Threat Brief — 2026-08-19 — IKE Exploitation, SilkParasite APT, Dahua Mass Hack
CISA added four critical CVEs to its Known Exploited Vulnerabilities catalog today, including a Windows IKE Extension RCE now under active attack. A previously unreported espionage operation dubbed SilkParasite is targeting Central Asian governments with five novel RAT families. Separately, a single actor compromised more than 14,500 Dahua cameras across Ukraine and Russia, and a cyberattack on Berlin's city network cut 50,000 families off from benefits.
Top Items
- Windows IKE Extension RCE actively exploited (CISA KEV). CISA added a critical-severity remote code execution flaw in the Windows Internet Key Exchange (IKE) Service Extensions to its KEV catalog, confirming in-the-wild exploitation. Three other critical CVEs (macOS, SharePoint, vCenter) were added in the same batch. All four require immediate patching. (src: BleepingComputer), (src: The Hacker News)
- SilkParasite espionage campaign targets Central Asian governments. A previously unreported APT operation dubbed SilkParasite deploys seven RAT families—five of them never before seen—against government bodies in Central Asia. The scale and novelty of the toolset suggest a well-resourced state-aligned actor. (src: The Hacker News)
- 14,500+ Dahua cameras mass-hacked across Ukraine and Russia. A single actor used credential attacks, two authentication-bypass flaws, and peer-to-peer functionality to compromise over 14,530 Dahua devices between June and July 2026. The attacker's surveillance-log server was left publicly accessible. (src: SecurityLab), (src: The Hacker News)
- Berlin cyberattack cuts 50,000 families off benefits. A single hacker attack forced two government departments to disconnect from Berlin's city network, disrupting benefits for 50,000 families. The incident highlights the cascading impact of municipal network compromises. (src: SecurityLab)
- StopAndProtect operation weaponizes ~2,000 hacked WordPress sites. A global cybercrime campaign abuses thousands of compromised WordPress installations as malware distribution, C2, and data-staging infrastructure—storing stolen documents, screenshots, and activity logs on the hijacked sites. (src: The Hacker News)
- Ransomware paralyzes Canadian hospital engineering systems. An attack on Canada's Health Sciences Centre forced manual ventilation and froze access systems. Patient treatment was reportedly unchanged, but the incident demonstrates ransomware's ability to cripple building-management and clinical-support infrastructure without directly touching patient records. (src: SecurityLab)
- Sorry ransomware spreads across China targeting SMEs. A ransomware variant dubbed "Sorry" is locking servers without warning across China, with small and medium enterprises as the primary victims. (src: Anquanke)
- Phishing 3.0: the fight moves to agent-versus-agent. A new analysis argues that as AI-powered email agents increasingly act on behalf of users, traditional payload-scanning defenses are insufficient—the threat model shifts to adversarial AI agents interacting with defensive AI agents. (src: The Hacker News)
- Microsoft delays critical mail-server patch after AI finds too many vulnerabilities. AI-assisted code review uncovered so many issues in a Microsoft mail-server patch that the release was cancelled outright. This illustrates both the power and the operational friction of AI-driven vulnerability discovery at scale. (src: SecurityLab)
- Windows Defender crash bug fixed. Microsoft resolved a known issue causing Windows Defender to crash with 0xc0000005 access-violation errors after a recent security update. (src: BleepingComputer)
- Fresh-cookie prices for 2FA bypass rise 13%. Stolen session cookies that bypass two-factor authentication now average $10–15 per log, with streaming-data subscriptions up to $300/month—signalling sustained demand and the diminishing value of passwords alone. (src: SecurityLab)
- AI agents breaking production security via prompt injection and MCP. Researchers from Yandex and Sber will dissect how text from pull requests becomes executable commands in agentic AI systems, highlighting new risks from prompt injection and Model Context Protocol. (src: SecurityLab)
Themes
AI as both shield and sword. Multiple today's items highlight the dual-edged nature of AI in security: Microsoft's AI-driven vuln discovery overloaded its patch pipeline, researchers warn of prompt-injection attacks on production AI agents, and Phishing 3.0 reframes the threat landscape as agent-versus-agent. Defensive and offensive AI capabilities are escalating in parallel, and operational processes haven't caught up.
IoT and edge-device mass compromise remains trivially achievable. The Dahua camera hack (14,500+ devices via credential attacks and auth bypasses) reinforces that unpatched edge devices are low-hanging fruit for both espionage and botnet recruitment. CISA's simultaneous KEV additions for macOS, SharePoint, vCenter, and IKE underscore that the attack surface spans consumer IoT to enterprise infrastructure.
===
THREAT-TOPICS===
[{"slug":"windows-ike-extension-rce-actively-exploited","headline":"Critical Windows IKE Extension RCE actively exploited, added to CISA KEV","findingIds":[8905,8915],"status":"new"},
{"slug":"silkparasite-espionage-central-asia","headline":"SilkParasite APT targets Central Asian governments with five novel RATs","findingIds":[8921],"status":"new"},
{"slug":"dahua-cameras-mass-hacked-ukraine-russia","headline":"14,500+ Dahua cameras mass-hacked across Ukraine and Russia","findingIds":[8912,8922],"status":"new"},
{"slug":"berlin-government-cyberattack-50000-families-benefits-disrupted","headline":"Berlin cyberattack cuts 50,000 families off benefits","findingIds":[8907],"status":"new"},
{"slug":"stopandprotect-wordpress-malware-campaign","headline":"StopAndProtect abuses 2,000 hacked WordPress sites for malware and data theft","findingIds":[8914],"status":"new"},
{"slug":"canada-health-sciences-centre-ransomware","headline":"Ransomware paralyzes Canadian hospital engineering systems","findingIds":[8911],"status":"new"},
{"slug":"sorry-ransomware-campaign-china-smes","headline":"Sorry ransomware locks servers across China targeting SMEs","findingIds":[8909],"status":"new"},
{"slug":"phishing-3-agent-versus-agent","headline":"Phishing 3.0 reframes defense as agent-versus-agent","findingIds":[8923],"status":"new"},
{"slug":"microsoft-delays-mail-server-patch-ai-vuln-overload","headline":"Microsoft cancels mail-server patch after AI finds too many vulnerabilities","findingIds":[8918],"status":"new"},
{"slug":"windows-defender-crash-fix","headline":"Microsoft fixes Windows Defender 0xc0000005 crash bug","findingIds":[8913],"status":"new"},
{"slug":"fresh-cookies-2fa-bypass-price-rise","headline":"Stolen 2FA-bypass cookie prices rise 13%","findingIds":[8908],"status":"new"},
{"slug":"ai-agents-prompt-injection-production-security","headline":"Researchers to dissect prompt injection and MCP risks in production AI agents","findingIds":[8917],"status":"new"}]
