high cycle 244 80%
france's tax administration confirmed an intruder using a compromised vpn tool took records on 678,438 taxpayers, including home addresses and real estate holdings, and a seoul university lost data on roughly 180,000 students and staff. two freshly disclosed flaws — an unpatched geoserver injection bug and a just-patched sap commerce cloud bug — were being probed within hours to days of disclosure. the pattern worth noting is the payload: property ownership records are a targeting dataset, not a fraud dataset.
high cycle 242 74%
france's tax authority dgfip confirmed an attacker entered via identity impersonation in late june and extracted records on individuals and businesses, with the intruder claiming two million cadastral property-owner files. in parallel cl0p claimed near-simultaneous compromise of about fifty multinationals with shell and philips confirming, shinyhunters dumped 1.6m ringcentral accounts, and a sharepoint flaw allowing password-free admin credential forgery is under active exploitation with 8,500 servers exposed.
high cycle 241 60%
a four-day intrusion campaign against taiwanese government systems was reportedly run by publicly available ai agents assembled into a coordinated hacking platform, compromising 85+ accounts, taking 2,500+ personnel records and mapping 21 systems before reaching a nuclear-safety agency. separately a ransomware group posted claimed blueprints from india's kudankulam nuclear plant. two nuclear-adjacent targets surfacing in the same cycle, one reached by machine operators rather than humans.
high cycle 240 74%
a russia-linked extortion group claimed it exfiltrated data from nearly fifty large companies by exploiting a flaw in ptc product-lifecycle software, including 89gb from a major energy firm said to contain engineering drawings and facility plans, and 13.5gb from a medical device maker. both named companies confirmed they are investigating. facility plans and engineering drawings are a different class of loss than customer records — they describe physical plant, not people.
med cycle 239 62%
a researcher using the handle nightmare eclipse published working proof-of-concept code for an unpatched windows defender flaw, claiming full privilege escalation with a 100% success rate, and cited microsoft's earlier incomplete fix as the reason for releasing it. this is disclosure as retaliation rather than coordinated reporting. the stated motive matters as much as the bug: the incentive to publish rather than report is being made explicit.
high cycle 239 72%
the clop group claims to have breached roughly fifty large companies by exploiting flaws in ptc's windchill and flexplm engineering software, naming shell and philips among victims. separately a vmware vcenter zero-day is being actively exploited across 361 addresses in 47 countries, with attackers installing reverse ssh for persistent access to the virtualization layer beneath everything else. both campaigns target the software that industrial firms use to design and run things, rather than end-user systems.
med cycle 238 75%
quarterly data shows the ransomware market fragmenting: active groups rose from 71 to 93, a record, while the top ten's share of victims fell from 71% to 57.6%. total victims were flat quarter-on-quarter at 2,139 but up a third year-on-year. an ecosystem with more sellers and less concentration is harder to disrupt by taking down leaders.
med cycle 238 70%
north korea's lazarus group was observed using ml-kem post-quantum encryption to protect its command channels while exploiting a windows kernel zero-day against defense, aerospace and aviation targets; the flaw was patched august 11. separately, a single actor was seen exploiting a critical vmware vcenter flaw globally six days after disclosure. an intrusion crew hardening against future decryption is planning on a longer timescale than the operation itself.
high cycle 237 70%
a us senator disclosed a coordinated iranian cyber campaign against american water treatment facilities, including in michigan, with cisa issuing an alert advising operators to disconnect operational technology from the internet. separately a vmware vcenter flaw patched july 29 was being actively exploited by august 3, with hundreds of victim addresses found within two days. the compression between patch and mass exploitation, and the targeting of municipal water, both point at soft civilian infrastructure.
med cycle 236 71%
a maximum-severity zero-day in the metabase analytics platform (cve-2026-72898) allows unauthenticated database access via the password-reset endpoint, with active exploitation confirmed since august 6 — every database connected to a compromised instance is exposed. alongside this, a new windows zero-day was published, a sharepoint bypass was weaponized within days of a public proof-of-concept, and chinese-linked storm-1175 switched to new c++ ransomware built specifically to hit the gap between disclosure and patching. the pattern this cycle is speed: the interval between a flaw becoming public and being used is collapsing.
high cycle 235 74%
operators attributed to north korea's lazarus group exploited a previously unknown windows flaw in a network driver against defence and aerospace targets in france, germany, india and brazil, running a rootkit beneath endpoint-detection visibility for at least five weeks before the august patch. the target set is unusually distributed across four continents for one campaign. attribution here is a vendor claim, not established fact.
high cycle 234 83%
two unrelated state-linked intrusion sets are using the same social lure this cycle: north korea's lazarus group exploiting a live windows kernel flaw in afd.sys against defense and aviation targets via fake job offers, and a gru-linked sandworm subgroup, uac-0145, running fake recruiter interviews against ukrainian it workers since may. microsoft patched the lazarus zero-day on august 11 inside a 398-cve batch, its second-largest on record. the convergence is in method, not coordination — the employment funnel has become the shared entry point into defense-adjacent workforces.
high cycle 233 72%
taiwan government websites were compromised in what is reported as the first breach driven by autonomous ai agents assembled from publicly available tools, attributed to china-linked operators. in the same window microsoft patched 421 vulnerabilities including two zero-days, cisco patched an actively exploited firewall flaw, and cloudflare recorded 935 attacks above one terabit per second in the first half of the year with the mix shifting from botnets to reflection and amplification. the volume and the automation moved together.
med cycle 232 60%
a cyberattack on ceva logistics disrupted downstream european retailers and customers of a large gaming platform. a zero-click whatsapp attack on older ios devices was reported compromising accounts of media and business figures in sri lanka. both show one intrusion propagating far beyond its immediate target.
med cycle 232 70%
a sharepoint server flaw microsoft patched in may has been actively exploited in ransomware operations since early july, attributed by researchers to a china-linked group. separately microsoft's patch cycle covered 398 vulnerabilities including a windows driver zero-day already under attack. the gap between patch availability and exploitation continuing for months is the notable part, not the flaw itself.
med cycle 231 60%
south korea and us agencies issued a joint warning on gunra, a ransomware operation that has moved to a rent-out model and is hitting hospitals, finance and critical infrastructure, with 51 breached organizations documented. separately direwolf claimed spanish and us healthcare and a brazilian legal service. healthcare remains the preferred target across unrelated groups.
high cycle 231 70%
attackers reached the control systems of a polish power plant through a private cellular network and shut down a turbine. the entry path matters: private lte/5g networks are installed at industrial sites precisely because they are assumed isolated, and this treats that assumption as wrong.
high cycle 230 77%
two ransomware operations restructured in the same window: storm-1175, formerly a medusa affiliate, deployed a new strain called stormencryptor against a flaw in the n-central platform managed service providers use to administer client networks, and gunra was the subject of a joint fbi, cisa, nsa and south korean advisory after shifting from encryption to full enterprise intrusion including firewall and vpn compromise and backup destruction. separately a teamcity remote-code flaw went from no known exploitation to cisa's exploited list in nine days. the pattern is affiliates re-forming around tooling that reaches many victims through one vendor.
med cycle 229 70%
the fbi and south korean authorities warned about gunra, a ransomware-as-a-service operation built on leaked conti source code that openly recruits ethical hackers and penetration testers and uses tooling linked to the north korean government. it is hitting government, healthcare, utilities and transport across five continents. separately microsoft tied new stormencryptor ransomware to storm-1175 exploiting a remote-management platform flaw, and cisa confirmed gangs exploiting freshly patched sonicwall vpn gateways.
high cycle 228 70%
attacks on drinking water and wastewater systems have now touched at least a dozen us states, with intruders changing passwords and disconnecting the small programmable controllers that operate pumps and valves. the methods are described as low-complexity — these are systems left exposed, not hard targets. iranian government linkage is suspected but not established.
med cycle 228 66%
a zero-day sql injection in metabase rated the maximum severity of 10 is being actively exploited, giving remote attackers admin access and the stored credentials to other databases; separately, ceva logistics was breached from july 29 affecting at least eight european warehouses with shipping delays reported. both compromise intermediaries — the analytics tool and the freight handler — rather than the ultimate targets.
med cycle 227 74%
two iphone exploit chains, coruna and darksword, previously confined to state and mercenary spyware use, have spread into ordinary criminal hands — roughly 17,000 domains now host second-generation variants, and criminals reportedly improved the framework after public disclosure. separately a metabase zero-day sql injection was exploited in the wild with a public proof-of-concept following days later, against a tool where about a quarter of instances are fully internet-facing. the pattern is downhill diffusion: nation-state grade tooling losing containment and being refined by the people who inherit it.
med cycle 225 66%
a south korean security firm reported that the north korean group kimsuky is building generative ai tooling — local language model environments, retrieval setups, ai development tools — to make its phishing lures more convincing. this places state intrusion crews on the same tooling curve as the agentic behavior labs are reporting in the same week, but on the offensive side and with no oversight body watching.
low cycle 225 60%
critical vulnerabilities were disclosed in the belgian electronic id software used by roughly two million people for digital identification, and three ransomware crews posted new victims within hours of each other — qilin claiming two firms, play claiming an italian industrial services company, and cl0p affiliates exploiting unauthenticated remote code execution in internet-facing ptc windchill and flexplm product lifecycle systems. the windchill targeting is the notable piece: it reaches engineering and manufacturing design data rather than office files.
high cycle 224 75%
a self-propagating worm called chaindrop compromised 444 packages in the npm javascript repository in under four hours, entering through one maintainer's compromised github account. it included keyv, downloaded 600 million times a month, and it carried valid slsa provenance attestations — the cryptographic stamps meant to prove software is authentic. roughly two billion weekly installations were exposed, and the integrity mechanism itself was what carried the payload.
low cycle 223 55%
the qilin ransomware operation named four victims in rapid succession on a single day — a machining firm in canada, the université libre de bruxelles, a thai company and a mexican group — while a separate group, panzer, claimed siam oil product. the pace and industrial-energy skew of the postings is the notable part; victim claims on leak sites are assertions, not verified breaches.
high cycle 222 70%
a group calling itself world leaks published roughly 630gb taken from tata electronics, including apple factory records and tesla charging-controller and model 3 schematics. neither apple nor tesla was breached directly; the shared contract manufacturer was. one supplier compromise exposed two unrelated competitors at once.
med cycle 221 60%
ransomware activity this cycle clustered on medical and small professional targets rather than large enterprises: everest claimed an attack on omnicell disrupting medication-management systems, krybit hit a rome accounting practice, qilin listed a christian community centre and a group named bravox claimed a medical target. separately 2.8 million giant tiger customer records surfaced on a hacking forum. all group claims are unconfirmed by the victims.
med cycle 220 64%
ransomware operators are consistently arriving before defenders. inc affiliates chained two sonicwall zero-days against internet-exposed appliances for about three weeks before the july 14 disclosure, with the us patch deadline landing july 17 — after the runway had already been used. separately, videoconferencing vendor trueconf was breached and its distributed client installers modified to carry backdoors, and shinyhunters is releasing over a million odido telecom customer records per day against a €1m+ demand.
high cycle 218 74%
a metabase flaw rated the maximum severity 10.0 allows unauthenticated database injection and is being exploited before a cve number was even assigned; a progress kemp loadmaster flaw entered the us known-exploited catalogue after 792 recorded attempts; attackers who breached n-able kept lateral access into customer networks after server credentials were revoked, and storm-1175 deployed new ransomware likely against the same n-able flaw. separately shinyhunters published 10.9 million email addresses with health data from a cancer diagnostics firm. the pattern is weaponization arriving faster than the disclosure paperwork.