Confidential Β· 28 Aug 2026
π‘οΈ Daily Cybersecurity Briefing β 2026-08-28 (Friday)¶
Window: last 24β48h (Aug 27β28). Severity: π΄ CRITICAL Β· π‘ HIGH Β· π’ MEDIUM.
Threat level GUARDEDVictims L30D 105Top actor QilinM&A L30D $94.5M
πΌ M&A ACTIVITY¶
No new cybersecurity M&A deals confirmed in the Aug 27β28 windowMediumno announcements identified from SecurityWeek, Infosecurity Magazine, or trade press in this period. Deal velocity typically slows at the end of August before accelerating in September with conference season (mWISE, Cybersecurity Summit). Most recent tracked deal: Brinqa acquires PlexTrac (Aug 19, undisclosed value, exposure management).
L30D summary (Jul 29 β Aug 28): 22+ deals tracked; total disclosed value exceeds $3.8B. Five headline transactions: Visa's $2.4B acquisition of BioCatch (behavioral biometrics, Aug 3); Cyera's ~$1B LOI to acquire Oasis Security (identity security, Jul 28); Okta's ~$200M acquisition of Permiso Security (cloud identity threat detection, Jul 30); ThreatLocker's $190M Series D (Jul 30); Zenity's $125M Series C (AI agent governance, Aug 4). Secondary cluster: Datavault AI's $94.5M acquisition of CyberCatch, Oligo Security's $60M Series C (runtime security), Brinqa/PlexTrac (exposure management). Consolidation theme: identity security, AI agent governance, and exposure management remain the three dominant consolidation vectors; the pipeline is active and the August 2026 SecurityWeek roundup (not yet published) will confirm the full month count.
β οΈ CRITICAL BREACHES & INCIDENTS¶
Manchester Airports Group β 8.7M customers' data stolen across three UK airports (disclosed Aug 27)CriticalManchester Airports Group (MAG) confirmed a cyberattack over the weekend that exposed personal data of approximately 8.7 million customers of Manchester Airport, London Stansted, and East Midlands Airport. Compromised data includes airport WiFi registrations, email addresses, phone numbers, vehicle registrations, and parking/lounge/fast-track bookings. Payment card numbers and account passwords were not on the affected system. MAG says it contained the breach immediately and is working with specialist advisers and relevant authorities. A ransom was demanded but not paid. No threat actor has been publicly attributed. Aviation safety and passenger operations were unaffected. Scale makes this one of the largest UK data incidents of 2026; the WiFi email harvest of ~8.7M addresses is likely to fuel follow-on phishing campaigns. The Register Β· Cybernews Β· Infosecurity Magazine
Qilin DLS β Providence Investments (USA, financial services) and Displaydata (UK, technology) posted Aug 27HighQilin added two new victims to its data-leak site on August 27: Providence Investments (US financial services) and Displaydata (UK, electronic shelf-label technology company). Neither listing provides data samples, exfiltration volume, or ransom details. π₯ Unverified claims; verify before treating as confirmed breaches. Both are part of Qilin's 104+ victim August total. RedPacket/Providence Β· ransomware.live/Displaydata
Akira DLS β Cetylite Industries, CGP MEP, and Seabrook Island Community posted Aug 27MediumAkira posted three new victims on August 27: Cetylite Industries (US, specialty chemical/pharmaceutical ingredient manufacturer), CGP MEP (MEP engineering/construction), and Seabrook Island Community (US, property management/residential HOA). π₯ All unverified DLS claims. Akira maintains its position as the #2 August group by volume. RansomLook/Akira
π CRITICAL VULNERABILITIES¶
CVE-2026-60004 β Gitea code injection; FCEB deadline TODAY (Aug 28); cryptomining malware confirmed on 5,000+ exposed instancesCriticalCISA added CVE-2026-60004 to the KEV catalog (Aug 25) and set a Federal Civilian Executive Branch (FCEB) remediation deadline of August 28, 2026. Exploitation is confirmed: a developer published an incident report describing how their self-hosted Gitea instance was compromised and crypto-mining malware deployed; Shadowserver now tracks approximately 5,000 Gitea instances exposed online. The flaw allows an authenticated user with only repository write permissions (not admin) to abuse Gitea's `diffpatch` endpoint to install and execute a Git hook from repository-controlled content, enabling RCE as the Gitea service account. Patch: Gitea 1.27.1 (released late July 2026). Any organization running self-hosted Gitea must patch today or take the instance offline. Help Net Security Β· BleepingComputer Β· CISA
CVE-2026-66384 β JFrog Artifactory path traversal; KEV added Aug 27HighCISA added CVE-2026-66384 (JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory) to the KEV catalog on August 27. The flaw allows an authenticated user to write data outside the intended Docker cache path via archive extraction/write handling with traversal sequences. Exploited in the wild. JFrog has issued a patch; the vulnerability is distinct from the AI-discovered Artifactory zero-days (CVE-2026-65617 series) documented in July but affects the same product family. FCEB agencies must remediate by September 9, 2026. CISA KEV Aug 27 Β· JFrog Security Advisories
CVE-2026-53362 (Linux Kernel) and CVE-2023-49105 (ownCloud Improper Authentication) β KEV added Aug 27HighCISA also added CVE-2026-53362 (Linux Kernel unspecified vulnerability) and CVE-2023-49105 (ownCloud authentication bypass β a 2023 flaw still exploited in 2026) to the KEV catalog. Linux kernel flaw: FCEB deadline September 9. ownCloud: already patched in 2023 but still being exploited against unpatched instances. CISA KEV Aug 27
π¨ INTELLIGENCE AGENCY ALERTS & POLICY¶
N-able N-central MSP platform β authentication bypass enables attackers to reach all managed customer endpoints; second hotfix now required (CVE-2026-18577)CriticalAttackers exploited an authentication bypass in N-able's N-central Remote Monitoring and Management (RMM) platform β used by MSPs to manage thousands of client endpoints β to gain administrative access and pivot to customer networks. After compromising an N-central server, attackers used the platform's legitimate Take Control feature to reach managed endpoints and registered persistent Cloudflare tunnels (no inbound firewall rule required, survive reboots). The first patch (August 2) proved incomplete; the second hotfix (version 2026.3.1.10) is now required for all on-premises deployments. Cloud-hosted deployments are also affected. CISA added CVE-2026-18577 to the KEV catalog. MSPs running N-central must apply the second hotfix immediately; customer networks remain exposed until they do. This is a supply-chain attack on the MSP layer itself β the blast radius is every endpoint that N-central manages. The Hacker News Β· The Register Β· Huntress
Operation QUICSILVER β China-nexus actor targets Myanmar diplomats with QUICAgent Go backdoor; ASEAN/BIMSTEC intelligence interests confirmed (Seqrite/The Hacker News Aug 18β26)HighSeqrite and The Hacker News documented a China-nexus espionage campaign (Operation QUICSILVER) targeting Myanmar government and IT sectors from AprilβJuly 2026. Lures include Burmese-language documents impersonating Myanmar's Information Technology and Cyber Security Department and graduation ceremony invitations for government training programs. The final payload is QUICAgent, a 64-bit Go 1.20 backdoor that hides C2 traffic in QUIC protocol to Cloudflare Workers URLs, delaying execution and performing 1,000 SHA-256 iterations to evade analysis. Recovered deleted files indicate interest in ASEAN, BIMSTEC, UN meetings, Malaysia, China, and Myanmar foreign affairs β classic pre-positioning for regional diplomatic intelligence. Broader coverage appeared Aug 18β26. Seqrite Β· The Hacker News
π THREAT ACTOR & CAMPAIGN ACTIVITY¶
Qilin β August total now 110+; Providence Investments and Displaydata extend the run; continues to dominate 2026 ransomware volumeCriticalQilin's August victim count surpassed 104 as of Aug 26 and continues to grow. With the Aug 27 additions (Providence Investments, Displaydata, plus LGG Advisors, Open Sports, DAB Investments per Ransomware.live), the group is on track for its highest single-month total. The ATF posting last week (unconfirmed, no data samples) remains the highest-profile government claim. Qilin has claimed 2,203 cumulative victims and 891 in 2026 alone. The August surge is led by financial services, manufacturing, and technology β sectors where Qilin has historically underperfomed relative to Akira. ransomware.live/qilin Β· RedPacket
Akira β Cetylite, CGP MEP, Seabrook Island (Aug 27); consistent #2 in August with 56+ victimsHighAkira posted three new Aug 27 victims and remains the second-most-active ransomware group in August, trailing Qilin significantly but ahead of Sinobi (which emerged as #3 last week). Akira focuses on corporate SME targets in the $10Mβ$100M revenue range. RansomLook/Akira
Three Russia-linked clusters (UNC6293, UNC7005, UNC5976) targeting academia, aerospace/defense, governments, and think tanks across Europe and US via legitimate authentication flowsHighGoogle Threat Intelligence Group tracking three distinct Russia-nexus threat clusters conducting cyber espionage via OAuth token theft and abused cloud authentication flows (not traditional phishing), complicating detection. Targets span academic institutions, aerospace and defense contractors, Western European governments, and policy think tanks. The OAuth authentication-abuse vector (first documented in the APT29 campaign reported Aug 21β24) is now confirmed across multiple Russia-linked operators. Malware Patrol Security Signals (Aug 11β25)
π GEOPOLITICS¶
Analyst lens: how this week's cyber activity maps to state strategy. Defense Β· cyber Β· economics.
The Manchester Airports Group breach β 8.7M records, actor unattributed β arrives the same week as the N-able MSP platform compromise (customer-network supply chain) and the Gitea developer-infrastructure exploit, forming a pattern that is more than coincidence: critical enabling infrastructure is now the primary target, with the goal of harvesting credentials and establishing persistent reach, not headline destruction.CriticalMAG's airport WiFi databases are intelligence goldmines: air-traveller identity graphs, travel patterns, vehicle registrations, and contact details for 8.7M people who include business travellers, government officials, and military personnel. The attacker's decision not to release data publicly (no DLS posting, ransom not paid, incident not claimed) is operationally consistent with intelligence collection rather than financial extortion. The N-able attack's use of Cloudflare tunnels for persistence is the same evasion technique documented in the Russia-GRU Amazon disclosure (Jul 28); the Gitea compromise targeting code repositories is the same vector as the DPRK supply-chain strategy documented at DEF CON Aug 9. None of these can be attributed with confidence on this window's evidence alone, but the convergence pattern is visible. The Register/MAG Β· The Hacker News/N-able
Russia's Bashkortostan oil refinery and Ozon logistics strikes (Aug 27) extend Ukraine's deep-strike doctrine to the Russian domestic economy: civilian commercial infrastructure is now a legitimate Ukrainian target, not just military logistics.HighUkrainian drones hit the Bashneft-Ufaneftekhim refinery in Ufa (Bashkortostan Republic) and Ozon e-commerce logistics facilities in Orenburg and Ufa on August 27, while Russian forces struck Poltava energy infrastructure and a Kyiv residential building the same night. The Ozon strike is the most symbolically significant: Ozon is Russia's equivalent of Amazon and serves tens of millions of Russian consumers. Ukraine is signaling that Russian economic normalcy behind the front is not protected. The cyber dimension of this escalation is the absence of cyber: both sides are currently prioritising kinetic strikes on economic infrastructure over the cyber harassment campaigns that characterised 2022β2024, suggesting cyber has been relegated to preparation-and-collection rather than disruption in the current operational phase. GlobalSecurity.org/Ukraine
Operation QUICSILVER's ASEAN/BIMSTEC intelligence focus confirms that China's diplomatic intelligence collection has expanded beyond its immediate Taiwan/South China Sea concerns to include the entire ASEAN diplomatic apparatus.HighMyanmar is particularly sensitive because of China's deep Belt and Road infrastructure investment and Myanmar's ongoing military-junta relationship with Beijing, which gives China both official access and a strategic interest in understanding how ASEAN partners view that relationship. The QUICAgent backdoor's use of Cloudflare Workers as a C2 relay is the same infrastructure-blending technique used by the Iranian MOIS-linked actors sanctioned August 24 β different state actors converging on the same evasion stack (trusted CDN infrastructure for C2) because Western ISPs and threat intelligence cannot easily block Cloudflare without collateral damage. Seqrite/QUICSILVER
The N-able N-central MSP takeover is the week's most structurally significant security event for European and UK mid-market businesses: the attack's blast radius is every endpoint managed through a compromised N-central server, meaning thousands of SME clients may have had lateral-movement access established without direct compromise of any individual organization.HighThe UK and EU SME market relies disproportionately on a small number of MSP management platforms (N-able, ConnectWise, Kaseya) β this is a concentration risk that regulators have noted but not resolved. The attack's persistence mechanism (Cloudflare tunnels registered as services, surviving reboot, requiring no inbound firewall rule) cannot be detected by perimeter security alone; each managed endpoint must be individually scanned. MSPs serving CNI-adjacent clients (NHS trusts, local government, utilities) should treat this as a potential indicator-of-compromise event across their full customer estate. The Register/N-able Β· Huntress
M&A activity
Socure β Fravityβ
Brinqa β PlexTracβ
Munich Re (via HSB) β $575Mβ
Fortinet β Virtue AIβ