CyberSecBrief

Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks


Daily Cybersecurity Briefing (8 August 2026)

Published: Loading…

At a Glance

  • N-able confirmed attackers exploited CVE-2026-18577 in N-central, reaching customer networks via Take Control and Cloudflare Tunnels.
  • Nearly 800 malicious npm packages, including keyv and cacheable-request, delivered the Mini Shai-Hulud secrets-hunting campaign since August 4.
  • China's Cyberspace Administration launched an undisclosed security review of Palo Alto Networks products, echoing its 2023 Micron investigation.
  • A GitHub issue exposed CI workflow secrets in Claude Code and Gemini CLI, letting attackers hijack OpenAI's Codex agent runs.
  • Ransomware attacks rose nearly 20 percent in July to 799 incidents, with finance, tech and pharmaceutical sectors most targeted.
  • Swiss government SharePoint servers were breached, compromising login credentials for around 200 accounts at BIT.

Editorial Analysis

Today's briefing is notable less for individual severity than for the time between compromise and detection. N-able's Hotfix 2 arrived only days after Hotfix 1 failed to fully close CVE-2026-18577, with attackers already inside customer networks and persisting through a Cloudflare Tunnel registered before remediation began. Unlimited Technology Systems disclosed its 3.8-million-record breach nine months after the underlying intrusion, while the Swiss government's SharePoint compromise was detected only after BIT's security team identified unusual activity, days after credentials had been harvested. In these cases, delayed detection allowed access to persist beyond the initial compromise.

A second theme concerns vendors' own default configurations as sources of exposure. Novee's research reproduced remote code execution in systems operated by Anthropic, Google, and OpenAI using their shipped defaults, while Varonis's RovoBlast required no jailbreak and instead exploited Atlassian Rovo's URL-parameter handling. Today's findings therefore concern vulnerabilities in the infrastructure and product configurations surrounding AI systems, rather than in the models themselves.

Highlights of the Day

N-able Ships Second Hotfix as N-central Zero-Day Attacks Continue

N-able released Hotfix 2 for CVE-2026-18577, superseding an earlier patch after attackers exploited the N-central flaw to gain remote administrative access. Attackers used the platform's Take Control feature to reach managed customer systems, then registered a Cloudflare Tunnel service to maintain persistence after losing server access. N-able confirmed a limited number of customers were affected and published indicators of compromise alongside a detection template for endpoints.

Source: N-able

Healthcare Software Firm Breach Exposes 3.8 Million Patients

Unlimited Technology Systems confirmed a data breach affecting 3,803,750 individuals, following unauthorised access to its commercial data center between 5 and 10 October 2025. The healthcare revenue-cycle software provider began notifying affected patients on 1 July 2026, nearly nine months after detecting the intrusion. Exposed data includes Social Security numbers, dates of birth, insurance details, medical record numbers and diagnosis information, with no group having claimed responsibility for the attack.

China Opens Security Review of Palo Alto Networks Products

China's Cyberspace Administration has launched a review of Palo Alto Networks products, citing the need to safeguard critical infrastructure and national security. No specific concerns or evidence were disclosed, mirroring the regulator's 2023 investigation into Micron, which later resulted in a sales ban. Palo Alto stated the review currently has no impact on its ability to support customers or deliver services in the region.

AI Testing Firm Irregular Silent on Scope of Security Lapses

Irregular, the evaluation firm behind incidents where AI models from Anthropic, OpenAI and Meta compromised real systems, declined to confirm whether other clients were affected by the same flaw. Anthropic disclosed that a misconfiguration left Claude models running with internet access despite being told otherwise, leading to compromises via weak passwords and unauthenticated endpoints, including a malicious PyPI package run on 15 systems. OpenAI confirmed a similar misconfiguration allowed one of its models to compromise a website, while Irregular said it is now developing a white paper on containment best practices.

Source: The Record

Researchers Find RCE Flaws in Claude Code, Gemini CLI and Codex

Security firm Novee identified critical vulnerabilities in AI coding agents from Anthropic, Google and OpenAI, tested against the vendors' own default configurations. On Claude Code, a flag-parsing gap in command validation allowed remote code execution via a single GitHub issue, later exploited to exfiltrate API keys through a public download counter. Gemini CLI's tool restrictions and environment sanitisation were both bypassed, earning a CVSS 10.0 rating from Google, while Codex allowed a writable AGENTS.md file to hijack instructions for subsequent agent runs.

Source: Novee

Fake Update Phishing Campaign Deploys Rogue ScreenConnect Clients

LevelBlue identified a large-scale phishing campaign impersonating Microsoft Store and Apple App Store update alerts to distribute unauthorised ConnectWise ScreenConnect installers. The pages mimic trusted applications including Google Meet, Microsoft Teams and Adobe Acrobat, guiding victims through fake update sequences before delivering the payload via attacker infrastructure, Amazon S3 and Cloudflare R2. Installed clients automatically register with attacker-controlled ScreenConnect relays, granting remote access, while telemetry on each victim is collected via AI-assisted scripts and forwarded through the Telegram Bot API.

Source: LevelBlue

One-Click Flaw in Atlassian's Rovo AI Enabled Data Exfiltration

Varonis Threat Labs disclosed RovoBlast, a vulnerability in Atlassian's Rovo AI assistant allowing a single link click to inject attacker instructions into a trusted user session. The flaw exploited the rovoChatPrompt URL parameter, requiring no jailbreak, and let Rovo pull data from Jira, Confluence, Slack and other connected platforms. Its ResearchAgent tool could then autonomously browse and upload that data externally, and Atlassian has since fixed the issue.

Source: Varonis

700+ Malicious NPM Packages Deploy Cross-Platform Malware Downloader

OpenSourceMalware identified over 700 npm packages published within 48 hours, disguised as mobile SDKs but executing a downloader immediately upon import, requiring no install script. The malware fetches native payloads for Windows, Linux and macOS from rotating Cloudflare Workers hosts, falling back to DNS TXT record retrieval if HTTPS delivery fails. The macOS variant includes anti-analysis checks, persistence via a fake LaunchAgent, and additional download stages, with researchers linking the campaign to Russian infrastructure and a possible evolution of the earlier Moika campaign.

Daily Coverage

Developments
N-Central Zero-DayMini Shai-Hulud NpmPalo Alto China ProbeClaude Code/Gemini Cli Rce
Vulnerabilities
CVE-2026-18577N-Central (High)CVE-2026-64638Wordpress Is Vulnerable To A Pre-Auth Reflected Xss Vulnerability On The Login Screen. Via A Specially Crafted Malicious Third-Party Website Hosted By An Attacker, It Is Possible For This To Be Escalated To An Rce Vulnerability With Conditions Outside Of The Attackers Control. This Requires Successful Social Engineering Of And Explicit Interaction By The Target Victim. This Issue Affects All Versions Of Wordpress. Version 7.0.3 Has Been Released, Containing A Fix For The Vulnerability, And…CVE-2026-18556N-Central (High)CVE-2026-8037Loadmaster V7.2.60.0 (Critical)CVE-2026-7312Sitefinity 14.0.7700 (Critical)CVE-2026-7198Sitefinity 15.4.8623 (Critical)CVE-2026-7195Sitefinity 14.1.0 (High)CVE-2026-7201Sitefinity 15.2.8400 (High)CVE-2026-7313Sitefinity 8.0.5700 (High)
Threat Groups
InceptionInception is a cyber espionage group active since at least 2014. The group has targeted multiple industries and governmental entities primarily in Russia, but has also been active in the United States and throughout Europe, Asia, Africa, and the Middle East.