August 2026 in review
Across the tracker, 7 claims carry no disclosure date and are counted in no month.
July 2026 includes the launch-day seed of 461 stories first seen on ; the story delta above compares against it.
- threat intel11 sources
Australia arrests alleged TeamPCP hackers behind supply-chain attacks
Australian authorities arrested and charged two individuals allegedly linked to TeamPCP, a hacking group responsible for developer supply chain attacks. The operation targeted the software development ecosystem to gain broad access to downstream users and systems.
Why it matters: Software developers and companies relying on third-party dependencies are exposed to compromised code; this takedown may disrupt one supply chain attack vector but practitioners should review their software bill of materials and dependency security controls.
Grouped: similar headlines.
- vulnerabilities9 sources
Microsoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-days
Microsoft released security updates on August 6, 2026 addressing 400 vulnerabilities, including one zero-day under active exploitation and two additional publicly disclosed zero-days. Organizations running Microsoft products should prioritize deployment of these patches to mitigate immediate attack surface from the exploited and disclosed flaws.
Why it matters: Practitioners managing Windows, Office, and other Microsoft infrastructure must evaluate and apply these updates urgently, particularly for the three zero-day flaws already known to attackers or the public.
- breaches incidents9 sources
Canadian man pleads guilty to Snowflake hacks that led to 165 breaches
A 26-year-old Ontario resident pleaded guilty to fraud, identity theft, and conspiracy charges stemming from 2024 attacks on Snowflake that compromised 165 organizations. The defendant faces up to 32 years in prison for the coordinated campaign targeting the cloud data platform.
Why it matters: Organizations using Snowflake should review whether they were affected in the campaign and verify account security controls, as this case confirms the severity of the breach and closure of one attack vector.
- vulnerabilities7 sources
PaperCut warns of NG, MF flaw exploited in zero-day attacks
PaperCut disclosed that a zero-day vulnerability affects all versions of PaperCut NG and PaperCut MF print management software and is currently being exploited in active attacks.
Why it matters: Organizations running PaperCut NG or MF need to assess exposure immediately, as exploitation is underway and no patch was available at disclosure.
Grouped: the same names (PAPERCUT MF, PAPERCUT NG).
- ot ics7 sources
Defending Against an Active Threat to Siemens S7 Series PLCs
Federal agencies (NSA, CISA, FBI, DOE, EPA) are warning of an active cyber threat targeting Internet-exposed Siemens S7 Series programmable logic controllers (PLCs) using artificial intelligence (AI)-generated exploitation scripts. Threat actors leverage Internet scanning services to identify poorly protected PLCs and use AI-assisted tools that mimic legitimate monitoring software to gain read/write access via the S7comm protocol. The advisory urges owners and operators of critical manufacturing, energy, water, chemical, food, and commercial facilities to immediately inventory systems, apply security patches, isolate PLCs from the Internet, strengthen access controls, and deploy intrusion detection to monitor for anomalous activity.
Why it matters: PLC operators and critical infrastructure owners in manufacturing, energy, water, chemical, and food sectors must act immediately to audit and secure Siemens S7 systems, as threat actors are actively conducting reconnaissance and testing exploitation capabilities that could disrupt industrial processes, cause safety incidents, damage equipment, or compromise operational data.
Grouped: the same names (ENVIRONMENTAL PROTECTION AGENCY, INFRASTRUCTURE SECURITY AGENCY, INTERNET-EXPOSED PLCS).
- government policy7 sources
White House taps security firms for offensive hack-back operations
The White House has issued a memo directing the National Coordination Center to create a program enabling private security firms to seek approval for offensive hacking operations against foreign cybercrime organizations. The initiative represents a shift toward privatized offensive cyber capabilities as part of U.S. cybersecurity strategy.
Why it matters: Security practitioners and firms should monitor eligibility criteria and legal frameworks for this program, as it changes the liability and regulatory landscape for offensive operations that were previously restricted to government agencies.
Grouped: similar headlines.
- ransomware6 sources
Ransom Cartel ransomware creator sentenced to 16 years in prison
Maksim Silnikau, creator and administrator of the Ransom Cartel ransomware operation, received a 16-year prison sentence for orchestrating attacks against at least 18 companies across multiple countries. The sentencing reflects U.S. law enforcement's response to his leadership of a significant ransomware-as-a-service (RaaS) platform that facilitated extortion campaigns.
Why it matters: Security practitioners should note that law enforcement is actively prosecuting RaaS operators and their leadership; this case demonstrates consequences for ransomware creators and reinforces the risk profile for organizations targeted by Ransom Cartel variants.
- breaches incidents5 sources
Boston Scientific says cyberattack disrupted operations globally
Boston Scientific, a medical technology company, experienced a cyberattack that disrupted IT systems and caused operational impacts across its global operations.
Why it matters: Healthcare organizations and customers relying on Boston Scientific devices and services need visibility into the scope and duration of disruptions, and security teams should monitor for supply chain effects on connected medical infrastructure.
Grouped: similar headlines and the same name (BOSTON SCIENTIFIC).
- ransomware5 sources
More than 200 victims of Medusa ransomware identified over the last year, CISA says
CISA and the FBI updated their advisory on Medusa ransomware, reporting that the group has compromised more than 500 victims as of April 2026, up from the 300 victims previously disclosed in 2025. Many targets operate in critical infrastructure sectors.
Why it matters: Organizations in critical infrastructure and other sectors face active targeting by Medusa; practitioners should review CISA advisories for indicators of compromise and implement controls aligned with known attack patterns.
Grouped: similar headlines.
- ransomware5 sources
FBI, South Korea warn of Gunra ransomware gang targeting critical infrastructure
The FBI and South Korea's government have warned that the Gunra ransomware gang is exploiting firewall vulnerabilities to breach critical infrastructure organizations. The threat actors gain initial access through unpatched security appliances from widely used vendors.
Why it matters: Critical infrastructure operators must immediately audit and patch firewalls from affected vendors; this group poses direct operational risk to power, water, and other essential services.
- CVE-2026-59310Broadcom VMware vCenterfederal fix deadline
- CVE-2026-73570Synacor Zimbra Collaboration Suite (ZCS)federal fix deadline
- CVE-2019-1068Microsoft SQL Serverfederal fix deadline
- CVE-2026-65400Apple macOSfederal fix deadline
- CVE-2026-8452Citrix NetScaler ADC and NetScaler Gatewayfederal fix deadline
- CVE-2026-20349Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) federal fix deadline
- CVE-2026-72898Metabase Metabasefederal fix deadline
- CVE-2026-63077JetBrains TeamCityfederal fix deadline
- CVE-2026-8037Progress LoadMasterfederal fix deadline
- CVE-2026-21962Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-infederal fix deadline
- CVE-2025-62593Ray-Project Rayfederal fix deadline
- CVE-2026-18577N-able N-centralfederal fix deadline
- CVE-2026-55040Microsoft SharePointfederal fix deadline
- CVE-2026-9198IBM Langflowfederal fix deadline
- CVE-2026-60004Gitea Giteafederal fix deadline
- CVE-2026-33824Microsoft Internet Key Exchange (IKE) Service Extensionsfederal fix deadline
- CVE-2023-49105ownCloud ownCloudfederal fix deadline
- CVE-2021-23758Ajax.NET Professional Ajax.NET Professionalfederal fix deadline
- CVE-2026-18556N-able N-centralfederal fix deadline
- CVE-2026-72530TrueConf Serverfederal fix deadline
- CVE-2026-82078PaperCut NG/MFfederal fix deadline
- CVE-2026-64849MLflow MLflowfederal fix deadline
- CVE-2022-0995Linux Kernelfederal fix deadline
- CVE-2026-68820Microsoft Windows Ancillary Function Driver for WinSock federal fix deadline
- CVE-2026-34486Apache Tomcatfederal fix deadline
| Qilin | 171 claims | +33 vs prior month |
| The Gentlemen | 110 claims | -44 vs prior month |
| Clop | 90 claims | +89 vs prior month |
| INC Ransom | 45 claims | +7 vs prior month |
| Orova | 45 claims | +45 vs prior month |
| Direwolf | 41 claims | +41 vs prior month |
| KryBit | 38 claims | +13 vs prior month |
| Storm | 38 claims | +38 vs prior month |
| Akira | 31 claims | +7 vs prior month |
| LockBit | 28 claims | +18 vs prior month |
Leak-site claim data is unverified: RansomLook (CC BY 4.0).