🛡️ Cyber Pulse Weekly | 17–23 August 2026 — Threats, CVEs, Attacks & AI Innovations

đź“° Cyber Pulse: Top 10 Cybersecurity Stories This Week

  1. Clop expands PTC Windchill and FlexPLM data-theft campaign

    GE and Philips investigated Clop claims, while Philips confirmed it contained an attempted compromise of a specific internal enterprise server without customer-environment impact. The campaign is linked to active exploitation of CVE-2026-12569 and JSP web shells targeting internet-facing PTC platforms.

    Source: BleepingComputer — https://www.bleepingcomputer.com/news/security/philips-and-ge-investigating-clop-ransomware-data-theft-claims/

  2. Poland investigates MyDr healthcare breach affecting nearly 19 million people

    Authorities investigated unauthorized access to historical MyDr data that may affect nearly 19 million people and more than 12,000 medical facilities. Poland said the national P1 e-health platform remained secure while connected-system certificates were replaced as a precaution.

    Source: Recorded Future News — https://therecord.media/poland-probes-mydr-healthcare-software-breach

  3. CISA confirms active exploitation of critical Windows IKE flaw

    CISA added CVE-2026-33824 to its exploited-vulnerability catalog after confirming attacks against Windows IKE Extension. Microsoft patched the unauthenticated network RCE in April and advised updating or restricting UDP 500 and 4500.

    Source: BleepingComputer — https://www.bleepingcomputer.com/news/security/cisa-critical-windows-ike-extension-flaw-now-exploited-in-attacks/

  4. Medusa tally exceeds 500 U.S. critical-infrastructure victims

    A joint CISA, FBI and HHS advisory said Medusa had impacted more than 500 U.S. critical-infrastructure organizations as of April 2026. The agencies emphasized vulnerability remediation, network segmentation and restrictions on remote services.

    Source: BleepingComputer — https://www.bleepingcomputer.com/news/security/cisa-medusa-ransomware-hit-over-500-critical-infrastructure-orgs/

  5. Critical MLflow SSRF is exploited to target cloud credentials

    CISA confirmed exploitation of CVE-2026-64849, an unauthenticated SSRF bypass that can expose internal services and cloud metadata. MLflow 3.15.0 contains the fix, and potentially exposed credentials should be reviewed and rotated.

    Source: BleepingComputer — https://www.bleepingcomputer.com/news/security/cisa-warns-of-hackers-exploiting-critical-mlflow-vulnerability/

  6. Zimbra command-injection flaw enters active exploitation

    CERT Polska warned that attackers are exploiting CVE-2026-73570 when Zimbra SNMP notifications are enabled. Zimbra fixed the unauthenticated command-injection issue in version 10.1.20 and advised compromise checks.

    Source: BleepingComputer — https://www.bleepingcomputer.com/news/security/critical-zimbra-rce-flaw-now-actively-exploited-in-attacks/

  7. AI-generated scripts target Siemens industrial controllers

    U.S. agencies warned of ongoing activity using AI-generated Python tools against exposed Siemens S7 PLCs. The campaign creates reconnaissance and potential disruption risks across manufacturing, energy, water and other critical sectors relevant to Gulf operators.

    Source: BleepingComputer — https://www.bleepingcomputer.com/news/security/us-warns-of-ai-powered-attacks-on-siemens-plcs-in-critical-infrastructure/

  8. Rust packages hit by credential-stealing supply-chain attack

    Attackers compromised a maintainer account and poisoned three Rust crates with malware that ran during compilation. Affected organizations were advised to assume compromise, rotate accessible secrets and rebuild from safe sources.

    Source: BleepingComputer — https://www.bleepingcomputer.com/news/security/hackers-poison-arrayref-rust-crate-to-push-infostealer-malware/

  9. SynkLoader spreads through Microsoft Teams help-desk phishing

    SynkLoader is delivered through Teams messages impersonating corporate IT support and a fake Microsoft-hosted installer. Its modules can steal credentials, establish persistence, create a reverse proxy and provide remote control.

    Source: BleepingComputer — https://www.bleepingcomputer.com/news/security/new-synkloader-malware-pushed-in-microsoft-teams-phishing-campaign/

  10. Thousands of active AWS access keys found in public repositories

    Researchers identified more than 9,300 publicly exposed AWS access keys that remained valid, including credentials with extensive permissions. The finding reinforces automated secret scanning, rapid revocation and least-privilege controls across cloud development pipelines.

    Source: BleepingComputer — https://www.bleepingcomputer.com/news/security/hundreds-of-leaked-aws-keys-give-full-control-over-corporate-accounts/