Daily Briefing – Sunday, 23rd August 2026

🎧 Subscribe to the podcast feed

Security News

Hackers infect Android car head units with proxy botnet malware (BleepingComputer)
Supply-chain attack on legitimate device-update apps silently enlists compromised in-vehicle Android systems into a proxy botnet β€” no visible symptoms to the owner. The attack surface has reached automotive infotainment.

Banking Trojans Manic, Grandoreiro, ToxicPanda 2.0 in the Spotlight (SecurityWeek)
Three concurrent banking trojan campaigns: Manic (Android, spyware-equipped), Grandoreiro (active Latin America/Europe campaign), and ToxicPanda 2.0 (expanded variant). Busy picture for financial sector defenders.

ShinyHunters Targets Education Sector with Oracle PeopleSoft Exploit (Mandiant / Google Threat Intelligence)
UNC6240 (ShinyHunters) actively exploiting Oracle PeopleSoft to compromise universities and large institutions. If PeopleSoft is in your environment, review the advisory today.

Named Pipes Under Attack: Securing Windows Interprocess Communication (BleepingComputer)
Weak access controls in Windows named pipe implementations can expose privileged services to untrusted processes β€” a lateral movement and privilege escalation path actively used by threat actors.

A revisit of remote Spectre attacks on Cloudflare Workers (Cloudflare)
Remote Spectre-class side-channel attacks demonstrated against Cloudflare's JavaScript sandbox. Cloudflare has published full analysis β€” relevant to anyone operating serverless workloads at scale.

If you're not using AI to attack your own systems, your adversaries will (The Register)
Federal advisories now explicit: AI agents have been used in real-life attacks against critical infrastructure multiple times in recent weeks. Offensive AI capability is operational, not theoretical.

Microsoft Entra ID max severity flaw β€” still actively exploited (BleepingComputer)
The maximum-severity Entra ID vulnerability patched this week remains under active exploitation. If your environment hasn't been patched, this is the second reminder.

CTO at NCSC: Week ending 23 August 2026 (NCSC Substack)
Weekly highlights and blueteamsec reading list from the NCSC's CTO. UK defensive intelligence summary.


UK & Critical National Infrastructure

No new formal NCSC advisories in the past 48 hours. No UK ransomware victims in this cycle.

The more significant angles for UK defenders are indirect:

  • Vietnam Electricity (EVNHANOI) claimed by Emperador β€” a national power grid operator. The same threat model applies to UK energy infrastructure. This is the third consecutive briefing cycle with energy sector ransomware as a lead theme.
  • Rhysida's CRI Electric hit (US energy utility) and TheGentlemen's continued European energy campaign (Italy, Norway) reinforce this as a persistent, not episodic, threat.
  • The Android car head unit botnet extends the OT attack surface into automotive systems β€” relevant to any organisation with fleet management or connected vehicle infrastructure.
  • The CTO at NCSC weekly summary for w/e 23 August is available at the link above.

Ransomware Victims (48h)

47 victims Β· 10 groups Β· 48-hour window ending 23 Aug 2026
⚠️ = healthcare or critical infrastructure   πŸ‡¬πŸ‡§ = UK victim

CoinbaseCartel β€” 13 victims

VictimCountrySector
⚠️ Integrated Health SystemsUSHealthcare
Tower InsuranceNZFinancial Services
Flecha BusARTransportation
OTEIS Conseil & IngΓ©nierieFRProfessional Services
Kessler CreativeUSProfessional Services
Klasko Immigration Law PartnersUSProfessional Services
Abacus Advisorsβ€”Financial Services
Longhorn Investmentsβ€”Financial Services
LifeBank Microfinance FoundationPHFinancial Services
PT. Bank Perekonomian Rakyat BintanIDFinancial Services
RXPE GroupCNManufacturing
PT Perusahaan Jamu Air MancurIDAgriculture & Food
PatelUSOther

TheGentlemen β€” 16 victims

VictimCountrySector
⚠️ Ariel EnergiaITEnergy & Utilities
⚠️ AquaseaNOEnergy & Utilities
Meridian Logistics GroupUSTransportation
Oceanica InternacionalWSTransportation
ESCON GroupUSManufacturing
Akatake EngineeringJPManufacturing
LOG SystemsPLTechnology
dlp motiveDETechnology
ARBEITERKAMMERNATProfessional Services
UOLconsultBRProfessional Services
CAZ InvestmentsBZFinancial Services
Magdalena Grand Beach Golf ResortMXHospitality
AlmeerAEOther
AWJ HoldingAEOther
Geb SasFROther
Lexacauchoβ€”Other

Qilin β€” 7 victims

VictimCountrySector
⚠️ Quaker State MexicoMXEnergy & Utilities
Gindre IndiaINManufacturing
The Pendas Law FirmUSProfessional Services
CinΓ©polisMXHospitality
iPicUSHospitality
Blake ServicesUSOther
ProfessionalUSOther

Rhysida β€” 3 victims

VictimCountrySector
⚠️ CRI ElectricUSEnergy & Utilities
⚠️ Fairview Dental GroupUSHealthcare
Battle Creek Public SchoolsUSEducation

ShinyHunters β€” 2 victims

VictimCountrySector
⚠️ NovoCure LimitedILHealthcare (medical devices)
BOK FinancialUSFinancial Services

SpaceBears β€” 2 victims

VictimCountrySector
holzmarkt chemnitzDERetail & E-Commerce
FreelomCZOther

Single victims

GroupVictimCountrySector
Emperador⚠️ Vietnam Electricity (EVNHANOI)VNEnergy & Utilities (national grid)
Helix⚠️ AmSpecUSEnergy & Utilities
DragonForceHogan Omidi P.C.USProfessional Services
LockBit5icnavais.comPTOther
Show Comments