The CyberWire Daily Podcast 8.20.26
Ep 2619 | 8.20.26

The robots have gone bananas.

Transcript

Federal agencies warn of an active campaign targeting critical infrastructure. Citrix races to patch critical NetScaler flaws. More than 50,000 exposed Stripe API keys raise fraud concerns. Black Hat and DEF CON attendees are targeted in a new social engineering campaign. Atlassian, Splunk, and Cisco fix hundreds of vulnerabilities. A new Android banking trojan adds an unusual twist. A healthcare breach impacts 3.8 million people. SilkParasite expands cyberespionage in Central Asia. And CISA eyes a major overhaul of federal cyber software procurement. Our guest is Chris Wallis, founder and CEO of Intruder, on how AI agents killed the annual pentest and are reshaping exposure management. AI powered robots find bananas quite appealing.

Today is Thursday August 20th 2026. I’m Dave Bittner. And this is your CyberWire Intel Briefing.

Federal agencies warn of an active cyber campaign targeting critical infrastructure.

Federal agencies are warning of an active cyber campaign targeting critical infrastructure through internet-exposed Siemens S7 Series programmable logic controllers (PLCs), which are widely used in energy, water, agriculture, manufacturing, and defense. According to a joint advisory from the NSA, FBI, and other agencies, attackers are using artificial intelligence to generate exploit scripts that accelerate the discovery and exploitation of known vulnerabilities. These AI-assisted tools can mimic legitimate monitoring software, lowering the technical barrier for attackers and enabling faster adaptation to defensive measures. Officials say the activity appears focused on reconnaissance and capability development, potentially laying the groundwork for future disruptive attacks rather than immediate data theft. The advisory urges organizations to isolate PLCs from the internet, apply security patches, and strengthen monitoring. Experts warn that many exposed PLCs are connected by third-party vendors without operators’ knowledge, increasing the risk of operational disruption, equipment damage, and loss of control over critical industrial processes if attackers succeed.

Citrix urges immediate patching of two newly disclosed vulnerabilities. 

Citrix is urging customers to immediately patch two newly disclosed vulnerabilities affecting NetScaler ADC and NetScaler Gateway appliances. The most critical, CVE-2026-19490, allows unauthenticated attackers to bypass authentication under certain Gateway and AAA configurations, particularly when Security Assertion Markup Language (SAML) authentication is enabled. The second, CVE-2026-19489, is a high-severity memory overflow flaw that can enable denial-of-service attacks when SIP Application Layer Gateway (ALG) is enabled in large-scale NAT deployments. Citrix recommends administrators review their configurations, determine whether affected features are in use, and upgrade to the latest supported firmware versions. Although neither vulnerability has been observed in active attacks, Citrix noted that previous NetScaler flaws were exploited shortly after disclosure. With more than 23,000 NetScaler instances exposed online, organizations are encouraged to patch promptly to reduce potential risk.

Researchers uncover more than 50,000 exposed Stripe API keys. 

Ransomnews researchers uncovered more than 50,000 exposed Stripe API keys across public GitHub repositories, GitHub Actions logs, and misconfigured web servers, demonstrating how leaked credentials can quickly lead to fraud and account compromise. In one case, researchers used an active key to access a merchant’s customer data, create a fraudulent payment link, and process a $1 test charge within 17 hours. A recently discovered dataset contained live API keys for 659 merchant accounts and approximately 35 GB of customer and payment data, although Stripe itself was not compromised. The report highlights that exposed secret keys often provide full API access, enabling attackers to create charges, issue refunds, and modify webhooks. Researchers recommend rotating exposed keys, using restricted API keys, auditing version control history, and enabling fraud detection to reduce risk.

A social engineering campaign targets Black Hat and DEF CON attendees.

Huntress researchers uncovered a social engineering campaign targeting Black Hat and DEF CON attendees, with attackers impersonating a CoinDesk executive on X to lure victims into opening a malicious Google Doc. The document uses Google Apps Script to collect reconnaissance data, including IP address, operating system, location, and installed cryptocurrency wallets, before presenting fake errors that prompt users to download malware or run terminal commands. macOS victims receive malware resembling Atomic macOS Stealer (AMOS), while Windows users are targeted with payloads linked to credential theft, remote access, and persistent backdoors. A secondary lure uses a fake Dropbox DocSend site to distribute additional malware, including NetSupport RAT. Huntress advises users to treat unsolicited Google Docs like email attachments and avoid documents that request software updates, terminal commands, or security bypasses.

Atlassian, Splunk, and Cisco address more than 400 vulnerabilities across their enterprise products. 

Atlassian, Splunk, and Cisco have released security updates addressing more than 400 vulnerabilities across their enterprise products, including numerous critical- and high-severity flaws. Atlassian patched roughly 109 unique CVEs affecting products such as Jira, Confluence, and Bitbucket, while Splunk fixed more than 150 vulnerabilities across Enterprise, SOAR, and related applications. Cisco also resolved 15 vulnerabilities, including multiple critical flaws in Crosswork and Secure Workload that could enable remote code execution, authentication bypass, and other attacks. None of the vendors reported active exploitation, but organizations are urged to apply the updates promptly to reduce risk.

New Android malware combines spyware, banking fraud, and remote control capabilities. 

Researchers at ThreatFabric have identified Manic, a new Android malware active since at least February that combines spyware, banking fraud, and remote control capabilities. Targeting users across Europe, particularly Ukraine, the malware impersonates legitimate apps using transparent overlays to capture PINs, passwords, recovery phrases, and authentication codes while allowing apps to function normally. After gaining Accessibility permissions, it can steal notifications, SMS messages, files, location data, and provide remote access via WebRTC. A notable feature is its fallback data exfiltration method: if a compromised device cannot reach its command-and-control server, encrypted data is relayed through nearby infected devices using Wi-Fi Direct or Bluetooth, enabling multi-hop transfers. Users are advised to avoid unofficial apps, limit Accessibility permissions, and enable Google Play Protect.

A cyberattack exposes personal and health information of nearly 3.8 million individuals. 

CareCloud is notifying nearly 3.8 million individuals that personal and health information may have been exposed following a March cyberattack on one of its Amazon Web Services (AWS) environments. The company said attackers accessed and allegedly exfiltrated data between March 10 and 16, though no unauthorized activity has been detected since. Potentially affected information includes Social Security numbers, financial data, medical records, and insurance information. CareCloud says it is strengthening security measures, while multiple law firms are investigating the incident. The breach is currently the third-largest healthcare data breach reported in 2026 to the U.S. Department of Health and Human Services.

SilkParasite targets government organizations across Central Asia. 

Bitdefender Labs has uncovered SilkParasite, a cyberespionage campaign assessed with medium confidence as China-linked that has targeted government organizations across Central Asia since late 2025. Researchers identified seven remote access tool (RAT) families, including five previously undocumented, designed with modular, plugin-based architectures that minimize detection through in-memory execution and DLL sideloading. Unlike mass-produced AI-generated malware, SilkParasite appears to have been professionally engineered, with limited evidence suggesting AI-assisted development rather than AI-written code. The campaign relies on spear-phishing documents tailored to regional government agencies and uses trusted services, including Google Drive, for command-and-control communications. Bitdefender found links to known China-nexus malware families and infrastructure but stopped short of attributing the operation to a specific threat group. Researchers warn that the campaign demonstrates sophisticated, low-profile tradecraft likely to reappear against other regions and sectors.

CISA explores contracting out its cybersecurity software procurement. 

The Cybersecurity and Infrastructure Security Agency (CISA) is exploring the use of a contractor to manage enterprise-wide cybersecurity software procurement through a single acquisition process. A recently issued sources sought notice marks the beginning of market research for a potential contract supporting approximately $600 million in annual cyber software purchases, with the potential to expand to $6 billion over the contract’s lifetime. Working with the General Services Administration’s Assisted Acquisition Services, CISA is seeking support for enterprise licensing, software asset management, vendor management, procurement analytics, and strategic acquisition planning. The effort aligns with CISA’s transition from the Continuous Diagnostics and Mitigation (CDM) program’s approved product list to a new Cyber Product List and Technical Capability Catalog, which will serve as the foundation for future federal cybersecurity software acquisitions.

 

On our Industry Voices segment, we hear my conversation with Intruder's Founder and CEO Chris Wallis from Black Hat. Chris and I discussed the demise of annual pentests and how AI agents are reshaping exposure management. Here’s our conversation

 

We’ll be right back.

 

Welcome back. That was my conversation with Chris Wallis, Founder and CEO at Intruder discussing how the end of pentesting and AI's new exposture management role. If you enjoyed this conversation and want to learn more, check out the links in our show notes. 

AI powered robots see the appeal of bananas. 

The future of robotics may arrive with fewer dramatic robot uprisings and more bananas pressed into unexpected service. During a visit to robotics startup Generalist AI, a robotic arm demonstrated an ability to learn on the fly, even improvising by using a banana as a tool, a small but telling glimpse of how AI-powered machines are becoming more adaptable.

Founded by former Google DeepMind and Boston Dynamics researchers, Generalist is taking a different approach to robot training. Instead of relying solely on massive datasets or open-source language models, the company collects high-quality demonstrations using custom camera-equipped grippers worn by human trainers. The result is a proprietary foundation model designed to generalize across tasks, rather than failing when something as trivial as the lighting changes. Experts say the company’s combination of strong engineering and carefully curated training data puts it among the closest contenders to deploying truly useful robots in real-world commercial environments.     Some robots are still learning to grasp the world. This one apparently started with the produce aisle.

 

And that’s the CyberWire Daily, brought to you by N2K CyberWire.

For links to all of today’s stories, check out our Daily Briefing at the cyberwire dot com.

We’d love to know what you think of this podcast. Your feedback ensures we deliver the insights that keep you a step ahead in the rapidly changing world of cybersecurity. If you like the show, please share a rating and review in your podcast app. Please also fill out the survey in the show notes or send an email to cyberwire@n2k.com

We’re proud that N2K CyberWire is part of the daily routine of the most influential leaders and operators in the public and private sector, from the Fortune 500 to many of the world’s preeminent intelligence and law enforcement agencies.

N2K helps cybersecurity professionals and organizations grow, learn, and stay ahead. We’re the nexus for discovering the people, tech, and ideas shaping the industry.  Learn how at n2k.com.

N2K’s lead producer is Liz Stokes. We’re mixed by  Tré Hester, with original music by and sound design Elliott Peltzman. Our contributing host is Maria Varmazis. Our executive producer is Jennifer Eiben. Peter Kilpe is our publisher. And I’m Dave Bittner. Thanks for listening.