Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks
Daily Cybersecurity Briefing (4 August 2026)
Published: Loading…
At a Glance
- N-able's first patch for N-central authentication bypass CVE-2026-18577 proved incomplete, allowing continued attacker administrative access.
- Iran-linked hackers extended water system cyberattacks beyond Minnesota into Michigan, South Dakota and Georgia, with no operational disruption.
- Russian state actor Storm-2945, linked to Midnight Blizzard, hijacked hotel Wi-Fi captive portals to steal Microsoft credentials.
- ExfilSquad hackers leaked contact data of over 100,000 UK police officers and staff from the PNLD database.
- INC Ransomware became the dominant actor exploiting SonicWall SMA 1000 vulnerabilities for root access and lateral movement.
- Unit 42 detailed three attack paths letting malware hijack Google Password Manager's synced passkey-protected accounts without user verification.
Editorial Analysis
Today's briefing shows management-plane infrastructure emerging as a common point of failure across several unrelated incidents. N-able's first fix for the N-central authentication bypass proved incomplete, allowing attackers to retain administrative access to managed endpoints even after remediation began, with a working hotfix released only days later. SonicWall's SMA 1000 chain shows a similar dynamic over a longer timeline: INC Ransom has become a prominent actor exploiting vulnerabilities weeks after initial exploitation and before public disclosure, while many appliances remain unpatched or may already be compromised.
Trusted network infrastructure is also being repurposed for credential theft. Storm-2945, linked to Russia's Midnight Blizzard, is hijacking hotel and conference-venue Wi-Fi captive portals to steal Microsoft credentials from travellers, while a separate Russian-speaking access broker was found conducting reconnaissance and Active Directory compromise across more than a dozen countries before reselling access to different ransomware groups within weeks of the initial intrusion.
A third theme concerns authentication assumptions at the client level. Newly disclosed Pass-ta-key attacks allow malware already running on a Windows device to silently hijack Google Password Manager's synced passkeys without triggering a fingerprint or PIN prompt. Passkeys remove several weaknesses associated with passwords, but the underlying device remains a point of failure.
Highlights of the Day
SonicWall VPN Flaw Chain Lets Attackers Gain Root Access
SonicWall patched two SMA 1000 vulnerabilities, CVE-2026-15409 and CVE-2026-15410, exploited since June 2026 by threat actor UTA0533. Chaining an unauthenticated WebSocket bypass with a path-traversal flaw grants attackers full root access to VPN appliances. INC Ransomware has since become the dominant actor weaponising the exploit chain, deploying malware including ROOTRUN and ORANGETAIL against unpatched, internet-facing devices.
Exposed Server Reveals Russian Access Broker's Ransomware Pipeline
CloudSEK identified an exposed server belonging to a Russian-speaking initial access broker exploiting internet-facing appliances across a dozen countries. The operator achieved full Active Directory compromise at multiple organisations, later claimed by different ransomware groups within weeks. The same infrastructure also supported Sliver C2 collection against Ukrainian defence and aerospace targets, including IP camera surveillance.
N-able N-central Flaws Exploited to Gain Admin-Level Access
Threat actors are actively exploiting two authentication bypass vulnerabilities, CVE-2026-18556 and CVE-2026-18577, in N-able's N-central remote monitoring platform. N-able released hotfix 2026.3.1.7 on 2 August after detecting anomalous activity, with successful exploitation granting attacker-level administrator access. Post-exploitation activity includes Cloudflare tunnel persistence and deployment of suspicious executables via 'Take Control' remote access tools.
Notarized macOS Malware Poses as Video Conferencing App
Researchers identified CrashStealer, macOS infostealer malware distributed via a fake Werkbit videoconferencing site requiring a PIN code for access. The Werkbit Setup loader carries a valid Apple developer certificate and passed notarization, bypassing Gatekeeper before fetching CrashStealer from an attacker server. The malware harvests Keychain data, credentials from 14 password managers, browser cookies, and 80 cryptocurrency wallet extensions.
iOS Exploit Kit DarkSword Spreads Across Multiple Chinese Operators
Censys traced a leaked six-vulnerability iOS exploit chain called DarkSword to at least seven operators running over 180 web properties, mostly hosted in Hong Kong. Researchers used stable panel login page hashes to track infrastructure that otherwise rotates hosts weekly, uncovering a Chinese-speaking operator bundling an Apple ID credential-harvesting decoy directly into exploit-chain staging pages. The chain targets iOS 18.4 through 18.7, deploying keychain, iCloud, and Wi-Fi credential-stealing modules.
Hijacked LiteLLM Gateways Can Steal AI Keys, Forge Tool Calls
Security researcher wunderwuzzi demonstrated how an attacker with admin access to a LiteLLM AI gateway can reroute traffic through a malicious proxy. The technique harvests backend LLM provider credentials and injects forged responses or tool calls into client applications like Claude Code, bypassing prompt-level defences entirely. Initial access can come from leaked master keys or unpatched vulnerabilities, including CVE-2026-42271, listed on CISA's Known Exploited Vulnerabilities catalogue.
Malware Bypasses Verification to Hijack Google-Synced Passkeys
Researchers detailed three attack techniques against Google's synced passkey ecosystem, allowing malware on a compromised Windows device to authenticate without user interaction or biometric verification. One variant registers an attacker-controlled key to forge user-verification signals, while a further technique extracts the master key from Chrome's memory, enabling decryption of all synced passkeys. eBay and other relying parties fixed the flaws following disclosure, though Google's implementation cannot rotate the extracted master key.
Daily Coverage