Cyber Threat Intelligence 19 August 2026
-
Industrial Sector
- CISA Malcolm
"Successful exploitation of these vulnerabilities could allow an attacker to cause a denial-of-service condition or execute arbitrary code."
https://www.cisa.gov/news-events/ics-advisories/icsa-26-230-01 - Siemens Simcenter Nastran
"Simcenter Nastran is affected by a stack overflow vulnerability that could be triggered when an application binary reads arbitrary string as a file argument. If a user is tricked to run one of the impacted application binary with a malicious string, an attacker could leverage the vulnerability to perform remote code execution in the context of the current process. Siemens has released new versions for the affected products and recommends to update to the latest versions."
https://www.cisa.gov/news-events/ics-advisories/icsa-26-230-02
Vulnerabilities
- NASA Ground Control Software Flaw Enables Unauthenticated Commands
"A critical vulnerability in NASA's open-source AMMOS Instrument Toolkit (AIT)-GUI ground software has been found that could allow unauthenticated attackers to issue spacecraft and instrument commands, execute server-side scripts and run command sequences. AIT-GUI is the browser-based operator console for NASA's AMMOS Instrument Toolkit, an open-source framework for ground data systems that communicate with instruments and spacecraft. The flaw, tracked as GHSA-p9r8-2q67-fp86 and given a CVSS ratting of 9.4, affects AIT-GUI versions through 2.5.1. No CVE has been assigned at the time of writing."
https://www.infosecurity-magazine.com/news/nasa-ground-control-software-flaw/ - Dozens Of WebKit Vulnerabilities Patched With Fresh MacOS, iOS Security Updates
"Apple on Monday announced a fresh round of macOS, iOS, and iPadOS security updates that address dozens of vulnerabilities, most of which affect the web browser engine WebKit. macOS Tahoe 26.6.2 is now rolling out with fixes for 28 security defects, including 21 in WebKit that could lead to Safari/process crashes, memory corruption, and sensitive data disclosure. The update also resolves seven issues in Audio, ImageIO, IOGPUFamily, and Kernel that could lead to sensitive user information disclosure, denial-of-service (DoS), arbitrary code execution, memory corruption, system termination, and kernel memory disclosure or corruption."
https://www.securityweek.com/dozens-of-webkit-vulnerabilities-patched-with-fresh-macos-ios-security-updates/
https://www.malwarebytes.com/blog/bugs/2026/08/apple-fixes-another-image-processing-flaw-that-could-allow-code-execution
https://www.theregister.com/security/2026/08/18/apple-plugs-image-processing-hole-ripe-for-spyware-abuse/5289031 - Attackers Exploit MLflow SSRF Flaw To Steal Cloud Credentials And Secrets
"Two critical vulnerabilities impacting MLflow, an open-source artificial intelligence (AI) platform, and FUXA, an open-source, web-based SCADA / HMI software built for operational technology (OT) and industrial automation, are witnessing malicious scanning and exploitation efforts. According to independent reports from watchTowr and VulnCheck, the vulnerabilities in question are as follows -"
https://thehackernews.com/2026/08/attackers-exploit-mlflow-ssrf-flaw-to.html - CISA Adds Four Known Exploited Vulnerabilities To Catalog
"CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
CVE-2026-33824 Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability
CVE-2026-55040 Microsoft SharePoint Weak Authentication Vulnerability
CVE-2026-59310 Broadcom VMware vCenter Path Traversal Vulnerability
CVE-2026-65400 Apple macOS Improper Authentication Vulnerability"
https://www.cisa.gov/news-events/alerts/2026/08/18/cisa-adds-four-known-exploited-vulnerabilities-catalog - CoSnitch: When Your AI Assistant Becomes Its Own Whistleblower
"Varonis Threat Labs uncovered another one-click vulnerability in Microsoft Copilot Personal dubbed CoSnitch (critical, CVE-2026-24301), which quietly executes an attack chain that exfiltrates data from enterprises without obvious red flags. What makes CoSnitch unique is how Copilot surfaced its own vulnerabilities, a method we are calling meta-hacking. Our researchers didn't have to reverse-engineer the flaw. The AI exposed the weakness during normal use, highlighting a meaningful shift in how security flaws are found, and a preview of what's ahead as AI gets woven deeper into enterprise systems."
https://www.varonis.com/blog/cosnitch
https://www.darkreading.com/vulnerabilities-threats/cosnitch-attack-copilot-mapping-out-architecture
https://thehackernews.com/2026/08/microsoft-copilot-personal-flaws-could.html
https://www.theregister.com/research/2026/08/18/copilot-tricked-into-telling-reseachers-how-to-hack-itself/5288857 - AI "Mind Viruses" Can Spread Between Agents Through Persistent Prompt Files
"Security researchers at Anthropic and Switzerland's EPFL have demonstrated that self-propagating payloads can spread from one artificial intelligence (AI) agent to the next through the editable system prompt files that autonomous agent harnesses use to carry state between sessions. The work, released as a preprint on August 10, 2026, tests the technique in a simulated six-agent coding collaboration and in a chain of paired agents modeled on OpenClaw, the open-source autonomous assistant formerly known as Clawdbot and Moltbot."
https://thehackernews.com/2026/08/ai-mind-viruses-can-spread-between.html
https://arxiv.org/abs/2608.10218
Malware
- Beware Of Phishing Emails Disguised As Requests To Review Quotes (PhantomStealer)
"The AhnLab SEcurity intelligence Center (ASEC) recently identified a phishing email campaign that disguised itself as a request to review a quote. The threat actor impersonated a sales team member at a specific overseas company and, by claiming that a previous quote needed to be revised and product versions verified, tricked recipients into opening the Attachment. The email contained a malicious file named “7200_Quantum_Enterprise_LLC_SSO-0661.GZ” , which contained a malicious compressed file."
https://asec.ahnlab.com/en/95000/ - Beware Of Phishing Emails Disguised As Transaction Receipts
"Recently, the AhnLab SEcurity intelligence Center (ASEC) identified instances of phishing emails that were disguised as transaction receipts. The emails impersonated employees of a specific US company. The body of the message stated that a transaction receipt was attached and asked the recipient to review it and confirm whether funds had been deposited into their account, thereby enticing the recipient to open the Attachment."
https://asec.ahnlab.com/en/95001/ - Attack Cases For Domestic Web Servers Running SoftEther VPN In Korea
"The AhnLab SEcurity intelligence Center (ASEC) recently identified attack cases in which attackers targeted web servers in Korea to install SoftEther VPN. Attack cases involving the installation of SoftEther VPN, an open-source VPN, were previously discussed in the 2024 ASEC blog post titled “Analysis of Attack Cases Targeting ERP Servers in Korea to Install SoftEther VPN” [1]. The threat actor currently carrying out similar attacks exhibits the same characteristics as the case described above and is therefore classified as Larva-26010. It appears that the threat actor ultimately installed the SoftEther VPN service to use the infected systems as VPN servers."
https://asec.ahnlab.com/en/94995/ - Clop Returns With Custom Implant In Mass-Extortion Campaign
"ReliaQuest identified a custom web shell highly likely linked to "Clop" (aka Cl0p), a financially motivated ransomware and extortion group known for mass-exploiting enterprise software vulnerabilities. The web shell is deployed after exploitation of CVE-2026-12569 (CVSS 9.3) in PTC Windchill, an industry-standard product lifecycle management (PLM) platform used by manufacturing enterprises worldwide to store engineering data and product designs. The web shell gives attackers a direct path to credential theft and large-scale data exfiltration, with no additional tooling required. Unlike generic command shells, this implant decrypts credentials, delivers malware, and maps stored files for exfiltration."
https://reliaquest.com/blog/clop-returns-with-custom-implant-in-mass-extortion-campaign/
https://www.bleepingcomputer.com/news/security/clop-created-custom-web-shell-for-windchill-data-theft-attacks/ - CISA: Windows Task Host Flaw Now Exploited By Ransomware Gangs
"The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that ransomware gangs are also exploiting a high-severity Windows Task Host vulnerability that was flagged as actively exploited in April. Task Host is a core Windows system component that allows DLL-based processes to run in the background and prevents data corruption by ensuring they close properly during shutdown. Tracked as CVE-2025-60710, this Windows privilege escalation security flaw was patched by Microsoft in November 2025 and stems from a link following weakness that affects Windows 11 and Windows Server 2025 devices."
https://www.bleepingcomputer.com/news/security/cisa-windows-task-host-flaw-now-exploited-by-ransomware-gangs/ - The Mistake That Exposed a Global Cyber Crime Operation
"Most cyber crime investigations reveal the aftermath of an attack. Few reveal the attackers themselves. That’s what makes Check Point Research‘s latest investigation into StopAndProtect so unusual. While analyzing a newly identified cyber crime operation, researchers uncovered a series of operational security (OPSEC) mistakes that exposed the attackers’ own infrastructure including: victim logs, screenshots, source code, internal management tools, and evidence of a campaign impacting more than 5,000 infected computers worldwide. The investigation also uncovered files referencing close to 2,000 compromised WordPress domains, providing a rare look inside how a modern cyber criminal operation is built and managed."
https://blog.checkpoint.com/research/the-mistake-that-exposed-a-global-cyber-crime-operation/
https://research.checkpoint.com/2026/thousands-of-hacked-wordpress-sites-one-operation-unmasking-stopandprotect/ - Living Off The Cloud: A Python Implant Hiding Its Entire C2 Inside Microsoft 365 & Azure
"The Ontinue Cyber Defense Center uncovered an undocumented Python implant framework while investigating an ongoing campaign in July 2026. We track it internally as TWINLOOT, named after its SharePoint C2 folder ‘TwinLoot’. TWINLOOT is a modular, PyArmor-hardened Python implant designed to operate its entire command-and-control infrastructure inside trusted Microsoft services. Tasking flows through SharePoint Online file dead-drops via the Microsoft Graph API. Interactive operator access routes through WebRTC DataChannels relayed by Microsoft Teams TURN servers. Graph API traffic is driven through a headless instance of the victim’s own Edge browser, making it indistinguishable from legitimate user activity."
https://www.ontinue.com/resource/python-implant-hiding-its-entire-c2-inside-microsoft-365-azure/
https://thehackernews.com/2026/08/twinloot-abuses-sharepoint-and-teams-to.html
https://www.darkreading.com/cloud-security/silent-twinloot-threat-operates-microsoft-cloud - Beware The Ransomware Rescuer: Ransom Busters
"The GuidePoint Research and Intelligence Team (GRIT) has responded to several recent ransomware incidents in which victims received an unexpected email from an ostensible third-party entity referring to itself as “Ransom Busters.” In these messages, the third-party offers to help the victim recover from ransomware attack. This immediately stands out as anomalous. While cybersecurity firms commonly reach out to ransomware victims to offer consulting or recovery services, it is generally done only after the attack becomes public knowledge. This ostensible third-party’s insight into an attack that was not yet public is alarming. It raises the question how “Ransom Busters” could know about the incident at all."
https://www.guidepointsecurity.com/blog/beware-ransom-busters/
https://www.darkreading.com/cyberattacks-data-breaches/ransom-busters-ransomware-actor-incident-recovery-service
https://thehackernews.com/2026/08/ransom-busters-claims-it-hacked.html - StubMaker RubyGems Campaign Delivers a Windows Infostealer
"On August 15, 2026, we discovered newly-published RubyGems packages that installs a multi-stage Windows infostealer malware. This new malware harvests browser credentials, cryptocurrency wallets, seed phrases, and Telegram data. All of the malicious Rubygems packages appear to be typosquats of popular Ruby dependencies, but rather than the clever SEO-fueled typosquats we've seen from other threat actors (e.g. events-channel imitating the popular Node.js events module), they're all clumsy typos. But don't let that fool you into not taking them seriously. The threat actor still managed hundreds of downloads before the packages were taken down."
https://opensourcemalware.com/blog/stubmaker-rubygems-windows-infostealer
https://thehackernews.com/2026/08/16-typosquatted-rubygems-packages-steal.html - More Than 200 Victims Of Medusa Ransomware Identified Over The Last Year, CISA Says
"Federal cybersecurity agencies warned on Tuesday that troves of new victims of the Medusa ransomware gang have been identified over the last year. The Cybersecurity and Infrastructure Security Agency (CISA) and FBI updated an advisory on the group initially released in March 2025 — writing that as of April 2026, Medusa actors have hit more than 500 victims. CISA previously said 300 victims, many of which are in critical infrastructure sectors, were attacked as of 2025."
https://therecord.media/more-than-200-medusa-ransomware-victims-in-last-year-cisa
https://cyberscoop.com/medusa-ransomware-tactics-cisa-advisory/ - Hackers Target Ukrainian Agency Managing Assets Seized From Sanctioned Russians
"Ukraine’s agency responsible for managing assets seized from criminals and sanctioned individuals said Tuesday that it had been targeted by a cyberattack as it investigates a potential coordinated effort to disrupt its operations. The Asset Recovery and Management Agency, known as ARMA, manages assets seized by Ukrainian authorities, including those linked to sanctioned Russians and alleged collaborators with Moscow. The agency said the latest attack came amid preparations to select a manager for seized corporate rights in IDS Ukraine, one of the country’s largest producers of bottled mineral water and beverages."
https://therecord.media/hackers-target-ukraine-agency-sanctioned-russians - Weaponized AI: The Commoditization Of Cybercrime
"The Trellix Advanced Research Center has been actively monitoring dark web forums and criminal communication channels for emerging threats tied to artificial intelligence (AI). What we are observing in 2026 is not speculative – it is operational. Underground threat actors are no longer simply discussing AI as a future capability. They are advertising, selling, and deploying AI-enhanced tools and services with increasing sophistication and commercial maturity. This blog documents the findings from our underground intelligence collection efforts, spanning autonomous kill-chain planning engines, uncensored AI-as-a-service platforms, AI-enhanced malware crypters, stolen API credential markets, and AI-assisted insider threat tooling."
https://www.trellix.com/blogs/research/weaponized-ai-commoditization-of-cybercrime/ - Operation ASTERIX: Anatomy Of a Crypto Fraud Pipeline
"Rapid7 researchers identified an exposed web directory on infrastructure used to support a cryptocurrency fraud operation. The server contained raw phone-number datasets, account-validation tools, enriched lead records, phishing panels, voice-dialing scripts, fake wallet applications, persistence mechanisms, and Telegram exfiltration code. Among the artifacts was evidence that the operator relied on AI coding assistants throughout the campaign's development; recovered prompts, shell history, and project files show AI being used to package Electron applications, obfuscate code, troubleshoot builds, modify phishing infrastructure, and prepare malware for distribution."
https://www.rapid7.com/blog/post/tr-operation-asterix-crypto-fraud-vishing-phishing/
Breaches/Hacks/Leaks
- Cyber Incident Disrupts Student Services At UT San Antonio
"IT systems at the University of Texas (UT) San Antonio have been taken offline following a cyber incident, causing significant disruption to student registrations and payments ahead of the start of term this week. A statement released by university leaders on August 17 revealed that the institution had identified “attempted unauthorized activity” at the edge of its network, before reaching core systems. At this point, University Technology Solutions (UTS) took action with expert partners to contain the activity, resulting in some systems being taken offline so a thorough evaluation of the environment can take place and to assess whether additional protections need to be implemented."
https://www.infosecurity-magazine.com/news/cyber-incident-ut-san-antonio/
https://therecord.media/university-of-texas-forced-to-take-systems-offline-cyberattack-san-antonio - Berlin Cuts Two State Ministries Off Government Network After Security Breach
"Two Berlin state ministries have been cut off from the city government’s IT network after authorities discovered a security breach. The affected ministries — one responsible for urban development, construction and housing, and the other for mobility, transport, climate protection and the environment — have been isolated from government networks since Friday as a precaution, the Berlin Senate Chancellery said in a statement on Monday. Officials have not said who was behind the breach, how the attackers gained access or whether any data was stolen. It is also unclear when the intrusion occurred."
https://therecord.media/berlin-cuts-two-state-ministries-off-government-breach
General News
- 17 Iranians Charged With Conducting Massive Cyber Theft Campaign On Behalf Of The Islamic Revolutionary Guard Corps And Other Iranian Entities
"A 14-count superseding (S2) indictment was unsealed today charging 17 members of the Mabna Institute, an Iran-based company that, since at least 2013, has conducted a coordinated campaign of cyber intrusions into computer systems for 144 U.S.-based universities, 178 foreign universities, at least 42 U.S.-based private sector companies, at least 11 foreign private sector companies, at least five U.S. federal and state government agencies, and at least two non-governmental organizations (NGOs). The Mabna Institute stole more than 31 terabytes of academic data and intellectual property from these universities, as well as the email accounts of employees at the private sector companies, government agencies, and NGOs."
https://www.justice.gov/opa/pr/17-iranians-charged-conducting-massive-cyber-theft-campaign-behalf-islamic-revolutionary
https://cyberscoop.com/mabna-institute-iranian-hackers-indictment/ - CISOs Break Their Silence In 'Declassified' Docuseries
"Most attendees at RSAC and Black Hat conferences go to network and learn about emerging threats. But Danielle Lewan, Clint Howard II, and 11 long-time chief information security officers (CISOs) arrive with cameras rolling and a different agenda: turning their breach-response stories into compelling television. Last year, Lewan launched Red Mirror Studios, an independent film studio dedicated to cybersecurity alongside Howard, co-founder and chief creative officer. She founded the studio after working to produce a different docuseries titled "CISO: The Worst Job I Ever Wanted," while director of global marketing at Nagomi Security in 2025."
https://www.darkreading.com/cyber-risk/cisos-break-their-silence-in-declassified-docuseries - A Hollowed Out Data Layer Is Making CISOs Fly Blind Into AI Attacks
"The security industry is currently transitioning to an era where both offense and defense are AI-led, and every SOC operates at machine speed. However, what most CISOs have not yet reckoned with is that the AI defenders they are about to deploy will inherit a data foundation that two years of ingestion cost pressure has quietly hollowed out. The result is a security industry heading into an AI era with less visibility than it had five years ago. In the 2026 SANS SOC Survey, 24% of security leaders named lack of enterprise-wide visibility as their single biggest barrier to effective security operations, ranking it above staffing and automation gaps. That gap is widening at the exact moment offensive AI is closing the distance between attackers and defenders."
https://www.helpnetsecurity.com/2026/08/18/siem-data-blind-spots-mapping/ - Attackers Turn To AI For Help Identifying Files Worth Stealing
"AI tools are being used by cyber attackers to write malicious code, build tools that harvest credentials, search compromised networks, identify valuable business information, manage technical infrastructure and generate commands during intrusions. Gambit Security researchers examined three unrelated threat actors that show how AI can support different stages of a cyberattack. Across the cases, attackers used AI to create scripts and exploitation tools, identify high-value business information, perform IT and DevOps tasks, and generate and refine commands during active intrusions."
https://www.helpnetsecurity.com/2026/08/18/gambit-security-ai-cyberattack-tools-report/ - 2026 Mid-Market Ransomware Report
"The way ransomware gets covered centers on the biggest names and the highest ransoms. That framing leaves the impression that ransomware is mainly an enterprise problem. The data says otherwise. Across three and a half years of attacks, from 2023 through the first half of 2026 in North America and Europe, roughly three in four ransomware victims with a known revenue figure were mid-market companies earning $10 million to $1 billion a year. This is the first time the Black Kite Research Group has studied the mid-market as its own segment, rather than as companies scattered through larger studies."
https://blackkite.com/reports/2026-mid-market-report
https://www.infosecurity-magazine.com/news/threequarters-ransomware-attacks/ - Passwords Stored In Public Google Doc Then Showed Up In Search Results
"Welcome, once again, to PWNED, the weekly column where we highlight others’ security failures. Hopefully, there’s a lesson in all this, but it could just be “stop shooting yourself in the foot.” Our story today comes courtesy of Siim Kostabi, co-founder of Pageloot, a company that provides QR codes businesses can use for marketing. Kostabi’s tale of tech terror reminds us that credentials, even for a staging server, have a lot of value in the wrong hands."
https://www.theregister.com/security/2026/08/13/passwords-stored-in-public-google-doc-then-showed-up-in-search-results/5287028
https://www.malwarebytes.com/blog/news/2026/08/be-careful-what-you-put-in-anyone-with-the-link-google-docs - CISO Conversations: Nico Waisman – From Self-Taught Hacker To AI-Driven Offensive Security At XBOW
"“I don’t think I ever chose a career in cybersecurity. It chose me.” Well, we’ll see… Nico Waisman was born and still lives in Argentina. If what he says is accurate, it suggests he was born in 1982; one year before a seven-year period of military dictatorship in Argentina came to an end. Argentine youngsters in the 1980s lived in a time of youthful rebelliousness against the law and the establishment, lingering after the dictatorships. For Waisman, this youthful rebelliousness turned toward emerging technology. He became fascinated by the idea of being able to subvert this tech into doing something he wanted it to do. In short, he became a young hacker – but it was the challenge and enjoyment of doing it rather than any desire to make money or cause harm from it that drove him."
https://www.securityweek.com/ciso-conversations-nico-waisman-from-self-taught-hacker-to-ai-driven-offensive-security-at-xbow/ - AI-Driven Vulnerability Surge Breaks The Traditional Patching Model
"Recent analysis from Rapid7 demonstrates the fallacy of defenders continuing to rely on patching their way out of problems. “Q2 2026 was not just another busy quarter in cyber. It felt more like a stress test of the way we currently manage exposure. Traditional patch cycles are being overwhelmed by the sheer volume of vulnerabilities and attacker speed and precision,” writes Rapid7 in its latest report titled ‘the compression era’. “Vulnerabilities are being disclosed at higher volume, proof-of-concept code is appearing faster, exploitability is being tested earlier, and attackers are getting better at turning public information into operational access.” SecurityWeek spoke to Christiaan Beek, Rapid7’s VP of cyber intelligence for a deeper understanding of the cause and effect of this stress. But let’s be clear from the start: the compressive force behind this stress test is artificial intelligence (AI)."
https://www.securityweek.com/ai-driven-vulnerability-surge-breaks-the-traditional-patching-model/ - Ukrainian Software Developer Faces 12 Years In Swiss Ransomware Trial
"Swiss prosecutors are seeking a 12-year prison sentence for a Ukrainian software developer linked to an international ransomware operation that caused hundreds of millions of dollars in damage to its victims. The 52-year-old defendant went on trial at Zurich District Court on Monday over his alleged involvement in attacks using LockerGoga, MegaCortex and Nefilim ransomware. His alleged victims included Swiss train manufacturer Stadler Rail, banking software developer Crealogix and building technology company Meier Tobler."
https://therecord.media/ukrainian-software-developer-court-switzerland - How QR-Code Phishing Can Slip Past Corporate Security Measures
"Familiarity might breed contempt. But in the world of cybersecurity, it also breeds complacency, which can be a lot more dangerous. So it is with QR codes, which have become a common sight on menus, lampposts and parking meters – and, increasingly, in emails over recent years. The challenge is that they’re also a great way to disguise malicious links, bypass some traditional corporate security filters, and to move the interaction from a corporate computer to a personal phone with fewer security controls. Attackers will continue to experiment and innovate with new ways to avoid detection. And new “quishing” techniques to snare unwitting employees. Here’s what you need to understand to keep your organization safe."
https://www.welivesecurity.com/en/business-security/qr-code-phishing-slip-past-corporate-security-measures/
อ้างอิง
Electronic Transactions Development Agency (ETDA)
- CISA Malcolm