Skip to content

Confidential Β· 16 Aug 2026

πŸ›‘οΈ Daily Cybersecurity Briefing β€” 2026-08-16 (Sunday)

Window: last 24–48h (August 15–16). Severity: πŸ”΄ CRITICAL Β· 🟑 HIGH Β· 🟒 MEDIUM.

Threat level GUARDEDVictims L30D 121Top actor QilinM&A L30D $94.5M

πŸ’Ό M&A ACTIVITY

Datavault AI (NASDAQ: DVLT) β†’ CyberCatch Holdings $94.5M all-cash (announced Aug 14)MediumDefinitive agreement to acquire 100% of CyberCatch (TSXV: CYBE), a San Diego AI compliance and cyber-risk platform covering NIST CSF 2.0, CMMC 2.0, ISO 27001, HIPAA, and PCI DSS via continuous agentic AI control assessment and automated pen testing. CyberCatch will operate as a Datavault subsidiary; founder Sai Huda becomes subsidiary president. Subject to TSXV and shareholder/court approvals. Datavault AI IR Β· Investing.com
L30D summary (Jul 17 – Aug 16): 35 named deals tracked; disclosed capital exceeds $5.1B. Largest by value: Visa β†’ BioCatch ($2.4B, behavioural biometrics); Cyera β†’ Oasis Security (~$1B, NHI/DSPM); Okta β†’ Permiso Security (~$200M, identity threat detection); ThreatLocker $190M Series D; Zenity $125M Series C (AI-agent governance); Datavault AI β†’ CyberCatch $94.5M (continuous compliance AI). Consolidation themes unchanged: AI-agent governance and NHI, autonomous offensive security, continuous compliance/GRC automation. SecurityWeek M&A tracker

⚠️ CRITICAL BREACHES & INCIDENTS

Stade FranΓ§ais Paris / Qilin β€” Aug 15 deadline passed, data confirmed leaked, systems restoredHighThe Record confirms Stade FranΓ§ais has restored its IT environment from clean backups following the Qilin ransomware attack. The club acknowledged that a sample of stolen data has been published online β€” specifically identity documents (passports and national ID cards) belonging to 18 players were released as proof. The club is investigating full scope and working to notify affected individuals. French authorities were informed and a criminal complaint filed. Status of any full-dataset publication remains unconfirmed in open-source reporting; the samples are confirmed. πŸŸ₯ DLS claim; full dataset publication unconfirmed. The Record Β· ZATAZ Β· Cyberattaque.org
LiteLLM supply chain attack (March 2026) β€” CloudSEK/Hudson Rock August disclosure: 2,500+ orgs and 434,000 CI/CD pipelines exposedCriticalCloudSEK and Hudson Rock have separately published victim data from the March 24 2026 TeamPCP supply chain attack on LiteLLM, confirming this is the largest known AI infrastructure supply chain breach to date. TeamPCP compromised LiteLLM's build pipeline via a poisoned Trivy security scanner, publishing malicious LiteLLM versions 1.82.7 and 1.82.8 to PyPI (live for 40 minutes). The payload: harvested environment variables, `.aws/credentials`, `.kube/config`; attempted Kubernetes lateral movement; installed a persistent systemd backdoor. Named organizations in CloudSEK's high-confidence list include NVIDIA, AWS, Samsung, Salesforce, Cisco, Siemens, ServiceNow, London Stock Exchange Group, FedEx, Volkswagen, Zscaler, and Thales. FBI July 2, 2026 FLASH advisory (TeamPCP) warned that exfiltrated credentials represent a persistent long-term threat β€” affiliated actors are expected to weaponize them well after the initial intrusion. If your org has ever had LiteLLM 1.82.7 or 1.82.8 in a CI/CD pipeline, treat all environment credentials as compromised. CloudSEK Β· SecurityWeek Β· DevOps.com

πŸ”“ CRITICAL VULNERABILITIES

GeoServer zero-day PATCHED β€” CVSS 9.8 SQL injection to RCE now has a fix (apply immediately)CriticalGeoServer released versions 3.0.1, 2.28.5, and 2.27.6 on August 15, addressing the critical unauthenticated SQL injection in `jsonArrayContains` that leads to remote code execution via PostGIS/H2 JDBC. GitHub advisory GHSA-mqjf-5f49-2fjh, CVSS 9.8. Active exploitation probes were observed within hours of the zero-day's public disclosure on August 12. Prior update in this briefing series flagged no patch available β€” that has changed. GeoServer is widely used by government agencies, utilities, environmental monitoring, and geospatial intelligence organisations; patch urgency is highest for any internet-facing deployment. The Hacker News Β· SecurityAffairs Β· OSGeo Discourse
SAP Commerce Cloud CVE-2026-58231 (CVSS 10.0) β€” active exploitation confirmed, no public PoC yetHighDefused honeypot data confirms exploitation attempts against the maximum-severity SAP Commerce Cloud deserialization flaw three days after SAP's August 11 patch. Affects SAP Commerce Cloud COM_CLOUD 2211/2211-JDK21; fix requires upgrade to 2211.55 or 2211-jdk21.17. An attacker exploiting this achieves unauthenticated RCE across any reachable Commerce Cloud instance. Temporary mitigation: IP-filter the vulnerable Data Hub Adapter endpoint. SOCRadar Β· BleepingComputer

🚨 INTELLIGENCE AGENCY ALERTS & POLICY

No new CISA/FBI/NSA advisories published August 15–16.HighStanding priorities from prior 72h remain active: GeoServer patch (now available β€” see above), Windows DNS CVE-2026-62878 wormable RCE, Lazarus/CVE-2026-68820 KEV deadline ~August 25, and LAUNDRY BEAR/Zimbra CVE-2025-66376 ongoing (AA26-204A). See prior briefings for full details.

🌐 THREAT ACTOR & CAMPAIGN ACTIVITY

The_Gentlemen β€” 483+ claimed victims across 77 countries, 11 new DLS postings in last 24h (most active group globally)CriticalThe Gentlemen ransomware-as-a-service has surpassed 483 claimed victims since mid-2025, now scaling faster than any group on record, with June 2026 representing 117 claimed victims β€” their single highest monthly count. The 90% affiliate revenue share (vs. the 70-80% industry norm) has driven rapid affiliate recruitment. Per ransomware.live daily activity, The_Gentlemen posted 11 new claims in the last 24 hours. Double-extortion model: encryption plus exfiltration. Primary sectors: professional services, construction, healthcare, and conglomerates. Halcyon threat assessment Β· Unit 42
Active DLS groups in last 24h (ransomware.live aggregate): The_Gentlemen (11), Krybit (9), LockBit (6), Qilin (6), Brain Cipher (4)High45 new ransomware victim claims tracked globally in the August 15–16 window. Krybit continues elevated tempo at 9 new postings. LockBit's 6-claim pace is consistent with operator-level rebuilding activity observed since its partial disruption earlier in 2026. πŸŸ₯ All DLS postings are unverified claims; verify before treating as confirmed breaches. ransomware.live Β· PurpleOps tracker
Clop Windchill/FlexPLM campaign β€” Philips confirms server compromise, Shell/GE investigations ongoingHighPhilips has now confirmed "compromise of a specific enterprise server related to internal data," adding that customer environments were unaffected. Shell and GE have not publicly confirmed breach scope. The 43-victim campaign exploited CVE-2026-12569 (CVSS 9.3, PTC Windchill/FlexPLM deserialization) from early June as a zero-day. Ransom-ISAC assesses exploitation began at least six weeks before the June 17 patch. This remains the most significant active industrial data-theft campaign since MOVEit 2023. BleepingComputer Β· TechTimes

🌍 GEOPOLITICS

Analyst lens: how this week's cyber activity maps to state strategy. Defense Β· cyber Β· economics.
The LiteLLM supply chain breach β€” targeting AI infrastructure shared by NVIDIA, Cisco, Siemens, and government contractors β€” is structurally different from ransomware or espionage: it represents pre-positioned access across the AI development stack of Western critical-sector organisations.CriticalTeamPCP's August-disclosed victim map shows a cross-section of NATO-aligned defense supply chain, financial infrastructure, and government IT all sharing a compromised dependency. The FBI FLASH (July 2) warning that credentials will be weaponized long after the intrusion is the critical read: this is a persistent foothold operation with a multi-month exploitation horizon, not a smash-and-grab. The geopolitical risk is that an actor with access to LiteLLM-connected CI/CD credentials can inject malicious code into software destined for defense and critical infrastructure at a later, chosen moment. CloudSEK Β· SecurityWeek
China's cyber pre-positioning against Taiwan has entered an operational phase: Taiwan's NSB documented 2.63 million daily cyberattacks on average in 2025, more than double 2023 levels, targeting energy, emergency services, hospitals, and communications.CriticalCSIS and Global Taiwan Institute analysts assess PRC-linked groups are not just probing but pre-positioning for activation during a contingency. The pattern β€” low-noise, persistent, infrastructure-focused β€” mirrors FSB router operations in Europe (AA26-194A). Both represent the same strategic doctrine: achieve access at scale well before kinetic events, so the decision to act requires only execution, not preparation. Chinese and Japanese diplomatic friction (PRC economic pressure over PM Takaichi's Taiwan comments) is a visible indicator of rising regional tension the pre-positioning is designed to service. Global Taiwan Institute Β· AEI China-Taiwan Update Aug 7
Russia's Sandworm (UAC-0145) pivot to targeting Ukrainian IT professionals via fake job interviews β€” deploying a trojanized WireGuard VPN client β€” is a tactical shift from infrastructure attacks to supply-chain-of-people.HighBy compromising a system administrator, Sandworm gains the same access they would from a network intrusion β€” without the associated network noise. Ukraine's IT sector has become a high-value target precisely because Ukrainian sysadmins manage infrastructure serving both domestic and NATO-adjacent organisations. CERT-UA disclosed this campaign August 10; it has been ongoing since May. Any Ukrainian IT firm contracted to Western organisations should treat this as a direct supply-chain risk. The Hacker News Β· BleepingComputer
North Korea's employment of a fake IT worker inside a US federal agency β€” confirmed by FBI Cyber Branch deputy director Todd Hemmen on July 28 β€” demonstrates that DPRK's IT worker program has now successfully penetrated US government vetting processes, not just commercial employers.HighThe agency is unnamed; data accessed is unspecified. The July 31 global alert (US plus 14 foreign partners) on North Korean IT worker risk was the policy response, but the structural problem β€” that remote IT contractors are rarely subject to the same in-person identity verification as cleared employees β€” remains unresolved. The financial dimension (funding DPRK weapons programs) and the intelligence dimension (access to government networks) are converging in the same campaign. TechCrunch Β· Federal News Network
The Delta flight evil-twin Wi-Fi attack (DEF CON flight, Aug 10) illustrates how consumer-grade offensive hardware has compressed the cost of man-in-the-middle attacks to near-zero and made them operable in physically constrained, previously impractical environments.MediumA Wi-Fi Pineapple device de-authenticated passengers from the real network and served a credential-harvesting rogue AP at 30,000 feet. Delta locked all affected frequent-flyer accounts as a precaution; federal authorities boarded in Atlanta. While the incident is operationally minor, it signals that airport transit β€” particularly after security conferences β€” is a realistic credential-collection opportunity at scale for patient actors using the same hardware. Cybernews Β· View From The Wing
Threat actors
1 Β· Qilin546 YTD
2 Β· The Gentlemen335 YTD
3 Β· Akira228 YTD
4 Β· DragonForce248 YTD
M&A activity
Socure β†’ Fravityβ€”
Brinqa β†’ PlexTracβ€”
Munich Re (via HSB) β†’ $575Mβ€”
Fortinet β†’ Virtue AIβ€”