- SandwormThreat actor linked to Russian government
ThreatNoir Afternoon Brief — August 10
Afternoon Review in IT Security — August 10, 2026
The cybersecurity landscape continues to face escalating threats as attackers demonstrate sophisticated techniques targeting critical infrastructure, enterprise software, and developer tools. Today's briefing covers emerging attack vectors in energy systems, active exploitation of enterprise vulnerabilities, and supply chain compromises affecting cryptocurrency users and hardware customers.
Novel Private APN Pivot Let Hackers Sabotage Second Polish Energy Facility
CERT.PL has identified what appears to be the first documented instance of a private APN being weaponized as an attack vector against critical infrastructure. Attackers successfully leveraged this novel pivot technique to compromise a second Polish energy facility, marking an escalation in sophistication for infrastructure-targeting operations. The Sandworm malware was identified as the tool used in this campaign, indicating nation-state involvement in the attack. Source: Novel Private APN Pivot Let Hackers Sabotage Second Polish Energy Facility
This development underscores the evolving threat landscape for operational technology environments, where attackers are discovering and exploiting previously unconsidered network access points. Organizations managing critical energy infrastructure should reassess their network segmentation strategies and monitoring capabilities for private APN traffic.
Critical Progress LoadMaster Flaw Now Actively Exploited in Attacks
The U.S. Cybersecurity and Infrastructure Security Agency has issued a warning that CVE-2026-8037, a critical-severity command injection vulnerability in Progress Kemp LoadMaster, is being actively exploited in attacks. The vulnerability poses significant risk to organizations relying on this load balancing solution for their network infrastructure. Source: Critical Progress LoadMaster flaw now actively exploited in attacks
Organizations operating LoadMaster instances should prioritize patching immediately, as the active exploitation indicates attackers have already developed reliable exploitation methods. The critical severity rating combined with active exploitation creates an urgent remediation window for affected environments.
Solidity Pro VS Code Extensions Steal Crypto Wallets, API Keys, and Credentials
Cybersecurity researchers have identified malicious Microsoft Visual Studio Code extensions masquerading as Solidity development tools that deliver credential and cryptocurrency wallet stealing capabilities. The extensions, distributed under names including "solidity-pro" and variants, deployed BAT, JavaScript, and HTA droppers alongside Lumma Stealer and clipboard stealing functionality to compromise developer credentials and digital assets. Source: Solidity Pro VS Code Extensions Steal Crypto Wallets, API Keys, and Credentials
While the malicious extensions have been removed from the Open VSX marketplace, the attack demonstrates the persistent risk of supply chain compromise targeting developer communities. Developers should audit their VS Code extension installations and verify the legitimacy of development tools before installation, particularly those targeting specialized programming languages like Solidity.
Valve Notifies Steam Hardware Customers of a Data Breach
Valve has begun notifying Steam hardware customers in Europe of a data breach resulting from a compromise of CEVA Logistics, its shipping partner. The breach exposed customer data through the third-party logistics provider rather than through Valve's direct systems, highlighting the cascading risks of supply chain dependencies. Source: Valve notifies Steam hardware customers of a data breach
This incident reinforces the critical importance of vendor risk management and third-party security assessments. Organizations must implement comprehensive monitoring and contractual requirements for logistics and shipping partners who handle sensitive customer information.
Today's threat landscape demonstrates that attackers continue to identify and exploit emerging attack surfaces across infrastructure, enterprise software, developer tools, and supply chain relationships. Security teams should prioritize vulnerability patching, supply chain risk assessment, and monitoring of novel attack vectors in their respective operational environments.
Sources & IOCs
Source articles and extracted indicators (defanged where appropriate).
- Critical command injection vulnerability in Progress Kemp LoadMaster
- Lumma StealerSimilar playbook observed with threat cluster WhiteCobra distributing Lumma Stealer.
- clipboard stealerAnother malicious extension 'ethdevtools.solidity-language-support' used a clipboard stealer.
- BAT, JavaScript, and HTA droppersOther malicious VS Code extensions deliver these types of payloads.
hxxps://github[.]com/web3devtoolsx/solidity-proGitHub repository for one of the malicious extensions.