Cyber Digest
A daily roundup of key cybersecurity developments across sectors
Executive Summary
A Tuesday digest anchored by active Russia Fork-style ransomware escalation against critical infrastructure, the first documented private-cellular-network pivot into a European heat plant, and a New Zealand sanctions action with direct regional significance. First, CISA, the FBI, DoD DC3, NSA, US Secret Service and the Republic of Korea's National Police Agency released a joint #StopRansomware advisory on Gunra, a ransomware-as-a-service derived from the leaked Conti source code whose affiliates have been targeting government, critical manufacturing, healthcare, transport and utilities across the Americas, Europe, the Middle East, Africa and Asia-Pacific. Second, CERT Polska disclosed at DEF CON a second Polish heat plant attack β hidden for months β revealing the first known use of a private cellular data network as a pathway into an industrial control system, with the infection originating from already-compromised wind farm firewalls. Third, New Zealand sanctioned 33 Russian individuals and entities, including Cyber Army of Russia Reborn members, a GRU Unit 29155 commander and Russian IT firm LANIT. Fourth, Microsoft disclosed that China-linked Storm-1175 deployed a new ransomware strain, StormEncryptor, likely using the N-able N-central flaw (CVE-2026-18577) for initial access β extending the week's RMM exploitation theme.
The N-able N-central exploitation chain is directly relevant to Australian managed service providers, who rely heavily on RMM platforms to manage client endpoints β a compromised N-central instance grants attackers the same elevated access legitimate technicians use, and Microsoft's disclosure that China-linked Storm-1175 ransomware now leverages this flaw means Australian MSPs still running affected N-central versions should treat the vendor's Hotfix 2 as urgent and audit server access logs. The Gunra ransomware advisory is a Five Eyes-aligned warning for Australian critical infrastructure operators: the advisory names healthcare, financial services, critical manufacturing, transport, government and utilities as the primary targets, aligning with ACSC's Essential Eight and ransomware guidance β offline immutable backups and prioritised patching of internet-exposed VPN/RDP remain the highest-yield controls. The Polish private-cellular-network intrusion carries a direct lesson for Australian energy and OT operators, whose distributed renewable sites also rely on private cellular links; ACSC guidance on OT security should be extended to treat these networks as hostile, not trusted, surfaces. ACSC has released no new advisories since the weekend; its current homepage focus remains frontier-AI board guidance, CI Fortify OT isolation, and secure agentic AI adoption in defence.
Today's digest tightens three entrenched weekly themes. Privileged-management and RMM exploitation keeps escalating: the week began with the N-able N-central Hotfix 2 (CVE-2026-18577), and Microsoft now attributes a new China-linked ransomware operation (StormEncryptor by Storm-1175) to likely initial access through that same flaw β the first documented end-to-end ransomware deployment on the RMM attack surface, matching the week's pattern of internet-exposed management appliances being weaponised at speed. Critical-infrastructure OT targeting is broadening from awareness to documented incident: the Polish private-cellular-network pivot (first-known use of that path into ICS, traced from wind-farm firewalls through a cellular router to factory-default controllers) arrives alongside the Gunra RaaS advisory naming critical sectors and the US Senate's Water Cyber Shield Act introduced Monday, capping a week that has consistently tied OT/ICS resilience to the highest-impact defensive stakes. State-sanctioning of cyber behaviour is consolidating among Five Eyes allies: New Zealand's CARR/GRU/LANIT sanctions follow Australia's earlier designations and the US Treasury's 2024 actions, showing a converging Western posture on cyber-accountability alongside the ongoing RussiaβUkraine cyber conflict (Sandworm's recruiter-impersonation campaign against Ukrainian IT workers reported this cycle). For CISOs heading into mid-August, the convergence of RMM exploitation, private-network OT pivots, and accelerating AI-agent security controls (Kimsuky's offline AI stack, OpenAI's Astra pause) confirms the priority ordering: patch velocity on internet-exposed management surfaces, OT network segmentation, phishing-resistant MFA, and human review of AI-driven remediation.
Incident Map
Global (Macro) 4 stories
FBI, CISA and International Partners Warn of Gunra Ransomware Targeting Critical Infrastructure
A joint advisory (AA26-222A) from the FBI, CISA, DoD DC3, NSA, US Secret Service and the Republic of Korea's National Police Agency details Gunra, a ransomware-as-a-service variant derived from leaked Conti source code. Gunra first emerged April 2025, launched a structured RaaS affiliate program in early 2026, and operates a double-extortion model with a Tor-based negotiation portal and dedicated leak site. Victim sectors span healthcare, financial services, critical manufacturing, transport, government, utilities, academia, media and retail across the Americas, Europe, the Middle East, Africa and Asia-Pacific. The advisory includes patching priorities for internet-facing VPN/RDP, offline immutable backups, and network segmentation. **Verification: Verified** (joint official advisory with IOCs).
China-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flaw
Microsoft's Threat Intelligence team disclosed that Storm-1175, a financially motivated China-linked threat actor, has deployed a previously undocumented ransomware strain called StormEncryptor β a C++ locker that appends `.encrypted` to encrypted files and drops `!!!README_FIRST!!!.txt` ransom notes, marking a shift from the actor's prior use of Medusa. Microsoft assesses the initial-access vector is likely exploitation of CVE-2026-18577 in N-able N-central, tying the new ransomware to the same RMM vulnerability that drove the week's hotfix cycle. **Verification: Reported** (vendor analysis; exploitation path assessed, not directly observed).
Kimsuky Builds Offline AI Stack to Boost Phishing and Automate Malware Development
South Korea's Genians reports that North Korean espionage group Kimsuky (under the Reconnaissance General Bureau) is running AI offline on its own servers, connecting document-search tools to stolen files and assembling the software components needed to fold AI into its malware. Genians found no evidence of proprietary model training but describes the group in a "research and knowledge acquisition" stage, using AI to automate phishing and malware development. **Verification: Reported** (vendor telemetry-based; no intrusion confirmed).
New Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFA
Three research efforts (SpecterOps, Palo Alto Networks Unit 42, and a Windows Hello for Business chain) demonstrated that passkey protections can be defeated without breaking the underlying cryptography β by reusing signed authentication material Windows had exposed, abusing cloud-synced passkey systems from malware already on a victim machine, and using a Windows Hello for Business key from a compromised user session without a fresh PIN or biometric check. SpecterOps showed a Windows/Entra ID chain that can impersonate privileged users while satisfying phishing-resistant MFA. **Verification: Verified** (published technical research, not yet observed in the wild).
- TrueConf Server Flaws Exploited to Replace Client Installers with PhantomCore β Head Mare weaponised a flaw chain (KLCERT-26-057/058) in unpatched TrueConf servers to replace client installers with a backdoor/RAT, targeting Russian industrial companies across instrumentation, electronics, transport, energy, IT and software. (The Hacker News, 2026-08-10)
- OpenAI's Next AI Model Astra Shows Cyber Performance Strong Enough to Trigger Pause β OpenAI said it is pausing some internal activities involving Astra after an internal evaluation found significant advancement in agentic coding and cybersecurity; controls include isolated testing, restricted network/tool access, model-weight protection and universal monitoring for risky actions. (The Hacker News, 2026-08-10)
- Solidity Pro VS Code Extensions Steal Crypto Wallets, API Keys, and Credentials β Malicious VS Code extensions (`helper-beeps.solidity-pro`, `web3devtoolsx.solidity-pro`) evolved from a Cloudflare-Workers-delivered Python payload into a full information stealer exfiltrating browser profiles, crypto wallets, source-control/API/SSH keys and Telegram tokens. (The Hacker News, 2026-08-10)
Government 2 stories
New Zealand Sanctions Russian Hackers, Propaganda Groups Over Ukraine War
New Zealand imposed new sanctions on 33 Russian individuals and entities over roles in supporting Russia's war in Ukraine, including cyberattacks, sanctions evasion and anti-Ukraine propaganda. The designations include Yuliya Pankratova and Denis Degtyarenko (Cyber Army of Russia Reborn / Z-Pentest), Aleksandr Volosovik (alleged operator of bulletproof hoster Media Land), Andrey Averyanov (former commander of GRU Unit 29155), the Kremlin-backed Internet Development Institute and its director Alexey Goreslavsky, and Russian IT firm LANIT. Measures include asset freezes and travel bans, and prohibit New Zealanders from making funds available to designates.
Senate Democrats Introduce Bill Distributing $300 Million Annually for Water System Cybersecurity
Senator Adam Schiff and Senator Amy Klobuchar introduced the Water Cyber Shield Act, allocating $300 million per year of State Revolving Funds to water and wastewater cybersecurity. The bill would give the EPA authority to regulate water-sector cyber protections, require risk assessments and corrective actions, and impose incident-reporting obligations aligned with the forthcoming CIRCIA rules β following cyberattacks on at least 30 water systems in about 12 US states attributed by experts to Iran-linked groups.
Energy & Utilities 1 story
Poland Uncovers Second Heat Plant Cyberattack That Went Hidden for Months
CERT Polska revealed at DEF CON that an attack on a Polish combined heat and power plant supplying ~50,000 residents went unrecognised as malicious during last winter, initially blamed on a contractor error. The investigation traced the first known use of a private cellular data network as an ICS pathway: attackers moved from already-compromised wind farm firewalls to a cellular router, then across the private network to a heat plant controller still running factory-default credentials, dwelled 11 days, and disabled Siemens controllers on 29 December before wiping network equipment to destroy forensic evidence β only one legacy router's logs enabled reconstruction. CERT Polska warns the "trusted" private cellular network misconfiguration is believed widespread internationally.
Defence 0 stories
- Russian Military Hackers Pose as Recruiters to Target Ukrainian IT Workers β CERT-UA says Sandworm (APT44/Seashell Blizzard) has run a fake-recruitment campaign since at least May, impersonating recruiters on Ukrainian job sites and using a modified "SopraVPN" app built from WireGuard code to covertly execute commands, targeting system administrators and IT professionals. (The Record, 2026-08-11)
Healthcare 1 story
Data Breaches Announced by Loma Linda University Health & UCLA Health
Two California academic providers disclosed incidents. Loma Linda University Health reported that a dataset containing medical record numbers, dates of birth and limited clinical information from an IRB-approved research study was inadvertently uploaded to an external AI platform (no SSNs or financial data involved; affected count not yet disclosed). UCLA Health notified patients of an improper disclosure to an outside healthcare provider occurring between December 2024 and April 2026, involving names, DOBs, health insurance and clinical referral data, with last-four SSNs for a limited number of individuals; UCLA reported no evidence of misuse. **Breach Triage: Confirmed** β both are first-party disclosures to state regulators.
Legal Services 0 stories
- Two American Law Firms Pay Multi-Million Dollar Ransoms β Risky.Biz reports two US law firms paid multi-million-dollar ransoms in ransomware incidents, the latest in a pattern of legal-sector payouts where firms' sensitive client data makes them high-value targets; the bulletin aired 10 August. (Risky.Biz, 2026-08-10)
Analytics
Source Reliability Index
| Tier | Label | Description |
|---|---|---|
| β Tier 1 | Very High | Official / first-party |
| β Tier 2 | High | Established cyber journalism |
| β Tier 3 | Moderate | General tech/news media |
| β Tier 4 | Low | Social / unverified |