Sponsored by

~7 MIN READ
Fact More than 22,000 Citrix NetScaler ADC appliances and 1,800 NetScaler Gateway instances are still sitting exposed on the public internet and actively exploitable, per Shadowserver. (BleepingComputer, August 2026)
The Signal
 
The line between attacker and tool keeps blurring, last week an AI coding assistant ran a ransomware gang's recon, while plain old extortion still knocked out a capital city's services. Here's what changed, and one patch deadline you may have already missed.

PS: Was this forwarded to you? Subscribe free at exzeccyber.com/subscribe

In this edition
  📌 Big Cyber News
  🚨 Can't Miss
  🤖 AI in Cyber
  🕵️ Threat Intel
  🛠️ Tools & Tactics
  🧪 Strange Cyber
📌 Big Cyber News
 
GOVERNMENT RANSOMWARE
💸 Berlin's Government Got Blackmailed, and the Bill Is 30 Bitcoin
Intro
Rhysida wanted €2 million from the government of a G7 capital. Berlin's answer, in front of cameras, was basically "try and stop us."
What Happened
On August 14, ransomware group Rhysida knocked several Berlin state departments offline, hardest hit was housing benefits, dark for a week. Rhysida demanded 30 bitcoin (about €2 million) in a leak-site post, claiming it stole 5.79 terabytes on 12,000+ people. Berlin hasn't verified that figure but confirms personal data may be included.
Why It Matters
This is the capital of Germany, weeks before its state election, with residents unable to get housing payments processed. Ransomware hitting government services lands on citizens who never chose to be a target.
The Other Side
Rhysida's numbers are unverified, and the group has overstated hauls before (British Library, 2023, demanded 20 bitcoin, dumped the files anyway). Officials insist the September 20 election itself is unaffected.
 
👉 Takeaway
Refusing to pay is right, but it still leaves real people without benefits for a week. Government IT needs bank-speed incident response, not permit-office speed.
TL;DR: A ransomware gang demanded €2 million from Berlin's state government after knocking out housing-benefit systems for a week; the city refused to pay.
Further reading: The Local
🚨 Can't Miss
 
 
GOVERNMENT BREACH
Latvia's road agency, CSDD, was breached by attackers who accessed payment records on roughly two thirds of the country, about 1.2 million people and 200,000 businesses, some dating to 2008. The supervisory board resigned within a day; the chief said he's stepping down once the probe wraps. Mandatory security requirements weren't met, and CSDD is now blaming its IT contractor, who disputes it.
When two thirds of a country is in one breach, "we'll do better" isn't enough, someone has to own the fix.
 
TRAVEL BREACH
Hackers hit systems tied to Manchester, Stansted, and East Midlands airports, pulling emails, phone numbers, plates, and postcodes from parking, lounge, and Wi-Fi sign-ups. No payment data taken, operations undisrupted, but no group has claimed it yet. MAG pulled its Manage My Booking portal offline as a precaution.
Expect a wave of phishing texts pretending to be MAG support, that's usually next.
 
RETAIL BREACH
ShinyHunters claimed 25.8 million stolen Carhartt records and a $3.3 million demand. Troy Hunt at Have I Been Pwned checked the data and found only 12.9 million were real, the rest was fake .edu addresses, impossible birthdates, and customers "in" Montenegro who never were.
Extortion gangs inflate scale to juice the ransom, verify the numbers before you panic or pay.

How AI-Era Pricing Is Reshaping Finance Operations

Usage-based and hybrid pricing models are changing how B2B companies generate revenue — and creating new headaches for the finance teams behind them.

Tabs co-founder Rebecca Schwartz and PwC Partner Amit Dhir sat down to unpack exactly what that means in practice: how pricing model decisions ripple into revenue recognition, forecasting, and financial ops — and what it takes to scale without piling on manual work.

Watch the on-demand recording to get practical frameworks, real-world examples, and a clear path to operationalizing usage-based revenue — including a forward-looking take on how AI will reshape financial workflows. If your team is navigating pricing complexity heading into the back half of the year, this is worth an hour.

🤖 AI in Cyber
 
 
AI-ASSISTED RANSOMWARE
Researchers at Gambit found a ransomware affiliate running Cursor Agent, an AI coding tool built on Claude Sonnet, to scan networks, crack certificates, and move through at least 10 compromised environments. The AI wasn't hacked, it was just handed valid credentials and pointed at a target like any other employee tool. The group also shipped a new Linux strain built to hit VMware ESXi servers.
If an AI assistant can do recon and lateral movement with stolen credentials, treat any AI tool with system access like a privileged account, because it is one.
 
AI VULNERABILITY
ServiceNow patched three maximum-severity AI Platform flaws: two let unauthenticated attackers run arbitrary code, one allowed SQL injection into the underlying database. No exploitation spotted yet, and patches are out for hosted and self-hosted customers. Unauthenticated code execution in a platform this widely used tends to get weaponized eventually.
Running ServiceNow's AI Platform? Patch now, before someone builds the proof of concept for you.
🕵️ Threat Intel
 
 
STATE-SPONSORED
US authorities seized domains for QScan and QTRouter, hacking platforms allegedly built by a Nanjing company staffed with former Chinese military personnel. The campaign ran 2018 through at least this June, hitting NASA, the Fed, the Senate, DOE, DOJ, HHS, hospitals, telecoms, utilities, plus failed scans of a US election system. Most high-value attempts reportedly failed, but the target list itself is the story.
State-sponsored groups scan everything, even targets they never breach, patch and monitor accordingly.
 
STATE-SPONSORED
EU officials say state-linked hackers, widely believed Russian, are targeting diplomats directly on Signal and WhatsApp, posing as the apps' own support staff to harvest account PINs. The EU's cybersecurity board logged eight significant incidents in H1 2026 alone, and says 190+ threat actors have targeted the bloc in the past year. No malware, no exploits, just a well-timed message pretending to be tech support.
Signal and WhatsApp will never ask for your PIN in a chat, treat any message claiming otherwise as an attack.
🛠️ Tools & Tactics
 
 
Practical play
CVE-2026-8452 in Citrix NetScaler ADC and Gateway looked like a denial-of-service bug until watchTowr showed attackers can get root-level RCE instead. CISA added it to its Known Exploited Vulnerabilities list August 26 and gave federal agencies until August 29 to patch. More than 22,000 NetScaler ADC and 1,800 Gateway instances were still exposed online as of that deadline, per Shadowserver, and attackers are already dropping web shells on unpatched boxes.
Run NetScaler? Patch before you finish reading this newsletter, not after.

Stop Paying for 6 Tools. One AI Does It All.

Most e-commerce sellers juggle 6–8 tools and pay hundreds monthly to keep operations running. StoreClaw replaces the stack with one autonomous AI engine that monitors competitors, optimizes listings, automates marketing, and tracks profit 24/7. Connect your store and let AI handle the work — no prompts, no complex setup, no credit card required.

🧪 Strange Cyber
 
Strange but real
🕸️ A DDoS Botnet Got Bored and Started a Side Business
Intro
Somewhere out there, 296,000 hacked smart devices just got a promotion.
What Happened
Shadowserver has been tracking Dysphoria for a while, originally just another DDoS-for-hire botnet on hijacked IoT gear. Recently it grew a new feature: infected devices now function as residential proxies, letting other criminals route traffic through your hacked camera or router to look like an ordinary home user.
Why It Matters
Residential proxy networks are valuable precisely because they look legitimate, fraud systems trust home IPs far more than data center ones. A quarter-million-device botnet pivoting into that market is a bigger long-term threat than another round of DDoS.
The Other Side
DDoS botnets adding proxy features isn't new, criminals monetize infected devices multiple ways. What's notable is the scale, 296,000 devices is serious inventory to sell.
 
👉 Takeaway
If your smart device suddenly runs hotter or your bandwidth usage looks weird, it might not be DDoS traffic anymore, it might be someone else's internet browsing wearing your IP address as a disguise.
TL;DR: A 296,000-device IoT botnet built for DDoS attacks has pivoted into renting itself out as a residential proxy service.
Further reading: The Hacker News

How 2M+ Professionals Stay Ahead on AI

What’s the secret to staying ahead of the curve in the world of AI? Information. 

Luckily, you can join 2,000,000+ early adopters reading The Rundown AI — the free newsletter that makes you smarter on AI with just a 5-minute read per day.