Cybersecurity Intelligence Report — 20 August 2026

Written by

in

> CRITICAL SECTION

[13] Critical RCE flaw in Windows IKE Extension now actively exploited (BleepingComputer)
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned that hackers are exploiting a critical-severity remote code execution (RCE) flaw in the Windows Internet Key Exchange (IKE) Service Extensions component. […]

[10] Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active Exploitation (TheHackerNews)
CVEs: CVE-2026-65400
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added four critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, stating they are being exploited in the wild. The shortcomings added to the KEV catalog are listed below – CVE-2026-65400 (CVSS score: 9.8) – An improper authentication vulnerability impacting Apple macOS that could allow an

> CISA KEV (last 14 days)

CVE Vendor/Product Score Required action
CVE-2026-64849 [CISA KEV] CVE-2026-64849: MLflow Server-Side Request Forgery Vulnerability – MLflow MLflow 6 MLflow Server-Side Request Forgery Vulnerability – MLflow MLflow. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholde

> RANSOMWARE VICTIMS (today)

  • everest: Grupo DT, Capgemini Engineering
  • xpl0itrs: Target

> NEWS

[8] CISA: Medusa ransomware hit over 500 critical infrastructure orgs (BleepingComputer)
The FBI said Tuesday that the Medusa ransomware gang has breached more than 500 critical infrastructure organizations in the United States since June 2021. […]

[8] CISA Urges Immediate Patching of Exploited Microsoft, VMware, Apple Vulnerabilities (SecurityWeek)
The flaws can be exploited for remote code execution, authentication bypass, and device takeover. The post CISA Urges Immediate Patching of Exploited Microsoft, VMware, Apple Vulnerabilities appeared first on SecurityWeek .

[8] Chrome, Firefox Updates Patch Dozens of Vulnerabilities (SecurityWeek)
The bugs could lead to code execution, privilege escalation, sandbox escape, and information disclosure. The post Chrome, Firefox Updates Patch Dozens of Vulnerabilities appeared first on SecurityWeek .

[8] Medusa ransomware gang has hit over 500 organizations, CISA warns (HelpNetSecurity)
Medusa ransomware has breached more than 500 organizations since it first appeared in June 2021, the FBI, CISA, and the Department of Health and Human Services (HHS) said in an updated joint advisory. The update builds on an advisory first issued in March 2025 and draws on FBI investigations conducted as late as April 2026. “Medusa developers and affiliates have impacted over 500 victims from a variety of critical infrastructure sectors,” the advisory reads, listing … <a hre

[7] Google’s AI security agents found 100+ critical software vulnerabilities in just two days (HelpNetSecurity)
Google’s Mandiant has disclosed the workings of an internal tool that uses chains of AI agents to hunt for vulnerabilities in source code, saying it found over 100 verified, high-severity flaws in just two days during a live investigation into stolen corporate repositories. The tool, called the Agentic Vulnerability Discovery Harness (AVDH), has been running inside Mandiant for ten months. In that time it has scanned tens of millions of lines of code and produced … <a href="https:

[6] Hackers Compromised 14,500+ Dahua Devices Using Credential Attacks, Auth Bypasses, and P2P (TheHackerNews)
Cybersecurity researchers at Hunt.io have disclosed details of a campaign that they say compromised more than 14,530 Dahua devices between June 17 and July 22, 2026, using credential attacks, two authentication-bypass flaws, and a peer-to-peer (P2P) relay technique. The activity, codenamed Operation CameraSwarm, was reconstructed from a 407 MB exposed working directory containing 2,616 files

[6] Clop-Linked Windchill Web Shell Decrypts Credentials and Maps Engineering Data (TheHackerNews)
A JavaServer Pages (JSP) web shell deployed following the exploitation of a critical security flaw in PTC Windchill and FlexPLM servers is specifically designed for the enterprise Product Lifecycle Management (PLM) software, according to new findings from ReliaQuest. The cybersecurity company characterized the web shell as a fully equipped extortion platform capable of mapping sensitive vault

[6] [RANSOMWARE] thegentlemen leaked Babcock (ransomware.live/thegentlemen)
Victim: Babcock | Group: thegentlemen | Website: babcock.co.za | Country: ZA | Details: babcock.co.za rocketreach.co/babcock-international-group-africa-profile_b5cda591f42e0b42 Babcock Africa is a leading engineering and asset management company specializing in critical infrastructure and heavy equipment across the African continent. With over 130 years of experience, it provides lifet

[5] Rogue ransomware affiliate poses as recovery firm to steal payments (BleepingComputer)
A suspected ransomware affiliate is posing as a ransomware recovery service called "Ransom Busters," contacting the victims before the attacks become public and claiming to be able to provide decryption keys and delete stolen data for a fee. […]

[5] [RANSOMWARE] qilin leaked Semana (ransomware.live/qilin)
Victim: Semana | Group: qilin | Website: www.semana.es | Country: ES | Details: N/A

[5] [RANSOMWARE] Helix leaked Delek US (ransomware.live/Helix)
Victim: Delek US | Group: Helix | Country: US | Details: Delek US is live. T1 unlocks in 12 hours, then 24 hours per remaining tier.

[5] [RANSOMWARE] Deadlock leaked UFOC (ransomware.live/Deadlock)
Victim: UFOC | Group: Deadlock | Website: www.ufoc.com.tw/en/company | Country: TW | Details: United Fiber Optic Communication Inc. (UFOC) is an established, publicly traded telecommunications company from Taiwan. The company acts as a total solution provider for communication networks and specializes in the manufacture of fiber optic cables and the provision of integrated technological syst

[5] [RANSOMWARE] Deadlock leaked Global Terminal Services (ransomware.live/Deadlock)
Victim: Global Terminal Services | Group: Deadlock | Website: globalterminal-tr.com | Country: TR | Details: GTS legally registered as Global Terminal Hizmetleri A.Ş. It is the largest independent storage terminal for liquid fuels and oil in the entire Mediterranean region. 470gb

[5] [RANSOMWARE] settra leaked wcmanagement.info (ransomware.live/settra)
Victim: wcmanagement.info | Group: settra | Website: wcmanagement.info | Details: Documents of West Coast Management and Realty PROLOGUE Over 1,000 debt collection records with names…

[5] [RANSOMWARE] settra leaked alphanumeric.com (ransomware.live/settra)
Victim: alphanumeric.com | Group: settra | Website: alphanumeric.com | Country: US | Details: ALPHANUMERIC SYSTEMS, INC.: Internal Documents of an American IT Company PROLOGUE Internal documents…

[5] [RANSOMWARE] settra leaked am-bition.jp (ransomware.live/settra)
Victim: am-bition.jp | Group: settra | Website: am-bition.jp | Country: JP | Details: Internal Documents of the AMBITION Group and Its Insurance Partner Hope SSI PROLOGUE AMBITION Co., L…

[5] [RANSOMWARE] settra leaked grecosteel.com (ransomware.live/settra)
Victim: grecosteel.com | Group: settra | Website: grecosteel.com | Country: GR | Details: How Greco Steel Products Lost Control of Finances and Payroll PROLOGUE: 19 document categories. A co…

[5] [RANSOMWARE] settra leaked makfreight.com (ransomware.live/settra)
Victim: makfreight.com | Group: settra | Website: makfreight.com | Country: MY | Details: M.A.K. Freight Systems: Seven Vulnerabilities of a Canadian Freight Broker PROLOGUE We have in our p…

[5] [RANSOMWARE] xpl0itrs leaked Mihuru (ransomware.live/xpl0itrs)
Victim: Mihuru | Group: xpl0itrs | Details: Consumer travel financing

[5] [RANSOMWARE] krybit leaked sunsea.co.th (ransomware.live/krybit)
Victim: sunsea.co.th | Group: krybit | Website: sunsea.co.th | Country: TH | Details: Sunsea Plastics P.S. Co., Ltd. is a Thai family-owned company established in 1988, headquartered in Bang Na, Bangkok, Th…

> SUMMARY

New items collected: 86. Critical items: 2. Active ransomware groups represented today: 2. CVEs to prioritise for review: CVE-2026-65400, CVE-2026-64849.

Sources: BleepingComputer, TheHackerNews, SecurityWeek, HelpNetSecurity, KrebsOnSecurity, CISA KEV, ransomware.live

Open the companion interactive HTML intelligence report

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *