Briefing β€” 25 August 2026

🎧 Subscribe to the podcast feed

Security News

US sanctions Iranian cyber actors as UK discloses power plant attack (The Record) β€” Iran-linked actors caused an operational shutdown of a UK power generation facility; the US responded with sanctions against the responsible Iranian cyber operators.

Sleepwalker backdoor targets Windows machines (The Register) β€” A new stealthy Windows backdoor uses advanced persistence mechanisms to evade standard detection; no patch currently available.

CVE-2026-50661: Windows BitLocker Security Feature Bypass (MSRC) β€” A vulnerability allowing attackers to bypass BitLocker disk encryption with serious implications for device theft and data recovery scenarios.

CVE-2026-47292: VS Code MSSQL Extension Remote Code Execution (MSRC) β€” RCE vulnerability in the Visual Studio Code MSSQL database extension; developers using VS Code with SQL Server tooling should patch today.

Exploited Zimbra Flaw Highlights Shrinking Window to Patch (Dark Reading) β€” Active exploitation demonstrates the narrowing gap between vulnerability disclosure and attacker exploitation; Zimbra environments are persistent targets.

Unpatched Calix flaw lets hackers bypass NAT (BleepingComputer) β€” An unpatched vulnerability in Calix networking equipment allows attackers to bypass NAT and expose internal devices directly to the internet.

Active attacks on WordPress miniOrange authentication plugin (BleepingComputer) β€” Attackers are exploiting an auth bypass in the miniOrange plugin to gain unauthenticated access to WordPress installations.

ReliaQuest confirms ShinyHunters breach, says data theft failed (SecurityWeek) β€” ShinyHunters successfully compromised cybersecurity firm ReliaQuest but the company says the attempted data theft was blocked before exfiltration.

Nvidia senior manager linked to AI server smuggling scheme (Ars Technica) β€” A senior Nvidia employee is implicated in illegally exporting Supermicro AI servers to China in violation of US export controls.

AliExpress caught fingerprinting via inaudible audio (Ars Technica) β€” AliExpress was found using inaudible browser audio signals to uniquely fingerprint and track visitors across sessions even after clearing cookies.

WordlistLoader malware disguises payload as ordinary text (Dark Reading) β€” A new malware loader evades detection by disguising its payload as ordinary wordlist files commonly associated with legitimate security tools.

LLMs could exploit inference engines to control host machines (Boyd Kane) β€” Research explores how language models could potentially exploit vulnerabilities in inference engine runtimes to take control of their host systems.


UK & Critical National Infrastructure

Iran-linked cyberattack disrupts UK power plant β€” An Iran-linked threat actor caused an operational shutdown of a UK power generation facility. The US government has sanctioned the responsible Iranian cyber operators in response. This is a rare public admission of physical operational impact from a cyberattack on UK critical national infrastructure. UK CNI operators β€” particularly in the energy sector β€” should treat this as an active, demonstrated threat. The Register | The Record

No new NCSC advisories published in the past 48 hours. Check ncsc.gov.uk/news/alerts-advisories for the latest guidance.

Also relevant for UK defenders: metaencryptor hit Weber Water Resources (US) β€” a reminder that water utilities are in scope for ransomware groups as well as state-sponsored actors. UK water sector should maintain tight patch cadence.


Ransomware Victims (48h)

54 victims Β· 20 groups

GroupVictimCountrySector
akiraBihlDEOther
arcusmediaMark'Technoβ€”Technology
arcusmediaManagementProβ€”Professional Services
Barracuda⚠️ Skyline Implants & PeriodonticsUSHealthcare
BarracudaNamyang Industrial Co., Ltd.KRManufacturing
Barracuda⚠️ Clinical Associates of the Finger Lakes (CAFL)USHealthcare
blackwaterwww.ptesm.comPTβ€”
Booba ProjectChernyy & AssociatesRUProfessional Services
Booba ProjectDavroc πŸ‡¬πŸ‡§GBTechnology
Booba ProjectCountry-Wide InsuranceUSFinancial Services
Booba ProjectFederis AbogadosMXProfessional Services
coinbasecartelWestwing Group SEDERetail & E-Commerce
Dark ProjectJones, Little & Co., CPAs, LLPUSProfessional Services
Dark ProjectThe Liberty GroupUSβ€”
Dark ProjectFurnished QuartersUSHospitality
Dark ProjectDesign-Aire Engineering, INCUSManufacturing
DeadlockSHAHEEN LAW GROUP PLCUSProfessional Services
DeadlockFBCZAβ€”
dragonforceCribaARTechnology
dragonforceFratoBROther
dragonforceWozairAEOther
dragonforceBrookview FinancialCAFinancial Services
emperadorFRUCASTRO SLESAgriculture & Food
kazu⚠️ PappyJoe: Healthcare Management SystemUSHealthcare
kazu⚠️ Instituto Ferrero de Neurología y SueñoARHealthcare
kazu⚠️ Brazil Mobilemed: Cloud PACS PlatformBRHealthcare
kazuCanada Yocale: Appointment ManagementCAProfessional Services
kazu⚠️ PawlyClinic: Digital Veterinary Care PlatformUSHealthcare
kazu⚠️ Dr Akbar Niazi Teaching HospitalPKHealthcare
kazu⚠️ Centro Médico Especializado OSIMXHealthcare
kazu⚠️ Meducar: Telemedicine and Patient ManagementBRHealthcare
kazu⚠️ ConsultorioMovil: Telemedicine and Healthcare SystemMXHealthcare
krybitresi.comDERetail & E-Commerce
lockbit5adt.comUSProfessional Services
majinahanashiPCA *****β€”β€”
metaencryptorWoodlore International Inc.CAOther
metaencryptorTrailer Transit IncUSTransportation
metaencryptor⚠️ Weber Water ResourcesUSEnergy & Utilities
metaencryptor⚠️ MPA Pharma GmbHDEHealthcare
metaencryptorAquamar IncUSAgriculture & Food
metaencryptorCorona CorporationJPOther
metaencryptorFactoryFiveUSManufacturing
Panzer⚠️ Government of VojvodinaRSGovernment & Defense
PanzerSenvibeβ€”Technology
qilinColdfish SeafoodCAAgriculture & Food
qilinA&E + SMA DesignAEProfessional Services
qilinS.E.M.P. s.r.l.ITManufacturing
qilinClear AlignUSProfessional Services
qilinDiforCLTechnology
qilinBlack Cat Engineering & Construction WLLQAManufacturing
safepaylagegepesca.itITAgriculture & Food
shinyhuntersCyrusOne, LLC.USTechnology
Storm⚠️ City of MitchellUSGovernment & Defense
StormSharp Motor GroupAUTransportation
Show Comments