HERMES // CYBER INTELLIGENCE // 2026-08-20

Cybersecurity Intelligence Report — 20 August 2026

CRITICAL 2

[10] Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active Exploitation

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added four critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, stating they are being exploited in the wild. The shortcomings added to the KEV catalog are listed below - CVE-2026-65400 (CVSS score: 9.8) - An improper authentication vulnerability impacting Apple macOS that could allow an

KEV 1

[6] [CISA KEV] CVE-2026-64849: MLflow Server-Side Request Forgery Vulnerability - MLflow MLflow

MLflow Server-Side Request Forgery Vulnerability - MLflow MLflow. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.. Due: 2026-09-02

DLS VICTIMS 3

[5] [RANSOMWARE] everest leaked Capgemini Engineering

Victim: Capgemini Engineering | Group: everest | Country: FR | Details: [AI generated] Capgemini Engineering is a global technology and engineering services company headquartered in France. It provides R&D and engineering outsourcing services across industries including aerospace, automotive, telecommunications, energy, and semiconductors. Operating in over 30 countries

NEWS 20

[8] Medusa ransomware gang has hit over 500 organizations, CISA warns

Medusa ransomware has breached more than 500 organizations since it first appeared in June 2021, the FBI, CISA, and the Department of Health and Human Services (HHS) said in an updated joint advisory. The update builds on an advisory first issued in March 2025 and draws on FBI investigations conducted as late as April 2026. “Medusa developers and affiliates have impacted over 500 victims from a variety of critical infrastructure sectors,” the advisory reads, listing … <a hre

[7] Google’s AI security agents found 100+ critical software vulnerabilities in just two days

Google’s Mandiant has disclosed the workings of an internal tool that uses chains of AI agents to hunt for vulnerabilities in source code, saying it found over 100 verified, high-severity flaws in just two days during a live investigation into stolen corporate repositories. The tool, called the Agentic Vulnerability Discovery Harness (AVDH), has been running inside Mandiant for ten months. In that time it has scanned tens of millions of lines of code and produced … <a href="https:

[6] Hackers Compromised 14,500+ Dahua Devices Using Credential Attacks, Auth Bypasses, and P2P

Cybersecurity researchers at Hunt.io have disclosed details of a campaign that they say compromised more than 14,530 Dahua devices between June 17 and July 22, 2026, using credential attacks, two authentication-bypass flaws, and a peer-to-peer (P2P) relay technique. The activity, codenamed Operation CameraSwarm, was reconstructed from a 407 MB exposed working directory containing 2,616 files

[6] Clop-Linked Windchill Web Shell Decrypts Credentials and Maps Engineering Data

A JavaServer Pages (JSP) web shell deployed following the exploitation of a critical security flaw in PTC Windchill and FlexPLM servers is specifically designed for the enterprise Product Lifecycle Management (PLM) software, according to new findings from ReliaQuest. The cybersecurity company characterized the web shell as a fully equipped extortion platform capable of mapping sensitive vault

[6] [RANSOMWARE] thegentlemen leaked Babcock

Victim: Babcock | Group: thegentlemen | Website: babcock.co.za | Country: ZA | Details: babcock.co.za rocketreach.co/babcock-international-group-africa-profile_b5cda591f42e0b42 Babcock Africa is a leading engineering and asset management company specializing in critical infrastructure and heavy equipment across the African continent. With over 130 years of experience, it provides lifet

[5] [RANSOMWARE] Helix leaked Delek US

Victim: Delek US | Group: Helix | Country: US | Details: Delek US is live. T1 unlocks in 12 hours, then 24 hours per remaining tier.

[5] [RANSOMWARE] Deadlock leaked UFOC

Victim: UFOC | Group: Deadlock | Website: www.ufoc.com.tw/en/company | Country: TW | Details: United Fiber Optic Communication Inc. (UFOC) is an established, publicly traded telecommunications company from Taiwan. The company acts as a total solution provider for communication networks and specializes in the manufacture of fiber optic cables and the provision of integrated technological syst

[5] [RANSOMWARE] Deadlock leaked Global Terminal Services

Victim: Global Terminal Services | Group: Deadlock | Website: globalterminal-tr.com | Country: TR | Details: GTS legally registered as Global Terminal Hizmetleri A.Ş. It is the largest independent storage terminal for liquid fuels and oil in the entire Mediterranean region. 470gb

[5] [RANSOMWARE] settra leaked wcmanagement.info

Victim: wcmanagement.info | Group: settra | Website: wcmanagement.info | Details: Documents of West Coast Management and Realty PROLOGUE Over 1,000 debt collection records with names...

[5] [RANSOMWARE] settra leaked alphanumeric.com

Victim: alphanumeric.com | Group: settra | Website: alphanumeric.com | Country: US | Details: ALPHANUMERIC SYSTEMS, INC.: Internal Documents of an American IT Company PROLOGUE Internal documents...

[5] [RANSOMWARE] settra leaked am-bition.jp

Victim: am-bition.jp | Group: settra | Website: am-bition.jp | Country: JP | Details: Internal Documents of the AMBITION Group and Its Insurance Partner Hope SSI PROLOGUE AMBITION Co., L...

[5] [RANSOMWARE] settra leaked grecosteel.com

Victim: grecosteel.com | Group: settra | Website: grecosteel.com | Country: GR | Details: How Greco Steel Products Lost Control of Finances and Payroll PROLOGUE: 19 document categories. A co...

[5] [RANSOMWARE] settra leaked makfreight.com

Victim: makfreight.com | Group: settra | Website: makfreight.com | Country: MY | Details: M.A.K. Freight Systems: Seven Vulnerabilities of a Canadian Freight Broker PROLOGUE We have in our p...

[5] [RANSOMWARE] krybit leaked sunsea.co.th

Victim: sunsea.co.th | Group: krybit | Website: sunsea.co.th | Country: TH | Details: Sunsea Plastics P.S. Co., Ltd. is a Thai family-owned company established in 1988, headquartered in Bang Na, Bangkok, Th...