Daily cybersecurity intelligence digest from CyberNetSec.io - August 21, 2026
📊 8 threat intelligence reports covering vulnerabilities, exploits, threat actors, and security advisories.
1. Medusa Ransomware Hits 500+ Critical Infrastructure Victims
A joint advisory from CISA, FBI, and HHS warns that the Medusa ransomware operation has now compromised over 500 critical infrastructure organizations globally. The update highlights the RaaS group's rapid growth since adopting an affiliate model, its aggressive exploitation of new vulnerabilities, and its frequent targeting of the Healthcare and Public Health (HPH) sector.
2. NSA & ISASecure to Develop OT Security Certification for NSS
The U.S. National Security Agency (NSA) is partnering with ISASecure to develop the High Criticality Component Security Assurance (HCSA) certification. This new scheme aims to increase the security and supply chain confidence of commercial operational technology (OT) components procured for use in high-stakes U.S. National Security Systems (NSS), building upon the ISA/IEC 62443 standard.
3. AI-Generated Scripts Target Siemens PLCs in Active Threat
A joint advisory from five U.S. federal agencies, including the NSA and CISA, warns of an active threat targeting Siemens S7 Series PLCs in critical infrastructure. Attackers are reportedly using Artificial Intelligence (AI) to generate exploit scripts from public information, dramatically lowering the barrier to entry for attacking internet-exposed industrial controllers and disrupting critical processes.
4. Over 14,500 Dahua Cameras Hacked in Operation CameraSwarm
A hacking campaign dubbed "Operation CameraSwarm" has compromised over 14,530 Dahua IP cameras and recorders, primarily in Ukraine and Russia. Researchers at Hunt.io report the attackers used a mix of credential stuffing, exploitation of critical authentication-bypass vulnerabilities (CVE-2021-33044, CVE-2021-33045), and abuse of Dahua's P2P feature to gain access and install a persistent backdoor.
5. CISA KEV: TrueConf Server RCE Flaws Actively Exploited
CISA has added two critical vulnerabilities in TrueConf Server (CVE-2026-72529 and CVE-2026-72530) to its Known Exploited Vulnerabilities (KEV) catalog, citing active exploitation. Attackers are chaining the flaws to achieve unauthenticated remote code execution (RCE), escape a sandbox environment, and deploy backdoors like PhantomCore with the highest system privileges.
6. Majinahanashi Ransomware Targets Hotels in UK and Malaysia
A newly identified ransomware group named 'Majinahanashi' has claimed responsibility for attacks against hotels in the UK and Malaysia. The Windows-based ransomware, tracked by CYFIRMA, employs a double-extortion model and exhibits sophisticated defense evasion and recovery inhibition capabilities, including deleting Volume Shadow Copies and clearing Windows event logs before encryption.
7. APT36 Uses PATCHCORD Backdoor in Espionage Campaign
The cyber-espionage group APT36 (Transparent Tribe) is suspected to be behind a new campaign targeting telecommunications and critical infrastructure in South Asia. The campaign uses a new malware family, including a primary backdoor named PATCHCORD, and leverages legitimate cloud services like Google Sheets and GitHub Gists for command-and-control, making detection more challenging.
8. Active Exploits Target Critical SPIP CMS RCE (CVE-2026-77647)
A critical unauthenticated remote code execution (RCE) vulnerability, CVE-2026-77647, is being actively exploited in the SPIP content management system. The flaw, rated 9.8 CVSS, affects all versions prior to 4.4.20 and allows a remote attacker to gain full control of a vulnerable server with no user interaction, prompting an urgent call for administrators to patch immediately.
📌 Subscribe to daily updates at CyberNetSec.io
All reports include detailed analysis, IOCs, mitigation strategies, and references.
Top comments (0)