Summary & highlights
CI Fortify: CISA/ASD/NCSC-UK/CCCS Joint OT Isolation Guidance Exposes Communications-Continuity Gap for Critical Infrastructure Operators. Claude in Chrome "PleaseFix" Prompt-Injection Flaw Enables Gmail/Slack/X/Claude.ai Account Takeover. UNC6671 Automates Microsoft 365 Data Theft via Vishing-Driven AiTM Phishing and Session Hijacking.
Highlights
- TL-2026-1923 — Claude in Chrome "PleaseFix" Prompt-Injection Flaw Enables Gmail/Slack/X/Claude.ai Account Takeover
- TL-2026-1926 — UNC6671 Automates Microsoft 365 Data Theft via Vishing-Driven AiTM Phishing and Session Hijacking
- TL-2026-1927 — NatJack: NAT Connection-Tracking Manipulation Attacks Hijack TCP Sessions Across Windows, Linux, and macOS (CVE-2026-56181, CVE-2026-63913)
- TL-2026-1928 — Bendix EC80 Truck Brake Controller: 2024 Safety Recall Covertly Patched RCE and DoS Vulnerabilities
- TL-2026-1929 — Claude Code RCE via Malicious .mcp.json in Pull Request Branches
Theme of the day
Exploitation of critical pre-auth
- adversary-in-the-middle
- credential-theft
- session-hijacking
- macos
- remote-code-execution
Threats published
18 threat lines in the 2026-08-07 debrief, most severe first; entries marked (update) revise an earlier report. Each links to its full profile.
- CVE-2026-65400: macOS Screen Sharing Authentication Bypass Grants Unauthenticated Root AccessCRITICAL
- Google Chrome 151 Update Fixes 41 Security Vulnerabilities, Including 6 Critical FlawsCRITICAL
- Unauthenticated Metabase SQL Injection Zero-Day (GHSA-vwf4-m7j8-wcjf) Exploited to Steal Framework and Tally Customer DataCRITICAL
- FirewallFalcon Manager: Supply-Chain Backdoor in Underground VPN Server InfrastructureCRITICAL
- TeamPCP LiteLLM Supply Chain Attack — Trojaned PyPI Packages (v1.82.7/1.82.8) with Multi-Stage C2 Payload (update)CRITICAL
- ChainDrop npm Supply-Chain Compromise: Self-Propagating Mini Shai-Hulud Credential-Stealing Worm Affecting 444+ Packages (update)CRITICAL
- "When Agentic Glue Melts": Five workerd Memory-Corruption Flaws Enable Cross-Tenant Secret Theft and Code Mode Sandbox Escape on Cloudflare Workers (update)CRITICAL
- Claude in Chrome "PleaseFix" Prompt-Injection Flaw Enables Gmail/Slack/X/Claude.ai Account TakeoverHIGH
- UNC6671 Automates Microsoft 365 Data Theft via Vishing-Driven AiTM Phishing and Session HijackingHIGH
- NatJack: NAT Connection-Tracking Manipulation Attacks Hijack TCP Sessions Across Windows, Linux, and macOS (CVE-2026-56181, CVE-2026-63913)HIGH
- Bendix EC80 Truck Brake Controller: 2024 Safety Recall Covertly Patched RCE and DoS VulnerabilitiesHIGH
- Claude Code RCE via Malicious .mcp.json in Pull Request BranchesHIGH
- Microsoft 365 AitM Phishing Campaign Hijacks Sessions via Residential Proxies to Harvest Payroll and Finance EmailsHIGH
- WordPress Core XSS2Shell Vulnerability Chains Pre-Auth XSS to RCE (CVE-2026-64638)HIGH
- GepyS Banking Malware and Rust Clipboard Hijacker: Two H1 2026 Attack Chains (Gen Digital)HIGH
- Nearly 800 Malicious npm Packages Deliver Cross-Platform WEL1DROPPER RAT and Infostealer ('Flooding Dropper' Campaign)HIGH
- ClickFix Attacks Deliver Go-Based macOS Infostealer Targeting Crypto Wallets and Keychain DataHIGH
- CI Fortify: CISA/ASD/NCSC-UK/CCCS Joint OT Isolation Guidance Exposes Communications-Continuity Gap for Critical Infrastructure Operators
Techniques observed
164 MITRE ATT&CK and ATLAS techniques appear across the day’s reports.
- T1001
- T1003
- T1005
- T1008
- T1016
- T1018
- T1020
- T1021
- T1021.005
- T1027
- T1027.002
- T1033
- T1036
- T1036.005
- T1040
- T1041
- T1046
- T1047
- T1048
- T1053.003
- T1053.005
- T1055
- T1056.002
- T1059
- T1059.004
- T1059.007
- T1068
- T1069
- T1070
- T1070.008
- T1071
- T1071.001
- T1071.004
- T1074
- T1078
- T1078.001
- T1078.004
- T1080
- T1082
- T1083
- T1087
- T1087.004
- T1090
- T1090.002
- T1095
- T1098
- T1098.001
- T1098.005
- T1102
- T1105
- T1111
- T1114.002
- T1119
- T1133
- T1136
- T1140
- T1176
- T1185
- T1187
- T1189
- T1190
- T1195
- T1195.001
- T1199
- T1203
- T1204
- T1204.001
- T1204.002
- T1204.004
- T1205
- T1210
- T1211
- T1212
- T1213
- T1213.002
- T1218
- T1222.002
- T1480
- T1485
- T1486
- T1489
- T1496
- T1497
- T1497.001
- T1499.001
- T1499.002
- T1499.004
- T1505.003
- T1518
- T1526
- T1528
- T1529
- T1530
- T1534
- T1537
- T1538
- T1539
- T1543
- T1543.001
- T1546
- T1547
- T1547.001
- T1548
- T1548.006
- T1550
- T1550.001
- T1550.004
- T1552
- T1552.001
- T1552.004
- T1553
- T1553.001
- T1554
- T1555
- T1555.001
- T1555.003
- T1556
- T1557
- T1560
- T1564
- T1564.008
- T1565.001
- T1565.002
- T1566
- T1566.002
- T1566.004
- T1567
- T1570
- T1572
- T1573
- T1574
- T1583
- T1583.001
- T1583.006
- T1583.008
- T1584
- T1585
- T1586
- T1587.001
- T1587.004
- T1588
- T1588.002
- T1588.005
- T1588.006
- T1589
- T1590
- T1590.005
- T1592.002
- T1592.004
- T1595.002
- T1599
- T1599.001
- T1608
- T1608.001
- T1608.005
- T1610
- T1611
- T1613
- T1614
- T1620
- T1622
- T1657
- T1684.001
- T1685
Threat actors
4 named threat actors across the reports.
Nation-state attribution
- Russia (suspected, unconfirmed)
Threat categories
- ICS_SCADA
- VULNERABILITY
- PHISHING
- MALWARE
- SUPPLY_CHAIN
- DATA_BREACH
Severity breakdown
- critical7
- high10
- medium0
- low0
Indicator & detection coverage
Counts only: the indicator values and detection rule text behind them are tiered.
- network 116
- file 88
- entity 72
- infrastructure 46
- package 35
- tool 33
- behavioral 28
- malware 14
- technique 4