IT Security Newsletter

IT Security Newsletter - 8/20/2026

Written by Cadre | Thu, Aug 20, 2026

AI-fueled attacks pose 'active threat' to water, other sectors, U.S. agencies warn

Hackers are targeting water, food, energy, chemical, manufacturing and commercial facilities by taking aim at Siemens S7 Series programmable logic controllers (PLCs) and making use of artificial intelligence in the attacks, U.S. government agencies warned Wednesday. It's the latest government warning about attacks on critical infrastructure as the United States wages war against Iran, which the government blamed for a recent campaign against water and wastewater systems. READ MORE...

9 million images of people's faces exposed by reverse lookup service

Researcher Jeremiah Fowler found a cloud database containing more than 9 million image files accessible without authentication, WIRED reports. The leaky bucket, containing some 450 GB of images, was traced back to a US-registered company called ClarityCheck. In their own words, ClarityCheck says: "Use reverse image search to identify anyone in a photo. Find names, social profiles, and online presence in seconds." READ MORE...

SilkParasite Threatens Central Asian Orgs With Flurry of RATs

A China-nexus cyber-espionage operation is actively targeting government organizations across Central Asia with a collection of mostly previously unidentified remote access Trojans (RATs) from seven different malware families to establish and maintain long-term access to selected victims. Researchers from Bitdefender Labs began tracking the activity in late 2025 after they detected an infection at a Central Asian government body involved in economic decision-making. READ MORE...

Threat Actor Hacks 14,000 IP Cameras in Ukraine and Russia

A threat actor has conducted a mass-hacking campaign against Dahua IP cameras, compromising over 14,000 of them across Ukraine and Russia, Hunt.io reports. The activity, referred to as Operation CameraSwarm, occurred between June 17 and July 22. It initially involved global scanning across Russian, Mexican, and Vietnamese ISP ranges. Hunt.io says it gained access to the threat actor's servers, where it found 2,616 files across 234 subdirectories, left in an open HTTP directory. READ MORE...

8,539 reasons to rethink how vulnerabilities get patched

The window for responding to newly disclosed security flaws is getting shorter. Exploit code can appear quickly, exploitability can be tested soon after disclosure, and organizations have a growing number of weaknesses to sort through. Rapid7 counted 8,539 high- and critical-severity vulnerability disclosures, twice the number recorded a year earlier. The increase adds pressure to a patching process that requires teams to decide which problems deserve immediate attention. READ MORE...

AI is making fraud harder to spot and identity harder to prove

Online fraud has become a routine concern for consumers and businesses that rely on digital accounts, payments and customer service. Experian's 2026 U.S. Identity & Fraud Report describes a market where scams extend across messages, websites, documents, voices, images and account activity. Fraud used to be treated as an isolated event, such as a forged check, stolen credit card or false invoice. READ MORE...

Atlassian, Splunk Patch Dozens of Critical, High-Severity Vulnerabilities

Atlassian and Splunk this week announced patches for over 250 vulnerabilities across their products, including dozens of critical- and high-severity flaws. On Tuesday, Atlassian published a Security Bulletin detailing 10 critical- and 162 high-severity issues in third-party dependencies, patched with fresh security updates. Because the vulnerable libraries are used across multiple products, many of the patched security defects affect multiple products. READ MORE...

'Grandoreiro' Malware Resurfaces With Mexico Campaign

The Grandoreiro banking Trojan continues to pose a significant threat to banking customers, primarily in Latin America, more than two years after law enforcement disrupted its operations. The latest evidence is a new campaign using the 12-year-old payload that's targeting users in Mexico. The operators are using DLL sideloading and a legitimate file-management application to deliver the malware. Telemetry from the campaign showed a handful of victims in North America and Europe as well. READ MORE...

New Manic Android malware can exfiltrate data through nearby devices

A new Android malware named Manic targeting users in multiple European countries has a fallback mechanism for exfiltrating data through nearby infected devices. The malware has been active since at least February and combines spyware, banking fraud, and remote control capabilities. It targets at least 169 banking, government/eID, payment, crypto wallet, messaging, and authenticator/2FA apps, with users in Ukraine being the primary focus. READ MORE...

Critical Zimbra RCE flaw now actively exploited in attacks

CERT Polska, the Polish Computer Emergency Response Team (CERT), warned that attackers have begun exploiting a critical vulnerability in Zimbra Collaboration Suite (ZCS). ZCS is a popular email and collaboration software suite used by hundreds of millions of people and organizations worldwide. The Zimbra security team released version 10.1.20 on July 20 to patch the vulnerability, which allows unauthenticated attackers to gain remote code execution READ MORE...

  • ...in 1833, future President Benjamin Harrison is born in North Bend, OH.
  • ...in 1882, Tchaikovsky's "1812 Overture" is first performed in Moscow.
  • ...in 1911, a dispatcher in the New York Times office sends the first telegram around the world via a commercial service.
  • ...in 1975, Viking 1, the first spacecraft to land successfully on Mars, is launched.