Summary & highlights
Claude-Powered OpenClaw AI Agent Autonomously Exploits Gym Booking API Authorization Flaw. Claude-Powered AI Agent (OpenClaw) Autonomously Exploits Broken Access Control Flaw in Gym Booking API. Royal Navy K3 Scout Drone Cameras Found Transmitting Heartbeat Signals to China-Based IP Address.
Highlights
- TL-2026-1966 — WSUS NTLM Relay Attack Chain Enables Malicious Update Deployment via SUSDB Stored Procedures
- TL-2026-1968 — CSS Bomb Attacks: CSS-Based Trust-Boundary Bypass Leaks Webmail Passwords and Tokens (Outlook, Gmail, Yahoo, AOL, Fastmail, Proton Mail)
- TL-2026-1970 — Payroll Pirates (Storm-2755) Abuse Microsoft Graph for HR/Finance Staff Recon After AiTM Account Compromise
- TL-2026-1971 — WordPress Supply Chain Attack via BdThemes Promotional API Feed Poisoning (Element Pack, Prime Slider, and 5 More Plugins)
- TL-2026-1973 — UAC-0145 (Sandworm subcluster) trojanizes WireGuard VPN client "SopraVPN" in fake IT recruitment campaign impersonating Sopra Steria Bulgaria
Theme of the day
Activity centered on abc-news, active-directory, agentic-ai.
- credential-theft
- authentication-bypass
- defense-evasion
- privilege-escalation
- active-exploitation
Threats published
20 threat lines in the 2026-08-10 debrief, most severe first; entries marked (update) revise an earlier report. Each links to its full profile.
- Origin-Validation Bypass in Connective (Nitro Software Belgium) eID Browser Extension Enables PIN Theft, Signature Forgery, and Drive-By RCE Across 2M+ Belgian UsersCRITICAL
- Metabase Zero-Day (GHSA-vwf4-m7j8-wcjf): Unauthenticated SQL Injection via /api/session/reset_password Exploited to Steal Database CredentialsCRITICAL
- Unauthenticated SQL Injection Zero-Day in Metabase (CVSS 10.0, GHSA-vwf4-m7j8-wcjf) Exploited to Steal Framework, Tally, and LexisNexis Customer DataCRITICAL
- Metabase Unauthenticated SQL Injection Zero-Day (GHSA-vwf4-m7j8-wcjf, CVSS 10.0) Exploited to Steal Connected Database CredentialsCRITICAL
- N-able N-central Authentication Bypass (CVE-2026-18577) Actively Exploited for Admin Takeover (update)CRITICAL
- Pass-ta-key: Novel Attack Surface in Google Password Manager Synced Passkey Authentication (update)CRITICAL
- CVE-2026-65400: macOS Screen Sharing Authentication Bypass Grants Unauthenticated Root Access (update)CRITICAL
- WSUS NTLM Relay Attack Chain Enables Malicious Update Deployment via SUSDB Stored ProceduresHIGH
- CSS Bomb Attacks: CSS-Based Trust-Boundary Bypass Leaks Webmail Passwords and Tokens (Outlook, Gmail, Yahoo, AOL, Fastmail, Proton Mail)HIGH
- Payroll Pirates (Storm-2755) Abuse Microsoft Graph for HR/Finance Staff Recon After AiTM Account CompromiseHIGH
- WordPress Supply Chain Attack via BdThemes Promotional API Feed Poisoning (Element Pack, Prime Slider, and 5 More Plugins)HIGH
- UAC-0145 (Sandworm subcluster) trojanizes WireGuard VPN client "SopraVPN" in fake IT recruitment campaign impersonating Sopra Steria BulgariaHIGH
- Fake GoogleTranslate Chrome Extension Enables Remote Browser Control and Credential Theft via Rust Loader, AutoIt, and Stealc v2HIGH
- TXTBOOK: Dependency Confusion Campaign Drops Sliver via DNS TXT-Record Staging Against T-BankHIGH
- Aeternum Loader Uses Polygon Blockchain Smart Contracts for Resilient C2, Deploys XWorm and XMRigHIGH
- DeadLock Ransomware: Rust-Based Encryptor with Decentralized Recovery Infrastructure on Polygon and SessionHIGH
- Claude-Powered OpenClaw AI Agent Autonomously Exploits Gym Booking API Authorization FlawMEDIUM
- Claude-Powered AI Agent (OpenClaw) Autonomously Exploits Broken Access Control Flaw in Gym Booking APIMEDIUM
- Royal Navy K3 Scout Drone Cameras Found Transmitting Heartbeat Signals to China-Based IP AddressMEDIUM
- BdThemes WordPress Plugin Supply-Chain Attack Poisons API to Create Rogue AdminsMEDIUM
Techniques observed
151 MITRE ATT&CK and ATLAS techniques appear across the day’s reports.
- AML.T0051
- T1005
- T1018
- T1021
- T1021.005
- T1027
- T1027.010
- T1033
- T1036
- T1036.005
- T1046
- T1053
- T1053.003
- T1053.005
- T1055
- T1056
- T1056.001
- T1056.002
- T1057
- T1059
- T1059.001
- T1059.004
- T1059.007
- T1059.010
- T1068
- T1069
- T1070.006
- T1071
- T1071.001
- T1072
- T1078
- T1078.002
- T1078.004
- T1082
- T1083
- T1087
- T1087.002
- T1087.003
- T1087.004
- T1090
- T1090.002
- T1098
- T1098.005
- T1102
- T1105
- T1106
- T1110.001
- T1111
- T1112
- T1113
- T1114.002
- T1119
- T1133
- T1134
- T1136
- T1136.001
- T1136.002
- T1140
- T1176
- T1185
- T1187
- T1190
- T1195
- T1195.002
- T1195.003
- T1197
- T1199
- T1203
- T1204
- T1204.001
- T1204.002
- T1210
- T1211
- T1212
- T1213
- T1217
- T1219
- T1222.002
- T1482
- T1485
- T1489
- T1490
- T1496
- T1497
- T1505
- T1505.003
- T1518.001
- T1526
- T1528
- T1531
- T1538
- T1539
- T1542.005
- T1543
- T1546
- T1547
- T1548
- T1548.006
- T1550.001
- T1552
- T1552.001
- T1552.004
- T1553.002
- T1555
- T1555.003
- T1556
- T1556.006
- T1557
- T1557.001
- T1558
- T1562.001
- T1564
- T1564.003
- T1564.008
- T1565.001
- T1566
- T1566.001
- T1566.002
- T1566.003
- T1567
- T1568
- T1569
- T1570
- T1572
- T1573
- T1573.001
- T1574
- T1583
- T1583.001
- T1583.004
- T1583.008
- T1584
- T1585
- T1585.001
- T1587.001
- T1588
- T1589
- T1592.002
- T1594
- T1595.002
- T1595.003
- T1596.005
- T1606
- T1608
- T1608.001
- T1608.006
- T1614
- T1620
- T1657
- T1684.001
- T1685
Threat actors
4 named threat actors across the reports.
Nation-state attribution
- Russia
Threat categories
- VULNERABILITY
- SUPPLY_CHAIN
- PHISHING
- MALWARE
- RANSOMWARE
Severity breakdown
- critical7
- high9
- medium4
- low0
Indicator & detection coverage
Counts only: the indicator values and detection rule text behind them are tiered.
- network 87
- file 78
- entity 69
- infrastructure 44
- tool 30
- behavioral 28
- malware 9
- package 9
- technique 1