Skip to content

Confidential ยท 09 Aug 2026

๐Ÿ›ก๏ธ Daily Cybersecurity Briefing โ€” 2026-08-09 (Sunday)

Window: last 24โ€“48h (August 8โ€“9). Severity: ๐Ÿ”ด CRITICAL ยท ๐ŸŸก HIGH ยท ๐ŸŸข MEDIUM.

Threat level GUARDEDVictims L30D 131Top actor QilinM&A L30D $125M

๐Ÿ’ผ M&A ACTIVITY

No new deals confirmed with an August 8โ€“9 announcement date. The SecurityWeek August monthly roundup will consolidate any same-week deals when published (typically mid-month).
L30D summary (Jul 10 โ€“ Aug 9): 19 named deals tracked, total disclosed capital exceeds $4.3B. Biggest three: Visa/BioCatch ($2.4B โ€” behavioural biometrics AI for fraud detection), Cyera/Oasis Security (~$1B โ€” NHI + data security platform), Okta/Permiso (~$200M โ€” identity threat detection / AI-agent governance). Next tier: ThreatLocker $190M Series D, Onyx Security $113M, Neo $100M, Oak $60M, Act Security $60M, Obsidian Security $85M. Structural theme: non-human identity (NHI) and AI-agent security account for 8+ of 19 deals โ€” the single dominant capital theme of H2 2026. Pending close: Accenture/Dragos+runZero+NetRise (~$4.175B, expected August/September). SecurityWeek M&A tracker

โš ๏ธ CRITICAL BREACHES & INCIDENTS

North Carolina Ports (Wilmington, Morehead City, Charlotte Inland Port) โ€” day 5 of manual operations; investigation ongoingHighAll three NC port facilities remain on full manual processing as of August 8. Normal gate schedules resumed August 6 but every transaction is handled without automated systems. An external forensics firm is working alongside NC DOIT; no attacker identified and no data-exfiltration disclosure as of August 8. US Coast Guard is monitoring. ๐ŸŸจ Partial information โ€” attribution and scope pending forensic conclusions. BleepingComputer ยท The Record ยท CyberScoop
Filtronic (UK defence/telecoms electronics manufacturer) โ€” Qilin DLS claim August 8HighQilin posted Filtronic plc, a UK-listed manufacturer of RF/microwave components used in defence and telecommunications infrastructure, to its data-leak site on August 8. No statement from Filtronic; data scope and impact unconfirmed. Filtronic supplies components to the UK and allied defence supply chains โ€” a notable target profile for a RaaS group with aggressive sector diversification. ๐ŸŸฅ DLS claim only โ€” verify before treating as a confirmed breach. Hendry Adrian ransomware tracker
Louisville Bar Association (US) โ€” INC Ransom DLS claim August 8HighINC Ransom posted the Louisville Bar Association (Kentucky, US legal professional association) to its leak site on August 8. No victim statement; data scope unconfirmed. Consistent with INC Ransom's sustained 2026 campaign targeting the legal sector. ๐ŸŸฅ Unverified โ€” verify before treating as a confirmed breach. ransomware.live
Ingersoll Rand โ€” Everest ransomware DLS claim August 8, attack dated July 22HighEverest ransomware group claimed a breach of Ingersoll Rand (US industrial/HVAC/tools manufacturer) posted August 8 with an estimated attack date of July 22. A separate DeXpose.io report attributes an intrusion to "0apt ransomware," creating ambiguous attribution โ€” the two may reference the same incident. Ingersoll Rand has not issued a statement. Notably, this is at least Ingersoll Rand's second reported ransomware-related incident of 2026 (ALP-001 was attributed to them in March 2026). ๐ŸŸฅ Unverified and attribution disputed โ€” verify before treating as a confirmed breach. FalconFeeds on X ยท DeXpose
CSS webmail attacks โ€” Outlook, Gmail unpatched chains; Yahoo/AOL patchedHighPortSwigger researcher Gareth Heyes demonstrated at Black Hat USA 2026 (published August 8โ€“9) CSS-based attack chains against major webmail providers requiring no JavaScript. Active unpatched chains: Outlook/Firefox allows spoofing a Microsoft sign-in page to capture passwords; Gmail's image-set() bypass enables CSS-exfiltration of email content. Yahoo/AOL patched a paste-race that stole email/login tokens; Fastmail patched two CSS mutation bugs. Proton Mail proxy bypass no longer works. Any organisation relying on webmail UI isolation should note that Outlook and Gmail chains remain unpatched as of August 9. The Hacker News

๐Ÿ”“ CRITICAL VULNERABILITIES

LegacyHive (Windows User Profile Service LPE, NightmareEclipse) โ€” day 26 unpatched โ€” Patch Tuesday August 11 TOMORROWCriticalNo Microsoft CVE, no official advisory, no patch as of August 9. Microsoft acknowledged and is "actively investigating." Community expectation is that August 11 Patch Tuesday (tomorrow) will include a formal fix; Microsoft has not confirmed. Combined with BlueHammer CVE-2026-33825 this delivers unauthenticated-to-SYSTEM in two steps on any fully-patched Windows desktop or server. 0patch micropatch (free) remains the only available remediation for organisations that cannot wait. BleepingComputer ยท SecurityWeek
JetBrains TeamCity CVE-2026-63077 (CVSS critical, unauthenticated RCE) โ€” FCEB deadline passed August 8HighDeserialization of untrusted data enabling unauthenticated remote code execution in TeamCity on-premise. CISA added to KEV with a federal remediation deadline of August 8 (now passed). On-premise TeamCity instances still exposed should be treated as urgent โ€” CI/CD servers hold build secrets, signing keys, and deployment credentials that are prime pivot targets. The Hacker News ยท CISA KEV
N-able N-central โ€” Hotfix 2 (build 2026.3.1.10) required; HF1 alone insufficientHighN-able confirmed on August 6 that the original HF1 (build 2026.3.1.7) for CVE-2026-18577 left an alternative exploitation path open; HF2 supersedes it. Cloud-hosted N-central was patched automatically; self-hosted/on-premise deployments must apply HF2 manually. Attackers used the N-central admin console to reach customer (managed endpoint) environments and establish persistence via the Take Control feature and Cloudflare tunnels. Any MSP/MSSP on on-premise N-central that hasn't confirmed HF2 is still exposed. N-able ยท The Hacker News
DEF CON 34 closing-day disclosures โ€” macOS Keychain, password managers, CPDLC aviationMediumToday's DEF CON 34 closing included: macOS Keychain CVE-2026-28860 โ€” novel flaw extracting all stored Keychain passwords without requiring root or master-password re-entry; password manager chain vulnerabilities across Dashlane, NordPass, Keeper, ProtonPass, and RoboForm (all patched before disclosure); live demonstration of CPDLC (Controller-Pilot Data Link Communications) attacks against commercial aviation digital cockpit communications. Recordings to be posted to media.defcon.org post-conference. DEF CON 34 ยท TechTimes

๐Ÿšจ INTELLIGENCE AGENCY ALERTS & POLICY

CISA KEV โ€” no new additions confirmed in August 8โ€“9 windowMediumThe most recent additions remain the August 3โ€“4 batch (CVE-2026-18577 N-able, CVE-2026-9198 Langflow, CVE-2026-34486 Apache Tomcat, CVE-2026-63077 TeamCity). No new KEV entries have been confirmed for August 8โ€“9 at time of writing. The unusually compressed FCEB deadlines (3โ€“5 days vs the standard 21 under BOD 26-04) on all four recent additions remain the relevant operational signal. CISA KEV catalog
Patch Tuesday August 11 (tomorrow) โ€” large release expected; watch for LegacyHive CVE and possible N-able hardening additionsHighJuly 2026 set a record at 622 CVEs patched. August is expected to be another large batch. Priority watches: LegacyHive (official CVE/patch expected but unconfirmed); any additional N-central/N-able hardening updates; possible Cisco follow-on to the August 5โ€“6 batch. Senserva Patch Tuesday tracker ยท The Hacker News โ€” July Patch Tuesday record
DEF CON 34 closes today โ€” Gen. Paul Nakasone (ret. NSA/USCYBERCOM) and Jeff Moss closing fireside chatMediumThe closing keynote pairs NSA/CYBERCOM's most recent director with DEF CON's founder at the conference's main stage. Nakasone's public appearances since retirement have consistently signalled that US offensive cyber doctrine is being re-scoped to encompass AI-enabled offensive capabilities. Conference theme "AI agents graduate from novelty to standard hacking weapon" has framed the entire event. Recordings typically take 48โ€“72h to post. DEF CON 34

๐ŸŒ THREAT ACTOR & CAMPAIGN ACTIVITY

Qilin โ€” three new victims on August 8 DLS: Filtronic (UK), Clausing (US manufacturing), CLLS Co LtdCriticalQilin posted three new victims within the August 8 window. Filtronic is a UK defence/telecoms electronics supplier (most significant target by sector). Clausing Industrial is a Michigan-based metalworking machinery manufacturer. CLLS Co Ltd is an unidentified entity. Qilin has now posted 110+ victims in August 2026 alone, continuing to run well above any other single group this year. ๐ŸŸฅ All three DLS claims โ€” verify before treating as confirmed breaches. ransomware.live
INC Ransom โ€” Louisville Bar Association (US legal) DLS claim August 8HighINC Ransom continues its documented 2026 campaign targeting law firms and legal-sector organisations, adding the Louisville Bar Association to its leak site on August 8. INC Ransom now claims 885+ total victims since 2023. ๐ŸŸฅ Unverified โ€” verify before treating as a confirmed breach. ransomware.live
Everest ransomware โ€” Ingersoll Rand claim August 8 (attack July 22), disputed attributionHighEverest posted Ingersoll Rand (US industrial, CVSS 9.9-zone SonicWall exposure possible) with an attributed attack date of July 22. Attribution is disputed by a separate "0apt" claim for the same target. Everest is a multifaceted threat group combining ransomware, data-leak extortion, IAB operations, and confirmed insider recruitment tactics active since December 2020. The ambiguity warrants monitoring rather than definitive tracking at this stage. ๐ŸŸฅ Unverified, attribution contested. FalconFeeds on X
RansomHub โ€” effectively dormant; 0 new victim claims in 30 daysMediumRansomHub, which peaked at 736 victims in 2025 and held the #1 position for most of that year, has posted zero new victims in the last 30 days (842 cumulative total). The cause โ€” law enforcement disruption, voluntary exit, or rebrand โ€” has not been publicly confirmed. Historical pattern: major RaaS groups that go dark typically resurface as rebranded operations (cf. LockBit โ†’ LockBit Neo, BlackCat โ†’ ? post-Cronos). Monitor for successor or rebrand. Group-IB ยท Black Kite 2026 Ransomware Report

๐ŸŒ GEOPOLITICS

Analyst lens: how this week's cyber activity maps to state strategy. Defense ยท cyber ยท economics.
DEF CON 34's closing keynote โ€” the first time a former NSA Director / USCYBERCOM Commander has appeared at the conference's main closing stage โ€” signals that AI-enabled offensive cyber has crossed the threshold from classified doctrine into acknowledged public posture.CriticalGen. Nakasone's presence alongside Jeff Moss is not a symbolic gesture: Nakasone's post-retirement commentary has consistently framed AI offensive capability as the next decade's decisive military lever, and DEF CON's explicit theme this year ("AI agents graduate from novelty to standard hacking weapon") is an industry-wide acknowledgement the threshold has been crossed. The structural implication for portfolio executives: the gap between state-grade and criminal AI-enabled attack capability is compressing faster than any defensive toolchain can respond, and the US government is signalling awareness of exactly this dynamic in public, from a hacker conference stage. DEF CON 34 ยท TechTimes
Three US critical-infrastructure sectors hit in a five-day window (August 4โ€“8): water/wastewater (Iranian OT campaign), transportation (NC Ports), and defence manufacturing (IEH Corporation SEC disclosure) โ€” with no confirmed connection between the three, the convergence is nonetheless a systemic risk indicator.HighThe three incidents are almost certainly operationally unrelated: the Iranian water campaign is an OT/PLC play, NC Ports is unattributed, and IEH Corp has not disclosed a threat actor. But the pattern is a policy-level concern: US critical-infrastructure sectors lack the cross-sector threat-sharing velocity to detect concurrent campaigns and identify whether they are coordinated. The DOD's DIB Cybersecurity program (voluntary but incentivised) and the EPA's water-sector authorities are the two most relevant policy instruments โ€” both are under-resourced relative to the identified exposure. EPA/CISA advisory ยท The Record โ€” NC Ports ยท The Record โ€” IEH Corp
DPRK's npm software supply chain campaign โ€” documented at DEF CON 34 as the largest software supply chain attack operation in the npm ecosystem โ€” represents a qualitatively different threat vector from last week's Lazarus/Gunra ransomware tool-sharing story: this is North Korea systematically poisoning developer infrastructure at the foundational layer.HighThe npm campaign (targeting the registry that serves 1.7 billion downloads/week) is about persistent developer-side compromise at scale, not one-time access brokering. This completes a picture of North Korean cyber operations in 2026 that spans three distinct models simultaneously: direct espionage (Lazarus), criminal ransomware partnership (Gunra/LockBit lineage), and supply-chain poisoning (npm). Each targets a different stage of the enterprise software lifecycle โ€” and collectively they represent the most diversified offensive portfolio of any single state actor currently documented. DEF CON 34 talks
RansomHub's abrupt operational halt is the single most structurally significant ransomware development of Q3 2026 and deserves an economic lens: the group that displaced LockBit as the #1 RaaS platform has gone dark under circumstances that, if law-enforcement-driven, would be the second takedown of the #1 group in two years โ€” a pattern that suggests the model of a stable, dominant, long-lived RaaS platform is becoming structurally untenable under sustained law enforcement pressure.HighThe consequence is accelerated fragmentation: new groups (Bavaqai, Nova, Qilin's continued growth) fill the vacuum faster than capacity is destroyed, and the affiliate pool becomes more distributed and less predictable. For boards and insurers tracking ransomware risk, a world of 20 mid-tier groups is harder to model and insure against than one with 2โ€“3 dominant operations โ€” the variance is up even as the top-line victim count grows. Group-IB ยท Black Kite 2026 Report
Threat actors
1 ยท Qilin546 YTD
2 ยท The Gentlemen335 YTD
3 ยท Akira228 YTD
4 ยท DragonForce248 YTD
M&A activity
Socure โ†’ Fravityโ€”
Brinqa โ†’ PlexTracโ€”
Munich Re (via HSB) โ†’ $575Mโ€”
Fortinet โ†’ Virtue AIโ€”