Bulletins //

NormCyber Threat Bulletin: August 2026

Cyber Threat Intelligence Roundup: Qilin Ransomware, FortiBleed, Opera GX and Hotel Wi-Fi Attacks

Cyber threats continue to evolve as attackers exploit vulnerabilities in widely used technology, target internet-facing security infrastructure and develop new techniques to compromise business accounts and sensitive data.

In this cyber threat intelligence roundup, the NormCyber Threat Intelligence team examines four emerging cyber security threats organisations should be aware of: a hotel Wi-Fi DNS poisoning campaign targeting Microsoft 365 accounts, Qilin ransomware attacks exploiting Palo Alto PAN-OS, an Opera GX zero-click vulnerability and the FortiBleed credential harvesting campaign targeting Fortinet FortiGate firewalls.

Below, we explain each threat, why it matters and where you can find the full technical analysis and recommendations.

Hotel Wi-Fi DNS Poisoning Campaign Targets Microsoft 365 Accounts

A hotel Wi-Fi DNS poisoning campaign demonstrates how attackers can target Microsoft 365 accounts without relying on conventional phishing emails.

By compromising the network infrastructure that users connect to, attackers can potentially redirect traffic and expose business accounts and sensitive information. This creates a particular risk for employees accessing corporate services while travelling.

Why does the hotel Wi-Fi attack matter?

Business travellers may naturally assume that a hotel’s Wi-Fi network is safe to use. However, compromised network infrastructure can create risks that are difficult for an individual user to identify.

Organisations should therefore consider the security implications of employees accessing corporate accounts and applications through external and potentially untrusted networks.

Palo Alto PAN-OS Flaw Exploited to Deploy Qilin Ransomware

Threat actors are exploiting a vulnerability affecting Palo Alto Networks PAN-OS to gain network access and deploy Qilin ransomware.

Security appliances such as firewalls are particularly attractive targets because they sit at the perimeter of corporate networks. If attackers successfully compromise these systems, they may gain an initial foothold from which they can conduct further malicious activity.

A successful intrusion could lead to data theft, ransomware deployment and significant business disruption.

Why does the Qilin ransomware threat matter?

An unpatched firewall can effectively become an entry point into the organisation it was intended to protect.

Organisations using affected technology should understand their exposure, ensure appropriate security updates and mitigations have been applied, and monitor their environments for indications of compromise.

Opera GX Zero-Click Vulnerability Could Enable Data Theft

A zero-click vulnerability affecting the Opera GX browser could allow a malicious website to access user data without requiring the victim to click a link, download a file or deliberately interact with malicious content.

Zero-click vulnerabilities are particularly concerning because they reduce the amount of user interaction required for a successful attack. Simply visiting malicious or compromised web content may be enough to create exposure.

Information obtained through an attack could also help threat actors conduct subsequent activity, including more convincing and targeted phishing attacks.

Why does the Opera GX vulnerability matter?

Web browsers process significant amounts of potentially sensitive information and are used continuously across business and personal environments.

The vulnerability highlights the importance of maintaining up-to-date browsers and applications as part of an organisation’s wider vulnerability management and cyber security strategy.

FortiBleed Campaign Targets Fortinet FortiGate Firewalls

The FortiBleed credential harvesting campaign is targeting Fortinet FortiGate firewalls using stolen or guessed login credentials.

Internet-facing security devices are high-value targets for cyber criminals because compromising them can provide access to the networks they are designed to protect.

If attackers successfully compromise a firewall, they may be able to establish persistence, access additional systems, steal sensitive information or prepare the environment for subsequent ransomware attacks.

Why does the FortiBleed campaign matter?

Compromised credentials remain an effective route into corporate environments, particularly when they provide access to critical network infrastructure.

Organisations should protect internet-facing infrastructure with strong authentication and access controls, while monitoring for suspicious authentication attempts and other signs of compromise.

 

What These Emerging Cyber Threats Mean for Organisations

Although these four cyber threats use different attack techniques, they demonstrate a common challenge for organisations: attackers are looking for weaknesses across the entire technology environment.

That includes the networks employees connect to, the browsers and applications they use, account credentials and the security infrastructure protecting corporate systems.

Reducing cyber risk therefore requires more than responding to individual vulnerabilities. Organisations need visibility of emerging threats, effective vulnerability management, strong identity and access controls, secure configuration of internet-facing infrastructure and the ability to detect suspicious activity quickly.

Timely cyber threat intelligence can help security teams understand emerging risks, determine whether their organisation may be exposed and prioritise the actions that matter most.

 

Stay Informed About the Latest Cyber Security Threats

The cyber threat landscape changes quickly. New vulnerabilities, ransomware campaigns and attack techniques can create risks for organisations with little warning.

NormCyber’s Threat Intelligence team regularly analyses emerging cyber threats and vulnerabilities to help organisations understand their potential exposure and take appropriate action

Subscribe to the Threat Bulletin Here: