~/greenteam/nerd

Tuesday, August 4, 2026

Daily digest

Heavy vulnerability day: two actively-exploited RMM/VPN flaws (N-able, SonicWall) and a new Google Password Manager passkey attack chain all warrant fast attention alongside the ongoing APT29 hotel Wi-Fi campaign targeting Microsoft 365 credentials.

cybersec The Hacker News

CISA Adds Exploited N-able N-central Flaw to KEV After Customer Compromises

CISA added CVE-2026-18577 (CVSS 8.2), an authentication bypass in N-able N-central affecting both hosted and on-premises servers, to its Known Exploited Vulnerabilities catalog. The flaw is an incomplete patch for a previously fixed bug (CVE-2026-18556) and has already been used to compromise customer environments.

Why it matters: If N-central or similar RMM tooling is used to manage the Intune fleet or endpoints, this gives attackers admin access to management infrastructure — patch immediately and treat as a KEV-mandated remediation for federal contractors.

cybersec The Hacker News

INC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 Flaws

The INC Ransomware group has become the leading threat actor exploiting recently disclosed vulnerabilities in SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances, according to Resecurity. The group has accelerated activity since early August, listing multiple new victims on its data leak site.

Why it matters: SMA appliances are common remote-access gateways in government and contractor networks; unpatched instances are an active ransomware entry point and a direct 800-171 access-control concern.

cybersec The Hacker News

New cPanel Critical Flaw Could Let Hosting Customers Run SQL as Database Root

cPanel patched CVE-2026-58048 (CVSS 9.4), a flaw allowing an authenticated hosting customer to execute SQL in the database's root context, breaking the privilege boundary between a cPanel account and the server's administrative database identity. The security release also closed two other account-boundary escape routes.

cybersec The Hacker News

Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts

Unit 42 disclosed three attack paths — dubbed Pass-ta-key, Silver Pass-ta-key, and Golden Pass-ta-key — against Chrome's Google Password Manager cloud authenticator. Malware running as a standard user on Windows can sign into passkey-protected accounts without any biometric, PIN, or visible prompt, with the strongest variant targeting the master key.

Why it matters: Any Intune-managed Windows 11 devices using Chrome-synced passkeys for account access are exposed once malware has local user-level presence — passkeys should not be assumed phishing-proof against already-compromised endpoints.

cybersec BleepingComputer

Hotel Wi-Fi Attacks Use Custom Malware to Breach Microsoft 365 Accounts

Microsoft attributed a global campaign targeting hospitality Wi-Fi networks to the Russian state-sponsored group Midnight Blizzard (APT29). The attackers compromise hotel networks to steal credentials and deploy espionage malware against traveling users, including targeting Microsoft 365 logins.

Why it matters: Staff traveling with GCC High-enrolled devices on hotel Wi-Fi are a credential-theft target; enforce VPN-only or hotspot-only connectivity policy for M365 access on travel and review Conditional Access rules for untrusted networks.

cybersec Dark Reading

Device Code Phishing Up 1,500% in 2026; Vishing Doubles

New research shows device code phishing attacks rose 1,500% in 2026, alongside a doubling of voice-phishing (vishing) incidents. Both techniques are increasingly used to bypass entrenched security controls like MFA while leaving minimal forensic evidence.

Why it matters: Device code phishing directly targets Azure AD/Entra ID authentication flows used in M365 GCC High tenants — confirm device code flow is disabled or tightly restricted via Conditional Access if not already done.

cybersec The Hacker News

18 Malicious npm Packages Deliver Cross-Platform RAT to Alibaba Tool Users

Researchers found 18 malicious npm packages, including one impersonating the private Alibaba package "lib-mtop," delivering a cross-platform remote access trojan to users of Alibaba developer tools. The campaign targets Chinese-speaking development environments through a supply-chain dependency confusion technique.

Why it matters: A reminder to audit npm dependency pinning and private-package naming conventions in any Ansible/automation tooling pipelines that pull from public registries to avoid similar dependency-confusion exposure.

cybersec The Record

Biotech Giant Amgen Says Patient Data Stolen from Third-Party Cloud Systems

Amgen disclosed to regulators that patient information and proprietary company data were accessed through a breach of third-party cloud systems. The company filed the disclosure under SEC breach reporting requirements.

cmmc Federal News Network

Senate Stopgap Extends Key Cyber Authorities, TMF

The Senate's continuing resolution would keep the government funded through Dec. 11 while extending cyber information-sharing authorities and the Technology Modernization Fund. The CR also would delay OMB's planned grants process rewrite.

Why it matters: Continuity of cyber information-sharing authorities (CISA 2015 Act protections) affects incident-reporting liability shielding for contractors; watch for lapse risk if the CR doesn't pass cleanly.

cmmc FedScoop

FedRAMP Director Put on Administrative Leave After Veterans' Hiring Comments

FedRAMP director Pete Waterman was placed on administrative leave following comments on his personal LinkedIn criticizing veterans' hiring preference as applied to FedRAMP Cybersecurity Service civilian applicants, which he called "brutally unfair when taken to the extreme."

Why it matters: Leadership disruption at FedRAMP PMO could slow authorization processing timelines — relevant for tracking any pending ATO/authorization work tied to GCC High or AWS GovCloud service offerings.

cmmc NextGov

Lawmakers Propose Giving 2015 OPM Breach Victims Identity Protection for Life

A bipartisan bill would extend lifetime identity-protection coverage for the 22.1 million people affected by the 2015 China-linked OPM data breaches. Current coverage is scheduled to expire Sept. 30.

infrastructure The Register

AI Slop Pollutes the CVE Pipeline with Fake Vulns

Security researchers report a rising volume of AI-generated, low-quality or fabricated vulnerability reports flooding the CVE submission pipeline, worsening NIST's existing processing backlog. The trend threatens to slow legitimate vulnerability triage and scoring.

Why it matters: A degraded NVD/CVE pipeline directly affects vulnerability scanning and POA&M prioritization under 800-171/CMMC — expect longer delays getting authoritative CVSS scores for real flaws.

infrastructure The Register

Russian Spies Turn Public Wi-Fi into Malware Delivery Systems

Russia's SVR intelligence service has been observed compromising public and hospitality Wi-Fi networks to conduct keylogging, audio-visual surveillance, and authentication token theft via a tool dubbed CaptivePortal. Security agencies have put the hospitality sector on alert.