/Product Score Required action
    CVE-2025-62593 [CISA KEV] CVE-2025-62593: Ray-Project Ray Code Injection Vulnerability – Ray-Project Ray 6 Ray-Project Ray Code Injection Vulnerability – Ray-Project Ray. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders

    > RANSOMWARE VICTIMS (today)

    • AuditTeam: De***up
    • incransom: SD Associates Sdn Bhd, Third Coast Bancshares

    > NEWS

    [8] Forminator WordPress Flaw Can Enable Unauthenticated RCE via Malicious PHP Uploads (TheHackerNews)
    A critical security flaw has been disclosed in Forminator Forms, a WordPress plugin with more than 600,000 active installations, that could be exploited to achieve arbitrary code execution on susceptible sites. The vulnerability, tracked as CVE-2026-15748, is rated 9.8 out of 10.0 on the CVSS scoring system. It was discovered and reported by a security researcher who goes by the online alias "

    [7] Microsoft working on Defender patch for ShieldBreak zero-day (BleepingComputer)
    Microsoft is working on a security patch for the "ShieldBreak" zero-day vulnerability disclosed last week by security researcher "Nightmare Eclipse" and now tracked as CVE-2026-69414. […]

    [7] IAM Compliance Requirements and Best Practices (TheHackerNews)
    IAM compliance is the practice of demonstrating that identity and access controls are not only documented but actually enforced across users, applications, infrastructure, and non-human identities. This guide explains what IAM compliance requires, which regulations matter, and how organizations move from periodic access reviews toward continuous, evidence-backed verification that auditors can

    [7] Attackers exploit patched macOS Screen Sharing flaw to deploy cryptominer (HelpNetSecurity)
    A recently patched security flaw in Apple macOS is being actively exploited by hackers to bypass authentication, gain root access, and install a cryptominer, the Netherlands’ National Cyber Security Centre (NCSC) warns. The vulnerability, tracked as CVE-2026-65400, , let attackers authenticate to macOS Screen Sharing without valid login credentials. Apple fixed the issue with updates to macOS Sequoia (15.7.9), Sonoma (14.8.9), and Tahoe (26.6.1), and advised its macOS users to upgrade their s

    [7] [RANSOMWARE] direwolf leaked Eva AI Limited (ransomware.live/direwolf)
    Victim: Eva AI Limited | Group: direwolf | Website: eva.ai | Country: GB | Details: Human Resources

    [7] [RANSOMWARE] dragonforce leaked Vermont XCenter (ransomware.live/dragonforce)
    Victim: Vermont XCenter | Group: dragonforce | Website: vermont.com.br | Country: BR | Details: A Vermont coloca seus clientes estrategicamente no Centro das Decisões, pois entende que o cliente deve estar no Centro das Atenções. Com isso estabelecido, a companhia acredita que é mais simples interpretar o mercado a partir dos desejos e perspectivas do mesmo. Vermont XCenter: Centro de interAçõ

    [6] Cavern C2 Uses DNS and Google Apps Script to Blend Into Legitimate Traffic (TheHackerNews)
    Cybersecurity researchers have traced the continued evolution of the Cavern (aka Cav3rn) command-and-control (C2) framework used by Iranian nation-state hackers in attacks targeting entities in Israel. Russian cybersecurity company Kaspersky said its ongoing monitoring of the threat activity cluster since December 2025 has led to the discovery of previously unreported components that expand the

    [6] Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5 Proxies (TheHackerNews)
    Cybersecurity researchers have flagged a previously undocumented Linux botnet family dubbed Evooo1Bot that derives its core functionality from the Mirai botnet source code and is equipped to turn internet-facing devices into SOCKS proxies. "While the malware reuses the DDoS engine from the publicly leaked Mirai source code, it extends the original framework with numerous capabilities, including

    [6] Apple macOS Screen Sharing Flaw Exploited on Internet-Exposed Macs to Install Monero Miner (TheHackerNews)
    A recently patched security flaw in Apple macOS has come under active exploitation in the wild to deploy a cryptocurrency miner, the Netherlands National Cyber Security Centre (NCSC-NL) has warned. The vulnerability in question is CVE-2026-65400 (CVSS score: 9.8), a critical authentication issue impacting the Screen Sharing component that could allow an attacker already on the network to

    [5] Philips and GE investigating Clop ransomware data theft claims (BleepingComputer)
    Tech giants General Electric (GE) and Philips have also confirmed they're investigating claims that the Clop ransomware gang breached their systems and stole data. […]

    [5] SAP Commerce Cloud CVE-2026-58231 Targeted in Exploitation Attempts Days After Patch (TheHackerNews)
    A maximum-severity security vulnerability impacting SAP Commerce Cloud is witnessing active exploitation efforts. The vulnerability, tracked as CVE-2026-58231, is rated 10.0 on the CVSS scoring system. It relates to an instance of insufficient authorization checks and input validation. "SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit

    [5] [RANSOMWARE] nightspire leaked T****w**x (ransomware.live/nightspire)
    Victim: T****w**x | Group: nightspire | Details: Data is not available now.

    [5] [RANSOMWARE] insomnia leaked Codinter (ransomware.live/insomnia)
    Victim: Codinter | Group: insomnia | Website: www.codinter.com | Country: US | Details: Private company supplying welding, cutting, finishing products and services across North/Central/South America. Offers equipment, tools, accessories, consumables – from mobile units to robotic systems. Oil industry: pipeline, tanks, refinery, platforms.

    [5] [RANSOMWARE] qilin leaked GSW Gemeinschaftsstadtwerke GmbH (ransomware.live/qilin)
    Victim: GSW Gemeinschaftsstadtwerke GmbH | Group: qilin | Website: www.gsw-kamen.de | Country: DE | Details: N/A

    [5] [RANSOMWARE] qilin leaked White-Daters & Associates, Inc (ransomware.live/qilin)
    Victim: White-Daters & Associates, Inc | Group: qilin | Website: www.whitedaters.com | Country: US | Details: N/A

    [5] [RANSOMWARE] qilin leaked The University of the West Indies (ransomware.live/qilin)
    Victim: The University of the West Indies | Group: qilin | Website: www.uwi.edu | Country: TT | Details: N/A

    [5] [RANSOMWARE] qilin leaked EmpireWorks (ransomware.live/qilin)
    Victim: EmpireWorks | Group: qilin | Website: www.empireworks.com | Details: N/A

    [5] [RANSOMWARE] play leaked Bridgeport Capital Services (ransomware.live/play)
    Victim: Bridgeport Capital Services | Group: play | Website: www.bridgeportcapital.com | Country: US | Details: United States

    [5] [RANSOMWARE] play leaked Sam Pack Auto Group (ransomware.live/play)
    Victim: Sam Pack Auto Group | Group: play | Website: www.sampack.com | Country: US | Details: United States

    [5] [RANSOMWARE] play leaked Woodhaven Association (ransomware.live/play)
    Victim: Woodhaven Association | Group: play | Website: www.woodhavenassociation.com | Country: US | Details: United States

    > SUMMARY

    New items collected: 80. Critical items: 4. Active ransomware groups represented today: 2. CVEs to prioritise for review: CVE-2026-58231, CVE-2026-65400, CVE-2026-59310, CVE-2025-62593, CVE-2026-15748, CVE-2026-69414.

    Sources: BleepingComputer, TheHackerNews, SecurityWeek, HelpNetSecurity, KrebsOnSecurity, CISA KEV, ransomware.live

    Open the companion interactive HTML intelligence report

  • Cybersecurity Intelligence Report — 17 August 2026

    > CRITICAL SECTION

    [12] Week in review: Salesforce and ServiceNow portals exposed for 17 months, exploited Metabase 0-day (HelpNetSecurity)
    Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: GitHub Dependabot malware alerts now cover eight ecosystems GitHub has flagged npm malware since March 2026. Anyone pulling in a bad PyPI, Maven, RubyGems, NuGet, Go, crates.io, or PHP Composer package has had no such warning, because GitHub’s malware detection only ever watched one ecosystem. That changed this month. Dependabot malware alerts, which had run on npm data alone, now … <a href

    > CISA KEV (last 14 days)

    CVE Vendor/Product Score Required action
    No newly collected KEV entries.

    > RANSOMWARE VICTIMS (today)

    No victims timestamped today were present in the collected feed.

    > NEWS

    [7] [RANSOMWARE] emperador leaked Albania's Official National Teacher Training Portal (ransomware.live/emperador)
    Victim: Albania's Official National Teacher Training Portal | Group: emperador | Country: AL | Details: Albania’s official national teacher training portal provides centralized professional development resources and accredited programs for educators nationwide. This leak include data such as; Roughly ~100k Full national ID numbers, full names and teacher certificates in PDF. [Size: 5.9 GB | Sector: E

    [7] [RANSOMWARE] emperador leaked Albania's official national teacher training portal. (ransomware.live/emperador)
    Victim: Albania's official national teacher training portal. | Group: emperador | Country: AL | Details: Albania’s official national teacher training portal provides centralized professional development resources and accredited programs for educators nationwide. This leak include data such as; Roughly ~100k Full national ID numbers, full names and teacher certificates in PDF. [Size: 5.9 GB | Sector: E

    [7] [RANSOMWARE] medusalocker leaked Twal Family IT Lab (ransomware.live/medusalocker)
    Victim: Twal Family IT Lab | Group: medusalocker | Details: Personal IT home lab. AD domain: twalfamily.com. VMware vSphere, multiple AD domains. Daniel Al Twal works at Technology North Corp (Edmonton), former DND co-op. No corporate target. Previously misidentified as Forces/forces.gc.ca. | 4172 Wolfe Point Way, Ottawa, ON K1V 1P5, Canada

    [5] [RANSOMWARE] qilin leaked Teikoku USA (ransomware.live/qilin)
    Victim: Teikoku USA | Group: qilin | Website: www.teikokuusa.com | Country: US | Details: N/A

    [5] [RANSOMWARE] qilin leaked AGUNSA (ransomware.live/qilin)
    Victim: AGUNSA | Group: qilin | Website: www.agunsa.com | Country: CL | Details: N/A

    [5] [RANSOMWARE] qilin leaked Coface (ransomware.live/qilin)
    Victim: Coface | Group: qilin | Website: www.coface.it | Country: IT | Details: N/A

    [5] [RANSOMWARE] qilin leaked Spoonful of Comfort (ransomware.live/qilin)
    Victim: Spoonful of Comfort | Group: qilin | Website: www.spoonfulofcomfort.com | Country: US | Details: N/A

    [5] [RANSOMWARE] Panzer leaked SAGASTA sro (ransomware.live/Panzer)
    Victim: SAGASTA sro | Group: Panzer | Website: sagasta.cz | Country: CZ | Details: SAGASTA is a design and engineering company specializing in modern construction, offering comprehensive design, engineering, and consulting services in the fields of railway, road, bridge, and water management construction.

    [5] [RANSOMWARE] Eclipse leaked Moscord (ransomware.live/Eclipse)
    Victim: Moscord | Group: Eclipse | Website: moscord.com | Country: SG | Details: Moscord is a digital marketplace that connects buyers and sellers in the maritime industry, offering a platform for various suppliers to aggregate and present their products. The company aims to enhance business operations for its clients by providing innovative solutions in procurement, logistics,

    [5] [RANSOMWARE] qilin leaked Mulino Padano (ransomware.live/qilin)
    Victim: Mulino Padano | Group: qilin | Website: www.mulinopadano.it | Country: IT | Details: N/A

    [5] [RANSOMWARE] qilin leaked WEBA Meubelen (ransomware.live/qilin)
    Victim: WEBA Meubelen | Group: qilin | Website: www.weba.be | Country: BE | Details: N/A

    [5] [RANSOMWARE] settra leaked galmack.com.ec (ransomware.live/settra)
    Victim: galmack.com.ec | Group: settra | Website: galmack.com.ec | Country: EC | Details: GALMACK S.A.: Internal Documents of an Ecuadorian Auto Dealership Holding PROLOGUE Inside: monthly b…

    [5] [RANSOMWARE] settra leaked airoyal.biz (ransomware.live/settra)
    Victim: airoyal.biz | Group: settra | Website: airoyal.biz | Details: AIROYAL COMPANY: Internal Documents of an American Industrial Components Distributor PROLOGUE We hav…

    [5] [RANSOMWARE] settra leaked tiltstudio.com (ransomware.live/settra)
    Victim: tiltstudio.com | Group: settra | Website: tiltstudio.com | Country: DE | Details: The Tilt Studio Archives Investigation of a Corporate Archive Leak from an Entertainment Network PRO…

    [5] [RANSOMWARE] medusalocker leaked All Parts Dry Cleaning (ransomware.live/medusalocker)
    Victim: All Parts Dry Cleaning | Group: medusalocker | Website: allpartsdrycleaning.co.uk | Country: GB | Details: Dry cleaning & laundry. Domain: allpartsdrycleaning.co.uk. | United Kingdom

    [5] [RANSOMWARE] medusalocker leaked Idex Group (ransomware.live/medusalocker)
    Victim: Idex Group | Group: medusalocker | Website: idex-group.com | Country: DE | Details: Organization with 30 emails extracted. Domain: idex-group.com

    [5] [RANSOMWARE] medusalocker leaked Bija Industrie (ransomware.live/medusalocker)
    Victim: Bija Industrie | Group: medusalocker | Website: bija-industrie.com | Country: FR | Details: Organization with 693 emails extracted. Domain: bija-industrie.com

    [5] [RANSOMWARE] medusalocker leaked Thecourierguy (ransomware.live/medusalocker)
    Victim: Thecourierguy | Group: medusalocker | Website: thecourierguy.co.za | Country: ZA | Details: Organization with 2018 emails extracted. Domain: thecourierguy.co.za

    [5] [RANSOMWARE] Helix leaked Kennedy Jenks (ransomware.live/Helix)
    Victim: Kennedy Jenks | Group: Helix | Country: US | Details: Kennedy Jenks is live. T1 is unlocked. T2 in 24 hours, then one day each through T4.

    [5] [RANSOMWARE] lockbit5 leaked actua.fr (ransomware.live/lockbit5)
    Victim: actua.fr | Group: lockbit5 | Website: actua.fr | Country: FR | Details: Groupe Actua is a recruitment and temporary staffing agency headquartered in Strasbourg, founded in…

    > SUMMARY

    New items collected: 47. Critical items: 1. Active ransomware groups represented today: 0. CVEs to prioritise for review: none identified in the selected items.

    Sources: BleepingComputer, TheHackerNews, SecurityWeek, HelpNetSecurity, KrebsOnSecurity, CISA KEV, ransomware.live

    Open the companion interactive HTML intelligence report

  • Cybersecurity Intelligence Report — 16 August 2026

    > CRITICAL SECTION

    No new score-10 intelligence items were collected.

    > CISA KEV (last 14 days)

    CVE Vendor/Product Score Required action
    No newly collected KEV entries.

    > RANSOMWARE VICTIMS (today)

    No victims timestamped today were present in the collected feed.

    > NEWS

    [7] [RANSOMWARE] xpl0itrs leaked RapidFort (ransomware.live/xpl0itrs)
    Victim: RapidFort | Group: xpl0itrs | Website: rapidfort.com | Country: US | Details: Software supply chain security

    [5] [RANSOMWARE] xpl0itrs leaked Dynatrace (ransomware.live/xpl0itrs)
    Victim: Dynatrace | Group: xpl0itrs | Website: dynatrace.com | Country: AT | Details: AI observability platform

    [5] [RANSOMWARE] xpl0itrs leaked Oz Hair & Beauty (ransomware.live/xpl0itrs)
    Victim: Oz Hair & Beauty | Group: xpl0itrs | Website: ozhairandbeauty.com | Country: AU | Details: Hair and beauty products

    [5] [RANSOMWARE] xpl0itrs leaked ********* (ransomware.live/xpl0itrs)
    Victim: ********* | Group: xpl0itrs | Details: School management software

    [5] [RANSOMWARE] direwolf leaked DodoPayments (ransomware.live/direwolf)
    Victim: DodoPayments | Group: direwolf | Website: dodopayments.com | Country: IN | Details: Financial Software

    [5] [RANSOMWARE] direwolf leaked AAM:HOA Management (ransomware.live/direwolf)
    Victim: AAM:HOA Management | Group: direwolf | Website: associatedasset.com | Country: US | Details: HOA Management

    [5] [RANSOMWARE] direwolf leaked TOTVS (ransomware.live/direwolf)
    Victim: TOTVS | Group: direwolf | Website: totvs.com | Country: BR | Details: Business Services

    [5] [RANSOMWARE] direwolf leaked Colla Health (ransomware.live/direwolf)
    Victim: Colla Health | Group: direwolf | Website: collahealth.com | Country: US | Details: Healthcare

    [5] [RANSOMWARE] direwolf leaked PayrHealth (ransomware.live/direwolf)
    Victim: PayrHealth | Group: direwolf | Website: payrhealth.com | Country: US | Details: Healthcare

    [5] [RANSOMWARE] direwolf leaked DXS International (ransomware.live/direwolf)
    Victim: DXS International | Group: direwolf | Website: dxs-systems.co.uk | Country: GB | Details: Healthcare

    [5] [RANSOMWARE] ms13089 leaked servmarmg.cl (ransomware.live/ms13089)
    Victim: servmarmg.cl | Group: ms13089 | Website: servmarmg.cl | Country: CL | Details: Empresa con más de 25 años de experiencia en el rubro marítimo, orientada a ejecutar operaciones con estándares de calidad, control de riesgo y tiempos de respuesta consistentes…

    [5] [RANSOMWARE] spacebears leaked SEARS (Grupo Sanborns) (ransomware.live/spacebears)
    Victim: SEARS (Grupo Sanborns) | Group: spacebears | Website: www.sears.com.mx | Country: MX | Details: SEARS (Grupo Sanborns, S.A. de C.V.) is a leading Mexican retail company and a key subsidiary of Grupo Carso, owned by the Slim family.Founded in 1903 by the Sanborn brothers, the company has grown into one of the country’s most iconic and successful retail groups.It owns and operates two of Mexico’

    [5] [RANSOMWARE] securotrop leaked Lepi Enterprises (ransomware.live/securotrop)
    Victim: Lepi Enterprises | Group: securotrop | Website: www.lepienterprises.com | Country: US | Details: Status: AWAITING Size: 692 GB

    [5] [RANSOMWARE] Barracuda leaked VR Advogados (ransomware.live/Barracuda)
    Victim: VR Advogados | Group: Barracuda | Website: vradvogados.com.br | Country: BR | Details: VR Advogados, a Brazilian law firm, neglected its clients’ personal data, violating laws regarding data storage and confidentiality—they posted and shared all of their clients’ documents, passport information, and powers of attorney via a Discord server. We hacked it. Now we have 3,000 documents bel

    > SUMMARY

    New items collected: 15. Critical items: 0. Active ransomware groups represented today: 0. CVEs to prioritise for review: none identified in the selected items.

    Sources: BleepingComputer, TheHackerNews, SecurityWeek, HelpNetSecurity, KrebsOnSecurity, CISA KEV, ransomware.live

    Open the companion interactive HTML intelligence report

  • Cybersecurity Intelligence Report — 15 August 2026

    > CRITICAL SECTION

    [12] Adobe Patches Three CVSS 10.0 ColdFusion and Campaign Classic Flaws (TheHackerNews)
    CVEs: CVE-2026-48362
    Adobe has shipped updates to address multiple critical security vulnerabilities impacting ColdFusion, Commerce, and Campaign Classic that, if successfully exploited, could result in arbitrary code execution and privilege escalation. The most severe of the flaws are listed below – CVE-2026-48362 (CVSS score: 10.0) – An operating system command injection vulnerability in ColdFusion that could

    [12] ⚡ Weekly Recap: AI Goes Rogue, Metabase 0-Day, MCP Supply-Chain Attacks, and Router Backdoors (TheHackerNews)
    A lot of security problems still begin with someone doing a completely normal thing. Cloning a repo. Answering a call. Leaving a box exposed. Trusting the default. That pretty much covers the mood this week. Old bugs are back, supply chains are getting stranger, and some exploit paths are so short you wonder what was supposed to stop them in the first place. That’s only part of it. Here’s

    [12] Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication (TheHackerNews)
    Metabase has warned that a maximum-severity security flaw impacting its business intelligence and data visualization software package has been exploited in the wild as a zero-day. The vulnerability (CVSS score: 10.0), which does not carry a CVE identifier, allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, enabling them to gain

    [10] Cisco ASA and FTD Flaw Exploited in the Wild Can Trigger Remote DoS (TheHackerNews)
    CVEs: CVE-2026-20349
    Cisco has warned that a new vulnerability impacting Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software has been exploited in the wild. The high-severity flaw, tracked as CVE-2026-20349 (CVSS score: 8.6), is a case of insufficient error checking when processing HTTP requests that could allow an unauthenticated, remote attacker to trigger

    [10] BdThemes Supply Chain Attack Poisons JSON to Create Rogue WordPress Admins (TheHackerNews)
    Cybersecurity researchers have warned of a supply chain compromise impacting WordPress plugin vendor BdThemes, prompting the content management systems (CMS) platform's plugins team to temporarily disable their downloads. "Unlike traditional software supply chain attacks, zero source code files were modified within the official WordPress.org repository," Wordfence researcher Paolo Tresso said.

    [10] Hackers Exploiting Unpatched GeoServer Zero-Day (SecurityWeek)
    The security defect is described as an SQL injection that could allow attackers to achieve remote code execution. The post Hackers Exploiting Unpatched GeoServer Zero-Day appeared first on SecurityWeek .

    [10] [RANSOMWARE] chaos leaked tomorrowsoffice.com (ransomware.live/chaos)
    Victim: tomorrowsoffice.com | Group: chaos | Website: tomorrowsoffice.com | Country: GB | Details: URGENT DATA LEAK NOTICE: TOMORROW'S OFFICE Target: Tomorrow’s Office (tomorrowsoffice.com) Status: Ongoing Data Publication Countdown Security researchers have successfully exfiltrated 125 GB of critical and confidential data from the internal infrastructure of Tomorrow’s Office (tomorrowsoff…

    > CISA KEV (last 14 days)

    CVE Vendor/Product Score Required action
    CVE-2026-18556 [CISA KEV] CVE-2026-18556: N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability – N-able N-central 10 N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability – N-able N-central. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product
    CVE-2026-20349 [CISA KEV] CVE-2026-20349: Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Heap Inspection Vulnerability – Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) 6 Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Heap Inspection Vulnerability – Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) . Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requ
    CVE-2026-68820 [CISA KEV] CVE-2026-68820: Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability – Microsoft Windows Ancillary Function Driver for WinSock 6 Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability – Microsoft Windows Ancillary Function Driver for WinSock . Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud servic
    CVE-2026-72898 [CISA KEV] CVE-2026-72898: Metabase SQL Injection Vulnerability – Metabase Metabase 6 Metabase SQL Injection Vulnerability – Metabase Metabase. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are r
    CVE-2026-8037 [CISA KEV] CVE-2026-8037: Progress LoadMaster Command Injection Vulnerability – Progress LoadMaster 6 Progress LoadMaster Command Injection Vulnerability – Progress LoadMaster. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. S
    CVE-2026-63077 [CISA KEV] CVE-2026-63077: JetBrains TeamCity Deserialization of Untrusted Data Vulnerability – JetBrains TeamCity 6 JetBrains TeamCity Deserialization of Untrusted Data Vulnerability – JetBrains TeamCity. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are
    CVE-2026-34486 [CISA KEV] CVE-2026-34486: Apache Tomcat Missing Encryption of Sensitive Data Vulnerability – Apache Tomcat 6 Apache Tomcat Missing Encryption of Sensitive Data Vulnerability – Apache Tomcat. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavail
    CVE-2026-9198 [CISA KEV] CVE-2026-9198: IBM Langflow Code Injection Vulnerability – IBM Langflow 6 IBM Langflow Code Injection Vulnerability – IBM Langflow. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are r

    > RANSOMWARE VICTIMS (today)

    • Panzer: Alpine Electronics Europe
    • anubis: Interim HealthCare
    • blackwater: www.amca.org.ar, www.shalina.com

    > NEWS

    [9] Microsoft patches LegacyHive Windows zero-day vulnerability (BleepingComputer)
    Microsoft has released security patches to address a Windows zero-day vulnerability known as "LegacyHive," disclosed after the July 2026 Patch Tuesday. […]

    [9] Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor (TheHackerNews)
    The North Korean threat actor known as Lazarus Group has been attributed to the zero-day exploitation of a newly patched security flaw impacting Microsoft Windows to deliver a never-before-seen backdoor targeting defense and aerospace companies across France, Germany, Brazil, and India. The activity, per Check Point Research, is part of Operation Dream Job, a long-running cyber espionage and

    [9] DeadLock Ransomware Uses Polygon Smart Contracts to Make Extortion Infra Harder to Disrupt (TheHackerNews)
    The ransomware group known as DeadLock has been observed using decentralized infrastructure to facilitate victim communications and data leak operations in a bid to improve operational resilience. "Its recovery ecosystem combines the Session messaging network with blockchain-backed services that store and deliver resources used throughout the extortion process," the Microsoft Threat

    [9] [RANSOMWARE] shinyhunters leaked Baxter International, Inc. (ransomware.live/shinyhunters)
    Victim: Baxter International, Inc. | Group: shinyhunters | Website: baxter.com | Country: US | Details: Over 7.1M Salesforce records containing some PII was compromised. This is a final warning to reach out by 17 Aug 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 14 Aug 2026 | Warning: FINAL WARN

    [9] [RANSOMWARE] shinyhunters leaked Ali** ********** (ransomware.live/shinyhunters)
    Victim: Ali** ********** | Group: shinyhunters | Details: August 7, 2026 3:00 PM ET: Over 11.5 million records across Salesforce, ServiceNow, and Entra containing some PII of customers and employees and 3.1TB+ of internal corporate data was compromised. This is a final warning to reach out by 10 August 2026 before we leak along with several annoying (digit

    [8] Critical VMware vCenter RCE flaw exploited for reverse SSH access (BleepingComputer)
    A recently patched critical vulnerability (CVE-2026-59310) in VMware vCenter Syslog Server is being exploited in an active campaign to deploy a reverse SSH tool for persistence and remote access. […]

    [8] Attackers Exploit SharePoint Authentication Bypass After Public PoC Release (TheHackerNews)
    Threat actors have begun to exploit a newly disclosed Microsoft SharePoint vulnerability following the release of a proof-of-concept (PoC) code. The vulnerability in question is CVE-2026-55040 (CVSS score: 9.1), which refers to a critical security feature bypass that stems from weak authentication. It was patched by Microsoft as part of its July 2026 Patch Tuesday updates. "The authentication

    [8] Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access (TheHackerNews)
    Threat actors have begun to actively exploit a recently patched critical security flaw in Broadcom VMware vCenter, according to new findings from QUIRSO. The vulnerability in question is CVE-2026-59310 (CVSS score: 9.8), a directory-traversal vulnerability in the VMware vCenter server that a malicious actor with network access can exploit to execute arbitrary code. Patches for the flaw were

    [8] Gunra Ransomware Exploits Fortinet FortiOS, FortiProxy Flaws to Breach Networks (TheHackerNews)
    Cybersecurity and intelligence agencies from South Korea and the U.S. warned of Gunra ransomware attacks targeting critical infrastructure sectors and organizations across the world. Targets of these attacks include healthcare and public health, financial services, government services and facilities, and professional and nonprofit services. "Gunra is another variant in the ongoing trend of

    [8] Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer (TheHackerNews)
    A cluster of nearly 800 malicious packages has been published to the npm registry as part of a new campaign designed to deliver cross-platform malware targeting Windows, Mac, and Linux systems. "These packages appear to use AI slop squatted, or randomly generated typo-squatting package names, but all of them deliver a powerful RAT and infostealer payload," OpenSourceMalware researcher Paul

    [8] AI-Assisted HTTP Terminator Finds Novel HTTP Desync Techniques and Apache Zero-Day (TheHackerNews)
    PortSwigger says HTTP Terminator, an artificial intelligence (AI)-assisted research system built by James Kettle, generated and proved new HTTP desynchronization techniques after exploring 30,000 candidate desync vectors. PortSwigger said a separate human-guided discovery cascade also exposed a zero-day in Apache Traffic Server. Kettle said HTTP Terminator tested 30,000 websites where

    [8] [RANSOMWARE] blacknevas leaked Arkın Group / Arkın Casino, The Arkın Colony, The Arkın Iskele, and Arkın Palm Beach (ransomware.live/blacknevas)
    Victim: Arkın Group / Arkın Casino, The Arkın Colony, The Arkın Iskele, and Arkın Palm Beach | Group: blacknevas | Website: arkingroup.com | Country: TR | Details: CYBERSECURITY: ARKIN HOTEL GROUP SUFFERS MASSIVE DATA BREACH — OVER 1 TB OF GUEST AND CASINO DATA STOLENCybersecurity experts from Cyclops Threat Intelligence have reported a critical incident affecting the Arkın Group hotel chain (www.arkingroup.com), including its premium properties The Arkın Colo

    [7] 737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One (TheHackerNews)
    A massive set of 737 free VPN and proxy extensions have been found to mainly target Russian-speaking users seeking access to blocked services with an aim to intercept browser traffic and route them through a proxy infrastructure. The extensions, published across at least 40 Chrome Web Store developer accounts, racked up 75,486 installs. Of those identified, 274 have been found to impersonate 66

    [7] ShieldBreak Zero-Day PoC Claims Microsoft Defender Patch Bypass With SYSTEM Access (TheHackerNews)
    The security researcher going by the name Chaotic Eclipse (aka INFINITE NIGHTMARE, MSNightmare, and Nightmare-Eclipse) has released a proof-of-concept (PoC) for a new Microsoft zero-day called ShieldBreak. The vulnerability, rooted in Microsoft Defender for Windows, demonstrates a patch bypass for CVE-2026-50656 (CVSS score: 7.8), otherwise known as RoguePlanet. RoguePlanet has been described

    [7] Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack (TheHackerNews)
    Microsoft released its monthly security updates on Tuesday, and one of the flaws it closed is already being used in attacks. The bug sits in a core Windows kernel driver that handles network socket operations. An attacker with code already running on a machine can use it to escalate to SYSTEM. That patch goes out first. The flaw is tracked as CVE-2026-68820 (CVSS score: 7.0) and is the only

    [7] Sandworm-Linked UAC-0145 Uses Fake Job Interviews to Push VPN That Can Run Commands (TheHackerNews)
    The Computer Emergency Response Team of Ukraine (CERT-UA) has disclosed details of a new social engineering campaign orchestrated by Russian nation-state threat actors targeting IT workers in the country by masquerading as recruiters to trick them into installing malware. CERT-UA pinned the activity on a threat cluster it tracks as UAC-0145, which is a subgroup within Sandworm (aka APT44,

    [7] Adobe Commerce Bug Targeted Immediately After Disclosure (SecurityWeek)
    The first exploitation attempts targeting CVE-2026-71362 were observed shortly after Adobe released patches. The post Adobe Commerce Bug Targeted Immediately After Disclosure appeared first on SecurityWeek .

    [7] [RANSOMWARE] coinbasecartel leaked Turner and Townsend (ransomware.live/coinbasecartel)
    Victim: Turner and Townsend | Group: coinbasecartel | Website: turnerandtownsend.com | Country: GB | Details: [AI generated] Turner and Townsend is a global professional services company headquartered in the United Kingdom. Founded in 1946, it operates in the construction, real estate, infrastructure, and natural resources sectors. The firm provides project management, cost management, and programme managem

    [7] [RANSOMWARE] rhysida leaked Pierce Township (ransomware.live/rhysida)
    Victim: Pierce Township | Group: rhysida | Website: piercetownship.org | Country: US | Details: Pierce Township Pierce Township is a growing community in Ohio that blends rural charm with suburban living, covering 23.5 square miles and home to over 16,000 residents.We are pleased to present:Judicial materials – Grand Jury subpoena response incl. hospital records (Mercy Hospital), public record

    [7] [RANSOMWARE] thegentlemen leaked Avanta Maroc Ex Adecco (ransomware.live/thegentlemen)
    Victim: Avanta Maroc Ex Adecco | Group: thegentlemen | Website: avanta.ma | Country: MA | Details: avanta.ma rocketreach.co/avanta-maroc-ex-adecco-profile_b7352c87c4297b95 Avanta Maroc, formerly known as Adecco Maroc, is a prominent human resources and recruitment agency based in Casablanca, Morocco. The company specializes in connecting job seekers with top employers by offering tailored workfo

    > SUMMARY

    New items collected: 619. Critical items: 7. Active ransomware groups represented today: 3. CVEs to prioritise for review: CVE-2026-20349, CVE-2026-68820, CVE-2026-59310, CVE-2026-48362, CVE-2026-18556, CVE-2026-72898, CVE-2026-8037, CVE-2026-63077, CVE-2026-34486, CVE-2026-9198.

    Sources: BleepingComputer, TheHackerNews, SecurityWeek, HelpNetSecurity, KrebsOnSecurity, CISA KEV, ransomware.live

    Open the companion interactive HTML intelligence report

  • Cybersecurity Intelligence Report — 2026-08-04

    Cybersecurity Report 2026-08-04

    Cybersecurity Intelligence Report — 2026-08-04

    CRITICAL SECTION

    [10]

    [CISA KEV] CVE-2026-18577: N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability – N-able N-central (CISA KEV)

    CVEs: CVE-2026-18577

    N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability – N-able N-central. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.. Due: 2026-08-06

    [10]

    [RANSOMWARE] dragonforce leaked TUI China (ransomware.live/dragonforce)

    Victim: TUI China | Group: dragonforce | Website: tui.cn | Country: CN | Details: An affiliate of TUI Group, the world's number one leisure tourism business, TUI China was established in late 2003 as the first joint venture with foreign majority share in the Chinese tourism industry.
    Passports, visas, internal documentation, legal and financial documents, etc.

    CISA KEV (last 14 days)

    CVE Vendor/Product Score Required Action
    CVE-2026-18577 [CISA KEV] CVE-2026-18577: N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability – N-able N-central 10 N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability – N-able N-central. Required action: Apply mitigations in accordance with vendor instruction

    RANSOMWARE VICTIMS (today)

    dragonforce: [RANSOMWARE] dragonforce leaked TUI China, [RANSOMWARE] dragonforce leaked Baicizhan
    incransom: [RANSOMWARE] incransom leaked clintonhealthaccess.org, [RANSOMWARE] incransom leaked Oleoductos del Valle
    qilin: [RANSOMWARE] qilin leaked Universitatea De Vest Vasile Goldi Din Arad, [RANSOMWARE] qilin leaked Service Electric, [RANSOMWARE] qilin leaked Freedom Claims Management
    safepay: [RANSOMWARE] safepay leaked pradotuylaw.com, [RANSOMWARE] safepay leaked naskdoorinc.com, [RANSOMWARE] safepay leaked new-point.it, [RANSOMWARE] safepay leaked simonrack.com, [RANSOMWARE] safepay leaked hanan-hov.co.il, [RANSOMWARE] safepay leaked azn.co.jp, [RANSOMWARE] safepay leaked southshorerecycling.com, [RANSOMWARE] safepay leaked cpu-ag.com, [RANSOMWARE] safepay leaked multiaqua.com
    anubis: [RANSOMWARE] anubis leaked BLACKBURN'S, [RANSOMWARE] anubis leaked Cameron Regional Medical Center, [RANSOMWARE] anubis leaked Winn-Dixie
    ransomhouse: [RANSOMWARE] ransomhouse leaked PCL Holding
    akira: [RANSOMWARE] akira leaked Albers Mechanical Contractors, [RANSOMWARE] akira leaked Belasco Electric
    lockbit5: [RANSOMWARE] lockbit5 leaked sirsa.it, [RANSOMWARE] lockbit5 leaked sms-sme.com, [RANSOMWARE] lockbit5 leaked adventusasia.com, [RANSOMWARE] lockbit5 leaked pcclimitedindia.com, [RANSOMWARE] lockbit5 leaked delkartindustries.com, [RANSOMWARE] lockbit5 leaked micropack.com.ar, [RANSOMWARE] lockbit5 leaked setic-pourtier.com, [RANSOMWARE] lockbit5 leaked microphase.com, [RANSOMWARE] lockbit5 leaked rai.com.br
    payload: [RANSOMWARE] payload leaked Hans & Jos. Kronenberg GmbH

    NEWS

    [8]

    Hugging Face Diffusers Flaws Could Let Model Repositories Execute Arbitrary Code (TheHackerNews)

    Three high-severity security flaws have been disclosed in Hugging Face's Diffusers library that could allow crafted model repositories to stealthily execute arbitrary code on machines that load it, opening the artificial intelligence (AI) supply chain to security risk.

    "These vulnerabilities are bypassing trust_remote_code, the safeguard designed to stop unreviewed code from running in the

    [7]

    18 Malicious npm Packages Deliver Cross-Platform RAT to Alibaba Tool Users (TheHackerNews)

    Cybersecurity researchers have discovered a new set of malicious npm packages that target users of Alibaba developer tools with a cross-platform remote access trojan (RAT) as part of a sophisticated, targeted software supply chain attack targeting Chinese-speaking environments.

    One of the packages in question is "lib-mtop," an unscoped package with the same name as a private Alibaba package

    [7]

    N‑able Patches Vulnerability Exploited to Hack N-central Servers (SecurityWeek)

    <p>The N‑central vulnerability CVE-2026-18577 has been exploited in the wild after threat actors found a patch bypass.</p>
    <p>The post <a href="https://www.securityweek.com/n-able-patches-vulnerability-exploited-to-hack-n-central-servers/">N‑able Patches Vulnerability Exploited to Hack N-central Servers</a> appeared first on <a href="https://www.securityweek.com">SecurityWeek</a>.</p>

    [7]

    [RANSOMWARE] dragonforce leaked Baicizhan (ransomware.live/dragonforce)

    Victim: Baicizhan | Group: dragonforce | Website: www.baicizhan.com | Country: CN | Details: Baicizhan is a language learning platform specializing in English instruction. It offers a wide range of tools and resources designed to help users overcome the challenges of learning English.

    [5]

    Hotel Wi-Fi attacks use custom malware to breach Microsoft 365 accounts (BleepingComputer)

    Microsoft has linked a global campaign targeting hospitality Wi-Fi networks to the Russian threat actor Midnight Blizzard, also known as APT29. […]

    [5]

    N-able warns of N-central auth bypass flaw exploited in attacks (BleepingComputer)

    N-able is warning customers that hackers are exploiting an authentication bypass vulnerability (CVE-2026-18577) affecting both hosted and on-premises N-central servers. […]

    [5]

    INC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 Flaws (TheHackerNews)

    The INC Ransomware operation has emerged as the "dominant threat actor" exploiting the recently disclosed security flaws in SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances.

    In a report published over the weekend, Resecurity said it observed the INC Ransomware accelerating its activity since the beginning of August 2026, listing multiple victims on its data leak site. Per

    [5]

    N-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incomplete (TheHackerNews)

    N-able said attackers exploited an authentication bypass in N-central to gain remote administrative access and reach the customer systems managed through those servers.

    Its first fix was incomplete. CVE-2026-18577 affects N-central builds prior to 2026.3.1.7. N-able shipped build 2026.3.1.7 on August 2 as the first unaffected version.

    N-central is the remote monitoring and management platform

    [5]

    Russian State APT Linked to Recent Public Wi-Fi Gateway Hacking (SecurityWeek)

    <p>Midnight Blizzard has been stealing Microsoft account credentials via compromised Wi-Fi networks at hospitality organizations.</p>
    <p>The post <a href="https://www.securityweek.com/russian-state-apt-linked-to-recent-public-wi-fi-gateway-hacking/">Russian State APT Linked to Recent Public Wi-Fi Gateway Hacking</a> appeared first on <a href="https://www.securityweek.com">SecurityWeek</a>.</p>

    [5]

    Attackers exploit N-able N-central flaw to reach managed endpoints (CVE-2026-18577) (HelpNetSecurity)

    <p>Attackers are exploiting an authentication bypass vulnerability (CVE-2026-18577) in N-able N-central, a remote monitoring and management (RMM) solution widely used by managed service providers, to gain access to managed endpoints. How the flaw was discovered &#8220;On July 31, 2026, N‑able saw an increase in licensing issues for our on-premises N‑central customers. Licensing issues are not uncommon, but the volume was high and the engineering and security teams were engaged,&#8221; N-able sha

    [5]

    [RANSOMWARE] incransom leaked clintonhealthaccess.org (ransomware.live/incransom)

    Victim: clintonhealthaccess.org | Group: incransom | Website: clintonhealthaccess.org | Country: US | Details: This Clinton foundation sponsors the sterilization of women in Africa and South America.
    With the help of this foundation, organs harvested criminally by transplant surgeons from people in Third World countries are legalized to improve the quality of life of the rich in capitalist countries, includ

    [5]

    [RANSOMWARE] incransom leaked Oleoductos del Valle (ransomware.live/incransom)

    Victim: Oleoductos del Valle | Group: incransom | Country: AR | Details: During the analysis of data obtained from Oldelval, we have compiled information covering key aspects of the company's operations. The materials include:

    1.HR documentation: full payroll data, bank account details (CBU), employee health insurance records (OSDE, SWISS MEDICAL), as well as severanc

    [5]

    [RANSOMWARE] qilin leaked Universitatea De Vest Vasile Goldi Din Arad (ransomware.live/qilin)

    Victim: Universitatea De Vest Vasile Goldi Din Arad | Group: qilin | Website: www.uvvg.ro | Country: RO | Details: N/A

    [5]

    [RANSOMWARE] safepay leaked pradotuylaw.com (ransomware.live/safepay)

    Victim: pradotuylaw.com | Group: safepay | Website: pradotuylaw.com | Country: US | Details: The firm focuses on practice areas including personal injury, wrongful death, workplace harassment, business litigation, civil settlements, and environmental litigation. …

    [5]

    [RANSOMWARE] safepay leaked naskdoorinc.com (ransomware.live/safepay)

    Victim: naskdoorinc.com | Group: safepay | Website: naskdoorinc.com | Country: US | Details: Headquartered in West Chester, Pennsylvania, the company has served customers throughout southeastern Pennsylvania and northern Delaware for several decades. Although …

    [5]

    [RANSOMWARE] safepay leaked new-point.it (ransomware.live/safepay)

    Victim: new-point.it | Group: safepay | Website: new-point.it | Country: IT | Details: Headquartered in Signa, Florence, Italy, the company was founded in 2006 and has grown into one of Italy's established suppliers …

    [5]

    [RANSOMWARE] safepay leaked simonrack.com (ransomware.live/safepay)

    Victim: simonrack.com | Group: safepay | Website: simonrack.com | Country: ES | Details: Headquartered in Alfamén, Zaragoza, Spain, the company has been manufacturing metal shelving since 1964 and has become one of Europe's …

    [5]

    [RANSOMWARE] safepay leaked hanan-hov.co.il (ransomware.live/safepay)

    Victim: hanan-hov.co.il | Group: safepay | Website: hanan-hov.co.il | Country: IL | Details: Headquartered in Neve Yamin, Israel, the company provides comprehensive logistics support for construction, infrastructure, industrial, and commercial projects throughout the …

    [5]

    [RANSOMWARE] anubis leaked BLACKBURN'S (ransomware.live/anubis)

    Victim: BLACKBURN'S | Group: anubis | Website: blackburnsmed.com | Country: US | Details: Major home healthcare provider data breach.

    [5]

    [RANSOMWARE] anubis leaked Cameron Regional Medical Center (ransomware.live/anubis)

    Victim: Cameron Regional Medical Center | Group: anubis | Website: cameronregional.org | Country: US | Details: Patient and employee data breach at a healthcare provider.

    [5]

    [RANSOMWARE] safepay leaked azn.co.jp (ransomware.live/safepay)

    Victim: azn.co.jp | Group: safepay | Website: azn.co.jp | Country: JP | Details: Founded in 1991, the company specializes in comprehensive asset management, inheritance planning, business succession consulting, real estate advisory services, and …

    [5]

    [RANSOMWARE] safepay leaked southshorerecycling.com (ransomware.live/safepay)

    Victim: southshorerecycling.com | Group: safepay | Website: southshorerecycling.com | Country: US | Details: The company specializes in metal recycling, concrete and asphalt recycling, aggregate production, and construction waste processing for commercial, industrial, and …

    [5]

    [RANSOMWARE] safepay leaked cpu-ag.com (ransomware.live/safepay)

    Victim: cpu-ag.com | Group: safepay | Website: cpu-ag.com | Country: DE | Details: Founded in 1981 and headquartered in Friedberg, Bavaria, the company has more than four decades of experience developing specialized software …

    [5]

    [RANSOMWARE] safepay leaked multiaqua.com (ransomware.live/safepay)

    Victim: multiaqua.com | Group: safepay | Website: multiaqua.com | Country: US | Details: Founded in 1999, the company specializes in the design, engineering, and production of air-cooled water chillers, heat pump chillers, hydronic …

    [5]

    [RANSOMWARE] anubis leaked Winn-Dixie (ransomware.live/anubis)

    Victim: Winn-Dixie | Group: anubis | Website: winndixie.com | Country: US | Details: Inside a multibillion-dollar retail giant.

    [5]

    [RANSOMWARE] ransomhouse leaked PCL Holding (ransomware.live/ransomhouse)

    Victim: PCL Holding | Group: ransomhouse | Website: www.pclholding.com | Country: CA | Details: PCL Holding Public Company Limited is a Thai-based holding entity operating as a premier importer and distributor of diagnostic instruments, reagents, and consumables for medical and research laboratories. The company manages a comprehensive portfolio of products across hematology, chemistry, immuno

    [5]

    [RANSOMWARE] qilin leaked Service Electric (ransomware.live/qilin)

    Victim: Service Electric | Group: qilin | Website: www.secv.com | Country: US | Details: N/A

    [5]

    [RANSOMWARE] akira leaked Albers Mechanical Contractors (ransomware.live/akira)

    Victim: Albers Mechanical Contractors | Group: akira | Website: albersmechanicalcontractors.com | Country: US | Details: Albers Mechanical Contractors specializes in custom fabrication, welding, stainless steel fabri
    cation, and dust collection HVAC solutions. With over 54 years of experience, they provide desi
    gn and on-site consultations, positioning themselves as leaders in facility solutions.

    We will upload 30gb

    [5]

    [RANSOMWARE] akira leaked Belasco Electric (ransomware.live/akira)

    Victim: Belasco Electric | Group: akira | Website: belascoelectric.com | Country: US | Details: Belasco Electric is a reliable electrical service provider based in Muskegon, Michigan, caterin
    g to both residential and commercial clients. They offer a wide range of services including eme
    rgency generator systems, fire alarm security systems, HVAC wiring, and EV installation.

    We will upload 16g

    [5]

    [RANSOMWARE] lockbit5 leaked sirsa.it (ransomware.live/lockbit5)

    Victim: sirsa.it | Group: lockbit5 | Website: sirsa.it | Country: IT | Details: SIRSA operates in the field of processing and molding plastic materials, offering concrete, safe, an…

    [5]

    [RANSOMWARE] lockbit5 leaked sms-sme.com (ransomware.live/lockbit5)

    Victim: sms-sme.com | Group: lockbit5 | Website: sms-sme.com | Country: RO | Details: SMS-SME is a global leader in marine cargo access and securing equipment, specializing in RORO equip…

    [5]

    [RANSOMWARE] lockbit5 leaked adventusasia.com (ransomware.live/lockbit5)

    Victim: adventusasia.com | Group: lockbit5 | Website: adventusasia.com | Country: SG | Details: Adventus is a Top-Rated Information and Communications Technology (ICT) Solutions and Services Provi…

    [5]

    [RANSOMWARE] lockbit5 leaked pcclimitedindia.com (ransomware.live/lockbit5)

    Victim: pcclimitedindia.com | Group: lockbit5 | Website: pcclimitedindia.com | Country: IN | Details: PIONEER COLDSTORE & CLADDING PVT. LTD. (PCC) is Leading Manufactures of insulated Panels for Coldsto…

    [5]

    [RANSOMWARE] lockbit5 leaked delkartindustries.com (ransomware.live/lockbit5)

    Victim: delkartindustries.com | Group: lockbit5 | Website: delkartindustries.com | Details: Delkart Industries Limited specializes in manufacturing high-quality custom felts, automobile carpet…

    [5]

    [RANSOMWARE] lockbit5 leaked micropack.com.ar (ransomware.live/lockbit5)

    Victim: micropack.com.ar | Group: lockbit5 | Website: micropack.com.ar | Country: AR | Details: Micropack is a well-known food and household goods distributor that has been serving businesses and…

    [5]

    [RANSOMWARE] lockbit5 leaked setic-pourtier.com (ransomware.live/lockbit5)

    Victim: setic-pourtier.com | Group: lockbit5 | Website: setic-pourtier.com | Country: FR | Details: Consolidating gains and preparing the future, Setic, Pourtier C2S help you to stay ahead of the prod…

    [5]

    [RANSOMWARE] lockbit5 leaked microphase.com (ransomware.live/lockbit5)

    Victim: microphase.com | Group: lockbit5 | Website: microphase.com | Country: US | Details: Microphase Corporation is an innovative and trusted customer-driven supplier of advanced electronic…

    [5]

    [RANSOMWARE] lockbit5 leaked rai.com.br (ransomware.live/lockbit5)

    Victim: rai.com.br | Group: lockbit5 | Website: rai.com.br | Country: BR | Details: Grupo Rái is one of the largest independent communication groups in Brazil, consisting of six specia…

    [5]

    [RANSOMWARE] payload leaked Hans & Jos. Kronenberg GmbH (ransomware.live/payload)

    Victim: Hans & Jos. Kronenberg GmbH | Group: payload | Website: kronenberg-gmbh.de | Country: DE | Details: Hans & Jos. Kronenberg GmbH is a German company founded in 1932 and based in Bergisch Gladbach. It specializes in the development and manufacturing of high-quality components for the elevator industry and mechanical engineering, including door locks, switches, control panels, and LED lighting.

    [5]

    [RANSOMWARE] qilin leaked Freedom Claims Management (ransomware.live/qilin)

    Victim: Freedom Claims Management | Group: qilin | Website: www.freedomclaimsinc.com | Country: US | Details: N/A

    SUMMARY

    Summary

    Total new items: 70
    Critical items: 2
    CISA KEV count: 1
    Ransomware victim groups today: 9

    Companion HTML report: https://liberpulse.com/wp-content/uploads/2026/08/cyber_report_2026-08-04.html

  • Cybersecurity Intelligence Report – 2026-08-03

    CISA KEV

    No CISA KEV items in the last 14 days.

    RANSOMWARE VICTIMS (DLS Monitoring)

    • [RANSOMWARE]: Victim: Alcon Inc. | Group: shinyhunters | Website: alcon.com | Country: CH | Details: Over 25 million Salesforce records containing some PII was compromised.

      This is a final warning to reach out by 4 August 2026 before we leak along with several annoying (digital) problems that’ll come your way. Make the right decision, don’t be the next headline., Victim: Questel SAS | Group: shinyhunters | Website: questel.com | Country: FR | Details: Over 21 million Salesforce records containing some PII and 147GB+ of internal corporate data was compromised.

      This is a final warning to reach out by 4 August 2026 before we leak along with several annoying (digital) problems that’ll come your way. Make the right decision, don’t be the next headl, Victim: www.prohealth.sg | Group: krybit | Website: www.prohealth.sg | Country: SG | Details: ProHealth Medical Group Pte Ltd is a Singaporean private primary healthcare group founded in the 1990s, headquartered at…, Victim: ecfa.org | Group: incransom | Website: ecfa.org | Country: US | Details: The Evangelical Council for Financial Accountability (ECFA) is an American accreditation agency founded in 1979 that certifies Christian churches and nonprofits based on financial integrity, board governance, and transparent fundraising. It represents over 2,700 member organizations with billions in, Victim: INTERTRUST AUSTRALIA PTY LTD | Group: qilin | Website: www.seedoutsourcing.com | Country: AU | Details: N/A, Victim: Asset Flooring Group Australia | Group: qilin | Website: www.assetflooring.com.au | Country: AU | Details: N/A, Victim: Mairie de Drancy | Group: qilin | Website: www.drancy.fr | Country: FR | Details: N/A, Victim: www.dcpartner.co.za | Group: krybit | Website: www.dcpartner.co.za | Country: ZA | Details: DC Partner (Pty) Ltd is a South African market-leading Payment Distribution Agency (PDA), one of only four NCR-accredite…

    NEWS

    • [9] [RANSOMWARE] shinyhunters leaked Alcon Inc. — Victim: Alcon Inc. | Group: shinyhunters | Website: alcon.com | Country: CH | Details: Over 25 million Salesforce records containing some PII was compromised.

      This is a final warning to reach out by 4 August 2026 before we leak along with several annoying (digital) problems that’ll come your way. Make the right decision, don’t be the next headline. source

    • [9] [RANSOMWARE] shinyhunters leaked Questel SAS — Victim: Questel SAS | Group: shinyhunters | Website: questel.com | Country: FR | Details: Over 21 million Salesforce records containing some PII and 147GB+ of internal corporate data was compromised.

      This is a final warning to reach out by 4 August 2026 before we leak along with several annoying (digital) problems that’ll come your way. Make the right decision, don’t be the next headl source

    • [6] Week in review: Claude breached three companies during tests, AD CS domain-takeover PoC released —

      Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Nono: Open-source sandbox for AI agents AI coding agents run with the same permissions as their users, meaning they can access sensitive files, credentials, and production systems. A prompt injection, hallucinated command, or simple mistake can quickly turn that access into a security incident. To reduce the risk, Luke Hinds and Stephen Parkinson co-founded nolabs and released Nono, an open-sourc source

    • [5] [RANSOMWARE] krybit leaked www.prohealth.sg — Victim: www.prohealth.sg | Group: krybit | Website: www.prohealth.sg | Country: SG | Details: ProHealth Medical Group Pte Ltd is a Singaporean private primary healthcare group founded in the 1990s, headquartered at… source
    • [5] [RANSOMWARE] incransom leaked ecfa.org — Victim: ecfa.org | Group: incransom | Website: ecfa.org | Country: US | Details: The Evangelical Council for Financial Accountability (ECFA) is an American accreditation agency founded in 1979 that certifies Christian churches and nonprofits based on financial integrity, board governance, and transparent fundraising. It represents over 2,700 member organizations with billions in source
    • [5] [RANSOMWARE] qilin leaked INTERTRUST AUSTRALIA PTY LTD — Victim: INTERTRUST AUSTRALIA PTY LTD | Group: qilin | Website: www.seedoutsourcing.com | Country: AU | Details: N/A source
    • [5] [RANSOMWARE] qilin leaked Asset Flooring Group Australia — Victim: Asset Flooring Group Australia | Group: qilin | Website: www.assetflooring.com.au | Country: AU | Details: N/A source
    • [5] [RANSOMWARE] qilin leaked Mairie de Drancy — Victim: Mairie de Drancy | Group: qilin | Website: www.drancy.fr | Country: FR | Details: N/A source
    • [5] [RANSOMWARE] krybit leaked www.dcpartner.co.za — Victim: www.dcpartner.co.za | Group: krybit | Website: www.dcpartner.co.za | Country: ZA | Details: DC Partner (Pty) Ltd is a South African market-leading Payment Distribution Agency (PDA), one of only four NCR-accredite… source
    • [5] [RANSOMWARE] krybit leaked nigeria.asa-international.com — Victim: nigeria.asa-international.com | Group: krybit | Website: nigeria.asa-international.com | Country: NG | Details: ASHA Microfinance Bank Limited (ASA Nigeria) is a Nigerian for-profit deposit-taking microfinance institution, a fully l… source
    • [5] [RANSOMWARE] krybit leaked www.ville-rinxent.fr — Victim: www.ville-rinxent.fr | Group: krybit | Website: www.ville-rinxent.fr | Country: FR | Details: Mairie de Rinxent (Municipality of Rinxent) is the official website of the town hall (mairie) of Rinxent, a small French… source
    • [5] [RANSOMWARE] krybit leaked countrymotors.com.mx — Victim: countrymotors.com.mx | Group: krybit | Website: countrymotors.com.mx | Country: MX | Details: Country Motos S.A. de C.V. (also known as Country Motors or Country Honda) is a Mexican motorcycle dealership and multi-… source
    • [5] [RANSOMWARE] SilentRansomGroup leaked Moses & Singer — Victim: Moses & Singer | Group: SilentRansomGroup | Country: US | Details: Moses & Singer LLP is a full-service law firm specializing in corporate transactions, intellectual pro… source
    • [5] [RANSOMWARE] krybit leaked www.buzztrading104.co.za — Victim: www.buzztrading104.co.za | Group: krybit | Website: www.buzztrading104.co.za | Country: ZA | Details: Buzz Trading 104 (Pty) Ltd (also trading as Master Products) is a South African privately owned manufacturer and wholesa… source
    • [5] [RANSOMWARE] qilin leaked Wire Products — Victim: Wire Products | Group: qilin | Website: www.wireproducts.us | Country: US | Details: N/A source
    • [5] [RANSOMWARE] CRPxO leaked Encore Enterprises, Inc. — Victim: Encore Enterprises, Inc. | Group: CRPxO | Website: encore.bz | Country: US | Details: Sector: Commercial Real Estate | Data leaked: 700.0 GB source
    • [5] [RANSOMWARE] shinyhunters leaked Lumenis Ltd. — Victim: Lumenis Ltd. | Group: shinyhunters | Website: lumenis.com | Country: IL | Details: Over 1.1 million records containing some Pil of customers/employees and 176GB+ of internal corporate data was compromised.

      This is a final warning to reach out by 4
      August 2026 before we leak along with several annoying (digital) problems that’ll come your way. Make the right decision, don’t be source

    SUMMARY

    Total new items: 20. Critical count: 0. Ransomware groups active: 1. Top CVEs to patch: N/A.

    Sources: BleepingComputer, TheHackerNews, SecurityWeek, HelpNetSecurity, KrebsOnSecurity, CISA KEV, ransomware.live

    Companion report: Download HTML report

  • Cybersecurity Intelligence Report – 2026-08-03

    CISA KEV

    No CISA KEV items in the last 14 days.

    RANSOMWARE VICTIMS (DLS Monitoring)

    • [RANSOMWARE]: Victim: Alcon Inc. | Group: shinyhunters | Website: alcon.com | Country: CH | Details: Over 25 million Salesforce records containing some PII was compromised.

      This is a final warning to reach out by 4 August 2026 before we leak along with several annoying (digital) problems that’ll come your way. Make the right decision, don’t be the next headline., Victim: Questel SAS | Group: shinyhunters | Website: questel.com | Country: FR | Details: Over 21 million Salesforce records containing some PII and 147GB+ of internal corporate data was compromised.

      This is a final warning to reach out by 4 August 2026 before we leak along with several annoying (digital) problems that’ll come your way. Make the right decision, don’t be the next headl, Victim: www.prohealth.sg | Group: krybit | Website: www.prohealth.sg | Country: SG | Details: ProHealth Medical Group Pte Ltd is a Singaporean private primary healthcare group founded in the 1990s, headquartered at…, Victim: ecfa.org | Group: incransom | Website: ecfa.org | Country: US | Details: The Evangelical Council for Financial Accountability (ECFA) is an American accreditation agency founded in 1979 that certifies Christian churches and nonprofits based on financial integrity, board governance, and transparent fundraising. It represents over 2,700 member organizations with billions in, Victim: INTERTRUST AUSTRALIA PTY LTD | Group: qilin | Website: www.seedoutsourcing.com | Country: AU | Details: N/A, Victim: Asset Flooring Group Australia | Group: qilin | Website: www.assetflooring.com.au | Country: AU | Details: N/A, Victim: Mairie de Drancy | Group: qilin | Website: www.drancy.fr | Country: FR | Details: N/A, Victim: www.dcpartner.co.za | Group: krybit | Website: www.dcpartner.co.za | Country: ZA | Details: DC Partner (Pty) Ltd is a South African market-leading Payment Distribution Agency (PDA), one of only four NCR-accredite…

    NEWS

    • [9] [RANSOMWARE] shinyhunters leaked Alcon Inc. — Victim: Alcon Inc. | Group: shinyhunters | Website: alcon.com | Country: CH | Details: Over 25 million Salesforce records containing some PII was compromised.

      This is a final warning to reach out by 4 August 2026 before we leak along with several annoying (digital) problems that’ll come your way. Make the right decision, don’t be the next headline. source

    • [9] [RANSOMWARE] shinyhunters leaked Questel SAS — Victim: Questel SAS | Group: shinyhunters | Website: questel.com | Country: FR | Details: Over 21 million Salesforce records containing some PII and 147GB+ of internal corporate data was compromised.

      This is a final warning to reach out by 4 August 2026 before we leak along with several annoying (digital) problems that’ll come your way. Make the right decision, don’t be the next headl source

    • [6] Week in review: Claude breached three companies during tests, AD CS domain-takeover PoC released —

      Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Nono: Open-source sandbox for AI agents AI coding agents run with the same permissions as their users, meaning they can access sensitive files, credentials, and production systems. A prompt injection, hallucinated command, or simple mistake can quickly turn that access into a security incident. To reduce the risk, Luke Hinds and Stephen Parkinson co-founded nolabs and released Nono, an open-sourc source

    • [5] [RANSOMWARE] krybit leaked www.prohealth.sg — Victim: www.prohealth.sg | Group: krybit | Website: www.prohealth.sg | Country: SG | Details: ProHealth Medical Group Pte Ltd is a Singaporean private primary healthcare group founded in the 1990s, headquartered at… source
    • [5] [RANSOMWARE] incransom leaked ecfa.org — Victim: ecfa.org | Group: incransom | Website: ecfa.org | Country: US | Details: The Evangelical Council for Financial Accountability (ECFA) is an American accreditation agency founded in 1979 that certifies Christian churches and nonprofits based on financial integrity, board governance, and transparent fundraising. It represents over 2,700 member organizations with billions in source
    • [5] [RANSOMWARE] qilin leaked INTERTRUST AUSTRALIA PTY LTD — Victim: INTERTRUST AUSTRALIA PTY LTD | Group: qilin | Website: www.seedoutsourcing.com | Country: AU | Details: N/A source
    • [5] [RANSOMWARE] qilin leaked Asset Flooring Group Australia — Victim: Asset Flooring Group Australia | Group: qilin | Website: www.assetflooring.com.au | Country: AU | Details: N/A source
    • [5] [RANSOMWARE] qilin leaked Mairie de Drancy — Victim: Mairie de Drancy | Group: qilin | Website: www.drancy.fr | Country: FR | Details: N/A source
    • [5] [RANSOMWARE] krybit leaked www.dcpartner.co.za — Victim: www.dcpartner.co.za | Group: krybit | Website: www.dcpartner.co.za | Country: ZA | Details: DC Partner (Pty) Ltd is a South African market-leading Payment Distribution Agency (PDA), one of only four NCR-accredite… source
    • [5] [RANSOMWARE] krybit leaked nigeria.asa-international.com — Victim: nigeria.asa-international.com | Group: krybit | Website: nigeria.asa-international.com | Country: NG | Details: ASHA Microfinance Bank Limited (ASA Nigeria) is a Nigerian for-profit deposit-taking microfinance institution, a fully l… source
    • [5] [RANSOMWARE] krybit leaked www.ville-rinxent.fr — Victim: www.ville-rinxent.fr | Group: krybit | Website: www.ville-rinxent.fr | Country: FR | Details: Mairie de Rinxent (Municipality of Rinxent) is the official website of the town hall (mairie) of Rinxent, a small French… source
    • [5] [RANSOMWARE] krybit leaked countrymotors.com.mx — Victim: countrymotors.com.mx | Group: krybit | Website: countrymotors.com.mx | Country: MX | Details: Country Motos S.A. de C.V. (also known as Country Motors or Country Honda) is a Mexican motorcycle dealership and multi-… source
    • [5] [RANSOMWARE] SilentRansomGroup leaked Moses & Singer — Victim: Moses & Singer | Group: SilentRansomGroup | Country: US | Details: Moses & Singer LLP is a full-service law firm specializing in corporate transactions, intellectual pro… source
    • [5] [RANSOMWARE] krybit leaked www.buzztrading104.co.za — Victim: www.buzztrading104.co.za | Group: krybit | Website: www.buzztrading104.co.za | Country: ZA | Details: Buzz Trading 104 (Pty) Ltd (also trading as Master Products) is a South African privately owned manufacturer and wholesa… source
    • [5] [RANSOMWARE] qilin leaked Wire Products — Victim: Wire Products | Group: qilin | Website: www.wireproducts.us | Country: US | Details: N/A source
    • [5] [RANSOMWARE] CRPxO leaked Encore Enterprises, Inc. — Victim: Encore Enterprises, Inc. | Group: CRPxO | Website: encore.bz | Country: US | Details: Sector: Commercial Real Estate | Data leaked: 700.0 GB source
    • [5] [RANSOMWARE] shinyhunters leaked Lumenis Ltd. — Victim: Lumenis Ltd. | Group: shinyhunters | Website: lumenis.com | Country: IL | Details: Over 1.1 million records containing some Pil of customers/employees and 176GB+ of internal corporate data was compromised.

      This is a final warning to reach out by 4
      August 2026 before we leak along with several annoying (digital) problems that’ll come your way. Make the right decision, don’t be source

    SUMMARY

    Total new items: 20. Critical count: 0. Ransomware groups active: 1. Top CVEs to patch: N/A.

    Sources: BleepingComputer, TheHackerNews, SecurityWeek, HelpNetSecurity, KrebsOnSecurity, CISA KEV, ransomware.live

    Companion report: Download HTML report

  • Cybersecurity Intelligence Report  02 August 2026

    CRITICAL SECTION

    No critical items found today.

    CISA KEV (Last 14 days)

    No KEV items in the last 14 days.

    RANSOMWARE VICTIMS (today)

    thegentlemen: Philippine Savings Bank

    play: The Butcher Brothers, Sigma Plastics Group, Cambridge Management

    incransom: quantinuum.com

    Global Secret Group: Vernon & Waldrep

    qilin: The Saturday Evening Post, Commercial Furniture Interiors, Dienst Pack Systems, Ceragres, Pointe Property Group, Schreiner Trockenbau GmbH

    Gammax: MTCO (Mahmoud Altaheni & Partners Trading Co)

    coinbasecartel: CEN and Cenelec, MIM Fertility, M. B. Kahn Construction Co., Xs Cad

    secp0: Color Communications LLC, JM Bozeman Enterprises, Indigo Group, Richmond Plywood Corporation Limited, Mike Brandner Law

    NEWS

    [7] Rails patches critical Active Storage flaw with RCE potential

    [7] Ruby on Rails Patches Critical Vulnerability

    [5] Adobe Campaign Classic CVSS 10.0 Flaw Could Run Code Without User Interaction

    SUMMARY

    Total new items: 29

    Critical items: 0

    Ransomware victim disclosures today: 22

    Companion HTML report: Full HTML report