Cybersecurity Weekly Briefing, 22-28 August

August 28, 2026

FBI disrupts two platforms used by Chinese state-sponsored hackers against U.S. critical infrastructure

The U.S. Department of Justice and FBI have seized domains used by QScan and QTRouter, two platforms operated by the China-linked QTFY group to support computer intrusions and conceal the origin of malicious activity. According to court documents, QTFY, which is linked to Nanjing Xinjiuwei Network Technology Company, provided hacking services to customers including China’s Ministry of State Security and People’s Liberation Army.

QScan automatically scanned and infected thousands of IoT devices, which were subsequently incorporated into QTRouter alongside commercial proxy services and leased VPS infrastructure to create an obfuscation network. Victims include NASA, the Federal Reserve, the U.S. Senate and the Departments of Energy, Justice, and Health and Human Services. Because the seized domains were hard-coded into both platforms for communications and authentication, the operation rendered QScan and QTRouter inoperable.

The FBI and NSA have also published indicators associated with QTFY activity dating back to at least 2018.

More info

Cyberattack on Boston Scientific disrupts global operations and customer shipments

U.S. medical-device manufacturer Boston Scientific has confirmed a cybersecurity incident that caused a network outage and affected IT systems and business applications supporting its global operations. The company detected the attack on August 25 and activated its incident-response procedures with assistance from external cybersecurity specialists to contain the threat and assess its scope.

Affected functions include the ability to process and ship customer orders, and Boston Scientific has not yet provided a timeline for full system restoration. The company manufactures medical devices including pacemakers, defibrillators, stents and catheters and operates across more than one hundred countries, increasing the potential downstream impact of a prolonged disruption to its supply chain.

The initial access vector, responsible threat actor and possible data exfiltration have not been publicly disclosed.

More info

Cyberattack attributed to Iran-linked actors knocks UK power generator offline for four days

A cyberattack publicly attributed to Iran-linked actors knocked a small UK power generation facility offline for four days in July, causing a direct operational impact on energy infrastructure. British authorities have not publicly confirmed the attribution or disclosed the identity of the facility, initial access vector or affected systems.

The National Cyber Security Centre was informed of the incident, and the UK Government subsequently issued security guidance to energy companies. The Department for Energy stated that the affected generator was small and that the attack caused no power outages and posed no risk to the stability of the national electricity grid.

The incident has increased scrutiny of the exposure of smaller, increasingly digital and remotely managed energy facilities to cyber operations linked to state actors.

More info

Large-scale DDoS attack targets Norway's shared government digital services

The Norwegian Digitalization Agency (Digdir) suffered a distributed denial-of-service attack this week targeting shared digital infrastructure used by public-sector organizations across the country. The attack began during the early hours of August 24 and caused disruptions and degraded availability across services supporting citizen authentication, electronic signatures, government forms and data exchange between public agencies.

Digdir managed to keep most of the infrastructure operational, although some services experienced availability problems during the incident. The agency said there is no evidence that its systems were breached or that personal information was compromised.

The pro-Russian Server Killers group subsequently claimed responsibility for the activity, although Norwegian authorities have not officially confirmed the attribution.

More info

Active exploitation of critical Citrix NetScaler vulnerability enables remote code execution

CISA has added CVE-2026-8452 to its Known Exploited Vulnerabilities catalog, a critical vulnerability affecting NetScaler ADC and NetScaler Gateway for which a public proof of concept is available. While NetScaler initially characterized the issue as a memory overflow capable of causing unpredictable behavior or denial of service,

WatchTowr researchers demonstrated that vulnerable configurations can be exploited remotely without authentication to achieve code execution. Security researchers subsequently observed exploitation attempts in the wild, including web-shell deployment and reconnaissance commands. CISA added the flaw to KEV on August 26, increasing the urgency of patching internet-exposed appliances.

Organizations should apply the fixed NetScaler releases and examine affected devices for signs of post-compromise activity.

More info