Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks
Daily Cybersecurity Briefing (5 August 2026)
Published: Loading…
At a Glance
- ChainDrop, a self-propagating npm worm, compromised over 400 packages across nine organisations within four hours on 4 August 2026.
- CVE-2026-18577, an authentication bypass in N-able N-central, allows unauthenticated remote attackers to gain full administrative control of RMM servers.
- Midnight Blizzard's CaptiveCrunch campaign abuses hotel and conference Wi-Fi captive portals to steal Microsoft 365 credentials and deploy malware.
- Switzerland's Federal Office for Information Technology and Communications had approximately 200 SharePoint accounts compromised via suspected July Patch Tuesday vulnerabilities.
- Fifteen chained vulnerabilities in TP-Link Omada's Zero-Touch Provisioning system enable device spoofing, credential theft, and remote code execution.
- cPanel CVE-2026-58048 (CVSS 9.4) allows authenticated hosting customers to execute arbitrary SQL commands with full database administrative privileges.
Editorial Analysis
Today's briefing is dominated by the ChainDrop supply-chain worm. Within four hours on 4 August, a single compromised maintainer account became the origin of a self-propagating worm that spread across more than 400 npm packages spanning nine organisations, including keyv, flat-cache, and cache-manager. Unlike a conventional package compromise, ChainDrop uses stolen npm tokens to republish itself across every package accessible to the compromised account. It also carries valid SLSA provenance signatures and uses an Ethereum blockchain dead-drop for command and control, while targeting Claude Code and VS Code environments through additional hooks.
The campaign also complicates a conventional incident-response step. ChainDrop's payload is designed to activate when the stolen GitHub token is revoked, meaning credential rotation can trigger execution if the malicious preinstall hook remains in place. The malicious preinstall hook must therefore be removed before the compromised credentials are rotated, otherwise the credential revocation can trigger the worm. ChainDrop additionally demonstrates how legitimate provenance mechanisms can coexist with malicious content: a valid SLSA signature confirms where a package was published, but does not by itself establish that the publishing account was acting legitimately.
Highlights of the Day
Self-Propagating npm Worm Compromises Over 400 Packages
A self-propagating worm named ChainDrop compromised 444 npm packages and 2,212 versions within four hours on 4 August 2026. Attackers hijacked maintainer GitHub accounts to publish poisoned releases carrying valid SLSA provenance, including keyv, flat-cache and file-entry-cache. The payload harvests credentials from developer machines and CI runners, republishes itself using stolen tokens, and communicates via an Ethereum blockchain-based command and control channel.
Microsoft Bounty Program Pays Out Record $20 Million
Microsoft's Bounty Program awarded more than $20 million to 562 security researchers across 64 countries this year, its largest payout to date. This exceeds last year's total of $17 million distributed to 344 researchers from 59 countries. Zero Day Quest, a live hacking event held at Microsoft's Redmond campus, drew researchers from 20 countries who submitted nearly 700 vulnerability reports and earned $2.3 million in awards.
cPanel Patches Critical Flaw Allowing Database Root Access
cPanel patched CVE-2026-58048, a critical flaw letting authenticated customers execute SQL commands with full database administrative privileges. The bug stems from SQL mode not being preserved during database renaming, and may extend to operating-system-level compromise on some configurations. The same release also fixes an HTTP request-smuggling flaw in cpsrvd and an Exim vulnerability allowing privilege escalation via .forward file expansion.
Researchers Find 15 Flaws in TP-Link's Zero-Touch Provisioning System
Forescout Research disclosed 15 vulnerabilities in TP-Link's Omada Zero-Touch Provisioning ecosystem, affecting routers, IP cameras, controllers and mobile apps. The flaws include hard-coded cryptographic keys, insecure credential transmission, and cross-channel scripting in the controller web interface. Combined with two previously disclosed vulnerabilities, researchers demonstrated practical attacks allowing device spoofing, credential theft and network infiltration.
Swiss IT Agency Hacked, 200 SharePoint Accounts Compromised
Switzerland's Federal Office for Information Technology and Communications disclosed that hackers compromised around 200 accounts on its on-premises SharePoint servers. The agency suspects attackers exploited SharePoint vulnerabilities patched in July, several of which appear in CISA's Known Exploited Vulnerabilities catalogue. Initial analysis found no evidence that data beyond login credentials was accessed, and affected servers are being reinstalled as a precaution.
WhatsApp Voting Scam Hijacks Accounts via Linked Devices
A WhatsApp scam uses messages asking recipients to vote in a fake contest, often sent from already-compromised contacts. Clicking the link leads to a page abusing WhatsApp's legitimate Linked Devices feature, tricking victims into authorising a session controlled by the attacker. Once linked, the attacker can read messages, send messages as the victim, and spread the scam to their contacts without triggering typical login alerts.
Daily Coverage