PULSE
FEED
vulnKEV agrega CVE-2026-93952 — Arista / VeloCloud OrchestratorvulnKEV agrega CVE-2026-94127 — F5 / BIG-IP APMvulnKEV agrega CVE-2026-93616 — Check Point / Multiple ProductsvulnKEV agrega CVE-2026-85102 — Check Point / Multiple ProductsvulnKEV agrega CVE-2026-7273 — Zyxel / GS1900 Series SwitchesvulnKEV agrega CVE-2025-39964 — Linux / KernelvulnKEV agrega CVE-2026-53266 — Linux / KernelvulnKEV agrega CVE-2025-39682 — Linux / KernelvulnKEV agrega CVE-2026-58704 — Google / PixelvulnKEV agrega CVE-2026-76460 — Cisco / Identity Services EnginevulnKEV agrega CVE-2026-87886 — Acronis / BackupvulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-93952 — Arista / VeloCloud OrchestratorvulnKEV agrega CVE-2026-94127 — F5 / BIG-IP APMvulnKEV agrega CVE-2026-93616 — Check Point / Multiple ProductsvulnKEV agrega CVE-2026-85102 — Check Point / Multiple ProductsvulnKEV agrega CVE-2026-7273 — Zyxel / GS1900 Series SwitchesvulnKEV agrega CVE-2025-39964 — Linux / KernelvulnKEV agrega CVE-2026-53266 — Linux / KernelvulnKEV agrega CVE-2025-39682 — Linux / KernelvulnKEV agrega CVE-2026-58704 — Google / PixelvulnKEV agrega CVE-2026-76460 — Cisco / Identity Services EnginevulnKEV agrega CVE-2026-87886 — Acronis / BackupvulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / Artifactory
Kalir Brief · Item23 September 2026 · 09:29 UTC
BRIEFRansomwarecriticalP95

Emperador ransomware publishes Brazil's Federal Revenue Service

Receita Federal do Brasil (Ministério da Fazenda)

Detected23 September 2026 · 09:29 UTC
Why it matters

Ransomware group Emperador listed Brazil's Receita Federal (Finance Ministry) on its leak site, claiming thousands of documents with personnel and customer data plus gov.br credentials and passwords. A breach of the federal tax authority impacts citizen tax data nationwide and enables identity theft and downstream fraud.

MetadataRECORD
CategoryRansomware
Severitycritical
Priority score95
Detected23 September 2026 · 09:29 UTC
Related items6
Ransomware34
Ransomware MedusaLock publica a la empresa francesa AokkefMedusaLock ransomware published French organization Aokkef, with roughly 137 emails extracted. It is a small, low-impact victim but confirms the group's ongoing campaign and extortion activity.
2h
Ransomware46
Ransomware MedusaLock publica al proveedor búlgaro Abv.bgMedusaLock ransomware lists Bulgarian web and email provider Abv.bg, with roughly 583 employee emails exposed. As a major national portal, a breach here risks user and corporate data as well as follow-on phishing. It is a fresh victim publish worth tracking.
2h
Ransomware52
Ransomware MedusaLock publica a la tecnológica checa SeznamMedusaLock ransomware claims Czech internet and technology company Seznam.cz as a victim, with roughly 115 employee emails extracted. A fresh listing of a high-profile regional tech company points to data theft and extortion. It is a useful benchmark for ransomware pressure on large web platforms.
2h
Ransomware42
Víctima de ransomware publicada por SilentRansomGroupThe ransomware.live tracker shows a fresh victim listed by the silentransomgroup, but the entry is redacted with the country and sector still hidden while a full-data timer runs. It matters only as a lead to watch, since the victim identity may be disclosed shortly. No regional or sector linkage can be confirmed yet.
10h
Ransomware55
Silent Ransom publica a la firma legal estadounidense Clark HillSilent Ransom Group has listed Clark Hill, a large US law firm, as a ransomware victim. Law firms hold privileged, confidential client data, so a breach can disrupt litigation and expose sensitive information. Outside the region, but a notable active victim publication to track.
11h
Ransomware76
ShinyHunters amenaza con filtrar datos de Fresenius Medical CareShinyHunters has listed Fresenius Medical Care, a major German healthcare and dialysis provider, threatening to publish sensitive data unless contacted by 25 Sep 2026. Ransomware against healthcare can disrupt clinical operations and exposes protected health information. Outside Latin America, but a fresh, high-impact victim worth tracking.
11h