DEV Community

NetSecOpsIO
NetSecOpsIO

Posted on Originally published at cyber.netsecops.io

Daily Cybersecurity Intelligence - August 20, 2026

Daily cybersecurity intelligence digest from CyberNetSec.io - August 20, 2026


πŸ“Š 13 threat intelligence reports covering vulnerabilities, exploits, threat actors, and security advisories.


1. US Agencies Warn of AI-Powered Attacks on Siemens PLCs

A joint advisory from CISA, the NSA, FBI, and other U.S. agencies warns of an active threat campaign against Siemens S7 series Programmable Logic Controllers (PLCs). Threat actors are reportedly using artificial intelligence to generate Python-based exploit scripts that masquerade as legitimate monitoring tools. The campaign is focused on reconnaissance against U.S. critical infrastructure, including energy, water, and manufacturing sectors. Attackers are identifying internet-exposed PLCs and leveraging open-source libraries to gain read/write access, posing a significant risk of future disruptive attacks.

πŸ“– Read full report β†’


2. Medusa Ransomware Attacks Surpass 500 Victims

An updated joint advisory from the FBI, CISA, and HHS reveals the Medusa ransomware group has compromised over 500 organizations since June 2021, a sharp increase from previous reports. Operating as a Ransomware-as-a-Service (RaaS), the group targets critical infrastructure sectors including healthcare and defense. Medusa affiliates gain access via initial access brokers and by exploiting unpatched vulnerabilities, sometimes within 24 hours of public disclosure. The group employs a double-extortion model, encrypting data and leaking it on a dark web site if the ransom is not paid.

πŸ“– Read full report β†’


3. Operation CameraSwarm Hacks 14,500 Dahua Devices

A hacking campaign dubbed "Operation CameraSwarm" compromised over 14,500 Dahua IP cameras and NVRs in a 35-day period, primarily in Ukraine and Russia. Researchers at Hunt.io discovered the campaign after the attacker left tools and logs on an exposed server. The operation used a combination of brute-force attacks on port 37777, exploitation of two known authentication-bypass vulnerabilities (CVE-2021-33044 and CVE-2021-33045), and a novel abuse of Dahua's P2P cloud service to compromise devices behind NAT.

πŸ“– Read full report β†’


4. MyDr Healthcare Data Breach Impacts Half of Poland

Polish authorities are investigating a colossal data breach at MyDr, a healthcare software provider, that may have exposed the personal and medical data of nearly 19 million peopleβ€”almost half of Poland's population. Attackers claim to have stolen 2.5 terabytes of data, including national ID numbers (PESEL), medical consultation notes, and prescription details. The incident, believed to be for extortion, is being called one of the largest in the country's history. MyDr provides software to over 12,000 medical facilities across Poland.

πŸ“– Read full report β†’


5. Mid-Market Companies Primary Target of Ransomware

A new report from Black Kite reveals that mid-market companies are the primary target of ransomware attacks, accounting for 73% of all incidents between January 2023 and June 2026. These firms, with revenues between $10 million and $1 billion, are seen as an economic "sweet spot" for attackersβ€”large enough to pay a ransom but often lacking the robust security of large enterprises. The manufacturing sector was the most victimized industry. The report also found that victims often fail to improve their security posture post-attack, with many remaining exposed to known vulnerabilities.

πŸ“– Read full report β†’


6. US Senators Introduce Quantum-GUARD Act

U.S. Senators introduced the bipartisan Quantum Grid Utility Assurance and Resilient Defense (Quantum-GUARD) Act of 2026. The bill aims to protect the nation's electric grid from future cybersecurity threats posed by quantum computers, which could break current encryption standards. The legislation directs the Department of Energy to study quantum risks to the power grid, establish a testing environment for post-quantum cryptography (PQC), and requires FERC to incorporate quantum risks into its reliability standards. The move follows NIST's finalization of PQC standards in 2024.

πŸ“– Read full report β†’


7. CISA KEV Catalog Updated with Four Critical Flaws

CISA has added four critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, indicating they are under active attack. The flaws affect Apple macOS, Microsoft SharePoint, VMware vCenter, and Microsoft's IKE service. The vulnerabilities include an improper authentication flaw in macOS Screen Sharing (CVE-2026-65400), a weak authentication flaw in SharePoint (CVE-2026-55040), a path traversal RCE in vCenter (CVE-2026-59310), and a double free RCE in Microsoft IKE (CVE-2026-33824). Federal agencies are mandated to patch these flaws by a specified deadline.

πŸ“– Read full report β†’


8. SilkParasite Campaign Targets Central Asia with New RATs

Bitdefender has uncovered a cyberespionage campaign named "SilkParasite," attributed with medium confidence to a China-nexus threat actor. Active since October 2025, the campaign targets government entities involved in economic decision-making in Central Asian countries like Uzbekistan and Kazakhstan. The attackers use spear-phishing and DLL sideloading to deploy seven RAT families, five of which were previously undocumented. One notable RAT, DriveSilkRAT, uses Google Drive for command and control, helping it to evade detection by blending in with legitimate cloud traffic.

πŸ“– Read full report β†’


9. Zombie Card Attack Revives Expired Visa Cards

Researchers have developed a proof-of-concept attack called "Zombie Card" that can force expired Visa contactless cards to be accepted for payments. The attack requires physical proximity to the card and uses a man-in-the-middle relay, such as two NFC-enabled phones, to intercept and alter the expiration date sent to the payment terminal. This allows offline transactions to be approved on the terminal, even though the card is expired. The researchers successfully demonstrated the attack and disclosed it to Visa, but no specific mitigation has been announced.

πŸ“– Read full report β†’


10. Operation ShadowRecruit Spreads SheetAgent RAT in India

A malware campaign in India, dubbed "Operation ShadowRecruit," is targeting job seekers with a new Remote Access Trojan (RAT) called "SheetAgent." Discovered by Seqrite, the campaign uses convincing fake recruitment notices for Indian government positions to lure victims. The multi-stage attack uses a malicious LNK file and PowerShell to deploy the RAT. In a novel twist, SheetAgent uses Google Sheets as a resilient, backup command-and-control (C2) channel, allowing it to receive commands and exfiltrate data by reading from and writing to a spreadsheet.

πŸ“– Read full report β†’


11. NIST Publishes New Guidance for BACS Security

The U.S. National Institute of Standards and Technology (NIST) has released new guidance to help organizations secure their Building Automation and Control Systems (BACS). Aimed at resource-constrained operators, the guidance provides practical, actionable steps to harden critical OT systems that manage functions like HVAC, lighting, and access control. Key recommendations include disabling unused services, segmenting networks, enforcing strong access control with MFA for remote access, and maintaining offline backups to protect against ransomware.

πŸ“– Read full report β†’


12. Balonx Sistema PhaaS Targets Mexican Banking Sector

Group-IB has exposed a sophisticated Phishing-as-a-Service (PhaaS) platform named "Balonx Sistema" that is enabling widespread financial fraud against customers of over 20 banks in Mexico. The platform provides subscribers with real-time phishing kits that use WebSockets to intercept credentials and 2FA codes live. The operation, promoted on Facebook, also distributes a malicious Android application based on the Spyroid RAT to gain persistent control over victims' mobile devices, highlighting a multi-faceted approach to financial theft.

πŸ“– Read full report β†’


13. Identity Abuse via Trusted Communication Channels

Unit 42 researchers have identified a significant increase in threat actors abusing enterprise collaboration platforms like Microsoft Teams and Slack for malicious purposes. Attackers are moving beyond traditional email phishing to exploit the trust inherent in these authenticated environments. These campaigns involve identity phishing, credential theft, social engineering, and malware delivery, often initiated from compromised accounts, external federations, or guest access. With malicious activity quadrupling over the past year, this report analyzes the common attack pathways, TTPs including impersonation and adversary-in-the-middle techniques, and provides critical defense strategies for securing the modern collaboration-centric attack surface.

πŸ“– Read full report β†’


πŸ“Œ Subscribe to daily updates at CyberNetSec.io

All reports include detailed analysis, IOCs, mitigation strategies, and references.

Top comments (0)