This Week in Cybersecurity
Each week at Applied Tech we recap the biggest cybersecurity news headlines from the week to keep you informed and ready to face the latest threats. Here’s your breakdown for the week of August 8th-14th!
RingCentral's Ransom Refusal Ends in Full Data Dump
ShinyHunters breached RingCentral in July via a “sophisticated social engineering campaign,” and after the company refused to pay, the extortion gang leaked 280GB of a claimed 623GB haul on its dark web site. Have I Been Pwned has since confirmed the leak affects 1.6 million accounts, exposing names, emails, phone numbers, and physical addresses.
RingCentral says the core platform was untouched and only a “limited portion” of customers were hit, but hasn’t explained the initial access vector. This is just the latest notch in ShinyHunters’ belt, which has now claimed breaches spanning Salesforce, Salesloft Drift, Snowflake, and Oracle PeopleSoft customers over the past year.
Source: BleepingComputer
Read More
White House Flips Script: Private Firms Can Now Hack Back
In a first, the Trump administration will let vetted private companies conduct offensive cyber operations — including spyware-based surveillance and destructive attacks — against criminal hackers, reversing a decades-old federal policy that confined the private sector to defense only. Participants must escrow $1 million, get DOJ and DHS sign-off per operation, and stay under federal supervision, with guidance on program requirements due within two months.
Critics warn the policy could expose American cybersecurity workers to prosecution or detention abroad as “non-uniformed combatants,” and one industry veteran called the plan “half-baked.” The move comes amid a surge of state-sponsored attacks on US water infrastructure tied to Iran and a broader wave of autonomous AI-driven cyberattacks that have reportedly broken containment in frontier model testing.
Source: TechCrunch
Read More
North Korea's Dream Job Campaign Gets System-Level Upgrade
Lazarus Group exploited CVE-2026-68820, a Windows AFD.sys privilege-escalation flaw patched this Patch Tuesday, as a zero-day to hit defense and aerospace firms in France, Germany, Brazil, and India. The attacks are part of the long-running Operation Dream Job, luring victims with fake recruiter messages (impersonating firms like Lockheed Martin and Enveil) that lead to a trojanized PDF viewer or DLL side-loading chain deploying a new backdoor called Troy.
The exploit grants SYSTEM access and pairs with an upgraded FudModule 3.1 rootkit that can now tamper with Windows Smart App Control to stay hidden, while the campaign hides its C2 infrastructure inside hijacked WordPress, SharePoint, and Roundcube servers. Check Point reported the flaw to Microsoft in late July after finding evidence of exploitation dating back to early June.
Source: The Hacker News
Read More
Apple's Spyware Alarm Goes Off Again
Apple fired off a fresh batch of “Threat Notification” alerts to iPhone users on August 13, warning select individuals they were targeted by mercenary spyware—a program Apple’s run since 2021 aimed at journalists, activists, politicians, and diplomats. Apple won’t name the spyware vendor behind any given alert, so there’s no confirmation this batch ties to Pegasus specifically, though NSO Group’s tool remains the most notorious example of the category.
The company calls these “high-confidence” alerts, not routine warnings, and stresses it’ll never ask targets to click links, install profiles, or hand over credentials, a swipe at copycat phishing attempts riding on the notifications’ credibility.
Source: BleepingComputer
Read More

About Applied Tech, An HBS Brand
Applied Tech is a leading IT and cybersecurity services provider dedicated to helping organizations protect their digital assets and scale their IT capabilities. Our proactive services span cloud management, security, productivity, and IT growth strategy—delivered by an experienced team with solutions built around your goals.
As part of Heartland Business Systems, we now bring greater resources, broader capabilities, and deeper technical expertise to every client relationship.
Get in Touch with Us


