Cleartext – August 20, 2026
Thursday, August 20, 2026·10:26
Enjoy the show? Subscribe to never miss an episode.
show notes
Cleartext – August 20, 2026
Daily cybersecurity briefing for CISOs and security leaders.
Episode Summary
Today's episode covers 9 stories across 4 topic areas, including: US agencies warn of AI-powered attacks on Siemens industrial controllers; US charges Iranian hackers over $3.4 billion intellectual property theft; Latvian officials resign after cyberattack exposes data on 1.2 million people.
Stories Covered
🌍 Geopolitical
US agencies warn of AI-powered attacks on Siemens industrial controllers
Help Net Security · Aug 20 · Relevance: █████████░ 9/10
Why it matters to CISOs: A joint NSA/CISA/FBI/DOE/EPA advisory on AI-assisted exploitation of Siemens S7 PLCs across water, energy, and manufacturing sectors represents an urgent operational threat for any organization with OT/ICS infrastructure. CISOs with critical infrastructure exposure need to immediately assess internet-exposed PLC inventories and review segmentation controls.
- NSA, CISA, FBI, DOE, and EPA issued a joint advisory warning of AI-generated exploit scripts targeting Siemens S7 Series PLCs
- Targeted sectors include water, energy, and manufacturing — core critical infrastructure verticals
- This marks a potentially first-of-its-kind documented use of AI-assisted development in active ICS exploitation campaigns
US charges Iranian hackers over $3.4 billion intellectual property theft
BleepingComputer · Aug 19 · Relevance: ████████░░ 8/10
Why it matters to CISOs: The DOJ indictment of 17 members of Iran's Mabna Institute for stealing 31 terabytes of data from U.S. universities, companies, and government agencies highlights the persistent state-sponsored threat to research-intensive enterprises and defense contractors. CISOs should use this as a trigger to review exposure of academic partnerships and IP repositories.
- 17 alleged Iranian hackers charged for operating Mabna Institute, a government-linked hacking-for-hire group
- Campaign stole 31 terabytes of data valued at $3.4 billion from U.S. universities, companies, and federal agencies
- Targets included email accounts at government agencies and intellectual property from dozens of academic institutions
Latvian officials resign after cyberattack exposes data on 1.2 million people
The Record (Recorded Future) · Aug 19 · Relevance: ███████░░░ 7/10
Why it matters to CISOs: Latvia's road traffic agency breach — exposing data on roughly two-thirds of the national population and triggering senior official resignations — is a stark reminder for CISOs of the board-level and political accountability that follows large-scale government-adjacent data exposures, with implications for public-sector supply chain partners.
- Latvia's road traffic agency suffered a breach exposing data connected to approximately 1.2 million individuals, roughly two-thirds of the country's population
- The incident prompted calls for senior officials to resign, with confirmed departures reported
- Attack underscores persistent targeting of European government infrastructure and the political accountability consequences of significant data breaches
T-Mobile ‘chopped a cable’ to expel Chinese hackers from its network
TechCrunch Security · Aug 19 · Relevance: ███████░░░ 7/10
Why it matters to CISOs: T-Mobile's decision to physically sever network infrastructure to eject Chinese-backed threat actors illustrates the extreme measures telecom operators must consider when dealing with state-sponsored persistence — a playbook decision point relevant to CISOs building incident response runbooks for nation-state intrusions.
- T-Mobile identified Chinese state-sponsored hackers early enough in an intrusion to prevent a large-scale breach
- The company physically cut a cable as a containment measure to expel the threat actors from its network
- The incident is part of the broader Salt Typhoon / Chinese telecom espionage campaign targeting U.S. carriers
📡 Macro Trends
Password spraying attacks surge 155x as hackers exploit MFA gaps
BleepingComputer · Aug 19 · Relevance: ███████░░░ 7/10
Why it matters to CISOs: A 155x surge in password spraying attacks in H1 2026 — with one campaign generating 81 million login attempts in two weeks by exploiting legacy authentication and MFA policy gaps — provides CISOs with concrete data to drive board conversations on authentication hygiene and accelerate legacy protocol deprecation.
- Huntress observed a 155x increase in password spraying attacks in H1 2026 compared to prior period
- A single campaign generated over 81 million login attempts in two weeks
- Attackers specifically exploited legacy authentication protocols and gaps in MFA policy coverage leaving some login flows unprotected
🔓 Data Breach
The long tail of Clop’s PTC hack is just beginning to emerge
CyberScoop · Aug 19 · Relevance: ████████░░ 8/10
Why it matters to CISOs: Clop's exploitation of a zero-day in PTC's Windchill and FlexPLM product lifecycle management software — affecting manufacturers and defense-adjacent firms — follows its MOVEit and GoAnywhere playbook and signals another long-tail mass-exploitation event that supply chain and third-party risk programs must now account for.
- Clop exploited a critical zero-day vulnerability in PTC's Windchill and FlexPLM PLM software, likely compromising victims in June before sending extortion emails in July
- PTC software is widely used in manufacturing, defense, and engineering supply chains
- The pattern mirrors Clop's prior mass-exploitation campaigns (MOVEit, GoAnywhere), suggesting a broad and growing victim list
Over 500 Critical Infrastructure Organizations Hit by Medusa Ransomware
Infosecurity Magazine · Aug 19 · Relevance: ████████░░ 8/10
Why it matters to CISOs: An FBI warning that Medusa ransomware has hit over 500 critical infrastructure organizations with enhanced TTPs raises the operational risk bar for CISOs in regulated and infrastructure-adjacent sectors who must reassess ransomware resilience, detection coverage, and incident response readiness.
- FBI warned that Medusa ransomware-as-a-service has struck over 500 critical infrastructure organizations
- The RaaS operation has significantly enhanced its tactics, techniques, and procedures, making defensive countermeasures harder
- Critical infrastructure sectors are primary targets, elevating regulatory and operational risk exposure
Electronic health record company CareCloud says 3.7 million people affected by breach
The Record (Recorded Future) · Aug 19 · Relevance: ███████░░░ 7/10
Why it matters to CISOs: CareCloud's breach of 3.7 million patient records — with an attacker dwelling in the EHR environment for eight hours — is one of the largest U.S. healthcare breaches of the year and carries significant HIPAA notification, HHS reporting, and litigation exposure for healthcare sector CISOs and their third-party risk programs.
- Healthtech firm CareCloud confirmed 3,756,469 individuals had medical records stolen, filed with HHS
- The attacker accessed CareCloud's electronic health record environment for approximately eight hours
- Breach ranks among the largest U.S. healthcare data incidents of 2026, triggering HIPAA obligations and potential regulatory scrutiny
🚨 Critical Vulnerability
Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active Exploitation
The Hacker News · Aug 19 · Relevance: █████████░ 9/10
Why it matters to CISOs: CISA's addition of four critical CVEs — including flaws in SharePoint, vCenter, and macOS — to the KEV catalog signals active in-the-wild exploitation of enterprise staples; CISOs must treat these as emergency patch priorities with immediate asset exposure checks across hybrid environments.
- CISA added four critical vulnerabilities to its KEV catalog, confirming active exploitation in the wild
- Affected platforms include Apple macOS, Microsoft SharePoint, VMware vCenter, and Microsoft IKE — all widely deployed enterprise infrastructure
- CVE-2026-65400 in macOS carries a CVSS score of 9.8 and involves an improper authentication flaw
Further Reading
- 🌍 US agencies warn of AI-powered attacks on Siemens industrial controllers — Help Net Security
- 🌍 US charges Iranian hackers over $3.4 billion intellectual property theft — BleepingComputer
- 🌍 Latvian officials resign after cyberattack exposes data on 1.2 million people — The Record (Recorded Future)
- 🌍 T-Mobile ‘chopped a cable’ to expel Chinese hackers from its network — TechCrunch Security
- 📡 Password spraying attacks surge 155x as hackers exploit MFA gaps — BleepingComputer
- 🔓 The long tail of Clop’s PTC hack is just beginning to emerge — CyberScoop
- 🔓 Over 500 Critical Infrastructure Organizations Hit by Medusa Ransomware — Infosecurity Magazine
- 🔓 Electronic health record company CareCloud says 3.7 million people affected by breach — The Record (Recorded Future)
- 🚨 Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active Exploitation — The Hacker News
Full Transcript
Click to expand full episode transcript
Alex: Welcome to Cleartext. It's Thursday, August 20th, 2026. I'm Alex Chen.
Jordan: And I'm Jordan Reeves. Let's get into it.
Alex: So Jordan, you've been staring at the AI-ICS advisory all morning. Set the table for us.
Jordan: Five agencies. NSA, CISA, FBI, DOE, EPA. A joint advisory warning that threat actors are using AI to generate exploit scripts targeting Siemens S7 PLCs. Water systems, energy infrastructure, manufacturing. This is the thing we've been warning about in theory, and now five federal agencies are saying it's happening in practice. This may be the first documented case of AI-assisted exploit development being used in active ICS campaigns.
Alex: And for our audience, let's be precise about what this means operationally. PLCs are the small industrial computers that open valves, run pumps, control machinery. They are the physics layer. If you compromise a PLC, you're not stealing data, you're potentially breaking things in the physical world. The Siemens S7 series is ubiquitous. It's the backbone of industrial automation in dozens of countries.
Jordan: What makes this qualitatively different is the AI piece. Writing ICS exploits historically required deep domain expertise. You needed to understand proprietary protocols, ladder logic, the specific firmware versions. That was a natural barrier to entry. AI lowers that barrier dramatically. You don't need a team of ICS specialists anymore. You need a capable LLM and a target list of internet-exposed PLCs, which, by the way, are trivially discoverable through Shodan and similar tools.
Alex: So the action items here are clear and urgent. If you have OT or ICS infrastructure, today is the day you audit your internet-exposed PLC inventory. Not next quarter. Today. Review your segmentation controls between IT and OT networks. And if you're running Siemens S7 series controllers, make sure you're consuming the vendor's hardening guidance and the specific IOCs in this advisory.
Jordan: I'd add one more thing. This should change how you model threat actors in your OT risk assessments. The assumption that ICS exploitation requires nation-state resources is no longer safe. AI has democratized that capability. Your threat model needs to account for mid-tier actors with AI tooling now, not just the top five APTs.
Alex: Perfectly said. Let's stay on the geopolitical thread because we have a cluster of nation-state stories today. The DOJ unsealed charges against seventeen members of Iran's Mabna Institute.
Jordan: Seventeen defendants. Thirty-one terabytes of stolen data. Three point four billion dollars in estimated value. This is a hacking-for-hire operation linked to the Iranian government that systematically pillaged U.S. universities, private companies, and federal agencies over multiple years. The primary target was intellectual property and research data.
Alex: For CISOs at research-intensive organizations, defense contractors, or anyone with significant academic partnerships, this is a direct threat profile. Thirty-one terabytes is an enormous exfiltration volume. That doesn't happen without dwell time and access to bulk data repositories. The question every CISO in these sectors should be asking is, do we have adequate monitoring on our research data stores? Can we detect bulk exfiltration from our IP repositories?
Jordan: And the university angle matters because universities are often the softest point in the supply chain. They collaborate with defense contractors, pharmaceutical companies, tech firms. They hold pre-publication research, grant proposals, proprietary datasets. And their security posture is, charitably, uneven. If you have partnerships with academic institutions that involve sensitive IP, your third-party risk program needs to account for that exposure explicitly.
Alex: Moving to the T-Mobile story, which is a fascinating case study in incident response decision-making. T-Mobile identified Chinese state-sponsored hackers, part of the Salt Typhoon campaign targeting U.S. carriers, and physically severed a cable to contain the intrusion.
Jordan: I love this story because it cuts through all the incident response theory and gets to the fundamental question. When you're facing a nation-state actor with demonstrated persistence capabilities, what are you actually willing to do? T-Mobile chopped a cable. They caused an operational disruption to themselves to ensure containment. That's a decision that requires pre-authorization, board-level understanding, and frankly, organizational courage.
Alex: This is a playbook conversation for every CISO. Do you have pre-approved authorities to take extreme containment actions? Have you wargamed scenarios where the right answer is self-imposed downtime? If the answer is no, you're going to waste critical hours during a real incident seeking authorization while a nation-state actor maintains access.
Jordan: And credit to T-Mobile for catching it early enough. Early detection is what made physical containment viable rather than catastrophic. If they'd found this six months later, cutting a cable wouldn't have mattered.
Alex: Let's shift to Clop, because they're back with another mass-exploitation campaign, and the pattern is now unmistakable.
Jordan: Clop exploited a zero-day in PTC's Windchill and FlexPLM software. Product lifecycle management tools used heavily in manufacturing, defense, and engineering supply chains. They likely compromised victims in June, sat on the access, and started sending extortion emails in July. This is the MOVEit playbook. It's the GoAnywhere playbook. Clop finds a zero-day in enterprise file transfer or supply chain software, exploits it at scale, exfiltrates data, and then methodically extorts hundreds of victims.
Alex: For CISOs, the question is no longer whether Clop will do this again, it's which software is next. If your organization uses PTC products, you need to assume compromise and investigate. Check the IOCs, review your logs from June forward, and engage your IR team. But more broadly, this reinforces the need for robust third-party software inventories. You cannot defend against supply chain exploitation if you don't know what's in your environment.
Jordan: The long tail is the key phrase. CyberScoop's reporting suggests the victim list is still growing. We're going to be hearing about PTC-related breaches for months.
Alex: The FBI is also warning about Medusa ransomware, which has now hit over five hundred critical infrastructure organizations. Jordan, what's notable here beyond the volume?
Jordan: The evolution of their TTPs. Medusa operates as ransomware-as-a-service, and the FBI is specifically calling out that they've significantly enhanced their techniques. This isn't the same Medusa from eighteen months ago. They're harder to detect, harder to contain, and they're deliberately targeting critical infrastructure, which means regulatory consequences compound the operational impact.
Alex: If you're in a regulated sector and you haven't pressure-tested your ransomware resilience recently, this is your signal. Recovery time objectives, backup integrity, detection coverage against the specific Medusa TTPs in the FBI's advisory. All of it needs to be validated, not assumed.
Jordan: And let's not forget CareCloud. Three point seven million patient records stolen after an attacker spent eight hours in their EHR environment.
Alex: Eight hours. That's a relatively short dwell time, which means either they were highly efficient or they had pre-positioned access. Either way, nearly four million records makes this one of the largest healthcare breaches of the year. HIPAA notification obligations, HHS reporting, and the litigation exposure is going to be enormous. For any CISO relying on third-party EHR platforms, this is a reminder that your compliance obligations don't transfer with your data processing agreements. You own the risk to your patients.
Jordan: Let's hit the vulnerability story quickly because it's actionable. CISA added four critical CVEs to the Known Exploited Vulnerabilities catalog. Apple macOS, Microsoft SharePoint, VMware vCenter, and Microsoft IKE. All confirmed actively exploited in the wild.
Alex: The macOS flaw, CVE-2026-65400, carries a CVSS of nine point eight. Improper authentication. These are enterprise infrastructure staples. SharePoint, vCenter, macOS. They're in virtually every hybrid environment. Treat these as emergency patch priorities. Run asset exposure checks today across your estate and confirm your vulnerability management team is tracking KEV additions in near real-time.
Jordan: And briefly on the Latvia story. Their road traffic agency was breached, exposing data on one point two million people, roughly two-thirds of the national population. Senior officials have resigned.
Alex: The accountability angle is what matters here. This is a government agency breach that triggered political consequences. Officials lost their jobs. For CISOs, this is the trajectory of breach accountability globally. It's moving beyond regulatory fines into personal and organizational consequences. If you're in public sector or government-adjacent work, the political dimension of a breach is now a first-order risk.
Jordan: And the password spraying story rounds out the picture. Huntress observed a hundred and fifty-five times increase in password spraying attacks in the first half of 2026. One campaign generated eighty-one million login attempts in two weeks by targeting legacy authentication protocols and gaps in MFA coverage.
Alex: This is the authentication hygiene story that never dies. Legacy protocols that bypass MFA. Service accounts without conditional access policies. Federated login flows where MFA isn't enforced consistently. If you haven't completed your legacy authentication deprecation, this data gives you the ammunition for that board conversation. Eighty-one million attempts in two weeks is a number that gets attention.
Jordan: So Alex, stepping back and looking at everything today, what's the theme?
Alex: The theme is that the cost of legacy assumptions is accelerating. The assumption that ICS exploitation requires nation-state resources. The assumption that your PLM software vendor isn't a Clop target. The assumption that MFA covers all your login flows. Every one of these stories is about a gap between what organizations believe about their security posture and what's actually true. And adversaries, whether they're AI-augmented, state-sponsored, or ransomware operators, are finding those gaps faster than defenders are closing them.
Jordan: I'd frame it as convergence. AI is converging with ICS threats. Nation-state TTPs are converging with criminal ransomware operations. Physical and digital containment are converging in incident response. The silos that security programs were built around don't reflect how attacks actually work anymore. CISOs who are still organizing their teams and budgets around those silos are going to keep getting surprised.
Alex: Well said. What to watch next week, I'd say the PTC victim disclosures from the Clop campaign. That list is going to grow, and if you're in manufacturing or defense supply chains, you want to get ahead of it.
Jordan: And I'd watch for follow-on reporting from the AI-ICS advisory. If federal agencies are publishing jointly, they have intelligence they're not sharing publicly yet. There's more to this story.
Alex: That's our show for Thursday, August 20th. Show notes and links to every story we covered are at cleartext.fm. I'm Alex Chen.
Jordan: I'm Jordan Reeves. Stay sharp out there.
Cleartext is an automated daily podcast for CISOs and security leaders. Generated 2026-08-20.
Sources are pulled from: CyberScoop, The Record, SecurityWeek, Krebs on Security, Dark Reading, Cybersecurity Dive, BleepingComputer, Wired, Ars Technica, TechCrunch, Help Net Security, VentureBeat, Risky Business News, The Hacker News, CISA, and BankInfoSecurity.