CVE-2025-68613, CVE-2026-20896, CVE-2026-27771, CVE-2026-41679, CVE-2026-59774, CVE-2026-60004, CVE-2026-63077, CVE-2026-64531
Hashes:
a8460f446be540410004b1a8db4083773fa46f7fe76fa84219c93daa1669f8f2
IP Addresses:
163.7.8.79
Get tomorrow's brief in your inbox
Today: JetBrains TeamCity CVE-2026-63077 added to CISA KEV with federal agencies facing an August 8 deadline. Ransom Cartel creator sentenced to 16 years, Snowflake hacker pleads guilty over breaches affecting 100 million people, and 321 n8n instances exposed via leaked GitHub API tokens. Critical Gitea file-read flaw allows unauthenticated attackers to read server files via Org-mode markup.
JetBrains TeamCity CVE-2026-63077 RCE Under Active Exploitation
CISA added CVE-2026-63077 to the Known Exploited Vulnerabilities catalog on August 5, confirming active exploitation of the critical deserialization flaw affecting all TeamCity On-Premises versions. The vulnerability (CVSS 9.8) allows unauthenticated attackers to bypass authentication via the agent polling protocol and execute arbitrary OS commands with TeamCity server process privileges. Successful exploitation exposes TeamCity data, configurations, stored credentials, and can compromise CI/CD pipelines and build artifacts. EPSS scoring shows low predicted exploitation likelihood (0.006, 48th percentile), but confirmed exploitation makes this a priority target.
Gitea Critical File Read Vulnerability CVE-2026-59774
Unauthenticated attackers can read any file accessible to the Gitea service account in versions 1.22.1 through 1.27.0 using crafted Org-mode markup submitted to public repositories. The flaw (CVSS 9.8) stems from Gitea's Org-mode renderer not overriding the go-org library's default ReadFile callback, allowing #+INCLUDE directives with absolute paths to retrieve server filesystem content. Gitea's advisory describes an escalation chain where attackers read app.ini, extract INTERNAL_TOKEN, inject Git hooks through the internal logger, and achieve command execution during anonymous clone operations. The file-read primitive was publicly previewed before formal disclosure.
OVSwrap Linux Kernel Local Privilege Escalation CVE-2026-64531
A memory corruption flaw in the Linux kernel's Open vSwitch datapath (CVSS 7.8) gives ordinary local users a path to root on default-configured distributions. The vulnerability requires no existing OVS bridge, no running ovs-vswitchd, and no host-level CAP_NET_ADMIN. Attackers create unprivileged user and network namespaces to gain namespace-scoped CAP_NET_ADMIN and reach the vulnerable flow-installation path. A public exploit with pre-built records for roughly 800 kernel builds ships with logic-bug-grade reliability. Fixed in stable trees July 24 (5.15.212, 6.1.178, 6.6.145, 6.12.97, 6.18.40, 7.1.5), but distribution kernels carry backports requiring vendor-specific tracking.
Leaked n8n API Tokens Expose 321 Live Instances
GitGuardian researchers found 321 n8n workflow automation instances accepting API tokens exposed in public GitHub commits, representing 36% of reachable instances tested. The tokens provide authenticated access to workflow definitions, execution data, and stored credentials for databases, source repositories, cloud environments, and AI services. Four documented attack techniques require only standard REST API calls with no CVE exploitation. The exposure is compounded by 58% of scanned instances running versions affected by known security advisories, including CVE-2025-68613 (CVSS 9.9, CISA KEV, EPSS 0.979 at 100th percentile) confirming exploitation in the wild.
2 claims tracked across 2 groups in the last 48 hours:
| Group | Victim | Sector | Country |
|---|---|---|---|
| dark project | Thermo King | Manufacturing | Not specified |
| panzer | Festina Group | Retail/Jewelry | Not specified |
| panzer | Surakarta University | Education | Indonesia |
These are unverified claims from ransomware leak sites, not confirmed breaches.
Ransom Cartel Creator Sentenced to 16 Years
Maksim Silnikau, 40, received 16 years in federal prison for creating and operating Ransom Cartel ransomware-as-a-service from 2021 to 2023. Operating under handles "J.P. Morgan," "lansky," and "xxx," Silnikau built the infrastructure including locking software, credential marketplace, hidden affiliate panel, and cryptocurrency mixer integration. The operation attacked at least 18 companies in California, New York, Nebraska, and abroad between 2021 and 2023. Silnikau purchased credentials from initial access brokers, ran affiliate ratings systems, and split proceeds with attackers. The sentence exceeds the 13 years seven months given to Yaroslav Vasinskyi for 2,500+ REvil attacks and $700 million in ransom demands. Silnikau faces unresolved charges in New Jersey over the Angler Exploit Kit malvertising scheme (2013-2022), and co-defendants Volodymyr Kadariya ($2.5M State Department reward) and Andrei Tarasov (Secret Service wanted list) remain at large.
Snowflake Hacker Pleads Guilty Over 165 Organization Breaches
Connor Riley Moucka, 26, pleaded guilty August 5 in Seattle federal court to computer fraud, wire fraud, aggravated identity theft, and conspiracy charges over 2024 Snowflake customer account breaches affecting at least 165 organizations and exposing records of at least 100 million people. Moucka personally collected at least $495,000 from ransoms and data sales. The intrusions relied on credentials harvested by infostealer malware years earlier (some from November 2020) that were never rotated, with targeted accounts lacking MFA. Mandiant found 79.7% of compromised accounts had prior credential exposure, and compromised instances had no network allow lists. Stolen data included call/text history, payroll records, DEA registration numbers, passport and Social Security numbers. AT&T confirmed records for nearly all cellular customers from May 1 to October 31, 2022 were taken. Sentencing scheduled October 27, faces two-year mandatory minimum and up to 30 years. Co-defendant John Erin Binns remains outside US custody.
22-Second Automated SSH Compromise Chain
Automated SSH actors are achieving full persistence in 22 seconds using pre-scripted playbooks executing immediately after successful authentication. On May 23, 2026, source IP 163.7.8.79 authenticated to a Cowrie honeypot using compromised credentials (root / Aa123123123) and within 22 seconds injected a backdoor SSH key (hash: a8460f446be540410004b1a8db4083773fa46f7fe76fa84219c93daa1669f8f2), changed the root password, cleared /etc/hosts.deny, and performed automated reconnaissance. The attacker removed existing .ssh directories before key injection to eliminate legitimate access. The source returned multiple times throughout the day executing identical command sequences. A single honeypot captured 112,000+ SSH sessions and 72,000+ authentication attempts from 175+ unique malicious IPs over 30 days, with 21 successful logins from 21 different sources on May 23 alone clustered between 01:00-02:30 UTC.
NullReceiver: Blockchain C2 Concealment via Empty Ethereum Transfers
Trojanized npm packages "bianira-ui" and "fluid-type-ui" employ NullReceiver, an evolution of EtherHiding blockchain-based C2 that conceals the C2 server IP address inside the destination address of a completely empty Ethereum transfer. The technique decodes attacker infrastructure from blockchain transactions, providing a resilient dead drop resolver that survives traditional C2 blocklists.
Paperclip AI Agent Platform Flaws Allow Host Command Execution CVE-2026-41679
Two security flaws in Paperclip AI agent control plane allow attackers to execute commands on network servers or developer computers by importing malicious agents. CVE-2026-41679 (CVSS 10.0) affects network-accessible authenticated deployments using default registration configuration, requiring no pre-existing account or victim interaction. GHSA-x8hx-rhr2-9rf7 (CVSS 9.6) targets local_trusted mode (default), requiring a user to open an attacker-controlled page while Paperclip is running. Both paths exploit Paperclip's process adapter which intentionally launches configured commands as child processes. Attackers could register without invitation, create and approve CLI challenges, import malicious agent configurations defining new companies, and execute arbitrary commands with server process privileges. Fixed in v2026.416.0, which requires instance-administrator access for imports targeting new companies. Rapid7 shipped a public Metasploit module, CISA SSVC classifies as proof-of-concept, EPSS 0.020 (78th percentile).
keyv/cacheable npm Worm Propagates via AI Agent Configuration Files
The keyv/cacheable npm supply chain compromise (active since August 4, 2026) affects 440+ packages across 2,000+ versions and propagates as a worm by stealing npm tokens and republishing trojanized versions. The malware executes via preinstall hooks and through IDE configuration files (.claude/settings.json SessionStart, .vscode/tasks.json folderOpen) that trigger when directories are opened, requiring no npm install. Payload downloads standalone Bun runtime, harvests AWS metadata, cloud keys, Vault tokens, Kubernetes service accounts, GitHub Actions secrets, npm tokens, and private keys, then uses stolen npm credentials to inject hooks into other accessible packages. A host-level dead-man's switch installed as macOS LaunchAgent or Linux systemd user service polls GitHub API every 60 seconds and triggers remote-supplied handler when stolen token is revoked. The watcher self-destructs after 24-hour TTL or successful token revocation.
Chinese Zbtlink Routers Ship With Factory Backdoor
At least 20 Chinese router models from Zbtlink ship with factory-implanted backdoors in all 21 firmware images spanning 2+ years. The backdoors start automatically and beacon to Chinese infrastructure, opening unauthenticated root shells.
macOS ClickFix Campaign Adopts Server-Side Fingerprinting
Microsoft Threat Intelligence observed a macOS ClickFix campaign distributing MacSync and Atomic Stealer (AMOS) through 250+ algorithmically named domains that evolved from openly serving malicious commands to concealing lures behind server-side browser-fingerprinting gates. The gate shows Terminal command payloads only to visitors whose environment appears consistent with a genuine macOS browser, hiding from crawlers and sandboxes. Windows browsers receive decoy pages (fake browser extensions, VPN landing pages, or unrelated business impersonations). The technique allows ClickFix to bypass quarantine handling, code-signing evaluation, and notarization checks typically applied to downloaded macOS applications.
AI Agent Security Flaws Enable Cross-Agent Attacks
Multiple AI agent platforms (Google ADK, AWS, Vercel) patched flaws allowing low-privileged public-facing agents to trigger commands executed by high-privileged agents. Google ADK for Python (90M+ downloads) allowed prompt injections in GitHub pull requests to exploit trust boundaries between agents with different privilege levels, creating pathways to approve or execute malicious code in CI/CD workflows. The attacks demonstrate agent-to-agent exploitation as a new privilege-escalation surface. AWS, Google, and Vercel flaws let untrusted instructions reach agent tools without verifying model authorization, with some attack paths bypassing the model entirely.
Attackers Compile Post-Exploitation Toolkit Inside Oracle Databases
Attackers used SQL injection to feed Java source code to Oracle databases, compiling khunt post-exploitation toolkit as stored schema objects and executing commands from inside the database engine without writing executables to disk. The technique demonstrates a new approach to deploying post-exploitation tools that evade file-based detection.
CVE-2026-63077: JetBrains TeamCity Deserialization RCE - Covered in Critical Alerts
CVE-2026-59774: Gitea Org-Mode File Read - Covered in Critical Alerts
CVE-2026-64531: OVSwrap Linux Kernel Privilege Escalation - Covered in Critical Alerts
CVE-2026-41679: Paperclip AI Agent Command Execution - Covered in Business & Infrastructure Threats
CVE-2025-68613: n8n Expression Injection - CISA KEV added March 11, 2026, CVSS 9.9, EPSS 0.979 (100th percentile), confirmed exploitation in wild
Gitea CVE Cluster
Critical and high-severity Gitea vulnerabilities recently disclosed include CVE-2026-60004 (RCE, patched in 1.27.1), CVE-2026-20896 (Docker reverse-proxy authentication bypass observed under active probing 13 days post-disclosure, EPSS 0.318 at 98th percentile), and CVE-2026-27771 (container-registry access control flaw affecting 30,000+ deployments across 30+ countries, EPSS 0.431 at 99th percentile).
Veeam, Terraform MCP, Django Patch Critical Flaws
HashiCorp, Veeam, and Django patched 11 vulnerabilities including a CVSS 9.5 unauthenticated flaw in Veeam Service Provider Console exposing managed agent credentials, a CVSS 10.0 cross-tenant flaw in HashiCorp's MCP server allowing Terraform token reuse across user sessions, and multiple Django vulnerabilities.
Open VSX Removes 77 Malicious Evil Twin Extensions
Open VSX marketplace removed 77 malicious extensions impersonating legitimate developer tools that exfiltrated system and development environment information. The evil twin extensions were uploaded July 26 to August 1, 2026.
This brief surfaces three converging attack patterns: automated exploitation reaching from authentication to persistence in under 30 seconds (SSH botnets, npm worms with dead-man's switches), AI agent platforms introducing new trust boundaries that attackers are learning to cross (agent-to-agent privilege escalation, model bypass), and supply chain compromises weaponizing developer tooling configuration files as first-class execution surfaces (.claude/, .vscode/ triggering on folder open, not just package install). The Snowflake guilty plea and Ransom Cartel sentencing demonstrate law enforcement closing on 2024-era credential-stuffing and RaaS operators, while the TeamCity KEV addition and 22-second SSH compromise show defenders still racing automated post-exploitation. The shift from hoping credentials expire to actively embedding switches that punish remediation (keyv/cacheable) marks adversary adaptation to defensive playbooks.