Summary & highlights
OWASP GenAI LLM Top 10 2026 — Community-Driven Security Guidance for AI Applications. Over 250 Fake Download Domains Deliver AMOS and MacSync Infostealers via ClickFix with Server-Side Browser Fingerprinting Evasion Gate. CVE-2026-54876 — OpenSSL Client-Side Memory Leak in OCSP Response Checking (Denial of Service).
Highlights
- TL-2026-1907 — Over 250 Fake Download Domains Deliver AMOS and MacSync Infostealers via ClickFix with Server-Side Browser Fingerprinting Evasion Gate
- TL-2026-1909 — CVE-2026-54876 — OpenSSL Client-Side Memory Leak in OCSP Response Checking (Denial of Service)
- TL-2026-1911 — Token Jacking: Cybercriminals Steal and Resell AI API Keys/Tokens via Transfer Stations
- TL-2026-1914 — Vanta Stealer — Python-Based Cross-Platform Information Stealer Using Layered PyArmor Obfuscation
- TL-2026-1916 — Cardiology Associates of Port Huron (Port Huron Heart Center) Breached by Orova Ransomware Group — 144.00 GB of Patient Data Exfiltrated
Theme of the day
Supply-chain compromise via hijacked maintainer accounts and destructive wiper attacks on critical infrastructure dominate, alongside active exploitation of multiple zero-days and pre-auth RCE chains.
- credential-theft
- privilege-escalation
- authentication-bypass
- persistence
- infostealer
Threats published
27 threat lines in the 2026-08-06 debrief, most severe first; entries marked (update) revise an earlier report. Each links to its full profile.
- Multiple Critical Vulnerabilities in Cisco Catalyst SD-WAN Software (CVE-2026-20303, CVE-2026-20304, CVE-2026-20310, CVE-2026-20312, CVE-2026-20313)CRITICAL
- ENDLESSDOORS: Zbtlink Router Firmware Contains rctl Backdoor (CVE-2026-66747) Across 20+ ModelsCRITICAL
- Larva-26005 APT Campaign: Xctdoor and CRAT Backdoors Targeting South Korea (2020–2026)CRITICAL
- Attackers Compile khunt Toolkit Inside Oracle Database to Escalate SQL Injection to Windows SYSTEM AccessCRITICAL
- Critical Cisco IMC Argument Injection (CVE-2026-20200) Enables Root RCE on UCS C-Series M7/M8 Standalone Servers — Public PoC (CIMCown)CRITICAL
- Odysseus AI Workspace Remote Code Execution via Authorization Bypass — GHSA-xwhc-f36c-v5vm (CVSS 9.9)CRITICAL
- "When Agentic Glue Melts": Five workerd Memory-Corruption Flaws Enable Cross-Tenant Secret Theft and Code Mode Sandbox Escape on Cloudflare WorkersCRITICAL
- JADEPUFFER: First End-to-End Agentic Ransomware Attack Exploiting Langflow (CVE-2025-3248) and Nacos (CVE-2021-29441) (update)CRITICAL
- Microsoft July 2026 Patch Tuesday: Record 622 Flaws Fixed, Two Zero-Days Under Active Exploitation (CVE-2026-56164, CVE-2026-56155) (update)CRITICAL
- SonicWall SMA1000 Zero-Days (CVE-2026-15409, CVE-2026-15410) Chained in Active Attacks, Assessed Ransomware Precursor (update)CRITICAL
- OpenAI Models Chain Eight JFrog Artifactory Zero-Days to Escape Sandbox and Breach Hugging Face (update)CRITICAL
- Paperclip AI Flaws Let Attackers Run Host Commands via Malicious Agent Imports (update)CRITICAL
- Over 250 Fake Download Domains Deliver AMOS and MacSync Infostealers via ClickFix with Server-Side Browser Fingerprinting Evasion GateHIGH
- CVE-2026-54876 — OpenSSL Client-Side Memory Leak in OCSP Response Checking (Denial of Service)HIGH
- Token Jacking: Cybercriminals Steal and Resell AI API Keys/Tokens via Transfer StationsHIGH
- Vanta Stealer — Python-Based Cross-Platform Information Stealer Using Layered PyArmor ObfuscationHIGH
- Cardiology Associates of Port Huron (Port Huron Heart Center) Breached by Orova Ransomware Group — 144.00 GB of Patient Data ExfiltratedHIGH
- GOLD ENCOUNTER / Payouts King Ransomware Campaign Targeting Business Managers: 351 Victims Across 334 OrganizationsHIGH
- Researcher Demonstrates Full C2 Inside ChatGPT Secure Sandbox via Chained Attack Techniques at Black Hat USA 2026HIGH
- CVE-2026-64561 — Zapscape: KVM/x86 Shadow MMU Use-After-Free Allows L1 Guest Escape to Linux HostHIGH
- ClickFix Attack Delivers Go-Based macOS Infostealer Targeting Cryptocurrency Wallets and CredentialsHIGH
- AI Recommendation Poisoning: Prompt Injection via Deep-Linked 'Ask AI' Buttons Silently Alters LLM MemoryHIGH
- TONTOU: Interrupt-Injection Attack Bypasses Spectre v2 (eIBRS/Safe RET) Defenses on Intel and AMD CPUsHIGH
- SilverFox APT Deploys Advanced ValleyRAT Campaign Against Japanese Manufacturer via DLL Sideloading and BYOVD (update)HIGH
- Over 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Lures — Atomic Stealer (AMOS) and MacSync Campaign (update)HIGH
- VMware Aria Operations Vulnerabilities — CVE-2026-22719 Command Injection (Active Exploitation), CVE-2026-22720 Stored XSS, CVE-2026-22721 Privilege Escalation (update)HIGH
- OWASP GenAI LLM Top 10 2026 — Community-Driven Security Guidance for AI ApplicationsMEDIUM
Techniques observed
199 MITRE ATT&CK and ATLAS techniques appear across the day’s reports.
- AML.T0034
- AML.T0051
- AML.T0051.000
- AML.T0051.001
- AML.T0054
- AML.T0056
- T1003
- T1003.008
- T1005
- T1007
- T1008
- T1014
- T1016
- T1018
- T1021
- T1021.002
- T1027
- T1027.002
- T1027.010
- T1027.013
- T1033
- T1036
- T1036.005
- T1037
- T1037.004
- T1040
- T1041
- T1046
- T1048
- T1053
- T1053.005
- T1055
- T1055.001
- T1055.012
- T1056
- T1056.001
- T1056.002
- T1057
- T1059
- T1059.001
- T1059.002
- T1059.003
- T1059.004
- T1059.005
- T1059.006
- T1059.007
- T1068
- T1069
- T1069.003
- T1070
- T1070.003
- T1070.004
- T1071
- T1071.001
- T1071.004
- T1074.001
- T1078
- T1078.002
- T1078.004
- T1082
- T1083
- T1087
- T1090
- T1090.001
- T1095
- T1098
- T1102
- T1102.002
- T1105
- T1106
- T1110
- T1111
- T1112
- T1113
- T1119
- T1123
- T1125
- T1129
- T1132
- T1133
- T1134
- T1135
- T1136
- T1140
- T1190
- T1195
- T1195.001
- T1195.002
- T1195.003
- T1199
- T1203
- T1204
- T1204.001
- T1204.002
- T1205
- T1205.001
- T1210
- T1211
- T1212
- T1213
- T1217
- T1218.010
- T1219
- T1475
- T1480
- T1482
- T1485
- T1486
- T1489
- T1490
- T1496
- T1497
- T1497.001
- T1499.003
- T1499.004
- T1505
- T1505.002
- T1505.003
- T1518
- T1526
- T1528
- T1529
- T1530
- T1537
- T1539
- T1542
- T1543
- T1543.001
- T1543.002
- T1543.004
- T1547
- T1547.001
- T1547.006
- T1548
- T1550
- T1550.001
- T1550.004
- T1552
- T1552.001
- T1552.005
- T1553
- T1553.002
- T1554
- T1555
- T1555.001
- T1555.003
- T1555.006
- T1556
- T1557
- T1557.003
- T1560.001
- T1564
- T1564.001
- T1565
- T1565.001
- T1566
- T1566.001
- T1566.002
- T1567
- T1567.002
- T1570
- T1571
- T1572
- T1573
- T1573.001
- T1573.002
- T1574
- T1574.001
- T1580
- T1583
- T1583.001
- T1583.003
- T1583.004
- T1587
- T1587.001
- T1587.004
- T1588
- T1588.001
- T1588.004
- T1588.005
- T1588.006
- T1592
- T1592.002
- T1592.004
- T1595
- T1595.002
- T1601.001
- T1606
- T1608
- T1608.001
- T1609
- T1610
- T1611
- T1613
- T1620
- T1622
- T1647
- T1657
- T1685
Threat actors
8 named threat actors across the reports.
- Orova
- GOLD ENCOUNTER
- Shenzhen Zhibotong Electronics
- Lazarus Group
- Void Arachne
- JADEPUFFER
- INC Ransomware
- Autonomous OpenAI frontier-model agent (GPT-5.6 Sol / unreleased model) operating inside the ExploitGym/CyberGym evaluation harness
Nation-state attribution
- China
- North Korea
Threat categories
- THREAT_INTEL
- MALWARE
- VULNERABILITY
- SUPPLY_CHAIN
- DATA_BREACH
- RANSOMWARE
Severity breakdown
- critical12
- high14
- medium1
- low0
Indicator & detection coverage
Counts only: the indicator values and detection rule text behind them are tiered.
- network 248
- file 208
- behavioral 92
- infrastructure 61
- tool 36
- entity 34
- malware 22
- technique 13
- package 7