Daily Briefing – Saturday, 22nd August 2026

🎧 Subscribe to the podcast feed

Ransomware Activity

69 victims Β· 20 groups Β· 48-hour window ending 22 Aug 2026

⚠️ = healthcare or critical infrastructure

TheGentlemen β€” 16 victims

VictimCountrySector
Ariel EnergiaITEnergy & Utilities
AquaseaNOEnergy & Utilities
Oceanica InternacionalWSTransportation
CAZ InvestmentsBZFinancial Services
ARBEITERKAMMERNATProfessional Services
ESCON GroupUSManufacturing
Akatake EngineeringJPManufacturing
Magdalena Grand Beach Golf ResortMXHospitality
LOG SystemsPLTechnology
dlp motiveDETechnology
UOLconsultBRProfessional Services
AlmeerAEOther
AWJ HoldingAEOther
Geb SasFROther
Lexacauchoβ€”Other
P**** R*****β€”Other

Direwolf β€” 13 victims

VictimCountrySector
Studeeβ€”Education
Deer Creek-Mackinaw CUSDUSEducation
Reviso Cloud Accounting LimitedDKFinancial Services
HP CarriersUSTransportation
Allstar IndustriesUSManufacturing
ProSim Aviation ResearchNLTechnology
Authenticate Information SystemsUSTechnology
Aztec SoftwareMXTechnology
iSON XPERIENCESMXHospitality
MCT Group of CompaniesAEOther
The Revel CollectiveUSOther
Diaco Globalβ€”Other
NorthStarCAOther

Qilin β€” 9 victims

VictimCountrySector
Quaker State MexicoMXEnergy & Utilities
Gindre IndiaINManufacturing
The Pendas Law FirmUSProfessional Services
CinΓ©polisMXHospitality
iPicUSHospitality
QuestronixPHTechnology
Trends And ConceptsZAOther
Blake ServicesUSOther
ProfessionalUSOther

Titan β€” 9 victims (Italy focus)

VictimCountrySector
⚠️ Alto Calore Servizi SPAITEnergy & Utilities (water)
Termotecnica Industriale S.r.l.ITManufacturing
Elbor S.p.A.ITManufacturing
CONDOR SPAITManufacturing
ELCON MEGARAD S.p.AITManufacturing
TECNOLOGICA S.r.l.ITTechnology
Tedesco & Partners STP srlITProfessional Services
POEMA S.r.l.ITOther
CTP S.r.l.ITOther

Rhysida β€” 2 victims

VictimCountrySector
⚠️ Fairview Dental GroupUSHealthcare
Battle Creek Public SchoolsUSEducation

iah6477 β€” 3 victims

VictimCountrySector
regencycentersUSRetail & E-Commerce
acimaUSFinancial Services
marvinβ€”Technology

Panzer β€” 2 victims

VictimCountrySector
NteitaliaITTechnology
Frisian Flag IndonesiaIDAgriculture & Food

Play β€” 2 victims

VictimCountrySector
Be MediaUSTechnology
LatoplastLVManufacturing

MajinaHanashi β€” 2 victims

VictimCountrySector
The Margo Hotel πŸ‡¬πŸ‡§GBHospitality
Grand Ion Delemen Hotelβ€”Hospitality

Single victims

GroupVictimCountrySector
Anubis⚠️ Interim HealthCareUSHealthcare
DeadlockJP Molyneux Studio πŸ‡¬πŸ‡§GBProfessional Services
LockBit5usbank.comUSFinancial Services
DragonForceHogan Omidi P.C.USProfessional Services
AkiraJC SalesUSRetail
EverestCCA Bankβ€”Financial Services
PayloadQualiflex DatacenterCHTechnology
EmperadorNetExamβ€”Technology
ShinyHuntersCyrus******β€”Technology
xpl0itrsGruppo Spaggiari ParmaITManufacturing
SilentRansomGroupD...β€”Unknown

Security News

Microsoft warns of max severity Entra ID flaw exploited in attacks (BleepingComputer)
Critical vulnerability in Microsoft's cloud identity platform actively exploited in the wild at time of disclosure β€” patch immediately if you run Microsoft cloud identity infrastructure.

Hundreds of leaked AWS keys give full control over corporate accounts (BleepingComputer)
Active AWS access keys found exposed in public repositories, each granting full admin access. If any AWS key has left your environment, rotate and audit now.

Cisco bug severity warning reads like Olympic gymnastics scores: 10, 10, 9.9, 9.6, and 7.5 (The Register)
Dense Cisco patch release β€” two CVEs rated 10, plus 9.9, 9.6, and 7.5. Review the full advisory if you have Cisco infrastructure in scope.

New SynkLoader malware pushed in Microsoft Teams phishing campaign (BleepingComputer)
Windows malware loader delivered via Teams external guest access phishing β€” a persistent blind spot that attackers continue to exploit.

New phishing toolkit uses passkeys to maintain access after password resets (SecurityWeek)
Attackers register attacker-controlled passkeys on compromised accounts, surviving password resets. Breaks the standard remediation playbook.

Critical isolated-vm vulnerability leads to RCE on host (SecurityWeek)
Sandbox escape in the popular Node.js isolated-vm library allows host-level code execution. Patch if it's in your stack.

Canada's Hospital for Sick Children attacked by cybercriminals again as employee data stolen (The Record)
Second ransomware attack on SickKids following last year's incident β€” employee and job applicant data stolen. Healthcare remains a primary target.

Rust supply chain attack linked to North Korean hackers (SecurityWeek)
The poisoned arrayref crate attack attributed to North Korean threat actors β€” a deliberate, state-sponsored developer credential operation, not opportunistic.

Encrypted prompts bypass AI safety guardrails in Grok and Gemini (SecurityWeek)
Prompt injection confirmed to bypass safety controls in multiple major AI platforms. The attack surface continues to expand.

Lawmakers call for investigation into impact of CISA staffing cuts (The Record)
US legislators formally request probe into whether CISA β€” the agency responsible for US civilian cyber defence β€” has been significantly degraded by personnel reductions.


UK & Critical National Infrastructure

No new NCSC advisories in the past 48 hours.

UK ransomware victims this cycle:

  • The Margo Hotel (Hospitality) β€” claimed by MajinaHanashi, publication pending
  • JP Molyneux Studio (London interior design) β€” claimed by Deadlock

Both are lower CNI criticality. The sharper UK angles are broader:

  • The Microsoft Entra ID exploitation affects any organisation on Microsoft cloud identity β€” covering the majority of UK public sector and enterprise.
  • Cisco's critical patch cluster applies equally to UK infrastructure operators.
  • TheGentlemen's European energy sector targeting (Italy, Norway, Austria) is worth flagging to UK OT defenders.
  • The Titan group's continuing focus on Italian utilities β€” including Alto Calore Servizi, a Campania water authority β€” is the most significant active CNI exposure in this cycle.

CISA Known Exploited Vulnerabilities

No new KEV entries added on 22 August 2026.

Show Comments