Briefing — 20 August 2026

🎧 Subscribe to the podcast feed

Security News

NSA/FBI/CISA: AI-generated code used to attack Siemens PLCs (The Register) — Attackers using AI-written scripts to compromise internet-exposed Siemens S7 programmable logic controllers at water, energy, and manufacturing facilities. The advisory explicitly states this is "not a theoretical risk."

CareCloud breach: 3.7 million patients affected (BleepingComputer) — Eight-hour intrusion at US healthcare IT firm exposed patient records from millions of individuals.

Medusa ransomware: 500+ critical infrastructure victims since 2021 (CISA) — Updated advisory; healthcare, education, and government the primary targets. Up from 300 victims reported last year.

Sakura Internet breach: 1.36 million accounts exposed (BleepingComputer) — Japanese cloud and data centre provider's sales system compromised; customer contract and membership data stolen.

Kriminal: no-filter AI platform for cybercrime (Dark Reading) — Officially forbids illicit use while providing guardrail-free social engineering, offensive tools, and OSINT for cryptocurrency.

CameraSwarm: 14,500 Dahua cameras compromised in 35 days (BleepingComputer) — Mass IoT compromise campaign targeting cameras in Ukraine and Russia; likely botnet infrastructure expansion.

Rogue ransomware affiliate poses as recovery firm (BleepingComputer) — "Ransom Busters" contacts victims before public disclosure, posing as a recovery service to steal ransom payments.

GigaWiper: destructive backdoor assembled from multiple malware families (Microsoft) — Modular design combining existing components; harder to attribute and easier to repurpose.

SilkParasite (FamousSparrow-linked) targeting Central Asian orgs (Dark Reading) — Chinese-nexus APT running spear-phishing campaign deploying multiple remote access trojans.

17 Iranian hackers charged over $3.4B IP theft (BleepingComputer) — Mabna Institute members indicted for long-running theft from US universities and companies.

Password spraying surges 155x in H1 2026 (BleepingComputer) — One campaign: 81 million login attempts in two weeks. Legacy authentication without MFA is the primary gap being exploited.

UK & Critical National Infrastructure

No new NCSC advisories in the past 48 hours.

The NSA/FBI/CISA joint advisory on AI-generated attacks against Siemens S7 PLCs is directly relevant to UK defenders. Siemens S7 Series controllers are widely deployed across UK water, energy, and manufacturing sectors. Internet-exposed OT devices should be audited and access eliminated where not operationally required.

Two UK ransomware victims this cycle: InVentry (Qilin, Technology sector) and CRASL (TheGentlemen, sector unconfirmed). TheGentlemen also claimed Babcock in South Africa — a government and defence contractor — in the same window.

The password spraying surge is particularly relevant to UK public sector and enterprise environments where legacy authentication protocols remain in use. SMTP and IMAP auth, older VPN gateways, and ActiveSync endpoints are primary targets.

Ransomware Victims — 48 Hours

46 victims · 18 groups

GroupVictimCountrySector
AkiraEricksen KrentelProfessional Services
CoinbaseCartelCrowe🇺🇸Professional Services
CoinbaseCartelAdvanced Engineering ConsultantsProfessional Services
DeadlockGlobal Terminal Services🇹🇷Transportation
DeadlockUFOC🇹🇼
Direwolf⚠️ Lifesum🇸🇪Healthcare
Direwolf⚠️ Photon Health, Inc.🇺🇸Healthcare
DirewolfInfoFlo CRM🇺🇸Technology
DirewolfPayUpFinancial Services
DragonForceR & D Machine and Engineering🇺🇸Manufacturing
EmperadorPrefeitura Municipal de Arcos🇧🇷Government & Defence
GunraBOMOHSA🇭🇳
Helix⚠️ Delek US🇺🇸Energy & Utilities
IncransomBANGKOKCABLE🇹🇭Manufacturing
IncransomCDGARVINLAW🇺🇸Professional Services
IncransomEXEL🇨🇦Technology
Incransomnyklawfirm.com🇦🇪Professional Services
Incransomssf-int.com🇩🇪Professional Services
IncransomUNIPLASTICS.COM🇺🇸Manufacturing
InsomniaRedacted🇺🇸
Krybitautomotoresrosedal.com.ar🇦🇷Retail & E-Commerce
Krybitsipresitalia.it🇮🇹Manufacturing
Krybitsunsea.co.th🇹🇭
Krybitwww.hsi.info🇭🇰
Krybitwww.mestojilemnice.cz🇨🇿
OrovaDL HOLDINGS GROUP🇭🇰
PlayColtrane Systems🇺🇸Technology
QilinBerlin Brandenburgische Wohnungsbaugenossenschaft🇩🇪
QilinConstructora Jimenez🇲🇽Manufacturing
QilinEstech🇩🇪Technology
QilinIntegraduanas🇺🇾
Qilin⚠️ InVentry 🇬🇧🇬🇧Technology
Qilin⚠️ Medochemie🇨🇾Healthcare
QilinMovitecnica🇵🇪Manufacturing
QilinPhilippe Hottinguer Finance🇫🇷Financial Services
Qilin⚠️ Smart Energies🇩🇪Energy & Utilities
QilinThrifty Building Supply🇺🇸Retail & E-Commerce
QilinWIS LOGISTICS🇺🇸Transportation
SilentRansomGroupT... P... L... (redacted)
SilentRansomGroupTroutman Pepper Locke🇺🇸Professional Services
TheGentlemenBabcock🇿🇦Government & Defence
TheGentlemenCRASL 🇬🇧🇬🇧
TheGentlemenRoadvision Systems🇸🇪Transportation
TheGentlemenSenvest Capital🇨🇦Financial Services
ThreeAmmecasem.org🇲🇽
xpl0itrsMihuru
Show Comments