DEV Community

NetSecOpsIO
NetSecOpsIO

Posted on • Originally published at cyber.netsecops.io

Daily Cybersecurity Intelligence - August 4, 2026

Daily cybersecurity intelligence digest from CyberNetSec.io - August 4, 2026


📊 14 threat intelligence reports covering vulnerabilities, exploits, threat actors, and security advisories.


1. INC Ransomware Exploits SonicWall SMA 1000 Zero-Days

The INC Ransomware group is actively exploiting a critical vulnerability chain (CVE-2026-15409 and CVE-2026-15410) in SonicWall's SMA 1000 series VPN appliances. Initially exploited as zero-days in June 2026, the flaws allow unauthenticated remote attackers to gain root access and deploy ransomware. The campaign has impacted organizations globally across multiple sectors, with attackers leveraging compromised VPNs to pivot into internal networks. CISA has added both vulnerabilities to its KEV catalog, urging immediate patching and threat hunting for signs of compromise, including specific attacker tools and persistence mechanisms.

📖 Read full report →


2. Active Exploitation of N-able N-central Flaw CVE-2026-18577

A critical authentication bypass vulnerability (CVE-2026-18577) in N-able's N-central RMM platform is under active exploitation following an incomplete patch for a previous flaw. Attackers are gaining administrative access to N-central consoles, allowing them to compromise managed endpoints and establish persistence using tools like Cloudflare Tunnels. The vulnerability affects both cloud and on-premises versions, posing a severe supply chain risk to Managed Service Providers (MSPs) and their customers. CISA has added the CVE to its KEV catalog, and N-able has released an emergency hotfix.

📖 Read full report →


3. Cyberattacks on U.S. Water Systems Linked to Iran

A coordinated series of cyberattacks has targeted water and wastewater facilities across at least seven U.S. states, with suspected links to Iranian state-sponsored actors. The attackers exploited internet-exposed Programmable Logic Controllers (PLCs), primarily from Rockwell Automation, to disrupt operations, lock out operators, and force some utilities to switch to manual control. While no water contamination has been reported, the incidents highlight severe vulnerabilities in the nation's critical infrastructure, prompting urgent warnings from the FBI, CISA, and the EPA.

📖 Read full report →


4. Amgen Cloud Data Breach Exposes Patient and Corporate Data

Biopharmaceutical giant Amgen has disclosed a 'material' cybersecurity incident involving unauthorized access to its third-party cloud storage systems. The breach, detected in July 2026, resulted in the exfiltration of sensitive data, including proprietary corporate information and patients' protected health information (PHI). While Amgen states the attack is not expected to have a material impact on its operations or finances, the full scope of the breach is still under investigation. The incident highlights the growing threat of supply chain attacks targeting sensitive data stored in cloud environments.

📖 Read full report →


5. Thermo Fisher DNA Software Flaw (CVE-2026-17583)

A critical vulnerability (CVE-2026-17583) in Thermo Fisher Scientific's forensic DNA analysis software could allow for the nearly undetectable tampering of evidence. The flaw, affecting Applied Biosystems software, fails to cryptographically verify the integrity of DNA data files, enabling malicious modification. This could compromise the integrity of criminal investigations and legal proceedings. Thermo Fisher has released patches for supported products but noted that files created before patching cannot be retroactively validated, and some end-of-life products will not be updated.

📖 Read full report →


6. COLDCARD Wallet Flaw Suspected in $88.6M Bitcoin Theft

A firmware vulnerability in COLDCARD Bitcoin hardware wallets is the suspected cause of a theft totaling approximately $88.6 million in Bitcoin. The flaw, which caused the device to use a weak pseudorandom number generator (PRNG) for creating recovery seeds, allowed attackers to predict and reconstruct private keys. The theft occurred in automated sweeps just before the vulnerability was publicly disclosed. Users of affected devices are urged to generate new seeds on patched firmware and transfer their funds immediately, as simply updating the device does not secure existing, compromised wallets.

📖 Read full report →


7. JetBrains TeamCity Auth Bypass Flaw (CVE-2026-63077)

JetBrains has patched a critical authentication bypass vulnerability (CVE-2026-63077) in its TeamCity On-Premises CI/CD server. The flaw allows an unauthenticated remote attacker to gain administrative privileges and achieve remote code execution, posing a severe risk to software supply chain integrity. All on-premises versions are affected. While there is no evidence of active exploitation, the history of nation-state actors targeting TeamCity makes immediate patching a top priority for all customers. JetBrains has released updated versions and a security patch plugin.

📖 Read full report →


8. Hugging Face Diffusers Flaws Expose AI Supply Chain

Three high-severity vulnerabilities, dubbed 'FaceHugger,' have been discovered in Hugging Face's popular Diffusers library for AI models. The flaws (CVE-2026-44513, CVE-2026-44827, CVE-2026-45804) allow a malicious AI model to bypass a key security feature, trust_remote_code=false, and execute arbitrary code on a developer's machine. This poses a significant AI supply chain risk, as loading a seemingly benign model could lead to a system compromise. Hugging Face has patched the vulnerabilities in Diffusers version 0.38.0 and users are urged to update.

📖 Read full report →


9. UK Police National Legal Database (PNLD) Data Breach

The UK's Police National Legal Database (PNLD) has suffered a data breach, resulting in the exposure of contact information for police officers, staff, and criminal justice partners. The compromised data, which includes names, work email addresses, and organizations, was published on the dark web. While passwords were not compromised, the breach creates a significant risk of sophisticated phishing attacks against law enforcement and government personnel. The extortion group ExfilSquad has been linked to the incident.

📖 Read full report →


10. Cisco Firewall Manager Flaw CVE-2026-20316 Actively Exploited

Cisco has released hotfixes for an actively exploited vulnerability (CVE-2026-20316) in its Secure Firewall Management Center (FMC). The flaw involves hard-coded credentials that allow an unauthenticated attacker to access a low-privileged account. Attackers are reportedly chaining this with a second bug (CVE-2026-20079) to achieve full root access and compromise the central management platform for Cisco firewalls. CISA has added the primary CVE to its KEV catalog, signaling an urgent need for organizations to patch and restrict access to their FMC interfaces.

📖 Read full report →


11. Midnight Blizzard (APT29) Targets Hotel Wi-Fi for M365 Credential Theft

The Russian state-sponsored group Midnight Blizzard (also known as APT29 or Nobelium) is conducting a campaign called 'CaptiveCrunch,' compromising public Wi-Fi gateways at hotels and conference centers. The attackers modify DNS settings on the compromised routers to perform adversary-in-the-middle (AitM) attacks, intercepting and stealing Microsoft 365 and Azure AD credentials. The campaign uses malware like CornFlake and ChocoShell and targets government and industry organizations in the US and Europe, highlighting the risks of using public Wi-Fi.

📖 Read full report →


12. Cloud Zero-Day Exposes Multi-Tenant Environments

A major, unnamed cloud provider has disclosed a critical zero-day vulnerability that allows for privilege escalation and could enable attackers to break tenant isolation in multi-tenant containerized environments. The flaw, which has seen limited exploitation, could allow attackers to pivot between customer workloads. The incident has triggered a global security alert, with CISA urging organizations to validate cloud logging and isolation policies. The vulnerability exposes weaknesses in workload identity federation and token-signing processes, prompting a re-evaluation of cloud trust boundaries.

📖 Read full report →


13. Frontier AI Discovers 14,000+ OSS Zero-Days

Palo Alto Networks' Unit 42 has developed an autonomous vulnerability discovery system, NOVA, powered by frontier AI. In just two months, NOVA analyzed nearly 4,000 open-source projects and uncovered over 14,000 vulnerabilities, with 99.4% being previously unknown. This research demonstrates a fundamental shift in cybersecurity, drastically accelerating vulnerability discovery and collapsing the time between disclosure and potential exploitation. The findings underscore the urgent need for advanced defense strategies like virtual patching to counter the increased risk to the global software supply chain.

📖 Read full report →


14. Malware Bypasses DNS via Direct-to-IP C2

A Unit 42 analysis of over 4 million malware samples reveals a critical security blind spot: 45% of malware with command-and-control (C2) activity uses direct-to-IP (D2IP) connections, completely bypassing DNS-based security controls. This technique, employed by malware like Phorpiex and SectopRAT, renders DNS filtering and sinkholing ineffective. The research proposes a 'Zero Trust IP' (ZT-IP) enforcement model, which verifies outbound connections against sanctioned DNS lookups, as an effective countermeasure to detect and block this widespread evasion tactic.

📖 Read full report →


📌 Subscribe to daily updates at CyberNetSec.io

All reports include detailed analysis, IOCs, mitigation strategies, and references.

Top comments (0)