Late August tightened around infrastructure and access: Qilin widened its ransomware lead, technology moved into the top victim sector, and the U.S. remained dominant even as its share fell again. Enterprise-facing vulnerabilities clustered around Oracle/WebLogic, SharePoint, vCenter, Zimbra, PaperCut, and NetScaler, while malware activity leaned heavily into stealers, loaders, mobile banking fraud, and remote access. The common thread is speed. Actors are exploiting exposed services, abusing social engineering, and rotating infrastructure quickly, putting fast patching and stronger identity controls at the center of the defensive picture.
Report Links
Download Threat Brief For August 16-31 2026
Byer-Nichols Threat Brief Podcast August 16-31 2026
Ransomware Actors
| Ransomware | Percentage | Last Period | Two Ago |
|---|---|---|---|
| Qilin | 17.71% | 1 | 2 |
| The Gentlemen | 9.48% | 2 | 1 |
| Dire Wolf | 4.65% | 9 | N/A |
| INC Ransom | 4.29% | 5 | 5 |
| LockBit | 3.94% | N/A | 16 |
Qilin separated from the pack, climbing to 17.71% and adding 4.82 percentage points while holding the top spot. The Gentlemen stayed #2 but cooled to 9.48%. Dire Wolf is the real mover, jumping from ninth to third, while INC Ransom remained steady and LockBit returned to the top five. Notably, the top-five share fell from 44.34% to 40.07%, so Qilin’s surge is happening inside a more fragmented field rather than a broader consolidation.
Victim Sector
| Sector | Percentage | Last Period | Movement |
|---|---|---|---|
| Technology | 16.28% | 2 | 2 -> 1 |
| Manufacturing | 15.74% | 1 | 1 -> 2 |
| Financial Services | 14.13% | 5 | 5 -> 3 |
| Construction | 12.88% | 4 | same |
| Retail | 8.94% | 3 | 3 -> 5 |
Victim Location
| Victim | Percentage | Last Period | Movement |
|---|---|---|---|
| USA | 41.32% | 1 | same |
| Germany | 6.62% | 4 | 4 -> 2 |
| Italy | 5.19% | 3 | same |
| UK | 3.94% | 4 | same |
| Canada | 2.50% | 2 | 2 -> 5 |
Victim Org Size
| Size | Percentage | Last Period | Change |
|---|---|---|---|
| Small Business (500 or less) | 76.57% | 73.28% | +3.29% |
| Mid-Market (501-5000) | 16.99% | 17.49% | -0.50% |
| Large Enterprise (5000+) | 6.44% | 9.23% | -2.79% |
Trending Adversaries
Aur0ra brings a newer AI-assisted criminal angle, while Cl0p remains the most recognizable mass-exploitation specialist in the set. Dark Caracal, Mabna Institute, and Transparent Tribe skew toward longer-term espionage and intelligence collection, while Storm-1175 operates at ransomware speed, weaponizing exposed web-facing systems and newly disclosed flaws quickly. Together, the group shows the current split clearly: persistent intelligence collection on one side and rapid exploitation-for-impact on the other.
- Aur0ra
- Cl0p
- Dark Caracal
- Mabna Institute
- Storm-1175
- Transparent Tribe
Trending & Actively Exploited Vulnerabilities
Late August’s exploited-vulnerability list is concentrated in enterprise infrastructure rather than everyday end-user software: Oracle/WebLogic, SharePoint, VMware vCenter, Zimbra, PaperCut, and Citrix NetScaler all sit in high-value administrative or collaboration paths. Microsoft IKE and the Linux kernel broaden the exposure into core operating-system components, while two PaperCut entries reinforce how often attackers return to centralized management platforms with broad network reach. Internet-facing admin services and management tools should remain at the front of the patch queue.
| CVE | Vendor | Product |
|---|---|---|
| CVE-2026-21962 | Oracle | HTTP Server and Oracle Weblogic Server Proxy Plug-in |
| CVE-2026-33824 | Microsoft | Internet Key Exchange (IKE) Service Extensions |
| CVE-2026-53362 | Linux | Kernel |
| CVE-2026-55040 | Microsoft | SharePoint |
| CVE-2026-59310 | Broadcom | VMware vCenter |
| CVE-2026-65400 | Apple | macOS |
| CVE-2026-73570 | Synacor | Zimbra Collaboration Suite (ZCS) |
| CVE-2026-81578 | PaperCut | NG/MF |
| CVE-2026-82078 | PaperCut | NG/MF |
| CVE-2026-8452 | Citrix | NetScaler ADC and NetScaler Gateway |
Trending Malware
| Trending Malware | Details |
|---|---|
| Amatera Stealer | Information-stealing malware-as-a-service and ACR Stealer successor built to harvest credentials and sensitive endpoint data while improving anti-analysis evasion. |
| C2Looper | Rust-based backdoor that uses GitHub as command-and-control and supports reconnaissance, arbitrary command execution, and second-stage payload delivery. |
| MacSync Stealer | macOS-focused information stealer that uses ClickFix-style social engineering, rotating infrastructure, and scripted collection to steal credentials and sensitive files. |
| SynkLoader | Modular loader delivered through Microsoft Teams phishing that combines memory-resident components, credential phishing, tunneling, and hands-on-keyboard access. |
| ToxicPanda 2.0 | Android banking trojan and remote-access tool built for on-device fraud through overlays, Accessibility abuse, PIN capture, and expanded remote control. |
| ValleyRAT | Windows remote-access trojan used in evolving campaigns that rely on fake installers, malicious email, staged payload delivery, and anti-analysis techniques. |
Top News
- Chinese ZBT Routers Sold Worldwide Contain Backdoors
- Claude Desktop Malvertising Campaign Hit 29 Organizations with SectopRAT
- Delta flight carrying DEF CON “hackers” hit by Wi-Fi attack mid-air
- Interpol's Jackal IV Disrupts West African Crime Infrastructure
- NovaCookies' Kit Steals Microsoft 365 Sessions for $320 a Month
- Post-DEF CON Phishing Uses Malicious Google Doc to Deliver Malware
- Russian Hackers Phish EU Officials Over Messaging Apps
Contributors
Written by Jeremy Nichols, Director, Security Programs & Strategy at SecureSky Executive Summaries & Adversary Bio's by Geoff Rehmet, Cybersecurity Architect Produced & Distributed By Phish Tank Digital