Daily cybersecurity intelligence digest from CyberNetSec.io - August 20, 2026
π 13 threat intelligence reports covering vulnerabilities, exploits, threat actors, and security advisories.
1. US Agencies Warn of AI-Powered Attacks on Siemens PLCs
A joint advisory from CISA, the NSA, FBI, and other U.S. agencies warns of an active threat campaign against Siemens S7 series Programmable Logic Controllers (PLCs). Threat actors are reportedly using artificial intelligence to generate Python-based exploit scripts that masquerade as legitimate monitoring tools. The campaign is focused on reconnaissance against U.S. critical infrastructure, including energy, water, and manufacturing sectors. Attackers are identifying internet-exposed PLCs and leveraging open-source libraries to gain read/write access, posing a significant risk of future disruptive attacks.
2. Medusa Ransomware Attacks Surpass 500 Victims
An updated joint advisory from the FBI, CISA, and HHS reveals the Medusa ransomware group has compromised over 500 organizations since June 2021, a sharp increase from previous reports. Operating as a Ransomware-as-a-Service (RaaS), the group targets critical infrastructure sectors including healthcare and defense. Medusa affiliates gain access via initial access brokers and by exploiting unpatched vulnerabilities, sometimes within 24 hours of public disclosure. The group employs a double-extortion model, encrypting data and leaking it on a dark web site if the ransom is not paid.
3. Operation CameraSwarm Hacks 14,500 Dahua Devices
A hacking campaign dubbed "Operation CameraSwarm" compromised over 14,500 Dahua IP cameras and NVRs in a 35-day period, primarily in Ukraine and Russia. Researchers at Hunt.io discovered the campaign after the attacker left tools and logs on an exposed server. The operation used a combination of brute-force attacks on port 37777, exploitation of two known authentication-bypass vulnerabilities (CVE-2021-33044 and CVE-2021-33045), and a novel abuse of Dahua's P2P cloud service to compromise devices behind NAT.
4. MyDr Healthcare Data Breach Impacts Half of Poland
Polish authorities are investigating a colossal data breach at MyDr, a healthcare software provider, that may have exposed the personal and medical data of nearly 19 million peopleβalmost half of Poland's population. Attackers claim to have stolen 2.5 terabytes of data, including national ID numbers (PESEL), medical consultation notes, and prescription details. The incident, believed to be for extortion, is being called one of the largest in the country's history. MyDr provides software to over 12,000 medical facilities across Poland.
5. Mid-Market Companies Primary Target of Ransomware
A new report from Black Kite reveals that mid-market companies are the primary target of ransomware attacks, accounting for 73% of all incidents between January 2023 and June 2026. These firms, with revenues between $10 million and $1 billion, are seen as an economic "sweet spot" for attackersβlarge enough to pay a ransom but often lacking the robust security of large enterprises. The manufacturing sector was the most victimized industry. The report also found that victims often fail to improve their security posture post-attack, with many remaining exposed to known vulnerabilities.
6. US Senators Introduce Quantum-GUARD Act
U.S. Senators introduced the bipartisan Quantum Grid Utility Assurance and Resilient Defense (Quantum-GUARD) Act of 2026. The bill aims to protect the nation's electric grid from future cybersecurity threats posed by quantum computers, which could break current encryption standards. The legislation directs the Department of Energy to study quantum risks to the power grid, establish a testing environment for post-quantum cryptography (PQC), and requires FERC to incorporate quantum risks into its reliability standards. The move follows NIST's finalization of PQC standards in 2024.
7. CISA KEV Catalog Updated with Four Critical Flaws
CISA has added four critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, indicating they are under active attack. The flaws affect Apple macOS, Microsoft SharePoint, VMware vCenter, and Microsoft's IKE service. The vulnerabilities include an improper authentication flaw in macOS Screen Sharing (CVE-2026-65400), a weak authentication flaw in SharePoint (CVE-2026-55040), a path traversal RCE in vCenter (CVE-2026-59310), and a double free RCE in Microsoft IKE (CVE-2026-33824). Federal agencies are mandated to patch these flaws by a specified deadline.
8. SilkParasite Campaign Targets Central Asia with New RATs
Bitdefender has uncovered a cyberespionage campaign named "SilkParasite," attributed with medium confidence to a China-nexus threat actor. Active since October 2025, the campaign targets government entities involved in economic decision-making in Central Asian countries like Uzbekistan and Kazakhstan. The attackers use spear-phishing and DLL sideloading to deploy seven RAT families, five of which were previously undocumented. One notable RAT, DriveSilkRAT, uses Google Drive for command and control, helping it to evade detection by blending in with legitimate cloud traffic.
9. Zombie Card Attack Revives Expired Visa Cards
Researchers have developed a proof-of-concept attack called "Zombie Card" that can force expired Visa contactless cards to be accepted for payments. The attack requires physical proximity to the card and uses a man-in-the-middle relay, such as two NFC-enabled phones, to intercept and alter the expiration date sent to the payment terminal. This allows offline transactions to be approved on the terminal, even though the card is expired. The researchers successfully demonstrated the attack and disclosed it to Visa, but no specific mitigation has been announced.
10. Operation ShadowRecruit Spreads SheetAgent RAT in India
A malware campaign in India, dubbed "Operation ShadowRecruit," is targeting job seekers with a new Remote Access Trojan (RAT) called "SheetAgent." Discovered by Seqrite, the campaign uses convincing fake recruitment notices for Indian government positions to lure victims. The multi-stage attack uses a malicious LNK file and PowerShell to deploy the RAT. In a novel twist, SheetAgent uses Google Sheets as a resilient, backup command-and-control (C2) channel, allowing it to receive commands and exfiltrate data by reading from and writing to a spreadsheet.
11. NIST Publishes New Guidance for BACS Security
The U.S. National Institute of Standards and Technology (NIST) has released new guidance to help organizations secure their Building Automation and Control Systems (BACS). Aimed at resource-constrained operators, the guidance provides practical, actionable steps to harden critical OT systems that manage functions like HVAC, lighting, and access control. Key recommendations include disabling unused services, segmenting networks, enforcing strong access control with MFA for remote access, and maintaining offline backups to protect against ransomware.
12. Balonx Sistema PhaaS Targets Mexican Banking Sector
Group-IB has exposed a sophisticated Phishing-as-a-Service (PhaaS) platform named "Balonx Sistema" that is enabling widespread financial fraud against customers of over 20 banks in Mexico. The platform provides subscribers with real-time phishing kits that use WebSockets to intercept credentials and 2FA codes live. The operation, promoted on Facebook, also distributes a malicious Android application based on the Spyroid RAT to gain persistent control over victims' mobile devices, highlighting a multi-faceted approach to financial theft.
13. Identity Abuse via Trusted Communication Channels
Unit 42 researchers have identified a significant increase in threat actors abusing enterprise collaboration platforms like Microsoft Teams and Slack for malicious purposes. Attackers are moving beyond traditional email phishing to exploit the trust inherent in these authenticated environments. These campaigns involve identity phishing, credential theft, social engineering, and malware delivery, often initiated from compromised accounts, external federations, or guest access. With malicious activity quadrupling over the past year, this report analyzes the common attack pathways, TTPs including impersonation and adversary-in-the-middle techniques, and provides critical defense strategies for securing the modern collaboration-centric attack surface.
π Subscribe to daily updates at CyberNetSec.io
All reports include detailed analysis, IOCs, mitigation strategies, and references.
Top comments (0)