Threat Intel
August 17th Threat Intel: From Colombian Ransomware to AI‑Driven Espionage and Critical Vulnerabilities
This week’s bulletin highlights a ransomware hit on Colombia’s Ministry of Justice that stalled drug‑monitoring services, a 19‑million‑person data breach at Poland’s MyDr platform, and a social‑engineering attack on Levi Strauss that stole internal data. A phishing incident at U.S. defense contractor IEH Corp exposed sensitive engineering files. Researchers exposed a China‑linked AI campaign that mapped Taiwanese government systems, a North Korea‑linked Kimsuky offline AI toolkit, and the replayability of encrypted reasoning blocks from major LLM APIs. Patch Tuesday saw Microsoft, Apple, Adobe
Top Attacks & Breaches
- Colombia’s Ministry of Justice suffered a ransomware assault that encrypted portions of its infrastructure, disrupting drug‑monitoring and legal services. No data exfiltration was reported.
- Poland’s MyDr healthcare platform was breached, potentially affecting 19 million users. Attackers claimed 2.5 TB of data, including a senior politician’s personal details and prescription records.
- Levi Strauss & Co. faced a social‑engineering breach that compromised three employee devices. Preliminary checks show no consumer data was accessed.
- IEH Corp, a U.S. defense and aerospace supplier, fell victim to a phishing attack that stole credentials via a fake document‑sharing link, risking exposure of customer orders and export‑controlled tech.
AI‑Driven Threats
- Researchers identified a China‑linked campaign deploying autonomous AI agents against Taiwanese government systems, compromising 85 accounts and 2,500 personnel records before targeting nuclear safety and energy firms.
- North Korea‑linked Kimsuky is building an offline AI environment to automate phishing, intelligence analysis, and malware development, combining local language models with code and transcription tools.
- Analysis of over 315,000 encrypted reasoning blocks from OpenAI, Anthropic, and Google APIs revealed that replaying these blocks can expose API keys, passwords, and private cryptographic material.
Patch Tuesday Highlights
- Microsoft’s August update patches 421 vulnerabilities, including CVE‑2026‑68820, a WinSock driver flaw that can elevate local attackers to SYSTEM.
- Apple fixed CVE‑2026‑65400, a macOS screen‑sharing flaw that lets attackers authenticate without credentials, already being used to deploy Monero miners.
- Adobe addressed CVE‑2026‑71362, a critical authentication bug in Commerce and Magento that enables session hijacking.
- Zoom patched three critical RCE vulnerabilities in Zoom Workplace, affecting annotation features and requiring no user interaction.