Last Week in Threats: Week 34
Bottom Line
What changed this week: Ransomware activity remained flat at 242 victims, but the Direwolf group surged 40 percent to 21 victims while long-dominant Clop dropped out of the top ranks, and five new vulnerabilities joined the CISA Known Exploited Vulnerabilities catalog targeting collaboration platforms (Zimbra), video-conferencing servers (TrueConf), and machine-learning operations tools (MLflow, Ray).
Who is most exposed: Manufacturing organizations (42 victims this week, 17 percent of the total), companies running email collaboration suites, and technology teams operating ML-ops or distributed-computing platforms in cloud environments where server-side request forgery can expose credentials.
Recommended action: Patch CVE-2026-73570 (Zimbra), CVE-2026-64849 (MLflow), and CVE-2025-62593 (Ray) by their federal due dates, and hunt for anomalous outbound connections from collaboration and ML-ops servers that could indicate post-exploitation command-and-control activity.
The Week in Review
The week of August 17 to 23, 2026 marked a shift in the ransomware landscape despite flat overall volume. Direwolf surged 40 percent week-over-week to claim 21 victims, while Clop, which led the prior week with 46 postings, dropped out of the top ten entirely. Qilin and TheGentlemen remained the top two groups but both declined modestly. Manufacturing dominated the victim distribution with 42 organizations compromised, followed by technology and professional services sectors.
Five new entries joined the CISA Known Exploited Vulnerabilities catalog, a notable concentration in collaboration and developer tooling. Zimbra Collaboration Suite (CVE-2026-73570, command injection), MLflow (CVE-2026-64849, server-side request forgery enabling cloud credential theft), and Ray-Project Ray (CVE-2025-62593, code injection) all appeared in active AlienVault OTX threat pulses, signaling in-the-wild exploitation. TrueConf Server contributed two code-injection flaws. The pattern underscores adversary interest in platforms that bridge organizational boundaries (email, video conferencing) and that operate with elevated cloud privileges (ML-ops, distributed computing).
The week's most-reported malicious IP, 62.60.130.253 (Serbia, CIPHER OPERATIONS hosting), accumulated 21,987 reports from 784 distinct AbuseIPDB contributors. The top-six enriched IPs split evenly between datacenter hosting (4) and residential ISPs (2), consistent with a mixed infrastructure of rented servers and compromised home routers. None cross-referenced as active malware command-and-control hosts in ThreatFox or URLhaus data pulled the same day.
Ransomware Leak-Site Activity
242 victims posted to ransomware leak sites during the week of August 17-23, 2026, unchanged from the prior week but with a shifted group composition (ransomware.live aggregated from ledger, August 24).
- Top groups by victim count: Qilin (32, down from 37 the prior week), TheGentlemen (28, down from 31), Direwolf (21, up from 15, +40%), CoinbaseCartel (16, new to top ten), Storm (12, up from 10)
- Top victim countries: United States (75), unknown/undisclosed (26), Italy (18), Germany (10), Mexico (9)
- New groups this week: CoinbaseCartel, Kazu, Titan, DYSPHOR1A, ShinyHunters entered the top ten; Clop (46 victims last week) dropped out entirely
Sector & Technology Watch
Manufacturing organizations dominated the victim distribution at 42 postings (17 percent of the week), continuing a multi-week trend. The week's exploited vulnerabilities concentrated on collaboration platforms, video-conferencing infrastructure, and ML-ops tooling (ransomware.live victim descriptions, August 24; CISA KEV additions August 17-23).
- Most-targeted industries: Manufacturing (42), Technology (18), Professional Services (15), Education (8), Healthcare (7). Manufacturing held the top position for the second consecutive week, consistent with adversary focus on organizations operating 24/7 production lines that cannot tolerate downtime.
- Technology in the crosshairs: Collaboration and email platforms (Zimbra Collaboration Suite, CVE-2026-73570), video-conferencing infrastructure (TrueConf Server, CVE-2026-72530 and CVE-2026-72529), ML-ops and data-science tooling (MLflow CVE-2026-64849, Ray-Project Ray CVE-2025-62593). All five appeared in AlienVault OTX threat pulses as of August 24, confirming active exploitation.
- If you run Zimbra, MLflow, or Ray: Verify patch status for the CVEs above by their CISA due dates, and review authentication, network, and cloud IAM logs for post-exploitation indicators (anomalous outbound connections, IAM role assumption, bucket enumeration).
Most-Reported Malicious IPs
AbuseIPDB's 100-percent-confidence blacklist as of August 24, 2026 at 20:00 UTC returned 100 addresses. The top-reported IPs by cumulative community submissions:
- 62.60.130.253 (GB, CIPHER OPERATIONS hosting) — 21,987 reports from 784 contributors (AbuseIPDB, August 24)
- 41.181.156.205 (ZA, MTN residential ISP) — 6,098 reports from 1,130 contributors; reverse DNS ties to routemaster.co.za (AbuseIPDB / AlienVault OTX / Pulsedive, August 24)
- 185.223.235.2 (NL, Infrawatch residential ISP) — 2,586 reports from 192 contributors (AbuseIPDB, August 24)
- 180.76.147.239 (CN, Baidu datacenter/hosting) — 1,081 reports from 491 contributors (AbuseIPDB, August 24)
- 103.108.67.180 (HK, HUANGYUN hosting) — 1,087 reports from 413 contributors (AbuseIPDB / AlienVault OTX / Pulsedive, August 24)
Reported activity associated with these IPs includes SSH brute-force attempts, email and credential brute-force, port scanning, and web-application attacks (inferred from abuse category distribution, AbuseIPDB, August 24). GreyNoise Community tagged 41.181.156.205 and 103.108.67.180 as malicious with no benign-scanner classification (GreyNoise Community, August 24).
Context matters: The AbuseIPDB blacklist is a community-contributed snapshot and may include legitimate security-research scanners. Cross-reference any IP before blocking it in production.
Attacker Infrastructure & Networks
Infrastructure enrichment of the top six malicious IPs reveals a balanced split between datacenter hosting (4 IPs) and residential ISPs (2 IPs), indicating adversaries continue to operate from both rented servers and compromised home networks (AbuseIPDB usage-type field, August 24).
- Nastiest networks: AS16637 (African Network Information Center / MTN SA, 1 IP, residential ISP), AS401696 (cognetcloud INC / HUANGYUN, 1 IP, datacenter hosting). AlienVault OTX (ASN), August 24.
- Hosting vs. home: Four of six enriched IPs traced to datacenter or web-hosting providers; two traced to consumer residential ISPs (compromised endpoints, not malicious providers). When a large consumer ISP appears in malicious-IP rankings, the signal is compromised subscriber devices (routers, IoT), not provider misconduct.
- Also known malware infrastructure: None of the six enriched IPs appeared as active command-and-control hosts or malware-delivery servers in abuse.ch ThreatFox or URLhaus databases as of August 24. This week's top malicious IPs are scanning and brute-force sources, not confirmed C2 endpoints.
The genuine infrastructure risk this week is the datacenter hosting cut, where providers may host bulletproof or loosely monitored infrastructure. The residential ISP entries (AS16637 MTN SA) represent compromised home networks, not a malicious provider.
Exploited-Vulnerability Watch
CISA added five vulnerabilities to the Known Exploited Vulnerabilities catalog between August 17 and 23, 2026. All five carried active-exploitation evidence in the form of named threat pulses on AlienVault OTX as of August 24:
- CVE-2026-73570 — Synacor Zimbra Collaboration Suite, OS command injection; remediation due August 24 (CISA KEV, added August 21). AlienVault OTX pulse: "CVE-2026-73570 Zimbra SNMP Command Injection RCE Actively Exploited (KEV)" (2 pulses, OTX, August 24).
- CVE-2026-72530 — TrueConf Server, code injection; remediation due September 3 (CISA KEV, added August 20).
- CVE-2026-72529 — TrueConf Server, missing authentication for critical function; remediation due August 23 (CISA KEV, added August 20).
- CVE-2026-64849 — MLflow, server-side request forgery enabling cloud credential theft; remediation due September 2 (CISA KEV, added August 19). AlienVault OTX pulse: "MLflow CVE-2026-64849 SSRF Credential Theft + FUXA RCE Scanning" (3 pulses, OTX, August 24).
- CVE-2025-62593 — Ray-Project Ray, code injection; remediation due August 20 (CISA KEV, added August 17). AlienVault OTX pulse: "RondoDox Botnet: From Zero to 174 Exploited Vulnerabilities" (4 pulses, OTX, August 24).
Malware & C2
abuse.ch ThreatFox recorded 2,486 total indicators over a rolling three-day window as of August 24, 2026, including 874 fresh command-and-control IOCs (ThreatFox, August 24).
Top malware families by IOC volume (ThreatFox, 3-day window ending August 24): php.shin_webshell (199 IOCs), Overlord RAT (150), VShell (95), Remus (56), Cobalt Strike (55), Sliver (49), Vidar (45). Webshells (Shin) and legitimate red-team tools repurposed for adversary use (Cobalt Strike, Sliver) dominated the distribution, consistent with post-exploitation and persistence activity.
The Hunting Takeaway
Hunt for anomalous outbound connections from collaboration and ML-ops platforms. This week's KEV additions concentrated on internet-facing services that operate with elevated privileges: email servers (Zimbra), video-conferencing infrastructure (TrueConf), and machine-learning experiment-tracking platforms (MLflow, Ray) often deployed in cloud environments with IAM roles granting access to S3 buckets, databases, and compute resources.
The hunting angle: servers in these categories should not initiate arbitrary outbound connections to the internet. A Zimbra mail server connecting to an unknown external IP on port 443 or 4444, or an MLflow instance making HTTP requests to cloud metadata endpoints or S3 buckets it does not own, is a post-exploitation indicator. Hunt for this in proxy logs, firewall logs, and cloud VPC flow logs.
The MLflow SSRF flaw (CVE-2026-64849) explicitly enables cloud credential theft via the instance metadata service, so cross-reference any suspicious MLflow or Ray traffic with CloudTrail (AWS), Azure Activity Log, or GCP Cloud Audit Logs for IAM role assumption, bucket enumeration, or secret-manager access from unexpected source IPs.
This is a described behavioral hunt rather than a full query implementation. The specific log sources and field names vary widely by environment (firewall vendor, cloud provider, SIEM normalization). Focus on identifying servers in the affected technology classes, then filtering their outbound traffic for connections to IP ranges outside your known infrastructure.
Check Your Environment
IP sweep: Search your logs for connections involving this week's high-confidence malicious IPs. The sweep excludes 185.223.235.2 (Infrawatch), which may be a legitimate security-research scanner despite its AbuseIPDB listing.
Splunk SPL:
index=firewall OR index=proxy OR index=netflow
(src_ip IN ("41.181.156.205", "103.108.67.180", "180.76.147.239", "62.60.130.253", "77.42.49.249")
OR dest_ip IN ("41.181.156.205", "103.108.67.180", "180.76.147.239", "62.60.130.253", "77.42.49.249"))
| stats count by src_ip, dest_ip, dest_port, action
| sort - count
Microsoft KQL (Sentinel / Defender):
union DeviceNetworkEvents, CommonSecurityLog, AzureNetworkAnalytics_CL
| where RemoteIP in ("41.181.156.205", "103.108.67.180", "180.76.147.239", "62.60.130.253", "77.42.49.249")
or LocalIP in ("41.181.156.205", "103.108.67.180", "180.76.147.239", "62.60.130.253", "77.42.49.249")
| summarize Count=count() by LocalIP, RemoteIP, RemotePort, ActionType
| order by Count desc
Vulnerability check: Verify that systems running Zimbra Collaboration Suite, TrueConf Server, MLflow, or Ray-Project Ray are patched for their respective CVEs. Cross-reference your inventory against the NVD pages above to confirm version applicability.
Note: These queries were generated with AI assistance and are a starting point, not a verdict. A query that returns no results does not mean the threat is absent. Confirm that the referenced indexes, sourcetypes, and field names exist in your environment, that the relevant data is actually being ingested, and that names match your schema (watch for spelling and naming drift). Validate against your own ingest and audit trails before drawing conclusions.
Appendix: Raw Tables
Top Ransomware Groups (ransomware.live, August 24, 2026)
| Group | Victim Count | Change from W33 |
|---|---|---|
| Qilin | 32 | -13.5% |
| TheGentlemen | 28 | -9.7% |
| Direwolf | 21 | +40% |
| CoinbaseCartel | 16 | new to top 10 |
| Storm | 12 | +20% |
| Incransom | 11 | new to top 10 |
| Kazu | 9 | new to top 10 |
| Titan | 8 | new to top 10 |
| DYSPHOR1A | 7 | new to top 10 |
| ShinyHunters | 6 | new to top 10 |
Most-Reported Malicious IPs (AbuseIPDB 100% confidence, August 24, 2026 at 20:00 UTC)
| IP Address | Country | ASN / ISP | Origin Type | Total Reports | Contributors |
|---|---|---|---|---|---|
| 62.60.130.253 | GB | CIPHER OPERATIONS | datacenter | 21,987 | 784 |
| 41.181.156.205 | ZA | AS16637 MTN SA | residential | 6,098 | 1,130 |
| 185.223.235.2 | NL | Infrawatch Limited | residential | 2,586 | 192 |
| 180.76.147.239 | CN | Baidu | datacenter | 1,081 | 491 |
| 103.108.67.180 | HK | AS401696 HUANGYUN | datacenter | 1,087 | 413 |
| 77.42.49.249 | FI | Hetzner Online GmbH | datacenter | 317 | 204 |
Attacker Networks (AlienVault OTX ASN, August 24, 2026)
| ASN | Provider | Origin Class | IP Count | Total Reports |
|---|---|---|---|---|
| AS16637 | African Network Information Center / MTN SA | residential (compromised endpoints) | 1 | 6,098 |
| AS401696 | cognetcloud INC / HUANGYUN | datacenter hosting | 1 | 1,087 |
New CISA KEV Entries (August 17-23, 2026)
| CVE | Vendor/Product | Vulnerability Type | Date Added | Due Date | OTX Pulse Count |
|---|---|---|---|---|---|
| CVE-2026-73570 | Synacor Zimbra Collaboration Suite | OS Command Injection | 2026-08-21 | 2026-08-24 | 2 |
| CVE-2026-72530 | TrueConf Server | Code Injection | 2026-08-20 | 2026-09-03 | 0 |
| CVE-2026-72529 | TrueConf Server | Missing Authentication | 2026-08-20 | 2026-08-23 | 0 |
| CVE-2026-64849 | MLflow | Server-Side Request Forgery | 2026-08-19 | 2026-09-02 | 3 |
| CVE-2025-62593 | Ray-Project Ray | Code Injection | 2026-08-17 | 2026-08-20 | 4 |
Top Malware Families (abuse.ch ThreatFox, 3-day window ending August 24, 2026)
| Family | IOC Count |
|---|---|
| php.shin_webshell | 199 |
| Overlord RAT | 150 |
| VShell | 95 |
| Remus | 56 |
| Cobalt Strike | 55 |
| Sliver | 49 |
| Vidar | 45 |
Methodology & Sources
This weekly recap aggregates open-source threat intelligence feeds to provide a retrospective view of the ransomware, exploit, and malicious-infrastructure landscape for the week that just ended. Data is pulled from ransomware.live (victim ledger accumulated every six hours via automated collection), AbuseIPDB (point-in-time blacklist snapshot), CISA's Known Exploited Vulnerabilities catalog (filtered by date-added), and enrichment sources including GreyNoise Community, AlienVault OTX, Pulsedive, and abuse.ch ThreatFox. All figures are aggregate public statistics attributed to their upstream providers with inline pull dates, not Focused Hunts proprietary detections. Every published number, including chart values, traces back to the raw snapshot retained at output/weekly/data/2026-W34.json.
Week-over-week trends rely on successive snapshots and begin only once a prior week exists. When feed coverage is incomplete, affected totals are reported as a floor with the covered date range disclosed inline. Actor claims from ransomware leak sites are kept separate from confirmed CISA or abuse.ch listings. Enrichment data is best-effort and subject to API availability; unavailable sources are omitted rather than estimated. This methodology ensures every claim is reproducible and every limitation is transparent.
