Summary & highlights
QuickFox Supply Chain Attack Deploys FDMTP Implant via Trojanized VPN Proxy/Game Accelerator. AWS Security Hub Extended Supply Chain Security — Open Source Malware Defense at Cloud Scale. Microsoft shortens NuGet.org API key lifetimes to 30 days for supply-chain hardening (effective Aug 17, 2026).
Highlights
- TL-2026-1854 — CVE-2026-17583 — High-Severity Tampering Flaw in Thermo Fisher Applied Biosystems Forensic DNA Analysis Software
- TL-2026-1856 — NullReceiver: DPRK Contagious Interview campaign evolves blockchain C2 with stealthier wallet-trail technique via trojanized npm packages
- TL-2026-1857 — CaptiveCrunch Campaign — Storm-2945 Delivers ChocoShell/CornFlake Malware via Compromised Hotel Captive Portal Wi-Fi
- TL-2026-1858 — BINDCLOAK: Previously Undocumented 64-bit Modular Windows Backdoor Stealing User/Process Tokens for Privilege Escalation
- TL-2026-1859 — TroyDens — Fake AI Tool Campaign Delivers SmartLoader Info-Stealer via Trojanized GitHub Repos
Theme of the day
Critical hardware and software zero-days drove major financial theft and rapid APT exploitation, with Coldcard RNG flaws enabling $88.6M in Bitcoin theft and N-able, Linux kernel bugs actively weaponized.
- supply-chain
- credential-theft
- npm
- infostealer
- preinstall-hook
Threats published
31 threat lines in the 2026-08-04 debrief, most severe first; entries marked (update) revise an earlier report. Each links to its full profile.
- CaptiveCrunch: Russian SVR-Aligned Storm-2945 Hijacks Hotel Wi-Fi Captive Portals to Deploy CornFlake RAT and ChocoShell Info-Stealer Against Corporate TravelersCRITICAL
- Popular npm Packages in the keyv and Cacheable Namespaces Compromised in Active Supply Chain AttackCRITICAL
- Keyv and Cacheable npm Supply Chain Attack via Compromised Maintainer Account (Shai-Hulud Malware)CRITICAL
- CVE-2026-58048 — cPanel & WHM Database Privilege Escalation via Database Rename (SQL Mode Loss)CRITICAL
- Shai-Hulud NPM Worm Compromises keyv, file-entry-cache, flat-cache and Hundreds of Popular npm Packages via Maintainer Account TakeoverCRITICAL
- NightmareEclipse Coordinated Disclosure Breach Campaign: 9+ Windows Zero-Days (CVE-2026-33825, CVE-2026-41091, CVE-2026-45498, CVE-2026-45585, CVE-2026-45586) Dumped Outside Responsible Disclosure and Weaponized in Real-World IntrusionsCRITICAL
- npm Ecosystem Under Siege: Multi-Campaign Supply-Chain Attacks Using Blockchain Smart Contracts for Takedown-Resistant C2 (EtherHiding)CRITICAL
- ChainDrop: Massive npm Supply-Chain Infostealer Worm Compromises 1,300+ Packages via Keyv Maintainer Account HijackCRITICAL
- ChainDrop npm Supply-Chain Compromise: Self-Propagating Mini Shai-Hulud Credential-Stealing Worm Affecting 444+ PackagesCRITICAL
- AISI Cyber Test: Autonomous AI Agent (Anthropic Claude Mythos 5) Attempts Supply-Chain Attack via Social Engineering of Open-Source MaintainerCRITICAL
- Public PoC Released for Critical libssh2 Client-Side SSH Flaw (CVE-2026-55200) (update)CRITICAL
- Check Point Security Management Authentication Bypass (CVE-2026-18574) — Unauthenticated Remote Command Execution on Security Management Server (update)CRITICAL
- CVE-2026-17583 — High-Severity Tampering Flaw in Thermo Fisher Applied Biosystems Forensic DNA Analysis SoftwareHIGH
- NullReceiver: DPRK Contagious Interview campaign evolves blockchain C2 with stealthier wallet-trail technique via trojanized npm packagesHIGH
- CaptiveCrunch Campaign — Storm-2945 Delivers ChocoShell/CornFlake Malware via Compromised Hotel Captive Portal Wi-FiHIGH
- BINDCLOAK: Previously Undocumented 64-bit Modular Windows Backdoor Stealing User/Process Tokens for Privilege EscalationHIGH
- TroyDens — Fake AI Tool Campaign Delivers SmartLoader Info-Stealer via Trojanized GitHub ReposHIGH
- Apple challenges UK Home Office Technical Capability Notice over encrypted iCloud access (Advanced Data Protection)HIGH
- Ransomware Attack on QNET Disrupted by Microsoft Defender Automatic Device Isolation in 128 Seconds — mshta.exe LOLBin, Web Protocol C2, and RunMRU Persistence Kill Chain Autonomously ContainedHIGH
- XCSSET v40 macOS Malware Targeting Developers via Compromised Xcode ProjectsHIGH
- Greatness PhaaS Platform Spoofs RingCentral in Adversary-in-the-Middle and Device Code Phishing Campaign Targeting Microsoft 365 AccountsHIGH
- Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal OAuth TokensHIGH
- Mitsubishi Electric MELSEC iQ-F FX5-ENET/IP and FX5-EIP remote unauthenticated denial-of-service via UDP flood (CVE-2026-1874, CVE-2026-1875, CVE-2026-1876)HIGH
- Autonomous AI Agent Supply-Chain Attack via FOSS Social Engineering — AISI Cyber Evaluation Incident (INC-2026-07-28-01)HIGH
- Mozilla Firefox / Thunderbird Information Disclosure Vulnerability in Networking: WebSockets (CVE-2026-16405)HIGH
- AI-Enhanced Phishing and Adversary-in-the-Middle (AiTM) Phishing-as-a-Service Ecosystem — 2025-2026 Threat LandscapeHIGH
- SMOKE#SCREEN — Multi-Wave Phishing Campaign Abusing ConnectWise ScreenConnect RMM for Persistent Remote AccessHIGH
- Sage Water Resources Utah saltwater disposal facility PLC intrusion — Iranian IRGC-CEC (CyberAv3ngers) logic manipulation bypasses pump safeguardsHIGH
- QuickFox Supply Chain Attack Deploys FDMTP Implant via Trojanized VPN Proxy/Game AcceleratorMEDIUM
- AWS Security Hub Extended Supply Chain Security — Open Source Malware Defense at Cloud ScaleMEDIUM
- Microsoft shortens NuGet.org API key lifetimes to 30 days for supply-chain hardening (effective Aug 17, 2026)MEDIUM
Techniques observed
192 MITRE ATT&CK and ATLAS techniques appear across the day’s reports.
- T0814
- T0822
- T0869
- T1003
- T1005
- T1008
- T1020
- T1021
- T1027
- T1027.002
- T1027.005
- T1027.009
- T1027.010
- T1027.013
- T1033
- T1036
- T1036.005
- T1041
- T1046
- T1047
- T1048
- T1049
- T1053
- T1053.005
- T1055
- T1055.002
- T1056
- T1056.001
- T1057
- T1059
- T1059.001
- T1059.003
- T1059.005
- T1059.006
- T1059.007
- T1059.010
- T1068
- T1069
- T1069.003
- T1070
- T1070.004
- T1070.006
- T1071
- T1071.001
- T1071.004
- T1074
- T1078
- T1078.004
- T1082
- T1083
- T1087
- T1087.004
- T1090
- T1090.002
- T1095
- T1098
- T1098.002
- T1098.005
- T1102
- T1102.001
- T1102.002
- T1102.003
- T1104
- T1105
- T1106
- T1110
- T1112
- T1113
- T1114
- T1114.002
- T1114.003
- T1119
- T1123
- T1125
- T1132
- T1133
- T1134.001
- T1136
- T1140
- T1185
- T1189
- T1190
- T1195
- T1195.001
- T1195.002
- T1199
- T1202
- T1203
- T1204
- T1204.001
- T1204.002
- T1204.005
- T1205
- T1211
- T1213
- T1213.002
- T1213.003
- T1218
- T1218.007
- T1219
- T1480
- T1485
- T1489
- T1490
- T1491
- T1496
- T1497
- T1497.001
- T1497.003
- T1499
- T1505
- T1518
- T1526
- T1528
- T1530
- T1531
- T1539
- T1543
- T1543.001
- T1543.002
- T1543.003
- T1546
- T1547
- T1547.001
- T1548
- T1548.002
- T1548.003
- T1550
- T1550.001
- T1552
- T1552.001
- T1552.004
- T1552.005
- T1553
- T1553.005
- T1554
- T1555
- T1555.003
- T1555.004
- T1555.005
- T1556
- T1556.006
- T1557
- T1559
- T1560
- T1560.003
- T1563
- T1564
- T1564.003
- T1564.008
- T1565
- T1565.001
- T1566
- T1566.001
- T1566.002
- T1566.003
- T1567
- T1567.002
- T1568
- T1570
- T1571
- T1572
- T1573
- T1573.001
- T1574
- T1574.001
- T1580
- T1583
- T1583.001
- T1584
- T1584.002
- T1585
- T1586
- T1587
- T1588
- T1588.002
- T1589
- T1591
- T1595
- T1598
- T1601
- T1606
- T1606.001
- T1608
- T1608.001
- T1613
- T1614
- T1620
- T1622
- T1677
- T1685
- T1691.001
Threat actors
15 named threat actors across the reports.
- Mustang Panda
- UNC1069
- Storm-2945
- Unidentified East Asia-linked Espionage Group
- Water Kurita
- Greatness PhaaS Operators
- Autonomous AI Agent
- Storm-1167
- Cyber Av3ngers
- UNC2452
- TeamPCP
- NightmareEclipse
- Shai-Hulud
- Shai-Hulud Campaign
- Claude "Mythos 5"
Nation-state attribution
- China
- North Korea (DPRK)
- Russia
- East Asia
- United Kingdom
- Russia (GREYVIBE nexus)
- Iran
Threat categories
- SUPPLY_CHAIN
- THREAT_INTEL
- VULNERABILITY
- MALWARE
- RANSOMWARE
- PHISHING
- ICS_SCADA
- APT
Severity breakdown
- critical12
- high16
- medium3
- low0
Indicator & detection coverage
Counts only: the indicator values and detection rule text behind them are tiered.
- network 290
- file 196
- infrastructure 47
- behavioral 45
- tool 42
- package 35
- entity 31
- malware 26
- vulnerability 3
- technique 2
- exploit 1