🎧 Subscribe to the podcast feed
Security News
North Korean Rust supply chain attack — full scope still emerging (BleepingComputer / SecurityWeek)
The poisoned arrayref crate (1M+ monthly downloads) remains the key story as attribution to DPRK actors is confirmed. Developer teams running Rust build pipelines should audit dependency chains now.
Microsoft Entra ID max-severity flaw — still actively exploited (BleepingComputer)
Seven days since Patch Tuesday and active exploitation continues. Cloud identity platform privilege escalation — patch priority remains critical.
Banking trojans: Manic, Grandoreiro, ToxicPanda 2.0 active simultaneously (SecurityWeek)
Three concurrent Android banking trojan campaigns targeting financial institutions across Latin America, Europe, and beyond. Manic exfiltrates via proximity protocols on nearby devices.
Federal advisories confirm AI-generated code used in real infrastructure attacks (The Register)
Not theoretical, not a conference demo — AI-assisted attack code has been used against critical infrastructure controllers. If this isn't in your threat model, it needs to be.
Kriminal no-filter AI platform lowering capability bar for threat actors (Dark Reading)
An uncensored AI platform designed for criminal use is circulating in threat actor communities, reducing the technical skill required for malware development and social engineering.
Hundreds of leaked AWS keys with full admin access — scale of exposure confirmed (BleepingComputer)
Leaked access keys found to grant full administrative control over corporate AWS accounts. Source: public repositories, misconfigured tooling, stale CI configs. Rotate and audit.
Russian intelligence adds OAuth abuse to phishing toolkit (The Register)
OAuth token theft survives password resets — the standard IR playbook of resetting credentials doesn't remediate access. Detection and token revocation must be part of the response.
SANS ISC Stormcast — Aug 24: cloud metadata scanning active (SANS Internet Storm Center)
Continued scanning for cloud metadata service endpoints (169.254.169.254 and equivalents) observed — classic pre-credential-harvest reconnaissance in cloud environments.
UK & Critical National Infrastructure
No new NCSC advisories in the past 48 hours. No UK-flagged ransomware victims in this cycle.
The energy sector targeting pattern continues for a third consecutive briefing cycle. Emperador's claim against Vietnam's national electricity operator EVNHANOI — if confirmed — represents a ransomware actor targeting a national grid operator. TheGentlemen's active campaign against European energy utilities (Italy, Norway) and Rhysida's prior hit on CRI Electric in the US reinforce a sustained, not episodic, interest in the energy sector. UK energy infrastructure defenders should treat this as a persistent threat trend.
MetaEncryptor's hit against Weber Water Resources (US water utility) is the latest in a pattern of water sector targeting. UK water utilities fall under NIS Regulations — this week's victim pattern warrants a review of sector-wide detection and response posture.
The Kazu healthcare software campaign (9 victims, all healthcare technology platforms) is relevant to UK health sector defenders. Targeting healthcare software vendors rather than hospitals directly is a supply-chain approach that could affect NHS trusts and primary care networks through their technology providers.
The NCSC CTO weekly summary for w/e 23 August is available at ctoatncsc.substack.com and covers the AI-in-attacks thread from a UK defensive perspective.
Ransomware Victims (48h)
55 victims · 14 groups · 48-hour window ending 24 Aug 2026
⚠️ = healthcare or critical infrastructure
CoinbaseCartel — 13 victims
| Victim | Country | Sector |
|---|---|---|
| ⚠️ Integrated Health Systems | US | Healthcare |
| Tower Insurance | NZ | Financial Services |
| ⚠️ Flecha Bus | AR | Transportation |
| OTEIS Conseil & Ingénierie | FR | Professional Services |
| ⚠️ Longhorn Investments | — | Financial Services |
| Kessler Creative | US | Professional Services |
| Klasko Immigration Law Partners | US | Professional Services |
| Patel | US | Other |
| ⚠️ Abacus Advisors | — | Financial Services |
| ⚠️ LifeBank Microfinance Foundation | PH | Financial Services |
| PT Perusahaan Jamu Air Mancur | ID | Agriculture & Food |
| ⚠️ PT. Bank Perekonomian Rakyat Bintan | ID | Financial Services |
| Westwing Group SE | DE | Retail & E-Commerce |
Kazu — 9 victims
| Victim | Country | Sector |
|---|---|---|
| ⚠️ PappyJoe: Healthcare Management System | US | Healthcare |
| ⚠️ Instituto Ferrero de Neurología y Sueño | AR | Healthcare |
| ⚠️ Brazil Mobilemed: Cloud PACS Platform | BR | Healthcare |
| Canada Yocale: Appointment Management System | CA | Professional Services |
| ⚠️ PawlyClinic: Digital Veterinary Care Platform | US | Healthcare |
| ⚠️ Dr Akbar Niazi Teaching Hospital | PK | Healthcare |
| ⚠️ Centro Médico Especializado OSI | MX | Healthcare |
| ⚠️ Meducar: Telemedicine and Patient Management System | BR | Healthcare |
| ⚠️ ConsultorioMovil: Telemedicine and Healthcare System | MX | Healthcare |
Qilin — 8 victims
| Victim | Country | Sector |
|---|---|---|
| S.E.M.P. s.r.l. | IT | Manufacturing |
| Clear Align | US | Professional Services |
| Difor | CL | Technology |
| Black Cat Engineering & Construction WLL | QA | Manufacturing |
| Euroflora srl | IT | Agriculture & Food |
| Tecnici Associati STP | IT | Other |
| Studio BOLDRIN PAOLO | IT | Professional Services |
| Aurore Development S.p.A. | IT | Other |
MetaEncryptor — 7 victims
| Victim | Country | Sector |
|---|---|---|
| Woodlore International Inc. | CA | Other |
| ⚠️ Trailer Transit Inc | US | Transportation |
| ⚠️ Weber Water Resources | US | Energy & Utilities (water) |
| ⚠️ MPA Pharma GmbH | DE | Healthcare |
| Aquamar Inc | US | Agriculture & Food |
| Corona Corporation | JP | Other |
| FactoryFive | US | Manufacturing |
ShinyHunters — 4 victims
| Victim | Country | Sector |
|---|---|---|
| CyrusOne, LLC. | US | Technology (data centres) |
| ReliaQuest, LLC | US | Technology (security firm) |
| ⚠️ NovoCure Limited | IL | Healthcare (medical devices) |
| ⚠️ BOK Financial | US | Financial Services |
Barracuda — 3 victims
| Victim | Country | Sector |
|---|---|---|
| ⚠️ Skyline Implants & Periodontics | US | Healthcare |
| Namyang Industrial Co., Ltd. | KR | Manufacturing |
| ⚠️ Clinical Associates of the Finger Lakes (CAFL) | US | Healthcare |
Emperador — 2 victims
| Victim | Country | Sector |
|---|---|---|
| FRUCASTRO SL | ES | Agriculture & Food |
| ⚠️ Vietnam Electricity (EVNHANOI) | VN | Energy & Utilities (national grid) |
LockBit5 — 2 victims
| Victim | Country | Sector |
|---|---|---|
| adt.com | US | Professional Services (security company) |
| icnavais.com | PT | Other |
SpaceBears — 2 victims
| Victim | Country | Sector |
|---|---|---|
| holzmarkt chemnitz | DE | Retail & E-Commerce |
| Freelom | CZ | Other |
Single victims
| Group | Victim | Country | Sector |
|---|---|---|---|
| Helix | ⚠️ AmSpec | US | Energy & Utilities |
| Storm | ⚠️ The Cecilian Bank | US | Financial Services |
| incransom | el-group | CH | Other |
| killsec | ⚠️ Global Go | PE | Transportation |
| majinahanashi | PCA ***** | — | Other |