PULSE
LIVE0signals / 24h
FEED
vulnKEV agrega CVE-2023-49105 — ownCloud / ownCloudvulnKEV agrega CVE-2026-53362 — Linux / KernelvulnKEV agrega CVE-2026-66384 — JFrog / ArtifactoryvulnKEV agrega CVE-2021-23758 — Ajax.NET Professional / Ajax.NET ProfessionalvulnKEV agrega CVE-2015-3246 — Red Hat / LibuservulnKEV agrega CVE-2015-5287 — Red Hat / Automatic Bug Reporting ToolvulnKEV agrega CVE-2022-0995 — Linux / KernelvulnKEV agrega CVE-2026-8452 — Citrix / NetScaler ADC and NetScaler GatewayvulnKEV agrega CVE-2019-1068 — Microsoft / SQL ServervulnKEV agrega CVE-2026-60004 — Gitea / GiteavulnKEV agrega CVE-2026-21962 — Oracle / HTTP Server and Oracle Weblogic Server Proxy Plug-invulnKEV agrega CVE-2026-73570 — Synacor / Zimbra Collaboration Suite (ZCS)vulnKEV agrega CVE-2026-72530 — TrueConf / ServervulnKEV agrega CVE-2026-72529 — TrueConf / ServervulnKEV agrega CVE-2023-49105 — ownCloud / ownCloudvulnKEV agrega CVE-2026-53362 — Linux / KernelvulnKEV agrega CVE-2026-66384 — JFrog / ArtifactoryvulnKEV agrega CVE-2021-23758 — Ajax.NET Professional / Ajax.NET ProfessionalvulnKEV agrega CVE-2015-3246 — Red Hat / LibuservulnKEV agrega CVE-2015-5287 — Red Hat / Automatic Bug Reporting ToolvulnKEV agrega CVE-2022-0995 — Linux / KernelvulnKEV agrega CVE-2026-8452 — Citrix / NetScaler ADC and NetScaler GatewayvulnKEV agrega CVE-2019-1068 — Microsoft / SQL ServervulnKEV agrega CVE-2026-60004 — Gitea / GiteavulnKEV agrega CVE-2026-21962 — Oracle / HTTP Server and Oracle Weblogic Server Proxy Plug-invulnKEV agrega CVE-2026-73570 — Synacor / Zimbra Collaboration Suite (ZCS)vulnKEV agrega CVE-2026-72530 — TrueConf / ServervulnKEV agrega CVE-2026-72529 — TrueConf / Server
Kalir Brief1,018 items in archive

Underground · what matters today

130items · 7d26%

The underground stories that broke through this window. Gov/mil, access sales, ransomware, leaks, stealers. Screenshots and context on each.

High+Critical106
New · 24H9
Dominant categoryLeak85 items

Distribution by category · window

  • Gov / Military
    5
  • Access sale
    8
  • Ransomware
    31
  • Leak
    85
  • Stealer
    0
  • Other
    1
Filters

Window

Category

Severity

Feed1–24 · 31
Ransomware
Ransomware
P62

Ransomware Wallstreet publica datos del municipio de Andover, Massachusetts

Town of Andover, Massachusetts (USA)

The Wallstreet ransomware group listed the Town of Andover, Massachusetts, a U.S. municipal government, as a victim. Municipal data, including citizen records and infrastructure details, may be exposed. Although outside Latin America, this fresh ransomware victim is relevant for tracking current ransomware activity.

Ransomware23h ago
Ransomware
Ransomware
P55

Ransomware Falcon publica a DistributionNOW (distribuidor de energía de EE. UU.)

DistributionNOW

Falcon ransomware claims 344 GB exfiltrated from energy distributor DistributionNOW, including financial records, SCADA gateway backups, and PLC logic. Loss of OT-related data indicates potential impact on industrial operations. This case is relevant to Latin American energy and critical infrastructure sectors as a warning of similar attack patterns.

Ransomware1d ago
Ransomware
Ransomware
P60

Ransomware Falcon publica a Globus Medical (fabricante de dispositivos médicos de EE. UU.)

Globus Medical

Falcon ransomware claims to have exfiltrated 2.96 TB from medical device maker Globus Medical, including customer records, FDA submissions, and product complaint logs. The incident exposes sensitive healthcare and regulatory data, raising supply-chain concerns. Even though the victim is in the US, this type of attack highlights TTPs relevant for Latin American healthcare and critical infrastructure defenders.

Ransomware1d ago
Ransomware
Ransomware
P70

Ransomware Qilin publica a la constructora qatarí Black Cat Engineering

Black Cat Engineering Construction Wll

Qilin ransomware has added Black Cat Engineering Construction Wll, a Qatari manufacturing/construction company, to its leak site. The publication may expose project documents and corporate data. This fresh ransomware incident highlights the group's ongoing activity in the Gulf region.

Ransomware1d ago
Ransomware
Ransomware
P70

Ransomware Qilin publica a la consultora británica Absolute Consultancy Services

Absolute Consultancy Services

Qilin ransomware has published Absolute Consultancy Services, a UK-based professional services firm. The leak may include client data and corporate documents. This is a fresh victim post, indicating active ransomware operations targeting the professional services sector.

Ransomware1d ago
Ransomware
Ransomware
P70

Ransomware Qilin publica a la farmacéutica Crystalpharmatech

Crystalpharmatech

The Qilin ransomware group has added Crystalpharmatech to its leak site. The company is in the healthcare sector, and the publication likely includes sensitive corporate and possibly patient-related data. This is a fresh ransomware incident that requires immediate attention.

Ransomware1d ago
Ransomware
Ransomware
P58

Filtración de 1 TB de datos técnicos de i-one (Corea del Sur)

i-one

The South Korean auto parts maker i-one was listed by the Black X ransomware group, which claims to have exfiltrated 1 TB of technical data, including drawings and supply chain information. The exposure of industrial intellectual property is critical for the company and its customers. Organizations should verify if this campaign affects their supply chain.

Ransomware1d ago
Ransomware
Ransomware
P65

Filtración de datos de millones de clientes de FE Credit (Vietnam)

FE Credit

FE Credit, a Vietnamese financial institution, was published by the Black X ransomware group, which claims to hold personal data of millions of customers. The exposure of a financial database at this scale could enable large-scale fraud and targeted phishing. This warrants monitoring and CERT coordination.

Ransomware1d ago
Ransomware
Ransomware
P72

Fábrica de Rodamientos FRM (Brasil) listada por ransomware zawoo

FRM - Fábrica de Rolamentos e Mancais Ltda

The Brazilian bearing manufacturer FRM was listed as a victim of the zawoo ransomware group, indicating a recent compromise and possible data theft. This is a fresh ransomware victim in Latin America, and industrial organizations in the region should check for exposure to this campaign.

Ransomware1d ago
Ransomware
Ransomware
P55

Ransomware Qilin publica a la empresa estadounidense Bandit Industries

Bandit Industries

Ransomware group Qilin published Bandit Industries, a US company, on its leak site. The entry is fresh on ransomware.live, indicating an active campaign. Although the victim is outside Latin America, it confirms Qilin's current operations and can inform defensive monitoring for similar attacks in the region.

Ransomware2d ago
Ransomware
Ransomware
P50

Ransomware Qilin publica a AUM Construction

AUM Construction

The Qilin ransomware group has published AUM Construction as a victim on its leak site. The company is a US-based manufacturing firm, and the breach may involve data theft and operational disruption. While not in Latin America, it signals Qilin's active targeting of manufacturing and should prompt defenders to assess similar exposure in the region.

Ransomware2d ago
Ransomware
Ransomware
P75

Ransomware Rhysida publica datos de Valley Health Team

Valley Health Team

The Rhysida ransomware group has published what it claims is Valley Health Team's data, including 9 million files (3.28 TB) with 160,870 patient records and 7.6 million unencrypted EHR scans, plus financial and tax documents. This is a confirmed healthcare data breach with sensitive medical and personal information exposed. Affected individuals face identity theft and privacy risks, and the organization needs immediate incident response.

Ransomware3d ago
Ransomware
Ransomware
P40

Nueva víctima de Silent Ransom Group (nombre pendiente de divulgación)

The Silent Ransom Group has published a redacted ransomware victim entry with the full data timer already active, indicating an imminent or fresh leak. The victim's name, country, and sector are still hidden, so the impact cannot be fully assessed. Monitor the group's leak site for the full disclosure and prepare incident response if the victim is identified as relevant.

Ransomware4d ago
Ransomware
Ransomware
P60

Ransomware iah6477 publica datos de Mat Holdings Inc

Mat Holdings Inc

The US manufacturing company Mat Holdings Inc has been listed on a ransomware data-leak site by the group iah6477, with 148.2 GiB of data claimed to be published. Although the victim is outside Latin America, this is a fresh ransomware incident that may indicate the group's current targeting. Monitoring the leaked data is advisable to identify any impact on business partners or supply chain.

Ransomware5d ago
Ransomware
Ransomware
P55

Ransomware Qilin publica a la financiera canadiense Northern Leasing Systems

Northern Leasing Systems

Qilin listed Northern Leasing Systems, a Canadian financial services company, on its leak site, signaling a confirmed ransomware incident. The financial sector impact raises the risk of sensitive customer data exposure. Immediate defensive review and communication with sectoral CERTs is recommended.

Ransomware5d ago
Ransomware
Ransomware
P50

Ransomware Qilin publica a la empresa estadounidense California Truck Equipment

California Truck Equipment

Qilin has added California Truck Equipment, a US transportation company, to its ransomware leak site. This confirms a recent compromise and likely data exfiltration. Transportation organizations should review their defenses and watch for similar ransomware activity.

Ransomware5d ago
Ransomware
Ransomware
P50

Ransomware Qilin publica a la empresa británica Metal Conversions

Metal Conversions

The Qilin ransomware group has listed Metal Conversions, a UK-based manufacturing company, on its leak site. The publication indicates the company was compromised and sensitive data may have been exfiltrated. Although not in Latin America, the victim should be monitored and relevant parties should be notified.

Ransomware5d ago
Ransomware
Ransomware
P66

Ransomware Aurora expone código fuente de ShipERP (ERPIS LLC)

ERPIS LLC (ShipERP)

Aurora ransomware claims to have breached ERPIS LLC (ShipERP), a Texas-based SAP integrator serving Boeing, Pfizer, NVIDIA, and other major enterprises. The leak allegedly includes full source code across all versions of ShipERP, the company's main revenue asset, plus potential customer data. This is a high-impact software supply-chain incident, though not in Latin America.

Ransomware5d ago
Ransomware
Ransomware
P42

Ransomware Qilin publica a WireCo (manufacturera de EE. UU.)

WireCo

WireCo, a US manufacturing company, has been posted by the Qilin ransomware group. The compromise likely includes exfiltration of corporate data and operational disruption. It is not in the Latin American region, reducing its priority for local defenders.

Ransomware5d ago
Ransomware
Ransomware
P68

Qilin ransomware publica a ATF, agencia del gobierno de EE. UU.

ATF

Qilin has listed ATF, categorized as US Government & Defense, on its ransomware leak site. If confirmed, this would be a significant breach of a federal entity, potentially involving sensitive government data. The impact is global due to the nature of the agency, though it does not directly target Latin America.

Ransomware5d ago
Ransomware
Ransomware
P45

Ransomware Qilin publica a Integrex RCM (EE. UU.)

Integrex RCM

Qilin ransomware listed Integrex RCM, a US professional services firm, on its leak site. The specific data exposed is not yet detailed, but confirmed ransomware victims indicate potential data theft and network compromise. Outside Latin America, so lower priority, but still a real incident to track.

Ransomware5d ago
Ransomware
Ransomware
P42

Ransomware OROVA publica al despacho contable taiwanés Bai-chi CPA

Bai-chi CPA Firm

The OROVA ransomware group has published Bai-chi CPA Firm, a registered Taiwanese accounting practice, on its leak site. The victim publication indicates a confirmed compromise and likely exposure of client financial data. While small and outside Latin America, it is a fresh ransomware victim relevant to third-party risk tracking.

Ransomware6d ago
Ransomware
Ransomware
P52

Ransomware OROVA publica a la farmacéutica taiwanesa Arich Enterprise

Arich Enterprise Co., Ltd.

Arich Enterprise, a Taiwanese pharmaceutical distributor serving medical centers and pharmacies, has been published by the OROVA ransomware group. This indicates a confirmed ransomware compromise with potential business and supply-chain data exposed. The incident merits monitoring because of the critical healthcare sector and the victim publication being recent.

Ransomware6d ago
Ransomware
Ransomware
P48

Ransomware OROVA publica a la empresa Central Florida Civil LLC

Central Florida Civil LLC

OROVA has listed Central Florida Civil LLC, a US underground utilities and site development company, on its ransomware victim site. This confirms a recent breach and likely exposure of company data. It is a smaller non-regional victim, but still requires tracking for data leaks and supply-chain impact.

Ransomware6d ago