Confidential ยท 10 Aug 2026
๐ก๏ธ Daily Cybersecurity Briefing โ 2026-08-10 (Monday)¶
Window: last 24โ48h (August 8โ10). Severity: ๐ด CRITICAL ยท ๐ก HIGH ยท ๐ข MEDIUM.
Threat level GUARDEDVictims L30D 131Top actor QilinM&A L30D $125M
๐ผ M&A ACTIVITY¶
Zenity raises $125M Series C โ largest AI-agent-security raise of H2 2026MediumTel Aviv-based Zenity (founded 2021) closed a $125M Series C led by Norwest Venture Partners, with SoftBank Vision Fund 2, Hitachi Ventures, LG Technology Ventures, Qumra Capital, Vertex Ventures, Third Point Ventures, DTCP, and Intel Capital participating. Total raised reaches $180M. Platform governs AI-agent intent deterministically โ allowing, modifying, or blocking autonomous actions โ targeting the projected 1-billion AI-agent enterprise deployment wave. Announced August 3โ4, captured here after the Monday cycle. Zenity ยท SecurityWeek
No other deals confirmed with an August 9โ10 announcement date.
L30D summary (Jul 10 โ Aug 10): 33 named deals tracked, total disclosed capital exceeds $4.7B. Biggest five: Visa/BioCatch ($2.4B โ behavioral biometrics AI for fraud), Cyera/Oasis Security (~$1B LOI โ NHI + data security), Okta/Permiso (~$200M โ identity threat detection), ThreatLocker $190M Series D, Glow $180M Series A ($1.2B valuation). Zenity $125M and Cathedral $160M are the headline late-July additions just now visible in the full count. Theme unchanged: non-human identity (NHI) and AI-agent security account for 10+ of 33 deals โ the dominant capital theme of H2 2026. SecurityWeek M&A tracker
โ ๏ธ CRITICAL BREACHES & INCIDENTS¶
Swiss Federal IT Office (FOITT/BIT) โ SharePoint exploitation chain; 200 accounts compromisedHighSwitzerland's Federal Office of Information Technology, Systems and Telecommunication detected an intrusion on July 28 and disclosed it publicly August 7. Attackers exploited the same Microsoft SharePoint vulnerability chain expected to receive a full patch at tomorrow's Patch Tuesday (CVE-2026-55040 JWT token forgery + CVE-2026-56164 EoP). Approximately 200 user and technical accounts compromised; credentials stolen. FOITT has blocked all external access, reset all passwords, and is rebuilding affected servers. No evidence of data exfiltration beyond credentials; attackers described as "previously unknown." The timing โ attack landed days after July Patch Tuesday, exploiting flaws only partially addressed โ makes this the sharpest illustration yet of the window between Microsoft disclosure and adversary weaponisation. BleepingComputer ยท Help Net Security
Wall Street hedge funds โ AI vishing wave; FINRA Fusion Center activated (August 5โ6)HighUNC6671 (also tracked as Redact, Pink, Helix, Falcon; Google Threat Intelligence attribution; linked to former BlackFile operation) used voice-cloning technology to impersonate executives at Citadel, Point72, Millennium Management, Two Sigma, Apollo Global Management, KKR, and Moody's on August 5, attempting to extract credentials or network access via phone calls and audio messages. Two Sigma confirmed a blocked attempt with no impact. Point72 informed investors its initial review found no client data stolen; investigation ongoing. Citadel and Millennium declined to comment on breach status. The attack marks the first live test of FINRA's Financial Intelligence Fusion Center as a cross-industry defense mechanism. UNC6671 had previously targeted manufacturing and hospitality; this pivot to top-tier financial-sector institutions represents a material escalation in target profile. ๐จ Partial โ some firms investigating. BleepingComputer ยท Fortune ยท TechTimes
North Carolina Ports โ day 6 manual operations; attack contained, no attribution (August 10)HighAll three NC port facilities (Wilmington, Morehead City, Charlotte Inland Port) remain on manual processing as of August 10, six days after the August 4 cyberattack. Normal gate schedules resumed August 6โ7, but IT systems are not yet restored. External forensics firm and US Coast Guard monitoring; no threat actor has claimed responsibility; attack vector and data-exfiltration status remain undisclosed. ๐จ Partial information โ attribution and scope pending forensic conclusions. BleepingComputer ยท Maritime Executive
Metabase zero-day (CVSS 10.0, no CVE) โ active exploitation against Framework and TallyHighAn unauthenticated SQL injection/RCE vulnerability in Metabase Cloud and all self-hosted versions 1.58+ was disclosed August 7 after active exploitation against Framework (financial infrastructure) and Tally (accounting). Attackers exfiltrated data before the flaw was patched. Fixes available: x.58.24 / x.59.21 / x.60.17 / x.61.11 / x.62.9 / x.63.5. No CVE assigned yet. Any self-hosted Metabase installation on an affected version should be treated as compromised pending patch and investigation. BleepingComputer ยท The Hacker News
๐ CRITICAL VULNERABILITIES¶
Progress Kemp LoadMaster CVE-2026-8037 (CVSS 9.6) โ FCEB deadline TODAY; 792 exploit attempts loggedCriticalCISA added LoadMaster to KEV on August 7. Command injection via unsanitized input in multiple command endpoints allows unauthenticated attackers to execute arbitrary commands on the appliance. Active exploitation confirmed: 792 attempts from 65 IPs over 41 days; 5 attempts on August 4 alone. Federal Civilian Executive Branch (FCEB) agencies had a BOD 26-04 remediation deadline of August 10 โ today. Any unpatched LoadMaster appliance (widely deployed as ADC/load balancer in enterprise and government networks) should be treated as compromised. The Hacker News ยท CISA KEV ยท SecurityAffairs
Patch Tuesday August 11 TOMORROW โ SharePoint RCE chain actively exploited; watch for LegacyHive resolutionCriticalMicrosoft's August Patch Tuesday drops tomorrow (August 11). Pre-release intelligence identifies a high-priority SharePoint chain: CVE-2026-55040 (CVSS 9.1, JWT token validation bypass allowing unauthenticated token forgery against on-premises SharePoint Server Subscription Edition, 2019, and 2016) combined with CVE-2026-56164 (EoP), plus a still-embargoed second component completing the RCE chain. Microsoft has confirmed at least two vulnerabilities are being actively exploited in the wild ahead of patch release โ the Swiss FOITT breach is likely related. Volume expected: 200โ300+ CVEs following July's record 621. LegacyHive (Windows User Profile Service LPE, day 27 unpatched โ no CVE, no advisory) may or may not be addressed; pre-release forecasts do not confirm it. 0patch micropatch remains the only available interim fix. Help Net Security Forecast ยท BleepingComputer LegacyHive
CISA KEV August 7 batch โ 4 new additions; Joomla and Langflow auth bypass join catalogMediumIn addition to LoadMaster (CVE-2026-8037), CISA added: CVE-2026-48908 (JoomShaper SP Page Builder, unrestricted file upload with dangerous type), CVE-2026-55255 (IBM Langflow, auth bypass via user-controlled key โ distinct from the August 4 code-injection CVE-2026-9198), and CVE-2026-56290 (Joomla, improper access control). BOD 26-04 is generating unusually compressed remediation windows for all recent additions; the August cadence reflects CISA's posture shift toward faster federal enforcement timelines. CISA
๐จ INTELLIGENCE AGENCY ALERTS & POLICY¶
Five Eyes joint AI/Telecom advisory (August 4) โ AI is compressing attack timelines faster than defenders can respondCriticalAll five Five Eyes agencies (CISA/FBI/NSA, NCSC-UK, ACSC, Canadian Centre for Cyber Security, NCSC-NZ) published a joint advisory warning that AI is accelerating adversary attack timelines faster than telecom and enterprise defenders can adapt, referencing Anthropic frontier model evaluations showing near-full penetration of controlled classified-environment simulations. Advisory urges enhanced visibility tooling, faster patch cycles, and strict access control. NCSC-UK CTO Ollie Whitehouse issued a parallel statement on AI security. This is the first Five Eyes publication to cite internal AI frontier-model test results as the evidentiary basis for an operational warning. Cybersecurity Dive ยท VoIP Review
CISA ICS advisory โ CPDLC aviation digital cockpit communications (August 7, ICSA-26-219-01)HighCISA published an ICS advisory covering controller-pilot data link communications (CPDLC) over ATN-B1, the digital text-based system used in commercial aviation cockpit-to-ATC communications. Advisory follows the DEF CON 34 live demonstration of CPDLC attack chains on August 8. Risk to live flight operations is constrained by operational procedures, but the combination of a public PoC and a formal CISA advisory warrants attention from aviation sector operators. CISA ICS Advisories
Patch Tuesday August 11 preparation noteMediumTwo flaws being actively exploited in the wild are expected to receive patches tomorrow. Federal teams should have a same-day deployment readiness plan for the SharePoint chain given active in-wild exploitation and the Swiss government compromise as a proof-of-impact. CISA BOD 26-04
๐ THREAT ACTOR & CAMPAIGN ACTIVITY¶
Ransomware DLS activity August 8โ9 โ Studio Associato Tibaldi (Italy), Siam Oil Product (Thailand), Daily Trust (Nigeria)HighThree organizations posted to ransomware.live in the August 8โ9 window. Studio Associato Tibaldi is a Rome-based professional firm. Siam Oil Product Co. Ltd. is a Thai petroleum and industrial distributor. Daily Trust is a major Nigerian national newspaper. Group attribution is unconfirmed for all three in available sources. ๐ฅ DLS claims only โ verify before treating as confirmed breaches. ransomware.live
Qilin โ sustained #1 position; Qilin/LockBit/DragonForce cartel alignment announced on dark webHighQilin holds the top position in the 2026 ransomware leaderboard with 335 victims in the last 3 months and 546 YTD. Dark web forum reporting indicates Qilin, LockBit (Neo-era operations), and DragonForce have announced a cartel-style coordination arrangement โ affiliate sharing, infrastructure overlap, and joint targeting. If confirmed, this would be the first formalized multi-group operational cartel of this scale since the DarkSide-REvil era. Monitor for coordinated victim clustering or simultaneous postings as a corroborating signal. ๐ฅ Cartel announcement from dark web forums โ treat as intelligence lead, not confirmed structure. Black Kite 2026 Ransomware Report ยท ransomware.live stats
INC Ransom โ SonicWall SMA 1000 campaign active across AU, US, UAE, Colombia, SwitzerlandHighINC Ransom continues exploiting the CVE-2026-15409 / CVE-2026-15410 SonicWall SMA 1000 zero-day chain (CVSS 10.0 pre-auth WebSocket bypass + path traversal to root) at scale. Attackers are stealing TOTP seeds and active session databases โ patching alone is insufficient remediation if seeds were already exfiltrated. Multiple new DLS victims from the affected geographies have appeared since August 1. INC Ransom now claims 885+ total victims. The Hacker News ยท SC Media
RansomHub โ dormant at 30+ days with zero new victims; cause still unconfirmedMediumRansomHub remains at zero new victim postings for over 30 days (842 cumulative total since inception). No law enforcement action, voluntary exit, or rebrand has been publicly confirmed. Group-IB ยท Black Kite 2026 Report
๐ GEOPOLITICS¶
Analyst lens: how this week's cyber activity maps to state strategy. Defense ยท cyber ยท economics.
The Five Eyes AI advisory (August 4) is the clearest public signal yet that Western intelligence agencies believe AI-enabled cyberattacks have crossed from theoretical to operational risk โ and that the gap between state-grade and commercial defensive capability is widening, not narrowing.CriticalCiting frontier model evaluations that show near-full penetration of controlled classified environments, the joint advisory is not a forward-looking warning โ it is an acknowledgement of a present-tense capability shift. For government and critical-infrastructure operators, the implication is structural: patch cycles designed around human-operated attack timelines are miscalibrated against AI-accelerated exploitation. The advisory does not name a specific adversary โ precisely because the capability is not yet exclusive to one actor. Cybersecurity Dive
Switzerland's federal government IT office being breached through the same SharePoint chain that Microsoft only partially addressed in July Patch Tuesday is the week's sharpest example of government infrastructure sitting inside the adversary's exploitation window.HighThe attack on FOITT/BIT (July 28) and the two SharePoint CVEs expected at tomorrow's Patch Tuesday are not coincidental โ the full chain was in attacker hands while governments and enterprises were still deploying the partial July fix. For policy: the compressed FCEB BOD 26-04 deadlines CISA has been applying to recent KEV additions are a recognition that the traditional 21-day federal patching window is operationally irrelevant against adversaries who weaponise within hours of disclosure. BleepingComputer ยท CISA BOD 26-04
Iran's shift to living-off-the-land (LoTL) tradecraft โ abusing legitimate IT management tools with no custom malware โ has made its 4,800-incidents-per-month campaign against Israel significantly harder to detect and attribute; this is a deliberate platform decision, not a capability gap.HighThe move mirrors the Western intelligence community's own most-effective offensive techniques (Volt Typhoon's LoTL posture, APT29's use of native cloud APIs). For the Iran-Israel cyber conflict, it means the incident rate visible in attribution reports represents only the fraction where Iranian activity deviated enough from legitimate admin behavior to trigger alerts. The structural consequence: a 4,800-incidents-per-month number is almost certainly a floor, not a ceiling. Times of Israel ยท SOCRadar
The UNC6671 financial-sector AI vishing wave (August 5) demonstrates that the voice-cloning capability once associated with nation-state operations is now deployed by non-state extortion groups at commercial scale against the world's most sophisticated financial-sector security teams.HighUNC6671 pivoted from manufacturing and hospitality targets to Point72, Citadel, Millennium, Two Sigma, Apollo, KKR, and Moody's in a single coordinated wave. The FINRA Financial Intelligence Fusion Center activating for the first time signals that the financial sector is treating AI vishing as a systemic, cross-institution threat rather than individual incident response. The structural read: social-engineering attacks at this level previously required nation-state voice-clone infrastructure; the barrier is now commercial. BleepingComputer ยท Fortune
M&A activity
Socure โ Fravityโ
Brinqa โ PlexTracโ
Munich Re (via HSB) โ $575Mโ
Fortinet โ Virtue AIโ