Daily cybersecurity intelligence digest from CyberNetSec.io - August 5, 2026
📊 12 threat intelligence reports covering vulnerabilities, exploits, threat actors, and security advisories.
1. NPM 'Shai-Hulud' Worm Supply Chain Attack
A massive, self-propagating supply chain attack dubbed 'Mini Shai-Hulud' struck the NPM ecosystem on August 4, 2026. After compromising a popular developer's GitHub account, attackers injected a credential-stealing worm into foundational packages like keyv and cacheable. The worm rapidly spread to over 440 packages, impacting projects with a combined total of over 2 billion monthly downloads. The malware harvests a wide range of secrets, including NPM/GitHub tokens and cloud credentials, and uses an Ethereum smart contract for dynamic C2 infrastructure, posing a severe risk to the software supply chain.
2. CISA KEV Catalog Adds N-able, Langflow, Tomcat Flaws
The U.S. CISA has added three actively exploited vulnerabilities to its KEV catalog, mandating federal agencies to patch by August 7, 2026. The flaws include a critical RCE in IBM's Langflow (CVE-2026-9198), an authentication bypass in N-able N-central (CVE-2026-18556), and an encryption bypass in Apache Tomcat (CVE-2026-34486). The N-able flaw was exploited as a zero-day against MSPs, while the Tomcat vulnerability has been linked to a China-nexus threat actor's campaign targeting global infrastructure.
3. Teams Vishing to Chaos Ransomware Attacks
A threat group tracked as STAC4749 is targeting North American organizations with a voice phishing (vishing) campaign on Microsoft Teams. Posing as IT support, the attackers trick employees into granting remote access via legitimate tools like Quick Assist. Once inside, they deploy custom malware and establish persistence, culminating in the deployment of Chaos ransomware. In one case, the entire attack from initial call to network-wide encryption took less than 17 hours, highlighting the speed and effectiveness of this social engineering-based approach.
4. TP-Link Omada Zero-Touch Provisioning Flaws
Forescout researchers have disclosed 15 new vulnerabilities in TP-Link's Omada Zero-Touch Provisioning (ZTP) system, used for deploying network devices. The flaws, affecting hardware, software, and cloud controllers, can be chained to achieve full network takeover. Attack vectors include credential harvesting, device hijacking, and injecting malicious code into administrator web interfaces. With over 1,800 Omada controllers exposed online, the risk is significant. The vulnerabilities also impact other TP-Link ecosystems like VIGI and Tapo.
5. Brown Health Medical Group Data Breach
Brown Health Medical Group-MA, operated by Lifespan Physician Group, has reported a data breach affecting 311,760 individuals. The incident, which occurred in December 2025, involved unauthorized access to a legacy file server. It took nearly seven months for the organization to determine the full scope and begin notifying victims. The compromised server contained a vast range of sensitive data, including names, Social Security numbers, financial details, and extensive medical records, putting victims at high risk of identity theft and fraud.
6. Block Inc. $45M Cash App Settlement
Block Inc., parent company of Cash App, has agreed to a $45 million settlement with 46 U.S. states to resolve allegations of inadequate security and consumer protection. State attorneys general claimed Block misled users about the app's safety, prioritized growth over security, and failed to provide adequate support for fraud victims. The settlement requires Block to strengthen identity verification, expand customer support, and respond more quickly to unauthorized transaction reports, in addition to the monetary payment.
7. JetBrains IDE and TeamCity Critical Vulnerabilities
JetBrains has released urgent security updates for critical and high-severity vulnerabilities in its IntelliJ-based IDEs and TeamCity CI/CD server. The flaws, including a critical RCE in TeamCity's Git integration (CVE-2026-65907) and a command injection flaw in IDEs (CVE-2026-49366), pose a severe software supply chain risk. They could allow attackers to execute code, access source code and credentials, and compromise entire development environments. Users are urged to update immediately.
8. Bank of America Phishing Campaign Uses ScreenConnect
A phishing campaign impersonating Bank of America is distributing a disguised version of the ScreenConnect remote access tool. According to Huntress researchers, the attack uses social engineering to lure victims into downloading a malicious installer. The payload installs the legitimate ScreenConnect RMM tool under the name 'Windows Security' and uses a VBScript with SDDL strings to modify its permissions, making it invisible and difficult to remove, even for administrators. This grants the attackers persistent, stealthy access to the victim's machine.
9. Open Secure AI Alliance SAFE Framework Proposal
The Open Secure AI Alliance, in collaboration with The Linux Foundation, has proposed a new framework called the Shared AI Findings Exchange (SAFE) for standardizing the reporting of AI security incidents. Announced at Black Hat USA 2026, the initiative aims to create a confidential pipeline for collecting, analyzing, and sharing threat intelligence from incidents involving agentic AI. Key members like NVIDIA, Cisco, and CrowdStrike are backing the proposal, which defines reporting timelines and aims to foster a collective defense approach to systemic AI risks.
10. Microsoft Defender Automatic Isolation Case Study
In a case study involving the company QNET, Microsoft has detailed how its Defender platform's automatic device isolation feature stopped a ransomware attack in just 128 seconds. The attack began by using the legitimate Windows binary 'mshta.exe' to download a remote payload, a common living-off-the-land technique. Defender's behavioral and correlation engines identified the malicious pattern and autonomously isolated the device, preventing lateral movement and data encryption without requiring manual SOC intervention.
11. Singapore iMessage Courier Phishing Scam
The Singapore Police Force has issued an alert regarding a widespread phishing scam on Apple iMessage that has defrauded at least 251 victims of over S$1.2 million since late June 2026. Scammers, using foreign numbers, impersonate courier companies like DHL and SingPost, luring victims with fake 'failed delivery' notifications. They trick targets into clicking a link, paying a small 're-delivery fee' on a spoofed website, and thereby harvesting their credit card and banking credentials to make large unauthorized transfers.
12. Cloud Misconfiguration Data Breaches in 2026
Two recent major incidents in 2026 highlight that cloud misconfigurations remain a leading cause of data breaches. In one case, a cloud application platform's default public access setting exposed 38 million records from 47 organizations. In another, a cloud data platform provider's failure to enforce multi-factor authentication (MFA) led to a breach affecting 165 of its customers. These events underscore the critical importance of proper cloud service configuration and the adoption of Cloud Security Posture Management (CSPM) tools to prevent human error.
📌 Subscribe to daily updates at CyberNetSec.io
All reports include detailed analysis, IOCs, mitigation strategies, and references.
Top comments (0)