Weekly recap: Week of 17 to 23 August 2026
Review the week's tracked stories, vulnerability changes, and unverified leak-site claims for the dates shown.
144 qualifying stories tracked from Monday-Sunday calendar week, August 17 to August 23, 2026; change from the prior 7 days: -25 vs prior period; 10 Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities (KEV) entries added from Monday-Sunday calendar week, August 17 to August 23, 2026; 240 leak-site claims observed by tracked feeds from Monday-Sunday calendar week, August 17 to August 23, 2026
Monday to Sunday, UTC. Permalink label: 2026-W34.
- vulnerabilities4 sourcesMicrosoft Entra ID Flaw (CVSS 10.0) Exploited in Wild, Allows Remote Code ExecutionSource ↗
Microsoft disclosed a maximum-severity remote code execution vulnerability in Entra ID (CVE-2026-69836, CVSS 10.0) that has been actively exploited. The company stated that no customer action is required, suggesting either automatic mitigation or that the vulnerability has already been patched.
Grouped: similar headlines and the same Common Vulnerabilities and Exposures (CVE) record (CVE-2026-69836).
- ransomware2 sourcesClop Returns with Custom Implant in Mass-Extortion CampaignSource ↗
Clop has deployed a custom web shell following exploitation of CVE-2026-12569 in PTC Windchill, a product lifecycle management platform used by manufacturers. The implant decrypts stored credentials in plaintext, maps sensitive vault data, and includes a Java class loader enabling arbitrary code execution entirely in memory. The shell's tight integration with Windchill's APIs and database schema makes it difficult to detect using signature-based controls, as its traffic blends with normal application behavior.
Grouped: the same names (JAVASERVER PAGES, PTC WINDCHILL).
- vulnerabilities2 sourcesCritical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public ProjectsSource ↗
GitLab released security updates for a critical GraphQL vulnerability tracked as CVE-2026-19478 that could allow unauthenticated attackers to modify or delete public projects and user data in Community and Enterprise editions. The flaw carries a CVSS score of 9.4. The article text is incomplete.
Grouped: similar headlines and the same Common Vulnerabilities and Exposures (CVE) record (CVE-2026-19478).
- vulnerabilities17th August - Threat Intelligence ReportSource ↗
Colombia's Ministry of Justice suffered a ransomware attack that encrypted files but did not result in data theft, while Poland's MyDr platform exposed personal data of nearly 19 million citizens after attackers leaked a senior official's identification details. Levi Strauss & Co. reported a social-engineering compromise of employee devices that yielded corporate information but no consumer data, and IEH Corporation confirmed a phishing-based Microsoft 365 mailbox breach that could reveal customer communications and export-controlled technical data. Microsoft's August Patch Tuesday addressed 421 vulnerabilities including the actively exploited Common Vulnerabilities and Exposures (CVE)-2026-68820, Apple patched CVE-2026-65400 allowing unauthenticated macOS Screen Sharing access, and Adobe fixed CVE-2026-71362 affecting Commerce authentication, while threat actors leveraged artificial intelligence (AI)-driven tools in campaigns targeting Taiwanese systems and North Korean phishing infrastructure.
- ransomwareThe long tail of Clop’s PTC hack is just beginning to emergeSource ↗
Clop, a prolific data theft extortion group, exploited a critical zero-day vulnerability (CVE-2026-12569) in PTC's Windchill and FlexPLM software products to compromise dozens of organizations across manufacturing, aerospace, and retail sectors. The group deployed custom web shells designed specifically for Windchill that automate credential theft, malware delivery, and data exfiltration while evading detection. PTC patched the vulnerability on June 18, but exploitation occurred in early June, and the full scope of compromise remains unclear as companies continue investigating and Clop sends extortion demands.
- vulnerabilitiesCritical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active ExploitationSource ↗
CISA added four critical vulnerabilities to its Known Exploited Vulnerabilities catalog on August 19, 2026, including CVE-2026-65400, an improper authentication flaw in Apple macOS with a CVSS score of 7.1. All four vulnerabilities are confirmed to be exploited in the wild.
- threat intelUAT-10147 deploys SPECTRE: A cross-platform implant with Linux rootkit and BYOVD capabilitiesSource ↗
Cisco Talos identified UAT-10147, a Chinese-speaking intrusion group operating the SPECTRE cross-platform backdoor, which combines custom malware with kernel-level rootkits and bring-your-own-vulnerable-driver (BYOVD) techniques to disable endpoint detection and response (EDR) products. The Windows and Linux variants support extensive command sets for persistence, privilege escalation, credential theft, and process injection, while the integrated Specter Linux rootkit uses ftrace hooking for stealthy kernel-level hiding. Evidence suggests the threat actor incorporates artificial intelligence (AI)-assisted code generation in developing malware components and leverage SEO fraud utilities, open-source post-exploitation tools, and multiple commodity backdoors to maintain access to compromised IIS and Linux servers.
- ransomwareSuspected China-Nexus Actor Exploits VMware vCenter Flaw, Deploys Babuk-Derived RansomwareSource ↗
Researchers have attributed exploitation of CVE-2026-59310, a critical directory-traversal flaw in VMware vCenter (CVSS 9.8), to a suspected China-linked APT group. The attackers are deploying a Babuk-derived ransomware variant against affected organizations.
- vulnerabilitiesCISA Adds One Known Exploited Vulnerability to CatalogSource ↗
CISA added CVE-2025-62593, a Ray-Project code injection vulnerability, to its Known Exploited Vulnerabilities (KEV) Catalog based on active exploitation evidence. The addition underscores CISA's ongoing effort to track vulnerabilities actively abused by threat actors and reinforces BOD 26-04 requirements for federal agencies to prioritize remediation of high-risk KEV Catalog entries on publicly exposed assets.
- vulnerabilitiesElementor Pro Flaw Could Let Unauthenticated Attackers Upload PHP and Execute CodeSource ↗
Researchers disclosed a critical vulnerability (CVE-2026-32475) in Elementor Pro's Forms module that allows unauthenticated attackers to upload and execute arbitrary PHP files. The flaw scores 9.0 CVSS and stems from insufficient validation of file uploads.
| Qilin | 32 claims | -5 vs prior week |
| The Gentlemen | 28 claims | -3 vs prior week |
| Direwolf | 21 claims | +6 vs prior week |
| Coinbasecartel | 16 claims | +12 vs prior week |
| Storm | 12 claims | +2 vs prior week |
| INC Ransom | 11 claims | +4 vs prior week |
| Kazu | 9 claims | +9 vs prior week |
| Titan | 7 claims | +7 vs prior week |
| Dysphor1a | 6 claims | +6 vs prior week |
| Metaencryptor | 6 claims | +6 vs prior week |
Leak-site claim data is unverified: RansomLook (CC BY 4.0), with ransomware.live as a failover, credited and linked as its terms require (Source: Ransomware.live).
- Is Cyber missing the Marque?Takedown · Disruption · Cisco Talos
A White House presidential memorandum issued August 14, 2026, directs the Department of Justice and Department of Homeland Security to establish a program authorizing private cybersecurity companies to conduct offensive cyber operations against transnational criminal organizations outside U.S. borders under government delegation. The framework creates significant operational questions around attribution, jurisdiction, intelligence handling, and the implications when private sector employees conduct state-authorized attacks. The memorandum provides 60 days for DOJ and DHS to develop operating procedures before any operations can be approved.
- 'Grandoreiro' Malware Resurfaces With Mexico CampaignTakedown · Dark Reading
Grandoreiro, a banking Trojan that had been subject to law enforcement action, has reemerged with new capabilities designed to evade detection and analysis. The malware is now targeting victims in Mexico with these enhanced evasion techniques.
- US charges Iranian hackers over $3.4 billion intellectual property theftIndictment · BleepingComputer
The US Department of Justice charged 17 Iranian nationals affiliated with Mabna Institute, a hacking-for-hire operation, for conducting multi-year cyber espionage campaigns targeting American organizations. The charges relate to theft of intellectual property valued at approximately $3.4 billion across numerous sectors and industries.
- DOJ secures indictment of 17 Iranians accused of ‘massive’ cyber theft campaignIndictment · DataBreaches.net
The Department of Justice unsealed an indictment against 17 Iranian nationals on Tuesday for conducting a cyber theft campaign targeting American and foreign institutions. The defendants, allegedly affiliated with the Mabna Institute, are accused of operating on behalf of Iran's Islamic Revolutionary Guard Corps (IRGC) across 14 counts.
- US charges Iranians for sprawling hacking campaign on government agencies, universitiesIndictment · The Record
The U.S. Justice Department charged 17 individuals linked to Iran with hacking email accounts at federal agencies. The alleged campaign also involved theft of intellectual property from numerous universities. The indictment highlights ongoing state-sponsored cyber threats targeting government and academic networks.
- Defending Against an Active Threat to Siemens S7 Series PLCsSanction · Disruption · CISA Alerts and Advisories
Federal agencies (NSA, CISA, FBI, DOE, EPA) are warning of an active cyber threat targeting Internet-exposed Siemens S7 Series programmable logic controllers (PLCs) using artificial intelligence (AI)-generated exploitation scripts. Threat actors leverage Internet scanning services to identify poorly protected PLCs and use AI-assisted tools that mimic legitimate monitoring software to gain read/write access via the S7comm protocol. The advisory urges owners and operators of critical manufacturing, energy, water, chemical, food, and commercial facilities to immediately inventory systems, apply security patches, isolate PLCs from the Internet, strengthen access controls, and deploy intrusion detection to monitor for anomalous activity.
- Eight years later, federal authorities re-up charges against alleged Iranian hackers at Mabna InstituteIndictment · CyberScoop
Federal authorities unsealed an expanded indictment against 17 Iranians affiliated with the Mabna Institute, a Tehran-based firm alleged to have conducted state-sponsored cyber theft targeting universities, governments, and companies. The indictment builds on a 2018 case with eight additional defendants and documents compromises of over 100,000 professor email accounts globally, theft of at least 31.5 terabytes of academic and research data, and breaches affecting five U.S. government agencies and dozens of private companies. The Justice Department states U.S. universities spent approximately $3.4 billion to procure and access the stolen data and intellectual property.
- 17 Iranians Charged With Conducting Massive Cyber Theft Campaign On Behalf Of The Islamic Revolutionary Guard Corps And Other Iranian EntitiesIndictment · U.S. Department of Justice
United States Attorney for the Southern District of New York, Jamie McDonald, Assistant Attorney General for National Security, John A. Eisenberg, and Assistant Director in Charge of the New York Field Office of the Federal Bureau of Investigation (“FBI”), James C. Barnacle, Jr., announced today the unsealing of a 14-count Superseding (“S2”) Indictment charging 17 members of the Mabna Institute, an Iran-based company that, since at least 2013, conducted a coordinated campaign of cyber intrusions into computer systems to 144 U.S.-based universities, 178 foreign universities, at least 42 U.S.-ba
- 17 Iranians Charged with Conducting Massive Cyber Theft Campaign on Behalf of the Islamic Revolutionary Guard Corps and Other Iranian EntitiesIndictment · U.S. Department of Justice
A 14-count superseding (S2) indictment was unsealed today charging 17 members of the Mabna Institute, an Iran-based company that, since at least 2013, has conducted a coordinated campaign of cyber intrusions into computer systems for 144 U.S.-based universities, 178 foreign universities, at least 42 U.S.-based private sector companies, at least 11 foreign private sector companies, at least five U.S. federal and state government agencies, and at least two non-governmental organizations (NGOs). The Mabna Institute stole more than 31 terabytes of academic data and intellectual property from these
- Illinois Man Charged With Scheme To Impersonate Doctors And Make False Statements To Obtain GLP-1 MedicationsIndictment · U.S. Department of Justice
United States Attorney for the Southern District of New York, Jamie McDonald, Assistant Director in Charge of the New York Field Office of the Federal Bureau of Investigation (“FBI”), James C. Barnacle, Jr., and Special Agent in Charge of the New York Regional Office of the U.S. Department of Health and Human Services Office of Inspector General (“HHS-OIG”), Naomi D. Gruchacz, announced that RODNEY GREER, a/k/a “Christian Marchand,” appeared for arraignment today in connection with a four-count Indictment charging GREER with a scheme to impersonate doctors to obtain unauthorized prescription m
- Man Charged for Interstate Threats and CyberstalkingIndictment · U.S. Department of Justice
A man with ties to New Jersey, Georgia, Malaysia, Morocco, and Albania was charged with threatening to kill and injure victims in New Jersey and Pennsylvania.
- Police bust cybercrime ring accused of stealing €30 million in four-day spreeArrest · Seizure · Disruption · Help Net Security
German and Brazilian law enforcement dismantled an international bank fraud ring that stole approximately 30 million euros from a German financial institution over four days. The operation, named Klonen, resulted in the arrest of four suspects in Brazil on August 13, with additional suspects sought in Spain and Bulgaria. The attackers exploited a vulnerability in a booking process to execute the theft.
- CVE-2026-65400Apple macOSdue
- CVE-2026-73570Synacor Zimbra Collaboration Suite (ZCS)due
- CVE-2026-21962Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-indue
- CVE-2025-62593Ray-Project Raydue
- CVE-2026-59310Broadcom VMware vCenterdue
- CVE-2026-55040Microsoft SharePointdue
- CVE-2026-33824Microsoft Internet Key Exchange (IKE) Service Extensionsdue
- CVE-2026-72530TrueConf Serverdue
- CVE-2026-64849MLflow MLflowdue
- CVE-2026-72529TrueConf Serverdue
- CVE-2026-12569PTC Windchill and FlexPLMEPSS up 10 points in about a week
- CVE-2026-45659Microsoft SharePoint ServerEPSS up 66 points in about a week
- CVE-2016-0034Microsoft SilverlightEPSS up 11 points in about a week
- CVE-2021-29441alibaba nacosEPSS up 18 points in about a week
- CVE-2019-1068Microsoft SQL ServerEPSS up 12 points in about a week
- claimS.E.M.P. s.r.l.Unverified claim. Claimed by Qilin.
- claimEuroflora srlUnverified claim. Claimed by Qilin.
- claimTecnici Associati STPUnverified claim. Claimed by Qilin.
- claimStudio BOLDRIN PAOLOUnverified claim. Claimed by Qilin.
- claimAurore Development S.p.A.Unverified claim. Claimed by Qilin.
- claimClear AlignUnverified claim. Claimed by Qilin.
- claimDiforUnverified claim. Claimed by Qilin.
- claimBlack Cat Engineering & Construction WLLUnverified claim. Claimed by Qilin.
- claimAGS CinemasUnverified claim. Claimed by The Gentlemen.
- claimEyecare Center of SnohomishUnverified claim. Claimed by The Gentlemen.
- claimGould Sherwood ConsultingUnverified claim. Claimed by The Gentlemen.
- claimEspacUnverified claim. Claimed by The Gentlemen.
- claimLayherUnverified claim. Claimed by The Gentlemen.
- claimVolktekUnverified claim. Claimed by The Gentlemen.
- claimMeridian Logistics GroupUnverified claim. Claimed by The Gentlemen.
- claimUOLconsultUnverified claim. Claimed by The Gentlemen.
- claimNorthStarUnverified claim. Claimed by Direwolf.
- claimAztec SoftwareUnverified claim. Claimed by Direwolf.
- claimThe Revel CollectiveUnverified claim. Claimed by Direwolf.
- claimProSim Aviation ResearchUnverified claim. Claimed by Direwolf.
Ransomware claim data is unverified: RansomLook (CC BY 4.0), with ransomware.live as a failover, credited and linked as its terms require (Source: Ransomware.live).