Cybersecurity Report  2026-07-20T04:00:28.426975

Generated: 2026-07-20T03:01:23.097309 UTC

RANSOMWARE VICTIMS (today)

Doommageddon: [RANSOMWARE] Doommageddon leaked Reni Farmácias Associadas

unsafe: [RANSOMWARE] unsafe leaked CCR Solutions

qilin: [RANSOMWARE] qilin leaked PP+K, [RANSOMWARE] qilin leaked Eana, [RANSOMWARE] qilin leaked Synergy Products, [RANSOMWARE] qilin leaked Don Tortaco Mexican Grill, [RANSOMWARE] qilin leaked Associated Theatrical Contractors, [RANSOMWARE] qilin leaked City Ambulance Service, [RANSOMWARE] qilin leaked Famesa

nova: [RANSOMWARE] nova leaked meralmanisa, [RANSOMWARE] nova leaked Dephub, [RANSOMWARE] nova leaked Jota Joias Premium

krybit: [RANSOMWARE] krybit leaked eurohold.bg

payload: [RANSOMWARE] payload leaked CKR Consulting Engineers

blackout: [RANSOMWARE] blackout leaked yano.tokyo, [RANSOMWARE] blackout leaked www.miatech.net, [RANSOMWARE] blackout leaked bluebellgroup.com

thegentlemen: [RANSOMWARE] thegentlemen leaked Ecopetrol

ULose: [RANSOMWARE] ULose leaked KyungRok, [RANSOMWARE] ULose leaked NRCapital, [RANSOMWARE] ULose leaked HanDok, [RANSOMWARE] ULose leaked HIZE Aero, [RANSOMWARE] ULose leaked MSICapital

The Green Blood Group: [RANSOMWARE] The Green Blood Group leaked DAF SENEGAL, [RANSOMWARE] The Green Blood Group leaked ECOBAT EGYPT

NEWS

  1. [9] Week in review: High severity WordPress vulnerabilities, fake OAuth IDs bypass sign-in logs  HelpNetSecurity.

    Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Two new high severity WordPress vulnerabilities, patch immediately! The 7.0.2 WordPress security release addresses one critical and one high severity security issue. Cynative: Open-source deep research agent Running a large language model against a live cloud account to hunt for security holes comes with an obvious hazard. An agent that holds real credentials and a mandate to poke around can R

  2. [8] Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution  TheHackerNews. F5 has shipped fixes for a critical nginx flaw that lets a remote, unauthenticated attacker trigger a heap buffer overflow in the worker process with crafted HTTP requests. CVE-2026-42533 was patched on July 15 in nginx 1.30.4 (stable) and 1.31.3 (mainline), and in NGINX Plus 37.0.3.1; anyone on an earlier build should upgrade. Triggering it can crash or restart the worker, causing a denial of
  3. [7] UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices wih Malware  TheHackerNews. Russian state-sponsored threat actors have been observed leveraging the infamous ClickFix strategy to trick Ukrainian targets into infecting their own machines with data-stealing malware. According to the Computer Emergency Response Team of Ukraine (CERT-UA), the activity has been attributed to UAC-0145, a sub-cluster within Sandworm, an advanced hacking unit affiliated with GRU, Russia's
  4. [6] SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access  TheHackerNews. A previously undocumented threat actor has been attributed to the exploitation of recently disclosed SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances as zero-days prior their public disclosure since June 22, 2026. Cybersecurity company Volexity is tracking the activity under the moniker UTA0533. The discovery was made following an incident response investigation earlier this

SUMMARY

Total new items: 30

Critical count: 0

Ransomware victims listed: 25

Top CVEs to patch urgently: CVE-2026-42533

Sources: BleepingComputer, TheHackerNews, SecurityWeek, HelpNetSecurity, KrebsOnSecurity, CISA KEV, ransomware.live