Late August tightened around infrastructure and access: Qilin widened its ransomware lead, technology moved into the top victim sector, and the U.S. remained dominant even as its share fell again. Enterprise-facing vulnerabilities clustered around Oracle/WebLogic, SharePoint, vCenter, Zimbra, PaperCut, and NetScaler, while malware activity leaned heavily into stealers, loaders, mobile banking fraud, and remote access. The common thread is speed. Actors are exploiting exposed services, abusing social engineering, and rotating infrastructure quickly, putting fast patching and stronger identity controls at the center of the defensive picture.

Report Links

Download Threat Brief For August 16-31 2026

Byer-Nichols Threat Brief Podcast August 16-31 2026

Ransomware Actors

Ransomware Percentage Last Period Two Ago
Qilin 17.71% 1 2
The Gentlemen 9.48% 2 1
Dire Wolf 4.65% 9 N/A
INC Ransom 4.29% 5 5
LockBit 3.94% N/A 16

Qilin separated from the pack, climbing to 17.71% and adding 4.82 percentage points while holding the top spot. The Gentlemen stayed #2 but cooled to 9.48%. Dire Wolf is the real mover, jumping from ninth to third, while INC Ransom remained steady and LockBit returned to the top five. Notably, the top-five share fell from 44.34% to 40.07%, so Qilin’s surge is happening inside a more fragmented field rather than a broader consolidation.

Victim Sector

Sector Percentage Last Period Movement
Technology 16.28% 2 2 -> 1
Manufacturing 15.74% 1 1 -> 2
Financial Services 14.13% 5 5 -> 3
Construction 12.88% 4 same
Retail 8.94% 3 3 -> 5

Victim Location

Victim Percentage Last Period Movement
USA 41.32% 1 same
Germany 6.62% 4 4 -> 2
Italy 5.19% 3 same
UK 3.94% 4 same
Canada 2.50% 2 2 -> 5

Victim Org Size

Size Percentage Last Period Change
Small Business (500 or less) 76.57% 73.28% +3.29%
Mid-Market (501-5000) 16.99% 17.49% -0.50%
Large Enterprise (5000+) 6.44% 9.23% -2.79%

Trending Adversaries

Aur0ra brings a newer AI-assisted criminal angle, while Cl0p remains the most recognizable mass-exploitation specialist in the set. Dark Caracal, Mabna Institute, and Transparent Tribe skew toward longer-term espionage and intelligence collection, while Storm-1175 operates at ransomware speed, weaponizing exposed web-facing systems and newly disclosed flaws quickly. Together, the group shows the current split clearly: persistent intelligence collection on one side and rapid exploitation-for-impact on the other.

  • Aur0ra
  • Cl0p
  • Dark Caracal
  • Mabna Institute
  • Storm-1175
  • Transparent Tribe

Trending & Actively Exploited Vulnerabilities

Late August’s exploited-vulnerability list is concentrated in enterprise infrastructure rather than everyday end-user software: Oracle/WebLogic, SharePoint, VMware vCenter, Zimbra, PaperCut, and Citrix NetScaler all sit in high-value administrative or collaboration paths. Microsoft IKE and the Linux kernel broaden the exposure into core operating-system components, while two PaperCut entries reinforce how often attackers return to centralized management platforms with broad network reach. Internet-facing admin services and management tools should remain at the front of the patch queue.

CVE Vendor Product
CVE-2026-21962 Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in
CVE-2026-33824 Microsoft Internet Key Exchange (IKE) Service Extensions
CVE-2026-53362 Linux Kernel
CVE-2026-55040 Microsoft SharePoint
CVE-2026-59310 Broadcom VMware vCenter
CVE-2026-65400 Apple macOS
CVE-2026-73570 Synacor Zimbra Collaboration Suite (ZCS)
CVE-2026-81578 PaperCut NG/MF
CVE-2026-82078 PaperCut NG/MF
CVE-2026-8452 Citrix NetScaler ADC and NetScaler Gateway

Trending Malware

Trending Malware Details
Amatera Stealer Information-stealing malware-as-a-service and ACR Stealer successor built to harvest credentials and sensitive endpoint data while improving anti-analysis evasion.
C2Looper Rust-based backdoor that uses GitHub as command-and-control and supports reconnaissance, arbitrary command execution, and second-stage payload delivery.
MacSync Stealer macOS-focused information stealer that uses ClickFix-style social engineering, rotating infrastructure, and scripted collection to steal credentials and sensitive files.
SynkLoader Modular loader delivered through Microsoft Teams phishing that combines memory-resident components, credential phishing, tunneling, and hands-on-keyboard access.
ToxicPanda 2.0 Android banking trojan and remote-access tool built for on-device fraud through overlays, Accessibility abuse, PIN capture, and expanded remote control.
ValleyRAT Windows remote-access trojan used in evolving campaigns that rely on fake installers, malicious email, staged payload delivery, and anti-analysis techniques.

Top News

  • Chinese ZBT Routers Sold Worldwide Contain Backdoors
  • Claude Desktop Malvertising Campaign Hit 29 Organizations with SectopRAT
  • Delta flight carrying DEF CON “hackers” hit by Wi-Fi attack mid-air
  • Interpol's Jackal IV Disrupts West African Crime Infrastructure
  • NovaCookies' Kit Steals Microsoft 365 Sessions for $320 a Month
  • Post-DEF CON Phishing Uses Malicious Google Doc to Deliver Malware
  • Russian Hackers Phish EU Officials Over Messaging Apps

Contributors

Written by Jeremy Nichols, Director, Security Programs & Strategy at SecureSky Executive Summaries & Adversary Bio's by Geoff Rehmet, Cybersecurity Architect Produced & Distributed By Phish Tank Digital