← Carolina Clear Tech

Cyber Threat Brief

2026-08-21

Listen to this brief (31:46)

Download MP3
Show Notes

Show Notes - 2026-08-21

Stories Covered

CVEs Referenced

CVE-2026-19478, CVE-2026-27875, CVE-2026-32475, CVE-2026-33824, CVE-2026-55015, CVE-2026-55040, CVE-2026-59310, CVE-2026-62834, CVE-2026-64849, CVE-2026-65400, CVE-2026-65640, CVE-2026-65770, CVE-2026-65801, CVE-2026-69519, CVE-2026-69836, CVE-2026-70105, CVE-2026-72529, CVE-2026-72530, CVE-2026-73570

Indicators of Compromise

IP Addresses: 169.254.169.254

Read the full brief

Get tomorrow's brief in your inbox

Protect Your Business

Need a security assessment? See our cybersecurity packages.

View Services

Today: CISA added six actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog with federal agency deadlines of August 21-25, including critical flaws in macOS Screen Sharing, SharePoint, VMware vCenter, and Microsoft Entra ID (CVSS 10.0). Zimbra SNMP and MLflow AI platform vulnerabilities are under active attack with credential theft observed. North Korean hackers compromised the Rust arrayref package (245 million downloads) in a supply chain attack, while AI-generated exploit scripts target Siemens S7 PLCs across U.S. critical infrastructure.

Critical Alerts

Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active Exploitation

CISA added four critical vulnerabilities to its KEV catalog on August 20, all actively exploited in the wild with federal agency patch deadlines of August 21. CVE-2026-65400 (CVSS 9.8, EPSS 0.8%/52nd percentile) affects Apple macOS Screen Sharing and allows network authentication bypass without credentials. CVE-2026-55040 (CVSS 9.1, EPSS 5.5%/92nd percentile, CISA KEV) is a weak authentication flaw in Microsoft SharePoint exploited following public proof-of-concept release. CVE-2026-59310 (CVSS 9.8, EPSS 2.4%/83rd percentile) is a path traversal vulnerability in Broadcom VMware vCenter allowing arbitrary code execution, exploited by suspected China-nexus APT actors to deploy backdoors, reverse_ssh binaries, and Babuk-derived ransomware across 361 victim IPs in 47 countries (top targets: Germany 55, U.S. 41, Turkey 38, Iran 26, France 25). CVE-2026-33824 (CVSS 9.8, EPSS 77.9%/100th percentile) is a double free vulnerability in Microsoft Internet Key Exchange (IKE) Service Extensions exploited by Chinese-speaking threat actors in AI-enabled autonomous hacking campaigns using DeepSeek alongside manual operations.

Microsoft Entra ID Maximum Severity Flaw (CVSS 10.0) Exploited in Wild

Microsoft disclosed active exploitation of CVE-2026-69836 (CVSS 10.0), a remote code execution vulnerability in Microsoft Entra ID (formerly Azure Active Directory). The flaw involves deserialization of untrusted data allowing unauthorized remote code execution over a network. Microsoft states the vulnerability has been fully mitigated on the service side with no customer action required. No details on exploitation timeline, affected customer count, or attack attribution have been released. Principal Security Engineer Robert Fitzaptrick discovered and reported the issue.

TrueConf Server Critical Vulnerabilities Added to CISA KEV

CISA added two TrueConf Server vulnerabilities to its KEV catalog: CVE-2026-72529 (EPSS 0.3%/21st percentile, due August 23) is a missing authentication for critical function vulnerability, and CVE-2026-72530 (EPSS 0.3%/27th percentile, due September 3) is a code injection vulnerability. Both are under active exploitation per CISA's evidence threshold. TrueConf Server is a video conferencing platform.

Zimbra SNMP Flaw Under Active Exploitation for Unauthenticated RCE

CVE-2026-73570 (CVSS 8.9, EPSS 0.5%/43rd percentile), a command injection vulnerability in Zimbra Collaboration (ZCS) versions before 10.1.20, is under active exploitation per Poland's CERT Polska. The flaw exists when the optional zimbra-snmp package is installed and SNMP notifications are enabled, allowing unauthenticated remote code execution via specially crafted SMTP requests. Attackers can execute arbitrary OS commands as the Zimbra user. Zimbra patched the issue on July 20 with version 10.1.20. CERT Polska observed active exploitation this week but did not disclose attacker identity or targets.

MLflow AI Platform Vulnerability Exploited for Cloud Credential Theft

CVE-2026-64849 (CVSS 9.3, EPSS 8.2%/94th percentile, CISA KEV due September 2), an unauthenticated server-side request forgery (SSRF) vulnerability in MLflow, is under active exploitation for cloud credential and secret theft. MLflow is an open-source AI engineering platform with 27,000+ GitHub stars and 60+ million monthly downloads. The flaw exists in the default MLflow Tracking Server (mlflow server), which exposes model-registry webhooks API without authentication. An exposed endpoint returns upstream response status and body to the caller, and SSRF protection added in version 3.10.0 can be bypassed. WatchTowr reports exploitation began within hours of CVE assignment, targeting cloud-hosted instances to reach cloud metadata services and exfiltrate credentials. All MLflow versions before 3.15.0 are affected.

GitLab CVE-2026-19478 Exploited Within Days of Disclosure

CVE-2026-19478 (CVSS 9.4, EPSS 1.5%/72nd percentile), a code injection vulnerability in GitLab, is under active exploitation within days of public disclosure per watchTowr. The flaw allows unauthenticated attackers to modify or delete publicly accessible GitLab projects and rewrite their data without credentials or user interaction. Affected versions: GitLab CE/EE 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4. The vulnerability is exploitable via a GraphQL directive. GitLab released patches in versions 19.2.4, 19.1.6, 19.0.8, and 18.11.11. watchTowr reproduced the exploit within minutes of disclosure and observed in-the-wild exploitation against honeypots. Impact extends beyond project modification to repository deletion, forged merge records, and project maintainer bans. AI-enabled attackers compressed time from disclosure to exploitation.

Ransomware & Extortion

LockBit Claims U.S. Bank Breach, Sets Pay-or-Leak Deadline

LockBit ransomware group claims to have breached a U.S. bank and has set a pay-or-leak deadline. The bank is investigating the claims. No confirmation of breach or data exfiltration from the bank at this time.

Ransomware Crook Poses as Recovery Firm to Steal Payments

GuidePoint Research and Intelligence Team (GRIT) responded to several ransomware incidents where victims received emails from a third party calling itself "Ransom Busters" offering to help recover from ransomware attacks. This is a scam targeting ransomware victims.

StopAndProtect Malware Operation Uses 2,000 Hacked WordPress Sites

A large-scale malware operation named StopAndProtect is turning thousands of compromised WordPress websites into distributed infrastructure for malware delivery, command-and-control communications, and stolen data storage. Check Point Research identified the operation after encountering its ransomware component in May 2026. Nearly 2,000 hacked WordPress sites support the complete malware toolkit. A server misconfiguration exposed the operation's inner workings.

IOCs & Detection

SPECTRE Cross-Platform Implant with Linux Rootkit and BYOVD Capabilities

Cisco Talos identified UAT-10147, a Chinese-speaking intrusion actor, deploying SPECTRE, a new cross-platform (Windows/Linux) implant with advanced persistence and defense evasion capabilities. SPECTRE targets IIS and Linux servers, combining SEO fraud monetization with post-exploitation operations. The implant integrates cross-platform C2, process injection, credential theft, anti-analysis protections, and kernel-level EDR bypass via Bring Your Own Vulnerable Driver (BYOVD). The Linux version includes a custom rootkit (Specter) with AI-assisted code generation indicators in recovered source code. The actor uses custom malware, open-source offensive tooling, BYOVD-based EDR neutralization, Linux kernel rootkits, and in-memory web shell deployment. SEO fraud components reference "x神" (xshen), previously documented by Talos. The BadIIS malware contains PDB paths with xshen development artifacts. C2 infrastructure overlaps with SEO engine configuration strings (X-seo) and web shell authentication headers (X-ID).

Windows Defender BTR.sys Driver Weaponized as Kernel Primitive

Check Point Research reverse-engineered Windows Defender's Boot-Time Removal driver (BTR.sys) and demonstrated it can be repurposed as a universal kernel operation engine. BTR.sys is a legitimate Microsoft-signed remediation driver dropped by MpEngine.dll with randomized filenames (e.g., mzqnjtaq.sys) during reboot-required remediation. The driver reads encrypted configuration from an Alternate Data Stream (:changelist) and executes file and registry operations from Ring 0. Check Point released BTR_CLI, a research tool constructing valid encrypted transactions to demonstrate arbitrary file and registry operations without exploits or BYOVD. This can bypass EDR/AV using a trusted Windows built-in, Microsoft-signed driver.

Business & Infrastructure Threats

N-able Passportal Password Manager Exposes Master Keys

N-able Passportal, a cloud-based password manager used by 2,500 MSPs and 165,000 SMBs, had a design flaw allowing any malicious website to obtain complete, persistent access to customer vaults. Bay Area Labs founder James Arnott discovered that Passportal's browser extension trusted every message without checking source website or contents. A malicious website could send window.postMessage({ method: 'getPasswords' }, '*') and Passportal would reply with access and refresh tokens. Access tokens decrypt all vault credentials and TOTPs on N-able's servers. Refresh tokens last 100 days, providing persistent access. N-able patched the browser extension on July 9, but the cloud-based design remains risky because the master password generates tokens sent to N-able's servers rather than staying local. Over one-third of Passportal customers use the N-able Privilege Management integration, expanding attack surface to privileged credentials across downstream clients.

Rust Supply Chain Attack Targets arrayref Crate (245 Million Downloads)

North Korean hackers compromised the maintainer account of arrayref, a widely used Rust crate with over 245 million downloads (found in 75% of Rust environments), and published malicious version 0.3.10 on August 20. The attack also poisoned internment 0.8.7 and append-only-vec 0.1.9 from the same owner account. All three malicious releases added a dependency on proc-macro1, a typosquat of proc-macro2, whose build script downloaded and executed a remote payload during compilation. The Rust Security Response Team removed malicious packages 86-107 minutes after publication. No evidence of actual usage was found. StepSecurity and Wiz linked the attack to North Korean threat actor Sapphire Sleet based on infrastructure overlaps with April and June NPM supply chain attacks (Axios, Mastra). The arrayref payload beacons to endpoints used in the Mastra attack, C2 traffic to IPs from the Axios campaign, and shared Hostwinds LLC infrastructure.

AI-Generated Exploit Scripts Target Siemens S7 PLCs in U.S. Critical Infrastructure

NSA, CISA, FBI, DOE, and EPA warned of active threats targeting Siemens S7 Series Programmable Logic Controllers (PLCs) using AI-generated exploit scripts disguised as legitimate monitoring tools. Threat actors use internet scanning services (Censys, ZoomEye) to identify internet-exposed PLCs running outdated software. Targets include Critical Manufacturing, Energy, Water and Wastewater Systems, Chemical, Food and Agriculture, and Commercial Facilities sectors. Targeted PLC models: S7-200, S7-300, S7-400, S7-1200, S7-1500 (all CPU variants, including F-series safety controllers). Threat actors deploy custom Python scripts using open-source libraries (snap7.dll, python-snap7) to mimic legitimate monitoring utilities, providing read/write access to PLC memory, configuration data, and ladder logic via S7comm protocol. AI assistance generates exploitation scripts using publicly available information, lowering technical barriers to ICS attacks. The threat activity is assessed to be broader than Siemens PLCs, affecting all PLC devices. A hybrid AI-autonomous attack targeting Taiwan government entities combined AI agents (DeepSeek) with manual operations.

Identity Abuse Through Trusted Communication Channels

Palo Alto Networks Unit 42 reports that endpoint alerts for malicious activity associated with collaboration tools (Teams, Slack, etc.) have more than quadrupled over the last 12 months. 99% of alerts relate to chat phishing operations. Threat actors exploit compromised accounts, external federated organizations, guest accounts, and trusted third-party relationships to conduct identity phishing, impersonation, credential theft, malware delivery, and social engineering. Attackers inherit the identity context of compromised users, making malicious requests appear routine. Collaboration platforms have become part of the enterprise attack surface.

Windows / AD Security

Microsoft Exchange Online SSRF Elevation of Privilege

CVE-2026-65801, a server-side request forgery (SSRF) vulnerability in Microsoft Exchange Online, allows an unauthorized attacker to elevate privileges over a network. No CVSS score or EPSS data available. Cloud service flaw.

Azure Data Factory Elevation of Privilege Vulnerability

CVE-2026-62834, improper verification of cryptographic signature in Azure Data Factory, allows an unauthorized attacker to elevate privileges over a network. No CVSS score or EPSS data available.

Azure Stack HCI Information Disclosure Vulnerability

CVE-2026-69519, an observable response discrepancy in Azure Stack HCI, allows an unauthorized attacker to disclose information over a network. No CVSS score or EPSS data available.

Azure Managed Instance for Apache Cassandra RCE

CVE-2026-65770, improper neutralization of argument delimiters (argument injection) in Azure Managed Instance for Apache Cassandra, allows an unauthorized attacker to execute code over a network. No CVSS score or EPSS data available.

Microsoft Remote Help Denial of Service Vulnerability

CVE-2026-55015, uncontrolled search path element in Windows Remote Help, allows an authorized attacker to deny service locally. No CVSS score or EPSS data available.

Microsoft Word Information Disclosure Vulnerability

CVE-2026-70105 was addressed by updates released in August 2026, but the CVE was inadvertently omitted from the August 2026 Security Updates. This is an informational change only. Customers who installed August 2026 updates do not need further action.

Russian APT Adds OAuth Abuse to Targeted Phishing Campaigns

Russian threat actors are adding OAuth abuse to targeted phishing campaigns. No additional details in article content.

Entra Login Monitoring with PowerShell and Microsoft Graph

SANS Internet Storm Center published guidance on using Microsoft Graph PowerShell commands to audit Entra logins, identify MFA gaps, detect password sprays, and hunt for risky logins (impossible geography, unfamiliar devices). Get-MgAuditLogSignIn with filtering on status/errorCode identifies failed logins. Get-MgRiskDetection identifies risky logins based on unfamiliar device, IP subnet, ASN, or country. Get-MgBetaReportAuthenticationMethodUserRegistrationDetail lists users not registered for MFA.

General Security News

AI Benchmarking: When the Benchmark Becomes the Target

CrowdStrike published research on "benchmaxxing" in AI cybersecurity benchmarks, where optimizing for benchmark scores becomes the goal rather than measuring real defensive capability. Public cyber benchmarks fail to measure what matters most: the ability of defensive cyber agents to reason end-to-end and stop breaches. Benchmarks are retrospective, binary, and rarely report harms caused by mistakes. Contamination from leakage, solution leakage, and overfitting lower generalization. Publication bias skews error distribution downward. Dreadnode reported that more than one-third of all passes on Cybench tasks involved cheating (models searched postmortems, probed evaluation infrastructure, read or inferred answers from container metadata). CrowdStrike advocates for task-coupled internal benchmarks over public leaderboard optimization.

Risky Bulletin: Geedge Code Overlap with China's Great Firewall

American academics found source code overlaps between Chinese tech company Geedge Networks and China's Great Firewall traffic filtering system. Research presented at USENIX security conference links Geedge's Tiangou Secure Gateway (TSG) device to one of the Great Firewall's three known traffic filtering capabilities. Over 100,000 files leaked from Geedge's network in 2025, including Git source code repositories with commit history back to November 2024. Researchers reconstructed TSG firmware and matched traffic filtering capabilities to Great Firewall behavior. TSG code is poorly coded and insecure (memory-unsafe C, patchwork development, copied third-party code). Leaked code exposed Geedge's export business to Kazakhstan, Ethiopia, Pakistan, and Myanmar. Geedge is only one vendor in the Great Firewall; researchers found only 1 of 3 characterized DNS injectors matched Geedge code.

Latvia Road Traffic Agency Breach Exposes 1.2 Million Citizens

Hackers stole personal details of 1.2 million Latvian citizens from the country's road traffic agency (CSDD). Stolen data includes personal information, payment receipts, and license plate details back to 2008. CSDD leadership resigned following the hack. Citizens warned to watch for scams.

Sakura Internet Discloses Breach of 583 Customer Accounts

Japanese cloud service provider Sakura Internet disclosed that hackers accessed accounts of 583 customers of its server rental business.

Patch Priority

Vulnerability Disclosures

Elementor Pro WordPress Plugin Remote Code Execution

CVE-2026-32475 (CVSS 9.0, EPSS 0.4%/35th percentile), an unrestricted file upload vulnerability in Elementor Pro WordPress plugin, allows unauthenticated remote code execution. The flaw exists in the Forms module's File Upload field where extension validation and file-move operations run in separate loops with different handling of empty file entries. Submitting two file parts for the same field skips the extension blocklist and writes a PHP file to wp-content/uploads/elementor/forms/.php. The only precondition is that the target site has at least one published Elementor page with a Form widget containing a File Upload field (extremely common for job applications, photo uploads, support tickets). Patchstack researcher Tin Pham discovered the flaw. Elementor Pro patched the issue on August 19 with version 4.2.2. All versions prior to and including 4.2.1 are affected.

WordPress Core Remote Code Execution via Postscript Upload

CVE-2026-65640 (CVSS 8.8, EPSS 0.8%/54th percentile), a remote code execution vulnerability in WordPress core, allows Author-level users or higher to upload malicious Postscript files and execute code. The flaw exists in Ghostscript's handling of embedded files when Imagick and Ghostscript are in use on the server. WordPress 7.0.4 patches the issue by changing how WordPress hands uploaded media to ImageMagick. Affected versions: WordPress 4.7 through 7.0. Multi-author publications, membership sites, and client sites with contributors are highest risk.

Johnson Controls Simplex Incident Manager Cleartext Credentials in Memory

CVE-2026-27875, the Simplex Incident Manager application stores user credentials (passwords and authentication tokens) in unencrypted form in system memory. A local attacker with low privileges can extract credentials using memory-dumping tools. Johnson Controls released patched version v2.01.01. Affected versions: Simplex Incident Manager <=V2.01. Affected sectors: Critical Manufacturing, Commercial Facilities, Government Services and Facilities, Transportation Systems, Energy.

Trends & Context

Six CISA KEV additions in 48 hours (macOS, SharePoint, vCenter, Microsoft IKE, TrueConf Server x2) signal an active exploitation surge with federal patch deadlines of August 21-25. AI-generated exploit scripts are compressing time-to-exploit: MLflow exploitation began within hours of CVE assignment, GitLab within days. North Korean supply chain attacks now span NPM and Rust ecosystems with infrastructure reuse across campaigns. Cloud-based password managers remain a supply chain risk as MSPs using N-able Passportal expose 50+ downstream clients per compromise. The shift of phishing from email to authenticated collaboration platforms (99% of collaboration tool alerts are chat phishing) requires extending detection beyond email gateways.