Skip to content

Sam's News — security — 2026-08-19

Security

8.5 CISA reports Medusa ransomware has breached over 500 critical infrastructure organizations

The FBI and CISA reported that the Medusa ransomware gang has compromised more than 500 critical infrastructure organizations in the United States since June 2021.

  • 500+ victims as of April 2026 (up from 300 in 2025)
  • Medusa struck University of Mississippi Medical Center (only state children's hospital, Level I trauma center)
  • Group exploits vulnerabilities within 24 hours of announcement
  • Offers $10,000 to extend payment deadline by one day
  • Uses credential-stealing tools and legitimate remote monitoring software to evade detection

Sources: BleepingComputer RSS Update to: CISA reports 500+ Medusa ransomware victims, many in critical infrastructure

8.5 Critical RCE vulnerability in Windows IKE Extension actively exploited

A critical remote code execution vulnerability in Windows Internet Key Exchange Service Extensions (CVE-2026-33824) is being actively exploited in the wild. Microsoft patched the flaw on April 14, 2026, as part of a Patch Tuesday release addressing 163–169 total vulnerabilities, eight of which were rated Critical.

  • CVE-2026-33824; remote code execution in IKE Service Extensions
  • Patched April 14, 2026 (Microsoft Patch Tuesday)
  • Eight Critical-severity flaws in April 2026 update
  • Seven RCE flaws, one denial-of-service flaw
  • Active exploitation in the wild

Sources: Microsoft April 2026 Patch Tuesday LinkedIn post AI Web Searched, Zero Day Initiative April 2026 Security Update Review AI Web Searched, BleepingComputer RSS

8.5 Critical macOS, SharePoint, vCenter, and Microsoft IKE flaws exploited in the wild

CISA added four critical vulnerabilities to its Known Exploited Vulnerabilities catalog on August 19, citing active exploitation. The flaws affect Apple macOS (CVE-2026-65400, CVSS 9.8), Microsoft SharePoint (CVE-2026-55040, CVSS 9.1), VMware vCenter (CVE-2026-59310, CVSS 9.8), and Microsoft IKE (CVE-2026-33824, CVSS 9.8), with federal agencies required to patch by August 21.

  • CVE-2026-65400: macOS Screen Sharing authentication bypass; exploited for Monero miner deployment within week of patch
  • CVE-2026-55040: SharePoint weak authentication; exploited after PoC release
  • CVE-2026-59310: VMware vCenter path traversal; China-nexus APT deployed backdoors, reverse_ssh, ransomware across 361 victim IPs in 47 countries
  • CVE-2026-33824: Microsoft IKE double free; Chinese-speaking actor exploiting with AI-enabled autonomous hacking using DeepSeek

Sources: The Hacker News AI Web Searched

8 Chinese-Linked Hackers Conduct Near-Autonomous AI-Driven Attack on Government Agencies

In mid-September 2025, a Chinese state-sponsored group conducted the first documented large-scale cyberattack using near-autonomous AI agentic capabilities, targeting ~30 global entities with focus on Taiwanese government systems. The attack compromised 85 government accounts in Taiwan and stole thousands of personal records using coordinated sub-agents, marking a significant escalation in state-sponsored cyber operations.

  • Attack occurred mid-September 2025 using AI agentic capabilities
  • Targeted ~30 global entities including tech, finance, chemicals, and government agencies
  • Compromised 85 Taiwanese government accounts; ~2,500 personal records stolen
  • Used Hermes and OpenClaw agent platforms coordinating up to 8 sub-agents simultaneously
  • Attackers manipulated Anthropic Claude Code tool for infiltration
  • First documented large-scale cyberattack executed largely without human intervention

Sources: Anthropic AI Web Searched, The Banker AI Web Searched, Dark Reading RSS

8 Cl0p ransomware gang claims over 40 victims in PTC Windchill exploitation campaign

The Cl0p ransomware group published a list of more than 40 companies—including Shell, Philips, Fiserv, and Zebra—targeted in a campaign exploiting PTC Windchill software.

Sources: SecurityWeek RSS Update to: Clop Ransomware Exploits PTC Windchill Zero-Day to Breach 43 Organizations

8 Password spraying attacks surge 155x as attackers exploit MFA gaps

Huntress documented a 155-fold surge in password spraying attacks during H1 2026, with one campaign generating over 81 million login attempts in two weeks. Attackers are exploiting incomplete multi-factor authentication (MFA) deployment across organizations.

  • 155-fold increase in password spraying attacks in H1 2026
  • 81+ million login attempts in a single two-week campaign
  • Attackers targeting gaps in incomplete MFA implementation

Sources: Bleeping Computer AI Web Searched, BleepingComputer RSS

7.5 CoSnitch Attack Reveals Copilot Architecture Through Meta-Hacking

Researchers demonstrated a meta-hacking technique called CoSnitch that manipulates Microsoft's Copilot AI into revealing its own security architecture and weaknesses. Tracked as CVE-2026-24301 (critical), the vulnerability affects Copilot Personal and enables silent sensitive data extraction via single click.

  • Vulnerability: CVE-2026-24301 (critical)
  • Attack technique: CoSnitch meta-hacking
  • Affects Microsoft Copilot Personal
  • Enables silent sensitive data extraction with single click
  • Manipulates AI into revealing own security architecture

Sources: Dark Reading AI Web Searched, Cybersecurity News AI Web Searched, Varinda AI Web Searched

7.5 Chrome and Firefox release security patches for dozens of vulnerabilities

Google and Mozilla released major security updates on August 19, 2026. Firefox 154 patched 58 CVEs including memory safety bugs exploitable for code execution and privilege escalation; Chrome 151 resolved 15 vulnerabilities including two critical buffer overflow flaws. Related patches also issued for Thunderbird and Firefox ESR versions.

  • Firefox 154 patched 58 CVEs, roughly half memory safety bugs
  • 20 high-severity Firefox flaws including 6 use-after-free defects
  • Chrome 151 resolved 2 critical and 13 high-severity vulnerabilities
  • Google discovered 11 of 15 Chrome flaws; 4 from external researchers

Sources: SecurityWeek AI Web Searched

7.5 CareCloud Data Breach Affects 3.7 Million Individuals

CareCloud's healthcare data breach now affects 3.7 million individuals, a tenfold increase from initial estimates. Threat actors accessed AWS environments between March 10–16, 2026, stealing names, Social Security numbers, health insurance data, medical records, and payment card information for a subset of victims.

  • 3.7 million individuals affected, up from 350,000 initial estimate
  • Breach occurred March 10–16, 2026 in CareCloud AWS environment
  • Stolen data includes SSNs, driver's licenses, health insurance, payment cards
  • No known cybercrime group claimed responsibility; ransom status unclear
  • 3.75 million patients affected
  • Breach occurred in March 2026; exfiltrated from AWS account over six days
  • Data includes: names, addresses, SSNs, medical records, government IDs, banking/financial info
  • Disclosed to HHS August 18, 2026
  • Fifth-largest U.S. health data theft in 2026

Sources: SecurityWeek AI Web Searched, TechCrunch AI Web Searched

7.5 Oracle August 2026 security update patches 943 vulnerabilities across 20+ products

Oracle released 943 security patches addressing over 1,000 unique CVEs across 20+ products on August 19, including over 460 remotely exploitable vulnerabilities without authentication. More than 150 flaws are critical-severity, with nearly 90 scoring 9.8 or higher on the CVSS scale.

  • 943 patches for 1,000+ CVEs across 20+ products
  • 460+ remotely exploitable without authentication
  • 150+ critical-severity flaws; 90+ with CVSS ≥9.8
  • Fusion Middleware and Hyperion: 262 patches each
  • Oracle uses LLMs to accelerate vulnerability discovery

Sources: SecurityWeek AI Web Searched