Canadian Cyber Security Journal
SOCIAL:
Filed under: News

Cybersecurity Daily Brief — Monday, August 24, 2026

Here are today’s top cybersecurity stories for Monday, August 24, 2026.

SickKids Hospital Discloses Employee Data Breach Linked to Third-Party Software Flaw
The Hospital for Sick Children in Toronto confirmed unauthorized access to personal information belonging to current and former employees, job applicants, and staff at Boomerang Health and the SickKids Foundation. The hospital traces the incident to a vulnerability in third-party software also used by other organizations and says patient records and clinical systems remain unaffected. SickKids restored its external careers website and is offering affected individuals 24 months of credit monitoring and identity protection. BleepingComputer | The Record

Private Equity Giant Apollo Global Management Confirms Data Breach
Apollo Global Management disclosed a social engineering attack, which gave intruders unauthorized access to some cloud platforms between July 6 and July 10, exposing names, dates of birth, addresses, contact information, and Social Security numbers. The firm found no evidence the stolen data appeared for sale or use in fraud and is offering affected individuals credit monitoring. The incident follows Google warnings naming the extortion group UNC6671, also tracked as Falcon, Helix, Pink, or Redact, as targeting Apollo alongside other private equity firms including Blackstone, Bridgewater, and Bain Capital. SecurityWeek | TechCrunch

ReliaQuest Contains Social Engineering Attack, Disputes Ransomware Claim
Threat actors registered a lookalike domain and stood up a counterfeit ReliaQuest single sign-on page behind a content delivery network, then called employees while posing as security staff to steer them toward the fake portal. One employee entered credentials and approved a multi-factor push notification, giving attackers temporary access to a single user identity before layered security controls contained the intrusion. The extortion group ShinyHunters listed ReliaQuest on its leak site the next day, a claim the company disputes, saying no customer data or internal systems were accessed. BleepingComputer | ReliaQuest

Critical Keycloak Flaw Lets Unauthenticated Attackers Take Over Any Account
Researchers disclosed CVE-2026-18963, a CVSS 9.1 flaw in the open-source identity platform Keycloak stemming from improper state validation in the reset-credentials authentication flow. An unauthenticated attacker sends a crafted request skipping the email-based action token and moving straight to the password update step, taking over any account including administrators. Keycloak fixed the issue in version 26.7.2, and organizations running self-managed instances need to update without delay. The Hacker News

OpenAI Launches Cybersecurity Model With Reduced Safeguards for Exploit Work
OpenAI released GPT-5.6-Cyber, a specialized version of GPT-5.6 Sol trained for vulnerability research, exploit development, and incident response, available to vetted organizations through a new Daybreak Red access tier. The model completes 95 percent of prompts on OpenAI’s internal cybersecurity benchmark, compared with 1.5 percent for the standard-safeguard version, by reducing refusals on higher-risk dual-use tasks. OpenAI acknowledges the reduced-safeguard model carries risks from misuse or misalignment beyond standard deployments. The Hacker News | OpenAI

Iran-Linked Hackers Force Small UK Power Plant Offline for Four Days
A cyberattack attributed to Iran-linked hackers took a small-scale UK energy generator offline for four consecutive days in July, marking what officials describe as the first successful attack of its kind against UK energy infrastructure. Authorities say the incident posed no risk to the broader national grid, and the National Cyber Security Centre now handles at least four nationally significant cyberattacks weekly. The disclosure follows a wave of Iran-linked intrusions against US water utilities around the same period. Help Net Security | SecurityWeek

Cloaked Fake Banking Websites Evade Scanners Through SEO Poisoning
Fortra researchers documented a rise of more than 40 percent in Chameleon SEO poisoning activity, a technique manipulating search rankings to surface cloned banking login pages built to steal credentials and hijack active sessions. The pages serve different content depending on how a visitor arrives, letting them evade standard security scans and stay active in search results for days or weeks. Fortra recommends context-aware monitoring and stronger checks on newly registered lookalike domains. Help Net Security

New SynkLoader Malware Spreads Through Microsoft Teams Phishing
Researchers at Expel identified SynkLoader, a previously unknown modular malware family combining Python, PowerShell, C#, and C++ components, distributed through Microsoft Teams messages impersonating an IT service desk. Attackers registered their own Microsoft 365 tenant and asked targets to run a fake PowerShell maintenance tool, which deploys a credential-stealing fake Windows lock screen and runs many payloads in memory to reduce detection. Expel assesses with low to medium confidence the malware ties to ransomware operators or an initial access broker. Dark Reading

Ransomware Attackers Increasingly Target Mid-Market Companies
A new Black Kite report finds 73 percent of publicly disclosed ransomware and data-extortion incidents in North America and Europe between 2023 and mid-2026 hit companies with 10 million to 1 billion dollars in annual revenue, with incident volume growing 44 percent over the period. Manufacturing accounted for more than a quarter of victims, and nearly 30 percent of mid-market organizations analyzed carried at least one known exploited vulnerability. Researchers point to weaker security budgets and growing third-party exposure as key drivers. Help Net Security

Malware Turns Android Car Head Units Into Proxy Botnet Nodes
Kaspersky documented the first known malware infection chain targeting car head units running Android, abusing the built-in software updater on affected DoFun devices to install a reverse-proxy module turning vehicles into botnet nodes for ad fraud and traffic relay. Researchers attribute the campaign with high confidence to MoYu Group, an actor linked to the BADBOX botnet, which sells consumer hardware pre-loaded with a firmware backdoor through ordinary supply chains. Independent researchers at Nokia confirmed the same proxy module active on Android TV set-top boxes. Help Net Security | BleepingComputer

Stay tuned for today’s in-depth analysis posts.

Enjoy this article? Don’t forget to share.