USA: Cybersecurity Situation, August 2026
Ransomware led August in the USA, with 25 cases and 18 critical CVEs; banking and water regulation also shaped the agenda.
Key findings
- Ransomware was the month’s dominant threat in the USA, accounting for 25 of 92 verified incidents and a strong presence in healthcare, manufacturing, and transportation.
- Signal quality improved from July, with fewer uncategorized incidents and more events clearly attributed by source.
- CISA and federal agencies hardened their OT and exposed-software response, with alerts on Siemens S7, water, and multiple exploited CVEs.
- Regulation gained standalone weight, especially in banking, child privacy, information sharing, and water-sector security.
- Boston Scientific, North Carolina Ports, and the ShipMonk-Trezor chain marked three distinct impact types: operational, logistical, and data exposure.
- Leak site activity remained high, but many claims had no public confirmation, requiring a distinction between extortion, encryption, and simple mention.
- The rise in critical CVEs mentioned points to a defensive agenda focused on urgent patching, external exposure, and third-party control.
Monthly reference modules
These modules are automatically completed with the verified dated facts within the period. Each one states its source base and counting criterion so the figures reconcile across modules. They are the recurring month-to-month readout, and the analysis that follows expands on the cases without repeating this summary.
Indicator window: 92 dated facts in August 2026 · 1 from prior months (comparative frame, not monthly volume) · 1 without confirmed date (excluded from indicators). Facts from prior months are used only as a comparative frame in the analysis, never as volume for this period.
Executive monthly summary for the U.S.
August 2026 was dominated in the United States by ransomware, with 25 verified incidents and a clear concentration in healthcare, manufacturing, transportation, finance, and utilities. The risk surface combined extortion, operational disruption, several active exploitation alerts, and a more intense regulatory agenda, with 11 documented policy moves and 18 critical CVEs mentioned.
The clearest intrusion case was the cyberattack on Boston Scientific, which the company described as a global operational disruption and an impact to on-premise systems used to process and ship orders. At the same time, pressure on the healthcare sector remained high because of campaigns by Medusa, Gunra, STORM, CoinbaseCartel, Chaos, Metaencryptor, KRYBIT, and Global Secret Group, with multiple posts on leak sites and several cases in which the source did not specify whether there was encryption, exfiltration, or only an extortion demand.
The critical infrastructure front was also severe. CISA, together with other federal agencies, warned about active attacks against Siemens S7 PLCs exposed to the internet, while another wave of incidents affected water and wastewater systems in more than one state. On the identity and enterprise software front, CISA added multiple exploited flaws to KEV, including Metabase, VMware vCenter, Windows IKE, SharePoint, Cisco ASA/FTD, and Citrix NetScaler.
The risk level for the U.S. in August is assessed as high. The volume rose from 73 to 92 verified incidents, the share of unclassified incidents fell, and references to critical CVEs and regulatory moves increased sharply.
National Snapshot for the Month in the USA
The United States closed August with a mix of operational pressure, regulatory exposure, and active vulnerability exploitation that affected both private companies and critical infrastructure and government agencies. The qualitative reading is high because the verified base grew, the dominant threat shifted to ransomware, and active campaigns touched sectors with direct impact on essential services.
The month’s most consistent signal was the shift from diffuse or unclassified incidents toward better defined cases by source, with more leak site posts, more security advisories, and more confirmations of operational impact. That did not eliminate uncertainty, but it did reduce the relative weight of ambiguous events compared with the prior month.
On the regulatory front, August showed both greater pressure and greater granularity. The OCC and the FDIC redefined supervisory action thresholds, the FTC maintained and clarified safeguard obligations under GLBA, the Senate extended the information sharing framework, and the White House and the Department of Justice pushed tougher measures against transnational threats and supply chain risks. In water, energy, and telecom, the federal government responded with notices, orders, and preventive litigation.
As regional context, several August reports on Brazil, Chile, and other Latin American countries were used by US or global media as a regulatory and operational mirror. They do not add volume to the USA report, but they do show that child privacy, platform controls, water, and critical infrastructure problems continued crossing jurisdictions and were read by North American regulators as part of the same tightening cycle.
Period indicators in the USA
| Indicator | August 2026 | Previous month | Change |
|---|---|---|---|
| Verified facts for the period | 92 | 73 | +19 |
| Unclassified incidents (breaches or outages) | 12 | 23 | -11 |
| Cases with ransomware or extortion as the primary focus | 25 | 22 | +3 |
| Unencrypted exfiltration (simple extortion) | 2 | n/d | n/d |
| Mentioned only on a leak site | 4 | n/d | n/d |
| Classification could not be determined from the material | 19 | n/d | n/d |
| Documented fraud or phishing cases | 4 | 1 | +3 |
| Documented regulatory moves | 11 | 7 | +4 |
| Critical CVEs mentioned | 18 | 8 | +10 |
| Sectors with at least one documented fact | 7 | 7 | unchanged |
| Main threat of the month | Ransomware (25 of 92 facts) | Incidents (23 of 73 facts) | change in dominance |
| Facts with direct source confirmation | 77% | n/d | n/d |
| Time window for the indicators | 92 facts dated in August 2026, 1 from previous months as a comparison frame, 1 undated excluded | same | same |
| Base for all indicators | 92 | 73 | +19 |
Quick read on the indicators
August was clearer than July. The number of unclassified facts fell, and better-attributed cases increased, although a significant share of ransomware posts remained claims or were only partially classified. At the same time, the technical attack surface widened with many more critical CVEs, while regulatory activity took on greater weight of its own.
Relevant incidents in the USA
Boston Scientific and the global operational outage
Boston Scientific was one of the month’s most visible corporate incidents in the USA because the company itself confirmed unauthorized activity that affected on-premise systems and caused a global operational outage. The company also said its cloud systems were not impacted, which narrowed the technical scope and helped separate the incident from a full compromise scenario.
Available coverage did not allow a precise determination of whether clinical or patient data was stolen. What was clear was the impact on business processes, especially order processing and shipping, and that the company worked with outside specialists to contain the threat and restore continuity.
Water systems, from Minnesota to more than 100 exposed systems
The campaign against water and wastewater systems remained one of the month’s most sensitive stories. CISA confirmed that more than 100 internet-exposed systems were attacked in July, with impact in Michigan, Minnesota and at least five other states, while the FBI and other agencies stressed that the most common vector was direct exposure of PLCs and operational controls.
The body of reporting also made clear that this was not just a technical alert. Publications documented loss of monitoring and control functionality, password changes and remote manipulation in water systems, with a joint response from federal, state and local authorities. In some materials, the campaign was attributed to actors linked to Iran, but that attribution appears as an intelligence judgment or a media hypothesis, not as a uniform fact across all sources.
North Carolina Ports and the logistics disruption
North Carolina Ports confirmed a cyberattack that disrupted its IT systems and affected operations in Wilmington, Morehead City and Charlotte Inland Port. The authority shifted to manual processes, activated its contingency plan and coordinated with federal and state agencies, including the Coast Guard and CISA.
There was no public evidence of sensitive data compromise or a formal attribution of the attack during the period. Even so, the incident mattered because it showed how an attack focused on administrative IT can quickly spill into delays at gates, cargo handling and maritime coordination.
Trezor, ShipMonk and customer data exposure
The breach tied to logistics provider ShipMonk exposed data belonging to nearly 14,000 Trezor customers, including names, email addresses, phone numbers and shipping addresses. The incident did not compromise Trezor’s own infrastructure or hardware wallets, but it did expose personal information useful for targeted phishing and potential physical attacks.
The key technical detail was the exploitation of a vulnerability in Metabase, which allowed unauthorized access to ShipMonk’s analytics instance. The case matters for the USA not only because of the presence of American customers, but because it again highlights dependence on third-party logistics and analytics chains in digital commerce.
Boston Scientific, McKesson and healthcare as a target
McKesson confirmed an incident involving unauthorized access to third-party applications and data theft, although the extreme figures circulated by other outlets remained claims from the attacker group or unspecified reports. Amgen, for its part, reported theft of patient information and proprietary data stored in the cloud.
The healthcare sector also faced heavy operational pressure from Medusa and Gunra activity, along with new posts from STORM, CoinbaseCartel, Chaos, Global Secret Group and other groups claiming U.S. victims. The final picture is not one major event, but sustained pressure on hospitals, clinics, providers and distributors.
Active threats and campaigns in the USA
Ransomware and extortion
In August, ransomware was the main focus, with 25 cases out of 92 incidents and a highly uneven level of certainty. There were two confirmed cases of exfiltration without encryption, four mentions limited to leak sites, and nineteen situations where the material did not make it possible to determine whether there was encryption, exfiltration, or both.
Among the better defined cases was Boston Scientific, which the primary source did not present as ransomware, but as a cybersecurity incident with operational disruption. On the purely extortion side, STORM, CoinbaseCartel, Global Secret Group, KRYBIT, Chaos, Metaencryptor, DragonForce, Emperador, Wallstreet, Falcon, and Qilin accounted for much of the criminal market noise, although not all of the listings were publicly confirmed by victims.
Cases with confirmed exfiltration without encryption
The material made it possible to isolate two cases in which extortion was described as exfiltration without encryption. One was mswalker.com, where follow-up reporting indicated about 620 GB extracted before any encryption was mentioned. The other involved a scenario in which the coverage itself described the publication of sensitive data without being able to support that encryption was the main issue.
In this category, the operational pattern matters as much as the volume. The goal was not to shut down a service, but to use stolen data to pressure the target with the threat of publication. That makes early detection harder, because the company can keep operating while the damage is already underway.
Cases mentioned only on leak sites
Four incidents remained at the level of a simple leak-site mention. This included claims by groups such as Chaos, STORM, CoinbaseCartel, and others about victims in the United States, but without independent public confirmation of the technical scope or the type of information exposed.
That subgroup matters because it shows the gap between the extortion economy and official visibility. An actor can publish a name, a sample, or a threat and still, by the end of the period, there may be no validation strong enough to describe the episode as a confirmed breach.
Fraud, phishing, and account takeover
Documented fraud and phishing activity was low in absolute volume, but very clear in direction. There were four cases, two centered on fraudulent calls or spoofing to obtain data, and two tied to AI-driven scams and weak identity verification.
The most repeated pattern was the use of support or fraud team impersonation to force account changes or transfers. That scheme appears in materials on financial institutions as well as in more general notes on deepfakes and remittances, reinforcing that the human vector remained a relevant entry point in the USA.
APT, espionage, and hacktivism
The APT and espionage segment was marked by Salt Typhoon, Lilac Typhoon, and the operation against QTFY and its QScan and QTRouter platforms. In telecommunications, the sources described a broad espionage campaign with access to lawful intercept, metadata, and obfuscation nodes. In the QTFY case, the focus was on federal agencies, hospitals, energy, and finance.
There was also material on the Iranian campaign against water and on the federal warning about Siemens S7 PLCs. That front does not fit neatly into ransomware or fraud, because it involves remote access, reconnaissance, and exploitation of exposed OT, with potential physical or operational impact rather than monetary loss.
Cases with the highest classification uncertainty
Nineteen incidents linked to ransomware or extortion did not allow the material to determine whether there was encryption, exfiltration, or only publication on a leak site. That ambiguity is not trivial, because it changes how response, notification, and external communication should be prioritized.
Operationally, this block requires careful treatment of any aggregate reading. The month brought more visible criminal activity, but also more documentary noise. The useful takeaway is not that every case caused more damage, but that there were more claims, more campaigns, and more public visibility around extortion.
Critical vulnerabilities affecting the US
August’s technical pressure in the US was driven in large part by the addition of multiple flaws to CISA’s KEV catalog and by joint alerts about active exploitation. The mix of Citrix NetScaler, VMware vCenter, Metabase, Windows, SharePoint, Cisco ASA/FTD, and Zimbra showed that exposure was not concentrated in a single product family.
| CVE | Software | Exploitation | Source |
|---|---|---|---|
| CVE-2026-72898 | Metabase | Active exploitation, unauthenticated SQL injection | SecurityOnline.info, NVD, Metabase |
| CVE-2026-59310 | Broadcom VMware vCenter Server | Active exploitation, path traversal and RCE | CISA, xhack.io, The Hacker News |
| CVE-2026-8452 | Citrix NetScaler ADC and Gateway | Active exploitation | CISA, The Hacker News, BleepingComputer |
| CVE-2026-68820 | Windows WinSock / afd.sys | Active exploitation, local privilege escalation | CISA, SecurityOnline.info |
| CVE-2026-20349 | Cisco ASA and FTD | Active exploitation, DoS / restarts | CISA, SecurityOnline.info |
| CVE-2026-55040 | Microsoft SharePoint | Active exploitation | CISA, xhack.io |
| CVE-2026-33824 | Microsoft Windows IKE Service Extensions | Active exploitation | CISA, xhack.io |
| CVE-2026-21962 | Oracle HTTP Server and WebLogic Proxy Plug-in | Active exploitation | SecurityArsenal, CISA |
| CVE-2026-73570 | Zimbra Collaboration Suite | Active exploitation, command injection | HackerStorm, CiberPlaneta |
| CVE-2026-18577 | N-able N-central | Active exploitation, authentication bypass | Rapid7, Wiz, CISA |
| CVE-2026-69836 | Microsoft Entra ID | Active exploitation, RCE CVSS 10.0 | Yahoo Tech, Microsoft |
| CVE-2026-12710 | Google Cloud Application Integration | Missing authorization flaw, already patched by vendor | NVD, KENET-CERT, Threat Radar |
| CVE-2026-59780 | Apache CloudStack | Sensitive information exposure | NVD, Apache CloudStack Project |
| CVE-2026-71494 | Infracost / Terraform Cloud workflows | Token exposure via untrusted hostname | cvefeed.io |
| CVE-2026-71567 | openshift-metal3/fakefish | OS command injection, high severity | NVD, INCIBE-CERT |
| CVE-2025-62593 | Ray | Active exploitation | CISA, CyberSecureFox |
| CVE-2026-49431 | Not specified in the material | Pending analysis | INCIBE-CERT |
| CVE-2026-73047 | Not specified in the material | High severity, information disclosure | INCIBE-CERT |
Technical read of the table
CISA’s bias in August was clearly operational. The goal was not only to publish flaws, but also to set very aggressive remediation deadlines for federal agencies and push private organizations to treat exposure as real. Metabase, NetScaler, vCenter, and N-central stand out as high-priority products because they combine exposed attack surface, broad adoption, and real-world exploitation.
Regulation and compliance in USA
August’s regulatory agenda in the USA was intense and, on several fronts, clearly tougher. There were eleven documented moves, with the financial system as the main focus, but water, telecom, child privacy, information sharing, and the energy supply chain were also on the radar.
The OCC and the FDIC issued a uniform final rule on unsafe or unsound practices, with an explicit materiality threshold for MRAs and a shift toward material financial risks. That may sound like classic bank supervision, but it also affects how banks turn cybersecurity findings into compliance actions.
At the same time, the FTC kept in place and clarified the GLBA Safeguards Rule for financial institutions, while NIST published quick references to translate CSF 2.0 into concrete controls. In practice, that pushes banks, fintechs, and vendors to document controls, risk assessments, and third-party oversight more thoroughly.
Most relevant regulatory moves
| Date | Measure | Scope | Operational reading |
|---|---|---|---|
| 2026-08-27 | Joint OCC/FDIC final rule on unsafe or unsound practices and MRA | Federal banking | Raises the enforcement threshold and prioritizes material risks |
| 2026-08-27 | OCC update to PPM 5310-3 | Bank supervision | More transparency and consistency in enforcement |
| 2026-08-27 | FTC keeps GLBA Safeguards Rule in place | Financial sector | Requires security programs with administrative, technical, and physical safeguards |
| 2026-08-25 | NIST SP 1347 guidance for CSF 2.0 | Technical controls | Makes it easier to map the framework to verifiable controls |
| 2026-08-19 | Water Cyber Shield Act draft | Drinking water and wastewater | Signals a tougher posture for the water sector |
| 2026-08-21 | DOJ and TikTok / ByteDance privacy settlement | Child protection | Reinforces pressure on platforms and data handling |
| 2026-08-08 | Extension of the Cybersecurity Information Sharing Act to 2026-12-11 | Information sharing | Keeps liability protections in place for now |
Financial sector, privacy, and enforcement
The financial system was where regulation and cybersecurity overlapped most. FinCEN imposed a historic penalty on UBS Financial Services for BSA violations, and the debate over supervision, material risk, vendors, authentication, and incident reporting remained very active.
There was also a $400 million settlement between DOJ and TikTok / ByteDance over child privacy. While it was not a banking case, it set the tone for enforcement against large platforms with operations in the USA. For compliance teams, August showed that exposure is not limited to technical failures, it also includes data handling, disclosure, and third-party governance.
Water, energy, and telecommunications
The water sector saw a notable regulatory and operational response, with joint notices from federal agencies, legislative proposals, and public tracking of more than 100 exposed systems. The energy sector also gained weight with Executive Order 14420 on foreign equipment in the bulk power system.
Telecommunications remained at the center of espionage concerns, with Salt Typhoon still in the background. Although much of the material focused on campaigns from previous years, August reopened the debate over foreign vendors, interconnections, and residual exposure in critical networks.
Most Affected Sectors in the USA
The sector signal for the month was broad, but not scattered. Health care, manufacturing, transportation, finance, and utilities accounted for much of the activity, with water and telecommunications as critical infrastructure fronts and digital services as an indirect exposure vector.
Health care faced the heaviest pressure from ransomware and extortion, but also from unauthorized access incidents, double-extortion warnings, and vulnerabilities affecting the supplier chain. Activity from Medusa and Gunra reinforced the pattern of attacks on hospitals and public health organizations, while STORM, CoinbaseCartel, and other groups added more volume.
Manufacturing and transportation showed up in ransomware campaigns, CVE exploitation, and operational incidents. Encryption was not always involved, but victim disclosure, extortion pressure, and disruptions to administrative processes, logistics, and corporate systems were. In some cases, such as North Carolina Ports, the damage was more about continuity than confidentiality.
Finance and insurance kept the most visible regulatory weight. U.S. Bank denied compromise after a LockBit claim, FinCEN sanctioned UBSFS, and the OCC and the FDIC shifted the supervisory baseline. For financial institutions, August was not just a month of incidents, but of changing expectations for control.
Utilities, especially water, confirmed that OT exposure remains a federal priority. The combination of exposed PLCs, credential changes, and attacks across multiple states shows that the resilience of local infrastructure is not an isolated or purely technical issue. The vulnerability of those environments was also tied to legislative warnings and direct pressure from CISA.
Trends and signals to watch in the USA
A comparison with July shows an improvement in signal quality, not a reduction in risk. Verified incidents rose from 73 to 92, untagged incidents fell from 23 to 12, and the dominant category shifted from generic incidents to ransomware. That points to a month with better analytical visibility and more well-documented criminal campaigns.
The jump from 8 to 18 critical CVEs mentioned is the strongest technical signal of the month. It does not mean there were ten times more exploited vulnerabilities in the country, but that the material reviewed placed much more emphasis on active exploitation, KEV, and patch timelines. For defenders, that means August functioned as a month of pressure around known exposure.
Regulatory activity also increased, from 7 to 11 documented moves. Not all had the same impact, but they did show convergence across banking, water, privacy, information sharing, and energy. The practical reading is that compliance stopped being a side issue and became part of the cybersecurity response.
What to watch in September is whether the wave of leak site posts turns into more public confirmations or whether ambiguity continues to dominate. It is also worth watching the KEV deadline for NetScaler, the real behavior of the groups that exploited Metabase, and whether regulatory measures in water and energy become more concrete obligations for operators and critical infrastructure.
Security recommendations for USA
U.S. security teams should prioritize patching and external exposure in parallel. The mix of Metabase, NetScaler, vCenter, N-central, SharePoint, Windows IKE and Zimbra calls for a remediation campaign based on KEV, not theoretical severity. If an asset is internet-facing or supports remote access, it needs to be at the front of the work queue.
In healthcare and critical services, organizations should strengthen segmentation, phishing-resistant MFA and immutable backups. The warnings on Medusa and Gunra again show abuse of RMM, lateral movement with valid credentials and backup deletion as a recurring pattern. If that trio is not contained, response will be more expensive and slower.
Organizations with logistics, analytics or business software third parties should review permissions, tokens, service accounts and monitoring of access to shared platforms. The ShipMonk case, along with the supplier breach and leak site extortion, shows that indirect exposure can end up affecting customers, reputation and mandatory notifications.
In water, energy and manufacturing, this month’s operational minimum is to inventory exposed PLCs and OT equipment, remove unnecessary direct access and validate factory or shared credentials. Federal alerts on Siemens S7 and water systems made clear that the issue is not abstract, but about exposed surface, weak authentication and remote administration without enough control.
| Priority | Action | Reason |
|---|---|---|
| High | Patch KEV assets with external exposure | CISA confirmed active exploitation across multiple families |
| High | Review MFA, RMM and privileged credentials | Recurring patterns in Medusa, Gunra and similar ransomware |
| High | Inventory and isolate exposed OT | Water, energy and manufacturing remain under pressure |
| Medium | Review third parties with access to customer data | ShipMonk, logistics and analytics cases show indirect risk |
| Medium | Strengthen logging and evidence retention | Useful for response, notification and litigation |
| Medium | Validate incident reporting processes | The regulatory and contractual environment has become more demanding |
Frequently Asked Questions
What changed between July and August in the U.S., volume or severity?
Both increased, but the clearest shift was in signal quality. August recorded 92 verified incidents, up from 73 in July, unclassified incidents fell, and ransomware became the dominant category. Critical CVEs mentioned and documented regulatory actions also rose sharply.
Which sectors were most exposed in the U.S., and why does it matter to cross-reference them with CVEs?
Healthcare, manufacturing, transportation, finance, water, and telecommunications accounted for a large share of the incidents. Cross-referencing them with CVEs matters because several exploited flaws affected remote access software, virtualization, identity systems, and administrative tools used by those same industries.
What practical priority do Medusa and Gunra have compared with other ransomware groups?
Medusa and Gunra should be treated as high priority because official material linked them to active campaigns against healthcare, critical infrastructure, and enterprise environments, along with double extortion tactics, abuse of exposed vulnerabilities, and lateral movement. The other groups added volume, but with more uncertainty in classification.
What does the confirmation of more than 100 water systems attacked mean for a local operator in the U.S.?
It means this was not an isolated case or just a media headline. CISA acknowledged a concrete figure of more than 100 exposed systems attacked in July, and federal advisories continued to call for segmentation, PLC control, and the removal of direct internet access. For a local operator, the risk is both operational and regulatory.
What is the difference between a leak site mention and a confirmed breach in the U.S.?
A leak site mention is only a claim by the actor or tracker and does not, by itself, equal a verified breach. In August there were four such mentions and nineteen cases where the source did not allow the impact type to be determined. The distinction is key to avoid overreacting or underestimating.
Technical appendix: indicators of compromise and TTPs
This month’s materials do provide TTPs and some useful technical signals, though not always classic IoCs. In ransomware and extortion, the recurring patterns are RMM abuse, PsExec, WMI, lateral movement, shadow copy deletion, pre-encryption staging, and the use of valid credentials. In OT, the material points to Siemens S7 PLCs exposed to the internet, port 102, the use of snap7, and AI-generated exploitation scripts.
In the case of Gunra, the sources cite Fortinet exploitation, credential dumping, RDP, Impacket, exfiltration of local and cloud data, and encryption with ChaCha20 and RSA-4096. In the case of Metabase, the most repeated technical vector was the /api/session/reset_password endpoint or equivalent unauthenticated SQL injection paths.
The material also mentions specific domains and artifacts in campaigns that are not always strictly US-focused. Among the clearest are models.litellm.cloud, M365-OWA[.]com and owa-ms365[.]com in the CaptiveCrunch campaign, and the QScan and QTRouter domains seized by the DOJ in the operation against China-sponsored hacking. Because of their cross-threat value, these elements should be kept as operational reference material, even if not all of them relate directly to the USA.
Material limitations
This report was built exclusively from the material provided for the USA and August 2026. Facts from earlier months included in the file were used only as comparative context and were not counted as part of the month’s volume. There was also one incident without a confirmed date, which was excluded from all indicators.
A zero value in an indicator, especially for CVEs, does not mean there are no critical vulnerabilities in the region. It means none appeared in the material analyzed for this period. This issue did include many critical CVEs, but the methodological rule remains the same for any future note.
Aggregated telemetry, such as attack attempts, blocks, or scans, was not used as an incident or as trend data. When intelligence sources provided detection or exploitation figures, they were always treated as technical context or a methodological warning, not as country telemetry.
Sources outside the permitted list were also not used as evidence, nor were social media posts or sponsored content not authorized by the assignment. When a source presented a claim that was not confirmed by the victim or by a regulator, it was treated as such and not as a verified breach.
Sources
- Cybersecurity Data Sharing Faces Liability DeadlineGlobal Finance Magazine
- McKesson Confirms Breach: 284M Records, $55M Demand ...Tech Insider
- Cybersecurity in Telecom Industry: Threats and DefenseCloudSEK
- Vendor Risk Management Doesn't Get Its Own Exam ...Mitratech
- Weekly Threat Intelligence Report – August 2026SecurityOnline.info
- CISA KEV August 2026: 9 New Exploited CVEs to Patch NowSmenode Academy
- Subpart B—Review of ICTS TransactionsGovRegs
- Update on recent cybersecurity incidentBoston Scientific
- AI Deepfake Scams Are Draining the Remittances Latino Families Send Home — Here's How to Fight BackInkl
- Citrix NetScaler: CISA warnt vor kritischer RCE-LückeBoerse Express
- Russian-Speaking Cybercriminals Used SpaceX's AI Tool ...Claims Journal
- S-5368 – Water cybersecurity for utilitiesCivicsProject
- Russian-Speaking Hackers Used Cursor AI in Attacks on ...eSecurityPlanet
- CISA Flags Six Actively Exploited NetScaler, SQL Server, Linux, and Ajax.NET FlawsMallory.ai
- OCC and FDIC finalize narrower bank supervision proceduresAmerican Banker
- Office of the Comptroller of the Currency / FDIC, análisis en American Banker y MLexOffice of the Comptroller of the Currency / FDIC, análisis en American Banker y MLex
- OCC Acts to Improve Transparency and Consistency in Bank Enforcement ActionsOffice of the Comptroller of the Currency
- Chile database leak with 10 million records · Kalir Brief · Pulse | PulseKalir Pulse
- Reg Wrap: US raises threshold for bank supervision and enforcementThe Banker
- BPI Statement on OCC, FDIC Rule on Unsafe, Unsound Practices and Issuance of Matters Requiring AttentionBank Policy Institute
- CISA orders feds to patch Citrix NetScaler RCE flaw by August 29, 2026BleepingComputer
- Memory Overflow Vulnerability in Citrix NetScaler ADC and NetScaler Gateway (CVE-2026-8452)RedLegg
- Além de TikTok e Discord, ANPD tem mais processos contra outras big techsMetrópoles
- Agencies Issue Final Rule to Prioritize Material Financial RisksOffice of the Comptroller of the Currency
- US says Chinese-linked hackers attacked NASA, Senate and govt agenciesAl Jazeera
- Ransomware Group Emperador Hits: Capitol MechanicsHookPhish
- New Silent Ransom Group victim (name pending disclosure)Kalir Pulse
- ¿Cómo usan la IA las organizaciones criminales? Esto dice un estudioGerente
- Medusa Ransomware: Federal Advisory Raises HIPAA Control BarTechSignal
- Gramm-Leach-Bliley ActFederal Trade Commission
- Capitol Mechanics Listed by Emperador Ransomware GroupGalaxyWarden
- Microsoft says AI gateways should be treated as Tier-0 assetsCisoVoice
- Enforcement ActionsOffice of the Comptroller of the Currency (OCC)
- US bank regulators finalize rules defining 'unsafe' bank practicesReuters
- Agencies Issue Final Rule to Prioritize Material Financial Risks and Enhance Consistency and Transparency in Supervision and EnforcementOffice of the Comptroller of the Currency (OCC)
- Building resilience before, during and after a significant eventABA Banking Journal (American Bankers Association)
- Capitol Mechanics — EMPERADOR Ransomware AttackBreach House
- FinanceFederal Trade Commission
- Unsafe or Unsound Practices and Matters Requiring Attention: FinalOffice of the Comptroller of the Currency (OCC)
- Top Bank Watchdogs Adopt Plan to Narrow Oversight ...Bloomberg
- Russian-speaking cybercriminals used SpaceX's Cursor AI ...Reuters
- Unsafe or Unsound Practices, Matters Requiring Attention (Regla final conjunta OCC/FDIC)Office of the Comptroller of the Currency
- CISA Adds Six Exploited Flaws to KEV, Including NetScaler, Linux ...The Hacker News
- CISA Flags Six Exploited Vulnerabilities in KEV CatalogSecurity Online
- Boston Scientific hit by cyberattack, global operations affected (social post)Reuters
- Boston Scientific Says Cyberattack Disrupting Global OperationsMorningstar / Dow Jones Newswires
- TikTok multada por datos de menores: EE.UU. y Brasil actúanTrucoteca
- Medical device maker Boston Scientific says a cyberattack is causing a global disruption to its operationsTechCrunch
- Boston Scientific says a cyberattack is disrupting its global operationsYahoo Finance
- OCC on AI in Banking: Rules, Timeline, What Applies (2026)BankingNewsAI
- China-backed hacking network targeted US hospital systemsBecker's Hospital Review
- Boston Scientific hit by cyberattack, global operations affectedReuters
- DHS Cybersecurity Rules Create Compliance ConflictsLegis1
- Chinese Hackers Hit NASA, DOJ, and the Fed in Massive Campaign, DOJ SaysYahoo News
- Brazil’s Data Protection watchdog fines TikTok over the mishandling of minors’ personal dataCADE – Civil Society Alliances for Digital Empowerment
- Brazilian Agency Fines TikTok $30 million for Failures in Protecting Childrens and Teenagers DataFolha de S.Paulo (ed. internacional)
- Brazil fines TikTok owner €25 million for violations in child and adolescent data protectionPlataforma Media
- Fed, NASA, DOJ targeted by Chinese state-sponsored hackers, DOJ saysCNBC
- DOJ blames China for string of hacks targeting federal networksPolitico
- EUA desarticulam operação de hackers chineses que invadiu Nasa, Fed e SenadoValor Econômico
- US says Chinese hackers broke into DOJ, NASA, Federal Reserve, SenateUSA Today
- US Says Chinese Hackers Broke Into Justice Department, NASA, Federal Reserve, Senate, and MoreU.S. News / Reuters
- FDIC 2025 Report on Cybersecurity and Resilience: 2025 Report on Cybersecurity and Resilience — What It Says, Who It Applies ToFDIC / BankingNewsAI (resumen)
- wmiemporium.com — KRYBIT Ransomware AttackBreach House
- Treasury Forms Quantum-Readiness Task Force for Financial SectorMallory.ai
- Associação Portuguesa de Bancos alerta para chamadas fraudulentas em seu nomeRTP
- Takeaways from the OCC's Cybersecurity and Financial ...Young & Associates Inc.
- FFIEC Compliance Assessments | IT Handbook Readiness | Lazarus AllianceLazarus Alliance
- CISA KEV Adds 4 Critical CVEs, 3 Rated CVSS 9.8 [2026]Tech-Insider
- CVE-2026-8452 — Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability (known exploited)netVigilance
- Brazil Fines TikTok $29.8M for Guest Browsing That Tracked 8 Million MinorsTechTimes
- CVE-2026-8452: Citrix NetScaler Exploited (KEV)OpenVPN Blog
- Who regulates AI in banking? Every major authority, tracked.BankingNewsAI
- EXCLUSIF - Selon certaines sources, SLB a obtenu l'accès aux précieuses données sur les gisements pétroliers du Venezuela grâce à un contratReuters / Boursorama
- FFIEC Compliance: An IT and Cybersecurity Guide for Financial ...CMIT Solutions
- Ascension/AMSURG, In the Matter of (timeline item)Federal Trade Commission
- Cybersecurity Framework 2.0: Informative References Quick-Start Guide (NIST SP 1347)NIST
- Bank Cybersecurity Regulations: OSFI, FFIEC, and NYDFSArmour Cyber
- Cyware Daily Threat Intelligence - August 25, 2026Cyware
- TikTok é multado em R$ 153,7 milhões pela ANPD por falhas na proteção de criançasO A Juricaba
- Lawmakers press Commerce to restrict Americans from aiding foreign spy agenciesNextgov
- CISA додає чотири критичні вразливості до KEVCyberSecureFox
- GLOBAL SECRET GROUP Ransomware: 3 US Victims Posted in 24 HoursSecurity Arsenal
- VMware vCenter Zero-Day: CVE-2026-59310 Hits 47 NationsTech-Insider
- EXCLUSIVE-SLB gains access to Venezuela's coveted oilfield data ...Devdiscourse
- DeepSeek y los hackers de Xi Jinping: ataques duplicados, controles casi nulos y una brecha que inquieta a OccidenteInfobae
- Brazil fines TikTok $30m for child data privacy violationsAl Jazeera
- TikTok may have collected data on 20% of Brazil's children, ANPD saysMLex
- Brazil fines TikTok owner ByteDance for unlawful processing of teenagers' dataReuters
- StormEncrypter Ransomware: IOCs, MITRE TTPs & DetectionManageEngine
- Weekly CVE: 9 CISA KEV Additions: vCenter, Zimbra, ...FireCompass
- Brazil fines TikTok record US$30 million for profiting from children’s dataSouth China Morning Post
- SLB obtiene acceso a los codiciados datos sobre yacimientos petrolíferos de Venezuela a través de un contratoGBM Media
- Brazil's TikTok fine sends signal to other platformsValor International
- New crew Storm goes after US clinics, banks and factories | IntelFusionsIntelFusions
- Brazil fines TikTok $30 mn in 'powerful signal' over child safetyFrance24
- Brazil Fines TikTok Owner ByteDance R$154 Million Over Kids DataBrazil Stock Guide
- mswalker.com Ransomware Claim (2026) — What’s Alleged & Am I Affected?RecentBreaches
- ANPD multa TikTok em R$ 153,7 milhões por falhas na proteção de dados de crianças e adolescentesANPD
- mswalker.com — CHAOS Ransomware AttackBreach House
- Victim: mswalker.com – chaosransomware.live
- mswalker.com: Unconfirmed Breach Claims & DoxxScan™ RatingRecentBreaches
- Victim: Lockheed Architectural Solutions, Inc. – Global Secret Groupransomware.live
- CVE-2026-59780 - Apache CloudStack LDAPNVD (NIST)
- Victim: Tiseo Paving – Global Secret Groupransomware.live
- CHAOS Ransomware Gang: 3 New Victims Posted in 24 HoursSecurity Arsenal
- Account takeover fraud in financial services needs stronger call verificationNHIMG
- Text - H.R.10146 - AI Advertising Disclosure Act, 119th Congress (2025-2026)Congress.gov
- DRAGONFORCE Ransomware Gang: 4 New Victims Posted in 24 Hours — Cross-Border Campaign Analysis and Detection EngineeringSecurity Arsenal
- METAENCRYPTOR Ransomware Gang: 7 Victims in 24 Hours Cross-Sector Blitz Targeting Transportation, Energy and HealthcareSecurityArsenal
- North Carolina Ports cyberattack: What happened, what we know and what we still don'tShieldworkz
- Listing of Metaencryptor victims including Trailer Transit IncIntel and Breaches (X)
- Trezor Data Breach Analysis: 14000 Customers Exposed in ShipMonk Metabase SQL Injection IncidentRescana
- U.S. Implements Operation Economic Outcast Sanctioning Irans Military Activities, Cyber Threats, and Illicit Oil TradeU.S. Department of State
- United States Implements Operation Economic Outcast – Fact SheetU.S. Department of State
- KRYBIT Ransomware Gang: 13 Victims in 48 HoursSecurity Arsenal
- Financial Institutions – Office of Cybersecurity and Critical Infrastructure ProtectionU.S. Department of the Treasury
- How should financial institutions implement cyber governance and evidence collection for NYDFS Part 500 compliance?NHIMG
- What Is Financial Cybersecurity Compliance? DefinitionNHIMG
- Weekly CISA KEV Updates: 24 August 2026HackerStorm
- New U.S. bill targets growing cyber threats to water infrastructureEnvironmental Science & Engineering Magazine (ESEmag)
- Group: Dark ProjectRansomware.live
- BARRACUDA Ransomware Gang: 3 New Victims PostedSecurity Arsenal
- First Amendment Challenges to Regulation of Social Media (CRS Report R49308)Congressional Research Service / Congress.gov
- Bipartisan Senate bill aims to prepare energy sector for Q-DayCyberScoop
- Briefing: H.R. 10139 – Ratepayer Bill of Rights Act of 2026The Legis Ledger
- HR 10139 – Ratepayer Bill of Rights Act of 2026PoliScore
- Representative Seth Magaziner Introduces H.R. 10146: AI Advertising Disclosure ActMoomoo News
- Text - H.R.10146 - AI Advertising Disclosure ActU.S. Government Publishing Office / Congress.gov
- Almost Every House Republican Voted To Block State and Local Governments’ Ability To Protect Residents From AI Data CentersCenter for American Progress Action
- H.R.10139 - Ratepayer Bill of Rights Act of 2026Congress.gov
- CaptiveCrunch: malware en Wi-Fi público para viajerosMicrosoft News Source LATAM
- TikTok, DOJ Settle Children's Privacy Charges For $400MMediaPost
- Treasury launches task force to prepare financial sector for quantum cyber threatsNextgov / Government Executive Media Group
- ERM software for financial institutions: 2026 buyer's guideDiligent Corporation
- Federal Banking Agencies Announce Coordinated Approach to Handling Highly Sensitive Information During ExaminationsDebevoise & Plimpton LLP
- GSA, Treasury kick off post-quantum initiatives to protect against cyber threatsFederal News Network
- InfoSec GRC Brief | April 30, 2026SaltyCloud
- Federal Banking Agencies Announce Coordinated Approach to Handling Highly Sensitive Information During ExaminationsDebevoise Data Blog
- tm2621515-3_defm14cU.S. Securities and Exchange Commission
- Iran hacks reveal weak spot on US, UK water, power grids as regime aims to maximize disruption expertNew York Post
- STORM Ransomware Gang: 7 New Victims Posted in 72 HoursSecurity Arsenal
- Storm gang claims Indiana acute care hospital in fresh leak postMedRisk
- Government Agencies Updates Warning Against MedusaThe National Law Review
- Trailer Transit Inc Listed by Metaencryptor Ransomware Group | 2026-08GalaxyWarden
- CISO Daily Briefing – August 23, 2026Cloud Security Alliance
- MLflow SSRF Under Active Attack: A Platform Breach VectorCloud Security Alliance
- Trailer Transit Inc Listed by Metaencryptor Ransomware Group | 2025-09GalaxyWarden
- Warner Bill Would Force CISA to Refresh Infrastructure Cyber Plans for AI ThreatsJain.com
- Trailer Transit Inc — METAENCRYPTOR Ransomware AttackBreach House
- More than 30 Minnesota water systems targeted in coordinated cyberattackTeknopolitika
- Missing Authorization in Google Cloud Application Integration QueryEngineTask (CVE-2026-12710)Mallory Security Labs
- Without A Legal Framework, ANPD And Sectoral Authorities Advance AI RegulationTozziniFreire Advogados
- COINBASECARTEL Ransomware Gang: 13 Victims Posted in 24 HoursSecurity Arsenal
- Tom Barrett bill bars federal involvement in data center ...The Detroit News
- Senator Adam B. Schiff introduces S. 5368: Water Cyber Shield Act of 2026Quiver Quantitative
- Threats Tagged 'cve-2026-12710'Threat Radar
- CVE-2026-12710 - Missing Authorization in Application Integration QueryEngineTaskKENET-CERT
- Ransomware group coinbasecartel hits Integrated Health SystemsHackerFeeds
- CVE-2026-12710 Detail - Google Cloud Application IntegrationNVD (NIST)
- RXPE Group Ransomware Claim (2026) — What’s Alleged & Am I Affected?RecentBreaches
- Cybersecurity Weekly News: 15–21 August 2026Boston Institute of Analytics
- US crypto regulations in 2026: the complete mapCrypto.news
- Integrated Health Systems Ransomware Claim (2026) — What’s Alleged & Am I Affected?RecentBreaches
- Coinbase Cartel lists medical billing firm Integrated Health SystemsMedRisk
- CoinbaseCartel Breaches Integrated Health SystemsMalware.news
- TikTok agrees to $400 million settlement on US children's privacy lawsuitNHK World-Japan
- TikTok, feds settle children's privacy lawsuit for $400 millionABC News
- Victim: Integrated Health SystemsRansomware.live
- CVE-2026-59780: Apache CloudStack LDAP provider configuration disclosurecvefeed.io
- CVE-2026-71494 - Infracost: Terraform Cloud and registry token exposure via untrusted hostnamecvefeed.io
- Permitted Payment Stablecoin Issuer Customer Identification ProgramCrypto Council for Innovation
- CVE-2026-59085: Server-Side Request Forgery (SSRF) in Apache CloudStackOffSeq Threat Radar
- FinCEN, other federal regulators propose GENIUS Act CIP ruleCCH Incorporated (VitalLaw)
- ACWA Weekly Wrap Vol. XVII, Issue 26 (Week of August 17, 2026)ACWA
- CISA and partners issue advisory on active threat to Siemens programmable logic controllerInside Cybersecurity
- Latam Pass Data Breach: Exposed BIN Data Creates Fraud Risk Beyond Partial Card ClaimsTechTimes
- LATAM Pass sofre ataque cibernético e expõe dados de clientesMinuto da Segurança
- Financial Services AI Security: The 2026 PlaybookAccuroAI
- Фахівці T-Mobile фізично перерізали мережевий кабель, щоб зупинити китайських хакерів просто під час зламуВсеЗависло
- Cybersecurity Data Sharing Faces Liability DeadlineGlobal Finance Magazine
- BPI and The Clearing House Association Comment on FinCEN's Customer Identification Program Proposal for Permitted Payment Stablecoin IssuersBank Policy Institute
- ANPD abre caminho para volta das lives se Discord apresentar 'medidas razoáveis'Folha de S.Paulo
- Cybersecurity Data Sharing Faces Liability DeadlineGlobal Finance Magazine (GFMag)
- Operation Economic Outcast: Treasury Sanctions Nearly 60 Iran-Linked Targets and Names Digital Assets a Sanctionable SectorTRM Labs
- TikTok agrees to $400 million US children's privacy settlementReuters
- [ADVISORY] Apache CloudStack LTS Security Releases 4.20.3.1 and 4.22.1.1Apache CloudStack Project
- CVE-2026-59780 — Apache CloudStack LDAP 提供商配置泄露漏洞cve.imfht.com
- Troutman Pepper Locke Silent as Threat Actors Leak Client Data, Tens of Thousands of SSNsDatabreaches.net
- Satine Sentinel: August 21, 2026SatineTech
- Weekly Intelligence Report - 21 Aug 2026Cyfirma
- The Presidential Memo on Combating Transnational Cybercrime: Implications for Industry and GovernmentCenter for Strategic and International Studies (CSIS)
- Medusa Ransomware Mitigation Checklist for Healthcare, K-12, and GovernmentMyDataPath
- US says hackers are targeting vulnerable water systems with the help of AITechCrunch
- Text - H.R.10118 - 119th Congress (2025-2026): No Data Center NDAs ActCongress.gov (U.S. Congress)
- FINRA Cybersecurity Practices For Member FirmsFINRA / NCFACanada
- Preparing for SEC, FINRA, and GLBA Audits: An Executive's GuideDigeteks
- Five Agencies Warn AI Is Lowering the Bar for ICS Attacks on Critical InfrastructureAIGovernance.com
- Ransomware attacks surge in 2026 with bold new extortion tacticsQUE.com
- August 20, 2026 Briefing — PolicySignalPolicySignal
- MPF cobra Discord sobre políticas de proteção a crianças e adolescentesVeja
- US agencies warn of AI-powered attacks on Siemens ...Help Net Security
- Bipartisan Bill Targets Quantum Cybersecurity Risks to the U.S. Electric GridThe Quantum Insider
- OpenAI Pauses Training Over Concerns About Safety (sección sobre Quantum-GUARD Act)The Wall Street Journal
- САЩ подготвят електрическата мрежа за квантовата ера с нов закон за киберсигурностe-security.bg
- Federal Water Tap, August 17, 2026: Two Big Colorado River Reservoirs Hit Record LowsCircle of Blue / Coyote Gulch
- Recent Water Utility Attacks Show Why OT Security Can’t WaitSecurity Boulevard
- EUA alertam que dispositivos da Siemens podem ser hackeados em meio a temores de que Irã esteja invadindo estações de tratamento de águaReuters via Investing.com
- What we know so far about the hacking campaign against US water systemsCybersecurity Dive
- Feds Confirm AI Is Writing Exploits for Siemens PLCs Used ...TechTimes
- Les attaques contre l'approvisionnement en eau dans le Minnesota et le Michigan ne sont pas une surpriseOPSWAT
- (TLP:CLEAR) CISA ICS Advisories, Additional Alerts, Updates and Bulletins - August 20, 2026WaterISAC
- EVEREST Ransomware Gang: 4 New Victims Posted in Single-Day Surge — Tech & Professional Services Targeting Analysis with Detection RulesSecurity Arsenal
- Kingston Technology Ransomware Claim (2026) — What’s Alleged & Am I Affected?RecentBreaches
- Kingston TechnologyBreachSense
- Kingston Technology: Exclusive: RAM maker Kingston Technology investigating ransomware claimsRankiteo
- Victim: Kingston Technology - Ransomware.liveRansomware.live
- Kingston Technology: Unconfirmed Breach Claims & DoxxScan™ RatingRecentBreaches
- Kingston Technology Listed by Everest Ransomware GroupGalaxyWarden
- Kingston Technology — EVEREST Ransomware Attack | Breach HouseBreach House
- Grupo DT Listed by Everest Ransomware Group | GalaxyWardenGalaxyWarden
- 119th Congress (2025-2026): No Data Center NDAs Act – All Information (Except Text)Congress.gov
- Congress Faces Vehicle Data Privacy Gap, CRS SaysLegis1
- 2026 State and Federal AI Legislation UpdatesCenter for Democracy & Technology (CDT)
- FY2026 NDAA Embeds Cyber and AI Governance RulesLegis1
- Число жертв Medusa в США превысило 500: под ударом ...Techora.ru
- CISA Warns Medusa Ransomware Threatens Critical InfrastructureGovly
- LockBit 5.0 targets U.S. Bank, one of the largest banks in the United StatesEscudoDigital
- US Bank investigates LockBit's claims as ransomware crims set pay-or-leak deadlineThe Register
- CISA Known Exploited Vulnerabilities Alert – August 2026Xhack.io
- T-Mobile отвоевала сети у китайских хакеров Salt TyphoonSecurityLab.ru
- CISA Warns Medusa Ransomware Has Hit 500 Critical-Infrastructure Orgs, Tags Two TrueConf Server Flaws as Actively ExploitedTech-Quire
- CISA flags healthcare as frequent Medusa ransomware victimTech Informed
- PART 314—STANDARDS FOR SAFEGUARDING CUSTOMER INFORMATION (GLBA Safeguards Rule)GovRegs
- Senate Introduces Water Cybersecurity ProgramGovly
- THEGENTLEMEN Ransomware Gang: 5 New Victims in 72 Hours — Cross-Sector Campaign Targeting Defense, Finance and Critical TransportSecurity Arsenal
- #StopRansomware advisory on Medusa ransomware (social media post)FBI Jacksonville
- CVE-2026-49431INCIBE-CERT
- Third Coast Bancshares Data Breach in 2026BreachSense
- Agencies issue update on Medusa ransomware activityAmerican Hospital Association (AHA)
- So About That Iranian Cyberattack on Our Water SupplySlate
- HHS, FBI warn hospitals as Medusa ransomware tops 500 victimsBecker's Hospital Review
- US warns Siemens devices can be hacked amid fears Iran is breaching water plantsReuters
- Commission Actions | Comisión Federal de ComercioFederal Trade Commission
- US charges 17 Iranians over 'massive' cyber theft campaignBBC News
- T-Mobile Sent Four People With Scissors to Stop Chinese HackersYahoo News
- DOJ Charges 17 Iranians in Mabna Institute Cyber TheftSecurityOnline.info
- Brazil's ANPD emerges as a powerful enforcer of data privacyManageEngine Insights
- MPF pede ao Discord informações sobre riscos a crianças e adolescentesG1 / Globo
- Data Retention And Disposal: GLBA Compliance RequirementsArchon Data Store
- FDIC and OCC Propose New Frameworks for Disclosure of Confidential Supervisory InformationSimpson Thacher & Bartlett LLP
- Cybersecurity: Active Threat to Siemens S7 Series PLCsVirginia Department of Health
- T-Mobile cortó físicamente un cable para expulsar a hackers chinos de su redDiarioBitcoin
- T-Mobile 'chopped a cable' to expel Chinese hackers from its networkTechCrunch
- QILIN Ransomware Gang: 15 New Victims Posted in 72 Hours — Cross-Sector Campaign Targeting Energy, Hospitality & ManufacturingSecurity Arsenal
- Lansing Urgent Care Data Breach in 2026BreachSense
- The Policy Newsletter: State and Federal Data and Privacy LegislationPlural Policy
- Troutman Pepper Locke LLP Data Theft Extortion by SilentRansomGroup (Repeat Attack Including Physical Intrusion) — Threat ID TL-2026-2103Threadlinqs Intelligence
- SILENTRANSRANSOMGROUP: 3 New Victim Postings on Dark Web Leak Site — US Professional Services Targeting Analysis & Detection EngineeringSecurity Arsenal
- Third Coast Bancshares Listed by Inc Ransom ...GalaxyWarden
- Lansing Urgent Care Data Breach? Lawyers Investigate ...ClassAction.org
- United States Data Protection & Privacy Regulation MonitorGDPRI / DataProtection.gi
- FDIC Considers Industry Standard-Setting Organization for Third-Party Service ProvidersNational Law Review
- Crypto breaches 2026: shipping leaks fuel wrench attackscrypto.news
- MULTI-COUNTRY PREVENTIVE ALERT (government, telecommunications, databases, access) – UNCONFIRMEDVECERT Radar
- Medusa Ransomware Hit 500 Critical Sites, FBI Says in New AlertTech Debrief
- Stablecoin issuer customer identification rule: what it asksDidit.me
- NCRC Submits Comment to FDIC on Bank Secrecy Act ...NCRC
- CISA, FBI and HHS Update Joint Cybersecurity Advisory on Medusa RansomwareCISA (US DHS)
- Medusa Ransomware (CISA AA25-071A): 500+ victims, 24h patching window, and exploited CVEsChors Security
- Feds update guidance on Medusa Ransomware after healthcare attacksPaubox
- Over 500 Critical Infrastructure Organizations Hit by Medusa RansomwareInfosecurity Magazine
- Eight years later, federal authorities re-up charges against Iranian hackersCyberScoop
- 17 Iranians Charged With Conducting Massive Cyber Theft Campaign On Behalf Of Islamic Revolutionary Guard CorpsU.S. Attorney’s Office – Southern District of New York
- 17 Iranians Charged with Conducting Massive Cyber Theft Campaign on Behalf of Islamic Revolutionary Guard CorpsUnited States Department of Justice
- Weekly Enforcement & Compliance Insight Digest – August 24, 2026Across Oversight
- GLOBAL SECRET GROUP Ransomware: 3 US Victims in 4 Days – Manufacturing, Retail, and Healthcare Targeting Analysis with Detection RulesSecurityArsenal
- Cyberattacks on water facilities test US defenses, reveal gapsThe Christian Science Monitor
- Notice of Data IncidentAOL
- HackZero Privacy PolicyHackZero
- Discord suspends livestreams in Brazil after teen's suicideCTV News
- Data privacy laws worldwide: orientation guideActonic
- Privacidade e Verificação de Idade: O Limite da Lei e ANPDTecDiario
- CISA Adds Four Critical Vulnerabilities to KEV CatalogCyberSecureFox
- Discord suspends livestreams to comply with Brazil’s requirementsAgência Brasil / EBC
- Após suspender lives do Discord, ANPD avalia incluir mais plataformas digitais na fiscalizaçãoExame
- Discord Halts Livestreams in Brazil After Child-Safety FailuresGadgets Now / Reuters
- Satellite Cybersecurity Act Clears Three CommitteesCYSAT News
- Brazil suspends Discord live video after teenager’s death. What changes for usersPlataforma Media
- Bipartisan Push to Quantum-Proof the GridTai News
- Medusa: more than 500 organisations hit - BerigoBerigo (resumen de advisory CISA/FBI/HHS)
- Bipartisan Bill Targets Quantum Cybersecurity Risks to the U.S. Electric GridThe Quantum Insider
- Sens. Coons, Rounds introduce bill offering solutions for post-quantum cryptography in the electric sectorInside Cybersecurity
- Protect Against Medusa Ransomware AttacksAmpcus Cyber
- SWK Cybersecurity News Recap August 2026SWK Technology
- Medusa Ransomware Hit Over 500 Critical Infrastructure Organizations2W Tech
- Medusa Ransomware Hits 500 Critical Infrastructure OrgsCybersecurity Insiders
- The Package Registry Layer: How Supply-Chain Attacks ...Yahoo News
- Timeline of the Suicide Case that Led Brazil to Suspend Discord LivestreamsFolha de S.Paulo (Internacional)
- Prazo para Discord suspender lives no Brasil termina nesta segunda-feiraUOL Tilt
- Sanctions 2026 - USA – Washington, DC, Trends and DevelopmentsChambers & Partners
- CVE-2025-62593: Fallo Crítico En Ray Explotado ActivamenteCyberSecureFox
- CVE-2026-71567 DetailNVD (NIST)
- Ecopetrol Data Leak: Hackers Claim 327095 FilesThe Rio Times
- Falla crítica en MLflow bajo explotación activa — CISA ...Ciberseguridad LATAM
- IoT News Digest 2633IoT News Digest (Substack)
- The LiteLLM Breach: 153 GB of AI and Cloud Credentials ...CybelAngel
- Added to CISA KEV (CVE-2026-42208)CERT Uganda
- CVE-2026-71567INCIBE-CERT
- House Calendars for August 17, 2026 - 119th Congress, 2nd SessionGovInfo / U.S. Government Publishing Office
- FinCEN Commits to Forbear from BSA Enforcement for Authorized Financial Services in VenezuelaFinCEN / Baker McKenzie
- CVE-2026-71567 - Exploits & SeverityFeedly CVE / EUVD aggregator
- Doxo (timeline item) - August 17, 2026Federal Trade Commission
- Missouri hospital hit by ransomware attackBecker's Hospital Review
- Discord blocks live broadcasts in Brazil as determined by the ANPD after investigationMixVale
- Suspected China-Nexus Actor Exploits VMware vCenter FlawThe Hacker News
- Cyber Roundup — Week of August 10thCybelAngel
- Weekly Cyber Threats & Breaches Report: 10-16 Aug 2026FireCompass
- CISA AA26-097A: Iranian-Affiliated Actors Escalate PLC Exploitation Across Water, Energy, and Municipal OTOTSecurityWire
- Third-Party Risk Management (TPRM): Lifecycle, Frameworks, and ...CloudSEK
- INCRANSOM Ransomware Gang: 7 New Victims Posted in 72 Hours — Cross-Sector Campaign Analysis and Detection Engineering BriefSecurity Arsenal
- Report: Utah among 12 states whose water infrastructure was targeted by IranKSL
- A 153GB Leak From the LiteLLM Breach Shows Supply-Chain Defense Still Runs on Voluntary Disclosure, Not LawPeople of Internet
- Ciberataques a infraestructura crítica: riesgos para empresas latinoamericanasBluewaves Investment
- Ransomware Group Storm Hits: Rood and Riddle Equine HospitalHookphish
- Brecha en gestor de salud expuso datos de 3,8 millones de personas en EE.UU.NIVEL4 Labs
- Interim HealthCare — ANUBIS Ransomware AttackBreach House
- Victim: Interim HealthCareransomware.live
- Interim HealthCare Ransomware Claim (2026) — What’s Alleged & Am I Affected?RecentBreaches
- Ransomware Group Claims Attack on Interim HealthCareBreachLetter
- Infraestructura crítica en riesgo: el nuevo frente de la ciberseguridadDiario Río Negro
- CVE-2026-73047INCIBE-CERT
- Ransomware: anubis claims Interim HealthCare (US)Matproof
- The LiteLLM supply chain attack yields a 153GB dump: 433,909 files, 2,488 corporate domains, keys still live five months laterMindPattern.ai
- Five months later, the LiteLLM supply chain attack hit 2,500 organizationsInfosec.ge
- Forty Minutes Was EnoughMedium
- Trezor Confirms ShipMonk Data Breach Exposed Nearly 14,000 CustomersBreach.news
- Como o Discord perdeu lives no Brasil em 3 dias úteisFolha de S.Paulo
- GlobalSecretGroup Ransomware Escalates Extortion Activity in August 2026BrinzTech
- Hackers target business giants across multiple industries with severe cyberattackCaliber AZ
- March 2026 roundup on privacy, security and AI regulationDailySynapse
- XPL0ITRS Ransomware Gang: 3 New Victims PostedSecurity Arsenal
- The State of Ransomware Q2 2026Check Point Research
- DIREWOLF Ransomware Gang: 6 Victims Posted in 48 Hours — Healthcare & Tech Targeting Analysis with Detection RulesSecurity Arsenal
- Ciberataque a sistemas de agua en Minnesota genera advertencia para América LatinaRio Negro al Día
- OCC Requests Comment on Proposed Changes to Information Disclosure RulesCornerstone Licensing
- FinCEN fines UBS a record $125 million for repeated Bank Secrecy Act violationsRegTech News
- Ransomware Group anubis Hits: Interim HealthCareHookphish
- Banks Lose Key KYC Tool as U.S. Ownership Reporting ExemptedCommerce Security Authority
- Banking Cybersecurity Requirements: Regulatory Landscape for Financial InstitutionsSecure Systems
- Trezor alerta sobre una filtración de datos de clientes a través del proveedor ShipMonkSecurityLab
- HIPRA Advances Out of Senate HELP CommitteeJD Supra
- Key Takeaways from the OCC and FDIC CSI ProposalsFreshfields Bruckhaus Deringer
- 2026 Cybersecurity and Privacy Enforcement TrendsSecurityPost.org
- What we know about the alleged Iranian hacks on US water utilitiesTechCrunch
- Victim: Rood & Riddle Equine Hospitalransomware.live
- Rood & Riddle Equine Hospital Ransomware Claim (2026) — What’s Alleged & Am I Affected?RecentBreaches
- News – Statement of enforcement policy in support of economic recovery and earthquake relief efforts in VenezuelaFinCEN
- FinCEN Permanently Repeals Domestic BOI ReportingRegTech
- LiteLLM Supply Chain Hack Hit 2488 FirmsTechTimes
- CVE-2026-74243INCIBE-CERT
- Compliance Brief - August 12, 2026Global RADAR
- Trezor Data Breach 2026: ShipMonk and Metabase Vulnerabilities Expose Customer DataAviatrix Threat Research Center
- CVE-2026-74241 - Vulnerability DetailsOpenCVE
- Grupo de hackers diz ter roubado dados de quase 50 empresas, incluindo Philips e ShellG1 / Globo
- Banco Central mira IA para travar fraude no Pix em tempo realO Agente Financeiro
- Who Owns the Compliance Failure? Bank-Fintech LiabilityShumaker
- FinCEN Final Rule Permanently Narrows U.S. Ownership ...FinCrime Central
- Cl0p Ransomware Attack Hits Major Global CompaniesCryptonomist
- CVE-2026-74244 - Vulnerability DetailsOpenCVE
- The SECURE Data Act 2026 and GUARD Financial Data Act – overview of proposed federal powersDLA Piper
- AI Chatbots as Companions: Overview, Uses, and ...Congressional Research Service
- Known Exploited Vulnerabilities CatalogCISA
- ICYMI: Chairman Cassidy, Hassan Advance Legislation to Protect Americans Private Health DataU.S. Senate HELP Committee
- The Privatization of Cyber Offense: Washington's New Playbook Against Transnational CybercrimeCyber Center Space
- LiteLLM's March PyPI compromise maps to 434,000 CI/CD pipelines | CorgeaCorgea
- LiteLLM Supply Chain Attack Exposes 153GB of Corporate CredentialsTech-Quire
- Hacking group claims mass data theft from Shell, Philips, Fiserv and GEYahoo Finance
- The authenticity of the samples and the integrity of the databases remain unconfirmed.VECERT Analyzer
- 🚨Cyber Alert ‼️ 🇺🇸US - Trezor / ShipMonk breach summaryHackmanac
- Trezor Data Breach Exposes 13689 Customers via ShipMonkOurCryptoTalk
- 2026 Trezor — ShipMonk fulfillment breach; 13,689 customers (addresses/phones; Metabase path)BreachHistory
- Beneath the Waterline: Iran's Deniable Campaign Against America's Weakest Infrastructure- 294Infosources
- Criptografia, morte de adolescente e admissão de falha: entenda por que a ANPD suspendeu as lives do Discord no BrasilO Globo
- Nota pública sobre a determinação da suspensão da funcionalidade de lives no Discord por parte da ANPDDataPrivacyBR
- ECA Digital amplia poder da ANPD para fiscalizar redes e proteger menoresBrasil247
- Brazil: ANPD Regulates Digital ECA Transparency ReportsBaker McKenzie
- Critical Infrastructure Under Siege: How Vulnerable Default Passwords Left U.S. Water Systems Open to Coordinated CyberattacksMySelectRoof
- Suisun City Ransomware AttackTechTimes
- ABA, BPI seek deadline extension for comment on FDIC disclosure ruleABA Banking Journal
- COINBASECARTEL Ransomware Gang: 4 New Victims Posted in 48 Hours — Professional Services, Agriculture and Manufacturing Targeting Analysis with Detection RulesSecurity Arsenal
- Iran-Linked Water Attacks Now Confirmed in 12 StatesXcitium ThreatLabs
- 14,000 Trezor Customers Impacted by Data Breach at ShipMonkSecurityWeek
- Trezor shipping provider breach exposes personal data of nearly 14,000 customersThe Block
- GLBA Safeguards Rule Requirements: Complete Guide [2026]SaltyCloud
- Sens. Klobuchar, Schiff Introduce Comprehensive Cybersecurity Bill in Wake of Recent Cyberattacks on Water InfrastructureOffice of Senator Amy Klobuchar
- LiteLLM Supply Chain Breach Spreads Credential Stealer Across Thousands of Enterprise CI/CD EnvironmentsCyberpress
- HIPRA Advances Out of Senate HELP CommitteeAlston & Bird
- El INCIBE-CERT alerta de tres vulnerabilidades en PLCnext de Phoenix ContactMoncloa
- Mexico KYC & AML Compliance 2026: The LFPIORPI ReformShuftiPro
- CVE-2025-41770: PLCnext Engineer DoS VulnerabilitySentinelOne
- Trezor: ShipMonk breach exposed data of 13689 buyersCryptodaily
- Tras alerta investigan ciberataques a Entel, Movistar y TelmexNIVEL4 Labs
- Trezor, SafePal Breaches Expose 53487 Wallet OwnersShattered.io
- Penetration Testing for Financial Institutions: 2026 Guide - CYBRICYBRI
- Cyber Intel Brief: CVE-2026-72898 in MetabaseDataminr
- Imprensa global repercute suspensão do Discord no Brasil e vê intensos conflitos do governo com empresas de tecnologiaO Globo
- Expanding Capabilities to Combat Transnational Cyber-Enabled CrimeThe White House
- Apagão do "Go Live": por que a ANPD desligou as transmissões ao vivo do Discord no Brasil e o que esperar agoraInsight News
- PREVENTIVE ALERT : CONSOLIDATEDVECERTRadar (X)
- Discord reage à suspensão de 'lives', diz que ANPD foi prematura e rebate alegações do governoO Globo
- Are hacks of U.S. water facilities a new front in the Iran war?NPR
- United States: President Trump Authorizes Private Sector Cyber Operations ProgramBaker McKenzie
- Microsoft Patch Tuesday for August 2026 Fixed a Zero-Day and Wormable RCESecurity Affairs
- Brazil Suspends Discord Livestreaming After Teenager’s DeathBloomberg
- Brazilian Agency Orders Discord to Suspend Livestreams after Teenager's DeathFolha de S.Paulo
- Gunra ransomware targets hospitals: CISA, FBI issue new warningBecker's Hospital Review
- Water Cyber Shield Act Seeks Cybersecurity Standards After Utility ...Security Boulevard
- Understanding the Brazilian Censorship of Discord and Brazil’s Digital ECAAkitaOnRails
- Brazil orders Discord to suspend livestreaming after teen's deathUPI
- Agência Nacional de Proteção de Dados suspende lives do Discord no BrasilG1 / Globo
- The SCREEN Act's VPN Trigger, Not Its Quorum Failure, Is the Real ProblemPeople of the Internet
- TeamPCP’s LiteLLM Backdoor: New Data Shows 2,100+ Orgs ExposedCloud Security Alliance Labs
- CVE-2026-68820: Windows AFD.sys Use-After-Free Actively ExploitedSecurity Arsenal
- Fact Sheet: President Donald J. Trump Expands Capabilities to Combat Transnational Cyber-Enabled CrimeThe White House
- CSIRT Panamá Aviso 2026-ago-12: Vulnerabilidad de Denegación de Servicio en Cisco Secure Firewall ASA y FTDCSIRT Panamá
- Em medida preventiva, ANPD determina que Discord suspenda transmissões ao vivo no BrasilANPD (portal oficial del gobierno de Brasil)
- Brazil agency orders Discord chat platform to suspend livestreaming over child safety concernsReuters
- Brazil: ANPD Orders Discord to Suspend Go Live Streaming in 3 DaysObsidianRI
- The Ripple Effect: Massive Data Breach at Unlimited Technology Systems Highlights Vulnerability in Healthcare Supply ChainHealth Recovery Support
- Minnesota Water Attacks: OT Security Lessons for CISOsLares
- Attackers Exploit VMware vCenter Vulnerability to Gain Persistent AccessThe Hacker News
- Documento da ANPD expõe falhas que levaram à suspensão do DiscordMetrópoles
- Beneficial ownership regime's demise removes tool for banksAmerican Banker
- SEC Cybersecurity Disclosure Rules: A Compliance Guide for ...Compyl
- Cybercrime News For Aug. 11, 2026. Hackers Cripple 911 In California City.WCYB Digital Radio
- CVE-2026-20349 — Cisco ASA and FTD VPN Heap Inspection Denial-of-Service Flaw0dayNews
- Ransomware Hits 911 Systems and Government Services Across Five StatesProtect Computer
- Un fallo de la IA que usaba para estafar delata a un ciberdelincuenteEl País
- Water Water Everywhere - Possible Iranian Attack to Water InfrastructureSecurity Boulevard
- LiteLLM Supply-Chain Attack - Technology, Banking and ...Security Affairs
- TeamPCP Campaign Timeline: From the Trivy ...CloudSEK
- July 2026 US Water Infrastructure Attacks - IoT M2M CouncilIoT M2M Council
- Gunra Shifts Ransomware to Perimeter Break-ins · PlainSec briefing, 2026-08-12PlainSec
- NYDFS Cybersecurity Regulation (23 NYCRR 500): The Complete Compliance GuideCompyl
- Senate bill directs EPA to develop baseline cyber ...Inside Cybersecurity
- OCC's new approach to vendor oversight intensifies scrutiny of fintech and critical activitiesNoah News
- Ransomware breach at health IT vendor tops 3.8 million patientsBecker's Hospital Review
- Sens. Schiff and Klobuchar unveil new cybersecurity billUPI
- S. 3893: SAFE ActModernAction
- CRI2026 - BLOCKING LARGE-SCALE ADVERSARIAL DISTILLATION EFFORTS (BLADE) ACTGovInfo
- CVE-2026-72898 entry in Vulnerability-LookupCIRCL
- Metabase CVE-2026-72898 vulnerability listingUpGuard
- CVE-2026-72898 exploited: patch Metabase nowSenserva
- CVE-2026-72898 · Metabase · CVSS 10.0 · CISA KEVCVE Brief
- Healthcare Orgs Warned About Gunra Ransomware AttacksHIPAA Journal
- CVE-2026-72898: Metabase SQL Injection Under Active Exploitation - Detection and Remediation GuideSecurityArsenal
- Metabase CVE-2026-72898 CISA KEV Patch GuideFixitPhill
- CVE-2026-20349: Cisco ASA and FTD VPN DoS FlawSocPrime
- Heap Inspection in Cisco Firewall Threat Defense (FTD) ...Cybersecurity-help.cz
- CVE-2026-20349 · Cisco · CVSS 9.5 · CISA KEV · CVE BriefCVE Brief
- Cisco ASA and FTD Flaw Exploited in the Wild Can Trigger ...The Hacker News
- CVE-2026-20349: Cisco ASA și FTD, exploatate activ | Awarely MonitorAwarely Monitor
- CVE-2026-20349 Detail - NVDNVD
- Federal Agencies Warn of Gunra Ransomware Targeting Healthcare, Government and Critical ServicesObiaks
- #StopRansomware: Gunra RansomwareCISA
- CVE-2026-72898 Detail - NVDNVD
- Ciberataque a Ecopetrol: qué datos quedaron expuestosITSitio Colombia
- CISAgov communication on Gunra ransomware advisoryCISA
- Unlimited Technology Systems updates recent data breach to 3.8M victimsPaubox
- US healthcare software giant Unlimited Technology Systems admits hackers may have stolen sensitive data of 3.8 million peopleTechRadar
- Agencies warn of attacks by Gunra ransomwareAHA News
- Risky Bulletin: Pwnie Awards 2026 winnersRisky Business
- How Prepared Are We for Cyberattacks on Cities, Water Systems?NPR / KQED Forum
- CoreBreak: i Tool degli Agent AI Partono Senza il ModelloPasquale Pillitteri
- Cyberattacks target PLCs at multiple U.S. water utilitiesESEMAG
- Tienen que desenchufar literalmente la ciudad para frenar a los hackers: el ataque que ha dejado sin red al 911 en CaliforniaLa Razón
- Ransomware breach at health IT vendor tops 3.8 million patientsBecker's Hospital Review
- Experts say healthcare faces cybersecurity crisis: 'These are patient ...Cybersecurity Dive
- La inteligencia artificial reduce a segundos el tiempo para explotar fallas de ciberseguridadEl Economista
- Visa identifica más de US$26 mil millones en presuntos fraudes con inteligencia artificial en América Latina y el CaribeEl Briefing PA
- Erin Thompson, In the Matter of (timeline item) - August 10, 2026Federal Trade Commission
- Federal advisory warns of Gunra ransomware targeting healthcarePaubox
- Weekly CISA KEV Updates: 10 August 2026HackerStorm
- CVE-2026-72898 — CVSS 10.0, CRITICALCVE Security
- EEUU alertó ciberataques a empresas chilenas de telecomunicaciones ligados a hackers chinosBioBioChile
- Reportes de inteligencia de Estados Unidos alertan sobre actividad maliciosa y uso de malware en los sistemas de las empresas de telecomunicaciones en ChileRevistaSeguridad.cl
- EE.UU. advirtió a Chile sobre la presencia del APT Lilac TyphoonSecurity-Chu
- Chile's Cybersecurity PushThe Rio Times
- CVE-2026-72898 - Vulnerability DetailsOpenCVE
- Cyber attack targets California city's 911 systemABC News
- Una ciudad del norte de California declaró el estado de emergencia tras un ciberataque que afectó el sistema 911 y otros servicios claveInfobae
- North Carolina Ports Authority Cyberattack Disrupts IT Systems and Port Operations at Wilmington, Morehead City, and Charlotte Inland PortRescana
- Chaos as California city declares state of emergency after hackers ...Yahoo News / NewsNation
- Suisun City Declares State of Emergency After CyberattackKQED
- PDI investiga posible espionaje a Entel, Movistar y Telmex24Horas
- Diputados piden esclarecer eventual ciberespionaje a empresas de telecomunicacionesEmol
- Deeplinks BlogEFF
- INTELLIGENCE CONSOLE – threat activity involving telecommunications entities such as Claro (Latin America / Dark Web) – UNCLASSIFIEDVECERT Radar
- Suisun City declares state of emergency after IT systems breachKCRA
- Suisun City Council Declares State of Emergency in response to Cybersecurity IncidentSuisun City
- CVE-2026-68820 | Microsoft Windows AFD.sys VulnerabilityUpGuard
- "Lilac Typhoon": PDI indaga "posibles ataques informáticos" de un grupo de ciberespionaje asiáticoCooperativa
- Nueva York destina USD $9 millones para blindar 153 sistemas de agua contra ciberataquesDiario Bitcoin
- "Lilac Typhoon": PDI indaga "posibles ataques informáticos"Radio Cooperativa
- Suisun City declares state of emergency after cyberattackTelemundo Area de la Bahia
- Cyberattack Hits North Carolina Ports, Disrupts OperationsProtect Computer
- Known Exploited Vulnerabilities CatalogCVE Circl
- NewsBites Volume XXVIII – Issue 58SANS Institute
- Tech Bills of the Week: Deterring AI distillation; Taxing AI developers and moreNextgov
- Did Iran hack water systems in at least seven US states?BBC
- Cidade dos EUA declara emergência após ciberataque atingir sistemas do 911 e da políciaTarget W
- DEF CON 34: muestran cómo se pueden hackear los controles biométricos de bancos y fintech de América LatinaClarín
- North Carolina Ports Authority Faces Major Cyberattack, Operations DisruptedSamSearch
- La capacidad de los modelos de IA para burlar la seguridad alarma a gobiernos y empresasEFE
- Detectan intentos de explotación de una vulnerabilidad crítica en Progress Kemp LoadMasterAltonaSpain
- Maritime Cybersecurity Bulletin - August 7th, 2026Cydome
- Progress security advisory (AV26-552) – Update 2CSIRTS.com
- Coast Guard says it is monitoring cyberattack that disrupted North Carolina portsCyberScoop
- Cybersecurity Weekly Report : August 3-9, 2026Cyberinfos
- Hackers targeted US private equity, other firms including Blackstone, CMEReuters
- Unlimited Technology Systems data breach exposes information of 3.8M patientsTop Class Actions
- SQL injection using an unauthenticated endpoint leading to ... (Security Advisory)Metabase
- El Pentágono admite en un juzgado que Grok participó en el ataque a Irán: 2.000 municiones en 96 horasDigitalBrain
- The White House Is Right on AI. Now Let Defenders Use It.War on the Rocks
- Federal systems increasingly likely face accidental AI breach after Hugging Face, experts sayNextgov
- 2026 ShipMonk — Metabase vulnerability path; unauthorized access to customer/order data (Trezor notices)BreachHistory
- NC Ports operating manually after cyberattack disrupts statewide systemsWECT
- Former NSA Cyber Leaders Warn AI Is Accelerating Cyber OperationsExecutiveGov
- Adobe Uses AI Agents to Virtual-Patch CVEs in Minutes (section on Metabase CVE-2026-72898)Cloud Security Newsletter
- Ransomware a Oldelval: la gobernanza que le falta a Vaca MuertaDataTrends Latam
- Oleada de 'hackeos' a los sistemas de agua potable de EEUU: la guerra moderna que apunta a Irán como sospechosoEl Español
- DRAGONFORCE Ransomware Gang: 4 US Victims in Single Day Leak BatchSecurity Arsenal
- Minnesota & other US Water Cyber Attacks, CISA AA26-097ATenable
- Blocking Large-scale Adversarial Distillation Efforts Act of 2026 (BLADE Act/SB 5252) was introduced to SenateDigital Policy Alert
- S. 5252 (IS) - Blocking Large-scale Adversarial Distillation Efforts Act of 2026GovInfo
- The Threat of CCP-Controlled Infrastructure in the U.S. Communications BackboneBenton Institute for Broadband & Society
- SCREEN Act: Developers Must Now Verify Every User’s IdentityByteIota
- Coweta, Okla., Confronts Systemwide Ransomware AttackGovTech
- City of Coweta, Oklahoma Hit by Anubis Ransomware AttackThreadlinqs Intelligence
- City of Coweta Refuses Ransom After CyberattackGovly
- Coweta Ransomware Attack Locks City Computers As Officials Refuse To Pay HackersRadio Oklahoma News
- City of Coweta Hit by Ransomware: Oklahoma Community Faces Major Digital Disruption as Recovery BeginsUNDERCODE News
- CISA Añade Tres Vulnerabilidades Activamente ExplotadasCybersecurefox
- Ransomware Alert: Oldelval victim of INC RANSOMFalconFeeds
- El FBI alerta de un ciberataque contra sistemas de agua en siete estados de EE.UU.Moncloa
- UBS hit with $125m fine by US FinCENFintech Futures
- S. 3097 (RS) - Health Information Privacy Reform Act | Content DetailsGovInfo
- Chinese telecom firms kept footholds in US networks despite federal crackdowns, House probe findsNextgov
- Chinese Telecom Hack Exposed Data Centers, House Report to SayBloomberg
- CVE-2026-34486 Apache Tomcat - f4n6f4n6
- CISA KEV Catalog — Known Exploited Vulnerabilities TrackerCVETodo
- The Morning Risk Report: UBS Fined $125 Million Over Alleged AML FailuresThe Wall Street Journal
- UBS fined $125 million by US regulators for money laundering violationsReuters
- FinCEN Assesses Historic $125 Million Penalty Against UBS Financial Services Inc. for Recidivist BSA ViolationsFinCEN
- Oldelval Cyberattack Hits Argentina's Top Oil Pipeline - The Rio TimesThe Rio Times
- Ecopetrol Ransomware Attack, July 2026: The GentlemenDataEnforce
- California drugmaker Amgen reports theft of patient data in cyber incidentThe Mercury News
- Argentina's Main Oil Pipeline Was Hacked. The Oil Kept ...The Rio Times
- PRESS DIGEST 2 AUG 2026: Hunt Oil in VEN; Vaca Muerta pipeline ...Energy Analytics Institute
- Ciberseguridad en los servicios financieros: amenazas y cumplimientoWiz
- INCRANSOM Ransomware Gang: 10 Victims in 5 Days — Cross-Sector Campaign Hits Healthcare, Energy & Quantum TechSecurity Arsenal
- Cybersecurity Resource CenterNew York State Department of Financial Services
- Top Financial Services Cybersecurity RegulationsHYPR
- Guía de seguridad y cumplimiento de datos financierosPetronella Technology Group
- Cumplimiento de la seguridad de los datos financierosDPO Consulting
- Michigan joins Minnesota in reporting cyberattacks, with FBI investigatingAl Jazeera
- 7 States' Water Systems Hit by Cyberattacks Likely Tied to IranWIRED
- Argentina's Oldelval Cyberattack Disclosure Shows Securities Law, Not Cyber Law, Is Doing the WorkPeople of Internet
- Interlock Ransomware Strikes Gardiner Family ChiropracticDexpose
- Interlock and Clop Ransomware Claims Put Two Businesses Under Fresh Dark Web Pressure + VideoUNDERCODE NEWS
- Gardiner Family Chiropractic Ransomware Claim (2026) — What’s Alleged & Am I Affected?Recent Breaches
- Suspected Iran-Linked Campaign Targeted U.S. Water Utility ICSMallory
- Ciberataque al agua en Minnesota: memo apunta a IránQore
- Wave of Hacks Hits U.S. Water FacilitiesThe Wall Street Journal
- Feds issue warning to local water systems over increased cyber threats after Minnesota hacksABC News
- Hackers targeted municipal water systems in 7 states this week, FBI and EPA warnYahoo News
- US cyber defence agency warns hackers are increasingly targeting water systemsThe Straits Times
- CVE Brief - July 30, 2026CVE Brief
- Boletín Semanal de Ciberseguridad, 25-31 de julioTelefónica Tech
- US cyber defense agency warns hackers are increasingly targeting water systemsReuters
- CISA warns of 'significant increase' in cyber threats to US water utilitiesE&E News
- US authorities see 'significant escalation' in attacks on water system devicesCybersecurity Dive
- US authorities probe cyberattack on water systems in MinnesotaAl Jazeera
- Investigators probing possible Iran connection to Minnesota water system cyberattacksABC News
- So About That Iranian Cyberattack on Our Water SupplySlate
- Estados Unidos sospecha que Irán pudo estar tras el ciberataque a los sistemas de agua de MinnesotaLa Tercera
- FBI Investiga ciberataque contra sistemas de agua en Minnesota; señalan a hacker iraníesExcélsior
- Alerta sobre nueva campaña de ciberataques que afecta a organizaciones de América LatinaEstamos en Línea
- Iran-linked CyberAv3ngers suspected in attacks on Minnesota water systemsThe Register
- FBI investiga ciberataques contra sistemas de abastecimiento de agua en Míchigan y MinnesotaEl Nuevo Día
- A exploração de vulnerabilidades virou o vetor de acesso nº1: por que mais patches é apenas parte da respostaGetup Cloud
- Federal Regulators Settle HIPAA Enforcement Action with OSF HealthcareLeadingAge
- Avisos | INCIBE-CERTINCIBE-CERT
- INCIBE alerta de una inyección SQL en ERPNext que permite ejecutar consultas arbitrariasMoncloa.com / INCIBE-CERT
- Cyberattack targets more than 30 Minnesota water systemsUSA Today
- Estafas digitales: cómo operan las bandas que usan inteligencia artificial para engañarElonce
- Qué hay detrás de los ciberataques contra sistemas de agua en 7 estados de EEUU y por qué muchos apuntan a IránEl Observador
- El FBI investiga ciberataques a los sistemas de agua de Michigan y MinnesotaUnivision
- Hackers targeted municipal water systems in 7 states this week, FBI saysNBC News
- Ataque cibernético coordenado atinge 30 estações de água nos Estados Unidos e mobiliza força-tarefaTecmundo
- Ciberataque coordinado afectó a más de 30 sistemas comunitarios de agua en MinnesotaNivel4
- Minnesota cyberattack has hallmarks of Iran-backed hackers, source saysNBC News
- Las Noticias Más Importantes de IA HoyTrend Micro
- Vulnpedia — Vulnerability Reference, Triage & PoC FinderVulnpedia
- CVE Tools — The CVE database that answers backCVE Tools
- CISA Alerta sobre Explotación Activa en Fortinet FortiOS (CVE-2025-68686) para PersistenciaDevel Group
- Salt Typhoon: What It Is, How It Works & 2026 StatusCorenexis
- T-Mobile Cut Cable to Eject Salt Typhoon HackersCyber Kendra
- Americas OT/ICS & SCADA CybersecurityShieldworkz
- Iran‑Linked Hackers Exploit Internet‑Facing PLCs at U.S. Water Utilities, Prompt Call for CISA OT Security DirectiveLiveThreat.ai
- CVE-2026-71494INCIBE-CERT
- Security Fixes in Apache CloudStack 4.20.3.1 and 4.22.1.1ShapeBlue
- Technical analysis of Iranian Cyber campaigns targeting OT/ICS in water and energy sectorsShieldworkz
- Cloud IAM Misconfiguration Hits 98% of Accounts [2026]Shattered
- Due diligence programs for correspondent accounts for foreign financial institutionsGovRegs
- New cybersecurity committee follows years of attacks on Mississippi’s public sectorMississippi Independent
- Avisos SCIINCIBE-CERT
- (TLP:CLEAR) CISA Issues Alert Urging Water and Wastewater Utilities to Protect OT Against Activity Targeting PLCsWaterISAC
- THEGENTLEMEN Ransomware Gang: 25 New Victims Posted, Sector Targeting Analysis and Detection RulesSecurity Arsenal
- CISA confirms hackers targeted over 100 US water systems during JulyTechCrunch
- FBI Issue Warning on IoT & OT VulnerabilitiesIoT M2M Council
- Top 10 Cybersecurity News (August 17, 2026): Jewelbug APT runs espionage and crypto fraud in parallel, Iran-linked hackers hit New Jersey, Alabama water utilities, and moreInnovateCybersecurity
- Top 10 Cybersecurity News (August 24, 2026): Hacker Sells Azure ...InnovateCybersecurity
- CISA and partners publish Gunra ransomware defense guidance for critical infrastructureCyberOGZ
- CISA and partners publish advisory on double-extortion ransomware threatInside Cybersecurity
- Defending Against Gunra: Key Takeaways from the Joint CISA AdvisoryCyber Defense Magazine
- This Week in Cyber - August 20–26, 2026CrunchAtlas
- FBI says Chinese hacking group targeted US government agencies ...ABC News
- Data breaches surge in 2026 as AI plays a growing role ...CNBC
- CISA still finds water system controls exposed online amid multistate hacksNextgov/FCW
- Government admits water system cyberattacks were worse than first reportedNBC Chicago
- Cybersecurity Alert: Coordinated Cyberattacks Hit 30+ Water SystemsVC3
- Iranian-Linked Cyberattacks Target U.S. Municipal Water and Wastewater Systems: 2026 Multistate Incident AnalysisRescana
- Over 100 U.S. Water Systems Were Hit in July Cyberattacks – That May Just Be The Test RunYahoo News
- Trump signs order banning some foreign equipment from U.S. energy gridReuters
- Fact Sheet: President Donald J. Trump Declares a National Emergency to Secure America’s Bulk Power SystemThe White House
- Declaring a National Emergency to Secure the United States Bulk Power System (Executive Order 14420)The White House
- US Energy Infrastructure Securitization and Foreign Equipment Restrictions: National Emergency Declarations and Supply Chain RealignmentMapShock
- CISA Advisory AA26-231A: Active Threat Actors Use AI-Generated ...OT Security Wire
- At least 12 states report cyberattacks on water systems ...CBS News
- Mapping Iranian Cyberattacks on U.S. Water SystemsCSIS
- What to Know About the U.S. Water Systems CyberattacksTime
- CISA AA26-222A: Gunra RansomwareSafeBreach
- Gunra Ransomware: How the MFA Bypass Works | Red HoundRed Hound
- Gunra Ransomware Hit Hospitals and Governments; Linux Victims Should Not Pay RansomTechtimes
- #StopRansomware: Gunra Ransomware - USCISA | lazarus.dayLazarus.day
- Gunra Ransomware Coverage for CISA Alert AA26-222A - SOC PrimeSOC Prime
- Medusa Ransomware: CISA, FBI, and HHS Issue Urgent Warning ...Cyberfence Platform
- Medusa Ransomware AA25-071A | SafeBreach CoverageSafeBreach
- CISA and HHS Issue Joint Advisory on Medusa Ransomware After ...Tech-Quire
- Medusa Ransomware Alert – Cyber JIFCyber JIF
- DOJ unseals new charges against 17 hackers in Iran-backed campaignReuters
- 17 Iranians charged in US cyber theft campaign, federal prosecutors sayABC News
- US says Chinese hackers broke into Justice Department, NASA, Federal Reserve and SenateReuters
- US federal agency confirms data breach in wake of claims by ransomware groupReuters
- Qilin ransomware publishes A&E + SMA Design (UAE) and US victimsPulse
- Treasury sanctions Iranian hackers tied to critical infrastructure breachesNextgov
- U.S. Sanctions Iran-Linked Hackers Behind Critical Infrastructure BreachesThe Hacker News
- What are the new US economic sanctions on Iran and its allies?Reuters
- Weekly Compliance Brief: August 17-21, 2026 | ClymClym
- This Week in Privacy: August 3–7, 2026PII.ai
- Senate passes stopgap funding bill with short-term extension of ...Inside Cybersecurity
- Right To Know - August 2026, Vol. 44 | News & EventsClark Hill
- White House Authorizes Private-Sector Offensive Cyber OperationsCrowell & Moring LLP
- The Digital Download | August 2026 - Alston & BirdAlston & Bird
- Legal & Compliance — August 2, 2026 Monthly - OriginBriefOriginBrief
- US Authorizes Private Cyber Firms to Hack Transnational Criminal ...Security Affairs
- This Week in ICT & Cybersecurity — Washington (#31, 2026)Queen Street Analytics
- Privacy & Cybersecurity Law BlogHunton Andrews Kurth LLP
- In a first, US will allow some private firms to carry out ...TechCrunch
- CISA KEV, August 2026: patch, then assume compromisePro IT Northwest
- CISA Alert: 4 Exploited Vulnerabilities to Patch NowBurgiTech
- Resumen de Amenazas — Agosto 2026: 10 vulnerabilidades críticas | Boletín de Seguridad CiberPlanetaCiberPlaneta
- Andover Listed by Wallstreet Ransomware GroupGalaxy Warden
- Victim: AndoverRansomware.live
- Ransomware Group Wallstreet Hits: AndoverHookPhish
- DragonForce ransomware publishes data of Brazilian ...Kalir Pulse
- AUM Construction Listed by Qilin Ransomware GroupGalaxy Warden
- Victim: AUM ConstructionRansomware.live
- Ransomware Group qilin Hits: AUM ConstructionHookPhish
- DistributionNOW (DNOW Inc.) Listed by Falcon ...Galaxy Warden
- Victim: DistributionNOW (DNOW Inc.)Ransomware.live
- VMware vCenter Directory Traversal Under Active Global ExploitationCloud Security Alliance
- How to find VMware vCenter assets on your networkrunZero
- VMware vCenter Zero-Day: CVE-2026-59310 Hits 47 NationsTech Insider
- VMware vCenter CVE-2026-59310: Active Exploitation of ...dev.to
- Microsoft's CVSS 10.0 Entra ID RCE Briefly Tagged ‘Exploited' Before Correction — and What That Reveals About Identity Infrastructure DisclosureYahoo Tech
- Microsoft patches critical Entra ID vulnerability (CVE-2026- ...)Help Net Security
- CVE-2026-21962: Oracle HTTP Server & WebLogic Proxy Plug-in Improper Access Control — KEV-Listed, Detection and Remediation GuideSecurityArsenal
- CISA Warns of Exploited Oracle WebLogic VulnerabilitySecurityWeek
- U.S. CISA adds maximum-severity Oracle flaw to its Known Exploited Vulnerabilities catalogSecurityAffairs
- CVE-2026-21962: Oracle WebLogic & HTTP Server Actively Exploited — Detection and Remediation GuideSecurityArsenal
- CVE-2026-18577: N-able N-central Authentication Bypass ...Rapid7
- CVE-2026-18577 Impact, Exploitability, and Mitigation StepsWiz
- CVE-2026-18577Tenable
- China-Linked Hackers Deploy New StormEncryptor ...The Hacker News
- 新種ランサムウェア「StormEncryptor」— 中国拠点の金銭目的グループがN-central脆弱性経由で投入かNEXSIGHT CYBER WIRE
- Storm-1175 Deploys StormEncryptor Ransomware via N-central FlawMaverc
- StormEncryptor - Mallory.aiMallory.ai
