What Business Owners Need to Know This Week

Week 35 (16–22 August 2026) inverts last week. In W34 every South African incident was confirmed by the organisation it happened to; this week none was. Two companies were named by ransomware groups and neither has acknowledged a compromise, which leaves the domestic picture resting on what attackers say about their victims. MedusaLocker listed The Courier Guy, South Africa’s largest express parcel courier, on 16 August; the company says the enquiry was the first it had heard of the claim and it can find no sign of a breach. The Gentlemen claimed Babcock, the South African arm of Babcock International, on 19 August. A third SA-tagged listing turned out to describe a company in Makati, in the Philippines.

The Bottom Line: The solid material this week is on the vulnerability side — nine catalogue additions in five days, six already past their remediation date on the day of publication. The board question is narrow and answerable: of those nine products, which do you run, and how long did it take to find out? An organisation that can answer in an afternoon has an asset inventory. One that cannot has six overdue jobs it has not yet identified.

The Week in Numbers

  • 9 new KEV additions in 5 days — three times the previous week, with six already overdue at publication; HIGH threat level for the 18th consecutive week.
  • 4 of 9 — map to products with a countable South African exposure, against one of three last week.
  • CVSS 9.8 — Windows IKE CVE-2026-33824, a double free reachable over UDP 500 and 4500, patched in April 2026 and added to the catalogue on 18 August with a three-day deadline.
  • 361 victim addresses across 47 countries — counted for VMware vCenter CVE-2026-59310 by 7 August.
  • 646 on-premises SharePoint instances — exposed in South Africa, against CVE-2026-55040 token forgery with public exploit code.
  • 19 July — the date exploitation attempts against that SharePoint flaw begin, three weeks before the public technical write-up.
  • USD 30,000 (~R485,000) — the fixed price MedusaLocker advertised for The Courier Guy data; a resale offer, not a negotiated double-extortion demand.
  • 3 SA-tagged listings, 1 not South African — country and sector fields on these records are assigned by the aggregator, not the victim.
  • 11 weeks — since the Regulator’s last substantive output (corrected; see below).

Major Incidents: Who Was Hit and How

The Courier Guy — A Claim, a Denial, and What Settles It

MedusaLocker listed South Africa’s largest express parcel courier on 16 August. The Courier Guy told reporters the enquiry was the first it had heard of the claim, that it has no evidence of any internal system being compromised, and that it is confident no customer data is involved. It has not notified the Information Regulator, on the stated basis that it has no information indicating a breach occurred, and says it will follow the POPIA process if the investigation finds otherwise. The actor’s post shows filenames rather than files and advertises the data for USD 30,000. That price is the tell: MedusaLocker’s recent posts routinely carry a fixed sum and the phrase “sale in one hand”, which marks a resale offer rather than a negotiated double-extortion demand. The rating is CLAIMED — a leak-site description is written by the attacker, and the denial is on the record. The company’s opening position is reasonable, and it is a position rather than a finding. The work that converts one into the other is bounded, and set out in the actions below.

Babcock SA — and a Phantom Victim in Makati

The Gentlemen claimed Babcock, the South African arm of Babcock International Group, on 19 August. Of the three listings carrying a South African country tag inside the window, one does not belong: Qilin listed “Trends And Concepts” on 20 August, which is Trends and Concepts Total Interior Solutions of Makati in the Philippines — a second tracker records the same claim against trendsandconcepts.com.ph while describing the business correctly, and a third aggregator repeated the South African tag and added a figure for people affected that the actor never published. Country and sector fields on leak-site records are assigned by the aggregator rather than the victim. Treat them as leads, not facts.

SharePoint Token Forgery — 646 Exposed SA Instances

CVE-2026-55040 lets an attacker mint a JSON web token that SharePoint accepts as any user, including a site administrator. It is fixed in the July 2026 update. Rapid7 published the technical chain on 11 August with a working proof of concept, exploitation using that code was reported within two days, and attempts against the flaw date back to 19 July. There are 646 on-premises SharePoint instances exposed in South Africa — an exposure count rather than a count of vulnerable systems, but it is the population an untargeted scanner sees. Hunt for tokens whose outer header carries alg set to none and an x5t thumbprint matching the server’s own security token service certificate.

The Other Overdue Six — IKE, vCenter, Ray, TrueConf, Zimbra

In deadline order: Ray below 2.52.0 was due 20 August; Windows IKE, VMware vCenter, on-premises SharePoint and macOS were due 21 August; TrueConf Server was due 23 August; Zimbra fell due on 24 August itself. Where you cannot patch immediately there are real compensating controls: block inbound UDP 500 and 4500 on any Windows host that does not terminate IPsec, block TCP 4307 to TrueConf servers, remove the zimbra-snmp package or disable SNMP notifications, and take the Ray dashboard on 8265 off any interface a browser can reach.

POPIA and Regulatory

A correction is owed to W34. Last week’s edition named the Regulator’s most recent publication as the enforcement notices of 2 June and put the interval at eleven weeks. The 2 June item is real but is not the most recent: the Regulator issued a PAIA section 77J enforcement notice to the Gauteng Department of Health dated 8 June 2026, ordering the release of internal audit reports and a schedule of payments to suppliers of a named hospital. Measured from 8 June, the interval at last week’s publication was ten weeks, not eleven. One caveat cuts firmly against reading too much into regulatory silence: since 1 April 2025, security compromise notifications reach the Regulator through its eServices portal, and it neither routinely publishes them nor maintains a public breach register — so the absence of a public statement about a breach is not evidence that it was not notified. The narrower statement that can be made is this: the Regulator has issued no public statement, assessment or enforcement notice concerning LEGO Certified Stores, Toyota South Africa Motors, Euphoria Telecom, DC Partner, Fidelity Services Group or The Courier Guy, and no substantive regulatory output at all for eleven weeks.

Full Intelligence Report

The complete Week 35 technical report covers the MedusaLocker claim against The Courier Guy with actor-pricing analysis, the Babcock listing, the rejected Philippine victim and aggregator attribution methodology, all nine catalogue additions with fixed versions and compensating controls, the SharePoint token-forgery hunt guidance, the corrected Information Regulator publication record, structured hunt missions with IOC tables and the full source list.

What Your Business Should Do Right Now

  • Work the nine catalogue additions against a real inventory, starting with the six already overdue: Ray (due 20 Aug), Windows IKE, VMware vCenter, on-premises SharePoint and macOS (21 Aug), TrueConf Server (23 Aug), Zimbra (24 Aug). If you cannot answer “which of these do we run?” in an afternoon, the inventory gap is the finding.
  • Apply compensating controls where you cannot patch today: Block inbound UDP 500 and 4500 on any Windows host that does not terminate IPsec, block TCP 4307 to TrueConf servers, remove the zimbra-snmp package or disable SNMP notifications, and take the Ray dashboard on port 8265 off any interface a browser can reach.
  • Patch on-premises SharePoint and hunt for forged tokens: CVE-2026-55040 mints a JWT that SharePoint accepts as any user including a site administrator, fixed in the July 2026 update. Hunt for tokens whose outer header carries alg set to none and an x5t thumbprint matching the server’s own security token service certificate. Exploitation attempts date back to 19 July.
  • If a ransomware group names you, run an evidence-led investigation before you run a denial: Reconcile the actor’s claim against mail export and search-audit logs, check remote desktop and VPN authentication for the fortnight before the listing date — exposed remote desktop is MedusaLocker’s documented primary entry route — and confirm whether the filenames on the leak post correspond to real documents.
  • Form your POPIA section 22 view in writing, early: The trigger is a reasonable belief that personal information was accessed by an unauthorised person, not certainty. Record the basis for your position and the evidence behind it while the investigation runs, rather than reconstructing it afterwards.
  • Treat leak-site country tags as leads, not facts: One of this week’s three South African listings was a company in the Philippines, and a third-party aggregator added a victim count the actor never published. Verify the domain, the registered address and a contact number before you act on a country tag or report one internally.
  • Read the price on a leak-site post: A fixed sum with a resale framing indicates data being sold on rather than a live negotiated extortion, which changes both the urgency and the likely provenance of the dataset. It does not make the claim false.
  • Do not read regulatory silence as non-notification: Compromise notifications reach the Regulator through the eServices portal and are not routinely published, and there is no public breach register. Absence of a statement tells you nothing about whether a company notified.