SECURITYINTEL DAILY BRIEF ■ Threat Intel Brief Thursday, August 20, 2026 INTEL CONFIDENCE 100% THREAT LEVEL CRITICAL THREAT OF THE DAY AI-Assisted Attacks Target Siemens Critical Infrastructure PLCs CRITICAL 5 C2 IPs 101 OTX IOCs 37 ARTICLES ■ ANALYST TLDR Active exploitation of critical vulnerabilities in macOS, Microsoft SharePoint, VMware vCenter, and Microsoft IKE has prompted urgent warnings from CISA, while a massive password spraying surge and AI-assisted attacks on Siemens S7 PLCs threaten enterprise and critical infrastructure. Meanwhile, threat actors are leveraging novel campaigns such as "CameraSwarm" targeting Dahua IP cameras, and the "SilkParasite" espionage group is deploying multiple new RATs against Central Asian governments. Organizations must prioritize immediate patching of these edge-facing and operating system vulnerabilities to mitigate severe exposure. ■ CRITICAL STORIES INFO #1 CISA Urges Immediate Patching of Exploited Microsoft, VMware, Apple Vulnerabilities Threat actors are actively exploiting critical vulnerabilities in macOS, SharePoint, vCenter, and Microsoft IKE for remote code execution and authentication bypass, landing them on CISA's KEV catalog. CRITICAL #2 US Warns of AI-Powered Attacks on Siemens PLCs in Critical Infrastructure State- and cybercrime actors are leveraging AI-assisted development to generate scripts and exploit known vulnerabilities targeting Siemens S7 Series PLCs within critical infrastructure. HIGH #3 Hackers Compromise 14,500+ Dahua Devices in CameraSwarm Campaign Attackers successfully breached over 14,500 Dahua IP cameras in a massive 35-day campaign using credential attacks, peer-to-peer (P2P) networks, and two critical authentication bypass flaws. HIGH #4 Cl0p Ransomware Group Names Over 40 Victims of PTC Windchill Campaign The Cl0p cybercrime syndicate has claimed exploitation of PTC Windchill, naming major global corporations including Shell, Philips, and Fiserv as victims of their latest data theft campaign. ■ CVEs IDENTIFIED [CVE-TBD-01] Apple macOS — Privilege Escalation and Device Takeover Critical [CVE-TBD-02] Microsoft SharePoint — Remote Code Execution Critical [CVE-TBD-03] VMware vCenter — Authentication Bypass Critical [CVE-TBD-04] Microsoft Windows IKE — Remote Code Execution Critical ■ THREAT ACTORS Mabna Institute State- (Iran) Charged by US DOJ for a years-long hacking-for-hire campaign stealing $3.4B in IP from US universities and government agencies Cl0p Ransomware Group Named over 40 corporate victims compromised via PTC Windchill exploitation SilkParasite Espionage Group Targeted Central Asian governments using seven RAT families, including five newly documented RATs ■ ATT&CK TTPs T1110.003 Password Spraying | Huntress observed a 155x surge in password spraying targeting legacy auth and MFA gaps T1190 Exploit Public-Facing Application | Cl0p exploiting PTC Windchill; Dahua camera compromises; CISA KEV additions T1212 Exploitation for Credential Access | Spectre attack against Cloudflare Workers to leak JWTs T1584.004 Compromise Infrastructure: Server | StopAndProtect campaign abusing 2,000 hacked WordPress sites T1588.007 Obtain Capabilities: Artificial Intelligence | Threat actors using AI-assisted scripts to target Siemens PLCs T1219 Remote Access Software | SilkParasite group deploying five new RAT families against Central Asian governments ■ PATCH PRIORITY [P1 PATCH NOW] ≤24h Apple macOS — Actively exploited vulnerability allowing device takeover — CISA KEV [P1 PATCH NOW] ≤24h Microsoft SharePoint — Actively exploited RCE vulnerability — CISA KEV [P1 PATCH NOW] ≤24h VMware vCenter — Actively exploited authentication bypass vulnerability — CISA KEV [P1 PATCH NOW] ≤24h Microsoft Windows IKE — Actively exploited RCE vulnerability — CISA KEV ■ RECOMMENDED ACTIONS TODAY 1 [P1] Immediately patch the actively exploited vulnerabilities in Apple macOS [ CVE-TBD -01], Microsoft SharePoint [ CVE-TBD -02], VMware vCenter [ CVE-TBD -03], and Microsoft IKE [ CVE-TBD -04] as mandated by CISA KEV updates. 2 [P1] Apply Google Chrome desktop security updates immediately to address two critical buffer overflow vulnerabilities [ CVE-TBD -05]. 3 [P1] Apply Oracle's August 2026 security updates to address over 460 remotely exploitable vulnerabilities across Oracle products. 4 [P2] Audit and secure Siemens S7 Series PLCs [ CVE-TBD -08] against AI-assisted exploitation by applying vendor-recommended patches and disabling unnecessary external access. 5 [P2] Disable legacy authentication protocols and enforce Multi-Factor Authentication (MFA) across all enterprise portals to mitigate the 155x surge in password spraying. LIVE IOC FEED C2 IP BLOCKLIST · AbuseCH Feodo · Showing 5 of 5 IP ADDRESS 162.243.103.246 PORT 8080 STATUS OFFLINE MALWARE Emotet COUNTRY US IP ADDRESS 50.16.16.211 PORT 443 STATUS ONLINE MALWARE QakBot COUNTRY US IP ADDRESS 34.204.119.63 PORT 443 STATUS OFFLINE MALWARE QakBot COUNTRY US IP ADDRESS 178.62.3.223 PORT 443 STATUS OFFLINE MALWARE QakBot COUNTRY GB IP ADDRESS 27.133.154.218 PORT 443 STATUS OFFLINE MALWARE QakBot COUNTRY JP FULL IOC EXPORT — GOOGLE SHEET All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs Updated daily · Export as CSV to import directly into your tools ■ Open Full IOC Sheet → IOC SOURCES: AbuseCH Feodo · AlienVault OTX NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB
SECURITYINTEL DAILY BRIEF
Thursday, August 20, 2026
INTEL CONFIDENCE 100%
AI-Assisted Attacks Target Siemens Critical Infrastructure PLCs
Active exploitation of critical vulnerabilities in macOS, Microsoft SharePoint, VMware vCenter, and Microsoft IKE has prompted urgent warnings from CISA, while a massive password spraying surge and AI-assisted attacks on Siemens S7 PLCs threaten enterprise and critical infrastructure. Meanwhile, threat actors are leveraging novel campaigns such as "CameraSwarm" targeting Dahua IP cameras, and the "SilkParasite" espionage group is deploying multiple new RATs against Central Asian governments. Organizations must prioritize immediate patching of these edge-facing and operating system vulnerabilities to mitigate severe exposure.
CISA Urges Immediate Patching of Exploited Microsoft, VMware, Apple Vulnerabilities
Threat actors are actively exploiting critical vulnerabilities in macOS, SharePoint, vCenter, and Microsoft IKE for remote code execution and authentication bypass, landing them on CISA's KEV catalog.
US Warns of AI-Powered Attacks on Siemens PLCs in Critical Infrastructure
State- and cybercrime actors are leveraging AI-assisted development to generate scripts and exploit known vulnerabilities targeting Siemens S7 Series PLCs within critical infrastructure.
Hackers Compromise 14,500+ Dahua Devices in CameraSwarm Campaign
Attackers successfully breached over 14,500 Dahua IP cameras in a massive 35-day campaign using credential attacks, peer-to-peer (P2P) networks, and two critical authentication bypass flaws.
Cl0p Ransomware Group Names Over 40 Victims of PTC Windchill Campaign
The Cl0p cybercrime syndicate has claimed exploitation of PTC Windchill, naming major global corporations including Shell, Philips, and Fiserv as victims of their latest data theft campaign.
Apple macOS — Privilege Escalation and Device Takeover
Microsoft SharePoint — Remote Code Execution
VMware vCenter — Authentication Bypass
Microsoft Windows IKE — Remote Code Execution
Charged by US DOJ for a years-long hacking-for-hire campaign stealing $3.4B in IP from US universities and government agencies
Named over 40 corporate victims compromised via PTC Windchill exploitation
Targeted Central Asian governments using seven RAT families, including five newly documented RATs
Apple macOS — Actively exploited vulnerability allowing device takeover — CISA KEV
Microsoft SharePoint — Actively exploited RCE vulnerability — CISA KEV
VMware vCenter — Actively exploited authentication bypass vulnerability — CISA KEV
Microsoft Windows IKE — Actively exploited RCE vulnerability — CISA KEV
■ RECOMMENDED ACTIONS TODAY
C2 IP BLOCKLIST · AbuseCH Feodo · Showing 5 of 5
FULL IOC EXPORT — GOOGLE SHEET
All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs Updated daily · Export as CSV to import directly into your tools
IOC SOURCES: AbuseCH Feodo · AlienVault OTX NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
