PULSE
FEED
vulnKEV agrega CVE-2025-39964 — Linux / KernelvulnKEV agrega CVE-2026-53266 — Linux / KernelvulnKEV agrega CVE-2025-39682 — Linux / KernelvulnKEV agrega CVE-2026-58704 — Google / PixelvulnKEV agrega CVE-2026-76460 — Cisco / Identity Services EnginevulnKEV agrega CVE-2026-87886 — Acronis / BackupvulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-42018 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-85706 — GitLab / Community Edition and Enterprise EditionvulnKEV agrega CVE-2026-86060 — MikroTik / RouterOSvulnKEV agrega CVE-2026-67277 — MikroTik / RouterOSvulnKEV agrega CVE-2026-19490 — Citrix / NetScalervulnKEV agrega CVE-2025-39964 — Linux / KernelvulnKEV agrega CVE-2026-53266 — Linux / KernelvulnKEV agrega CVE-2025-39682 — Linux / KernelvulnKEV agrega CVE-2026-58704 — Google / PixelvulnKEV agrega CVE-2026-76460 — Cisco / Identity Services EnginevulnKEV agrega CVE-2026-87886 — Acronis / BackupvulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-42018 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-85706 — GitLab / Community Edition and Enterprise EditionvulnKEV agrega CVE-2026-86060 — MikroTik / RouterOSvulnKEV agrega CVE-2026-67277 — MikroTik / RouterOSvulnKEV agrega CVE-2026-19490 — Citrix / NetScaler
Kalir Brief · Item21 September 2026 · 06:37 UTC
BRIEFRansomwarelowP41

ThreeAM ransomware publishes manufacturer Newman Tractor

Newman Tractor

Detected21 September 2026 · 06:37 UTC
Why it matters

The 'threeam' ransomware group published US heavy-equipment manufacturer Newman Tractor as a victim. Manufacturing firms are prime targets because operational downtime is costly, and extortion leaks can expose employee and customer data. It is outside LATAM but a fresh victim useful for tracking group TTPs.

MetadataRECORD
CategoryRansomware
Severitylow
Priority score41
Detected21 September 2026 · 06:37 UTC
Related items6
Ransomware50
Ransomware LockBit5 publica al banco etíope Siinqee BankThe LockBit5 ransomware group listed Siinqee Bank, an Ethiopian financial institution, on its leak site. A bank breach can disrupt payment and core banking services and expose customer financial data, and extortion often precedes data publication. Though outside Latin America, it is a fresh financial-sector victim worth tracking.
36m
Ransomware28
Ransomware Incransom publica a la ortodoncista estadounidense Maryann KrigerIncransom listed Bonita Orthodontics (Dr. Maryann Kriger), a small US practice, on its leak site. The claimed breach could expose patient records and PII, but the victim is small-scale and outside the LATAM focus. Limited regional relevance, useful mainly as context on the group's ongoing activity.
6h
Ransomware62
Ransomware Incransom publica a la inmobiliaria española Second HouseIncransom has listed Second House, a Barcelona-based real estate company with over 26 years in the property sector, on its extortion leak site. The group claims to have stolen corporate data, potentially including client, tenant and rental-management records. Spanish property and hospitality defenders should treat this as an active extortion campaign with data-leak risk.
6h
Ransomware76
Ransomware DragonForce publica a la aseguradora ARS RenacerThe DragonForce group has listed ARS Renacer, a Latin American health-risk administrator (ARS) licensed under SISALRIL that serves hundreds of thousands of affiliates, on its ransomware leak site. The posting implies exfiltration of member and medical data from a regulated health payer. This is a fresh regional healthcare ransomware victim; defenders should monitor for extortion escalation and abuse of exposed affiliate data.
10h
Ransomware70
Ransomware Emperador publica a la clínica Alabama Woman's Health CareThe Emperador ransomware group listed Alabama Woman's Health Care, a US healthcare provider, as a fresh victim, claiming theft of several thousand employee and patient documents plus a photo archive. Healthcare breaches expose highly sensitive medical and personal data and enable double-extortion. It matters as a newly published victim in a critical, regulated sector.
15h
Ransomware40
Ransomware auditteam publica a una empresa italianaThe auditteam ransomware group published a new Italian victim whose name is partially masked. The sector is not stated, but a fresh ransomware listing indicates a confirmed network compromise and data theft. Organizations in the affected sector across Italy/Europe should watch for extortion follow-up and reuse of stolen data.
16h