Why Should I Care? β 2026-08-11 | π΄ 0 HIGH Β· π‘ 1 MEDIUM Β· π΅ 20 RADAR Β· βͺ 226 FILTERED
π Briefing β 2026-08-11
21 vendor intel items scanned | π΄ 0 HIGH | π‘ 1 MEDIUM | π΅ 20 RADAR | βͺ 226 FILTERED
β No critical items today.
Everything else can wait.
π‘ Medium β review when time permits:
- #StopRansomware: Gunra Ransomware β Yes, if you operate in government, critical infrastructure, or other targeted sectors: Gunra ransomware encrypts data and threatens to leak it.
π΅ 15 items on the radar β see below β
Why Should I Care? π΄ HIGH β Handle Now
No HIGH priority items in the last 24h.
Why Should I Care? π‘ MEDIUM (1)
#StopRansomware: Gunra Ransomware
CISA Advisories
β Why Should I Care?
Yes, if you operate in government, critical infrastructure, or other targeted sectors: Gunra ransomware encrypts data and threatens to leak it. Act now.
π― Affected versions: CISA
π In plain English:
Gunra ransomware locks your files and threatens to publish stolen data online if you don't pay. An attacker can steal sensitive information from your systems, encrypt it, and hold it for ransom.
π§ Prerequisites:
- Access to internet-facing systems
- Presence of known exploited vulnerabilities
β± Urgency: High urgency due to active targeting of critical sectors with a double-extortion model.
Why Should I Care? π΅ On the Radar (20)
- BdThemes plugins supply-chain hack creates rogue WordPress admins (BleepingComputer) β A hacker exploited BdThemes' upstream infrastructure to inject malicious code into the JSON feeds used by their WordPress plugins. This created unauthorized admin accounts on affected sites, potentially giving attackers control over your WordPress installations.
- TrueConf Server Flaws Exploited to Replace Client Installers with PhantomCore (The Hacker News) β A threat actor named Head Mare exploited vulnerabilities in TrueConf servers to replace client installers with malware. This means that anyone using outdated versions of TrueConf could have their systems compromised by a backdoor or remote access trojan (RAT).
- LexisNexis shuts down services after suspicious activity on servers (BleepingComputer) β LexisNexis has taken down several of its key services due to suspicious activity on third-party managed servers. This means any organization relying on LexisNexis for compliance, risk management, or media monitoring may face disruptions until the issue is resolved.
- CISA: SonicWall SMA1000 flaws now exploited by ransomware gangs (BleepingComputer) β Ransomware groups have started using known flaws in SonicWall's SMA1000 remote access gateway, which can expose corporate networks and internal applications. This means your infrastructure might be at risk if you haven't patched these vulnerabilities.
- Solidity Pro VS Code Extensions Steal Crypto Wallets, API Keys, and Credentials (The Hacker News) β Malicious VS Code extensions named 'Solidity Pro' have been found stealing sensitive information like crypto wallets, API keys, and credentials. This affects developers using these extensions for Solidity development in VS Code.
- Critical Progress LoadMaster flaw now actively exploited in attacks (BleepingComputer) β A critical command injection flaw in Progress Kemp LoadMaster and MOVEit WAF is being actively exploited by hackers. This can allow unauthenticated attackers to execute arbitrary commands on your systems, leading to potential data breaches or service disruptions.
- Valve notifies Steam hardware customers of a data breach (BleepingComputer) β Valve notified Steam hardware customers in Europe about a data breach affecting their personal information due to a hack on its shipping partner, CEVA Logistics. This means that customer names, addresses, phone numbers, email addresses, and order details may have been compromised.
- Hackers breached a small Polish energy plant via private APN last year (BleepingComputer) β Hackers exploited a misconfigured private APN to breach an energy plant's operational technology network in Poland. They shut down the steam turbine and water treatment system, demonstrating how such vulnerabilities can disrupt critical services.
- China-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flaw (The Hacker News) β A new ransomware called StormEncryptor has been deployed by a China-linked hacker group. They likely exploit vulnerabilities in N-central to gain access and encrypt files, demanding a ransom.
- New Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFA (The Hacker News) β Three research efforts found ways to bypass passkey protections without breaking the underlying cryptography. This means attackers can impersonate users or recover private keys if malware is present on a device, potentially compromising enterprise security.
- AWS completes the 2026 Police-Assured Secure Facilities (PASF) audit in Europe (London) (AWS Security Blog) β AWS completes PASF audit in Europe (London).
- The Permanent Threat: Analyzing Aeternumβs Blockchain-Based C2 Operations and Communications (Palo Alto Unit 42) β Analysis of Aeternum botnet loader using blockchain.
- β‘ Weekly Recap: AI Goes Rogue, Metabase 0-Day, MCP Supply-Chain Attacks, and Router Backdoors (The Hacker News)
- New StormEncryptor ransomware used by former Medusa affiliate (BleepingComputer)
- 2026 AWS CyberVadis report now available for due diligence on third-party suppliers (AWS Security Blog)
βͺ 226 low-priority items filtered.
π¦ Aggregated and triaged by Donna AI | Sources: 9 vendor feeds | CISA KEV