threat-intel ISC Stormcast For Wednesday, August 12th, 2026 https://isc.sans.edu/podcastdetail/10048, (Wed, Aug 12th) The ISC Stormcast highlighted a significant increase in malicious email campaigns targeting financial institutions, leveraging sophisticated phishing techniques and exploiting vulnerabilities in legacy systems. The threa… SANS Internet Storm Center · Aug 12, 2026 High phishingransomwaresupply chain
threat-intel Gunra Ransomware Gang Exploits Fortinet Flaws, Bypasses MFA The Gunra ransomware gang, leveraging leaked Conti code and exploiting vulnerabilities in Fortinet products, is expanding its operations through a RaaS affiliate program and successfully bypassing defenses, including MFA… Dark Reading · Aug 11, 2026 High CVE-2024-55591CVE-2025-24472SOBRCAransomwareraasfortinet
ransomware Ransomware group hijacks hospital system’s Facebook page amid ongoing cyberattack fallout A ransomware group, believed to be “The Gentlemen,” has hijacked the Facebook page of AnMed, a nonprofit medical system in Georgia and South Carolina, to demand ransom after a prolonged cyberattack. The group claims to h… The Record · Aug 11, 2026 High USransomwarehealthcarecyberattack
ransomware DeadLock Ransomware Uses Polygon Smart Contracts to Make Extortion Infra Harder to Disrupt The DeadLock ransomware group is utilizing a sophisticated, blockchain-backed infrastructure to enhance operational resilience and evade takedown efforts. They leverage decentralized proxy servers managed via Polygon sma… The Hacker News · Aug 11, 2026 High ITSPPOransomwareblockchainsmart contracts
threat-intel Local governments in four states dealing with cyberattacks that have shut down services Local governments across four states – California, Oklahoma, South Dakota, Texas, and Wisconsin – are experiencing a surge in cyberattacks, leading to service disruptions and shutdowns. These attacks have impacted critic… The Record · Aug 11, 2026 High UScyberattacklocal governmentransomware
ransomware Gunra Ransomware Exploits Fortinet and Schneider Electric Flaws to Breach Networks The Gunra ransomware group, linked to state-sponsored actors, is aggressively targeting critical infrastructure and organizations globally, leveraging vulnerabilities in Fortinet and Schneider Electric appliances to gain… The Hacker News · Aug 11, 2026 High CVE-2024-5559CVE-2025-24472SOBRSPransomwarevulnerabilitysupply-chain
threat-intel The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and Communications Aeternum is a newly discovered blockchain-based botnet loader utilizing the Polygon blockchain for command and control. Instead of relying on traditional servers, threat actors use smart contracts to issue encrypted inst… Palo Alto Unit 42 · Aug 10, 2026 High blockchainc2polygon
threat-intel FBI, South Korea warn of Gunra ransomware gang targeting critical infrastructure The FBI and South Korea’s government have issued a cybersecurity advisory warning of the Gunra ransomware gang, which is exploiting vulnerabilities in Fortinet firewalls to target critical infrastructure organizations gl… The Record · Aug 10, 2026 High CVE-2024-55591CVE-2025-24472SONOransomwarevulnerabilitysupply-chain
threat-intel China-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flaw China-linked threat actor Storm-1175 has deployed a new ransomware strain, StormEncryptor, leveraging a vulnerability in N-able N‑central to gain initial access and subsequently deploy ransomware. This follows a pattern… The Hacker News · Aug 10, 2026 High CVE-2026-18577CVE-2026-18556CVE-2023-37679CHransomwarevulnerabilitypatch-bypass
threat-intel Senate Democrats introduce bill to distribute $300 million annually to shore up water system cybersecurity Senate Democrats are proposing a $300 million annual investment to bolster cybersecurity for U.S. water and wastewater systems, following a series of attacks targeting over 30 systems in approximately 12 states. The legi… The Record · Aug 10, 2026 High IRcybersecurityinfrastructurewater systems
ransomware ⚡ Weekly Recap: AI Goes Rogue, Metabase 0-Day, MCP Supply-Chain Attacks, and Router Backdoors This week’s security news is dominated by AI-related threats, including a vulnerability exploited in Metabase, a new Shai-Hulud worm leveraging the MCP Registry, and a Chinese review of Palo Alto Networks. Alongside the… The Hacker News · Aug 10, 2026 High CVE-2026-34348CVE-2026-18497CVE-2026-63508CHransomwaresupply-chainvishing
supply-chain China-linked hackers turning popular cybersecurity tool into ransomware launchpad, Microsoft warns China-linked hackers, believed to be part of the Storm-1175 group, are exploiting a critical vulnerability in N-central, a remote monitoring and management (RMM) tool, to deploy ransomware. This supply-chain attack is le… The Record · Aug 10, 2026 High CVE-2026-18577CHsupply-chainransomwarezero-day
ransomware #StopRansomware: Gunra Ransomware The FBI, CISA, and other agencies have issued a joint advisory regarding the Gunra ransomware threat, a sophisticated double-extortion variant derived from the Conti ransomware. Gunra has rapidly expanded through a RaaS… CISA Advisories · Aug 10, 2026 Critical CVE-2024-55591CVE-2025-24472USREransomwaredouble extortionr0aas
threat-intel Claude Code puts auto mode in the driver's seat Several security incidents and developments are highlighted, including a vulnerability in Joomla extensions, a Microsoft SharePoint issue leading to a zero-day attack, and ongoing efforts to combat Iranian propaganda and… The Register · Aug 10, 2026 Medium IRUSvulnerabilityphishingransomware
threat-intel IT threat evolution in Q2 2026. Non-mobile statistics In Q2 2026, Kaspersky products blocked a massive 399.3 million attacks originating from online resources, highlighting a continued surge in ransomware activity and botnet attacks. The Qilin ransomware group dominated, ac… Securelist · Aug 10, 2026 High CVE-2026-33825CVE-2026-50751CVE-2026-50752NEGEUNransomwarebotnetsupply chain
threat-intel Ransomware gangs skip the CEO, head straight for the 40-something IT manager Ransomware gangs are increasingly targeting IT managers, specifically those in their 40s, bypassing traditional executive channels to gain access to sensitive data and systems. This shift suggests a change in tactics by… The Register · Aug 9, 2026 Medium ransomwarecybersecuritylinux
threat-intel Cyber actualités ZATAZ de la semaine du 3 au 9 août 2026 This week, ZATAZ reports on a significant number of cyber incidents impacting France and beyond. A staggering 1.7 billion French IDs were found on the dark web, alongside 43 ransomware demands targeting France, primarily… ZATAZ · Aug 9, 2026 High FRTAdarkwebransomwaredata breach
threat-intel Devs to Anthropic, OpenAI, Cursor, and friends: Make security and privacy the default Several security-related stories are emerging, including a focus on AI security and vulnerabilities, a Russian phishing campaign mimicking Signal support, and ongoing efforts to improve security across various Linux and… The Register · Aug 8, 2026 Medium RUIRaisecurityphishing
threat-intel Rançongiciels : 43 revendications ciblent la France Between July 1st and August 8th, 43 French organizations were targeted in cybercriminal extortion claims, with a strong concentration among several ransomware-as-a-service groups. The Gentlemen and Qilin were the most ac… ZATAZ · Aug 8, 2026 High FRransomwarecybercrimeextortion
threat-intel OpenAI pledges to add Astra security as Anthropic loosens Fable's leash OpenAI is bolstering its AI security by integrating Astra, while Anthropic is loosening restrictions on its Fable system. This shift reflects growing concerns about the potential risks associated with increasingly autono… The Register · Aug 7, 2026 Medium IRaisecurityvulnerability