Skip to content

Confidential Β· 03 Aug 2026

πŸ›‘οΈ Daily Cybersecurity Briefing β€” 2026-08-03 (Monday)

Window: last 24–48h (August 2–3). Severity: πŸ”΄ CRITICAL Β· 🟑 HIGH Β· 🟒 MEDIUM.

Threat level GUARDEDVictims L30D 160Top actor QilinM&A L30D $2.4B

πŸ’Ό M&A ACTIVITY

No new acquisitions or funding rounds announced in the August 2–3 window as of this briefing. Black Hat USA 2026 Briefings begin August 5–6 and historically cluster vendor announcement activity; monitor for deal announcements mid-week.
L30D summary (Jul 4 – Aug 3): 30 named deals, $2.5B+ disclosed value. Three deals dominate: Cyera/Oasis Security (~$1B LOI β€” AI-native NHI + data security platform), Okta/Permiso (~$200M β€” identity threat detection and AI agent governance), and ThreatLocker ($190M Series D β€” Zero Trust endpoint allowlisting). Cathedral ($160M Series A, $1.4B valuation), Glow ($180M Series A, $1.2B valuation), and Qualcomm/SAM Seamless (>$150M β€” network security for embedded IoT) round out the top tier. AI agent identity and governance accounts for the majority of disclosed capital this month, consistent with the June trend. SecurityWeek M&A

⚠️ CRITICAL BREACHES & INCIDENTS

Marquis Software breach scope expands: 74+ banks and credit unions, 672,075+ individuals confirmed; two additional institutions filing notificationsHighArtisans' Bank (32,344 customers β€” names, SSNs) and VeraBank (37,318 customers β€” names, PII) have each filed breach notifications, adding to the 670,000+ figure disclosed July 31. Infosecurity Magazine now reports the total may reach 780,000 across all affected institutions. The August 2025 attack (SonicWall exploitation, no ransomware group claimed responsibility, ransom reportedly paid) has now rippled through at least 74 downstream client organisations in banking and credit-union sectors. No new forensic or attribution details published. 🟨 Company-filed breach notifications confirmed; total count still expanding as institutions file separately. BleepingComputer Β· TechNadu Β· Infosecurity Magazine
πŸŸ₯ TheGentlemen claim Philippine Savings Bank β€” second ransomware listing for this institution in 2026 (August 1) β€” The Gentlemen posted Philippine Savings Bank on their DLS on August 1, 2026. The bank was previously listed by Qilin in January 2026 (187 users, 200 records β€” confirmed claim). This August listing is a separate, independent claim from a different group. No statement from PSBank; no data published. Multiple DLS listings in the same calendar year from different groups can reflect either multiple independent compromises or recycling of the same stolen dataset β€” cannot be determined without PSBank disclosure. πŸŸ₯ DLS claim only; verify before treating as a confirmed new breach. RedPacket Security Β· Ransomware.live
πŸŸ₯ Play ransomware lists Sigma Plastics Group and The Butcher Brothers (August 1) β€” Play posted two US manufacturing/food-sector victims on its DLS August 1. Sigma Plastics Group is a major US plastics manufacturer (likely revenue $1B+ range). The Butcher Brothers operates in food processing/distribution. No statements from either organisation; no data published; no impact details available. πŸŸ₯ DLS claims only; both unverified. RedPacket Security β€” Sigma Β· GalaxyWarden β€” Butcher Brothers
πŸŸ₯ CRPxO claims Encore Enterprises (August 2) β€” 700 GB commercial real estate data β€” CRPxO listed Encore Enterprises, a US commercial real estate firm, on its leak site August 2 with a stated 700 GB of exfiltrated data. CRPxO is an emerging extortion group; this follows their July 31 listing of Turkish financial institutions. πŸŸ₯ DLS claim only; 700 GB figure is attacker-stated, unverified. Ransomware.live Β· RedPacket Security

πŸ”“ CRITICAL VULNERABILITIES

LegacyHive Windows zero-day β€” day 19 unpatched; Patch Tuesday August 11 is the expected fix window (8 days)HighNo official patch or CVE assigned. The Windows User Profile Service local privilege escalation (NightmareEclipse, disclosed July 15) remains functional on all supported Windows desktop and server versions. 0patch free micropatches (released July 20) remain the only available mitigation. Combined with any remote code execution foothold (including BlueHammer CVE-2026-33825, confirmed in ransomware chains as of Aug 1), this provides unauthenticated-to-SYSTEM escalation. Watch for Microsoft out-of-band or August 11 inclusion. BleepingComputer Β· SecurityWeek
No new CISA KEV additions confirmed for August 2–3MediumMost recent KEV additions remain from July 29 (CVE-2026-20316, Cisco Secure FMC hard-coded password) and July 27 (CVE-2025-68686 FortiOS; CVE-2026-16812 Arista VeloCloud Orchestrator). Black Hat Briefings (August 5–6) are the next likely trigger for new KEV activity. CISA KEV

🚨 INTELLIGENCE AGENCY ALERTS & POLICY

Black Hat USA 2026 Day 3 (training) β€” Briefings on August 5–6 will concentrate this week's government and research vulnerability disclosuresHighToday is the third day of pre-conference training. The main Briefings phase (August 5–6) carries the US government keynote lineup (White House National Cyber Director Sean Cairncross, CISA Director Nick Andersen, FBI Cyber Division AD Brett Leatherman) and peer-reviewed research presentations. Historically, Black Hat week is when CISA BOD actions, joint advisories, and vendor patch releases cluster. Expect new material Wednesday–Thursday. Black Hat USA 2026
No new CISA/FBI/NSA/NCSC advisories confirmed for August 2–3MediumThe most recently indexed joint advisory remains the August 1 EPA/FBI/CISA/NSA update expanding the Iranian PLC water campaign to Schneider Electric and Siemens scope. The CISA ICS advisory feed (last confirmed batch July 30) should be rechecked Wednesday. CISA Advisories

🌐 THREAT ACTOR & CAMPAIGN ACTIVITY

TheGentlemenHighcontinues high-volume posting into early August; Philippine Savings Bank (Aug 1) adds to their recent Southeast Asian targeting pattern (Malaysian Nuclear Agency, Jul 30). Still the highest-volume ransomware group in Q2 2026 (239 victims, 30.6% QoQ growth). πŸŸ₯ DLS claims. Halcyon
PlayHighlisted Sigma Plastics Group and The Butcher Brothers (both August 1, both US), adding manufacturing and food processing to recent victim profile. Play was last reported at 43 cumulative victims (last activity Jul 16) β€” this suggests continued operation despite lower visibility than TheGentlemen and Qilin. πŸŸ₯ DLS claims.
CRPxOMediumEncore Enterprises (Aug 2, 700 GB) follows their July 31 Turkish financial sector posting. CRPxO is showing a pattern of high-volume data theft claims (700 GB, 1.5 GB respectively) in rapid succession; group maturity and infrastructure are not yet well-documented. Watch for corroborating evidence before treating claims as confirmed. πŸŸ₯ DLS claim.
ShinyHunters triple-wave (EY, Brinks Home, RingCentral) β€” all post-deadline, still no confirmed data release as of August 3MediumDeadlines (July 30–31) passed without a confirmed public data dump on any of the three. Negotiations or legal proceedings likely ongoing. EY clients should assume exposure of tax-document PII (names, SSNs, bank/card data) and monitor Experian identity monitoring notifications. 🟨 Breaches confirmed by organisations; data publication status UNCONFIRMED.

🌍 GEOPOLITICS

Analyst lens: how this week's cyber activity maps to state strategy. Defense Β· cyber Β· economics.
The Iranian water PLC campaign in 7 US states operates on a different doctrinal premise than conventional gray-zone probing β€” it is wartime cyber doctrine executed during an active kinetic conflict (US/Israel-Iran military operations, February 28 onset), and the defender posture needs to reflect that distinction.CriticalCyberAv3ngers is not probing Western resilience to signal capability β€” it is executing sustained disruption against civilian infrastructure in parallel with Iran's conventional military posture (Strait of Hormuz interdiction, air-defense suppression attempts in July). The August 1 advisory expansion to Schneider Electric and Siemens coverage is not an escalation β€” it is a documentation lag catching up with what the adversary has actually been doing. OT operators in water, wastewater, and energy who have not acted on the 2024 CyberAv3ngers advisory (then Rockwell-only) should treat today as a wartime civil-defence posture, not routine patch prioritisation. Washington Post Β· EPA/FBI/CISA/NSA
DeepSeek's role in the Hermes Agent autonomous attack campaign (Unit 42, July 30) is structurally distinct from the Iranian OT campaign β€” but both illustrate the same underlying dynamic: state-adjacent actors operating outside Western AI governance frameworks are using tools that Western labs declined to deploy.HighThe US/EU regulatory stack (NIST AI RMF, EU AI Act enforcement from August 2) is optimised for compliance by entities subject to Western law. It provides no meaningful constraint on a Zhuhai-based operator integrating DeepSeek into Hermes Agent via Telegram, or on Iranian IRGC-affiliated actors using open-source PLC reconnaissance tooling. The policy gap is not "safe AI vs. unsafe AI" β€” it is "AI deployed under Western governance vs. AI deployed outside it." This week's Black Hat policy keynotes (Cairncross, Andersen, Leatherman, Aug 5–6) will likely attempt a public framing of this asymmetry; the substantive answer β€” if any β€” lies in export controls on advanced semiconductor IP and model weights, not in compliance frameworks. Unit 42 Β· CSIS
Play ransomware's August 1 batch targeting US manufacturing (Sigma Plastics) and food processing (The Butcher Brothers) extends a sector-targeting pattern that warrants monitoring for supply-chain disruption impact.HighPlastics manufacturing is upstream of packaging, automotive, medical device, and consumer electronics supply chains; food processing disruption carries immediate downstream consequences for distribution and retail. Neither victim has confirmed the attacks, but Play's DLS history shows a 60–90 day exfiltration-to-publication timeline β€” the intrusions likely preceded August 1. No indicators of nation-state direction; financial motivation assumed. Ransomware.live Β· HIPAA Journal
Marquis Software's expanding breach notification cascade (74+ institutions, 672K–780K individuals) is a textbook third-party supply-chain risk realisation β€” the kind of event that has driven the DORA and NIST CSF 2.0 supply-chain provisions, and that will likely accelerate federal banking regulator scrutiny of fintech and bank-software vendors.MediumThe breach itself (August 2025, SonicWall exploitation) predates both DORA enforcement (January 2025) and current US banking IT risk guidance updates. The fact that 74+ institutions are filing separate breach notifications β€” rather than a single coordinated disclosure β€” signals that vendor contractual breach-notification obligations in the banking sector are not yet standardised. FFIEC and OCC are likely reviewing vendor oversight guidance as a result. TechRadar Β· BleepingComputer
Threat actors
1 Β· Qilin546 YTD
2 Β· The Gentlemen335 YTD
3 Β· Akira228 YTD
4 Β· DragonForce248 YTD
M&A activity
Socure β†’ Fravityβ€”
Brinqa β†’ PlexTracβ€”
Munich Re (via HSB) β†’ $575Mβ€”
Fortinet β†’ Virtue AIβ€”