
Daily Cybersecurity News – August 20, 2026
CISA Adds 4 Critical Flaws to KEV for Active Exploitation
CriticalThe four KEV additions
- CVE-2026-65400 (9.8) – macOS Screen Sharing improper authentication
- CVE-2026-55040 (9.1) – SharePoint weak authentication bypass
- CVE-2026-59310 (9.8) – vCenter path traversal to RCE
- CVE-2026-33824 (9.8) – Windows IKE double free RCE
What happened
CISA added four critical vulnerabilities to its Known Exploited Vulnerabilities catalog, confirming they are under active exploitation in the wild.
The flaws are CVE-2026-65400 (CVSS 9.8), an improper authentication issue in Apple macOS Screen Sharing that lets a network attacker authenticate without credentials; CVE-2026-55040 (CVSS 9.1), weak authentication in Microsoft SharePoint allowing unauthorized bypass of a security feature over the network; CVE-2026-59310 (CVSS 9.8), a path traversal in Broadcom VMware vCenter Syslog server enabling arbitrary code execution with network access; and CVE-2026-33824 (CVSS 9.8), a double free in Microsoft Windows IKE Extension allowing unauthenticated remote code execution.
Vendors have issued patches. The macOS issue has been abused to deliver Monero miners. SharePoint saw exploitation after PoC release. vCenter was used by a suspected China-nexus APT to deploy backdoors, reverse_ssh, and in at least one case Babuk-derived ransomware, hitting 361 IPs across 47 countries. The IKE flaw was leveraged by a Chinese-speaking actor alongside AI-assisted operations.
Who is affected
Apple macOS systems running unpatched versions prior to Sequoia 15.7.9, Sonoma 14.8.9, and Tahoe 26.6.1, especially those with Screen Sharing exposed.
Microsoft SharePoint deployments, Broadcom VMware vCenter instances reachable over the network, and all supported Windows 10, Windows 11, and Windows Server releases with IKE version 2 enabled (UDP 500/4500).
Federal Civilian Executive Branch agencies face a short compliance window; enterprises and any internet-facing or poorly segmented instances of these products are also exposed.
Why it matters
All four carry critical scores and confirmed in-the-wild use, turning routine enterprise services into entry points for miners, ransomware, backdoors, and nation-state persistence.
vCenter and Windows IKE compromises enable deep infrastructure control and lateral movement. Broad geographic impact and mixed criminal/APT use raise the odds of rapid opportunistic scanning against unpatched fleets.
How it could have been prevented
Apply the vendor patches for all four CVEs immediately. FCEB agencies must complete remediation by August 21, 2026 per BOD 26-04.
For Windows IKE, if patching is delayed, block inbound UDP 500 and 4500 on systems that do not require IKE, or restrict to known peer addresses. Inventory and isolate internet-facing SharePoint, vCenter, and macOS Screen Sharing services. Monitor for anomalous authentication, Syslog activity, and unexpected miner or reverse-shell processes.
Relevant professional terms
- KEV catalog
- CISA's public list of vulnerabilities confirmed to be actively exploited in the real world, used to force prioritized patching.
- Double free
- A memory-corruption bug where the same memory block is freed twice, often enabling an attacker to hijack program control flow for remote code execution.
Critical Windows IKE RCE Under Active Exploitation
CriticalWhat happened
CISA added CVE-2026-33824 to its KEV catalog after confirming active exploitation of a critical remote code execution flaw in the Windows Internet Key Exchange (IKE) Service Extensions (also called MS-IKEE).
The vulnerability is a double free that lets an unauthenticated attacker send specially crafted packets to UDP ports 500 or 4500 on systems with IKEv2 enabled and achieve code execution. Microsoft patched it in the April 2026 Patch Tuesday release. CISA ordered FCEB agencies to remediate within three days under BOD 26-04 and urged all defenders to prioritize the fix. Reporting links exploitation to a Chinese-speaking threat actor also running AI-assisted campaigns.
Who is affected
All supported Windows 10, Windows 11, and Windows Server releases that have IKE version 2 enabled and accept inbound traffic on UDP 500 or 4500.
Any internet-facing or poorly firewalled Windows hosts using IPsec/IKE are at highest risk; systems that do not use IKE can still be exposed if the service is listening.
Why it matters
Unauthenticated network RCE with a 9.8 CVSS score and high EPSS makes this an ideal wormable or mass-scanning target. Successful exploitation yields immediate code execution for ransomware, backdoors, or lateral movement inside enterprise and government networks.
CISA's rapid KEV addition and short federal deadline underscore the operational urgency.
How it could have been prevented
Install the Microsoft security update for CVE-2026-33824 on all affected Windows systems without delay.
If immediate patching is impossible, block inbound UDP 500 and 4500 on hosts that do not require IKE, or configure firewall rules to accept traffic only from known peer addresses. Confirm IKE is disabled where unused and monitor for anomalous packet traffic to those ports.
Relevant professional terms
- Remote code execution (RCE)
- A flaw that lets an attacker run their own code on a target system from across the network, usually without prior access.
- IKE Extension (MS-IKEE)
- Microsoft's set of additional capabilities for the Internet Key Exchange protocol that support authentication, DoS protection, and interoperability with IPsec peers.
BTR Reforged Turns Defender Driver into Kernel Primitive
HighHow it works
Researchers mapped BTR.sys encrypted configuration, integrity checks, and execution pipeline. Valid transactions delivered via alternate data stream trigger arbitrary kernel file and registry ops. BTR_CLI constructs these transactions to demonstrate EDR/AV disarmament under a trusted Microsoft signature, avoiding classic exploit or BYOVD patterns.
What happened
Check Point Research fully reverse-engineered the Windows Defender Boot-Time Removal driver (BTR.sys) and its proprietary encrypted transaction format, then showed how the legitimate, Microsoft-signed remediation component can be turned into an attacker-controlled kernel operation engine.
The driver can be instructed to perform arbitrary file and registry operations from Ring 0 without classic exploits, memory corruption, or traditional BYOVD. Researchers released BTR_CLI, a tool that builds valid encrypted transactions to safely demonstrate the capability, including use as an EDR/AV bypass that disarms security products while still running under a trusted signed driver.
Who is affected
Windows systems that load or can be made to load the Defender BTR remediation driver (commonly appearing under randomized names in System32\drivers with matching service entries).
Organizations relying on Microsoft Defender and endpoint security stacks that trust signed Microsoft drivers are in scope for abuse of this primitive.
Why it matters
A built-in, signed Defender component becomes a stealthy kernel primitive for file/registry manipulation and security-product disablement. Attackers gain powerful Ring-0 capabilities without needing vulnerable third-party drivers, complicating detection and raising the bar for defenders who whitelist Microsoft-signed code.
The research highlights how remediation infrastructure itself can become an offensive asset.
Relevant professional terms
- BYOVD
- Bring Your Own Vulnerable Driver - a technique where attackers load a legitimate but flawed signed driver to gain kernel privileges.
- Ring 0
- The highest privilege level in the CPU protection rings, where the kernel and drivers run with full hardware and memory access.
AI Aids Hackers Targeting US Water Siemens Controllers
HighWhat happened
CISA, FBI, NSA and partners warned that hackers are actively targeting Siemens S7 programmable logic controllers used in U.S. water and wastewater systems, energy, manufacturing, and agriculture.
Attackers are using AI to generate exploit scripts from public information against internet-connected or poorly secured S7 devices running outdated software. The activity forms part of broader campaigns against water infrastructure; disruption could cause downtime, safety incidents, or equipment damage. Prior incidents linked to suspected Iranian actors have hit facilities in multiple states.
Who is affected
Operators of Siemens S7 PLCs in water supply, wastewater, and other critical infrastructure sectors across the United States, especially internet-exposed or unpatched units.
Rural utilities and smaller facilities with limited security resources face elevated risk because the devices often serve large geographic areas and remain online for remote management.
Why it matters
Compromise of PLCs can directly affect physical processes that deliver safe drinking water or treat wastewater, creating public-safety and environmental consequences beyond typical IT breaches.
AI lowers the skill barrier for crafting exploits against already fragile OT devices, accelerating opportunistic attacks on critical infrastructure that CISA has long urged to keep offline.
How it could have been prevented
Disconnect Siemens S7 and similar PLCs from the public internet wherever possible. Apply available firmware and software updates promptly and enforce strong authentication and network segmentation.
Restrict remote access to known management stations via VPN or jump hosts, monitor for anomalous PLC traffic, and follow CISA guidance for water-sector cyber hygiene and incident reporting.
Relevant professional terms
- PLC
- Programmable Logic Controller - an industrial computer that automates physical processes such as pumps, valves, and treatment systems.
- OT (Operational Technology)
- Hardware and software that monitors and controls physical equipment and processes, as opposed to traditional IT systems that handle data.
Manic Android Malware Exfils via Nearby Infected Devices
HighWhat happened
ThreatFabric identified a new Android malware family called Manic that blends banking-trojan and spyware capabilities. It targets Ukrainian banks, government and identity apps, messaging services, plus Russian, European, and global fintech, crypto, and military-focused communications.
Distributed through phishing sites and dropper apps posing as utilities, Manic abuses accessibility services and notification access for overlays, lock-screen credential theft, device control, location tracking, and file collection. Its novel feature is a Wi-Fi mesh relay that lets offline infected phones exfiltrate data via nearby compromised devices that have internet access. Activity traces to February 2026 with ongoing development of stronger anti-analysis and phishing features.
Who is affected
Android users, particularly those in Ukraine and secondary targets in Russia, Central/Western Europe, and the UK who install apps from untrusted sources or fall for phishing lures.
The malware monitors 169 package IDs spanning banks, P2P/BNPL, crypto wallets/exchanges, messaging, government eID, browsers, authenticators, and email clients.
Why it matters
Financial fraud plus full-device surveillance in one package, combined with the ability to exfiltrate from offline phones through a peer mesh, expands the attack surface beyond single-device connectivity.
Broad targeting of both civilian financial apps and military messaging raises espionage and hybrid-threat concerns alongside classic banking malware impact.
How it could have been prevented
Install apps only from official stores, avoid sideloading, and scrutinize accessibility-service and notification-permission requests. Keep Android updated and use reputable mobile security tools that detect overlay and accessibility abuse.
Enterprises and high-risk users should enforce MDM policies that block unknown sources, monitor for suspicious device-admin or accessibility grants, and educate on phishing droppers impersonating utilities.
Relevant professional terms
- Accessibility services abuse
- Malware misuses Android's built-in accessibility features (meant for users with disabilities) to read screens, capture input, and control the device.
- Wi-Fi mesh exfiltration
- A technique where infected devices form an ad-hoc wireless network so offline victims can relay stolen data through nearby online compromised peers.
T-Mobile Cuts Cable to Evict Chinese Hackers
HighWhat happened
Bloomberg reporting detailed how T-Mobile cybersecurity staff identified and expelled Chinese state-backed hackers (Salt Typhoon) from its network in 2024 during a broad campaign against telecoms.
After months of hunting, the team traced unusual behavior on one system to a router belonging to another telecom. T-Mobile's cyber chief and three colleagues drove to a nearby data center, located the compromised box, and physically snipped the cable connecting it to the outside world. The larger Salt Typhoon campaign hit AT&T, Verizon, Viasat, Charter, Windstream and others to steal phone records and data on senior U.S. officials.
Who is affected
T-Mobile successfully contained the intrusion early and avoided a large-scale customer-data breach. Other major U.S. telecom, satellite, and network providers were compromised in the same campaign.
Customers and government officials whose call records or metadata were targeted by Salt Typhoon across the affected carriers.
Why it matters
Physical cable-cutting as a last-resort containment measure underscores both the depth of access the actors achieved and the limits of purely logical isolation when trusted interconnects are abused.
Salt Typhoon's focus on telecom metadata of political figures highlights strategic intelligence collection against critical communications infrastructure.
How it could have been prevented
Maintain rigorous network segmentation, continuous monitoring of interconnects and unusual east-west traffic, and rapid incident-response playbooks that include physical isolation options for compromised hardware.
Telecom operators should inventory and tightly control third-party router links, apply least-privilege access, and share indicators of Salt Typhoon-style activity with peers and government partners.
Relevant professional terms
- Salt Typhoon
- A Chinese government-linked hacking group known for long-term intrusions into telecommunications providers to harvest call records and metadata.
- Network interconnect
- A physical or logical link between two carriers' networks that can become an entry point if one side is compromised.
US Charges 17 Iranians in Government University Hacks
MediumWhat it means
Expect continued U.S. pursuit of Iranian cyber actors via indictments, sanctions, and rewards even for older campaigns. Universities and research orgs should treat credential-stuffing and spear-phishing against faculty as persistent state-level threats, enforce MFA everywhere, monitor for anomalous library and email access, and prepare for long-tail remediation costs. Private-sector partners of academia face secondary exposure through shared credentials or stolen IP.
What happened
The U.S. Justice Department unsealed a 14-count superseding indictment charging 17 individuals tied to Iran's Mabna Institute with a multi-year hacking campaign conducted on behalf of the Islamic Revolutionary Guard Corps.
Prosecutors allege the group breached email accounts at the Department of Labor, Federal Energy Regulatory Commission, multiple U.N. organizations, and state agencies in Hawaii and Indiana, plus 144 U.S. universities, 42 U.S. companies, 178 foreign universities, and at least 11 foreign companies. They stole roughly 31 terabytes of academic data, intellectual property, theses, and journals (about 8,000 professor accounts) that were supplied to the Iranian government and sold via Iranian websites. Eight defendants had been charged in a 2018 case; the State Department offered a $10 million reward for information on five named individuals.
Who is affected
U.S. and foreign universities, research institutions, government agencies (federal, state, and U.N.-affiliated), and private companies whose email and library systems were compromised between roughly 2013 and later years.
Professors and researchers whose credentials and scholarly work were stolen; universities that collectively spent about $20 million on investigation and remediation.
Why it matters
The campaign shows sustained, industrial-scale intellectual-property theft for state benefit, converting academic access into both intelligence and a commercial product sold inside Iran.
Superseding charges and large rewards signal continued U.S. focus on holding IRGC-linked cyber actors accountable even years after the intrusions.
Relevant professional terms
- Indictment
- A formal criminal accusation issued by a grand jury that allows prosecutors to bring defendants to trial.
- IRGC
- Islamic Revolutionary Guard Corps - the Iranian military organization alleged to have directed the Mabna Institute's hacking-for-hire operations.