Ransomware Activity
The past 48 hours produced north of 75 claimed victims across 25 distinct groups — one of the more active periods recently.
titan
At least 9 Italian firms claimed, spanning manufacturing, technology, professional services, and utilities. Notable: Alto Calore Servizi SPA — a public water utility serving municipalities in Avellino and Benevento, Campania. ⚠️ Critical infrastructure.
qilin
14 victims across multiple continents including Medochemie (CY — pharmaceutical manufacturer ⚠️ Healthcare), InVentry (GB — technology), Smart Energies (DE — energy), WIS LOGISTICS (US), Thrifty Building Supply (US), Estech (DE), Constructora Jimenez (MX), Movitecnica (PE), Semana (ES), Provite (NL), Questronix (PH), Trends and Concepts (ZA), Philippe Hottinguer Finance (FR), Integraduanas (UY).
everest
5 victims including Kingston Technology (US — major memory products manufacturer) and Capgemini Engineering (FR — global engineering services, 30+ countries). Also: CCA Bank, Experts Entreprendre (FR), Grupo DT (ES).
DYSPHOR1A
6 victims including the Indonesian National Police Database — 52,000 officer records including passwords and facial photographs. ⚠️ Government. Also: University of Delhi (IN — Education), AYUDHYA TH Insurance / Allianz Thailand (⚠️ Financial), GUSTO College GLMS (TH), Job Net .COM.MM (MM), Strategy First International College (MM).
direwolf
4 victims: Lifesum (SE — health/nutrition app ⚠️ Healthcare), Photon Health (US ⚠️ Healthcare), PayUp (Financial software), InfoFlo CRM (US — Technology).
lockbit5
U.S. Bank (US) — one of the largest US financial institutions. Claim unverified; no data released. ⚠️ Financial Services.
SilentRansomGroup
Troutman Pepper Locke (US — law firm) — noted as the second attack within a year, with the first involving physical intrusion. Plus two additional redacted entries.
shinyhunters
Countdown posted for a target identified only as "Cyrus" — deadline end of day 24 August 2026. Final warning language suggests imminent leak if ransom not paid.
Helix
Delek US (US — energy/refining). Countdown timer active. ⚠️ Energy sector.
akira
3 victims: Cascade Coffee (US — contract coffee manufacturer), Deas Millwork (US — architectural millwork), Ericksen Krentel (US — CPA/advisory, 30GB data including client PII).
incransom
BANGKOKCABLE (TH — manufacturing), Universal Plastics / UNIPLASTICS.COM (US — manufacturing), CDGARVINLAW (US — legal), EXEL Systems (CA — HVAC/energy).
krybit
5 victims: sunsea.co.th (TH), Město Jilemnice (CZ — municipal government), automotoresrosedal.com.ar (AR), sipresitalia.it (IT — manufacturing), www.hsi.info (HK).
Deadlock
JP Molyneux Studio (GB — interior design), UFOC (TW — fibre optic/telecoms), Global Terminal Services (TR — liquid fuel storage, 470GB claimed ⚠️ Critical infrastructure).
thegentlemen
Babcock (ZA — engineering/defense/critical infrastructure ⚠️), Roadvision Systems (logistics software), P**** R***** (US — redacted event rental company).
play
Be Media (US — Technology), Latoplast (LV — Manufacturing), Coltrane Systems (US — Technology).
xpl0itrs
Target (US — major retail ⚠️), Gruppo Spaggiari Parma (IT — school management software), Mihuru (consumer travel financing).
majinahanashi
The Margo Hotel (GB — 8,080 files scheduled for publication ⚠️ UK), Grand Ion Delemen Hotel.
coinbasecartel
Crowe (US — major public accounting/consulting firm), Advanced Engineering Consultants.
threeam
mecasem.org (MX — precision engineering/testing).
kairos
Ayuntamiento de Velilla de San Antonio (ES — municipal government, Madrid).
Other groups
payload: Qualiflex Datacenter (CH) — multiple Swiss companies affected including HWZ, myenb.ch, schelling.ch. | Panzer: Frisian Flag Indonesia (ID — dairy/food). | insomnia: unnamed fluid systems company (US — aerospace/defense, redacted). | Orova: DL Holdings Group (HK — financial). | emperor: NetExam (US — LMS/education tech).
NCSC Guidance
Managing the cyber risk of agentic AI — Published 20 August 2026. The NCSC urges organisations deploying autonomous AI systems to use sandboxing, implement active oversight, and apply safeguards to limit unintended activity. Particularly relevant given this week's reports of state-sponsored actors integrating AI into post-compromise operations.
Security News
Note: The FreshRSS news feed remains unavailable due to a Cloudflare subdomain misconfiguration redirecting to a different service. The NCSC has migrated its RSS feeds to new URLs — those feeds are now back in service and have been updated in our sources.
CISA Known Exploited Vulnerabilities — 20 August 2026
Two new entries added, both affecting TrueConf Server (video conferencing):
- CVE-2026-72529 — TrueConf Server Missing Authentication for Critical Function (CWE-306). Allows unauthenticated remote code execution via port 4307/TCP. ⚠️ Patch deadline: 23 August 2026 (federal agencies — 2 days).
- CVE-2026-72530 — TrueConf Server Code Injection (CWE-94). Allows escape from isolated environment and arbitrary code execution on the host. Patch deadline: 3 September 2026.
Patches available from TrueConf. Advisories via Kaspersky ICS-CERT. Full catalogue at CISA KEV.