Daily Briefing — 21 August 2026

🎧 Subscribe to the podcast feed

Ransomware Activity

The past 48 hours produced north of 75 claimed victims across 25 distinct groups — one of the more active periods recently.

titan

At least 9 Italian firms claimed, spanning manufacturing, technology, professional services, and utilities. Notable: Alto Calore Servizi SPA — a public water utility serving municipalities in Avellino and Benevento, Campania. ⚠️ Critical infrastructure.

qilin

14 victims across multiple continents including Medochemie (CY — pharmaceutical manufacturer ⚠️ Healthcare), InVentry (GB — technology), Smart Energies (DE — energy), WIS LOGISTICS (US), Thrifty Building Supply (US), Estech (DE), Constructora Jimenez (MX), Movitecnica (PE), Semana (ES), Provite (NL), Questronix (PH), Trends and Concepts (ZA), Philippe Hottinguer Finance (FR), Integraduanas (UY).

everest

5 victims including Kingston Technology (US — major memory products manufacturer) and Capgemini Engineering (FR — global engineering services, 30+ countries). Also: CCA Bank, Experts Entreprendre (FR), Grupo DT (ES). Claims unverified — Everest has a history of fabrication.

DYSPHOR1A

6 victims including the Indonesian National Police Database — 52,000 officer records including passwords and facial photographs. ⚠️ Government. Also: University of Delhi (IN — Education), AYUDHYA TH Insurance / Allianz Thailand (⚠️ Financial), GUSTO College GLMS (TH), Job Net .COM.MM (MM), Strategy First International College (MM).

direwolf

4 victims: Lifesum (SE — health/nutrition app ⚠️ Healthcare), Photon Health (US ⚠️ Healthcare), PayUp (Financial software), InfoFlo CRM (US — Technology).

lockbit5

U.S. Bank (US) — the bank has clarified the breach relates to a fourth-party incident (a vendor's vendor), not a direct compromise. ⚠️ Financial Services. Story developing.

SilentRansomGroup

Troutman Pepper Locke (US — law firm) — second attack within a year; the first involved physical intrusion. Plus two additional redacted entries.

shinyhunters

Countdown posted for a target identified only as "Cyrus" — deadline end of day 24 August 2026.

Helix

Delek US (US — energy/refining). Countdown timer active. ⚠️ Energy sector.

akira

3 victims: Cascade Coffee (US), Deas Millwork (US), Ericksen Krentel (US — CPA/advisory, 30GB data including client PII).

incransom

BANGKOKCABLE (TH), Universal Plastics (US), CDGARVINLAW (US — legal), EXEL Systems (CA — HVAC/energy).

krybit

5 victims: sunsea.co.th (TH), Město Jilemnice (CZ — municipal government), automotoresrosedal.com.ar (AR), sipresitalia.it (IT), www.hsi.info (HK).

Deadlock

JP Molyneux Studio (GB — interior design), UFOC (TW — fibre optic/telecoms), Global Terminal Services (TR — liquid fuel storage, 470GB claimed ⚠️ Critical infrastructure).

thegentlemen

Babcock (ZA — engineering/defense ⚠️), Roadvision Systems, P**** R***** (US — redacted).

play

Be Media (US), Latoplast (LV — Manufacturing), Coltrane Systems (US).

xpl0itrs

Target (US — major retail ⚠️), Gruppo Spaggiari Parma (IT — school management software), Mihuru.

majinahanashi

The Margo Hotel (GB — 8,080 files scheduled for publication), Grand Ion Delemen Hotel.

coinbasecartel

Crowe (US — major public accounting/consulting firm), Advanced Engineering Consultants.

threeam

mecasem.org (MX — precision engineering/testing).

kairos

Ayuntamiento de Velilla de San Antonio (ES — municipal government, Madrid).

Other groups

payload: Qualiflex Datacenter (CH) — multiple Swiss firms affected. | Panzer: Frisian Flag Indonesia (ID — dairy/food). | insomnia: unnamed fluid systems company (US — aerospace/defense, redacted). | Orova: DL Holdings Group (HK — financial). | emperor: NetExam (US — LMS/education tech).


Security News

Microsoft patches exploited max-severity Entra ID vulnerability (SecurityWeek) — A maximum-severity flaw in Microsoft's cloud identity platform was actively exploited at the time of disclosure. Patch immediately. BleepingComputer coverage.

Cisco patches five critical/high vulnerabilities (10, 10, 9.9, 9.6, 7.5) (The Register) — Unusual spread of severity scores across today's Cisco advisories. Review your Cisco estate.

Hospital for Sick Children (SickKids) attacked again — employee data stolen (The Record) — Second cyberattack on the Toronto children's hospital; employee and job applicant data exposed. ⚠️ Healthcare. BleepingComputer.

New phishing toolkit persists via passkeys after password reset (SecurityWeek) — Novel post-compromise persistence technique: attackers register attacker-controlled passkeys, maintaining access even after the victim resets their password.

Hackers abuse FTP server banners to deliver Windows malware (BleepingComputer) — Malware delivered via FTP banner text at the protocol handshake level — an unusual and low-visibility initial access vector.

Rust crate supply chain attack attributed to North Korea (SecurityWeek) — The arrayref crate poisoning reported yesterday has been attributed to North Korean threat actors. The Register.

Critical isolated-vm vulnerability allows sandbox escape to host RCE (SecurityWeek) — The widely-used Node.js VM sandbox library has a critical flaw allowing host-level code execution. Patch immediately if using isolated-vm.

SynkLoader malware delivered via Microsoft Teams phishing (BleepingComputer) — New malware loader using Teams as an initial access vector, continuing a trend of attackers weaponising enterprise collaboration platforms.

Encrypted prompts bypass AI safety guardrails in Grok and Gemini (SecurityWeek) — Researchers demonstrate that encrypted or obfuscated prompt injections evade content safety filters in multiple major AI platforms.

Lawmakers call for investigation into CISA staffing cut impact (The Record) — US legislators formally request an inquiry into whether CISA budget and staffing cuts have degraded the agency's ability to protect federal infrastructure.

U.S. Bank: LockBit5 breach claim relates to fourth-party incident (The Record) — The bank clarifies it was not directly compromised; the data comes from a breach at a vendor of one of its vendors.

Russian actors abuse OAuth flows in targeted phishing campaign (The Register) — Three suspected Russian intelligence clusters targeting aerospace, defence, government, and think tanks across Europe and the US.


NCSC Guidance

Managing the cyber risk of agentic AI — Published 20 August 2026. The NCSC urges organisations deploying autonomous AI systems to use sandboxing, implement active oversight, and apply safeguards to limit unintended activity. Particularly relevant given this week's reports of state-sponsored actors integrating AI into post-compromise operations.


CISA Known Exploited Vulnerabilities — 20 August 2026

Two new entries added, both affecting TrueConf Server (video conferencing):

  • CVE-2026-72529 — Missing Authentication for Critical Function (CWE-306). Unauthenticated RCE via port 4307/TCP. ⚠️ Patch deadline: 23 August 2026 (federal agencies — 2 days). BleepingComputer | The Register.
  • CVE-2026-72530 — Code Injection (CWE-94). Escape from isolated environment, arbitrary code execution on host. Patch deadline: 3 September 2026.

Patches available from TrueConf. Advisories via Kaspersky ICS-CERT. Full catalogue at CISA KEV.

Show Comments