Ransomware Activity
66 victims across 22 groups in the past 48 hours.
krybit — 14 victims
⚠️ seashellhospital.com (IN, Healthcare)
BrainCipher — 8 victims
⚠️ ccsperfusion.com (US, Healthcare)
lockbit5 — 6 victims
thegentlemen — 5 victims
⚠️ Nutex Health (US, Healthcare) | The Sole (UK, Retail)
play — 4 victims | incransom — 4 victims
lichtvision.com (UK, Technology)
direwolf — 3 | qilin — 3 | everest — 3 | akira — 3
Wallstreet — 2 victims
⚠️ Cedar County Memorial Hospital (US, Healthcare)
fulcrumsec — 1 victim
Manchester Airports Group (UK, Transportation)
Other groups (1 victim each)
SilentRansomGroup, rhysida, bravox, ransomhouse, medusalocker, majinahanashi, Global Secret Group, interlock, Falcon, crypto24
UK victims: Manchester Airports Group (fulcrumsec), The Sole (thegentlemen), lichtvision.com (incransom)
⚠️ Healthcare victims: seashellhospital.com IN (krybit), ccsperfusion.com US (BrainCipher), Nutex Health US (thegentlemen), Cedar County Memorial Hospital US (Wallstreet)
Security News
SonicWall warns of two SMA1000 zero-days exploited in attacks (SecurityWeek)
CVE-2026-83549 and CVE-2026-83548 are chainable for unauthenticated RCE on SMA 1000 appliances. Actively exploited — patch immediately.
JFrog Artifactory CVE-2026-82329 — critical auth bypass under active exploitation (The Register)
Unauthenticated attackers can gain admin-level access. Widely used in software supply chains — high blast radius.
Old unpatched flaws let attackers breach Philippines nuclear agency (Dark Reading)
Attackers exploited unpatched ownCloud vulnerabilities to steal reactor databases and personnel records.
Law enforcement disrupts 23-year-old Sality botnet (The Register)
CrowdStrike and Shadowserver joined police to poison the P2P network and sinkhole traffic, dismantling one of the longest-running botnets in existence.
Critical Langflow flaw CVE-2026-0768 exploited, AI platform attacks rise (Dark Reading)
Active exploitation of the AI development platform underscores growing attacker interest in AI infrastructure.
Attacker stole METR API key, used $600K in credits undetected for weeks (The Register)
AI safety org METR disclosed an API key theft that went unnoticed while the attacker consumed hundreds of thousands in compute credits.
Microsoft tracks counterfeit installer campaign leading to system compromise (Microsoft Security Blog)
Deceptive software downloads used as initial access vector for full system compromise.
Phishing actors abuse Faronics Deploy to install ScreenConnect (BleepingComputer)
Attackers leverage legitimate endpoint management tool to silently deploy remote access software.
Stronger security drives ransomware groups to recruit insiders (Dark Reading)
As defences improve, ransomware groups are shifting toward insider recruitment for initial access.
Aesto Health data breach affects over 9.5 million patients (BleepingComputer)
One of the largest healthcare breaches of the year, disclosed amid broader ransomware pressure on the health sector.
NCSC
No new alerts today. The most recent advisory — Disruptive cyber activity highlights risk from internet-exposed systems and edge devices (27 Aug 2026) — urges OT operators to address avoidable vulnerabilities. Given this week's ransomware activity against aviation and healthcare infrastructure, the guidance remains highly relevant.