Briefing — 14 August 2026

🎧 Subscribe to the podcast feed | Download episode

Ransomware Victims (48h)

GroupVictimCountrySector
clop⚠️ Starkey.comUSHealthcare
clop⚠️ Philips.comNLHealthcare
clopShell.comGBEnergy & Utilities
clopFiserv.comUSFinancial Services
clopGE.comUSTechnology
clopAldoGroup.comCARetail
clopMammut.comCHRetail
clopSuunto.cnFIRetail
clopMamasAndPapas.comGBRetail
clopClover.comUSRetail
clopThermos.comUSRetail
clopG3Aerospace.comUSGovernment & Defense
clopToastTab.comUSHospitality
clopIntellihot.comUSHospitality
clopJPMGroup.co.inINFinancial Services
clopOmniTanker.comUSTransportation
clopLifeStraw.comUSRetail
clopAtomberg.comINManufacturing
clopMidlandInd.com.auAUManufacturing
clopLarGan.com.twTWManufacturing
clopHongHe-Tech.comCNTechnology
clop9Altitudes.comINTechnology
clopFluidLogic.comUSTechnology
clopQCPL.inINManufacturing
clopSMAPCENTER.UAH.EDUUSEducation
clopPartech.comUSTechnology
clopNetPower.comTechnology
clopNUVITIA.COMFRTechnology
clopIPMSOLUTIONS.SKSKProfessional Services
clopECCELLENT.COMITOther
clopSTNET.ITITTechnology
clopITKHOLDING.HUHUTechnology
clopARCHERGREY.COMUSOther
clopSPKAA.COMKZOther
clopIVALUESYS.COMUSTechnology
clopNUOVACMM.COMITOther
clopWATERLANDPE.COMPEOther
clopINTELLIGENTGROWTHSOLUTIONS.COMUSProfessional Services
clopBRILLONCONSUMER.COMMXRetail
clopTRISTAR.COMUSOther
clopCORNELIUS.COMUSOther
clopIRCO.COMIROther
incransom⚠️ DiabetesAndMetabolism.comUSHealthcare
incransomPacific-Construction.comGBManufacturing
incransomCambriaLawFirm.comCAProfessional Services
incransomBEDC.com.auAUEnergy & Utilities
incransomStuartAndAssociates.comUSProfessional Services
incransomGamaus.comUSTechnology
incransomCLGroupUSProfessional Services
SilentRansomGroupReminger AttorneysDEProfessional Services
SilentRansomGroupRiker Danzig LLPUSProfessional Services
SilentRansomGroupRiker Danzig SchererProfessional Services
SilentRansomGroup[redacted]Unknown
SilentRansomGroup[redacted]Unknown
blacknevas⚠️ Enteroptyx OphthalmologyUSHealthcare
blacknevasWestbrook GreenhouseUSAgriculture
blacknevasJack Rutherford CustomsCAProfessional Services
blacknevasPortable Intelligence IncUSTechnology
blacknevasComputer Country & NetworksTechnology
majinahanashi⚠️ UAB BiotechaLTHealthcare
majinahanashiAltairUSTechnology
majinahanashiCalicheCLEnergy
majinahanashiCamandona SACHOther
majinahanashiEticodOther
qilinD & J Beverage ServiceUSHospitality
qilinUnited Association Local 345USOther
qilinWantedNLOther
krybit⚠️ LabIndia.comINHealthcare
krybithisstw.comTWOther
krybitlhyk.com.sgSGOther
AiLockDAISENJPTechnology
AiLockYaomasaJPOther
rhysida⚠️ SIA Medical CentreAUHealthcare
coinbasecartelHitachi High-TechJPManufacturing
akiraCF SupplyRetail
thegentlemenSafewareUSTechnology
kairosHightech SignsUSManufacturing
dragonforceGB Group S.APLFinancial Services
payloadZara Investment HoldingJOFinancial Services

Security News

Global Threat Campaign Hits Critical VMware vCenter Flaw (Dark Reading) — CVE-2026-59310 actively exploited globally; patching alone may not fully mitigate.

Apple Sends New 'Threat Notification' Alerts Over Mercenary Spyware Attacks (BleepingComputer) — High-confidence detections; recipients should contact security professionals.

Akira Hackers Disable EDR With Safe Mode, Steal Data but Fail to Encrypt (BleepingComputer) — Safe Mode with Networking used to bypass endpoint defences; exfiltration succeeded.

Borrowing Windows Hello Keys for Authentication and Persistence (dirkjanm.io) — Novel credential theft technique for post-compromise persistence.

Identity Crisis: Kerberos Vulnerabilities — Downgrade, DoS, Domain Takeover (Semperis) — Critical AD attack chains; full domain compromise possible.

New Zealand Says China Tried Using Space Investments to Spy on Local Affairs (The Register) — NZSIS disrupted Chinese GBSI installation targeting military intelligence.

OpenAI Launches 'Computer History' — Keylogging for ChatGPT Pro (The Register) — Opt-in event capture; unencrypted local storage; increased prompt injection risk.

Ukraine Shuts Down 94 Fraudulent Call Centers, Seizes Millions (BleepingComputer) — Large-scale takedown of investment fraud operations.

CISA KEV

No new additions on 13–14 August. Most recent (11 August): CVE-2026-68820 (Windows CLFS, Lazarus), CVE-2026-20349 (Cisco ASA/FTD), CVE-2026-72898 (Metabase). Full catalog →

Show Comments