
Hackers hiding in plain sight.
Medusa’s reach grows. Cl0p expands its victim list. The DOJ charges 17 alleged Iranian hackers. CISA sounds the alarm on four exploited vulnerabilities. TWINLOOT hides in plain sight inside Microsoft 365. Maria Varmazis shares the latest from the space-cyber realm as Ukraine strikes Russia’s satellite nerve center. The FDA considers guardrails for AI medical devices. Expired credit cards get an unexpected second life. A disgruntled contractor heads to prison. Dave Bittner sits down with Brian Vecci, Field CTO at Varonis, at Black Hat USA to discuss how AI is calling your security bluff. Highway hijinks meet high-tech hardware.
Today is Wednesday August 19th 2026. I’m Dave Bittner. And this is your CyberWire Intel Briefing.
Officials tally Medusa’s violations of U.S. critical infrastructure.
The Cybersecurity and Infrastructure Security Agency (CISA), alongside the FBI and the Department of Health and Human Services (HHS), has warned that the Medusa ransomware gang has compromised more than 500 U.S. critical infrastructure organizations since June 2021. The updated advisory marks a significant increase from the more than 300 victims reported in 2025 and highlights sectors including healthcare, defense, manufacturing, government, information technology, and financial services. Officials urge organizations to prioritize patching vulnerabilities, segment networks to limit lateral movement, and restrict remote access from untrusted sources. Active since 2021, Medusa evolved from a closed ransomware operation into a ransomware-as-a-service (RaaS) model that recruits affiliates through cybercriminal forums. CISA also notes that Medusa is often confused with other malware families, including MedusaLocker, despite being a separate ransomware operation.
The DOJ charges 17 Iranian nationals allegedly behind a long-running hacking campaign.
The U.S. Department of Justice has charged 17 Iranian nationals for their alleged roles in a long-running hacking campaign tied to the Islamic Revolutionary Guard Corps (IRGC). Prosecutors say the operation, conducted through the Mabna Institute, targeted U.S. government agencies, universities, companies, and United Nations organizations beginning around 2013. According to the indictment, the hackers compromised thousands of professor email accounts, stealing at least 31 terabytes of research, intellectual property, academic publications, and other sensitive data. The Justice Department says the stolen information was provided to the Iranian government and sold through online platforms in Iran. The State Department is offering up to $10 million for information on five alleged participants. Officials estimate U.S. universities spent roughly $20 million investigating and remediating the breaches, highlighting the campaign’s lasting financial and security impact.
Cl0p claims more than 40 victims.
The Cl0p ransomware group has claimed more than 40 victims in a campaign exploiting CVE-2026-12569, a critical remote code execution flaw in PTC’s Windchill and FlexPLM platforms. The vulnerability, first observed in active attacks earlier this year, enables unauthenticated attackers to execute arbitrary code. Security researchers say Cl0p affiliates deployed web shells and a custom implant capable of mapping sensitive data, decrypting credentials, and maintaining persistent access for large-scale data theft. The gang has published the names of alleged victims, including Shell, Philips, Fiserv, Zebra Technologies, Toast, and Ingersoll Rand, while listing the types and volumes of stolen data. None of the named companies has confirmed a significant breach, though several say they are investigating. The campaign mirrors Cl0p’s previous mass extortion operations targeting widely used enterprise software vulnerabilities.
CISA urges immediate patching of vulnerabilities affecting Microsoft, VMware, and Apple products.
CISA is urging organizations to immediately patch four actively exploited vulnerabilities affecting Microsoft, VMware, and Apple products. The flaws include critical remote code execution and authentication bypass issues in Windows Internet Key Exchange (IKE), Microsoft SharePoint, VMware vCenter, and macOS Screen Sharing. Researchers have linked the Microsoft and VMware vulnerabilities to real-world attacks, while the Apple flaw has been used to gain unauthorized access and deploy cryptocurrency mining malware. All four vulnerabilities have been added to CISA’s Known Exploited Vulnerabilities (KEV) catalog, with federal agencies directed to apply patches by August 21.
TWINLOOT malware conceals its C2 traffic within Microsoft 365 services.
Researchers at Ontinue have uncovered TWINLOOT, a Python-based malware implant that conceals its command-and-control traffic within legitimate Microsoft 365 services. First observed in July 2026, the malware uses SharePoint Online to exchange commands and stolen data, Microsoft Teams infrastructure for covert remote access, and the victim’s Edge browser to communicate with Microsoft Graph, making malicious activity appear legitimate. The campaign begins with a fake IT support call over Teams, convincing victims to run a malicious PowerShell command. TWINLOOT also displays a counterfeit Windows lock screen to harvest passwords and includes a persistence technique that requires no administrator privileges. Ontinue found no confirmed link to a known threat group but advises organizations to closely monitor unusual activity involving Microsoft Graph, SharePoint, Teams, browser automation, and OAuth applications.
Ukraine strikes Russia’s satellite nerve center.
Maria Varmazis is the host of the T-Minus space cyber podcast, and every Wednesday she joins us here with the latest news from the wild blue yonder. She files this report on a recent Ukrainian strike on a Russian satellite facility.
The FDA explores regulation of generative AI-enabled medical devices.
Thanks, Maria.
The U.S. Food and Drug Administration (FDA) is seeking public input on how to regulate generative AI-enabled medical devices, releasing a discussion paper that outlines potential clinical risks and regulatory considerations. The agency emphasizes it regulates medical devices, not generative AI software itself, and plans to apply a risk-based approach based on a device’s intended use and technical characteristics. The paper raises questions about higher-risk functions, such as AI systems that direct treatment decisions or emergency care, compared to those providing general information. Public comments are open through October 19 and will help shape future guidance. Industry experts note that generative AI introduces new challenges, including hallucinations, model drift, data poisoning, and expanded cybersecurity risks, requiring stronger lifecycle management and evaluation than traditional medical software.
Researchers exploit expired credit cards.
Researchers from the University of Massachusetts Amherst have demonstrated that some expired Visa contactless credit cards can still be used for payments by exploiting a weakness in the EMV contactless protocol. Presented at USENIX Security 2026, the research shows that attackers using NFC proxy devices can alter the expiration date seen by a point-of-sale terminal because Visa’s contactless implementation does not cryptographically bind that field. As a result, some payment terminals and issuing banks may authorize transactions from expired cards, depending on their validation processes. The researchers found that Mastercard, American Express, and Discover resisted the attack under their tested configurations. The team disclosed the issue to Visa in 2025, but says neither Visa nor affected banks have confirmed whether the vulnerability has been fully addressed.
Two years in prison for a contractor turned extortionist.
A former data analyst has been sentenced to two years in federal prison after attempting to extort his employer using stolen company data. Cameron Curry, a contractor at Brightly Software, abused his legitimate access after learning his contract would not be renewed. Prosecutors said he created the online persona “Loot” and sent more than 60 emails demanding a $2.5 million cryptocurrency payment, threatening to leak sensitive corporate records and employee personal information. Investigators traced the campaign through email metadata and cryptocurrency accounts linked to Curry’s family, leading to his arrest and conviction on six extortion-related charges. The case highlights the persistent risk posed by insider threats and underscores the importance of immediately revoking system access and closely monitoring privileged users during employee or contractor departures.
On our Industry Voices segment, we hear my conversation with Varonis' Field CTO Brian Vecci from Black Hat. Brian and I discussed how AI is calling your security bluff. Here’s our conversation
We’ll be right back.
Welcome back. That was my conversation with Brian Vecci, Field CTO at Varonis discussing how AI is calling your security bluff. If you enjoyed this conversation and want to learn more, check out the links in our show notes.
Highway hijinks meet high-tech hardware.
Our “legitimate businessman's desk” reports cargo thieves appear to have read the memo on AI’s booming value, and then skipped straight to the action scenes. According to a story in Wired, investigators say two recent shipments of expensive AI data center equipment vanished after escort vehicles were deliberately disabled, one by a rear-end collision and another by a PIT-style maneuver, leaving millions of dollars in hardware missing. While the incidents remain under investigation, security experts say they reflect a broader shift in cargo theft. Criminals increasingly combine cyber-enabled fraud, stolen trucking identities, and compromised motor carrier registrations with old-fashioned deception, and occasionally, a little automotive choreography. As AI infrastructure drives demand for high-value servers, chips, and cooling equipment, freight companies are responding with stronger identity checks, GPS tracking, and license plate monitoring. For the industry, moving AI hardware now requires more than logistics. It increasingly resembles protecting a rolling vault, complete with determined adversaries and ever more creative escape plans.
And that’s the CyberWire Daily, brought to you by N2K CyberWire.
For links to all of today’s stories, check out our Daily Briefing at the cyberwire dot com.
We’d love to know what you think of this podcast. Your feedback ensures we deliver the insights that keep you a step ahead in the rapidly changing world of cybersecurity. If you like the show, please share a rating and review in your podcast app. Please also fill out the survey in the show notes or send an email to cyberwire@n2k.com
We’re proud that N2K CyberWire is part of the daily routine of the most influential leaders and operators in the public and private sector, from the Fortune 500 to many of the world’s preeminent intelligence and law enforcement agencies.
N2K helps cybersecurity professionals and organizations grow, learn, and stay ahead. We’re the nexus for discovering the people, tech, and ideas shaping the industry. Learn how at n2k.com.
N2K’s lead producer is Liz Stokes. We’re mixed by Tré Hester, with original music by and sound design Elliott Peltzman. Our contributing host is Maria Varmazis. Our executive producer is Jennifer Eiben. Peter Kilpe is our publisher. And I’m Dave Bittner. Thanks for listening.

