Summary & highlights
Google Blogger Automated Malware False Positive Locks Hundreds of Blogs — Platform-Wide Enforcement Error Triggered by Tightened Safe Browsing Post-VEIL#DROP (August 2026). Immigration & Asylum Policy as an Enabler of Transnational Repression (Citizen Lab / Foreign Policy Centre policy analysis, IALDF v. Rubio lawsuit, Freedom House 2026). Botnet Scanning Internet-Exposed Router Diagnostic Tools Exploiting OS Command Injection (CVE-2024-12856, CVE-2013-7179, CVE-2020-8949, CVE-2024-48419).
Highlights
- TL-2026-1884 — Botnet Scanning Internet-Exposed Router Diagnostic Tools Exploiting OS Command Injection (CVE-2024-12856, CVE-2013-7179, CVE-2020-8949, CVE-2024-48419)
- TL-2026-1885 — CVE-2026-34486: Apache Tomcat EncryptInterceptor Bypass Actively Exploited in SnowLight and AI-Assisted Campaigns
- TL-2026-1886 — Pass-ta-Key Attacks Let Malware Hijack Google Password Manager Synchronized Passkeys (Chrome on Windows)
- TL-2026-1887 — OVSWrap (CVE-2026-64531): Linux kernel Open vSwitch datapath 16-bit nla_len wraparound local privilege escalation with public PoC targeting ~800 x86-64 kernel builds
- TL-2026-1888 — Three PhaaS Kits (Sneaky 2FA, EvilTokens, EvilProxy) Targeting US Organizations to Steal M365 Credentials and Session Tokens
Theme of the day
- credential-theft
- c2-infrastructure
- social-engineering
- remote-code-execution
- authentication-bypass
Threats published
27 threat lines in the 2026-08-05 debrief, most severe first; entries marked (update) revise an earlier report. Each links to its full profile.
- Octagon Android RAT — Fake Bahrain Civil Defense App Targets Mobile Endpoints via Multi-Stage PayloadCRITICAL
- ELECTRUM (Russian state-linked) PathWiper destructive wiper campaign targets Ukrainian ISPs and Polish CHP/energy facilitiesCRITICAL
- August 2026 Patch Roundup: 11 Critical/High CVEs in Veeam VSPC (CVE-2026-58073, CVSS 9.5), HashiCorp Terraform MCP Server (CVE-2026-16498, CVSS 10.0), and DjangoCRITICAL
- Paperclip AI Flaws Let Attackers Run Host Commands via Malicious Agent ImportsCRITICAL
- CVE-2026-9198 — Unauthenticated RCE in IBM Langflow Under Active Exploitation (Auto-Login Bypass + Code Injection Chain)CRITICAL
- Coldcard Security Audit Phishing Campaign Installs ConnectWise ScreenConnect RATCRITICAL
- Agent-to-Agent Privilege Boundary Failures in Google ADK for Python (adk-python) CI/CD Workflows via Cross-Agent Prompt InjectionCRITICAL
- Pre-auth RCE chains in Bonita BPM 10.4.3 and Apache OFBiz 24.09.05 (CVE-2026-31986)CRITICAL
- Samsung Bixby Exploit Chain — System-Level RCE via Samsung Members, Samsung Account, and Capsule Bypass (CVE-2025-21079, CVE-2025-58486, CVE-2025-58487)CRITICAL
- Coldcard Hardware Wallet Firmware RNG Vulnerability (Yasmarang Fallback) Leads to ~$116M Bitcoin TheftCRITICAL
- Keyv and Cacheable npm Supply Chain Attack via Compromised Maintainer Account (Shai-Hulud Malware) (update)CRITICAL
- AISI Cyber Test: Autonomous AI Agent (Anthropic Claude Mythos 5) Attempts Supply-Chain Attack via Social Engineering of Open-Source Maintainer (update)CRITICAL
- Khunt Post-Exploitation Toolkit Deployed via Oracle Database JVM (Huntress Discovery) (update)CRITICAL
- Botnet Scanning Internet-Exposed Router Diagnostic Tools Exploiting OS Command Injection (CVE-2024-12856, CVE-2013-7179, CVE-2020-8949, CVE-2024-48419)HIGH
- CVE-2026-34486: Apache Tomcat EncryptInterceptor Bypass Actively Exploited in SnowLight and AI-Assisted CampaignsHIGH
- Pass-ta-Key Attacks Let Malware Hijack Google Password Manager Synchronized Passkeys (Chrome on Windows)HIGH
- OVSWrap (CVE-2026-64531): Linux kernel Open vSwitch datapath 16-bit nla_len wraparound local privilege escalation with public PoC targeting ~800 x86-64 kernel buildsHIGH
- Three PhaaS Kits (Sneaky 2FA, EvilTokens, EvilProxy) Targeting US Organizations to Steal M365 Credentials and Session TokensHIGH
- macOS ClickFix Campaign Using Browser Fingerprinting Gate to Distribute Atomic Stealer (AMOS) and MacSync InfostealersHIGH
- Greatness PhaaS — AiTM phishing platform targeting Microsoft 365 and multi-platform credentials via spoofed RingCentral voicemail campaignsHIGH
- Over 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Lures — Atomic Stealer (AMOS) and MacSync CampaignHIGH
- Ransom Cartel ransomware creator Maksim Silnikau sentenced to 16 years in federal prisonHIGH
- NullReceiver: DPRK Contagious Interview campaign evolves blockchain C2 with stealthier wallet-trail technique via trojanized npm packages (update)HIGH
- Autonomous AI Agent Supply-Chain Attack via FOSS Social Engineering — AISI Cyber Evaluation Incident (INC-2026-07-28-01) (update)HIGH
- Sage Water Resources Utah saltwater disposal facility PLC intrusion — Iranian IRGC-CEC (CyberAv3ngers) logic manipulation bypasses pump safeguards (update)HIGH
- Google Blogger Automated Malware False Positive Locks Hundreds of Blogs — Platform-Wide Enforcement Error Triggered by Tightened Safe Browsing Post-VEIL#DROP (August 2026)LOW
- Immigration & Asylum Policy as an Enabler of Transnational Repression (Citizen Lab / Foreign Policy Centre policy analysis, IALDF v. Rubio lawsuit, Freedom House 2026)
Techniques observed
178 MITRE ATT&CK and ATLAS techniques appear across the day’s reports.
- T0869
- T1003
- T1005
- T1007
- T1008
- T1021
- T1027
- T1027.010
- T1027.013
- T1033
- T1036
- T1036.005
- T1041
- T1046
- T1048
- T1053
- T1055
- T1056
- T1056.001
- T1056.002
- T1057
- T1059
- T1059.001
- T1059.002
- T1059.003
- T1059.004
- T1059.006
- T1059.007
- T1068
- T1069
- T1070
- T1070.004
- T1070.006
- T1071
- T1071.001
- T1074.001
- T1078
- T1082
- T1083
- T1087
- T1090
- T1095
- T1098
- T1102.002
- T1105
- T1106
- T1110.003
- T1112
- T1113
- T1114
- T1119
- T1125
- T1133
- T1137
- T1140
- T1190
- T1195
- T1195.001
- T1199
- T1202
- T1203
- T1204
- T1204.002
- T1204.005
- T1205
- T1211
- T1213
- T1217
- T1218
- T1218.010
- T1219
- T1222
- T1406
- T1407
- T1417
- T1418
- T1429
- T1430
- T1437
- T1464
- T1480
- T1484
- T1485
- T1489
- T1490
- T1491
- T1495
- T1496
- T1497
- T1497.001
- T1505
- T1513
- T1518
- T1528
- T1529
- T1531
- T1538
- T1539
- T1541
- T1543
- T1543.001
- T1543.003
- T1543.004
- T1546
- T1547
- T1548
- T1548.002
- T1550
- T1552
- T1552.001
- T1552.004
- T1553
- T1553.002
- T1554
- T1555
- T1555.001
- T1555.003
- T1555.005
- T1556
- T1557
- T1558
- T1559
- T1560
- T1560.001
- T1562
- T1564.001
- T1565
- T1566
- T1566.002
- T1566.003
- T1567
- T1568
- T1570
- T1572
- T1573
- T1573.001
- T1574
- T1580
- T1583
- T1583.001
- T1585
- T1586
- T1587
- T1587.001
- T1588
- T1588.001
- T1588.002
- T1588.005
- T1588.006
- T1589
- T1589.001
- T1589.002
- T1591
- T1592
- T1595
- T1595.002
- T1596
- T1598
- T1598.003
- T1603
- T1606
- T1608
- T1608.001
- T1608.006
- T1614
- T1620
- T1621
- T1622
- T1624
- T1626
- T1628
- T1629
- T1636.002
- T1636.004
- T1657
- T1660
- T1684.001
- T1685
Threat actors
11 named threat actors across the reports.
- Authoritarian states
- UNC5174
- Sneaky Log
- Ransom Cartel
- APT44
- Unnamed
- UNC1069
- Autonomous AI Agent
- Cyber Av3ngers
- TeamPCP
- Claude "Mythos 5"
Nation-state attribution
- China
- Russia
- North Korea (DPRK)
- Iran
Threat categories
- THREAT_INTEL
- VULNERABILITY
- MALWARE
- PHISHING
- RANSOMWARE
- SUPPLY_CHAIN
- ICS_SCADA
Severity breakdown
- critical13
- high12
- medium0
- low1
Indicator & detection coverage
Counts only: the indicator values and detection rule text behind them are tiered.
- network 292
- file 161
- tool 53
- behavioral 40
- entity 35
- infrastructure 31
- malware 18
- package 7