PULSE
LIVE0signals / 24h
FEED
vulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-42018 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-85706 — GitLab / Community Edition and Enterprise EditionvulnKEV agrega CVE-2026-86060 — MikroTik / RouterOSvulnKEV agrega CVE-2026-67277 — MikroTik / RouterOSvulnKEV agrega CVE-2026-19490 — Citrix / NetScalervulnKEV agrega CVE-2025-25249 — Fortinet / Multiple ProductsvulnKEV agrega CVE-2026-87491 — Google / Chromium V8vulnKEV agrega CVE-2026-20079 — Cisco / Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall ManagementvulnKEV agrega CVE-2026-75650 — Adobe / Commerce and MagentovulnKEV agrega CVE-2026-81963 — Microsoft / WindowsvulnKEV agrega CVE-2026-86218 — N-able / N-centralvulnKEV agrega CVE-2026-85880 — Microsoft / WindowsvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-42018 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-85706 — GitLab / Community Edition and Enterprise EditionvulnKEV agrega CVE-2026-86060 — MikroTik / RouterOSvulnKEV agrega CVE-2026-67277 — MikroTik / RouterOSvulnKEV agrega CVE-2026-19490 — Citrix / NetScalervulnKEV agrega CVE-2025-25249 — Fortinet / Multiple ProductsvulnKEV agrega CVE-2026-87491 — Google / Chromium V8vulnKEV agrega CVE-2026-20079 — Cisco / Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall ManagementvulnKEV agrega CVE-2026-75650 — Adobe / Commerce and MagentovulnKEV agrega CVE-2026-81963 — Microsoft / WindowsvulnKEV agrega CVE-2026-86218 — N-able / N-centralvulnKEV agrega CVE-2026-85880 — Microsoft / Windows
Kalir Brief · Item15 September 2026 · 06:12 UTC
BRIEFRansomwarehighP60

Qilin ransomware publishes Spanish company Geieg

Geieg

Detected15 September 2026 · 06:12 UTC
Why it matters

The Qilin ransomware group listed Geieg, a Spanish organisation, as a victim on its leak site. Publication signals a confirmed intrusion with data-theft extortion, exposing employee and client data. Spanish-speaking defenders should treat this as an active ransomware case in their region.

MetadataRECORD
CategoryRansomware
Severityhigh
Priority score60
Detected15 September 2026 · 06:12 UTC
Related items6
Ransomware52
Ransomware Shadowbyt3 publica a HandyTrac (Greystar, Arizona)Shadowbyt3 listed HandyTrac, a tenant key-control and access-management provider used by Greystar's Litchfield Park property. Leaked data includes physical-to-digital key maps, employee identity and credential data, and financial/vendor records. Exposed key-control reports and staff credentials can enable physical intrusion and account abuse at managed sites, making this a fresh and actionable victim even though it is US-based.
6h
Ransomware45
Ransomware Anubis publica a la firma contable Better AccountingThe Anubis ransomware group listed Better Accounting Solutions, a professional-services accounting firm, on its leak site, referencing Wall Street accountants' data. Data stolen from an accounting firm can include financial records and client information valuable for fraud and follow-on attacks. It is a fresh victim listing, though a small target outside the region.
7h
Ransomware45
Ransomware Eclipse publica al distrito escolar Dublin City SchoolsThe Eclipse ransomware group has listed Dublin City Schools, a Georgia (US) school district, on its leak site as a fresh victim. Education victims typically face operational downtime plus exposure of student and staff data, but this instance is outside Latin America, so it mainly serves to track the group's targeting.
14h
Ransomware45
Ransomware Eclipse publica al mayorista francés Rosello et FilsThe Eclipse ransomware group published Rosello & Fils, a French fruit and vegetable wholesaler in the agriculture and food sector, on its leak site. As a freshly-listed victim outside LATAM it is mainly context for regional defenders but confirms the group's ongoing activity. No compromise details pointing to the region are indicated.
15h
Ransomware35
LockBit5 publica a la firma finlandesa HTT OyLockBit5 has listed Finnish accounting firm HTT Oy as a ransomware victim on its leak site. Accounting firms hold sensitive financial records of many client companies, making them attractive extortion targets. A breach here can cascade into data-exposure and fraud risks across the firm's entire client base.
16h
Ransomware40
LockBit5 publica a la empresa taiwanesa tpi.twLockBit5 has listed the Taiwanese technology company tpi.tw as a ransomware victim on its leak site. The intrusion targets a tech firm, and stolen data may be published if no ransom is paid. Even a smaller victim can expose supply-chain partners and customers to follow-on phishing and fraud.
16h
Qilin ransomware publishes Spanish company Geieg · Kalir Brief · Pulse | Pulse