Confidential ยท 21 Aug 2026
๐ก๏ธ Daily Cybersecurity Briefing โ 2026-08-21 (Friday)¶
Window: last 24โ48h (August 20โ21). Severity: ๐ด CRITICAL ยท ๐ก HIGH ยท ๐ข MEDIUM.
Threat level GUARDEDVictims L30D 107Top actor QilinM&A L30D $94.5M
๐ผ M&A ACTIVITY¶
No new deals confirmed August 20โ21Mediummid-August quiet period continues; SecurityWeek's August roundup typically publishes at month-end.
L30D summary (Jul 22 โ Aug 21): ~28 named deals tracked in the trailing 30 days. Largest single transaction: Visa โ BioCatch ($2.4B, Aug 3) โ largest cybersecurity deal of H2 2026 to date. Other headline rounds: Zenity $125M Series C (AI-agent governance, Aug 4), Datavault AI โ CyberCatch $94.5M all-cash (Aug 14), Oligo Security $60M Series C (runtime application security, Aug 4), Okta โ Permiso Security ~$200M (ITDR, Jul). Consolidation theme: AI-agent security governance, non-human identity, and runtime protection dominate new capital; Visa/BioCatch signals card-network entry into biometric fraud-prevention. SecurityWeek M&A tracker
โ ๏ธ CRITICAL BREACHES & INCIDENTS¶
Baylor Genetics notifies 305,066 patients โ genetic test results, SSNs, DOBs, health insurance data, and employee financial account numbers exposed in June 11โ17 intrusionCriticalHouston-based genomics testing laboratory notified approximately 305,066 individuals (248,430 in Texas, 56,636 in Massachusetts) on August 20 for an intrusion detected around June 15. The attacker accessed systems between June 11โ17; data review concluded around July 30. Exposed fields include genetic test results, SSNs, dates of birth, health insurance information, and employee financial account numbers. Baylor Genetics handles genetic testing across reproductive health, oncology, and rare disease; clients include hospitals and specialist practices. Actor not publicly named; disclosure pattern is consistent with ransomware. Notifications are triggering HIPAA breach reporting to HHS. BankInfoSecurity ยท Cybersecurity Dive
ShinyHunters/Questel update: breach confirmed August 13, data now published โ Questel notified CNIL and filed criminal complaints; vishing entry into Microsoft 365, not SalesforceHighQuestel SAS (French IP and patent management firm) confirmed on August 13 that a voice phishing call gave attackers entry to part of its Microsoft 365 environment, and that some stolen data has since been published online. ShinyHunters originally listed Questel on August 1, claiming 21M+ Salesforce records and 147 GB of data; Questel characterises the confirmed unauthorized access as limited to a Sales SharePoint site in Microsoft 365. The company notified CNIL (French data regulator) and filed criminal complaints. Questel serves major enterprise clients managing patent portfolios โ disclosed IP data has competitive-intelligence value beyond PII fraud. ๐จ Partial confirmation (breach and publication confirmed; Salesforce scope disputed by Questel). SQ Magazine ยท CyberInsider
Microsoft Copilot "CoSnitch" exfiltration flaw disclosed August 20 โ third critical data-movement vulnerability in Copilot this yearHighVaronis disclosed a critical exfiltration vulnerability in Microsoft Copilot dubbed CoSnitch, which allows Copilot to move data to external destinations without triggering standard DLP alerts. No CVE or Microsoft patch confirmed as of August 20. This is the third serious Copilot data-movement vulnerability Varonis has disclosed in 2026, with all three affecting organizations that have deployed Copilot across Microsoft 365 environments at scale. ๐จ Moderate โ research-disclosed; scope of real-world exploitation not confirmed. Varonis August 20 disclosure
๐ฅ Babcock Africa / TheGentlemen DLS claim August 19 โ critical infrastructure engineering firm serving Africa โ TheGentlemen ransomware group posted Babcock Africa on August 19. Babcock Africa provides engineering and asset management services to critical infrastructure and heavy equipment sectors across the African continent. Data scope and impact unconfirmed. ๐ฅ DLS claim only; verify before treating as confirmed breach. ransomware.live
๐ CRITICAL VULNERABILITIES¶
CVE-2026-72529 + CVE-2026-72530 โ TrueConf Server unauthenticated RCE; CISA KEV August 20; FCEB deadline August 23 (2 days)CriticalCISA added two TrueConf Server vulnerabilities to the KEV catalog on August 20, both actively exploited. CVE-2026-72529 (CVSS 9.8): missing authentication for critical function; an unauthenticated remote attacker on port 4307/TCP can invoke an undocumented API function to execute arbitrary scripts. CVE-2026-72530 (CVSS 9.0): code injection allowing sandbox escape and arbitrary code execution on the host. Affects TrueConf Server 5.3.xโ5.5.5 and earlier. TrueConf is an on-premises video conferencing platform used by government, military, and enterprise customers in Russia and CIS countries with significant government/critical infrastructure deployments; FCEB agencies must remediate CVE-2026-72529 by August 23. CISA KEV alert ยท Kaspersky ICS CERT advisory
CVE-2026-68820 โ Windows WinSock (AFD.sys) use-after-free; DPRK exploitation confirmed with kernel-mode rootkit deploymentCriticalNorth Korean threat actors exploited CVE-2026-68820 (WinSock Ancillary Function Driver, CVSS 9.8) in Operation Dream Job to deploy a kernel-mode rootkit achieving ring-0 persistence. Patched in Patch Tuesday August 12; CISA KEV added August 11. Priority: any unpatched Windows endpoint is vulnerable to kernel-level compromise by a nation-state adversary. BleepingComputer Patch Tuesday ยท Help Net Security
CVE-2026-62878 (Windows DNS Server, CVSS 9.8, wormable) + CVE-2026-62815 (Microsoft QUIC, CVSS 9.8, no-user-interaction RCE) โ Patch Tuesday August 12 critical residualsHighBoth are critical patches from August Patch Tuesday (421 CVEs, 42 Critical, 3 zero-days) with no known in-the-wild exploitation yet. CVE-2026-62878 is a stack-based buffer overflow in Windows DNS Server that is wormable โ a single exploit can propagate across domain-joined infrastructure. CVE-2026-62815 is a QUIC protocol RCE requiring no user interaction. Both should be treated as imminent exploitation risks given Patch Tuesday timing. SecurityWeek
CISA KEV August 18 batch โ FCEB remediation deadline TODAY (August 21)HighThe four CVEs added August 18 (CVE-2026-33824 Microsoft IKE double free, CVE-2026-55040 SharePoint weak authentication, CVE-2026-59310 VMware vCenter path traversal, CVE-2026-65400 Apple macOS improper authentication) carry a 21-day FCEB remediation window closing August 21. Non-federal organizations should prioritize VMware vCenter (hypervisor-level blast radius) and SharePoint. CISA KEV
๐จ INTELLIGENCE AGENCY ALERTS & POLICY¶
AA26-222A โ #StopRansomware: Gunra Ransomware (CISA + FBI + DC3 + NSA + USSS + South Korea NPA, August 10) โ standing advisory; active threat to healthcare, government, and critical servicesCriticalGunra is a Conti-derived RaaS that emerged April 2025 and is actively targeting healthcare, government, and critical services globally with double-extortion (data theft + encryption). The joint advisory (six agencies including South Korea NPA) reflects active operations by a growing affiliate base. Cross-platform builders, management panel, and DLS in operation. Indicators and detection guidance in the advisory. CISA AA26-222A ยท DataBreaches.net coverage
US DOJ charges 17 Iranians (alleged Mabna Institute members) for long-running data theft against US academic and corporate targetsHighThe Department of Justice indicted 17 individuals alleged to be associated with the Mabna Institute, a Tehran-based organization that conducted hacking-for-hire operations stealing academic research, intellectual property, and corporate data from universities, research institutions, and private sector entities in the US and allied countries. The indictment reflects continued US enforcement action against Iranian state-adjacent cyber operations. DOJ announcement
No new CISA/FBI/NSA/NCSC-UK/Five Eyes advisories published August 20โ21.MediumUkraine Independence Day elevated threat window (August 24) is 3 days out; watch for pre-emptive Five Eyes communications ahead of the August 22โ26 risk window.
๐ THREAT ACTOR & CAMPAIGN ACTIVITY¶
Qilin โ continues as most prolific ransomware group; 1,484 attacks in last 12 months, 500+ in 2026HighQilin remains the most active ransomware operation globally by victim count, having filled much of the void left by RansomHub's collapse. Sector-agnostic opportunistic targeting pattern continues; active victims in August span logistics, finance, construction, industrial, and healthcare across US, UK, France, and South America. Black Kite 2026 Ransomware Report
TheGentlemen โ Babcock Africa claim August 19; group has claimed 10% of 2026 global ransomware victimsHighTheGentlemen (Storm-2697) posted Babcock Africa August 19. KELA's analysis of an internal chat leak confirmed the group's scale: approximately 10% of all 2026 ransomware victim claims globally. June 2026 was the group's highest month (117 victims). The group's 90% affiliate cut and cross-platform capability continue to drive volume. ๐ฅ Babcock Africa claim unverified. KELA ยท Halcyon
ShinyHunters Salesforce campaign update โ Questel data confirmed published; Alcon (25M+ records) and Lumenis still unresolvedHighFollowing Questel's August 13 breach confirmation and CNIL notification, ShinyHunters has published the stolen data. Alcon Inc. (Swiss ophthalmology firm, 25M+ claimed Salesforce records) and Lumenis (Israeli medical devices, 1.1M+ records) remain unconfirmed; both listed August 1 with August 4 contact deadlines that have now passed. ShinyHunters continues targeting enterprises with deep Salesforce deployments; the vishing โ Microsoft 365 vector is the confirmed initial access method at Questel. ๐ฅ Alcon and Lumenis DLS claims unconfirmed.
Everest โ Kingston Technology (138 GB APAC data) and Capgemini Engineering listed August 20; group posted 6+ victims in 24hHighEverest ransomware posted Kingston Technology (US, DRAM and flash storage manufacturer, 9,438 files / 138.49 GB of data described as covering Taiwan, Japan, Korea, Thailand, Vietnam, India, Australia, and Southeast Asia) and Capgemini Engineering (France, global engineering services) on August 20, alongside CCA Bank (Cameroon), Grupo DT (Mexico), and Experts Entreprendre (France). Kingston said operations were unaffected; Capgemini has not issued a statement. Everest has 392+ claimed victims to date. ๐ฅ All DLS claims; unverified. Cyber Daily ยท Cypro
ShinyHunters โ Logitech/Streamlabs payment deadline August 21; data-release threat activeHighShinyHunters posted Logitech (US, peripherals and Streamlabs streaming platform) on August 18 with an August 21 payment deadline. As of August 21, Logitech has not issued a statement and no data has been published. ShinyHunters continues its enterprise extortion campaign alongside the ongoing Questel/Alcon/Lumenis Salesforce-credential tranche. The Logitech claim would add a major consumer brand with registered user and streaming identity data. ๐ฅ DLS claim; unverified. Watch for data publication. Cyber Daily ยท Cybernews
Direwolf โ 8 new DLS postings August 21 including ProSim Aviation Research (France), iSON XPERIENCES, and Reviso Cloud AccountingMediumDirewolf (Rust-based encryptor with decentralized recovery infrastructure, profiled by Microsoft Security Aug 10) posted at least 8 victims on August 21, spanning aviation engineering software, business services, financial software, and construction materials. The group continues building volume across mid-market targets. ๐ฅ All DLS claims; unverified. Microsoft Security Blog โ Deadlock/Direwolf profile
North Korean Operation Dream Job โ CVE-2026-68820 (WinSock) exploitation for kernel rootkit deployment confirmed August 2026MediumDPRK threat actors (linked to Lazarus/Operation Dream Job) are actively weaponizing the August Patch Tuesday zero-day CVE-2026-68820 to deploy a kernel-mode rootkit. This continues DPRK's pattern of exploiting Windows kernel vulnerabilities for persistent, stealthy access to target networks. Patch immediately. BleepingComputer
๐ GEOPOLITICS¶
Analyst lens: how this week's cyber activity maps to state strategy. Defense ยท cyber ยท economics.
Ukraine Independence Day (August 24) is now 3 days out; Russia is confirmed to be preparing a major strike campaign on Kyiv energy infrastructure drawing on strategic missile reserves โ the highest-probability kinetic + cyber window since the Patriot battery strikes in May.CriticalUkrainian Strategic Communications, German diplomatic ministry, and multiple Western partners have all independently confirmed an elevated threat posture through August 24. Russia has a documented pattern of timing mass strikes and cyber operations to coincide with major Ukrainian state holidays. Critical infrastructure facilities โ power substations, thermal power plants, railway hubs โ face the highest targeting probability. Cyber pre-staging (NoName DDoS, OT network probing) typically precedes kinetic strikes by 24โ72h. Ukrainian CERT and NATO partners should treat August 22โ24 as a maximum-alert window. Visit Ukraine threat assessment ยท Kyiv Independent ยท Zelensky warning
Baylor Genetics genetic data joins CareCloud as the second healthcare genomics/EHR breach in one week โ together they confirm that specialized health data platforms holding the most sensitive categories of personal data (genetic, psychiatric, reproductive) operate below the security baseline of the regulated entities they serve.CriticalGenetic test results are immutable identifiers that enable discrimination, insurance fraud, and blackmail at a qualitatively different level from SSNs alone. Baylor Genetics serves oncology and reproductive health clients through hospital and specialist practice channels โ the downstream patient population spans whatever subset of 305,066 individuals received genetic testing through those clinical relationships. The data category here exceeds what HIPAA breach notification disclosures typically communicate to patients; state AGs are likely to pursue enforcement beyond federal minimum requirements. BankInfoSecurity ยท Cybersecurity Dive
TrueConf Server's CISA KEV listing (two CVEs, CVSS 9.8/9.0, actively exploited) is more significant than the CVSS scores suggest: TrueConf is the dominant on-premises video conferencing platform for Russian government ministries, military agencies, and state-owned enterprises.HighWestern exploitation of these vulnerabilities against Russian targets would represent access to encrypted government communications infrastructure; Russian and allied state actors exploiting them against Western TrueConf deployments (NATO members with Russian-procured software in pre-accession or dual-use environments) could achieve equivalent access. The 2-day FCEB remediation deadline (August 23) reflects urgency; any organization with TrueConf in its supply chain or vendor base should treat this as a same-day priority. CISA KEV ยท Kaspersky ICS CERT
The Mabna Institute indictment and the DPRK kernel rootkit exploitation of CVE-2026-68820 in the same week confirm that state-affiliated actors โ not just criminal affiliates โ continue to use Patch Tuesday zero-day windows as strategic collection opportunities.HighThe pattern: a zero-day lands in the public domain via Patch Tuesday; nation-state actors with pre-positioned access weaponize it within days before enterprise patch cycles close the window. DPRK moved from disclosure (August 12 Patch Tuesday) to confirmed in-the-wild kernel rootkit deployment within approximately 72 hours โ a tempo that defeats monthly patch cadences. H1 2026 state-sponsored incidents: North Korea 99, Russia +30% (per Korea Times/TechTimes). Korea Times
M&A activity
Socure โ Fravityโ
Brinqa โ PlexTracโ
Munich Re (via HSB) โ $575Mโ
Fortinet โ Virtue AIโ