Confidential Β· 25 Aug 2026
π‘οΈ Daily Cybersecurity Briefing β 2026-08-25 (Tuesday)¶
Window: last 24β48h (Aug 23β25). Severity: π΄ CRITICAL Β· π‘ HIGH Β· π’ MEDIUM.
Threat level GUARDEDVictims L30D 105Top actor QilinM&A L30D $94.5M
πΌ M&A ACTIVITY¶
Brinqa acquires PlexTrac (Aug 19)MediumPen-testing and offensive-security reporting platform joins Brinqa's exposure management stack, closing the CTEM loop: identify exposures, prioritise, remediate, then prove the fix held. Deal makes Brinqa the largest standalone unified exposure management vendor (3,000+ customers, 57 countries, 25%+ of Fortune 500). Value undisclosed. Help Net Security Β· Yahoo Finance
L30D summary (Jul 25 β Aug 25): 22 deals tracked; total disclosed value exceeds $3.6B. Three headline transactions: Visa's $2.4B acquisition of BioCatch (behavioral biometrics, Aug 3); Cyera's ~$1B LOI to acquire Oasis Security (identity security, Jul 28); Okta's ~$200M acquisition of Permiso Security (cloud identity threat detection, Jul 30). Secondary cluster: ThreatLocker $190M Series D, Zenity $125M Series C (AI agent governance), Datavault AI's $94.5M acquisition of CyberCatch. Consolidation theme: exposure management is now a distinct category alongside identity and AI-security tooling β Brinqa/PlexTrac is the defining move of the week.
β οΈ CRITICAL BREACHES & INCIDENTS¶
Apollo Global Management β social engineering breach July 6β10; SSNs, DOBs, home addresses compromised; part of coordinated wave targeting major financial firmsCriticalApollo (NYSE: APO, AUM ~$700B) confirmed hackers breached its cloud platforms July 6β10 using phone-based vishing: attackers called employees posing as IT helpdesk staff to obtain access credentials. Data exposed includes names, dates of birth, contact information, home addresses, and Social Security numbers. Apollo learned of the scope on Aug 12 and notified California AG Aug 20. The group, tracked as Falcon/Helix/Pink/Redact, ran concurrent campaigns against Blackstone, Bridgewater, Bain Capital, and other financial and private-equity firms in the same window. No data publicly posted or ransomware deployed β this is a credential/PII exfiltration operation, not a ransomware event. TechCrunch Β· Bloomberg Β· PYMNTS
ShinyHunters β BOK Financial and NovoCure ransom deadlines expired Aug 24; no confirmed data publication at time of writingHighBoth deadlines passed as of yesterday's briefing. Neither BOK Financial nor NovoCure has issued a public statement confirming or denying. No verified data publication observed on the DLS as of this run. Monitor DLS and company disclosures; do not treat as confirmed breaches until data appears or companies notify. π₯ Unverified DLS claims. DEXpose/BOK Β· DEXpose/NovoCure
SynkLoader β new Microsoft Teams phishing malware family steals Windows credentials via fake IT-helpdesk lockscreenHighFirst compiled July 28; discovered Aug 18 by Expel during incident response on a client network. Attacker contacts victim via Teams impersonating the company's IT helpdesk, directs them to install a fake "PowerShell Cleaner" MSI hosted on Microsoft Azure (making the download appear trustworthy). Installer deploys Python-based loader that presents a fake Windows lock screen to harvest credentials; back-channel provides attackers with remote desktop, reverse proxy, and interactive PowerShell shell. LockBit 5.0 affiliates use a nearly identical Teams-helpdesk lure to push Quick Assist remote access β the pattern is now multi-group. Patch/block: restrict Teams to known federated tenants; disable or MFA-gate remote-assistance tools. BleepingComputer Β· Expel Β· The Hacker News
π CRITICAL VULNERABILITIES¶
CVE-2026-21962 β Oracle HTTP Server / WebLogic Server Proxy Plug-in; CVSS 10.0; CISA KEV Aug 24; 140,000+ attacks already loggedCriticalImproper access control in Oracle's HTTP Server and WebLogic Proxy Plug-in allows an unauthenticated network attacker to achieve total control of all accessible data β create, delete, modify, or exfiltrate. CVE disclosed January 2026; exploit code went public March 2026; active exploitation immediately followed. 140K+ attacks logged by Aug 25 (shattered.io). FCEB agencies must patch by CISA deadline (expect Sep 13). Non-FCEB: apply Oracle April 2026 CPU or latest security patch now. WebLogic is a high-frequency target: nation-state and commodity actors both exploit it at scale. CISA KEV Aug 24 Β· shattered.io Β· Penligent
CVE-2026-68820 β Windows WinSock use-after-free; FCEB deadline expired TODAY Aug 25; DPRK actors confirmed exploiting for kernel SYSTEMHighFCEB agencies were required to patch by end of today. DPRK-linked actors exploit this afd.sys EoP bug for SYSTEM-level access from a low-privileged local foothold. Any organisation not yet patched August 2026 Patch Tuesday cumulative update should treat this as urgent. CISA KEV Β· Rapid7
π¨ INTELLIGENCE AGENCY ALERTS & POLICY¶
CISA KEV Aug 24: CVE-2026-21962 (Oracle WebLogic Proxy Plug-in, CVSS 10.0)CriticalBOD 26-04 applies; FCEB agencies must remediate on deadline. 140K+ documented attacks make this a near-certain exploitation target for any exposed instance. Apply Oracle CPU patch immediately. CISA alert
CVE-2026-68820 FCEB deadline passed (Aug 25) β DPRK exploitation standing.HighDeadline expired today; any outstanding unpatched FCEB system is in breach of BOD. Audit patch state against August Patch Tuesday cumulative update. CISA KEV
Ukraine SBU/CERT-UA Independence Day window (Aug 24) β now passed; CERT-UA to publish post-event assessment.MediumRussian attacks on Aug 24 focused on physical infrastructure (143 drones + 8 missiles, 8 killed, 43 injured) with no separately confirmed major cyber infrastructure takedown. Monitor CERT-UA for any post-event cyber incident disclosure. Kyiv Independent Β· ABC News
π THREAT ACTOR & CAMPAIGN ACTIVITY¶
Qilin β #1 globally; Clear Align (US optical engineering), Difor (Chile), Aurore Development S.p.A. (Italy), Black Cat Engineering & Construction all claimed Aug 23; sustained posting pace with cross-sector, cross-geography spreadCriticalQilin posted four new victims in a single day, spanning three countries and three sectors (technology, distribution, professional services, construction). The geographic diversification β US, Chile, and Italy in one batch β is consistent with Qilin's deliberate spread to reduce pattern recognition and law-enforcement focus. All π₯ unverified DLS claims. DEXpose/Clear Align Β· DEXpose/Aurore Β· DEXpose/Difor
DragonForce β 7 new victims in 24 hours, UAE real estate and manufacturing focus; cumulative claim count at 631+ as of Aug 3HighDragonForce posted 7 victims in a 24-hour window, with UAE real estate and manufacturing sectors prominently targeted, representing a continuing expansion beyond DragonForce's traditional US/EU manufacturing base into the Gulf. π₯ Unverified DLS claims. PurpleOps Β· Ransomware.live/DragonForce
The Gentlemen β Espac (Chile, construction, Aug 24) claimed; maintained posting tempo on Ukraine Independence DayHighThe Gentlemen continue multi-sector, multi-continent posting pace, now adding Chilean construction to the Aug window (following Thialf, Promatrix, Babcock Africa in prior days). π₯ Unverified DLS claim. DEXpose/Espac
Apollo Global Management vishing wave (Falcon/Helix/Pink/Redact) β financially-motivated social engineering group running concurrent campaigns against multiple PE and hedge fund firmsHighThe same group that hit Apollo also targeted Blackstone, Bridgewater, and Bain Capital in the same JulyβAugust window. The tactic (phone-based IT helpdesk impersonation to obtain cloud credentials) requires no malware and bypasses most technical controls. Financial services and private equity firms with cloud-hosted data stores are the primary attack surface. Verify helpdesk call-back procedures and enforce out-of-band confirmation for any credential or access change. TechCrunch
π GEOPOLITICS¶
Analyst lens: how this week's cyber activity maps to state strategy. Defense Β· cyber Β· economics.
Russia chose physical kinetics over cyber for Ukraine's Independence Day, launching 143 drones and 8 missiles on Aug 24 and killing 8 β but the pre-positioned cyber pressure (APT29 OAuth campaign, UAC-0099 MATCHBOIL/DRAGSTARE) represents the persistent underlying coercive layer that does not need a specific execution date.CriticalThe Independence Day attack was primarily physical (Oniks anti-ship missiles, Kh-31P air-launched missiles, Shahed-type drones), not a cyber strike β Russia's cyber operations against Ukraine have shifted toward slower-burn intelligence collection and defense-industrial espionage rather than dramatic infrastructure takedowns. Ukraine downed 109 of 143 drones and 3 of 8 missiles; the remainder hit civilian and infrastructure targets. US Patriot interceptor deliveries remain halted. The cyber and physical pressure are complementary, not alternatives β watch for cyber follow-on as attack assessment data is collected. Kyiv Independent Β· ABC News
The Apollo/Blackstone/Bridgewater vishing wave signals that financially-motivated threat actors with DPRK-adjacent tactics are now systematically targeting private-equity and alternative-asset management firms β the "know your investor" data held in these firms' CRMs and cloud drives is a high-value secondary market target.CriticalSocial Security numbers, home addresses, and investor identity data from PE firms are raw material for SIM-swap attacks, targeted spear-phishing, and identity fraud against high-net-worth individuals. The Falcon/Helix/Pink/Redact group runs a structurally identical playbook to DPRK-linked Sapphire Sleet (IT-helpdesk impersonation) and Scattered Spider (vishing). Attribution is unconfirmed, but the escalation against regulated financial institutions will force SEC/FINRA disclosure obligations across multiple firms this quarter. Bloomberg Β· Benzinga
CVE-2026-21962 at CVSS 10.0 with 140,000+ documented attacks illustrates that commodity actors are now operating at nation-state scanning throughput β the distinction between "targeted" and "opportunistic" exploitation has collapsed for high-profile middleware.HighOracle WebLogic is embedded across government, financial services, and critical infrastructure globally. A CVSS 10.0 unauthenticated RCE on a widely deployed middleware server β with exploit code public since March 2026 β means any unpatched instance is de facto compromised. The KEV addition 5 months after CVE disclosure reflects a persistent exposure window caused by slow enterprise patch cycles in complex middleware environments. CISA KEV Β· shattered.io
SynkLoader and the Falcon/Helix/Pink/Redact vishing campaigns both exploit the same gap: employees will comply with urgent, authoritative-sounding requests from someone claiming to be IT or helpdesk, regardless of the channel β Teams, phone, or email.HighTwo independent groups, in the same two-week window, built their entire attack chain on social engineering rather than technical exploitation. LockBit 5.0 affiliates use the same Teams lure. This convergence suggests that for well-defended organisations with patched endpoints and EDR, the social engineering vector has become the path of least resistance. Defender response: mandatory out-of-band verification for any credential change, remote-access installation, or privilege request β regardless of whether the request comes via Teams, phone, or email. BleepingComputer Β· Expel
M&A activity
Socure β Fravityβ
Brinqa β PlexTracβ
Munich Re (via HSB) β $575Mβ
Fortinet β Virtue AIβ