← Carolina Clear Tech

Cyber Threat Brief

2026-08-24

Listen to this brief (10:01)

Download MP3
Show Notes

Show Notes - 2026-08-24

Stories Covered

CVEs Referenced

CVE-2019-18935, CVE-2021-29441, CVE-2021-3156, CVE-2022-0847, CVE-2022-27925

Indicators of Compromise

Domains: 197[.]150, tippusoni[.]in

Read the full brief

Get tomorrow's brief in your inbox

Protect Your Business

Need a security assessment? See our cybersecurity packages.

View Services

Daily Cyber Threat Brief - 2026-08-24

Today: Chinese cybercrime group UAT-10147 is using AI tools to automate exploitation of known vulnerabilities across 170,000 targets, deploying a new cross-platform implant called SPECTRE with EDR bypass capabilities. Iran-linked hackers shut down a UK power plant for four days in July, raising questions about distributed energy infrastructure resilience. ShinyHunters claims a breach of cybersecurity firm ReliaQuest, and a new attack technique revives expired Visa contactless cards for fraudulent transactions.


Critical Alerts

UAT-10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR Bypass and Linux Rootkit (CVE-2022-0847, CVE-2021-3156, CVE-2019-18935, CVE-2022-27925)

Cisco Talos disclosed a Chinese-speaking cybercrime group, UAT-10147, targeting Windows and Linux web servers across education, media, tech, and gaming sectors using a 170,000-URL target list. The group integrates AI tools (PentestGPT, DeepAudit) to automate exploitation, reconnaissance, and payload generation at scale. They chain known vulnerabilities for initial access and privilege escalation, deploying BadIIS (MaaS), Noodle RAT, Gh0stCringe, Quasar RAT, and a new cross-platform implant called SPECTRE. On Linux, they exploit CVE-2022-0847/Dirty Pipe (CISA KEV, EPSS 0.886), CVE-2021-3156/Baron Samedit (CISA KEV, EPSS 0.993), CVE-2019-18935/Telerik UI deserialization (CISA KEV, ransomware-linked, EPSS 0.997), and CVE-2022-27925/Zimbra RCE (CISA KEV, ransomware-linked, EPSS 0.987). On Windows, they use EfsPotato for privilege escalation, configure Defender exclusions, and persist via scheduled tasks disguised as "Google Chrome Start."


Ransomware & Extortion

ShinyHunters Claims Hack of ReliaQuest

Threat actor ShinyHunters posted claims of breaching cybersecurity firm ReliaQuest. The claim surfaced on a forum after ReliaQuest's threat research team (@ReliaQuestTR) published tracking of ShinyHunters campaigns. A forum user replied with screenshots and the taunt "Who's hunting who?" ReliaQuest deleted the original tweet and has not posted since. No confirmation or proof of breach has been provided by either party.


Business & Infrastructure Threats

Iran-Linked Hackers Shut Down UK Power Plant for Four Days

Iranian-affiliated hackers shut down a small-scale UK power plant for four days in July 2026. The attack was not publicly reported until August 22. The facility was not a major grid asset, and wider grid stability was not affected, but the incident demonstrates operational disruption capability against distributed energy infrastructure. Security experts warn this attack pattern is repeatable and could be deployed at scale against thousands of distributed UK energy assets. The attackers are believed to be the same group that previously breached US water utilities. Since the Iran-US/Israel conflict escalated, Iranian cyber groups have targeted critical infrastructure across the US, Israel, GCC states, and Europe.

Expired Visa Contactless Cards Can Be Revived for Fraudulent Transactions

Researchers at UMass Amherst developed an NFC Man-in-the-Middle attack that modifies the expiration date on contactless card transactions in transit. Banks delegate expiration checks to POS terminals rather than enforcing them server-side. The attack works on Visa terminals and was not caught by five tested banks' backends. Mastercard, Amex, and Discover terminals detected the hash mismatch and rejected the modified transactions. The attack requires only basic NFC emulators and a recovered expired card.

Lazarus Hacks South Korea's Presidential Office

North Korean espionage group Lazarus compromised South Korea's Presidential Office in February 2026 as part of a broader campaign that hit 100+ victims by April, including universities, police departments, news agencies, and hospitals. Investigation is ongoing with no technical details released.

SFR Telco Breach Exposes 2.1M French Customers

French telecom SFR suffered a breach exposing names, postal addresses, phone numbers, contract details, and for some customers, IP addresses and equipment details. 2.1 million customers affected.


Windows / AD Security

DOUBLECUP Malware Uses PNG Payload Delivery via FINDSTR

SANS ISC analyzed a DOUBLECUP malware sample that appends a PowerShell payload after the end of a PNG file (not true steganography). The payload begins with CR+LF bytes, allowing extraction via Windows FINDSTR command piped directly into powershell.exe. This technique avoids embedding payloads in image metadata or pixel data, instead exploiting how Windows text tools handle binary files.


General Security News

Anthropic Expands Mythos 5 Access for Defenders, Launches $35M Open Source Security Fund

Anthropic is expanding access to its Mythos 5 model for defensive security use through partner integrations. Claude Security (public beta for Enterprise customers) now runs code scans on Mythos 5, surfacing findings with CWE categories, confidence/severity ratings, and suggested fixes. The new Defender Advantage Fund (0xDAF) provides $35M in Claude credits toward open source security projects. The Cyber Verification Program is expanding to cover broader dual-use capabilities on Opus and Sonnet models with reduced safeguards for authorized security work.

TikTok Settles $400M Children's Privacy Lawsuit

TikTok reached a $400M settlement with the DOJ over COPPA violations, paying $300M immediately and $100M after a prior consent decree against Musical.ly is vacated.


Patch Priority


Vulnerability Disclosures

Multiple CVEs Actively Exploited by UAT-10147

The UAT-10147 campaign chains multiple known CVEs, several of which are CISA KEV entries with near-perfect EPSS scores: CVE-2019-18935 (Telerik UI deserialization, EPSS 0.997, ransomware-linked), CVE-2022-27925 (Zimbra RCE, EPSS 0.987, ransomware-linked), CVE-2022-0847 (Dirty Pipe, EPSS 0.886), CVE-2021-3156 (sudo heap overflow, EPSS 0.993), CVE-2021-29441/29442 (Nacos auth bypass, EPSS 0.696/0.655). All have been in CISA KEV for years; any unpatched instances are high-priority targets.


Trends & Context

AI-assisted offensive operations are moving from theoretical to operational. UAT-10147's use of PentestGPT and DeepAudit to automate exploit refinement and post-exploitation at scale across 170,000 targets marks a shift in how commodity threat actors operate. Meanwhile, the Iran-UK power plant incident reinforces that distributed critical infrastructure, often operated by smaller entities with limited security budgets, remains a soft target for state-affiliated groups testing operational disruption capabilities.