Confidential Β· 04 Aug 2026
π‘οΈ Daily Cybersecurity Briefing β 2026-08-04 (Tuesday)¶
Window: last 24β48h (August 3β4). Severity: π΄ CRITICAL Β· π‘ HIGH Β· π’ MEDIUM.
Threat level ELEVATEDVictims L30D 150Top actor QilinM&A L30D $125M
πΌ M&A ACTIVITY¶
Visa acquires BioCatch for $2.4 billion (August 3)CriticalVisa signed a definitive agreement to acquire BioCatch from Permira-advised funds. BioCatch is the market-leading behavioural biometrics AI platform: 1.8 billion devices protected, 760 million users, 350+ banking clients across 21 countries including 100+ of the world's largest banks. Visa's rationale: account takeovers and scams cost the global economy $1T+ annually and AI is enabling fraud at unprecedented scale; behavioural biometrics is the countermeasure. Deal expected to close by end of Visa's fiscal Q2 2027, pending regulatory approval. This is the largest fintech security acquisition of 2026 to date. Visa IR Β· CNBC
Balance Theory raises $19M Series A (August 1)MediumAI-driven CISO investment management platform led by SYN Ventures (DataTribe, TEDCO participating). Helps enterprise security teams evaluate and optimise spending across $1B+ portfolios. Addresses portfolio visibility gap that has become acute as security budgets scale alongside the AI threat surface. SecurityWeek
L30D summary (Jul 5 β Aug 4): 28 named deals, $4.7B+ disclosed value. Three transactions dominate: Visa/BioCatch ($2.4B β behavioural biometrics AI), Cyera/Oasis Security (~$1B LOI β AI-native NHI and data security platform), and Okta/Permiso (~$200M β identity threat detection and AI agent governance). July's funding round cluster (Cathedral $160M, Glow $180M, ThreatLocker $190M Series D) signals sustained institutional conviction in zero trust, AI-security, and behavioural analytics plays. The structural theme across the month: AI-powered fraud, non-human identity (NHI), and agentic security operations are capturing the majority of disclosed capital. SecurityWeek M&A
β οΈ CRITICAL BREACHES & INCIDENTS¶
N-able N-central actively exploited β RMM pivot to all managed endpoints; CISA KEV Aug 3CriticalCVE-2026-18576 (initial auth bypass) patched in N-central 2026.3; CVE-2026-18577 (incomplete patch, alternate path) added to CISA KEV August 3 with hotfix 2026.3.1.7 released the same day. Attackers gain admin access to N-central RMM servers, then pivot via the built-in "Take Control" feature to reach every managed endpoint downstream. IOCs include Cloudflare tunnel persistence, a service named "Cloudflared", and svchost.exe in users' documents folder. N-central is used by MSPs managing thousands of client environments β a single compromised instance is a mass-access event. Apply 2026.3.1.7 immediately; rotate admin credentials; hunt for "Cloudflared" service installs on managed endpoints. BleepingComputer Β· CISA Β· SecurityWeek
ShinyHunters fourth wave β Questel SAS, Alcon Inc., Lumenis Ltd. β August 4 contact deadline TODAYCriticalShinyHunters posted three new victims on August 1 with an August 4 contact deadline, meaning potential data dumps may occur today if organisations have not responded. Claims: Questel SAS (France, IP management β 21M+ Salesforce records + 147 GB internal data); Alcon Inc. (Switzerland, global ophthalmology medical device and pharma β 25M+ Salesforce records with PII); Lumenis Ltd. (Israel, surgical and aesthetic laser systems β 1.1M+ customer/employee records + 176 GB internal data). All three follow the same Salesforce-targeting tradecraft used in the Brinks Home attack (Entra vishing, July 13). No statements from any of the three organisations; no data published yet. π₯ DLS claims only; verify before treating as confirmed breaches. Monitor ransomware.live and Dark Web Informer for data dump activity today. BreachNews Β· DeXpose β Questel Β· RedPacket β Alcon Β· RedPacket β Lumenis
ExfilSquad breaches UK Police National Legal Database β 135,000 officer records confirmedHighAttack detected July 26; PNLD confirmed the breach. ExfilSquad claims 135,000 contact records covering UK police officers, criminal justice staff, and government partners (names, organisations, email addresses). Primary concern: exposure of officers involved in sensitive organised crime and counter-terrorism investigations. ExfilSquad also claimed 607,000 records from the UK Department for Education in the same wave; 14 total victims across 5 countries. This is the same ExfilSquad group that claimed Analog Devices (SEC 8-K filed July 29, 570K records). π¨ PNLD confirmed; data contents and full scope under investigation. BleepingComputer Β· The Hacker News Β· SecurityAffairs
Amgen discloses third-party cloud breach β PHI and proprietary data exfiltratedHighAmgen filed an SEC 8-K approximately August 3 disclosing unauthorised access to third-party cloud systems detected in July 2026. Exfiltrated data includes patient protected health information (PHI) and proprietary company data. No patient count disclosed; no threat actor claimed credit; forensic investigation ongoing; no operational disruption reported. π¨ Company-confirmed via SEC filing; scope and attribution still under investigation. The Record Β· BleepingComputer
Accenture confirms 35 GB source code and credentials theft by threat actor "888"HighThreat actor "888" (PwnForums moderator) claimed theft of Azure DevOps source code, Azure access keys, RSA/SSH keys, tokens, and config files. Accenture confirmed the incident, stating it was contained with no operational impact. Disclosure approximately July 29. The 888 actor is an emerging extortion operator and this is a significant confirmed theft of cloud infrastructure credentials from a top-5 global consulting and IT services firm. π¨ Confirmed by Accenture; forensic scope to be confirmed. SecurityWeek Β· BleepingComputer
ShinyHunters triple-wave (EY, Brinks Home, RingCentral) β all post-deadline; no confirmed public data release as of August 4MediumAll three July 30β31 deadlines have passed without a confirmed dump. Negotiations or legal proceedings likely ongoing. Ransomware.live
π CRITICAL VULNERABILITIES¶
CVE-2026-18577 β N-able N-central auth bypass β CISA KEV August 3, actively exploitedCriticalIncomplete fix for CVE-2026-18576; allows attackers to authenticate to N-central via alternate path or channel; hotfix 2026.3.1.7 released August 3. Federal agencies under BOD 26-04 must remediate on all public-facing N-central instances. For MSPs: treat as critical; check downstream client environments for Cloudflare tunnel IOCs. CISA KEV Β· N-able
LegacyHive Windows zero-day β day 20 unpatched; Patch Tuesday August 11 in 7 daysCriticalNo CVE, no official patch. Windows User Profile Service local privilege escalation (NightmareEclipse, disclosed July 15) remains functional on all supported Windows versions. Combined with BlueHammer CVE-2026-33825 (confirmed in ransomware chains), delivers unauthenticated-to-SYSTEM in two steps. 0patch micropatch remains the only available mitigation. BleepingComputer
CVE-2026-15409 / CVE-2026-15410 β SonicWall SMA1000 CVSS 10.0 and 7.2 β INC Ransomware actively deployingHighUnauthenticated WebSocket tunnel + root privilege escalation chain exploited as zero-days since at least June 22; both added to CISA KEV July 14. INC Ransomware (885 cumulative victims, accelerating as of August 2026) is confirmed exploiting this chain to breach organisations in the US, Australia, UAE, Colombia, and Switzerland across private and government sectors. Any unpatched SMA1000 appliance on the internet should be treated as compromised. SecurityWeek Β· The Hacker News
CVE-2026-12569 β PTC Windchill/FlexPLM CVSS 9.8 β Clop actively exfiltrating PLM dataHighCritical RCE via deserialization; disclosed June 17; Clop affiliates deploying JSP webshells on internet-exposed PLM systems to exfiltrate manufacturing IP, design files, and supply chain data. Targets are predominantly manufacturing, retail, and engineering SMEs. CISA KEV entry imposes 3-day federal remediation deadline. Patch Windchill and FlexPLM immediately; take PLM interfaces off public internet. BleepingComputer Β· Help Net Security
π¨ INTELLIGENCE AGENCY ALERTS & POLICY¶
Black Hat USA 2026 government keynote β August 4 (today): White House National Cyber Director, CISA, FBI Cyber DivisionCriticalOpening keynote "Cyber Power in the Age of AI" features Sean Cairncross (National Cyber Director), Nick Andersen (Acting CISA Director), Brett Leatherman (FBI Cyber Division AD), and Katie Sutton (Assistant Secretary of War for Cyber Policy). These appearances will set the formal US government framing for AI-cyber policy heading into Q3. Main Briefings (100+ peer-reviewed presentations, AI-themed research dominant) run August 5β6. Historically, Black Hat week clusters CISA BOD actions, joint advisories, and vendor patch releases β expect new material WednesdayβThursday. Black Hat USA 2026 Β· Black Hat Keynote Release
CISA KEV update August 3 β CVE-2026-18577 (N-able N-central) added; BOD 26-04 remediation requiredCriticalSee Vulnerabilities section for full details. CISA
INC Ransomware exploiting SonicWall SMA1000 zero-days (CVE-2026-15409/15410) β CISA KEV July 14HighActive campaign against public-sector and private-sector organisations; 885+ cumulative victims. SC Media
π THREAT ACTOR & CAMPAIGN ACTIVITY¶
ShinyHuntersCriticalFourth Salesforce-targeting wave active (Questel, Alcon, Lumenis β Aug 4 deadline today). Deadlines passed on EY, Brinks Home, RingCentral with no confirmed data release. New leak infrastructure announced: "permanent" hosting of stolen data even post-payment, a significant tradecraft shift. CyberNews
ExfilSquadHighEmerges as a high-volume new extortion actor: 14 victims in latest wave across 5 countries; UK PNLD (135K police records), Analog Devices (570K records, SEC-filed), UK Dept for Education (607K records), Accenture (35 GB cloud credentials). Cross-sector, cross-country targeting with fast disclosure timelines distinguishes ExfilSquad from slower RaaS operators. Watch for additional victim disclosures.
INC RansomwareHigh885 cumulative victims, accelerating August activity via SonicWall SMA1000 zero-day chain (CVE-2026-15409/15410, CISA KEV July 14). Targets spanning US, Australia, UAE, Colombia, Switzerland; multi-sector. The Hacker News
AnubisHighNew DLS postings August 3: Winn-Dixie (US grocery chain, Southeast), Cameron Regional Medical Center (US healthcare). Both unverified; pattern of food retail + healthcare targeting continues. π₯ DLS claims only. Ransomware.live
QilinHigh1,358 cumulative victims (H1 2026: 370 North America, 158 Europe/UK; 443% YoY increase). Active exploitation of CVE-2026-0257 (Palo Alto GlobalProtect, CISA KEV May 29) continues. Arctic Wolf confirmed multiple June 2026 intrusions via this vector with domain-wide encryption as outcome. BleepingComputer Β· Arctic Wolf
RansomHouseMediumPCL Holding Public Co. Ltd (Thailand, diversified holding company) listed on DLS with estimated attack date July 18. π₯ DLS claim only. RansomLook
Chaos ransomware via Microsoft Teams vishing (STAC4749, Sophos)MediumIT helpdesk impersonation via external Teams accounts; intrusion-to-encryption in under 17 hours in worst case; 50% of attacks targeting Canada, 45% USA. Campaign tracked FebruaryβJune 2026; 3+ confirmed Chaos ransomware deployments. Sectors: services, manufacturing, energy, construction. BleepingComputer Β· Sophos
π GEOPOLITICS¶
Analyst lens: how this week's cyber activity maps to state strategy. Defense Β· cyber Β· economics.
The Black Hat government keynote today (Cairncross, Andersen, Leatherman, Sutton) is the first formal US government cyber policy statement since the Hermes Agent/DeepSeek autonomous attack disclosure and the EU AI Act high-risk enforcement start β watch for whether the administration frames AI safety controls as a national-security tool, not just a compliance regime.CriticalThe DeepSeek/Hermes Agent case (Unit 42, July 30) established empirically that Chinese-origin AI models execute attacks that Western models refuse. The EU AI Act commenced enforcement August 2. The White House has not yet formally addressed the AI-governance asymmetry in the adversarial context (state-adjacent actors outside Western legal reach are deploying unconstrained models). Today's keynote is the first venue where that framing can emerge publicly. The substantive policy instrument β if any β will likely be in export controls on advanced model weights and semiconductor IP, not compliance frameworks. Black Hat Β· Unit 42
The Iranian water OT campaign (7 US states, 30+ Minnesota facilities, Michigan/Georgia/South Dakota confirmed) continues to evolve as an active wartime cyber operation, not gray-zone signalling β the August 3 extension to Georgia and Michigan signals expanding scope, not a plateau.CriticalIran-linked CyberAv3ngers are targeting Rockwell Automation/Allen-Bradley PLCs across water and wastewater systems; FBI, CISA, NSA, EPA, DOE, and US Cyber Command maintain a joint advisory. The attack method (modified PLC passwords, IP address changes to disconnect remote monitoring) mirrors the 2023 Rockwell campaign, now executed at 7-state scale under active US/Israel-Iran kinetic conflict (February 28 onset). OT operators in water, energy, and critical manufacturing should treat the Iran campaign as wartime civil-defence doctrine, not routine threat intel. The Register Β· Washington Post
The ExfilSquad UK PNLD breach (135,000 police and criminal justice records) lands at a structurally sensitive moment for UK law enforcement: operational security for sensitive investigations is now contingent on a database that has been actively breached, and the attacker is not a state but an extortion operator without geopolitical constraints.HighUK law enforcement's digital infrastructure has been under sustained pressure since the 2023 Police Service of Northern Ireland breach (10,000 officers) and the 2024 Metropolitan Police supplier breach. PNLD holds contact and organisational data for officers across all UK constabularies and criminal justice bodies. The NCSC-UK will be assessing whether a data harvesting risk (targeted surveillance of officers' contact information by hostile states or organised crime) compounds the initial extortion exposure. The Hacker News Β· SecurityAffairs
Visa's $2.4B acquisition of BioCatch is a structural bet that behavioural biometrics is the primary AI-era countermeasure to AI-powered fraud β and that the fraud cost trajectory (officially $1T+ annually, likely higher given attribution gaps) justifies acquiring the market leader rather than building.HighThe strategic read: as AI enables social engineering and account takeover at scale (Brinks Home CEO confirmed Entra vishing by ShinyHunters July 13; CRPxO, ShinyHunters, Anubis all showing rapid volume growth), payments networks need a layer below authentication that cannot be spoofed by AI-generated credentials. Behavioural biometrics β how you interact with a device, not who you claim to be β is that layer. Visa's $2.4B bet will drive competitor replication (Mastercard, Amex, major banks) and is likely to accelerate the BioCatch model's consolidation as a baseline financial-services security control within 18β24 months. CNBC Β· Visa IR
M&A activity
Socure β Fravityβ
Brinqa β PlexTracβ
Munich Re (via HSB) β $575Mβ
Fortinet β Virtue AIβ