Category: Cybersecurity

  • [RANSOMWARE] qilin leaked Hawaii Family Dental

    CRITICAL SECTION

    [10] [RANSOMWARE] dragonforce leaked RUS Industrial (ransomware.live/dragonforce)

    CISA KEV

    No recent KEV items in the last 14 days.

    RANSOMWARE VICTIMS (DLS Monitoring)

    dragonforce: [RANSOMWARE] dragonforce leaked RUS Industrial, [RANSOMWARE] dragonforce leaked Lamont Pridmore, [RANSOMWARE] dragonforce leaked www.mbmlawsc.com

    thegentlemen: [RANSOMWARE] thegentlemen leaked CFS, [RANSOMWARE] thegentlemen leaked Paula Fish, [RANSOMWARE] thegentlemen leaked Las Cenizas, [RANSOMWARE] thegentlemen leaked Kenaitze Indian Tribe, [RANSOMWARE] thegentlemen leaked Additive Manufacturing, [RANSOMWARE] thegentlemen leaked Salem Saleh Babgi, [RANSOMWARE] thegentlemen leaked Salama Medicals Distributors Private, [RANSOMWARE] thegentlemen leaked Krafman, [RANSOMWARE] thegentlemen leaked Kosh Innovations, [RANSOMWARE] thegentlemen leaked Saturn Industries, [RANSOMWARE] thegentlemen leaked Acosta Sons, [RANSOMWARE] thegentlemen leaked OHK Energy, [RANSOMWARE] thegentlemen leaked Hutch Paving, [RANSOMWARE] thegentlemen leaked CRB group, [RANSOMWARE] thegentlemen leaked Partition Specialties, [RANSOMWARE] thegentlemen leaked Preferred, [RANSOMWARE] thegentlemen leaked Premier Fiduciary, [RANSOMWARE] thegentlemen leaked Bater, [RANSOMWARE] thegentlemen leaked Precision Concrete Pumping, [RANSOMWARE] thegentlemen leaked Clear Vision Signs, [RANSOMWARE] thegentlemen leaked Orsima, [RANSOMWARE] thegentlemen leaked The Municipal Chamber of Serra, [RANSOMWARE] thegentlemen leaked Efrata College of Education, [RANSOMWARE] thegentlemen leaked Amicell, [RANSOMWARE] thegentlemen leaked Known, [RANSOMWARE] thegentlemen leaked Peachtree Group, [RANSOMWARE] thegentlemen leaked Municipalidad de San Luis, [RANSOMWARE] thegentlemen leaked World Wide Fittings, [RANSOMWARE] thegentlemen leaked Chemco Systems, [RANSOMWARE] thegentlemen leaked Total Auto Business Solutions, [RANSOMWARE] thegentlemen leaked Okovolt Solartechnik, [RANSOMWARE] thegentlemen leaked Pertamina

    cmdorganization: [RANSOMWARE] cmdorganization leaked Stewart Belland & Associates Inc.

    CRPxO: [RANSOMWARE] CRPxO leaked KUVEYT TURK, [RANSOMWARE] CRPxO leaked FINANSBANK, [RANSOMWARE] CRPxO leaked ANADOLUBANK, [RANSOMWARE] CRPxO leaked THY, [RANSOMWARE] CRPxO leaked JOHNSON & JOHNSON, [RANSOMWARE] CRPxO leaked DOĞAN HOLDİNG, [RANSOMWARE] CRPxO leaked ANADOLU SİGORTA, [RANSOMWARE] CRPxO leaked HYUNDAI, [RANSOMWARE] CRPxO leaked ASELSAN, [RANSOMWARE] CRPxO leaked A101

    insomnia: [RANSOMWARE] insomnia leaked Merritt Woodwork, [RANSOMWARE] insomnia leaked Laempe Reich

    qilin: [RANSOMWARE] qilin leaked Community Management Associates, [RANSOMWARE] qilin leaked The Dcoop, [RANSOMWARE] qilin leaked Hawaii Family Dental

    genesis: [RANSOMWARE] genesis leaked ****

    interlock: [RANSOMWARE] interlock leaked Gardiner Family Chiropractic

    clop: [RANSOMWARE] clop leaked BLUEVISTALLC.COM

    Booba: [RANSOMWARE] Booba Project leaked Betz Industries

    NEWS

    [9] Hacker uses DeepSeek AI to autonomously attack vulnerable servers
    A Chinese-speaking threat actor is using the DeepSeek AI model and the open-source Hermes Agent to conduct autonomous cyberattacks on exposed servers with limited human involvement. […]

    [8] Critical Code Execution Vulnerability Patched in TeamCity
    <p>Tracked as CVE-2026-63077, the security defect can be exploited without authentication via the agent polling protocol.</p>
    <p>The post <a href="https://www.securityweek.com/critical-code-execution-vulnerability-patched-in-teamcity/">Critical Code Execution Vulnerability Patched in TeamCity </a> a

    [7] HollowFrame Loader Deploys Matryoshka Backdoor in Spear-Phishing Attack on Law Firm
    Cybersecurity researchers have shed light on a previously undocumented Go-based loader framework called HollowFrame and a Rust-based malware family tracked as Matryoshka.

    According to Blackpoint Cyber, the intrusion sequence begins with a spear-phishing message containing a link to an encrypted arc

    [7] Chinese Hacker Commands DeepSeek via Telegram to Launch Autonomous Attacks
    Palo Alto Networks' Unit 42 says a Chinese-speaking threat actor used DeepSeek through the open-source Hermes Agent framework to launch attacks autonomously.

    After an initial Telegram instruction, the agent found internet-facing systems and selected public exploits. The researchers recovered no fur

    [7] [RANSOMWARE] thegentlemen leaked CFS
    Victim: CFS | Group: thegentlemen | Website: cfsinc.com | Country: US | Details: cfsinc.com zoominfo.com/c/cfs-inc/12944410 CFS Inc. is a Massachusetts-based marketing support services company with over 30 years of experience in print management, direct mail, kitting, promotional items, and fulfillm

    [7] [RANSOMWARE] thegentlemen leaked Paula Fish
    Victim: Paula Fish | Group: thegentlemen | Website: paulafish.pl | Country: PL | Details: paulafish.pl zoominfo.com/c/paula-fish/448451882 Paula Fish is a market leader in fish processing in Central Europe, headquartered in Słupsk, Poland. Founded in 1998, the company specializes in the catching, pr

    [7] [RANSOMWARE] dragonforce leaked Lamont Pridmore
    Victim: Lamont Pridmore | Group: dragonforce | Website: lamontpridmore.co.uk | Country: GB | Details: Lamont Pridmore is a leading independent chartered accountancy practice based in Carlisle, Cumbria, and Lancashire, offering a comprehensive range of accountancy, tax, and business advisory services

    [7] [RANSOMWARE] dragonforce leaked www.mbmlawsc.com
    Victim: www.mbmlawsc.com | Group: dragonforce | Website: www.mbmlawsc.com | Country: US | Details: MBM Law (Moore Bradley Myers) is a South Carolina-based law firm founded in 1971. For over half a century, the firm has represented individuals, families, and businesses across a wide range of legal ma

    [7] [RANSOMWARE] cmdorganization leaked Stewart Belland & Associates Inc.
    Victim: Stewart Belland & Associates Inc. | Group: cmdorganization | Website: stewartbellandassociates.ca | Country: CA | Details: Stewart Belland & Associates Inc. (SBA) is a Civil Enforcement Agency licensed by the Province of Alberta. Operating since 1996, under the Alberta Civil Enforcement Act

    [6] Online ad firm Adform’s script compromised to steal cryptocurrency
    Online advertising firm Adform suffered a supply-chain attack that delivered cryptocurrency-stealing scripts to websites using its ad platform, replacing wallet addresses copied to visitors' clipboards with ones controlled by an attacker. […]

    [6] Anthropic’s Claude breached three companies during security tests
    <p>Anthropic has disclosed that its AI model Claude gained unauthorized access to the systems of three different organizations during cybersecurity evaluations. The disclosure follows OpenAI&#8217;s July 21 announcement that some of its models had escaped an isolated testing environment by exploitin

    [5] Critical Flaw Allowed to Azure Cosmos DB Pwnage
    <p>Named CosmosEscape, the vulnerability exposed the primary key for Cosmos DB accounts, granting full read and write access.</p>
    <p>The post <a href="https://www.securityweek.com/critical-flaw-led-to-azure-cosmos-db-pwnage/">Critical Flaw Allowed to Azure Cosmos DB Pwnage</a> appeared first on <a h

    [5] Horizon3.ai expands NodeZero with automated web application attack path testing
    <p>Horizon3.ai has expanded its NodeZero platform with AI-powered web application pentesting. The platform can now autonomously test web applications and identify attack paths that chain application vulnerabilities, credential theft, lateral movement, cloud access, and data exposure. Web application

    [5] AttackIQ targets CTEM execution with AVA Agentic OS
    <p>AttackIQ has announced AVA Agentic OS, an agentic operating system designed to operationalize Continuous Threat Exposure Management. CTEM has emerged as the strategic framework for managing cyber risk, yet many organizations continue to struggle to operationalize CTEM across fragmented security t

    [5] [RANSOMWARE] CRPxO leaked KUVEYT TURK
    Victim: KUVEYT TURK | Group: CRPxO | Country: TR | Details: Sector: Banking | Data leaked: 0.8 GB

    [5] [RANSOMWARE] CRPxO leaked FINANSBANK
    Victim: FINANSBANK | Group: CRPxO | Country: TR | Details: Sector: Banking | Data leaked: 2.3 GB

    [5] [RANSOMWARE] CRPxO leaked ANADOLUBANK
    Victim: ANADOLUBANK | Group: CRPxO | Country: TR | Details: Sector: Banking | Data leaked: 0.4 GB

    [5] [RANSOMWARE] CRPxO leaked THY
    Victim: THY | Group: CRPxO | Country: TR | Details: Sector: Aviation | Data leaked: 4.2 GB

    [5] [RANSOMWARE] CRPxO leaked JOHNSON & JOHNSON
    Victim: JOHNSON & JOHNSON | Group: CRPxO | Country: US | Details: Sector: Healthcare / Pharmaceutical | Data leaked: 1.9 GB

    [5] [RANSOMWARE] CRPxO leaked DOĞAN HOLDİNG
    Victim: DOĞAN HOLDİNG | Group: CRPxO | Country: TR | Details: Sector: Media / Energy Conglomerate | Data leaked: 3.1 GB

    [5] [RANSOMWARE] CRPxO leaked ANADOLU SİGORTA
    Victim: ANADOLU SİGORTA | Group: CRPxO | Country: TR | Details: Sector: Insurance | Data leaked: 1.2 GB

    [5] [RANSOMWARE] CRPxO leaked HYUNDAI
    Victim: HYUNDAI | Group: CRPxO | Country: KR | Details: Sector: Automotive | Data leaked: 1.5 GB

    [5] [RANSOMWARE] CRPxO leaked ASELSAN
    Victim: ASELSAN | Group: CRPxO | Country: TR | Details: Sector: Defense / Electronics | Data leaked: 4.5 GB

    [5] [RANSOMWARE] CRPxO leaked A101
    Victim: A101 | Group: CRPxO | Country: TR | Details: Sector: Grocery / Retail | Data leaked: 0.2 GB

    [5] [RANSOMWARE] insomnia leaked Merritt Woodwork
    Victim: Merritt Woodwork | Group: insomnia | Website: www.merrittwoodwork.com | Country: US | Details: Merritt provides strategic interior solutions for global estates and superyachts, from concept to execution. With precision planning and careful craftsmanship, it partners with top designers and cr

    [5] [RANSOMWARE] insomnia leaked Laempe Reich
    Victim: Laempe Reich | Group: insomnia | Website: www.laempereich.com | Country: US | Details: Laempe Reich is North America’s leading foundry core machine supplier, providing sand core equipment and technology for metal casting. As partner of Laempe Mössner Sinto, it serves the industry for over 80

    [5] [RANSOMWARE] qilin leaked Community Management Associates
    Victim: Community Management Associates | Group: qilin | Website: www.cmamanagement.com | Country: US | Details: N/A

    [5] [RANSOMWARE] thegentlemen leaked Las Cenizas
    Victim: Las Cenizas | Group: thegentlemen | Website: cenizas.cl | Country: CL | Details: cenizas.cl zoominfo.com/c/cenizas/430439098 Grupo Minero Las Cenizas, a prominent medium-scale mining company in Chile with over four decades of industry experience. The company specializes in the production of

    [5] [RANSOMWARE] thegentlemen leaked Kenaitze Indian Tribe
    Victim: Kenaitze Indian Tribe | Group: thegentlemen | Website: kenaitze.org | Country: US | Details: kenaitze.org The Kenaitze Indian Tribe is a federally recognized sovereign nation of the Kahtnuht'ana Dena'ina people located on Alaska's Kenai Peninsula. Its core mission is "to assure Kahtnuht'ana

    [5] [RANSOMWARE] thegentlemen leaked Additive Manufacturing
    Victim: Additive Manufacturing | Group: thegentlemen | Website: additivemanufacturingllc.com | Country: US | Details: additivemanufacturingllc.com zoominfo.com/c/additive-manufacturing-llc/369228736 Additive Manufacturing LLC is a U.S.-based company headquartered in Las Vegas, Nevada, specializing i

    [5] [RANSOMWARE] thegentlemen leaked Salem Saleh Babgi
    Victim: Salem Saleh Babgi | Group: thegentlemen | Website: babgi.com.sa | Country: SA | Details: babgi.com.sa zoominfo.com/c/salem-saleh-babgi-co-ltd/372739058 Babgi Group, founded in 1978 by Sheikh Salem Saleh Babgi, is a major Saudi Arabian conglomerate with over 1,900 employees and revenues excee

    [5] [RANSOMWARE] thegentlemen leaked Salama Medicals Distributors Private
    Victim: Salama Medicals Distributors Private | Group: thegentlemen | Website: salamapharma.co.tz | Country: TZ | Details: salamapharma.co.tz zoominfo.com/c/salama-medicals-distributors-private-ltd/356160819 Salama Pharmaceuticals Limited is Tanzania’s leading importer and distributor of pharmaceutic

    [5] [RANSOMWARE] thegentlemen leaked Krafman
    Victim: Krafman | Group: thegentlemen | Website: krafman.se | Country: SE | Details: krafman.se Krafman (operated by Krafguard AB) is a Swedish credit reporting and debt collection service provider licensed and supervised by the Swedish Authority for Privacy Protection (IMY). The platform offers fas

    [5] [RANSOMWARE] thegentlemen leaked Kosh Innovations
    Victim: Kosh Innovations | Group: thegentlemen | Website: koshinnovations.com | Details: koshinnovations.com zoominfo.com/c/kosh-innovations/369426368 Kosh Innovations, established in 2008 in Pondicherry, India, is a leading manufacturing solutions provider specializing in precision engineering, pla

    [5] [RANSOMWARE] thegentlemen leaked Saturn Industries
    Victim: Saturn Industries | Group: thegentlemen | Website: saturnind.com | Details: saturnind.com zoominfo.com/c/saturn-industries-ltd/348367401 Saturn Industries, based in Winnipeg, Manitoba, is a specialized manufacturer of custom-engineered trailers and overhead lifting products. Operating as a d

    [5] [RANSOMWARE] thegentlemen leaked Acosta Sons
    Victim: Acosta Sons | Group: thegentlemen | Website: acostaandsons.com | Country: US | Details: acostaandsons.com zoominfo.com/c/acosta–sons-inc/398811105 Acosta and Sons is a family-owned appliance sales and repair company based in The Bronx, New York, with additional locations serving the broader

    [5] [RANSOMWARE] thegentlemen leaked OHK Energy
    Victim: OHK Energy | Group: thegentlemen | Website: ohkenergy.com | Country: SG | Details: ohkenergy.com rocketreach.co/ohk-energy-profile_b6d2700bc7449e3f OHK Energy is Ireland’s largest and most trusted renewable energy provider and retrofit specialist, registered with the Sustainable Energy Autho

    [5] [RANSOMWARE] thegentlemen leaked Hutch Paving
    Victim: Hutch Paving | Group: thegentlemen | Website: hutchpaving.com | Country: US | Details: hutchpaving.com zoominfo.com/c/hutch-paving-inc/38258180 Hutch Paving is a highly respected asphalt and concrete paving contractor based in Southeast Michigan, serving the region since 1993. The company sp

    [5] [RANSOMWARE] thegentlemen leaked CRB group
    Victim: CRB group | Group: thegentlemen | Website: crbgroup.com | Country: BR | Details: crbgroup.com zoominfo.com/c/crb-group-gmbh/23317692 CRB is a leading global provider of sustainable engineering, architecture, construction, and consulting solutions, primarily serving the life sciences and food

    [5] [RANSOMWARE] thegentlemen leaked Partition Specialties
    Victim: Partition Specialties | Group: thegentlemen | Website: psi3g.com | Country: US | Details: psi3g.com zoominfo.com/c/partition-specialties-inc/90587733 Partition Specialties, Inc. (PSI), founded in 1958, is a leading commercial interior contractor based in California, serving clients across Ca

    [5] [RANSOMWARE] thegentlemen leaked Preferred
    Victim: Preferred | Group: thegentlemen | Website: preferredtool.com | Country: US | Details: preferredtool.com Preferred Tool & Die is a precision manufacturing company based in Shelton, Connecticut, specializing in custom metal and plastic injection molds as well as complex stamped components. The

    [5] [RANSOMWARE] thegentlemen leaked Premier Fiduciary
    Victim: Premier Fiduciary | Group: thegentlemen | Website: premierfiduciary.com | Country: GB | Details: premierfiduciary.com zoominfo.com/c/premier-fiduciary/346765473 Premier Fiduciary is a global corporate and fiduciary services provider specializing in tailored solutions for private wealth clien

    [5] [RANSOMWARE] thegentlemen leaked Bater
    Victim: Bater | Group: thegentlemen | Website: bater.pl | Country: PL | Details: bater.pl zoominfo.com/c/bater-ltd/429692403 Bater is a leading Polish manufacturer of traction and stationary batteries, founded in 1990 with production facilities in Warsaw and Gliwice. The company specializes in produ

    [5] [RANSOMWARE] thegentlemen leaked Precision Concrete Pumping
    Victim: Precision Concrete Pumping | Group: thegentlemen | Website: precisionconcretepump.com | Country: US | Details: precisionconcretepump.com zoominfo.com/c/precision-concrete-pumping-inc/356699459 Precision Concrete Pumping, Inc. is an MBE-certified concrete pumping company established in 1988,

    [5] [RANSOMWARE] thegentlemen leaked Clear Vision Signs
    Victim: Clear Vision Signs | Group: thegentlemen | Website: clearvisionsigns.net | Country: GB | Details: clearvisionsigns.net zoominfo.com/c/clear-vision-signs/365480092 Clear Vision Signs is a full-service architectural signage and graphics company based in Dade City, Florida, serving clients nati

    [5] [RANSOMWARE] thegentlemen leaked Orsima
    Victim: Orsima | Group: thegentlemen | Website: orsima.com | Details: orsima.com zoominfo.com/c/orsima/347930414 ORSIMA is a leading Algerian IT services company with over 30 years of expertise in digital transformation, data center modernization, and cybersecurity. As a strategic partner of major t

    [5] [RANSOMWARE] thegentlemen leaked The Municipal Chamber of Serra
    Victim: The Municipal Chamber of Serra | Group: thegentlemen | Website: camaraserra.es.gov.br | Country: BR | Details: camaraserra.es.gov.br The Municipal Chamber of Serra (Câmara Municipal da Serra) is the legislative body of the city of Serra, located in the state of Espírito Santo, Brazil. As the

    [5] [RANSOMWARE] thegentlemen leaked Efrata College of Education
    Victim: Efrata College of Education | Group: thegentlemen | Website: emef.ac.il | Country: IL | Details: emef.ac.il zoominfo.com/c/efrata-college-of-education/1337375131 Emuna-Efrata Academic College is a higher education institution located formed by the merger of Efrata College of Education and Em

    [5] [RANSOMWARE] thegentlemen leaked Amicell
    Victim: Amicell | Group: thegentlemen | Website: amicell.co.il | Country: IL | Details: amicell.co.il zoominfo.com/c/amicell/426539109 Amicell (Amit Industries Ltd.) is a leading Israeli manufacturer founded in 1989, specializing in custom-designed battery packs, chargers, and Battery Management Sys

    [5] [RANSOMWARE] thegentlemen leaked Known
    Victim: Known | Group: thegentlemen | Website: known.is | Country: IS | Details: known.is zoominfo.com/c/known/480652891 Known is an award-winning, data-driven marketing, creative, and media agency headquartered in New York. The company uniquely combines PhD data scientists with world-class creative

    [5] [RANSOMWARE] thegentlemen leaked Peachtree Group
    Victim: Peachtree Group | Group: thegentlemen | Website: peachtreegroup.com | Country: US | Details: peachtreegroup.com zoominfo.com/c/peachtree-group/5000000011 Peachtree Group is a vertically integrated investment management firm headquartered in Atlanta, Georgia, with a history dating back to 197

    [5] [RANSOMWARE] thegentlemen leaked Municipalidad de San Luis
    Victim: Municipalidad de San Luis | Group: thegentlemen | Website: munisanluis.gob.pe | Country: PE | Details: munisanluis.gob.pe zoominfo.com/c/municipalidad-de-san-luis/1322909314 The District Municipality of San Luis is the local government body for the San Luis district in Lima, Peru, dedicated

    [5] [RANSOMWARE] thegentlemen leaked World Wide Fittings
    Victim: World Wide Fittings | Group: thegentlemen | Website: worldwidefittings.com | Country: GB | Details: worldwidefittings.com zoominfo.com/c/world-wide-fittings-inc/42729844 World Wide Fittings, Inc. is a global manufacturer of precision-engineered steel and stainless steel hydraulic tube and pi

    [5] [RANSOMWARE] thegentlemen leaked Chemco Systems
    Victim: Chemco Systems | Group: thegentlemen | Website: chemcosystems.net | Country: US | Details: chemcosystems.net zoominfo.com/c/chemco-systems-lp/39588004 Chemco Systems is a world leader in the design and manufacturing of bulk chemical storage, handling, and feed systems for air and water pollu

    [5] [RANSOMWARE] thegentlemen leaked Total Auto Business Solutions
    Victim: Total Auto Business Solutions | Group: thegentlemen | Website: autorepairsoftware.com | Country: US | Details: autorepairsoftware.com Total Auto Business Solutions, Inc. (TABS) is a leading provider of comprehensive shop management software, best known for its flagship product, AutoFluent. F

    [5] [RANSOMWARE] thegentlemen leaked Okovolt Solartechnik
    Victim: Okovolt Solartechnik | Group: thegentlemen | Website: oekovolt.com | Country: DE | Details: oekovolt.com Ökovolt Solartechnik GmbH is an Austrian company specializing in the planning, installation, and maintenance of photovoltaic systems for private, commercial, and industrial clients. Based

    [5] [RANSOMWARE] thegentlemen leaked Pertamina
    Victim: Pertamina | Group: thegentlemen | Website: pertamina.com | Country: ID | Details: pertamina.com REV – $23.2 Billion zoominfo.com/c/pt-pertamina/191250883 Pertamina is an energy company primarily in the oil and gas sector. The company provides services for new and renewable energy, and other

    [5] [RANSOMWARE] genesis leaked ****
    Victim: **** | Group: genesis | Website: . | Country: US | Details: A healthcare organization

    [5] [RANSOMWARE] interlock leaked Gardiner Family Chiropractic
    Victim: Gardiner Family Chiropractic | Group: interlock | Website: gardinerfamilychiropractic.com | Country: US | Details: Gardiner Family Chiropractic has been providing medical services to residents of Gardiner and the surrounding area since 1989. However, it is not responsible for its patients an

    [5] [RANSOMWARE] clop leaked BLUEVISTALLC.COM
    Victim: BLUEVISTALLC.COM | Group: clop | Website: BLUEVISTALLC.COM | Country: US | Details: [AI generated] N/A

    [5] [RANSOMWARE] Booba Project leaked Betz Industries
    Victim: Betz Industries | Group: Booba Project | Website: www.betzindustries.com | Country: US | Details: Industrial Machinery Manufacturing Stolen data: 7 GB.

    [5] [RANSOMWARE] qilin leaked The Dcoop
    Victim: The Dcoop | Group: qilin | Website: www.dcoop.es | Country: ES | Details: N/A

    [5] [RANSOMWARE] qilin leaked Hawaii Family Dental
    Victim: Hawaii Family Dental | Group: qilin | Website: www.hawaiifamilydental.com | Country: US | Details: N/A

    SUMMARY

    Total new items: 88; Critical: 1; Ransomware groups: 10; KEV items: 0

    Companion HTML report: https://liberpulse.com/wp-content/uploads/2026/08/cyber_report_latest.html

    Sources: BleepingComputer, TheHackerNews, SecurityWeek, HelpNetSecurity, KrebsOnSecurity, CISA KEV, ransomware.live

  • Cybersecurity Intelligence Report — 30 July 2026

    CRITICAL SECTION

    • [13] Cisco warns of FMC static credential flaw exploited in zero-day attacks (BleepingComputer) — CVE-2026-20316
      Cisco is warning that a high-severity Secure Firewall Management Center (FMC) static credential vulnerability, tracked as CVE-2026-20316, was actively exploited in zero-day attacks to gain unauthorized access to vulnerable devices. […]
    • [12] Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape (TheHackerNews) — CVE-2026-59309
      Broadcom has released security updates to address multiple security flaws impacting VMware ESX, vCenter, Workstation, and Fusion, three of which have been designated as critical in severity.

      The first of the three critical-rated flaws is CVE-2026-59309 (CVSS score: 9.8), which has been described as an authentication bypass in VMware vCenter.

      "A malicious actor with network access to vCenter

    CISA KEV SECTION

    CVE Vendor/Product Score Required Action
    CVE-2026-20316 Unknown 6 Apply vendor patch as soon as possible

    RANSOMWARE VICTIMS (DLS Monitoring)

    • [RANSOMWARE]: [RANSOMWARE] spacebears leaked StellarRAD Systems, [RANSOMWARE] incransom leaked harwal.net, [RANSOMWARE] Black X leaked sanaa hospital, [RANSOMWARE] Black X leaked Tong Kong E & E Sdn Bhd (95907X), [RANSOMWARE] insomnia leaked Sky Solutions, [RANSOMWARE] akira leaked Northwood Country Club, [RANSOMWARE] Section9 leaked ****.com.pa, [RANSOMWARE] aurora leaked Bretford Manufacturing, [RANSOMWARE] gunra leaked Weilhotel, [RANSOMWARE] NotPetya leaked Maersk

    NEWS SECTION

    • [9] Russian hackers exploit Exchange OWA zero-day for long-term mailbox access (BleepingComputer) — The Russian state-sponsored hacking group Laundry Bear, also known as Void Blizzard, is exploiting an Exchange Outlook Web Access vulnerability in email campaigns to deliver a sophisticated backdoor called OWAReaper. […]
    • [8] Public PoC Released for Exploited Check Point SmartConsole Authentication Bypass (TheHackerNews) — Cybersecurity researchers have shared additional technical details about a recently patched critical security flaw impacting Check Point Security Management Server and Multi-Domain Security Management Server (MDS) that has come under active exploitation in the wild.

      The vulnerability, tracked as CVE-2026-16232 (CVSS score: 9.3), is an authentication bypass in the SmartConsole login process that

    • [8] New Gitea RCE Lets Repository Writers Plant a Git Hook to Run Shell Commands (TheHackerNews) — Gitea, the self-hosted Git platform, has patched a critical remote code execution vulnerability. A user with ordinary repository write access can turn attacker-controlled patch content into a live Git hook and run shell commands as the Gitea service account.

      Tracked as CVE-2026-60004 (CVSS score: 9.8), the flaw affects Gitea versions 1.17 and later before 1.27.1 and is fixed in 1.27.1. The

    • [7] Researchers Show a Single Malicious Webpage Visit Can Compromise Tor Browser (TheHackerNews) — Nebula Security says a patched Firefox JIT flaw could be triggered by simply visiting a malicious webpage and was also used to compromise Tor Browser.

      Tracked as CVE-2026-10702, the bug provides arbitrary code execution inside the browser's renderer process. Mozilla rated it High and fixed it in the Firefox 151.0.3 update.

      "No settings or additional user interaction are required," Eten Zou,

    • [6] JFrog Zero-Days Exploited in OpenAI-Hugging Face Hack (SecurityWeek) — <p>The OpenAI models targeted services beyond Hugging Face as they attempted to solve the tasks they were given.</p>
      <p>The post <a href="https://www.securityweek.com/jfrog-zero-days-exploited-in-openai-hugging-face-hack/">JFrog Zero-Days Exploited in OpenAI-Hugging Face Hack</a> appeared first on <a href="https://www.securityweek.com">SecurityWeek</a>.</p>
    • [6] Tengu botnet reboots Linux devices to survive removal (HelpNetSecurity) — <p>A new Mirai-derived IoT botnet can force an infected Linux device to reboot once its main process is killed, giving its persistence mechanisms another opportunity to relaunch it, Nozomi Networks Labs has found. The malware, dubbed Tengu, was discovered by a machine-learning system the company uses to identify malware families that do not match known signatures. Researchers first observed the dropper reaching their honeypots through Telnet credential brute-force attacks. Tengu isn&#8217;t just
    • [6] ShutterGap: Aryon Security finds 3.7M AWS cloud resources exposed beyond CSPM/CNAPP visibility (HelpNetSecurity) — <p>Research from Aryon reveals that each year, 3,731,699 short-lived cloud resources containing highly sensitive information are publicly exposed. This impacts any organization using AWS services that support public sharing. These exposures often last only minutes or hours, too briefly for periodically scanning CSPM and CNAPP platforms to detect, yet long enough for attackers to discover and copy them.  The findings expose a fundamental limitation of the reactive CSPM/CNAPP model: some cloud mi
    • [6] [CISA KEV] CVE-2026-20316: Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability – Cisco Secure Firewall Management Center (FMC) (CISA KEV) — Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability – Cisco Secure Firewall Management Center (FMC). Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.. Due: 2026-08-01
    • [6] [RANSOMWARE] spacebears leaked StellarRAD Systems (ransomware.live/spacebears) — Victim: StellarRAD Systems | Group: spacebears | Website: www.stellarrad.com | Country: US | Details: Since 1981, StellarRAD Systems exists to solve the critical issues facing our clients, both large and small. We provide a broad range of services and solutions to help telecommunications providers around the world facilitate change and achieve their vision while optimizing performance and productivi
    • [5] Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory (TheHackerNews) — Cybersecurity researchers have flagged a maximum-severity security flaw in Ruflo, an open-source agent meta-harness for Anthropic Claude Code and OpenAI Codex, that could result in unauthenticated remote code execution.

      The vulnerability, tracked as CVE-2026-59726 (CVSS score: 10.0), impacts all versions of the project before version 3.16.3. It has been codenamed RufRoot by Noma Security's

    • [5] [RANSOMWARE] incransom leaked harwal.net (ransomware.live/incransom) — Victim: harwal.net | Group: incransom | Website: harwal.net | Country: AE | Details: Harwal.net

      Harwal Group is the largest plastics recycler in the Middle East, founded in 1938, with an annual processing capacity of over 200,000 tons of plastics and metals.
      Manufacturing includes construction materials, pre-engineered building systems, industrial packaging, consumer goods, and

    • [5] [RANSOMWARE] Black X leaked sanaa hospital (ransomware.live/Black X) — Victim: sanaa hospital | Group: Black X | Country: YE | Details: [AI generated] N/A
    • [5] [RANSOMWARE] Black X leaked Tong Kong E & E Sdn Bhd (95907X) (ransomware.live/Black X) — Victim: Tong Kong E & E Sdn Bhd (95907X) | Group: Black X | Website: https://wa.me/tongkong | Country: MY | Details: It contains sensitive data, including customers and banking records.
    • [5] [RANSOMWARE] insomnia leaked Sky Solutions (ransomware.live/insomnia) — Victim: Sky Solutions | Group: insomnia | Website: www.skysolutions.com.pa | Country: PA | Details: Sky Solutions is a leading distribution company for Telecommunication products and services in Panamá. Currently serving 4 regions in Panama covering +4,000 points of sales; retail chains and supermarkets.
    • [5] [RANSOMWARE] akira leaked Northwood Country Club (ransomware.live/akira) — Victim: Northwood Country Club | Group: akira | Details: Northwood Country Club is a private club located in Meridian, Mississippi, known for its beauti
      ful facilities and convenient city location. The club offers a range of amenities including cha
      mpionship golf, clubhouse dining, swimming pool, tennis, and fitness services.

      We will upload corporate dat

    • [5] [RANSOMWARE] Section9 leaked ****.com.pa (ransomware.live/Section9) — Victim: ****.com.pa | Group: Section9 | Country: PA | Details: TRAVEL
    • [5] [RANSOMWARE] aurora leaked Bretford Manufacturing (ransomware.live/aurora) — Victim: Bretford Manufacturing | Group: aurora | Website: Bretford Manufacturing | Country: US | Details: Bretford Manufacturing, Inc. is a privately held manufacturer of charging solutions for mobile devices, founded in 1948 and headquartered in Franklin Park, Illinois. With ~60 employees and ~$10M annual revenue, it serves education, healthcare, retail, and government sectors.

      The exposed material in

    • [5] [RANSOMWARE] gunra leaked Weilhotel (ransomware.live/gunra) — Victim: Weilhotel | Group: gunra | Website: weilhotel.com | Country: MY | Details: Sector: Hotel | Revenue: US$ 5,000,000
    • [5] [RANSOMWARE] NotPetya leaked Maersk (ransomware.live/NotPetya) — Victim: Maersk | Group: NotPetya | Website: maersk.com | Country: DK | Details: A.P. Moller-Maersk, the Danish shipping and logistics conglomerate, was hit by the NotPetya wiper malware, causing major disruption to its global container shipping operations.

    SUMMARY

    Total new items: 54; Critical count: 2; Ransomware groups active: 0; Top CVEs to patch: CVE-2026-20316, CVE-2026-59309, CVE-2026-16232, CVE-2026-60004, CVE-2026-10702

    Sources: BleepingComputer, TheHackerNews, SecurityWeek, HelpNetSecurity, KrebsOnSecurity, CISA KEV, ransomware.live

    Companion HTML report: Download report

  • Cybersecurity Intelligence Report  2026-07-28

    Cybersecurity Intelligence Report  2026-07-28

    Collected: 2026-07-28T04:00:42.803070

    CRITICAL SECTION

    CISA KEV SECTION

    CVE Vendor/Product Score Required Action
    CVE-2025-68686 Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability 6 Apply vendor mitigations / follow CISA guidance
    CVE-2026-16812 Arista VeloCloud Orchestrator On 6 Apply vendor mitigations / follow CISA guidance
    CVE-2026-54121 4 Apply vendor mitigations / follow CISA guidance
    CVE-2026-27577 1 Apply vendor mitigations / follow CISA guidance

    RANSOMWARE VICTIMS (DLS Monitoring)

    shinyhunters: BH Security, LLC. (brinkshome.com), RingCentral, Inc., Ernst & Young

    chaos: vit-best.com

    nightspire: The Mountain, Kates Nussman Ellis Earle & Landolfi LLP, Akribis Systems Pte Ltd, Thai Seng International Co. Ltd, MKS Transformator, OPTIDEA GmbH, Furama Bukit Bintang, K. Venkatesh, Co, Wings Argo Private Limited, KSL Dirtworks LLC, Diffusion de Produits Inoxydables, TFG Benefits, Inc.

    dragonforce: Katathani Phuket Beach Resort

    termite: Affinia Healthcare, JD Young

    incransom: minigrip.com.mx, DUCON, greenecountyga.gov, foundationstofreedom.org

    anubis: Prelys Courtage, Coca-Cola / Fairlife

    safepay: zinorm.de, moebelmayer.de, paritaet-nrw.org, haugbuersten.de, landesmuseum.de, hst.eu, braywoodschool.co.uk, weier.org, bnpdist.com

    qilin: Groupe Fenwick, Savills France, Wilbert’s

    CRPxO: IPTV Platform, Marketech, American Hospice & Home Health Services (Ahhh Care), Bright Star Partners Insurance, eCare Platform, Dignity Phoenix, Schorr Law, Simpkins Law Firm, Leah Walker Orthodontics, Elko Dental Specialists

    Deadlock: Hardware Asesorias Software Ltda, Tesco Engineer

    Global Secret Group: Louisiana Coalition Against | Domestic Violence

    NEWS SECTION

  • Cybersecurity Daily — 2026-07-27

    CRITICAL SECTION

    [12] Week in review: ServiceNow pre-auth RCE exploited in the wild, Hugging Face breached (HelpNetSecurity)
    <p>Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: AI agents are still logging in as humans Most large companies run more than one AI platform at the same time. Developers pull up coding assistants, marketing teams lean on writing tools, and analysts query enterprise search across separate vendors. Single-provider setups keep giving way to mixed stacks as companies keep their options open. PR3TACK preemptive framework maps threats before &#8230;

    CISA KEV (last 14 days)

    No CISA KEV items found.

    RANSOMWARE VICTIMS (today)

    [RANSOMWARE]: [RANSOMWARE] Deadlock leaked West African Resources ltd, [RANSOMWARE] Section9 leaked *******.com, [RANSOMWARE] dragonforce leaked Syntron Bioresearch, [RANSOMWARE] dragonforce leaked Deluxe Medical Supply, [RANSOMWARE] ExfilSquad leaked District of Columbia Public Schools, [RANSOMWARE] ExfilSquad leaked Police National Legal Database, [RANSOMWARE] Global Secret Group leaked Nexon Corp., [RANSOMWARE] CRPxO leaked ProSmile Family Dental Care, [RANSOMWARE] CRPxO leaked Qube Aviation Catering, [RANSOMWARE] CRPxO leaked Performance Data Solutions, [RANSOMWARE] CRPxO leaked Host & Protect (RedBlink), [RANSOMWARE] CRPxO leaked RnnR Cloud, [RANSOMWARE] CRPxO leaked CodeConductor.ai, [RANSOMWARE] CRPxO leaked Prei Capital, [RANSOMWARE] CRPxO leaked FLP Law Group LLP, [RANSOMWARE] CRPxO leaked Summit Hill Insurance, [RANSOMWARE] CRPxO leaked MRO Aerospace, [RANSOMWARE] incransom leaked takethehop.com, [RANSOMWARE] Global Secret Group leaked Park Manufacturing Corp., [RANSOMWARE] ExfilSquad leaked Wesco International

    NEWS

    [7] [RANSOMWARE] Deadlock leaked West African Resources ltd (ransomware.live/Deadlock)
    Victim: West African Resources ltd | Group: Deadlock | Website: www.westafricanresources.com | Country: AU | Details: West African Resources Limited (ASX: WAF) isan Australia-based, mid-tier gold mining and exploration companywith its primary operations located in Burkina Faso, West Africa . Founded in 2006, the company is headquartered in Subiaco, Western Australia, and focuses on the acquisition, development, and

    [7] [RANSOMWARE] Section9 leaked *******.com (ransomware.live/Section9)
    Victim: *******.com | Group: Section9 | Country: US | Details: ECOMMERCE

    [7] [RANSOMWARE] dragonforce leaked Syntron Bioresearch (ransomware.live/dragonforce)
    Victim: Syntron Bioresearch | Group: dragonforce | Website: syntron.net | Country: US | Details: Syntron Bioresearch, Inc. specializes in manufacturing rapid in vitro diagnostic tests and detection readers, focusing on fertility and over-the-counter tests for ovulation and pregnancy. The company is licensed as a Medical Device Establishment by the US FDA and the State of California Department o

    [7] [RANSOMWARE] dragonforce leaked Deluxe Medical Supply (ransomware.live/dragonforce)
    Victim: Deluxe Medical Supply | Group: dragonforce | Website: deluxemedical.com | Country: US | Details: Deluxe Medical Supply is a distributor of healthcare supplies that focuses on delivering quality home healthcare products and services. They provide a wide range of medical equipment, including mobility aids, incontinence supplies, and compression therapy garments, aimed at restoring independence an

    [7] [RANSOMWARE] ExfilSquad leaked District of Columbia Public Schools (ransomware.live/ExfilSquad)
    Victim: District of Columbia Public Schools | Group: ExfilSquad | Website: dcps.dc.gov | Country: US | Details: [AI generated] District of Columbia Public Schools (DCPS) is a public school district serving Washington, D.C., USA. It operates as the primary government-run K-12 educational system for the nation's capital, overseeing dozens of schools, thousands of students, and a large workforce of educators and

    [7] [RANSOMWARE] ExfilSquad leaked Police National Legal Database (ransomware.live/ExfilSquad)
    Victim: Police National Legal Database | Group: ExfilSquad | Country: GB | Details: DATA SUMMARY:
    135k law enforcement contact records with first/last name, email, police force area, etc.

    [6] [RANSOMWARE] Global Secret Group leaked Nexon Corp. (ransomware.live/Global Secret Group)
    Victim: Nexon Corp. | Group: Global Secret Group | Website: nexon.com | Country: KR | Details: Internal infrastructure audit revealed multiple critical entry points across distributed network segments.

    [5] [RANSOMWARE] CRPxO leaked ProSmile Family Dental Care (ransomware.live/CRPxO)
    Victim: ProSmile Family Dental Care | Group: CRPxO | Country: US | Details: Sector: Healthcare / Dental | Data leaked: 9.6 GB

    [5] [RANSOMWARE] CRPxO leaked Qube Aviation Catering (ransomware.live/CRPxO)
    Victim: Qube Aviation Catering | Group: CRPxO | Country: US | Details: Sector: Aviation / Catering | Data leaked: 22.5 GB

    [5] [RANSOMWARE] CRPxO leaked Performance Data Solutions (ransomware.live/CRPxO)
    Victim: Performance Data Solutions | Group: CRPxO | Country: US | Details: Sector: Motorsport / Data Acquisition | Data leaked: 12.8 GB

    [5] [RANSOMWARE] CRPxO leaked Host & Protect (RedBlink) (ransomware.live/CRPxO)
    Victim: Host & Protect (RedBlink) | Group: CRPxO | Country: US | Details: Sector: Web Hosting / Security | Data leaked: 156.2 GB

    [5] [RANSOMWARE] CRPxO leaked RnnR Cloud (ransomware.live/CRPxO)
    Victim: RnnR Cloud | Group: CRPxO | Country: US | Details: Sector: Technology / Cloud Services | Data leaked: 68.9 GB

    [5] [RANSOMWARE] CRPxO leaked CodeConductor.ai (ransomware.live/CRPxO)
    Victim: CodeConductor.ai | Group: CRPxO | Website: CodeConductor.ai | Country: US | Details: Sector: Technology / AI / SaaS | Data leaked: 52.4 GB

    [5] [RANSOMWARE] CRPxO leaked Prei Capital (ransomware.live/CRPxO)
    Victim: Prei Capital | Group: CRPxO | Country: US | Details: Sector: Financial / Capital | Data leaked: 18.7 GB

    [5] [RANSOMWARE] CRPxO leaked FLP Law Group LLP (ransomware.live/CRPxO)
    Victim: FLP Law Group LLP | Group: CRPxO | Country: US | Details: Sector: Legal / Bankruptcy | Data leaked: 42.1 GB

    [5] [RANSOMWARE] CRPxO leaked Summit Hill Insurance (ransomware.live/CRPxO)
    Victim: Summit Hill Insurance | Group: CRPxO | Country: US | Details: Sector: Insurance | Data leaked: 34.5 GB

    [5] [RANSOMWARE] CRPxO leaked MRO Aerospace (ransomware.live/CRPxO)
    Victim: MRO Aerospace | Group: CRPxO | Country: US | Details: Sector: Aerospace / Defense | Data leaked: 87.3 GB

    [5] [RANSOMWARE] incransom leaked takethehop.com (ransomware.live/incransom)
    Victim: takethehop.com | Group: incransom | Website: takethehop.com | Country: US | Details: The HOP, an American regional public transit system operated by the Hill Country Transit District (HCTD). Founded in the 1960s in the state of Texas (USA) as a voluntary transportation service, the organization has grown over the decades into a major public public-transport network.

    [5] [RANSOMWARE] Global Secret Group leaked Park Manufacturing Corp. (ransomware.live/Global Secret Group)
    Victim: Park Manufacturing Corp. | Group: Global Secret Group | Website: parkmfg.com | Country: US | Details: Country: Cambridge, Minnesota 55008, US |
    Website: parkmfg.com |
    Revenue: $17.9 Million |
    Industry: Appliances, Electrical, and Electronics Manufacturing |
    Employees: 50-100 |
    Properties: 195 GB (411,109 Files, 48,413 Folders)

    [5] [RANSOMWARE] ExfilSquad leaked Wesco International (ransomware.live/ExfilSquad)
    Victim: Wesco International | Group: ExfilSquad | Country: US | Details: Revenue: $24B

    DATA SUMMARY:
    2.6M~ records containing: customer and employee PII, account and contact data, CRM user profiles, credit and business identifiers, authentication metadata, and access information.

    [5] [RANSOMWARE] genesis leaked Williams Accounting Professional (ransomware.live/genesis)
    Victim: Williams Accounting Professional | Group: genesis | Website: bramptondirect.ca | Country: CA | Details: A full service CPA firm

    [5] [RANSOMWARE] genesis leaked JJP Slip Forming Inc. (ransomware.live/genesis)
    Victim: JJP Slip Forming Inc. | Group: genesis | Website: . | Country: US | Details: A company that operates in the Restaurants industry

    [5] [RANSOMWARE] genesis leaked Building Envelope Systems (ransomware.live/genesis)
    Victim: Building Envelope Systems | Group: genesis | Website: infinitypipeinc.com | Country: US | Details: A reputable construction company based in Plainville, MA

    [5] [RANSOMWARE] genesis leaked Westlake Realty Group, Inc. (ransomware.live/genesis)
    Victim: Westlake Realty Group, Inc. | Group: genesis | Website: westlake-realty.com | Country: US | Details: A full-service real estate development company

    [5] [RANSOMWARE] genesis leaked Servonix Technologies (ransomware.live/genesis)
    Victim: Servonix Technologies | Group: genesis | Website: servonix.com | Country: US | Details: A provider of IT services

    [5] [RANSOMWARE] genesis leaked Infinity Pipeline,Inc. (ransomware.live/genesis)
    Victim: Infinity Pipeline,Inc. | Group: genesis | Website: infinitypipeinc.com | Country: US | Details: A family owned, local construction company.

    [5] [RANSOMWARE] Global Secret Group leaked Hinduja Tech | BMW Group & Škoda Auto (ransomware.live/Global Secret Group)
    Victim: Hinduja Tech | BMW Group & Škoda Auto | Group: Global Secret Group | Website: hindujatech.com | Country: IN | Details: Country: India |
    Website: hindujatech.com |
    Revenue: $381 Million |
    Industry: Engineering Services, Architecture, Engineering & Design, Product Engineering Solutions |
    Employees: 2000-5000 |
    Properties: 515 GB (212,785 Files, 83,982 Folders)

    [5] [RANSOMWARE] Global Secret Group leaked Pro-Tuff | Decals (ransomware.live/Global Secret Group)
    Victim: Pro-Tuff | Decals | Group: Global Secret Group | Website: protuffdecals.com | Country: US | Details: Country: Crystal Lake, US |
    Website: protuffdecals.com |
    Revenue: $9.6 million |
    Industry: Business Services General, Business Services |
    Employees: 10-20 |
    Properties: 412 GB (589,623 Files, 40,081 Folders)

    [5] [RANSOMWARE] Deadlock leaked High Class Car Limo (ransomware.live/Deadlock)
    Victim: High Class Car Limo | Group: Deadlock | Website: www.highclasscarlimo.com | Country: US | Details: High Class Limousine & Car Service Corp. is a licensed private passenger transportation service in New York City, founded in 1995, specializing in non-emergency medical transportation . The company provides rides to medical appointments, dialysis sessions, and rehabilitation facilities, and has loca

    [5] [RANSOMWARE] anubis leaked Eagle Crest Communities (ransomware.live/anubis)
    Victim: Eagle Crest Communities | Group: anubis | Website: eaglecrestlife.org | Country: US | Details: Patient and employee data breach at elderly care service.

    [5] [RANSOMWARE] Global Secret Group leaked Spergel (ransomware.live/Global Secret Group)
    Victim: Spergel | Group: Global Secret Group | Website: spergel.ca | Country: CA | Details: Country: Canada |
    Website: spergel.ca |
    Revenue: $28.2 Million |
    Industry: Business Services,Project Management |
    Employees: 51-200 |
    Properties: 5.4 TB (7,830,792 Files, 902,844 Folders)

    [5] [RANSOMWARE] Deadlock leaked Caspian One (ransomware.live/Deadlock)
    Victim: Caspian One | Group: Deadlock | Website: www.caspianone.com | Country: AZ | Details: Caspian One is an international provider of IT services and specialist talent for industries such as FinTech investment banking and broadcasting. Based in England the company offers professional recruitment and managed technology solutions and operates in Europe and North America.

    [5] [RANSOMWARE] Section9 leaked *****.com.pt (ransomware.live/Section9)
    Victim: *****.com.pt | Group: Section9 | Country: PT | Details: UNIVERSITY

    [5] [RANSOMWARE] Section9 leaked ********.com.uy (ransomware.live/Section9)
    Victim: ********.com.uy | Group: Section9 | Country: UY | Details: FOOD & SERVICES

    [5] [RANSOMWARE] Section9 leaked ****.fr (ransomware.live/Section9)
    Victim: ****.fr | Group: Section9 | Country: FR | Details: RETAIL

    [5] [RANSOMWARE] Section9 leaked ********.com (ransomware.live/Section9)
    Victim: ********.com | Group: Section9 | Country: US | Details: NEWS

    [5] [RANSOMWARE] Section9 leaked ******.com.se (ransomware.live/Section9)
    Victim: ******.com.se | Group: Section9 | Country: SE | Details: HEALTHCARE

    [5] [RANSOMWARE] Section9 leaked ******.com (ransomware.live/Section9)
    Victim: ******.com | Group: Section9 | Country: US | Details: CYBERSECURITY

    [5] [RANSOMWARE] Section9 leaked ****.com.mc (ransomware.live/Section9)
    Victim: ****.com.mc | Group: Section9 | Country: MC | Details: TRAVEL & TOURISM

    [5] [RANSOMWARE] Section9 leaked *****.ind.br (ransomware.live/Section9)
    Victim: *****.ind.br | Group: Section9 | Country: BR | Details: AGRICULTURE

    [5] [RANSOMWARE] Section9 leaked ********** (ransomware.live/Section9)
    Victim: ********** | Group: Section9 | Details: CYBERSECURITY

    [5] [RANSOMWARE] Section9 leaked *****.com.br (ransomware.live/Section9)
    Victim: *****.com.br | Group: Section9 | Country: BR | Details: FINTECH

    [5] [RANSOMWARE] Section9 leaked ****.com.br (ransomware.live/Section9)
    Victim: ****.com.br | Group: Section9 | Country: BR | Details: TELECOM

    [5] [RANSOMWARE] Section9 leaked ****.com (ransomware.live/Section9)
    Victim: ****.com | Group: Section9 | Country: BE | Details: INDUSTRY

    [5] [RANSOMWARE] Section9 leaked ********.com.jp (ransomware.live/Section9)
    Victim: ********.com.jp | Group: Section9 | Country: JP | Details: SOFTWARE

    [5] [RANSOMWARE] Section9 leaked *****.com.cn (ransomware.live/Section9)
    Victim: *****.com.cn | Group: Section9 | Country: CN | Details: FINANCE

    [5] [RANSOMWARE] Section9 leaked ******.net.br (ransomware.live/Section9)
    Victim: ******.net.br | Group: Section9 | Country: BR | Details: TAX

    [5] [RANSOMWARE] Section9 leaked ******.com.br (ransomware.live/Section9)
    Victim: ******.com.br | Group: Section9 | Country: BR | Details: MEDIA

    [5] [RANSOMWARE] Section9 leaked ********.com.br (ransomware.live/Section9)
    Victim: ********.com.br | Group: Section9 | Country: BR | Details: MINING

    [5] [RANSOMWARE] Global Secret Group leaked Prism Telecom (ransomware.live/Global Secret Group)
    Victim: Prism Telecom | Group: Global Secret Group | Website: prismtelecom.com | Country: FI | Details: Backbone network traffic analysis and SS7 protocol vulnerability assessment across 3 continents.

    [5] [RANSOMWARE] Global Secret Group leaked Cipher Dynamics (ransomware.live/Global Secret Group)
    Victim: Cipher Dynamics | Group: Global Secret Group | Website: cipherdyn.com | Country: IN | Details: Zero-trust architecture review and cryptographic key management assessment.

    [5] [RANSOMWARE] Global Secret Group leaked Stratos Network (ransomware.live/Global Secret Group)
    Victim: Stratos Network | Group: Global Secret Group | Website: stratosns.com | Country: AE | Details: Satellite communication relay analysis with deep-packet inspection across 14 ground stations.

    [5] [RANSOMWARE] Global Secret Group leaked OmniLink AG (ransomware.live/Global Secret Group)
    Victim: OmniLink AG | Group: Global Secret Group | Website: omnilink.software | Country: DE | Details: Full-scope penetration testing of financial transaction processing pipeline and API gateway.

    [5] [RANSOMWARE] Global Secret Group leaked Vertex Systems (ransomware.live/Global Secret Group)
    Victim: Vertex Systems | Group: Global Secret Group | Website: vertexsystems.com | Country: US | Details: Ongoing analysis of cloud-native architecture and microservice communication protocols.

    [5] [RANSOMWARE] Global Secret Group leaked Farmers Mutual Fire Insurance (ransomware.live/Global Secret Group)
    Victim: Farmers Mutual Fire Insurance | Group: Global Secret Group | Website: farmersofmarble.com | Country: US | Details: Country: Pennsylvania, United States |
    Website: farmersofmarble.com |
    Revenue: $5.2 Million |
    Industry: Insurance |
    Employees: 11-50 |
    Properties: 5.72 GB (18,699 Files, 2,631 Folders)

    [5] [RANSOMWARE] Global Secret Group leaked West Sixth Law (ransomware.live/Global Secret Group)
    Victim: West Sixth Law | Group: Global Secret Group | Website: agslawyers.com | Country: US | Details: Country: Columbus, Indiana, United States |
    Website: agslawyers.com |
    Revenue: $5 Million |
    Industry: Law Firms & Legal Services |
    Employees: 11-50 Employees |
    Properties: 328 GB (708,816 Files, 47,925 Folders)

    [5] [RANSOMWARE] Global Secret Group leaked Baker Business & Tax Solutions (ransomware.live/Global Secret Group)
    Victim: Baker Business & Tax Solutions | Group: Global Secret Group | Website: bakerbusinessandtax.com | Country: US | Details: Country: Kentucky, United States |
    Website: bakerbusinessandtax.com |
    Revenue: $1 Million |
    Industry: Accounting for Legal Practices |
    Employees: 1-10 Employees |
    Properties: 213Gb (817,209 Files, 48,866 Folders)

    [5] [RANSOMWARE] Global Secret Group leaked Carpets Direct (ransomware.live/Global Secret Group)
    Victim: Carpets Direct | Group: Global Secret Group | Website: carpetsdirectfindlay.com | Country: US | Details: Country: Ohio, United States |
    Website: carpetsdirectfindlay.com |
    Revenue: $5 Million |
    Industry: Retail,Furniture |
    Employees: 11-50 |
    Properties: 31.1 GB (1,442 Files, 788 Folders)

    [5] [RANSOMWARE] Global Secret Group leaked AnyWeather (ransomware.live/Global Secret Group)
    Victim: AnyWeather | Group: Global Secret Group | Website: ohrestorationservices.com | Country: US | Details: Country: Kentucky, United States |
    Website: ohrestorationservices.com |
    Revenue: $6 Million |
    Industry: Construction |
    Employees: 30 Employees |
    Properties: 301 GB (33,041 Files, 4,133 Folders)

    [5] [RANSOMWARE] Global Secret Group leaked Middendorf Animal Hospital & Laser Centre (ransomware.live/Global Secret Group)
    Victim: Middendorf Animal Hospital & Laser Centre | Group: Global Secret Group | Website: middendorfanimalhospital.com | Country: US | Details: Country: Kentucky, United States |
    Website: middendorfanimalhospital.com |
    Revenue: <$5 Million |
    Industry: Healthcare Services,Veterinary Services |
    Employees: 11-50 |
    Properties: 28.1 GB (34,237 Files, 8,806 Folders)

    [5] [RANSOMWARE] Global Secret Group leaked Chappell Supply & Equipment (ransomware.live/Global Secret Group)
    Victim: Chappell Supply & Equipment | Group: Global Secret Group | Website: chappellsupply.com | Country: US | Details: Country: Oklahoma, United States |
    Website: chappellsupply.com |
    Revenue: $9.2 Million |
    Industry: Consumer Services,Retail,Manufacturing,Repair Services |
    Employees: 11-50 |
    Properties: 160 GB (268,758 Files, 30,522 Folders)

    [5] [RANSOMWARE] Global Secret Group leaked La Sevillanita (ransomware.live/Global Secret Group)
    Victim: La Sevillanita | Group: Global Secret Group | Website: lasevillanita.com | Country: AR | Details: Country: Argentina |
    Website: lasevillanita.com |
    Revenue: $15 million |
    Industry: Freight & Logistics Services,Transportation |
    Employees: 11-50 |
    Properties: 200 GB (385,318 Files, 13,074 Folders)

    [5] [RANSOMWARE] Global Secret Group leaked One Plus Capital (ransomware.live/Global Secret Group)
    Victim: One Plus Capital | Group: Global Secret Group | Website: onepluscapital.net | Country: CY | Details: Country: Cyprus |
    Website: onepluscapital.net |
    Revenue: $7 Million |
    Industry: Finance |
    Employees: 11-50 |
    Properties: 117 GB (285,919 Files, 32,404 Folders)

    [5] [RANSOMWARE] Global Secret Group leaked Acens | Cloud & Backup (ransomware.live/Global Secret Group)
    Victim: Acens | Cloud & Backup | Group: Global Secret Group | Website: acens.com | Country: ES | Details: Country: Spain |
    Website: acens.com |
    Revenue: $46.3 Million |
    Industry: Hosting |
    Employees: 201-500

    [5] [RANSOMWARE] Global Secret Group leaked West Nova Fuels & Superline Fuels (ransomware.live/Global Secret Group)
    Victim: West Nova Fuels & Superline Fuels | Group: Global Secret Group | Website: westnovasuperline.ca | Country: CA | Details: Country: Canada |
    Website: westnovasuperline.ca |
    Revenue: $18.9 Million |
    Industry: Convenience Stores, Gas Stations & Liquor Stores |
    Employees: 51-200 |
    Properties: 45.8 GB (114,200 Files, 2,672 Folders)

    [5] [RANSOMWARE] Global Secret Group leaked Sinop Energia (ransomware.live/Global Secret Group)
    Victim: Sinop Energia | Group: Global Secret Group | Website: sinopenergia.com.br | Country: BR | Details: Country: Brazil |
    Website: sinopenergia.com.br |
    Revenue: $12.2 Million |
    Industry: Electricity, Oil & Gas |
    Employees: 51-200 |
    Properties:300 GB (43,113 Files, 5,372 Folders)

    [5] [RANSOMWARE] Global Secret Group leaked Al Hayat | Pepsi (ransomware.live/Global Secret Group)
    Victim: Al Hayat | Pepsi | Group: Global Secret Group | Website: alhayatco.com | Country: IQ | Details: Country: Iraq |
    Website: alhayatco.com |
    Revenue: $100 Million |
    Industry: Food & Beverage |
    Employees: 501-1,000 |
    Properties: 138 GB (205,992 Files, 17,178 Folders)

    [5] [RANSOMWARE] Global Secret Group leaked SPDM (ransomware.live/Global Secret Group)
    Victim: SPDM | Group: Global Secret Group | Website: spdm.org.br | Country: BR | Details: Country: Brazil |Website: spdm.org.br |Revenue: $197 Million |Industry: Hospitals & Clinics |Employees: 10.000 – 20.000 |Properties: 847 GB (871,912 Files, 76,047 Folders)

    [5] [RANSOMWARE] Global Secret Group leaked Nourison | Home (ransomware.live/Global Secret Group)
    Victim: Nourison | Home | Group: Global Secret Group | Website: nourison.com | Country: US | Details: Country: New Jersey 07663, US |
    Website: nourison.com |
    Revenue: $59.4 Million |
    Industry: Wholesale, Furniture, Home Decor, Retail, Real Estate |
    Employees: 100-300 |
    Properties: 799 GB (93,941 Files, 13,733 Folders)

    [5] [RANSOMWARE] Global Secret Group leaked Cold Front Distribution (ransomware.live/Global Secret Group)
    Victim: Cold Front Distribution | Group: Global Secret Group | Website: coldfrontdist.com | Country: US | Details: Country: Colorado, United States |
    Website: coldfrontdist.com |
    Revenue: $120.1 Million |
    Industry: Transportation |
    Employees: 201-500 Employees |
    Properties: 473 GB (890,775 Files, 51,621 Folders)

    [5] [RANSOMWARE] Global Secret Group leaked Portman Finance Group (ransomware.live/Global Secret Group)
    Victim: Portman Finance Group | Group: Global Secret Group | Website: portmanfinancegroup.co.uk | Country: GB | Details: Country: United Kingdom |
    Website: portmanfinancegroup.co.uk |
    Revenue: £300 Million |
    Industry: Finance |
    Employees: 1000-5000 Employees |
    Properties: 209 GB (255,244 Files, 34,852 Folders)

    [5] [RANSOMWARE] Global Secret Group leaked OFS (ransomware.live/Global Secret Group)
    Victim: OFS | Group: Global Secret Group | Website: ofs.com | Country: US | Details: Country: Indiana, United States |
    Website: ofs.com |
    Revenue: $517.1 Million |
    Industry: Furniture,Manufacturing,Transportation |
    Employees: 1K – 5K |
    Properties: 321 GB (322,742 Files, 18,081 Folders)

    [5] [RANSOMWARE] Global Secret Group leaked Uniview Technologies (ransomware.live/Global Secret Group)
    Victim: Uniview Technologies | Group: Global Secret Group | Website: uniview.com | Country: CN | Details: Country: China |
    Website: uniview.com |
    Revenue: $610 Million |
    Industry: Manufacturing, Electronics |
    Employees: 1000-5000 Employees |
    Properties: 1.5 TB (2,172,194 Files, 114,352 Folders)

    [5] [RANSOMWARE] Global Secret Group leaked Novum Energy (ransomware.live/Global Secret Group)
    Victim: Novum Energy | Group: Global Secret Group | Website: novumenergy.com | Country: US | Details: Country: Texas, United States |
    Website: novumenergy.com |
    Revenue: $966 Million |
    Industry: Convenience Stores, Gas Stations & Liquor Stores |
    Employees: 51-200 |
    Properties: 842 GB (971,325 Files, 117,085 Folders)

    [5] [RANSOMWARE] chaos leaked remco.ca (ransomware.live/chaos)
    Victim: remco.ca | Group: chaos | Website: remco.ca | Country: CA | Details: Founded in 1977 and headquartered in Quebec, Canada, Remco is an industry leader in warehousing, transportation and country-wide distribution for the retail industry

    [5] [RANSOMWARE] qilin leaked Contacto Garantido (ransomware.live/qilin)
    Victim: Contacto Garantido | Group: qilin | Website: www.contactogarantido.com | Country: MX | Details: N/A

    [5] [RANSOMWARE] qilin leaked Universitatea de Vest „Vasile Goldiș” din Arad (ransomware.live/qilin)
    Victim: Universitatea de Vest „Vasile Goldiș” din Arad | Group: qilin | Website: www.uvvg.ro | Country: RO | Details: N/A

    [5] [RANSOMWARE] m3rx leaked hydraulic-components.net (ransomware.live/m3rx)
    Victim: hydraulic-components.net | Group: m3rx | Website: hydraulic-components.net | Country: DE | Details: +44 1142764430 , VHS Hydraulics is a prominent supplier of hydraulic components and power packs, featuring products from renowned brands like Rexroth, Walvoil, and Casappa. With over 25 years of experience, they specialize in engineering bespoke power packs for demanding applications. Based in Sheff

    [5] [RANSOMWARE] m3rx leaked createinfor.pt (ransomware.live/m3rx)
    Victim: createinfor.pt | Group: m3rx | Website: createinfor.pt | Country: PT | Details: +351 262187684 , CreateInfor is a company that operates in the Repair Services industry. It employs 10to19 people and has 500Kto1M of revenue. The company is headquartered in Caldas da Rainha, Leiria, Portugal. Stolen: —

    [5] [RANSOMWARE] m3rx leaked servicebypremier.com (ransomware.live/m3rx)
    Victim: servicebypremier.com | Group: m3rx | Website: servicebypremier.com | Country: US | Details: +1(954) 646-0016 , This local HVAC and Refrigeration company, established in 2007, provides services across South Florida, from Florida City to Port St. Lucie. They specialize in commercial HVAC and refrigeration repairs, including maintenance for A/C and refrigeration equipment. The company prides

    [5] [RANSOMWARE] ExfilSquad leaked Analog Devices (ransomware.live/ExfilSquad)
    Victim: Analog Devices | Group: ExfilSquad | Website: analog.com | Country: US | Details: Revenue: $12.7B

    DATA SUMMARY:
    570K~ records containing: customer PII and addresses.

    [5] [RANSOMWARE] ExfilSquad leaked Bonava (ransomware.live/ExfilSquad)
    Victim: Bonava | Group: ExfilSquad | Website: bonava.se | Country: SE | Details: Revenue: SEK 8B

    DATA SUMMARY:
    842K~ records containing: significant PII, property ownership/interests, warranty and repair cases, contractor information, marketing preferences, and customer service history.

    [5] [RANSOMWARE] ExfilSquad leaked City of Atlanta (ransomware.live/ExfilSquad)
    Victim: City of Atlanta | Group: ExfilSquad | Website: atlantaga.gov | Country: US | Details: DATA SUMMARY:
    3M~ records containing: significant PII, citizen service requests, addresses, municipal case history, and internal case management data.

    [5] [RANSOMWARE] ExfilSquad leaked City of Houston (ransomware.live/ExfilSquad)
    Victim: City of Houston | Group: ExfilSquad | Website: houstontx.gov | Country: US | Details: DATA SUMMARY:
    6M~ records containing: significant PII, resident contact details, service requests, complaint descriptions, addresses, location data, case/ticket metadata, department routing, service status, resolution information, and extensive CRM metadata.

    [5] [RANSOMWARE] ExfilSquad leaked Viavi Solutions (ransomware.live/ExfilSquad)
    Victim: Viavi Solutions | Group: ExfilSquad | Website: viavisolutions.com | Country: US | Details: Revenue: $1B

    DATA SUMMARY:
    430K~ records containing: customer and partner contact information, significant PII, and enterprise account identifiers.

    [5] [RANSOMWARE] ExfilSquad leaked Newcastle University (ransomware.live/ExfilSquad)
    Victim: Newcastle University | Group: ExfilSquad | Website: ncl.ac.uk | Country: GB | Details: DATA SUMMARY:
    440K~ records containing: applicant and student contact information, significant PII, and admissions data.

    [5] [RANSOMWARE] ExfilSquad leaked Zenith Bank Plc (ransomware.live/ExfilSquad)
    Victim: Zenith Bank Plc | Group: ExfilSquad | Website: zenithbank.com | Country: NG | Details: Revenue: ₦2.3T

    DATA SUMMARY:
    90M~ records containing: extensive PII, banking relationships, account information, financial data, government identifiers, customer contact information, and banking support cases.

    [5] [RANSOMWARE] ExfilSquad leaked Frontier Airlines (ransomware.live/ExfilSquad)
    Victim: Frontier Airlines | Group: ExfilSquad | Website: flyfrontier.com | Country: US | Details: Revenue: $1.5B

    DATA SUMMARY:
    2.4M~ records containing: significant PII, customer support cases, flight and travel information, complaint records, baggage details, and customer support email communications.

    [5] [RANSOMWARE] ExfilSquad leaked TaylorMade & Sun Day Red golf (ransomware.live/ExfilSquad)
    Victim: TaylorMade & Sun Day Red golf | Group: ExfilSquad | Website: taylormadegolf.com | Country: US | Details: Revenue: $1.5B

    DATA SUMMARY:
    2M~ records containing: significant PII, customer support history, orders, shipping information, business account data, financial/account information, internal notes, attachments, and AI support chat transcripts.

    [5] [RANSOMWARE] ExfilSquad leaked Allstate (ransomware.live/ExfilSquad)
    Victim: Allstate | Group: ExfilSquad | Website: allstate.com | Country: US | Details: Revenue: $67B

    DATA SUMMARY:
    657K~ records containing: significant PII, recruitment and licensing information, onboarding data, and internal employee account information.

    [5] [RANSOMWARE] ExfilSquad leaked Microsoft (ransomware.live/ExfilSquad)
    Victim: Microsoft | Group: ExfilSquad | Website: microsoft.com | Country: US | Details: Revenue: $318B

    DATA SUMMARY:
    8M~ records containing: significant PII, employee and customer contact information, authentication data, password hashes, portal identities, corporate account information, business leads, facilities management records, internal service tickets, and access permissions.

    [5] [RANSOMWARE] ExfilSquad leaked UK Department for Education (ransomware.live/ExfilSquad)
    Victim: UK Department for Education | Group: ExfilSquad | Website: education.gov.uk | Country: GB | Details: DATA SUMMARY:
    Help Portal (~600K records) – Parent and staff contact records containing full names, email addresses, phone numbers, and job titles.

    Turing Portal (~7K records) – Contact records containing full names, email addresses, phone numbers, and job titles.

    [5] [RANSOMWARE] arcusmedia leaked Brazer Ingenierie (ransomware.live/arcusmedia)
    Victim: Brazer Ingenierie | Group: arcusmedia | Website: brazeringenierie.com | Country: MA | Details: Brazer Ingénierie is a professional integrator specializing in IT and telecommunications s Deadline: 2026-08-01 21:06:00.000000

    [5] [RANSOMWARE] arcusmedia leaked Power Moendas (ransomware.live/arcusmedia)
    Victim: Power Moendas | Group: arcusmedia | Website: powermoendas.com.br | Country: BR | Details: Based in the sugar-energy industrial hub, in the city of Sertãozinho/SP, Power Empral has Deadline: 2026-08-01 21:06:00.000000

    [5] [RANSOMWARE] Doommageddon leaked iw steelTEC Makine San. ve Tic. A.Ş. (ransomware.live/Doommageddon)
    Victim: iw steelTEC Makine San. ve Tic. A.Ş. | Group: Doommageddon | Country: TR | Details: Status: leaked | Data size: 100 GB | Files: 0 files | Deadline: 2026-03-08T00:00:00Z

    SUMMARY

    Total new items: 98
    Critical count: 1
    Ransomware victims today: 95
    CISA KEV items: 0

    Companion HTML report: download report

  • Cybersecurity Intelligence Report – 2026-07-24

    Companion HTML report: Download HTML report

    Today: 98 new items; 2 critical.

  • Cybersecurity Intelligence Report  2026-07-23

    Companion HTML report: Download HTML report

    CRITICAL SECTION

    [12] CISA orders urgent action on actively exploited Langflow RCE flaw (BleepingComputer)
    The Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday ordered U.S. government agencies to prioritize patching an actively exploited vulnerability in the Langflow visual framework for building AI agents. […]

    CISA KEV (Known Exploited Vulnerabilities)

    CVE Vendor/Product Score Required Action
    CVE-2026-16232 CISA KEV 6 Assess and patch immediately
    CVE-2026-50522 CISA KEV 6 Assess and patch immediately

    RANSOMWARE VICTIMS (DLS Monitoring)

    [RANSOMWARE] dragonforce leaked Koshkaryan Law Group: [RANSOMWARE] dragonforce leaked Koshkaryan Law Group

    [RANSOMWARE] kairos leaked LR Reed: [RANSOMWARE] kairos leaked LR Reed

    [RANSOMWARE] nova leaked VNSO: [RANSOMWARE] nova leaked VNSO

    [RANSOMWARE] blacknevas leaked Zuni Shopping Center, Inc.: [RANSOMWARE] blacknevas leaked Zuni Shopping Center, Inc.

    [RANSOMWARE] qilin leaked P & A Construction: [RANSOMWARE] qilin leaked P & A Construction

    [RANSOMWARE] BrainCipher leaked windiam.com: [RANSOMWARE] BrainCipher leaked windiam.com

    [RANSOMWARE] qilin leaked Primeline Logistics: [RANSOMWARE] qilin leaked Primeline Logistics

    [RANSOMWARE] qilin leaked Recsa: [RANSOMWARE] qilin leaked Recsa

    [RANSOMWARE] qilin leaked Salida Union School District: [RANSOMWARE] qilin leaked Salida Union School District

    [RANSOMWARE] chaos leaked neopharmlabs.com: [RANSOMWARE] chaos leaked neopharmlabs.com

    [RANSOMWARE] qilin leaked Cpcg: [RANSOMWARE] qilin leaked Cpcg

    [RANSOMWARE] qilin leaked EFU Life Assurance: [RANSOMWARE] qilin leaked EFU Life Assurance

    [RANSOMWARE] qilin leaked Infina Health: [RANSOMWARE] qilin leaked Infina Health

    [RANSOMWARE] m3rx leaked ubfreight.com: [RANSOMWARE] m3rx leaked ubfreight.com

    [RANSOMWARE] krybit leaked dhli.in: [RANSOMWARE] krybit leaked dhli.in

    [RANSOMWARE] krybit leaked Vibonum Technologies Private Limited: [RANSOMWARE] krybit leaked Vibonum Technologies Private Limited

    [RANSOMWARE] akira leaked Kruse Construction: [RANSOMWARE] akira leaked Kruse Construction

    [RANSOMWARE] akira leaked University Sprinkler Systems: [RANSOMWARE] akira leaked University Sprinkler Systems

    [RANSOMWARE] Booba Project leaked Pelli Clarke Pelli Architects: [RANSOMWARE] Booba Project leaked Pelli Clarke Pelli Architects

    [RANSOMWARE] chaos leaked issvc.com: [RANSOMWARE] chaos leaked issvc.com

    NEWS

    [8] Ubuntu snap-confine Flaw Could Give Local Users Root on Default Desktop Installs (TheHackerNews)
    Cybersecurity researchers have disclosed details of a new local privilege escalation (LPE) vulnerability in snap-confine that an unprivileged user can trigger to obtain root access and gain complete control of a target environment.

    The high-severity flaw, tracked as CVE-2026-8933 (CVSS score: 7.8), impacts default installations of Ubuntu Desktop 24.04, 25.10, and 26.04. The disclosure comes as

    [8] Another SharePoint RCE exploited: Patch, then rotate your machine keys (CVE-2026-50522) (HelpNetSecurity)
    <p>Attackers are exploiting a critical SharePoint remote code execution (RCE) vulnerability (CVE-2026-50522) to extract the servers&#8217; IIS machine keys. &#8220;WatchTowr is observing active exploitation of CVE-2026-50522 against on-premise Microsoft SharePoint deployments following the release of public exploit code, with attackers stealing machine keys to retain long-term access,&#8221; the offensive security company warned on Tuesday. WatchTowr&#8217;s global honeypot network registered su

    [7] [RANSOMWARE] dragonforce leaked Koshkaryan Law Group (ransomware.live/dragonforce)
    Victim: Koshkaryan Law Group | Group: dragonforce | Website: koshlaw.com | Country: US | Details: Koshkaryan Law Group is a legal firm specializing in personal injury and criminal defense cases. They prioritize client service and provide personalized attention to ensure favorable outcomes for their clients. The firm offers free initial consultations and is dedicated to keeping clients informed a

    [5] Swiss rail giant Stadler rejects $12.3M ransom demand after cyberattack (BleepingComputer)
    Swiss rail vehicle manufacturer Stadler Rail says the Everest ransomware gang demanded about $12.3 million after breaching a data exchange platform shared with one of its suppliers. […]

    [5] How enterprise GenAI can amplify ransomware risk — and how to contain it (BleepingComputer)
    Enterprise AI can accelerate ransomware attacks when AI assistants and agents inherit excessive permissions or compromised identities. Acronis explains how identity controls, governance, and least-privilege access help reduce AI-enabled ransomware risk while supporting secure AI adoption. […]

    [5] Hackers Exploit Windmill Flaw to Read Arbitrary Server Files Without Authentication (TheHackerNews)
    A high-severity security flaw impacting open-source developer platform Windmill has come under active exploitation in the wild, per VulnCheck.

    The vulnerability in question is CVE-2026-29059 (CVSS score: 7.5), a case of unauthenticated path traversal impacting Windmill’s “get_log_file” endpoint (“/api/w/{workspace}/jobs_u/get_log_file/{filename}”).

    “The filename parameter is concatenated into

    [5] Lookout identifies exploitable vulnerabilities in mobile apps (HelpNetSecurity)
    <p>Lookout has announced the launch of the Lookout Mobile Software Exposure Center (MSEC). Integrated natively into the Lookout Mobile Endpoint Security platform, MSEC enables organizations to continuously detect, validate, prioritize, and remediate exploitable vulnerabilities across their mobile software ecosystem. The advancement of frontier AI models, such as Anthropic&#8217;s Claude Mythos, marks a fundamental shift in the cybersecurity landscape. By reducing the cost and time required to di

    [5] [RANSOMWARE] kairos leaked LR Reed (ransomware.live/kairos)
    Victim: LR Reed | Group: kairos | Country: AU | Details: LR Reed is a family-owned business with over 30 years of experience, specializing in Owners Corporation management and developer services. They provide a comprehensive range of management services, including asset management, legislative compliance, and financial accounting, ensuring a transparent a

    [5] [RANSOMWARE] nova leaked VNSO (ransomware.live/nova)
    Victim: VNSO | Group: nova | Details: Công nghệ VNSO is a leading provider of cloud and server solutions in Vietnam, offering a wide range of services including hosting, VPS, cloud storage, private cloud, anti-DDoS, and CDN. Their products cater to various needs, from high-performance cloud servers to dedicated servers for gaming and AI

    [5] [RANSOMWARE] blacknevas leaked Zuni Shopping Center, Inc. (ransomware.live/blacknevas)
    Victim: Zuni Shopping Center, Inc. | Group: blacknevas | Country: US | Details: A family-owned commercial corporation incorporated in New Mexico, USA, that owns and operates Halona Plaza, a multi-purpose retail and tourism hub in the heart of the Zuni Pueblo reservation.The business dates back to 1910 and was formally incorporated as Zuni Shopping Center, Inc. in 1961. Over the

    [5] [RANSOMWARE] qilin leaked P & A Construction (ransomware.live/qilin)
    Victim: P & A Construction | Group: qilin | Website: www.paconst.com | Country: US | Details: N/A

    [5] [RANSOMWARE] BrainCipher leaked windiam.com (ransomware.live/BrainCipher)
    Victim: windiam.com | Group: BrainCipher | Website: windiam.com | Details: [AI generated] N/A

    [5] [RANSOMWARE] qilin leaked Primeline Logistics (ransomware.live/qilin)
    Victim: Primeline Logistics | Group: qilin | Website: www.primeline.ie | Country: IE | Details: N/A

    [5] [RANSOMWARE] qilin leaked Recsa (ransomware.live/qilin)
    Victim: Recsa | Group: qilin | Website: www.recsa.com | Country: CR | Details: N/A

    [5] [RANSOMWARE] qilin leaked Salida Union School District (ransomware.live/qilin)
    Victim: Salida Union School District | Group: qilin | Website: www.salida.k12.ca.us | Country: US | Details: N/A

    [5] [RANSOMWARE] chaos leaked neopharmlabs.com (ransomware.live/chaos)
    Victim: neopharmlabs.com | Group: chaos | Website: neopharmlabs.com | Country: US | Details: Notice of Data Escalation: 3% Proof Publication

    Management is ignoring the seriousness of the situation and refusing to engage in dialogue. We are publishing a 3% sample of our 627 GB archive right now.

    We are giving management 48 hours to reach out to us. If they fail to contact us within this ti

    [5] [RANSOMWARE] qilin leaked Cpcg (ransomware.live/qilin)
    Victim: Cpcg | Group: qilin | Website: www.cpcgr.com | Country: BR | Details: N/A

    [5] [RANSOMWARE] qilin leaked EFU Life Assurance (ransomware.live/qilin)
    Victim: EFU Life Assurance | Group: qilin | Website: www.efulife.com | Country: PK | Details: N/A

    [5] [RANSOMWARE] qilin leaked Infina Health (ransomware.live/qilin)
    Victim: Infina Health | Group: qilin | Website: www.infinahealth.com | Details: N/A

    [5] [RANSOMWARE] m3rx leaked ubfreight.com (ransomware.live/m3rx)
    Victim: ubfreight.com | Group: m3rx | Website: ubfreight.com | Details: UB Freight is a leading provider of worldwide freight services, specializing in air and sea freight, customs clearance, and warehousing solutions. They cater to a diverse clientele, including large companies with complex shipping needs and individuals looking to send personal items overseas. With IA

    [5] [RANSOMWARE] krybit leaked dhli.in (ransomware.live/krybit)
    Victim: dhli.in | Group: krybit | Website: dhli.in | Country: IN | Details: Delhi Heart & Lung Institute (DHLI) is a tertiary care 100-bedded super specialty hospital established in 2003 in New De…

    [5] [RANSOMWARE] krybit leaked Vibonum Technologies Private Limited (ransomware.live/krybit)
    Victim: Vibonum Technologies Private Limited | Group: krybit | Website: Vibonum Technologies Private Limited | Country: IN | Details: *** is a recently incorporated Indian private limited company established on March 27, …

    [5] [RANSOMWARE] akira leaked Kruse Construction (ransomware.live/akira)
    Victim: Kruse Construction | Group: akira | Details: Kruse Construction is a mechanical contractor with over 50 years of experience in the petroleum
    and petrochemical industry, specializing in the construction and maintenance of liquid petrole
    um truck, rail, and pipeline terminals. The company also provides services for bulk plants, pip
    eline pump st

    [5] [RANSOMWARE] akira leaked University Sprinkler Systems (ransomware.live/akira)
    Victim: University Sprinkler Systems | Group: akira | Details: University Sprinklers is BC’s largest irrigation company, specializing in the installation of i
    rrigation sprinkler systems and landscape lighting for both residential and commercial clients.
    With over 40 years of experience, they provide tailored irrigation solutions that ensure healt
    hy lawns and

    [5] [RANSOMWARE] Booba Project leaked Pelli Clarke Pelli Architects (ransomware.live/Booba Project)
    Victim: Pelli Clarke Pelli Architects | Group: Booba Project | Website: www.pcparch.com | Country: US | Details: Architecture and Planning Stolen data: 45 GB.

    [5] [RANSOMWARE] chaos leaked issvc.com (ransomware.live/chaos)
    Victim: issvc.com | Group: chaos | Website: issvc.com | Country: SG | Details: issvc.com

    Official Notice to Management and Stakeholders

    The time window has expired. Exactly 24 hours remain until the final deadline. If an agreement is not reached by the end of this period, the complete confidential dataset totaling 262 GB will be published into the public domain.

    Compromised

    SUMMARY

    Total new items: 63, critical: 1, ransomware victims today: 20.

    Top CVEs to patch urgently: CVE-2026-50522, CVE-2026-8933, CVE-2026-16232, CVE-2026-29059, CVE-2026-48294.

    Sources: BleepingComputer, TheHackerNews, SecurityWeek, HelpNetSecurity, KrebsOnSecurity, CISA KEV, ransomware.live

  • Cybersecurity Intelligence Report — 2026-07-21

    Cybersecurity Intelligence Report — 2026-07-21

    CRITICAL SECTION

    • [14] ServiceNow pre-auth RCE exploited in the wild (CVE-2026-6875) (HelpNetSecurity) — CVEs: CVE-2026-6875
      <p>Attackers have begun exploiting CVE-2026-6875, a critical pre-authentication vulnerability in the ServiceNow AI Platform, according to threat intelligence firm Defused. About the vulnerability ServiceNow AI is a Platform-as-a-Service that lets organizations build and automate digital workflows. CVE-2026-6875 is a code injection vulnerability that lets unauthenticated attackers escape ServiceNow’s script sandbox and execute code remotely on a targeted instance. The vulnerability was unea
    • [12] ⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More (TheHackerNews)
      A single request should not be able to do this much. But this week, small inputs led to code execution, memory loss, stolen keys, and disabled security tools.

      The paths were often simple: exposed systems, weak checks, old drivers, fake prompts, and public code used for malware delivery. Some bugs were new. Others were already being used before defenders had time to patch.

      Here is the full

    CISA KEV

    No CISA KEV items in the last 14 days.

    RANSOMWARE VICTIMS (DLS MONITORING)

    Unknown: [RANSOMWARE] nova leaked Jrd logistics, [RANSOMWARE] akira leaked McKeever , Varga & Senko, [RANSOMWARE] safepay leaked wdk.de, [RANSOMWARE] safepay leaked jaecklin-industrial.de, [RANSOMWARE] safepay leaked lbb-treuhand.de, [RANSOMWARE] safepay leaked timetex.de, [RANSOMWARE] safepay leaked stroebel-gruppe.de, [RANSOMWARE] safepay leaked industriesjaro.com, [RANSOMWARE] safepay leaked cenesco.de, [RANSOMWARE] safepay leaked acsmallmaxwell.com.au, [RANSOMWARE] safepay leaked mende-grundbesitz.de, [RANSOMWARE] kairos leaked College O’Sullivan de Québec, [RANSOMWARE] kairos leaked Collge O’Sullivan de Québec, [RANSOMWARE] incransom leaked Ali-Monde, [RANSOMWARE] coinbasecartel leaked Caterpillar, [RANSOMWARE] anubis leaked Bath Fitter, [RANSOMWARE] anubis leaked Fairlife / Coca-Cola, [RANSOMWARE] nova leaked Rumah Sakit Universitas Indonesia (RSUI), [RANSOMWARE] nova leaked Universidad Nacional de Mar del Plata, [RANSOMWARE] coinbasecartel leaked Colliers Real Estate, [RANSOMWARE] akira leaked L&A Transport, [RANSOMWARE] nova leaked Koplarla, [RANSOMWARE] qilin leaked Bolt & Nut Manufacturing, [RANSOMWARE] chaos leaked wikoff.com

    NEWS

    [9] Russian-Speaking Hacker Uses Google Gemini CLI to Control Botnet of Eight Dental Clinic PCs (TheHackerNews) — A solo Russian-speaking threat actor known as “bandcampro” outsourced a chunk of their operations to Google’s open-source Gemini CLI artificial intelligence (AI) and commandeered a live botnet.

    The findings come from an analysis of 200 Gemini CLI session logs between March 19 and April 21, 2026, which found the threat actor using AI, among other things, to crack passwords, set up a residential

    [9] [RANSOMWARE] nova leaked Jrd logistics (ransomware.live/nova) — Victim: Jrd logistics | Group: nova | Details: Jrd logistics LTD is an India-based freight forwarding and supply chain company headquartered in Kolkata that provides international logistics, customs clearance, warehousing, and multimodal transport services – Nova Provide tree and samples from stolen data to the company when its get in touch with

    [8] Critical ServiceNow code execution flaw now exploited in attacks (BleepingComputer) — Attackers have begun exploiting a critical vulnerability (CVE-2026-6875) in the ServiceNow AI Platform, according to threat intelligence company Defused. […]

    [8] SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch (SecurityWeek) — <p>The zero-days CVE-2026-15409 and CVE-2026-15410 were exploited by a threat actor tracked by Volexity as UTA0533.</p>
    <p>The post <a href=”https://www.securityweek.com/sonicwall-zero-days-exploited-to-deliver-custom-malware-for-weeks-before-patch/”>SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch</a> appeared first on <a href=”https://www.securityweek.com”>SecurityWeek</a>.</p>

    [8] WP2Shell WordPress Vulnerabilities Exploited in the Wild (SecurityWeek) — <p>Exploitation of the new WordPress vulnerabilities tracked as CVE-2026-60137 and CVE-2026-63030 started soon after disclosure.</p>
    <p>The post <a href=”https://www.securityweek.com/wp2shell-wordpress-vulnerabilities-exploited-in-the-wild/”>WP2Shell WordPress Vulnerabilities Exploited in the Wild</a> appeared first on <a href=”https://www.securityweek.com”>SecurityWeek</a>.</p>

    [7] [RANSOMWARE] akira leaked McKeever , Varga & Senko (ransomware.live/akira) — Victim: McKeever , Varga & Senko | Group: akira | Details: McKeever Varga & Senko is a firm of Certified Public Accountants dedicated to providing superio
    r client service and professional guidance. They offer a range of services including informativ
    e articles, interactive financial calculators, and links to external resources to assist their
    clients.

    We

    [6] Estée Lauder discloses data breach via Oracle E-Business flaw (BleepingComputer) — Cosmetics giant Estée Lauder is notifying customers of a data breach after hackers exploited a flaw in Oracle E-Business Suite that the company used for human resources (HR) operations. […]

    [6] SonicWall SMA1000 flaws exploited as zero-days to push custom malware (BleepingComputer) — Two recently disclosed SonicWall SMA1000 vulnerabilities were exploited in zero-day attacks for weeks, allowing threat actors to install custom malware on vulnerable VPN appliances. […]

    [6] World’s Largest AI Model Repository Hugging Face Breached by Autonomous AI Agent (TheHackerNews) — In an ironic twist, open-source artificial intelligence (AI) platform Hugging Face revealed that it was the victim of a hack perpetrated by an autonomous AI agent system.

    The company said it detected and responded to the incident targeting its production infrastructure earlier last week.

    “We identified unauthorized access to a limited set of internal datasets and to several credentials used by

    [6] New Index Tracks Material Breaches — And Refuses to Add Up the Losses (SecurityWeek) — <p>Longtime cybersecurity executive Richard Bird built the resource for security experts, journalists, policymakers, and everyday citizens.</p>
    <p>The post <a href=”https://www.securityweek.com/new-index-tracks-material-breaches-and-refuses-to-add-up-the-losses/”>New Index Tracks Material Breaches — And Refuses to Add Up the Losses</a> appeared first on <a href=”https://www.securityweek.com”>SecurityWeek</a>.</p>

    [6] Hugging Face breached by autonomous AI agent (HelpNetSecurity) — <p>Hugging Face, the widely used platform for sharing open-source machine learning models and datasets, has disclosed a security breach it says was carried out by an autonomous AI agent system. How the attack unfolded In a blog post published Thursday (July 16), the company said that earlier that week, it identified unauthorized access to some internal datasets and to several credentials used by its services. The intrusion was executed via a malicious dataset that abused … <a href=”https:/

    [5] More alerts are making your team slower, and an outcome-based SOC fixes that (HelpNetSecurity) — <p>In this Help Net Security video, Thom Langford, EMEA CTO, Rapid7, explains why piling on more security alerts makes a SOC slower to respond. Attackers log in with stolen credentials and use trusted tools like PowerShell instead of custom malware. He shares a case where attackers called a help desk, reset a privileged cloud account, and exposed thousands of passwords in three minutes. Ransomware groups can go from access to payload in under three hours. … <a href=”https://www.helpnetsecu

    [5] [RANSOMWARE] safepay leaked wdk.de (ransomware.live/safepay) — Victim: wdk.de | Group: safepay | Website: wdk.de | Country: DE | Details: Founded in 1950 and headquartered in Frankfurt am Main, the organization serves as the central voice of German manufacturers of …

    [5] [RANSOMWARE] safepay leaked jaecklin-industrial.de (ransomware.live/safepay) — Victim: jaecklin-industrial.de | Group: safepay | Website: jaecklin-industrial.de | Country: DE | Details: Founded in 1935 by Julius Jäcklin, the company has developed from a regional machine repair workshop into a globally recognized …

    [5] [RANSOMWARE] safepay leaked lbb-treuhand.de (ransomware.live/safepay) — Victim: lbb-treuhand.de | Group: safepay | Website: lbb-treuhand.de | Country: DE | Details: The company specializes in tax consulting, auditing, accounting, payroll administration, financial reporting, and business advisory services for private individuals, self-employed …

    [5] [RANSOMWARE] safepay leaked timetex.de (ransomware.live/safepay) — Victim: timetex.de | Group: safepay | Website: timetex.de | Country: DE | Details: The company traces its origins to 1991, when the TimeTEX brand was acquired and expanded into a comprehensive supplier of …

    [5] [RANSOMWARE] safepay leaked stroebel-gruppe.de (ransomware.live/safepay) — Victim: stroebel-gruppe.de | Group: safepay | Website: stroebel-gruppe.de | Country: DE | Details: Headquartered in Langenzenn, Bavaria, the company was founded in 1978 by Gerlinde and Gerhard Ströbel and has grown from a …

    [5] [RANSOMWARE] safepay leaked industriesjaro.com (ransomware.live/safepay) — Victim: industriesjaro.com | Group: safepay | Website: industriesjaro.com | Country: CA | Details: Over several decades, Jaro has evolved from manufacturing telephone booths into a supplier of advanced outdoor enclosures, interactive kiosks, bus …

    [5] [RANSOMWARE] safepay leaked cenesco.de (ransomware.live/safepay) — Victim: cenesco.de | Group: safepay | Website: cenesco.de | Country: DE | Details: Founded in 1998, the company provides comprehensive information technology solutions for small and medium-sized enterprises (SMEs), helping organizations modernize their …

    [5] [RANSOMWARE] safepay leaked acsmallmaxwell.com.au (ransomware.live/safepay) — Victim: acsmallmaxwell.com.au | Group: safepay | Website: acsmallmaxwell.com.au | Country: AU | Details: Founded in 1916 by Ambrose Cecil Small, the firm has provided professional accounting and financial services to businesses and individuals …

    [5] [RANSOMWARE] safepay leaked mende-grundbesitz.de (ransomware.live/safepay) — Victim: mende-grundbesitz.de | Group: safepay | Website: mende-grundbesitz.de | Country: DE | Details: Founded in 1994, the company specializes in the professional administration of residential, commercial, and mixed-use real estate throughout the Berlin …

    [5] [RANSOMWARE] kairos leaked College O’Sullivan de Québec (ransomware.live/kairos) — Victim: College O’Sullivan de Québec | Group: kairos | Country: CA | Details: Collège O’Sullivan de Québec offers a variety of training programs both in-class and online, focusing on fields such as administration, insurance, office management, IT, web development, and marketing. The institution aims to equip students with the skills needed for the job market and higher educat

    [5] [RANSOMWARE] kairos leaked Collge O’Sullivan de Québec (ransomware.live/kairos) — Victim: Collge O’Sullivan de Québec | Group: kairos | Country: CA | Details: Collège O’Sullivan de Québec offers a variety of training programs both in-class and online, focusing on fields such as administration, insurance, office management, IT, web development, and marketing. The institution aims to equip students with the skills needed for the job market and higher educat

    [5] [RANSOMWARE] incransom leaked Ali-Monde (ransomware.live/incransom) — Victim: Ali-Monde | Group: incransom | Country: US | Details: Ali-Monde is a food production and distribution company that’s been around for over 50 years. They’ve got 5 of their own brands and an impressive lineup of 800+ dry, organic, and gluten-free products. Based just south of Montreal, they distribute food across Quebec, Ontario, New Brunswick, and parts

    [5] [RANSOMWARE] coinbasecartel leaked Caterpillar (ransomware.live/coinbasecartel) — Victim: Caterpillar | Group: coinbasecartel | Country: US | Details: [AI generated] Caterpillar Inc. is an American multinational corporation headquartered in Irving, Texas. It is the world’s leading manufacturer of construction and mining equipment, diesel and natural gas engines, industrial gas turbines, and diesel-electric locomotives. Operating in over 190 countr

    [5] [RANSOMWARE] anubis leaked Bath Fitter (ransomware.live/anubis) — Victim: Bath Fitter | Group: anubis | Country: US | Details: Employee data breach at a major manufacturing company.

    [5] [RANSOMWARE] anubis leaked Fairlife / Coca-Cola (ransomware.live/anubis) — Victim: Fairlife / Coca-Cola | Group: anubis | Country: US | Details: www.fairlife.com

    [5] [RANSOMWARE] nova leaked Rumah Sakit Universitas Indonesia (RSUI) (ransomware.live/nova) — Victim: Rumah Sakit Universitas Indonesia (RSUI) | Group: nova | Country: ID | Details: Rumah Sakit Universitas Indonesia (RSUI) is the teaching hospital of the University of Indonesia, providing advanced medical care, education, and clinical research in Indonesia – medical data from drive at risk, Nova Provide tree and samples from stolen data to the company when its get in touch with

    [5] [RANSOMWARE] nova leaked Universidad Nacional de Mar del Plata (ransomware.live/nova) — Victim: Universidad Nacional de Mar del Plata | Group: nova | Country: AR | Details: The Universidad Nacional de Mar del Plata offers a wide range of academic programs, including undergraduate and postgraduate degrees, vocational training, and distance education. It serves students, faculty, and the broader community by promoting research, innovation, and cultural activities. The un

    [5] [RANSOMWARE] coinbasecartel leaked Colliers Real Estate (ransomware.live/coinbasecartel) — Victim: Colliers Real Estate | Group: coinbasecartel | Country: US | Details: [AI generated] Colliers International is a global commercial real estate services company headquartered in Toronto, Canada. It operates across more than 60 countries, offering services including property management, investment sales, leasing, valuation, and advisory. The firm serves corporate, insti

    [5] [RANSOMWARE] akira leaked L&A Transport (ransomware.live/akira) — Victim: L&A Transport | Group: akira | Details: L & A Transport is a reputable trucking company with over 50 years of experience in providing a
    wide range of shipping services, including international shipping, white glove handling, and l
    ogistics solutions for businesses of all sizes. They specialize in truckloads, container loads,
    less than con

    [5] [RANSOMWARE] nova leaked Koplarla (ransomware.live/nova) — Victim: Koplarla | Group: nova | Website: kopkarla.com | Country: ID | Details: Koperasi Konsumen Karyawan PT Aplikanusa Lintasarta (KOPKARLA) was established in 1992 and at that time was focusing on saving and loan business. Since 1998, KOPKARLA has evolved and expanded its business to provide an installation services and solution of telecommunication network (datacomm)

    [5] [RANSOMWARE] qilin leaked Bolt & Nut Manufacturing (ransomware.live/qilin) — Victim: Bolt & Nut Manufacturing | Group: qilin | Website: www.bnml.co.uk | Country: GB | Details: N/A

    [5] [RANSOMWARE] chaos leaked wikoff.com (ransomware.live/chaos) — Victim: wikoff.com | Group: chaos | Website: wikoff.com | Country: US | Details: [PUBLIC DISCLOSURE]

    Target: Wikoff Color Corporation (wikoff.com)
    Data Volume: 650 GB
    Status: Full Compromise Confirmed

    We are officially confirming that the entire internal infrastructure of Wikoff Color Corporation—ranging from Board of Directors financial reports and proprietary R&D formulas…

    SUMMARY

    Total new items: 65. Critical: 2. Ransomware groups active today: 1.

    Top CVEs to patch urgently: CVE-2026-6875 (2), CVE-2026-15409 (1), CVE-2026-15410 (1), CVE-2026-63030 (1), CVE-2026-60137 (1).

    Sources: BleepingComputer, TheHackerNews, SecurityWeek, HelpNetSecurity, KrebsOnSecurity, CISA KEV, ransomware.live

    Companion HTML report: Full HTML report

  • Cybersecurity Daily  2026-07-20

    Companion HTML report: Download HTML report (zip)

    CRITICAL SECTION

    None today.

    CISA KEV (last 14 days)

    None listed in the collector output.

    RANSOMWARE VICTIMS (today)

    Doommageddon: Reni Farmácias Associadas

    unsafe: CCR Solutions

    qilin: PP+K, Eana, Synergy Products, Don Tortaco Mexican Grill, Associated Theatrical Contractors, City Ambulance Service, Famesa

    nova: meralmanisa, Dephub, Jota Joias Premium

    krybit: eurohold.bg

    payload: CKR Consulting Engineers

    blackout: yano.tokyo, www.miatech.net, bluebellgroup.com

    thegentlemen: Ecopetrol

    ULose: KyungRok, NRCapital, HanDok, HIZE Aero, MSICapital

    The Green Blood Group: DAF SENEGAL, ECOBAT EGYPT

    NEWS

    1. [9] Week in review: High severity WordPress vulnerabilities, fake OAuth IDs bypass sign-in logs (HelpNetSecurity) — Reports indicate WordPress-related flaws and OAuth client ID spoofing that may bypass sign-in logs; review authentication logs and apply patches.
  • [8] Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution (TheHackerNews) — A vulnerability reported in NGINX can crash worker processes and may allow remote code execution; administrators should apply vendor updates and restart affected services. CVE(s): CVE-2026-42533
  • [7] UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices wih Malware (TheHackerNews) — Russian state-sponsored threat actors have been observed leveraging the infamous ClickFix strategy to trick Ukrainian targets into infecting their own machines with data-stealing malware.

    According to the Computer Emergency Response Team of Ukraine (CERT-UA), the activity has been attributed to UAC-0145, a sub-cluster within Sandworm, an advanced hacking unit affiliated with GRU, Russia’s

  • [6] SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access (TheHackerNews) — Several zero-day flaws in SonicWall SMA appliances are reported to have been exploited before disclosure; isolate affected appliances and seek vendor mitigations.
  • SUMMARY

    Total new items: 30

    Critical count: 0

    Ransomware victims listed: 25

    Top CVEs to patch urgently: CVE-2026-42533

    Sources: BleepingComputer, TheHackerNews, SecurityWeek, HelpNetSecurity, KrebsOnSecurity, CISA KEV, ransomware.live