Mathew Potter
Security Analyst
Some weeks the news feels like a stack of unrelated incidents. Today is one of those days, but the through line is familiar: attackers reuse infrastructure, exploit unpatched software, and lean on social engineering when the technical door is slow to open.
On August 26 the US Department of Justice and FBI announced seizures of two platforms, QScan and QTRouter, linked to a China-sponsored cluster tracked as QTFY and a company called Nanjing Xinjiuwei Network Technology. The tools reportedly helped operators hide their origin while probing and breaching targets across government and critical infrastructure.
Named victims in reporting include the Federal Reserve, NASA, the US Senate, and multiple federal departments, plus hospitals, telecoms, and financial firms. A takedown is good news. It is not a reset. State-sponsored groups and their contractors recycle playbooks, buy new domains, and rent fresh infrastructure within weeks.
For private-sector readers the lesson is narrower: if federal-grade targets get hit with commodity-style tooling, your perimeter is not an afterthought. External exposure reviews and mail authentication checks are how you find the same classes of weakness before someone else does.
Switzerland's federal administration confirmed that more than 200 accounts were compromised after attackers exploited a vulnerability in Microsoft SharePoint. That pattern keeps showing up in 2026: a patch exists, adoption lags, and government or enterprise tenants become the batch job.
If you still have SharePoint or Exchange hybrids on old builds, treat patch verification as a renewal and client-questionnaire item, not a ticket you close when the vendor posts a bulletin. Carriers and corporate security teams are asking for proof of patch status, not a verbal "we are fine."
Kaseya's breach roundup this week also highlighted Greatness, a phishing-as-a-service kit targeting Microsoft 365 users with fake RingCentral notifications. PhaaS means the emails look polished because the kit is sold to many operators, not because your users got uniquely careless.
Defence is still basics done consistently: impersonation protection, conditional access, device compliance, and simulations that include voice and SMS, not just malicious links. AI-written lures are part of the story now, but the delivery mechanism is still "click here to fix your account."
AnMed in South Carolina confirmed patient data was compromised after a late-July ransomware incident that disrupted operations for weeks. A group calling itself The Gentlemen claimed the attack and even posted from one of AnMed's social accounts. Whether attribution holds or not, the operational pain is real: weeks of recovery, regulatory notice, and patients asking what was taken.
Law firms and insurers reading this should expect more client letters and regulator filings from healthcare partners. If your matters touch PHI, your own security questionnaire answers will get read more closely.
Headline seizures make the news. SharePoint patches and PhaaS kits make the breaches. If you want a written, scoped read on your exposure without a sales pitch, that is what Forensic Five does from St. Albert, Alberta. We stay in the lane: assess, document, hand you a report your insurer and clients can actually use.
Security Analyst
Mathew leads assessments and consulting at Forensic Five from St. Albert, Alberta. His background is Linux systems, networks, and application infrastructure.