PULSE
FEED
vulnKEV agrega CVE-2026-7273 — Zyxel / GS1900 Series SwitchesvulnKEV agrega CVE-2025-39964 — Linux / KernelvulnKEV agrega CVE-2026-53266 — Linux / KernelvulnKEV agrega CVE-2025-39682 — Linux / KernelvulnKEV agrega CVE-2026-58704 — Google / PixelvulnKEV agrega CVE-2026-76460 — Cisco / Identity Services EnginevulnKEV agrega CVE-2026-87886 — Acronis / BackupvulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-42018 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-85706 — GitLab / Community Edition and Enterprise EditionvulnKEV agrega CVE-2026-86060 — MikroTik / RouterOSvulnKEV agrega CVE-2026-67277 — MikroTik / RouterOSvulnKEV agrega CVE-2026-7273 — Zyxel / GS1900 Series SwitchesvulnKEV agrega CVE-2025-39964 — Linux / KernelvulnKEV agrega CVE-2026-53266 — Linux / KernelvulnKEV agrega CVE-2025-39682 — Linux / KernelvulnKEV agrega CVE-2026-58704 — Google / PixelvulnKEV agrega CVE-2026-76460 — Cisco / Identity Services EnginevulnKEV agrega CVE-2026-87886 — Acronis / BackupvulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-42018 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-85706 — GitLab / Community Edition and Enterprise EditionvulnKEV agrega CVE-2026-86060 — MikroTik / RouterOSvulnKEV agrega CVE-2026-67277 — MikroTik / RouterOS
Kalir Brief · Item22 September 2026 · 13:49 UTC
BRIEFRansomwarehighP42

Akira ransomware publishes Italian firm DI.C.S.EL. S.R.L.

DI.C.S.EL. S.R.L.

Detected22 September 2026 · 13:49 UTC
Why it matters

The Akira group listed DI.C.S.EL. S.R.L., an Italian electrical and measurement solutions firm in Lombardy, claiming it will leak 9 GB of corporate data including employee IDs, driver's licenses, financials and NDAs. The victim is outside Latin America, but the publication is fresh and confirms an active intrusion with exfiltration. It is a useful TTP/targeting signal for defenders in the industrial and electrical sector.

MetadataRECORD
CategoryRansomware
Severityhigh
Priority score42
Detected22 September 2026 · 13:49 UTC
Related items6
Ransomware48
Ransomware n0n publica al proveedor retail FinSoftThe ransomware group 'n0n' published FinSoft, a retail back-office software vendor whose Kolibri platform serves 10+ retail chains (keddo, marc, lancaster and others). Client databases with sales, stock, pricing and financial records leak one per day after the deadline. It is a fresh supply-chain-style breach affecting many downstream retailers.
11h
Ransomware45
Ransomware publica a los despachos Hogan Lovells y CadwaladerThe SilentRansomGroup listed Hogan Lovells and Cadwalader, two prominent international law firms, on its leak site; the combined name is unusual and may indicate confusion or a hoax. Law firms hold highly confidential client and deal data, making them prized targets. Defenders should verify the claim before acting on it.
15h
Ransomware50
Ransomware Metaencryptor publica al proveedor automotriz AstemoThe Metaencryptor group published Astemo, a Japanese automotive mega-supplier with roughly 80,000 employees worldwide, on its leak site. Such a tier-1 supplier sits deep in global automotive supply chains, so a data-theft incident can ripple to OEMs and partners. It matters for defenders tracking ransomware against manufacturing, even though the victim is outside LATAM.
15h
Ransomware68
Ransomware Play publica a la fabricante brasileña MetallcoThe Play ransomware group has listed Metallco, a Brazilian manufacturing company, on its leak site. Manufacturing is part of Brazil's critical supply chain, and Play typically exfiltrates data before encrypting, so stolen corporate data may soon surface. Latin American defenders should treat this as an active regional ransomware incident.
15h
Ransomware38
Nightspire publica un colegio de EE. UU. como víctima de ransomwareNightspire ransomware listed a US school as a victim, though no data samples were published at the time of collection. Education victims hold student and staff PII, making them attractive for downstream identity fraud if the leak is confirmed. It signals an active ransomware campaign and a sector pattern worth monitoring despite the limited detail.
19h
Ransomware44
Ransomware Nightspire publica a la consultora italiana 360 ConsulenzaNightspire ransomware listed 360 Consulenza S.r.l., an Italian professional-services firm, claiming theft of client documents, project files and software source code. Publishing source code and client data enables follow-on fraud, IP theft and phishing against the firm's customers. It sits outside Latin America but shows an active group and a pattern regional defenders should track.
19h