HERMES // CYBER INTELLIGENCE // 2026-08-17

Cybersecurity Intelligence Report — 17 August 2026

CRITICAL 1

[12] Week in review: Salesforce and ServiceNow portals exposed for 17 months, exploited Metabase 0-day

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: GitHub Dependabot malware alerts now cover eight ecosystems GitHub has flagged npm malware since March 2026. Anyone pulling in a bad PyPI, Maven, RubyGems, NuGet, Go, crates.io, or PHP Composer package has had no such warning, because GitHub’s malware detection only ever watched one ecosystem. That changed this month. Dependabot malware alerts, which had run on npm data alone, now … <a href

KEV 0

No newly collected entries.

DLS VICTIMS 0

No newly collected entries.

NEWS 20

[7] [RANSOMWARE] emperador leaked Albania's Official National Teacher Training Portal

Victim: Albania's Official National Teacher Training Portal | Group: emperador | Country: AL | Details: Albania’s official national teacher training portal provides centralized professional development resources and accredited programs for educators nationwide. This leak include data such as; Roughly ~100k Full national ID numbers, full names and teacher certificates in PDF. [Size: 5.9 GB | Sector: E

[7] [RANSOMWARE] emperador leaked Albania's official national teacher training portal.

Victim: Albania's official national teacher training portal. | Group: emperador | Country: AL | Details: Albania’s official national teacher training portal provides centralized professional development resources and accredited programs for educators nationwide. This leak include data such as; Roughly ~100k Full national ID numbers, full names and teacher certificates in PDF. [Size: 5.9 GB | Sector: E

[7] [RANSOMWARE] medusalocker leaked Twal Family IT Lab

Victim: Twal Family IT Lab | Group: medusalocker | Details: Personal IT home lab. AD domain: twalfamily.com. VMware vSphere, multiple AD domains. Daniel Al Twal works at Technology North Corp (Edmonton), former DND co-op. No corporate target. Previously misidentified as Forces/forces.gc.ca. | 4172 Wolfe Point Way, Ottawa, ON K1V 1P5, Canada

[5] [RANSOMWARE] Panzer leaked SAGASTA sro

Victim: SAGASTA sro | Group: Panzer | Website: sagasta.cz | Country: CZ | Details: SAGASTA is a design and engineering company specializing in modern construction, offering comprehensive design, engineering, and consulting services in the fields of railway, road, bridge, and water management construction.

[5] [RANSOMWARE] Eclipse leaked Moscord

Victim: Moscord | Group: Eclipse | Website: moscord.com | Country: SG | Details: Moscord is a digital marketplace that connects buyers and sellers in the maritime industry, offering a platform for various suppliers to aggregate and present their products. The company aims to enhance business operations for its clients by providing innovative solutions in procurement, logistics,

[5] [RANSOMWARE] settra leaked galmack.com.ec

Victim: galmack.com.ec | Group: settra | Website: galmack.com.ec | Country: EC | Details: GALMACK S.A.: Internal Documents of an Ecuadorian Auto Dealership Holding PROLOGUE Inside: monthly b...

[5] [RANSOMWARE] settra leaked airoyal.biz

Victim: airoyal.biz | Group: settra | Website: airoyal.biz | Details: AIROYAL COMPANY: Internal Documents of an American Industrial Components Distributor PROLOGUE We hav...

[5] [RANSOMWARE] settra leaked tiltstudio.com

Victim: tiltstudio.com | Group: settra | Website: tiltstudio.com | Country: DE | Details: The Tilt Studio Archives Investigation of a Corporate Archive Leak from an Entertainment Network PRO...

[5] [RANSOMWARE] lockbit5 leaked actua.fr

Victim: actua.fr | Group: lockbit5 | Website: actua.fr | Country: FR | Details: Groupe Actua is a recruitment and temporary staffing agency headquartered in Strasbourg, founded in...