Daily Security Intel

Archives
Log in
Subscribe
August 20, 2026

[SecurityIntel] 20 Aug | AI-Assisted Attacks Target Siemens Critical Infrastructure PLCs

SECURITYINTEL DAILY BRIEF

■ ThreatIntel Brief

Thursday, August 20, 2026

INTEL CONFIDENCE  100%

THREAT LEVEL

CRITICAL

THREAT OF THE DAY

AI-Assisted Attacks Target Siemens Critical Infrastructure PLCs

CRITICAL

5

C2 IPs

101

OTX IOCs

37

ARTICLES

■ ANALYST TLDR

Active exploitation of critical vulnerabilities in macOS, Microsoft SharePoint, VMware vCenter, and Microsoft IKE has prompted urgent warnings from CISA, while a massive password spraying surge and AI-assisted attacks on Siemens S7 PLCs threaten enterprise and critical infrastructure. Meanwhile, threat actors are leveraging novel campaigns such as "CameraSwarm" targeting Dahua IP cameras, and the "SilkParasite" espionage group is deploying multiple new RATs against Central Asian governments. Organizations must prioritize immediate patching of these edge-facing and operating system vulnerabilities to mitigate severe exposure.

■ CRITICAL STORIES

INFO#1

CISA Urges Immediate Patching of Exploited Microsoft, VMware, Apple Vulnerabilities

Threat actors are actively exploiting critical vulnerabilities in macOS, SharePoint, vCenter, and Microsoft IKE for remote code execution and authentication bypass, landing them on CISA's KEV catalog.

CRITICAL#2

US Warns of AI-Powered Attacks on Siemens PLCs in Critical Infrastructure

State-sponsored and cybercrime actors are leveraging AI-assisted development to generate scripts and exploit known vulnerabilities targeting Siemens S7 Series PLCs within critical infrastructure.

HIGH#3

Hackers Compromise 14,500+ Dahua Devices in CameraSwarm Campaign

Attackers successfully breached over 14,500 Dahua IP cameras in a massive 35-day campaign using credential attacks, peer-to-peer (P2P) networks, and two critical authentication bypass flaws.

HIGH#4

Cl0p Ransomware Group Names Over 40 Victims of PTC Windchill Campaign

The Cl0p cybercrime syndicate has claimed exploitation of PTC Windchill, naming major global corporations including Shell, Philips, and Fiserv as victims of their latest data theft campaign.

■ CVEs IDENTIFIED

[CVE-TBD-01]

Apple macOS — Privilege Escalation and Device Takeover

Critical

[CVE-TBD-02]

Microsoft SharePoint — Remote Code Execution

Critical

[CVE-TBD-03]

VMware vCenter — Authentication Bypass

Critical

[CVE-TBD-04]

Microsoft Windows IKE — Remote Code Execution

Critical

■ THREAT ACTORS

Mabna Institute

State-Sponsored (Iran)

Charged by US DOJ for a years-long hacking-for-hire campaign stealing $3.4B in IP from US universities and government agencies

Cl0p

Ransomware Group

Named over 40 corporate victims compromised via PTC Windchill exploitation

SilkParasite

Espionage Group

Targeted Central Asian governments using seven RAT families, including five newly documented RATs

■ ATT&CK TTPs

T1110.003
Password Spraying | Huntress observed a 155x surge in password spraying targeting legacy auth and MFA gaps
T1190
Exploit Public-Facing Application | Cl0p exploiting PTC Windchill; Dahua camera compromises; CISA KEV additions
T1212
Exploitation for Credential Access | Spectre attack against Cloudflare Workers to leak JWTs
T1584.004
Compromise Infrastructure: Server | StopAndProtect campaign abusing 2,000 hacked WordPress sites
T1588.007
Obtain Capabilities: Artificial Intelligence | Threat actors using AI-assisted scripts to target Siemens PLCs
T1219
Remote Access Software | SilkParasite group deploying five new RAT families against Central Asian governments

■ PATCH PRIORITY

[P1 PATCH NOW]≤24h

Apple macOS — Actively exploited vulnerability allowing device takeover — CISA KEV

[P1 PATCH NOW]≤24h

Microsoft SharePoint — Actively exploited RCE vulnerability — CISA KEV

[P1 PATCH NOW]≤24h

VMware vCenter — Actively exploited authentication bypass vulnerability — CISA KEV

[P1 PATCH NOW]≤24h

Microsoft Windows IKE — Actively exploited RCE vulnerability — CISA KEV

■ RECOMMENDED ACTIONS TODAY

1[P1] Immediately patch the actively exploited vulnerabilities in Apple macOS [CVE-TBD-01], Microsoft SharePoint [CVE-TBD-02], VMware vCenter [CVE-TBD-03], and Microsoft IKE [CVE-TBD-04] as mandated by CISA KEV updates.
2[P1] Apply Google Chrome desktop security updates immediately to address two critical buffer overflow vulnerabilities [CVE-TBD-05].
3[P1] Apply Oracle's August 2026 security updates to address over 460 remotely exploitable vulnerabilities across Oracle products.
4[P2] Audit and secure Siemens S7 Series PLCs [CVE-TBD-08] against AI-assisted exploitation by applying vendor-recommended patches and disabling unnecessary external access.
5[P2] Disable legacy authentication protocols and enforce Multi-Factor Authentication (MFA) across all enterprise portals to mitigate the 155x surge in password spraying.
LIVE IOC FEED

C2 IP BLOCKLIST  ·  AbuseCH Feodo  ·  Showing 5 of 5

IP ADDRESS

162.243.103.246

PORT

8080

STATUS

OFFLINE

MALWARE

Emotet

COUNTRY

US

IP ADDRESS

50.16.16.211

PORT

443

STATUS

ONLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

34.204.119.63

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

178.62.3.223

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

GB

IP ADDRESS

27.133.154.218

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

JP

FULL IOC EXPORT — GOOGLE SHEET

All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs
Updated daily · Export as CSV to import directly into your tools

■  Open Full IOC Sheet  →

IOC SOURCES: AbuseCH Feodo  ·  AlienVault OTX
NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB

Don't miss what's next. Subscribe to Daily Security Intel:
← Newer [SecurityIntel] 21 Aug | Active Exploitation of Zimbra CVE-2026-73570 RCE Vulnerability Older → [SecurityIntel] 19 Aug | Ransomware Gangs Actively Exploit Windows Task Host
Powered by Buttondown, the easiest way to start and grow your newsletter.