Skip to content

Confidential Β· 08 Aug 2026

πŸ›‘οΈ Daily Cybersecurity Briefing β€” 2026-08-08 (Saturday)

Window: last 24–48h (August 7–8). Severity: πŸ”΄ CRITICAL Β· 🟑 HIGH Β· 🟒 MEDIUM.

Threat level ELEVATEDVictims L30D 133Top actor QilinM&A L30D $125M

πŸ’Ό M&A ACTIVITY

No new deals confirmed with an August 7–8 announcement date in available sources. SecurityWeek's August monthly roundup will consolidate any same-week deals when published.
L30D summary (Jul 9 – Aug 8): 38 named deals tracked. Capital is front-loaded: Visa/BioCatch ($2.4B β€” behavioural biometrics AI for financial fraud detection), Cyera/Oasis Security (~$1B LOI β€” AI-native NHI + data security), Okta/Permiso (~$200M β€” identity threat detection and AI-agent governance), ThreatLocker ($190M Series D), Glow ($180M Series A/$1.2B val), Cathedral ($160M Series A/$1.4B val). Structural theme: non-human identity (NHI), AI-agent security, and agentic SOC automation captured 14+ of 38 deals β€” the dominant capital theme of H2 2026. Pending close: Accenture/Dragos+runZero+NetRise (~$4.175B, expected August/September 2026). SecurityWeek M&A

⚠️ CRITICAL BREACHES & INCIDENTS

Iranian-linked OT attacks on water utilities confirmed across 12 states β€” Clayton County Water Authority (GA) issued boil-water advisoryCriticalEPA, FBI, CISA, and NSA issued a joint advisory warning of active Iranian-affiliated exploitation of internet-exposed PLCs and SCADA at drinking water and wastewater utilities across at least 12 US states (up from 7 as of late July). Confirmed new states in this window: South Dakota, Georgia, New Jersey (two municipalities), Michigan, Minnesota. Attackers changing PLC passwords, disabling alarms, disrupting monitoring and control. No confirmed drinking water contamination as of Aug 5. Joint advisory available at EPA/CISA. 🟨 Attribution to Iranian actors confirmed by US government but not publicly named as Iran in the advisory itself. The Record Β· ABC News Β· EPA/CISA joint advisory
Levi Strauss β€” social engineering breach disclosed Aug 7 β€” corporate file access, consumer data not affectedHighA threat actor gained unauthorized access via social engineering of employee computers and accessed corporate files. Levi Strauss states consumer data was not affected and the breach was contained shortly after discovery with no operational disruption. No attributed threat actor or exfiltration volume disclosed. 🟨 Partial information. The Record
IEH Corporation (US military components manufacturer) β€” SEC cybersecurity disclosure Aug 7HighIEH Corp, which produces components for military satellites, missiles, and fighter jets, disclosed a cyberattack to the SEC. The incident was discovered in early August; containment actions were taken immediately. No further technical detail or threat actor publicly disclosed. The defense-industrial base (DIB) sector has been an explicit target in Russian FSB Center 16's ongoing infrastructure campaign (see Intelligence Alerts below). πŸŸ₯ Verify before treating as a confirmed breach. The Record
Stade FranΓ§ais (Top 14 rugby club, Paris) β€” cyberattack and data leak under investigationHighThe Paris-based rugby club restored systems following a cyberattack and is investigating a confirmed data leak. No attributed actor. Attack timing and exfiltration scope not yet publicly confirmed. πŸŸ₯ Verify before treating as a confirmed breach. The Record
Prosper / 700Credit β€” dual breach disclosures affecting ~20M individualsMediumTwo separate breach disclosures affect combined approximately 20 million individuals. Full scope, timelines, and affected data types not yet detailed in available reporting. 🟨 Partial information β€” monitor for individual company notifications. The Record

πŸ”“ CRITICAL VULNERABILITIES

Cisco Aug 5–6 patch batch β€” 12 SD-WAN and IOS XE flaws including three CVSS 9.9 bugs and CIMCown CVE-2026-20200 (CVSS 9.8, PoC available)CriticalCisco released a hardening update covering 12 vulnerabilities across Catalyst SD-WAN and IOS XE. Three SD-WAN flaws rated CVSS 9.9: CVE-2026-20303 (improper input validation), CVE-2026-20304 (improper access control), CVE-2026-20310 (improper link resolution) β€” each enables remote code execution or privilege escalation by an unauthenticated attacker. Additionally, CVE-2026-20200 "CIMCown" (CVSS 9.8) in the IMC web interface allows root OS command execution with low-privileged authentication; a public PoC is available. SD-WAN has had six exploited zero-days in 2026 alone β€” a target-rich surface for state actors and ransomware operators. Patch immediately via advisory cisco-sa-hardening-iosxe-V8NMuMZJ. The Hacker News Β· Help Net Security β€” CIMCown Β· SecurityWeek
CVE-2026-9198 β€” Langflow (CVSS 9.8) β€” CISA KEV, FCEB deadline Aug 7 (now passed)CriticalUnauthenticated RCE in IBM Langflow AI workflow platform (all default deployments with LANGFLOW_AUTO_LOGIN=true). Attacker calls the /api/v1/auto_login endpoint to mint a superuser bearer token with no credentials, then chains to the code-validation endpoint to execute arbitrary Python on the server. Public PoCs widely available since late July. CISA added Aug 5 with an unusually compressed deadline of Aug 7 β€” federal agencies are now overdue. Fixed in Langflow 1.10.1. Any organisation running Langflow should treat this as urgent. The Hacker News Β· CISA KEV Β· BleepingComputer
LegacyHive (Windows User Profile Service LPE) β€” day 25 unpatched, Patch Tuesday Aug 11 expectedHighNo Microsoft CVE, no official advisory, no patch as of Aug 8. Microsoft has acknowledged and is "actively investigating." The community expects the Aug 11 Patch Tuesday to address it; unconfirmed by Microsoft. 0patch micropatch remains available free of charge for any environment that cannot wait. Combined with BlueHammer CVE-2026-33825, delivers unauthenticated-to-SYSTEM in two steps. BleepingComputer Β· SecurityWeek
N-able N-central β€” second hotfix issued Aug 7 after continued exploitation via new bypassHighN-able released a second emergency hotfix on August 7 following reports of additional zero-day exploitation against N-central servers after CVE-2026-18577's HF1 patch. A third vulnerability (CVE-2026-64564, tentatively named SCTPhantom) enabling account takeover is reported but not yet in the CISA KEV catalog as of Aug 8. Attackers continue using the Take Control feature to deploy Cloudflare tunnels for persistence into MSP-managed customer environments. Any MSP/MSSP running N-central must confirm they have applied all HF1 and HF2 patches and review Take Control audit logs. The Hacker News Β· Huntress

🚨 INTELLIGENCE AGENCY ALERTS & POLICY

EPA + FBI + CISA + NSA joint advisory β€” Iranian attacks on US water and wastewater utilities β€” 12 states affectedCriticalThe four-agency advisory (published around Aug 4–5) warns of ongoing Iranian-affiliated exploitation of internet-exposed industrial controllers at drinking water and wastewater systems. Attack methods: default credential abuse, OT protocol exploitation, PLC password changes, alarm disabling, loss of monitoring and control. Clayton County Water Authority (GA) issued a boil-water advisory. No water contamination confirmed. Utilities are directed to immediately disable remote OT access or require MFA, change all default credentials, and segment OT/IT networks. EPA advisory Β· The Record Β· Tech Times
CISA KEV β€” Langflow CVE-2026-9198, N-central CVE-2026-18556/18577, TeamCity CVE-2026-63077 β€” all FCEB deadlines now passedHighThree of CISA's most recent KEV additions all have federal remediation deadlines that have passed as of August 8: Langflow (Aug 7), N-central (Aug 6), TeamCity (Aug 8). CISA's use of compressed 3-5 day windows (vs. the standard 21 days in BOD 26-04) on all three signals confirmed, active, and fast-moving exploitation in each case. CISA KEV catalog
CISA + NSA + FBI + international partners β€” AA26-194A "Improve Router Hygiene" β€” Russian FSB Center 16 (Ghost Blizzard/Static Tundra)HighJoint advisory (published July 13; 12 international co-signatories including NCSC-UK and ACSC) documents a decade-long FSB campaign exploiting routers with default/weak SNMP community strings via the CISCO-CONFIG-COPY-MIB to exfiltrate device configs, plus Cisco Smart Install abuse. Sectors: comms, DIB, energy, finance, government, healthcare. Includes specific mitigation steps: SNMP hardening, Smart Install disable, config-copy MIB access control. DIB orgs (cf. IEH Corp disclosure above) are an explicit named target. CISA AA26-194A Β· NSA PDF
DEF CON 34 β€” Day 2 (Aug 7) notable disclosuresMediumrekordbox (Pioneer DJ, the dominant professional DJ platform) silently exposes the entire hard drive via an NFS server when network-playing music β€” any host on the same network segment can read the full filesystem, not just the music library. CVE-2026-45459 (Microsoft Excel, patched July Patch Tuesday): crafted server response simultaneously bypasses the trusted-records protection and network isolation, enabling arbitrary file access without user warnings. AI Village running poster sessions on AI agent security failures: prompt injection via telemetry pipelines, phone calls, Slack integrations, product description fields. DEF CON 34 Β· Microsoft MSRC CVE-2026-45459

🌐 THREAT ACTOR & CAMPAIGN ACTIVITY

Ransomware global volume jumped 20% in July β€” 799 incidents (Comparitech), highest month of 2026CriticalComparitech counted 799 claimed ransomware attacks in July 2026, up from 668 in June β€” the second-highest month of the year after a Q2 relative lull. Sector spikes: Finance +71% MoM, Technology +62%, Healthcare +46%, Education +44%. US-based organisations up 31% vs June. Published Aug 7. The Register Β· Comparitech
Storm-2945 / Midnight Blizzard (SVR) β€” CaptiveCrunch campaign: hotel and airport Wi-Fi hijacked to deliver CornFlake RAT and ChocoShell credential stealerCriticalMicrosoft named and attributed a campaign (active since at least May 2026, first flagged by ReliaQuest in July) hijacking captive-portal Wi-Fi at hotels, airports, conference centres, and universities to intercept travellers' connections. Fake browser/OS update prompts deliver two custom malware families: CornFlake (persistent RAT β€” disguises as "Cloud Sync Service", keylogging, credential/M365 token theft, audio/video capture, USB monitoring, with watchdog persistence restoration) and ChocoShell (in-memory PowerShell credential stealer targeting browser cookies, saved passwords, M365 and Azure AD tokens, Wi-Fi credentials). Infrastructure panel: FruitStone C2. Target profile: business travellers, government and diplomatic personnel. Mitigation: always-on full-tunnel VPN; never install updates from captive portal pages. The Hacker News Β· BleepingComputer Β· The Record
North Korea Lazarus Group / Gunra ransomware β€” confirmed tool and infrastructure sharing (AhnLab report)CriticalSouth Korean intelligence agencies and AhnLab documented parallel campaigns (2025 through H1 2026) in which Lazarus Group and the Gunra ransomware operation ran simultaneous intrusions against the same South Korean targets using identical zero-days in mandatory Korean financial security software, the same malware filenames, privilege escalation tools, C2 infrastructure, and SSH key fingerprints. Lazarus objective: espionage backdoors in 72+ organisations (government, crypto exchanges, IT service providers); Gunra objective: encryption, data theft, extortion (Conti v2 lineage, turned RaaS January 2026). Separate reporting links Lazarus toolchain to Medusa ransomware operations. The pattern inverts the traditional ransomware affiliate model: a state actor supplying tools to a criminal group rather than the reverse. 🟨 Multiple independent sources corroborate the infrastructure overlap; full operational coordination unconfirmed. The Record Β· BleepingComputer Β· Security.com
Play β€” Signature Services (US) β€” DLS listing Aug 6HighPlay posted Signature Services (US, business services) on Aug 6; files encrypted and data claimed exfiltrated. πŸŸ₯ Unverified β€” verify before treating as a confirmed breach. ransomware.live
RansomHub (via RansomHouse brand) β€” TechVentures Bank S.A. β€” DLS listing Aug 6HighTechVentures Bank S.A. posted to RansomHouse data-leak site Aug 6; double-extortion format. πŸŸ₯ Unverified β€” verify before treating as a confirmed breach. ransomware.live

🌍 GEOPOLITICS

Analyst lens: how this week's cyber activity maps to state strategy. Defense Β· cyber Β· economics.
Iran's expansion of its water utility OT campaign from 7 to 12 states in one week is a calculated escalation, not an opportunistic spillover β€” it signals that Tehran is deliberately broadening its critical infrastructure disruption footprint as a coercive instrument, likely in response to ongoing US-Iran diplomatic stalemate and residual tension from Operation Epic Fury.CriticalThe joint EPA/FBI/CISA/NSA advisory is the first four-agency water-sector advisory since the 2023 Iranian Cyber Av3ngers campaign. The structural exposure is unchanged: the US water sector has ~50,000 community water systems, the majority of which are small utilities running internet-exposed OT with default credentials and no segmentation β€” the attack surface is too large for the current regulatory framework (the America's Water Infrastructure Act provides authority but not enforcement at the utility level). The Clayton County boil-water advisory is the first direct public-safety consequence of a US-attributed Iranian campaign in the water sector. The near-term risk is not mass contamination but sustained service disruption across a geographically distributed sector. EPA advisory Β· The Record
The US-China tech war crossed a new threshold this week: the FCC is drafting a ban on Chinese optical transceiver imports for data centre use, and China has retaliated with drone export curbs, a Foreign Trade Law investigation, and sanctions on 7 US entities β€” completing the first full cycle of reciprocal technology-sector restrictions in a 72-hour window.CriticalThe optical transceiver ban, if implemented, targets a component with no short-term US substitute at hyperscaler scale, introducing a supply bottleneck into AI data centre construction at precisely the moment demand is most acute. Commerce's concurrent restriction on 19 Chinese/Taiwanese firms from buying US quantum computing, AI, and cloud technology tightens the same supply chain from the other direction. Xi's public legal arsenal warnings ahead of the expected summit signal that Beijing is negotiating from a position it believes is strengthening, not weakening. For any organisation with supply chain exposure to Chinese optical vendors: the FCC move is still a draft, but the direction of travel is confirmed. Bloomberg β€” optical ban Β· Bloomberg β€” China retaliation Β· CyberScoop β€” Commerce restrictions
The House Select Committee on China's bipartisan report (published Aug 4–5) establishes, with technical data, that China Mobile, China Unicom, and China Telecom retained active network pathways inside US telecom data centres after FCC revocations β€” with China Mobile's network appearing in Salt Typhoon C2 routing paths at least 192 times.HighThis is the most specific public technical linkage yet between Chinese state-owned telcos and the Salt Typhoon campaign infrastructure (200+ organisations, 80 countries, GhostSpider and Masol RAT backdoors). The operational implication: the defensive response to Salt Typhoon may have been incomplete because the underlying infrastructure ties were not severed when licences were revoked. The policy gap β€” no mandatory network-topology audit of foreign carrier infrastructure following a licence revocation β€” is now publicly documented. Bloomberg Β· The Record
The Lazarus Group/Gunra ransomware tool-sharing pattern represents the clearest documented case of a UN-sanctioned state actor deliberately blurring the state/criminal boundary in ransomware operations β€” a strategic model that complicates both attribution and diplomatic response, because the observable footprint looks criminal until the SSH key fingerprint or the zero-day is matched.HighThe state-actor-as-supplier model (Lazarus supplying tools to Gunra) is structurally different from previous North Korean operations (Lazarus running ransomware directly, as with WannaCry) or criminal-affiliate-to-state (a criminal group selling access to a state). It creates plausible deniability for the state while maintaining tool/TTP control. Separately, the North Korean pattern of targeting South Korean mandatory financial security software (government-mandated install base) as the primary initial access vector is a systemic regulatory risk: government mandated software creates mandatory attack surface. The Record Β· AhnLab
Threat actors
1 Β· Qilin546 YTD
2 Β· The Gentlemen335 YTD
3 Β· Akira228 YTD
4 Β· DragonForce248 YTD
M&A activity
Socure β†’ Fravityβ€”
Brinqa β†’ PlexTracβ€”
Munich Re (via HSB) β†’ $575Mβ€”
Fortinet β†’ Virtue AIβ€”