PULSE
LIVE0signals / 24h
FEED
vulnKEV agrega CVE-2026-59822 — BerriAI / LiteLLMvulnKEV agrega CVE-2026-48710 — Kludex / StarlettevulnKEV agrega CVE-2026-49869 — Kestra / Kestra OSSvulnKEV agrega CVE-2026-82329 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-9586 — Sangoma / SwitchvoxvulnKEV agrega CVE-2026-83548 — SonicWall / SMA1000 AppliancesvulnKEV agrega CVE-2026-83549 — SonicWall / SMA1000 AppliancesvulnKEV agrega CVE-2026-82078 — PaperCut / NG/MFvulnKEV agrega CVE-2026-81578 — PaperCut / NG/MFvulnKEV agrega CVE-2023-49105 — ownCloud / ownCloudvulnKEV agrega CVE-2026-53362 — Linux / KernelvulnKEV agrega CVE-2026-66384 — JFrog / ArtifactoryvulnKEV agrega CVE-2021-23758 — Ajax.NET Professional / Ajax.NET ProfessionalvulnKEV agrega CVE-2015-3246 — Red Hat / LibuservulnKEV agrega CVE-2026-59822 — BerriAI / LiteLLMvulnKEV agrega CVE-2026-48710 — Kludex / StarlettevulnKEV agrega CVE-2026-49869 — Kestra / Kestra OSSvulnKEV agrega CVE-2026-82329 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-9586 — Sangoma / SwitchvoxvulnKEV agrega CVE-2026-83548 — SonicWall / SMA1000 AppliancesvulnKEV agrega CVE-2026-83549 — SonicWall / SMA1000 AppliancesvulnKEV agrega CVE-2026-82078 — PaperCut / NG/MFvulnKEV agrega CVE-2026-81578 — PaperCut / NG/MFvulnKEV agrega CVE-2023-49105 — ownCloud / ownCloudvulnKEV agrega CVE-2026-53362 — Linux / KernelvulnKEV agrega CVE-2026-66384 — JFrog / ArtifactoryvulnKEV agrega CVE-2021-23758 — Ajax.NET Professional / Ajax.NET ProfessionalvulnKEV agrega CVE-2015-3246 — Red Hat / Libuser
Kalir Brief · Item5 September 2026 · 11:03 UTC
BRIEFRansomwarehighP65

Aurora ransomware publishes data from US defense contractor Metrea LLC

Metrea LLC / Commuter Air Technology, Inc.

Detected5 September 2026 · 11:03 UTC
Why it matters

Aurora ransomware leaked 339 MB from Metrea LLC, a US defense contractor providing ISR aircraft for US SOCOM, and its subsidiary Commuter Air Technology. The dump includes Harris PRC-117G military radio documentation, exposing sensitive operational data. This is a significant defense-sector breach of interest to CTI operators tracking cyber threats against military supply chains.

MetadataRECORD
CategoryRansomware
Severityhigh
Priority score65
Detected5 September 2026 · 11:03 UTC
Related items6
Ransomware72
Ransomware Silent Ransom publica al bufete estadounidense Holland & KnightThe Silent Ransom Group has published Holland & Knight, a major US law firm, on its ransomware victim site. Law firms hold sensitive client data, and a confirmed ransomware publication can lead to document leaks and legal or regulatory damage. This is a fresh ransomware victim incident relevant for tracking, even though the firm is outside Latin America.
4d
Ransomware35
Ransomware Rhysida publica a la organización húngara Szechenyi ProgramirodaThe Rhysida ransomware group has listed the Hungarian nonprofit Szechenyi Programiroda on its leak site. Although the victim is outside Latin America, monitoring Rhysida activity helps anticipate tactics, infrastructure, and potential targeting of regional entities. Organizations should review their exposure to Rhysida indicators.
4d
Ransomware55
Ransomware Qilin publica a la Commission de la construction du QuébecThe Commission de la construction du Québec (CCQ), a public agency overseeing Quebec's construction industry, has been listed on the Qilin ransomware leak site. Government agencies are high-value targets and the incident may expose sensitive employee and project data. While outside Latin America, it is a fresh ransomware event worth tracking for regional CTI.
4d
Ransomware62
Ransomware Wallstreet publica datos del municipio de Andover, MassachusettsThe Wallstreet ransomware group listed the Town of Andover, Massachusetts, a U.S. municipal government, as a victim. Municipal data, including citizen records and infrastructure details, may be exposed. Although outside Latin America, this fresh ransomware victim is relevant for tracking current ransomware activity.
6d
Ransomware55
Ransomware Falcon publica a DistributionNOW (distribuidor de energía de EE. UU.)Falcon ransomware claims 344 GB exfiltrated from energy distributor DistributionNOW, including financial records, SCADA gateway backups, and PLC logic. Loss of OT-related data indicates potential impact on industrial operations. This case is relevant to Latin American energy and critical infrastructure sectors as a warning of similar attack patterns.
6d
Ransomware60
Ransomware Falcon publica a Globus Medical (fabricante de dispositivos médicos de EE. UU.)Falcon ransomware claims to have exfiltrated 2.96 TB from medical device maker Globus Medical, including customer records, FDA submissions, and product complaint logs. The incident exposes sensitive healthcare and regulatory data, raising supply-chain concerns. Even though the victim is in the US, this type of attack highlights TTPs relevant for Latin American healthcare and critical infrastructure defenders.
6d