Top impactful security developments (2026-08-25 06:48) - 2 days summary
Key security incidents that have been publicly reported between the start of the coverage window and 2026‑08‑25
| Date (approx.) | Incident type | Target / Affected asset | Why it is high‑impact | Public source |
|---|---|---|---|---|
| 2026‑08‑23 18:30 UTC | LockBit 5 ransomware – data‑exfiltration and encryption of the adt.com infrastructure | Large‑scale SaaS provider (advertising technology) | LockBit 5 is a “big‑game” ransomware family that routinely demands multi‑million‑dollar ransoms and publishes stolen data on public leak sites. | https://mastodon.social/@RedPacketSecurity/117146429632577167 |
| 2026‑08‑23 17:18 UTC | Qilin ransomware – compromise of Aurore Development S.p.A. | Italian software‑development firm (source‑code repository exposed) | Qilin is a newer ransomware strain that has been observed stealing source‑code and demanding high‑value ransoms; the breach includes proprietary IP. | https://mastodon.social/@RedPacketSecurity/117145960185959129 |
| 2026‑08‑23 17:18 UTC | Qilin ransomware – compromise of Studio Boldrin Paolo | Italian design studio (client data and design assets) | The attack demonstrates Qilin’s expanding targeting of creative‑industry firms that store large amounts of personal data. | https://mastodon.social/@RedPacketSecurity/117145960189159422 |
| 2026‑08‑23 17:18 UTC | Qilin ransomware – compromise of Euroflora srl | Italian horticultural company (financial and client records) | Shows the ransomware’s reach into mid‑size enterprises with valuable commercial data. | https://mastodon.social/@RedPacketSecurity/117145960184937263 |
| 2026‑08‑23 13:19 UTC | Storm ransomware – breach of The Cecilian Bank | Regional bank (financial transaction data) | Storm is known for rapid encryption and aggressive extortion; a banking victim raises the stakes for the financial sector. | https://mastodon.social/@RedPacketSecurity/117143612491116890 |
| 2026‑08‑23 07:21 UTC | The Gentlemen ransomware – breach of Gould Sherwood Consulting | Consulting firm (client contracts and personal data) | The Gentlemen ransomware has been linked to state‑aligned actors; the leak of consulting contracts can have geopolitical implications. | https://mastodon.social/@RedPacketSecurity/117143612491116890 |
| 2026‑08‑24 03:17 UTC | Krypter (Krybit) ransomware – compromise of resi.com | Online retailer (customer PII and payment data) | Krybit is a fast‑moving ransomware family that has begun targeting e‑commerce platforms, exposing large volumes of payment information. | https://mastodon.social/@RedPacketSecurity/117148317276916991 |
| 2026‑08‑24 22:27 UTC | Qilin ransomware – new victim S.E.M.P. S.R.L. | Italian engineering firm (project files and CAD data) | Continues the trend of Qilin hitting engineering and design firms that store valuable IP. | https://social.circl.lu/@Ransomlook/117152840121579279 |
| 2026‑08‑24 16:28 UTC | Dragonforce ransomware – victim Consultores De Seguros | Insurance consultancy (policyholder data) | Dragonforce is a newer ransomware strain that targets the insurance sector, a critical infrastructure domain. | https://social.circl.lu/@Ransomlook/117151425104852320 |
| 2026‑08‑24 13:33 UTC | Dragonforce ransomware – victim Frato | Italian media company (content archives) | Demonstrates the expanding portfolio of Dragonforce beyond financial services. | https://social.circl.lu/@Ransomlook/117150738282762054 |
Phishing‑as‑a‑Service campaigns (URDNA analysis)
A series of automated phishing URLs were flagged by the URDNA service during the same period. While not ransomware, these campaigns are noteworthy because they are actively being used to harvest credentials and deliver malware:
| Date (UTC) | Phishing URL (obfuscated) | Observed target | URDNA analysis link |
|---|---|---|---|
| 2026‑08‑24 02:30 UTC | hxxps://venturecombillingpagerupdate.weebly.com |
Generic credential‑stealing page | https://urldna.io/scan/6a8b97aa3b77500 |
| 2026‑08‑24 02:00 UTC | hxxps://acces7.godaddysites.com |
Credential‑stealing landing page | https://urldna.io/scan/6a8b12d3b77500 |
| 2026‑08‑23 23:30 UTC | hxxps://docs.google.com/presentation/... |
Social‑engineering document lure | https://urldna.io/scan/6a8b12cd3b77500 |
| 2026‑08‑23 22:00 UTC | hxxps://webmailsupporthelpdesk.weebly.com |
Email‑service spoof | https://urldna.io/scan/6a8ab6be3b77500 |
| 2026‑08‑23 21:30 UTC | hxxps://eagtjjucl.web.app |
Malicious web‑app download | https://urldna.io/scan/6a8a15c53b77500 |
| 2026‑08‑23 20:00 UTC | hxxps://666php.weebly.com |
Generic phishing kit | https://urldna.io/scan/6a8b4b1d3b77500 |
| 2026‑08‑23 19:30 UTC | hxxps://metamaskauth.yzz.me |
Cryptocurrency‑wallet credential theft | https://urldna.io/scan/6a8ab0543b77500 |
| 2026‑08‑23 18:30 UTC | hxxps://srvr.b4a.app |
Remote‑access tool download | https://urldna.io/scan/6a8b752b3b77500 |
| 2026‑08‑23 17:30 UTC | hxxps://docs.google.com/forms/... |
Credential‑harvesting form | https://urldna.io/scan/6a8a15c53b77500 |
| 2026‑08‑23 16:00 UTC | hxxps://metamaskcasino.de.com |
Crypto‑phishing site | https://urldna.io/scan/6a8ccd0a3b77500 |
| 2026‑08‑23 15:30 UTC | hxxps://docs.google.com/presentation/... |
Document‑based lure | https://urldna.io/scan/6a8b12cd3b77500 |
| 2026‑08‑23 14:00 UTC | hxxps://docs.google.com/drive/... |
Drive‑based phishing | https://urldna.io/scan/6a8aa25b3b77500 |
| 2026‑08‑23 13:30 UTC | hxxps://naverassist-01.weebly.com |
Credential‑stealing page | https://urldna.io/scan/6a8ab6be3b77500 |
| 2026‑08‑23 12:00 UTC | hxxps://zirnbra.weebly.com |
Generic phishing kit | https://urldna.io/scan/6a8a3fc63b77500 |
| 2026‑08‑23 11:30 UTC | hxxps://eagtjjucl.web.app (repeat) |
Remote‑access tool download | https://urldna.io/scan/6a8a15c53b77500 |
| 2026‑08‑23 10:00 UTC | hxxps://index-6v11.vercel.app |
Malicious JavaScript payload | https://urldna.io/scan/6a8a25b3b77500 |
| 2026‑08‑23 09:30 UTC | hxxps://docs.google.com/forms/... |
Credential‑harvesting form | https://urldna.io/scan/6a8a15c53b77500 |
| 2026‑08‑23 08:30 UTC | hxxps://metamaskauth.yzz.me (repeat) |
Crypto‑wallet credential theft | https://urldna.io/scan/6a8ab0543b77500 |
| 2026‑08‑23 07:30 UTC | hxxps://site-0iom9xtic.godaddysites.com |
Phishing landing page | https://urldna.io/scan/6a8c78b83b77500 |
| 2026‑08‑23 06:30 UTC | hxxps://metamaskcasino.de.com (repeat) |
Crypto‑phishing | https://urldna.io/scan/6a8ccd0a3b77500 |
| 2026‑08‑23 05:30 UTC | hxxps://sheratonmelbourne.spahotel.guru |
Travel‑industry phishing | https://urldna.io/scan/6a8cbf253b77500 |
| 2026‑08‑23 04:30 UTC | hxxps://sakshitulsyan.github.io/amozon.github.io/ |
GitHub‑hosted phishing page | https://urldna.io/scan/6a8c8e603b77500 |
| 2026‑08‑23 03:30 UTC | hxxps://kusdkufududuuxux.weebly.com |
Generic phishing kit | https://urldna.io/scan/6a8c8e603b77500 |
Observations
- Ransomware – The most frequent families observed in the window are LockBit 5, Qilin, Storm, The Gentlemen, and the newer Dragonforce and Krybit strains. Victims span SaaS providers, engineering firms, banks, insurance consultancies, and e‑commerce sites, indicating a broadening of target sectors.
- Supply‑chain / zero‑day – No explicit CVE identifiers or publicly disclosed zero‑day exploits were present in the collected posts. The ransomware campaigns themselves act as “active‑exploitation” events, but they are not tied to a disclosed library flaw.
- Phishing – URDNA analysis flagged dozens of active phishing URLs, many of which mimic legitimate services (Google Docs/Forms, MetaMask, travel sites) and are designed to harvest credentials or deliver malware. The volume and variety suggest a coordinated “phishing‑as‑a‑service” operation.
- Impact rating – All ransomware incidents listed involve high‑value data (financial records, source code, proprietary designs) and have been publicly claimed with ransom demands in the high‑six‑figure range, meeting the “critical/high impact” threshold for priority 3. The phishing campaigns, while not ransomware, are actively delivering credential theft tools and should be treated as high‑risk for organizations whose employees may encounter these lures.
Recommendations (based on the observed incidents)
- Ransomware preparedness – Verify that all critical assets (source‑code repositories, financial databases, design files) are backed up offline and that immutable backups exist. Test restore procedures regularly.
- Network segmentation – Isolate high‑value systems (e.g., development environments, banking applications) from general‑purpose workstations to limit lateral movement of ransomware.
- Email & web filtering – Deploy URL‑reputation and anti‑phishing gateways that block the domains and patterns identified by URDNA (Weebly, GodaddySites, GitHub‑pages, etc.).
- Credential hygiene – Enforce MFA on all privileged accounts, rotate secrets regularly, and monitor for credential‑stuffing attempts against the listed phishing URLs.
- Threat‑intel monitoring – Subscribe to feeds that track Qilin, LockBit 5, Dragonforce, and Krybit activity, as they have shown a rapid expansion into new industry verticals.
All URLs above are directly taken from the publicly available posts that reported the incidents.
Model=gpt-oss:120b top_k=70 context_window=131072 query_mode=cluster