1. NAS Devices Become the #1 Ransomware Target
The biggest trend in ransomware this month is not attacking servers or workstations β it is going after network-attached storage (NAS) devices. Attackers have realized that small businesses increasingly use NAS devices (QNAP, Synology, Western Digital) as their primary backup target. Encrypt the NAS, and you destroy both live data AND backups in one attack.
Multiple NAS vulnerabilities have been added to CISA's Known Exploited Vulnerabilities catalog since June, and ransomware gangs are actively scanning for unpatched devices. The attack chain is simple: scan the internet for NAS admin panels exposed to the web β try default credentials β deploy ransomware β demand payment in Bitcoin.
π‘οΈ What to do RIGHT NOW:
- β’ Disable internet access to your NAS admin panel. If you need remote file access, use a VPN β never expose the admin interface to the public internet.
- β’ Change default passwords immediately. If your NAS username is still "admin", assume it is already compromised.
- β’ Update NAS firmware. QNAP, Synology, and WD have all released security patches. Install them now.
- β’ Verify your 3-2-1 backup strategy. If your only backup is on a NAS in the same building, you do not have a backup. Add an off-site cloud backup.
2. VPN Appliances β The Front Door Is Unlocked
VPN appliances from Ivanti, Citrix, Fortinet, and SonicWall continue to be the most common entry point for ransomware attacks. These devices sit at the edge of your network, exposed to the internet, and are frequently exploited within days of a vulnerability being disclosed. CISA has added dozens of VPN-related CVEs to the KEV catalog in 2026 alone.
The pattern is consistent: a VPN vulnerability is disclosed β attackers scan for vulnerable devices within hours β they gain initial access β move laterally through the network β deploy ransomware. The entire process can take less than 24 hours from patch release to exploitation.
π§ If you use any of these VPN products:
- β’ Check for firmware updates weekly β not monthly. Subscribe to your vendor's security advisory list.
- β’ Enable MFA on VPN access β a stolen password alone should never be enough to connect to your network.
- β’ If your VPN appliance is end-of-life and no longer receiving patches, replace it immediately.
3. MFA Fatigue β When Two-Factor Is Not Enough
Attackers have found a way around MFA: MFA fatigue attacks (also called "push bombing"). When an attacker already has a valid username and password (from a phishing attack or data breach), they trigger repeated push notifications to the victim's phone. The victim, annoyed and confused, eventually taps "Accept" β and the attacker is in.
This technique has been used in several high-profile breaches this year, including attacks on Uber, Cisco, and Microsoft. The defense is simple but requires configuration: enable number matching on your MFA system. Instead of just tapping "Accept", the user must type a code displayed on the login screen. This prevents accidental approval.
4. Microsoft August Patch Tuesday β Critical Updates
Microsoft's August 2026 security update includes patches for 6 actively exploited vulnerabilities, including remote code execution flaws in Windows TCP/IP and the Windows Kernel. These vulnerabilities are being used in the wild right now to gain initial access to business networks.
If you manage your own Windows updates: install this month's patches within 48 hours. If you use managed IT: verify with your provider that August patches have been deployed. Do not defer these updates β the exploits are already in circulation.
August 2026 To-Do List
- Check your NAS: is the admin panel exposed to the internet? Fix that now.
- Update all VPN/firewall appliances to the latest firmware.
- Enable number matching on your MFA system to block push-bombing attacks.
- Apply Microsoft August security updates within 48 hours.
- Review your off-site backup β if ransomware hits, can you restore without the NAS?
Free Security Assessment β Check Your Exposure
20 questions covering backup strategy, endpoint protection, access controls, and network security. Get your risk score in 3 minutes.
Start Free Assessment β