CVE-2008-4128, CVE-2018-0171, CVE-2026-40467, CVE-2026-40468
IP Addresses:
179.43.166.242
Get tomorrow's brief in your inbox
Today: CISA adds an 18-year-old Cisco CSRF flaw to KEV with a 3-day deadline. Russian FSB continues targeting routers worldwide with default credentials. Microsoft deprecates SMS and voice MFA in favor of passkeys starting September 1. Progress Software orders ShareFile customers to shut down Storage Zone Controllers over an active threat.
CISA Adds CVE-2008-4128 to Known Exploited Vulnerabilities Catalog
CISA added CVE-2008-4128 to the KEV catalog based on evidence of active exploitation. This is an 18-year-old cross-site request forgery vulnerability in Cisco IOS with EPSS 12% (96th percentile). The vulnerability is being exploited by Russian FSB Center 16 as part of their ongoing router compromise campaigns targeting critical infrastructure.
Progress ShareFile Storage Zone Controller Threat
Progress Software is ordering customers to immediately shut down Windows servers running Storage Zone Controllers due to a credible external security threat. The company has disabled access to affected accounts as a precaution while working with security experts. No indications of unauthorized access to ShareFile accounts or data have been confirmed yet, but the threat is significant enough to warrant emergency shutdown procedures.
3 claims tracked across 2 groups in the last 48 hours. These are unverified claims from ransomware leak sites, not confirmed breaches.
| Group | Victim | Sector | Country |
|---|---|---|---|
| d1r | Synopsys | Technology | Unknown |
| d1r | ARM | Technology | Unknown |
| d1r | Bosch | Manufacturing | Unknown |
| Syndicate | Nayax | Fintech | Israel |
U.S. Sanctions First VPN Service for Ransomware Support
The U.S. Treasury sanctioned First VPN Service (1VPNS) and its Ukrainian administrator Dmytro Rashevskyi for enabling ransomware attacks on U.S. organizations. First VPN, operational since 2014, advertised no logging and no law enforcement cooperation. The service was dismantled in May 2026 by international law enforcement. Victims included U.S. hospitals, municipalities, financial services firms, and businesses. Treasury also sanctioned Belarusian national Yegeniy Vladimirovich Silayev for selling cryptors to hide ransomware from security tools.
UK and EU Jointly Sanction Russian Cyber Networks
The UK and EU imposed coordinated sanctions on 24 Russian individuals and entities for cyberattacks and disinformation. Targets include GRU senior leadership (Vyacheslav Stafeyev, Ivan Senin, Ivan Kasyanenko), FSB Center 16, GRU Unit 29155 cyber division, and operators behind Lumma Stealer. The EU formally attributed a December 2025 attack on Poland's energy grid to FSB Center 16, which could have left 500,000 citizens without electricity. This is the first joint UK-EU cyber sanctions action, bringing total UK Russia-related sanctions to 3,400.
Russian FSB Center 16 Continues Targeting Network Devices
U.S. and 12 allied countries issued a joint advisory warning that Russian FSB Center 16 continues compromising routers and networking equipment to gain access to critical infrastructure worldwide. Targets include defense, energy, financial services, government, and healthcare sectors. The attackers scan for exposed SNMP services with default or weak passwords, exploit Cisco vulnerabilities (CVE-2008-4128, CVE-2018-0171), and abuse Cisco Smart Install. The NSA emphasized basic router hygiene as a deterrent against state-level actors.
Jscrambler npm Package Compromised in Supply Chain Attack
The Jscrambler npm package was compromised to publish malicious versions 8.16, 8.17, 8.18, and 8.20 containing Rust-based information stealers targeting Windows, macOS, and Linux. The attack used compromised npm publishing credentials. The malware targets credentials, secrets, cloud operator tokens, cryptocurrency wallets, AI coding assistants, MCP server configurations, messaging apps, browsers, Steam sessions, and OS keyrings. NPM data shows 1,479 downloads before the packages were deprecated. The first clean version is 8.22. The attack overlaps with IronWorm activity documented by JFrog. Affected packages include Jscrambler-webpack-plugin 8.6.2, gulp-Jscrambler 8.6.2, grunt-Jscrambler 8.5.2, and Jscrambler-metro-plugin 9.0.2.
148 npm Packages Turned Student Browsers Into DDoS Botnet
148 npm packages disguised as student web proxies turned visitors' browsers into a DDoS botnet for two weeks in May. The packages (names like charlie-kirk, ilovefemboys, miguelphonk) shipped a proxy app branded "Lucide" that worked as advertised while silently loading a remote code loader and WebSocket flood generator. The attack targeted browsers, not developers. Students using the proxy to bypass school filters unknowingly joined the botnet. JFrog analysis found a remote script loader fetching code from GitHub with no integrity checks, plus an HTTP flood module posting 2 MB/second per visitor and a WebSocket module opening 30 connections per browser to a Wisp endpoint injecting malvertising. An archived payload targeted cdn.caan.edu (a nursing school in Illinois) with 2 GB/second from 1,000 open tabs.
ModHeader Extension With 1.6M Installs Pulled for Dormant Collector
Google and Microsoft removed ModHeader, a header-editing extension with 1.6 million installs, after researchers found a hidden browsing-history collector in the official store version. The collector was dormant (empty allow-list kept it switched off), but the infrastructure was complete: device fingerprinting, domain encryption, daily scheduled uploads to api.stanfordstudies.com, and 1000-domain local storage. The collector never ran because the allow-list shipped empty, but enabling it would require only a small update with no new permissions. Automated checkers rated ModHeader 95/100 safe because encrypted data, gated uploads, and minified code frustrated detection. Microsoft pulled Edge listing July 3, Google removed Chrome July 10.
Grok Build Uploaded Entire Git Repositories to xAI Storage
xAI's Grok Build coding CLI uploaded entire Git repositories (full commit history) to xAI-controlled Google Cloud Storage, not just files needed for coding tasks. A researcher captured uploads showing 5.10 GiB sent to /v1/storage while model traffic was 192 KB (27,800x gap). The destination bucket grok-code-session-traces stored tracked files plus history. A test file explicitly marked "never read" was recovered from the captured bundle. When Grok read a .env file, secrets went into model turns and session archives unredacted. The "Improve the model" toggle did not stop uploads. On July 13, xAI shut off storage uploads via server-side switch (no client update), returning disable_codebase_upload: true and trace_upload_enabled: false. xAI has not confirmed if this reaches all accounts or is permanent.
CISA GitHub Leak Postmortem: Key Management and Reporting Gaps
CISA issued a postmortem on a contractor's public GitHub repository leak that exposed 844 MB of internal data for six months, including AWS GovCloud keys and plaintext passwords for dozens of internal systems. CISA took over 48 hours to invalidate AWS keys due to system complexities and interconnections. The report identified gaps: no distinct reporting channels for incidents affecting CISA itself versus its products, contractors ignored nine automated alerts from GitGuardian, and the incident playbook didn't cover GitHub or cloud services. CISA is refining reporting channels, implementing continuous GitHub scanning, and improving secret management.
Microsoft Entra ID Makes Passkeys Default Authentication Method
Microsoft is rolling out passkeys as the default phishing-resistant authentication method in Entra ID starting September 1, 2026. Users enabled for SMS or voice will automatically be enabled for passkeys. On February 1, 2027, Microsoft will retire native SMS and voice authentication. Organizations requiring SMS/voice must choose a telecom provider through the Microsoft Security Store starting September 18. Microsoft Threat Intelligence observed AI-enabled phishing campaigns reaching 54% click-through rates compared to 12% for traditional campaigns. Passkeys use public-key cryptography, making them phishing-resistant by design.
Attacker Uses Suspected AI-Generated PowerShell Script for AD Enumeration
An intrusion in early June 2026 involved an unknown threat actor using an AI-generated PowerShell script for Active Directory enumeration. The script (titled "100% Working AD Information Gathering Script - FULLY FIXED") showed signs of LLM iteration: placeholder strings, over-engineered code with five-step cascading fallback for Domain Controller discovery, and beautified console output. The attacker established RDP access with pre-compromised credentials, staged tools in C:\ProgramData, mapped the AD environment aggressively, then deployed s5cmd and SharpShares for bulk file operations and network share enumeration. Data was exported to CSV files, archived, and exfiltrated, with an HTML summary report created. The incident demonstrates AI lowering barriers to entry for less-skilled attackers while maintaining traditional smash-and-grab tactics.
Forg365 PhaaS Targets Microsoft 365 With Device Code and AitM
A new phishing-as-a-service platform called Forg365 combines device code phishing, adversary-in-the-middle tactics, AI-assisted lure creation, and post-compromise mailbox operations targeting Microsoft 365. The service costs $400/month or $3,800/year, distributed via Telegram. Attack chains use legitimate email infrastructure (Amazon SES, Twilio SendGrid) and Forg365-controlled domains. The platform offers device-auth phishing (Microsoft verification code page authorizing attacker session) and AitM phishing with route tokens, session cookies, and VPN detection for decoy redirection. A Chromium extension called ForgCookie enables automatic SSO cookie refresh. Post-compromise features include keyword monitoring and AI-assisted message drafting.
ShinyHunters Abused OAuth to Target Salesforce for a Year
Microsoft identified year-long campaigns (mid-2025 to mid-2026) by threat actors using tradecraft associated with ShinyHunters to target Salesforce instances via three paths: vishing-driven OAuth consent abuse, supply chain compromise of trusted integrations (Salesloft Drift, Gainsight), and misconfigured guest access. The attacks abused trusted OAuth relationships for unauthorized access, data exfiltration, and persistence without exploiting Salesforce vulnerabilities. Microsoft worked with Salesforce to improve telemetry granularity in Defender for Cloud Apps for near-real-time detection. Google's Mandiant documented related campaigns as UNC6040/UNC6240 (vishing) and UNC6395/GRUB1 (Drift compromise). Known victims include Google, Cloudflare, Zscaler, Palo Alto Networks, Chanel, Pandora, Adidas, Qantas, and LVMH brands.
CVE-2026-40467 and CVE-2026-40468 in gawk
Microsoft published information on two gawk vulnerabilities: CVE-2026-40467 (use after free) and CVE-2026-40468 (heap buffer overflow). No additional details provided in MSRC Security Update Guide.
Critical Zimbra XSS Flaw Patched
Zimbra is urging customers to apply updates for a critical stored cross-site scripting vulnerability in Classic Web Client that could result in arbitrary code execution. Specially crafted emails can execute malicious scripts in a user's session, allowing access to mailbox information, session data, or account settings. The vulnerability has not yet been assigned a CVE identifier.
Microsoft Discloses GigaWiper Backdoor
Microsoft detailed a new post-compromise backdoor called GigaWiper with three destructive capabilities: wipe whole disk, overwrite Windows drive, or run fake ransomware that encrypts with an unsaved key. The malware also takes screenshots, records screens, and launches hidden VNC sessions. Artifacts are similar to BLUERABBIT backdoor assessed to be Iran-nexus threat actor work.
SHELLSTORM Web Shell Campaign Hits 1.4 Million Domains
More than 1.4 million domains targeted in large-scale operation exploiting 27 CVEs in WordPress plugins to deploy web shells. Largest infections in Taiwan, U.S., Germany, France, and U.K. The web shell access is used for further payload delivery. This represents web shell access brokerage at scale.
CrashStealer macOS Malware Uses Notarized Dropper
A new macOS information stealer called CrashStealer uses a signed and Apple-notarized dropper (Werkbit.app) to pass Gatekeeper checks. Unlike AppleScript or Objective-C wrappers, CrashStealer is native C++. It validates login passwords locally, harvests browsers, cryptocurrency wallets (80+ extensions), password managers (14 apps), and keychain data, encrypts with AES-GCM, and exfiltrates over libcurl to 179.43.166.242. The dropper originates from werkbit.io (registered June 2026) and gates downloads behind a meeting PIN. The installer contacts github.com/mgothiclove to retrieve a curl command that downloads CrashReporter.dmg. The malware persists as a LaunchAgent and resists analysis through control-flow flattening, encrypted strings, and anti-debugging.
MemGhost Attack Plants False Memories in AI Agents
Researchers demonstrated stealth memory injection attacks against AI agents with persistent memory. A single email can trick an agent into saving false information, hiding the change, and steering later responses. The attack targets agents like OpenClaw that store state in plain text files (MEMORY.md, AGENTS.md). The MemGhost tool achieved 87.5% success against GPT-5.4 and 71.4% against Claude Sonnet 4.6 in background-mode tests. Success was lower in foreground mode where users see replies. Crude versions ("save this quietly") fail against strong models, but trained adversarial payloads bypass defenses.
Context Bombing: Defensive Prompt Injection
Researchers from Tracebit demonstrated "context bombing," using prompt injections as a defensive technique. Planting forbidden prompts (e.g., Anthrax spore development steps, Tiananmen Square Tank Man references for Chinese LLMs) alongside secrets in AWS environments triggers LLM refusal mechanisms, shutting down AI hacking agents. Testing against Opus 4.8, Gemini 3.1 Pro, GLM 5.2, DeepSeek 4 Pro, and Kimi 2.6 showed planting one string cut full admin compromise from 57% to 5% across 152 attack runs. Opus 4.8 went from 93% admin access to 0% when confronting context bombs.
SQL Injection Leads to BadIIS Persistence
Huntress SOC documented a June incident where an attacker exploited SQL injection on a web page with insufficient input validation to gain access to an MSSQL instance. The attacker used base64-encoded PowerShell to download scripts, ran reconnaissance (tasklist /svc), exfiltrated results to 334thribetlhkyo977gqrcht1k7bvdj2.oastify.com, enabled Remote Desktop Services, created adminweb2$ account with local administrator privileges, and installed BadIIS modules (HttpFastCgiModule.dll, HttpCgiModule.dll) using appcmd.exe. The attacker disabled Windows Defender but did not target EDR.
Federal Election Defense Networks Eroding
State election officials report federal support is evaporating after Trump administration fired EAC commissioners and DOJ sent warning letters threatening criminal prosecution for election officials. CISA has largely gone quiet on cybersecurity support to states. Oregon and Arizona are building their own defense networks. Oregon ranks top 10 in voter participation, relies on mail-in voting, and is urging drop box use over USPS after Iranian hackers defaced Arizona's candidate bio portal last year.
Microsoft Windows 10 Extended Support
Microsoft is emailing Windows 10 holdouts offering Extended Security Updates for another year. Windows 10 support officially ends October 14, 2025, but Microsoft is extending ESU availability through October 2026 for $30/year for consumers.
Three patterns stand out today. First, legacy vulnerabilities remain high-value targets: an 18-year-old Cisco CSRF flaw just made CISA's KEV list because Russian state actors are actively exploiting it alongside even older flaws (CVE-2018-0171) to compromise routers worldwide. Second, trusted infrastructure is the new attack surface: OAuth relationships (Salesforce), notarized apps (CrashStealer), signed extensions (ModHeader), and npm packages (Jscrambler, student proxies) all provide cover for malicious operations by appearing legitimate. Third, AI is accelerating both sides: attackers are using LLMs to generate AD enumeration scripts and phishing emails at scale, while defenders are experimenting with "context bombing" to weaponize LLM safety mechanisms against attacking agents. The gap between trusted and trustworthy is widening faster than defensive visibility can close it.