<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[CISO Intelligence]]></title><description><![CDATA[Intelligent ideas. Actionable advice. ]]></description><link>https://www.cisointelligence.co</link><image><url>https://substackcdn.com/image/fetch/$s_!dHG7!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe26b6c29-ab25-4075-b37d-d271750820af_368x368.png</url><title>CISO Intelligence</title><link>https://www.cisointelligence.co</link></image><generator>Substack</generator><lastBuildDate>Mon, 21 Sep 2026 02:06:55 GMT</lastBuildDate><atom:link href="https://www.cisointelligence.co/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[Jonathan Care]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[cisointelligence@substack.com]]></webMaster><itunes:owner><itunes:email><![CDATA[cisointelligence@substack.com]]></itunes:email><itunes:name><![CDATA[Jonathan Care]]></itunes:name></itunes:owner><itunes:author><![CDATA[Jonathan Care]]></itunes:author><googleplay:owner><![CDATA[cisointelligence@substack.com]]></googleplay:owner><googleplay:email><![CDATA[cisointelligence@substack.com]]></googleplay:email><googleplay:author><![CDATA[Jonathan Care]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[Breaking: Cisco FMC Compromised by Sandworm and Qilin Ransomware — 11 September 2026]]></title><description><![CDATA[Cisco FMC Compromised by Sandworm and Qilin Ransomware &#8212; Three Threat Clusters Confirmed]]></description><link>https://www.cisointelligence.co/p/breaking-cisco-fmc-compromised-by</link><guid isPermaLink="false">https://www.cisointelligence.co/p/breaking-cisco-fmc-compromised-by</guid><dc:creator><![CDATA[Jonathan Care]]></dc:creator><pubDate>Fri, 11 Sep 2026 17:01:01 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!dHG7!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe26b6c29-ab25-4075-b37d-d271750820af_368x368.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h2>Cisco FMC Compromised by Sandworm and Qilin Ransomware &#8212; Three Threat Clusters Confirmed</h2><p>Cisco Talos has confirmed that three distinct threat clusters &#8212; including Russian state-sponsored group Sandworm and a Qilin ransomware affiliate &#8212; are actively exploiting two patched vulnerabilities in Cisco Secure Firewall Management Center (FMC). CVE-2026-20079 (CVSS 10.0) gives an unauthenticated remote attacker root access to FMC via an authentication bypass in the web interface. CVE-2026-20316 (CVSS 5.3) provides low-privilege access that can be chained for privilege escalation. The result: management plane compromise of your Cisco firewall estate, with attackers deploying web shells, harvesting credentials, and in one cluster, deploying Qilin ransomware across managed endpoints.</p><h2>Cluster 1: UAT-12197 &#8212; Credential Theft and Database Access</h2><p>This group exploited CVE-2026-20079 to deploy JSP-based web shells and a Java Archive command executor on compromised FMC instances. Their objective was credential and authentication data harvesting from internal databases. Web shells provide persistent access to the FMC host, allowing attackers to query managed device configurations and extract authentication tokens. If your FMC is exposed and unpatched, assume credentials for every managed firewall have been collected.</p><h2>Cluster 2: UAT-11823 &#8212; Sandworm Reconnaissance and Cyclops Blink Deployment</h2><p>This cluster combined both vulnerabilities to deliver a Netcat reverse shell, bash scripts for harvesting managed-device configurations, and a variant of Cyclops Blink &#8212; the modular ELF implant previously attributed to Sandworm, the Russian GRU's Main Centre for Special Technologies (GTsST). Cyclops Blink was originally used in the 2022 campaign against WatchGuard firewalls and network storage devices. Its appearance on Cisco FMC represents a documented expansion of Sandworm's targeting into Cisco infrastructure. The implant provides modular reconnaissance, command execution, and persistent C2 capabilities. A Russian military intelligence service now potentially holds root on your firewall management plane.</p><h2>Cluster 3: UAT-11988 &#8212; Qilin Ransomware via Living-off-the-Land</h2><p>This ransomware operator exploited CVE-2026-20316 for initial access then used legitimate built-in FMC tooling for reconnaissance &#8212; classic living-off-the-land technique. They dropped tunneling tools for persistent access, collected credentials, built a target list of endpoints to encrypt, terminated security tools, and deployed Qilin ransomware on selected systems. The use of FMC's own management tooling to propagate ransomware means the attack moves through your firewall management infrastructure, not around it.</p><h2>So What / Action</h2><p>The CISA KEV deadline for CVE-2026-20079 is September 12, 2026 &#8212; tomorrow. If you run Cisco FMC and have not applied the hotfix, you are accepting root-level risk from two nation-state groups and an active ransomware operator. Priority sequence: apply hotfixes for both CVE-2026-20079 and CVE-2026-20316 now. Check for the license.tmp indicator &#8212; if www user invoked package_info.pl against /var/tmp/license.tmp, assume compromise. If found: isolate the FMC, rotate all managed device credentials, review pushed policies for unauthorized changes, and conduct forensic triage before restoring trust to the management plane. Cisco will ship a comprehensive hardening release next week &#8212; plan for that upgrade cycle now. 700+ FMC instances are internet-exposed. If yours is one of them, this is no longer a patching decision. It is an incident response decision.</p>]]></content:encoded></item><item><title><![CDATA[Breaking: Cisco FMC CVSS 10.0 Root Access Under Active Attack, NetScaler and Fortinet on 72-Hour KEV Clock — 10 September 2026]]></title><description><![CDATA[Cisco Firewall Management Center Root Access (CVE-2026-20079)]]></description><link>https://www.cisointelligence.co/p/breaking-cisco-fmc-cvss-100-root</link><guid isPermaLink="false">https://www.cisointelligence.co/p/breaking-cisco-fmc-cvss-100-root</guid><dc:creator><![CDATA[Jonathan Care]]></dc:creator><pubDate>Thu, 10 Sep 2026 08:03:21 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!dHG7!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe26b6c29-ab25-4075-b37d-d271750820af_368x368.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h2>Cisco Firewall Management Center Root Access (CVE-2026-20079)</h2><p>Cisco has confirmed active exploitation of CVE-2026-20079, a maximum-severity CVSS 10.0 authentication bypass in Secure Firewall Management Center and Security Cloud Control Firewall Management. An unauthenticated attacker sends crafted HTTP requests to the web interface, abuses an improperly configured boot-time system process, and executes commands as root. No credentials, no interaction, root on the box.</p><p>The uncomfortable part is what FMC is: the central management plane for your Cisco firewall estate. One compromised FMC can push policy to every firewall it manages. Cisco says PSIRT became aware of exploitation in August, but the example IOC in the advisory carries a July 23 timestamp and overlaps with the exploited CVE-2026-20316 static credential flaw disclosed in July, so assume attackers may have been inside for weeks. There are no workarounds. Upgrade on-prem FMC now; Cisco has already patched the cloud-hosted SCC service.</p><p>For detection, grep /var/log/messages for license.tmp. A sudo invocation of package_info.pl against /var/tmp/license.tmp by the www user means assume compromise and start triage.</p><h2>Citrix NetScaler Authentication Bypass (CVE-2026-19490)</h2><p>The same KEV batch adds CVE-2026-19490, a CVSS 9.3 authentication bypass in NetScaler ADC and NetScaler Gateway. Where the appliance fronts an AAA virtual server or a Gateway configuration (SSL VPN, ICA Proxy, CVPN, RDP Proxy), an unauthenticated remote attacker can skip authentication entirely. Citrix shipped fixes on August 21; nineteen days later CISA has confirmed in-the-wild exploitation. Three-day federal clock, forensic triage required.</p><h2>Fortinet FortiOS Heap Overflow (CVE-2025-25249)</h2><p>Fortinet rounds out the batch with CVE-2025-25249, a heap-based buffer overflow in the cw_acd daemon affecting FortiOS, FortiSwitchManager and FortiSASE. CVSS 7.4, code execution from crafted packets, and despite the sub-9.0 score CISA still put it on the same 72-hour clock with mandatory forensics.</p><h2>Action</h2><p>Three perimeter products, three vendors, one 72-hour window that closes September 12. Sequence by blast radius: FMC and SCC first (management plane, no workaround, root), NetScaler AAA and Gateway second (remote access authentication), Fortinet third. Inventory internet-exposed management interfaces today. If your FMC shows the license.tmp indicator, treat the whole managed estate as suspect: rotate credentials, review pushed policies and objects, image the box and triage before you trust that management plane again. Patch Tuesday handed you 974 CVEs this week. CISA just told you which ones come first.</p>]]></content:encoded></item><item><title><![CDATA[Breaking: PaperCut NG/MF Zero-Day RCE Chain Under Active Attack — 31 August 2026]]></title><description><![CDATA[PaperCut NG/MF Zero-Day RCE Chain: CVSS 9.4, Actively Exploited, Now in CISA KEV]]></description><link>https://www.cisointelligence.co/p/breaking-papercut-ngmf-zero-day-rce</link><guid isPermaLink="false">https://www.cisointelligence.co/p/breaking-papercut-ngmf-zero-day-rce</guid><dc:creator><![CDATA[Jonathan Care]]></dc:creator><pubDate>Mon, 31 Aug 2026 17:04:11 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!dHG7!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe26b6c29-ab25-4075-b37d-d271750820af_368x368.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h2>PaperCut NG/MF Zero-Day RCE Chain: CVSS 9.4, Actively Exploited, Now in CISA KEV</h2><h3>What's Happening</h3><p>CISA has added both PaperCut NG/MF vulnerabilities from the zero-day emergency that began on 27 August, CVE-2026-81578 and CVE-2026-82078, to its Known Exploited Vulnerabilities catalog on evidence of active exploitation, with federal agencies required to patch by 14 September. The two flaws chain into unauthenticated remote code execution. CVE-2026-81578 (CVSSv4 8.8) is an authentication bypass in the web management interface; CVE-2026-82078 (CVSSv4 9.4) is unsafe dynamic class loading in the database connector.</p><p>The bypass abuses the Apache Tapestry framework's "complex direct" request format: the attacker nominates a public page (Error, Exception, or Home) for display while invoking administrative components belonging to ConfigEditor or UserList. PaperCut validates access only for the displayed page, so the administrative components execute unauthenticated. The attacker then rewrites four external user-lookup settings (db-driver, db-url, id-to-username-sql, enabled) to point at a malicious JDBC connection and crafted SQL, then triggers a user search that executes it. Via the bundled Derby driver and H2's INIT mechanism, that SQL creates a JavaScript-backed trigger running on the Nashorn engine, which starts an operating-system process. Remote code execution with no credentials and no user interaction.</p><p>PaperCut has confirmed customer incidents; a university security team and its DFIR firm supplied the evidence that let the vendor reproduce the chain. A Metasploit module is now public.</p><h3>Why This Matters Now</h3><p>Exploitation is confirmed in the wild, and public weaponization lowers the skill floor by the hour. The patch situation compounds this: the first emergency patch released on 28 August was itself bypassable using the Home page variant, so PaperCut shipped Emergency Patch Release 2 for versions 24, 25, and 26 on Windows, Linux, and macOS. Any organisation that applied only the first patch is not protected and must re-patch. PaperCut treats all NG and MF versions as potentially affected, so older releases need an upgrade path, not a hotfix. And the precedent is bad: the 2023 PaperCut flaw CVE-2023-27350 was mass-exploited by ransomware operators. Print management servers sit across enterprise, education, and healthcare estates, chronically under-patched and frequently internet-exposed.</p><p>For detection, watch for unauthenticated POSTs to /app?service=direct/ URIs referencing ConfigEditor or UserList, alerts involving post-exploitation behaviour around pc-app.exe, missing or truncated server.log files, and the log signatures "No suitable driver found for jdbc" and "DatabaseUtils - Database error looking up cardID".</p><h3>So What / Action</h3><p>Inventory every PaperCut NG/MF Application Server, including instances behind VPNs and across education and healthcare estates. Apply Emergency Patch Release 2 immediately to anything internet-facing, and treat anyone patched with Release 1 as unpatched. Where patching is delayed, restrict web access to trusted internal IP ranges using firewall rules or a reverse proxy. Verify the four user-lookup settings have not been tampered with, and check server.log integrity on every server exposed since 27 August. For confirmed exposure, run forensic triage: with a KEV listing and public exploit tooling, treat the server as compromised until proven otherwise.</p>]]></content:encoded></item><item><title><![CDATA[Breaking: Citrix NetScaler Pre-Auth RCE Under Active Attack — 28 August 2026]]></title><description><![CDATA[Citrix NetScaler Pre-Auth RCE Actively Exploited in the Wild]]></description><link>https://www.cisointelligence.co/p/breaking-citrix-netscaler-pre-auth</link><guid isPermaLink="false">https://www.cisointelligence.co/p/breaking-citrix-netscaler-pre-auth</guid><dc:creator><![CDATA[Jonathan Care]]></dc:creator><pubDate>Fri, 28 Aug 2026 12:03:17 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!dHG7!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe26b6c29-ab25-4075-b37d-d271750820af_368x368.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h2>Citrix NetScaler Pre-Auth RCE Actively Exploited in the Wild</h2><p>CISA has added CVE-2026-8452 to its Known Exploited Vulnerabilities catalog with a 3-day remediation deadline of August 29, after confirmation that attackers are actively exploiting the flaw to deploy web shells on unpatched NetScaler appliances.</p><p>Citrix originally disclosed CVE-2026-8452 on June 30 as a memory overflow vulnerability leading to denial of service on appliances configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server. Patches shipped the same day in versions 14.1-72.61, 13.1-63.18, and 13.1-37.272. At the time, Citrix stated it had not observed exploitation.</p><p>The severity escalated dramatically on August 14 when watchTowr Labs published a technical analysis and working proof-of-concept demonstrating that the flaw could be chained into full, unauthenticated remote code execution, well beyond the denial-of-service impact Citrix originally described. The NVD rates this CVE at 9.8 (Critical). Within days, threat intelligence firm Defused confirmed the first exploitation hits on its sensors. Previdian reported attackers dropping web shells named "x.php" and "z.php" and running discovery commands across compromised systems from at least three unique IPs in three different countries.</p><p>Notably, Citrix's own advisory has still not been updated to acknowledge in-the-wild exploitation, despite CISA's KEV listing and multiple independent confirmations.</p><h2>NetScaler Authentication Bypass Still Unlisted</h2><p>A second critical NetScaler vulnerability, CVE-2026-19490 (CVSS 9.3), remains unlisted on the KEV catalog. This authentication bypass, disclosed August 19, allows an unauthenticated remote attacker to circumvent login controls entirely. No public exploitation has been confirmed yet, but given CVE-2026-8452's trajectory from disclosure to active exploitation in under two weeks, the window for preemptive patching is narrow.</p><h2>Additional KEV Additions</h2><p>CISA's August 26 KEV batch also includes five other vulnerabilities: Microsoft SQL Server RCE (CVE-2019-1068), a Linux Kernel out-of-bounds write (CVE-2022-0995), two Red Hat privilege escalation flaws from 2015 (CVE-2015-3246, CVE-2015-5287), and an Ajax.NET deserialization vulnerability (CVE-2021-23758). All carry August 29 or September 9 remediation deadlines.</p><h2>So What / Action</h2><p>If you run NetScaler ADC or Gateway and have not patched since June 30, treat this as an emergency. Patch to 14.1-72.61, 13.1-63.18, or 13.1-37.272 immediately. Check for indicators of compromise: web shells named x.php or z.php in web directories, unexpected process execution from the NetScaler service account, and anomalous outbound connections. If you cannot patch by Saturday, consider isolating Gateway and AAA virtual servers until remediation is complete. Also patch CVE-2026-19490 while you are at it. Citrix's track record on timely advisory updates is poor; do not wait for their confirmation to act.</p>]]></content:encoded></item><item><title><![CDATA[Breaking: Gitea RCE Under Active Exploitation — CVSS 9.8 Cryptojacking Campaign — 27 August 2026]]></title><description><![CDATA[Gitea RCE Under Active Exploitation &#8212; CVSS 9.8, Cryptojacking Campaign Confirmed]]></description><link>https://www.cisointelligence.co/p/breaking-gitea-rce-under-active-exploitation</link><guid isPermaLink="false">https://www.cisointelligence.co/p/breaking-gitea-rce-under-active-exploitation</guid><dc:creator><![CDATA[Jonathan Care]]></dc:creator><pubDate>Thu, 27 Aug 2026 17:01:24 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!dHG7!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe26b6c29-ab25-4075-b37d-d271750820af_368x368.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h2>Gitea RCE Under Active Exploitation &#8212; CVSS 9.8, Cryptojacking Campaign Confirmed</h2><p>CISA has added CVE-2026-60004 to its Known Exploited Vulnerabilities catalog, confirming active exploitation of a critical remote code execution vulnerability in Gitea, the widely deployed self-hosted Git platform. The flaw carries a CVSS score of 9.8 and federal agencies have until August 28 to patch.</p><h3>What's Happening</h3><p>The vulnerability exists in Gitea's diffpatch API endpoint. An attacker with repository write access can send a malicious patch to plant an executable Git hook and execute arbitrary shell commands as the Gitea service account. Because Gitea allows open registration by default, an unauthenticated external actor can create an account, create a repository, and trigger the exploit without needing pre-existing credentials. All versions from 1.17 onward are affected. The fix shipped in version 1.27.1, released in late July.</p><p>CISA's KEV listing was prompted by confirmed in-the-wild exploitation. A public incident report from a Gitea operator describes an attacker leveraging CVE-2026-60004 to deploy a cryptocurrency-mining dropper. The attacker registered an account, created a repository, exploited the diffpatch endpoint, and planted a Git hook that executed a multi-stage payload. The dropper cleared environment variables, killed competing high-CPU processes, fetched architecture-appropriate binaries, executed them, and cleaned up after itself. The hosting provider flagged the VPS for sustained CPU violations before the operator discovered the compromise.</p><h3>Why This Matters Now</h3><p>Gitea is popular with organisations that want Git hosting without relying on GitHub or GitLab. Many of those deployments run with default open registration enabled, making the attack path from "unauthenticated outsider" to "root-level code execution" achievable in minutes. Shadowserver data and security firm reconnaissance suggest a sizable number of internet-facing Gitea instances remain unpatched. The exploit does not require credentials, does not require user interaction, and works over HTTPS, making perimeter defences irrelevant if the Gitea web interface is reachable.</p><p>This is also the second significant supply-chain-adjacent development this week targeting developer infrastructure, following the Oracle WebLogic nation-state campaign covered earlier today.</p><h3>So What / Action</h3><p>Inventory every Gitea instance in your environment, including those behind VPNs. If you are running any version below 1.27.1, upgrade immediately. If open registration is not required, disable it now: set `DISABLE_REGISTRATION = true` and `ENABLE_OPENID_SIGNUP = false` in your Gitea configuration. Enable `REQUIRE_SIGNIN_VIEW = true` to force authentication for all page access. Check Git hook directories (`.git/hooks/`) on existing repositories for unexpected executables. Review Gitea access logs for new account registrations from unfamiliar IP addresses and repositories containing suspicious patch files. If patching is not immediately possible, place Gitea instances behind an authentication reverse proxy until the update is applied.</p>]]></content:encoded></item><item><title><![CDATA[Breaking: Oracle WebLogic CVSS 10.0 Under Active Nation-State Exploitation — 27 August 2026]]></title><description><![CDATA[Oracle WebLogic Under Active Nation-State Exploitation &#8212; CVSS 10.0, 100+ Countries Hit]]></description><link>https://www.cisointelligence.co/p/breaking-oracle-weblogic-cvss-100-377</link><guid isPermaLink="false">https://www.cisointelligence.co/p/breaking-oracle-weblogic-cvss-100-377</guid><dc:creator><![CDATA[Jonathan Care]]></dc:creator><pubDate>Thu, 27 Aug 2026 08:01:47 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!dHG7!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe26b6c29-ab25-4075-b37d-d271750820af_368x368.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h2>Oracle WebLogic Under Active Nation-State Exploitation &#8212; CVSS 10.0, 100+ Countries Hit</h2><p>CISA has added CVE-2026-21962 to its Known Exploited Vulnerabilities catalog with a 72-hour remediation deadline that expires today, August 27. The vulnerability carries a maximum CVSS score of 10.0 and affects Oracle HTTP Server and the Oracle WebLogic Server Proxy Plug-in. This is not theoretical.</p><h3>What's Happening</h3><p>A China-linked threat actor is exploiting CVE-2026-21962 in an active campaign across more than 100 countries, delivering the SNOWLIGHT downloader to government and commercial infrastructure targets. The flaw is an improper access control vulnerability that allows an unauthenticated attacker with network access via HTTP to gain complete access to all accessible data on the affected Oracle HTTP Server or WebLogic Server Proxy Plug-in instance, including unauthorized creation, deletion, and modification of critical data.</p><p>Honeypot data from CloudSEK confirms attackers are chaining CVE-2026-21962 with older WebLogic RCE flaws (CVE-2020-14882/14883, CVE-2020-2551, CVE-2017-10271), showing a sustained, multi-vector campaign against Oracle middleware.</p><h3>Why This Matters Now</h3><p>The vulnerability was disclosed and patched by Oracle in January 2026. Seven months later, it remains widely unpatched and under active nation-state exploitation. CISA's three-day deadline for federal agencies underscores the urgency. If you run Oracle HTTP Server or WebLogic Server Proxy Plug-in versions 12.2.1.4.0, 14.1.1.0.0, or 14.1.2.0.0 and have not applied the January 2026 Critical Patch Update, you should assume hostile access.</p><h3>Also This Week: NetScaler Double Trouble</h3><p>Citrix disclosed CVE-2026-19490 (CVSS 9.3 authentication bypass) on August 19, two days after confirming active exploitation of CVE-2026-8452 (pre-auth memory overflow, CVSS 8.8) on the same NetScaler ADC and Gateway appliances. Both target perimeter-facing AAA and Gateway virtual servers. A public PoC exists for CVE-2026-8452. The authentication bypass requires no credentials and no user interaction. Fix versions differ between the two CVEs (14.1-73.32+ for CVE-2026-19490, 14.1-72.61+ for CVE-2026-8452), meaning patching one does not patch the other. If you run NetScaler in Gateway or AAA mode, patch both to the latest available build immediately.</p><h3>So What / Action</h3><p>Check your asset inventory for Oracle HTTP Server and WebLogic Server Proxy Plug-in (versions 12.2.1.4.0, 14.1.1.0.0, 14.1.2.0.0) and Citrix NetScaler ADC/Gateway. Apply the January 2026 Oracle Critical Patch Update now. Patch NetScaler to 14.1-73.32 or later (which covers both CVEs). Hunt for SNOWLIGHT IOCs on any Oracle middleware exposure. If you cannot patch immediately, isolate or disable internet-facing Oracle HTTP Server and WebLogic Proxy Plug-in instances. This is a CVSS 10.0 flaw being exploited by a state actor to compromise government infrastructure. The three-day window is not a suggestion.</p>]]></content:encoded></item><item><title><![CDATA[Breaking: Oracle WebLogic CVSS 10.0 & VMware vCenter Under Active Nation-State Exploitation — 26 August 2026]]></title><description><![CDATA[Oracle WebLogic Maximum-Severity Flaw Under Active Exploitation (CVE-2026-21962)]]></description><link>https://www.cisointelligence.co/p/breaking-oracle-weblogic-cvss-100-3ed</link><guid isPermaLink="false">https://www.cisointelligence.co/p/breaking-oracle-weblogic-cvss-100-3ed</guid><dc:creator><![CDATA[Jonathan Care]]></dc:creator><pubDate>Wed, 26 Aug 2026 12:01:20 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!dHG7!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe26b6c29-ab25-4075-b37d-d271750820af_368x368.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h2>Oracle WebLogic Maximum-Severity Flaw Under Active Exploitation (CVE-2026-21962)</h2><p>CISA added CVE-2026-21962 to the Known Exploited Vulnerabilities catalog on August 24, 2026. The vulnerability carries a CVSS score of 10.0 &#8212; the maximum &#8212; and affects Oracle HTTP Server and the Oracle WebLogic Server Proxy Plug-in. It allows an unauthenticated attacker with HTTP network access to gain complete control of accessible data: creation, deletion, and modification of critical data, plus full access to all Oracle HTTP Server and WebLogic Proxy Plug-in reachable data. No credentials, no user interaction, no existing privileges required.</p><p>Oracle patched this in January 2026. That has not stopped exploitation. CloudSEK, GreyNoise, and SOCRadar have all confirmed active attacks. A CloudSEK honeypot captured exploitation within days of disclosure, alongside attacks chaining older WebLogic RCE flaws (CVE-2020-14882, CVE-2020-2551, CVE-2017-10271) &#8212; threat actors are treating WebLogic as a persistent attack surface, combining new and vintage vulnerabilities rather than moving on. The same CVE is also among those exploited by a China-linked threat actor delivering the SNOWLIGHT downloader across more than 100 countries. FCEB agencies have until August 27 to patch under BOD 26-04.</p><h2>VMware vCenter Exploited by Suspected China APT Across 47 Countries (CVE-2026-59310)</h2><p>CVE-2026-59310 is a CVSS 9.8 path traversal vulnerability in Broadcom VMware vCenter Server, added to KEV on August 18. A threat actor with network access to vCenter can execute arbitrary code without valid credentials. Broadcom disclosed it on July 29; exploitation began five days later, on August 3.</p><p>A suspected China-nexus APT has exploited this flaw to deploy backdoors and reverse_ssh binaries for persistent access. In at least one case, the campaign led to Babuk-derived ransomware deployment. 361 unique victim IP addresses have been identified across 47 countries, with Germany (55), the US (41), Turkey (38), Iran (26), and France (25) seeing the highest concentration. European infrastructure is heavily represented in the victim set. Microsoft IKE (CVE-2026-33824), SharePoint (CVE-2026-55040), and Apple macOS Screen Sharing (CVE-2026-65400) were all added to KEV the same day, all under active exploitation.</p><h2>So What / Action</h2><p>Two maximum-critical unauthenticated RCE vectors are under active exploitation right now, and neither requires sophisticated social engineering &#8212; just network access to an exposed service. The WebLogic flaw (CVSS 10.0) is as bad as it gets: unauthenticated, remote, complete data access. The vCenter flaw (CVSS 9.8) is being weaponised by a nation-state actor with ransomware follow-through and has already hit 47 countries, with European organisations disproportionately affected.</p><p>If you run Oracle HTTP Server or WebLogic Proxy Plug-in and have not applied the January 2026 Critical Patch Update, treat this as a P1 incident: patch immediately, then audit HTTP access logs for the exploitation IOCs published by CloudSEK and GreyNoise. For VMware vCenter, if patching is not yet complete, restrict network access to vCenter interfaces to management VLANs only and monitor for reverse_ssh and Babuk indicators. Both KEV entries carry BOD 26-04 compliance deadlines that have already passed for FCEB agencies; private-sector organisations should treat those deadlines as a floor, not a ceiling.</p>]]></content:encoded></item><item><title><![CDATA[Breaking: Iran Infrastructure Attacks, US Sanctions, UK Power Plant Down — 26 Aug 2026]]></title><description><![CDATA[Iran-Linked Attacks on Water and Energy Infrastructure: US Sanctions and UK Power Plant Shutdown]]></description><link>https://www.cisointelligence.co/p/breaking-iran-infrastructure-attacks</link><guid isPermaLink="false">https://www.cisointelligence.co/p/breaking-iran-infrastructure-attacks</guid><dc:creator><![CDATA[Jonathan Care]]></dc:creator><pubDate>Wed, 26 Aug 2026 08:01:41 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!dHG7!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe26b6c29-ab25-4075-b37d-d271750820af_368x368.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h2>Iran-Linked Attacks on Water and Energy Infrastructure: US Sanctions and UK Power Plant Shutdown</h2><p>The US Treasury has sanctioned six Iranian MOIS-linked cyber operatives under Operation Economic Outcast, targeting individuals behind sustained attacks on US critical infrastructure including energy companies, defence contractors, hospitals, and financial institutions. Three of those designated &#8212; Keyvan Fayyaz Ghareh Blagh, Saber Shahbazi Balujeh, and Mohammad Reza Kadkhoda'i &#8212; have been conducting network compromise operations against US critical infrastructure since at least late 2023. Blockchain analysis by TRM Labs reveals $16.8 million in on-chain funds across 30 wallets linked to the Mabna Institute actors, with one individual controlling 92% of that volume. The State Department has concurrently offered a $10 million reward for information on foreign-directed cyber attacks against US critical infrastructure.</p><p>Separately, Iranian-linked hackers have attacked over 30 water and wastewater utilities across at least 12 US states. CISA and FBI are assisting recovery efforts. The attacks exploited basic vulnerabilities in exposed operational technology, reinforcing that many municipal systems remain dangerously soft targets. This is not speculative &#8212; the breaches are confirmed, ongoing, and affecting drinking water systems.</p><p>In the UK, suspected Iranian hackers forced a small power plant offline for four days, marking what is believed to be the first successful cyberattack on a British energy facility. The UK government has stated there was no risk to the wider energy system. The incident was first reported by The Telegraph and has not been formally attributed to Iran by either government, though cybersecurity analysts assess Iranian involvement as likely given the operational pattern and timing alongside the broader campaign.</p><h2>Gitea RCE Added to KEV (CVE-2026-60004)</h2><p>CISA added CVE-2026-60004 to the Known Exploited Vulnerabilities catalog on August 25, with a remediation deadline of August 28. The vulnerability allows attackers with repository write access to inject malicious code via the diffpatch API endpoint, planting executable Git hooks that run shell commands as the Gitea service account. Gitea patched this in version 1.27.1 (late July). This is the second Gitea exploitation in recent months &#8212; CVE-2026-20896 was flagged in early July. Gitea is widely deployed in self-hosted DevOps environments, and a compromised Git host gives attackers direct access to source code and CI/CD pipelines. Upgrade to 1.27.1 immediately. Audit Git hooks and repository access logs for any unauthorised changes.</p><h2>So What / Action</h2><p>The convergence of state-directed attacks on water, energy, and healthcare infrastructure with financial motivations ($16.8M in on-chain proceeds) means the threat model has shifted. These are not intelligence-gathering operations alone &#8212; the actors are also profit-driven, which lowers the threshold for collateral damage. For CISOs: (1) If you operate water, energy, or healthcare OT systems, treat Iranian-linked IOCs as active threats now, not theoretical. Audit all remote access paths and enforce network segmentation between IT and OT. (2) Gitea instances &#8212; upgrade to 1.27.1 and check for modified Git hooks. A compromised Gitea host is a supply chain risk for everything it builds. (3) The $10M State Department reward signals that the US is actively seeking attribution intelligence &#8212; share relevant indicators with CISA and FBI. (4) Review the OFAC designations and associated wallet addresses against your own transaction monitoring. These actors operate in both espionage and financially-motivated modes.</p>]]></content:encoded></item><item><title><![CDATA[Breaking: Oracle WebLogic CVSS 10.0 in KEV, Siemens PLCs Under AI Attack, China-Nexus APT Hits 47 Countries — 25 Aug 2026]]></title><description><![CDATA[Oracle WebLogic CVSS 10.0 Added to KEV &#8212; Active Exploitation Confirmed]]></description><link>https://www.cisointelligence.co/p/breaking-oracle-weblogic-cvss-100</link><guid isPermaLink="false">https://www.cisointelligence.co/p/breaking-oracle-weblogic-cvss-100</guid><dc:creator><![CDATA[Jonathan Care]]></dc:creator><pubDate>Tue, 25 Aug 2026 08:01:42 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!dHG7!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe26b6c29-ab25-4075-b37d-d271750820af_368x368.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h2>Oracle WebLogic CVSS 10.0 Added to KEV &#8212; Active Exploitation Confirmed</h2><p>CISA has added CVE-2026-21962 to its Known Exploited Vulnerabilities catalog as of August 24, confirming active exploitation in the wild. The flaw, rated CVSS 10.0, is an improper access control vulnerability affecting both Oracle HTTP Server and the Oracle WebLogic Server Proxy Plug-in. Successful exploitation allows unauthenticated attackers to create, delete, or modify critical data and gain complete access to all accessible data on affected systems. Weaponised scripts and automated scanning are already being observed targeting internet-facing instances. FCEB agencies must remediate by August 27 under BOD 26-04. Oracle HTTP Server and the WebLogic proxy plug-in sit at the boundary between external users and internal applications, making this a high-priority perimeter risk. Any unpatched, network-reachable Oracle middleware instance should be treated as presumed compromised until verified otherwise.</p><h2>CISA/NSA/FBI Joint Advisory: AI-Powered Attacks Targeting Siemens S7 PLCs</h2><p>A joint advisory from CISA, NSA, and FBI warns that threat actors are using AI-generated exploit scripts to target internet-exposed Siemens S7 Series programmable logic controllers. The affected sectors include water and wastewater, energy, critical manufacturing, chemical, and food and agriculture. The AI-assisted approach lowers the skill barrier for OT exploitation, enabling actors who would previously lack the expertise to craft ICS-specific payloads to now generate functional attack code. Any organisation running Siemens S7 PLCs exposed to the internet or on bridged OT/IT networks should immediately audit exposure, enforce network segmentation, and apply detection rules from the advisory. This is the clearest confirmation yet that AI is being weaponised directly against industrial control systems, not just IT infrastructure.</p><h2>SPIP CMS RCE (CVE-2026-77806) &#8212; Added to KEV, Exploited in the Wild</h2><p>CISA added CVE-2026-77806 (CVSS 9.8) to the KEV catalog on August 24, confirming active exploitation. The vulnerability allows unauthenticated remote code execution in SPIP versions before 4.4.21. A public exploit is circulating. Any internet-facing SPIP instance should be upgraded to 4.4.21 immediately. SPIP is widely used in French-speaking government and institutional websites, making this a particular concern for European public-sector organisations.</p><h2>China-Nexus APT Campaign: VMware vCenter Exploitation Spans 47 Countries</h2><p>German incident response firm QUIRSO has published detailed analysis of the China-nexus APT campaign exploiting CVE-2026-59310 (VMware vCenter, CVSS 9.8). The actor, assessed as Chinese-speaking with UTC+08:00 operational hours, began exploiting the flaw five calendar days after public disclosure. The campaign has compromised 361 unique victim IPs across 47 countries, with Germany (55), the US (41), Turkey (38), Iran (26), and France (25) most affected. The attack chain includes JSP webshell deployment disguised as VMware performance monitoring tools, credential theft from vmdir, creation of persistent admin accounts, and lateral movement to ESXi hosts for Babuk-derived ransomware deployment. The use of reverse SSH binaries, WebSocket-based C2 with XOR-obfuscated addresses, and sudoers persistence through the perfcharts service account indicates a sophisticated, well-resourced operator. Patch to vCenter 9.1.0.0300+ or 8.0 U3k+ immediately and audit for indicators of compromise.</p><h2>So What / Action</h2><p>This is an unusually concentrated burst of critical exploitation. Four CVSS 9.8+ vulnerabilities hit the KEV in eight days, a nation-state actor is running ransomware operations from vCenter compromises across European infrastructure, and AI is being directly weaponised against industrial control systems. The patch window from disclosure to exploitation has collapsed to days, not weeks. Prioritise: (1) Oracle WebLogic/HTTP Server instances &#8212; CVSS 10.0, perimeter-facing, actively scanned; (2) Windows IPsec/VPN hosts running IKE &#8212; wormable, pre-auth RCE; (3) VMware vCenter &#8212; check for IOCs from the China-nexus campaign, especially cron jobs in /etc/cron.d/ referencing syslog or perf, unexpected admin accounts, and reverse SSH binaries; (4) Siemens S7 PLCs &#8212; audit all OT exposure, enforce air-gap discipline; (5) SPIP installations &#8212; upgrade immediately. If you run Oracle middleware at the edge, assume compromise and investigate, don't just patch.</p>]]></content:encoded></item><item><title><![CDATA[Breaking: Iran-Linked Attack Shuts Down UK Power Plant — vCenter Mass Exploitation Escalates — 24 August 2026]]></title><description><![CDATA[Iran-Linked Cyberattack Shuts Down UK Power Plant]]></description><link>https://www.cisointelligence.co/p/breaking-iran-linked-attack-shuts</link><guid isPermaLink="false">https://www.cisointelligence.co/p/breaking-iran-linked-attack-shuts</guid><dc:creator><![CDATA[Jonathan Care]]></dc:creator><pubDate>Mon, 24 Aug 2026 12:01:19 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!dHG7!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe26b6c29-ab25-4075-b37d-d271750820af_368x368.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h2>Iran-Linked Cyberattack Shuts Down UK Power Plant</h2><p>A cyberattack attributed to Iran-linked threat actors forced a small UK power generator offline for four days in July, marking the first confirmed state-linked cyberattack to cause operational disruption of British energy infrastructure. The Telegraph first reported the incident on 22 August; the UK government has briefed energy companies on strengthening cybersecurity defences, while the NCSC is assessing the threat.</p><p>The affected facility, believed to be a gas peaker plant supplying on-demand capacity, was taken offline for four days with staff forced to restore operations manually. The government confirmed the incident posed no risk to national electricity supply. Neither the specific actors nor the attack vector have been formally confirmed, though experts note that compromising critical infrastructure does not necessarily require sophisticated techniques: exposed internet-facing devices, compromised remote access credentials, and vulnerable gateways all present viable entry points.</p><p>The significance extends beyond the generating capacity lost. Security researchers at Orange Cyberdefense note a "second-order cognitive effect" &#8212; demonstrating that UK energy infrastructure can be reached and disrupted through cyber activity, which can undermine public trust and confidence. e2e-assure CEO Rob Demain raises the more systemic concern: the question is not how to protect one small generator, but whether the same route into that generator exists across fifty others. The UK's increasingly distributed electricity system means vulnerabilities repeated across multiple assets compound into a much larger risk.</p><p>This incident validates longstanding NCSC warnings about state-backed threats to critical national infrastructure. It follows a pattern of Iranian cyber operations escalating alongside geopolitical confrontation, with Iran-linked groups using cyber operations as a primary weapon favouring disruption and strategic messaging.</p><h2>VMware vCenter Under Active Exploitation &#8212; CVE-2026-59310</h2><p>German incident response firm Quirso has documented active exploitation of CVE-2026-59310, a CVSS 9.8 path traversal vulnerability in VMware vCenter's Syslog server. The flaw allows unauthenticated remote code execution by an attacker with network access to vCenter.</p><p>Broadcom published the advisory on 29 July, stating no observed exploitation. By 3 August, compromised systems were already contacting attacker infrastructure. Within 48 hours, 361 victim IP addresses appeared across 47 countries, with Germany, the US, Turkey, Iran, and France accounting for 185 of them. The speed from disclosure to mass exploitation points to the advisory itself as the campaign trigger.</p><p>For persistence, the threat actor deployed reverse_ssh, an open-source SSH-based reverse shell framework designed for penetration testing. Because it dials outward rather than accepting inbound connections, it bypasses controls designed to block unsolicited access. CISA added CVE-2026-59310 to the KEV catalogue on 18 August with a remediation deadline of 21 August.</p><p>Patching alone is insufficient. As Sectigo's Jason Soroko notes, there are two clocks to manage: one for closing the vulnerability and one for evicting anyone who entered before the patch. No workaround exists. Fixed releases are vCenter 9.1.0.0300, 9.0.2.0100, 8.0 U3k, and 8.0 U2f.</p><h2>So What / Action</h2><p>For the Iran-linked energy attack: audit all internet-facing OT and ICS assets, particularly in energy and utilities. Remove unnecessary remote access routes, rotate credentials for supplier and dormant accounts, and restrict network access to operational systems. Assume that the same attack paths present in one facility exist across your estate. Confirm that IT/OT segmentation is enforced, not just documented. The distributed nature of modern energy infrastructure means a single vulnerability pattern replicated across sites is a systemic risk, not an isolated incident.</p><p>For vCenter: if you run VMware vCenter and have not yet patched to the fixed releases, treat this as an active compromise assumption. Patch immediately, then hunt for reverse_ssh and other persistence mechanisms. Credential rotation and full incident response triage are essential &#8212; patching without eviction is leaving the front door closed with intruders already inside.</p>]]></content:encoded></item><item><title><![CDATA[Breaking: China-Nexus APT Exploits VMware vCenter at Scale — 361 Hosts, Ransomware Deployed — 24 August 2026]]></title><description><![CDATA[China-Nexus APT Exploits VMware vCenter Flaw at Scale, Deploys Ransomware]]></description><link>https://www.cisointelligence.co/p/breaking-china-nexus-apt-exploits</link><guid isPermaLink="false">https://www.cisointelligence.co/p/breaking-china-nexus-apt-exploits</guid><dc:creator><![CDATA[Jonathan Care]]></dc:creator><pubDate>Mon, 24 Aug 2026 08:01:50 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!dHG7!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe26b6c29-ab25-4075-b37d-d271750820af_368x368.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h2>China-Nexus APT Exploits VMware vCenter Flaw at Scale, Deploys Ransomware</h2><p>A suspected China-nexus advanced persistent threat is actively exploiting CVE-2026-59310, a critical directory-traversal vulnerability in Broadcom VMware vCenter Server (CVSS 9.8), to gain unauthenticated remote code execution with root privileges on vCenter Server Appliances. German incident response firm QUIRSO, which uncovered the campaign, assesses with moderate confidence that the actor operates from the UTC+08:00 time zone based on Chinese-language artifacts in attacker scripts, reuse of Chinese security research, and victimology that excludes mainland China.</p><p>The campaign has compromised at least 361 unique victim IP addresses across 47 countries. The heaviest concentrations are in Germany (55), the United States (41), Turkey (38), Iran (26), and France (25). European organisations are prominently represented.</p><h3>Attack Chain</h3><p>Exploitation begins five days after Broadcom's July 29 patch release. The actor abuses vCenter's syslog service to write a malformed cron job file to /etc/cron.d, achieving immediate root-level code execution without any privilege escalation step. From there, the campaign follows a methodical progression:</p><p>- A cron-deployed backdoor ("linuxFile") connects to C2 over WebSocket (ws://intel.se9ly9upbhay.shop:8080/ws) with XOR-obfuscated addressing and custom application-layer cryptography. Persistence is established via systemd and cron. - Three cronjobs impersonating legitimate VMware services (vmware-vpxd-stats, vmware-perf-collect, vmware-perf-sync) add attacker SSH keys, drop a JSP web shell (vmware-perf-update.jsp), and run Base64-encoded scripts that harvest vmdir credentials and create a vSphere SSO Administrator account ("adminuser"). - A sudoers entry grants the "perfcharts" service account unrestricted passwordless root access. - A reverse SSH binary is deployed to ESXi hosts via an "esxi.sh" downloader, with infrastructure at 185.144.28[.]120:3232. - Local "adminuser" accounts are created on ESXi hosts, enabling ransomware deployment.</p><p>The ransomware encrypts files with the ".babyk" extension, consistent with Babuk-derived ransomware. QUIRSO suspects the ransomware may be a smokescreen designed to destroy forensic evidence (particularly ESXi log files) rather than the primary objective of the campaign.</p><h3>Attribution and Infrastructure</h3><p>In a follow-up analysis, QUIRSO identified a GitHub repository (pikpak0066/tmpclean, created August 14) linked to the same threat actor. The repository masquerades as a /tmp cleaning daemon for Linux but reverse engineering confirmed the published binaries are the actor's reverse SSH builds. Additional infrastructure includes 146.59.252[.]178 (used for CVE-2026-59309 authentication bypass exploitation and vSphere REST API discovery), 5.34.177[.]38:9861 (backdoor distribution), and 192.255.141[.]13:8080.</p><p>The campaign also exploits CVE-2026-59309, a separate vCenter authentication bypass, on the same systems. No overlap was observed between the two exploitation chains, suggesting either parallel actors or a sophisticated multi-vector approach.</p><h3>So What / Action</h3><p>This is not a scanning campaign &#8212; it is a structured, multi-stage intrusion operation with credential theft, lateral movement, and ransomware deployment by an actor with nation-state tradecraft. If you run VMware vCenter and have not patched since July 29, assume compromise. Immediate priorities:</p><p>1. Patch vCenter immediately &#8212; CVE-2026-59310 (VMSA-2026-0012) and CVE-2026-59309. Both are under active exploitation. CISA's remediation deadline was August 21. 2. Hunt for IOCs &#8212; Check /etc/cron.d/ for files named with "poc59310" or "vmware-perf-" prefixes. Look for the "vcenter_admin" and "adminuser" accounts. Search /etc/sudoers.d/ for "vmware-perf". Audit authorized_keys files for attacker SSH keys. 3. Inspect vSphere SSO &#8212; Review Administrator group membership for unauthorised accounts, particularly any created via vmdir LDAP operations from external IPs. 4. Block C2 infrastructure &#8212; Add the identified IPs and domains to network blocklists. 5. Assume lateral movement &#8212; If vCenter was compromised, treat all managed ESXi hosts and guest VMs as potentially affected until forensic review completes.</p><p>European CISOs should treat this as a live, ongoing campaign. The 361 compromised IPs likely represent a fraction of total impact.</p>]]></content:encoded></item><item><title><![CDATA[Breaking: AI-Generated Exploits Attack Siemens S7 PLCs Across Critical Infrastructure — 21 August 2026]]></title><description><![CDATA[AI-Generated Exploits Target Siemens S7 PLCs Across Critical Infrastructure]]></description><link>https://www.cisointelligence.co/p/breaking-ai-generated-exploits-attack</link><guid isPermaLink="false">https://www.cisointelligence.co/p/breaking-ai-generated-exploits-attack</guid><dc:creator><![CDATA[Jonathan Care]]></dc:creator><pubDate>Fri, 21 Aug 2026 08:03:05 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!dHG7!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe26b6c29-ab25-4075-b37d-d271750820af_368x368.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h2>AI-Generated Exploits Target Siemens S7 PLCs Across Critical Infrastructure</h2><p>Five US federal agencies &#8212; NSA, CISA, FBI, Department of Energy, and EPA &#8212; issued joint advisory AA26-231A on August 20 warning that threat actors are using AI-generated exploitation scripts to attack Siemens S7 Series programmable logic controllers across energy, water and wastewater, chemical, food and agriculture, and critical manufacturing sectors. The advisory describes the campaign as an "active threat" &#8212; not theoretical, not reconnaissance-only, but ongoing exploitation of internet-exposed PLCs.</p><p>The attack chain is straightforward and marks a genuine inflection point in ICS threats. Actors use internet scanning services (Censys, ZoomEye) to find exposed S7-200, S7-300, S7-400, S7-1200, and S7-1500 PLCs running outdated firmware or with weak configurations. They then feed that targeting data into AI tools that generate functional Python exploitation scripts using the open-source snap7.dll and python-snap7 libraries &#8212; the same libraries legitimate engineers use for PLC monitoring and programming. The scripts are disguised as legitimate monitoring tools and provide read/write access to PLC memory, configuration data, and ladder logic via the S7comm protocol.</p><p>This is the first confirmed joint-agency warning that names AI-generated exploit code as an active component of a critical infrastructure attack campaign. The scripts are not proof-of-concept or researcher tools; they are functional weaponised code being deployed against production systems that control water treatment, power generation, and chemical processing. The advisory explicitly states that exploitation could lead to disruption of industrial processes, safety incidents, equipment damage, and data compromise.</p><p>The targeted S7 Series PLCs span every major generation Siemens has shipped. The S7-1500 F-series (failsafe) controllers are specifically called out, meaning safety-instrumented systems are in scope. Many of these devices run end-of-life firmware or use legacy protocols like Modbus that lack authentication or encryption. Siemens has stated there are no new vulnerabilities in its products &#8212; the attack exploits known weaknesses and misconfigurations identified in a July 2025 advisory (SSA-104599).</p><p>The broader context matters. This campaign follows a wave of Iran-nexus attacks against water and wastewater facilities across at least 12 US states, where operators were temporarily locked out of their own PLCs. Whether the current campaign originates from the same actors or from opportunistic copycats exploiting the same exposed attack surface is unclear. The advisory does not attribute the activity to a specific nation-state group.</p><p>Separately, the same week saw reporting on a near-autonomous multi-agent AI attack framework (Hermes/OpenClaw) that targeted Taiwanese government infrastructure over 3-4 July, cracking 85 credentials, exfiltrating 2,564 personnel records, and establishing persistent backdoors across multiple government portals. That campaign produced 1,395 files of output and expanded to target IT supply chain vendors, a nuclear safety agency, and seven energy sector companies. The cost of running a competent attack has collapsed. The cost of defending against one has not.</p><h2>So What / Action</h2><p>If you operate Siemens S7 PLCs in any critical infrastructure sector, this advisory demands immediate action. Audit external-facing PLCs for internet exposure &#8212; if any S7 controller is reachable from outside your OT network, take it offline or isolate it now. Ensure firmware is current on all S7 Series devices, particularly the S7-1200 and S7-1500 families which remain widely deployed. Enable multi-factor authentication wherever the management interface supports it. Deploy ICS-aware monitoring to detect anomalous S7comm traffic, unexpected connection attempts from snap7-based tools, and credential access patterns that don't match legitimate maintenance windows. The barrier to ICS exploitation has just been lowered by an order of magnitude; your defensive baseline needs to move up by the same margin.</p><p>Jonathan Care has 33 years in cybersecurity and fraud detection. These are his personal views, not those of his employer.</p>]]></content:encoded></item><item><title><![CDATA[Breaking: China-Nexus APT Mass-Exploits VMware vCenter — 361 Victims, Ransomware Deployed — 20 August 2026]]></title><description><![CDATA[China-Nexus APT Exploits VMware vCenter Flaw at Scale &#8212; 361 Victims, Ransomware Deployed]]></description><link>https://www.cisointelligence.co/p/breaking-china-nexus-apt-mass-exploits</link><guid isPermaLink="false">https://www.cisointelligence.co/p/breaking-china-nexus-apt-mass-exploits</guid><dc:creator><![CDATA[Jonathan Care]]></dc:creator><pubDate>Thu, 20 Aug 2026 17:02:10 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!dHG7!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe26b6c29-ab25-4075-b37d-d271750820af_368x368.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h2>China-Nexus APT Exploits VMware vCenter Flaw at Scale &#8212; 361 Victims, Ransomware Deployed</h2><p>A suspected China-nexus advanced persistent threat has rapidly weaponised CVE-2026-59310, a critical (CVSS 9.8) path traversal vulnerability in the VMware vCenter Syslog server, compromising at least 361 unique IP addresses across 47 countries within five days of public disclosure. German incident response firm QUIRSO assessed with moderate confidence that the actor operates from the UTC+8 timezone, citing Chinese-language artefacts in attack scripts, reuse of Chinese security research, and systematic exclusion of mainland China from victimology.</p><p>The attack chain starts with an unauthenticated network request to the vCenter Syslog service, which writes a malformed cron file to `/etc/cron.d`. This grants immediate root-level code execution on the vCenter Server Appliance without requiring prior authentication or local privilege escalation. From there, the actor:</p><p>- Deployed a WebSocket-based backdoor ("linuxFile") connecting to `ws://intel.se9ly9upbhay.shop:8080/ws` with XOR-obfuscated C2 addresses and application-layer encryption - Established persistence through systemd services and cron jobs disguised as legitimate VMware processes (`vmware-vpxd-stats-`, `vmware-perf-collect-`, `vmware-perf-sync-*`) - Dropped a JSP web shell (`vmware-perf-update.jsp`) for alternative access - Created multiple administrative accounts on vCenter and vSphere SSO, including through LDAP manipulation of the VMware Directory Service (vmdir) - Stole vCenter machine credentials via the `vmafd` Python module and `/etc/sudoers.d/vmware-perf` for passwordless root sudo - Deployed `reverse_ssh` binaries for persistent remote access across ESXi hosts - In at least one case, deployed Babuk-derived ransomware encrypting ESXi files with the `.babyk` extension &#8212; potentially as a smokescreen to destroy forensic evidence rather than as the primary campaign objective</p><p>Europe is heavily represented in the victim distribution: Germany (55 IPs), France (25), alongside the US (41), Turkey (38), and Iran (26). The breadth of compromise across 47 countries and the speed of exploitation &#8212; first observed August 3, just five days after the July 29 patch release &#8212; indicates a pre-positioned capability or rapid weaponisation pipeline.</p><p>Separately, CVE-2026-33824 (CVSS 9.8), a double-free vulnerability in Microsoft's IKE Service Extensions, has been added to CISA's KEV catalog with confirmed active exploitation. Unit 42 reports a different Chinese-speaking threat actor exploiting this flaw while simultaneously running an autonomous, AI-driven hacking campaign using DeepSeek. This represents one of the first documented cases of a nation-state-affiliated actor deploying large-language-model-powered autonomous attack infrastructure alongside manual exploitation.</p><p>Three further KEV additions carry the same August 21 BOD 26-04 remediation deadline: CVE-2026-65400 (macOS Screen Sharing authentication bypass, CVSS 9.8, actively exploited for Monero mining), CVE-2026-55040 (SharePoint authentication bypass, CVSS 9.1, PoC-available exploitation), and CVE-2026-59309 (VMware vCenter authentication bypass, chained with CVE-2026-59310 in observed attacks).</p><h2>So What / Action</h2><p>If you run VMware vCenter and haven't patched since July 29, assume compromise. The attack chain provides full root access from a single unauthenticated request &#8212; there is no lateral movement required, no privilege escalation needed. Patch immediately; if patching isn't possible today, isolate vCenter from all untrusted network access and audit for the IOC patterns QUIRSO has published (cron files matching `zz-poc59310-`, accounts named `vcenter_admin`/`vcadmin`/`adminuser`, sudoers entries in `/etc/sudoers.d/vmware-perf`). For IKE VPN infrastructure, the CVE-2026-33824 patch is equally urgent given the AI-augmented exploitation campaign &#8212; this is no longer theoretical. The three-day BOD 26-04 deadline (August 21) exists because these are being exploited at speed and scale.</p><p>Jonathan Care has 33 years in cybersecurity and fraud detection. These are his personal views, not those of his employer.</p>]]></content:encoded></item><item><title><![CDATA[Breaking: Four CVSS 9.8 Vulnerabilities Under Active APT Exploitation — CISA KEV Update With 72-Hour Deadline]]></title><description><![CDATA[Four Critical Vulnerabilities Added to CISA KEV With Active Exploitation &#8212; Including APT Ransomware Campaign and AI-Driven Hacking]]></description><link>https://www.cisointelligence.co/p/breaking-four-cvss-98-vulnerabilities</link><guid isPermaLink="false">https://www.cisointelligence.co/p/breaking-four-cvss-98-vulnerabilities</guid><dc:creator><![CDATA[Jonathan Care]]></dc:creator><pubDate>Wed, 19 Aug 2026 17:01:48 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!dHG7!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe26b6c29-ab25-4075-b37d-d271750820af_368x368.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h2>Four Critical Vulnerabilities Added to CISA KEV With Active Exploitation &#8212; Including APT Ransomware Campaign and AI-Driven Hacking</h2><p>CISA added four vulnerabilities to its Known Exploited Vulnerabilities catalog on August 18, all with confirmed active exploitation in the wild. Three carry CVSS 9.8. Two are linked to Chinese state-nexus actors. One has already resulted in ransomware deployment. The 72-hour patching deadline (August 21) makes this the most consequential KEV update in months.</p><h3>VMware vCenter Path Traversal &#8212; CVE-2026-59310 (CVSS 9.8)</h3><p>A suspected China-nexus APT is exploiting a directory traversal vulnerability in the vCenter Syslog server to achieve remote code execution. German incident response firm QUIRSO assessed with moderate confidence that the operator works in the UTC+08:00 timezone, based on Chinese-language artifacts in attacker scripts, reuse of Chinese security research, and operational patterns consistent with Chinese-speaking APTs.</p><p>The campaign has compromised 361 unique victim IP addresses across 47 countries. Germany (55), the United States (41), Turkey (38), Iran (26), and France (25) top the list. Mainland China is conspicuously absent from the victim list.</p><p>The attack chain is elaborate. Initial exploitation via CVE-2026-59310 deploys a WebSocket-based backdoor ("linuxFile") that connects to XOR-obfuscated C2 infrastructure. The actor then creates persistent access through cron jobs disguised as VMware services, drops a JSP web shell, adds rogue administrative accounts to vSphere SSO, extracts vmdir credentials to escalate privileges, and deploys a reverse SSH binary for lateral movement. The campaign culminates in Babuk-derived ransomware on ESXi hosts, encrypting files with the ".babyk" extension.</p><p>Separately, CVE-2026-59309 (vCenter authentication bypass) was also exploited on the same compromised appliance as early as August 1, with a rogue admin account created via the vSphere REST API using a User-Agent masquerading as "GoodMoodle-VCFleet/1.0."</p><p>Patches were released by Broadcom on July 29. The first exploitation activity appeared five days later.</p><h3>Microsoft IKE Service Extensions Double Free &#8212; CVE-2026-33824 (CVSS 9.8)</h3><p>A double free vulnerability in the Windows Internet Key Exchange service extensions allows unauthenticated remote code execution over the network via UDP ports 500 or 4500. No authentication required, no user interaction needed.</p><p>Palo Alto Networks Unit 42 reports that this flaw is being exploited by a Chinese-speaking threat actor who simultaneously launched an AI-enabled autonomous hacking campaign using DeepSeek. The actor combined manual exploitation of known vulnerabilities with autonomous AI-driven attack flows. This represents one of the first confirmed cases of a threat actor using large language models to autonomously orchestrate vulnerability exploitation in the wild, a worrying escalation in offensive AI use.</p><p>Any Windows system running IKE VPN services with ports 500 or 4500 exposed to the internet is at risk.</p><h3>Apple macOS Screen Sharing Authentication Bypass &#8212; CVE-2026-65400 (CVSS 9.8)</h3><p>A logic flaw in macOS Screen Sharing allows a network-adjacent attacker to authenticate without valid credentials. The Dutch NCSC reports active exploitation against Macs with port 5900 exposed to the internet, with attackers gaining root access and deploying Monero cryptocurrency miners.</p><p>Security researcher Alfredo Pesoli of Bynario disclosed the bug, which resides in a legacy VNC authentication path. A separate but related pre-auth vulnerability (discovered by @osxreverser, who deliberately did not report it to Apple) was also patched in macOS 26.6. Calif demonstrated a working exploit for both flaws developed by an AI agent in four hours, underscoring how AI is collapsing the gap between vulnerability disclosure and weaponisation.</p><p>Security firm scans identified approximately 40,000 internet-exposed Macs running Screen Sharing, nearly half in the United States, including systems at universities and businesses.</p><p>Patch immediately: macOS Tahoe 26.6.1, macOS Sequoia 15.7.9, or macOS Sonoma 14.8.9. If patching is not possible, disable Screen Sharing entirely (General &gt; Sharing &gt; toggle off Screen Sharing).</p><h3>Microsoft SharePoint Authentication Bypass &#8212; CVE-2026-55040 (CVSS 9.1)</h3><p>A weak authentication flaw in on-premises SharePoint Server allows unauthenticated attackers to bypass security features over the network and impersonate any user, including administrators. The vulnerability targets the JWT validation pipeline in SharePoint Subscription Edition.</p><p>Rapid7 published a working proof-of-concept on August 11, and honeypots recorded exploitation attempts within roughly 24 hours. Active exploitation in the wild is now confirmed.</p><h3>So What / Action</h3><p>This is a patch-everything-you-can-immediately week. The vCenter campaign is the highest severity: if you run VMware infrastructure and have not applied the July 29 patches, assume compromise and begin incident response, not just patching. Check for the specific IOCs: rogue cron jobs under /etc/cron.d with VMware-themed names, unauthorized accounts ("vcenter_admin", "vcadmin", "adminuser"), the "linuxFile" backdoor process, and reverse SSH binaries. For IKE, any Windows server with VPN services facing the internet should be patched today &#8212; this is an unauthenticated RCE with no user interaction. Mac fleets with Screen Sharing enabled, especially those exposed via port 5900, need the emergency Apple updates immediately. SharePoint admins should verify they are running the latest patches and check logs for unauthorised JWT token usage. The AI-driven exploitation of the IKE flaw by a state actor is a signal moment: the gap between disclosure and weaponisation is now measured in hours, not days.</p>]]></content:encoded></item><item><title><![CDATA[Breaking: Four Actively Exploited CVEs Added to CISA KEV — Three CVSS 9.0+ — 19 Aug 2026]]></title><description><![CDATA[CISA Adds Four Actively Exploited Vulnerabilities to KEV &#8212; Three CVSS 9.0+]]></description><link>https://www.cisointelligence.co/p/breaking-four-actively-exploited</link><guid isPermaLink="false">https://www.cisointelligence.co/p/breaking-four-actively-exploited</guid><dc:creator><![CDATA[Jonathan Care]]></dc:creator><pubDate>Wed, 19 Aug 2026 08:02:04 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!dHG7!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe26b6c29-ab25-4075-b37d-d271750820af_368x368.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h2>CISA Adds Four Actively Exploited Vulnerabilities to KEV &#8212; Three CVSS 9.0+</h2><p>CISA has added four vulnerabilities to its Known Exploited Vulnerabilities catalog, all with confirmed active exploitation. Three carry CVSS scores of 9.0 or above. The additions, made August 18, come with remediation deadlines as short as three days under BOD 26-04.</p><h2>macOS Screen Sharing Authentication Bypass (CVE-2026-65400, CVSS 9.8)</h2><p>The most urgent addition. A pre-authentication bypass in macOS Screen Sharing allows remote attackers on the network to authenticate without valid credentials. The Dutch National Cyber Security Centre (NCSC-NL) confirmed on August 12 that the flaw is under active exploitation &#8212; attackers are compromising internet-exposed Macs (specifically those with port 5900 open) and deploying Monero cryptocurrency miners after gaining root access. Apple patched the vulnerability last week for macOS Tahoe, Sequoia, and Sonoma. If you run macOS servers or developer workstations exposed to the internet, this is not theoretical &#8212; cryptomining payloads are already deployed in the wild. KEV remediation deadline: August 21.</p><h2>VMware vCenter Directory Traversal RCE (CVE-2026-59310, CVSS 9.8)</h2><p>A directory traversal vulnerability in VMware vCenter's Syslog service component enables remote code execution by any attacker with network access. Broadcom disclosed the flaw on July 29; by August 3 &#8212; five days later &#8212; a suspected China-nexus APT was already exploiting it at scale. The QUIRSO research team has traced the campaign to 361 victim IP addresses across 47 countries, with Germany, the US, Turkey, Iran, and France accounting for over half of confirmed victims. In at least one case, Babuk-derived ransomware was deployed as a forensic smokescreen after the attackers established persistent backdoor access via reverse SSH tunnels. This is datacentre infrastructure under active nation-state attack. KEV remediation deadline: August 21.</p><h2>Microsoft SharePoint Authentication Bypass (CVE-2026-55040, CVSS 9.1)</h2><p>A weak authentication vulnerability in SharePoint Server's JWT validation pipeline allows unauthenticated remote attackers to bypass security controls and impersonate privileged accounts. Microsoft patched it in July's Patch Tuesday, but Rapid7 published a proof-of-concept on August 12 &#8212; and active exploitation followed within days. On-premises SharePoint Server Subscription Edition and 2019/2016 are affected. If you run SharePoint and haven't applied July's patches, assume compromise. KEV remediation deadline: August 21.</p><h2>Microsoft IKE Service Extensions Double Free (CVE-2026-33824)</h2><p>A double-free vulnerability in Microsoft's Internet Key Exchange service extensions could enable remote code execution. CISA's KEV listing confirms active exploitation. This was patched in August Patch Tuesday alongside the afd.sys privilege escalation (CVE-2026-68820, also KEV-listed and exploited by Lazarus Group). KEV remediation deadline: August 21.</p><h2>So What / Action</h2><p>Four actively exploited vulnerabilities added to KEV in a single day, three of them CVSS 9.0+ &#8212; and all with an August 21 remediation deadline. That is 72 hours from now. For CISOs: run immediate exposure assessments against all four CVEs. Prioritise by attack surface &#8212; internet-facing vCenter and SharePoint instances first, followed by macOS endpoints with Screen Sharing enabled and remote access. For vCenter specifically: if you cannot patch by August 21, audit for unauthorised reverse SSH connections and backdoor accounts, because the exploitation campaign is mature and widespread. For macOS: verify Screen Sharing is disabled on internet-exposed hosts, or confirm the Apple patch is applied. The three-day BOD 26-04 window is not aspirational &#8212; it reflects how fast these are being exploited in the wild.</p>]]></content:encoded></item><item><title><![CDATA[Breaking: Russian Cyber Campaign Hits French Tax Authority — France Summons Ambassador]]></title><description><![CDATA[Russian Cyber Campaign Hits French Tax Authority &#8212; France Summons Ambassador]]></description><link>https://www.cisointelligence.co/p/breaking-russian-cyber-campaign-hits</link><guid isPermaLink="false">https://www.cisointelligence.co/p/breaking-russian-cyber-campaign-hits</guid><dc:creator><![CDATA[Jonathan Care]]></dc:creator><pubDate>Mon, 17 Aug 2026 17:03:10 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!dHG7!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe26b6c29-ab25-4075-b37d-d271750820af_368x368.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h2>Russian Cyber Campaign Hits French Tax Authority &#8212; France Summons Ambassador</h2><p>France's Ministry of Economy has confirmed a major cyberattack against the French tax platform (impots.gouv.fr), with attackers accessing highly sensitive personal and financial data belonging to French citizens. Digital Affairs Minister Jean-No&#235;l Barrot announced that France will summon the Russian ambassador to Paris, citing a "large-scale cyber campaign" attributed to Russian state actors targeting multiple European countries including France.</p><p>The breach was first claimed in cybercrime forums before the Ministry confirmed it less than 24 hours later. The attack targeted critical government financial infrastructure &#8212; the tax authority's systems &#8212; exposing personal and financial data at a scale still under investigation. The severity rating assigned to the incident is the highest possible: an attack threatening the organisation's existence, according to external TPRM assessments.</p><p>The diplomatic escalation follows Finland's July 13 summoning of Russia's ambassador over a separate cyber campaign, and Germany's similar diplomatic action. Three European nations have now formally accused Russia of state-sponsored cyber operations against their government systems. France's response is notable for the speed and directness of the attribution, and for the target: a core revenue-collection platform handling the financial data of 67 million citizens.</p><p>The incident adds a new dimension to the Russian cyber threat picture. Previous European campaigns focused on espionage and disruption. This attack on a financial infrastructure platform &#8212; with confirmed data exfiltration of personal and financial records &#8212; represents a shift toward operations that directly compromise citizen trust in government digital services.</p><h2>So What / Action</h2><p>For CISOs with European operations or EU data processing: this is a concrete escalation from espionage to infrastructure compromise with data exfiltration. If your organisation interfaces with French government systems (tax filing, GFI integration, DSN reporting), verify those connection points for compromise indicators. For any organisation in an EU member state: treat this as confirmation that Russian state actors are actively targeting government financial infrastructure, not just conducting reconnaissance. Review threat models for any system that handles citizen financial data, and ensure your incident response plan accounts for the diplomatic dimension &#8212; breaches involving state actors now carry mandatory reporting implications under NIS2. If your government interfaces were built on trust (API keys, shared certificates, SAML federations with .gouv.fr domains), validate that trust now.</p>]]></content:encoded></item><item><title><![CDATA[Breaking: North Korean Zero-Day + VMware vCenter Under Active APT Exploitation — 17 August 2026]]></title><description><![CDATA[North Korean Lazarus Group Exploits Windows Zero-Day in Defense Sector Campaign]]></description><link>https://www.cisointelligence.co/p/breaking-north-korean-zero-day-vmware</link><guid isPermaLink="false">https://www.cisointelligence.co/p/breaking-north-korean-zero-day-vmware</guid><dc:creator><![CDATA[Jonathan Care]]></dc:creator><pubDate>Mon, 17 Aug 2026 12:02:10 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!dHG7!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe26b6c29-ab25-4075-b37d-d271750820af_368x368.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h2>North Korean Lazarus Group Exploits Windows Zero-Day in Defense Sector Campaign</h2><p>CISA has issued an Emergency Directive ordering federal agencies to patch CVE-2026-68820, a use-after-free vulnerability in the Windows Ancillary Function Driver for WinSock (afd.sys), within 14 days. The flaw, disclosed as part of Microsoft's August 2026 Patch Tuesday, carries a CVSS score of 7.0 but has been confirmed as actively exploited in the wild by North Korea's Lazarus Group as part of Operation Dream Job.</p><p>Operation Dream Job is a long-running social engineering campaign where Lazarus operatives impersonate recruiters from companies including Lockheed Martin and privacy-tech firm Enveil, contacting targets on LinkedIn before sending malicious PDF files. Once opened, the documents deploy a backdoor that gathers device information before exploiting CVE-2026-68820 to escalate privileges from limited access to SYSTEM-level control &#8212; the highest privilege level in Windows. The same afd.sys component was previously exploited by Lazarus in 2024.</p><p>Check Point, which disclosed the vulnerability to Microsoft, confirmed targets spanning defence sectors including surveillance sensors, drones, and robotics in France, Germany, Brazil, and India. The campaign's danger lies not just in the zero-day itself but in Lazarus' ability to weave legitimate infrastructure into every attack stage: real vendor branding, top-ranked search results, and compromised organisations providing apparent authenticity. The FBI is separately investigating an incident where a US federal agency inadvertently hired a North Korean IT worker as part of the same infiltration strategy.</p><p>There is no workaround. A device restart is required. The CISA deadline is August 25, 2026.</p><h2>VMware vCenter Under Active APT Exploitation Across 47 Countries</h2><p>A critical VMware vCenter directory-traversal vulnerability, CVE-2026-59310 (CVSS 9.8), is being actively exploited by a suspected APT actor just five days after Broadcom publicly disclosed it on July 29. German incident response firm QUIRSO discovered the campaign during an engagement, finding 361 compromised server IP addresses across 47 countries, with concentrations in Germany, the US, Turkey, Iran, and France.</p><p>The attack chain shows path traversal activity consistent with CVE-2026-59310, followed by deployment of a malicious cron job that installs reverse_ssh &#8212; an open-source tool establishing outbound SSH connections to attacker-controlled infrastructure. This persistence mechanism bypasses security controls designed to block suspicious inbound requests. Every unpatched internet-facing vCenter server appears reachable and vulnerable.</p><p>Separately, Defused Cyber reports a spike in scanning targeting CVE-2026-59309 (also CVSS 9.8), an authentication bypass in vmdir, suggesting exploitation of VMware vulnerabilities may be broadening. Chinese APT group UNC5174 has previously weaponised VMware flaws in espionage campaigns, and the reverse_ssh tool overlaps with tooling used by China-nexus cluster PurpleHaze. Attribution for the current campaign remains unconfirmed.</p><p>Patches for both CVE-2026-59309 and CVE-2026-59310 were released by Broadcom in late July. If you run vCenter and have not patched, treat this as an emergency: audit for reverse_ssh binaries and unexpected cron jobs immediately, then patch.</p><h2>So What / Action</h2><p>Two urgent patch-or-justify items this week. The Windows Winsock elevation-of-privilege flaw is the only confirmed-exploited CVE from August Patch Tuesday, and CISA's Emergency Directive makes the August 25 deadline mandatory for federal agencies and a de facto standard for everyone else. If your organisation has any exposure to defence or aerospace supply chains, the Dream Job campaign's European targeting makes this personal. Patch all Windows endpoints and verify detection coverage for kernel-driver race condition exploitation.</p><p>For VMware vCenter: if you have not patched VMSA-2026-0006 yet, stop reading this and patch now. The five-day gap between disclosure and active exploitation, with confirmed compromises in 47 countries, means any internet-facing unpatched vCenter should be assumed compromised. Hunt for reverse_ssh binaries, unexpected cron entries, and anomalous outbound SSH connections before patching &#8212; patching a compromised system without remediation just closes the door behind the attacker who is already inside.</p>]]></content:encoded></item><item><title><![CDATA[Breaking: Gunra Ransomware Targets Critical Infrastructure — Joint CISA/FBI/NSA Advisory]]></title><description><![CDATA[Gunra Ransomware Targets Critical Infrastructure Across Europe and Asia &#8212; Joint CISA/FBI/NSA Advisory]]></description><link>https://www.cisointelligence.co/p/breaking-gunra-ransomware-targets</link><guid isPermaLink="false">https://www.cisointelligence.co/p/breaking-gunra-ransomware-targets</guid><dc:creator><![CDATA[Jonathan Care]]></dc:creator><pubDate>Fri, 14 Aug 2026 17:02:08 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!dHG7!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe26b6c29-ab25-4075-b37d-d271750820af_368x368.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h2>Gunra Ransomware Targets Critical Infrastructure Across Europe and Asia &#8212; Joint CISA/FBI/NSA Advisory</h2><p>A six-agency joint advisory published August 10 warns that Gunra ransomware is actively targeting healthcare, financial services, government facilities, and professional services organisations worldwide. Advisory AA26-222A, authored by CISA, FBI, NSA, US Secret Service, DoD Cyber Crime Center, and South Korea's National Police Agency, provides full tactical details on a ransomware-as-a-service operation that has listed 51 victims since April 2025, with the majority in Australia, East Asia, and Europe.</p><p>Gunra gains initial access by exploiting Fortinet FortiOS and FortiProxy vulnerabilities CVE-2024-55591 and CVE-2025-24472 in internet-facing devices. The operation then runs a double-extortion model: exfiltrate data, encrypt systems, and threaten publication on a Tor-based leak site if the ransom is not paid within five to seven days. The Conti-derived ransomware uses ChaCha20 or Salsa20 stream ciphers for encryption and has been observed encrypting 9TB in a single operation. A formal RaaS affiliate programme was launched on dark web forums in January 2026, offering affiliates a management panel, configurable builder, and cross-platform locker payloads.</p><p>The tradecraft is unusually sophisticated for a ransomware operation. Gunra actors have been observed tampering with VDI authentication portals to bypass MFA, inserting a hardcoded one-time password that grants access regardless of the real credential. They manipulate SSL-VPN appliance traffic control to intercept credentials and session cookies, then hijack sessions to impersonate legitimate users. Lateral movement uses Impacket's psexec.py and smbclient.py via SMB, with secretsdump.py harvesting password hashes from domain controllers. Data exfiltration routes through Microsoft OneDrive and SharePoint via an executable called main.exe, with select victims seeing terabyte-scale archives uploaded to MEGA. The group deletes system and network access logs, clears command history, and operates primarily between 10pm and 6am local time.</p><p>The Lazarus connection elevates concern. South Korean security researchers at AhnLab found that some of the watering-hole infrastructure used by Gunra also deployed Struggle (SIGNBT 3.0) and Brandoor (COPPERHEDGE), both attributed to North Korea's Lazarus Group. While Gunra and Lazarus appear to be separate operations, the shared infrastructure suggests limited collaboration or at least tool exchange. Palo Alto Networks previously documented Andariel, a Lazarus sub-cluster, partnering with Play ransomware in October 2024. The pattern of nation-state actors renting initial access to ransomware crews is accelerating.</p><p>For European organisations, the targeting pattern is clear. Spain features prominently in Gunra's victim list, and the operation's Fortinet-focused initial access vector overlaps significantly with the FortiBleed credential crisis, which compromised validated login credentials for 86,644 Fortinet firewalls across 194 countries. Any organisation still running unpatched FortiOS or using credentials that have not been rotated since June remains at elevated risk.</p><h2>So What / Action</h2><p>Three immediate actions. First, if you run Fortinet FortiGate or FortiProxy appliances, verify that CVE-2024-55591 and CVE-2025-24472 are patched and that all administrator credentials have been rotated, with MFA enforced and legacy SHA-256 password hashes eliminated. Second, hunt for Gunra indicators: Impacket tool execution on domain controllers, unexpected outbound connections to MEGA, authentication anomalies on SSL-VPN appliances, and any VDI authentication portal modifications that introduce static OTP values. Third, review backup architecture: Gunra deliberately deletes primary and disaster-recovery backups before encryption. If your backups are not immutable and physically segmented, they are not backups.</p><p>The joint advisory with full IOCs and detection guidance is at CISA AA26-222A.</p>]]></content:encoded></item><item><title><![CDATA[Breaking: Metabase 10.0 Zero-Day, CISA Emergency Directive for Windows AFD, VMware vCenter Exploited Across 47 Countries — 14 Aug 2026]]></title><description><![CDATA[Metabase Zero-Day (CVSS 10.0) Actively Exploited &#8212; CISA KEV Deadline Today]]></description><link>https://www.cisointelligence.co/p/breaking-metabase-100-zero-day-cisa</link><guid isPermaLink="false">https://www.cisointelligence.co/p/breaking-metabase-100-zero-day-cisa</guid><dc:creator><![CDATA[Jonathan Care]]></dc:creator><pubDate>Fri, 14 Aug 2026 12:01:48 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!dHG7!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe26b6c29-ab25-4075-b37d-d271750820af_368x368.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h2>Metabase Zero-Day (CVSS 10.0) Actively Exploited &#8212; CISA KEV Deadline Today</h2><p>A maximum-severity SQL injection vulnerability in Metabase is being exploited in the wild as a zero-day. CVE-2026-72898 carries a CVSS score of 10.0 and allows unauthenticated remote attackers to inject arbitrary SQL via the password-reset endpoint, granting administrator access to the Metabase instance. From there, attackers can steal stored database credentials, read connected data, modify application configuration, and export information. CISA added the vulnerability to its Known Exploited Vulnerabilities catalog on August 11, with a federal remediation deadline of August 14 &#8212; today.</p><p>Metabase Cloud was directly attacked. Framework, the laptop maker, confirmed customer names, login IPs, addresses, phone numbers, and emails were accessed. Workflow automation platform n8n disclosed that 136 customer records were compromised, including bcrypt-hashed passwords for five n8n Cloud accounts and a historical bug that stored passwords in plaintext for 25 users. Kilo Code confirmed its Slackbot integration was compromised. Wiz estimates approximately 2,500 self-hosted Metabase instances are internet-accessible, with around 25% of cloud environments running Metabase exposed.</p><p>Affected versions span x.58.0 through x.63.3. Patches are available: x.58.24, x.59.21, x.60.17, x.61.11, x.62.9, and x.63.5. As a temporary workaround, block the `/api/session/reset_password` endpoint. After patching, revoke all active sessions, audit admin accounts and API keys, and rotate credentials for all connected databases. Look for the IoC pattern: a POST to `/api/session/reset_password` returning 400, followed by a GET to `/api/user/current` returning 200.</p><h2>CISA Emergency Directive: Windows AFD Zero-Day Exploited by North Korean APT</h2><p>CISA has issued an Emergency Directive requiring all federal civilian executive branch agencies to patch CVE-2026-68820 within 14 days. The vulnerability is a use-after-free race condition in the Windows Ancillary Function Driver for WinSock (afd.sys) that allows an attacker with a low-privileged foothold to escalate privileges to full SYSTEM control. Patched in Microsoft's August 2026 Patch Tuesday, the exploit requires a system reboot with no viable workaround.</p><p>The directive follows confirmed active exploitation by North Korean state-sponsored actors, attributed to ongoing Operation Dream Job campaigns. The attack chain uses social engineering lures on platforms like LinkedIn, targeting technical and engineering professionals in the defense, aerospace, drone, and robotics sectors across North America, Europe, and India. Victims are induced to download trojanized PDF viewers or malicious application archives via DLL sideloading, which then deploy persistent backdoors (ForestTiger, Troy) and trigger the AFD exploit for kernel-level privilege escalation.</p><h2>VMware vCenter Exploited Across 47 Countries</h2><p>A critical directory-traversal vulnerability in VMware vCenter is being actively exploited in the wild, with 361 unique victim IP addresses identified across 47 countries. CVE-2026-59310 (CVSS 9.8) resides in the vCenter Syslog server component, allowing unauthenticated remote code execution. Patches were released by Broadcom on July 29. QUIRSO, the German cybersecurity firm tracking the campaign, found that compromised systems began contacting attacker infrastructure on August 3, just five days after public disclosure.</p><p>The attack chain involves path traversal through the syslog service, followed by deployment of a malicious cron job to establish persistence using reverse_ssh, an open-source tool that creates outbound SSH tunnels to attacker-controlled infrastructure, bypassing inbound firewall rules. The activity strongly correlates with APT-level tradecraft, and Chinese threat actor UNC5174 has previously weaponised VMware vulnerabilities in espionage campaigns. Separately, Defused Cyber reports a spike in scanning targeting CVE-2026-59309 (CVSS 9.8), an authentication bypass in vmdir, suggesting broader exploitation efforts against VMware infrastructure are underway.</p><p>So what / Action: Three urgent items demand attention this week. Patch Metabase immediately if you run it, especially any internet-facing instances, and check for the reset_password IoC pattern. Deploy Microsoft's August Patch Tuesday updates across all Windows endpoints, prioritising systems used by staff in defence, aerospace, and high-tech sectors, and enforce reboots. If you operate VMware vCenter, apply Broadcom's VMSA-2026-0006 patches now, audit for reverse_ssh and unexpected cron jobs, and segment vCenter management interfaces from the internet. All three vulnerabilities share a common trait: the window between disclosure and exploitation has collapsed to days, not weeks.</p>]]></content:encoded></item><item><title><![CDATA[Breaking: Iran-Linked Cyberattacks Hit Water Utilities Across 12 US States — 14 August 2026]]></title><description><![CDATA[Iran-Linked Cyberattacks Hit Water Utilities Across 12 US States]]></description><link>https://www.cisointelligence.co/p/breaking-iran-linked-cyberattacks-cdc</link><guid isPermaLink="false">https://www.cisointelligence.co/p/breaking-iran-linked-cyberattacks-cdc</guid><dc:creator><![CDATA[Jonathan Care]]></dc:creator><pubDate>Fri, 14 Aug 2026 08:02:31 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!dHG7!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe26b6c29-ab25-4075-b37d-d271750820af_368x368.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h2>Iran-Linked Cyberattacks Hit Water Utilities Across 12 US States</h2><p>Water and wastewater systems across at least seven, and possibly as many as twelve, US states have been targeted by cyberattacks over the past two weeks, with multiple former US officials and current reporting pointing to Iran as the likely perpetrator. The FBI, EPA, and CISA have all issued advisories confirming the campaign, which targets programmable logic controllers (PLCs) manufactured by Rockwell Automation that manage water flow and chemical composition in treatment facilities.</p><p>In multiple incidents, attackers modified operator passwords to lock out legitimate staff and disconnected the PLCs from control systems. CISA confirmed that some attacks were severe enough to trigger boil-water notices to affected populations. While no major disruptions to water safety have been confirmed, operators were able to switch to manual operations in many cases. The gap between "no lasting damage" and "chemical composition tampering" is measured in monitoring capability, not attacker intent.</p><p>The targeting pattern follows previous Iranian operations against US water infrastructure. In 2023, the CyberAv3ngers group linked to Iran's IRGC infiltrated Israeli-made Unitronics controllers widely deployed in US water systems. The current campaign shares the same playbook: internet-facing PLCs with weak or default authentication, discovered through automated scanning, then exploited for operational disruption.</p><p>Former NSA director Paul Nakasone called water "probably the most brittle" of the 16 critical infrastructure sectors. Former FBI cyber deputy Cynthia Kaiser, now at Halcyon, stated she is "incredibly confident" the attacks are Iranian, citing geopolitical motivation, capability, and targeting history. Former NSA cybersecurity director Rob Joyce highlighted that the water sector's decentralisation, with over 52,000 local providers many serving only a few hundred people, creates an enormous attack surface defended by staff who often lack cybersecurity expertise.</p><p>The enforcement gap remains unresolved. The EPA's 2023 attempt to mandate cybersecurity evaluations for water systems was withdrawn after states sued over cost concerns. This week, Democratic Senators Adam Schiff and Amy Klobuchar introduced the Water Shield Cyber Act to give EPA explicit cybersecurity authority, while Republican Representative Rick Crawford's existing legislation proposing an independent cybersecurity standards body for the sector has gained the endorsement of the American Water Works Association, representing 4,300 utilities. New York State has announced over $9 million in cybersecurity grants to protect 153 water systems.</p><p>For CISOs: If your organisation operates or depends on water/wastewater infrastructure, audit all internet-facing PLCs immediately, enforce strong authentication on all operational technology, segment OT from IT networks, and ensure manual fallback procedures are tested and current. If you supply technology to this sector, assume your internet-facing management interfaces are being actively scanned and exploited. This campaign is ongoing.</p>]]></content:encoded></item></channel></rss>