Article Read Time

1. Federal Agencies Warn Medusa Ransomware Has Now Hit More Than 500 Critical Infrastructure Organizations
The FBI, CISA, and HHS published an updated #StopRansomware advisory on August 18, raising the confirmed Medusa victim count above 500 critical infrastructure organizations, up from roughly 300 in the previous guidance. Investigators note the group has sharply compressed its exploitation timeline, weaponizing newly disclosed vulnerabilities within 24 hours and, in some cases, using exploits before public disclosure. Healthcare remains a favored target, alongside education, legal, insurance, technology, and manufacturing.
Source: CISA URL: https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-071a
2. Threat Actor Claims 3.6 Million Employee Records Pulled From Corporate Azure Tenants
A criminal operating as “TheHatman” spent the week listing large internal employee directories on cybercrime forums, claiming each was extracted directly from a victim organization’s Microsoft Azure tenant. Named organizations include McDonald’s (roughly 1.7 million records), Tata Consultancy Services (around 800,000), Vodafone (about 425,000), HCL, and Kyndryl, with the actor claiming approximately 3.64 million records in total. The access reportedly came from compromised credentials rather than any flaw in Azure itself, and Hudson Rock has tied infostealer infections to several of the affected tenants. TCS has publicly disputed the claim, telling regulators it found no credible evidence of intrusion and that the data appears to be more than four years old.
Source: BleepingComputer URL: https://www.bleepingcomputer.com/news/security/hacker-claims-36-million-azure-account-records-stolen-from-major-companies/
3. “CoSnitch” Copilot Flaw Chain Patched After Eight Months, and the AI Helped Find It
Varonis disclosed CoSnitch (CVE-2026-24301), a chain of three flaws in Microsoft Copilot Personal that allowed one-click, silent data exfiltration from connected apps including Gmail, Drive, Calendar, and OneDrive. The chain combined automatic prompt execution on page load, exfiltration through Copilot’s own URL-fetch function to an attacker webhook, and a persistence trick that wrote attacker instructions into Copilot’s long-term memory. The discovery method drew as much attention as the bug: researchers describe “meta-hacking,” in which Copilot surfaced details of its own architecture and weaknesses during normal use. Microsoft shipped patches on August 18, roughly eight months after the December 2025 report, and Varonis has seen no evidence of exploitation in the wild.
Source: Varonis URL: https://www.varonis.com/blog/cosnitch
4. More Than 14,500 Dahua Surveillance Devices Compromised in Sustained Credential and Auth Bypass Campaign
Researchers tracking a long-running operation against Dahua surveillance hardware reported over 14,530 compromised devices, 1,923 persistent attacker-created accounts, and 283 peer-to-peer compromises. The operator combined credential stuffing, authentication bypass flaws, and abuse of P2P connectivity features to build durable access across exposed devices. Language artifacts recovered from the operator’s working directory point to a Russian-speaking actor, though the activity has not been attributed to any named group or state entity.
Source: The Hacker News URL: https://thehackernews.com/2026/08/hackers-compromised-14500-dahua-devices.html
5. Suspected Russian Operators Abuse Google OAuth and WhatsApp Device Linking to Hijack Accounts
A suspected Russian state-aligned group is running highly targeted phishing operations that abuse legitimate Google OAuth flows and WhatsApp’s device-linking feature to take over accounts without ever capturing a password. The campaigns are deliberately small, often fewer than five recipients at a time, with operators impersonating State Department officials and walking targets through app-password and device-pairing steps. The approach sidesteps many conventional phishing detections precisely because every step uses a real, trusted authentication flow.
Source: The Hacker News URL: https://thehackernews.com/2026/08/suspected-russian-hackers-abuse-google.html
