Skip to content

Confidential ยท 30 Aug 2026

๐Ÿ›ก๏ธ Daily Cybersecurity Briefing โ€” 2026-08-30 (Sunday)

Window: last 24โ€“48h (Aug 28โ€“30). Severity: ๐Ÿ”ด CRITICAL ยท ๐ŸŸก HIGH ยท ๐ŸŸข MEDIUM.

Threat level GUARDEDVictims L30D 98Top actor QilinM&A L30D $94.5M

๐Ÿ’ผ M&A ACTIVITY

No new cybersecurity M&A deals confirmed in the Aug 29โ€“30 windowMediumUS Labor Day weekend (Aug 30 โ€“ Sep 1) is consistently the quietest period in the deal calendar. Expect a burst of announcements at mWISE (Sep 15โ€“17) and other September conference events.
L30D summary (Jul 31 โ€“ Aug 30): 16 named deals tracked in database; total disclosed value exceeds $4.1B. Headline transactions: Visa's $2.4B acquisition of BioCatch (behavioral biometrics/fraud prevention, Aug 3); Cyera's ~$1B LOI to acquire Oasis Security (AI agent identity, Jul 28); Okta's ~$200M acquisition of Permiso Security (cloud identity threat detection, Jul 30); ThreatLocker's $190M Series D (zero-trust endpoint, Jul 30); Zenity's $125M Series C (AI agent governance, Aug 4); Datavault AI's $94.5M acquisition of CyberCatch (compliance AI, Aug 14). Consolidation theme: identity security, AI agent governance, and exposure management remain the three dominant vectors; Bank of America's acquisition of UK red-team firm MDSec (undisclosed, Aug 3) signals enterprise financial-sector in-housing of offensive security capability. SecurityWeek M&A Tracker

โš ๏ธ CRITICAL BREACHES & INCIDENTS

Rhysida claims Berlin state government โ€” 5.79TB exfiltrated Aug 7โ€“12; 30 BTC ransom demand; Berlin refuses to pay; data auction timer started Aug 28CriticalRhysida posted a DLS claim on August 28 stating it extracted 5.79TB from Berlin's Senate Department for Mobility, Transport, Climate Protection and Environment between August 7 and 12, 2026. The group claims 80,000 administrative offence proceedings and 46,500 contracts, plus emails, phone numbers, passwords, and classified material. The 30 BTC demand (approx EUR 2M) was rejected by Mayor Kai Wegner and Interior Senator Iris Spranger: "The state of Berlin will not submit to extortion." Rhysida has started a seven-day auction countdown. Interior Senator Spranger stated that areas relevant to the September 20 Abgeordnetenhaus (state parliament) election have not been compromised. ๐ŸŸฅ DLS claim unverified; scope based on group assertion. Rhysida is thought to operate from Russia/Eastern Europe; it previously attacked the British Museum. The Hacker News ยท Security Affairs ยท Yahoo News
Boston Scientific โ€” cyberattack disruption confirmed to include manufacturing; no restoration timeline as of Aug 29CriticalMedTech Dive confirmed on August 29 that the Boston Scientific cyberattack (discovered Aug 25, disclosed Aug 26) has disrupted product manufacturing in addition to order processing and shipping. Employees at the Cork, Ireland factory remain unable to work. The company has not identified the actor, disclosed the attack vector, or provided a restoration timeline. Boston Scientific manufactures stents, defibrillators, and electrophysiology catheters used in time-sensitive cardiovascular procedures โ€” extended disruption carries patient-safety implications. No new actor attribution in this window. MedTech Dive ยท Boston Scientific IR
Cosmos EVM blockchain โ€” Cosmos Labs admits it wrongly cleared the vulnerability behind the $5.7M six-chain exploit (Aug 29 post-mortem)HighThe Block reported August 29 that Cosmos Labs has acknowledged it incorrectly assessed the vulnerability (GHSA-7g4w-cg88-2cq2) as posing "no risk to funds" when it was first reported via bug bounty on April 25. The flaw โ€” a balance-handling error in the shared Cosmos EVM module โ€” was exploited from August 20โ€“25 across six blockchains (MANTRA lost $3.6M; KiiChain lost 148M KII tokens; four others affected; total approx $5.7M). The attack began 11 hours and 50 minutes after the first public pull-request describing the exploitation path. Cosmos Labs urged all EVM chains to halt validators and apply emergency patches; most have now done so. ๐ŸŸฅ Official post-mortem from Cosmos Labs; individual chain losses partially verified; total figure is an aggregate. The Block ยท The Hacker News ยท Crypto.news

๐Ÿ”“ CRITICAL VULNERABILITIES

PaperCut NG/MF โ€” Release 2 of the emergency patch now live (Aug 28); organizations that applied the original patch must update againHighPaperCut released Release 2 of its August 27 emergency patch following discovery that the original patch could be bypassed via multiple paths. Release 2 (available for versions 24, 25, 26) includes additional hardening developed with Huntress and watchTowr. Organizations that patched over the Aug 27โ€“28 weekend should verify they are running Release 2. CVE-2026-81578 (CVSS 8.8 auth bypass) and CVE-2026-82078 (CVSS 9.4 unsafe class loading) remain actively exploited. PaperCut is investigating reports of post-patch issues with Card/ID lookup and SAML (a known Release 1 side effect not present in Release 2). PaperCut Advisory ยท BleepingComputer
ServiceNow โ€” three CVSS 10.0 flaws remain unpatched on self-hosted deployments; holiday-weekend exploitation windowCriticalServiceNow's three maximum-severity vulnerabilities (CVE-2026-18885, CVE-2026-18886, CVE-2026-74820 โ€” unauthenticated code injection, privilege escalation, and SQL injection) were patched August 27; cloud-hosted customers were auto-patched, but self-hosted instances (common in regulated sectors) require manual action. The Labor Day weekend is a favored exploitation window for threat actors targeting US enterprise IT teams running with reduced staff. CISA has not yet added these to the KEV catalog; the absence of a deadline should not delay patching. The Hacker News

๐Ÿšจ INTELLIGENCE AGENCY ALERTS & POLICY

No new CISA/FBI/NSA/NCSC advisories or KEV additions in the Aug 29โ€“30 windowMediumThe Aug 26 KEV batch (Citrix NetScaler CVE-2026-8452 and Microsoft SQL Server CVE-2019-1068 with Aug 29 deadlines, plus four others) remains the active FCEB action set. Next KEV batch is expected early week of Sep 1. The Cosmos EVM exploit has no CVE assigned; if exploited instances of Cosmos-based DeFi infrastructure are categorized as critical national financial infrastructure by any Five Eyes regulator, a CISA advisory would be expected.

๐ŸŒ THREAT ACTOR & CAMPAIGN ACTIVITY

Rhysida โ€” Berlin breach extends the group's targeting of high-value European institutions and critical social infrastructure; pre-election timing raises interference concernsCriticalRhysida's Berlin claim adds a major European capital government to a portfolio that includes the British Museum (UK, 2024), Lurie Children's Hospital (US, 2024), and the NHS vendor Synnovis (UK, 2024). The group characteristically targets organisations where data sensitivity maximises extortion leverage. The September 20 Berlin election timing is the most sensitive aspect: even if election systems are unaffected (as Interior Senator Spranger stated), the publication of 46,500 contracts and 80,000 administrative proceedings from the city government two weeks before a vote is a democracy-manipulation capability regardless of Rhysida's commercial motive. Berlin's refusal to pay means the data auction proceeds.
Qilin โ€” 6 new victims on Aug 29 alone; full-year total exceeds 2,200; group dominates 2026 ransomware volumeCriticalRansomware.live reported 19 total ransomware victims on August 29, with Qilin accounting for six โ€” including Bandit Industries (US manufacturing) and LAPoco Architects (US professional services). ๐ŸŸฅ DLS claims unverified; confirm before treating as confirmed breaches. Qilin's 2,200+ cumulative total and 140+ August victims (with two days remaining in the month) make it the single most active ransomware group of 2026 by a wide margin. Manufacturing (5 victims Aug 29 across all groups) and Retail/E-Commerce (3 victims) were the highest-targeted sectors for the day. Ransomware.live
Cosmos EVM exploit โ€” 11-hour window from public exploitation path to first attack; bug-bounty process failed; blockchain infrastructure concentration risk validatedHighThe Cosmos EVM timeline (bug bounty April 25, wrongly cleared, public PR describing exploitation path August 20 at 07:16 UTC, first attack August 20 at 19:06 UTC) is a documented case of shared-infrastructure concentration risk materializing at scale. Six independent blockchains running the same EVM module were simultaneously vulnerable; the attacker needed to exploit only one shared library to drain six networks. This mirrors the supply-chain concentration risk documented in the ai-infrastructure-concentration-risk signal.

๐ŸŒ GEOPOLITICS

Analyst lens: how this week's cyber activity maps to state strategy. Defense ยท cyber ยท economics.
Rhysida's Berlin attack two weeks before the September 20 state election is structurally indistinguishable from an influence operation, regardless of the group's stated commercial motive.CriticalThe exfiltration of 46,500 Berlin government contracts and 80,000 administrative proceedings โ€” now offered for auction โ€” gives any state actor that purchases the data a complete map of Berlin's regulatory relationships, supplier dependencies, and administrative decisions. Germany's federal election is over, but the Berlin state parliament (Abgeordnetenhaus) contest on September 20 occurs in the city that hosts NATO headquarters, Germany's federal ministries, and the EU's primary diplomatic corridor. The data's intelligence value to any adversary interested in European governance exceeds its EUR 2M ransom price by orders of magnitude. The Hacker News ยท Security Affairs
The Cosmos EVM exploit is the first documented case of a bug-bounty failure leading to multi-chain DeFi infrastructure loss at this scale, and it validates the structural risk that shared blockchain infrastructure modules pose to the global crypto economy.CriticalCosmos EVM is used by dozens of chains; $5.7M was drained from six in five days because the same library was shared across all of them. Cosmos Labs' April 25 triage ("no risk to funds") was wrong; the window from a public proof-of-concept to exploitation was under 12 hours. As DeFi platforms begin handling regulated financial assets (tokenized securities, stablecoins, CBDC bridges), infrastructure failures at this layer move from "crypto losses" to "financial system losses" on regulators' risk maps. The Block ยท The Hacker News
Boston Scientific's extended disruption โ€” now confirmed to include manufacturing, not just logistics โ€” is a test case for whether US healthcare supply chain regulation has kept pace with the sector's digital dependencies.HighThe FDA's medical device cybersecurity guidance (2023) applies to device design, not to the ERP and order-management systems that route physical product. Boston Scientific's Cork factory going offline for a week because of a cyberattack against business systems โ€” not the devices themselves โ€” is a regulatory gap: the disrupted systems are neither FDA-regulated nor covered by HIPAA, yet their failure removes cardiovascular devices from hospital supply chains. CISA's healthcare sector risk advisor and FDA's CDRH should be coordinating on this now. MedTech Dive ยท TechCrunch
The ServiceNow CVSS 10.0 cluster and the PaperCut second-patch-required situation share a structural feature: enterprise platforms that are trusted by design are not being treated as attack surfaces.HighServiceNow holds privileged maps of IT estates across defense contractors and federal agencies; PaperCut controls print workflows in NHS trusts and clinical environments. Both are "operational background" tools that security teams rarely include in crown-jewel asset inventories. The Labor Day weekend โ€” reduced staff, slower patch cycles, attacker awareness of holiday windows โ€” makes the next 72 hours the highest-risk period for ServiceNow self-hosted deployment exploitation since the advisory was published. The Hacker News ยท BleepingComputer
Threat actors
1 ยท Qilin546 YTD
2 ยท The Gentlemen335 YTD
3 ยท Akira228 YTD
4 ยท DragonForce248 YTD
M&A activity
Socure โ†’ Fravityโ€”
Brinqa โ†’ PlexTracโ€”
Munich Re (via HSB) โ†’ $575Mโ€”
Fortinet โ†’ Virtue AIโ€”