View all sources for this day →

The Signal

These stories call for separate security decisions rather than a single response: infrastructure exposure, user-mediated execution, mobile interaction, and card replacement sit at different control boundaries. The practical takeaway is to distinguish how access is gained, which asset is at risk, and who can act on the relevant control. [1][2][3][4]

Must Know

Siemens S7 controller attack advisory

Security · Supply Chain

What happened

Five U.S. federal agencies issued a joint advisory about an active campaign targeting Siemens S7 Series PLCs, covering S7-200 through S7-1500 F-series controllers. [1]

The advisory says actors use Internet scanning services to find exposed or poorly protected Siemens PLCs running outdated software, with activity targeting multiple U.S. critical-infrastructure sectors. [1]

Why it matters

Observed activity reportedly begins with scanning and read operations to map target environments before writes; the agencies assess this as pre-positioning against specific CPU models. [1]

StopAndProtect WordPress compromise network

Incident · Exploitation

What happened

Check Point Research identified StopAndProtect as an operation using nearly 2,000 compromised WordPress domains to deliver malware, control infected machines, and store stolen data. [2]

The campaign begins with a ClickFix-style fake CAPTCHA that instructs visitors to copy and run a PowerShell command, followed by .NET downloaders and loaders. [2]

Why it matters

The operation does not deploy ransomware against every victim; operators may first collect file lists and selectively exfiltrate files, with encryption or screen locking occurring later depending on their objectives. [2]

Manic Android malware analysis

Incident · Identity

What happened

ThreatFabric’s Mobile Threat Intelligence team identified Manic, an Android malware active in the wild since at least February 2026 and still under development as of July. [3]

Manic combines banking fraud and spyware, targeting 169 Android applications across banking, payments, government and identity services, cryptocurrency, messaging, browsers, email and 2FA. [3]

Why it matters

The malware provides attackers with WebRTC-based remote screen viewing and interaction, can conceal activity with black or fake screens and messages, and can remove itself from the app launcher while remaining activatable through a wrapper or deep link. [3]

Research on expired-card payment authorization

Research · Security

What happened

A University of Massachusetts Amherst team reported that a contactless credit card can continue working after its printed expiration date, including after the cardholder receives a replacement. [4]

The researchers called the issue the “Zombie Card” attack and presented their findings at USENIX Security 2026. [4]

Why it matters

The work was motivated by documented improper handling of expired cards; the source says issuers instruct cardholders to destroy expired cards after replacement, but cardholders routinely underestimate this risk. [4]

Also Worth Knowing

Indictments over alleged Iranian cyber espionage

Incident · Identity

What happened

The U.S. Department of Justice unsealed a superseding indictment charging 17 members of the Iran-based Mabna Institute over hacking campaigns conducted since at least 2013 on behalf of the IRGC and other Iranian government and university clients. [5]

Vulnerability patching analysis

Vulnerability · Exploitation

What happened

Rapid7’s Q2 2026 Threat Landscape Report counted 8,539 high- and critical-severity vulnerability disclosures, twice the number recorded a year earlier. [6]

ThreatsDay vulnerability and incident roundup

Research · AI & Agents

What happened

The article says some of the week’s trouble involves trusted capabilities being used as permitted, including signed drivers turned against defenses and legitimate applications helping malware blend in. [7]

Sources (7)
  1. [1] NSA, CISA, FBI, DOE, and EPA Warn of Active AI-Assisted Attacks on Siemens S7 PLCs

    securityaffairs · August 20, 2026

  2. [2] StopAndProtect Turns 2,000 Hacked WordPress Sites Into a Criminal Network

    securityaffairs · August 20, 2026

  3. [3] Manic: The Android Malware That Exfiltrates Data Even When the Phone Is Offline

    securityaffairs · August 20, 2026

  4. [4] Researchers find a loophole that lets expired credit cards make unauthorized payments

    helpnetsecurity · August 20, 2026

  5. [5] US Indicts 17 Iranians Over Years-Long Cyber Espionage Campaign

    securityaffairs · August 20, 2026

  6. [6] 8,539 reasons to rethink how vulnerabilities get patched

    helpnetsecurity · August 20, 2026

  7. [7] ThreatsDay: Gogs 10.0 RCE, n8n Workflow-to-RCE, $10M Reward, GLM-5.3 AI Exploit and More

    the hacker news · August 20, 2026