🎧 Subscribe to the podcast feed
Ransomware Activity
The past 48 hours produced north of 75 claimed victims across 25 distinct groups — one of the more active periods recently.
titan
At least 9 Italian firms claimed, spanning manufacturing, technology, professional services, and utilities. Notable: Alto Calore Servizi SPA — a public water utility serving municipalities in Avellino and Benevento, Campania. ⚠️ Critical infrastructure.
qilin
14 victims across multiple continents including Medochemie (CY — pharmaceutical manufacturer ⚠️ Healthcare), InVentry (GB — technology), Smart Energies (DE — energy), WIS LOGISTICS (US), Thrifty Building Supply (US), Estech (DE), Constructora Jimenez (MX), Movitecnica (PE), Semana (ES), Provite (NL), Questronix (PH), Trends and Concepts (ZA), Philippe Hottinguer Finance (FR), Integraduanas (UY).
everest
5 victims including Kingston Technology (US — major memory products manufacturer) and Capgemini Engineering (FR — global engineering services, 30+ countries). Also: CCA Bank, Experts Entreprendre (FR), Grupo DT (ES). Claims unverified — Everest has a history of fabrication.
DYSPHOR1A
6 victims including the Indonesian National Police Database — 52,000 officer records including passwords and facial photographs. ⚠️ Government. Also: University of Delhi (IN — Education), AYUDHYA TH Insurance / Allianz Thailand (⚠️ Financial), GUSTO College GLMS (TH), Job Net .COM.MM (MM), Strategy First International College (MM).
direwolf
4 victims: Lifesum (SE — health/nutrition app ⚠️ Healthcare), Photon Health (US ⚠️ Healthcare), PayUp (Financial software), InfoFlo CRM (US — Technology).
lockbit5
U.S. Bank (US) — the bank has clarified the breach relates to a fourth-party incident (a vendor's vendor), not a direct compromise. ⚠️ Financial Services. Story developing.
SilentRansomGroup
Troutman Pepper Locke (US — law firm) — second attack within a year; the first involved physical intrusion. Plus two additional redacted entries.
shinyhunters
Countdown posted for a target identified only as "Cyrus" — deadline end of day 24 August 2026.
Helix
Delek US (US — energy/refining). Countdown timer active. ⚠️ Energy sector.
akira
3 victims: Cascade Coffee (US), Deas Millwork (US), Ericksen Krentel (US — CPA/advisory, 30GB data including client PII).
incransom
BANGKOKCABLE (TH), Universal Plastics (US), CDGARVINLAW (US — legal), EXEL Systems (CA — HVAC/energy).
krybit
5 victims: sunsea.co.th (TH), Město Jilemnice (CZ — municipal government), automotoresrosedal.com.ar (AR), sipresitalia.it (IT), www.hsi.info (HK).
Deadlock
JP Molyneux Studio (GB — interior design), UFOC (TW — fibre optic/telecoms), Global Terminal Services (TR — liquid fuel storage, 470GB claimed ⚠️ Critical infrastructure).
thegentlemen
Babcock (ZA — engineering/defense ⚠️), Roadvision Systems, P**** R***** (US — redacted).
play
Be Media (US), Latoplast (LV — Manufacturing), Coltrane Systems (US).
xpl0itrs
Target (US — major retail ⚠️), Gruppo Spaggiari Parma (IT — school management software), Mihuru.
majinahanashi
The Margo Hotel (GB — 8,080 files scheduled for publication), Grand Ion Delemen Hotel.
coinbasecartel
Crowe (US — major public accounting/consulting firm), Advanced Engineering Consultants.
threeam
mecasem.org (MX — precision engineering/testing).
kairos
Ayuntamiento de Velilla de San Antonio (ES — municipal government, Madrid).
Other groups
payload: Qualiflex Datacenter (CH) — multiple Swiss firms affected. | Panzer: Frisian Flag Indonesia (ID — dairy/food). | insomnia: unnamed fluid systems company (US — aerospace/defense, redacted). | Orova: DL Holdings Group (HK — financial). | emperor: NetExam (US — LMS/education tech).
Security News
Microsoft patches exploited max-severity Entra ID vulnerability (SecurityWeek) — A maximum-severity flaw in Microsoft's cloud identity platform was actively exploited at the time of disclosure. Patch immediately. BleepingComputer coverage.
Cisco patches five critical/high vulnerabilities (10, 10, 9.9, 9.6, 7.5) (The Register) — Unusual spread of severity scores across today's Cisco advisories. Review your Cisco estate.
Hospital for Sick Children (SickKids) attacked again — employee data stolen (The Record) — Second cyberattack on the Toronto children's hospital; employee and job applicant data exposed. ⚠️ Healthcare. BleepingComputer.
New phishing toolkit persists via passkeys after password reset (SecurityWeek) — Novel post-compromise persistence technique: attackers register attacker-controlled passkeys, maintaining access even after the victim resets their password.
Hackers abuse FTP server banners to deliver Windows malware (BleepingComputer) — Malware delivered via FTP banner text at the protocol handshake level — an unusual and low-visibility initial access vector.
Rust crate supply chain attack attributed to North Korea (SecurityWeek) — The arrayref crate poisoning reported yesterday has been attributed to North Korean threat actors. The Register.
Critical isolated-vm vulnerability allows sandbox escape to host RCE (SecurityWeek) — The widely-used Node.js VM sandbox library has a critical flaw allowing host-level code execution. Patch immediately if using isolated-vm.
SynkLoader malware delivered via Microsoft Teams phishing (BleepingComputer) — New malware loader using Teams as an initial access vector, continuing a trend of attackers weaponising enterprise collaboration platforms.
Encrypted prompts bypass AI safety guardrails in Grok and Gemini (SecurityWeek) — Researchers demonstrate that encrypted or obfuscated prompt injections evade content safety filters in multiple major AI platforms.
Lawmakers call for investigation into CISA staffing cut impact (The Record) — US legislators formally request an inquiry into whether CISA budget and staffing cuts have degraded the agency's ability to protect federal infrastructure.
U.S. Bank: LockBit5 breach claim relates to fourth-party incident (The Record) — The bank clarifies it was not directly compromised; the data comes from a breach at a vendor of one of its vendors.
Russian actors abuse OAuth flows in targeted phishing campaign (The Register) — Three suspected Russian intelligence clusters targeting aerospace, defence, government, and think tanks across Europe and the US.
NCSC Guidance
Managing the cyber risk of agentic AI — Published 20 August 2026. The NCSC urges organisations deploying autonomous AI systems to use sandboxing, implement active oversight, and apply safeguards to limit unintended activity. Particularly relevant given this week's reports of state-sponsored actors integrating AI into post-compromise operations.
CISA Known Exploited Vulnerabilities — 20 August 2026
Two new entries added, both affecting TrueConf Server (video conferencing):
- CVE-2026-72529 — Missing Authentication for Critical Function (CWE-306). Unauthenticated RCE via port 4307/TCP. ⚠️ Patch deadline: 23 August 2026 (federal agencies — 2 days). BleepingComputer | The Register.
- CVE-2026-72530 — Code Injection (CWE-94). Escape from isolated environment, arbitrary code execution on host. Patch deadline: 3 September 2026.
Patches available from TrueConf. Advisories via Kaspersky ICS-CERT. Full catalogue at CISA KEV.