Cybersecurity radar on
Point-in-time cybersecurity signals across Latin America detected on X (Twitter): breaches, CVEs, ransomware, regulation, fraud, phishing, and APT activity. Updated every 4 hours.
Activity by country
Tap a country to filter the feed
Latest signals
Live- Latin AmericaCVE8hMicrosoft Entra ID CVE-2026-69836 CVSS 10.0 mitigated with no customer action
Unsafe deserialization flaw in Entra ID exploited in the wild; Microsoft fully mitigated it server-side.
- ParaguayBreach8hPampaLeaks integrates Paraguay Civil Registry and Health data into Samaritan API
Over 6.9M Civil Registry and 2.4M Health records exposed via new endpoints on DaaS platform.
- Latin AmericaCVE9hCISA adds CVE-2026-68820 afd.sys zero-day to KEV with Aug 25 deadline
Use-After-Free in Windows afd.sys with confirmed exploitation for privilege escalation.
Sources:@iss_kk_official - Latin AmericaCVE13hCisco patches nine CVEs in Crosswork and Secure Workload, five with CVSS 10.0
Includes SQL injection, improper access control and authentication bypass. No workarounds; upgrade to fixed releases recommended.
- PeruRansomware14hKillSec claims ransomware attack on Global Go in Peru
Transportation company listed on threat actor leak site; possible system encryption.
- Latin AmericaBreach16hMulti-country preventive alert for alleged database leaks in Ecuador, Mexico, Colombia and Argentina
VECERT post details 24 unconfirmed alerts of webshells, VPN access and alleged databases in several Latam countries and others.
Sources:@VECERTRadar - ChileRansomware16hQilin ransomware claims attack on Difor Chile
Ransomware group publishes Difor Chile S.A. as victim, major automotive dealer.
- ArgentinaRansomware20hRansomware hits Instituto Ferrero de Neurología y Sueño in Argentina
Disruption to medical and administrative systems; impacts care for neurological and sleep disorders.
- BrazilRansomware21hKazu ransomware hits Mobilemed, PACS provider in Brazil
Attack confirmed on August 23 2026 on medical imaging platform.
- Latin AmericaCVE1dChina-nexus actor exploits VMware vCenter flaw and deploys Babuk-derived ransomware
CVSS 9.8 already exploited in the wild. Apply Broadcom late-July patch if vCenter is not yet updated.
Sources:@Wojzechowski - United StatesRansomware1dCoinbasecartel claims ransomware attack on Integrated Health Systems in the US
- United StatesRansomware1dFBI Chicago warns on Gunra ransomware operating as criminal service in USA
Attackers infiltrate networks to steal and encrypt information, then use it for extortion.
Sources:@hacklatino2025 - ArgentinaBreach1dpensamientodigital.com.ar database leak in Argentina
Threat actor offering dump with emails, support tickets and website activity logs from the site.
- Latin AmericaRansomware1dShinyhunters observes new ransomware victim BOK Financial in the USSources:@sec_news_com
- United StatesRansomware1dHelix claims ransomware victim AmSpec in US energy sectorSources:@ThreatAtlas
- ArgentinaBreach1dArgentina dismantles iris-scan money laundering ring moving $27 billion
Judicial operation in Buenos Aires and Córdoba seizes biometric data from vulnerable individuals to create fake identities and channel funds from illegal gambling.
Sources:@ElPortavozARG - ChileBreach1dFONASA Chile database leak advertised in forums
Threat actor gethacked offers dataset of 732,000 records including customer, claims and support ticket data.
Sources:@CyberPulse56 - Latin AmericaBreach1dApollo Global Management confirms data breach exposing sensitive PII
Exposure of full names, home addresses, birth dates, and Social Security numbers of clients.
Sources:@TraffAlex - MexicoCVE1dFortiBleed remains active on Mexican government firewalls, new attacker IPs published by CISA
Post warns about unpatched Fortinet firewalls in Mexico and ongoing exploit activity.
Sources:@Spaceprogrammer - Latin AmericaBreach1d300,000 Chihuahua Health Ministry medical records for sale
Patient data on criminal forums.
Sources:@Spaceprogrammer - ArgentinaBreach1dCoinbaseCartel posts possible Flecha Bus Argentina data leak
Group claims leak on dark web site on August 22, 2026.
- ArgentinaRansomware1dCoinbasecartel claims ransomware attack on Flecha Bus in ArgentinaSources:@ThreatAtlas
- BrazilRansomware1dLockbit5 claims ransomware attack on icnavais.com in Brazil
Brazilian shipbuilding company listed on the group's leak site.
- MexicoRansomware2dQilin ransomware targets Quaker State Mexico
Ransomware activity reported with Qilin hitting Quaker State in Mexico.
- MexicoBreach2dAlert over data leak from Internet para el Bienestar in Mexico
Reported leak of information related to the government initiative for low-cost telephony and internet.
Sources:@victor_ruiz - BrazilRegulation2dANPD opens two oversight processes on 22 digital services including social media and AI
Companies will have 10 business days to respond regarding deepfakes and virtual crimes.
- Latin AmericaRansomware2dQilin ransomware hits The Pendas Law Firm in the USSources:@TweetThreatNews
- BoliviaRegulation2dBolivia advances national cybersecurity agenda via ENTEL project #BoliviaCibersegura2026
ENTEL manager highlights cybersecurity as a country-wide agenda built on cooperation and complementarity.
Sources:@Urgentebo - Latin AmericaCVE2dCitrix patches CVE-2026-19490 CVSS 9.3 auth-bypass in NetScaler
Vulnerability in SSL VPN / ICA Proxy; update to 14.1-73.32 or 13.1-63.21.
Sources:@OpenVPN - MexicoBreach2dCredentials leaked from Altamira municipal government, Mexico
Administrative access and travel database allegedly leaked on cybercrime forum from government server.
Sources:@DarkWebInformer - Latin AmericaBreach2dMunicipal Government of Altamira, Tamaulipas, allegedly breached with access leakSources:@DarkWebInformer
- Latin AmericaRansomware2dLockBit claims US Bank breach and sets leak deadline
LockBit threatens to leak stolen data on September 3; bank investigates but has not confirmed unauthorized access.
- Latin AmericaCVE2dCISA adds four actively exploited CVEs to KEV catalog
Includes CVE-2026-59310 (VMware vCenter), CVE-2026-33824 (Windows IKE), CVE-2026-55040 (SharePoint) and CVE-2026-65400 (macOS). Federal agency patch deadline: August 21.
- MexicoRansomware2dCinépolis listed as Qilin ransomware victim in Mexico
Ransomware attack reported on August 21, 2026, without official company confirmation.
- BoliviaBreach2dUnverified claim of 160k records leak at Inocuidad Santa Cruz, Bolivia
Dump attributed to konata_izumi_shell with ID photos and hepatitis/TB/STI screens. Government not confirmed. Ignore WhatsApp renewal links.
Sources:@BreachHistoryBH