PULSE
FEED
vulnKEV agrega CVE-2026-93952 — Arista / VeloCloud OrchestratorvulnKEV agrega CVE-2026-94127 — F5 / BIG-IP APMvulnKEV agrega CVE-2026-93616 — Check Point / Multiple ProductsvulnKEV agrega CVE-2026-85102 — Check Point / Multiple ProductsvulnKEV agrega CVE-2026-7273 — Zyxel / GS1900 Series SwitchesvulnKEV agrega CVE-2025-39964 — Linux / KernelvulnKEV agrega CVE-2026-53266 — Linux / KernelvulnKEV agrega CVE-2025-39682 — Linux / KernelvulnKEV agrega CVE-2026-58704 — Google / PixelvulnKEV agrega CVE-2026-76460 — Cisco / Identity Services EnginevulnKEV agrega CVE-2026-87886 — Acronis / BackupvulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-93952 — Arista / VeloCloud OrchestratorvulnKEV agrega CVE-2026-94127 — F5 / BIG-IP APMvulnKEV agrega CVE-2026-93616 — Check Point / Multiple ProductsvulnKEV agrega CVE-2026-85102 — Check Point / Multiple ProductsvulnKEV agrega CVE-2026-7273 — Zyxel / GS1900 Series SwitchesvulnKEV agrega CVE-2025-39964 — Linux / KernelvulnKEV agrega CVE-2026-53266 — Linux / KernelvulnKEV agrega CVE-2025-39682 — Linux / KernelvulnKEV agrega CVE-2026-58704 — Google / PixelvulnKEV agrega CVE-2026-76460 — Cisco / Identity Services EnginevulnKEV agrega CVE-2026-87886 — Acronis / BackupvulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / Artifactory
Kalir Brief · Item24 September 2026 · 22:47 UTC
BRIEFRansomwarehighP36

Pear ransomware publishes US endoscopy center Westside GI

Westside GI

Detected24 September 2026 · 22:47 UTC
Why it matters

The 'Pear' ransomware group listed Westside GI, a US ambulatory endoscopy center, as a victim. Healthcare ransomware disrupts patient care and exposes protected health information, a high-value target for extortion. It is a fresh victim publication with no confirmed regional tie.

MetadataRECORD
CategoryRansomware
Severityhigh
Priority score36
Detected24 September 2026 · 22:47 UTC
Related items6
Ransomware● 52
Ransomware Everest publica al organismo europeo CENELECEverest ransomware published CENELEC, the Brussels-based European Committee for Electrotechnical Standardization, as a victim. Standards and electrotechnical/energy-sector bodies are critical-infrastructure adjacent, so the listing matters for supply-chain and sector awareness. It is outside LATAM, so it ranks below regional alerts.
1h
Ransomware● 45
Ransomware Everest publica a la japonesa UNIRITAThe Everest ransomware group listed UNIRITA, a Tokyo-listed IT and infrastructure-software vendor, as a victim on its leak site. Named corporate victims such as mid-size IT vendors matter because they can be supply-chain footholds into their customers. It is a real but lower-priority alert for a LATAM-focused feed.
1h
Ransomware● 69
Ransomware BLACKNET-00 contra el municipio de Tel Aviv-YafoThe BLACKNET-00 group claims to have breached the Tel Aviv-Yafo municipality, a government target, and is publishing it as a ransomware victim. A municipal compromise exposes citizen services, internal systems and sensitive records, and the same group is listing multiple victims, signalling an active campaign. Even though it is outside LATAM, government-targeting ransomware from an active crew is worth tracking for pattern awareness.
1h
Ransomware● 70
Blacknet-00 publica el robo de datos de SriLankan AirlinesThe Blacknet-00 group claims an official breach of SriLankan Airlines, the national flag carrier, typically meaning exfiltrated passenger and operational data. State-linked airlines hold passport, booking and employee data, making this a high-value leak with identity-theft and DDoS follow-on risk. Airlines and their partners should monitor for leaked customer credentials and extortion pressure.
1h
Ransomware● 48
Ransomware LockBit publica a la aseguradora de salud Taspen LifeThe LockBit5 group listed Taspen Life, a health and group insurance provider (listed under Kazakhstan), as a ransomware victim. Healthcare breaches disrupt patient and policyholder services and expose sensitive health and personal data. It lies outside Latin America but is a fresh victim relevant for sector and insurer monitoring.
3h
Ransomware● 68
Ransomware Qilin publica a la fabricante española Iberia CompositechQilin ransomware listed Iberia Compositech Manufacturing, a Spanish manufacturer, as a fresh victim on its leak site with no sample data published yet. An active extortion usually gives defenders a short window to contain, assess backups and check whether Ibero-American subsidiaries or shared credentials are exposed. Manufacturing is a frequent supply-chain entry point, so this warrants monitoring.
3h