Daily cybersecurity intelligence digest for 14 June 2026. Our automated collection pipeline processed feeds from BleepingComputer, The Hacker News, SecurityWeek, Help Net Security, KrebsOnSecurity, the CISA Known Exploited Vulnerabilities catalogue and ransomware.live data-leak-site monitoring. Below is today’s prioritised analysis.
1. Critical alerts (score ≥ 10)
[11] [RANSOMWARE] lapsus$ leaked INGKA GROUP (ransomware.live) A major data-leak event affecting INGKA GROUP (SE). This represents a high-severity breach with substantial organisational exposure and should be treated as a priority for affected supply chains.
2. CISA Known Exploited Vulnerabilities (last 14 days)
No new CISA KEV catalogue additions were recorded in today’s collection window.
3. Ransomware victims — data-leak-site monitoring
lapsus$: INGKA GROUP (SE); GITHUB INTERNAL (US)
shinyhunters: coe.int (FR)
krybit: www.mbt-energy.com (DE)
securotrop: Charisma Media (US)
Black X: Daechang Solution (KR)
Triple X: Bni.co.id bank of indonesia free data. (ID); Law Offices US immigrationonline.com (US)
Listings reflect claims published on criminal data-leak sites and have not been independently verified. Organisations named should treat these as alleged compromises pending confirmation.
4. Security news (score ≥ 5)
Critical Splunk Enterprise Flaw Lets Attackers Run Code Without Authentication (CVE-2026-20253) — TheHackerNews. Splunk has released security updates to address a critical security flaw in Splunk Enterprise that could be exploited to conduct unauthenticated file operations and even remote code execution.
The vulnerability, tracked
5. Summary
Total new items analysed: 15
Critical items (score ≥ 10): 1
CISA KEV additions: 0
Ransomware data-leak victims: 8 across 6 active group(s)
CVEs to prioritise for patching: CVE-2026-20253
The most pressing patching priority today is CVE-2026-20253 — organisations running affected software should apply the vendor update without delay given the unauthenticated remote-code-execution risk.
Active ransomware operators today: Black X, Triple X, krybit, lapsus$, securotrop, shinyhunters. Defenders should review external attack surface, enforce multi-factor authentication, and validate offline backups.
Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function Vulnerability – Oracle PeopleSoft Enterprise PeopleTools
9
See CISA KEV entry
RANSOMWARE VICTIMS (DLS Monitoring)
Group by ransomware group. Only include today’s victims.
payload: myipo.gov.my
NEWS SECTION
Other scored items (score >= 5)
[13] Google Confirms Exploitation of Oracle PeopleSoft Zero-Day by ShinyHunters (SecurityWeek) – Oracle has mitigated CVE-2026-35273, but it has not publicly confirmed the vulnerability’s in-the-wild exploitation.
The post Google Confirms Exploitation of Oracle PeopleSoft Zero-Day by ShinyHunters…
[11] Researchers release details, PoC for exploited Check Point VPN flaw (CVE-2026-50751) (HelpNetSecurity) – WatchTowr researchers have disclosed a technical analysis and a “Detection Artefact Generator” for CVE-2026-50751, an authentication bypass flaw in Check Point’s Remote Access VPN an…
[8] [RANSOMWARE] shinyhunters leaked Zayo.com & Allstream.com (ransomware.live/shinyhunters) – Victim: Zayo.com & Allstream.com | Group: shinyhunters | Country: US | Details: You wouldn’t want us to describe what data was taken from you publicly here. A fair assessment of this breach in terms o…
[7] LangGraph Flaw Chain Exposes Self-Hosted AI Agents to Remote Code Execution (TheHackerNews) – Cybersecurity researchers have disclosed details of three now-patched security flaws impacting LangGraph, including a critical vulnerability chain that could result in remote code execution.
LangGrap…
[7] Ivanti Sentry Exploitation Attempts Hitting Honeypots (SecurityWeek) – The critical-severity OS command injection vulnerability allows attackers to execute arbitrary code with root privileges.
The post Ivanti Sentry Exploitation Attempts Hitting Honeypots appeared first …
[7] Authorities dismantle crypto laundering service that moved €336 million for cybercriminals (HelpNetSecurity) – An international law enforcement operation has dismantled a cryptocurrency laundering service linked to ransomware groups and other cybercriminals that processed more than €336 million in illicit fund…
[7] [RANSOMWARE] threeam leaked mgrlaw.com (ransomware.live/threeam) – Victim: mgrlaw.com | Group: threeam | Website: mgrlaw.com | Country: US | Details: Mogren, Glessner & Ahrens Law Firm is a full-service law firm located in King County, specializing in family law, div…
[7] [RANSOMWARE] coinbasecartel leaked Demand.io (ransomware.live/coinbasecartel) – Victim: Demand.io | Group: coinbasecartel | Website: Demand.io | Country: US | Details: [AI generated] Demand.io is a technology company based in the United States that operates in the e-commerce and …
[7] [RANSOMWARE] dragonforce leaked Cheoy Lee Shipyards (ransomware.live/dragonforce) – Victim: Cheoy Lee Shipyards | Group: dragonforce | Website: www.cheoylee.com | Country: HK | Details: Cheoy Lee Shipyards Ltd. specializes in the design and manufacturing of a diverse range of vessels…
[7] [RANSOMWARE] dragonforce leaked Al Ishrak Contracting (ransomware.live/dragonforce) – Victim: Al Ishrak Contracting | Group: dragonforce | Website: www.alishrak.com | Country: AE | Details: Al Ishrak Contracting Company, established in 1975 in Dubai, specializes in construction works i…
[7] [RANSOMWARE] dragonforce leaked Corniche Hotel Abu Dhabi (ransomware.live/dragonforce) – Victim: Corniche Hotel Abu Dhabi | Group: dragonforce | Website: abudhabi.corniche-hotels.com | Country: AE | Details: At the heart of the Central Business District. Situated along the stunning Cornic…
[7] [RANSOMWARE] dragonforce leaked A. Liberty Engineering Co. Ltd (ransomware.live/dragonforce) – Victim: A. Liberty Engineering Co. Ltd | Group: dragonforce | Website: aleengg.com.hk | Country: HK | Details: Founded in 1973 as Liberty Electrical Engineering Company Limited, A. Liberty Engineering…
[7] [RANSOMWARE] dragonforce leaked Al Shafar GRC (ransomware.live/dragonforce) – Victim: Al Shafar GRC | Group: dragonforce | Website: www.asgrc.ae | Country: AE | Details: ASGRC is a leading provider of Glass Fiber Reinforced Concrete (GRC) solutions, specializing in the design, …
[7] [RANSOMWARE] dragonforce leaked The DRM (ransomware.live/dragonforce) – Victim: The DRM | Group: dragonforce | Website: www.drm.bh | Country: BH | Details: Durrat Resort Management specializes in providing high-quality resort management services. Their offerings include o…
[6] CISA orders feds to patch actively exploited Ivanti flaw by Sunday (BleepingComputer) – The U.S. Cybersecurity and Infrastructure Security Agency (CISA) ordered government agencies to patch an actively exploited Ivanti Sentry flaw within three days, as mandated by the newly issued Bindin…
[5] In Other News: Google Security Layoffs, AudiA6 Takedown, $400 Million Coupang Fine (SecurityWeek) – Other noteworthy stories that might have slipped under the radar: ICS device exposure remains flat as attack surface widens, Microsoft issues incident response playbook for AI, IBM and AT&T accus…
[5] [RANSOMWARE] stormous leaked mlit.com.my (ransomware.live/stormous) – Victim: mlit.com.my | Group: stormous | Website: mlit.com.my | Country: MY | Details: We have successfully breached the internal servers and network infrastructure of MLIT, gaining full unauthorized a…
[5] [RANSOMWARE] threeam leaked jetmachprod.com (ransomware.live/threeam) – Victim: jetmachprod.com | Group: threeam | Website: jetmachprod.com | Details: Jet Machined Products specializes in high-performance milled and turned components for the aerospace, instrumentation, ro…
[5] [RANSOMWARE] threeam leaked jastrebarsko.hr (ransomware.live/threeam) – Victim: jastrebarsko.hr | Group: threeam | Website: jastrebarsko.hr | Country: HR | Details: Town of Jastrebarsko, a historic city in Central Croatia located between Zagreb and Karlovac.
[5] [RANSOMWARE] threeam leaked palmero.com (ransomware.live/threeam) – Victim: palmero.com | Group: threeam | Website: palmero.com | Details: Palmero is a company dedicated to the manufacturing and marketing of capital goods, providing comprehensive solutions across vari…
[5] [RANSOMWARE] threeam leaked insamani.com.ar (ransomware.live/threeam) – Victim: insamani.com.ar | Group: threeam | Website: insamani.com.ar | Country: AR | Details: INSA INDELMA S.A. is a leading agro-industrial company in Argentina specializing in peanut production, expo…
[5] [RANSOMWARE] threeam leaked bsynchro.com (ransomware.live/threeam) – Victim: bsynchro.com | Group: threeam | Website: bsynchro.com | Country: DE | Details: BSynchro Holding is an insurtech software provider that specializes in innovative insurance solutions tailored fo…
[5] [RANSOMWARE] threeam leaked molinoscabodi.com.ar (ransomware.live/threeam) – Victim: molinoscabodi.com.ar | Group: threeam | Website: molinoscabodi.com.ar | Country: AR | Details: Molinos Cabodi Hnos. S.A. has been providing high-quality flour products since 1853, including va…
[5] [RANSOMWARE] threeam leaked ws.com.br (ransomware.live/threeam) – Victim: ws.com.br | Group: threeam | Website: ws.com.br | Country: BR | Details: WS Group Brasil is a Brazilian operations and business services provider engaged in logistics, technical support, contr…
[5] [RANSOMWARE] threeam leaked consultic.be (ransomware.live/threeam) – Victim: consultic.be | Group: threeam | Website: consultic.be | Country: BE | Details: ConsulTIC specializes in IT solutions, offering services such as application hosting, virtualization, telecommuti…
[5] [RANSOMWARE] threeam leaked amc.org.au (ransomware.live/threeam) – Victim: amc.org.au | Group: threeam | Website: amc.org.au | Country: AU | Details: The Australian Medical Council (AMC) is an independent national standards body responsible for the accreditation and …
[5] [RANSOMWARE] threeam leaked agroexportavocados.com (ransomware.live/threeam) – Victim: agroexportavocados.com | Group: threeam | Website: agroexportavocados.com | Country: MX | Details: Agro Industrial Exportadora SA de CV (AGRIEXP) is a Mexican holding company which is engaged …
[5] [RANSOMWARE] threeam leaked hoplongtech.com (ransomware.live/threeam) – Victim: hoplongtech.com | Group: threeam | Website: hoplongtech.com | Country: VN | Details: Công ty Cổ phần Công Nghệ Hợp Long is a leading distributor of automation equipment and industrial robotics…
[5] [RANSOMWARE] coinbasecartel leaked Cambridge Mobile Telematics (ransomware.live/coinbasecartel) – Victim: Cambridge Mobile Telematics | Group: coinbasecartel | Country: US | Details: [AI generated] Cambridge Mobile Telematics (CMT) is an American telematics technology company headquartered in Camb…
[5] [RANSOMWARE] shadowbyt3$ leaked Nintendo Company (Nintendo.com) (ransomware.live/shadowbyt3$) – Victim: Nintendo Company (Nintendo.com) | Group: shadowbyt3$ | Website: Nintendo.com | Country: JP | Details: proof: https://mega.nz/folder/3kBzQKgR#rIhDePsPMeFpfEGTPopDVQ We are ShadowByt3$ a extorti…
[5] [RANSOMWARE] akira leaked DDC Domus Design Collection (ransomware.live/akira) – Victim: DDC Domus Design Collection | Group: akira | Details: Founded in 1991 and headquartered in New York City, New York, DDC Domus Design Collection is a
company that manufactures as well as sell …
[5] [RANSOMWARE] shinyhunters leaked Madison Square Garden Sports Corp. (ransomware.live/shinyhunters) – Victim: Madison Square Garden Sports Corp. | Group: shinyhunters | Country: US | Details: Over 26 million records containing customer PII and other internal corporate data was compromised. This is a f…
[5] [RANSOMWARE] shinyhunters leaked JCPenney & several other subsdiaries under Catalyst Brands & Authentic Brands Group (ransomware.live/shinyhunters) – Victim: JCPenney & several other subsdiaries under Catalyst Brands & Authentic Brands Group | Group: shinyhunters | Country: US | Details: Hundreds of thousands of records containing PII (SSN, DOB, et…
[5] [RANSOMWARE] shinyhunters leaked American Tower Corporation (ransomware.live/shinyhunters) – Victim: American Tower Corporation | Group: shinyhunters | Country: US | Details: Over 5.2 million records consiting of a significant amount of customer and landowner PII, other records tied to other …
[5] [RANSOMWARE] krybit leaked aisem.gob.bo (ransomware.live/krybit) – Victim: aisem.gob.bo | Group: krybit | Website: aisem.gob.bo | Country: BO | Details: AISEM (Agencia de Infraestructura en Salud y Equipamiento Médico) is a Bolivian government agency responsible for …
[5] [RANSOMWARE] krybit leaked www.progress-security.com (ransomware.live/krybit) – Victim: www.progress-security.com | Group: krybit | Website: www.progress-security.com | Country: DE | Details: Progress Security Systems is a leading UAE-based provider of enterprise-grade security s…
[5] [RANSOMWARE] insomnia leaked The Vant Group (ransomware.live/insomnia) – Victim: The Vant Group | Group: insomnia | Website: www.thevantgroup.com | Country: US | Details: The Vant Group, founded in 1999, is an M&A advisory firm serving businesses up to $250M in revenue. It…
SUMMARY
Total new items: 69
Critical count: 2
Ransomware groups active: 1
Top CVEs to patch urgently: CVE-2026-50751, CVE-2026-35273
qilin (1921): Erie Management Group, LLC, Town of Chatham, MASSACHUSETTS, ClearCare Periodontal & Implant Centre, Patterson Health Center, Marc Dorcel (+1916 more)
bianlian (552): Encompass Technologies, Northern Minerals Limited, Aspire Rural Health System, Saunders and Saunders, Legal Aid Society of Salt Lake (+547 more)