Cybersecurity Intelligence Report — 2026-07-21

CRITICAL SECTION

CISA KEV

No CISA KEV items in the last 14 days.

RANSOMWARE VICTIMS (DLS MONITORING)

Unknown: [RANSOMWARE] nova leaked Jrd logistics, [RANSOMWARE] akira leaked McKeever , Varga & Senko, [RANSOMWARE] safepay leaked wdk.de, [RANSOMWARE] safepay leaked jaecklin-industrial.de, [RANSOMWARE] safepay leaked lbb-treuhand.de, [RANSOMWARE] safepay leaked timetex.de, [RANSOMWARE] safepay leaked stroebel-gruppe.de, [RANSOMWARE] safepay leaked industriesjaro.com, [RANSOMWARE] safepay leaked cenesco.de, [RANSOMWARE] safepay leaked acsmallmaxwell.com.au, [RANSOMWARE] safepay leaked mende-grundbesitz.de, [RANSOMWARE] kairos leaked College O'Sullivan de Québec, [RANSOMWARE] kairos leaked Collge O'Sullivan de Québec, [RANSOMWARE] incransom leaked Ali-Monde, [RANSOMWARE] coinbasecartel leaked Caterpillar, [RANSOMWARE] anubis leaked Bath Fitter, [RANSOMWARE] anubis leaked Fairlife / Coca-Cola, [RANSOMWARE] nova leaked Rumah Sakit Universitas Indonesia (RSUI), [RANSOMWARE] nova leaked Universidad Nacional de Mar del Plata, [RANSOMWARE] coinbasecartel leaked Colliers Real Estate, [RANSOMWARE] akira leaked L&A Transport, [RANSOMWARE] nova leaked Koplarla, [RANSOMWARE] qilin leaked Bolt & Nut Manufacturing, [RANSOMWARE] chaos leaked wikoff.com

NEWS

[9] Russian-Speaking Hacker Uses Google Gemini CLI to Control Botnet of Eight Dental Clinic PCs (TheHackerNews) — A solo Russian-speaking threat actor known as "bandcampro" outsourced a chunk of their operations to Google's open-source Gemini CLI artificial intelligence (AI) and commandeered a live botnet. The findings come from an analysis of 200 Gemini CLI session logs between March 19 and April 21, 2026, which found the threat actor using AI, among other things, to crack passwords, set up a residential

[9] [RANSOMWARE] nova leaked Jrd logistics (ransomware.live/nova) — Victim: Jrd logistics | Group: nova | Details: Jrd logistics LTD is an India-based freight forwarding and supply chain company headquartered in Kolkata that provides international logistics, customs clearance, warehousing, and multimodal transport services - Nova Provide tree and samples from stolen data to the company when its get in touch with

[8] Critical ServiceNow code execution flaw now exploited in attacks (BleepingComputer) — Attackers have begun exploiting a critical vulnerability (CVE-2026-6875) in the ServiceNow AI Platform, according to threat intelligence company Defused. [...]

[8] SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch (SecurityWeek) — <p>The zero-days CVE-2026-15409 and CVE-2026-15410 were exploited by a threat actor tracked by Volexity as UTA0533.</p> <p>The post <a href="https://www.securityweek.com/sonicwall-zero-days-exploited-to-deliver-custom-malware-for-weeks-before-patch/">SonicWall Zero-Days Exploited to Deliver Custom Malware for Weeks Before Patch</a> appeared first on <a href="https://www.securityweek.com">SecurityWeek</a>.</p>

[8] WP2Shell WordPress Vulnerabilities Exploited in the Wild (SecurityWeek) — <p>Exploitation of the new WordPress vulnerabilities tracked as CVE-2026-60137 and CVE-2026-63030 started soon after disclosure.</p> <p>The post <a href="https://www.securityweek.com/wp2shell-wordpress-vulnerabilities-exploited-in-the-wild/">WP2Shell WordPress Vulnerabilities Exploited in the Wild</a> appeared first on <a href="https://www.securityweek.com">SecurityWeek</a>.</p>

[7] [RANSOMWARE] akira leaked McKeever , Varga & Senko (ransomware.live/akira) — Victim: McKeever , Varga & Senko | Group: akira | Details: McKeever Varga & Senko is a firm of Certified Public Accountants dedicated to providing superio r client service and professional guidance. They offer a range of services including informativ e articles, interactive financial calculators, and links to external resources to assist their clients. We

[6] Estée Lauder discloses data breach via Oracle E-Business flaw (BleepingComputer) — Cosmetics giant Estée Lauder is notifying customers of a data breach after hackers exploited a flaw in Oracle E-Business Suite that the company used for human resources (HR) operations. [...]

[6] SonicWall SMA1000 flaws exploited as zero-days to push custom malware (BleepingComputer) — Two recently disclosed SonicWall SMA1000 vulnerabilities were exploited in zero-day attacks for weeks, allowing threat actors to install custom malware on vulnerable VPN appliances. [...]

[6] World's Largest AI Model Repository Hugging Face Breached by Autonomous AI Agent (TheHackerNews) — In an ironic twist, open-source artificial intelligence (AI) platform Hugging Face revealed that it was the victim of a hack perpetrated by an autonomous AI agent system. The company said it detected and responded to the incident targeting its production infrastructure earlier last week. "We identified unauthorized access to a limited set of internal datasets and to several credentials used by

[6] New Index Tracks Material Breaches — And Refuses to Add Up the Losses (SecurityWeek) — <p>Longtime cybersecurity executive Richard Bird built the resource for security experts, journalists, policymakers, and everyday citizens.</p> <p>The post <a href="https://www.securityweek.com/new-index-tracks-material-breaches-and-refuses-to-add-up-the-losses/">New Index Tracks Material Breaches — And Refuses to Add Up the Losses</a> appeared first on <a href="https://www.securityweek.com">SecurityWeek</a>.</p>

[6] Hugging Face breached by autonomous AI agent (HelpNetSecurity) — <p>Hugging Face, the widely used platform for sharing open-source machine learning models and datasets, has disclosed a security breach it says was carried out by an autonomous AI agent system. How the attack unfolded In a blog post published Thursday (July 16), the company said that earlier that week, it identified unauthorized access to some internal datasets and to several credentials used by its services. The intrusion was executed via a malicious dataset that abused … <a href="https:/

[5] More alerts are making your team slower, and an outcome-based SOC fixes that (HelpNetSecurity) — <p>In this Help Net Security video, Thom Langford, EMEA CTO, Rapid7, explains why piling on more security alerts makes a SOC slower to respond. Attackers log in with stolen credentials and use trusted tools like PowerShell instead of custom malware. He shares a case where attackers called a help desk, reset a privileged cloud account, and exposed thousands of passwords in three minutes. Ransomware groups can go from access to payload in under three hours. … <a href="https://www.helpnetsecu

[5] [RANSOMWARE] safepay leaked wdk.de (ransomware.live/safepay) — Victim: wdk.de | Group: safepay | Website: wdk.de | Country: DE | Details: Founded in 1950 and headquartered in Frankfurt am Main, the organization serves as the central voice of German manufacturers of …

[5] [RANSOMWARE] safepay leaked jaecklin-industrial.de (ransomware.live/safepay) — Victim: jaecklin-industrial.de | Group: safepay | Website: jaecklin-industrial.de | Country: DE | Details: Founded in 1935 by Julius Jäcklin, the company has developed from a regional machine repair workshop into a globally recognized …

[5] [RANSOMWARE] safepay leaked lbb-treuhand.de (ransomware.live/safepay) — Victim: lbb-treuhand.de | Group: safepay | Website: lbb-treuhand.de | Country: DE | Details: The company specializes in tax consulting, auditing, accounting, payroll administration, financial reporting, and business advisory services for private individuals, self-employed …

[5] [RANSOMWARE] safepay leaked timetex.de (ransomware.live/safepay) — Victim: timetex.de | Group: safepay | Website: timetex.de | Country: DE | Details: The company traces its origins to 1991, when the TimeTEX brand was acquired and expanded into a comprehensive supplier of …

[5] [RANSOMWARE] safepay leaked stroebel-gruppe.de (ransomware.live/safepay) — Victim: stroebel-gruppe.de | Group: safepay | Website: stroebel-gruppe.de | Country: DE | Details: Headquartered in Langenzenn, Bavaria, the company was founded in 1978 by Gerlinde and Gerhard Ströbel and has grown from a …

[5] [RANSOMWARE] safepay leaked industriesjaro.com (ransomware.live/safepay) — Victim: industriesjaro.com | Group: safepay | Website: industriesjaro.com | Country: CA | Details: Over several decades, Jaro has evolved from manufacturing telephone booths into a supplier of advanced outdoor enclosures, interactive kiosks, bus …

[5] [RANSOMWARE] safepay leaked cenesco.de (ransomware.live/safepay) — Victim: cenesco.de | Group: safepay | Website: cenesco.de | Country: DE | Details: Founded in 1998, the company provides comprehensive information technology solutions for small and medium-sized enterprises (SMEs), helping organizations modernize their …

[5] [RANSOMWARE] safepay leaked acsmallmaxwell.com.au (ransomware.live/safepay) — Victim: acsmallmaxwell.com.au | Group: safepay | Website: acsmallmaxwell.com.au | Country: AU | Details: Founded in 1916 by Ambrose Cecil Small, the firm has provided professional accounting and financial services to businesses and individuals …

[5] [RANSOMWARE] safepay leaked mende-grundbesitz.de (ransomware.live/safepay) — Victim: mende-grundbesitz.de | Group: safepay | Website: mende-grundbesitz.de | Country: DE | Details: Founded in 1994, the company specializes in the professional administration of residential, commercial, and mixed-use real estate throughout the Berlin …

[5] [RANSOMWARE] kairos leaked College O'Sullivan de Québec (ransomware.live/kairos) — Victim: College O'Sullivan de Québec | Group: kairos | Country: CA | Details: Collège O'Sullivan de Québec offers a variety of training programs both in-class and online, focusing on fields such as administration, insurance, office management, IT, web development, and marketing. The institution aims to equip students with the skills needed for the job market and higher educat

[5] [RANSOMWARE] kairos leaked Collge O'Sullivan de Québec (ransomware.live/kairos) — Victim: Collge O'Sullivan de Québec | Group: kairos | Country: CA | Details: Collège O'Sullivan de Québec offers a variety of training programs both in-class and online, focusing on fields such as administration, insurance, office management, IT, web development, and marketing. The institution aims to equip students with the skills needed for the job market and higher educat

[5] [RANSOMWARE] incransom leaked Ali-Monde (ransomware.live/incransom) — Victim: Ali-Monde | Group: incransom | Country: US | Details: Ali-Monde is a food production and distribution company that's been around for over 50 years. They've got 5 of their own brands and an impressive lineup of 800+ dry, organic, and gluten-free products. Based just south of Montreal, they distribute food across Quebec, Ontario, New Brunswick, and parts

[5] [RANSOMWARE] coinbasecartel leaked Caterpillar (ransomware.live/coinbasecartel) — Victim: Caterpillar | Group: coinbasecartel | Country: US | Details: [AI generated] Caterpillar Inc. is an American multinational corporation headquartered in Irving, Texas. It is the world's leading manufacturer of construction and mining equipment, diesel and natural gas engines, industrial gas turbines, and diesel-electric locomotives. Operating in over 190 countr

[5] [RANSOMWARE] anubis leaked Bath Fitter (ransomware.live/anubis) — Victim: Bath Fitter | Group: anubis | Country: US | Details: Employee data breach at a major manufacturing company.

[5] [RANSOMWARE] anubis leaked Fairlife / Coca-Cola (ransomware.live/anubis) — Victim: Fairlife / Coca-Cola | Group: anubis | Country: US | Details: www.fairlife.com

[5] [RANSOMWARE] nova leaked Rumah Sakit Universitas Indonesia (RSUI) (ransomware.live/nova) — Victim: Rumah Sakit Universitas Indonesia (RSUI) | Group: nova | Country: ID | Details: Rumah Sakit Universitas Indonesia (RSUI) is the teaching hospital of the University of Indonesia, providing advanced medical care, education, and clinical research in Indonesia - medical data from drive at risk, Nova Provide tree and samples from stolen data to the company when its get in touch with

[5] [RANSOMWARE] nova leaked Universidad Nacional de Mar del Plata (ransomware.live/nova) — Victim: Universidad Nacional de Mar del Plata | Group: nova | Country: AR | Details: The Universidad Nacional de Mar del Plata offers a wide range of academic programs, including undergraduate and postgraduate degrees, vocational training, and distance education. It serves students, faculty, and the broader community by promoting research, innovation, and cultural activities. The un

[5] [RANSOMWARE] coinbasecartel leaked Colliers Real Estate (ransomware.live/coinbasecartel) — Victim: Colliers Real Estate | Group: coinbasecartel | Country: US | Details: [AI generated] Colliers International is a global commercial real estate services company headquartered in Toronto, Canada. It operates across more than 60 countries, offering services including property management, investment sales, leasing, valuation, and advisory. The firm serves corporate, insti

[5] [RANSOMWARE] akira leaked L&A Transport (ransomware.live/akira) — Victim: L&A Transport | Group: akira | Details: L & A Transport is a reputable trucking company with over 50 years of experience in providing a wide range of shipping services, including international shipping, white glove handling, and l ogistics solutions for businesses of all sizes. They specialize in truckloads, container loads, less than con

[5] [RANSOMWARE] nova leaked Koplarla (ransomware.live/nova) — Victim: Koplarla | Group: nova | Website: kopkarla.com | Country: ID | Details: Koperasi Konsumen Karyawan PT Aplikanusa Lintasarta (KOPKARLA) was established in 1992 and at that time was focusing on saving and loan business. Since 1998, KOPKARLA has evolved and expanded its business to provide an installation services and solution of telecommunication network (datacomm)

[5] [RANSOMWARE] qilin leaked Bolt & Nut Manufacturing (ransomware.live/qilin) — Victim: Bolt & Nut Manufacturing | Group: qilin | Website: www.bnml.co.uk | Country: GB | Details: N/A

[5] [RANSOMWARE] chaos leaked wikoff.com (ransomware.live/chaos) — Victim: wikoff.com | Group: chaos | Website: wikoff.com | Country: US | Details: [PUBLIC DISCLOSURE] Target: Wikoff Color Corporation (wikoff.com) Data Volume: 650 GB Status: Full Compromise Confirmed We are officially confirming that the entire internal infrastructure of Wikoff Color Corporation—ranging from Board of Directors financial reports and proprietary R&D formulas…

SUMMARY

Total new items: 65. Critical: 2. Ransomware groups active today: 1.

Top CVEs to patch urgently: CVE-2026-6875 (2), CVE-2026-15409 (1), CVE-2026-15410 (1), CVE-2026-63030 (1), CVE-2026-60137 (1).

Sources: BleepingComputer, TheHackerNews, SecurityWeek, HelpNetSecurity, KrebsOnSecurity, CISA KEV, ransomware.live