Summary & highlights
GovCERT.HK Security Alert A26-08-01: Multiple Vulnerabilities in Microsoft Edge, Office 2019/LTSC 2021/LTSC 2024, Excel 2016, and Microsoft 365 Apps for Enterprise. ModernStealer: Cross-Platform Dark Web/Telegram Broker Network Claims Sale of Government and Defense Data. EU AI Act Article 50 Enforcement — Regulatory Transparency Obligations and Documented Cybersecurity Attack Surface from AI Content Provenance Bypass Techniques.
Highlights
- TL-2026-1825 — CVE-2026-50641: Plaintext Password Storage in Streamsoft Business Intelligence
- TL-2026-1831 — CVE-2026-31431: Linux Local Privilege Escalation Actively Exploited by UMBRAL BISON Within 24 Hours of Disclosure
- TL-2026-1832 — Octagon / OctagonPanel "Ward" Android RAT Impersonates Bahrain's "BH Alert" Civil Defense App to Steal Credentials, SMS/OTPs, and Banking Data
- TL-2026-1833 — Larva-24009 (aka HeptaX) Spear-Phishing Campaign Deploys QuasarRAT, UltraVNC and Updated Notifier Backdoor
- TL-2026-1834 — Alleged Żabka Polska Breach: 541K Jira Issues, 230K IT Tickets, 89 GitLab Repos, and Cloudflare/MongoDB/Broker Credentials Offered for €5,000
Theme of the day
Activity centered on 2fa-bypass, access-control-violation, account-discovery-risk.
- credential-theft
- cisa-kev
- social-engineering
- authentication-bypass
- active-exploitation
Threats published
35 threat lines in the 2026-08-03 debrief, most severe first; entries marked (update) revise an earlier report. Each links to its full profile.
- Coldcard Hardware Wallet RNG Flaw Enables $88.6M Bitcoin Theft from 4,585 AddressesCRITICAL
- N-able N-central Authentication Bypass (CVE-2026-18577) Actively Exploited for Admin TakeoverCRITICAL
- Coldcard Hardware Wallet Firmware RNG Flaw (No CVE Assigned) Linked to $88.6M Multi-Wave Bitcoin TheftCRITICAL
- CaptiveCrunch: Storm-2945 (Midnight Blizzard / APT29) compromises hotel WiFi gateways globally for credential theft and malware deliveryCRITICAL
- XCSSET v40 — macOS Developer Supply-Chain Malware Infecting Xcode Projects with Chrome CDP Hijacking and Telegram TrojanizationCRITICAL
- Coldcard Firmware RNG Flaw Enables Coordinated Bitcoin Wallet Theft ($70.2M Drained)CRITICAL
- Coldcard/Coinkite Hardware Wallet RNG Vulnerability Exploited — $88M+ Bitcoin StolenCRITICAL
- CVE-2026-16812 — Critical Unauthenticated OS Command Injection in Arista VeloCloud Orchestrator Actively ExploitedCRITICAL
- Check Point Security Management Authentication Bypass (CVE-2026-18574) — Unauthenticated Remote Command Execution on Security Management ServerCRITICAL
- DarkSword: iOS Exploit Chain Adopted by Multiple Threat Actors (CVE-2026-20700, CVE-2025-43529, CVE-2025-31277) (update)CRITICAL
- Iranian IRGC CyberAv3ngers APT Campaign Targeting Rockwell/Allen-Bradley PLCs (CISA AA26-097A) (update)CRITICAL
- Check Point Remote Access & Mobile Access VPN IKEv1 Authentication Bypass (CVE-2026-50751) Exploited by Qilin Ransomware Affiliate (update)CRITICAL
- CVE-2026-66066 "KindaRails2Shell": Critical Ruby on Rails Active Storage Flaw Allows Unauthenticated Arbitrary File Read / RCE via libvips Image Processing (update)CRITICAL
- CVE-2026-20316: Cisco Secure Firewall Management Center Hard-coded Password Vulnerability Added to CISA KEV (update)CRITICAL
- CVE-2026-50641: Plaintext Password Storage in Streamsoft Business IntelligenceHIGH
- CVE-2026-31431: Linux Local Privilege Escalation Actively Exploited by UMBRAL BISON Within 24 Hours of DisclosureHIGH
- Octagon / OctagonPanel "Ward" Android RAT Impersonates Bahrain's "BH Alert" Civil Defense App to Steal Credentials, SMS/OTPs, and Banking DataHIGH
- Larva-24009 (aka HeptaX) Spear-Phishing Campaign Deploys QuasarRAT, UltraVNC and Updated Notifier BackdoorHIGH
- Alleged Żabka Polska Breach: 541K Jira Issues, 230K IT Tickets, 89 GitLab Repos, and Cloudflare/MongoDB/Broker Credentials Offered for €5,000HIGH
- 1337_GTWK Linux Kernel Rootkit — AI-Assisted Malware-as-a-Service (elf.1337_gtwk_rootkit)HIGH
- Inside the Underground Business of the BTMOB Android RAT Malware-as-a-ServiceHIGH
- Pass-ta-key: Novel Attack Surface in Google Password Manager Synced Passkey AuthenticationHIGH
- Google Password Manager — Three Post-Compromise Attack Paths Against Chrome Cloud Authenticator (Pass-ta-key / Silver Pass-ta-key / Golden Pass-ta-key)HIGH
- BINDCLOAK Backdoor Campaign Targeting Middle East Government EntitiesHIGH
- Fake AI Developer Tool Installers Delivering Infostealer via SEO Poisoning and TyposquattingHIGH
- Fake Roblox Xeno Script Launcher Pushes Multi-Stage Java-Based Infostealer and RAT Malware (Powercat Campaign)HIGH
- DOUBLECUP ClickFix Loader-as-a-Service Hides Malware in Browser Cache Images via SteganographyHIGH
- Pass-ta-key Attacks Enable Malware to Hijack Google-Synced Passkeys via Chrome/TPM/Google Cloud Authenticator WeaknessesHIGH
- CaptiveCrunch: Storm-2945 (Midnight Blizzard sub-cluster) Hijacks Hotel Wi-Fi Captive Portals to Deliver CornFlake RAT and Steal Microsoft 365 Tokens (update)HIGH
- 18 Malicious npm Packages Deliver Cross-Platform RAT Targeting Alibaba Developer Tool Users (update)HIGH
- GovCERT.HK Security Alert A26-08-01: Multiple Vulnerabilities in Microsoft Edge, Office 2019/LTSC 2021/LTSC 2024, Excel 2016, and Microsoft 365 Apps for EnterpriseMEDIUM
- ModernStealer: Cross-Platform Dark Web/Telegram Broker Network Claims Sale of Government and Defense DataMEDIUM
- EU AI Act Article 50 Enforcement — Regulatory Transparency Obligations and Documented Cybersecurity Attack Surface from AI Content Provenance Bypass TechniquesMEDIUM
- Malwarebytes: Fake TikTok Follower/Engagement Services Expose Users to Account Takeover and Payment FraudLOW
- NVIDIA Releases SkillSpector: Open-Source Security Scanner for AI Agent SkillsLOW
Techniques observed
290 MITRE ATT&CK and ATLAS techniques appear across the day’s reports.
- T0806
- T0807
- T0809
- T0811
- T0813
- T0814
- T0819
- T0821
- T0822
- T0826
- T0828
- T0829
- T0831
- T0835
- T0836
- T0837
- T0838
- T0843
- T0846
- T0853
- T0858
- T0859
- T0861
- T0866
- T0868
- T0869
- T0878
- T0880
- T0883
- T0884
- T0885
- T0886
- T0888
- T0889
- T1003
- T1005
- T1007
- T1008
- T1010
- T1014
- T1016
- T1018
- T1020
- T1021
- T1021.001
- T1021.002
- T1021.004
- T1027
- T1027.003
- T1029
- T1033
- T1036
- T1036.003
- T1036.004
- T1036.005
- T1037
- T1039
- T1041
- T1046
- T1048
- T1049
- T1053
- T1053.005
- T1055
- T1055.009
- T1056
- T1056.001
- T1057
- T1059
- T1059.001
- T1059.003
- T1059.004
- T1059.006
- T1068
- T1069
- T1070
- T1071
- T1071.001
- T1071.004
- T1072
- T1074
- T1078
- T1078.003
- T1078.004
- T1082
- T1083
- T1087
- T1087.001
- T1087.004
- T1090
- T1090.002
- T1095
- T1098
- T1098.001
- T1098.005
- T1102
- T1102.002
- T1105
- T1106
- T1110
- T1110.002
- T1110.004
- T1111
- T1112
- T1113
- T1114
- T1115
- T1119
- T1120
- T1123
- T1125
- T1132
- T1132.001
- T1133
- T1134
- T1134.003
- T1136
- T1136.001
- T1140
- T1187
- T1189
- T1190
- T1195
- T1195.003
- T1199
- T1203
- T1204
- T1204.001
- T1204.002
- T1210
- T1211
- T1212
- T1213
- T1217
- T1218
- T1218.003
- T1218.005
- T1218.007
- T1219
- T1222.002
- T1398
- T1406
- T1407
- T1414
- T1417
- T1418
- T1420
- T1422
- T1424
- T1426
- T1429
- T1437
- T1453
- T1482
- T1485
- T1486
- T1489
- T1490
- T1496
- T1497
- T1497.001
- T1499
- T1505
- T1509
- T1513
- T1516
- T1518
- T1518.001
- T1521
- T1526
- T1528
- T1531
- T1533
- T1537
- T1539
- T1541
- T1542
- T1543
- T1543.001
- T1543.002
- T1543.003
- T1544
- T1546
- T1547
- T1547.001
- T1547.004
- T1547.006
- T1547.014
- T1548
- T1548.001
- T1548.002
- T1550
- T1550.001
- T1550.004
- T1552
- T1552.001
- T1552.002
- T1552.004
- T1553
- T1553.002
- T1554
- T1555
- T1555.003
- T1556
- T1557
- T1560
- T1564
- T1564.001
- T1564.003
- T1565
- T1566
- T1566.001
- T1566.002
- T1566.004
- T1567
- T1568
- T1569
- T1570
- T1571
- T1572
- T1573
- T1573.001
- T1573.002
- T1574
- T1580
- T1583
- T1583.001
- T1583.006
- T1584
- T1584.004
- T1584.006
- T1585
- T1585.001
- T1586.001
- T1587
- T1587.001
- T1587.004
- T1588
- T1588.001
- T1588.002
- T1588.005
- T1588.006
- T1589
- T1590
- T1591
- T1592
- T1592.002
- T1592.004
- T1593
- T1593.001
- T1593.003
- T1594
- T1595
- T1595.002
- T1596
- T1596.005
- T1598.003
- T1600.001
- T1600.002
- T1606
- T1608
- T1608.005
- T1608.006
- T1611
- T1613
- T1614
- T1614.001
- T1619
- T1620
- T1622
- T1624
- T1626
- T1628
- T1630
- T1632
- T1636
- T1646
- T1649
- T1650
- T1655
- T1657
- T1660
- T1663
- T1665
- T1684.001
- T1685
- T1686
- T1692.001
- T1692.002
- T1694.001
Threat actors
14 named threat actors across the reports.
- ModernStealer
- Criminal AI Abuse Ecosystem
- DuckTail
- UMBRAL BISON
- Larva-24009
- Markas Escobar
- EVLF
- Unidentified East Asia-Linked Threat Actor
- DOUBLECUP Operation
- Midnight Blizzard
- Storm-2945
- UNC6353
- Cyber Av3ngers
- Qilin ransomware affiliate
Nation-state attribution
- Vietnam
- Belarus
- Indonesia
- Unidentified (assessed East Asia)
- Russia
- Iran
Threat categories
- VULNERABILITY
- THREAT_INTEL
- FRAUD
- MALWARE
- DATA_BREACH
- APT
- ZERO_DAY
Severity breakdown
- critical14
- high16
- medium3
- low2
Indicator & detection coverage
Counts only: the indicator values and detection rule text behind them are tiered.
- network 316
- file 179
- behavioral 147
- entity 92
- infrastructure 72
- tool 57
- technique 54
- package 45
- malware 40