DEV Community

NetSecOpsIO
NetSecOpsIO

Posted on • Originally published at cyber.netsecops.io

Daily Cybersecurity Intelligence - August 11, 2026

Daily cybersecurity intelligence digest from CyberNetSec.io - August 11, 2026


📊 14 threat intelligence reports covering vulnerabilities, exploits, threat actors, and security advisories.


1. Lazarus Group Uses Windows Zero-Day CVE-2026-68820 for SYSTEM-Level Access

The North Korean state-sponsored Lazarus Group is actively exploiting a zero-day privilege escalation vulnerability (CVE-2026-68820) in a core Windows driver. The flaw, patched in Microsoft's August 2026 Patch Tuesday, is being used in the 'Operation Dream Job' campaign to deploy a rootkit and target defense and aerospace organizations. Attackers gain SYSTEM privileges to disable security software and conduct espionage.

📖 Read full report →


2. CISA Issues Alert on Gunra Ransomware Targeting Global Sectors

A joint advisory from CISA, FBI, NSA, and South Korean authorities warns of the Gunra Ransomware-as-a-Service (RaaS). Derived from leaked Conti source code, the group uses double extortion tactics, targeting critical infrastructure sectors like healthcare and government worldwide. The advisory details TTPs, including exploitation of known vulnerabilities and default credentials, and provides mitigation guidance.

📖 Read full report →


3. Storm-1175 Actor Uses New StormEncryptor Ransomware via N-able Flaw

The China-linked threat actor Storm-1175, formerly a Medusa ransomware affiliate, is now using a new custom ransomware called StormEncryptor. Microsoft reports the group is likely exploiting an N-able N-central RMM vulnerability (CVE-2026-18577) for initial access. The actor is known for rapid weaponization of new flaws, moving from compromise to encryption within days.

📖 Read full report →


4. Hackers Disrupt US Water Systems by Targeting Rockwell Automation PLCs

An ongoing cyber campaign linked to Iranian hackers is targeting U.S. water and wastewater facilities by exploiting internet-exposed Rockwell Automation PLCs. According to an FBI and EPA advisory, attackers are locking operators out of systems, causing operational disruptions like pressure loss and flooding in at least a dozen states. The campaign highlights the persistent risk of insecure ICS/OT devices.

📖 Read full report →


5. LiteLLM Supply Chain Attack Harvests Credentials from 2,500 Firms

A major supply chain attack targeting the open-source AI framework LiteLLM has exposed over 2,500 companies and 434,000 CI/CD pipelines. The threat actor, Team PCP, published malicious versions of the popular Python package on PyPI to harvest cloud credentials, API keys, and other secrets from AI development environments. The incident is considered the largest AI infrastructure breach of 2026.

📖 Read full report →


6. DentaQuest Notifies 15 Million Patients of Massive Data Breach

DentaQuest, a major U.S. dental benefits administrator, has disclosed a data breach affecting 15 million individuals, making it the largest healthcare breach of 2026. The data extortion group ShinyHunters claimed responsibility, leaking a 234 GB data archive after ransom negotiations failed. The exposed data includes names, Social Security numbers, and detailed medical and insurance information.

📖 Read full report →


7. Unlimited Systems Data Breach Affects 3.8 Million Patients

Unlimited Systems, a medical billing vendor, is notifying 3.8 million patients of a data breach stemming from an October 2025 ransomware attack. The nine-month delay in notification has led to a class-action lawsuit. The breach exposed sensitive patient data, including names, SSNs, and diagnosis information, affecting patients from 4,500 medical offices and highlighting healthcare supply chain risks.

📖 Read full report →


8. Hackers Use Private APN to Pivot into Polish Power Plant's OT Network

Poland's CERT has detailed a novel cyberattack where intruders breached a power plant's industrial network by pivoting through a private cellular network (APN). The attack, attributed to a Russian state-sponsored group, originated at a compromised wind farm and moved through the shared APN to the power plant, where attackers used default credentials on a PLC to shut down a steam turbine.

📖 Read full report →


9. Homebuilder Lennar Corp. Breach Exposes SSNs via Social Engineering

Lennar Corp., a leading U.S. homebuilder, is notifying an undisclosed number of individuals about a data breach that occurred in March 2026. Attackers used 'sophisticated social engineering tactics' to gain access to company systems and exfiltrate sensitive personal data, including names, Social Security numbers, and financial account information. The company discovered the breach in March but only began notifying victims in August.

📖 Read full report →


10. RovoBlast Prompt Injection Flaw in Atlassian Rovo AI Disclosed

Researchers have disclosed 'RovoBlast,' a critical one-click prompt injection vulnerability in Atlassian's Rovo AI assistant. By crafting a malicious link, an attacker could inject hidden commands into a user's AI session, compelling the AI to search for sensitive data in connected apps like Jira and Confluence and exfiltrate it to an external server. Atlassian has since patched the flaw.

📖 Read full report →


11. Coinkite Coldcard Firmware Flaw Enables $100M+ Bitcoin Heist

A five-year-old firmware vulnerability in Coinkite's popular Coldcard hardware wallets has been exploited by multiple hacking groups, leading to the theft of an estimated $100-130 million in Bitcoin. A build error caused the devices to use a weak random number generator, allowing attackers to guess private keys and drain wallets without physical access. Coinkite has issued an emergency patch and urges users to migrate funds.

📖 Read full report →


12. Oculus Pathology Discloses Patient Data Breach from Email Compromise

Oculus Pathology, a Texas-based diagnostic services provider, has disclosed a data breach resulting from unauthorized access to employee email accounts in April 2026. The incident potentially exposed a wide range of patient PII and protected health information (PHI), including Social Security numbers, medical diagnoses, and insurance details. The full scope and number of affected individuals are still under investigation.

📖 Read full report →


13. Kimwolf v7 Botnet Analysis: HTTP/2 DDoS & ENS C2

A new variant of the Kimwolf botnet, version 7, has been identified targeting Android-based IoT devices like TV boxes. This evolution introduces significant upgrades, including a sophisticated HTTP/2-based DDoS flood that mimics legitimate browser traffic, making it harder to mitigate. For command and control (C2), Kimwolf v7 implements a resilient, multi-layered system that leverages the Ethereum Name Service (ENS) to resolve C2 domains via public RPC endpoints. As a fallback, it uses a hard-coded Tor .onion address, demonstrating a direct response to previous C2 takedown efforts and increasing its operational durability.

📖 Read full report →


14. Aeternum Botnet Loader Leverages Polygon Smart Contracts

A C++ botnet loader named Aeternum is leveraging the public Polygon blockchain for its command-and-control (C2) infrastructure, creating a highly resilient and decentralized threat. Infected devices query public Remote Procedure Call (RPC) endpoints to retrieve commands stored on-chain in smart contracts. This method makes C2 takedowns extremely difficult. The loader also employs anti-evasion techniques, including VM detection. Analysis of the loader reveals a flawed encryption scheme for C2 payloads and its ability to download and execute secondary malware, such as the XMRig cryptominer.

📖 Read full report →


📌 Subscribe to daily updates at CyberNetSec.io

All reports include detailed analysis, IOCs, mitigation strategies, and references.

Top comments (0)