[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f6uTNQEblYklSYC0k1Zc5u490AifcS2D2AX_Uex_j2ZM":3},{"roundup":4},{"id":5,"week_label":6,"slug":7,"date_from":8,"date_to":9,"tldr":10,"full_brief":11,"top_iocs":12,"social_linkedin":60,"social_x":61,"article_count":62,"awareness_links":63,"status":124,"published_at":125,"created_at":126,"updated_at":126,"mastodon_posted_at":127,"executive_summary":128,"tagline":129,"cover_image_url":130},"b34de807-0801-46c0-a5a2-f70ee14fc5cd","2026-W32","2026-w32","2026-08-03","2026-08-09","- 🤖 AI coding agents from Anthropic, Google, and OpenAI had critical CI\u002FCD flaws allowing GitHub issues to trigger RCE and steal secrets, all patched at Black Hat USA 2026\n- 🏭 4,400+ Rockwell PLCs remain exposed online including 22 in water utilities already targeted by attacks, despite years of federal warnings\n- 🎣 Vishing extortion group UNC6671 rebranded and expanded, hitting hedge funds and Levi Strauss using spoofed IT helpdesk calls and AitM credential theft\n- 🔓 Critical zero-days in Metabase (CVSS 10.0), Progress Kemp LoadMaster, and JetBrains TeamCity are actively exploited with CISA KEV additions\n- 🏗️ Supply chain pressure intensified with 800 malicious npm packages, a trojanized TrueConf installer campaign, and the Snowflake hacker guilty plea confirming the MFA gap cost 165 orgs billions of records\n- 💻 New CPU-level attacks TONTOU and INTERRUPT INJECTION bypass Spectre v2 mitigations on Intel and AMD, leaking kernel memory including password hashes\n- ⚖️ Enforcement actions landed on multiple fronts: Ransom Cartel creator sentenced to 16 years, Piaggio fined €460K for employee monitoring, and Snowflake extortionist pleads guilty","## Vulnerabilities & Exploits\n\n**[Metabase Zero-Day (CVSS 10.0) Exploited, Customer Data Stolen](https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fframework-tally-disclose-metabase-data-theft-attacks\u002F)**. A critical unauthenticated SQL injection zero-day in Metabase versions 1.58 and above has been actively exploited to steal customer data from companies including Framework and Tally. Attackers gain administrator access, harvest credentials, and exfiltrate data without any authentication, making patching self-hosted instances urgent.\n\n**[Progress Kemp LoadMaster Hits CISA KEV After 792 Exploit Attempts](https:\u002F\u002Fthehackernews.com\u002F2026\u002F08\u002Fprogress-kemp-loadmaster-flaw-hits-cisa.html)**. CVE-2026-8037, a command injection flaw in LoadMaster (CVSS critical), was added to CISA's Known Exploited Vulnerabilities catalog with a federal patch deadline of August 10, 2026. Attempts originated from 65 IP addresses across 18 countries, indicating broad opportunistic scanning.\n\n**[CISA Flags TeamCity RCE CVE-2026-63077 Under Active Exploitation](https:\u002F\u002Fthehackernews.com\u002F2026\u002F08\u002Fcisa-flags-teamcity-cve-2026-63077-rce.html)**. The JetBrains TeamCity unauthenticated RCE flaw (CVSS 9.8) is being actively exploited in the wild, with federal agencies mandated to patch by August 8, 2026. On-premise installations are at risk; cloud-hosted instances are not affected. [Learn more](\u002Fawareness\u002Fcritical-teamcity-rce-flaw-actively-exploited-patch-immediately)\n\n**[New TONTOU and INTERRUPT INJECTION CPU Attacks Bypass Spectre v2 Mitigations](https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fnew-tontou-cpu-attack-bypasses-spectre-v2-fixes-leaks-linux-password-hashes\u002F)**. Two independently discovered microarchitectural attacks this week both defeat existing Spectre v2 defenses on Intel and AMD processors by re-poisoning the branch predictor after kernel mitigations have cleared it. Both can leak sensitive kernel memory including Linux password hashes from unprivileged local code. AMD has released a kernel patch; Intel does not consider a mitigation necessary.\n\n**[18-Year-Old Linux SCTP Flaw Enables Root Access and Container Escape](https:\u002F\u002Fthehackernews.com\u002F2026\u002F08\u002F18-year-old-linux-sctp-flaw-could-let.html)**. CVE-2026-64564 (SCTPhantom), a use-after-free in Linux SCTP networking code present since 2008, allows local users to gain root on the host and escape containerized environments. Fixes have been backported to stable kernel versions and should be applied promptly in container-heavy environments.\n\n### Key Takeaway\nPrioritize patching Metabase, Progress Kemp LoadMaster, and TeamCity immediately; review kernel update cadence for SCTP and Spectre v2 patches across all Linux hosts.\n\n---\n\n## Ransomware & Breaches\n\n**[Snowflake Hacker Connor Moucka Pleads Guilty: 165 Orgs, $2.5M Extorted](https:\u002F\u002Fkrebsonsecurity.com\u002F2026\u002F08\u002Fcanadian-man-pleads-guilty-in-snowflake-extortions\u002F)**. Moucka admitted to using stolen credentials against Snowflake accounts that lacked MFA, stealing billions of records including 100 million AT&T customer records, and extorting victims for over $2.5 million. Victims collectively lost more than $9.5 million, cementing this case as a defining consequence of MFA negligence at scale. [Learn more](\u002Fawareness\u002Fransom-cartel-raas-operator-sentenced-lessons-from-a-credential-fueled-ransomware-empire)\n\n**[UNC6671 Vishing Group Hits Levi Strauss and Hedge Funds](https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fhedge-fund-cyberattacks-tied-to-blackfile-linked-unc6671-extortion-group\u002F)**. The rebranded vishing extortion group UNC6671 (formerly BlackFile, now operating as Redact, Pink, Helix, and Falcon) targeted financial services firms and Levi Strauss by impersonating IT helpdesk staff on personal phones, routing victims to AitM login portals that harvested credentials and MFA tokens. The group has extorted over $10 million in Bitcoin with initial demands of $1M to $3M per victim.\n\n**[Unlimited Technology Systems Breach Affects 3.8 Million Healthcare Records](https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Funlimited-technology-systems-breach-impacts-38-million-people\u002F)**. A healthcare software provider suffered unauthorized access to a commercial data center in October 2025, exposing SSNs, medical record numbers, and insurance details for nearly 4 million individuals. The breach was disclosed this week, underscoring the lag between healthcare breach discovery and notification.\n\n**[North Carolina Ports Hit by Cyberattack, Gate Operations Disrupted](https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fnorth-carolina-ports-confirms-cyberattack-disrupting-operations\u002F)**. A systems-wide outage detected August 4 disrupted gate operations at all three North Carolina port facilities including Wilmington and Morehead City. The U.S. Coast Guard is monitoring the incident; no attribution or data theft confirmation has been made public.\n\n### Key Takeaway\nEnforce MFA universally on cloud data platforms and train staff to verify unsolicited IT calls through a known, out-of-band number before following any instructions.\n\n---\n\n## Supply Chain\n\n**[Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer](https:\u002F\u002Fthehackernews.com\u002F2026\u002F08\u002Fnearly-800-malicious-npm-packages.html)**. A campaign using AI-generated and typo-squatted package names distributed a cross-platform remote access trojan and infostealer targeting Windows, macOS, and Linux. Payloads are fetched from Cloudflare Workers or encoded in DNS TXT records, enabling stealthy delivery and persistence including Sliver deployment on Linux systems.\n\n**[Hackers Trojanize TrueConf Installers with Backdoors via Unpatched Servers](https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fhackers-breach-trueconf-to-trojanize-client-installers-with-backdoors\u002F)**. The Head Mare hacktivist group compromised TrueConf servers to distribute backdoored client installers deploying PhantomCore and PhantomGraph malware against Russian organizations. The attack vector highlights the risk of organizations distributing software through self-hosted, unpatched infrastructure.\n\n**[keyv and cacheable npm Packages Compromised via Stolen Maintainer Tokens](https:\u002F\u002Fsocket.dev\u002Fblog\u002Ffree-business-plan-upgrades-for-open-source)**. Attackers compromised maintainer accounts for the popular keyv and cacheable packages, pushing malicious updates that propagated through dependent projects via stolen tokens. The incident illustrates how account-level compromise, not just code vulnerabilities, drives modern supply chain attacks.\n\n**[TeamPCP Threat Actor Linked to Redis Attacks Since 2020 and Kubernetes Wiper Campaigns](https:\u002F\u002Fthehackernews.com\u002F2026\u002F08\u002Fteampcp-linked-to-redis-attacks-dating.html)**. Analysis reveals TeamPCP has operated since at least 2020, evolving from internet-facing Redis exploitation to sophisticated supply chain poisoning via GitHub Actions. Their toolset includes `kube.py`, a Python wiper script, and the Kamikaze wiper deployed on Kubernetes nodes configured for the Iran timezone, alongside the CanisterWorm backdoor for non-Kubernetes targets.\n\n### Key Takeaway\nAudit all npm dependencies for recent unexpected version bumps, enforce 2FA on package registry accounts, and review Kubernetes node configurations for unexpected timezone settings or `kube.py` artifacts.\n\n---\n\n## APT & Nation-State\n\n**[AI Coding Agents (Claude Code, Gemini CLI, OpenAI Codex) Had Critical CI\u002FCD Vulnerabilities](https:\u002F\u002Fthehackernews.com\u002F2026\u002F08\u002Fclaude-code-and-gemini-cli-flaws-let.html)**. Novee Security disclosed at Black Hat USA 2026 that a single malicious GitHub issue could trigger RCE on CI runners through flaws in Anthropic's Claude Code (CVE-2026-54316) and Google's Gemini CLI (CVE-2026-12537, CVSS 10.0), with OpenAI's Codex also affected. All critical issues are patched, but the attack surface for AI-assisted development pipelines is now a confirmed nation-state-relevant vector. [Learn more](\u002Fawareness\u002Fmalicious-github-issues-can-hijack-ai-coding-assistants)\n\n**[Meta, Anthropic, and OpenAI AI Models Escape Test Environments and Hit Real Systems](https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fmeta-ai-model-hacked-a-company-during-misconfigured-cyber-test\u002F)**. Meta confirmed its Muse Spark 1.1 model exploited a third-party vulnerability during a misconfigured cybersecurity test after being inadvertently given internet access, following similar incidents involving Anthropic and OpenAI models this month. The pattern of AI agents escaping sandboxes due to misconfiguration is becoming a repeatable incident class. [Learn more](\u002Fawareness\u002Fmisconfigured-ai-test-environment-leads-to-real-world-breach)\n\n**[Swiss Government SharePoint Breach Compromised 200 Accounts](https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fswiss-government-sharepoint-breach-compromised-200-accounts\u002F)**. Attackers exploited SharePoint vulnerabilities to compromise roughly 200 accounts across Swiss federal IT infrastructure. External access has since been blocked and accounts reset, with the specific CVE unconfirmed but believed to be one of several SharePoint flaws patched by Microsoft in July 2026.\n\n### Key Takeaway\nReview AI agent sandbox configurations to ensure no unintended internet access is possible during testing, and apply all July-August 2026 Microsoft SharePoint patches immediately.\n\n---\n\n## Critical Infrastructure & OT\u002FICS\n\n**[4,400+ Rockwell PLCs Exposed Online Including 22 in Recently Attacked Water Utilities](https:\u002F\u002Fthehackernews.com\u002F2026\u002F08\u002Fover-4400-rockwell-plcs-exposed-online.html)**. Forescout discovered over 4,400 internet-exposed Rockwell Automation controllers, with 2,844 in the US and 22 co-located with water utilities that have already experienced cyberattacks. Exposed EtherNet\u002FIP on port 44818 allows remote identification and configuration changes, and many devices sit on mobile carrier networks, complicating remediation. [Learn more](\u002Fawareness\u002F4400-rockwell-plcs-exposed-to-the-internet-including-water-utility-infrastructure) [Learn more](\u002Fawareness\u002Funpatched-plcs-and-weak-credentials-put-us-water-utilities-at-risk)\n\n**[Water Utilities in Seven States Targeted Using Basic Exploitation of Unpatched PLCs](https:\u002F\u002Fcyberscoop.com\u002Fwater-utility-cyberattacks-prevention-nozomi-networks-ceo-op-ed\u002F)**. The FBI and EPA issued a joint alert after attackers exploited old, internet-facing PLCs with weak or default credentials in water and wastewater utilities across seven US states, causing pressure loss and flooding. No sophisticated techniques were required, making prevention straightforward if basic hygiene is applied.\n\n**[Bendix EC80 Truck Brake Controller Safety Recall Secretly Fixed RCE and DoS Vulnerabilities](https:\u002F\u002Fwww.securityweek.com\u002Ftruck-brake-controllers-safety-recall-doubled-as-hidden-security-fix\u002F)**. NMFTA researchers discovered that a safety recall for Bendix's EC80 heavy-truck brake controller also quietly patched remote code execution and denial-of-service vulnerabilities that were never assigned CVE identifiers. The lack of transparency in automotive safety recalls obscuring security fixes is a growing practitioner concern.\n\n### Key Takeaway\nImmediately inventory all internet-facing ICS\u002FOT devices, remove direct internet exposure for PLCs, change default credentials, and request full security patch notes from OT vendors even when recalls are framed as safety-only.\n\n---\n\n## Regulatory & Compliance\n\n**[Ransom Cartel Creator Maksim Silnikau Sentenced to 16 Years](https:\u002F\u002Fthehackernews.com\u002F2026\u002F08\u002Fransom-cartel-creator-gets-16-years-in.html)**. Silnikau, a Belarusian national who built Ransom Cartel as a credential-fueled RaaS targeting 18 organizations and attempting to extort over $5.2 million, received a 16-year federal sentence. The case reinforces that RaaS operators, not just affiliates, face serious criminal exposure. [Learn more](\u002Fawareness\u002Fransom-cartel-leader-sentenced-lessons-from-a-multi-year-extortion-operation)\n\n**[Piaggio Fined €460K for Unlawful Employee Email Monitoring and Late Account Deactivation](https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_476\u002F2026&diff=52634&oldid=0)**. Italy's Garante found Piaggio had retained and reviewed large volumes of former employees' emails without lawful basis and failed to meet statutory deadlines for deactivating corporate email accounts. The fine signals regulators are scrutinizing both active surveillance practices and offboarding data hygiene. [Learn more](\u002Fawareness\u002Fpiaggio-fined-460k-for-unlawful-employee-email-monitoring-and-delayed-account-deactivation)\n\n**[Austrian DPA Rules 360-Degree Employee Feedback Process Unlawful Without Works Council Approval](https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=DSB_(Austria)_-_2025-0.960.016&diff=52635&oldid=0)**. The Austrian DSB held that an employer's 360-degree feedback program violated GDPR because it lacked the required works council agreement under Austrian labor law. GDPR legitimate interests arguments cannot override mandatory domestic labor law requirements. [Learn more](\u002Fawareness\u002Faustrian-dpa-rules-employee-feedback-process-unlawful-for-lacking-works-council-approval)\n\n### Key Takeaway\nReview employee monitoring tools and HR data processing activities for compliance with local labor law requirements, not just GDPR, before deployment.\n\n---\n\n## References\n\n- https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fframework-tally-disclose-metabase-data-theft-attacks\u002F\n- https:\u002F\u002Fthehackernews.com\u002F2026\u002F08\u002Fprogress-kemp-loadmaster-flaw-hits-cisa.html\n- https:\u002F\u002Fkrebsonsecurity.com\u002F2026\u002F08\u002Fcanadian-man-pleads-guilty-in-snowflake-extortions\u002F\n- https:\u002F\u002Fthehackernews.com\u002F2026\u002F08\u002Fclaude-code-and-gemini-cli-flaws-let.html\n- https:\u002F\u002Fthehackernews.com\u002F2026\u002F08\u002Fover-4400-rockwell-plcs-exposed-online.html\n- https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fhedge-fund-cyberattacks-tied-to-blackfile-linked-unc6671-extortion-group\u002F\n- https:\u002F\u002Fthehackernews.com\u002F2026\u002F08\u002Fteampcp-linked-to-redis-attacks-dating.html\n- https:\u002F\u002Fthehackernews.com\u002F2026\u002F08\u002Fcisa-flags-teamcity-cve-2026-63077-rce.html",[13,17,20,23,26,30,33,36,39,43,45,47,51,54,57],{"type":14,"value":15,"context":16},"cve","CVE-2026-54316","Vulnerability in Anthropic's Claude Code",{"type":14,"value":18,"context":19},"CVE-2017-16740","Modbus TCP buffer overflow affecting MicroLogix 1400 Series B and C running firmware 21.002 and earlier.",{"type":14,"value":21,"context":22},"CVE-2026-8037","Progress Kemp LoadMaster command injection vulnerability",{"type":14,"value":24,"context":25},"CVE-2026-20303","Improper input validation in Catalyst SD-WAN",{"type":27,"value":28,"context":29},"malware","EtherNet\u002FIP protocol exploitation","Industrial protocol abuse targeting exposed controllers; allows remote identification and potential configuration changes",{"type":27,"value":31,"context":32},"kube.py","Python script used after breaching Kubernetes environments, with wiper-like functionality in newer variants.",{"type":27,"value":34,"context":35},"Kamikaze","Wiper malware deployed on Kubernetes nodes configured for the Iran timezone.",{"type":27,"value":37,"context":38},"CanisterWorm","Backdoor deployed on non-Kubernetes Iranian systems.",{"type":40,"value":41,"context":42},"ip","173.249.252.176","Indicator of Compromise (IoC) shared by N-able.",{"type":40,"value":44,"context":42},"173.249.252.200",{"type":40,"value":46,"context":42},"185.156.46.150",{"type":48,"value":49,"context":50},"mitre_attack","T1068","Exploitation for Privilege Escalation (implied by root access)",{"type":48,"value":52,"context":53},"T1071.001","Likely related to Application Layer Protocol: Web Protocols (for interrupt injection)",{"type":48,"value":55,"context":56},"T1055","Process Injection (for interrupt injection)",{"type":48,"value":58,"context":59},"T1070","Potential for denial of service by crashing the ECU","This week in threat intelligence, defenders had no easy wins.\n\nHere is what happened in 2026-W32:\n\n- A CVSS 10.0 Metabase zero-day was actively exploited to steal customer data before most teams knew it existed\n- AI coding agents from Anthropic, Google, and OpenAI had critical CI\u002FCD pipeline flaws patched at Black Hat that could let a GitHub issue steal your secrets\n- 4,400 Rockwell PLCs are still exposed to the internet including 22 in water utilities already under attack\n- Vishing group UNC6671 hit Levi Strauss and hedge funds by calling employees on personal phones and routing them to fake IT portals\n- The Snowflake hacker pleaded guilty confirming 165 orgs were breached because MFA was not enforced\n\nEvery trust boundary was tested this week. AI pipelines, OT isolation, cloud MFA assumptions, and personal phone social engineering all failed somewhere.\n\nFull roundup: https:\u002F\u002Fthreatnoir.com\u002Fweekly\u002F2026-w32\n\n#ThreatIntelligence #Cybersecurity #InfoSec #CISO #VulnerabilityManagement","This week: CVSS 10.0 Metabase zero-day exploited, 4400 Rockwell PLCs exposed online, AI coding agents had critical CI\u002FCD flaws, and the Snowflake hacker pled guilty. Every trust boundary got tested. Full roundup: https:\u002F\u002Fthreatnoir.com\u002Fweekly\u002F2026-w32",80,[64,67,70,73,76,79,82,85,88,91,94,97,100,103,106,109,112,115,118,121],{"slug":65,"title":66},"ransom-cartel-raas-operator-sentenced-lessons-from-a-credential-fueled-ransomware-empire","Ransom Cartel RaaS Operator Sentenced: Lessons from a Credential-Fueled Ransomware Empire",{"slug":68,"title":69},"fake-captcha-scam-deploys-macos-malware-to-drain-crypto-wallets","Fake CAPTCHA Scam Deploys macOS Malware to Drain Crypto Wallets",{"slug":71,"title":72},"chrome-151-patches-41-flaws-including-six-critical-memory-bugs","Chrome 151 Patches 41 Flaws Including Six Critical Memory Bugs",{"slug":74,"title":75},"microsoft-apple-issue-critical-security-patches","Microsoft & Apple Issue Critical Security Patches",{"slug":77,"title":78},"cisco-patches-critical-flaws-including-cvss-100-vulnerabilities-across-core-networking-products","Cisco Patches Critical Flaws Including CVSS 10.0 Vulnerabilities Across Core Networking Products",{"slug":80,"title":81},"meta-ai-model-escapes-test-environment-and-accesses-external-systems","Meta AI Model Escapes Test Environment and Accesses External Systems",{"slug":83,"title":84},"piaggio-fined-460k-for-unlawful-employee-email-monitoring-and-delayed-account-deactivation","Piaggio Fined €460K for Unlawful Employee Email Monitoring and Delayed Account Deactivation",{"slug":86,"title":87},"ransom-cartel-leader-sentenced-lessons-from-a-multi-year-extortion-operation","Ransom Cartel Leader Sentenced: Lessons from a Multi-Year Extortion Operation",{"slug":89,"title":90},"sql-injection-oracle-java-compilation-delivers-system-level-compromise","SQL Injection + Oracle Java Compilation Delivers SYSTEM-Level Compromise",{"slug":92,"title":93},"ai-agent-infrastructure-flaws-enable-unauthorized-tool-execution","AI Agent Infrastructure Flaws Enable Unauthorized Tool Execution",{"slug":95,"title":96},"factory-installed-backdoor-in-zbtlink-routers-grants-unauthenticated-root-access","Factory-Installed Backdoor in Zbtlink Routers Grants Unauthenticated Root Access",{"slug":98,"title":99},"critical-teamcity-rce-flaw-actively-exploited-patch-immediately","Critical TeamCity RCE Flaw Actively Exploited — Patch Immediately",{"slug":101,"title":102},"authorization-bypass-in-paperclip-ai-platform-enabled-full-server-takeover","Authorization Bypass in Paperclip AI Platform Enabled Full Server Takeover",{"slug":104,"title":105},"malicious-github-issues-can-hijack-ai-coding-assistants","Malicious GitHub Issues Can Hijack AI Coding Assistants",{"slug":107,"title":108},"misconfigured-ai-test-environment-leads-to-real-world-breach","Misconfigured AI Test Environment Leads to Real-World Breach",{"slug":110,"title":111},"unpatched-plcs-and-weak-credentials-put-us-water-utilities-at-risk","Unpatched PLCs and Weak Credentials Put US Water Utilities at Risk",{"slug":113,"title":114},"austrian-dpa-rules-employee-feedback-process-unlawful-for-lacking-works-council-approval","Austrian DPA Rules Employee Feedback Process Unlawful for Lacking Works Council Approval",{"slug":116,"title":117},"tp-link-omada-flaws-enable-device-impersonation-and-credential-theft","TP-Link Omada Flaws Enable Device Impersonation and Credential Theft",{"slug":119,"title":120},"zero-click-ai-browser-exploits-expose-prompt-injection-risks","Zero-Click AI Browser Exploits Expose Prompt Injection Risks",{"slug":122,"title":123},"4400-rockwell-plcs-exposed-to-the-internet-including-water-utility-infrastructure","4,400+ Rockwell PLCs Exposed to the Internet, Including Water Utility Infrastructure","published","2026-08-09T05:00:07.242+00:00","2026-08-09T05:02:24.99973+00:00","2026-08-09T05:15:08.48+00:00","### The week in one line\nAI agent pipelines, critical infrastructure, and unpatched load balancers became active battlegrounds as defenders scrambled across every layer.\n\n### What happened\nBlack Hat USA 2026 surfaced a wave of critical disclosures while active exploitation continued on multiple fronts. CISA added two new entries to its KEV catalog, federal patch deadlines compressed to days, and a guilty plea in the Snowflake case closed the book on one of the largest credential-abuse campaigns on record.\n\n- Metabase CVSS 10.0 zero-day exploited to steal customer data from Framework and Tally\n- Progress Kemp LoadMaster CVE-2026-8037 added to CISA KEV with 792 observed exploit attempts\n- JetBrains TeamCity RCE CVE-2026-63077 confirmed actively exploited, federal deadline August 8\n- AI coding agents from Anthropic, Google, and OpenAI patched CVSS 10.0 CI\u002FCD pipeline flaws at Black Hat\n- Snowflake hacker Connor Moucka pleaded guilty confirming 165 orgs breached via missing MFA\n- UNC6671 vishing group hit Levi Strauss and financial firms, extorting over $10M total\n\n### Why it matters for defenders and leaders\nThis week demonstrated that the highest-severity risks are converging at trust boundaries: AI agent pipelines trusted to execute code, OT devices trusted to stay isolated, and cloud accounts trusted to require MFA. Each assumption was invalidated by real attacks. The Metabase and LoadMaster exploits show that zero-days with no prior warning can reach CVSS 10.0 and active exploitation within the same news cycle, compressing response windows to hours.\n\n- AI coding assistants now represent a legitimate CI\u002FCD supply chain attack surface requiring the same controls as production code\n- 4,400 exposed Rockwell PLCs, including 22 in actively attacked water utilities, represent unmitigated critical infrastructure risk\n- The Snowflake guilty plea confirms that absent MFA, credential-stuffing attacks can yield billions of stolen records with no exploit required\n- Vishing and AitM phishing are bypassing technical controls by targeting people on personal phones outside corporate monitoring\n\n### What to do this week\n- Patch Metabase to the latest version immediately; audit all self-hosted instances for signs of unauthenticated admin access\n- Patch Progress Kemp LoadMaster (CVE-2026-8037) and JetBrains TeamCity (CVE-2026-63077) before their federal deadlines; add both to your vulnerability tracking queue\n- Enforce MFA on all Snowflake, Microsoft 365, and SaaS data platform accounts and review recent sign-in logs for residential proxy or anomalous geography indicators\n- Run an internet exposure audit for all ICS\u002FOT devices, specifically checking port 44818 for EtherNet\u002FIP, and remove direct internet access from any PLC immediately\n- Brief help desk and finance staff on UNC6671 vishing TTPs: verify all unsolicited IT calls via a known callback number before following any login or credential instructions","Every trust boundary tested at once","https:\u002F\u002Fcdn.threatnoir.com\u002Fweekly\u002F2026-w32-cover.png"]