The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned that hackers are exploiting a critical-severity remote code execution (RCE) flaw in the Windows Internet Key Exchange (IKE) Service Extensions component. [...]
Cybersecurity Intelligence Report — 20 August 2026
CRITICAL 2
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added four critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, stating they are being exploited in the wild. The shortcomings added to the KEV catalog are listed below - CVE-2026-65400 (CVSS score: 9.8) - An improper authentication vulnerability impacting Apple macOS that could allow an
KEV 1
MLflow Server-Side Request Forgery Vulnerability - MLflow MLflow. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.. Due: 2026-09-02
DLS VICTIMS 3
Victim: Grupo DT | Group: everest | Country: MX | Details: [AI generated] N/A
Victim: Capgemini Engineering | Group: everest | Country: FR | Details: [AI generated] Capgemini Engineering is a global technology and engineering services company headquartered in France. It provides R&D and engineering outsourcing services across industries including aerospace, automotive, telecommunications, energy, and semiconductors. Operating in over 30 countries
Victim: Target | Group: xpl0itrs | Country: US | Details: General merchandise retail
NEWS 20
The FBI said Tuesday that the Medusa ransomware gang has breached more than 500 critical infrastructure organizations in the United States since June 2021. [...]
The flaws can be exploited for remote code execution, authentication bypass, and device takeover. The post CISA Urges Immediate Patching of Exploited Microsoft, VMware, Apple Vulnerabilities appeared first on SecurityWeek .
The bugs could lead to code execution, privilege escalation, sandbox escape, and information disclosure. The post Chrome, Firefox Updates Patch Dozens of Vulnerabilities appeared first on SecurityWeek .
Medusa ransomware has breached more than 500 organizations since it first appeared in June 2021, the FBI, CISA, and the Department of Health and Human Services (HHS) said in an updated joint advisory. The update builds on an advisory first issued in March 2025 and draws on FBI investigations conducted as late as April 2026. “Medusa developers and affiliates have impacted over 500 victims from a variety of critical infrastructure sectors,” the advisory reads, listing … <a hre
Google’s Mandiant has disclosed the workings of an internal tool that uses chains of AI agents to hunt for vulnerabilities in source code, saying it found over 100 verified, high-severity flaws in just two days during a live investigation into stolen corporate repositories. The tool, called the Agentic Vulnerability Discovery Harness (AVDH), has been running inside Mandiant for ten months. In that time it has scanned tens of millions of lines of code and produced … <a href="https:
Cybersecurity researchers at Hunt.io have disclosed details of a campaign that they say compromised more than 14,530 Dahua devices between June 17 and July 22, 2026, using credential attacks, two authentication-bypass flaws, and a peer-to-peer (P2P) relay technique. The activity, codenamed Operation CameraSwarm, was reconstructed from a 407 MB exposed working directory containing 2,616 files
A JavaServer Pages (JSP) web shell deployed following the exploitation of a critical security flaw in PTC Windchill and FlexPLM servers is specifically designed for the enterprise Product Lifecycle Management (PLM) software, according to new findings from ReliaQuest. The cybersecurity company characterized the web shell as a fully equipped extortion platform capable of mapping sensitive vault
Victim: Babcock | Group: thegentlemen | Website: babcock.co.za | Country: ZA | Details: babcock.co.za rocketreach.co/babcock-international-group-africa-profile_b5cda591f42e0b42 Babcock Africa is a leading engineering and asset management company specializing in critical infrastructure and heavy equipment across the African continent. With over 130 years of experience, it provides lifet
A suspected ransomware affiliate is posing as a ransomware recovery service called "Ransom Busters," contacting the victims before the attacks become public and claiming to be able to provide decryption keys and delete stolen data for a fee. [...]
Victim: Semana | Group: qilin | Website: www.semana.es | Country: ES | Details: N/A
Victim: Delek US | Group: Helix | Country: US | Details: Delek US is live. T1 unlocks in 12 hours, then 24 hours per remaining tier.
Victim: UFOC | Group: Deadlock | Website: www.ufoc.com.tw/en/company | Country: TW | Details: United Fiber Optic Communication Inc. (UFOC) is an established, publicly traded telecommunications company from Taiwan. The company acts as a total solution provider for communication networks and specializes in the manufacture of fiber optic cables and the provision of integrated technological syst
Victim: Global Terminal Services | Group: Deadlock | Website: globalterminal-tr.com | Country: TR | Details: GTS legally registered as Global Terminal Hizmetleri A.Ş. It is the largest independent storage terminal for liquid fuels and oil in the entire Mediterranean region. 470gb
Victim: wcmanagement.info | Group: settra | Website: wcmanagement.info | Details: Documents of West Coast Management and Realty PROLOGUE Over 1,000 debt collection records with names...
Victim: alphanumeric.com | Group: settra | Website: alphanumeric.com | Country: US | Details: ALPHANUMERIC SYSTEMS, INC.: Internal Documents of an American IT Company PROLOGUE Internal documents...
Victim: am-bition.jp | Group: settra | Website: am-bition.jp | Country: JP | Details: Internal Documents of the AMBITION Group and Its Insurance Partner Hope SSI PROLOGUE AMBITION Co., L...
Victim: grecosteel.com | Group: settra | Website: grecosteel.com | Country: GR | Details: How Greco Steel Products Lost Control of Finances and Payroll PROLOGUE: 19 document categories. A co...
Victim: makfreight.com | Group: settra | Website: makfreight.com | Country: MY | Details: M.A.K. Freight Systems: Seven Vulnerabilities of a Canadian Freight Broker PROLOGUE We have in our p...
Victim: Mihuru | Group: xpl0itrs | Details: Consumer travel financing
Victim: sunsea.co.th | Group: krybit | Website: sunsea.co.th | Country: TH | Details: Sunsea Plastics P.S. Co., Ltd. is a Thai family-owned company established in 1988, headquartered in Bang Na, Bangkok, Th...