π§ Subscribe to the podcast feed
Security News
Hackers infect Android car head units with proxy botnet malware (BleepingComputer)
Supply-chain attack on legitimate device-update apps silently enlists compromised in-vehicle Android systems into a proxy botnet β no visible symptoms to the owner. The attack surface has reached automotive infotainment.
Banking Trojans Manic, Grandoreiro, ToxicPanda 2.0 in the Spotlight (SecurityWeek)
Three concurrent banking trojan campaigns: Manic (Android, spyware-equipped), Grandoreiro (active Latin America/Europe campaign), and ToxicPanda 2.0 (expanded variant). Busy picture for financial sector defenders.
ShinyHunters Targets Education Sector with Oracle PeopleSoft Exploit (Mandiant / Google Threat Intelligence)
UNC6240 (ShinyHunters) actively exploiting Oracle PeopleSoft to compromise universities and large institutions. If PeopleSoft is in your environment, review the advisory today.
Named Pipes Under Attack: Securing Windows Interprocess Communication (BleepingComputer)
Weak access controls in Windows named pipe implementations can expose privileged services to untrusted processes β a lateral movement and privilege escalation path actively used by threat actors.
A revisit of remote Spectre attacks on Cloudflare Workers (Cloudflare)
Remote Spectre-class side-channel attacks demonstrated against Cloudflare's JavaScript sandbox. Cloudflare has published full analysis β relevant to anyone operating serverless workloads at scale.
If you're not using AI to attack your own systems, your adversaries will (The Register)
Federal advisories now explicit: AI agents have been used in real-life attacks against critical infrastructure multiple times in recent weeks. Offensive AI capability is operational, not theoretical.
Microsoft Entra ID max severity flaw β still actively exploited (BleepingComputer)
The maximum-severity Entra ID vulnerability patched this week remains under active exploitation. If your environment hasn't been patched, this is the second reminder.
CTO at NCSC: Week ending 23 August 2026 (NCSC Substack)
Weekly highlights and blueteamsec reading list from the NCSC's CTO. UK defensive intelligence summary.
UK & Critical National Infrastructure
No new formal NCSC advisories in the past 48 hours. No UK ransomware victims in this cycle.
The more significant angles for UK defenders are indirect:
- Vietnam Electricity (EVNHANOI) claimed by Emperador β a national power grid operator. The same threat model applies to UK energy infrastructure. This is the third consecutive briefing cycle with energy sector ransomware as a lead theme.
- Rhysida's CRI Electric hit (US energy utility) and TheGentlemen's continued European energy campaign (Italy, Norway) reinforce this as a persistent, not episodic, threat.
- The Android car head unit botnet extends the OT attack surface into automotive systems β relevant to any organisation with fleet management or connected vehicle infrastructure.
- The CTO at NCSC weekly summary for w/e 23 August is available at the link above.
Ransomware Victims (48h)
47 victims Β· 10 groups Β· 48-hour window ending 23 Aug 2026
β οΈ = healthcare or critical infrastructure π¬π§ = UK victim
CoinbaseCartel β 13 victims
| Victim | Country | Sector |
|---|---|---|
| β οΈ Integrated Health Systems | US | Healthcare |
| Tower Insurance | NZ | Financial Services |
| Flecha Bus | AR | Transportation |
| OTEIS Conseil & IngΓ©nierie | FR | Professional Services |
| Kessler Creative | US | Professional Services |
| Klasko Immigration Law Partners | US | Professional Services |
| Abacus Advisors | β | Financial Services |
| Longhorn Investments | β | Financial Services |
| LifeBank Microfinance Foundation | PH | Financial Services |
| PT. Bank Perekonomian Rakyat Bintan | ID | Financial Services |
| RXPE Group | CN | Manufacturing |
| PT Perusahaan Jamu Air Mancur | ID | Agriculture & Food |
| Patel | US | Other |
TheGentlemen β 16 victims
| Victim | Country | Sector |
|---|---|---|
| β οΈ Ariel Energia | IT | Energy & Utilities |
| β οΈ Aquasea | NO | Energy & Utilities |
| Meridian Logistics Group | US | Transportation |
| Oceanica Internacional | WS | Transportation |
| ESCON Group | US | Manufacturing |
| Akatake Engineering | JP | Manufacturing |
| LOG Systems | PL | Technology |
| dlp motive | DE | Technology |
| ARBEITERKAMMERN | AT | Professional Services |
| UOLconsult | BR | Professional Services |
| CAZ Investments | BZ | Financial Services |
| Magdalena Grand Beach Golf Resort | MX | Hospitality |
| Almeer | AE | Other |
| AWJ Holding | AE | Other |
| Geb Sas | FR | Other |
| Lexacaucho | β | Other |
Qilin β 7 victims
| Victim | Country | Sector |
|---|---|---|
| β οΈ Quaker State Mexico | MX | Energy & Utilities |
| Gindre India | IN | Manufacturing |
| The Pendas Law Firm | US | Professional Services |
| CinΓ©polis | MX | Hospitality |
| iPic | US | Hospitality |
| Blake Services | US | Other |
| Professional | US | Other |
Rhysida β 3 victims
| Victim | Country | Sector |
|---|---|---|
| β οΈ CRI Electric | US | Energy & Utilities |
| β οΈ Fairview Dental Group | US | Healthcare |
| Battle Creek Public Schools | US | Education |
ShinyHunters β 2 victims
| Victim | Country | Sector |
|---|---|---|
| β οΈ NovoCure Limited | IL | Healthcare (medical devices) |
| BOK Financial | US | Financial Services |
SpaceBears β 2 victims
| Victim | Country | Sector |
|---|---|---|
| holzmarkt chemnitz | DE | Retail & E-Commerce |
| Freelom | CZ | Other |
Single victims
| Group | Victim | Country | Sector |
|---|---|---|---|
| Emperador | β οΈ Vietnam Electricity (EVNHANOI) | VN | Energy & Utilities (national grid) |
| Helix | β οΈ AmSpec | US | Energy & Utilities |
| DragonForce | Hogan Omidi P.C. | US | Professional Services |
| LockBit5 | icnavais.com | PT | Other |