# Threat Intel Brief — August 4, 2026
TL;DR
- Critical RMM Exploit: N-able N-central authentication bypass (CVE-2026-18577) under active exploitation; initial patch incomplete, requiring emergency hotfix 2026.3.1.7.
- Russian APT29 Hotel Campaign: Midnight Blizzard targeting hospitality Wi-Fi globally with custom malware (CornFlake, ChocoShell) to harvest Microsoft 365 credentials from business travelers.
- Passkey Security Flaws: Three "Pass-ta-key" attacks allow malware on compromised Windows devices to hijack Google Password Manager passkeys without user interaction.
- Cryptocurrency Wallet Breach: COLDCARD hardware wallet RNG vulnerability enabled theft of $88.6 million in Bitcoin from thousands of wallets.
- Supply Chain Threats: 18 malicious npm packages target Alibaba developers; Hugging Face Diffusers library flaws (CVE-2026-44827, CVE-2026-45804, CVE-2026-44513) bypass trust controls.
Critical Threats
N-able N-central Authentication Bypass Under Active Exploitation
What happened: Attackers are exploiting CVE-2026-18577, an authentication bypass vulnerability in N-able N-central remote monitoring and management (RMM) servers. The flaw affects all versions prior to build 2026.3.1.7. N-able's initial patch (version 2026.3) proved incomplete, allowing attackers to discover an alternate exploitation path. Threat actors achieved full administrative access to N-central servers and used the Take Control feature to pivot to managed customer endpoints. Post-compromise activity included deploying Cloudflare tunnel services as persistence mechanisms that survive reboots and bypass firewall rules.
Impact: RMM platforms represent high-value targets enabling supply chain attacks against managed service providers (MSPs) and their downstream customers. Administrative compromise grants attackers the ability to deploy malware, exfiltrate data, or pivot to client networks at scale. N-central manages multi-OS systems and network devices across thousands of organizations. At least one MSP partner account was compromised with nine downstream organizations reached. The incomplete initial patch extended the exploitation window, allowing attackers additional time to compromise vulnerable systems.
Recommendations:
- Immediate (0-24h): Upgrade all N-central instances to build 2026.3.1.7. Hosted NCOD instances upgrade automatically; self-hosted servers require manual installation.
- Immediate (0-24h): Hunt for malicious Cloudflare tunnel services on all managed endpoints. Search for svchost.exe in users' Documents folders and services named 'Cloudflared'.
- 0-24h: Review N-central UI logs (ui_access_control.log) and correlate with C:\ProgramData\GetSupportService_N-Central\Logs\BASupSrvc_*.log.gz for unauthorized Take Control sessions.
- 0-24h: Block or investigate traffic from attacker IPs: 173.249.252.200, 87.249.138.34, 37.19.210.32, 37.153.90.88, 92.118.112.181, 68.235.46.214.
- 0-24h: Investigate connections to attacker domains: mousears.synology.me, wagoosh.direct.quickconnect.to, who-ripped-one.direct.quickconnect.to.
COLDCARD Hardware Wallet RNG Flaw Enables $88.6M Bitcoin Theft
What happened: A critical vulnerability in COLDCARD hardware wallet firmware contained a flawed random number generator (RNG) that allowed attackers to reconstruct wallet seeds and steal Bitcoin. The RNG integration error caused firmware to use a deterministic software fallback (MicroPython Yasmarang) instead of the STM32 hardware RNG. Attackers stole 1,367 BTC ($88.6 million) from 4,585 addresses across three waves starting July 30, 2026—approximately 30 hours before public disclosure. Affected versions: Mk2/Mk3 firmware 4.0.1-4.1.9, Mk4/Mk5 before 5.6.0 (standard) or 6.6.0X (Edge), Q devices before 1.5.0Q (standard) or 6.6.0QX (Edge).
Impact: Attackers can reconstruct wallet seeds offline using observable microcontroller identifiers and timing values, then derive private keys to steal funds. The vulnerability may have existed since 1995 in digital files. Firmware updates do not repair previously generated seeds—all seeds created on vulnerable firmware versions must be considered compromised. Organizations and individuals holding Bitcoin in affected wallets face total loss of funds. Automated tooling was used; attackers had pre-identified high-value targets before public disclosure.
Recommendations:
- Immediate (0-24h): Identify all COLDCARD devices running vulnerable firmware versions.
- Immediate (0-24h): Update to patched firmware: version 4.2.0+ (Mk2/Mk3), 5.6.0+ (Mk4/Mk5 standard), 1.5.0Q+ (Q standard), or 6.6.0X/6.6.0QX (Edge releases).
- Immediate (0-24h): Generate new wallet seeds on patched firmware and verify the new wallet address directly on the device display.
- 0-24h: Migrate all funds from old wallets: send a small test transaction first, then transfer remaining Bitcoin to the new wallet address.
- 0-24h: Retain old seed backups until migration is confirmed complete, then securely destroy compromised seed material.
Russian APT29 Targets Hospitality Wi-Fi Networks Globally
What happened: Microsoft attributed a global campaign (CaptiveCrunch) to Midnight Blizzard (APT29), a Russian threat actor linked to the Foreign Intelligence Service (SVR). The operation targets hotel and conference center Wi-Fi networks to compromise Microsoft 365 accounts of business travelers. Attackers manipulate DNS settings on captive portal equipment and deploy two custom malware families: CornFlake (Go-based RAT with keylogging, clipboard monitoring, screenshot capture, webcam/microphone surveillance, and credential theft) and ChocoShell (in-memory PowerShell credential stealer targeting browser cookies, saved passwords, and OAuth tokens). The campaign has been active since at least May 2026, with device code and OAuth phishing operations dating back to February 2026.
Impact: The campaign exploits the trusted intermediary role of hospitality providers to harvest credentials from traveling executives, diplomats, and government officials. Successful compromise grants persistent access to corporate and government Microsoft 365 environments, enabling email surveillance, cloud resource access, and lateral movement. The targeting of hospitality infrastructure creates a supply chain risk where hotels become unwitting participants in intelligence operations. Both Windows and Android devices are targeted, expanding the attack surface beyond traditional endpoint security controls.
Recommendations:
- 24-72h: Treat hotel and conference Wi-Fi as untrusted networks; use private cellular hotspots or managed VPN connections for corporate access.
- 24-72h: Implement phishing-resistant authentication with hardware-based MFA and passkeys; disable Microsoft Entra device code authentication flow when not operationally required.
- This week: Monitor for DNS configuration changes on captive portal infrastructure and implement network segmentation to isolate guest Wi-Fi from management interfaces.
- This week: Deploy endpoint detection rules for CornFlake persistence indicators: suspicious services named 'Cloud Sync Service', registry run key modifications in HKCU\Software\Microsoft\Windows\CurrentVersion\Run, and Go-based executables copying to %AppData% directories.
- This week: Alert on ChocoShell behavioral patterns including in-memory PowerShell execution targeting browser credential stores, particularly processes accessing Chrome/Edge Login Data files.
Threat Actor Activity
INC Ransomware Dominates SonicWall SMA 1000 Exploitation
INC Ransomware has emerged as the primary threat actor exploiting recently disclosed vulnerabilities in SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances. The operation chains CVE-2026-15409 and CVE-2026-15410 for arbitrary command execution and device takeover. Post-exploitation activities include credential extraction, theft of Time-Based One-Time Password (TOTP) MFA seed configurations for persistent access, and lateral movement into corporate networks. The attack chain deploys KNUCKLEBALL (Python script), Suo5 (open-source HTTP proxy), and ORANGETAIL (custom Java web shell). INC Ransomware has claimed 885 victims to date and accelerated activity since early August 2026, listing multiple new victims between July 17 and August 2. The group employs aggressive pressure tactics including direct phone calls to victims.
Organizations using SonicWall SMA 1000 appliances should immediately patch to the latest version, conduct threat hunting for /wsproxy endpoint abuse, rotate all credentials with access to SMA appliances, verify TOTP MFA seed integrity, and monitor for deployment of KNUCKLEBALL, Suo5, and ORANGETAIL tools.
ExfilSquad Breaches UK Police National Legal Database
ExfilSquad, a data extortion group, breached the UK's Police National Legal Database (PNLD), compromising contact data of over 100,000 police officers and criminal justice professionals. The group exfiltrated approximately 1.9 GB of data containing 135,000 contact records and published sample stolen data publicly while demanding ransom payment. PNLD serves 43 Home Office police forces in England and Wales, British Transport Police, and criminal justice professionals. ExfilSquad has also recently targeted American semiconductor company Analog Devices, indicating operations across multiple sectors and geographies. The group's targeting of law enforcement infrastructure represents a high-impact victim selection strategy, as compromise of police officer contact information poses operational security risks and potential physical safety concerns.
Chinese-Speaking Actor Deploys GHOSTBLADE via Leaked DarkSword Kit
An unknown Chinese-speaking threat actor is conducting a campaign targeting Apple iOS devices using a leaked DarkSword exploit kit to deploy GHOSTBLADE malware. The actor operates over 100 web properties concentrated in Hong Kong with reach into Japan, the United States, and Europe. Infrastructure includes fake AWS sign-in pages and Apple ID credential-harvesting decoys. The campaign targets iOS versions 18.4-18.7 via watering hole attacks. GHOSTBLADE modules dump credentials from keychain, iCloud, and Wi-Fi configurations. The actor uses Chinese-language administration panels and maintains direct contact channels via Telegram. Evidence suggests possible overlap with UNC6353 actor based on shared use of DarkSword and Coruna iOS exploit kits.
DOUBLECUP Loader-as-a-Service Commercializes ClickFix Attacks
DOUBLECUP is a Russian loader-as-a-service platform operating since June 2026 that uses ClickFix social engineering combined with steganography to deliver malware. The service forces browsers to download and cache malicious PNG images containing hidden payloads, then tricks victims into executing clipboard-injected commands. Final payloads include CountLoader (information stealer with cryptocurrency wallet detection, Signal Desktop checks, scheduled task persistence) and DeviceManager RAT (Python-based modular RAT using EtherHiding technique to retrieve C2 addresses from Ethereum/Polygon smart contracts). The service targets users of enterprise SaaS platforms through fake login pages impersonating NetSuite, Odoo, HubSpot, and Salesforce. DeviceManager includes CIS country exclusions, consistent with Russian cybercrime norms.
Geopolitical Context
Russian Intelligence Operations Target Western Business Infrastructure
The Midnight Blizzard (APT29) hospitality Wi-Fi campaign represents a continuation of Russian intelligence collection efforts targeting Western corporate and government networks. By compromising hotel and conference center infrastructure, the operation appears designed to harvest credentials from traveling executives, diplomats, and government officials. This approach exploits the trusted intermediary role of hospitality providers to gain persistent access to high-value organizational accounts. The campaign's global scope and sustained investment in custom malware development (CornFlake, ChocoShell) indicates state-level resourcing consistent with SVR intelligence priorities.
UK Law Enforcement Data Breach Highlights Institutional Vulnerabilities
The ExfilSquad breach of the Police National Legal Database exposes contact information for over 100,000 UK law enforcement and criminal justice professionals. While the compromised data appears limited to contact details rather than operational intelligence, the incident demonstrates persistent targeting of Western law enforcement systems by extortion-focused threat actors. The exposure of officer names and work email addresses increases the attack surface for credential phishing and social engineering targeting police forces, criminal justice agencies, and government partners. The breach may complicate UK-European law enforcement cooperation and information-sharing protocols.
Supply Chain Attacks Target Chinese Technology Sector
The discovery of 18 malicious npm packages targeting Alibaba developer tool users represents a sophisticated industrial espionage operation against Chinese technology sector developers. The campaign demonstrates advanced tradecraft through multi-layered dependency obfuscation and cross-platform payload delivery. The attack's narrow focus on Chinese-speaking developers using proprietary Alibaba tooling suggests an adversary with intimate knowledge of Chinese enterprise development environments. This incident underscores the strategic value of developer access as an entry point for intellectual property theft and corporate espionage within China's technology sector.
Recommended Actions
Immediate (0-24 hours)
1. Patch N-able N-central: Upgrade all instances to build 2026.3.1.7 and hunt for Cloudflare tunnel persistence mechanisms.
2. Migrate COLDCARD Wallets: Update firmware and transfer all Bitcoin from wallets with seeds generated on vulnerable firmware versions.
3. Audit npm Dependencies: Scan for 18 malicious packages (lib-mtop, aone-kit, aone-kit-cli, aone-sandbox, local-config-parser, smart-config-manager, cloud-config-fetcher, fast-transform-pipeline, aone-cloud-cli, colder-cli, def-open-client, feedback-ai-sdk, flight-compare-analyzer, lwp-web-client, lzd-unified-station-sdk, open-worker-cli, test-skill-zip, uniapi-bridge).
4. Patch SonicWall SMA 1000: Apply latest updates to remediate CVE-2026-15409 and CVE-2026-15410; rotate credentials and TOTP MFA seeds.
24-72 hours
1. Upgrade Hugging Face Diffusers: Update to version 0.38.0 or later to address CVE-2026-44827, CVE-2026-45804, and CVE-2026-44513.
2. Implement Hospitality Wi-Fi Controls: Use private cellular hotspots or managed VPNs for corporate access on hotel networks; disable Microsoft Entra device code authentication.
3. Patch Thermo Fisher DNA Software: Install vendor patches for CVE-2026-17583 in Applied Biosystems human identification software.
This week
1. Audit Passkey Implementations: Ensure relying parties require and validate the User Verified flag in WebAuthn assertions.
2. Deploy iOS Security Updates: Update all iOS devices to versions beyond 18.7 to patch DarkSword exploit kit vulnerabilities.
3. Review Cloud Platform Configurations: Audit Microsoft Power Platform and similar low-code environments for anonymous access misconfigurations.
4. Implement ClickFix Awareness Training: Educate users that legitimate CAPTCHA systems never require pasting and executing commands in terminal windows.
5. Monitor for BTMOB RAT Activity: Deploy mobile threat defense solutions on corporate Android devices to detect RAT behavior patterns.
Watch List
- N-able N-central: Monitor for additional exploitation attempts and ensure all systems are patched to 2026.3.1.7.
- Google Password Manager: Track Chromium issue 398125799 and Google security advisories for patches addressing passkey security domain secret exposure.
- SonicWall SMA 1000: Watch for INC Ransomware and other threat actors exploiting CVE-2026-15409 and CVE-2026-15410.
- iOS Exploit Kits: Monitor for proliferation of leaked DarkSword source code and adoption by additional threat actors.
- RMM Platform Vulnerabilities: Increased targeting of remote monitoring and management platforms for supply chain attacks.
Sources
- BleepingComputer: Hotel Wi-Fi attacks, N-able N-central exploitation, COLDCARD wallet flaw, ExfilSquad breach, DOUBLECUP service, Fake Roblox Xeno malware, BTMOB RAT analysis
- The Hacker News: Alibaba npm packages, Google Password Manager attacks, INC Ransomware, Chinese DarkSword campaign, UK PNLD breach, Thermo Fisher DNA software, N-able incomplete patch, Hugging Face Diffusers flaws
- Unit 42 (Palo Alto Networks): Pass-ta-key passkey attack research
- CERT.BE (Belgium): N-Central active exploitation warning
---
*This report synthesizes open-source threat intelligence for defensive planning. Organizations should validate findings against their specific environments and threat models. For technical indicators of compromise and detailed detection guidance, consult original source materials.*
