# Today's Top Stories

August 20, 2026

  1. 1
    0
    The Hacker News general Aug 19
    Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active Exploitation

    CISA added four critical vulnerabilities to its KEV catalog, including CVE-2026-65400 (CVSS 9.8), an improper authentication flaw in Apple macOS, alongside actively exploited bugs in Microsoft SharePoint, VMware vCenter, and Windows IKE. Security teams should prioritize patching these immediately given confirmed in-the-wild exploitation across major enterprise platforms.

  2. 2
    0
    BleepingComputer general Aug 19
    Critical RCE flaw in Windows IKE Extension now actively exploited

    CISA confirmed active exploitation of a critical RCE vulnerability in the Windows Internet Key Exchange (IKE) Service Extensions component, adding it to the KEV catalog. The flaw allows remote code execution without user interaction, making unpatched Windows systems running IKE an immediate priority for remediation.

  3. 3
    0
    BleepingComputer general Aug 19
    US warns of AI-powered attacks on Siemens PLCs in critical infrastructure

    NSA, FBI, and CISA jointly warned that threat actors are deploying AI-generated scripts to attack Siemens S7 Series PLCs used in U.S. critical infrastructure — marking one of the first documented cases of AI-assisted ICS exploitation. The advisory specifically calls out water sector exposure and exploitation of known vulnerabilities in Siemens industrial control systems.

  4. 4
    0
    SecurityWeek general Aug 19
    Cl0p Ransomware Group Names Over 40 Victims of PTC Windchill Campaign

    The Cl0p ransomware group has publicly named over 40 victims of its PTC Windchill campaign, including Shell, Philips, Fiserv, Zebra, Mindray, and Largan Precision. ReliaQuest analysis reveals the JSP web shell deployed post-exploitation is purpose-built for Windchill's PLM environment, capable of decrypting credentials and mapping engineering vault data for extortion.

  5. 5
    0
    BleepingComputer general Aug 19
    Password spraying attacks surge 155x as hackers exploit MFA gaps

    Huntress reported a 155x surge in password spraying attacks in H1 2026, with one campaign generating over 81 million login attempts in two weeks. Attackers specifically targeted legacy authentication protocols and unprotected login flows where MFA policies had gaps, underscoring the need for universal MFA enforcement including on legacy endpoints.

  6. 6
    0
    BleepingComputer general Aug 19
    CISA: Medusa ransomware hit over 500 critical infrastructure orgs

    The FBI and CISA updated their advisory on Medusa ransomware, confirming the group has breached more than 500 U.S. critical infrastructure organizations since June 2021. The updated advisory, co-authored with HHS, details Medusa's initial access techniques and post-compromise behavior based on a year's worth of FBI investigations.

  7. 7
    0
    The Hacker News general Aug 19
    Cloudflare Workers Spectre Attack Leaks JWT From Co-Located Worker at 12 Bits/Second

    Researchers disclosed a remote Spectre-based side-channel attack against Cloudflare Workers that exfiltrated a JWT from a co-located Worker at 12 bits/second in the production environment — 360 times faster than a prior 2021 attack. The attack exploits CPU micro-architectural weaknesses in multi-tenant serverless environments, raising concerns about cross-tenant data isolation in cloud platforms.

  8. 8
    0
    BleepingComputer general Aug 19
    US charges Iranian hackers over $3.4 billion intellectual property theft

    The U.S. DOJ charged 17 Iranians allegedly linked to the Mabna Institute hacking-for-hire operation with stealing $3.4 billion worth of intellectual property from U.S. government agencies and dozens of universities. The State Department is offering up to $10 million rewards for information on five of the named defendants.

  9. 9
    0
    BleepingComputer general Aug 19
    Healthtech firm CareCloud data breach impacts 3.7 million patients

    Healthcare IT firm CareCloud confirmed that a breach of its electronic health record environment — during which an attacker spent eight hours inside the system — ultimately affected 3,756,469 individuals, far exceeding the initially estimated 350,000. The HHS breach tracker now reflects the full impact, making this one of the larger healthcare data breaches reported in 2026.

  10. 10
    0
    BleepingComputer general Aug 18
    Microsoft starts removing WMIC tool used by cybercriminals

    Microsoft has begun removing the Windows Management Instrumentation Command-line (WMIC) tool from Windows 11 24H2, 25H2, and current beta builds, eliminating a utility that threat actors have routinely abused for living-off-the-land attacks. Security teams managing Windows 11 endpoints should audit scripts and tooling that depend on WMIC before broader rollout of affected builds.