Skip to content

Confidential Β· 15 Aug 2026

πŸ›‘οΈ Daily Cybersecurity Briefing β€” 2026-08-15 (Saturday)

Window: last 24–48h (August 13–15). Severity: πŸ”΄ CRITICAL Β· 🟑 HIGH Β· 🟒 MEDIUM.

Threat level GUARDEDVictims L30D 123Top actor QilinM&A L30D $94.5M

πŸ’Ό M&A ACTIVITY

No new acquisitions or funding rounds announced specifically on August 14–15.
L30D summary (Jul 15 – Aug 15): 34 named deals tracked; disclosed capital exceeds $5B. Dominant by value: Visa β†’ BioCatch ($2.4B, behavioural biometrics); Cyera β†’ Oasis Security (~$1B, NHI/DSPM); Okta β†’ Permiso Security (~$200M, identity threat detection); ThreatLocker $190M Series D; Glow $180M Series A ($1.2B valuation); Cathedral $160M Series A ($1.4B valuation); Zenity $125M Series C (AI-agent governance); Oligo Security $60M Series C (runtime security); Act Security $60M Seed+Series A. The three clearest capital concentration themes: AI-agent governance (Zenity, Onyx, Glow β€” >$400M combined); non-human identity (Oasis, Obsidian, Permiso/Okta β€” >$1.3B combined); autonomous offensive security (A Security $37M Series B). SecurityWeek M&A tracker

⚠️ CRITICAL BREACHES & INCIDENTS

Clop mass Windchill/FlexPLM campaign β€” ~50 organisations listed including Shell and PhilipsCriticalClop publicly claimed data theft from approximately 50 organisations via CVE-2026-12569 (CVSS 9.3, unsafe deserialization) in PTC Windchill and FlexPLM. Named entities include Shell (claimed 89 GB of engineering drawings, facility scans, and project plans), Philips (13.5 GB of PDF drawings and blueprints), General Electric, and Fiserv (already on DLS Aug 12; Fiserv denies any customer/bank/transaction data compromise). Shell and Philips confirmed investigations are underway. The Windchill/FlexPLM vector means data is overwhelmingly engineering and manufacturing IP β€” not financial or personal records β€” making the Fiserv denial structurally credible. πŸŸ₯ All listings are DLS claims; breach and exfiltration scope not confirmed for any named entity. Clop has a documented pattern of listing large names to force payment. Ransom-ISAC warned of this CVE on July 22. This is Clop's most aggressive mass-extortion wave since the MOVEit/GoAnywhere campaigns of 2023. BleepingComputer Β· TechNadu (Shell/Philips investigations) Β· Claims Journal
macOS Screen Sharing CVE-2026-65400 β€” attackers deploying Monero crypto miners via port 5900HighAttackers exploiting the Apple macOS Screen Sharing (VNC) remote root flaw to deploy XMRig Monero miners on unpatched systems. Netherlands NCSC flagged active abuse. Apple patched August 6 (macOS Tahoe 26.6.1 and Sequoia 15.6.1). Unpatched systems remain exposed; macOS Screen Sharing is enabled by default on many enterprise deployments. BleepingComputer Β· SC Media
Stade FranΓ§ais Paris / Qilin β€” Aug 15 deadline passed, data publication status unverifiedHighQilin's countdown on Stade FranΓ§ais Paris (French Top 14 rugby club, former Olympic venue) expired today August 15. The club has confirmed the attack, filed a criminal complaint, and restored IT systems from clean backups. Player passports and national ID cards were published as proof samples. Whether Qilin published the full dataset, extended the deadline, or accepted payment is not confirmed in available open-source intelligence as of briefing time. πŸŸ₯ Monitor ransomware.live and RansomLook for publication status. ZATAZ Β· Generation-NT Β· Deccan Herald

πŸ”“ CRITICAL VULNERABILITIES

GeoServer zero-day β€” unpatched SQL injection to RCE, active probing within hours of disclosureCriticalA SQL injection flaw in GeoServer's `jsonArrayContains` filter expression allows remote unauthenticated code execution via PostGIS/Oracle JDBC. Disclosed August 12 by researcher @q1uf3ng; active exploitation probes observed within hours. No CVE assigned and no patch available as of August 14. GeoServer is widely used by government agencies, utilities, environmental monitoring services, and geospatial intelligence organisations. Immediate mitigation: restrict public access; disable the jsonArrayContains filter endpoint where possible. The Hacker News Β· SecurityWeek Β· CSO Online
CVE-2026-62878 (Windows DNS Server, CVSS 9.8) β€” wormable RCE, patched August 11HighStack overflow in the Windows DNS Server service enabling unauthenticated remote code execution with no user interaction. No workaround exists; DNS servers are typically network-perimeter accessible. A network-propagating worm exploiting this flaw would have no effective blast-radius boundary. Patch was included in the August 2026 Patch Tuesday release; apply immediately on any Windows DNS Server deployment. SecurityWeek Patch Tuesday Β· Tenable
CVE-2026-68820 (Windows AFD.sys, Lazarus confirmed) β€” zero-day exploited 5 weeks pre-patchHighConfirmed Lazarus Group exploitation of this Windows WinSock driver use-after-free flaw, with artifacts dating to July 7, five weeks before Microsoft's August 11 patch. Payload: FudModule v3.1 kernel rootkit (kills 94 security monitoring channels) + ForestTiger backdoor. Entry vector: fake LinkedIn "Dream Job" offers targeting defense and aerospace employees. CISA KEV deadline: ~August 25. See also Threat Actor section below. BleepingComputer Β· Check Point Research
CVE-2026-59124 (Microsoft HPC Pack, CVSS 9.8) β€” unauthenticated RCE, patched August 11MediumUnauthenticated remote code execution in Microsoft's High-Performance Computing Pack. Relevant to research institutions, financial services quant desks, and computational sciences. Patched in August 2026 Patch Tuesday. Tenable Patch Tuesday

🚨 INTELLIGENCE AGENCY ALERTS & POLICY

Trump NSPM "Expanding Capabilities to Combat Transnational Cyber-Enabled Crime" β€” private-sector offensive cyber authorised (signed August 12)CriticalThe Presidential Memorandum establishes a formal federal program allowing vetted US cybersecurity companies to conduct government-supervised cyber surveillance and disruption operations against Cyber-Enabled Transnational Criminal Organizations (TCOs). The National Coordination Center, jointly directed by DOJ and DHS, oversees opt-in participation. Requirements: $1M bond/escrow (forfeited for contract violations), rigorous vetting, DOJ or DHS contract. Builds on the March 2026 cybercrime Executive Order. This is the first formal legal framework for US private-sector offensive cyber operations β€” previously the exclusive domain of NSA Cyber Command and FBI. Oversight and liability questions remain unresolved; Crowell & Moring, Wiley Law, and Federal News Network have flagged significant legal uncertainty around collateral damage liability and international law compliance. White House NSPM fact sheet Β· CyberScoop Β· The Record Β· Federal News Network
FCEB deadlines lapsed (Aug 14): CVE-2026-20349 (Cisco ASA/FTD) and CVE-2026-72898 (Metabase)HighBoth CISA KEV deadlines passed yesterday. Cisco ASA/FTD unauthenticated VPN DoS and Metabase SQL injection to admin access remain exploited in the wild. Commercial organisations with these products unpatched are exposed; treat as patch-immediately. No public reporting on FCEB compliance rates. CISA KEV
CISA/NSA Advisory AA26-194A (active) β€” FSB Center 16 router mass exploitationMediumJoint advisory from NSA, CISA, FBI, DC3, and 12 partner nations remains active. Campaign targets SNMP-misconfigured routers (default community strings) across communications, DIB, energy, financial services, government, and healthcare. Technique: SNMP Set-Request to exfiltrate running config via TFTP; also Cisco Smart Install exploitation. Disable Cisco Smart Install; harden SNMP. NSA/CISA AA26-194A

🌐 THREAT ACTOR & CAMPAIGN ACTIVITY

Lazarus Group (NK) β€” CVE-2026-68820 confirmed, FudModule v3.1 rootkit deployed against defense/aerospace sectorCriticalCheck Point Research confirmed Lazarus exploited the Windows AFD.sys zero-day for five weeks before the August 11 patch. Entry via fake LinkedIn job offers targeting defense and aerospace employees. FudModule v3.1 kills 94 security monitoring channels β€” this is one of the most capable kernel rootkits observed in the wild. ForestTiger backdoor provides persistent remote access. See also Geopolitics.
Clop β€” mass Windchill/FlexPLM campaign, ~50 named victims (most aggressive wave since MOVEit)CriticalClop has pivoted from secure file transfer to enterprise manufacturing PLM software as its mass-exploitation vector. CVE-2026-12569 gives Clop access to engineering IP rather than HR/financial data β€” a deliberate targeting of industrial and dual-use engineering documentation. At ~50 claimed victims across energy, manufacturing, apparel, aerospace, and fintech, this is Clop's largest simultaneous listing since the MOVEit/GoAnywhere 2023 campaigns.
Qilin β€” 335+ L3M victims, Aug 15 deadline on Stade FranΓ§ais unresolvedHighQilin remains Tier-1 with 335 victims in the last 3 months. The Stade FranΓ§ais deadline expired today. 7 additional DragonForce victims were posted in a 24-hour window on August 14, per PurpleOps tracking.
Everest β€” Allied Telesis (Japan, networking, ~$500M revenue) listed August 5MediumDLS claim, attack date estimated July 17. Everest has targeted manufacturing, IT services, and government across North America, Europe, and Asia. πŸŸ₯ DLS claim β€” scope unverified. DEXpose

🌍 GEOPOLITICS

Analyst lens: how this week's cyber activity maps to state strategy. Defense Β· cyber Β· economics.
North Korea's Lazarus Group weaponised a Windows zero-day against Western defense contractors for five weeks undetected β€” the FudModule v3.1 rootkit's ability to kill 94 monitoring channels is a direct counter-EDR capability development, not opportunistic.CriticalNK cyber operations have historically monetised intrusions (crypto theft) or conducted espionage; FudModule v3.1 and ForestTiger deployed against defense sector targets signals a shift toward persistent long-dwell access in DIB networks β€” consistent with pre-conflict ISR positioning or supply-chain intelligence collection. The LinkedIn Dream Job vector exploits a structural gap: defense employees receive LinkedIn messages from "recruiters" at unprecedented volume, making the lure low-cost and hard to block at scale. BleepingComputer Β· Forbes
The Trump NSPM creating a private-sector offensive cyber framework is a structural geopolitical shift: for the first time, vetted US companies can legally conduct offensive operations against foreign criminal networks β€” blurring the line between government cyber power and the commercial threat-intel industry.CriticalThe DOJ/DHS oversight model and $1M bond requirement are designed to prevent freelancing; the structural risk is that foreign adversaries will treat licensed US "cyber privateers" as state actors, opening participating companies to retaliatory state-sponsored attacks and creating attribution complexity. The framework is also explicitly aimed at ransomware TCOs β€” primarily Russia-based β€” raising the question of whether Kremlin-linked groups will accelerate attacks on US infrastructure in anticipation. CyberScoop Β· The Record
China escalated economic coercion against European defense supply chains by adding 14 EU entities to its export control list July 24 β€” including Rheinmetall, IHC (Netherlands), Vigo Photonics (Poland), and Tatra Trucks (Czech Republic).HighThe explicit justification was retaliation for the EU's 21st Russia sanctions package. Chinese and foreign firms are barred from supplying dual-use items of Chinese origin to these entities. For European defense primes and their Tier-2 suppliers, this is a supply-chain risk that materialises in 90–180 days as components in pipeline clear through or are diverted β€” and it foreshadows broader export control escalation if EU-Russia sanctions continue. ABC News Β· European Interest
Russia's FSB Center 16 mass router exploitation campaign β€” targeting SNMP-misconfigured infrastructure across NATO-aligned critical sectors β€” is simultaneously a pre-positioning operation and a signals collection effort.HighThe SNMP/TFTP exfiltration of router running configs gives Russia network topology maps of targeted organisations without deploying malware. This is patient, low-noise, and defensible only through configuration hygiene β€” making it ideal for sustained pre-conflict ISR. Twelve co-attributing nations confirms Western intelligence has high confidence in the attribution. NSA/CISA AA26-194A Β· Security Boulevard
Iran is simultaneously operating APT42 human-centric espionage, Screening Serpens RAT deployments, and CISA-advisory-level ICS attacks on US water systems β€” a multi-vector campaign that positions cyber as both a coercion lever and a negotiating card amid ongoing regional conflict.MediumThe water system attacks are particularly significant: CISA/EPA/FBI/NSA's joint advisory (AA26-097A) documented PLC/SCADA manipulation across 12 US utilities, and Senate legislation ($400M) has been proposed in response. Iran is running a playbook that signals willingness to escalate to kinetic-equivalent disruption β€” consistent with deterrence strategy, not just espionage. Unit 42 Β· CISA AA26-097A
Threat actors
1 Β· Qilin546 YTD
2 Β· The Gentlemen335 YTD
3 Β· Akira228 YTD
4 Β· DragonForce248 YTD
M&A activity
Socure β†’ Fravityβ€”
Brinqa β†’ PlexTracβ€”
Munich Re (via HSB) β†’ $575Mβ€”
Fortinet β†’ Virtue AIβ€”