Last Week in Threats Banner

Last Week in Threats: Week 34

Bottom Line

What changed this week: Ransomware activity remained flat at 242 victims, but the Direwolf group surged 40 percent to 21 victims while long-dominant Clop dropped out of the top ranks, and five new vulnerabilities joined the CISA Known Exploited Vulnerabilities catalog targeting collaboration platforms (Zimbra), video-conferencing servers (TrueConf), and machine-learning operations tools (MLflow, Ray).

Who is most exposed: Manufacturing organizations (42 victims this week, 17 percent of the total), companies running email collaboration suites, and technology teams operating ML-ops or distributed-computing platforms in cloud environments where server-side request forgery can expose credentials.

Recommended action: Patch CVE-2026-73570 (Zimbra), CVE-2026-64849 (MLflow), and CVE-2025-62593 (Ray) by their federal due dates, and hunt for anomalous outbound connections from collaboration and ML-ops servers that could indicate post-exploitation command-and-control activity.

The Week in Review

The week of August 17 to 23, 2026 marked a shift in the ransomware landscape despite flat overall volume. Direwolf surged 40 percent week-over-week to claim 21 victims, while Clop, which led the prior week with 46 postings, dropped out of the top ten entirely. Qilin and TheGentlemen remained the top two groups but both declined modestly. Manufacturing dominated the victim distribution with 42 organizations compromised, followed by technology and professional services sectors.

Five new entries joined the CISA Known Exploited Vulnerabilities catalog, a notable concentration in collaboration and developer tooling. Zimbra Collaboration Suite (CVE-2026-73570, command injection), MLflow (CVE-2026-64849, server-side request forgery enabling cloud credential theft), and Ray-Project Ray (CVE-2025-62593, code injection) all appeared in active AlienVault OTX threat pulses, signaling in-the-wild exploitation. TrueConf Server contributed two code-injection flaws. The pattern underscores adversary interest in platforms that bridge organizational boundaries (email, video conferencing) and that operate with elevated cloud privileges (ML-ops, distributed computing).

The week's most-reported malicious IP, 62.60.130.253 (Serbia, CIPHER OPERATIONS hosting), accumulated 21,987 reports from 784 distinct AbuseIPDB contributors. The top-six enriched IPs split evenly between datacenter hosting (4) and residential ISPs (2), consistent with a mixed infrastructure of rented servers and compromised home routers. None cross-referenced as active malware command-and-control hosts in ThreatFox or URLhaus data pulled the same day.

Ransomware Leak-Site Activity

242 victims posted to ransomware leak sites during the week of August 17-23, 2026, unchanged from the prior week but with a shifted group composition (ransomware.live aggregated from ledger, August 24).

Most active groups by victim postings (ransomware.live, August 24, 2026)
Qilin 32 TheGentlemen 28 Direwolf 21 CoinbaseCartel 16 Storm 12 Incransom 11 Kazu 9 Titan 8 DYSPHOR1A 7 ShinyHunters 6
  • Top groups by victim count: Qilin (32, down from 37 the prior week), TheGentlemen (28, down from 31), Direwolf (21, up from 15, +40%), CoinbaseCartel (16, new to top ten), Storm (12, up from 10)
  • Top victim countries: United States (75), unknown/undisclosed (26), Italy (18), Germany (10), Mexico (9)
  • New groups this week: CoinbaseCartel, Kazu, Titan, DYSPHOR1A, ShinyHunters entered the top ten; Clop (46 victims last week) dropped out entirely

Sector & Technology Watch

Manufacturing organizations dominated the victim distribution at 42 postings (17 percent of the week), continuing a multi-week trend. The week's exploited vulnerabilities concentrated on collaboration platforms, video-conferencing infrastructure, and ML-ops tooling (ransomware.live victim descriptions, August 24; CISA KEV additions August 17-23).

Victim postings by sector (ransomware.live, August 24, 2026)
Manufacturing 42 Technology 18 Professional Services 15 Education 8 Healthcare 7 Transportation 7 Energy & Utilities 6
  • Most-targeted industries: Manufacturing (42), Technology (18), Professional Services (15), Education (8), Healthcare (7). Manufacturing held the top position for the second consecutive week, consistent with adversary focus on organizations operating 24/7 production lines that cannot tolerate downtime.
  • Technology in the crosshairs: Collaboration and email platforms (Zimbra Collaboration Suite, CVE-2026-73570), video-conferencing infrastructure (TrueConf Server, CVE-2026-72530 and CVE-2026-72529), ML-ops and data-science tooling (MLflow CVE-2026-64849, Ray-Project Ray CVE-2025-62593). All five appeared in AlienVault OTX threat pulses as of August 24, confirming active exploitation.
  • If you run Zimbra, MLflow, or Ray: Verify patch status for the CVEs above by their CISA due dates, and review authentication, network, and cloud IAM logs for post-exploitation indicators (anomalous outbound connections, IAM role assumption, bucket enumeration).

Most-Reported Malicious IPs

AbuseIPDB's 100-percent-confidence blacklist as of August 24, 2026 at 20:00 UTC returned 100 addresses. The top-reported IPs by cumulative community submissions:

  • 62.60.130.253 (GB, CIPHER OPERATIONS hosting) — 21,987 reports from 784 contributors (AbuseIPDB, August 24)
  • 41.181.156.205 (ZA, MTN residential ISP) — 6,098 reports from 1,130 contributors; reverse DNS ties to routemaster.co.za (AbuseIPDB / AlienVault OTX / Pulsedive, August 24)
  • 185.223.235.2 (NL, Infrawatch residential ISP) — 2,586 reports from 192 contributors (AbuseIPDB, August 24)
  • 180.76.147.239 (CN, Baidu datacenter/hosting) — 1,081 reports from 491 contributors (AbuseIPDB, August 24)
  • 103.108.67.180 (HK, HUANGYUN hosting) — 1,087 reports from 413 contributors (AbuseIPDB / AlienVault OTX / Pulsedive, August 24)

Reported activity associated with these IPs includes SSH brute-force attempts, email and credential brute-force, port scanning, and web-application attacks (inferred from abuse category distribution, AbuseIPDB, August 24). GreyNoise Community tagged 41.181.156.205 and 103.108.67.180 as malicious with no benign-scanner classification (GreyNoise Community, August 24).

Context matters: The AbuseIPDB blacklist is a community-contributed snapshot and may include legitimate security-research scanners. Cross-reference any IP before blocking it in production.

Attacker Infrastructure & Networks

Infrastructure enrichment of the top six malicious IPs reveals a balanced split between datacenter hosting (4 IPs) and residential ISPs (2 IPs), indicating adversaries continue to operate from both rented servers and compromised home networks (AbuseIPDB usage-type field, August 24).

Networks hosting the most malicious IPs (AbuseIPDB usage-type + AlienVault OTX ASN, August 24, 2026)
AS16637 MTN SA (residential) 1 AS401696 HUANGYUN (hosting) 1
Where the attack traffic originates (AbuseIPDB usage-type, August 24, 2026)
Hosting: 4 Residential: 2 Datacenter/Hosting Residential ISP
  • Nastiest networks: AS16637 (African Network Information Center / MTN SA, 1 IP, residential ISP), AS401696 (cognetcloud INC / HUANGYUN, 1 IP, datacenter hosting). AlienVault OTX (ASN), August 24.
  • Hosting vs. home: Four of six enriched IPs traced to datacenter or web-hosting providers; two traced to consumer residential ISPs (compromised endpoints, not malicious providers). When a large consumer ISP appears in malicious-IP rankings, the signal is compromised subscriber devices (routers, IoT), not provider misconduct.
  • Also known malware infrastructure: None of the six enriched IPs appeared as active command-and-control hosts or malware-delivery servers in abuse.ch ThreatFox or URLhaus databases as of August 24. This week's top malicious IPs are scanning and brute-force sources, not confirmed C2 endpoints.

The genuine infrastructure risk this week is the datacenter hosting cut, where providers may host bulletproof or loosely monitored infrastructure. The residential ISP entries (AS16637 MTN SA) represent compromised home networks, not a malicious provider.

Exploited-Vulnerability Watch

CISA added five vulnerabilities to the Known Exploited Vulnerabilities catalog between August 17 and 23, 2026. All five carried active-exploitation evidence in the form of named threat pulses on AlienVault OTX as of August 24:

  • CVE-2026-73570 — Synacor Zimbra Collaboration Suite, OS command injection; remediation due August 24 (CISA KEV, added August 21). AlienVault OTX pulse: "CVE-2026-73570 Zimbra SNMP Command Injection RCE Actively Exploited (KEV)" (2 pulses, OTX, August 24).
  • CVE-2026-72530 — TrueConf Server, code injection; remediation due September 3 (CISA KEV, added August 20).
  • CVE-2026-72529 — TrueConf Server, missing authentication for critical function; remediation due August 23 (CISA KEV, added August 20).
  • CVE-2026-64849 — MLflow, server-side request forgery enabling cloud credential theft; remediation due September 2 (CISA KEV, added August 19). AlienVault OTX pulse: "MLflow CVE-2026-64849 SSRF Credential Theft + FUXA RCE Scanning" (3 pulses, OTX, August 24).
  • CVE-2025-62593 — Ray-Project Ray, code injection; remediation due August 20 (CISA KEV, added August 17). AlienVault OTX pulse: "RondoDox Botnet: From Zero to 174 Exploited Vulnerabilities" (4 pulses, OTX, August 24).

Malware & C2

abuse.ch ThreatFox recorded 2,486 total indicators over a rolling three-day window as of August 24, 2026, including 874 fresh command-and-control IOCs (ThreatFox, August 24).

Top malware families by IOC volume (ThreatFox, 3-day window ending August 24): php.shin_webshell (199 IOCs), Overlord RAT (150), VShell (95), Remus (56), Cobalt Strike (55), Sliver (49), Vidar (45). Webshells (Shin) and legitimate red-team tools repurposed for adversary use (Cobalt Strike, Sliver) dominated the distribution, consistent with post-exploitation and persistence activity.

The Hunting Takeaway

Hunt for anomalous outbound connections from collaboration and ML-ops platforms. This week's KEV additions concentrated on internet-facing services that operate with elevated privileges: email servers (Zimbra), video-conferencing infrastructure (TrueConf), and machine-learning experiment-tracking platforms (MLflow, Ray) often deployed in cloud environments with IAM roles granting access to S3 buckets, databases, and compute resources.

The hunting angle: servers in these categories should not initiate arbitrary outbound connections to the internet. A Zimbra mail server connecting to an unknown external IP on port 443 or 4444, or an MLflow instance making HTTP requests to cloud metadata endpoints or S3 buckets it does not own, is a post-exploitation indicator. Hunt for this in proxy logs, firewall logs, and cloud VPC flow logs.

The MLflow SSRF flaw (CVE-2026-64849) explicitly enables cloud credential theft via the instance metadata service, so cross-reference any suspicious MLflow or Ray traffic with CloudTrail (AWS), Azure Activity Log, or GCP Cloud Audit Logs for IAM role assumption, bucket enumeration, or secret-manager access from unexpected source IPs.

This is a described behavioral hunt rather than a full query implementation. The specific log sources and field names vary widely by environment (firewall vendor, cloud provider, SIEM normalization). Focus on identifying servers in the affected technology classes, then filtering their outbound traffic for connections to IP ranges outside your known infrastructure.

Check Your Environment

IP sweep: Search your logs for connections involving this week's high-confidence malicious IPs. The sweep excludes 185.223.235.2 (Infrawatch), which may be a legitimate security-research scanner despite its AbuseIPDB listing.

Splunk SPL:

index=firewall OR index=proxy OR index=netflow
(src_ip IN ("41.181.156.205", "103.108.67.180", "180.76.147.239", "62.60.130.253", "77.42.49.249")
 OR dest_ip IN ("41.181.156.205", "103.108.67.180", "180.76.147.239", "62.60.130.253", "77.42.49.249"))
| stats count by src_ip, dest_ip, dest_port, action
| sort - count

Microsoft KQL (Sentinel / Defender):

union DeviceNetworkEvents, CommonSecurityLog, AzureNetworkAnalytics_CL
| where RemoteIP in ("41.181.156.205", "103.108.67.180", "180.76.147.239", "62.60.130.253", "77.42.49.249")
     or LocalIP in ("41.181.156.205", "103.108.67.180", "180.76.147.239", "62.60.130.253", "77.42.49.249")
| summarize Count=count() by LocalIP, RemoteIP, RemotePort, ActionType
| order by Count desc

Vulnerability check: Verify that systems running Zimbra Collaboration Suite, TrueConf Server, MLflow, or Ray-Project Ray are patched for their respective CVEs. Cross-reference your inventory against the NVD pages above to confirm version applicability.

Note: These queries were generated with AI assistance and are a starting point, not a verdict. A query that returns no results does not mean the threat is absent. Confirm that the referenced indexes, sourcetypes, and field names exist in your environment, that the relevant data is actually being ingested, and that names match your schema (watch for spelling and naming drift). Validate against your own ingest and audit trails before drawing conclusions.

Appendix: Raw Tables

Top Ransomware Groups (ransomware.live, August 24, 2026)

Group Victim Count Change from W33
Qilin32-13.5%
TheGentlemen28-9.7%
Direwolf21+40%
CoinbaseCartel16new to top 10
Storm12+20%
Incransom11new to top 10
Kazu9new to top 10
Titan8new to top 10
DYSPHOR1A7new to top 10
ShinyHunters6new to top 10

Most-Reported Malicious IPs (AbuseIPDB 100% confidence, August 24, 2026 at 20:00 UTC)

IP Address Country ASN / ISP Origin Type Total Reports Contributors
62.60.130.253GBCIPHER OPERATIONSdatacenter21,987784
41.181.156.205ZAAS16637 MTN SAresidential6,0981,130
185.223.235.2NLInfrawatch Limitedresidential2,586192
180.76.147.239CNBaidudatacenter1,081491
103.108.67.180HKAS401696 HUANGYUNdatacenter1,087413
77.42.49.249FIHetzner Online GmbHdatacenter317204

Attacker Networks (AlienVault OTX ASN, August 24, 2026)

ASN Provider Origin Class IP Count Total Reports
AS16637African Network Information Center / MTN SAresidential (compromised endpoints)16,098
AS401696cognetcloud INC / HUANGYUNdatacenter hosting11,087

New CISA KEV Entries (August 17-23, 2026)

CVE Vendor/Product Vulnerability Type Date Added Due Date OTX Pulse Count
CVE-2026-73570Synacor Zimbra Collaboration SuiteOS Command Injection2026-08-212026-08-242
CVE-2026-72530TrueConf ServerCode Injection2026-08-202026-09-030
CVE-2026-72529TrueConf ServerMissing Authentication2026-08-202026-08-230
CVE-2026-64849MLflowServer-Side Request Forgery2026-08-192026-09-023
CVE-2025-62593Ray-Project RayCode Injection2026-08-172026-08-204

Top Malware Families (abuse.ch ThreatFox, 3-day window ending August 24, 2026)

Family IOC Count
php.shin_webshell199
Overlord RAT150
VShell95
Remus56
Cobalt Strike55
Sliver49
Vidar45

Methodology & Sources

This weekly recap aggregates open-source threat intelligence feeds to provide a retrospective view of the ransomware, exploit, and malicious-infrastructure landscape for the week that just ended. Data is pulled from ransomware.live (victim ledger accumulated every six hours via automated collection), AbuseIPDB (point-in-time blacklist snapshot), CISA's Known Exploited Vulnerabilities catalog (filtered by date-added), and enrichment sources including GreyNoise Community, AlienVault OTX, Pulsedive, and abuse.ch ThreatFox. All figures are aggregate public statistics attributed to their upstream providers with inline pull dates, not Focused Hunts proprietary detections. Every published number, including chart values, traces back to the raw snapshot retained at output/weekly/data/2026-W34.json.

Week-over-week trends rely on successive snapshots and begin only once a prior week exists. When feed coverage is incomplete, affected totals are reported as a floor with the covered date range disclosed inline. Actor claims from ransomware leak sites are kept separate from confirmed CISA or abuse.ch listings. Enrichment data is best-effort and subject to API availability; unavailable sources are omitted rather than estimated. This methodology ensures every claim is reproducible and every limitation is transparent.

← Back to Last Week in Threats