PULSE
FEED
vulnKEV agrega CVE-2026-93952 — Arista / VeloCloud OrchestratorvulnKEV agrega CVE-2026-94127 — F5 / BIG-IP APMvulnKEV agrega CVE-2026-93616 — Check Point / Multiple ProductsvulnKEV agrega CVE-2026-85102 — Check Point / Multiple ProductsvulnKEV agrega CVE-2026-7273 — Zyxel / GS1900 Series SwitchesvulnKEV agrega CVE-2025-39964 — Linux / KernelvulnKEV agrega CVE-2026-53266 — Linux / KernelvulnKEV agrega CVE-2025-39682 — Linux / KernelvulnKEV agrega CVE-2026-58704 — Google / PixelvulnKEV agrega CVE-2026-76460 — Cisco / Identity Services EnginevulnKEV agrega CVE-2026-87886 — Acronis / BackupvulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / ArtifactoryvulnKEV agrega CVE-2026-93952 — Arista / VeloCloud OrchestratorvulnKEV agrega CVE-2026-94127 — F5 / BIG-IP APMvulnKEV agrega CVE-2026-93616 — Check Point / Multiple ProductsvulnKEV agrega CVE-2026-85102 — Check Point / Multiple ProductsvulnKEV agrega CVE-2026-7273 — Zyxel / GS1900 Series SwitchesvulnKEV agrega CVE-2025-39964 — Linux / KernelvulnKEV agrega CVE-2026-53266 — Linux / KernelvulnKEV agrega CVE-2025-39682 — Linux / KernelvulnKEV agrega CVE-2026-58704 — Google / PixelvulnKEV agrega CVE-2026-76460 — Cisco / Identity Services EnginevulnKEV agrega CVE-2026-87886 — Acronis / BackupvulnKEV agrega CVE-2026-76461 — Cisco / Secure Email GatewayvulnKEV agrega CVE-2026-84869 — ConnectWise / ScreenConnectvulnKEV agrega CVE-2026-42016 — JFrog / Artifactory
Kalir Brief · Item22 September 2026 · 23:43 UTC
BRIEFRansomwarehighP76

ShinyHunters ransomware threatens Fresenius Medical Care

Fresenius Medical Care

Detected22 September 2026 · 23:43 UTC
Why it matters

ShinyHunters has listed Fresenius Medical Care, a major German healthcare and dialysis provider, threatening to publish sensitive data unless contacted by 25 Sep 2026. Ransomware against healthcare can disrupt clinical operations and exposes protected health information. Outside Latin America, but a fresh, high-impact victim worth tracking.

MetadataRECORD
CategoryRansomware
Severityhigh
Priority score76
Detected22 September 2026 · 23:43 UTC
Related items6
Ransomware55
Silent Ransom publica a la firma legal estadounidense Clark HillSilent Ransom Group has listed Clark Hill, a large US law firm, as a ransomware victim. Law firms hold privileged, confidential client data, so a breach can disrupt litigation and expose sensitive information. Outside the region, but a notable active victim publication to track.
36m
Ransomware33
Ransomware Anubis publica a la alemana Gaedke & PartnerThe ransomware group Anubis published German accounting firm Gaedke & Partner Steuerberatung on its leak site, claiming a breach of client information. Tax and accounting firms hold sensitive financial and personal records, making them high-value targets and a supply-chain risk for their clients. The victim is small and outside Latin America, but it is a freshly published extortion claim.
2h
Ransomware88
Ransomware Titan publica al prestador de salud argentino HospifarThe ransomware group Titan has listed Grupo Hospifar S.R.L., an Argentine healthcare provider, on its leak site. Healthcare is critical infrastructure and exposure of patient records carries regulatory and safety consequences. Argentine health entities should treat this as an active, time-sensitive incident.
4h
Ransomware55
Ransomware Kairos publica a Krapf Group, operador de transporte escolar de EE. UU.The Kairos ransomware group has published Krapf Group, a US transportation firm running 2,500+ school buses with 3,500 employees. The stolen data reportedly includes personal information of thousands of bus drivers, raising safety and privacy concerns for a large workforce. Freshly listed victims signal an active campaign worth tracking for TTPs and regional spillover.
8h
Ransomware42
Ransomware Qilin publica al local estadounidense The Fifty/50Qilin ransomware lists The Fifty/50, a US-based victim, on its leak site. No data volume or record count was disclosed yet, so impact is unclear. A fresh extortion listing signals an active incident that defenders may want to track for naming and TTPs.
10h
Ransomware50
Ransomware Akira reclama a la textilera TDMIAkira claims textile firm TDMI, threatening to release 33GB including employee SSNs, driver's licenses, passports, credit cards and client data. The mix of PII and financial data raises fraud and account-takeover risk. Track the leak for reuse of credentials and identity documents.
10h