data-breach Canada’s Hospital for Sick Children attacked by cybercriminals again as employee data stolen Canada’s Hospital for Sick Children suffered a data breach, exposing the personal information of current and former employees, potentially linked to a third-party software application. This follows a ransomware attack in… The Record · Aug 21, 2026 Medium healthcarecyberattackdata breach
threat-intel DYSPHOR1A, nouveau groupe de ransomware maître chanteur A new ransomware group, DYSPHOR1A, operating in conjunction with Normal Hunters, is leveraging a data extortion model – leaking and selling stolen data to pressure victims into paying to have the information removed. The… ZATAZ · Aug 21, 2026 High MYTHINdata-breachransomwareextortion
threat-intel Encore, encore, encore … un nouveau groupe ransomware : SovCali A new ransomware group, SovCali, has emerged, claiming to possess data from Lucid Motors and threatening to release 35 gigabytes of stolen information unless a private negotiation is established. SovCali operates by offe… ZATAZ · Aug 21, 2026 High RUransomwaretordata breach
threat-intel Cisco bug severity warning reads like Olympic gymnastics scores: 10, 10, 9.9, 9.6, and 7.5. This article is a collection of cybersecurity and technology news snippets from The Register. It covers a range of topics including a vulnerability in Microsoft SharePoint, a phishing campaign impersonating Signal suppor… The Register · Aug 21, 2026 Medium CVE-2026-20315CVE-2026-20317CVE-2026-20231vulnerabilityphishingransomware
threat-intel ISC Stormcast For Friday, August 21st, 2026 https://isc.sans.edu/podcastdetail/10062, (Fri, Aug 21st) The ISC Stormcast highlighted a significant increase in malicious email campaigns targeting financial institutions, leveraging sophisticated phishing techniques and exploiting vulnerabilities in legacy systems. The threa… SANS Internet Storm Center · Aug 21, 2026 High phishingransomwaresupply-chain
threat-intel US Bank investigates LockBit's claims as ransomware crims set pay-or-leak deadline A US bank is investigating claims by LockBit ransomware operators that they have stolen sensitive data and are threatening to leak it unless a ransom is paid. This follows a pattern of LockBit extortion attempts targetin… The Register · Aug 20, 2026 Medium ransomwarecybersecuritydata breach
threat-intel Ransomware crook poses as recovery firm to steal payments from fellow extortionists A Russian threat actor is impersonating Signal support to conduct phishing attacks targeting other ransomware groups. The goal is to steal payments intended for extortion activities, highlighting a concerning trend of or… The Register · Aug 20, 2026 Medium RUphishingransomwaresocial engineering
threat-intel Club One Casino revendiqué par 3AM puis PEAR Club One Casino is being linked to two separate extortion groups, 3AM and PEAR, in a concerning trend for the casino industry. Initial reports from August 2026 attributed the first attack to 3AM, focusing on internal fil… ZATAZ · Aug 20, 2026 Medium USransomwarecasinoextortion
threat-intel ICE boss to agents: Leave the Meta spy glasses at home Several security-related stories are emerging, including a warning about Meta’s spy glasses being used for phishing, a vulnerability exploited in Joomla extensions, and ongoing efforts to combat Iranian propaganda and ra… The Register · Aug 19, 2026 Medium IRcybersecuritythreat intelligencephishing
threat-intel Comcast gives its Wi-Fi motion detector a security makeover This article highlights a variety of cybersecurity and technology news stories, including a security update for Comcast's Wi-Fi motion detector, a method for social engineering AI reasoning engines, and ongoing efforts t… The Register · Aug 19, 2026 Medium IRsecurityphishingransomware
threat-intel Defending Against an Active Threat to Siemens S7 Series PLCs The National Security Agency (NSA), CISA, FBI, DOE, and EPA are issuing an advisory warning of an active cyber threat targeting Siemens S7 Series Programmable Logic Controllers (PLCs). Threat actors are leveraging AI to… CISA Advisories · Aug 19, 2026 High icsplccybersecurity
threat-intel StopAndProtect Uses Nearly 2,000 Hacked WordPress Sites to Spread Malware and Steal Data A sophisticated cybercrime operation, dubbed StopAndProtect, is leveraging over 6,000 compromised WordPress sites globally to distribute malware, steal data, and deploy ransomware. The attackers use a multi-stage attack… The Hacker News · Aug 19, 2026 High USRUINwordpressmalwareransomware
threat-intel Cl0p Ransomware Group Names Over 40 Victims of PTC Windchill Campaign The Cl0p ransomware group has publicly named over 40 organizations allegedly targeted in a campaign exploiting a vulnerability in PTC’s Windchill PLM platform. The group gained unauthorized access to sensitive data, incl… SecurityWeek · Aug 19, 2026 High CVE-2026-12569DEvulnerabilityransomwaredata breach
threat-intel Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active Exploitation Four critical vulnerabilities – affecting macOS, SharePoint, vCenter, and IKE – are currently being actively exploited in the wild. These flaws have led to widespread attacks, including the deployment of ransomware and b… The Hacker News · Aug 19, 2026 Critical CVE-2026-65400CVE-2026-55040CVE-2026-59310DEUSTRvulnerabilitycyberattackransomware
threat-intel Prison for data analyst who tried to extort $2.5 million from his employer A former data analyst, Cameron Curry, was sentenced to 24 months in prison after attempting to extort $2.5 million from his former employer, Brightly Software (now part of Siemens). Curry gained access to sensitive emplo… Graham Cluley · Aug 19, 2026 High USinsider threatdata breachextortion
threat-intel Clop-Linked Windchill Web Shell Decrypts Credentials and Maps Engineering Data A sophisticated, custom-built web shell, specifically designed for PTC Windchill and FlexPLM, has been deployed by the Clop ransomware gang. This web shell is capable of decrypting credentials, mapping sensitive data, an… The Hacker News · Aug 19, 2026 High CVE-2026-12569CVE-2021-27101CVE-2023-34362web shellcredential theftransomware
threat-intel ISC Stormcast For Wednesday, August 19th, 2026 https://isc.sans.edu/podcastdetail/10058, (Wed, Aug 19th) The ISC Stormcast highlighted a significant increase in malicious email campaigns targeting financial institutions, leveraging sophisticated phishing techniques and exploiting vulnerabilities in legacy systems. The threa… SANS Internet Storm Center · Aug 19, 2026 High phishingransomwarecredential theft
threat-intel More than 200 victims of Medusa ransomware identified over the last year, CISA says The CISA and FBI have updated their advisory on the Medusa ransomware gang, revealing that over 500 victims have been identified in the last year, with a significant focus on the healthcare sector. Medusa is known for ra… The Record · Aug 18, 2026 High ransomwaremedusazero-day
threat-intel Ransom Busters Claims It Hacked Ransomware Servers, Asks Victims for Up to $60,000 A threat actor calling itself Ransom Busters is offering to delete stolen ransomware data from servers in exchange for a payment, ranging from $20,000 to $60,000. GuidePoint Research and Intelligence Team (GRIT) has iden… The Hacker News · Aug 18, 2026 High USransomwaredata exfiltrationcredential theft
threat-intel University of Texas forced to take systems offline in San Antonio after cyberattack The University of Texas at San Antonio experienced a cyberattack that forced the university to temporarily take systems offline, impacting student services and class registration. Despite initial containment, the inciden… The Record · Aug 18, 2026 Medium cyberattackransomwareuniversity