News Last updated: 11 August 2026 14:55 UTC
Coming up
Full calendar →- ReportArctic Wolf Security Operations Report 20262 Sep – 28 Oct 2026in 22 days
- ReportENISA Threat Landscape 202620 Sep – 5 Nov 2026in 40 days
- ReportMicrosoft Digital Defense Report 20262 Oct – 15 Nov 2026in 52 days
Follow the daily brief: RSS · JSON point any reader at the RSS feed — no email needed.
How to read confidence
- Confirmed
- Verified by a primary source or first-party artifact.
- Corroborated
- Multiple independent secondary sources agree.
- Claimed
- A single claim (e.g. a leak-site post) without corroboration.
- Disputed
- Sources conflict; we show both sides and anchor on the facts.
Recently published reports
- IBM Cost of a Data Breach 20262026-08-03The Average Cost of a Data Breach Rises to $5 Million
- Our takeCISA added CVE-2025-68686 to KEV. It lets a remote unauthenticated attacker bypass a prior FortiOS symbolic-link patch via crafted HTTP requests, but only after filesystem-level compromise via another flaw. Patch if you run FortiOS yourself.Cyber Resilience desk
Sources (8)
- cisa_kev · cisa_kev
- cisa_advisories · cisa_advisories
- cccs · cccs
- hackernews · hackernews
- cccs · cccs
- cisa_advisories · cisa_advisories
- cccs · cccs
- helpnet · helpnet
What this means for you — Security leader:If FortiOS is in your estate, treat CVE-2025-68686 as a KEV item and patch to Fortinet’s fixed builds on the CISA deadline. Note the attacker needs a prior filesystem-level compromise; still prioritize because it defeats a post-exploit patch for symbolic-link persistency.What this means for you — Lean IT orgs:If you run a FortiGate or other FortiOS device, apply the vendor update now. You do not need a security team for this—use Fortinet’s fixed version list and your usual firmware upgrade path.What this means for you — MSP:Inventory every client FortiOS/FortiGate instance, map versions against Fortinet’s fixed builds, and schedule upgrades under the KEV window. Flag any appliance already known compromised or left on unsupported builds.What this means for you — Researcher:Post-exploit info-exposure that bypasses the symbolic-link persistency patch via crafted HTTP after filesystem compromise. Useful for chaining notes and for checking whether residual symlink/persist techniques still work on unpatched FortiOS. - Our takeAnother SharePoint deserialization RCE, critical severity. Not one of the three CVEs CISA says are under active exploitation (32201, 45659, 56164) — patch it anyway, on-prem SharePoint is now averaging multiple deserialization bugs per advisory cycle.
Sources (12)
- cisa_advisories · cisa_advisories
- cisa_advisories · cisa_advisories
- nvd_recent · nvd_recent
- nvd_recent · nvd_recent
- nvd_recent · nvd_recent
- nvd_recent · nvd_recent
- nvd_recent · nvd_recent
- cccs · cccs
- bleeping · bleeping
- securityweek · securityweek
- securityweek · securityweek
- bleeping · bleeping
What this means for you — Security leader:Patch all on-prem SharePoint (Subscription Edition, 2019, 2016) against CVE-2026-56164 and related deserialization/auth flaws now; confirm which of your instances are internet-facing and check CISA's KEV catalog for the actively-exploited set (32201, 45659, 56164).What this means for you — Lean IT orgs:If you run SharePoint on your own server (not Microsoft 365 cloud), get your IT provider to patch it immediately — attackers are actively breaking into unpatched on-prem SharePoint servers right now.What this means for you — MSP:Inventory every client running on-prem SharePoint Server (any edition); prioritize patching CVE-2026-56164 and the other actively exploited CVEs across all tenants before addressing lower-severity SharePoint CVEs in this batch.What this means for you — Researcher:Multiple SharePoint deserialization/auth CVEs landed together (50522, 58644, 55040, 56164) alongside CISA's advisory naming a different exploited set (32201, 45659, 56164) — worth mapping overlap and checking if 50522/58644 share a root cause with the confirmed-exploited chain. - Our takeIBM claims the average data breach now costs $4.99 million, with AI attacks a factor. A breach at a large enterprise means fines and restitution; at a resource-constrained business it can end the company overnight — either way, prevention beats cure.
Sources (1)
- infosec_mag · infosec_mag
What this means for you — Security leader:Use the $4.99M average to pressure-test IR budget, retainer coverage, and cyber-insurance limits against your actual blast radius. Factor faster AI-assisted intrusion into containment and escalation SLAs.What this means for you — Lean IT orgs:A breach at this scale can sink a lean shop—prioritize MFA, offline backups you have restored recently, and a one-page who-to-call plan over tools you cannot staff.What this means for you — MSP:Bring the $4.99M figure into QBRs to reset client expectations on IR retainers, backup restore drills, and insurance gaps across your book, especially accounts with no in-house security hire.What this means for you — Researcher:Treat $4.99M as an IBM-modeled average, not a universal loss figure—check the report’s sample, cost-inclusion rules, and the AI-attack methodology before citing it. - Our takeCISA adds CVE-2026-0770 to KEV: unauthenticated remote code execution in Langflow, exploitation confirmed. Langflow instances get spun up for AI experiments and forgotten — whether you're an enterprise lab or a two-person shop, find yours, get it off the open internet, patch.
Sources (5)
- cisa_kev · cisa_kev
- cisa_advisories · cisa_advisories
- bleeping · bleeping
- hackernews · hackernews
- hackernews · hackernews
What this means for you — Security leader:Confirm whether any Langflow instances run in your environment, especially internet-facing ones tied to AI/LLM pipelines, and patch per CISA's KEV deadline — exploitation is already confirmed.What this means for you — Lean IT orgs:If your team uses Langflow to build AI workflows, update it now; if you don't run Langflow or similar low-code AI tools, this one doesn't apply to you.What this means for you — MSP:Scan all client environments for Langflow deployments — it's often spun up ad hoc for AI prototyping and easy to miss in asset inventories — and patch or take exposed instances offline first.What this means for you — Researcher:Worth digging into how Langflow's flow-import/plugin-loading mechanism handles external code — the CWE class (inclusion of functionality from untrusted control sphere) suggests a template or deserialization-style injection point. - Our takeunsafe claims Presentations.AI as a victim. Single leak-site posting, no filing, no victim statement. Treat as unverified.
Sources (1)
- ransomware_live · ransomware_live
What this means for you — Security leader:Check for Presentations.AI in your third-party inventory; if present, invoke your vendor-incident playbook and request their IR status in writing.What this means for you — Lean IT orgs:If you use or supply Presentations.AI: change any shared passwords today, watch account and transaction activity, and don't click 'urgent' emails about this incident.What this means for you — MSP:Sweep client stacks for Presentations.AI dependencies and shared credentials; one leak-site claim can touch many of your clients at once.What this means for you — Researcher:Unverified leak-site claim by unsafe; track for proof-of-data posts before citing. Victim statement, if any, supersedes. - Our takeMicrosoft's July 2026 bundle fixes 1164 CVEs including 3 already exploited in the wild (SharePoint CVE-2026-58644, two others). Patch those three out-of-band this week; the rest on your normal cycle. Lean-IT shops without SharePoint can largely ignore it; enterprises running on-prem SharePoint must treat the KEV trio as urgent.
Sources (11)
- msrc_patch · msrc_patch
- nvd_recent · nvd_recent
- cccs · cccs
- cisa_kev · cisa_kev
- hackernews · hackernews
- hackernews · hackernews
- bleeping · bleeping
- cisa_kev · cisa_kev
- cert_eu · cert_eu
- securityweek · securityweek
- helpnet · helpnet
What this means for you — Security leader:Patch out-of-band this week for CVE-2026-58644 (SharePoint, KEV, exploited) and the other two exploited CVEs; the remaining 24 Critical-rated fixes ride the normal patch cycle. SharePoint on-prem servers get priority — check CCCS AL26-017 for scope.What this means for you — Lean IT orgs:If you run SharePoint on your own server (not the Microsoft 365 cloud version), patch it now — it's under active attack. If you use hosted Microsoft 365, this one doesn't apply to you; let Windows Update handle the rest on its normal schedule.What this means for you — MSP:Inventory which clients run on-prem SharePoint Server versus SharePoint Online — only the former needs emergency action for CVE-2026-58644. Push the other three exploited CVEs (2026-56155, 2026-56164, 2026-48561) across the fleet this week; the rest of the 1164 can wait for standard rollout.What this means for you — Researcher:CVE-2026-48561 (Copilot command injection, unauthenticated RCE over network) is worth watching independent of KEV status given the attack surface; CVE-2026-58644's deserialization root cause in SharePoint mirrors prior on-prem SharePoint RCE chains — worth comparing patch diffs. - Our takegenesis claims Interim HealthCare as a victim. No filing, no confirmation — leak-site post only. Claimed — unconfirmed. If you're a customer: change that password anywhere you reused it, and watch your statements.
Sources (1)
- ransomware_live · ransomware_live
What this means for you — Security leader:Check for Interim HealthCare in your third-party inventory; if present, invoke your vendor-incident playbook and request their IR status in writing.What this means for you — Lean IT orgs:If you use or supply Interim HealthCare: change any shared passwords today, watch account and transaction activity, and don't click 'urgent' emails about this incident.What this means for you — MSP:Sweep client stacks for Interim HealthCare dependencies and shared credentials; one leak-site claim can touch many of your clients at once.What this means for you — Researcher:Unverified leak-site claim by genesis; track for proof-of-data posts before citing. Victim statement, if any, supersedes. - Our takedirewolf lists BigSpark on its leak site. One source, no victim statement, no filing. Treat as unverified until corroborated.
Sources (1)
- ransomware_live · ransomware_live
What this means for you — Security leader:Check for BigSpark in your third-party inventory; if present, invoke your vendor-incident playbook and request their IR status in writing.What this means for you — Lean IT orgs:If you use or supply BigSpark: change any shared passwords today, watch account and transaction activity, and don't click 'urgent' emails about this incident.What this means for you — MSP:Sweep client stacks for BigSpark dependencies and shared credentials; one leak-site claim can touch many of your clients at once.What this means for you — Researcher:Unverified leak-site claim by direwolf; track for proof-of-data posts before citing. Victim statement, if any, supersedes. - Our takeanubis claims Cleaver-Brooks as a victim. Single leak-site posting, no filing, no victim statement. Treat as claimed, not fact.
Sources (1)
- ransomware_live · ransomware_live
What this means for you — Security leader:Check for Cleaver-Brooks in your third-party inventory; if present, invoke your vendor-incident playbook and request their IR status in writing.What this means for you — Lean IT orgs:If you use or supply Cleaver-Brooks: change any shared passwords today, watch account and transaction activity, and don't click 'urgent' emails about this incident.What this means for you — MSP:Sweep client stacks for Cleaver-Brooks dependencies and shared credentials; one leak-site claim can touch many of your clients at once.What this means for you — Researcher:Unverified leak-site claim by anubis; track for proof-of-data posts before citing. Victim statement, if any, supersedes. - Our takeDeadlock claims LT Group / Fortune Tobacco Corp as a victim. The posting cites 27 GB. Single leak-site posting, no filing, no victim statement. Treat as claimed, not fact.
Sources (1)
- ransomware_live · ransomware_live
What this means for you — Security leader:Check for LT Group / Fortune Tobacco Corp in your third-party inventory; if present, invoke your vendor-incident playbook and request their IR status in writing.What this means for you — Lean IT orgs:If you use or supply LT Group / Fortune Tobacco Corp: change any shared passwords today, watch account and transaction activity, and don't click 'urgent' emails about this incident.What this means for you — MSP:Sweep client stacks for LT Group / Fortune Tobacco Corp dependencies and shared credentials; one leak-site claim can touch many of your clients at once.What this means for you — Researcher:Unverified leak-site claim by Deadlock; track for proof-of-data posts before citing. Victim statement, if any, supersedes. - Our takegenesis lists Consolidated Medical Practices of Memphis on its leak site. Single leak-site posting, no filing, no victim statement. Claim only — unverified. If you're a customer: change that password anywhere you reused it, and watch your statements.
Sources (1)
- ransomware_live · ransomware_live
What this means for you — Security leader:Check for Consolidated Medical Practices of Memphis in your third-party inventory; if present, invoke your vendor-incident playbook and request their IR status in writing.What this means for you — Lean IT orgs:If you use or supply Consolidated Medical Practices of Memphis: change any shared passwords today, watch account and transaction activity, and don't click 'urgent' emails about this incident.What this means for you — MSP:Sweep client stacks for Consolidated Medical Practices of Memphis dependencies and shared credentials; one leak-site claim can touch many of your clients at once.What this means for you — Researcher:Unverified leak-site claim by genesis; track for proof-of-data posts before citing. Victim statement, if any, supersedes. - Our takegenesis lists Interim HealthCare (Oklahoma and Tulsa) on its leak site. Single leak-site posting, no filing, no victim statement. Claim only — unverified. Customers: watch card and account activity for fraud; be wary of 'urgent' emails citing this incident.
Sources (1)
- ransomware_live · ransomware_live
What this means for you — Security leader:Check for Interim HealthCare (Oklahoma and Tulsa) in your third-party inventory; if present, invoke your vendor-incident playbook and request their IR status in writing.What this means for you — Lean IT orgs:If you use or supply Interim HealthCare (Oklahoma and Tulsa): change any shared passwords today, watch account and transaction activity, and don't click 'urgent' emails about this incident.What this means for you — MSP:Sweep client stacks for Interim HealthCare (Oklahoma and Tulsa) dependencies and shared credentials; one leak-site claim can touch many of your clients at once.What this means for you — Researcher:Unverified leak-site claim by genesis; track for proof-of-data posts before citing. Victim statement, if any, supersedes. - Our takedirewolf leak-site posting names Chat Jurídico. Single-source, no filing, no advisory. Treat as claimed, not fact.
Sources (1)
- ransomware_live · ransomware_live
What this means for you — Security leader:Check for Chat Jurídico in your third-party inventory; if present, invoke your vendor-incident playbook and request their IR status in writing.What this means for you — Lean IT orgs:If you use or supply Chat Jurídico: change any shared passwords today, watch account and transaction activity, and don't click 'urgent' emails about this incident.What this means for you — MSP:Sweep client stacks for Chat Jurídico dependencies and shared credentials; one leak-site claim can touch many of your clients at once.What this means for you — Researcher:Unverified leak-site claim by direwolf; track for proof-of-data posts before citing. Victim statement, if any, supersedes. - Our takedirewolf's leak site lists Merge. Single leak-site posting, no filing, no victim statement. Claimed — unconfirmed.
Sources (1)
- ransomware_live · ransomware_live
What this means for you — Security leader:Check for Merge in your third-party inventory; if present, invoke your vendor-incident playbook and request their IR status in writing.What this means for you — Lean IT orgs:If you use or supply Merge: change any shared passwords today, watch account and transaction activity, and don't click 'urgent' emails about this incident.What this means for you — MSP:Sweep client stacks for Merge dependencies and shared credentials; one leak-site claim can touch many of your clients at once.What this means for you — Researcher:Unverified leak-site claim by direwolf; track for proof-of-data posts before citing. Victim statement, if any, supersedes. - Our takeqilin leak-site posting names HIGEN MOTOR(critical data). No filing, no confirmation — leak-site post only. Treat as unverified.
Sources (1)
- ransomware_live · ransomware_live
What this means for you — Security leader:Check for HIGEN MOTOR(critical data) in your third-party inventory; if present, invoke your vendor-incident playbook and request their IR status in writing.What this means for you — Lean IT orgs:If you use or supply HIGEN MOTOR(critical data): change any shared passwords today, watch account and transaction activity, and don't click 'urgent' emails about this incident.What this means for you — MSP:Sweep client stacks for HIGEN MOTOR(critical data) dependencies and shared credentials; one leak-site claim can touch many of your clients at once.What this means for you — Researcher:Unverified leak-site claim by qilin; track for proof-of-data posts before citing. Victim statement, if any, supersedes. - Our takedirewolf claims Swyft Inc. as a victim. Single leak-site posting, no filing, no victim statement. Treat as claimed, not fact.
Sources (1)
- ransomware_live · ransomware_live
What this means for you — Security leader:Check for Swyft Inc. in your third-party inventory; if present, invoke your vendor-incident playbook and request their IR status in writing.What this means for you — Lean IT orgs:If you use or supply Swyft Inc.: change any shared passwords today, watch account and transaction activity, and don't click 'urgent' emails about this incident.What this means for you — MSP:Sweep client stacks for Swyft Inc. dependencies and shared credentials; one leak-site claim can touch many of your clients at once.What this means for you — Researcher:Unverified leak-site claim by direwolf; track for proof-of-data posts before citing. Victim statement, if any, supersedes. - Our takedirewolf lists AliveCor, Inc. on its leak site. Single-source, no filing, no advisory. Treat as unverified. If you're a customer: change that password anywhere you reused it, and watch your statements.
Sources (1)
- ransomware_live · ransomware_live
What this means for you — Security leader:Check for AliveCor, Inc. in your third-party inventory; if present, invoke your vendor-incident playbook and request their IR status in writing.What this means for you — Lean IT orgs:If you use or supply AliveCor, Inc.: change any shared passwords today, watch account and transaction activity, and don't click 'urgent' emails about this incident.What this means for you — MSP:Sweep client stacks for AliveCor, Inc. dependencies and shared credentials; one leak-site claim can touch many of your clients at once.What this means for you — Researcher:Unverified leak-site claim by direwolf; track for proof-of-data posts before citing. Victim statement, if any, supersedes. - Our takedirewolf claims Statista GmbH as a victim. Single leak-site posting, no filing, no victim statement. Treat as unverified until corroborated.
Sources (1)
- ransomware_live · ransomware_live
What this means for you — Security leader:Check for Statista GmbH in your third-party inventory; if present, invoke your vendor-incident playbook and request their IR status in writing.What this means for you — Lean IT orgs:If you use or supply Statista GmbH: change any shared passwords today, watch account and transaction activity, and don't click 'urgent' emails about this incident.What this means for you — MSP:Sweep client stacks for Statista GmbH dependencies and shared credentials; one leak-site claim can touch many of your clients at once.What this means for you — Researcher:Unverified leak-site claim by direwolf; track for proof-of-data posts before citing. Victim statement, if any, supersedes. - Our takedirewolf claims Quironsalud as a victim. Single leak-site posting, no filing, no victim statement. Claim only — unverified. Customers: watch card and account activity for fraud; be wary of 'urgent' emails citing this incident.
Sources (1)
- ransomware_live · ransomware_live
What this means for you — Security leader:Check for Quironsalud in your third-party inventory; if present, invoke your vendor-incident playbook and request their IR status in writing.What this means for you — Lean IT orgs:If you use or supply Quironsalud: change any shared passwords today, watch account and transaction activity, and don't click 'urgent' emails about this incident.What this means for you — MSP:Sweep client stacks for Quironsalud dependencies and shared credentials; one leak-site claim can touch many of your clients at once.What this means for you — Researcher:Unverified leak-site claim by direwolf; track for proof-of-data posts before citing. Victim statement, if any, supersedes. - Our takedirewolf leak-site posting names Health Carousel. No filing, no confirmation — leak-site post only. Treat as unverified. Customers: watch card and account activity for fraud; be wary of 'urgent' emails citing this incident.
Sources (1)
- ransomware_live · ransomware_live
What this means for you — Security leader:Check for Health Carousel in your third-party inventory; if present, invoke your vendor-incident playbook and request their IR status in writing.What this means for you — Lean IT orgs:If you use or supply Health Carousel: change any shared passwords today, watch account and transaction activity, and don't click 'urgent' emails about this incident.What this means for you — MSP:Sweep client stacks for Health Carousel dependencies and shared credentials; one leak-site claim can touch many of your clients at once.What this means for you — Researcher:Unverified leak-site claim by direwolf; track for proof-of-data posts before citing. Victim statement, if any, supersedes. - Our takedirewolf claims Fondo as a victim. Single-source, no filing, no advisory. Treat as unverified until corroborated. If you're a customer: change that password anywhere you reused it, and watch your statements.
Sources (1)
- ransomware_live · ransomware_live
What this means for you — Security leader:Check for Fondo in your third-party inventory; if present, invoke your vendor-incident playbook and request their IR status in writing.What this means for you — Lean IT orgs:If you use or supply Fondo: change any shared passwords today, watch account and transaction activity, and don't click 'urgent' emails about this incident.What this means for you — MSP:Sweep client stacks for Fondo dependencies and shared credentials; one leak-site claim can touch many of your clients at once.What this means for you — Researcher:Unverified leak-site claim by direwolf; track for proof-of-data posts before citing. Victim statement, if any, supersedes. - Our takedirewolf lists Osmo Wallet on its leak site. Single leak-site posting, no filing, no victim statement. Claimed — unconfirmed. If you're a customer: change that password anywhere you reused it, and watch your statements.
Sources (1)
- ransomware_live · ransomware_live
What this means for you — Security leader:Check for Osmo Wallet in your third-party inventory; if present, invoke your vendor-incident playbook and request their IR status in writing.What this means for you — Lean IT orgs:If you use or supply Osmo Wallet: change any shared passwords today, watch account and transaction activity, and don't click 'urgent' emails about this incident.What this means for you — MSP:Sweep client stacks for Osmo Wallet dependencies and shared credentials; one leak-site claim can touch many of your clients at once.What this means for you — Researcher:Unverified leak-site claim by direwolf; track for proof-of-data posts before citing. Victim statement, if any, supersedes. - Our takebravox lists Elettrica System on its leak site. One source, no victim statement, no filing. Treat as unverified.
Sources (1)
- ransomware_live · ransomware_live
What this means for you — Security leader:Check for Elettrica System in your third-party inventory; if present, invoke your vendor-incident playbook and request their IR status in writing.What this means for you — Lean IT orgs:If you use or supply Elettrica System: change any shared passwords today, watch account and transaction activity, and don't click 'urgent' emails about this incident.What this means for you — MSP:Sweep client stacks for Elettrica System dependencies and shared credentials; one leak-site claim can touch many of your clients at once.What this means for you — Researcher:Unverified leak-site claim by bravox; track for proof-of-data posts before citing. Victim statement, if any, supersedes. - Our takeGlobal Secret Group leak-site posting names Coggins Insurance Agency. The posting cites 85.9 GB. No filing, no confirmation — leak-site post only. Claim only — unverified. Customers: watch card and account activity for fraud; be wary of 'urgent' emails citing this incident.
Sources (1)
- ransomware_live · ransomware_live
What this means for you — Security leader:Check for Coggins Insurance Agency in your third-party inventory; if present, invoke your vendor-incident playbook and request their IR status in writing.What this means for you — Lean IT orgs:If you use or supply Coggins Insurance Agency: change any shared passwords today, watch account and transaction activity, and don't click 'urgent' emails about this incident.What this means for you — MSP:Sweep client stacks for Coggins Insurance Agency dependencies and shared credentials; one leak-site claim can touch many of your clients at once.What this means for you — Researcher:Unverified leak-site claim by Global Secret Group; track for proof-of-data posts before citing. Victim statement, if any, supersedes. - Our takebravox claims Verona 83 as a victim. Single-source, no filing, no advisory. Treat as claimed, not fact.
Sources (1)
- ransomware_live · ransomware_live
What this means for you — Security leader:Check for Verona 83 in your third-party inventory; if present, invoke your vendor-incident playbook and request their IR status in writing.What this means for you — Lean IT orgs:If you use or supply Verona 83: change any shared passwords today, watch account and transaction activity, and don't click 'urgent' emails about this incident.What this means for you — MSP:Sweep client stacks for Verona 83 dependencies and shared credentials; one leak-site claim can touch many of your clients at once.What this means for you — Researcher:Unverified leak-site claim by bravox; track for proof-of-data posts before citing. Victim statement, if any, supersedes. - Our takeakira lists Alcast on its leak site. The posting cites 170 GB. No filing, no confirmation — leak-site post only. Treat as claimed, not fact.
Sources (1)
- ransomware_live · ransomware_live
What this means for you — Security leader:Check for Alcast in your third-party inventory; if present, invoke your vendor-incident playbook and request their IR status in writing.What this means for you — Lean IT orgs:If you use or supply Alcast: change any shared passwords today, watch account and transaction activity, and don't click 'urgent' emails about this incident.What this means for you — MSP:Sweep client stacks for Alcast dependencies and shared credentials; one leak-site claim can touch many of your clients at once.What this means for you — Researcher:Unverified leak-site claim by akira; track for proof-of-data posts before citing. Victim statement, if any, supersedes. - Our takePanzer claims The Minor Food Group as a victim. Single leak-site posting, no filing, no victim statement. Claimed — unconfirmed.
Sources (1)
- ransomware_live · ransomware_live
What this means for you — Security leader:Check for The Minor Food Group in your third-party inventory; if present, invoke your vendor-incident playbook and request their IR status in writing.What this means for you — Lean IT orgs:If you use or supply The Minor Food Group: change any shared passwords today, watch account and transaction activity, and don't click 'urgent' emails about this incident.What this means for you — MSP:Sweep client stacks for The Minor Food Group dependencies and shared credentials; one leak-site claim can touch many of your clients at once.What this means for you — Researcher:Unverified leak-site claim by Panzer; track for proof-of-data posts before citing. Victim statement, if any, supersedes. - Our takeakira lists One Vision Imaging on its leak site. The posting cites 180 GB. Single leak-site posting, no filing, no victim statement. Claimed — unconfirmed. Customers: watch card and account activity for fraud; be wary of 'urgent' emails citing this incident.
Sources (1)
- ransomware_live · ransomware_live
What this means for you — Security leader:Check for One Vision Imaging in your third-party inventory; if present, invoke your vendor-incident playbook and request their IR status in writing.What this means for you — Lean IT orgs:If you use or supply One Vision Imaging: change any shared passwords today, watch account and transaction activity, and don't click 'urgent' emails about this incident.What this means for you — MSP:Sweep client stacks for One Vision Imaging dependencies and shared credentials; one leak-site claim can touch many of your clients at once.What this means for you — Researcher:Unverified leak-site claim by akira; track for proof-of-data posts before citing. Victim statement, if any, supersedes. - Our takeakira claims i4 Solutions as a victim. The posting cites 170 GB. No filing, no confirmation — leak-site post only. Claim only — unverified.
Sources (1)
- ransomware_live · ransomware_live
What this means for you — Security leader:Check for i4 Solutions in your third-party inventory; if present, invoke your vendor-incident playbook and request their IR status in writing.What this means for you — Lean IT orgs:If you use or supply i4 Solutions: change any shared passwords today, watch account and transaction activity, and don't click 'urgent' emails about this incident.What this means for you — MSP:Sweep client stacks for i4 Solutions dependencies and shared credentials; one leak-site claim can touch many of your clients at once.What this means for you — Researcher:Unverified leak-site claim by akira; track for proof-of-data posts before citing. Victim statement, if any, supersedes. - Our takeGlobal Secret Group claims MACOFIN HELLAS S.A. as a victim. The posting cites 55.3 GB. One source, no victim statement, no filing. Treat as unverified until corroborated. If you're a customer: change that password anywhere you reused it, and watch your statements.
Sources (1)
- ransomware_live · ransomware_live
What this means for you — Security leader:Check for MACOFIN HELLAS S.A. in your third-party inventory; if present, invoke your vendor-incident playbook and request their IR status in writing.What this means for you — Lean IT orgs:If you use or supply MACOFIN HELLAS S.A.: change any shared passwords today, watch account and transaction activity, and don't click 'urgent' emails about this incident.What this means for you — MSP:Sweep client stacks for MACOFIN HELLAS S.A. dependencies and shared credentials; one leak-site claim can touch many of your clients at once.What this means for you — Researcher:Unverified leak-site claim by Global Secret Group; track for proof-of-data posts before citing. Victim statement, if any, supersedes. - Our takeqilin claims City of Winchester as a victim. Single-source, no filing, no advisory. Treat as unverified.
Sources (1)
- ransomware_live · ransomware_live
What this means for you — Security leader:Check for City of Winchester in your third-party inventory; if present, invoke your vendor-incident playbook and request their IR status in writing.What this means for you — Lean IT orgs:If you use or supply City of Winchester: change any shared passwords today, watch account and transaction activity, and don't click 'urgent' emails about this incident.What this means for you — MSP:Sweep client stacks for City of Winchester dependencies and shared credentials; one leak-site claim can touch many of your clients at once.What this means for you — Researcher:Unverified leak-site claim by qilin; track for proof-of-data posts before citing. Victim statement, if any, supersedes. - Our takeqilin's leak site lists B Wright Drywall. Single leak-site posting, no filing, no victim statement. Claimed — unconfirmed.
Sources (1)
- ransomware_live · ransomware_live
What this means for you — Security leader:Check for B Wright Drywall in your third-party inventory; if present, invoke your vendor-incident playbook and request their IR status in writing.What this means for you — Lean IT orgs:If you use or supply B Wright Drywall: change any shared passwords today, watch account and transaction activity, and don't click 'urgent' emails about this incident.What this means for you — MSP:Sweep client stacks for B Wright Drywall dependencies and shared credentials; one leak-site claim can touch many of your clients at once.What this means for you — Researcher:Unverified leak-site claim by qilin; track for proof-of-data posts before citing. Victim statement, if any, supersedes. - Our takeGlobal Secret Group claims Cook Remodeling as a victim. The posting cites 23.2 GB. Single-source, no filing, no advisory. Treat as claimed, not fact.
Sources (1)
- ransomware_live · ransomware_live
What this means for you — Security leader:Check for Cook Remodeling in your third-party inventory; if present, invoke your vendor-incident playbook and request their IR status in writing.What this means for you — Lean IT orgs:If you use or supply Cook Remodeling: change any shared passwords today, watch account and transaction activity, and don't click 'urgent' emails about this incident.What this means for you — MSP:Sweep client stacks for Cook Remodeling dependencies and shared credentials; one leak-site claim can touch many of your clients at once.What this means for you — Researcher:Unverified leak-site claim by Global Secret Group; track for proof-of-data posts before citing. Victim statement, if any, supersedes. - Our takeStorm lists Southern Metals on its leak site. Single-source, no filing, no advisory. Claim only — unverified.
Sources (1)
- ransomware_live · ransomware_live
What this means for you — Security leader:Check for Southern Metals in your third-party inventory; if present, invoke your vendor-incident playbook and request their IR status in writing.What this means for you — Lean IT orgs:If you use or supply Southern Metals: change any shared passwords today, watch account and transaction activity, and don't click 'urgent' emails about this incident.What this means for you — MSP:Sweep client stacks for Southern Metals dependencies and shared credentials; one leak-site claim can touch many of your clients at once.What this means for you — Researcher:Unverified leak-site claim by Storm; track for proof-of-data posts before citing. Victim statement, if any, supersedes. - Our takeStorm claims TRP International as a victim. Single-source, no filing, no advisory. Treat as unverified.
Sources (1)
- ransomware_live · ransomware_live
What this means for you — Security leader:Check for TRP International in your third-party inventory; if present, invoke your vendor-incident playbook and request their IR status in writing.What this means for you — Lean IT orgs:If you use or supply TRP International: change any shared passwords today, watch account and transaction activity, and don't click 'urgent' emails about this incident.What this means for you — MSP:Sweep client stacks for TRP International dependencies and shared credentials; one leak-site claim can touch many of your clients at once.What this means for you — Researcher:Unverified leak-site claim by Storm; track for proof-of-data posts before citing. Victim statement, if any, supersedes. - Our takeStorm's leak site lists Supportive Insurance Services. Single leak-site posting, no filing, no victim statement. Claim only — unverified. If you're a customer: change that password anywhere you reused it, and watch your statements.
Sources (1)
- ransomware_live · ransomware_live
What this means for you — Security leader:Check for Supportive Insurance Services in your third-party inventory; if present, invoke your vendor-incident playbook and request their IR status in writing.What this means for you — Lean IT orgs:If you use or supply Supportive Insurance Services: change any shared passwords today, watch account and transaction activity, and don't click 'urgent' emails about this incident.What this means for you — MSP:Sweep client stacks for Supportive Insurance Services dependencies and shared credentials; one leak-site claim can touch many of your clients at once.What this means for you — Researcher:Unverified leak-site claim by Storm; track for proof-of-data posts before citing. Victim statement, if any, supersedes. - Our takeWallstreet lists T.RAD North America on its leak site. No filing, no confirmation — leak-site post only. Treat as claimed, not fact.
Sources (1)
- ransomware_live · ransomware_live
What this means for you — Security leader:Check for T.RAD North America in your third-party inventory; if present, invoke your vendor-incident playbook and request their IR status in writing.What this means for you — Lean IT orgs:If you use or supply T.RAD North America: change any shared passwords today, watch account and transaction activity, and don't click 'urgent' emails about this incident.What this means for you — MSP:Sweep client stacks for T.RAD North America dependencies and shared credentials; one leak-site claim can touch many of your clients at once.What this means for you — Researcher:Unverified leak-site claim by Wallstreet; track for proof-of-data posts before citing. Victim statement, if any, supersedes. - Our takeWallstreet's leak site lists Black Hills Bentonite. Single-source, no filing, no advisory. Treat as unverified until corroborated.
Sources (1)
- ransomware_live · ransomware_live
What this means for you — Security leader:Check for Black Hills Bentonite in your third-party inventory; if present, invoke your vendor-incident playbook and request their IR status in writing.What this means for you — Lean IT orgs:If you use or supply Black Hills Bentonite: change any shared passwords today, watch account and transaction activity, and don't click 'urgent' emails about this incident.What this means for you — MSP:Sweep client stacks for Black Hills Bentonite dependencies and shared credentials; one leak-site claim can touch many of your clients at once.What this means for you — Researcher:Unverified leak-site claim by Wallstreet; track for proof-of-data posts before citing. Victim statement, if any, supersedes. - Our takespacebears leak-site posting names Elixi International SA. One source, no victim statement, no filing. Treat as claimed, not fact. If you're a customer: change that password anywhere you reused it, and watch your statements.
Sources (1)
- ransomware_live · ransomware_live
What this means for you — Security leader:Check for Elixi International SA in your third-party inventory; if present, invoke your vendor-incident playbook and request their IR status in writing.What this means for you — Lean IT orgs:If you use or supply Elixi International SA: change any shared passwords today, watch account and transaction activity, and don't click 'urgent' emails about this incident.What this means for you — MSP:Sweep client stacks for Elixi International SA dependencies and shared credentials; one leak-site claim can touch many of your clients at once.What this means for you — Researcher:Unverified leak-site claim by spacebears; track for proof-of-data posts before citing. Victim statement, if any, supersedes. - Our takeCCCS confirms CVE-2026-64638 is under active exploitation in WordPress <7.0.3. Update now.
Sources (1)
- cccs · cccs
What this means for you — Security leader:WordPress 7.0.3 patches CVE-2026-64638, confirmed under active exploitation. Update all self-hosted instances immediately and verify that auto-updates are enabled.What this means for you — Lean IT orgs:If you run your own WordPress site, update it to version 7.0.3 or newer right away — this vulnerability is already being exploited in the wild.What this means for you — MSP:Confirm that all client WordPress sites are updated to 7.0.3 or later; this CVE is under active exploitation and affects the majority of self-hosted instances.What this means for you — Researcher:WordPress 7.0.3 patches CVE-2026-64638 under confirmed active exploitation per CCCS advisory AV26-792. - Our takeWebPros advisory AV26-790 confirms a blind SQL injection (CVE-2026-64636) in Plesk Obsidian before 18.0.80.1 and 18.0.79.5. Patch now if you run it yourself.
Sources (1)
- cccs · cccs
What this means for you — Security leader:Apply the WebPros patches to reach Plesk Obsidian 18.0.80.1 or 18.0.79.5. Blind SQL injection in a hosting control panel is high risk if your instances are internet-facing.What this means for you — Lean IT orgs:If you run your own Plesk server, update it immediately to version 18.0.80.1 or 18.0.79.5. Most lean-IT teams use hosted services and can ignore this.What this means for you — MSP:Check every client Plesk Obsidian instance; patch to 18.0.80.1 or 18.0.79.5. Prioritize any exposed to the internet.What this means for you — Researcher:WebPros confirmed blind SQL injection (CVE-2026-64636) in Plesk Obsidian prior to 18.0.80.1 and 18.0.79.5. Patch or upgrade. - Our takeCISA added CVE-2026-20316 to KEV: hard-coded password in Cisco Secure FMC, exploited as a zero-day. Patch if you run FMC (enterprises, MSPs); most smaller shops don't deploy it and can skip this.
Sources (4)
- cisa_kev · cisa_kev
- cisa_advisories · cisa_advisories
- bleeping · bleeping
- helpnet · helpnet
What this means for you — Security leader:If you run Cisco Secure Firewall Management Center (FMC), treat CVE-2026-20316 as urgent: it is in CISA KEV with confirmed exploitation and allows unauthenticated remote login via a hard-coded low-privileged credential. Apply Cisco’s fixed releases or mitigations now and verify no unexpected FMC accounts or access.What this means for you — Lean IT orgs:Most lean-IT shops do not run Cisco FMC themselves. If a provider manages your firewalls on FMC, ask them today whether they have patched CVE-2026-20316 and what evidence they can share.What this means for you — MSP:Inventory every client with Cisco Secure Firewall Management Center; prioritize CVE-2026-20316—hard-coded credentials, unauthenticated remote access, actively exploited, now KEV. Patch or mitigate per Cisco, then check for unexpected logins on affected FMC instances.What this means for you — Researcher:CVE-2026-20316 is a hard-coded password in Cisco FMC, added to KEV after confirmed in-the-wild use. Compare Cisco’s advisory (affected trains, fix versions, any credential rotation guidance) with the KEV due date and public exploit reporting. - Our takeunsafe's leak site lists DECK APP TECHNOLOGIES PTE. LTD. Single-source, no filing, no advisory. Claim only — unverified.
Sources (1)
- ransomware_live · ransomware_live
What this means for you — Security leader:Check for DECK APP TECHNOLOGIES PTE. LTD in your third-party inventory; if present, invoke your vendor-incident playbook and request their IR status in writing.What this means for you — Lean IT orgs:If you use or supply DECK APP TECHNOLOGIES PTE. LTD: change any shared passwords today, watch account and transaction activity, and don't click 'urgent' emails about this incident.What this means for you — MSP:Sweep client stacks for DECK APP TECHNOLOGIES PTE. LTD dependencies and shared credentials; one leak-site claim can touch many of your clients at once.What this means for you — Researcher:Unverified leak-site claim by unsafe; track for proof-of-data posts before citing. Victim statement, if any, supersedes. - Our takethegentlemen's leak site lists CONTAC Ingenieros. Single-source, no filing, no advisory. Claimed — unconfirmed.
Sources (1)
- ransomware_live · ransomware_live
What this means for you — Security leader:Check for CONTAC Ingenieros in your third-party inventory; if present, invoke your vendor-incident playbook and request their IR status in writing.What this means for you — Lean IT orgs:If you use or supply CONTAC Ingenieros: change any shared passwords today, watch account and transaction activity, and don't click 'urgent' emails about this incident.What this means for you — MSP:Sweep client stacks for CONTAC Ingenieros dependencies and shared credentials; one leak-site claim can touch many of your clients at once.What this means for you — Researcher:Unverified leak-site claim by thegentlemen; track for proof-of-data posts before citing. Victim statement, if any, supersedes. - Our takethegentlemen's leak site lists RAK Construction. Single leak-site posting, no filing, no victim statement. Claimed — unconfirmed.
Sources (1)
- ransomware_live · ransomware_live
What this means for you — Security leader:Check for RAK Construction in your third-party inventory; if present, invoke your vendor-incident playbook and request their IR status in writing.What this means for you — Lean IT orgs:If you use or supply RAK Construction: change any shared passwords today, watch account and transaction activity, and don't click 'urgent' emails about this incident.What this means for you — MSP:Sweep client stacks for RAK Construction dependencies and shared credentials; one leak-site claim can touch many of your clients at once.What this means for you — Researcher:Unverified leak-site claim by thegentlemen; track for proof-of-data posts before citing. Victim statement, if any, supersedes. - Our takethegentlemen leak-site posting names Lancesoft India. Single-source, no filing, no advisory. Treat as unverified.
Sources (1)
- ransomware_live · ransomware_live
What this means for you — Security leader:Check for Lancesoft India in your third-party inventory; if present, invoke your vendor-incident playbook and request their IR status in writing.What this means for you — Lean IT orgs:If you use or supply Lancesoft India: change any shared passwords today, watch account and transaction activity, and don't click 'urgent' emails about this incident.What this means for you — MSP:Sweep client stacks for Lancesoft India dependencies and shared credentials; one leak-site claim can touch many of your clients at once.What this means for you — Researcher:Unverified leak-site claim by thegentlemen; track for proof-of-data posts before citing. Victim statement, if any, supersedes. - Our takethegentlemen leak-site posting names AIMS Group. No filing, no confirmation — leak-site post only. Treat as unverified.
Sources (1)
- ransomware_live · ransomware_live
What this means for you — Security leader:Check for AIMS Group in your third-party inventory; if present, invoke your vendor-incident playbook and request their IR status in writing.What this means for you — Lean IT orgs:If you use or supply AIMS Group: change any shared passwords today, watch account and transaction activity, and don't click 'urgent' emails about this incident.What this means for you — MSP:Sweep client stacks for AIMS Group dependencies and shared credentials; one leak-site claim can touch many of your clients at once.What this means for you — Researcher:Unverified leak-site claim by thegentlemen; track for proof-of-data posts before citing. Victim statement, if any, supersedes. - Our takethegentlemen claims AnMed as a victim. Single-source, no filing, no advisory. Claimed — unconfirmed. Customers: watch card and account activity for fraud; be wary of 'urgent' emails citing this incident.
Sources (1)
- ransomware_live · ransomware_live
What this means for you — Security leader:Check for AnMed in your third-party inventory; if present, invoke your vendor-incident playbook and request their IR status in writing.What this means for you — Lean IT orgs:If you use or supply AnMed: change any shared passwords today, watch account and transaction activity, and don't click 'urgent' emails about this incident.What this means for you — MSP:Sweep client stacks for AnMed dependencies and shared credentials; one leak-site claim can touch many of your clients at once.What this means for you — Researcher:Unverified leak-site claim by thegentlemen; track for proof-of-data posts before citing. Victim statement, if any, supersedes. - Our takethegentlemen lists NTU Alumni Club on its leak site. Single leak-site posting, no filing, no victim statement. Claimed — unconfirmed. If you're a customer: change that password anywhere you reused it, and watch your statements.
Sources (1)
- ransomware_live · ransomware_live
What this means for you — Security leader:Check for NTU Alumni Club in your third-party inventory; if present, invoke your vendor-incident playbook and request their IR status in writing.What this means for you — Lean IT orgs:If you use or supply NTU Alumni Club: change any shared passwords today, watch account and transaction activity, and don't click 'urgent' emails about this incident.What this means for you — MSP:Sweep client stacks for NTU Alumni Club dependencies and shared credentials; one leak-site claim can touch many of your clients at once.What this means for you — Researcher:Unverified leak-site claim by thegentlemen; track for proof-of-data posts before citing. Victim statement, if any, supersedes. - Our takethegentlemen leak-site posting names Canopy Support Services. No filing, no confirmation — leak-site post only. Treat as unverified until corroborated.
Sources (1)
- ransomware_live · ransomware_live
What this means for you — Security leader:Check for Canopy Support Services in your third-party inventory; if present, invoke your vendor-incident playbook and request their IR status in writing.What this means for you — Lean IT orgs:If you use or supply Canopy Support Services: change any shared passwords today, watch account and transaction activity, and don't click 'urgent' emails about this incident.What this means for you — MSP:Sweep client stacks for Canopy Support Services dependencies and shared credentials; one leak-site claim can touch many of your clients at once.What this means for you — Researcher:Unverified leak-site claim by thegentlemen; track for proof-of-data posts before citing. Victim statement, if any, supersedes.