Skip to content

Confidential ยท 24 Aug 2026

๐Ÿ›ก๏ธ Daily Cybersecurity Briefing โ€” 2026-08-24 (Monday)

Window: last 24โ€“48h (Aug 22โ€“24). Severity: ๐Ÿ”ด CRITICAL ยท ๐ŸŸก HIGH ยท ๐ŸŸข MEDIUM.

Threat level GUARDEDVictims L30D 111Top actor QilinM&A L30D $94.5M

๐Ÿ’ผ M&A ACTIVITY

No new cybersecurity M&A or funding deals were announced over the Aug 23โ€“24 weekend window. Deal flow resumes Monday.
L30D summary (Jul 25 โ€“ Aug 24): 21 deals tracked; total disclosed value exceeds $3.6B. Three headline transactions: Visa's $2.4B acquisition of BioCatch (behavioral biometrics, Aug 3); Cyera's ~$1B LOI to acquire Oasis Security (identity security, Jul 28); Okta's ~$200M acquisition of Permiso Security (cloud identity threat detection, Jul 30). Secondary cluster: Zenity $125M Series C (AI agent governance), Oligo Security $60M Series C (runtime application security), Datavault AI's $94.5M all-cash acquisition of CyberCatch Holdings (compliance SaaS, Aug 14). Consolidation theme: identity and AI-security tooling dominate, with behavioral biometrics moving into financial-services critical infrastructure via the Visa/BioCatch deal.

โš ๏ธ CRITICAL BREACHES & INCIDENTS

Russia-linked APT29 subclusters (ICE RELIC/UNC7005/UNC5976) โ€” abusing Google OAuth and WhatsApp device-linking to steal authentication tokens from defense, government, and think-tank targets, bypassing MFACriticalGoogle GTIG published Aug 21 revealing three Russia-linked espionage clusters targeting academics, diplomats, defense personnel, and think-tank researchers across the US and Europe. The groups โ€” assessed with high to moderate confidence as APT29/Cozy Bear subclusters โ€” manipulate victims into completing genuine OAuth, device-code, and device-linking authentication flows that hand attackers authenticated sessions without ever capturing a password. In one documented Aug 2026 operation, UNC7005 impersonated the Finnish Operations Center and routed targets through real Google OAuth pages toward attacker-controlled cloud projects. This is a step-change from credential-harvesting pages: MFA provides no defence if the attacker acquires a valid session token through a legitimate login. Targets: defense establishments, government ministries, academic institutions. Google GTIG ยท The Hacker News ยท The Register
ShinyHunters โ€” BOK Financial and NovoCure ransom deadlines expire TODAY (Aug 24); data publication status unconfirmed at briefing timeHighShinyHunters posted BOK Financial (NASDAQ: BOKF, $50B+ assets, Tulsa OK) and NovoCure (NYSE: NVCR, global oncology company, Baar Switzerland) on Aug 22 with a final deadline of Aug 24. Both deadlines hit as of this briefing. No official statements from either company; no confirmed data publication observed at time of writing. A separate partially redacted "Cyrus" listing carries the same deadline. Verify DLS status before treating as confirmed breaches. ๐ŸŸฅ Unverified DLS claims. DEXpose/BOK Financial ยท DEXpose/NovoCure
UAC-0099 (Russia-linked) โ€” MATCHBOIL/DRAGSTARE malware wave against Ukrainian government and defense sector ahead of Independence Day (Aug 24)HighCERT-UA documented a renewed UAC-0099 campaign using MATCHBOIL (loader), MATCHWOK (backdoor), and DRAGSTARE (stealer) against Ukrainian government agencies, defence forces, and defense-industrial enterprises. Attack vector: phishing emails disguised as court summons from UKR.NET addresses with shortened links to double-archived HTA files. Execution deploys a C# loader chain with scheduled-task persistence. Ukraine's Security Service (SBU) separately warned of elevated risk of cyberattacks timed to Aug 24 (Independence Day, 35th anniversary, fifth during full-scale invasion). SOC Prime / CERT-UA ยท The Hacker News ยท SBU Warning

๐Ÿ”“ CRITICAL VULNERABILITIES

CVE-2026-68820 โ€” Windows WinSock use-after-free; FCEB deadline TOMORROW Aug 25; North Korean actors exploiting for kernel SYSTEM escalationCriticalAdded to CISA KEV on Aug 11. DPRK-linked actors exploit this afd.sys elevation-of-privilege bug (low-privileged local attacker, no user interaction) to reach SYSTEM. FCEB agencies must patch by Aug 25. Non-FCEB: patch August 2026 Patch Tuesday cumulative update now. Rapid7 Patch Tuesday Analysis
CVE-2026-59310 โ€” Broadcom VMware vCenter path traversal (CVSS 9.8); unauthenticated RCE; Chinese-speaking actor exploiting with AI-enabled autonomous hacking toolsCriticalA Chinese-speaking threat actor is chaining CVE-2026-59310 (path traversal to arbitrary code execution from network access) with an AI-enabled autonomous hacking capability using DeepSeek for reconnaissance alongside manual exploitation. vCenter is a high-value target for lateral movement across virtualised infrastructure. Patch immediately. The Hacker News / CISA KEV ยท Senserva KEV tracker
CVE-2026-64849 โ€” MLflow SSRF (CISA KEV Aug 19); unauthenticated cloud credential theft via metadata endpoint abuseHighAttackers request cloud metadata endpoints via the exposed MLflow server, extracting temporary IAM credentials for lateral movement and data access. Affects MLflow versions before 3.15.0; actively scanned within hours of CVE assignment Aug 17. FCEB patch deadline: Sep 2. Patch or isolate MLflow instances immediately. BleepingComputer ยท CISA KEV Aug 19

๐Ÿšจ INTELLIGENCE AGENCY ALERTS & POLICY

FCEB deadline: CVE-2026-68820 (Windows WinSock) โ€” TOMORROW Aug 25.HighDPRK-linked actors confirmed exploiting for SYSTEM-level privilege escalation. Apply August 2026 Patch Tuesday cumulative update. CISA KEV catalog
Ukraine SBU/CERT-UA elevated alert โ€” Independence Day cyberattack risk window Aug 24.HighCERT-UA confirmed active UAC-0099 MATCHBOIL/DRAGSTARE campaign against government and defense. SBU warned of possible coordinated cyber and physical attacks timed to Aug 24 national events. CERT-EU and allied centres on heightened monitoring. Euromaidan Press ยท CERT-UA / SOC Prime
CISA/FBI/NSA Gunra ransomware advisory (AA26-222A, Aug 10) โ€” standing.MediumGunra RaaS targeting healthcare, government, financial services via Fortinet edge-device flaws (CVE-2024-55591, CVE-2025-24472). IOCs and mitigations at CISA AA26-222A.

๐ŸŒ THREAT ACTOR & CAMPAIGN ACTIVITY

Qilin โ€” #1 globally (335 L3M, 546 YTD); maintained posting pace over the weekend (PenLink, Agunsa, Quaker State Mexico, iPic); ongoing risk for European government and critical infrastructure around Ukraine Independence DayCriticalQilin posted PenLink (law enforcement data analytics), Agunsa (Chilean port logistics), Quaker State Mexico (petroleum), and iPic (cinema chain) on Aug 21โ€“22. All ๐ŸŸฅ unverified DLS claims. Qilin now accounts for roughly one in five ransomware victims globally in 2026. The Independence Day window (Aug 24) is an elevated risk period for Qilin and RaaS affiliates given documented targeting of European public-sector organisations. Qilin / ransomware.live
DragonForce โ€” R&D Machine and Engineering (US aerospace/defense, Aug 18) added to DLS; 631 cumulative claimed victims as of Aug 3; continues to expand into aerospace/defense sectorHighDragonForce posted R&D Machine and Engineering (rdmachine.com), an aerospace and defense manufacturer. Aerospace/defense is a high-sensitivity sector. Together with the July APAC MSP/telecom cluster (Edison Global Networks, ATCOM Technology), DragonForce is expanding beyond its traditional US/EU manufacturing base. ๐ŸŸฅ Unverified DLS claim. DEXpose
The Gentlemen โ€” Thialf (Netherlands), Promatrix, Babcock Africa posted Aug 18โ€“22; maintained high operational tempo heading into Independence Day windowHighThe Gentlemen, currently ranked #2 globally, continue to post multi-sector European and African victims. Babcock Africa (engineering services), Thialf (Dutch speed-skating arena โ€” critical event infrastructure), and Roadvision Systems (US transport tech, Aug 18) were claimed. ๐ŸŸฅ Unverified DLS claims. HookPhish
UAC-0099 / Russian APT โ€” MATCHBOIL/DRAGSTARE stealer campaign against Ukraine; CERT-UA attribution; targeting government ministries and defense-industrial firmsMediumDistinct from the APT29/ICE RELIC OAuth campaign above: UAC-0099 uses phishing and HTA payload chains as the intrusion method rather than session-token hijacking. The two campaigns together represent coordinated Russian cyber pressure against Ukrainian government and allied Western institutions simultaneously. SOC Prime

๐ŸŒ GEOPOLITICS

Analyst lens: how this week's cyber activity maps to state strategy. Defense ยท cyber ยท economics.
Russia is running simultaneous cyber operations at the strategic, operational, and tactical levels on Ukraine's Independence Day โ€” the joint APT29/ICE RELIC token-theft campaign against Western institutions and the UAC-0099 MATCHBOIL/DRAGSTARE attacks against Kyiv agencies are not separate incidents; they are coordinated pressure across fronts.CriticalThe GTIG disclosure (OAuth abuse against US/EU defense and think tanks) and the CERT-UA disclosure (HTA-phishing against Ukrainian government and defense-industrial firms) landed in the same week. Russia uses symbolic dates as cover for cyber surges; Aug 24 is the highest-risk single day of the calendar year for Ukraine-linked targets. Western defence ministries and defense contractors should assume heightened persistence attempts through today. GTIG ยท CERT-UA/SOC Prime
The APT29/ICE RELIC OAuth pivot โ€” moving from credential-harvesting pages to legitimate authentication flows โ€” is the most significant Russian tradecraft shift in 2026 and directly undermines enterprise MFA postures.HighDefenders who rely on phishing-resistant MFA have a partial gap: if users can be socially engineered into authorising a legitimate OAuth app owned by the attacker, the session token is valid regardless of MFA. The attack surface is every service that allows OAuth delegation โ€” Google Workspace, Microsoft 365, Okta, and any app-password delegation flow. Decision point: restrict third-party OAuth app authorisations to an approved list at the IdP level. GTIG / Security Affairs
North Korea's confirmed exploitation of CVE-2026-68820 for kernel-level SYSTEM privileges maps to DPRK's established pattern of pairing cyber-for-cash ransomware operations with precision APT access tools.HighThe WinSock vulnerability gives DPRK affiliates local privilege escalation on any Windows host where an operator already has a foothold โ€” exactly the capability needed to move laterally in corporate environments toward financial systems. The FCEB Aug 25 deadline is too late for any organisation already under a DPRK intrusion. Patch now, then audit for signs of the afd.sys exploitation chain. Rapid7
China's deployment of AI-enabled autonomous hacking tools in production against VMware vCenter (CVE-2026-59310) signals that AI-augmented exploitation has moved from research to operational use.HighThe documented combination of DeepSeek-powered autonomous reconnaissance with manual CVE exploitation on a CVSS 9.8 RCE suggests China is optimising attack throughput โ€” more targets, faster exploitation, lower operator cost per breach. Western critical-infrastructure operators should treat high-CVSS unauthenticated RCE flaws as under active AI-automated scanning, not just human-targeted exploitation. The Hacker News
The ShinyHunters extortion pressure on BOK Financial (BOKF, $50B+ assets) illustrates a sector shift: financial services have moved from being a well-defended secondary target to a primary extortion campaign vector in 2026.MediumShinyHunters now runs six concurrent financial and healthcare extortion campaigns (BOK, NovoCure, Baxter, Logitech, Lumenis, Alcon). The Alcon case shows systematic claim inflation (25M records claimed, 218K published), but even an inflated claim against a regulated institution triggers disclosure obligations, regulatory scrutiny, and reputational cost โ€” the extortion payoff is real regardless of the data scope. DEXpose
Threat actors
1 ยท Qilin546 YTD
2 ยท The Gentlemen335 YTD
3 ยท Akira228 YTD
4 ยท DragonForce248 YTD
M&A activity
Socure โ†’ Fravityโ€”
Brinqa โ†’ PlexTracโ€”
Munich Re (via HSB) โ†’ $575Mโ€”
Fortinet โ†’ Virtue AIโ€”