Confidential Β· 13 Aug 2026
π‘οΈ Daily Cybersecurity Briefing β 2026-08-13 (Thursday)¶
Window: last 24β48h (August 12β13). Severity: π΄ CRITICAL Β· π‘ HIGH Β· π’ MEDIUM.
Threat level GUARDEDVictims L30D 133Top actor QilinM&A L30D $37M
πΌ M&A ACTIVITY¶
No new deals confirmed with an August 12β13 announcement date. The mid-August post-Patch-Tuesday lull continues.
L30D summary (Jul 14 β Aug 13): ~34 named deals tracked; total disclosed capital exceeds $5.1B. Dominant by value: Visa/BioCatch ($2.4B β behavioral biometrics AI for fraud prevention, largest cybersecurity acquisition of 2026 YTD); Permiso/Okta (~$200M β identity threat detection); ThreatLocker $190M Series D; Glow $180M Series A (endpoint protection); Cathedral $160M Series A (agentic security); Zenity $125M Series C (AI-agent governance). The AI-agent security theme is the clear capital concentration point: 10+ of the 34 deals touch agent security, NHI, or autonomous-AI governance. Accenture/Dragos/runZero/NetRise $4.175B OT megadeal (announced Jun 18) remains in the expected AugustβSeptember close window; no confirmation yet. SecurityWeek M&A tracker
β οΈ CRITICAL BREACHES & INCIDENTS¶
CEVA Logistics β 8 European warehouses breached; Valve/Steam, banks, and retailers in blast radiusCriticalA cyberattack on July 29, 2026 hit at least eight CEVA Logistics warehouses across Europe, disrupting order processing systems and leaking customer data. CEVA notified customers August 1; the incident became publicly known via reporting on August 10β11. Exposed data includes names, addresses, phone numbers, emails, and order data for clients including Valve (Steam hardware customers notified), Ajax, and multiple banks and retailers. The Dutch Data Protection Authority is actively investigating. No payment or credential data was affected; no ransomware group has been attributed. One breach at a single logistics provider rapidly cascaded into a multi-sector customer data event β the classic third-party supply-chain amplification pattern. TechCrunch Β· The Register Β· FreightWaves
Wesco International / ExfilSquad β 2.6M cloud CRM records confirmed stolen; supply-chain phishing riskHighOn July 26, 2026, data extortion group ExfilSquad breached Wesco's cloud CRM environment. ExfilSquad distributed the data via torrents on August 7; Wesco confirmed the incident on August 11 after BleepingComputer reported. Stolen data includes customer lists, shipment details, and project pricing. No ransomware encryption and no internal IT disruption; Wesco says financial data is unaffected. The customer-list + pricing data combination is purpose-built for invoice fraud and spear-phishing across Wesco's distribution ecosystem (electronics, utilities, infrastructure clients). SC Media Β· BleepingComputer Β· DeXpose
Ethics (new group) debuts with 3 simultaneous DLS postings on August 12HighA ransomware operation calling itself Ethics appeared on August 12 with three victims: Philadelphia Insurance Companies (major US P&C insurer), BerlinerLuft Technology GmbH (German industrial HVAC manufacturer), and Holstrom, Block & Parke (US family law firm). Estimated attack dates range from September 2025 to June 2026. Ethics is a new entrant; RansomLook lists it as first seen August 12. π₯ DLS claims β attribution and scope unverified; verify before treating as confirmed breaches. DeXpose Β· RansomLook
Qilin / B Wright Drywall, Canada β construction firm added to Qilin DLS, Aug 11β13MediumQilin posted B Wright Drywall, a Canadian construction company, in its most recent update cycle. π₯ DLS claim β unverified. Stade FranΓ§ais Aug 15 deadline is now two days away; player passport/ID data published as evidence; no public confirmation of payment. ransomware.live / Qilin Β· RedPacket Security
π CRITICAL VULNERABILITIES¶
CVE-2026-20349 (Cisco ASA/FTD) β PATCH NOW AVAILABLE; FCEB deadline is August 14 (TOMORROW)CriticalCisco published hotfixes on August 11β12 for all affected release families: ASA 9.16 through 9.24 and FTD 7.0 through 10.0 (separate packages per hardware platform). Yesterday's advisory noted no patch; that has changed. FCEB agencies under the August 14 CISA KEV deadline should apply the hotfix immediately β the "disable RAVPN" workaround is no longer the only option. Exploitation remains active (unauthenticated remote DoS via crafted SSL VPN HTTP request; forces device reload). No attribution disclosed. Commercial organisations using Cisco ASA/FTD for remote access should patch on an emergency schedule. Cisco PSIRT Β· SecurityWeek Β· BleepingComputer
CVE-2026-59310 (VMware vCenter, CVSS 9.8) β Active exploitation in 47 countries; 361 compromised IPs; reverse-SSH persistenceCriticalThreat actors are actively exploiting Broadcom's July 29 patch for CVE-2026-59310, a directory-traversal vulnerability that enables arbitrary code execution on the vCenter host. Attack chain: path traversal exploit β malicious cron job β reverse_ssh open-source tunnel to attacker C2. First exploitation observed August 3 (five days post-patch); 343 of 361 victim IPs appeared by August 5. Broadcom advisory VMSA-2026-0006; no workaround β patching is the only remediation. 47-country spread and tight exploitation-to-compromise timeline signal a co-ordinated campaign, not opportunistic scanning. The Hacker News Β· SC Media Β· Rapid7
π¨ INTELLIGENCE AGENCY ALERTS & POLICY¶
No new CISA advisories or KEV additions since August 11 (Gunra AA26-222A, three-CVE KEV addition). Coverage from the August 11β12 briefings stands. Key pending actions: CVE-2026-20349 FCEB patch deadline August 14 and CVE-2026-72898 Metabase BOD β confirm remediation status today.
π THREAT ACTOR & CAMPAIGN ACTIVITY¶
Qilin β Stade FranΓ§ais Aug 15 deadline; 48 hours to data publicationCriticalQilin's countdown on the Stade FranΓ§ais Paris posting expires August 15. The group has published 18 photographs as proof, including apparent passports and ID cards of players. Club activated crisis management; filed complaint with French authorities; no payment confirmed. This is the highest-profile European sports organisation hit by Qilin this quarter. Verify on August 15 whether data is published. Generation NT Β· CyberAttaque.org
Ethics β New ransomware group emerges with 3-victim debutHighSee Breaches section. Worth watching: simultaneous multi-victim launch is a tactic used by newer groups attempting to establish credibility quickly. The victim spread (US insurance, German industrial, US legal) across three different sectors and two countries signals either a single campaign thread or a multi-affiliate structure from day one.
DeadLock β Blockchain-backed C2 hardens new group against law enforcement takedownHighDeadLock is operating with a decentralised infrastructure using blockchain-backed services for C2 communications and data-leak site operations. This eliminates the central server takedown vector that disrupted LockBit (Feb 2024) and ALPHV (Dec 2023). A technically sophisticated approach for a new group β indicates the lesson from high-profile law enforcement operations is being institutionalised by emerging actors. BleepingComputer
AnMed Health / TheGentlemen β clinical teams have full EHR access; FBI + SLED investigations continueMediumRecovery progress: clinical teams now have read/write EHR access; patient calls to physician offices resumed Wednesday. The group's Facebook hijack tactic (used to broadcast ransom demands directly to patients) has not been replicated by other groups yet, but the operational playbook is now documented. Negotiations status: not publicly disclosed. 6TB data claim remains unverified. The Record Β· CySecurity News
π GEOPOLITICS¶
Analyst lens: how this week's cyber activity maps to state strategy. Defense Β· cyber Β· economics.
Operation Matryoshka: Russia has industrialised AI-assisted election interference against EU statesCriticalGerman security authorities confirmed August 12 that a Russian-directed campaign distributed 180+ fabricated posts and 20 deepfake videos impersonating BBC and ARD broadcasting, targeting all mainstream parties ahead of September 2026 state elections. The operation, centrally directed from Russia through shell companies, aims to fracture the CDU/SPD/Green/FDP coalition and is explicitly sparing the AfD. The structural read: Russia is running industrial-scale cognitive warfare against NATO's most powerful European member at the regional level, not just the federal level. For executives: German political volatility directly affects NATO cohesion and EU regulatory posture β factor this into Q4 scenario planning. EUObserver Β· EUNews
Senate 86-11 passes Sanctioning Russia and Iran Act (Aug 7) β 100% tariff authority on Russian energy buyers, 6,800+ designations codifiedHighThe Lindsey O. Graham Sanctioning Russia and Iran Act of 2026 passed with strong bipartisan support. It codifies ~6,800 existing designations, creates 100% tariff authority on the top five buyers of Russian oil/gas, and includes Iran pressure provisions tied to the ongoing US-Iran armed standoff. The bill now goes to the House. The structural read: congressional intent to lock in Russia pressure beyond executive discretion; bipartisan floor for secondary-sanctions enforcement means even a policy pivot in the White House faces resistance. European energy supply chains exposed to Russian gas should scenario-plan the 100% tariff case now. NBC News Β· UPI
VMware vCenter exploitation at scale β 47 countries, 361 IPs in 5 days β maps to state-sponsored pre-positioningHighThe exploitation cadence (patch disclosure Jul 29, first attacks Aug 3, 343 victims by Aug 5) and geographic breadth (47 countries) are inconsistent with opportunistic criminal scanning β the timeline is too compressed and the targeting too wide. vCenter is the control plane for entire virtualisation estates. This profile matches the pre-positioning campaign doctrine documented by CISA for Salt Typhoon (telecom) and Volt Typhoon (critical infrastructure) β broad access established ahead of potential future activation. No attribution confirmed. The Hacker News Β· Rapid7
China-US diplomatic buffer: Xi's September 24 Washington visit creates a 6-week restraint windowMediumBeijing is running a dual-track posture: deploying measured economic countermeasures to US technology and forced-labour restrictions while preserving the September 24 summit as a de-escalation mechanism. Chinese APT groups are expected to hold kinetic operations during this window but will continue intelligence collection. The structural implication for cyber defenders: expect continued reconnaissance and pre-positioning by PRC-linked actors through September; post-summit risk posture should be assessed before October. Mondaq Sanctions Update Β· EclecticIQ
CEVA supply-chain breach illustrates the logistics-vector for targeting commercial intelligenceHighThe attack on eight CEVA warehouses cascaded into customer-data exposure for banks, retailers, and gaming platforms across Europe. The attack pattern β breach a logistics intermediary to harvest commercial customer networks β is increasingly attractive to state-adjacent actors needing to map Western commercial relationships without targeting the endpoint organisations directly. The Dutch DPA investigation establishes a regulatory precedent for EU third-party logistics breach response that will affect GDPR enforcement posture going forward. TechCrunch Β· Infosecurity Magazine
M&A activity
Socure β Fravityβ
Brinqa β PlexTracβ
Munich Re (via HSB) β $575Mβ
Fortinet β Virtue AIβ