Weekly Report
Period: Week 33, 2026 (2026-08-03 — 2026-08-10)
Summary
The week was defined by active exploitation of critical vulnerabilities in widely deployed enterprise infrastructure — CISA's addition of a JetBrains TeamCity flaw (CVE-2026-63077) to its Known Exploited Vulnerabilities catalog [6], and confirmed exploitation of a critical flaw in N-able's N-central platform tied to a new Russian-linked loader service, DOUBLECUP [8]. Veeam disclosed ten CVEs affecting Veeam ONE and Veeam Service Provider Console, including a maximum-severity remote-code-execution flaw (CVE-2026-64633, CVSS 10.0) [7]. An unverified claim of a 135,000-record breach of the UK Police National Legal Database by ExfilSquad also emerged, with officer-safety implications if confirmed [2].
Patterns and Trends
The week shows a convergence of two tracks: rapid exploitation of newly disclosed vulnerabilities in management and monitoring software (TeamCity, Veeam, N-central), and continued ransomware/data-leak activity against government and critical-business targets across multiple regions. Suspected Russian state-linked tradecraft (DOUBLECUP, APT29-style techniques) appears alongside government-targeted phishing campaigns (Larva-24009), suggesting overlapping interest in initial-access operations against public-sector networks [4][8]. Compared to prior weeks, the volume of near-simultaneous critical CVE disclosures with confirmed active exploitation (CISA KEV, Veeam, N-able) stands out, indicating compressed patch windows for defenders. Data-leak claims from criminal groups (ExfilSquad, Blacknevas) remain at moderate-to-unverified reliability, underscoring a continued gap between claimed and confirmed breach scope.
International (K2/K3)
The week under review was dominated by active exploitation of critical vulnerabilities across widely deployed enterprise software, alongside a series of ransomware and data-leak claims spanning Taiwan, Hungary, the United Kingdom, and Northern Cyprus. On 2026-08-05, CISA added CVE-2026-63077, a deserialization vulnerability in JetBrains TeamCity, to its Known Exploited Vulnerabilities catalog, citing evidence of active exploitation and mandating remediation for federal agencies under its Binding Operational Directive [6]. Separately, Veeam disclosed ten CVEs affecting Veeam ONE 13.1 and Veeam Service Provider Console 9.3, including CVE-2026-64633 (CVSS 10.0), which allows remote unauthenticated code execution on the agent host, and CVE-2026-58073 (CVSS 9.5), enabling impersonation via the Service Provider Console; official fixes have been released [7]. N-able also confirmed active exploitation of a critical flaw in its N-central platform (CVE-2026-18577), reported alongside emergence of a new Russian-linked loader service dubbed DOUBLECUP, which reporting links to APT29 tradecraft using fake login pages and disguised image files for initial access [8].
On the ransomware and data-theft front, Taiwan-based First Tek confirmed disruption to its operations following a ransomware attack, cited as part of a broader escalation of destructive intrusions against critical businesses, with LockBit and Qilin named among active groups in the wider criminal ecosystem [1]. In the United Kingdom, a threat actor calling itself ExfilSquad claimed on 2026-08-03 to have exfiltrated roughly 135,000 records from the UK Police National Legal Database, allegedly including names, work emails, and organizational data tied to police officers and legal-sector staff, raising concerns over officer safety should the claim be verified (C2 — unverified dark-web claim) [2]. In Hungary, the State Treasury's agricultural development network was reported compromised, described alongside an expanding phishing and malware campaign attributed to the Larva-24009 cluster targeting government networks internationally [4]. In Northern Cyprus, the Arkın hotel and casino group was reported to have suffered a breach in which the Blacknevas group claims to have exfiltrated over one terabyte of guest and casino data from its Arkın Colony, Arkın Iskele, and Arkın Palm Beach properties (B2 — usually reliable, probably true) [5].
The EU's CERT-EU published its monthly Cyber Brief for July 2026, citing INC Ransom and Play among ransomware operators active against European targets, alongside continued exploitation activity linked to SharePoint (A2 — completely reliable, confirmed) [3].
Assessment
Given that CISA and Veeam both confirmed active or catalogued exploitation of remote-code-execution flaws in widely used enterprise infrastructure and monitoring tools within the same week [6][7], it is likely (60-90%) that unpatched instances of TeamCity and Veeam ONE/Service Provider Console will be targeted by additional actors before organizations complete remediation. The reported use of DOUBLECUP and N-central exploitation by suspected Russian-linked operators [8], combined with expanding government-targeted campaigns such as Larva-24009 [4], suggests a possible (20-60%) continuation of state-linked initial-access operations against government and managed-service-provider networks in the near term. The UK police data leak claim remains unverified at C2 reliability and should be treated with caution pending confirmation from UK authorities [2].
Follow-up Items
- CVE-2026-63077 (JetBrains TeamCity) — added to CISA KEV catalog on 2026-08-05; remediation mandated for US federal agencies under Binding Operational Directive [6].
- CVE-2026-64633 (CVSS 10.0) and CVE-2026-58073 (CVSS 9.5) — affecting Veeam ONE 13.1 and Veeam Service Provider Console 9.
- CVE-2026-18577 (N-able N-central) — active exploitation confirmed; linked to DOUBLECUP loader activity attributed to suspected APT29 tradecraft [8].
- ExfilSquad's claimed breach of the UK Police National Legal Database (~135,000 records, claimed 2026-08-03) — remains unverified (C2); confirmation from UK authorities pending [2].
- CERT-EU's July 2026 Cyber Brief names INC Ransom and Play as active ransomware operators against European targets, alongside ongoing SharePoint exploitation — monitor for follow-up EU advisories [3].
Warning: Automated verification detected multiple potential inaccuracies. Please verify all claims against the original articles.
Generated 2026-08-10 04:43 UTC from 10 priority articles (8 cited).
[1] undercodenews.com — https://undercodenews.com/first-tek-ransomware-attack-disrupts-taiwan-operations-a-growing-warning-about-the-global-cybercrime-landscape-video/
[2] undercodenews.com — https://undercodenews.com/exfilsquad-claims-massive-uk-police-data-leak-raising-fresh-fears-over-officer-safety-video/
[3] cert.europa.eu — https://cert.europa.eu/publications/threat-intelligence/cb26-08/
[4] undercodenews.com — https://undercodenews.com/hungary-treasury-cyberattack-exposes-growing-threat-to-government-networks-as-larva-24009-expands-global-malware-campaigns-video/
[5] ransomware.live — https://www.ransomware.live/id/QXJrxLFuIEdyb3VwIC8gQXJrxLFuIENhc2lubywgVGhlIEFya8SxbiBDb2xvbnksIFRoZSBBcmvEsW4gSXNrZWxlLCBhbmQgQXJrxLFuIFBhbG0gQmVhY2hAYmxhY2tuZXZhcw==
[6] us-cert.gov — https://www.cisa.gov/news-events/alerts/2026/08/05/cisa-adds-one-known-exploited-vulnerability-catalog
[7] ncsc.fi — https://www.veeam.com/kb4892
[8] undercodenews.com — https://undercodenews.com/doublecup-emerges-as-a-dangerous-russian-loader-service-while-n-able-battles-active-exploitation-of-a-critical-n-central-flaw-video/