# Archive

Browse past daily curated stories

Aug 20 Aug 19 Aug 18 Aug 16 Aug 15 Aug 14 Aug 13 Aug 12 Aug 09 Aug 08 Aug 07 Aug 06 Aug 05 Aug 04 Aug 03 Aug 02 Aug 01 Jul 31 Jul 30 Jul 29 Jul 28 Jul 27 Jul 26 Jul 25 Jul 24 Jul 23 Jul 22 Jul 21 Jul 19 Jul 18

Thursday, August 20, 2026

  1. 1
    0
    The Hacker News general
    Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active Exploitation

    CISA added four critical vulnerabilities to its KEV catalog, including CVE-2026-65400 (CVSS 9.8), an improper authentication flaw in Apple macOS, alongside actively exploited bugs in Microsoft SharePoint, VMware vCenter, and Windows IKE. Security teams should prioritize patching these immediately given confirmed in-the-wild exploitation across major enterprise platforms.

  2. 2
    0
    BleepingComputer general
    Critical RCE flaw in Windows IKE Extension now actively exploited

    CISA confirmed active exploitation of a critical RCE vulnerability in the Windows Internet Key Exchange (IKE) Service Extensions component, adding it to the KEV catalog. The flaw allows remote code execution without user interaction, making unpatched Windows systems running IKE an immediate priority for remediation.

  3. 3
    0
    BleepingComputer general
    US warns of AI-powered attacks on Siemens PLCs in critical infrastructure

    NSA, FBI, and CISA jointly warned that threat actors are deploying AI-generated scripts to attack Siemens S7 Series PLCs used in U.S. critical infrastructure — marking one of the first documented cases of AI-assisted ICS exploitation. The advisory specifically calls out water sector exposure and exploitation of known vulnerabilities in Siemens industrial control systems.

  4. 4
    0
    SecurityWeek general
    Cl0p Ransomware Group Names Over 40 Victims of PTC Windchill Campaign

    The Cl0p ransomware group has publicly named over 40 victims of its PTC Windchill campaign, including Shell, Philips, Fiserv, Zebra, Mindray, and Largan Precision. ReliaQuest analysis reveals the JSP web shell deployed post-exploitation is purpose-built for Windchill's PLM environment, capable of decrypting credentials and mapping engineering vault data for extortion.

  5. 5
    0
    BleepingComputer general
    Password spraying attacks surge 155x as hackers exploit MFA gaps

    Huntress reported a 155x surge in password spraying attacks in H1 2026, with one campaign generating over 81 million login attempts in two weeks. Attackers specifically targeted legacy authentication protocols and unprotected login flows where MFA policies had gaps, underscoring the need for universal MFA enforcement including on legacy endpoints.

  6. 6
    0
    BleepingComputer general
    CISA: Medusa ransomware hit over 500 critical infrastructure orgs

    The FBI and CISA updated their advisory on Medusa ransomware, confirming the group has breached more than 500 U.S. critical infrastructure organizations since June 2021. The updated advisory, co-authored with HHS, details Medusa's initial access techniques and post-compromise behavior based on a year's worth of FBI investigations.

  7. 7
    0
    The Hacker News general
    Cloudflare Workers Spectre Attack Leaks JWT From Co-Located Worker at 12 Bits/Second

    Researchers disclosed a remote Spectre-based side-channel attack against Cloudflare Workers that exfiltrated a JWT from a co-located Worker at 12 bits/second in the production environment — 360 times faster than a prior 2021 attack. The attack exploits CPU micro-architectural weaknesses in multi-tenant serverless environments, raising concerns about cross-tenant data isolation in cloud platforms.

  8. 8
    0
    BleepingComputer general
    US charges Iranian hackers over $3.4 billion intellectual property theft

    The U.S. DOJ charged 17 Iranians allegedly linked to the Mabna Institute hacking-for-hire operation with stealing $3.4 billion worth of intellectual property from U.S. government agencies and dozens of universities. The State Department is offering up to $10 million rewards for information on five of the named defendants.

  9. 9
    0
    BleepingComputer general
    Healthtech firm CareCloud data breach impacts 3.7 million patients

    Healthcare IT firm CareCloud confirmed that a breach of its electronic health record environment — during which an attacker spent eight hours inside the system — ultimately affected 3,756,469 individuals, far exceeding the initially estimated 350,000. The HHS breach tracker now reflects the full impact, making this one of the larger healthcare data breaches reported in 2026.

  10. 10
    0
    BleepingComputer general
    Microsoft starts removing WMIC tool used by cybercriminals

    Microsoft has begun removing the Windows Management Instrumentation Command-line (WMIC) tool from Windows 11 24H2, 25H2, and current beta builds, eliminating a utility that threat actors have routinely abused for living-off-the-land attacks. Security teams managing Windows 11 endpoints should audit scripts and tooling that depend on WMIC before broader rollout of affected builds.