iCOUNTER News Roundup: Key Insights Defenders Can’t Afford to Miss
August 24, 2026


The latest iCOUNTER news puts a spotlight on a challenge security teams know well: attackers move fast, while defenders are often forced to work through fragmented signals, delayed disclosures, and exposures that have been sitting in plain sight. Over the past 30 days, iCOUNTER leaders John Watters and Roman Sannikov have appeared across leading cybersecurity publications to explain what recent ransomware campaigns, identity attacks, and enterprise vulnerabilities mean for defenders, and where organizations should focus next.
SharePoint exploitation moves from vulnerability disclosure to ransomware
Microsoft SharePoint was at the center of two recent stories featuring Roman Sannikov, iCOUNTER’s Global Research Coordinator.
On August 11, SC Media reported that a high-severity SharePoint Server vulnerability had been exploited in ransomware attacks. The flaw had been patched in May and added to CISA’s Known Exploited Vulnerabilities catalog in July, yet exploitation continued long enough to become part of an active ransomware operation.
Sannikov noted that the progression followed a familiar pattern: a reliable vulnerability attracts initial access brokers, access changes hands, and public attribution arrives only after exploitation has already matured. By the time ransomware entered the picture, organizations had been given months of warning through patches and confirmed exploitation.
The urgency increased again on August 12, when The IT Nerd covered a separate SharePoint authentication bypass. Threat actors began using public proof-of-concept code against real targets on the same day it was released.
“Hours passed between a researcher publishing proof-of-concept code and someone using it against real targets.”
Roman Sannikov, Global Research Coordinator at iCOUNTER
Together, the two stories show how quickly the window between disclosure and exploitation is shrinking. They also reinforce the danger of treating each vulnerability as an isolated event. As Sannikov explained, the larger story was the number of distinct routes into the same widely deployed enterprise platform surfacing at once.
Gunra ransomware shows why overnight detection coverage matters
Roman Sannikov also appeared in two reports on Gunra, the ransomware-as-a-service operation also known as Golden Community.
The IT Nerd reported on August 11 that Gunra affiliates were exploiting known Fortinet authentication-bypass vulnerabilities to gain access to healthcare, financial services, government, and critical-infrastructure environments. The group then used stolen VPN sessions, lateral-movement tools, and custom malware to pull data from Microsoft OneDrive and SharePoint before encryption began.
Infosecurity Magazine followed on August 12, highlighting the group’s ability to maintain persistence, bypass authentication controls, and exfiltrate tens of terabytes of data while administrators were offline.
“If your detection coverage drops off overnight, that’s exactly the gap this group, now also operating under the alias Golden Community, is built to exploit.”
Roman Sannikov, Global Research Coordinator at iCOUNTER
The coverage underscored a practical lesson for security teams: patching closes a known entry point, but it does not automatically remove persistence mechanisms, stolen sessions, or authentication backdoors established before the fix. Effective response has to look beyond the original vulnerability and account for what the attacker may have changed after gaining access.
Stolen identities are changing the economics of ransomware
In a July 17 report, SC Media examined Sophos research finding that identity lapses played a role in 79% of ransomware attacks. The findings showed why credentials have become so valuable to attackers: a valid identity can provide access without the noise and uncertainty of exploiting a technical vulnerability.
“Credentials have become the cheapest, highest-return way into a network, and an entire criminal economy has built up around them.”
Roman Sannikov, Global Research Coordinator at iCOUNTER
Sannikov also challenged the assumption that multifactor authentication ends the identity conversation. The report found that many organizations breached through compromised credentials already had MFA enabled. The real question is whether every access point is protected by a strong authentication method, and whether attackers can compromise the email account, phone number, session token, or service account on which that protection depends.
John Watters connects the Estée Lauder breach to Clop’s long game
Two July stories featured John Watters, iCOUNTER’s Chairman and CEO, discussing the roughly ten-month gap between the Estée Lauder intrusion and its public disclosure.
The IT Nerd’s July 21 coverage examined the breach as part of Clop’s broader campaign against Oracle E-Business Suite. Rather than attacking companies one by one, the group exploited software shared across many organizations and worked through its victim list over time.
“Clop rolls out its victim list over time rather than all at once, which means every new name that gets published is a live signal.”
John Watters, Chairman and CEO of iCOUNTER
That same perspective appeared in CPO Magazine’s July 27 report on the Estée Lauder breach. The article detailed the sensitive personal and employment information exposed and placed the incident in the context of Clop’s repeatable model: find one vulnerability in a widely used platform, quietly collect data from many victims, and control the pace of disclosure and extortion.
For defenders, every new victim named in a campaign should trigger a fresh assessment. If an organization uses the same platform, depends on a connected third party, or shares a similar exposure, the disclosure is actionable intelligence, not simply news about somebody else’s breach.
Turning intelligence into earlier action
Across eight stories and announcements published in the past 30 days, iCOUNTER experts helped connect individual incidents to the larger changes reshaping cybersecurity. Roman Sannikov showed how public exploit code, stolen identities, inconsistent detection coverage, and persistent access are compressing the time defenders have to respond. John Watters explained how adversaries such as Clop turn shared enterprise technology and delayed visibility into scalable business models.
The common thread is speed. The most useful intelligence does more than describe what already happened. It helps an organization recognize when another company’s breach, a newly published exploit, or an overnight change in attacker behavior is a signal about its own exposure, and act before that signal becomes an incident.
For more iCOUNTER news, expert commentary, and company updates, visit the iCOUNTER press page.
.avif)