DEV Community

NetSecOpsIO
NetSecOpsIO

Posted on Originally published at cyber.netsecops.io

Daily Cybersecurity Intelligence - August 21, 2026

Daily cybersecurity intelligence digest from CyberNetSec.io - August 21, 2026


📊 8 threat intelligence reports covering vulnerabilities, exploits, threat actors, and security advisories.


1. Medusa Ransomware Hits 500+ Critical Infrastructure Victims

A joint advisory from CISA, FBI, and HHS warns that the Medusa ransomware operation has now compromised over 500 critical infrastructure organizations globally. The update highlights the RaaS group's rapid growth since adopting an affiliate model, its aggressive exploitation of new vulnerabilities, and its frequent targeting of the Healthcare and Public Health (HPH) sector.

📖 Read full report →


2. NSA & ISASecure to Develop OT Security Certification for NSS

The U.S. National Security Agency (NSA) is partnering with ISASecure to develop the High Criticality Component Security Assurance (HCSA) certification. This new scheme aims to increase the security and supply chain confidence of commercial operational technology (OT) components procured for use in high-stakes U.S. National Security Systems (NSS), building upon the ISA/IEC 62443 standard.

📖 Read full report →


3. AI-Generated Scripts Target Siemens PLCs in Active Threat

A joint advisory from five U.S. federal agencies, including the NSA and CISA, warns of an active threat targeting Siemens S7 Series PLCs in critical infrastructure. Attackers are reportedly using Artificial Intelligence (AI) to generate exploit scripts from public information, dramatically lowering the barrier to entry for attacking internet-exposed industrial controllers and disrupting critical processes.

📖 Read full report →


4. Over 14,500 Dahua Cameras Hacked in Operation CameraSwarm

A hacking campaign dubbed "Operation CameraSwarm" has compromised over 14,530 Dahua IP cameras and recorders, primarily in Ukraine and Russia. Researchers at Hunt.io report the attackers used a mix of credential stuffing, exploitation of critical authentication-bypass vulnerabilities (CVE-2021-33044, CVE-2021-33045), and abuse of Dahua's P2P feature to gain access and install a persistent backdoor.

📖 Read full report →


5. CISA KEV: TrueConf Server RCE Flaws Actively Exploited

CISA has added two critical vulnerabilities in TrueConf Server (CVE-2026-72529 and CVE-2026-72530) to its Known Exploited Vulnerabilities (KEV) catalog, citing active exploitation. Attackers are chaining the flaws to achieve unauthenticated remote code execution (RCE), escape a sandbox environment, and deploy backdoors like PhantomCore with the highest system privileges.

📖 Read full report →


6. Majinahanashi Ransomware Targets Hotels in UK and Malaysia

A newly identified ransomware group named 'Majinahanashi' has claimed responsibility for attacks against hotels in the UK and Malaysia. The Windows-based ransomware, tracked by CYFIRMA, employs a double-extortion model and exhibits sophisticated defense evasion and recovery inhibition capabilities, including deleting Volume Shadow Copies and clearing Windows event logs before encryption.

📖 Read full report →


7. APT36 Uses PATCHCORD Backdoor in Espionage Campaign

The cyber-espionage group APT36 (Transparent Tribe) is suspected to be behind a new campaign targeting telecommunications and critical infrastructure in South Asia. The campaign uses a new malware family, including a primary backdoor named PATCHCORD, and leverages legitimate cloud services like Google Sheets and GitHub Gists for command-and-control, making detection more challenging.

📖 Read full report →


8. Active Exploits Target Critical SPIP CMS RCE (CVE-2026-77647)

A critical unauthenticated remote code execution (RCE) vulnerability, CVE-2026-77647, is being actively exploited in the SPIP content management system. The flaw, rated 9.8 CVSS, affects all versions prior to 4.4.20 and allows a remote attacker to gain full control of a vulnerable server with no user interaction, prompting an urgent call for administrators to patch immediately.

📖 Read full report →


📌 Subscribe to daily updates at CyberNetSec.io

All reports include detailed analysis, IOCs, mitigation strategies, and references.

Top comments (0)