CyberSecBrief

Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks


Daily Cybersecurity Briefing (4 August 2026)

Published: Loading…

At a Glance

  • N-able's first patch for N-central authentication bypass CVE-2026-18577 proved incomplete, allowing continued attacker administrative access.
  • Iran-linked hackers extended water system cyberattacks beyond Minnesota into Michigan, South Dakota and Georgia, with no operational disruption.
  • Russian state actor Storm-2945, linked to Midnight Blizzard, hijacked hotel Wi-Fi captive portals to steal Microsoft credentials.
  • ExfilSquad hackers leaked contact data of over 100,000 UK police officers and staff from the PNLD database.
  • INC Ransomware became the dominant actor exploiting SonicWall SMA 1000 vulnerabilities for root access and lateral movement.
  • Unit 42 detailed three attack paths letting malware hijack Google Password Manager's synced passkey-protected accounts without user verification.

Editorial Analysis

Today's briefing shows management-plane infrastructure emerging as a common point of failure across several unrelated incidents. N-able's first fix for the N-central authentication bypass proved incomplete, allowing attackers to retain administrative access to managed endpoints even after remediation began, with a working hotfix released only days later. SonicWall's SMA 1000 chain shows a similar dynamic over a longer timeline: INC Ransom has become a prominent actor exploiting vulnerabilities weeks after initial exploitation and before public disclosure, while many appliances remain unpatched or may already be compromised.

Trusted network infrastructure is also being repurposed for credential theft. Storm-2945, linked to Russia's Midnight Blizzard, is hijacking hotel and conference-venue Wi-Fi captive portals to steal Microsoft credentials from travellers, while a separate Russian-speaking access broker was found conducting reconnaissance and Active Directory compromise across more than a dozen countries before reselling access to different ransomware groups within weeks of the initial intrusion.

A third theme concerns authentication assumptions at the client level. Newly disclosed Pass-ta-key attacks allow malware already running on a Windows device to silently hijack Google Password Manager's synced passkeys without triggering a fingerprint or PIN prompt. Passkeys remove several weaknesses associated with passwords, but the underlying device remains a point of failure.

Highlights of the Day

SonicWall VPN Flaw Chain Lets Attackers Gain Root Access

SonicWall patched two SMA 1000 vulnerabilities, CVE-2026-15409 and CVE-2026-15410, exploited since June 2026 by threat actor UTA0533. Chaining an unauthenticated WebSocket bypass with a path-traversal flaw grants attackers full root access to VPN appliances. INC Ransomware has since become the dominant actor weaponising the exploit chain, deploying malware including ROOTRUN and ORANGETAIL against unpatched, internet-facing devices.

Source: Resecurity

Exposed Server Reveals Russian Access Broker's Ransomware Pipeline

CloudSEK identified an exposed server belonging to a Russian-speaking initial access broker exploiting internet-facing appliances across a dozen countries. The operator achieved full Active Directory compromise at multiple organisations, later claimed by different ransomware groups within weeks. The same infrastructure also supported Sliver C2 collection against Ukrainian defence and aerospace targets, including IP camera surveillance.

Source: CloudSEK

N-able N-central Flaws Exploited to Gain Admin-Level Access

Threat actors are actively exploiting two authentication bypass vulnerabilities, CVE-2026-18556 and CVE-2026-18577, in N-able's N-central remote monitoring platform. N-able released hotfix 2026.3.1.7 on 2 August after detecting anomalous activity, with successful exploitation granting attacker-level administrator access. Post-exploitation activity includes Cloudflare tunnel persistence and deployment of suspicious executables via 'Take Control' remote access tools.

Notarized macOS Malware Poses as Video Conferencing App

Researchers identified CrashStealer, macOS infostealer malware distributed via a fake Werkbit videoconferencing site requiring a PIN code for access. The Werkbit Setup loader carries a valid Apple developer certificate and passed notarization, bypassing Gatekeeper before fetching CrashStealer from an attacker server. The malware harvests Keychain data, credentials from 14 password managers, browser cookies, and 80 cryptocurrency wallet extensions.

Source: Kaspersky

iOS Exploit Kit DarkSword Spreads Across Multiple Chinese Operators

Censys traced a leaked six-vulnerability iOS exploit chain called DarkSword to at least seven operators running over 180 web properties, mostly hosted in Hong Kong. Researchers used stable panel login page hashes to track infrastructure that otherwise rotates hosts weekly, uncovering a Chinese-speaking operator bundling an Apple ID credential-harvesting decoy directly into exploit-chain staging pages. The chain targets iOS 18.4 through 18.7, deploying keychain, iCloud, and Wi-Fi credential-stealing modules.

Source: Censys

Hijacked LiteLLM Gateways Can Steal AI Keys, Forge Tool Calls

Security researcher wunderwuzzi demonstrated how an attacker with admin access to a LiteLLM AI gateway can reroute traffic through a malicious proxy. The technique harvests backend LLM provider credentials and injects forged responses or tool calls into client applications like Claude Code, bypassing prompt-level defences entirely. Initial access can come from leaked master keys or unpatched vulnerabilities, including CVE-2026-42271, listed on CISA's Known Exploited Vulnerabilities catalogue.

Malware Bypasses Verification to Hijack Google-Synced Passkeys

Researchers detailed three attack techniques against Google's synced passkey ecosystem, allowing malware on a compromised Windows device to authenticate without user interaction or biometric verification. One variant registers an attacker-controlled key to forge user-verification signals, while a further technique extracts the master key from Chrome's memory, enabling decryption of all synced passkeys. eBay and other relying parties fixed the flaws following disclosure, though Google's implementation cannot rotate the extracted master key.

Source: Unit 42

Daily Coverage

Developments
N-Central ExploitationIranian Water AttacksMidnight Blizzard Wi-FiPnld Leak
Vulnerabilities
CVE-2026-18577N-Central (High)CVE-2026-66066Rails < 7.2.3.2 (Critical)CVE-2026-18556N-Central (High)CVE-2026-17583CVE-2026-15409Sma1000 12.4.3-03245 (Critical)CVE-2026-15410Sma1000 12.4.3-03245 (High)CVE-2026-42271Litellm >= 1.74.2, < 1.83.7 (High)CVE-2026-17351Pgadmin 4 9.13 (Critical)CVE-2026-67320Axios 0.31.1 (High)
Threat Groups
Midnight BlizzardAPT29 is threat group that has been attributed to Russia's Foreign Intelligence Service (SVR). They have operated since at least 2008, often targeting government networks in Europe and NATO member countries, research institutes, and think tanks. APT29 reportedly compromised the Democratic National Committee starting in the summer of 2015. In April 2021, the US and UK governments attributed the SolarWinds Compromise to the SVR; public statements included citations to APT29, Cozy Bear, and The Dukes. Industry reporting also referred to the actors involved in this campaign as UNC2452, NOBELIUM, StellarParticle, Dark Halo, and SolarStorm.LAPSUS$LAPSUS$ is cyber criminal threat group that has been active since at least mid2021. LAPSUS$ specializes in largescale social engineering and extortion operations, including destructive attacks without the use of ransomware. The group has targeted organizations globally, including in the government, manufacturing, higher education, energy, healthcare, technology, telecommunications, and media sectors.Scattered SpiderScattered Spider is a native Englishspeaking cybercriminal group active since at least 2022. The group initially targeted customer relationship management (CRM) providers, business process outsourcing (BPO) firms, and telecommunications and technology companies before expanding in 2023 to gaming, hospitality, retail, managed service provider (MSP), manufacturing, and financial sectors. Scattered Spider relies heavily on social engineering, including impersonating IT and helpdesk staff, to gain initial access, bypass multifactor authentication (MFA), and compromise enterprise networks. The group has adapted its tooling to evade endpoint detection and response (EDR) defenses and used ransomware for financial gain. Scattered Spider had expanded into hybrid cloud and identity environments, using helpdesk impersonation and MFA bypass to obtain administrator access in Okta, AWS, and Office 365.INC RansomINC Ransom is a ransomware and data extortion threat group associated with the deployment of INC Ransomware that has been active since at least July 2023. INC Ransom has targeted organizations worldwide most commonly in the industrial, healthcare, and education sectors in the US and Europe.