← Carolina Clear Tech

Cyber Threat Brief

2026-08-08

Listen to this brief (16:59)

Download MP3
Show Notes

Show Notes - 2026-08-08

Stories Covered

CVEs Referenced

CVE-2007-3205, CVE-2016-2568, CVE-2018-1128, CVE-2018-5407, CVE-2018-6829, CVE-2019-6706, CVE-2019-9192, CVE-2019-9924, CVE-2025-62725, CVE-2026-18556, CVE-2026-18577, CVE-2026-32597, CVE-2026-44943, CVE-2026-44944, CVE-2026-48524, CVE-2026-55995, CVE-2026-63078, CVE-2026-68480, CVE-2026-6879, CVE-2026-8037

Indicators of Compromise

IP Addresses: 173.249.252.176, 173.249.252.200, 185.156.46.150, 23.234.94.43, 37.153.90.88, 37.19.210.32, 68.235.46.214, 68.235.46.235, 87.249.138.34, 92.118.112.181, 192.42.116.58, 192.42.116.105, 146.70.139.154

Read the full brief

Get tomorrow's brief in your inbox

Protect Your Business

Need a security assessment? See our cybersecurity packages.

View Services

Today: N-able releases second emergency hotfix as attackers persist in customer networks via Cloudflare tunnels. CISA adds Progress LoadMaster command injection to KEV after 792 exploit attempts. Metabase warns of maximum-severity zero-day enabling unauthenticated admin takeover and SQL injection.

Critical Alerts

N-able N-central Hotfix 2 Released as Attackers Persist (CVE-2026-18577, CVE-2026-18556)

N-able released a second emergency hotfix for N-central after confirming attackers reached managed customer systems and established persistence using Cloudflare tunnels. CVE-2026-18577 (CVSS 8.2) is an incomplete fix for CVE-2026-18556 (CVSS 8.2), both allowing authentication bypass and account takeover. CISA added both to KEV with due dates of August 6-7, 2026. Attackers used Take Control feature to access managed endpoints, then registered Cloudflare tunnel services for persistence that survived N-central access revocation. EPSS scores are 0.041 (90th percentile) for CVE-2026-18577 and 0.005 (40th percentile) for CVE-2026-18556, indicating active exploitation despite relatively low predicted exploitation probability at time of KEV addition.

Metabase Zero-Day Allows Unauthenticated Admin Access (No CVE, CVSS 10.0)

Metabase disclosed a maximum-severity zero-day allowing unauthenticated SQL injection into the application database, enabling admin access without authentication. Attackers can change configuration, steal database credentials, read connected data, and export data. Metabase Cloud already patched. Framework PC maker confirmed breach affecting customer names, IPs, addresses, phone numbers, and emails.

Progress LoadMaster Command Injection Added to CISA KEV (CVE-2026-8037)

CISA added CVE-2026-8037 (CVSS 9.6) to KEV following active exploitation. The command injection flaw in Progress Kemp LoadMaster allows unauthenticated attackers to execute arbitrary commands via unsanitized input in multiple command endpoints. eSentire reported 792 exploitation attempts over 41 days from 65 unique IPs across 18 countries. EPSS score is 0.848 (100th percentile), indicating extremely high predicted exploitation activity.

Ransomware & Extortion

City of Coweta, Oklahoma Hit with Ransomware

Coweta experienced a system-wide ransomware attack on August 5, 2026. The city contacted IT providers and cybersecurity professionals to secure systems and prevent further intrusion. Officials stated they have backups for recovery.

Victorian Court Data Leaked to Dark Web (Australia)

Personal information of Victorian court users was posted on the dark web in July 2026, triggering a police investigation. Names, emails, and job titles of people who attended online hearings in regional courts were published on an underground hacking forum. A user claimed responsibility.

UNC6671 Data Extortion Operations (Redact, Pink, Helix, Falcon Brands)

Google and Mandiant report UNC6671 continues vishing attacks against financial services, private equity, and professional services in North America, Australia, and UK. Attackers pose as IT help desk via personal mobile devices, directing victims to AitM phishing portals capturing credentials and MFA tokens. Automated Python and PowerShell scripts exfiltrate data from Microsoft 365 and Okta. Group operates under multiple brands: Redact, Pink, Helix, and Falcon, after retiring BlackFile brand in May 2026.

Business & Infrastructure Threats

Microsoft 365 AitM Phishing Campaign Targets Payroll Systems

Arctic Wolf Labs reports widespread AitM phishing campaign hijacking Microsoft 365 accounts to identify and collect payroll and finance personnel email. Campaign uses residential proxies to disguise sign-ins as consumer traffic, with automated activity maintaining sessions at eight-hour intervals. Impacts healthcare, education, manufacturing, government, and professional services in US, Canada, and Europe. Attack chain uses voicemail-themed lures through six-stage redirection via Google Meet, Google Ads, and Amazon S3 to evade filters. Attackers use geolocation APIs to select country-matched residential proxies for subsequent logins.

North Carolina Ports Disrupted by Cyberattack

US Coast Guard monitoring cyberattack that disrupted gate operations at all three North Carolina port facilities this week (Port of Wilmington, Port of Morehead City, Charlotte Inland Port). Ports shifted to manual processing while containing intrusion. Normal operations resumed as of Friday morning. No disclosure of attack nature, affected systems, or whether vessel operations, cargo-handling, or rail services were impacted. Coast Guard IT unit coordinating with partner agencies on investigation.

US Defense Supplier IEH Corp Phished

The Register reports attacker phished way into US defense supplier IEH Corp's Microsoft 365 account. Details limited.

ClickFix Campaign Delivers macOS Crypto Wallet Drainer

Huntress reports ClickFix attacks delivering Go-based macOS stealer capable of draining cryptocurrency wallets and stealing browser passwords, iCloud Keychain data, and cached credentials. Malware prompts victims to paste commands into Terminal, which fetches architecture-specific Mach-O payloads. DRAIN routine checks wallet balances and siphons funds to attacker wallets for Bitcoin, Litecoin, Dogecoin, Monero, Ethereum, and XRP. Malware can steal fractions (1%) or entire wallet contents. Infrastructure links to Aeza Group, sanctioned Russian bulletproof hosting provider.

General Security News

AI-Assisted HTTP Terminator Discovers Desync Techniques and Apache Zero-Day

PortSwigger's James Kettle used AI-assisted HTTP Terminator system to generate and prove new HTTP desynchronization techniques after testing 30,000 candidate vectors. Research found roughly 700 vulnerable targets including banks, government infrastructure, security products, and an airport. Discovered Apache Traffic Server zero-day CVE-2026-63078 (no public CVE record or Apache advisory available yet as of August 7). New techniques include dual-matching Content-Length pattern, dangling-byte RQP technique, and Shared-Parser Confusion attack. HTTP Terminator open-sourced; uses Claude for document extraction and test-case generation, Claude Code for investigation stage.

CSS Attacks Escape Email Boundaries in Webmail

PortSwigger researcher Gareth Heyes presented Black Hat research showing CSS in email can escape message boundaries and interfere with webmail interfaces across Outlook, Gmail, Fastmail, Proton Mail, Yahoo Mail, and AOL Mail. Techniques capture passwords, take over third-party accounts, leak tokens, hijack UI actions, and manipulate AI email tools. One Outlook/Firefox chain spoofs Microsoft sign-in and captures passwords. Yahoo/AOL paste race exposes Medium email-login tokens. Gmail/Cowork chain exfiltrates Slack tokens after prompt injection. Fastmail fixed two CSS mutation bugs; Proton Mail proxy bypass stopped working; Outlook label-jacking and Gmail image-set() bypass still work as of August 6. Public PoCs remain available.

Unit 42: Identity Weaknesses in 90% of Incidents

Unit 42's 2026 Global Incident Response Report shows identity weaknesses in nearly 90% of incidents, with 65% of initial access via identity-based techniques (credential theft, MFA manipulation, session hijacking, social engineering). 87% of incidents span multiple attack surfaces. Muddled Libra (Scattered Spider) demonstrates social-first entry tactics. Report highlights identity as primary attack foundation rather than technology vulnerabilities.

Ransomware Attacks Spike as World Distracted by AI

The Register reports ransomware attacks spiking while attention focused on AI developments. Mikko Hyppönen notes ten years since first corporate ransomware with no end in sight, though infosec remains stable career.

Patch Priority

Vulnerability Disclosures

Docker Compose Path Traversal (CVE-2025-62725)

Docker Compose vulnerable to path traversal via OCI artifact layer annotations. EPSS 0.137 (96th percentile).

Python xml.etree.ElementPath DoS (CVE-2026-6879)

Quadratic behavior in xml.etree.ElementPath index predicates. EPSS 0.003 (22nd percentile).

PyJWT Vulnerabilities

CVE-2026-32597 (EPSS 0.003, 19th percentile): PyJWT accepts unknown crit header extensions, violating RFC 7515. CVE-2026-48524 (EPSS 0.003, 26th percentile): PyJWKClient unbounded JWKS endpoint requests via attacker-controlled kid values (DoS).

open-iscsi Vulnerabilities

Multiple flaws disclosed: CVE-2026-55995 (EPSS 0.003, 17th percentile) double-free in iSNS attribute decoder, CVE-2026-44943 (EPSS 0.003, 26th percentile) remote limited file-write as root via discovery, CVE-2026-44944 (EPSS 0.001, 1st percentile) iscsiuio control-socket authentication bypass.

Linux Kernel Safe-RET Hardening (CVE-2026-68480)

x86/bugs: Make Safe-RET robust against interrupt injection. EPSS 0.002 (10th percentile).

Historical CVEs Published to MSRC

Multiple older CVEs added to Microsoft Security Update Guide: CVE-2007-3205 (PHP parse_str), CVE-2019-6706 (Lua use-after-free), CVE-2019-9924 (Bash rbash bypass), CVE-2019-9192 (glibc recursion), CVE-2018-5407 (SMT timing attack), CVE-2018-1128 (Ceph authentication), CVE-2018-6829 (Libgcrypt ElGamal), CVE-2016-2568 (pkexec session escape). These are historical Linux/FOSS vulnerabilities now documented in MSRC for reference.

Trends & Context

Three major themes today: RMM platform exploitation (N-able attackers persisting via Cloudflare tunnels despite patches), identity-based compromise outpacing technical vulnerabilities (90% of incidents per Unit 42), and maximum-severity zero-days in widely deployed business tools (Metabase CVSS 10.0). The N-able incident demonstrates attackers establishing durable persistence mechanisms before defenders can respond, while the Microsoft 365 AitM campaign shows systematic targeting of financial workflows through geographically matched residential proxies. CISA KEV additions continue to lag exploitation by weeks (LoadMaster had 792 attempts before KEV listing).