Last Week in Threats: Week 35
Bottom Line
What changed: Qilin ransomware surged 31% week-over-week to dominate the threat landscape, even as overall ransomware victim volume dropped 14.5% and seven new groups entered the top ten.
Who is most exposed: Organizations running developer tooling (JFrog Artifactory, Gitea), infrastructure systems (Linux Kernel, Red Hat), and edge appliances (Citrix NetScaler) face active exploitation of 11 newly cataloged vulnerabilities, with three already weaponized in an AI-driven campaign.
Recommended action: Patch the August 24-30 CISA KEV additions immediately and audit outbound traffic from developer environments for signs of data exfiltration tied to Qilin's accelerating operations.
The Week in Review
The week of August 24 to 30, 2026 marked a sharp divergence in the ransomware landscape. Overall victim postings fell to 207 (down from 242 the prior week, a 14.5% decline), but Qilin bucked the trend with a 31% surge to 42 victims, consolidating its position as the week's dominant threat actor. The drop in aggregate volume coincided with a reshuffling of the top ten, where seven new groups displaced established players, signaling an increasingly fragmented and competitive extortion ecosystem.
CISA added 11 vulnerabilities to the KEV catalog, heavily targeting developer and infrastructure environments. Three older CVEs (CVE-2021-23758, CVE-2015-3246, CVE-2015-5287) appeared in an AlienVault OTX pulse tied to a Chinese-speaking adversary integrating agentic AI into post-compromise operations, demonstrating that even legacy flaws remain actively weaponized when attackers adopt new tooling. The week's malicious IP snapshot showed a 71% hosting-to-residential split, with one address (45.148.10.157) accumulating 213,681 abuse reports, the highest volume of the week by an order of magnitude.
Ransomware Leak-Site Activity
Qilin's surge: Qilin posted 42 victims in the week ending August 30, up from 32 the prior week (a 31% increase, per ransomware.live as of August 31, 2026). This surge occurred while the overall ransomware volume fell 14.5%, making Qilin's momentum the clearest counter-trend signal of the week. With 2,248 total historical victims, Qilin remains one of the most prolific groups active today.
Reshuffled top ten: Seven groups entered the top ten this week, including krybit at #3 with 13 victims, akira at #4 with 12, and SilentRansomGroup at #5 with 10. TheGentlemen dropped from 28 to 21 victims (down 25%), and direwolf fell from #3 to #9. The churn reflects an increasingly competitive and fragmented extortion landscape where no single group outside Qilin maintained week-over-week growth.
Geography: The United States remained the top target country with 54 victims, followed by 36 whose country could not be determined from public postings. The UK, Germany, and Mexico each saw 8-14 victims.
Sector & Technology Watch
This week's CISA KEV additions concentrated risk in two technology classes: infrastructure and developer environments.
Infrastructure/OS (4 CVEs): Two Linux Kernel vulnerabilities (CVE-2026-53362, CVE-2022-0995) and two Red Hat privilege-escalation flaws (CVE-2015-3246 in Libuser, CVE-2015-5287 in the Automatic Bug Reporting Tool) expose enterprise Linux deployments. The Red Hat CVEs, though years old, appeared in 9-10 AlienVault OTX pulses tied to a Chinese-speaking adversary using agentic AI in post-compromise operations (per AlienVault OTX as of August 31, 2026), proving that legacy infrastructure remains a live target when combined with modern attack tooling.
Developer tooling (2 CVEs): JFrog Artifactory (CVE-2026-66384, path traversal) and Gitea (CVE-2026-60004, code injection) both enable attackers to compromise software supply chains. The Artifactory flaw was linked to one OTX pulse describing an ownCloud exploit used to steal nuclear records from a Philippine research body (per AlienVault OTX as of August 31, 2026).
Also targeted: Citrix NetScaler edge appliances (CVE-2026-8452), Microsoft SQL Server (CVE-2019-1068), Oracle HTTP Server and WebLogic (CVE-2026-21962), Ajax.NET (CVE-2021-23758), and ownCloud file-sharing (CVE-2023-49105).
Directive: If you run developer tooling or Linux infrastructure, prioritize the CVEs with CISA due dates of August 27-30 (already passed) and September 9-10. Audit artifact repositories and CI/CD pipelines for unauthorized access or modified packages.
IOC Watch: Most-Reported Malicious IPs
AbuseIPDB's blacklist as of August 31, 2026 (20:27 UTC) returned 100 addresses at 100% confidence. Ranked by total reports (the true activity signal, since confidence is constant), the top addresses this week were:
- 45.148.10.157 (NL): 213,681 reports from 918 distinct users, TECHOFF SRV LIMITED (hosting). This address dominated the week's abuse volume by an order of magnitude. GreyNoise: malicious.
- 62.60.130.253 (LT): 38,337 reports from 822 users, Cipher Operations (hosting). GreyNoise: malicious.
- 178.27.90.142 (DE): 6,463 reports from 1,155 users, Vodafone GmbH (residential ISP). This is a compromised home network endpoint, not a malicious provider. GreyNoise: malicious.
- 192.42.116.15 (NL): 698 reports from 287 users, confirmed Tor exit node operated by Church of Cyberology (per AbuseIPDB as of August 31, 2026). GreyNoise: malicious.
- 44.212.15.65 (US): 470 reports from 189 users, Amazon AWS (hosting). GreyNoise: suspicious.
Benign scanner caveat: 66.132.186.214 appeared in the AbuseIPDB blacklist with 4,471 reports, but GreyNoise confirmed it as a benign Censys scanner (per GreyNoise community tier as of August 31, 2026). Reports against scanner infrastructure reflect network reconnaissance, not malicious activity. This address is excluded from the malicious count.
Behavior analysis (inferred from AbuseIPDB categories, not shown in detail) indicates the week's IPs concentrated on SSH brute-force, email/credential attacks, and port scanning.
Attacker Infrastructure & Networks
Network ownership: The 14 enriched malicious IPs (excluding the benign Censys scanner) distributed across 9 unique ASNs, with no single network contributing more than one address. The dispersion reflects a highly distributed threat landscape this week rather than concentrated bulletproof hosting. Top networks by report volume (not count): AS48090 (Techoff Srv Limited, 1 IP with 213k reports) and AS215930 (Cipher Operations, 1 IP with 38k reports) (per AlienVault OTX ASN data as of August 31, 2026).
Hosting vs. residential: 71% of this week's malicious IPs (10/14) originated from data center/hosting environments, while 29% (4/14) came from residential ISPs (per AbuseIPDB usage-type as of August 31, 2026). The residential cut includes 178.27.90.142 (Vodafone Germany), a compromised consumer endpoint with 6,463 reports. When a residential ISP tops the abuse list, it indicates compromised home devices, not a malicious provider.
Infrastructure correlation: Cross-referencing the week's top IPs against ThreatFox and URLhaus showed no overlap with active C2 or malware-hosting infrastructure (per abuse.ch as of August 31, 2026). The week's malicious IPs concentrated on network scanning and credential attacks rather than malware distribution.
Tor presence: 192.42.116.15 is a known Tor exit node, contributing 698 reports. Tor-sourced abuse reflects anonymized attacker traffic rather than a compromised endpoint.
Exploited-Vulnerability Watch
CISA added 11 CVEs to the Known Exploited Vulnerabilities catalog between August 24 and 30, 2026 (per CISA KEV feed pulled August 31, 2026):
Active weaponization signals (AlienVault OTX pulse search as of August 31, 2026):
- CVE-2021-23758 (Ajax.NET deserialization): 9 pulses, including "Chinese-speaking adversary integrates agentic AI into post-compromise operations"
- CVE-2015-3246 (Red Hat Libuser race condition): 10 pulses, same AI-driven campaign
- CVE-2015-5287 (Red Hat ABRT privilege escalation): 9 pulses, same campaign
- CVE-2022-0995 (Linux Kernel out-of-bounds write): 12 pulses
- CVE-2026-66384 (JFrog Artifactory path traversal): 1 pulse, "ownCloud Flaw Exploited to Steal Nuclear Records From Philippine Research Body"
Recently added (weaponization not yet confirmed in OTX):
- CVE-2023-49105 (ownCloud authentication), due Aug 30
- CVE-2026-53362 (Linux Kernel), due Aug 30
- CVE-2026-8452 (Citrix NetScaler buffer overflow), due Aug 29
- CVE-2019-1068 (Microsoft SQL Server RCE), due Aug 29
- CVE-2026-60004 (Gitea code injection), due Aug 28
- CVE-2026-21962 (Oracle HTTP Server/WebLogic access control), due Aug 27
The Hunting Takeaway
Hunt for data exfiltration from developer environments tied to Qilin's surge. Qilin's 31% week-over-week increase, combined with two CISA KEV additions in developer tooling (JFrog Artifactory, Gitea), points to supply-chain compromise as a likely vector. Qilin has historically targeted large enterprises where source-code theft or artifact poisoning provides high-value ransom leverage.
Telemetry to hunt:
- Outbound connections from artifact repositories (Artifactory, Nexus) or Git servers to non-business IPs
- Unusual volume or timing of file downloads from internal package registries
- New SSH keys or API tokens created in CI/CD systems
- External DNS queries or HTTP requests from build agents to paste sites, file-sharing services, or newly registered domains
- Sudden increases in egress traffic volume from developer VLAN segments
Query example (Splunk SPL):
index=proxy (src_ip="artifact-repo-subnet/*" OR src_ip="cicd-subnet/*")
| where NOT match(dest, "known-good-domains")
| stats count, sum(bytes_out) as egress_bytes by src_ip, dest, user
| where egress_bytes > 10485760
| sort - egress_bytes
Query example (Microsoft KQL):
CommonSecurityLog
| where DeviceVendor == "Palo Alto Networks" or DeviceVendor == "Fortinet"
| where SourceIP has_any ("10.50.0.0/24", "10.60.0.0/24")
| where DestinationIP !has_any ("github.com", "gitlab.com", "known-artifact-cdn")
| summarize EgressMB = sum(SentBytes) / 1048576, ConnectionCount = count() by SourceIP, DestinationHostName, DestinationIP
| where EgressMB > 10
| order by EgressMB desc
Note: These queries were generated with AI assistance and are a starting point, not a verdict. A query that returns no results does not mean the threat is absent. Confirm that the referenced indexes, sourcetypes, and field names exist in your environment, that the relevant data is actually being ingested, and that names match your schema (watch for spelling and naming drift). Validate against your own ingest and audit trails before drawing conclusions.
Check Your Environment
Malicious IP sweep: Check firewall, proxy, and authentication logs for connections involving this week's high-confidence malicious IPs (excluding the benign Censys scanner and the Tor exit node, which may appear in legitimate traffic):
Splunk SPL:
index=firewall OR index=proxy OR index=auth
| where src_ip IN ("45.148.10.157", "62.60.130.253", "178.27.90.142", "44.212.15.65", "180.183.245.232", "192.144.140.170", "77.239.124.203", "40.119.43.218", "125.229.165.119", "20.121.117.218")
OR dest_ip IN ("45.148.10.157", "62.60.130.253", "178.27.90.142", "44.212.15.65", "180.183.245.232", "192.144.140.170", "77.239.124.203", "40.119.43.218", "125.229.165.119", "20.121.117.218")
| stats count by src_ip, dest_ip, action, user, timestamp
| sort - count
Microsoft KQL:
union CommonSecurityLog, SigninLogs, AzureActivity
| where TimeGenerated >= ago(7d)
| where SourceIP in ("45.148.10.157", "62.60.130.253", "178.27.90.142", "44.212.15.65", "180.183.245.232", "192.144.140.170", "77.239.124.203", "40.119.43.218", "125.229.165.119", "20.121.117.218")
or DestinationIP in ("45.148.10.157", "62.60.130.253", "178.27.90.142", "44.212.15.65", "180.183.245.232", "192.144.140.170", "77.239.124.203", "40.119.43.218", "125.229.165.119", "20.121.117.218")
| project TimeGenerated, SourceIP, DestinationIP, UserPrincipalName, Activity, ResultDescription
| order by TimeGenerated desc
Vulnerability check: Cross-reference the 11 CISA KEV CVEs added August 24-30 against your asset inventory. For each confirmed presence, prioritize patching by the CISA due date (several have already passed as of August 31): CVE-2023-49105 (ownCloud), CVE-2026-53362 (Linux Kernel), CVE-2026-66384 (JFrog Artifactory), CVE-2021-23758 (Ajax.NET), CVE-2015-3246 and CVE-2015-5287 (Red Hat), CVE-2022-0995 (Linux Kernel), CVE-2026-8452 (Citrix NetScaler), CVE-2019-1068 (Microsoft SQL Server), CVE-2026-60004 (Gitea), CVE-2026-21962 (Oracle HTTP/WebLogic). See the KEV catalog and each CVE's NVD page for patch links.
Note: These queries were generated with AI assistance and are a starting point, not a verdict. A query that returns no results does not mean the threat is absent. Confirm that the referenced indexes, sourcetypes, and field names exist in your environment, that the relevant data is actually being ingested, and that names match your schema (watch for spelling and naming drift). Validate against your own ingest and audit trails before drawing conclusions.
Appendix: Data Tables
Table A: Top Ransomware Groups (ransomware.live, August 31, 2026)
| Rank | Group | Victims |
|---|---|---|
| 1 | qilin | 42 |
| 2 | thegentlemen | 21 |
| 3 | krybit | 13 |
| 4 | akira | 12 |
| 5 | SilentRansomGroup | 10 |
| 6 | Dark Project | 6 |
| 7 | chaos | 6 |
| 8 | lockbit5 | 6 |
| 9 | direwolf | 5 |
| 10 | Orova | 5 |
Table B: Most-Reported Malicious IPs (AbuseIPDB, August 31, 2026)
| Rank | IP Address | Total Reports | ISP | Origin |
|---|---|---|---|---|
| 1 | 45.148.10.157 | 213,681 | TECHOFF SRV LIMITED | hosting |
| 2 | 62.60.130.253 | 38,337 | CIPHER OPERATIONS DOO BEOGRAD - NOVI BEOGRAD | hosting |
| 3 | 178.27.90.142 | 6,463 | Vodafone GmbH | residential |
| 4 | 192.42.116.15 | 698 | TOR EXIT AND MORE | hosting |
| 5 | 44.212.15.65 | 470 | Amazon Data Services Northern Virginia | hosting |
| 6 | 180.183.245.232 | 462 | Triple T Broadband Public Company Limited | residential |
| 7 | 192.144.140.170 | 397 | Tencent Cloud Computing (Beijing) Co., Ltd | hosting |
| 8 | 77.239.124.203 | 287 | ROCKET & MARINICA LTD | hosting |
| 9 | 20.121.117.218 | 139 | Microsoft Corporation | hosting |
| 10 | 130.12.182.196 | 115 | Netiface LLC | hosting |
Table C: New CISA KEV Entries (August 24-30, 2026)
| CVE ID | Product | Due Date |
|---|---|---|
| CVE-2023-49105 | ownCloud ownCloud | 2026-08-30 |
| CVE-2026-53362 | Linux Kernel | 2026-08-30 |
| CVE-2026-66384 | JFrog Artifactory | 2026-09-10 |
| CVE-2021-23758 | Ajax.NET Professional Ajax.NET Professional | 2026-09-09 |
| CVE-2015-3246 | Red Hat Libuser | 2026-09-09 |
| CVE-2015-5287 | Red Hat Automatic Bug Reporting Tool | 2026-09-09 |
| CVE-2022-0995 | Linux Kernel | 2026-09-09 |
| CVE-2026-8452 | Citrix NetScaler ADC and NetScaler Gateway | 2026-08-29 |
| CVE-2019-1068 | Microsoft SQL Server | 2026-08-29 |
| CVE-2026-60004 | Gitea Gitea | 2026-08-28 |
| CVE-2026-21962 | Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in | 2026-08-27 |
Methodology & Sources
This weekly recap aggregates open-source threat intelligence from ransomware.live, AbuseIPDB, and the CISA KEV catalog, with enrichment from GreyNoise (community tier), AlienVault OTX, Pulsedive (community tier), and abuse.ch. Figures represent aggregate public statistics captured at a point in time (August 31, 2026) rather than Focused Hunts detections, and all claims trace back to the raw snapshot retained at output/weekly/data/2026-W35.json. Week-over-week trends compare against the prior edition's snapshot (2026-W34.json).
Ransomware victim counts derive from the rolling ledger accumulated every six hours from ransomware.live; this week's total (207) represents the full Monday-Sunday window of August 24-30 with complete coverage (no missing days). AbuseIPDB's blacklist is a point-in-time snapshot, not a cumulative week; IP rankings use total reports and distinct user counts as the activity signal. CISA KEV entries are filtered by dateAdded falling within the window. Where sources were unavailable (OTX timeouts on several CVE pulse searches) or operate in degraded modes (GreyNoise and Pulsedive community tiers), the limitation is noted inline and affected sections are either omitted or presented with reduced confidence. All provider names, pull dates, and per-figure attributions appear inline in the body and appendix; actor claims (e.g., ransomware group postings) are kept separate from confirmed external listings.
