Threat Intelligence RoundUp: August

September 01, 2026

Our analyst team shares a few articles each week in our email newsletter which goes every Thursday. Make sure to register! This blog highlights those articles in order of what was the most popular in our newsletter – what our readers found the most intriguing. Stay tuned for a recap every month. We hope sharing these resources and news articles emphasizes the importance of cybersecurity and sheds light on the latest in threat intelligence.

1. CISA: Medusa ransomware hit over 500 critical infrastructure orgs – Bleeping Computer

The Cybersecurity and Infrastructure Security Agency (CISA), in coordination with the Department of Health and Human Services (HHS) and the Federal Bureau of Investigation (FBI), announced Tuesday that the Medusa ransomware group has breached more than 500 critical infrastructure organizations in the United States since June 2021. As of April 2026, the victims span multiple sectors, including Healthcare and Public Health, Defense Industrial Base, Critical Manufacturing, Government Services and Facilities, Information Technology, and Financial Services. Other affected organizations include those in the medical, education, legal, insurance, technology, and manufacturing industries. The updated figures represent an increase from a March 2025 joint advisory, which estimated that Medusa had impacted more than 300 critical infrastructure organizations.

The Medusa ransomware operation first emerged in January 2021, but its activity increased significantly in 2023 after the group launched the Medusa Blog leak site. The group began using stolen data as an additional form of leverage, threatening to publish sensitive information to pressure victims into paying ransoms. Medusa initially operated as a closed ransomware group but later evolved into a ransomware-as-a-service (RaaS) operation. Under this model, the group adopted an affiliate-based approach, allowing outside cybercriminals to carry out attacks using Medusa’s ransomware infrastructure. Read full article.

2. Sandworm hackers target IT pros with trojanized WireGuard VPN client – Bleeping Computer

Hackers linked to the Russian threat group Sandworm have been targeting IT professionals with fake job offers, according to the Ukrainian Computer Emergency Response Team (CERT-UA). The UAC-1045 campaign impersonated IT companies and recruiters, moving conversations to Telegram before sending victims fake technical assignments requiring access to a supposed corporate VPN. Attackers provided WireGuard configurations that triggered a fake error, then directed victims to download a modified client called “SopraVPN” from SourceForge. On Windows, the malware creates a scheduled task and downloads another payload; on Linux, it uses cURL to retrieve an executable from attacker-controlled infrastructure. Read More.

The North Carolina Ports Authority has confirmed that cyberattacks on three of its facilities disrupted IT systems and slowed operations. The attack was detected on August 4 and resulted in a system-wide outage, forcing gates at all three facilities to open at 8 a.m. on August 5 and causing delays for port operations and truckers. The affected facilities are the Port of Wilmington, Port of Morehead City, and Charlotte Inland Port, which together comprise the North Carolina Ports system’s two principal commercial deepwater seaports and an inland hub. The authority has not attributed the attack to a known threat actor and has not disclosed whether any sensitive data was compromised. Read more here.

Four cybercriminals have been arrested in Brazil, while three others have been charged in Europe over allegations that they exploited a vulnerability at a service provider to withdraw funds from Commerzbank customers’ accounts. The theft, investigated jointly by Brazilian and German federal police, took place over four days in November 2023 and resulted in losses of approximately €30 million. Commerzbank, one of Europe’s major financial institutions, generates more than €11.1 billion annual revenue. German authorities claim the hackers exploited a software vulnerability caused by a faulty update to the payment and transaction-processing system of a financial institution. The attackers used the vulnerability to initiate numerous unauthorized withdrawals from German online banking accounts. The stolen funds were then transferred to Brazil through an extensive network of accounts and transactions intended to obscure their origin. Authorities stated most of the money was withdrawn in Brazil, while smaller amounts were cashed out in four European countries. Read here.

5. ExfilSquad hackers leak info of over 100,000 UK police officers, staff – Bleeping Computer

On July 26, the U.K.’s Police National Legal Database (PNLD) was compromised, exposing the contact information of more than 100,000 police officers and criminal justice professionals. The data extortion group ExfilSquad claimed responsibility for the breach, having previously taken credit for the attack on Analog Devices. The incident is under investigation with support from cybersecurity experts and the National Crime Agency (NCA). At this time, investigators have found no evidence that passwords or other security credentials were compromised. Learn more.

6. Homeland Security Task Force (HSTF) investigation leads to dismantling of dark web drug trafficking organization – DOJ

A multinational law enforcement investigation has dismantled the “Undertaker45” dark web drug trafficking organization, which operated from 2017 to 2023. The group used several dark web marketplaces and encrypted messaging platforms to sell counterfeit OxyContin pills containing fentanyl and counterfeit Adderall pills containing methamphetamine. Led from Medellín, Colombia, the organization relied on U.S.-based members in Florida and North Carolina to receive and distribute the drugs across the country. The organization sold approximately 40 kilograms of methamphetamine and fentanyl pills and laundered about $2.5 million in proceeds, primarily through cryptocurrency. Read full article.

7. Hackers disrupt over 30 Minnesota water utilities in coordinated OT attack – Bleeping Computer

Minnesota IT Services (MNIT) activated its cybersecurity incident response capabilities following a targeted cyberattack affecting 30 community water service systems. The attack disrupted operational technology (OT), with multiple water treatment plants experiencing system outages for initially unknown reasons. Authorities later confirmed that “crews identified that the water plant outage was the result of a malicious cyberattack targeting computerized operating systems by unknown actors.”. In guidance published yesterday, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) advised critical infrastructure organizations to isolate key OT systems where possible to help ensure the continuity of essential services in the event of a cyberattack. Read full article.

8. New AmnesiaStealer macOS malware hijacks browser sessions via remote control – Bleeping Computer

A new information-stealing malware, AmnesiaStealer, is targeting macOS users through ClickFix campaigns. The malware can copy Chromium browser profiles, including active authentication sessions, and load them into a hidden browser, potentially allowing attackers to access victims’ accounts without needing their passwords or MFA codes. It can also steal passwords, cryptocurrency wallets, Apple Notes and documents, Keychain data, and other sensitive information from 16 Chromium-based browsers. Current campaigns use fake GitHub download pages to trick victims into downloading a password-protected ZIP archive. AmnesiaStealer’s stream_module can clone profiles from seven Chromium-based browsers, including Chrome, Edge, Vivaldi, Arc, Opera, Brave, and Chromium. It launches the legitimate browser in hidden, headless mode with weakened security settings, then copies the victim’s profile and stores the stolen data. Learn more.


Make sure to register for our weekly newsletter to get access to what our analysts are reading on a weekly basis.

See why DarkOwl is the Leader in Darknet Data

Copyright © 2026 DarkOwl, LLC All rights reserved.
Privacy Policy
DarkOwl is a Denver-based company that provides the world’s largest index of darknet content and the tools to efficiently find leaked or otherwise compromised sensitive data. We shorten the timeframe to detection of compromised data on the darknet, empowering organizations to swiftly detect security gaps and mitigate damage prior to misuse of their data.