Cybersecurity Weekly Briefing, 22-28 August
FBI disrupts two platforms used by Chinese state-sponsored hackers against U.S. critical infrastructure
The U.S. Department of Justice and FBI have seized domains used by QScan and QTRouter, two platforms operated by the China-linked QTFY group to support computer intrusions and conceal the origin of malicious activity. According to court documents, QTFY, which is linked to Nanjing Xinjiuwei Network Technology Company, provided hacking services to customers including China’s Ministry of State Security and People’s Liberation Army.
QScan automatically scanned and infected thousands of IoT devices, which were subsequently incorporated into QTRouter alongside commercial proxy services and leased VPS infrastructure to create an obfuscation network. Victims include NASA, the Federal Reserve, the U.S. Senate and the Departments of Energy, Justice, and Health and Human Services. Because the seized domains were hard-coded into both platforms for communications and authentication, the operation rendered QScan and QTRouter inoperable.
The FBI and NSA have also published indicators associated with QTFY activity dating back to at least 2018.
Cyberattack on Boston Scientific disrupts global operations and customer shipments
U.S. medical-device manufacturer Boston Scientific has confirmed a cybersecurity incident that caused a network outage and affected IT systems and business applications supporting its global operations. The company detected the attack on August 25 and activated its incident-response procedures with assistance from external cybersecurity specialists to contain the threat and assess its scope.
Affected functions include the ability to process and ship customer orders, and Boston Scientific has not yet provided a timeline for full system restoration. The company manufactures medical devices including pacemakers, defibrillators, stents and catheters and operates across more than one hundred countries, increasing the potential downstream impact of a prolonged disruption to its supply chain.
The initial access vector, responsible threat actor and possible data exfiltration have not been publicly disclosed.
Cyberattack attributed to Iran-linked actors knocks UK power generator offline for four days
A cyberattack publicly attributed to Iran-linked actors knocked a small UK power generation facility offline for four days in July, causing a direct operational impact on energy infrastructure. British authorities have not publicly confirmed the attribution or disclosed the identity of the facility, initial access vector or affected systems.
The National Cyber Security Centre was informed of the incident, and the UK Government subsequently issued security guidance to energy companies. The Department for Energy stated that the affected generator was small and that the attack caused no power outages and posed no risk to the stability of the national electricity grid.
The incident has increased scrutiny of the exposure of smaller, increasingly digital and remotely managed energy facilities to cyber operations linked to state actors.
Large-scale DDoS attack targets Norway's shared government digital services
The Norwegian Digitalization Agency (Digdir) suffered a distributed denial-of-service attack this week targeting shared digital infrastructure used by public-sector organizations across the country. The attack began during the early hours of August 24 and caused disruptions and degraded availability across services supporting citizen authentication, electronic signatures, government forms and data exchange between public agencies.
Digdir managed to keep most of the infrastructure operational, although some services experienced availability problems during the incident. The agency said there is no evidence that its systems were breached or that personal information was compromised.
The pro-Russian Server Killers group subsequently claimed responsibility for the activity, although Norwegian authorities have not officially confirmed the attribution.
Active exploitation of critical Citrix NetScaler vulnerability enables remote code execution
CISA has added CVE-2026-8452 to its Known Exploited Vulnerabilities catalog, a critical vulnerability affecting NetScaler ADC and NetScaler Gateway for which a public proof of concept is available. While NetScaler initially characterized the issue as a memory overflow capable of causing unpredictable behavior or denial of service,
WatchTowr researchers demonstrated that vulnerable configurations can be exploited remotely without authentication to achieve code execution. Security researchers subsequently observed exploitation attempts in the wild, including web-shell deployment and reconnaissance commands. CISA added the flaw to KEV on August 26, increasing the urgency of patching internet-exposed appliances.
Organizations should apply the fixed NetScaler releases and examine affected devices for signs of post-compromise activity.
◾ This newsletter is one of the deliverables of our Operational and Strategic Intelligence service. If you are interested in knowing the rest of the Operational and Strategic Intelligence contents included in the service, please contact us →
Cloud & Business Apps
Cybersecurity
Data & AI
IoT & Connectivity
Industry
Health
Banking and Finance
Public Sector
Retail
Tourism and Leisure
Transport & Logistics
Energy & Utilities
Smart Cities