This day 02:04 06:04 10:04 14:05 18:05 22:05
High  2026-08-18 18:05Z · last 4h · 20 findings · glm-5.2:cloud

Threat Brief — 2026-08-18 — Clop's Custom Shell, Mass Corp Leaks

Executive summary: Clop ransomware operators have deployed a purpose-built Java web shell targeting PTC Windchill and FlexPLM servers, marking a significant escalation in their data-theft campaign against manufacturing and retail tech stacks. Separately, internal directories from McDonald's, Vodafone, and seven other major corporations appeared on underground forums, and Iranian intelligence-operated "Handala" front was exposed as a state surveillance operation that fully compromised Israeli journalists' smartphones. On the infrastructure side, CISA published ICS advisories for Malcolm and Siemens Simcenter Nastran, both permitting remote code execution.

Top items

Themes

Targeted tooling meets mass opportunism: Clop's bespoke Windchill web shell and the Handala journalist-compromise operation both illustrate threat actors investing in highly tailored tooling for specific targets — while the McDonald's/Vodafone directory dump represents the opposite end: opportunistic mass data harvesting from whatever was accessible. Defenders should expect both vectors to persist simultaneously.

AI as both weapon and shield: The NSA's covert Mythos deployment, the "King Midas" agent-safety research, and Mandiant's agentic code-review framework all point to AI becoming an operational layer in offense, defense, and governance — with alignment risks that are not yet solved.

Public exploits · latest from the exploit feed

[remote] Ecava_ntegraXor IGX_16.0.701.10 - RCE 2026-10-01 15:15Z · RSS:exploit-db [webapps] Food-Ordering 1.0 - LFI 2026-10-01 15:15Z · RSS:exploit-db [webapps] WordPress 7.0.2 - Path Travesal 2026-10-01 15:15Z · RSS:exploit-db [webapps] TigerGraph_Community_Edition 4.2.4 - arbitrary file write 2026-10-01 15:15Z · RSS:exploit-db [remote] Teltonika_RutOS 00.07.06.21 - command injection 2026-10-01 15:15Z · RSS:exploit-db [webapps] POMS oretnom23v1.0 - SQLi vulnerabilities 2026-10-01 14:15Z · RSS:exploit-db [webapps] InvoicePlane 1.7.1 - RCE 2026-10-01 14:15Z · RSS:exploit-db [webapps] SuiteCRM 8.10.1 - Authenticated SSRF 2026-10-01 14:15Z · RSS:exploit-db [webapps] Krayin CRM 2.2.4 - IDOR 2026-10-01 14:15Z · RSS:exploit-db [remote] MikroTrick, 7.24, 7.24.2, 7.0.0, 7.23.4, 6.0.0, 6.49.21 - RCE 2026-09-30 15:11Z · RSS:exploit-db