Skip to content

Confidential Β· 11 Aug 2026

πŸ›‘οΈ Daily Cybersecurity Briefing β€” 2026-08-11 (Tuesday)

Window: last 24–48h (August 10–11). Severity: πŸ”΄ CRITICAL Β· 🟑 HIGH Β· 🟒 MEDIUM.

Threat level GUARDEDVictims L30D 130Top actor QilinM&A L30D $125M

πŸ’Ό M&A ACTIVITY

No new cybersecurity deals confirmed with an August 10–11 announcement date. The Black Hat USA 2026 window (Aug 3–8) concentrated the recent deal flow; this week is quieter.
L30D summary (Jul 12 – Aug 11): 34 named deals tracked, total disclosed capital exceeds $4.8B. Biggest five: Visa/BioCatch ($2.4B β€” behavioral biometrics AI for fraud), Cyera/Oasis Security (~$1B LOI β€” NHI + data security), Okta/Permiso (~$200M β€” identity threat detection), ThreatLocker $190M Series D, Glow $180M Series A. Runtime security is the latest sub-theme to attract large capital: Oligo Security ($60M Series C, Aug 4, Ballistic Ventures/Lightspeed β€” cloud workload and AI runtime protection) joins Cathedral ($160M), Zenity ($125M AI-agent governance), and Obsidian Security ($85M NHI/SaaS) as the Black Hat cohort. NHI and AI-agent security still account for 12+ of 34 L30D deals β€” the dominant capital theme of H2 2026. SecurityWeek M&A tracker

⚠️ CRITICAL BREACHES & INCIDENTS

TheGentlemen/AnMed Health β€” 83 of 106 healthcare facilities closed; 72-hour ransom deadline activeCriticalTheGentlemen claimed responsibility on their dark-web leak site August 10, identifying the July 26 cyberattack at AnMed Health System (106 facilities, upstate South Carolina and northeast Georgia). Eighty-three facilities closed at peak including oncology, radiation, infusion, and imaging services; 10 locations still shuttered a week post-attack. ERs remained open. TheGentlemen's DLS post issued a 72-hour payment demand. FBI and South Carolina SLED are investigating. This is TheGentlemen's most operationally disruptive healthcare attack to date β€” larger in facility-count than any prior campaign claim. 🟨 Attribution via DLS β€” verify before treating as confirmed. Healthcare IT News Β· Healthcare Dive Β· HIPAA Journal
Unlimited Technology Systems β€” 3,803,750 patients; largest US healthcare breach of 2026 YTDCriticalOhio-based healthcare revenue cycle management firm disclosed via HHS OCR late July 2026 that a hacking incident October 5–10, 2025 (detected October 19) exposed records of 3.8M individuals across downstream healthcare clients. Data stolen: names, SSNs, DOBs, email/mailing addresses, phone numbers, government IDs, insurance cards, health insurance policy numbers, medical record numbers, and diagnosis data. No threat actor has claimed the intrusion. This eclipses all other 2026 healthcare disclosures by victim count. SecurityWeek Β· Security Affairs
Pennsylvania Attorney General's Office β€” ransomware attack; 1,200 staff affected (August 11)HighA ransomware attack struck the Pennsylvania AG's communications systems this morning. 1,200 staff are affected; courts have granted extensions on pending cases. No threat actor has claimed the attack; investigation ongoing. The Record
Storm-1175 (China-linked) / StormEncryptor β€” MSP supply chain ransomware via N-central auth bypassHighMicrosoft Threat Intelligence reports that Storm-1175, a China-linked financially motivated actor formerly affiliated with the Medusa RaaS, has built and deployed a new custom C++ ransomware strain called StormEncryptor (.encrypted extension). Initial access vector: CVE-2026-18577 (N-able N-central authentication bypass, CISA KEV August 3) exploited as a zero-day before the patch landed. Post-compromise chain: AnyDesk/SimpleHelp for remote access, Mimikatz for credential dumping, Advanced IP Scanner for network mapping, then StormEncryptor deployment. MSP-hosted N-central instances are the target; downstream clients across APAC, Europe, and the Americas are affected. The Hacker News Β· BleepingComputer Β· Rapid7
TanStack / Mistral AI / UiPath β€” fresh supply chain attack disclosed (August 11)HighA software supply chain attack affecting TanStack (popular open-source React frontend library), Mistral AI, and UiPath was disclosed August 11. The combination of targets β€” open-source UI layer, AI model serving, and enterprise automation β€” suggests the attacker sought to reach organizations running AI-powered automation workflows. Attack vector, scope, and threat actor attribution are not yet confirmed. SecurityWeek πŸŸ₯ Breaking β€” verify scope before actioning.
Poland hidden ICS attack disclosed β€” heat plant; first known private cellular network attack pathHighPolish cybersecurity authorities revealed August 10 that a cyberattack on a combined heat and power plant occurred during winter and was kept hidden until now. The attack threatened the heating supply to tens of thousands of residents. Investigators identified the first known use of a private cellular data network (4G/5G) as the pathway into the industrial control system β€” bypassing the IT/OT network segregation model that underpins most OT security architectures. The Record

πŸ”“ CRITICAL VULNERABILITIES

August 2026 Patch Tuesday (today) β€” SharePoint unauthenticated RCE chain completed; ~533 CVEs across 69 packagesCriticalMicrosoft's August Patch Tuesday releases today (10:00 AM PDT). The headline is the completion of Rapid7's Pwn2Own Berlin 2026 two-vulnerability SharePoint chain: CVE-2026-55040 (JWT auth bypass, CVSS 9.1, patched July 14) combined with today's second embargoed RCE CVE creates a fully unauthenticated remote code execution path against on-premises SharePoint Server SE, 2019, and 2016 Enterprise. Organizations that applied the July update have broken the chain at the auth stage; the August patch closes the RCE component entirely. Additional critical items expected today: DNS Server RCE (unauthenticated), RD Gateway RCE, Hyper-V guest-to-host escape, Windows kernel LPE. Volume ~533 CVEs (24 Critical) β€” a significant reduction from July's record 621. ByteIota Β· Rapid7 Β· Help Net Security
LegacyHive Windows zero-day β€” potential official patch today; 0patch interim mitigation availableCriticalThe Windows User Profile Service LPE (day 28 unpatched, no CVE, no official advisory) dropped by researcher Nightmare Eclipse hours after July Patch Tuesday may receive an official CVE and fix in today's release. Advance notice for August lists a "Windows User Profile Service Vulnerability" β€” multiple analysts read this as LegacyHive. Affects all fully-patched Windows 10 (v2004+), Windows 11, and Windows Server. 0patch (ACROS Security) micropatch remains the only available protection until confirmation. Confirm against the Microsoft Security Update Guide at MSRC. BleepingComputer Β· SecurityWeek
CVE-2026-63077 (JetBrains TeamCity, CVSS 9.8) β€” federal deadline Aug 8 passed; exploitation ongoingHighUnsafe deserialization in TeamCity On-Premises allowing unauthenticated RCE was added to CISA KEV August 5 with a BOD 26-04 federal deadline of August 8. Deadline has now passed; exploitation against unpatched servers (pre-2026.1.3 / 2025.11.7) continues. Build-server compromise creates direct supply chain exposure. The Hacker News Β· SecurityWeek

🚨 INTELLIGENCE AGENCY ALERTS & POLICY

CISA/FBI/NSA/DC3/USSS/KNPA β€” #StopRansomware: Gunra (AA26-222A, August 10)CriticalSix agencies issued a joint advisory against Gunra ransomware, which emerged April 2025 as a Conti-derived double-extortion RaaS and launched a formal dark-web affiliate program ("Golden Community") in January 2026. Primary initial access: exploitation of Fortinet firewall CVE-2024-55591 and CVE-2025-24472. Novel defensive angle: Gunra's Linux ELF variants use a weak PRNG seeded with `srand(time(NULL))` β€” encryption keys are potentially recoverable from the timestamp seed. The South Korea KNPA co-signing signals concern over North Korean tool-sharing patterns identified in Gunra infrastructure. Critical infrastructure operators running unpatched Fortinet firewalls are the immediate priority. CISA AA26-222A Β· The Record Β· CyberScoop
Iran-linked OT attacks hit 12 US water utilities; Senate introduces $300M/year legislationHighWaterISAC and federal agencies confirmed Iran-backed actors conducted PLC/SCADA manipulation attacks against at least 12 US states' water and wastewater utilities, beginning with Minnesota (July 26–27, 30+ community systems). TTPs are consistent with Handala group ICS campaigns. Senate Democrats introduced legislation for $300M annually in water-sector cybersecurity funding plus expanded EPA regulatory authority in direct response. The Record Β· SecurityWeek
CISA KEV β€” Aug 10-11 additions expected this afternoonMediumPatch Tuesday days historically produce same-day KEV additions. Confirmed pre-window additions for context: CVE-2026-63077 (TeamCity, Aug 5), CVE-2026-9198 (IBM Langflow CVSS 9.8, Aug 4), CVE-2026-18577 (N-able N-central, Aug 3). Watch CISA KEV catalog for SharePoint and today's Patch Tuesday additions. CISA

🌐 THREAT ACTOR & CAMPAIGN ACTIVITY

TheGentlemen β€” AnMed Health DLS claim (Aug 10); 83 healthcare facilities; now the group's largest-impact incidentHighAttribution confirmed via leak-site claim. AIMS Group (UAE conglomerate) and Canopy Support Services (Canadian nonprofit) also posted Aug 10. The AnMed incident surpasses prior TheGentlemen healthcare attacks in operational disruption. πŸŸ₯ DLS claims β€” verify before treating as confirmed breaches. ransomware.live
Qilin β€” Stade FranΓ§ais Paris ransom deadline August 15; two new DLS victims August 10HighQilin posted Astro Electroplating (US manufacturing) and Chung Tai Shin Chemical Industry Co. (Taiwan chemicals) on August 10. Stade FranΓ§ais Paris (French rugby club) had player passport/identity documents leaked as proof-of-compromise; ransom deadline is August 15 β€” data publication imminent if unpaid. Qilin maintains the top leaderboard position. πŸŸ₯ DLS claims β€” verify. The Record Β· ransomware.live
INC Ransom β€” SonicWall campaign accelerating; ATMS & Co. (India) among Aug 10 victimsHighINC continues exploiting CVE-2026-15409/CVE-2026-15410 (SonicWall SMA 1000, CVSS 10.0/7.2). New tactic: actors calling victims posing as ransomware recovery consultants ("Andrew," a US number). TOTP seed theft confirmed β€” patching alone is insufficient if seeds were exfiltrated. 885+ cumulative victims. SecurityWeek Β· SC Media
Gunra RaaS β€” new entrant; Conti-derived; formal affiliate program since January 2026HighSee Intelligence Alerts section above. Gunra targets firewall-exposed networks, deploys cross-platform payloads (Windows and Linux ELF), and operates a Tor-based extortion portal. The decryptable PRNG flaw in Linux variants is a rare defensive opportunity β€” if you have Gunra-encrypted Linux systems, preserve the timestamp from the encryption event; keys may be recoverable. CISA AA26-222A
RansomHub β€” 45+ days at zero new victims; status still unconfirmedMediumRansomHub remains dormant with no new DLS postings for over 45 days (842 cumulative total). No law enforcement action, exit, or confirmed rebrand disclosed. Black Kite 2026 Report

🌍 GEOPOLITICS

Analyst lens: how this week's cyber activity maps to state strategy. Defense Β· cyber Β· economics.
Iran's confirmation as the actor behind OT attacks on 12 US states' water utilities is a structural escalation: this is no longer cyber activity on the Israel-adjacent theater β€” it is direct ICS targeting of the US homeland, using the Iran-Israel-US military conflict as cover for a deterrence-by-denial strategy against civilian infrastructure.CriticalThe Minnesota-first pattern (July 26–27) then spreading to Michigan, South Dakota, Georgia and beyond mirrors the scale of the 2021 Oldsmar, Florida water-plant attack, but across 30+ community systems simultaneously. PLC/SCADA manipulation β€” the same class of attack as Stuxnet and the 2021 Colonial Pipeline incident β€” against water utilities with minimal cyber defense is the adversary probing the floor on what Western publics will tolerate before civilian impact produces a political response. Senate's $300M/year legislation, if enacted, arrives years after the threat became operational. The Record Β· SecurityWeek
Poland's disclosure that attackers accessed an industrial control system via a private cellular (4G/5G) data network β€” rather than IT-OT lateral movement β€” invalidates the foundational assumption of OT security architecture: that physical network segregation protects OT environments from internet-reachable threats.HighThe IT/OT air-gap model assumes adversaries must first breach the IT network, traverse a DMZ, and then reach OT. A cellular uplink directly into the OT environment eliminates the entire IT path. For operators: audit all unauthorized or unmanaged cellular devices (including vendor-installed cellular IoT gateways and modem-embedded PLCs) within your OT environment. This vector was theoretical until this disclosure. The Record
The South Korea National Police Agency co-signing the Gunra ransomware advisory (AA26-222A) is a geopolitical signal as much as a threat-intel update: it reflects US-Korean intelligence coordination on what appears to be North Korean tool-sharing with criminal RaaS operators.HighThe North Korean tools-sharing finding in Gunra infrastructure β€” if confirmed β€” would extend the pattern of DPRK simultaneously running state-directed cyber operations (Lazarus/Kimsuky) and providing offensive tooling to criminal operators for plausible-deniability financial crime. The January 2026 affiliate program launch ("Golden Community") coincides with the period of peak DPRK cryptocurrency theft ($1.3B stolen 2024). CISA AA26-222A Β· The Record
The TanStack/Mistral AI/UiPath supply chain attack targets the exact combination of technologies that enterprise AI-automation stacks run on: an open-source UI library, an AI model provider, and an enterprise workflow-automation platform.HighAn attacker who can compromise packages at all three layers simultaneously can inject malicious AI model behavior, intercept automation decisions, or exfiltrate data from automated workflows without triggering alerts at any single layer. This is a higher-order attack: not targeting end-user systems but the orchestration layer of AI-driven business processes. The security industry does not yet have standardized detection coverage for AI workflow injection at the package dependency level. SecurityWeek
Threat actors
1 Β· Qilin546 YTD
2 Β· The Gentlemen335 YTD
3 Β· Akira228 YTD
4 Β· DragonForce248 YTD
M&A activity
Socure β†’ Fravityβ€”
Brinqa β†’ PlexTracβ€”
Munich Re (via HSB) β†’ $575Mβ€”
Fortinet β†’ Virtue AIβ€”