PULSE
FEED
vulnKEV agrega CVE-2026-7273 — Zyxel / GS1900 Series SwitchesvulnKEV agrega CVE-2025-39964 — Linux / KernelvulnKEV agrega CVE-2026-53266 — Linux / KernelvulnKEV agrega CVE-2025-39682 — Linux / KernelvulnKEV agrega CVE-2026-58704 — Google / PixelvulnKEV agrega CVE-2026-76460 — Cisco / Identity Services EnginevulnKEV agrega CVE-2026-87886 — Acronis / BackupvulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-42018 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-85706 — GitLab / Community Edition and Enterprise EditionvulnKEV agrega CVE-2026-86060 — MikroTik / RouterOSvulnKEV agrega CVE-2026-67277 — MikroTik / RouterOSvulnKEV agrega CVE-2026-7273 — Zyxel / GS1900 Series SwitchesvulnKEV agrega CVE-2025-39964 — Linux / KernelvulnKEV agrega CVE-2026-53266 — Linux / KernelvulnKEV agrega CVE-2025-39682 — Linux / KernelvulnKEV agrega CVE-2026-58704 — Google / PixelvulnKEV agrega CVE-2026-76460 — Cisco / Identity Services EnginevulnKEV agrega CVE-2026-87886 — Acronis / BackupvulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-42018 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-85706 — GitLab / Community Edition and Enterprise EditionvulnKEV agrega CVE-2026-86060 — MikroTik / RouterOSvulnKEV agrega CVE-2026-67277 — MikroTik / RouterOS
Kalir Brief · Item22 September 2026 · 03:01 UTC
BRIEFRansomwarehighP48

Ransomware n0n publishes retail vendor FinSoft

FinSoft (Kolibri back-office retail, Uzbekistán)

Detected22 September 2026 · 03:01 UTC
Why it matters

The ransomware group 'n0n' published FinSoft, a retail back-office software vendor whose Kolibri platform serves 10+ retail chains (keddo, marc, lancaster and others). Client databases with sales, stock, pricing and financial records leak one per day after the deadline. It is a fresh supply-chain-style breach affecting many downstream retailers.

MetadataRECORD
CategoryRansomware
Severityhigh
Priority score48
Detected22 September 2026 · 03:01 UTC
Related items6
Ransomware45
Ransomware publica a los despachos Hogan Lovells y CadwaladerThe SilentRansomGroup listed Hogan Lovells and Cadwalader, two prominent international law firms, on its leak site; the combined name is unusual and may indicate confusion or a hoax. Law firms hold highly confidential client and deal data, making them prized targets. Defenders should verify the claim before acting on it.
5h
Ransomware50
Ransomware Metaencryptor publica al proveedor automotriz AstemoThe Metaencryptor group published Astemo, a Japanese automotive mega-supplier with roughly 80,000 employees worldwide, on its leak site. Such a tier-1 supplier sits deep in global automotive supply chains, so a data-theft incident can ripple to OEMs and partners. It matters for defenders tracking ransomware against manufacturing, even though the victim is outside LATAM.
5h
Ransomware68
Ransomware Play publica a la fabricante brasileña MetallcoThe Play ransomware group has listed Metallco, a Brazilian manufacturing company, on its leak site. Manufacturing is part of Brazil's critical supply chain, and Play typically exfiltrates data before encrypting, so stolen corporate data may soon surface. Latin American defenders should treat this as an active regional ransomware incident.
5h
Ransomware38
Nightspire publica un colegio de EE. UU. como víctima de ransomwareNightspire ransomware listed a US school as a victim, though no data samples were published at the time of collection. Education victims hold student and staff PII, making them attractive for downstream identity fraud if the leak is confirmed. It signals an active ransomware campaign and a sector pattern worth monitoring despite the limited detail.
9h
Ransomware44
Ransomware Nightspire publica a la consultora italiana 360 ConsulenzaNightspire ransomware listed 360 Consulenza S.r.l., an Italian professional-services firm, claiming theft of client documents, project files and software source code. Publishing source code and client data enables follow-on fraud, IP theft and phishing against the firm's customers. It sits outside Latin America but shows an active group and a pattern regional defenders should track.
9h
Ransomware45
Ransomware Global Secret Group publica al fabricante Allied Supply Co.The ransomware group 'Global Secret Group' published Allied Supply Co., a US industrial machinery and wholesale firm, claiming about 25.3 GB of stolen files. The leak exposes internal business data and pressures the victim to pay. It is outside Latin America, but the TTPs and victim profile remain useful context.
10h