Historical intelligence backfill. This assessment covers reporting originally published on 2026-08-25 and was added to the RWP archive on 2026-09-07.

IT Intelligence · IT

The week after Patch Tuesday was stolen tax files, Zimbra, and a VPN that was Sandworm

Week of 18–25 August 2026. France's finance ministry: 678,000 records via stolen staff creds. Zimbra CVE-2026-73570 — hundreds of servers already popped. UAC-0145 trojanized WireGuard against IT staff.

RWP Ventures · 2026-09-07 · event 2026-08-25 · 2 min read · priority 8.1

Executive summary

FACT: Once August Patch Tuesday shipped, the following week was identity and mail servers. France's finance ministry (14 August, still the live story into this week): stolen staff credentials, tax and property data on 678,000 people and businesses copied. Zimbra Collaboration Suite CVE-2026-73570: unauthenticated RCE, Shadowserver 274 compromised instances and 8,200+ still unpatched in late-August reporting. UAC-0145 (Sandworm/APT44 overlap in that roundup): fake jobs and technical interviews, trojanized WireGuard for Windows PowerShell and Linux follow-on — aimed at IT professionals, which is how you get a foothold without a 0-day on the mail server.

Salesforce/ShinyHunters-style leak claims (21 million records / 147 GB in one 18 August brief) and a claimed Azure-tenant dump stayed UNVERIFIED in those write-ups. Federal AFD.sys KEV deadline was 25 August — the last day of this week.

ASSESSMENT: Creds and collaboration suites beat new malware this week. Sandworm-shaped VPN lures against the people who install VPNs is the APT thread.

The week in one assessment

If your edge is Zimbra or a helpdesk that clicks a “client WireGuard,” Patch Tuesday did not save you.

1. Most important development

Zimbra 73570 at hundreds of live compromises. Mail is identity.

2. Active exploitation

CONFIRMED Zimbra exploitation in Shadowserver's telling.

CONFIRMED AFD.sys still the KEV clock this week.

REPORTED France finance ministry via stolen creds.

UNKNOWN Azure/Salesforce megaleaks as stated.

3. Threat actor / campaign activity

UAC-0145 / Sandworm job-lure + fake VPN. ShinyHunters/Questal claims on Salesforce — treat as leak-site until the victim confirms. iAuthFlow (passkey-on-compromised-session toolkit) showed up in August malware lists — identity persistence after password change.

4. Vulnerabilities to prioritize

Zimbra 73570. Remaining August Patch Tuesday. Any internet-facing collaboration suite.

5. Identity / cloud / enterprise

Staff creds into a ministry. Passkey toolkits. VPN clients as malware. Helpdesk and IT hiring pipelines are in the threat model.

6. Ransomware / criminal activity

Direwolf listing Eva AI Limited 17 August — REPORTED. TWINLOOT (Python C2 inside Microsoft 365/Azure/Edge) is a technique note, not this week's named victim.

7. Defensive priorities

  1. Patch or isolate Zimbra.
  2. IT-staff hiring/interview downloads are malware.
  3. Hit the 25 August AFD.sys deadline.
  4. Do not brief unverified 21-million Salesforce claims as fact.

8. What changed from last week

The kernel 0-day became a deadline. The new noise was mail servers and fake VPNs.

9. What we are watching next

Zimbra count after the first week of scanning. Whether WireGuard lures move from IT pros to OT vendors.

10. RWP assessment

Confidence: High on Zimbra mass exploitation as reported. Medium on Sandworm alias mapping. Low on unverified cloud megaleaks.

Historical intelligence backfill of the week ending 25 August 2026; added 7 September 2026.

Sources

  1. CM Alliance — Major cyber attacks August 2026
  2. PBCS — Daily briefing 18 August 2026
  3. SecurityWeek — Zimbra CVE-2026-73570 mass exploitation (as cited in August roundups)
  4. Microsoft August Patch Tuesday / CISA KEV CVE-2026-68820 deadline 25 August — Microsoft August Patch Tuesday / CISA KEV CVE-2026-68820 deadline 25 August