Cyber Threat Intelligence Digest: Week 34

26th August 2026 - Threat Reports
Share
  • Vulnerabilities
  • Potential Threats
  • General News
  • Threat Actor Weekly Graph
  • Global Trends Powered by Recorded Future
  • Prominent Information Security Events
  • Remediation Actions

Executive Summary -
Highlights of Cyber Threat Intelligence Digest

Vulnerabilities

Marimo Addresses Code Injection Vulnerability CVE-2026-75149 - On 19 August 2026, VulnCheck disclosed CVE-2026-75149, a high-severity code injection vulnerability affecting Marimo. Marimo addressed the issue in version 0.23.15, and at the time of writing, no active exploitation has been observed in the wild.

The vulnerability allows a notebook to supply a Model Context Protocol (MCP) server entry containing a threat actor-controlled command; when a user opens the notebook in edit mode, marimo launches the supplied command as a local subprocess. According to a Hacker News report from 25 August 2026, exploitation requires user interaction but not authentication, and marimo's PEP 723 hardening filters notebook-supplied configuration through an allowlist.

Citrix Patches Two NetScaler Flaws CVE-2026-19490 and CVE-2026-19489 - On 19 August 2026, Cloud Software Group disclosed CVE-2026-19490 and CVE-2026-19489, affecting customer-managed NetScaler Application Delivery Controller (ADC) and NetScaler Gateway deployments. Both vulnerabilities affect NetScaler ADC and NetScaler Gateway 14.1 before 14.1-73.32 and 13.1 before 13.1-63.21, as well as NetScaler ADC FIPS before 14.1-73.32 FIPS and NetScaler ADC FIPS and NDcPP before 13.1-37.277, with Secure Private Access Hybrid deployments using customer-managed NetScaler instances also affected.

CVE-2026-19489 is a high-severity memory overflow vulnerability affecting configurations where Session Initiation Protocol Application Layer Gateway (SIP ALG) is enabled on a Large Scale NAT group, which can cause unpredictable system behaviour or denial-of-service. CVE-2026-19490 is an authentication bypass vulnerability affecting NetScaler systems configured as an authentication, authorisation and accounting (AAA) virtual server or Gateway, including SSL VPN, ICA Proxy, CVPN and RDP Proxy, with exposure in certain NetScaler releases also depending on whether a SAML Action is configured.

GitLab Vulnerability CVE-2026-19478 Under Active Exploitation Following its Disclosure - On 20 August 2026, SecurityWeek reported that WatchTowr had observed in-the-wild exploitation attempts targeting CVE-2026-19478, a critical code injection vulnerability affecting GitLab Community Edition (CE) and Enterprise Edition (EE). GitLab patched the flaw on 17 August 2026, releasing fixes in versions 19.2.4, 19.1.6, 19.0.8 and 18.11.11. The vulnerability can be exploited remotely without authentication under certain conditions via a GraphQL directive, and successful exploitation could allow a threat actor to modify or delete public projects and user data.

WatchTowr reported that exploitation attempts appeared in its honeypot network roughly two days after public disclosure, and advised organisations to review web logs for requests containing @gl_introduced. The firm warned that the vulnerability could be reproduced quickly using the advisory details and patch alone, even in the absence of public exploit code. As a mitigation, WatchTowr recommended restricting unauthenticated access to the /api/graphql endpoint or removing public repository access.

Potential Threats

CyberLeek-Themed Malware Campaign Uses GTA VI Lures and Disposable Infrastructure to Deliver Malicious ZIP Archives - On 23 August 2026, cybersecurity firm VECERT Analyzer reported a CyberLeek-themed malware distribution campaign exploiting interest in an alleged leaked version of Grand Theft Auto VI (GTA VI). CyberLeek is an online brand or identity associated with the distribution of allegedly leaked video game content, while GTA VI is an upcoming action-adventure video game developed by Rockstar Games and the sixth main instalment in the Grand Theft Auto series.

According to VECERT Analyzer, secondary threat actors capitalised on the CyberLeek branding to distribute malware through a fake CyberLeek Launcher, demanding payment in exchange for alleged game executables.

Threat Actors Use Microsoft Teams Phishing to Deploy SynkLoader - On 20 August 2026, Expel published a report on SynkLoader, a newly identified modular malware family first observed during an incident investigation on 18 August 2026 involving an EDR alert on a scheduled task. Expel assessed that the toolkit likely began distribution around 28 July 2026, based on file timestamps and compile dates, and assessed with low to medium confidence that it may belong to a ransomware group or an initial access broker that sells access to ransomware groups, owing to similarities in methods and functionality.

The infection chain began with a Microsoft Teams phishing message sent from an account using the Microsoft 365 username@company[.]onmicrosoft.com format and the display name "IT Service Desk (Fake Name)". The threat actor convinced the victim to download 331.msi from a Microsoft Azure Blob Storage endpoint at hxxps://filereserve[.]blob[.]core[.]windows[.]net/vgnghuyk/331/331[.]msi, lending the installer a Microsoft-associated appearance. At the time of writing, the URL remains active.

Malicious APKs Impersonating Cryptocurrency Services Deliver Android RAT - On 22 August 2026, Zscaler ThreatLabz reported a new Android remote access trojan (RAT) distributed through malicious applications hosted outside the Google Play Store. According to ThreatLabz, the malicious applications impersonate cryptocurrency services, including 1inch Wallet, Binance, Circle and MyCrypto.

Upon installation, the RAT's loader uses a malformed manifest header to hinder analysis. Having reverse-engineered the malware, ThreatLabz identified a range of capabilities in the Android RAT, including the collection of SMS messages, call logs and contact lists, the capture of clipboard contents and device screenshots, and the collection of image files. The malware also enables live screen monitoring and remote device control, can install additional Android Package Kit (APK) packages, and is capable of performing remote shell execution on the compromised device.

General News

Microsoft tests new privacy controls for Windows 11 desktop apps - Microsoft has begun testing new privacy controls in Windows 11 that allow users to manage camera, microphone and location permissions on a per-app basis, rather than through a single device-wide setting. The feature is shipping to systems on Windows 11 Insider Experimental Preview Build 26340.9233, with access reviewed and controlled via Settings > Privacy & Security, using dedicated toggles for each desktop app.

Microsoft has also warned users to grant access only to apps they trust, as some apps using shared system components or browser-hosted experiences may appear under a different name or as unsigned where the publisher cannot be verified. This builds on Microsoft's announcement in February of forthcoming smartphone-style permission prompts under the "Windows Baseline Security Mode" and "User Transparency and Consent" initiatives, driven by concerns over apps installing unwanted software or modifying core Windows settings without consent. The rollout is being carried out in a phased approach, with adjustments made based on feedback.

Iran-Linked Threat Actors Target UK-Based Power Plant in Cyberattack - On 22 August 2026, The Telegraph reported that Iran-linked threat actors had conducted a cyberattack against an unnamed UK-based power plant, causing a four-day outage. UK Energy Minister Michael Shanks acknowledged the incident on X (formerly Twitter) but stated that the affected facility was a small-scale energy generator and posed no threat to the broader grid.

Shanks also noted that officials had shared additional security guidance with energy companies following the incident and were continuing to coordinate with the National Cyber Security Centre (NCSC). As of this writing, UK officials have not publicly identified the affected facility or attributed the incident to a specific threat actor.

WhatsApp adds stronger two-step verification, multiple passkeys - WhatsApp has rolled out several new account security features, including support for multiple passkeys and stronger two-step verification. Users can now create a separate passkey for each platform, allowing more than one to be added to an account for those using both Android and iOS devices, managed via Settings. Two-step verification has also been upgraded from a six-digit PIN to a full alphanumeric password supporting special characters.

WhatsApp has also added more context to call screens on Android, showing whether a non-contact caller's number originates from a different country and whether any groups are shared, as a further layer of protection against scam attempts. This follows earlier security additions made this year, including Strict Account Settings for high-risk individuals, warnings for suspicious device-linking requests, and a beta "Scam Alert" feature that uses a local machine learning model to flag suspected scam messages.

Threat Actor Weekly Graph

Over the past 7 days, we have been tracking the following intent and opportunity changes within our Threat Actor Landscape.

Intent represents the potential targets of a group. When a group is observed attacking a different organisation or entity, their intent will increase.

Opportunity represents the various methods and technologies these groups may use. For example, if a group started using a new attack vector, such as a new kind of ransomware, their opportunity would increase.

Both intent and opportunity are scored out of 100 and are responsible for scoring the group's severity. These updates can be seen below.

 

● Limited Severity ● Basic Severity ● Moderate Severity ● High Severity
Threat Actor Severity Increase Opportunity Intent
GreenGolf ● Moderate → ● Moderate ● 61 → ● 59 ● 30 → ● 30
Dragon Force Group ● Moderate → ● Moderate ● 55
→ ● 54 ● 49 → ● 49
MedusaLocker NEW → ● Basic NEW → ● 25 NEW → ● 49
khosi NEW → ● Basic
NEW → ● 30 NEW → ● 25
Eclipse Ransomware Group NEW → ● Basic NEW → ● 25 NEW → ● 30

Global Trends Powered by Recorded Future

Within each category, we have provided the current top five globally trending items. Each item is linked to how actively trending it is and is marked with a small symbol.

The spikes in references are calculated over 60 days and are normalised to ensure they aren't disproportionate when compared to bigger entities that will naturally have more baseline mentions.

▲- Spike – This indicates a large increase in reporting volume and a high diversity in the event descriptions.
▲- Rise – This indicates a small increase in reporting volume with little diversity in the descriptions.

Attackers Methods Vulnerabilities Targets
JabaROOT ▲ Mirage2FA ▲ CVE-2026-60004 ▲ Norway ▲
SERVER KILLERS ▲ DDoS ▲ CVE-2026-21962 ▲ Boston Scientific  ▲
Huapi ▲ Chaos Ransomware ▲ CVE-2026-73570 ▲ Chemical Engineering ▲
Shadowbyt3 ▲

Botnet

▲ CVE-2026-46300 ▲ Electrical Power Distribution ▲
Awaken Likho ▲ Brain Cipher ▲ CVE-2026-55040 ▲ ReliaQuest ▲  

 

Prominent Information Security Events

CyberLeek-Themed Malware Campaign Uses GTA VI Lures and Disposable Infrastructure to Deliver Malicious ZIP Archives

Source: Insikt Group | Validated Intelligence Event

IOC: Domain - cyberleek[.]info

On 23 August 2026, cybersecurity firm VECERT Analyzer reported a CyberLeek-themed malware distribution campaign exploiting interest in an alleged leaked version of Grand Theft Auto VI (GTA VI). CyberLeek is an online brand associated with distributing allegedly leaked video game content, while GTA VI is an upcoming Rockstar Games title and the sixth main instalment in the Grand Theft Auto series. According to VECERT Analyzer, secondary threat actors capitalised on the CyberLeek branding to distribute malware through a fake "CyberLeek Launcher", demanding payment for alleged game executables. Within a 24-hour period, VECERT Analyzer identified 65 infrastructure and certificate entries, some active and others already inactive, with the actors using disposable domains, wildcard certificates, Cloudflare Pages and Cloudflare Workers to rotate landing pages rapidly and sustain the campaign as defenders block individual domains.

The campaign begins when a victim searches for GTA VI leaks or free downloads and lands on a fake CyberLeek page offering a "Full Leaked Version" of the game as "100% Safe", alongside a launcher setup, game files and a patch update. Before any download, JavaScript on the page collects the victim's IP address, approximate location, visited URL, referrer, User-Agent string, browser language, screen resolution and timezone, sending this as a "new visitor" event to a threat actor-controlled Telegram chat via a bot API.

When the victim selects a download, a further "download click" event with the same telemetry is sent to Telegram, and the request redirects to a separate domain delivering the launcher as a ZIP archive, still active at the time of writing. This separation of landing pages from delivery infrastructure lets the actors swap out blocked domains while keeping the archive centrally hosted. The victim is then expected to extract and run the alleged launcher; however, VECERT Analyzer confirmed only the fingerprinting, geolocation, Telegram telemetry, click monitoring and delivery mechanisms, without identifying the malware family or the archive's behaviour post-execution.

Malicious APK'S Impersonating Cryptocurrency Services Deliver Android RAT

Source: Insikt Group | Validated Intelligence Event

IOC: Hash: 0be6d372e1a4983dcee845730bdff286

On 22 August 2026, Zscaler ThreatLabz reported a new Android remote access trojan (RAT) distributed through malicious applications hosted outside the Google Play Store. According to ThreatLabz, the malicious applications impersonate cryptocurrency services, including 1inch Wallet, Binance, Circle and MyCrypto, likely aiming to attract victims already engaged with crypto wallets and exchanges who may be less cautious about sideloading apps to access such services.

Upon installation, the RAT's loader uses a malformed manifest header, a technique intended to hinder static analysis and complicate detection by security researchers and automated scanning tools. Having reverse-engineered the malware, ThreatLabz identified a broad range of capabilities within the Android RAT, reflecting a tool built for comprehensive surveillance and remote control rather than narrow, single-purpose theft.

Among these capabilities, the RAT collects SMS messages, call logs and contact lists, and captures clipboard contents, device screenshots and image files, all of which could expose sensitive personal or financial information. It also enables live screen monitoring and remote device control, giving an operator real-time visibility and hands-on access to the compromised device. Further functionality allows the RAT to install additional Android Package Kit (APK) packages and to perform remote shell execution, providing the means to deploy further payloads or issue arbitrary commands on the infected device.

Remediation Actions

Following the information provided above, we recommend that the technologies mentioned be fully patched and updated. We also want to highlight and recommend applying the following patches where applicable:

  • CVE-2026-75149 (Marimo) - This vulnerability can be remediated by updating to the most recent patch 0.23.15.

  • CVE-2026-19490, CVE-2026-19489 (Citrix) - Updating NetScaler to the most recent version will remediate these vulnerabilities.
  • CVE-2026-19478 (GitLab) - Installing the newest patches released by GitLab will prevent this vulnerability from being exploited.

If you are currently an Acumen Cyber Vulnerability Management customer, we will be proactively performing related searching and hunting activities within your environment.