Confidential Β· 12 Aug 2026
π‘οΈ Daily Cybersecurity Briefing β 2026-08-12 (Wednesday)¶
Window: last 24β48h (August 11β12). Severity: π΄ CRITICAL Β· π‘ HIGH Β· π’ MEDIUM.
Threat level GUARDEDVictims L30D 129Top actor QilinM&A L30D $37M
πΌ M&A ACTIVITY¶
No new deals confirmed with an August 11β12 announcement date. The Black Hat / Patch Tuesday window has paused deal flow; the next activity wave is expected mid-to-late August.
L30D summary (Jul 13 β Aug 12): 34 named deals tracked; total disclosed capital exceeds $5.1B. Top five by value: Visa/BioCatch ($2.4B β behavioral biometrics AI for fraud), Cyera/Oasis Security (~$1B LOI β NHI + data security platform merge), Okta/Permiso (~$200M β identity threat detection), ThreatLocker $190M Series D, Glow $180M Series A (endpoint protection). AI-agent security (Zenity $125M, Act Security $60M) and non-human identity (Cyera/Oasis LOI) are the capital concentration points β 12+ of 34 deals touch this theme. The Accenture/Dragos/runZero/NetRise $4.175B OT megadeal (announced June 18) is in the expected AugustβSeptember close window; no confirmation yet. SecurityWeek M&A tracker
β οΈ CRITICAL BREACHES & INCIDENTS¶
AnMed Health/TheGentlemen β Facebook page hijacked to display ransom demands; 6TB data claim; partial recovery under wayCriticalTwo weeks after the July 26 cyberattack on AnMed Health System (South Carolina/Georgia, 106 facilities), TheGentlemen has now hijacked the health system's Facebook page and is using it to broadcast ransom demands directly to patients and the public. The group claims 6TB of data stolen, including records relating to sexual assault, mental health, abortions, and sexual harassment investigations β the most sensitive categories of protected health information. On the recovery side, AnMed reports clinical teams now have full EHR read-write access, and patients can again call physicians' offices directly from Wednesday morning. FBI and South Carolina SLED investigations continue. Microsoft tracks TheGentlemen as Storm-2697, an offshoot from a Qilin payment dispute in mid-2025, now attributed with approximately 10% of global ransomware activity. π₯ DLS attribution β verify before treating as confirmed. The Record Β· Healthcare Dive Β· HIPAA Journal
Pennsylvania AG's Office/INC Ransom β attribution confirmed; SSNs stolen; AG refuses to payHighThe Pennsylvania Attorney General's Office has confirmed that INC Ransom is responsible for the August 11 ransomware attack that disrupted 1,200 staff. AG Dave Sunday confirmed the office refused to pay and is restoring systems; Social Security numbers and medical information are among the data confirmed stolen. Courts have granted extensions on affected cases. No data-publication date disclosed by INC Ransom. INC continues its SonicWall SMA 1000 CVE-2026-15409/15410 campaign across parallel targets β same group, same campaign. The Record Β· SecurityWeek
Morguard Corporation/Helix β 160GB; Canadian real estate firm in failed negotiations with emerging groupHighHelix (emerged July 2026), an extortion group that uses voice phishing and Microsoft OAuth abuse to harvest SharePoint data without deploying custom malware, posted Morguard on its DLS on August 7. Morguard is a major Canadian real estate investment and management firm. Negotiations began then stalled; Helix reports Morguard "reached out, took extensions, then ignored the negotiation." Data publication is expected imminently. 160GB claimed. Helix is a new entrant operating without traditional ransomware deployment β pure data-exfiltration extortion via OAuth token theft. π₯ DLS claim β verify before treating as confirmed. ransomware.live Β· DeXpose Β· SOCRadar
π CRITICAL VULNERABILITIES¶
August 2026 Patch Tuesday (Aug 11): ~400 CVEs, 3 zero-days β LegacyHive patched at last (CVE-2026-62832, day 29)CriticalMicrosoft's August release closes approximately 400 vulnerabilities across 69 product families, with 3 zero-days. The headline item: CVE-2026-62832 (Windows User Profile Service EoP) is the official patch for the LegacyHive PoC dropped by Nightmare Eclipse on July 14 β day 29 of exploitation window with only the 0patch interim micropatch available. Also notable: CVE-2026-68820 (Windows Ancillary Function Driver for WinSock use-after-free; exploited in wild; CISA KEV Aug 11), CVE-2026-65665 (SharePoint Server RCE CVSS 8.8, completes the Pwn2Own Berlin chain against on-prem SharePoint SE/2019/2016), and CVE-2026-62893 (Windows Deployment Services TFTP Server RCE CVSS 9.8, unauthenticated). If you applied the July 14 SharePoint JWT-auth fix (CVE-2026-55040) already, the chain is broken at the auth stage; applying today's RCE component closes the window entirely. BleepingComputer Β· Qualys Β· Rapid7
CVE-2026-20349 (Cisco ASA/FTD) β CISA KEV Aug 11; actively exploited; no patch availableCriticalCisco has confirmed active in-the-wild exploitation of CVE-2026-20349, a heap-inspection vulnerability in the Remote Access SSL VPN service of Cisco Adaptive Security Appliance and Firewall Threat Defense. An unauthenticated attacker sends crafted HTTP requests causing device reload (DoS). Cisco PSIRT is aware of attacks but has not disclosed attribution or targeted sectors. Critically, no patch is yet available; Cisco states fixes will be released later this month. CISA KEV federal deadline applies β FCEB agencies must apply mitigations by the deadline or disable the affected feature. Workarounds: disable RAVPN service if not required, or implement rate limiting on SSL VPN. Cisco PSIRT Β· CVE lookup
CVE-2026-58231 (SAP Commerce Cloud, CVSS 10.0) β August SAP Patch Day; 5 critical, including complete auth bypassCriticalSAP's August 2026 Security Patch Day (also Aug 11) included 28 new notes plus 2 updates. The critical floor-item is CVE-2026-58231 (CVSS 10.0), an improper authorization flaw in SAP Commerce Cloud (Data Hub Adapter) allowing unauthenticated complete account takeover. Second priority: SAP Note #3765948 (CVSS 9.9) patches a vulnerable servlet in SAP Manufacturing Integration and Intelligence (MII) that allows low-privileged attackers to execute arbitrary commands on the underlying OS β full infrastructure compromise. Also patched: unauthenticated memory corruption in the ABAP DIAG protocol path in SAP NetWeaver. SAP has not indicated in-the-wild exploitation of any of these issues. Priority for SAP Commerce Cloud and SAP MII administrators: treat as emergency. Pathlock Β· SecurityWeek
CVE-2026-72898 (Metabase, CVSS 10.0) + CVE-2026-68820 (Windows AFD) β CISA KEV additions Aug 11HighCISA added three CVEs to KEV on August 11. Metabase CVE-2026-72898 (unauthenticated SQL injection via password-reset endpoint, CVSS 10.0) was actively exploited August 2β8 against Framework laptops, n8n (136 customer records), Tally, and Kilo Code before Metabase patched it β FCEB BOD deadline applies. Windows AFD CVE-2026-68820 (use-after-free, exploited in wild) is patched in today's Patch Tuesday. Fixes for Metabase: upgrade to v58.24, v59.21, v60.17, v61.11, v62.9, or v63.5. CISA KEV Β· Wiz Β· BleepingComputer
π¨ INTELLIGENCE AGENCY ALERTS & POLICY¶
OpenAI launches GPT-5.6-Cyber via Daybreak Red β commercially gated offensive-AI for vetted security firmsHighOpenAI on August 10 expanded its Daybreak cybersecurity program into two tiers: Daybreak Blue (frontier general models including GPT-5.6 Sol, for approved defenders) and Daybreak Red (GPT-5.6-Cyber, gated behind tighter vetting, for authorized vulnerability research, exploit validation, and security testing). GPT-5.6-Cyber completed 95% of advanced cybersecurity prompts β exploit chain development, authentication bypass, privilege escalation β in internal evaluation; the standard GPT-5.6 Sol with default protections answered only 1.5% of the same set. The model independently found and disclosed two previously-unknown Chrome V8 engine vulnerabilities (patched by Google as CVE-2026-15903). This is a structural shift: offensive-capable AI models are now commercially available to vetted firms, not just state-sponsored actors with in-house capability. OpenAI Daybreak Β· Axios Β· Neowin
Dragos Q2 2026 industrial ransomware report: 1,140 OT incidents (+12% QoQ); shift to pure data-theft extortionMediumDragos published its Q2 2026 industrial ransomware analysis on August 11. Key finding: 1,140 ransomware incidents affected industrial organisations in Q2 2026, up 12% from 1,020 in Q1. Manufacturing accounted for 747 victim organisations; 117 incidents targeted engineering services and ICS equipment manufacturers. Critically, Dragos found no case in Q2 where ransomware operators reached Stage 2 of the ICS Cyber Kill Chain or directly manipulated control systems β operational disruption came from IT/virtualisation systems encryption, not OT manipulation. The most significant tactical shift: extortion is moving away from encryption toward pure data-theft, meaning restored systems do not end the extortion exposure. Dragos Β· Help Net Security
π THREAT ACTOR & CAMPAIGN ACTIVITY¶
TheGentlemen (Storm-2697) β AnMed Health Facebook hijack; 6TB; now 10% of global ransomware activityHighThe Facebook hijacking is a new operational tactic for TheGentlemen: using the victim's own public communications channel to pressure payment and amplify public visibility of the breach. Microsoft's Storm-2697 tracking connects the group to a Qilin payment dispute in mid-2025; independent research attributes approximately 10% of 2026 global ransomware activity to the group. With AnMed's 10 facilities still closed two weeks post-attack, this is the highest-impact healthcare incident of 2026 by operational disruption. The group also maintains active DLS claims against AIMS Group (UAE) and Canopy Support Services (Canada) from August 10. π₯ DLS claims. The Record Β· DeXpose
Qilin β Stade FranΓ§ais Paris Aug 15 deadline (3 days); new Q2 stats: 335 L3M, 546 YTDHighStade FranΓ§ais Paris (French rugby club) faces a ransomware deadline August 15 with player passport and identity documents already leaked. Data publication is likely Saturday if no payment. Qilin holds the Tier-1 leaderboard #1 position with 335 victims in the last 3 months and 546 year-to-date. The group continues targeting manufacturing (Astro Electroplating, Chung Tai Shin Chemical Industry) alongside opportunistic healthcare and services targets. π₯ DLS claims. The Record Β· ransomware.live
Helix β new OAuth/SharePoint extortion group emerging; Morguard (Canada) and Uber both claimedHighHelix is a data-extortion-only group that emerged July 2026 using a technique distinct from traditional ransomware: voice phishing, Microsoft OAuth token theft, and direct SharePoint repository exfiltration β no file encryption, no custom malware deployed. Victims lose data but not operational access; the leverage is pure publication threat. Helix has now claimed Morguard (real estate, Canada) and Uber. The OAuth-based initial access path is notable: it does not require credential compromise of a domain account, only an OAuth consent grant from a legitimate user. Defenders: audit OAuth app registrations and third-party SharePoint access grants. π₯ DLS claims. SOCRadar Β· DeXpose
INC Ransom β PA AG confirmed; SonicWall campaign continues; 885+ victims cumulativeMediumINC Ransom's SonicWall SMA 1000 CVE-2026-15409/15410 campaign (CVSS 10.0/7.2) is producing confirmed government victims: the Pennsylvania AG joins Louisville Bar Association (Aug 8) and ATMS & Co. (Aug 10) in the current campaign window. TOTP seed theft confirmed as a tactic β patching alone is insufficient if seeds were exfiltrated before patch. SecurityWeek Β· SC Media
RansomHub β 50+ days at zero new victims; status unresolvedMediumRansomHub has posted no new DLS victims for more than 50 days (842 cumulative). No law enforcement action, exit announcement, or confirmed rebrand. Black Kite 2026 Report
π GEOPOLITICS¶
Analyst lens: how this week's cyber activity maps to state strategy. Defense Β· cyber Β· economics.
OpenAI's commercial release of GPT-5.6-Cyber through Daybreak Red marks the point at which nation-state-grade offensive AI capability becomes available to any sufficiently vetted private-sector actor β the entry cost for advanced exploitation research has just compressed by an order of magnitude.CriticalA model that completes 95% of advanced exploit-chain, authentication-bypass, and privilege-escalation prompts β and independently found two previously unknown Chrome V8 zero-days β is not a research curiosity; it is an asymmetric capability shift. The vetting gate (Daybreak Red tier) is a policy instrument, not a technical control: the model exists, and the barrier to adversary acquisition is now organisational, not architectural. State actors with financial or intelligence resources to front legitimate security firms can access this tier. The practical consequence for defenders: AI is accelerating the offense/defense cycle simultaneously, but defensive tool-building lags offensive use by 12β18 months in every prior technology cycle. OpenAI Β· Axios
Cisco CVE-2026-20349 with no patch available and CISA KEV status exposes a structural gap in the US government's own vulnerability-response framework: federal agencies are required to remediate within the BOD deadline, but the vendor has not shipped a fix.HighThis situation β an actively exploited zero-day with a federal remediation deadline and no patch available β forces agencies to choose between accepting risk (leaving the VPN active) and operational disruption (disabling RAVPN). For enterprises, this is the same choice. The pattern is not new (Fortinet, Ivanti, and Palo Alto have all produced similar situations in the 2024β2026 cycle), but the frequency is increasing: attackers are deliberately targeting firewall and VPN appliances specifically because patch cycles are long and the devices sit at the network perimeter. Cisco PSIRT
The Accenture/Dragos/runZero/NetRise $4.175B deal entering its close window (AugustβSeptember) is the largest consolidation in OT security history, and its strategic logic maps directly to the Iran water-utility attacks and the Polish heat plant cellular compromise disclosed last week: enterprise IT-security buyers are now priced for OT threat coverage they cannot currently deliver.HighAccenture is acquiring $208M ARR / 53% YoY growth at roughly 20x revenue β a premium that reflects not just Dragos's software but the speed at which critical infrastructure operators are being forced to buy OT security expertise at scale. If the deal closes this month, it establishes a pricing floor for the entire OT security M&A market. SecurityWeek Β· Industrial Cyber
Dragos's Q2 2026 finding that ransomware operators did not achieve direct ICS manipulation in any of 1,140 industrial incidents is a double-edged message: the ICS Kill Chain Stage 2 threshold has not been crossed at scale, but the shift to pure data-theft extortion means that the threshold no longer needs to be crossed to produce severe operational and reputational consequences.HighA manufacturing plant that restores encrypted systems in 48 hours still faces months of data-leak-driven extortion if the attacker exfiltrated engineering drawings, supplier contracts, or employee PII. The "OT air-gap is sufficient" assumption β already challenged by the Polish cellular attack β is now challenged from the other direction: you don't need to touch the PLC if you can freeze the management layer and hold the data. Dragos Β· Help Net Security
M&A activity
Socure β Fravityβ
Brinqa β PlexTracβ
Munich Re (via HSB) β $575Mβ
Fortinet β Virtue AIβ