Briefing โ€” 26 August 2026

๐ŸŽง Subscribe to the podcast feed

Security News

CISA Warns of Exploited Gitea Vulnerability (SecurityWeek) โ€” CISA issued an alert for an actively exploited vulnerability in the Gitea self-hosted Git service; organisations running Gitea internally should treat this as a priority patch.

Alabama Launches Investigation Into OpenAI's Alleged Hack of Hugging Face (Slashdot) โ€” The state of Alabama is formally investigating allegations that OpenAI compromised the Hugging Face AI model and dataset platform, a significant and still-developing story.

AnonyMousKIT PhaaS uses voice AI to phish iPhone passcodes (BleepingComputer) โ€” A Phishing-as-a-Service platform is deploying voice AI agents to call iPhone users, impersonate Apple Support, and socially engineer device passcodes from victims.

58 arrested in Interpol international cybercrime crackdown (The Record) โ€” A multi-continent Interpol operation resulted in 58 arrests across cybercriminal networks and infrastructure.

Paylogix employee benefits platform breached by Akira (The Record) โ€” Akira ransomware stole financial and health data from Paylogix, which administers employee benefits programmes across multiple employers.

Hospital operator Nutex Health confirms data stolen in cyberattack (BleepingComputer) โ€” US hospital operator Nutex Health confirmed patient data was stolen in a cyberattack, extending the week's pattern of healthcare sector targeting.

Massive DDoS attack disrupts Norway's government digital services (BleepingComputer) โ€” A large-scale DDoS attack caused significant disruption to Norwegian government digital infrastructure; no attribution confirmed.

Hackers abuse npm mirrors for phishing redirects (BleepingComputer) โ€” Attackers are exploiting npm package mirror infrastructure as a phishing redirect host, leveraging the implicit trust developers place in the npm ecosystem.

Hidden Prompts Trick AI Into False Email Summaries (Dark Reading) โ€” Prompt injection attacks can manipulate AI email assistants into generating false message summaries, with the potential to cause recipients to act on entirely fabricated information.

All 1,449 Oracle patches applied โ€” and still breached (The Register) โ€” An attacker successfully compromised a fully-patched Oracle environment via misconfiguration, demonstrating that patching alone is not a sufficient security posture.

NemoClaw: Network-based LLM poisoning in OpenClaw (Dark Reading) โ€” A vulnerability in the OpenClaw open-source LLM framework allows network-based poisoning of model context โ€” a novel attack class against AI inference infrastructure.

Microsoft CVE batch: PowerShell RCE, NTFS RCE, Excel RCE (MSRC) โ€” A cluster of high-severity CVEs including CVE-2026-70337 (PowerShell RCE), CVE-2026-50448 (Windows NTFS RCE), CVE-2026-55137 (Excel RCE), and multiple elevation of privilege vulnerabilities across Winlogon, CLFS, and Windows Clipboard Server.


UK & Critical National Infrastructure

ShadowByt3$ hits two UK organisations simultaneously โ€” A-Plus Software Limited (technology) and Nottingham Trent University (education) were posted by ShadowByt3$ within minutes of each other on 25 August. The coordinated posting pattern against a software firm and a large UK university may indicate a campaign rather than opportunistic compromise. NTU holds research data, industry partnership IP, and student records across a large institution.

No new NCSC advisories published in the past 48 hours. Check ncsc.gov.uk/news/alerts-advisories for the latest guidance.

Norway government DDoS โ€” relevant signal for UK defenders โ€” The targeting logic for Scandinavian government digital services applies equally to UK public sector infrastructure. BleepingComputer

The Iranian power plant disruption context from Tuesday remains the standing CNI threat signal for UK energy sector operators. No follow-on UK-specific incidents reported, but the threat actor capability is confirmed and active.


Ransomware Victims (48h)

43 victims ยท 16 groups ยท 3 UK victims ๐Ÿ‡ฌ๐Ÿ‡ง

GroupVictimCountrySector
akiraWINTER IngenieureDEManufacturing
akiraDavis & Ferberโ€”Professional Services
arcusmediaMark'Technoโ€”Technology
arcusmediaManagementProโ€”Professional Services
AuditTeamma***upRUโ€”
blackwaterwww.ptesm.comPTโ€”
Booba ProjectChernyy & AssociatesRUProfessional Services
Booba ProjectDavroc ๐Ÿ‡ฌ๐Ÿ‡งGBTechnology
Booba ProjectCountry-Wide InsuranceUSFinancial Services
Booba ProjectFederis AbogadosMXProfessional Services
chaosparkderochie.comNLOther
chaosmswalker.comUSProfessional Services
chaoscopcp.comCNโ€”
Dark ProjectPump Engineering CompanyUSManufacturing
Dark Projectโš ๏ธ Dentist in New Britain, CTUSHealthcare
Dark ProjectJones, Little & Co., CPAs, LLPUSProfessional Services
Dark ProjectThe Liberty GroupUSโ€”
Dark ProjectFurnished QuartersUSHospitality
Dark ProjectDesign-Aire Engineering, INCUSManufacturing
DeadlockSHAHEEN LAW GROUP PLCUSProfessional Services
DeadlockFBCZAโ€”
direwolfStudio Legale ESEITProfessional Services
direwolfโš ๏ธ National Kidney RegistryUSHealthcare
dragonforceCribaARTechnology
dragonforceFratoBROther
dragonforceWozairAEOther
dragonforceBrookview FinancialCAFinancial Services
Global Secret GroupTiseo PavingUSTransportation
Global Secret GroupJohnson City HondaUSRetail & E-Commerce
Global Secret Groupโš ๏ธ Lockheed Architectural Solutions, Inc.USGovernment & Defense
majinahanashiPCA Group Sdn. Bhd.MYOther
Panzerโš ๏ธ Government of VojvodinaRSGovernment & Defense
qilinBrazosport CollegeUSEducation
qilinSC PaderTeG Cabluri ElectriceROManufacturing
qilinSTRUCTURED SETTLEMENT CAPITAL LLCUSFinancial Services
qilinAGROLAND S.A.ROAgriculture & Food
qilinConsultores de Segurosโ€”Financial Services
qilinColdfish SeafoodCAAgriculture & Food
safepayindustry.airliquide.krKRManufacturing
safepaylagegepesca.itITAgriculture & Food
ShadowByt3$Sinar Mas Agribusiness (Golden Agri-Resources)IDAgriculture & Food
ShadowByt3$A-Plus Software Limited ๐Ÿ‡ฌ๐Ÿ‡งGBTechnology
ShadowByt3$Knottingham Trent University ๐Ÿ‡ฌ๐Ÿ‡งGBEducation
Show Comments