Executive Summary -
Highlights of Cyber Threat Intelligence Digest
Vulnerabilities
Elastic Patches Missing Authorization Vulnerability CVE-2026-63262 Affecting Kibana - On 22 July 2026, Elastic released a patch addressing a missing authorisation vulnerability tracked as CVE-2026-63262, affecting Kibana versions 9.4.0 through 9.4.3. The flaw stems from a weakness within Kibana's space-level access control mechanism, which is designed to segregate data and resources between different organisational units or teams.
Exploitation could allow threat actors to conduct unauthorised cross-space information disclosure by submitting specially crafted user-supplied input that circumvents these access restrictions, potentially enabling an attacker with limited privileges in one space to view data belonging to another. At the time of writing, there are no reports of this vulnerability being exploited in the wild.
Veeam Patches Six Vulnerabilities in Veeam ONE - On 5 August 2026, Veeam patched six vulnerabilities affecting Veeam ONE 13.0.2.6723 and all earlier version 13 builds, tracked as CVE-2026-64633, CVE-2026-58075, CVE-2026-58074, CVE-2026-64631, CVE-2026-64634, and CVE-2026-64630. Veeam released Veeam ONE 13.1.0.7034 to address the flaws, and at the time of writing, no active exploitation has been reported.
CVE-2026-64633 is a remote code execution vulnerability allowing unauthenticated threat actors to execute arbitrary code on the agent host. CVE-2026-58075 is an arbitrary file read vulnerability that could allow unauthenticated attackers to read files from the host and potentially escalate privileges locally. CVE-2026-58074 is a code execution vulnerability enabling arbitrary code execution on the server. CVE-2026-64631 is a SQL injection vulnerability that could allow threat actors to inject queries and extract database contents. CVE-2026-64634 is a local privilege escalation vulnerability permitting escalation to the Reporter service context, and CVE-2026-64630 is an access control vulnerability allowing retrieval of report data beyond the scope of a shared report hyperlink.
Goose Maintainers Patch High-Severity Command Injection Vulnerability CVE-2026-72718 Affecting Goose CLI - On 10 August 2026, the goose maintainers patched CVE-2026-72718, a high-severity command injection vulnerability affecting goose command-line interface (CLI) versions before 1.44.0. At the time of writing, no active exploitation has been observed in the wild. The vulnerability occurs when goose review invokes the host's git executable to collect repository differences without removing threat actor-controlled Git configuration. A threat actor can prepare a repository whose .git/config assigns an arbitrary command to core.fsmonitor, so that during git diff HEAD, Git refreshes the repository index and triggers the specified command. The malicious .git/config must already be present on the target system before a user reviews the repository with goose, with possible delivery methods including archives, shared volumes, nested or automatically detected repositories, and continuous integration (CI) checkouts.
The malicious code runs before goose communicates with the artificial intelligence (AI) model and outside its large language model (LLM) tool-permission controls, requiring no submitted prompt, model invocation, tool authorisation, or trust prompt. Successful exploitation allows arbitrary commands to run with the privileges and environment of the user operating goose, enabling access to or modification of available files, as well as exfiltration of environment secrets and provider application programming interface (API) keys.
Potential Threats
Fake Google Play Store Page Distributes a Fake Jadlog Application to Deliver an Android Dropper - On 4 August 2026, malware researcher OpcodeIntel reported a web page hosted at seguro-play[.]store that impersonates the Google Play Store and distributes a fake Jadlog application to deliver an Android dropper against Brazilian users. At the time of writing, the web page remains active. Jadlog is a Brazilian logistics and parcel delivery company that provides shipping, e-commerce delivery, and transportation services across Brazil.
Additionally, malware researcher Hido Cohen noted that the fake Jadlog application ultimately leads to the deployment of BTMOB RAT v4.2. BTMOB is a malware-as-a-service (MaaS) Android remote access trojan (RAT) platform, first reported in February 2025.
UNC6671 Uses IT Helpdesk Vishing and AiTM Credential Theft in Multi-Brand Extortion Campaigns - On 7 August 2026, Google Threat Intelligence Group (GTIG) reported that UNC6671 (overlapping with activity Recorded Future tracks as CL-CRI-1116) conducted IT helpdesk voice phishing (vishing) campaigns leading to credential theft, cloud data theft, and extortion. Between April and July 2026, UNC6671 targeted organisations across manufacturing, real estate, healthcare, insurance, technology, transportation, hospitality, financial, and legal sectors, increasingly focusing on financial and legal entities such as private equity firms, law firms, and rating agencies. GTIG associated UNC6671 with the Redact, Pink, Helix, and Falcon extortion brands based on shared infrastructure, templates, targeting, and TTPs, assessing that a coordinated group most likely operates all four, though it noted actor splintering or outsourced extortion could also explain the overlaps.
The infection chain began with UNC6671 impersonating IT helpdesk staff to contact employees on personal mobile devices, sometimes spoofing legitimate helpdesk numbers, and instructing them to enable FIDO2 passkeys or alter their MFA enrolment under the guise of a security update. Victims were then directed to spoofed authentication portals styled to resemble their organisation's own login pages, where AiTM infrastructure captured credentials and MFA tokens to establish authenticated sessions. UNC6671 used compromised email accounts to reset passwords for applications outside SSO environments, deleted related security notifications to conceal its activity, and ran automated scripts to exfiltrate data from Microsoft 365 and Okta environments, feeding the stolen data into subsequent extortion.
Fake Zoom Installer Deploys Overlord RAT on macOS Systems Through .NET Downloader - On 6 August 2026, Jamf Threat Labs published a technical analysis detailing a macOS campaign that uses a fake Zoom installer to deliver a configured Overlord remote access trojan (RAT) build. Overlord is an open-source, cross-platform remote access framework whose agents communicate through encrypted WebSockets and support surveillance, command execution, file operations, remote desktop access, and extensible plugins. Jamf Threat Labs noted overlaps with prior macOS campaigns but did not attribute the activity to any specific threat actor, and the initial delivery vector remains under investigation. The campaign begins with a fake installer named ZoomMeetings, a self-contained .NET 10 downloader that runs as a native macOS ARM64 Mach-O wrapper containing embedded .NET assemblies. One of 34 extracted DLLs held an obfuscated C# string table, which the tool decodes via Base64 decoding and XORing with the key 0x94 to reveal threat actor infrastructure and payload URLs, before selecting a payload matching the host's detected operating system and architecture.
On macOS systems, ZoomMeetings writes the second-stage payload to /tmp/ZoomMeetings, makes it executable, and launches it via a backgrounded nohup command so it persists after the downloader exits, while also fetching the genuine Zoom installer to maintain the lure. Jamf Threat Labs also identified a related downloader, ZoomInstallerFull, using the same infrastructure and containing a program database path revealing the developer username "ollie" and project name "TheEgg". The second-stage payload was identified as an Overlord agent compiled with Garble obfuscation, containing a hard-coded command-and-control address at hub[.]zoom[.]com[.]kg over port 5173 and communicating via secure WebSockets; at the time of writing, this address returns an error. The build disables certificate validation by default, and although Overlord supports a Solana-based command-and-control resolver, this feature remains disabled in the analysed build.
General News
Local governments in four states dealing with cyberattacks that have shut down services - A city in California's Bay Area, Suisun City, had its 911 system taken down by hackers on Friday, one of several cyberattacks affecting government services nationwide that week. The town of 30,000 people said malicious software had infected and compromised its IT systems, hitting critical public safety operations including 911 routing, police and fire dispatch, records, and city services. The city shut down its entire network, and emergency calls are now being routed through the county's dispatch centre while the FBI investigates and helps maintain essential services. City hall was closed to in-person meetings on Monday, and a state of emergency was declared on Saturday to unlock emergency funding and services for the recovery effort.
Several other local governments reported similar incidents in the same week. Coweta, Oklahoma, suffered a ransomware attack that affected all computers, files, and digital services, though police and fire departments continued operating via unaffected off-site systems; the town of roughly 12,000 has offsite backups to restore data once the ransomware is cleared, and utility disconnections for nonpayment have been paused while systems are down. Mitchell, South Dakota, also shut down government networks following a cyberattack, though emergency services and email systems were reportedly unaffected, though neighbouring county officials were advised not to open emails from the town's government. Coryell County, Texas, and Washburn County, Wisconsin, disclosed further incidents, with Washburn County's court phone and fax lines still down days later, though hearings and e-filing continued unaffected. These attacks on local government coincide with a wider wave of cyberattacks affecting water and wastewater systems across at least 12 states.
Cyberattack on logistics giant Ceva hits retailers and Steam customers across Europe - A cyberattack on global freight company Ceva Logistics has reportedly disrupted shipments for major European retailers and potentially exposed customer data belonging to users of a popular video game platform. Ceva has not publicly disclosed the attack, but the company reportedly notified corporate clients earlier this month that a cyber intrusion was affecting part of its contract logistics business, disrupting operations at eight warehouses in Europe and causing shipping delays for affected retailers. Companies reported to have been impacted include Bol, De Bijenkorf, Ace & Tate, Ajax, and Steam's European hardware business. Bol was informed of the attack on 1 August, with an investigation finding that cybercriminals had accessed two Ceva systems used to process orders from one of its distribution centres, exposing customer and shipment information including names, addresses, phone numbers, email addresses, order numbers, tracking details, and purchase information. Bol suspended data exchanges with Ceva as a precaution and said Ceva had since taken steps to stop the unauthorised access and brought in outside cybersecurity specialists.
Valve, the US company behind the Steam gaming platform, began notifying European customers that information linked to physical Steam hardware purchases may have been compromised, as Ceva handles Valve's European shipments and can retain customer delivery records for up to 90 days after an order. Valve said it could not determine precisely which records were accessed and therefore notified all customers whose data it reasonably believed could have been affected, including names, addresses, phone numbers, email addresses, and details of the hardware ordered; the company said it was pressing Ceva for the full scope of the breach and notifying relevant data protection authorities. There has been no public attribution for the attack, and it remains unclear whether ransomware was involved or whether an extortion demand was made. Ceva, headquartered in France, is one of the world's largest logistics and supply chain companies, employing around 110,000 people across more than 1,700 facilities worldwide.
Three intrusions at UK criminal records office went undetected for two years - Britain's criminal records office has been reprimanded by the country's data protection regulator after being repeatedly breached over nearly two years, exposing the personal data of thousands of people including victims of domestic violence. The Information Commissioner's Office (ICO) censured ACRO Criminal Records Office over a range of security shortcomings, including antivirus alerts going unread and a critical system left unpatched for nearly four years. Basic failures allowed hackers to compromise the office in three separate intrusions between July 2021 and June 2023, all exploiting ACRO's public-facing customer portal, built on the Kentico content management system, which had run the same unpatched version since September 2019 despite known vulnerabilities, as neither ACRO, its managed service provider, nor its web development supplier knew who was responsible for applying fixes. Numerous warnings from the system's Trend Micro security software, including four quarantined attempts to install the Mimikatz credential-harvesting tool, also went unheeded, with ACRO unable to establish what process existed for handling such alerts.
A forensic investigation identified three distinct incidents, the most serious of which saw an attacker maintain persistent access to ACRO's website and content management system for around seven months between August 2022 and March 2023, staging the data of just under 11,000 people for exfiltration in February 2023; insufficient logging meant ACRO could not confirm whether the data was actually taken. Another incident reportedly involved an SQL injection exposing employee credentials. ACRO initially claimed its website was down for maintenance before disclosing the cybersecurity incident in April 2023, after which the Medusa ransomware group claimed responsibility, though no stolen data was ever published. ACRO notified more than 84,000 people as a precaution, and while network segmentation prevented the attacker reaching the core policing system, a factor the ICO cited in issuing a reprimand rather than a fine, ACRO has since decommissioned the compromised infrastructure and implemented a new security information and event management system.
Threat Actor Weekly Graph
Over the past 7 days, we have been tracking the following intent and opportunity changes within our Threat Actor Landscape.
Intent represents the potential targets of a group. When a group is observed attacking a different organisation or entity, their intent will increase.
Opportunity represents the various methods and technologies these groups may use. For example, if a group started using a new attack vector, such as a new kind of ransomware, their opportunity would increase.
Both intent and opportunity are scored out of 100 and are responsible for scoring the group's severity. These updates can be seen below.

| ● Limited Severity | ● Basic Severity | ● Moderate Severity | ● High Severity |
| Threat Actor | Severity Increase | Opportunity | Intent | ||||||
|---|---|---|---|---|---|---|---|---|---|
| CL0P Ransomware Group | ● High | → | ● High | ● 84 | → | ● 84 | ● 49 | → | ● 49 |
| ExfilSquad Group | NEW | → | ● Moderate | NEW |
→ | ● 35 | NEW | → | ● 55 |
| Booba Project Group | NEW | → | ● Basic | NEW | → | ● 25 | NEW | → | ● 40 |
| Panzer Ransomware Group | NEW | → | ● Basic |
NEW | → | ● 25 | NEW | → | ● 35 |
| 0xhonor | NEW | → | ● Basic | NEW | → | ● 30 | NEW | → | ● 30 |
Global Trends Powered by Recorded Future
Within each category, we have provided the current top five globally trending items. Each item is linked to how actively trending it is and is marked with a small symbol.
The spikes in references are calculated over 60 days and are normalised to ensure they aren't disproportionate when compared to bigger entities that will naturally have more baseline mentions.
▲- Spike – This indicates a large increase in reporting volume and a high diversity in the event descriptions.
▲- Rise – This indicates a small increase in reporting volume with little diversity in the descriptions.
| Attackers | Methods | Vulnerabilities | Targets | |||||
|---|---|---|---|---|---|---|---|---|
| ExfilSquad Group | ▲ | DeadLock Ransomware | ▲ | CVE-2026-68820 | ▲ | Taiwan | ▲ | |
| Lazarus Group | ▲ | Interlock | ▲ | CVE-2026-20349 | ▲ | CMA CGM | ▲ | |
| JabaROOT | ▲ | FudModule | ▲ | CVE-2026-18577 | ▲ | Merit France SAS | ▲ | |
| Ethics Group | ▲ |
AsyncRAT |
▲ | CVE-2026-50656 | ▲ | CEVA Logistics | ▲ | |
| BlueBravo | ▲ | Coruna | ▲ | CVE-2026-55040 | ▲ | Valve | ▲ | |
Prominent Information Security Events
Fake Google Play Store Page Distributes a Fake Jadlog Application to Deliver an Android Dropper
Source: Insikt Group | Validated Intelligence Event
IOC: Hash - 3f72767b211c84a7e35cdf397b228b22f2156984ea1c8cc4380b73a516c49ab8
On 4 August 2026, malware researcher OpcodeIntel reported a web page hosted at seguro-play[.]store that impersonates the Google Play Store and distributes a fake Jadlog application to deliver an Android dropper against Brazilian users. At the time of writing, the web page remains active, meaning users searching for or directed to the site remain at risk of downloading the malicious application. By mimicking the appearance and branding of the legitimate Google Play Store, the page is designed to lend an air of authenticity to the fake app and lower victims' guard against installing software from an unofficial source.
Jadlog is a Brazilian logistics and parcel delivery company that provides shipping, e-commerce delivery, and transportation services across Brazil. Its brand recognition among Brazilian consumers, many of whom would routinely expect to install a delivery-tracking application, makes it an effective lure for threat actors seeking to distribute malware under the guise of a legitimate courier service.
Additionally, malware researcher Hido Cohen noted that the fake Jadlog application ultimately leads to the deployment of BTMOB RAT v4.2. BTMOB is a malware-as-a-service (MaaS) Android remote access trojan (RAT) platform, first reported in February 2025. As a RAT, BTMOB would typically grant an operator remote control over an infected device, potentially enabling data theft, surveillance, or further compromise of the victim's information, and its availability as a MaaS offering means the tool could be used by multiple threat actors beyond those behind this specific campaign.
Fake Zoom Installer Deploys Overlord RAT on macOS Systems Through .NET Downloader
Source: Insikt Group | Validated Intelligence Event
IOC: Domain: hub[.]zoom[.]com[.]kg
On 6 August 2026, Jamf Threat Labs published a technical analysis detailing a macOS campaign that uses a fake Zoom installer to deliver a configured Overlord remote access trojan (RAT) build. Overlord is an open-source, cross-platform remote access framework whose agents communicate through encrypted WebSockets and support surveillance, command execution, file operations, remote desktop access, and extensible plugins. Jamf Threat Labs noted overlaps with prior macOS campaigns but did not attribute the activity to any specific threat actor, and the initial delivery vector remains under investigation. The campaign begins with a fake installer named ZoomMeetings, a self-contained .NET 10 downloader that executes as a native macOS ARM64 Mach-O wrapper containing embedded .NET assemblies. Of the 34 DLLs extracted from the binary, the first contained plaintext Zoom-related strings, distinguishing it from the remaining 33 standard .NET runtime libraries.
This first DLL also contains an obfuscated C# string table, which ZoomMeetings recovers by Base64-decoding each entry and XORing the result with the key 0x94, revealing threat actor infrastructure and payload URLs. ZoomMeetings then identifies the host's operating system and architecture and selects a matching payload URL, with each request requiring a randomly generated token or the server returns an HTTP 401 response. On macOS systems, it writes the payload to /tmp/ZoomMeetings, makes it executable, and launches it via a backgrounded nohup command so it persists after the downloader exits, while also fetching the genuine Zoom installer to preserve the lure. Jamf Threat Labs also identified a related downloader, ZoomInstallerFull, using the same infrastructure and containing a program database path revealing the developer username "ollie" and project name "TheEgg".
The second-stage payload was identified as an Overlord agent compiled with Garble obfuscation to hinder static analysis, containing a hard-coded command-and-control address at hub[.]zoom[.]com[.]kg over port 5173 and communicating via secure WebSockets; at the time of writing, this address returns an error. The build disables certificate validation by default, and although Overlord supports a Solana-based command-and-control resolver, this feature remains disabled in the analysed build.
Remediation Actions
Following the information provided above, we recommend that the technologies mentioned be fully patched and updated. We also want to highlight and recommend applying the following patches where applicable:
-
CVE-2026-63262 (Elastic) - This vulnerability can be remediated by updating to the most recent patch released by Elastic.
- CVE-2026-64633, CVE-2026-58075, CVE-2026-58074, CVE-2026-64631, CVE-2026-64634, CVE-2026-64630 (VEEAM) - Updating to VEEAM ONE 13.1.0.7034 will remediate these vulnerabilities.
- CVE-2026-72718 (Goose CLI) - Patching Goose CLI to version 1.44.0 will prevent this vulnerability from being exploited.
If you are currently an Acumen Cyber Vulnerability Management customer, we will be proactively performing related searching and hunting activities within your environment.