Ransomware Activity — 48 Hours
38 victims · 19 groups — Direwolf emerges with 2 US healthcare hits; Qilin leads on volume with 8 victims including a surveillance-tech contractor.
By Group
Qilin — 8 victims
Connections 🇧🇪 (Technology) · Radiant 🇸🇬 (Technology) · Lercher Werkzeugbau 🇦🇹 (Manufacturing) · 3F 🇩🇰 (Industry) · ⚠️ PenLink 🇺🇸 (Government & Defence) · Urban Worldwide 🇳🇱 (Logistics) · Ferrari Mangimi 🇮🇹 (Agriculture) · Aletex Group 🇪🇸 (Manufacturing)
Direwolf — 6 victims (new group)
DXS International 🇬🇧 (Technology) · ⚠️ PayrHealth 🇺🇸 (Healthcare) · ⚠️ Colla Health 🇺🇸 (Healthcare) · TOTVS 🇧🇷 (Technology) · AAM:HOA Management 🇺🇸 (Services) · DodoPayments 🇮🇳 (Fintech)
xpl0itrs — 3 victims
Oz Hair & Beauty 🇦🇺 (Retail) · [redacted] · RapidFort 🇺🇸 (Technology)
CoinbaseCartel — 3 victims
Turner and Townsend 🇬🇧 (Professional Services) · Sweet Water Holdings 🇺🇸 (Real Estate) · Serruya Private Equity 🇺🇸 (Finance)
Akira — 2 victims
Keystops 🇺🇸 (Retail) · Cozad Asset Management 🇺🇸 (Finance)
Storm — 2 victims
Hinman Straub 🇺🇸 (Legal) · 3-Point Australia 🇦🇺 (Construction)
Blackwater — 2 victims
shalina.com 🇮🇳 (Healthcare) · amca.org.ar 🇦🇷 (Services)
Single-victim groups: SpaceBears (Sears 🇲🇽), ⚠️ Anubis (Interim HealthCare 🇺🇸 — Healthcare), Panzer (Alpine Electronics 🇩🇪), ⚠️ Global Secret Group (Columbia University Dental 🇺🇸 — Healthcare), Interlock, Rhysida (Pierce Township 🇺🇸), Clop (ZEBRA.COM 🇺🇸), Barracuda, Securotrop, Safepay, MS13089, M3RX
Healthcare victims: 4 — PayrHealth, Colla Health, Interim HealthCare, Columbia University Dental
Security News
⚠️ macOS Screen Sharing flaw under active exploitation (Ars Technica) — Apple has patched the vulnerability; threat actors are actively exploiting unpatched systems. Update now.
New Evooo1Bot Linux botnet turns routers into SOCKS5 relay nodes (BleepingComputer) — Mirai-based botnet compromising Linux routers to build an anonymising proxy network; update firmware and change default credentials.
CISA KEV — No New Additions
No new vulnerabilities added to the Known Exploited Vulnerabilities catalogue today. Last entries were 11 August 2026: CVE-2026-68820 (Windows kernel — Lazarus), CVE-2026-20349 (Cisco ASA), CVE-2026-72898 (Metabase RCE).