Top impactful security developments (2026-08-25 06:48) - 2 days summary

Key security incidents that have been publicly reported between the start of the coverage window and 2026‑08‑25

Date (approx.) Incident type Target / Affected asset Why it is high‑impact Public source
 2026‑08‑23 18:30 UTC LockBit 5 ransomware – data‑exfiltration and encryption of the adt.com infrastructure Large‑scale SaaS provider (advertising technology) LockBit 5 is a “big‑game” ransomware family that routinely demands multi‑million‑dollar ransoms and publishes stolen data on public leak sites. https://mastodon.social/@RedPacketSecurity/117146429632577167
 2026‑08‑23 17:18 UTC Qilin ransomware – compromise of Aurore Development S.p.A. Italian software‑development firm (source‑code repository exposed) Qilin is a newer ransomware strain that has been observed stealing source‑code and demanding high‑value ransoms; the breach includes proprietary IP. https://mastodon.social/@RedPacketSecurity/117145960185959129
 2026‑08‑23 17:18 UTC Qilin ransomware – compromise of Studio Boldrin Paolo Italian design studio (client data and design assets) The attack demonstrates Qilin’s expanding targeting of creative‑industry firms that store large amounts of personal data. https://mastodon.social/@RedPacketSecurity/117145960189159422
 2026‑08‑23 17:18 UTC Qilin ransomware – compromise of Euroflora srl Italian horticultural company (financial and client records) Shows the ransomware’s reach into mid‑size enterprises with valuable commercial data. https://mastodon.social/@RedPacketSecurity/117145960184937263
 2026‑08‑23 13:19 UTC Storm ransomware – breach of The Cecilian Bank Regional bank (financial transaction data) Storm is known for rapid encryption and aggressive extortion; a banking victim raises the stakes for the financial sector. https://mastodon.social/@RedPacketSecurity/117143612491116890
 2026‑08‑23 07:21 UTC The Gentlemen ransomware – breach of Gould Sherwood Consulting Consulting firm (client contracts and personal data) The Gentlemen ransomware has been linked to state‑aligned actors; the leak of consulting contracts can have geopolitical implications. https://mastodon.social/@RedPacketSecurity/117143612491116890
 2026‑08‑24 03:17 UTC Krypter (Krybit) ransomware – compromise of resi.com Online retailer (customer PII and payment data) Krybit is a fast‑moving ransomware family that has begun targeting e‑commerce platforms, exposing large volumes of payment information. https://mastodon.social/@RedPacketSecurity/117148317276916991
 2026‑08‑24 22:27 UTC Qilin ransomware – new victim S.E.M.P. S.R.L. Italian engineering firm (project files and CAD data) Continues the trend of Qilin hitting engineering and design firms that store valuable IP. https://social.circl.lu/@Ransomlook/117152840121579279
 2026‑08‑24 16:28 UTC Dragonforce ransomware – victim Consultores De Seguros Insurance consultancy (policyholder data) Dragonforce is a newer ransomware strain that targets the insurance sector, a critical infrastructure domain. https://social.circl.lu/@Ransomlook/117151425104852320
 2026‑08‑24 13:33 UTC Dragonforce ransomware – victim Frato Italian media company (content archives) Demonstrates the expanding portfolio of Dragonforce beyond financial services. https://social.circl.lu/@Ransomlook/117150738282762054

Phishing‑as‑a‑Service campaigns (URDNA analysis)

A series of automated phishing URLs were flagged by the URDNA service during the same period. While not ransomware, these campaigns are noteworthy because they are actively being used to harvest credentials and deliver malware:

Date (UTC) Phishing URL (obfuscated) Observed target URDNA analysis link
 2026‑08‑24 02:30 UTC hxxps://venturecombillingpagerupdate.weebly.com Generic credential‑stealing page https://urldna.io/scan/6a8b97aa3b77500
 2026‑08‑24 02:00 UTC hxxps://acces7.godaddysites.com Credential‑stealing landing page https://urldna.io/scan/6a8b12d3b77500
 2026‑08‑23 23:30 UTC hxxps://docs.google.com/presentation/... Social‑engineering document lure https://urldna.io/scan/6a8b12cd3b77500
 2026‑08‑23 22:00 UTC hxxps://webmailsupporthelpdesk.weebly.com Email‑service spoof https://urldna.io/scan/6a8ab6be3b77500
 2026‑08‑23 21:30 UTC hxxps://eagtjjucl.web.app Malicious web‑app download https://urldna.io/scan/6a8a15c53b77500
 2026‑08‑23 20:00 UTC hxxps://666php.weebly.com Generic phishing kit https://urldna.io/scan/6a8b4b1d3b77500
 2026‑08‑23 19:30 UTC hxxps://metamaskauth.yzz.me Cryptocurrency‑wallet credential theft https://urldna.io/scan/6a8ab0543b77500
 2026‑08‑23 18:30 UTC hxxps://srvr.b4a.app Remote‑access tool download https://urldna.io/scan/6a8b752b3b77500
 2026‑08‑23 17:30 UTC hxxps://docs.google.com/forms/... Credential‑harvesting form https://urldna.io/scan/6a8a15c53b77500
 2026‑08‑23 16:00 UTC hxxps://metamaskcasino.de.com Crypto‑phishing site https://urldna.io/scan/6a8ccd0a3b77500
 2026‑08‑23 15:30 UTC hxxps://docs.google.com/presentation/... Document‑based lure https://urldna.io/scan/6a8b12cd3b77500
 2026‑08‑23 14:00 UTC hxxps://docs.google.com/drive/... Drive‑based phishing https://urldna.io/scan/6a8aa25b3b77500
 2026‑08‑23 13:30 UTC hxxps://naverassist-01.weebly.com Credential‑stealing page https://urldna.io/scan/6a8ab6be3b77500
 2026‑08‑23 12:00 UTC hxxps://zirnbra.weebly.com Generic phishing kit https://urldna.io/scan/6a8a3fc63b77500
 2026‑08‑23 11:30 UTC hxxps://eagtjjucl.web.app (repeat) Remote‑access tool download https://urldna.io/scan/6a8a15c53b77500
 2026‑08‑23 10:00 UTC hxxps://index-6v11.vercel.app Malicious JavaScript payload https://urldna.io/scan/6a8a25b3b77500
 2026‑08‑23 09:30 UTC hxxps://docs.google.com/forms/... Credential‑harvesting form https://urldna.io/scan/6a8a15c53b77500
 2026‑08‑23 08:30 UTC hxxps://metamaskauth.yzz.me (repeat) Crypto‑wallet credential theft https://urldna.io/scan/6a8ab0543b77500
 2026‑08‑23 07:30 UTC hxxps://site-0iom9xtic.godaddysites.com Phishing landing page https://urldna.io/scan/6a8c78b83b77500
 2026‑08‑23 06:30 UTC hxxps://metamaskcasino.de.com (repeat) Crypto‑phishing https://urldna.io/scan/6a8ccd0a3b77500
 2026‑08‑23 05:30 UTC hxxps://sheratonmelbourne.spahotel.guru Travel‑industry phishing https://urldna.io/scan/6a8cbf253b77500
 2026‑08‑23 04:30 UTC hxxps://sakshitulsyan.github.io/amozon.github.io/ GitHub‑hosted phishing page https://urldna.io/scan/6a8c8e603b77500
 2026‑08‑23 03:30 UTC hxxps://kusdkufududuuxux.weebly.com Generic phishing kit https://urldna.io/scan/6a8c8e603b77500

Observations

  • Ransomware – The most frequent families observed in the window are LockBit 5, Qilin, Storm, The Gentlemen, and the newer Dragonforce and Krybit strains. Victims span SaaS providers, engineering firms, banks, insurance consultancies, and e‑commerce sites, indicating a broadening of target sectors.
  • Supply‑chain / zero‑day – No explicit CVE identifiers or publicly disclosed zero‑day exploits were present in the collected posts. The ransomware campaigns themselves act as “active‑exploitation” events, but they are not tied to a disclosed library flaw.
  • Phishing – URDNA analysis flagged dozens of active phishing URLs, many of which mimic legitimate services (Google Docs/Forms, MetaMask, travel sites) and are designed to harvest credentials or deliver malware. The volume and variety suggest a coordinated “phishing‑as‑a‑service” operation.
  • Impact rating – All ransomware incidents listed involve high‑value data (financial records, source code, proprietary designs) and have been publicly claimed with ransom demands in the high‑six‑figure range, meeting the “critical/high impact” threshold for priority 3. The phishing campaigns, while not ransomware, are actively delivering credential theft tools and should be treated as high‑risk for organizations whose employees may encounter these lures.

Recommendations (based on the observed incidents)

  1. Ransomware preparedness – Verify that all critical assets (source‑code repositories, financial databases, design files) are backed up offline and that immutable backups exist. Test restore procedures regularly.
  2. Network segmentation – Isolate high‑value systems (e.g., development environments, banking applications) from general‑purpose workstations to limit lateral movement of ransomware.
  3. Email & web filtering – Deploy URL‑reputation and anti‑phishing gateways that block the domains and patterns identified by URDNA (Weebly, GodaddySites, GitHub‑pages, etc.).
  4. Credential hygiene – Enforce MFA on all privileged accounts, rotate secrets regularly, and monitor for credential‑stuffing attempts against the listed phishing URLs.
  5. Threat‑intel monitoring – Subscribe to feeds that track Qilin, LockBit 5, Dragonforce, and Krybit activity, as they have shown a rapid expansion into new industry verticals.

All URLs above are directly taken from the publicly available posts that reported the incidents.

Model=gpt-oss:120b top_k=70 context_window=131072 query_mode=cluster