grc-scanSecurity & governance
News digest21 August 2026Archived edition

Cybersecurity News

This edition was published on 21 August 2026 and is kept here unchanged as a record. The threats and cases it describes may have moved on — read the latest digest for the current picture.

The takeaway

This week's incidents share one thread: criminals increasingly went around security rather than through it — a phone call, a support-desk login, or a supplier's weak link did the job instead.

  • Never act on an unexpected phone call asking to reset a password or change account details — call back on a number you already have.
  • Keep automatic updates on for every Windows PC and Mac, and turn off remote-access features you don't actively use.
  • Treat QR codes in emails and texts with the same suspicion as a suspicious link — go to the supplier's site directly instead.

Cybersecurity News — 2026-08-21

Generated: 2026-08-21 | Sources: The Hacker News, BleepingComputer, The Register, SecurityWeek, Rapid7, Malwarebytes, Computing, The Record, Keepnet Labs


1. Criminals Talked Their Way Past a Password Reset — Then Leaked 1.6 Million Customers' Details

RingCentral, a widely used business phone and video-conferencing provider, was breached not by a hacking tool but by a phone call: an extortion group known as ShinyHunters rang an employee, posed as someone else, and talked them into handing over an account password — a technique called "vishing" (voice phishing). Once inside, the group stole names, addresses, emails and phone numbers for 1.6 million customer accounts, and in some cases notes containing sensitive medical conversations that had been logged through the platform. When RingCentral wouldn't pay, the gang published a 280-gigabyte archive of the stolen data on its leak site.

Why it matters for your business: your staff are the real target here, not your software. Anyone who can reset a password, approve a payment, or grant account access should follow one simple rule — never act on a phone call alone. Hang up and call the person or company back on a number you already have, especially if the request feels urgent.


2. A Help Desk Login Was the Way In: 740,000 Records Stolen From UK Government and Police Systems

A previously unknown criminal group calling itself ExfilSquad broke into the UK Department for Education's help-desk support portal and a separate legal-guidance database used by police forces, the Police National Legal Database. Between the two systems, roughly 740,000 records were taken — mostly names, email addresses, phone numbers and job titles belonging to parents, school staff, and police officers and legal staff, not the confidential case files police keep on suspects or victims. It's a reminder that the support or helpdesk tool sitting behind your main website or software is often less protected than the system it serves, and is an increasingly common way in.

Why it matters for your business: ask whoever runs your helpdesk, ticketing, or customer-support software the same questions you'd ask about your main systems — is multi-factor authentication switched on, and who can see customer contact details? A "minor" support tool is still a door into your customer list.


3. Two Flaws Attackers Are Already Using to Break Into Windows PCs and Macs — Patch Both This Week

Two separate flaws are now being actively exploited, one on each of the operating systems most small businesses run. On Windows, a bug in the built-in VPN service (IKE) lets an attacker take over a machine over the network with no password at all, just by sending it a crafted message — Microsoft's own advice, if you can't patch immediately, is to block the relevant network ports at the firewall. On the Mac, a flaw in the built-in Screen Sharing feature lets an attacker connect without a valid login; criminals have already used it on internet-exposed Macs to quietly install cryptocurrency-mining software.

Why it matters for your business: check that automatic updates are switched on for every Windows PC and Mac in your business, and if any Mac has Screen Sharing turned on and reachable from the internet, switch it off unless you specifically need it. Neither flaw needs a stolen password — just a machine that hasn't been updated.


4. A Widely Used Business Website Platform Let Attackers Log In as the Administrator — No Password Needed

Microsoft SharePoint, software many businesses use to run internal document sites and portals, had a critical flaw in how it checks login tokens: attackers who worked out the trick could forge a token that made SharePoint treat them as any user, including a full administrator, without ever entering a password. Criminals started exploiting it within days of technical details becoming public, targeting the "on-premises" version of SharePoint that organisations host themselves — Microsoft's cloud-hosted SharePoint Online was not affected.

Why it matters for your business: if your business or IT provider runs its own SharePoint server rather than Microsoft's cloud version, confirm this month's patch has been applied — this is exactly the kind of internal system owners assume "IT has handled" without ever actually asking.


5. A Crypto Wallet Maker's Delivery Partner Was Breached — Now Its Customers Are Bracing for Phishing Calls

Trezor, which makes hardware devices for storing cryptocurrency, warned nearly 14,000 customers that its order-fulfilment partner, ShipMonk, had been breached, exposing names, emails, phone numbers and home delivery addresses (no wallets, passwords or funds were touched). Trezor's own warning to customers is the useful part: expect fake "support" emails, fraudulent delivery texts, and phone calls asking you to "verify" account details — exactly the follow-up scams that appear after any breach notification, dressed up to look like they come from the company that was breached.

Why it matters for your business: if you or your business ever receive a breach notification from a supplier, treat every message that follows it with extra suspicion for weeks afterwards — criminals use real breach news to make fake follow-up calls and emails far more convincing.


6. Fake QR Codes on Invoices and Delivery Notices Are Now a Routine Scam, Not a Novelty

QR codes hidden inside emailed invoices, "your parcel is on hold" texts and calendar invites — a tactic called "quishing" — have jumped sharply over the past year, with Microsoft reporting a 146% rise in QR-code phishing attempts in early 2026 alone. The trick works because scanning a code with a phone camera skips the spam filters and link-checking that protect email, and most people haven't yet learned to be suspicious of a square barcode the way they now are of a dodgy link.

Why it matters for your business: tell your team the same rule applies to a QR code as to a link in an email — don't scan one from an unexpected invoice, delivery notice, or "scan to verify" message. If you need to check an invoice or track a parcel, go to the supplier's website or app directly instead.


Sources

Reading about a breach — could it happen to you?

Most of these stories start with something an attacker can see from the outside: an exposed service, a spoofable domain, weak encryption. You can check your own domain for the same things in about a minute — free, no login, nothing intrusive.

Summaries are compiled from public threat-intelligence feeds and security news sources. This digest is for awareness purposes only and does not constitute professional security advice.