← All threat briefs

Cybersecurity Brief — 2026-08-11

SECURITY // 2026-08-11

Cybersecurity Brief — 2026-08-11

Threat Activity

  • Gunra ransomware exploits Fortinet and Schneider Electric flaws for initial access. CISA and South Korean intelligence warned that Gunra (a Conti-derived RaaS operating since April 2025) is targeting critical infrastructure worldwide—healthcare, financial services, government, and professional services. Affiliates leverage CVE-2024-5559 (Schneider Electric PowerLogic P5) and CVE-2025-24472 (Fortinet FortiOS/FortiProxy) for initial access, then deploy double-extortion ransomware (Salsa20/ChaCha20 encryption, data leak site). The group also uses phishing, Impacket tools for lateral movement/credential dumping, and operates primarily 22:00–06:00 local time. 51 victims listed since April 2025, concentrated in South Korea, Brazil, Spain, Thailand, and Hong Kong. (Source: The Hacker News, CISA Advisory AA26-222A)

  • Attackers breach Polish CHP plant via private cellular network (APN), shut down turbine. CERT Polska disclosed a December 2025 intrusion at a combined heat-and-power plant serving ~50,000 residents. Attackers entered through a private APN managed by the grid operator, pivoting from a compromised wind-farm network (FortiGate VPN without MFA) through a Teltonika RUTX50 router to a WAGO PFC200 controller with default admin credentials, then to Siemens PLCs via S7 protocol. On Dec 29, they switched PLCs to STOP mode, shutting down the steam turbine and process-water treatment. Recovery began at 07:30 while attackers were still active; no heat/electricity loss to customers. CERT calls this the first observed real-world attack via private APN and recommends APN client isolation, treating APN as untrusted from OT side, and removing default credentials. (Source: The Hacker News)

  • Canadian threat actor Connor Riley Moucka ("Judische"/"Waifu") pleads guilty in Snowflake extortion campaign. Moucka, 26, of Kitchener, Ontario, admitted to computer fraud and conspiracy targeting 165+ organizations via stolen Snowflake credentials (accounts lacking MFA) between Feb–Oct 2024. Victims included TicketMaster, LendingTree, Advance Auto Parts, Neiman Marcus. Also admitted to stealing call/text records of 100M+ AT&T customers. Co-conspirators include U.S. Army soldier Cameron Wagenius ("Kiberphant0m," pleaded guilty July 2025) and John Erin Binns ("IRDev"/"IntelSecrets," linked to 2021 T-Mobile breach, reportedly in Turkey). The group collected $2.5M+ in ransoms and engaged in re-extortion, including targeting government officials' families. (Source: Krebs on Security)

Vulnerabilities & Advisories

  • CISA adds Gunra ransomware to #StopRansomware advisory series (AA26-222A, released Aug 10, 2026). Provides IOCs (STIX XML/JSON), detection guidance (Sigma/YARA), and mitigation priorities: patch internet-facing VPN/RDP, enforce MFA, implement offline immutable backups, segment networks to limit lateral movement. (Source: CISA)

Other Notable Items

  • AI-generated vulnerability reports flooding security teams. SANS researcher Stephen Sims warns that unproven AI findings are creating triage burden without actionable signal. (Source: The Hacker News)

Brief compiled from The Hacker News, Krebs on Security, and CISA advisories published August 10–11, 2026. All times approximate.