Skip to content

Confidential Β· 14 Aug 2026

πŸ›‘οΈ Daily Cybersecurity Briefing β€” 2026-08-14 (Friday)

Window: last 24–48h (August 13–14). Severity: πŸ”΄ CRITICAL Β· 🟑 HIGH Β· 🟒 MEDIUM.

Threat level GUARDEDVictims L30D 130Top actor QilinM&A L30D $94.5M

πŸ’Ό M&A ACTIVITY

No new acquisitions or funding rounds announced specifically on August 13–14. SecurityWeek's July 2026 M&A Roundup (21 deals) published August 13 confirms several transactions worth noting:
Cyera β†’ Oasis Security (~$1B) confirmedMediumThe LOI tracked July 28 has closed. Cyera (data security posture management) acquires Oasis Security (non-human identity governance), combining DSPM with NHI protection for AI agents and service accounts. Largest NHI deal of 2026. SecurityWeek M&A Roundup July 2026
Infoblox β†’ KentikMediumDNS and network intelligence platform merged with real-time traffic visibility for hybrid-cloud resilience. Terms undisclosed. SecurityWeek
A Security $37M Series BMediumAutonomous offensive security platform (continuous real-world pen testing via AI agents). SecurityWeek
Tenet Security $6M seedMediumStealth-mode network security platform exits stealth. SecurityWeek
L30D summary (Jul 15 – Aug 14): 36+ named deals; total disclosed capital exceeds $5.5B. Dominant by value: Visa β†’ BioCatch ($2.4B, behavioural biometrics); Cyera β†’ Oasis Security (~$1B, NHI/DSPM); Permiso β†’ Okta (~$200M, identity threat detection); ThreatLocker $190M Series D; Glow $180M Series A; Cathedral $160M Series A; Zenity $125M Series C. AI-agent governance, NHI protection, and autonomous offensive security are the three clearest capital concentration themes this month; 12+ of the tracked deals directly target agent security or autonomous AI. SecurityWeek M&A tracker

⚠️ CRITICAL BREACHES & INCIDENTS

LiteLLM supply chain attack β€” 153GB credentials, 2,488 corporate domains, AI infrastructure exposedCriticalIn March 2026, threat actor TeamPCP first compromised open-source security scanner Trivy on March 19 to steal LiteLLM's PyPI publishing tokens, then pushed two malicious LiteLLM releases (1.82.7 and 1.82.8) to PyPI on March 24. The packages ran a credential stealer on every Python invocation, harvesting cloud keys, access tokens, AI provider API keys, and CI/CD secrets from 433,909 files across 2,488 corporate domains. Hudson Rock's analysis (published August 13) links the archive to NVIDIA, Volkswagen, Microsoft, FedEx, S&P Global, John Deere, BT Group, ServiceNow, and Epic Games. This is part of a multi-ecosystem campaign: TeamPCP has now breached GitHub Actions, Docker Hub, npm (CanisterWorm), OpenVSX, and PyPI. NHS England Digital issued a cyber-alert for affected organisations. 🟨 Confidence: attack is confirmed; full victim list still being mapped. SecurityWeek Β· Help Net Security Β· Datadog Security Labs Β· NHS England Digital
Clop claims Fiserv (Aug 12) and FIS Global (Aug 5) β€” twin fintech DLS strikesCriticalClop posted Fiserv (Milwaukee-based payment processing and banking software, clients include thousands of banks and credit unions) on its DLS August 12. Separately, Clop listed FIS Global (Jacksonville-based, one of the world's largest financial technology companies) on August 5, claiming 874GB of exfiltrated data. Neither company has confirmed a breach or data theft. The DLS listings reference project files, CAD data, and Windchill-related materials; Clop has a documented pattern of listing large financial-sector names to create payment pressure, sometimes without successful exfiltration. πŸŸ₯ DLS claims β€” attribution and scope unverified; verify before treating as confirmed breaches. DeXpose β€” Fiserv Β· DeXpose β€” FIS Global Β· HookPhish
Trezor hardware wallets β€” 14,000 customers' PII exposed via ShipMonk fulfilment breachHighTrezor disclosed that a breach at its shipping and fulfilment partner ShipMonk exposed personal data of approximately 14,000 customers. Exposed fields include names, shipping addresses, email addresses, and order details. No private keys, wallet seeds, or financial data were exposed; there is no risk of crypto-asset compromise from this breach. The logistics-provider-as-attack-vector pattern (analogous to CEVA Logistics last week) is now established as a repeatable path into consumer hardware companies. BleepingComputer
Qilin β€” D&J Beverage Service added; Stade FranΓ§ais Aug 15 deadline is tomorrowHighQilin posted US beverages distributor D&J Beverage Service on August 13. πŸŸ₯ DLS claim β€” unverified. Separately, Qilin's countdown on Stade FranΓ§ais Paris (French rugby club, former Olympic venue) expires tomorrow August 15 at approximately 07:00 UTC; player passports and ID cards remain the published proof. The club has restored IT systems from clean backups and filed a criminal complaint; no public confirmation of payment. ransomware.live Β· The Record Β· ZATAZ
Rhysida β€” SIA Medical Centre, Melbourne, Australia (Aug 13 DLS)MediumRhysida posted SIA Medical Centre, a Melbourne-based medical practice founded in 1993. πŸŸ₯ DLS claim β€” attribution and scope unverified. RansomLook

πŸ”“ CRITICAL VULNERABILITIES

ShieldBreak β€” Microsoft Defender zero-day, no patch, public PoC, SYSTEM privileges on all WindowsCriticalResearcher Nightmare Eclipse published ShieldBreak on August 12 as a bypass for RoguePlanet (CVE-2026-50656, patched July 2026). ShieldBreak exploits a race condition in the Microsoft Malware Protection Engine via the Windows Cloud Filter API (cfapi), allowing any authenticated user to escalate to SYSTEM. Independently verified by analyst Will Dormann (100% success rate on Windows 11 25H2, Canary, and Windows Server 2025). No CVE assigned; no patch available; Microsoft threatened legal action before publication, researcher published anyway. Microsoft Defender must be enabled for exploitation. Any authentication-required privilege escalation to SYSTEM is immediately useful in post-exploitation. BleepingComputer Β· SecurityWeek Β· The Hacker News Β· TechCrunch
CVE-2026-55040 (SharePoint, CVSS 9.1) β€” Exploitation begins hours after Rapid7 PoC; RCE chain now completeCriticalRapid7 published a PoC on August 12 for this JWT token authentication bypass (patched July 14), developed at Pwn2Own Berlin. Exploitation of CVE-2026-55040 was detected within hours. Chained with August Patch Tuesday's CVE-2026-63520 (RCE, patched August 11), it achieves unauthenticated remote code execution on any unpatched SharePoint server β€” read and write access to enterprise document repositories with no valid credentials. Both flaws are now patched; organisations that have not applied the July and August SharePoint updates are exposed to this full chain. Security Affairs Β· Rapid7
CVE-2026-71362 (Adobe Commerce/Magento, CVSS 9.1) β€” Exploited in the wild within hours of patchHighAuthentication-bypass via incorrect session identity binding allows an unauthenticated attacker to take over any customer account. Sansec's Shield WAF is blocking active exploitation attempts; the flaw requires no account, no admin privileges, and no user interaction. Affects Commerce 2.4.4–2.4.9 and Magento Open Source 2.4.6–2.4.9. Patch in Adobe security bulletin APSB26-92 released August 11–12; apply immediately. BleepingComputer Β· Sansec Β· Security Affairs
CVE-2026-48362 (Adobe ColdFusion, CVSS 10.0) β€” Unauthenticated OS command injection; patch nowHighOS command injection in ColdFusion allows unauthenticated remote code execution. No active exploitation confirmed; Adobe and CISA recommend patching within 72 hours. Fixed in ColdFusion 2025.0.12 and 2023.0.23. Three separate CVSS 10.0 flaws patched across ColdFusion and Campaign Classic in the August bulletin. The Hacker News
CVE-2026-20349 (Cisco ASA/FTD) β€” FCEB remediation deadline is TODAY (Aug 14)HighFCEB agencies must have applied Cisco's August 11–12 hot fixes by close of business today. The unauthenticated VPN DoS via crafted HTTP request remains actively exploited; the hot fix covers all ASA 9.16–9.24 and FTD 7.0–10.0 release families. No workaround exists. Cisco PSIRT Β· Help Net Security

🚨 INTELLIGENCE AGENCY ALERTS & POLICY

No new CISA KEV additions or joint advisories published August 13–14. The August 11 KEV batch (CVE-2026-20349 Cisco ASA/FTD, CVE-2026-68820 Windows AFD, CVE-2026-72898 Metabase) remains current; CVE-2026-20349 deadline expires today. CISA ICS advisory batch next expected Tuesday August 19. Pending: confirmation that ShieldBreak receives CVE assignment and emergency guidance from CISA.
Key active Binding Operational Directives from the current Patch Tuesday cycle β€” verify compliance status:
CVE-2026-20349 (Cisco ASA/FTD): deadline TODAY Aug 14
CVE-2026-68820 (Windows WinSock AFD): patch available in Aug PT; FCEB agencies must apply
CVE-2026-72898 (Metabase): FCEB agencies must remediate or report exception
Gunra ransomware advisory AA26-222A (Aug 10, CISA/FBI/NSA/DC3/USSS/KNPA) remains actionable: Conti-derived RaaS, Fortinet initial access vectors, ChaCha20+RSA-4096 encryption. Linux variant has a decryptable time-seeded RNG flaw. CISA AA26-222A

🌐 THREAT ACTOR & CAMPAIGN ACTIVITY

Lazarus Group (DPRK) / Operation Dream Job β€” CVE-2026-68820 attribution confirmed; France and Germany defense firms in scopeCriticalCheck Point Research confirmed Lazarus deployed the FudModule kernel-mode rootkit and a newly documented Troy backdoor using CVE-2026-68820 (Windows WinSock AFD use-after-free) for at least five weeks before Microsoft's August 11 patch. Targets include defense and aerospace companies in France, Germany, Brazil, and India β€” LinkedIn fake job offers mimicking Lockheed Martin and Enveil were the lure. North Korea used quantum-resistant encryption on exfiltration channels. Patch (August 2026 PT) is available; any device in the target sector that hasn't applied Patch Tuesday should be treated as potentially compromised. BleepingComputer Β· The Hacker News Β· SecurityWeek
TeamPCP supply chain campaign β€” AI developer infrastructure systematically compromised across 5 ecosystemsCriticalThe same actor behind the Trivy compromise (March 2026) has now struck GitHub Actions, Docker Hub, npm (CanisterWorm), OpenVSX, and PyPI (LiteLLM). TeamPCP, a financially motivated cybercriminal group that emerged in late 2025, uses valid maintainer credentials obtained via prior compromises to inject information stealers that target CI/CD secrets, cloud API keys, and AI provider tokens. Endor Labs tracking indicates the actor continues to target packages with large install bases. Datadog Security Labs Β· Endor Labs Β· Trend Micro
Clop β€” Fiserv and FIS Global DLS claims in the same 10-day window; financial infrastructure in focusHighSee Breaches section. Two of the largest global financial technology providers claimed by Clop within the same cycle. Clop has a documented mass-exploitation pattern (MOVEit, GoAnywhere, Cleo) β€” no confirmed exploitation vector has been disclosed for either claim. Group remains operationally active; double-extortion combined with high-visibility fintech naming is its standard playbook for payment pressure. DeXpose
DeadLock β€” Microsoft full analysis confirms blockchain C2 model; Cry0 replicating approachHighMicrosoft Security Blog (August 10) confirms DeadLock stores C2 server addresses inside a Polygon blockchain smart contract, rotated at will by the operator for ~$1 in crypto. The Rust-based encryptor uses the Session messaging network for extortion negotiation. 80+ victims on four continents since July 2025. ReliaQuest (Q2 2026 quarterly) assesses with moderate confidence that blockchain-backed C2 will spread to other groups before year-end; Cry0 ransomware is already using the ICP blockchain for negotiations. This is the post-takedown-proof infrastructure the ransomware ecosystem has been moving toward since LockBit and ALPHV. Microsoft Security Blog Β· BleepingComputer
Qilin β€” Stade FranΓ§ais Aug 15 deadline expires tomorrow; Aug 13 victim D&J Beverage ServiceMediumAug 15 is the publication deadline for the 18-photograph evidence set (player passports/IDs). The club has restored systems and is not publicly engaging. Check Qilin DLS Saturday August 15–16 for data release or expiry. The Record Β· ransomware.live
AnMed Health / TheGentlemen β€” EHR fully restored; FBI and SLED investigations continuingMediumClinical teams have had full read/write EHR access since approximately August 11. Some outpatient imaging facilities remain affected. TheGentlemen's 6TB data claim (including HIV+ records, mental health, reproductive health records) has not been independently verified; the DLS posting and Facebook hijack remain the group's only public assertions. Negotiations status is not publicly disclosed. Fox Carolina Β· Healthcare IT News

🌍 GEOPOLITICS

Analyst lens: how this week's cyber activity maps to state strategy. Defense Β· cyber Β· economics.
DPRK expands Operation Dream Job targeting to European NATO allies: France and Germany defence contractors are now confirmed targetsCriticalThe Lazarus Group's CVE-2026-68820 campaign adds France and Germany (two of NATO's principal military contributors) to a target list previously concentrated in the Indo-Pacific. The attack vector β€” LinkedIn fake job offers mimicking US/European defence primes β€” is a direct, low-cost intelligence collection method against the Western defence industrial base at the moment it is most stretched. For executives: any defence-adjacent company with European personnel on LinkedIn should review endpoint security posture and consider this a persistent, nation-state threat, not a criminal nuisance. Check Point Research / BleepingComputer
LiteLLM supply chain: 2,488 enterprises' cloud and AI credentials exposed β€” state-intelligence windfallCriticalThe TeamPCP campaign extracted cloud keys, AI API tokens, and CI/CD secrets from global enterprises including defence contractors, critical infrastructure operators, and financial services firms. For a state-sponsored actor that obtains this dataset (or buys it), it is a near-complete map of enterprise AI pipeline dependencies, cloud workload ownership, and authenticated API access across roughly 2,500 of the most technology-dense firms in the world. The structural read: developer supply chains β€” not just operational systems β€” are now confirmed strategic targets. AI infrastructure is not just a productivity layer; it is an intelligence collection surface. SecurityWeek Β· Datadog Security Labs
Germany summons Russian ambassador as Operation Matryoshka escalates ahead of Saxony-Anhalt elections (September 6)HighGermany formally summoned the Russian ambassador over a combined hybrid-attack campaign: Operation Matryoshka AI-generated election disinformation (20 deepfake videos, 180+ fabricated posts impersonating BBC and ARD) combined with prior APT28 air-traffic control attacks on Deutsche Flugsicherung. The Russian Social Design Agency is confirmed as the operator; the campaign explicitly spares AfD while targeting CDU, SPD, Greens, and FDP. German Interior Ministry confirmed no active countermeasures as of mid-August. For portfolio companies: German political volatility directly affects EU regulatory posture and NATO industrial cohesion β€” scenario planning for unstable Q4 German politics is warranted. EUNews Β· NBC News
VMware vCenter APT campaign (361 victims, 47 countries) continues during Xi Washington preparation windowHighThe pre-positioning campaign exploiting CVE-2026-59310 is running at scale while the September 24 Xi-Washington summit creates a diplomatic restraint pressure on overt Chinese operations. The combination β€” broad persistent access to virtualisation control planes across 47 countries, acquired during a period of expected reduced operational tempo β€” is consistent with pre-crisis staging. The exploitation profile (compressed timeline, geographic breadth, persistence via reverse SSH) has been linked to state-sponsored APT doctrine by Rapid7 and independent researchers. No confirmed attribution, but the pattern matches documented PRC pre-positioning methodology. Executives should factor this into Q4 risk scenarios that include a post-summit deterioration of China-US relations. Rapid7 Β· The Hacker News
ShieldBreak and the researcher-sovereign disclosure model: Microsoft legal threat did not prevent publicationHighWhen Microsoft threatened legal action against researcher Nightmare Eclipse for ShieldBreak, the researcher published anyway. This is a strategic posture shift: researchers are increasingly treating their vulnerability discoveries as personal intellectual property with independent disclosure rights, even against corporate legal pressure. For state actors, the practical implication is that unpatched Windows Defender bypass capability is now public and will be incorporated into attacker toolkits before any patch lands. For security teams: no patch-based remediation is available; the risk is not patchable on any current timeline. TechCrunch Β· SecurityWeek
Threat actors
1 Β· Qilin546 YTD
2 Β· The Gentlemen335 YTD
3 Β· Akira228 YTD
4 Β· DragonForce248 YTD
M&A activity
Socure β†’ Fravityβ€”
Brinqa β†’ PlexTracβ€”
Munich Re (via HSB) β†’ $575Mβ€”
Fortinet β†’ Virtue AIβ€”