Weekly review
Week of August 3-9, 2026
The week featured a heavy wave of RMM/self-hosted tool exploitation (N-able, TeamCity, Metabase, Gitea) alongside continuing npm supply-chain worms, while CMMC remains in limbo with a public comment window closing and no clear replacement timeline; several notable items — a large healthcare breach, a fresh actively-exploited SharePoint RCE, and hard ransomware-volume data — didn't make the curated digests.
What you might have missed
Stories not surfaced in this week's daily digests.
CareCloud Notifies 345,000+ Patients of Cyberattack Data Theft
Healthcare technology vendor CareCloud disclosed that a cyberattack resulted in theft of names, Social Security numbers, driver's license numbers, financial account data, and medical/health insurance information for more than 345,000 patients. No ransomware group has claimed responsibility as of early August, and the threat actor remains undisclosed.
Why it matters: A large healthcare-sector breach exposing SSNs and financial data highlights third-party vendor risk that IT admins supporting healthcare clients need to track for breach-notification and downstream fraud exposure.
CMMC Reform Task Force RFI Comment Window Closes August 14
With CMMC Phase 2 (and all future phases) suspended pending review, the Pentagon's CMMC Reform Task Force opened a formal Request for Information soliciting industry recommendations on overhauling the program, with responses due by noon ET on August 14, 2026. Task force recommendations to the DoW CIO are expected roughly 60 days after the review began, putting a report in the mid-September timeframe, and DoD has cited SBA estimates that future CMMC phases could cost small/midsize firms over $7 billion annually against a shortage of roughly 100 authorized assessors for 100,000+ companies.
Why it matters: This is contractors' only near-term formal channel to influence how CMMC gets rebuilt, and the digest's CMMC coverage this week (early certifiers left stranded, DOT&E reports pulled) didn't surface this closing comment deadline.
Actively Exploited SharePoint RCE (CVE-2026-50522) Surfaces Amid Record-Setting Patch Tuesday
Following July's record-breaking Patch Tuesday — over 600 CVEs including 405 against Windows 11/Server 2025 and record counts for SharePoint and Office — Microsoft confirmed active exploitation of CVE-2026-50522, a SharePoint remote code execution flaw that lets attackers steal machine keys and maintain access even after patching. Analysts warn many organizations are still struggling to test and deploy the July patch backlog heading into August's cycle.
Why it matters: It directly bears on the Swiss government SharePoint breach the digest already flagged, suggesting a broader pattern of SharePoint-targeted intrusions that persist even after patching due to stolen machine keys.
Ransomware Attacks Jumped Nearly 20% in July, Utility Sector Hits Actually Down
UK research firm Comparitech counted 799 ransomware incidents in July, up from 668 in June, making it the second-busiest month of 2026 for ransomware. Notably, attacks on utility companies fell 44% during the same period even as water-sector intrusion headlines dominated coverage, indicating ransomware crews and state-linked infrastructure intruders are pursuing different targets.
Why it matters: The hard volume data adds important nuance to the digest's ransomware-targeting story by showing overall ransomware volume is climbing even as utility-sector ransomware specifically declines.
Themes this week
Patterns observed across coverage.
Enterprise remote-management and self-hosted tools are the week's dominant attack surface
N-able N-central needed two hotfix rounds after attackers reached customer systems, while TeamCity, Metabase, Gitea, Kemp LoadMaster, and now SharePoint all saw actively exploited critical flaws — a sustained wave against the admin/RMM tooling IT teams rely on daily.
Software supply chain poisoning continues unabated
The 1,300+-package ChainDrop npm worm, nearly 800 typosquatted malicious npm packages, trojanized TrueConf installers, and backdoored Zbtlink routers all point to attackers increasingly targeting build pipelines and distribution channels rather than end targets directly.
CMMC remains in prolonged limbo with real cost stakes
Beyond the digest's stories on stranded early-certified contractors and removed DOT&E reports, the Reform Task Force's RFI (due Aug 14) and DoD's own $7B/year cost estimate underscore that the program's future shape — and burden on small/midsize contractors — is still unresolved.
Attackers are moving down the org chart and off the beaten path
Ransomware crews now target mid-level IT managers over executives, AitM phishing hunts payroll/finance staff rather than C-suite, and Russian actors compromise hotel Wi-Fi to catch traveling employees — a consistent pivot toward less-defended entry points.
Suggested new sources
Worth considering for your feed list. Review and add manually.
Help Net Security
Broad practitioner-focused security news, vendor research roundups, and detailed Patch Tuesday analysisIts recurring Patch Tuesday forecast/retrospective pieces (like the one covering the SharePoint RCE above) give the kind of patch-management-load context that's largely absent from the current feed list.
RSS: https://www.helpnetsecurity.com/feed/
Industrial Cyber
OT/ICS and critical infrastructure security news and reportsGiven the digest's recurring water-utility and OT-modernization stories, a dedicated ICS/OT outlet would add depth the general cybersecurity feeds don't provide.
Wiz Research (Wiz Blog)
Cloud security research, including cloud misconfiguration and software supply-chain compromise analysisAs a vendor-neutral cloud-security research team, it frequently breaks or deeply analyzes supply-chain incidents (e.g., npm package compromises) that complement AWS's and Microsoft's own security blogs already in the feed.