This day 02:06 06:06 10:06 14:07 18:07 22:07
Info  2026-08-19 10:06Z · last 4h · 18 findings · glm-5.2:cloud

Threat Brief — 2026-08-19 — Extortion engines shift to PLM and macOS

Executive summary: Three distinct extortion/data-theft operations are escalating in parallel. CISA and FBI confirm Medusa ransomware has breached over 500 U.S. critical-infrastructure organizations since June 2021. Microsoft has mapped 30+ rotating domains behind MacSync, a macOS-focused infostealer, giving defenders actionable infrastructure to block. Separately, new technical detail on Clop's Windchill/FlexPLM JSP web shell reveals it actively decrypts stored credentials and exfiltrates engineering data—extending a campaign first observed last month. On the operational side, Windows 11 24H2 Home/Pro hits end of support in ~60 days.

Top items

Themes

Extortion diversification across platforms and verticals. Medusa (broad Windows ransomware, critical infra), Clop (targeted PLM data theft, enterprise engineering), and MacSync (macOS credential theft) demonstrate threat actors are simultaneously expanding platform coverage and deepening vertical-specific tooling. Defence teams can no longer assume ransomware groups will stay in their lane—macOS and OT-adjacent PLM systems are now squarely in scope.

Operational lifecycle pressure compounds. With both Windows Server 2022 (reported 2026-08-17) and now Windows 11 24H2 approaching EOL within 60 days, patch-and-upgrade velocity is becoming a security-critical bottleneck. An analysis piece from SecurityLab notes that AI-assisted vulnerability discovery is pushing patch volumes from ~60/month to hundreds per day, further straining admin capacity. (src: SecurityLab)

Public exploits · latest from the exploit feed

[remote] Ecava_ntegraXor IGX_16.0.701.10 - RCE 2026-10-01 15:15Z · RSS:exploit-db [webapps] Food-Ordering 1.0 - LFI 2026-10-01 15:15Z · RSS:exploit-db [webapps] WordPress 7.0.2 - Path Travesal 2026-10-01 15:15Z · RSS:exploit-db [webapps] TigerGraph_Community_Edition 4.2.4 - arbitrary file write 2026-10-01 15:15Z · RSS:exploit-db [remote] Teltonika_RutOS 00.07.06.21 - command injection 2026-10-01 15:15Z · RSS:exploit-db [webapps] POMS oretnom23v1.0 - SQLi vulnerabilities 2026-10-01 14:15Z · RSS:exploit-db [webapps] InvoicePlane 1.7.1 - RCE 2026-10-01 14:15Z · RSS:exploit-db [webapps] SuiteCRM 8.10.1 - Authenticated SSRF 2026-10-01 14:15Z · RSS:exploit-db [webapps] Krayin CRM 2.2.4 - IDOR 2026-10-01 14:15Z · RSS:exploit-db [remote] MikroTrick, 7.24, 7.24.2, 7.0.0, 7.23.4, 6.0.0, 6.49.21 - RCE 2026-09-30 15:11Z · RSS:exploit-db