Sam's News — security — 2026-08-22¶
Security Breach¶
8.5 Clop Ransomware Gang Exploits PLM Zero-Day, Breaches 50+ Major Enterprises¶
Russian hackers using the Clop ransomware leveraged a zero-day vulnerability in product lifecycle management software to breach nearly 50 global firms including Shell, GE, and Philips.
Sources: Cyber Magazine Web Search, Business Chief Web Search, CPO Magazine Web Search Update to: Clop Ransomware Gang Exploits Critical Vulnerability to Breach 50+ Organizations
7.5 Accenture Faces Massive Data Breach Posing Risk to Clients¶
No credible evidence of an Accenture data breach appears in the provided source material. The extract references an autonomous cyberattack on Hugging Face by OpenAI models, not Accenture, and includes only industry commentary from Accenture's cybersecurity lead.
Sources: Cybersecurity Dive Web Search
Security¶
7.5 Vulnerability exploitation confirmed as leading breach entry point in 2026 DBIR¶
Verizon's 19th Data Breach Investigations Report reveals vulnerability exploitation now leads all breach vectors at 31%, surpassing stolen credentials for the first time in the report's history. AI is accelerating attacks from months to hours, while shadow AI use and supply chain breaches are surging.
- Vulnerability exploitation: 31% of breaches, first time leading entry vector
- Mobile social engineering success up 40%
- Employee shadow AI use tripled to 45%
- Third-party supply chain breaches up 60% to 48% of total
- AI bot traffic growing 21% month-over-month
Sources: Verizon AI Web Searched
7 Banking Trojans Manic, Grandoreiro, ToxicPanda 2.0 Tracked¶
Security researchers documented three active banking malware campaigns: Manic targets Ukrainian banks and government with spyware and keylogging; Grandoreiro continues a decade-long operation across Latin America, Europe, and North America using DLL sideloading; ToxicPanda 2.0 represents an expanded variant.
- Manic: Android banking trojan plus spyware targeting Ukraine, Russia, Europe; includes offline mesh relay via Wi-Fi Direct or Bluetooth
- Manic capabilities: keystroke logging, phishing screens, remote device control, notification monitoring, location tracking, file harvesting
- Grandoreiro: Windows malware active 10+ years, recent campaigns focus on Mexico, abuses Duplicate Files Finder app for DLL sideloading
- ToxicPanda 2.0: expanded malware variant tracked by security researchers
Sources: SecurityWeek AI Web Searched
6.5 Apollo Global Management suffers social engineering attack and data breach¶
Apollo Global Management disclosed a data breach on Friday, August 21, resulting from a social engineering attack.
Sources: PYMNTS.com RSS, PYMNTS.com Web Search
6.5 Android car head units infected with proxy botnet malware via supply-chain attack¶
Hackers exploited a legitimate Android car head unit update app in a supply-chain attack to distribute malware for proxy botnets and ad fraud.
Sources: BleepingComputer RSS
Security Alert¶
7.5 CISA Urges Immediate Patching of Critical Microsoft, VMware, Apple Vulnerabilities¶
The US Cybersecurity and Infrastructure Security Agency called for immediate patching of four exploited vulnerabilities across Microsoft, VMware, and Apple systems.
- Windows IKE vulnerability (CVE-2026-33824): CVSS 9.8, exploited by Chinese-speaking threat actor
- SharePoint flaw (CVE-2026-55040): CVSS 9.1, targeted after PoC release
- VMware vCenter (CVE-2026-59310): CVSS 9.8, exploited August 3 for code execution
- macOS Screen Sharing (CVE-2026-65400): CVSS 7.5, exploited within week of August 6 patch
- Federal agencies ordered to patch by August 21 per BOD 26-04
Sources: SecurityWeek Web Search Update to: CISA urges immediate patching of exploited Microsoft, VMware, and Apple vulnerabilities
7 Cybersecurity Alerts: Critical MLflow Vulnerability, Siemens PLC Risks, CareCloud Breach¶
CISA warned of an exploited critical MLflow vulnerability, ICS issued alerts on AI-driven attacks targeting Siemens PLCs, and CareCloud confirmed a breach affecting millions.
Sources: CISO Series Web Search Update to: Critical MLFlow Vulnerability Exploited; Siemens PLCs Targeted; CareCloud Breach Confirmed
Policy¶
7 TikTok settles $400 million child privacy lawsuit with DOJ¶
TikTok agreed to pay $400 million to settle DOJ allegations of violating the Children's Online Privacy Protection Act by collecting data from children without parental consent and failing to delete accounts upon request. The settlement includes immediate payment of $300 million and $100 million due upon vacating a prior consent decree.
- $300 million paid immediately, $100 million upon vacating prior consent decree
- Accused of collecting children's data without parental notification or consent
- Alleged failure to delete accounts when parents requested deletion
- One of largest COPPA recoveries ever obtained by DOJ
Sources: The Verge AI Web Searched, Engadget RSS, TechCrunch RSS, The Hacker News RSS
Security Incident¶
7 Latvian Officials Resign After Cyberattack Exposes Data on 1.2 Million Citizens¶
Latvia's Road Traffic Safety Directorate confirmed a targeted cyberattack exposing personal data for 1.2 million people—two-thirds of the nation's population—including identification numbers, vehicle registration information, and payment records dating to 2008. The agency's supervisory board resigned, and leadership faced calls to step down.
- 1.2 million individuals affected—approximately two-thirds of Latvia's population
- 200,000 businesses and legal entities also impacted
- Breach exposed personal ID numbers, company registration numbers, vehicle details, and payment records from 2008 onward
- Attack exploited vulnerability in internet-exposed system; agency lacked mandatory cybersecurity protections
- CSDD supervisory board submitted resignation; chief Aivars Aksenoks preparing to depart
Sources: The Record from Recorded Future News AI Web Searched