CiberLATAMbywhalemate
Intelligence report

USA: Cybersecurity Situation, August 2026

Ransomware led August in the USA, with 25 cases and 18 critical CVEs; banking and water regulation also shaped the agenda.

Sep 1, 202624 min read
USA: Cybersecurity Situation, August 2026whalemateThe platform for managing human risk in cybersecurity.

Key findings

Monthly reference modules

These modules are automatically completed with the verified dated facts within the period. Each one states its source base and counting criterion so the figures reconcile across modules. They are the recurring month-to-month readout, and the analysis that follows expands on the cases without repeating this summary.

Indicator window: 92 dated facts in August 2026 · 1 from prior months (comparative frame, not monthly volume) · 1 without confirmed date (excluded from indicators). Facts from prior months are used only as a comparative frame in the analysis, never as volume for this period.

CIBERLATAM / WHALEMATE Verified Signal Monthly Dashboard August 2026 · USA Top threat: Ransomware (25 of 92 incidents). Coverage: 92 dated incidents in August 2026 · 1 prior month… VERIFIED INCIDENTS 92 period base: all counts measured from below on this total RANSOMWARE / EXTORTION 25 2 unencrypted exfiltration (simple extortion) · 4 only mentioned on leak site · 19 UNCLASSIFIED INCIDENTS 12 breaches or outages without declared threat type FRAUD / PHISHING 4 documented fraud campaigns documented REGULATIONS 11 rules, resolutions, or penalties UNIQUE CVEs 18 CVE-2024-55591 / CVE-2025-24472
Verified Signal Monthly Dashboard — Base: 92 verified incidents dated within the period for the USA.
MONTHLY FIXED MODULE Threat axis distribution August 2026 · USA Each event is counted in only one axis, so the total is exactly 92. "Unclassified incidents" is the remainder. Ransomware 25 Vulnerabilities 20 Unclassified 20 Incidents 12 Regulation 11 Fraud 4
Threat axis distribution — Each event is assigned to one axis based on its classification; the total reconciles to the 92 events in the period.
MONTHLY FIXED MODULE Sector Breakdown of Signals August 2026 · USA Base: 92 incidents in the period · total 132 because 33 incidents are classified in more than one sector. Public Sector / OIV 57 Technology 25 Energy 17 Other / unspecified sect… 14 Telecom 11 Finance 3 Healthcare 3 Education 2
Sector Breakdown of Signals — Heuristic sector classification of the victim. One incident may affect more than one sector, so the total can exceed the base.
MONTHLY FIXED MODULE Critical infrastructure in the USA August 2026 · USA 24 of 92 period facts involve critical infrastructure. One fact may appear in more than one category. Public sector / government 54 Explicit critical infrastructure 6 Energy / utilities 29 Telecom / connectivity 10
Critical infrastructure in the USA — Verified facts on public sector, utilities, and essential services

Executive monthly summary for the U.S.

August 2026 was dominated in the United States by ransomware, with 25 verified incidents and a clear concentration in healthcare, manufacturing, transportation, finance, and utilities. The risk surface combined extortion, operational disruption, several active exploitation alerts, and a more intense regulatory agenda, with 11 documented policy moves and 18 critical CVEs mentioned.

The clearest intrusion case was the cyberattack on Boston Scientific, which the company described as a global operational disruption and an impact to on-premise systems used to process and ship orders. At the same time, pressure on the healthcare sector remained high because of campaigns by Medusa, Gunra, STORM, CoinbaseCartel, Chaos, Metaencryptor, KRYBIT, and Global Secret Group, with multiple posts on leak sites and several cases in which the source did not specify whether there was encryption, exfiltration, or only an extortion demand.

The critical infrastructure front was also severe. CISA, together with other federal agencies, warned about active attacks against Siemens S7 PLCs exposed to the internet, while another wave of incidents affected water and wastewater systems in more than one state. On the identity and enterprise software front, CISA added multiple exploited flaws to KEV, including Metabase, VMware vCenter, Windows IKE, SharePoint, Cisco ASA/FTD, and Citrix NetScaler.

The risk level for the U.S. in August is assessed as high. The volume rose from 73 to 92 verified incidents, the share of unclassified incidents fell, and references to critical CVEs and regulatory moves increased sharply.

USA, August 2026, verified milestonesAug 01Waterin 9systemsAug 10 Gunrajoint alertAug 18Medusais updatedhealthcare19 Aug SiemensS7 under alertfederal26 AugBostonScientificoutage27 AugNetScaler upCISA KEV

Verified milestone timeline in the USA, August 2026 — Selected milestones of the month, focused on incidents, ransomware, and high-impact regulatory alerts.
USA, August 2026, monthly balanceBase of 92 verified events, with ransomware leading, followed by CVEs and regulation92Events25Ransomware18Critical CVEs11Regulation
Monthly verified signal balance in the USA — Simple comparison of the monthly base and its three most visible axes, using the figures provided in the prompt.

National Snapshot for the Month in the USA

The United States closed August with a mix of operational pressure, regulatory exposure, and active vulnerability exploitation that affected both private companies and critical infrastructure and government agencies. The qualitative reading is high because the verified base grew, the dominant threat shifted to ransomware, and active campaigns touched sectors with direct impact on essential services.

The month’s most consistent signal was the shift from diffuse or unclassified incidents toward better defined cases by source, with more leak site posts, more security advisories, and more confirmations of operational impact. That did not eliminate uncertainty, but it did reduce the relative weight of ambiguous events compared with the prior month.

On the regulatory front, August showed both greater pressure and greater granularity. The OCC and the FDIC redefined supervisory action thresholds, the FTC maintained and clarified safeguard obligations under GLBA, the Senate extended the information sharing framework, and the White House and the Department of Justice pushed tougher measures against transnational threats and supply chain risks. In water, energy, and telecom, the federal government responded with notices, orders, and preventive litigation.

As regional context, several August reports on Brazil, Chile, and other Latin American countries were used by US or global media as a regulatory and operational mirror. They do not add volume to the USA report, but they do show that child privacy, platform controls, water, and critical infrastructure problems continued crossing jurisdictions and were read by North American regulators as part of the same tightening cycle.

Period indicators in the USA

Indicator August 2026 Previous month Change
Verified facts for the period 92 73 +19
Unclassified incidents (breaches or outages) 12 23 -11
Cases with ransomware or extortion as the primary focus 25 22 +3
Unencrypted exfiltration (simple extortion) 2 n/d n/d
Mentioned only on a leak site 4 n/d n/d
Classification could not be determined from the material 19 n/d n/d
Documented fraud or phishing cases 4 1 +3
Documented regulatory moves 11 7 +4
Critical CVEs mentioned 18 8 +10
Sectors with at least one documented fact 7 7 unchanged
Main threat of the month Ransomware (25 of 92 facts) Incidents (23 of 73 facts) change in dominance
Facts with direct source confirmation 77% n/d n/d
Time window for the indicators 92 facts dated in August 2026, 1 from previous months as a comparison frame, 1 undated excluded same same
Base for all indicators 92 73 +19

Quick read on the indicators

August was clearer than July. The number of unclassified facts fell, and better-attributed cases increased, although a significant share of ransomware posts remained claims or were only partially classified. At the same time, the technical attack surface widened with many more critical CVEs, while regulatory activity took on greater weight of its own.

Relevant incidents in the USA

Boston Scientific and the global operational outage

Boston Scientific was one of the month’s most visible corporate incidents in the USA because the company itself confirmed unauthorized activity that affected on-premise systems and caused a global operational outage. The company also said its cloud systems were not impacted, which narrowed the technical scope and helped separate the incident from a full compromise scenario.

Available coverage did not allow a precise determination of whether clinical or patient data was stolen. What was clear was the impact on business processes, especially order processing and shipping, and that the company worked with outside specialists to contain the threat and restore continuity.

Water systems, from Minnesota to more than 100 exposed systems

The campaign against water and wastewater systems remained one of the month’s most sensitive stories. CISA confirmed that more than 100 internet-exposed systems were attacked in July, with impact in Michigan, Minnesota and at least five other states, while the FBI and other agencies stressed that the most common vector was direct exposure of PLCs and operational controls.

The body of reporting also made clear that this was not just a technical alert. Publications documented loss of monitoring and control functionality, password changes and remote manipulation in water systems, with a joint response from federal, state and local authorities. In some materials, the campaign was attributed to actors linked to Iran, but that attribution appears as an intelligence judgment or a media hypothesis, not as a uniform fact across all sources.

North Carolina Ports and the logistics disruption

North Carolina Ports confirmed a cyberattack that disrupted its IT systems and affected operations in Wilmington, Morehead City and Charlotte Inland Port. The authority shifted to manual processes, activated its contingency plan and coordinated with federal and state agencies, including the Coast Guard and CISA.

There was no public evidence of sensitive data compromise or a formal attribution of the attack during the period. Even so, the incident mattered because it showed how an attack focused on administrative IT can quickly spill into delays at gates, cargo handling and maritime coordination.

Trezor, ShipMonk and customer data exposure

The breach tied to logistics provider ShipMonk exposed data belonging to nearly 14,000 Trezor customers, including names, email addresses, phone numbers and shipping addresses. The incident did not compromise Trezor’s own infrastructure or hardware wallets, but it did expose personal information useful for targeted phishing and potential physical attacks.

The key technical detail was the exploitation of a vulnerability in Metabase, which allowed unauthorized access to ShipMonk’s analytics instance. The case matters for the USA not only because of the presence of American customers, but because it again highlights dependence on third-party logistics and analytics chains in digital commerce.

Boston Scientific, McKesson and healthcare as a target

McKesson confirmed an incident involving unauthorized access to third-party applications and data theft, although the extreme figures circulated by other outlets remained claims from the attacker group or unspecified reports. Amgen, for its part, reported theft of patient information and proprietary data stored in the cloud.

The healthcare sector also faced heavy operational pressure from Medusa and Gunra activity, along with new posts from STORM, CoinbaseCartel, Chaos, Global Secret Group and other groups claiming U.S. victims. The final picture is not one major event, but sustained pressure on hospitals, clinics, providers and distributors.

Active threats and campaigns in the USA

Ransomware and extortion

In August, ransomware was the main focus, with 25 cases out of 92 incidents and a highly uneven level of certainty. There were two confirmed cases of exfiltration without encryption, four mentions limited to leak sites, and nineteen situations where the material did not make it possible to determine whether there was encryption, exfiltration, or both.

Among the better defined cases was Boston Scientific, which the primary source did not present as ransomware, but as a cybersecurity incident with operational disruption. On the purely extortion side, STORM, CoinbaseCartel, Global Secret Group, KRYBIT, Chaos, Metaencryptor, DragonForce, Emperador, Wallstreet, Falcon, and Qilin accounted for much of the criminal market noise, although not all of the listings were publicly confirmed by victims.

Cases with confirmed exfiltration without encryption

The material made it possible to isolate two cases in which extortion was described as exfiltration without encryption. One was mswalker.com, where follow-up reporting indicated about 620 GB extracted before any encryption was mentioned. The other involved a scenario in which the coverage itself described the publication of sensitive data without being able to support that encryption was the main issue.

In this category, the operational pattern matters as much as the volume. The goal was not to shut down a service, but to use stolen data to pressure the target with the threat of publication. That makes early detection harder, because the company can keep operating while the damage is already underway.

Cases mentioned only on leak sites

Four incidents remained at the level of a simple leak-site mention. This included claims by groups such as Chaos, STORM, CoinbaseCartel, and others about victims in the United States, but without independent public confirmation of the technical scope or the type of information exposed.

That subgroup matters because it shows the gap between the extortion economy and official visibility. An actor can publish a name, a sample, or a threat and still, by the end of the period, there may be no validation strong enough to describe the episode as a confirmed breach.

Fraud, phishing, and account takeover

Documented fraud and phishing activity was low in absolute volume, but very clear in direction. There were four cases, two centered on fraudulent calls or spoofing to obtain data, and two tied to AI-driven scams and weak identity verification.

The most repeated pattern was the use of support or fraud team impersonation to force account changes or transfers. That scheme appears in materials on financial institutions as well as in more general notes on deepfakes and remittances, reinforcing that the human vector remained a relevant entry point in the USA.

APT, espionage, and hacktivism

The APT and espionage segment was marked by Salt Typhoon, Lilac Typhoon, and the operation against QTFY and its QScan and QTRouter platforms. In telecommunications, the sources described a broad espionage campaign with access to lawful intercept, metadata, and obfuscation nodes. In the QTFY case, the focus was on federal agencies, hospitals, energy, and finance.

There was also material on the Iranian campaign against water and on the federal warning about Siemens S7 PLCs. That front does not fit neatly into ransomware or fraud, because it involves remote access, reconnaissance, and exploitation of exposed OT, with potential physical or operational impact rather than monetary loss.

Cases with the highest classification uncertainty

Nineteen incidents linked to ransomware or extortion did not allow the material to determine whether there was encryption, exfiltration, or only publication on a leak site. That ambiguity is not trivial, because it changes how response, notification, and external communication should be prioritized.

Operationally, this block requires careful treatment of any aggregate reading. The month brought more visible criminal activity, but also more documentary noise. The useful takeaway is not that every case caused more damage, but that there were more claims, more campaigns, and more public visibility around extortion.

Critical vulnerabilities affecting the US

August’s technical pressure in the US was driven in large part by the addition of multiple flaws to CISA’s KEV catalog and by joint alerts about active exploitation. The mix of Citrix NetScaler, VMware vCenter, Metabase, Windows, SharePoint, Cisco ASA/FTD, and Zimbra showed that exposure was not concentrated in a single product family.

CVE Software Exploitation Source
CVE-2026-72898 Metabase Active exploitation, unauthenticated SQL injection SecurityOnline.info, NVD, Metabase
CVE-2026-59310 Broadcom VMware vCenter Server Active exploitation, path traversal and RCE CISA, xhack.io, The Hacker News
CVE-2026-8452 Citrix NetScaler ADC and Gateway Active exploitation CISA, The Hacker News, BleepingComputer
CVE-2026-68820 Windows WinSock / afd.sys Active exploitation, local privilege escalation CISA, SecurityOnline.info
CVE-2026-20349 Cisco ASA and FTD Active exploitation, DoS / restarts CISA, SecurityOnline.info
CVE-2026-55040 Microsoft SharePoint Active exploitation CISA, xhack.io
CVE-2026-33824 Microsoft Windows IKE Service Extensions Active exploitation CISA, xhack.io
CVE-2026-21962 Oracle HTTP Server and WebLogic Proxy Plug-in Active exploitation SecurityArsenal, CISA
CVE-2026-73570 Zimbra Collaboration Suite Active exploitation, command injection HackerStorm, CiberPlaneta
CVE-2026-18577 N-able N-central Active exploitation, authentication bypass Rapid7, Wiz, CISA
CVE-2026-69836 Microsoft Entra ID Active exploitation, RCE CVSS 10.0 Yahoo Tech, Microsoft
CVE-2026-12710 Google Cloud Application Integration Missing authorization flaw, already patched by vendor NVD, KENET-CERT, Threat Radar
CVE-2026-59780 Apache CloudStack Sensitive information exposure NVD, Apache CloudStack Project
CVE-2026-71494 Infracost / Terraform Cloud workflows Token exposure via untrusted hostname cvefeed.io
CVE-2026-71567 openshift-metal3/fakefish OS command injection, high severity NVD, INCIBE-CERT
CVE-2025-62593 Ray Active exploitation CISA, CyberSecureFox
CVE-2026-49431 Not specified in the material Pending analysis INCIBE-CERT
CVE-2026-73047 Not specified in the material High severity, information disclosure INCIBE-CERT

Technical read of the table

CISA’s bias in August was clearly operational. The goal was not only to publish flaws, but also to set very aggressive remediation deadlines for federal agencies and push private organizations to treat exposure as real. Metabase, NetScaler, vCenter, and N-central stand out as high-priority products because they combine exposed attack surface, broad adoption, and real-world exploitation.

Regulation and compliance in USA

August’s regulatory agenda in the USA was intense and, on several fronts, clearly tougher. There were eleven documented moves, with the financial system as the main focus, but water, telecom, child privacy, information sharing, and the energy supply chain were also on the radar.

The OCC and the FDIC issued a uniform final rule on unsafe or unsound practices, with an explicit materiality threshold for MRAs and a shift toward material financial risks. That may sound like classic bank supervision, but it also affects how banks turn cybersecurity findings into compliance actions.

At the same time, the FTC kept in place and clarified the GLBA Safeguards Rule for financial institutions, while NIST published quick references to translate CSF 2.0 into concrete controls. In practice, that pushes banks, fintechs, and vendors to document controls, risk assessments, and third-party oversight more thoroughly.

Most relevant regulatory moves

Date Measure Scope Operational reading
2026-08-27 Joint OCC/FDIC final rule on unsafe or unsound practices and MRA Federal banking Raises the enforcement threshold and prioritizes material risks
2026-08-27 OCC update to PPM 5310-3 Bank supervision More transparency and consistency in enforcement
2026-08-27 FTC keeps GLBA Safeguards Rule in place Financial sector Requires security programs with administrative, technical, and physical safeguards
2026-08-25 NIST SP 1347 guidance for CSF 2.0 Technical controls Makes it easier to map the framework to verifiable controls
2026-08-19 Water Cyber Shield Act draft Drinking water and wastewater Signals a tougher posture for the water sector
2026-08-21 DOJ and TikTok / ByteDance privacy settlement Child protection Reinforces pressure on platforms and data handling
2026-08-08 Extension of the Cybersecurity Information Sharing Act to 2026-12-11 Information sharing Keeps liability protections in place for now

Financial sector, privacy, and enforcement

The financial system was where regulation and cybersecurity overlapped most. FinCEN imposed a historic penalty on UBS Financial Services for BSA violations, and the debate over supervision, material risk, vendors, authentication, and incident reporting remained very active.

There was also a $400 million settlement between DOJ and TikTok / ByteDance over child privacy. While it was not a banking case, it set the tone for enforcement against large platforms with operations in the USA. For compliance teams, August showed that exposure is not limited to technical failures, it also includes data handling, disclosure, and third-party governance.

Water, energy, and telecommunications

The water sector saw a notable regulatory and operational response, with joint notices from federal agencies, legislative proposals, and public tracking of more than 100 exposed systems. The energy sector also gained weight with Executive Order 14420 on foreign equipment in the bulk power system.

Telecommunications remained at the center of espionage concerns, with Salt Typhoon still in the background. Although much of the material focused on campaigns from previous years, August reopened the debate over foreign vendors, interconnections, and residual exposure in critical networks.

Most Affected Sectors in the USA

The sector signal for the month was broad, but not scattered. Health care, manufacturing, transportation, finance, and utilities accounted for much of the activity, with water and telecommunications as critical infrastructure fronts and digital services as an indirect exposure vector.

Health care faced the heaviest pressure from ransomware and extortion, but also from unauthorized access incidents, double-extortion warnings, and vulnerabilities affecting the supplier chain. Activity from Medusa and Gunra reinforced the pattern of attacks on hospitals and public health organizations, while STORM, CoinbaseCartel, and other groups added more volume.

Manufacturing and transportation showed up in ransomware campaigns, CVE exploitation, and operational incidents. Encryption was not always involved, but victim disclosure, extortion pressure, and disruptions to administrative processes, logistics, and corporate systems were. In some cases, such as North Carolina Ports, the damage was more about continuity than confidentiality.

Finance and insurance kept the most visible regulatory weight. U.S. Bank denied compromise after a LockBit claim, FinCEN sanctioned UBSFS, and the OCC and the FDIC shifted the supervisory baseline. For financial institutions, August was not just a month of incidents, but of changing expectations for control.

Utilities, especially water, confirmed that OT exposure remains a federal priority. The combination of exposed PLCs, credential changes, and attacks across multiple states shows that the resilience of local infrastructure is not an isolated or purely technical issue. The vulnerability of those environments was also tied to legislative warnings and direct pressure from CISA.

A comparison with July shows an improvement in signal quality, not a reduction in risk. Verified incidents rose from 73 to 92, untagged incidents fell from 23 to 12, and the dominant category shifted from generic incidents to ransomware. That points to a month with better analytical visibility and more well-documented criminal campaigns.

The jump from 8 to 18 critical CVEs mentioned is the strongest technical signal of the month. It does not mean there were ten times more exploited vulnerabilities in the country, but that the material reviewed placed much more emphasis on active exploitation, KEV, and patch timelines. For defenders, that means August functioned as a month of pressure around known exposure.

Regulatory activity also increased, from 7 to 11 documented moves. Not all had the same impact, but they did show convergence across banking, water, privacy, information sharing, and energy. The practical reading is that compliance stopped being a side issue and became part of the cybersecurity response.

What to watch in September is whether the wave of leak site posts turns into more public confirmations or whether ambiguity continues to dominate. It is also worth watching the KEV deadline for NetScaler, the real behavior of the groups that exploited Metabase, and whether regulatory measures in water and energy become more concrete obligations for operators and critical infrastructure.

Security recommendations for USA

U.S. security teams should prioritize patching and external exposure in parallel. The mix of Metabase, NetScaler, vCenter, N-central, SharePoint, Windows IKE and Zimbra calls for a remediation campaign based on KEV, not theoretical severity. If an asset is internet-facing or supports remote access, it needs to be at the front of the work queue.

In healthcare and critical services, organizations should strengthen segmentation, phishing-resistant MFA and immutable backups. The warnings on Medusa and Gunra again show abuse of RMM, lateral movement with valid credentials and backup deletion as a recurring pattern. If that trio is not contained, response will be more expensive and slower.

Organizations with logistics, analytics or business software third parties should review permissions, tokens, service accounts and monitoring of access to shared platforms. The ShipMonk case, along with the supplier breach and leak site extortion, shows that indirect exposure can end up affecting customers, reputation and mandatory notifications.

In water, energy and manufacturing, this month’s operational minimum is to inventory exposed PLCs and OT equipment, remove unnecessary direct access and validate factory or shared credentials. Federal alerts on Siemens S7 and water systems made clear that the issue is not abstract, but about exposed surface, weak authentication and remote administration without enough control.

Priority Action Reason
High Patch KEV assets with external exposure CISA confirmed active exploitation across multiple families
High Review MFA, RMM and privileged credentials Recurring patterns in Medusa, Gunra and similar ransomware
High Inventory and isolate exposed OT Water, energy and manufacturing remain under pressure
Medium Review third parties with access to customer data ShipMonk, logistics and analytics cases show indirect risk
Medium Strengthen logging and evidence retention Useful for response, notification and litigation
Medium Validate incident reporting processes The regulatory and contractual environment has become more demanding

Frequently Asked Questions

What changed between July and August in the U.S., volume or severity?

Both increased, but the clearest shift was in signal quality. August recorded 92 verified incidents, up from 73 in July, unclassified incidents fell, and ransomware became the dominant category. Critical CVEs mentioned and documented regulatory actions also rose sharply.

Which sectors were most exposed in the U.S., and why does it matter to cross-reference them with CVEs?

Healthcare, manufacturing, transportation, finance, water, and telecommunications accounted for a large share of the incidents. Cross-referencing them with CVEs matters because several exploited flaws affected remote access software, virtualization, identity systems, and administrative tools used by those same industries.

What practical priority do Medusa and Gunra have compared with other ransomware groups?

Medusa and Gunra should be treated as high priority because official material linked them to active campaigns against healthcare, critical infrastructure, and enterprise environments, along with double extortion tactics, abuse of exposed vulnerabilities, and lateral movement. The other groups added volume, but with more uncertainty in classification.

What does the confirmation of more than 100 water systems attacked mean for a local operator in the U.S.?

It means this was not an isolated case or just a media headline. CISA acknowledged a concrete figure of more than 100 exposed systems attacked in July, and federal advisories continued to call for segmentation, PLC control, and the removal of direct internet access. For a local operator, the risk is both operational and regulatory.

What is the difference between a leak site mention and a confirmed breach in the U.S.?

A leak site mention is only a claim by the actor or tracker and does not, by itself, equal a verified breach. In August there were four such mentions and nineteen cases where the source did not allow the impact type to be determined. The distinction is key to avoid overreacting or underestimating.

Technical appendix: indicators of compromise and TTPs

This month’s materials do provide TTPs and some useful technical signals, though not always classic IoCs. In ransomware and extortion, the recurring patterns are RMM abuse, PsExec, WMI, lateral movement, shadow copy deletion, pre-encryption staging, and the use of valid credentials. In OT, the material points to Siemens S7 PLCs exposed to the internet, port 102, the use of snap7, and AI-generated exploitation scripts.

In the case of Gunra, the sources cite Fortinet exploitation, credential dumping, RDP, Impacket, exfiltration of local and cloud data, and encryption with ChaCha20 and RSA-4096. In the case of Metabase, the most repeated technical vector was the /api/session/reset_password endpoint or equivalent unauthenticated SQL injection paths.

The material also mentions specific domains and artifacts in campaigns that are not always strictly US-focused. Among the clearest are models.litellm.cloud, M365-OWA[.]com and owa-ms365[.]com in the CaptiveCrunch campaign, and the QScan and QTRouter domains seized by the DOJ in the operation against China-sponsored hacking. Because of their cross-threat value, these elements should be kept as operational reference material, even if not all of them relate directly to the USA.

Material limitations

This report was built exclusively from the material provided for the USA and August 2026. Facts from earlier months included in the file were used only as comparative context and were not counted as part of the month’s volume. There was also one incident without a confirmed date, which was excluded from all indicators.

A zero value in an indicator, especially for CVEs, does not mean there are no critical vulnerabilities in the region. It means none appeared in the material analyzed for this period. This issue did include many critical CVEs, but the methodological rule remains the same for any future note.

Aggregated telemetry, such as attack attempts, blocks, or scans, was not used as an incident or as trend data. When intelligence sources provided detection or exploitation figures, they were always treated as technical context or a methodological warning, not as country telemetry.

Sources outside the permitted list were also not used as evidence, nor were social media posts or sponsored content not authorized by the assignment. When a source presented a claim that was not confirmed by the victim or by a regulator, it was treated as such and not as a verified breach.

Sources