PULSE
LIVE0signals / 24h
FEED
vulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-42018 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-85706 — GitLab / Community Edition and Enterprise EditionvulnKEV agrega CVE-2026-86060 — MikroTik / RouterOSvulnKEV agrega CVE-2026-67277 — MikroTik / RouterOSvulnKEV agrega CVE-2026-19490 — Citrix / NetScalervulnKEV agrega CVE-2025-25249 — Fortinet / Multiple ProductsvulnKEV agrega CVE-2026-87491 — Google / Chromium V8vulnKEV agrega CVE-2026-20079 — Cisco / Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall ManagementvulnKEV agrega CVE-2026-75650 — Adobe / Commerce and MagentovulnKEV agrega CVE-2026-81963 — Microsoft / WindowsvulnKEV agrega CVE-2026-86218 — N-able / N-centralvulnKEV agrega CVE-2026-85880 — Microsoft / WindowsvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-42018 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-85706 — GitLab / Community Edition and Enterprise EditionvulnKEV agrega CVE-2026-86060 — MikroTik / RouterOSvulnKEV agrega CVE-2026-67277 — MikroTik / RouterOSvulnKEV agrega CVE-2026-19490 — Citrix / NetScalervulnKEV agrega CVE-2025-25249 — Fortinet / Multiple ProductsvulnKEV agrega CVE-2026-87491 — Google / Chromium V8vulnKEV agrega CVE-2026-20079 — Cisco / Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall ManagementvulnKEV agrega CVE-2026-75650 — Adobe / Commerce and MagentovulnKEV agrega CVE-2026-81963 — Microsoft / WindowsvulnKEV agrega CVE-2026-86218 — N-able / N-centralvulnKEV agrega CVE-2026-85880 — Microsoft / Windows
Kalir Brief · Item15 September 2026 · 08:12 UTC
BRIEFRansomwarehighP68

Thegentlemen ransomware lists Guatemalan IT integrator Somit

Somit

Detected15 September 2026 · 08:12 UTC
Why it matters

The thegentlemen ransomware group listed Somit, a Guatemalan IT systems integrator serving banks, universities and government clients, as a victim. A compromised integrator is a supply-chain risk: its access to client networks, telemedicine platforms and data centers could enable downstream intrusions. This makes it relevant to Latin American critical-infrastructure defenders.

MetadataRECORD
CategoryRansomware
Severityhigh
Priority score68
Detected15 September 2026 · 08:12 UTC
Related items6
Ransomware55
Ransomware thegentlemen publica a la heladería peruana GelartiThe thegentlemen ransomware group listed Gelarti, Peru's largest gourmet ice-cream chain with 39 outlets, as a victim. Retail and franchise operators hold customer loyalty, payment and supplier data. Encryption of POS or back-office systems could interrupt sales across Peru and expose customer and franchisee information.
57m
Ransomware52
Ransomware thegentlemen publica a la contable brasileña MultiplaThe thegentlemen group listed Multipla Contabilidade Empresarial, a family accounting firm in Piracicaba, São Paulo state, as a victim. Accounting firms concentrate tax, payroll and financial records of many client companies, so a breach can cascade to those clients. It is a smaller but real Brazilian data-exposure and extortion risk.
57m
Ransomware60
Ransomware thegentlemen publica al Colegio Humboldt de São PauloThe thegentlemen group lists Colegio Humboldt, the German binational school in São Paulo with ~1,200 students, claiming 300GB of stolen data. Schools hold student, family, health and staff records plus financial data. A leak of that volume at a high-profile institution raises serious privacy, extortion and reputational risk in Brazil.
57m
Ransomware62
Ransomware thegentlemen publica a la librería argentina Santa FeThe thegentlemen ransomware group listed Librería Santa Fe APS S.R.L., an Argentine book retailer and B2B distributor in Buenos Aires, as a victim. Such firms hold customer, supplier and school-institution sales data plus payment records. Encryption or data theft could disrupt book distribution across Argentina and expose customer PII to extortion.
57m
Ransomware60
Ransomware Qilin publica a la empresa española GeiegThe Qilin ransomware group listed Geieg, a Spanish organisation, as a victim on its leak site. Publication signals a confirmed intrusion with data-theft extortion, exposing employee and client data. Spanish-speaking defenders should treat this as an active ransomware case in their region.
3h
Ransomware52
Ransomware Shadowbyt3 publica a HandyTrac (Greystar, Arizona)Shadowbyt3 listed HandyTrac, a tenant key-control and access-management provider used by Greystar's Litchfield Park property. Leaked data includes physical-to-digital key maps, employee identity and credential data, and financial/vendor records. Exposed key-control reports and staff credentials can enable physical intrusion and account abuse at managed sites, making this a fresh and actionable victim even though it is US-based.
8h