Threat Intel Bi-Weekly + AI Vuln Monitor | Coverage: August 7, 2026 - August 7, 2026 | Sources: NVD • CISA KEV • Microsoft MSRC • Google GTIG • Palo Alto PSIRT • BleepingComputer • OWASP LLM | Published: Friday, August 7, 2026 -69% vs prior run

AI & Supply Chain

[MEDIUM]

CVE-2026-21852 — Claude Code

API key theft vulnerability in Claude Code enabling attackers to redirect API requests to attacker-controlled proxy, capturing full authorization header including plaintext API keys before trust prompt. In Anthropic Workspaces environments, single stolen key exposes entire team's data.

REMEDIATION

Rotate all Anthropic API keys immediately. Implement network egress filtering to prevent unauthorized API proxy redirection. Monitor Claude Code API traffic for suspicious destinations. Enable Workspaces audit logging.

Source: BeyondScale  •  Published: 2026-07-14

Threat Actors & Dark Web

[HIGH]

RANSOMWARE-BASELINE-2026 — Multiple industries globally

Ransomware attack volumes stabilized at elevated 'new normal' baseline through Q1 2026. The Gentlemen group expanded from 35 victims in Q4 2025 to 182 in Q1 2026 becoming second most active group. Qilin claimed highest victim count amongst all groups. Attack volume steady quarter-over-quarter and year-over-year.

REMEDIATION

Treat elevated ransomware baseline as permanent threat level. Implement offline air-gapped backups tested regularly. Deploy network segmentation to limit lateral movement. Establish and test incident response plans for sustained high-volume attack environment. Monitor for The Gentlemen and Qilin TTPs.

Source: Industrial Cyber  •  Published: 2026-04-01

[HIGH]

INC-RANSOMWARE-2026 — SonicWall SMA1000 customers

INC Ransomware group identified as primary threat actor exploiting SonicWall SMA1000 zero-day vulnerability chain (CVE-2026-15409 and CVE-2026-15410). Actively targeting secure remote access appliances for initial access and lateral movement into corporate networks.

REMEDIATION

Apply SonicWall platform hotfixes 12.4.3-03453 or 12.5.0-02835 immediately. Investigate SMA1000 logs for indicators of INC Ransomware compromise. Implement multi-factor authentication on all remote access services. Deploy endpoint detection and response (EDR) tools to detect ransomware behaviors.

Source: Tenable  •  Published: 2026-07-14

[HIGH]

NAIC-BREACH-2026 — National Association of Insurance Commissioners

ShinyHunters ransomware group claimed theft of 3.1 terabytes of data from National Association of Insurance Commissioners including insurer filings, credit rating files, and personally identifiable information. Data leaked on dark web. US Department of Homeland Security investigating since early July 2026.

REMEDIATION

Organizations in insurance sector should assume exposure and monitor for credential stuffing attacks. Implement dark web monitoring for organizational data. Review and strengthen third-party vendor security requirements. Deploy data loss prevention (DLP) tools to detect exfiltration attempts.

Source: BitSight  •  Published: 2026-06-01

Priority Action Matrix

01TODAYRANSOMWARE-BASELINE-2026 (Multiple industries globally): Treat elevated ransomware baseline as permanent threat level. Implement offline air-gapped backups tested regularly. Deploy network segmentation to limit lateral movement. Establish and test incident ...
02TODAYINC-RANSOMWARE-2026 (SonicWall SMA1000 customers): Apply SonicWall platform hotfixes 12.4.3-03453 or 12.5.0-02835 immediately. Investigate SMA1000 logs for indicators of INC Ransomware compromise. Implement multi-factor authentication on all remote ac...
03TODAYNAIC-BREACH-2026 (National Association of Insurance Commissioners): Organizations in insurance sector should assume exposure and monitor for credential stuffing attacks. Implement dark web monitoring for organizational data. Review and strengthen third-party vendor se...
04THIS WEEKCVE-2026-21852 (Claude Code): Rotate all Anthropic API keys immediately. Implement network egress filtering to prevent unauthorized API proxy redirection. Monitor Claude Code API traffic for suspicious destinations. Enable Workspa...

Biggest Risk This Period

BIGGEST RISK

RANSOMWARE-BASELINE-2026: Ransomware attack volumes stabilized at elevated 'new normal' baseline through Q1 2026. The Gentlemen group expanded from 35 victims in Q4 2025 to 182 in Q1 2026 becoming second most active group. Qilin claimed highest victim count amongst all groups. Attack volume steady quarter-over-quarter and year-over-year.