This Week in Cybersecurity: Cl0p Hits 40+ Enterprises, 3.7M Patient Records Stolen, and Six CVSS 9.8 Flaws Under Active Attack
By Mollie Horne
Enterprise software, healthcare, and critical infrastructure took the brunt this week as ransomware operators, nation-state actors, and credential thieves ratcheted up pressure across every sector.
The headline story is Cl0p's ruthless exploitation of a zero-day in PTC Windchill — the industrial platform underpinning engineering operations at Shell, Philips, and dozens of other household names. While that campaign was still unfolding, CareCloud disclosed that attackers quietly pillaged 3.7 million patient records from its Amazon Web Services environment back in March. Meanwhile, CISA added six actively exploited vulnerabilities to its KEV catalog — three scoring a maximum-tier CVSS 9.8 — giving federal agencies binding patching deadlines and signaling that enterprise patch queues are not moving fast enough. Layered on top of all that: a 30% surge in Russian cyberattacks, a Chinese APT deploying a nearly undetectable kernel-level backdoor across global telecom, a sweeping DOJ indictment of 17 Iranian IRGC contractors, and evidence that password-spraying campaigns have grown 155-fold in a single year.
The common thread this week is access — who has it, who's stealing it, and how attackers are making sure defenders can't see them doing either. Here's what you need to know.
Explore this content with AI:
ChatGPT | Perplexity | Claude | Google AI Mode
Cl0p's PTC Windchill Zero-Day Exposes Engineering Data at 40+ Global Enterprises
Cl0p has done it again. The ransomware group — responsible for the 2023 MOVEit and GoAnywhere mass-exploitation campaigns — spent late July and early August quietly working through a new victim list after weaponizing CVE-2026-12569 (CVSS 9.8), a critical improper input validation vulnerability in PTC Windchill PDMLink and FlexPLM that allows remote, unauthenticated arbitrary code execution. More than 30,000 organizations globally deploy these product lifecycle management systems. Starting August 12, Cl0p began publicly naming victims, and the roster is striking: Shell, Philips, Fiserv, Zebra Technologies, Ingersoll Rand, Toast, Mindray, Largan Precision, and more than 30 additional enterprises. GE was initially listed but subsequently removed. Most major targets have stated they are investigating the claims.
The attack method is particularly alarming for any organization that runs Windchill as the backbone of its product lifecycle management. According to ReliaQuest, Cl0p's custom implant "maps sensitive vault data, decrypts every credential in the Windchill keystore," and includes a Java class loader that enables arbitrary code execution deep within the application layer. Exfiltrated data per victim ranges from 1 GB to several terabytes and spans blueprints, engineering diagrams, project files, databases, and corporate documents. CISA added CVE-2026-12569 to its KEV catalog in June; the window between disclosure and Cl0p's exploitation underscores how quickly sophisticated operators convert newly public flaws into active campaigns.
Why it matters: This is the third major Cl0p mass-exploitation campaign in three years, and it follows the same template — identify a widely deployed enterprise platform, weaponize a critical RCE flaw, and extract data from as many customers as possible before defenders catch on. If your organization uses PTC Windchill, treat CVE-2026-12569 patching as P0 and audit your Windchill credential stores immediately. For every other enterprise: verify that your patch management program has visibility into third-party line-of-business applications, not just operating systems and browsers.
Read more at SecurityWeek
CareCloud Breach Exposes 3.7 Million Patients' Medical Records, Social Security Numbers, and Banking Data
A six-day intrusion in March 2026 has turned into one of the year's worst healthcare data disasters. CareCloud, a New Jersey-based company that provides electronic medical record storage and billing management to tens of thousands of US healthcare providers, confirmed August 18–19 that attackers accessed its Amazon Web Services environment between March 10 and 16, exfiltrating data belonging to approximately 3.75 million individuals. The compromised records include full names, postal addresses, Social Security numbers, medical and health records, government-issued identification (passports and driver's licenses), and banking and financial account information — essentially everything an identity thief or extortionist would want.
CareCloud filed the breach with the Department of Health and Human Services on August 18, with the victim count revised upward the following day. Breach notifications began going out to affected individuals on July 25, with 12–24 months of identity protection services offered through IDX. No ransomware group has claimed responsibility, and CareCloud has not disclosed how the attackers gained initial access to the AWS environment. TechCrunch places this as the fifth-largest healthcare breach of 2026 to date — a year that has already seen several eight-figure incidents. Because CareCloud operates as infrastructure for other providers rather than as a direct patient-facing organization, most of the 3.75 million affected individuals will have received their breach notification from a provider they recognized without ever having heard of CareCloud.
Why it matters: Healthcare cloud infrastructure is a high-value, concentrated target: compromise one platform, and you can reach the records of patients from hundreds of unrelated practices. The March-to-August gap between breach and disclosure underlines how long intrusions can go undetected in cloud environments, and how late notifications arrive relative to when data is actually in criminal hands. Healthcare organizations and their technology vendors need cloud posture management, real-time anomaly detection on data egress, and clear contractual requirements around breach notification timelines — not just HIPAA checkbox compliance.
Read more at TechCrunch
CISA Flags Six Critical CVEs Under Active Exploitation — Three at CVSS 9.8
CISA's Known Exploited Vulnerabilities catalog added six vulnerabilities confirmed as actively exploited within the past week, and the severity cluster is unusually acute. Three of the six score CVSS 9.8 — the highest tier short of a perfect 10: CVE-2026-33824 in Microsoft's Windows Internet Key Exchange Service (a double-free vulnerability enabling remote code execution), CVE-2026-59310 in Broadcom VMware vCenter (a path traversal flaw that can be chained to achieve full administrative control), and CVE-2026-65400 in Apple macOS (an improper authentication flaw in Screen Sharing, confirmed exploited to deploy cryptocurrency miners). The remaining three: CVE-2026-55040 in Microsoft SharePoint (security feature bypass, CVSS 9.1), CVE-2026-64849 in MLflow (server-side request forgery enabling cloud credential theft from the widely used AI engineering platform, CVSS 9.3), and CVE-2025-62593 in Ray, a distributed AI computing framework (code injection, CVSS 8.8).
The breadth of affected products — Windows, VMware, macOS, SharePoint, and two AI/ML frameworks — reflects how attackers scan horizontally across enterprise stacks rather than focusing on a single vendor. Federal civilian agencies have binding remediation deadlines under CISA's KEV mandate. For private-sector organizations, KEV additions serve as a prioritization signal: if a vulnerability is on this list, active exploitation in the wild is confirmed, not theoretical. The MLflow and Ray entries also point to a growing trend: AI infrastructure is now mainstream enough to be actively targeted. Credentials extracted from a compromised MLflow server can cascade into cloud environments, model repositories, and downstream data pipelines.
Why it matters: Six actively exploited critical flaws in a single week is not a slow week. Patch the Windows IKE, VMware vCenter, and macOS entries first — all confirmed at CVSS 9.8 with in-the-wild exploitation. If your organization runs MLflow or Ray in production, treat CVE-2026-64849 and CVE-2025-62593 as urgent: AI infrastructure tends to have privileged cloud access and is frequently less hardened than traditional enterprise systems.
Read more at Senserva KEV Tracker
State-Sponsored Attacks Rose 7.5% in H1 2026; China's BPFDoor Backdoor Creates Undetectable "Sleeper Cells" in Global Telecom
A new threat intelligence report from S2W TALON documented 158 confirmed state-sponsored cyberattack incidents in the first half of 2026 — a 7.5% increase over the prior period, with Russia posting the steepest acceleration at 30%. North Korea conducted 99 of those 158 incidents (a 13.8% increase), primarily targeting cryptocurrency platforms, IT providers, and software companies to fund its weapons programs; Pyongyang stole $2.02 billion in cryptocurrency in 2025 alone. Russia's 26 incidents targeted Ukraine most heavily but extended into Poland and Romania as Moscow tested the resilience of NATO's eastern flank. China's attributed incident count declined 17.5%, though analysts note that the decline likely reflects improved operational security rather than a genuine reduction in activity.
That suspicion is supported by the BPFDoor story that surfaced this week. Chinese APT Red Menshen — also tracked as Earth Bluecrow — is deploying version 2 of BPFDoor, a backdoor that embeds itself at the Linux kernel level within the Berkeley Packet Filter subsystem. BPFDoor v2 has no open listening ports, no external command-and-control connections, and activates only when it receives a specially crafted "magic packet" that can arrive on any port. In other words, it is invisible to standard firewalls and network scanners. Version 2 added public/private key encryption to the command channel. Rapid7 Labs documented seven previously undocumented variants deployed across global telecommunications infrastructure, describing the implants as "sleeper cells" that can lie dormant indefinitely and are activated only when needed.
Why it matters: BPFDoor's kernel-level operation represents a meaningful escalation in stealth. Organizations that rely on perimeter firewalls and signature-based network detection as their primary visibility layer will not see it. Effective detection requires behavioral monitoring at the kernel and process level, regular integrity checks on running kernel modules, and extended detection and response tooling that correlates endpoint and network telemetry. Telecom and critical infrastructure operators should treat any Linux environment with external-facing interfaces as a potential implant host until proven otherwise.
Read more at Korea Times / S2W TALON Report
DOJ Indicts 17 IRGC-Linked Iranians for $3.4B IP Theft as Password Spraying Surges 155x
Two credential-focused stories collided this week. On August 19, the Department of Justice unsealed charges against 17 members of Iran's Mabna Institute — contractors operating on behalf of the Islamic Revolutionary Guard Corps — for a multi-year hacking campaign targeting 178 universities across 22 countries (including 144 in the United States), 53 private companies (42 in the US), two NGOs, and at least 10 state government agencies. The group compromised approximately 8,000 professor accounts out of over 100,000 targeted, exfiltrated 31.5 terabytes of academic journals, theses, dissertations, ebooks, and research data, and extorted at least one major media organization for $6 million in Bitcoin. The stolen intellectual property is valued at approximately $3.4 billion. The State Department is offering up to $10 million for information on five of the defendants.
The same week, new research from Huntress documented a 155-fold surge in password-spraying attacks during the first half of 2026. The LSHIY campaign — the most documented single actor — logged over 81 million Microsoft 365 login attempts across a two-week window in mid-June by exploiting the OAuth ROPC (Resource Owner Password Credentials) grant, a legacy authentication flow that bypasses modern conditional access and MFA policies. The campaign compromised at least 78 accounts before it was fully characterized. The connection to the Iranian indictment is more than thematic: the Mabna group built its entire operation on credential theft at scale, and the LSHIY technique demonstrates how easily legacy authentication endpoints become a master key to enterprise environments when MFA is configured incompletely.
Why it matters: Block legacy authentication. If your Microsoft 365 or Azure environment still permits ROPC-based OAuth flows, you have an MFA bypass open right now that active campaigns are exploiting. Conditional access policies that block legacy authentication protocols are not optional hardening — they are the baseline. The Iranian indictment is also a reminder that state-sponsored credential theft targets universities and research institutions just as aggressively as defense contractors; any organization handling sensitive research data should be operating under the same threat model as a government agency.
Read more at BleepingComputer / DOJ and BleepingComputer / Password Spraying
Final thoughts
This week's headlines share a single uncomfortable truth: the perimeter is not holding. Cl0p got into enterprise engineering networks through an unpatched platform that didn't appear on anyone's urgent priority list. CareCloud's attackers spent six days inside an AWS environment before anyone noticed. BPFDoor is sitting inside telecommunications networks right now and leaving no log traces that standard monitoring would catch. The LSHIY password-spray campaign found 81 million open doors because legacy authentication flows were never turned off.
The answer is not more alerts — it's better architecture. Zero-trust network access, enforced MFA with no legacy protocol exceptions, cloud posture management, and endpoint behavioral monitoring are not aspirational; they're table stakes for operating in 2026's threat environment.
Check back next Tuesday for the next edition.
Ready to see how OpenVPN can help protect your organization from attacks?
Try the self-hosted Access Server solution or managed CloudConnexa service for free — no credit card required.
See Which One is Right for You