PULSE
FEED
vulnKEV agrega CVE-2026-93952 — Arista / VeloCloud OrchestratorvulnKEV agrega CVE-2026-94127 — F5 / BIG-IP APMvulnKEV agrega CVE-2026-93616 — Check Point / Multiple ProductsvulnKEV agrega CVE-2026-85102 — Check Point / Multiple ProductsvulnKEV agrega CVE-2026-7273 — Zyxel / GS1900 Series SwitchesvulnKEV agrega CVE-2025-39964 — Linux / KernelvulnKEV agrega CVE-2026-53266 — Linux / KernelvulnKEV agrega CVE-2025-39682 — Linux / KernelvulnKEV agrega CVE-2026-58704 — Google / PixelvulnKEV agrega CVE-2026-76460 — Cisco / Identity Services EnginevulnKEV agrega CVE-2026-87886 — Acronis / BackupvulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-93952 — Arista / VeloCloud OrchestratorvulnKEV agrega CVE-2026-94127 — F5 / BIG-IP APMvulnKEV agrega CVE-2026-93616 — Check Point / Multiple ProductsvulnKEV agrega CVE-2026-85102 — Check Point / Multiple ProductsvulnKEV agrega CVE-2026-7273 — Zyxel / GS1900 Series SwitchesvulnKEV agrega CVE-2025-39964 — Linux / KernelvulnKEV agrega CVE-2026-53266 — Linux / KernelvulnKEV agrega CVE-2025-39682 — Linux / KernelvulnKEV agrega CVE-2026-58704 — Google / PixelvulnKEV agrega CVE-2026-76460 — Cisco / Identity Services EnginevulnKEV agrega CVE-2026-87886 — Acronis / BackupvulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / Artifactory
Kalir Brief · Item23 September 2026 · 15:17 UTC
BRIEFRansomwarehighP66

Clop lists Australia's Transport for NSW state transport agency

Transport for NSW (Australia)

Detected23 September 2026 · 15:17 UTC
Reposts collapsed3
Why it matters

Clop listed Transport for NSW (transport.nsw.gov.au), the Australian state agency running trains, buses, ferries, roads and traffic systems. A ransomware hit on a government transport operator raises risks for public-safety and mobility infrastructure and potential exposure of citizen and operational data. Though outside Latin America, it is a genuine critical-infrastructure victim worth tracking for TTPs and victimology.

MetadataRECORD
CategoryRansomware
Severityhigh
Priority score66
Detected23 September 2026 · 15:17 UTC
Related items6
Ransomware32
Ransomware Settra publica a Vestfrost Solutions (Noruega)The Settra group listed Vestfrost Solutions, a Norwegian maker of commercial refrigeration equipment, as a ransomware victim. The impact is limited to a mid-sized industrial supplier outside Latin America. It matters mainly as tracking data for the group's targeting patterns, not as a regional alert.
46m
Ransomware40
Ransomware Spirals publica al grupo logístico Asyad (Omán)The Spirals group listed Asyad Group, Oman's integrated logistics provider ranked among the largest in MENA. Ransomware against a major logistics operator can disrupt port, freight and supply-chain operations. The victim is outside Latin America, so it is relevant but lower priority for a regional operator.
46m
Ransomware76
Ransomware Rhysida publica a la editorial latinoamericana LegisThe Rhysida group listed Legis, a 60-year-old Latin American legal and business publisher operating in Colombia, Venezuela, Argentina, Mexico, Peru and Chile. Stolen data reportedly includes SQL databases, PST/OST mail archives, legal documents and scanned cédula ID copies of shareholders. This is a large regional breach mixing corporate data with personal identity documents.
46m
Ransomware60
Ransomware Clop publica a la minorista canadiense ALDO GroupClop lists ALDO Group (aldoshoes.com), a major Canadian footwear retailer with global operations, as a victim. Clop is a prolific extortion group known for mass data-theft campaigns, so a confirmed hit on a large retailer is significant. Expect customer and employee data exposure and possible supply-chain fallout.
2h
Ransomware52
Ransomware Clop publica a la marca finlandesa SuuntoClop lists Suunto.cn, the Chinese storefront of Finnish sports-instrument maker Suunto, as a victim. Clop runs large-scale extortion campaigns, so the involvement of a recognized global brand is notable even if the listed domain is the China site. Exposure could include customer orders and account data.
2h
Ransomware58
Ransomware 'endzone' publica al operador móvil Trump MobileRansomware group 'endzone' lists Trump Mobile, a US MVNO, as a victim, claiming exposure of eSIM QR codes and customer PII. The brand's political profile makes it a notable target, though the operator reports only about 4,000 users, limiting impact. Watch for downstream SIM-swap and account-takeover attempts.
2h