August 24, 2026 Emerging Threats Weekly

Aug 24, 2026

This week’s briefing covers:

00:00 – Intro

00:39 [RANSOMWARE] Updated Medusa Advisory Shows Faster Exploit Adoption and Deeper Broker Use
A joint U.S. government advisory updated this week says the KTA321 (Medusa) ransomware-as-a-service operation has continued to expand and refine its access model. According to the updated reporting, the actors now rely heavily on access brokers, paying anywhere from $100 to $1 million (mn) depending on the exclusivity and value of the access.

03:36 [VULNERABILITY] SAP Commerce Cloud CVE-2026-58231 Drew Exploitation Attempts within Days
A critical SAP Commerce Cloud Data Hub Adapter flaw (CVE-2026-58231) drew exploitation attempts only days after patches became available. The vulnerability carries a CVSS score of 10.0 and affects COM_CLOUD 2211 and 2211-JDK21. It stems from insufficient authorization checks and input validation that can let an unauthenticated attacker abuse a default authentication client and submit crafted input to vulnerable functions.

06:29 [AI] PurpleDelta Scales Fraudulent Employment Operations with AI Support
Recorded Future has detailed an industrial-scale North Korean remote-worker operation it tracks as PurpleDelta, identifying at least 22 fabricated personas used to apply to more than 1,100 companies. One cluster alone submitted more than 60 applications per day and was highly likely to have secured roles at no less than ten organizations. Roughly 80% of the targeted companies were in North America, while personas claimed to be based in the U.S., Germany and Brazil.

08:50 [NEW TECHNIQUE] TwinLoot Turns Microsoft 365 Into An Attacker Control Plane
Ontinue’s investigation into an ongoing July campaign uncovered a Python-based malware framework, TWINLOOT, that runs its command-and-control almost entirely through Microsoft cloud services. The framework uses SharePoint Online and the Microsoft Graph API for dead-drop-style control, Microsoft Teams’ TURN relay infrastructure for interactive access and the victim’s own Microsoft Edge browser to carry Graph traffic.

11:54 [SOCIAL ENGINEERING] ClearFake Campaigns Deliver WordlistLoader and the Evolving Amatera Stealer
Gen Threat Labs identified a new loader, WordlistLoader, being used to deliver the Amatera stealer through ClearFake campaigns. The infection begins on compromised legitimate websites where malicious JavaScript overlays a fake CAPTCHA on top of the real page.

13:55 [MALWARE] AmnesiaStealer Brings ClickFix and Live Browser Hijack to macOS
Research shows a new macOS infostealer, AmnesiaStealer, being distributed through fake GitHub download pages that instruct victims to copy and paste a Base64-encoded command into Terminal. The command downloads a dropper script, retrieves a password-protected ZIP archive and executes a Rust-based payload.

Dive deeper:

Kroll’s Monthly Threat Intelligence Spotlight Report: https://www.kroll.com/en/reports/cyber/threat-intelligence-reports/cti-spotlight-trends-report

Kroll’s Cyber Threat Intelligence: https://www.kroll.com/en/services/cyber/threat-intelligence-services

Kroll’s Q4 2024 Cyber Threat Landscape: https://www.kroll.com/en/reports/cyber/threat-intelligence-reports/q4-2024-threat-landscape-report-phishing

Kroll’s 2025 Cyber Threat Landscape Report: Cybercrime in the Crypto Era: https://www.kroll.com/Reports/Cyber/Threat-Intelligence-Reports/Threat-Landscape-Report-Lens-on-Crypto

Playlist of Kroll's Weekly Cyber Threat Intelligence Briefings: https://www.youtube.com/playlist

Kroll Cyber Blog: https://www.kroll.com/en/insights/cyber

Kroll Cyber Threat Intelligence: https://www.kroll.com/en/services/cyber/threat-intelligence-services

Kroll Threat Intelligence Reports: https://www.kroll.com/en/reports/cyber/threat-intelligence-reports

Kroll Cyber and Data Resilience: https://www.kroll.com/en/services/cyber

#krollcyber #threatintelligence #cyberthreats