Cyber Threats Surge, Clop Claims Victims, French Tax Breach
Quick Answer
Cyber threats are escalating as Clop targets organizations and a French tax breach exposes sensitive data. Learn what happened, the risks involved, and key cybersecurity measures to reduce exposure and strengthen defenses.
Clop, Lazarus, and Zero-Days Dominate a Brutal Week for Cyber Defenders
This past week was a heavy one for the cybersecurity world, from the Clop extortion gang adding oil, healthcare, and industrial giants to its victim list, to a fresh French government data breach, an actively-exploited zero-day in an open-source mapping platform, and North Korea’s Lazarus Group burning through yet another Windows zero-day. Add in ransomware gangs racing to weaponize freshly disclosed VPN flaws, and it’s clear attackers aren’t slowing down for anyone’s summer break.
Clop ransomware gang claims Philips, GE, and Shell as new victims
Tech and industrial heavyweights General Electric and Philips confirmed they are investigating claims from the Clop ransomware gang that their systems were breached and data stolen. Philips said it identified and contained an “attempted cybersecurity compromise of a specific enterprise server,” insisting customer environments weren’t touched, while GE said it’s still assessing the situation. This comes just days after oil giant Shell also confirmed it’s looking into a “potential incident” after Clop claimed to have stolen 89GB of its data.
All three companies were named among 43 new victims on Clop’s leak site, tied to attacks exploiting a critical vulnerability in Internet-exposed PTC Windchill and FlexPLM software, tools used by more than 30,000 companies worldwide across aerospace, defense, automotive, and manufacturing. Clop claims to have stolen backups, project plans, facility photos, and engineering blueprints from the victims. BleepingComputer

French tax authority breach exposes data on 678,000 people
France’s Ministry of the Economy and Finance disclosed that an attacker broke into systems belonging to the General Directorate of Public Finances (DGFiP) and extracted tax and property records belonging to 678,000 individuals and businesses. The incident came to light after a hacker using the handle “ZeroBytes” listed the stolen database for sale on a hacking forum on August 12, claiming to have had access to a portal covering roughly 20 million French citizens.
The exposed data includes reference tax income, family quotient details, withholding tax rates, and cadastral records tied to property addresses and sizes, though the ministry says login credentials for individual online accounts were not compromised. This is the latest in a string of breaches to hit French government agencies this year, following incidents at the national employment agency and the national bank account registry. BleepingComputer
RingCentral confirms scale of ShinyHunters breach: 1.6 million accounts
The extortion group ShinyHunters stole personal data from 1.6 million RingCentral accounts after breaching the cloud communications company in July through what RingCentral described as a “sophisticated social engineering campaign.” Data breach notification service Have I Been Pwned confirmed the scope this week after analyzing a leaked archive, finding names, email addresses, phone numbers, and physical addresses exposed.
RingCentral, used by over 600,000 businesses for calling and messaging, says the core platform wasn’t affected and that it’s contacting impacted customers directly. ShinyHunters has been on a tear in 2026, previously linked to breaches at hundreds of Salesforce customers and over 100 organizations hit through an Oracle PeopleSoft zero-day. BleepingComputer

Unpatched GeoServer zero-day under active attack within hours of disclosure
A newly disclosed, still-unpatched zero-day in the open-source mapping platform GeoServer is already being exploited in the wild, according to threat intelligence firm watchTowr. The SQL injection flaw, which allows remote code execution and doesn’t yet have an assigned CVE number, was publicly disclosed on August 12 by a researcher on X. watchTowr said it observed exploitation attempts within hours, with hundreds of probes originating from a small pool of IP addresses testing for vulnerable systems before attempting further exploitation. Organizations running Internet-facing GeoServer instances should treat this as an urgent, unresolved risk since no official patch is available yet. The Hacker News
Hackers exploit patched macOS Screen Sharing flaw to mine crypto
The Netherlands’ National Cyber Security Centre (NCSC-NL) warned that attackers are actively exploiting a recently patched macOS vulnerability to deploy cryptocurrency-mining malware. The flaw, an authentication issue in the Screen Sharing component (CVSS 9.8), let attackers already on a network bypass credential checks to access the built-in remote desktop feature.
Apple fixed the bug in an emergency update earlier this month across macOS Tahoe, Sequoia, and Sonoma, but the Dutch agency says exploitation is ongoing across multiple systems that haven’t yet applied the patch, a reminder that “recently patched” doesn’t mean “no longer a problem.” The Hacker News
VMware vCenter attackers gain a foothold in 361 organizations across 47 countries
Security firm QUIRSO GmbH reported that attackers are actively exploiting a critical VMware vCenter directory-traversal flaw (CVE-2026-59310, CVSS 9.8) to establish persistent remote access on compromised servers. Patches were released by Broadcom late last month, but compromised systems were seen contacting attacker-controlled infrastructure just five days after the flaw’s public disclosure.
The attack chain deploys a malicious cron job and an open-source SSH tunneling tool to maintain long-term access. QUIRSO identified 361 unique victim IP addresses spread across 47 countries, underscoring just how quickly attackers move once a vCenter patch goes public. The Hacker News

Cisco ASA and FTD VPN flaw exploited to crash firewalls remotely
Cisco warned that a high-severity denial-of-service flaw (CVE-2026-20349, CVSS 8.6) in its Secure Firewall ASA and FTD software is being actively exploited to remotely crash devices. An unauthenticated attacker can send a single crafted HTTP request to the Remote Access SSL VPN service and force an affected device to reload, cutting off both perimeter protection and remote access simultaneously.
Cisco published the advisory on August 11 and confirmed it became aware of active exploitation this month. CISA added the flaw to its Known Exploited Vulnerabilities catalog the same day, giving federal agencies until August 14 to patch. There’s no workaround, so upgrading is the only fix. The Hacker News
Feds warn Gunra ransomware is hammering critical infrastructure
The FBI, CISA, NSA, U.S. Secret Service, and South Korea’s National Police Agency issued a joint advisory on August 10 warning that the Gunra ransomware operation, built on leaked Conti source code, is actively targeting healthcare, financial services, and government organizations worldwide. Gunra actors gain initial access by exploiting two known Fortinet FortiOS/FortiProxy authentication bypass flaws, then run a double-extortion playbook of data theft plus encryption.
There’s a silver lining for some victims: researchers found a cryptographic weakness in Gunra’s Linux variant caused by a time-seeded random number generator, which in some cases lets defenders reconstruct decryption keys without paying. The Record
CISA confirms ransomware gangs abusing SharePoint RCE bug
CISA confirmed that ransomware operators have begun actively exploiting a high-severity Microsoft SharePoint remote code execution vulnerability that’s been flagged as under attack since early July. The confirmation adds urgency for any organization still running unpatched, Internet-facing SharePoint servers, since ransomware crews typically move fast once a flaw proves reliable enough to weaponize at scale. BleepingComputer
DeadLock ransomware goes decentralized with blockchain-backed infrastructure
A ransomware operation calling itself DeadLock is using decentralized, blockchain-backed services to protect its communications with victims and shield its data-leak site from takedown efforts. Building extortion infrastructure on blockchain rails makes it significantly harder for law enforcement and researchers to disrupt leak sites the way they’ve done with more traditional dark-web hosting, a worrying evolution in ransomware tradecraft. BleepingComputer

Hardware wallet maker Trezor and supply-chain giant Wesco hit via vendor breaches
Hardware wallet manufacturer Trezor disclosed a breach affecting nearly 14,000 customers after its shipping and logistics provider, ShipMonk, was hacked, exposing names, addresses, emails, and phone numbers of customers across the US, UK, and several European countries. Separately, global supply chain and distribution giant Wesco confirmed it’s investigating a cybersecurity incident of its own. Computer maker Framework also notified “all” of its customers that hackers accessed their names, emails, phone numbers, and addresses, part of a broader spike in attacks hitting shipping, logistics, and hardware supply chains this month. Privacy Guides
Black Hat and DEF CON research exposes AI agent security gaps
Research presented around Black Hat 2026 and DEF CON 34 this month highlighted how AI systems and autonomous coding agents can leak data, compromise development pipelines, accelerate exploit creation, and take damaging real-world actions through vulnerable APIs when given too much autonomy. As enterprises race to deploy AI agents into production workflows, researchers are warning that the same speed and automation that make agentic AI attractive also compress the time defenders have to notice and respond when something goes wrong. eSecurity Planet
As cyber threats, ransomware attacks, data breaches, and zero-day exploits continue to rise, implementing DMARC, SPF, and DKIM remains an important step in strengthening email security and helping protect organizations against phishing and spoofing attacks.
General Manager
Founder and General Manager of DuoCircle. Product strategy and commercial lead for DMARC Report's 2,000+ customer base.
LinkedIn Profile →Take control of your DMARC reports
Turn raw XML into actionable dashboards. Start free - no credit card required.