Daily Briefing – Monday, 24th August 2026

🎧 Subscribe to the podcast feed

Security News

North Korean Rust supply chain attack — full scope still emerging (BleepingComputer / SecurityWeek)
The poisoned arrayref crate (1M+ monthly downloads) remains the key story as attribution to DPRK actors is confirmed. Developer teams running Rust build pipelines should audit dependency chains now.

Microsoft Entra ID max-severity flaw — still actively exploited (BleepingComputer)
Seven days since Patch Tuesday and active exploitation continues. Cloud identity platform privilege escalation — patch priority remains critical.

Banking trojans: Manic, Grandoreiro, ToxicPanda 2.0 active simultaneously (SecurityWeek)
Three concurrent Android banking trojan campaigns targeting financial institutions across Latin America, Europe, and beyond. Manic exfiltrates via proximity protocols on nearby devices.

Federal advisories confirm AI-generated code used in real infrastructure attacks (The Register)
Not theoretical, not a conference demo — AI-assisted attack code has been used against critical infrastructure controllers. If this isn't in your threat model, it needs to be.

Kriminal no-filter AI platform lowering capability bar for threat actors (Dark Reading)
An uncensored AI platform designed for criminal use is circulating in threat actor communities, reducing the technical skill required for malware development and social engineering.

Hundreds of leaked AWS keys with full admin access — scale of exposure confirmed (BleepingComputer)
Leaked access keys found to grant full administrative control over corporate AWS accounts. Source: public repositories, misconfigured tooling, stale CI configs. Rotate and audit.

Russian intelligence adds OAuth abuse to phishing toolkit (The Register)
OAuth token theft survives password resets — the standard IR playbook of resetting credentials doesn't remediate access. Detection and token revocation must be part of the response.

SANS ISC Stormcast — Aug 24: cloud metadata scanning active (SANS Internet Storm Center)
Continued scanning for cloud metadata service endpoints (169.254.169.254 and equivalents) observed — classic pre-credential-harvest reconnaissance in cloud environments.


UK & Critical National Infrastructure

No new NCSC advisories in the past 48 hours. No UK-flagged ransomware victims in this cycle.

The energy sector targeting pattern continues for a third consecutive briefing cycle. Emperador's claim against Vietnam's national electricity operator EVNHANOI — if confirmed — represents a ransomware actor targeting a national grid operator. TheGentlemen's active campaign against European energy utilities (Italy, Norway) and Rhysida's prior hit on CRI Electric in the US reinforce a sustained, not episodic, interest in the energy sector. UK energy infrastructure defenders should treat this as a persistent threat trend.

MetaEncryptor's hit against Weber Water Resources (US water utility) is the latest in a pattern of water sector targeting. UK water utilities fall under NIS Regulations — this week's victim pattern warrants a review of sector-wide detection and response posture.

The Kazu healthcare software campaign (9 victims, all healthcare technology platforms) is relevant to UK health sector defenders. Targeting healthcare software vendors rather than hospitals directly is a supply-chain approach that could affect NHS trusts and primary care networks through their technology providers.

The NCSC CTO weekly summary for w/e 23 August is available at ctoatncsc.substack.com and covers the AI-in-attacks thread from a UK defensive perspective.


Ransomware Victims (48h)

55 victims · 14 groups · 48-hour window ending 24 Aug 2026
⚠️ = healthcare or critical infrastructure

CoinbaseCartel — 13 victims

VictimCountrySector
⚠️ Integrated Health SystemsUSHealthcare
Tower InsuranceNZFinancial Services
⚠️ Flecha BusARTransportation
OTEIS Conseil & IngénierieFRProfessional Services
⚠️ Longhorn InvestmentsFinancial Services
Kessler CreativeUSProfessional Services
Klasko Immigration Law PartnersUSProfessional Services
PatelUSOther
⚠️ Abacus AdvisorsFinancial Services
⚠️ LifeBank Microfinance FoundationPHFinancial Services
PT Perusahaan Jamu Air MancurIDAgriculture & Food
⚠️ PT. Bank Perekonomian Rakyat BintanIDFinancial Services
Westwing Group SEDERetail & E-Commerce

Kazu — 9 victims

VictimCountrySector
⚠️ PappyJoe: Healthcare Management SystemUSHealthcare
⚠️ Instituto Ferrero de Neurología y SueñoARHealthcare
⚠️ Brazil Mobilemed: Cloud PACS PlatformBRHealthcare
Canada Yocale: Appointment Management SystemCAProfessional Services
⚠️ PawlyClinic: Digital Veterinary Care PlatformUSHealthcare
⚠️ Dr Akbar Niazi Teaching HospitalPKHealthcare
⚠️ Centro Médico Especializado OSIMXHealthcare
⚠️ Meducar: Telemedicine and Patient Management SystemBRHealthcare
⚠️ ConsultorioMovil: Telemedicine and Healthcare SystemMXHealthcare

Qilin — 8 victims

VictimCountrySector
S.E.M.P. s.r.l.ITManufacturing
Clear AlignUSProfessional Services
DiforCLTechnology
Black Cat Engineering & Construction WLLQAManufacturing
Euroflora srlITAgriculture & Food
Tecnici Associati STPITOther
Studio BOLDRIN PAOLOITProfessional Services
Aurore Development S.p.A.ITOther

MetaEncryptor — 7 victims

VictimCountrySector
Woodlore International Inc.CAOther
⚠️ Trailer Transit IncUSTransportation
⚠️ Weber Water ResourcesUSEnergy & Utilities (water)
⚠️ MPA Pharma GmbHDEHealthcare
Aquamar IncUSAgriculture & Food
Corona CorporationJPOther
FactoryFiveUSManufacturing

ShinyHunters — 4 victims

VictimCountrySector
CyrusOne, LLC.USTechnology (data centres)
ReliaQuest, LLCUSTechnology (security firm)
⚠️ NovoCure LimitedILHealthcare (medical devices)
⚠️ BOK FinancialUSFinancial Services

Barracuda — 3 victims

VictimCountrySector
⚠️ Skyline Implants & PeriodonticsUSHealthcare
Namyang Industrial Co., Ltd.KRManufacturing
⚠️ Clinical Associates of the Finger Lakes (CAFL)USHealthcare

Emperador — 2 victims

VictimCountrySector
FRUCASTRO SLESAgriculture & Food
⚠️ Vietnam Electricity (EVNHANOI)VNEnergy & Utilities (national grid)

LockBit5 — 2 victims

VictimCountrySector
adt.comUSProfessional Services (security company)
icnavais.comPTOther

SpaceBears — 2 victims

VictimCountrySector
holzmarkt chemnitzDERetail & E-Commerce
FreelomCZOther

Single victims

GroupVictimCountrySector
Helix⚠️ AmSpecUSEnergy & Utilities
Storm⚠️ The Cecilian BankUSFinancial Services
incransomel-groupCHOther
killsec⚠️ Global GoPETransportation
majinahanashiPCA *****Other
Show Comments