IT News Roundup: CISA KEV Exploits, AI Attacks on Industrial PLCs, Cloudflare Spectre Leak - August 20, 2026
CISA flags four actively exploited flaws in macOS, SharePoint, vCenter and Windows IKE; US agencies warn of AI-generated attacks on Siemens PLCs; Sakura Internet and CareCloud breaches hit millions.
The past 24 hours brought a heavy dose of active exploitation and AI-driven threat activity. CISA confirmed four patched flaws - spanning macOS, SharePoint, VMware vCenter and Windows IKE - are under real-world attack, while five U.S. agencies issued a joint warning that attackers are using AI-generated scripts against Siemens PLCs in critical infrastructure. On the breach front, Japanese cloud provider Sakura Internet reported exposure of up to 1.36 million accounts and healthcare IT firm CareCloud confirmed its incident hit more than 3.7 million patients. In cloud security, researchers demonstrated a remote Spectre attack leaking tokens from co-located Cloudflare Workers, OpenAI paused frontier RL training while it tightened internal defenses, and Microsoft moved to end license-included Azure VMware hosting as Broadcom pushes its VCF bundles.
CISA Adds Four Actively Exploited Flaws to KEV Catalog
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added four critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, confirming they are being exploited in the wild. The set includes CVE-2026-65400 (CVSS 9.8), an improper authentication flaw in Apple macOS that has been abused to deliver a Monero cryptocurrency miner, plus vulnerabilities affecting Microsoft SharePoint and VMware vCenter.
The vCenter weakness is assessed as having been exploited by a suspected China-nexus APT actor deploying backdoors and reverse_ssh binaries for persistent access; in at least one case the campaign led to Babuk-derived ransomware. The activity has compromised 361 unique victim IP addresses across 47 countries, with the heaviest concentrations in Germany (55), the U.S. (41), Turkey (38), Iran (26) and France (25). Palo Alto Networks Unit 42 separately observed a Chinese-speaking threat actor exploiting the Microsoft Internet Key Exchange flaw while running an AI-enabled autonomous hacking campaign using DeepSeek.
All four flaws have since been patched by their vendors. Federal Civilian Executive Branch agencies were given until August 21, 2026 to update affected systems under BOD 26-04 patching guidelines.
Source: The Hacker News
US Agencies Warn of AI-Generated Attacks on Siemens PLCs in Critical Infrastructure
The NSA, CISA, FBI, Department of Energy and Environmental Protection Agency issued a joint advisory warning that threat actors are using AI-generated scripts to exploit Siemens S7 Series programmable logic controllers (PLCs) in U.S. critical infrastructure. The agencies describe the activity as an ongoing, active threat rather than a theoretical risk.
Attackers have been using internet scanning services such as Censys and ZoomEye to locate exposed PLCs, then exploiting critical and high-severity vulnerabilities, outdated software and weak authentication. The custom tools are AI-written Python scripts built on the snap7.dll and python-snap7 libraries, disguised as legitimate OT monitoring software; they can provide read and write access to PLC memory, configuration data and ladder logic programs over the S7comm protocol.
The sectors most targeted include Critical Manufacturing, Energy, Water and Wastewater Systems, Chemical, Food and Agriculture and Commercial Facilities. The advisory notes that Siemens S7 PLCs are also used in the Defense Industrial Base and urges all PLC owners and operators to apply relevant mitigations, since ongoing targeting activity is broader than Siemens devices.
Source: BleepingComputer
Sakura Internet Hack Exposes Data of Up to 1.36 Million Accounts
Japanese cloud and data center provider Sakura Internet disclosed that hackers accessed its sales management system, where customer contract and membership information is stored. In an update to its initial notification from Monday, the company said the incident may have impacted up to 1,360,563 member accounts, though the exact number remains under investigation.
Hackers gained access to the IT system on August 9; the intrusion was discovered during the investigation of a separate, less severe breach at the Sakura Rental Server service that involved unauthorized logins to 583 accounts and malware installed on Sakura's systems.
The incident carries extra weight because Sakura Internet is a major provider of web hosting, VPS, public cloud, data center and GPU computing services in Japan, and has been selected as a domestic provider for the country's Government Cloud program aimed at reducing dependence on foreign hyperscalers.
Source: BleepingComputer
CareCloud Data Breach Confirmed to Impact 3.7 Million Patients
U.S. healthcare IT company CareCloud disclosed that the breach it suffered earlier this year has impacted more than 3.7 million individuals. The publicly traded firm provides electronic health records, medical billing, practice management and revenue-cycle services.
The incident was originally disclosed in March via a filing with the U.S. Securities and Exchange Commission, which noted an eight-hour network disruption on its platform and loss of access to one database containing patient data. In a report to the U.S. Department of Health and Human Services, CareCloud put the number of affected individuals at 3,756,469.
The company began distributing breach notifications on July 25 with further details from its investigation.
Source: BleepingComputer
Remote Spectre Attack Leaks JWT From Co-Located Cloudflare Worker
Security researchers disclosed a remote Spectre attack against Cloudflare Workers that leaked a JSON Web Token (JWT) from a co-located worker in the production environment at up to 12 bits per second - roughly 360 times faster than an earlier attack demonstrated in 2021. The end-to-end experiment used attacker and victim workers controlled by the researchers, with no customer data accessed.
Cloudflare Workers runs code from multiple tenants in separate V8 isolates within the same operating-system process, relying on language-level isolation rather than strict process boundaries to keep startup latency low. The team found that Cloudflare's Dynamic Process Isolation (DyPrIs) was insufficient: WebSocket communications provided a remote timing source, long-lived Durable Object invocations could run for five to more than 20 hours before isolation kicked in, and I/O-heavy activity suppressed the branch-misprediction signal DyPrIs uses for detection.
Cloudflare said the attack has been mitigated in production through improved DyPrIs, integration of the V8 Sandbox and Memory Protection Keys (MPK)-based in-process isolation, and that it found no indicators of active exploitation over the past three years. The researchers argue robust detection should occur during execution using a signal that cannot be suppressed by I/O activity.
Source: The Hacker News
OpenAI Pauses Frontier RL Training to Tighten Defenses Against Unsafe AI Behavior
OpenAI revealed that it paused reinforcement learning (RL) training for its latest models for two weeks while it shored up additional defenses and expanded the scope of its monitoring, in an effort to avert another Hugging Face-like incident.
"As models become more capable, the risks associated with developing and testing them internally also grow," the company said. The pause comes as frontier labs face increasing scrutiny over how they contain misaligned or unsafe behavior during training runs, and follows OpenAI's recent push for new customer privacy protections aimed at matching rivals on enterprise trust.
Source: The Hacker News
Microsoft Ends License-Included Azure VMware Solution as Broadcom Pushes VCF Bundles
Microsoft has signalled it will retire the license-included version of its Azure VMware Solution (AVS), ending one of the last remaining ways to run VMware products outside a big bundle. AVS currently includes vCenter, vSAN, vSphere and NSX along with licenses for all of them - but not the Software-Defined Datacenter Manager tool Broadcom uses to package its flagship Cloud Foundation (VCF) suite.
Since acquiring VMware, Broadcom has gone all-in on VCF and no longer sells a standalone low-end server virtualization product; its licensing changes also bar hyperscale partners from selling VMware licenses outright. Customers who rely on AVS will need to acquire their own VCF license and move to a different Azure arrangement by August 30, 2027.
The change is significant for organizations - including homelab-adjacent edge and branch deployments - that have used AVS as an alternative to committing to the full VCF bundle.
Source: The Register
← Back to Blog