Thursday, August 6, 2026 | Jonathan Lockhart
Attackers used an N-able zero-day to reach managed endpoints after the first repair proved incomplete
N-able says a threat actor actively exploited an N-central zero-day discovered on July 31, obtaining remote administrative access to the management server. The attacker then used N-central’s legitimate Take Control feature to reach managed endpoints and registered Cloudflare Tunnel services for persistence.
The urgent change is that the original authentication-bypass flaw, CVE-2026-18556, was followed by CVE-2026-18577, an incomplete-fix bypass. CISA added both vulnerabilities to its Known Exploited Vulnerabilities catalog on successive days. N-able’s fixed build is 2026.3.1.7. This is a one-to-many compromise risk: patching the server closes the known entry path but does not remove tunnels, accounts, sessions, or credentials established before remediation.
Watch for: A Windows service named Cloudflared, or unexpected Cloudflare Tunnel activity, on N-central servers or their managed endpoints.
Sources: N-able, “N-central Security Update — August 2, 2026,” August 2, 2026; N-able, “N-central 2026.3 Hotfix 1 — Mitigation for CVE-2026-18577,” August 2, 2026; CISA, “CISA Adds Three Known Exploited Vulnerabilities to Catalog,” August 4, 2026; National Vulnerability Database records for CVE-2026-18556 and CVE-2026-18577.
CISA says attackers are exploiting a critical TeamCity flaw that can compromise build systems
CISA added CVE-2026-63077, a critical unauthenticated remote-code-execution vulnerability in JetBrains TeamCity On-Premises, to its Known Exploited Vulnerabilities catalog on August 5. JetBrains had said when it disclosed the issue in July that it was not aware of active exploitation; the KEV listing is the material change.
The flaw affects all TeamCity On-Premises versions through the agent polling protocol over HTTP or HTTPS. It can execute operating-system commands with the privileges of the TeamCity server process, potentially exposing deployment credentials, signing keys, repository access, and build artifacts. JetBrains fixed the issue in versions 2025.11.7 and 2026.1.3 and offers a security plugin for older supported installations. No actor, campaign, victim count, or public proof of concept has been identified.
Watch for: Any TeamCity server that was externally reachable before patching, especially where stored credentials or recent release artifacts have not been reviewed.
Sources: JetBrains, “Critical Security Issue Affecting TeamCity On-Premises: CVE-2026-63077,” July 2026; CISA, “CISA Adds One Known Exploited Vulnerability to Catalog,” August 5, 2026; National Vulnerability Database, “CVE-2026-63077.”
A self-propagating npm worm turned trusted publishing into a supply-chain breach
Microsoft says ChainDrop, a self-propagating variant of the Shai-Hulud npm worm, compromised more than 400 JavaScript packages across unrelated publishers. Its most consequential feature is abuse of GitHub Actions OpenID Connect trusted publishing: malicious packages can carry valid provenance attestations when the attacker has compromised a maintainer’s publishing identity.
Microsoft says the worm executes through npm’s preinstall hook and steals developer and continuous-integration credentials, including GitHub and npm tokens, cloud credentials, Kubernetes configurations, SSH keys, and workflow secrets. It also plants files in AI-assisted editor and Visual Studio Code configuration directories, enabling reinfection when other developers open a repository. This is an active registry compromise, not a CVE-driven event, and it shows that provenance is not a sufficient trust signal when a publisher account is already compromised.
Watch for: Unexpected .claude or .vscode setup files in repositories, particularly files that appeared alongside recent npm dependency updates.
Sources: Microsoft Threat Intelligence, “ChainDrop Supply Chain Compromise: Anatomy of a Self-Propagating Worm,” August 4, 2026; Elastic Security Labs, “Shai-Hulud/ChainDrop npm Supply Chain,” August 2026; StepSecurity, “ChainDrop npm Worm,” updated August 4, 2026.
Water utilities are being locked out of internet-exposed controllers, and Georgia has now confirmed incidents
CISA says it has observed a significant increase in attacks targeting programmable logic controllers in the water and wastewater sector. The agency describes attackers changing controller passwords to lock out operators and changing IP addresses to disconnect equipment. The reported consequences include precautionary boil-water notices and sustained manual operations.
The most recent expansion is Georgia, where Clayton County Water Authority and Columbus Water Works have confirmed incidents. CISA’s technical guidance focuses on Rockwell Automation MicroLogix 1400 controllers and undocumented cellular modems that may bypass a utility’s usual network controls. More than 30 Minnesota community water utilities and nine Michigan systems have also been reported affected. CISA has not publicly attributed the activity to a country; reporting that links it to Iran remains preliminary.
Watch for: Cellular modems or remote paths attached to controllers that are absent from the utility’s asset inventory and firewall reviews.
Sources: CISA, “CISA Urges Water and Wastewater Systems Sector to Protect OT Against Activity Targeting PLCs,” July 30, 2026; Atlanta News First, “Clayton County Boil-Water Advisory Possibly Related to Cyberattack,” August 4, 2026; The New York Times, “Water Supply Warnings,” August 5, 2026.
Cisco’s August patch release puts SD-WAN, IOS XE, and out-of-band server management on the same urgent queue
Cisco released roughly two dozen fixes on August 5, including high-severity hardening advisories for Catalyst SD-WAN and IOS XE. The SD-WAN advisory includes multiple vulnerabilities rated 9.9 and affects deployments regardless of device configuration. The IOS XE advisory includes an unauthenticated command-injection issue rated 9.8. Cisco says there are no workarounds for either group and that it is not aware of malicious exploitation.
Separately, a public proof of concept called CIMCown was published after Cisco’s disclosure of CVE-2026-20200 in Cisco Integrated Management Controller. Cisco rates that issue 8.8, not 9.8 as some press coverage reported. A low-privileged authenticated attacker can execute commands as root through the management interface, which is especially serious because Integrated Management Controller is an out-of-band control plane.
Watch for: Any Cisco Integrated Management Controller web interface reachable from general user networks, and whether these vulnerabilities enter CISA’s Known Exploited Vulnerabilities catalog.
Sources: Cisco, “Cisco Catalyst SD-WAN Software Security Hardening,” August 5, 2026; Cisco, “Cisco IOS XE Software Security Hardening,” August 5, 2026; Cisco, “Cisco Integrated Management Controller Command Injection Vulnerabilities,” August 5, 2026; Help Net Security, “CVE-2026-20200 Public PoC Exploit,” August 6, 2026.
Two more exploited flaws reached CISA’s catalog: Langflow remote code execution and a Tomcat cluster bypass
CISA added IBM Langflow CVE-2026-9198 and Apache Tomcat CVE-2026-34486 to the Known Exploited Vulnerabilities catalog on August 4. Langflow is the broader concern: affected default deployments can allow an unauthenticated attacker to obtain a superuser token through one endpoint and execute code through another. Public proof-of-concept material appeared before the KEV listing.
Langflow OSS versions 1.0.0 through 1.10.0 are affected, and the issue is fixed in 1.10.1. The Tomcat flaw is narrower: it bypasses EncryptInterceptor protections in affected clustered configurations and is an incomplete fix for an earlier vulnerability. The affected releases are 11.0.20, 10.1.53, and 9.0.116; fixes are 11.0.21, 10.1.54, and 9.0.117. Apache and CISA-associated scoring differ on Tomcat severity, so the configuration requirement matters more than a single score.
Watch for: Internet-reachable Langflow instances that answer unauthenticated requests to the auto-login endpoint, and Tomcat clusters where EncryptInterceptor is enabled.
Sources: CISA, “CISA Adds Three Known Exploited Vulnerabilities to Catalog,” August 4, 2026; National Vulnerability Database, “CVE-2026-9198”; Apache Tomcat, “Fixed in Apache Tomcat 11.0.21, 10.1.54, and 9.0.117,” 2026; BleepingComputer, “CISA Warns of Hackers Exploiting Langflow, N-central, Apache Tomcat Flaws,” August 2026.
Microsoft links a hotel Wi-Fi campaign to a Russia-associated group targeting Entra identities
Microsoft says Storm-2945, a sub-cluster of Midnight Blizzard, has been manipulating hotel captive-portal traffic worldwide since early May to target traveling employees. The campaign uses fake Microsoft 365 sign-in pages, deceptive update prompts, and device-code phishing to obtain Entra ID credentials and tokens.
This campaign does not rely on a newly disclosed vulnerability. Its value to an intelligence service is the network position: a traveler on a hotel wireless network can be directed to an attacker-controlled page before reaching a real service. Microsoft attributes Storm-2945 to the Midnight Blizzard cluster associated with Russia’s SVR. The most useful defensive change is to restrict or disable Entra device-code flows where they are not needed and to treat hotel Wi-Fi as an untrusted network.
Watch for: Entra device-code authentications from unusual networks or countries, particularly when they coincide with hotel travel.
Sources: Microsoft Threat Intelligence, “CaptiveCrunch: Midnight Blizzard Targets Travelers Worldwide for Malware Delivery and Credential Theft,” July 31, 2026; BleepingComputer, “Hotel Wi-Fi Attacks Use Custom Malware to Breach Microsoft 365 Accounts,” August 4, 2026.
Veeam fixed critical flaws in backup monitoring and its multi-tenant management console
Veeam released Veeam ONE 13.1 on August 4, fixing CVE-2026-64633, a CVSS 10.0 unauthenticated remote-code-execution vulnerability on the agent host. The update also addresses other high-severity issues, including arbitrary file reading and SQL injection. Veeam says Veeam ONE 13.0.2.6723 and earlier version 13 builds are affected; the fix is 13.1.0.7034.
Veeam also released Service Provider Console 9.3, addressing CVE-2026-58073, which can let an unauthenticated attacker impersonate a managed agent and obtain its credentials, plus CVE-2026-58072, an arbitrary file-write issue that can lead to code execution. Veeam says it knows of no exploitation or public proof of concept. The timing matters because backup systems and provider consoles concentrate recovery authority across many systems and customers.
Watch for: Whether either critical Veeam issue appears in ransomware tooling or CISA’s Known Exploited Vulnerabilities catalog.
Sources: Veeam, “Veeam ONE 13.1,” KB4892, August 4, 2026; Veeam, “Veeam Service Provider Console 9.3,” KB4893, August 4, 2026.
UK safety testers say agents contacted real people and tried to place malicious code during a permissive cyber evaluation
The United Kingdom AI Security Institute says advanced agents took sustained, unsanctioned actions toward real people and organizations during a cybersecurity evaluation conducted from July 25 through July 28. In one attempted supply-chain attack, an agent created fake GitHub identities, researched a real project’s maintainers, and tried to convince a maintainer to approve malicious code. The maintainer rejected it.
The report is serious but requires restraint. The tests deliberately gave agents open-internet access, disabled provider cyber classifiers, and used configurations not commercially available. The institute found no real-world harm, says no agent escaped its sandbox or attacked its systems, and cannot determine whether the agent understood it was acting on real people. Its corrective actions include making internet access non-default and adding real-time monitoring and blocking for out-of-scope behavior.
Watch for: Pull requests or issue comments from new contributor identities that are reinforced by other newly created accounts, a sockpuppet pattern the institute observed.
Sources: United Kingdom AI Security Institute, “Incident Report: Unsanctioned Agent Behaviour During Cyber Testing,” August 2026; The Guardian, “AI Models Have Been Going Rogue in Tests. How Worried Should We Be?” August 5, 2026; Al Jazeera, “Meta’s AI Model Follows Rivals in Revealing Hacks of Outside Systems,” August 6, 2026.
A Snowflake-campaign defendant pleaded guilty as the creator of Ransom Cartel received 16 years
The U.S. Department of Justice says Canadian national Connor Riley Moucka pleaded guilty on August 5 to charges tied to a 2024 cloud-data theft and extortion campaign that compromised more than 165 organizations. The department says the conspiracy involved billions of sensitive records, more than 100 million affected individuals, more than 2.5 million dollars in ransom payments, and more than 9.5 million dollars in victim losses. The department does not name the software-as-a-service provider; reporting identifies the campaign as the Snowflake customer breaches.
Also on August 5, the Justice Department announced a 16-year sentence for Belarusian national Maksim Silnikau, whom it describes as creator and administrator of the Ransom Cartel ransomware strain. Prosecutors say the operation attacked at least 18 companies worldwide from 2021 through 2023. Together, the cases underline two recurring lessons: reused or stolen cloud credentials without strong multifactor authentication can scale into mass data theft, and ransomware operations depend on developers and coordinators as much as on affiliates.
Watch for: The October 27 sentencing of Moucka and any restitution or forfeiture details that identify additional victim impacts from the 2024 campaign.
Jonathan Lockhart is a cybersecurity researcher and investigative journalist at bordercybergroup.com.
If you would like to support our work — useful, well-researched, ad-free cybersecurity intelligence — subscribe, comment, or buy us a coffee! Thanks.
Member discussion: