Weekly Threat Intel Report — 2026-W33: 10-16 August 2026
TL;DR
This week's activity was defined by ransomware operators innovating around endpoint defenses, a new state-linked spearphishing wave against aerospace, and a heavy patch cycle spanning Windows, SAP, VMware, Metabase and macOS. Akira affiliates were observed booting Windows hosts into Safe Mode with Networking to strip out EDR before encrypting — a tactic that failed to encrypt in the reported case but still resulted in data theft. ShinyHunters disclosed the theft of 1.6 million RingCentral account records tied to a July intrusion. Microsoft profiled DeadLock, a Rust-based ransomware family that runs its victim negotiation and leak sites on decentralized infrastructure. Check Point tracked a new 2026 wave of the DPRK-linked Operation Dream Job against aerospace and aviation firms, using trojanized PDF viewers. Meanwhile, Microsoft's Patch Tuesday shipped fixes for 421 CVEs including an exploited zero-day (LegacyHive), and attackers are already exploiting fresh flaws in SAP Commerce Cloud, VMware vCenter, Metabase and macOS Screen Sharing.
Notable Activity by Actor
Akira — EDR evasion via Safe Mode
BleepingComputer reported on 13 August that an Akira ransomware affiliate rebooted a compromised Windows host into Safe Mode with Networking in order to prevent the endpoint's EDR agent from loading. With defenses effectively out of the picture, the operator staged and attempted encryption. In the reported case the encryption stage failed, but the affiliate had already exfiltrated victim data — leaving Akira with leverage for extortion even without a successful encryption event. This is a maturation of an older ransomware technique (MITRE T1562.009) and a reminder that boot-time integrity, tamper-protection settings, and out-of-band monitoring for unexpected reboots remain essential for endpoint defense.
ShinyHunters — RingCentral notifications hit 1.6M users
ShinyHunters was tied this week to a RingCentral breach affecting approximately 1.6 million accounts, according to notifications routed through Have I Been Pwned (BleepingComputer, 14 August). The intrusion itself dates to July 2026, continuing ShinyHunters' 2025-2026 pattern of large-scale SaaS/CRM data theft followed by delayed disclosure and extortion.
Lazarus Group — New Operation Dream Job wave against aerospace
Check Point Research reported on 11 August that a fresh 2026 wave of the long-running Operation Dream Job campaign is targeting the global defense sector, with a specific focus on aerospace and aviation. Operators are distributing modified PDF viewer applications designed to execute payloads embedded in specially crafted PDF lures. The initial-access vector remains the same social-engineering trick — fake recruiter outreach — but the payload chain has shifted toward abusing legitimate-looking document viewers to reduce user suspicion.
Jewelbug — Espionage and crypto-fraud from the same panel
BleepingComputer and DarkReading both covered a threat cluster tracked as Jewelbug, described as a hacker-for-hire group running government webmail intrusions in parallel with cryptocurrency fraud. What makes Jewelbug notable is that both activity types are driven from the same operator web panel, blurring the traditional line between state-style espionage and organized cybercrime.
Emerging Threats
DeadLock ransomware (Microsoft, 10 August)
Microsoft Threat Intelligence published a deep dive on DeadLock, a new financially motivated ransomware operation built around a Rust-based encryptor. What separates DeadLock from other RaaS newcomers is its use of decentralized infrastructure for victim communications, negotiation, and leak-site publication — a design that improves resilience against law-enforcement seizures. DeadLock uses double extortion: data is stolen before encryption and later published to coerce payment.
Gunra ransomware exploiting old Fortinet bugs
DarkReading reported on 11 August that a RaaS operation calling itself Gunra is finding success against critical-infrastructure targets by chaining older Fortinet firewall/VPN vulnerabilities with MFA bypass techniques. Reporting indicates Gunra's tooling reuses leaked Conti source code, positioning it in the growing post-Conti diaspora.
JWR phishing framework (Cisco Talos, 13 August)
Cisco Talos exposed a previously undocumented phishing framework internally branded "JWR" by its developer. JWR is purpose-built to convincingly impersonate the checkout and login pages of major payment processors and shopping platforms — a commodity-grade tool likely to see wide criminal adoption.
Industrialization of malware crypting (Recorded Future, 13 August)
Insikt Group published a profile of 24 threat actors selling malware crypting services, mapping the evasion-as-a-service supply chain. The recommendation to defenders — prioritize behavioral detection over static analysis — is worth repeating for anyone still weighting signature-based tooling too heavily.
Suspected Iranian activity against U.S. water systems
Attacks against internet-exposed PLCs at U.S. water utilities have widened to around a dozen states (DarkReading, 10 August). Public reporting continues to point at Iran-linked activity, likely opportunistic exploitation of exposed and weakly authenticated industrial devices rather than targeted intrusions. It is a stark reminder that basic exposure hygiene remains unresolved in a significant slice of U.S. critical infrastructure.
Vulnerabilities under active exploitation
- Microsoft Patch Tuesday (August 2026): 421 CVEs, 62 critical, one exploited zero-day tracked as "LegacyHive" (Cisco Talos, 11 August; BleepingComputer, 13 August).
- SAP Commerce Cloud RCE: A maximum-severity flaw patched only three days ago is already being exploited in the wild (BleepingComputer, 14 August).
- VMware vCenter CVE-2026-59310: Global exploitation campaign confirmed; researchers warn patching alone may not be sufficient to fully remediate (DarkReading, 13 August).
- Metabase SQL zero-day: Unauthenticated remote administrator access; no CVE assigned yet (DarkReading, 10 August).
- macOS Screen Sharing auth bypass: Public exploit code is being used to deploy Monero miners, per NCSC-NL (BleepingComputer, 14 August).
- Belgium eID browser extension: Severe vulnerabilities effectively broke the trust framework underlying Belgium's electronic ID system (DarkReading, 13 August).
Other notable events
- Shell confirmed it is investigating a potential incident after Clop claimed theft of 89 GB of data (BleepingComputer, 14 August).
- Colombia's Ministry of Justice was hit by ransomware days before a presidential transition, part of a broader uptick in attacks against Latin American government and critical-services organizations (DarkReading, 12 August).
- French tax authority (DGFiP) confirmed unauthorized access to its systems; a threat actor claims 600,000 victims (The Record, 14 August).
Defender Takeaways
- Assume EDR can be circumvented. The Akira Safe Mode technique is not new in principle, but its continued success in 2026 is a signal to review tamper protection, boot-time integrity monitoring, and detections for unexpected reboots or Safe Mode transitions on servers and endpoints.
- Patch cycle priorities this week: the LegacyHive Windows zero-day, SAP Commerce Cloud RCE, VMware vCenter CVE-2026-59310, the Metabase zero-day, and the macOS Screen Sharing authentication bypass. Treat exposed instances as compromise-until-proven-otherwise and add compensating controls where patching lags.
- Externally exposed OT and legacy edge devices remain the softest target. The ongoing water-sector intrusions and Gunra's success with old Fortinet CVEs reinforce that basic attack-surface hygiene — inventory, exposure reduction, MFA hardening — is where risk actually concentrates.
- Watch for Operation Dream Job lures in engineering and aerospace teams. Trojanized PDF viewers are a plausible entry vector; application allow-listing and enforced provenance for document-handling software matter more than another awareness email.
- Rebalance detection engineering toward behavior. With 24 crypting-service vendors profiled and phishing frameworks like JWR industrializing evasion, static/signature detections continue to lose ground.
- Prepare for the delayed-disclosure extortion cycle. ShinyHunters' pattern of exfiltration in month N followed by disclosure in month N+1 or later reinforces the need to hunt for prior compromise across SaaS, IdP, and CRM logs — not just wait for a notification.
Sources
- BleepingComputer — Akira hackers disable EDR with Safe Mode, steal data but fail to encrypt (2026-08-13): https://www.bleepingcomputer.com/news/security/akira-hackers-disable-edr-with-safe-mode-steal-data-but-fail-to-encrypt/
- BleepingComputer — RingCentral data breach exposed info of 1.6 million accounts (2026-08-14): https://www.bleepingcomputer.com/news/security/ringcentral-data-breach-exposed-info-of-16-million-accounts/
- Microsoft Threat Intelligence — DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure (2026-08-10): https://www.microsoft.com/en-us/security/blog/2026/08/10/deadlock-ransomware-breaking-down-a-rust-based-encryptor-with-decentralized-recovery-infrastructure/
- Check Point Research — Shattering the Dream – When a Job Offer Becomes a Zero-Day Attack (2026-08-11): https://research.checkpoint.com/2026/shattering-the-dream-when-a-job-offer-becomes-a-zero-day-attack/
- DarkReading — Gunra Ransomware Gang Exploits Fortinet Flaws, Bypasses MFA (2026-08-11): https://www.darkreading.com/cyberattacks-data-breaches/gunra-ransomware-gang-fortinet-flaws-bypasses-mfa
- DarkReading — Multistate Water System Attacks Widen, Iran Suspected (2026-08-10): https://www.darkreading.com/ics-ot-security/multistate-water-system-attacks-widen-iran-suspected
- DarkReading — 'Jewelbug' APT Balances State Espionage & Cryptocurrency Theft (2026-08-13): https://www.darkreading.com/threat-intelligence/jewelbug-apt-state-espionage-cryptocurrency-theft
- BleepingComputer — Hackers breach govt webmail while running parallel crypto fraud (2026-08-13): https://www.bleepingcomputer.com/news/security/hackers-breach-govt-webmail-while-running-parallel-crypto-fraud/
- Cisco Talos — Dissecting the JWR phishing framework (2026-08-13): https://blog.talosintelligence.com/dissecting-the-jwr-phishing-framework/
- Cisco Talos — Microsoft Patch Tuesday for August 2026 (2026-08-11): https://blog.talosintelligence.com/microsoft-patch-tuesday-for-august-2026/
- BleepingComputer — Microsoft patches LegacyHive Windows zero-day vulnerability (2026-08-13): https://www.bleepingcomputer.com/news/microsoft/microsoft-patches-legacyhive-windows-zero-day-vulnerability/
- BleepingComputer — Max severity SAP Commerce Cloud flaw now targeted in attacks (2026-08-14): https://www.bleepingcomputer.com/news/security/max-severity-sap-commerce-cloud-flaw-now-targeted-in-attacks/
- DarkReading — Global Threat Campaign Hits Critical VMware vCenter Flaw (2026-08-13): https://www.darkreading.com/vulnerabilities-threats/global-threat-campaign-critical-vmware-vcenter-flaw
- DarkReading — Metabase SQL Zero-Day Attacks Could Have Wide Blast Radius (2026-08-10): https://www.darkreading.com/vulnerabilities-threats/metabase-sql-zero-day-attacks-wide-blast-radius
- BleepingComputer — Hackers exploit macOS Screen Sharing flaw to deploy Monero miner (2026-08-14): https://www.bleepingcomputer.com/news/security/hackers-exploit-macos-screen-sharing-flaw-to-deploy-monero-miner/
- Recorded Future — Malware Crypting Services and the Threat Actors Who Sell Them (2026-08-13): https://www.recordedfuture.com/research/malware-crypting-services-threat-actors
- BleepingComputer — Shell investigates 'potential incident' after Clop data theft claims (2026-08-14): https://www.bleepingcomputer.com/news/security/shell-investigates-potential-incident-after-clop-data-theft-claims/
- DarkReading — Ransomware Hits Colombian Justice Ministry Days Before Presidential Transition (2026-08-12): https://www.darkreading.com/cyberattacks-data-breaches/ransomware-hits-colombian-justice-ministry-presidential-transition
- The Record — France investigates tax authority breach after hacker claims 600,000 victims (2026-08-14): https://therecord.media/french-tax-authority-dgfip-confirms-data-breach