PULSE
FEED
vulnKEV agrega CVE-2025-39964 — Linux / KernelvulnKEV agrega CVE-2026-53266 — Linux / KernelvulnKEV agrega CVE-2025-39682 — Linux / KernelvulnKEV agrega CVE-2026-58704 — Google / PixelvulnKEV agrega CVE-2026-76460 — Cisco / Identity Services EnginevulnKEV agrega CVE-2026-87886 — Acronis / BackupvulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-42018 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-85706 — GitLab / Community Edition and Enterprise EditionvulnKEV agrega CVE-2026-86060 — MikroTik / RouterOSvulnKEV agrega CVE-2026-67277 — MikroTik / RouterOSvulnKEV agrega CVE-2026-19490 — Citrix / NetScalervulnKEV agrega CVE-2025-39964 — Linux / KernelvulnKEV agrega CVE-2026-53266 — Linux / KernelvulnKEV agrega CVE-2025-39682 — Linux / KernelvulnKEV agrega CVE-2026-58704 — Google / PixelvulnKEV agrega CVE-2026-76460 — Cisco / Identity Services EnginevulnKEV agrega CVE-2026-87886 — Acronis / BackupvulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-42018 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-85706 — GitLab / Community Edition and Enterprise EditionvulnKEV agrega CVE-2026-86060 — MikroTik / RouterOSvulnKEV agrega CVE-2026-67277 — MikroTik / RouterOSvulnKEV agrega CVE-2026-19490 — Citrix / NetScaler
Kalir Brief · Item20 September 2026 · 12:37 UTC
BRIEFRansomwarehighP36

Qilin ransomware publishes German firm KMLS

KMLS

Detected20 September 2026 · 12:37 UTC
Why it matters

Qilin ransomware has listed KMLS, a German company, on its leak site, indicating a confirmed breach with likely data exfiltration. The group typically targets mid-market firms using double-extortion tactics. German industrial and supply-chain partners should assess their third-party exposure.

MetadataRECORD
CategoryRansomware
Severityhigh
Priority score36
Detected20 September 2026 · 12:37 UTC
Related items6
Ransomware42
Ransomware Qilin publica al minorista tailandés ShopDunkQilin ransomware has published ShopDunk, a Thai retail and e-commerce brand, as a victim on its extortion site. Publication implies a confirmed intrusion with a data-theft component, exposing customer and payment-adjacent records. Retail and e-commerce defenders should watch for credential-stuffing and fraud spikes.
32m
Ransomware52
Ransomware Qilin publica al Touring Club SuisseThe Qilin ransomware group has listed Touring Club Suisse, a major Swiss motoring and travel-services organization, on its leak site. A published victim of this scale signals a confirmed compromise and likely exfiltration of member and operational data. Swiss and neighboring financial/insurance partners should treat it as a real third-party risk.
32m
Ransomware44
Ransomware 'emperador' publica a la notaría italiana Studio Notarile CostantinoThe ransomware group 'emperador' has posted the Italian notary firm Studio Notarile Associato Salvatore Costantino e Anna Favarato to its leak site. The listing claims several thousand documents, including customer files and employee data. A freshly published victim signals an active extortion campaign and warrants monitoring.
3h
Ransomware46
Ransomware Nightspire publica a la sanitaria Great Bay Bio de Hong KongNightspire ransomware listed Great Bay Bio, a Hong Kong healthcare firm, among its victims; data availability is still unclear. Healthcare breaches endanger sensitive patient data and can disrupt clinical operations. It signals an active ransomware campaign, though outside the AR-LATAM region.
6h
Ransomware72
El ransomware n0n publica a la minorista deportiva FanaticsRansomware group n0n published US sports-commerce platform Fanatics, claiming 108 GB including 46,902 order files, customer PII, partner invoices and fraud-prevention data, with a 2026-09-23 deadline. A fresh, high-impact victim whose leaked records can drive follow-on fraud and third-party risk. Outside LatAm but timely as a newly published ransomware case.
10h
Ransomware48
Ransomware arcusmedia publica a la canadiense Schneider's Computingarcusmedia ransomware has published Canadian IT provider Schneider's Computing & Websites with a near-term deadline. Compromise of an IT and web-hosting provider can cascade to its many clients, amplifying impact. Though outside LATAM, it shows the group's active targeting of service providers.
20h