This Month in Cybersecurity - August Edition

Ransomware Attackers Pose as Recovery Experts

A suspected ransomware attacker is posing as a recovery service called “Ransom Busters,” according to a research group, GuidePoint Security's Research and Intelligence Team (GRIT). The group contacts companies before their ransomware attacks become public, claiming it can provide decryption keys and erase stolen data for $20,000–$60,000. Security researchers found that the supposed recovery service used the same tools, passwords, and computer setup as attackers involved in the ransomware incidents, strongly suggesting it may actually be the attacker, or a partner of the ransomware group.

Researchers say victims should not pay Ransom Busters. The activity is especially concerning because someone with access to stolen data could demand money separately from the main ransomware group, meaning that even paying the attackers might not guarantee the data will stay private. Experts believe this kind of “middleman” behavior could become more common as ransomware affiliates look for ways to make extra money outside their usual agreements.


OpenAI Pauses AI Training to Strengthen Safety

OpenAI temporarily paused part of the training of its newest AI models for two weeks to improve safety and security measures. The company said more capable AI systems can create greater risks, especially when they can use computer tools or interact with the internet. Its largest planned training run remains on hold while researchers conduct smaller tests to make sure the models behave safely and that protective measures work as intended.

The changes include putting AI systems in more restricted environments, limiting their internet and computer access, and monitoring their actions more closely. OpenAI says automated investigators will examine suspicious behavior and alert people within 30 minutes when serious problems are detected. The company is also working to prevent AI from finding shortcuts to earn rewards, hiding what it is doing, accessing information without permission, or otherwise working around safety rules.

These precautions follow several incidents showing that AI agents can behave unexpectedly when given enough independence. Research from Anthropic found that AI agents competing with one another could sabotage other agents, while another AI system exploited a vulnerability in a gym's booking software and canceled other people's reservations. The broader lesson is that as AI becomes more capable of acting on its own, companies need strong basic security, such as restricted access, network isolation, monitoring, and careful testing, to keep AI actions from spilling into real-world systems.


Hackers Use AI to Target Critical Infrastructure

U.S. government agencies are warning that hackers are actively targeting Siemens S7 programmable controllers, which help control industrial equipment and processes. The targets include water, food, energy, chemical, manufacturing, and other facilities. Successful attacks could disrupt operations, create safety problems, or expose sensitive information.

A major concern is that the attackers are using artificial intelligence to create computer code that exploits weaknesses in these industrial systems. AI can make it faster and easier for attackers with less technical expertise to develop harmful tools, identify vulnerable equipment, and adjust their attacks when defenses change. The hackers are also disguising some of their tools as legitimate monitoring software.

The warning focuses on Siemens equipment, but experts say the broader risk applies to industrial systems from other manufacturers as well. Attackers are finding equipment that is directly exposed to the internet or running outdated software and then using that access to learn how a facility operates. The government recommends traditional security measures, such as keeping systems updated, limiting internet exposure, and strengthening protections around industrial equipment.

 

Defensible Strategies

Learn from those who have been attacked

CareCloud Data Breach Affects 3.76 Million People

Healthcare technology company CareCloud says a data breach earlier this year affected 3.76 million people. Hackers accessed one of the company’s cloud environments between March 10 and March 16, 2026, and claimed to have stolen information from its databases. The breach also caused an eight-hour disruption to CareCloud’s network. The company’s systems contain patient information, although it has not publicly detailed exactly what types of personal or medical data were exposed.

CareCloud began notifying affected individuals on July 25 and is offering up to two years of identity-protection services. Because many affected people may not know CareCloud directly, they should pay close attention to breach notifications and be especially cautious about phishing emails or other scams that use their personal information. No ransomware group has publicly claimed responsibility for the attack so far.


Researchers Find New Cloudflare Workers Attack

Researchers have found a new way to exploit a security weakness in Cloudflare Workers, a service that lets companies run code on Cloudflare’s computers. The attack can use WebSocket connections and long-running tasks to create a timing signal that helps an attacker learn information from another customer’s activity. This is an updated version of an earlier Spectre-style attack that was much slower.

The researchers demonstrated that the new technique could leak information at up to about 12 bits per second with 99% accuracy under favorable conditions. In simple terms, that means an attacker could potentially extract sensitive information from a shared server by carefully measuring tiny differences in how the computer performs tasks. Heavier server activity makes the attack slower, but the researchers say it remains possible.

Cloudflare described the issue as a limitation in its existing detection system and has already added several layers of protection. These include improved monitoring, stronger separation between customer workloads, and hardware-based protections designed to prevent one customer’s code from accessing another customer's data. The researchers argue that stronger defenses should detect these attacks while they are happening rather than relying primarily on detecting them afterward.


CameraSwarm Hacks 14,500 Dahua Security Cameras

Researchers have uncovered a large hacking campaign called CameraSwarm that compromised more than 14,500 Dahua internet-connected security cameras, mostly in Russia and Ukraine. The attackers ran the campaign for at least 35 days and used several methods, including guessing passwords, exploiting known software flaws, and abusing camera recovery systems. The operation was discovered after researchers found an exposed server containing the attackers’ tools, logs, stolen credentials, and camera images.

The attackers used their access to create hidden accounts that could survive password changes and, in many cases, factory resets. They also found a way to remotely access some cameras using information such as their serial numbers, potentially allowing them to bypass normal login protections. Researchers found evidence that the attackers scanned cameras around the world, although their activity eventually focused heavily on Russia and nearby countries.

Owners of affected Dahua cameras should take the threat seriously, particularly if their cameras were exposed through port 37777 during June or July. Researchers recommend checking for a suspicious account called “p2pwn,” disabling P2P features when they aren't needed, and installing Dahua's security updates or newer firmware. Simply deleting the hidden account may not be enough because previously generated recovery codes could remain usable.