← Carolina Clear Tech

Cyber Threat Brief

2026-08-05

Listen to this brief (22:16)

Download MP3
Show Notes

Show Notes - 2026-08-05

Stories Covered

CVEs Referenced

CVE-2026-15409, CVE-2026-15410, CVE-2026-17583, CVE-2026-18411, CVE-2026-18556, CVE-2026-18577, CVE-2026-34486, CVE-2026-58047, CVE-2026-58048, CVE-2026-9198

Indicators of Compromise

IP Addresses: 207.174.0.143, 3.0.51.0, 11.110.0.137, 11.118.0.71, 11.126.0.78, 11.134.0.48, 11.136.0.32

Read the full brief

Get tomorrow's brief in your inbox

Protect Your Business

Need a security assessment? See our cybersecurity packages.

View Services

Today: INC ransomware is actively exploiting the SonicWall zero-day pair with rapid deployment times. CISA added three critical flaws to KEV including Langflow RCE, N-able auth bypass, and Apache Tomcat encryption bypass. Microsoft published details on ChainDrop, a supply chain worm that poisoned 400+ npm packages and self-propagates using stolen credentials.

Critical Alerts

SonicWall Zero-Days Exploited by INC Ransomware (CVE-2026-15409, CVE-2026-15410)

INC ransomware has emerged as the primary threat actor exploiting the SonicWall vulnerability chain disclosed July 14. The group has claimed nearly 900 victims across 71 countries and is now weaponizing both CVEs together for full access to vulnerable appliances. While initial exploitation began June 22 from common hosted infrastructure, INC's post-disclosure activity shows significantly faster operational tempo, moving from initial access to ransomware deployment rapidly. Huntress researchers spotted 30 SonicWall customers compromised in under two days last week. Both CVEs are CISA KEV entries with EPSS scores in the 99-100th percentile and a remediation deadline of July 17 (already passed). Ten of 17 SonicWall KEV entries since 2021 are linked to ransomware campaigns.

CISA KEV Additions: Langflow, N-able, Tomcat (CVE-2026-9198, CVE-2026-18556, CVE-2026-34486)

CISA added three actively exploited vulnerabilities to KEV on August 4 with a remediation deadline of August 7. CVE-2026-9198 (CVSS 9.8) is a code injection flaw in Langflow allowing unauthenticated RCE on default deployments by chaining an auto-login endpoint with a code validation endpoint. Fixed in Langflow 1.10.1 (July 2026). CVE-2026-18556 and CVE-2026-18577 (CVSS 8.2, 7.4) are authentication bypass flaws in N-able N-central exploited as zero-days to gain admin access and connect to managed systems. The initial fix was bypassed, prompting CVE-2026-18577. CVE-2026-34486 (CVSS 7.5) is an EncryptInterceptor bypass in Apache Tomcat that turns encryption from fail-closed to fail-open, enabling unauthenticated RCE on cluster members. Fixed in Tomcat 11.0.21, 10.1.54, 9.0.117 (April 2026). Chinese threat actors are exploiting CVE-2026-34486 in AI-enabled autonomous hacking campaigns using DeepSeek via the Hermes Agent framework.

Ransomware Claims (Last 48h)

Group Victim Sector Country
orova BJS Insurance & Financial Insurance US
orova Wisdom Oral Surgery Healthcare US
orova SURE TRAVEL COMPANY Travel Hong Kong
orova Cardiology Associates Healthcare US
orova Yost Home Improvements Construction US
orova KINGSSON Manufacturing Taiwan
orova SSI HOLDING (FAR EAST) LIMITED Holding Company Hong Kong
orova Sanrio Hong Kong Co., Ltd Retail Hong Kong
orova Tat Fung Textile Co., Ltd. Manufacturing Hong Kong
orova Integrated Site Management Real Estate US

10 claims tracked from the orova group in the last 48 hours. These are unverified claims from ransomware leak sites, not confirmed breaches.

Ransomware & Extortion

Microsoft Defender Adds Device Isolation to Attack Disruption

Microsoft announced device isolation as a new autonomous response action in Defender attack disruption. At QNET, Defender isolated a compromised endpoint 128 seconds after the first high-severity alert when an attacker used a living-off-the-land technique to retrieve a remote payload via a legitimate Windows tool. Device isolation blocks all external network connectivity while maintaining access to required security services, cutting off lateral movement, command and control, credential theft, and rapid encryption. The action is time-limited, operator-controlled, and scoped to affected devices. It complements existing user containment and is enforced only when the disruption pipeline reaches 99% precision confidence.

IOCs & Detection

45% of Malware Samples Bypass DNS Using Direct-to-IP Connections

Palo Alto Networks Unit 42 analyzed 4 million dynamic analysis reports and found 45.32% of malware samples with C2 activity made at least one direct-to-IP connection, bypassing DNS entirely. Measured as a fraction of all C2 connection attempts, D2IP traffic accounts for 23.17% of the total. Zero trust IP (ZT-IP) analysis surfaced Phorpiex ransomware droppers connecting directly to C2 IPs, persistent data exfiltration campaigns using custom obfuscated HTTP GET requests, and Mozi P2P botnet payloads delivered to IoT devices without DNS. TCP dominates D2IP traffic (94.43% prevalence, averaging 4.17 unique C2 IPs per sample), while UDP contacts far more addresses per sample (average 13.79) consistent with scanning and P2P mesh behavior.

Business & Infrastructure Threats

ChainDrop Supply Chain Attack: 400+ npm Packages Poisoned with Self-Propagating Worm

Microsoft Threat Intelligence identified a large-scale npm supply chain attack affecting more than 400 packages across multiple unrelated publishers including keyv, flat-cache, cache-manager, and others. The malicious releases contain a Mini Shai-Hulud variant, a self-propagating credential-stealing worm delivered through a heavily obfuscated Bun-based JavaScript payload executed via npm preinstall lifecycle hooks. The campaign began after a GitHub account compromise and started with 11 malware carriers in the keyv and cacheable namespaces (combined 500 million weekly downloads), then self-propagated to 433 additional packages. The malware searches for npm, GitHub, cloud, and infrastructure credentials, authenticates to npm, GitHub, AWS, Kubernetes, and HashiCorp Vault, and uses recovered npm tokens to enumerate packages, inject malware, increment patch versions, and republish. It also injects Claude and VS Code config files into repositories for developer-to-developer infection. The worm uses Ethereum blockchain for C2 (EtherHiding) and installs a dead-man's switch that polls GitHub API every 60 seconds and self-deletes if the token stops working or after 24 hours.

Smoke#Screen Campaign Delivers ScreenConnect via Rotating Social Engineering Lures

Securonix disclosed an active multi-wave campaign delivering ConnectWise ScreenConnect RMM agents via diverse social engineering lures including fake Zoom and Adobe updates, business document reviews, and system maintenance utilities. The campaign uses a toolkit of VBScript droppers, batch file loaders, compiled .NET executables, and HTML phishing pages, all pointing to a live WsgiDAV staging server at 207.174.0.143:8080. Successful attacks install a ScreenConnect agent beaconing to one of three attacker-controlled relay servers. The campaign rotates payloads between download sessions (making hash-based detection ineffective) and uses four psychologically different lure contexts to maximize victim population. Delivery leverages Dropbox shared links and Cloudflare Quick Tunnels to bypass domain reputation filters. One batch script variant disables Windows AMSI, escalates privileges via UAC, turns off SmartScreen, and removes Zone.Identifier ADS from downloaded MSI files before execution.

Frontier AI Autonomous Vulnerability Discovery: 14,090 OSS Vulnerabilities in Two Months

Palo Alto Networks Unit 42 built NOVA, an autonomous vulnerability discovery system powered by multiple frontier AI models. In two months, NOVA analyzed 3,915 OSS projects and uncovered 14,090 confirmed vulnerabilities, 99.4% previously unreported and 40% designated high or critical severity. The system performs project history review, source code reading, vulnerability candidate identification, PoC creation, deterministic validation, patch generation, and disclosure report production with no human in the loop until final review. Nearly every frontier and open-weight model could find real vulnerabilities, with strongest results from an ensemble approach. The research demonstrates AI fundamentally shifts vulnerability discovery dynamics, compressing the patch window and making virtual patching critical. Unit 42 is partnering with Lightwell and Akrites for responsible disclosure.

Greatness PhaaS Adds Device Code Phishing to Bypass MFA

The Greatness phishing-as-a-service platform now supports adversary-in-the-middle token theft, device code phishing, and OAuth consent abuse from a unified operator panel. Subscriptions start at $289/month (up from $120 in January 2024) via Telegram (@GreatnessPage, 3,250+ subscribers). The platform targets Microsoft 365, iCloud, Yahoo, and Google Workspace and provides 11+ downloadable lure templates (voicemail, document sharing, QR codes). Device code phishing abuses OAuth 2.0 Device Authorization Grant to bypass MFA. Operators access the panel via O365 Panel login page requiring user ID and 9-character license key, with dashboard providing campaign statistics, captured cookies, heat maps, and downloadable templates.

QuickFox VPN Supply Chain Attack Delivers FDMTP Backdoor Since August 2025

Fortinet disclosed a long-standing supply chain attack on QuickFox, a VPN and network acceleration tool for overseas Chinese users. The attack has been ongoing since at least August 2025 and involves a trojanized Windows installer delivering FDMTP, a Mustang Panda backdoor. The attack uses a modified Electron renderer HTML file to download and execute a JavaScript loader that fingerprints the victim, checks for Steam (aborts if present), validates at least one process from a list of 26 domestic applications/crypto wallets/developer tools is running, then downloads FDMTP via DLL side-loading. QuickFox removed malicious components in version 3.59.6 (released between July 25 and August 13, 2025). Earliest affected version was 3.0.51.0. The campaign solely targeted Windows users.

Kaspersky: Cloud Platforms Enable Phishers to Bypass MFA via AitM Attacks

Kaspersky reported phishing operators increasingly exploit legitimate cloud services (Cloudflare Workers, Vercel, Netlify, GitHub Pages, IPFS) to evade detection and streamline scam infrastructure. These platforms offer inherent trust and reputation, generous free-tier developer plans with minimal KYC, and native security features that obscure origin server IPs behind CDNs. A recent AitM campaign leveraging Cloudflare Workers executed multi-stage attacks through compromised websites and cloud-hosted pages. The first stage harvests target email addresses via fake CAPTCHA on compromised sites, embeds email in URL hash to avoid server requests, then redirects to workers.dev subdomain. The second stage presents genuine CAPTCHA, then initializes transparent proxy to capture MFA sessions. Shared subdomains hosting millions of legitimate projects cannot be blocked without collateral damage, requiring content-based analysis.

General Security News

Unitel Angola Hit by Cyberattack Hours Before IPO

Unitel, Angola's dominant mobile operator (66-76% market share), suffered a cyberattack on July 28 at 2:20 AM, the same day the government closed a 15% public offering raising $320 million. The attack caused widespread outages. Unitel restored 2G/3G service July 30 and SMS service July 31, but 4G/5G and digital services continue experiencing problems. The disruption caused financial services like Multicaixa Express (62% of financial transactions over networks in 2025) to fail, forcing businesses in Luanda to revert to cash. Unitel's stock rose 25% on IPO day then declined 13% the next day. No attribution or technical details disclosed.

cPanel Critical Flaw: SQL Execution as Database Root (CVE-2026-58048)

cPanel patched CVE-2026-58048 (CVSS 9.4), a privilege escalation flaw allowing authenticated hosting customers to execute SQL commands in the database's root context. The flaw affects all supported cPanel & WHM versions and WP Squared. Exploitation requires a valid cPanel account and access to MySQL/MariaDB feature. Depending on OS and database configuration, this may extend to OS-level compromise. The failure sits in the database-renaming process where SQL mode is not preserved, causing SQL to execute in root context. Also patched: CVE-2026-58047 (CVSS 5.6), an HTTP request smuggling issue in cpsrvd allowing unauthenticated remote attackers to manipulate responses and potentially leak credentials.

Patch Priority

Vulnerability Disclosures

Thermo Fisher Genetic Analyzers (CVE-2026-17583)

CISA published an ICS medical advisory for Thermo Fisher Applied Biosystems Genetic Analyzers. CVE-2026-17583 allows attackers to modify .fsa/.hid output files, tampering with DNA data and resulting in inaccurate test results. Affected products include Data Collection Software versions for 3500/3500xL, 3730/3730xL, SeqStudio, SeqStudio Flex, GeneMapper ID-X, 3130 Series, ABI PRISM 3100/3100-Avant, and ABI PRISM 310. Thermo Fisher released security updates implementing digital signatures on instrument software for all currently supported products. 3130 Series, ABI PRISM 3100/3100-Avant, and ABI PRISM 310 are End of Life with no updates provided.

Acrisure KARR BT and DR-100 Anti-Theft Systems (CVE-2026-18411)

CISA published an ICS advisory for Acrisure KARR BT and DR-100 dealer-installed automotive anti-theft systems. CVE-2026-18411 involves a shared Bluetooth authentication key across all affected devices. An attacker within Bluetooth range can issue unauthorized commands including door unlocking, engine immobilization, horn honking, and light flashing. Acrisure released firmware update July 20, 2026, available at karrsecurity.com. Affects more than 2 million vehicles in the US.

Trends & Context

Today's stories reflect three major trends: the continued exploitation of internet-exposed management interfaces (SonicWall, N-able, Tomcat) by ransomware groups with increasingly rapid deployment times; the maturation of supply chain attacks from one-off compromises to self-propagating worms (ChainDrop) that autonomously spread across package ecosystems; and the emergence of AI as both an offensive capability (autonomous vulnerability discovery, AI-enabled hacking campaigns) and a new attack surface (prompt injection, agent-to-agent attacks). The SonicWall and N-able incidents demonstrate that RMM and security appliance vendors remain high-value targets, while the ChainDrop worm shows attackers are building sophisticated automation that rivals legitimate CI/CD pipelines in complexity.