# Threat Intel Brief — August 7, 2026

TL;DR

  • Critical Linux kernel flaw (CVE-2026-64531) grants local root access via Open vSwitch; public exploit available for ~800 kernel builds.
  • CryptoJS weak RNG drained $5.7M from crypto wallets over 12 years; five wallet apps affected, recovery phrases permanently compromised.
  • Cisco patches 12 SD-WAN/IOS XE vulnerabilities, three rated CVSS 9.8+; immediate patching required for enterprise network infrastructure.
  • Canadian national pleads guilty to Snowflake breach affecting 165 organizations and theft of 100M+ AT&T customer records.
  • macOS ClickFix campaign evolves with browser fingerprinting to evade detection while delivering cryptocurrency-stealing infostealers.

---

Critical Threats

CryptoJS Weak Random Number Generator Drains $5.7 Million

What happened: A 12-year-old vulnerability in CryptoJS.lib.WordArray.random() enabled attackers to systematically drain cryptocurrency wallets by exploiting weak entropy generation. The flaw reduced cryptographic search spaces from 128-bit and 256-bit to approximately 2^39 and 2^47 respectively, allowing enumeration of recovery phrases. Five wallet applications were affected: RRWallet, Bexo Wallet, NanChat, Bitcoin Libre, and Milo. Two confirmed attack waves occurred in May–July 2026, stealing at least $5.7 million across Bitcoin, Ethereum, Tron, Rootstock, and Polygon networks.

Impact: Recovery phrases generated by affected CryptoJS versions (below 4.0.0) remain permanently compromised even after app updates or migration to hardware wallets. The vulnerability was present from June 2014 through February 2020 in production releases, though versions 3.2.0 and 3.2.1 briefly fixed the issue before version 3.3.0 reintroduced it. Organizations using CryptoJS for cryptographic operations face critical risk if the library generates security-sensitive values. The vulnerability received GHSA-rg76-677x-56q9 with CVSS 9.0 (Critical).

Recommendations:

  • Audit all applications for CryptoJS usage below version 4.0.0, prioritizing key generation and recovery phrase logic
  • Upgrade to CryptoJS 4.0.0 or later immediately; verify React Native forks (ferrumnet/bip39) are not reintroducing weak randomness
  • For crypto wallet operators: issue public advisories instructing users to generate new recovery phrases using patched software and migrate funds immediately
  • Monitor blockchain addresses using Coinspect's public checker; treat any match as immediate compromise requiring fund transfer to newly generated wallets

---

Linux Kernel OVSwrap Flaw Grants Local Root Access

What happened: A memory corruption vulnerability in the Linux kernel's Open vSwitch datapath (CVE-2026-64531, CVSS 7.8) allows local unprivileged users to gain root privileges on default-configured distributions. The flaw affects kernels with OVS conntrack support and unprivileged user namespaces enabled. A public exploit with pre-built records for approximately 800 kernel builds has been released, demonstrating reliable privilege escalation without requiring existing OVS bridges or running ovs-vswitchd.

Impact: Multi-tenant environments, shared hosting platforms, and systems with untrusted local users face immediate risk. The exploit auto-loads the openvswitch module on vulnerable systems and corrupts kernel credentials to achieve SYSTEM-level access. Fixed in stable kernels 5.15.212, 6.1.178, 6.6.145, 6.12.97, 6.18.40, and 7.1.5. Default configurations of AlmaLinux, Amazon Linux 2023, Arch, Debian, Fedora, Ubuntu 22.04, and others are exploitable. Ubuntu 26.04 is protected by default AppArmor policies.

Recommendations:

  • Apply vendor-provided patched kernels immediately (consult distribution security advisories for backported fixes)
  • If Open vSwitch is not required, block module loading: echo 'install openvswitch /bin/false' > /etc/modprobe.d/ovswrap.conf
  • Disable unprivileged user namespaces as interim mitigation: sysctl -w kernel.unprivileged_userns_clone=0
  • Monitor for unexpected openvswitch module loads and namespace creation by unprivileged users in auditd logs
  • Prioritize patching on multi-tenant systems and any environment where untrusted local users exist

---

Cisco SD-WAN and IOS XE Critical Vulnerabilities

What happened: Cisco released patches for 12 security vulnerabilities affecting Catalyst SD-WAN and IOS XE Software, including three flaws with CVSS scores of 9.8–9.9. The vulnerabilities impact SD-WAN devices regardless of configuration and IOS XE Software running in autonomous or controller mode. Affected versions span 20.9 through 26.1 for SD-WAN and 17.9 through 26.1 for IOS XE. Additionally, CVE-2026-20200 affects Cisco Integrated Management Controller (IMC) with proof-of-concept exploit available.

Impact: Unauthenticated remote attackers can compromise devices through unauthorized access, command injection, and privilege escalation. The IMC vulnerability is particularly severe as it allows compromise of the trust anchor below OS level, bypassing EDR and achieving persistent BIOS/SecureBoot-level access. Wide deployment of affected products in enterprise networks increases attack surface. Cisco discovered these vulnerabilities during internal security testing using AI models.

Recommendations:

  • Upgrade Catalyst SD-WAN Software to fixed versions: 20.9.10, 20.12.8.1, 20.15.6, 20.18.4, or 26.1.2
  • Upgrade IOS XE Software to: 17.9.10, 17.12.8, 17.15.6, 17.18.4/17.18.4a, or 26.1.2
  • Prioritize patching Cisco IMC for CVE-2026-20200 due to available PoC exploit
  • Audit access logs on SD-WAN controllers and IOS XE devices for unauthorized access or privilege escalation attempts
  • For devices running SD-WAN versions earlier than 20.9, migrate to a supported fixed release immediately

---

Gitea Unauthenticated File Read Vulnerability

What happened: A critical unauthenticated file-read vulnerability (CVE-2026-59774, CVSS 9.8) affects Gitea versions 1.22.1 through 1.27.0. Attackers can read arbitrary files accessible by the Gitea service account using crafted Org-mode markup in public repositories. The vulnerability requires no authentication or write access—only submission of malicious markup to a public repository endpoint. Fixed in Gitea 1.27.1.

Impact: Self-hosted instances with public repositories face immediate risk. Attackers can extract app.ini containing internal tokens, database credentials, OAuth secrets, and JWT signing keys. Theoretical escalation to remote code execution exists via token extraction and Git hook injection, though no public exploit demonstrates this chain. Gitea Cloud instances upgraded automatically. Rapid7 published a Metasploit module in June 2026.

Recommendations:

  • Upgrade all self-hosted Gitea instances to version 1.27.1 immediately
  • Review web server logs for anonymous POST requests to /{owner}/{repo}/markup endpoint with Org-mode content containing #+INCLUDE directives
  • If suspicious activity found, rotate INTERNAL_TOKEN in app.ini, all OAuth credentials, JWT signing keys, and database passwords
  • Inspect repository hook directories for unexpected executable files indicating attempted RCE escalation
  • If immediate patching impossible, temporarily disable public repository access until upgrade completed

---

Threat Actor Activity

UNC6671 Targets Financial Sector via Vishing

Google's Threat Intelligence Group tracks UNC6671, a financially motivated extortion group reportedly associated with BlackFile threat actors. The group evolved from the public "BlackFile" brand (February 2025) to "Redact" (May 2026), with GTIG assessing diversification across multiple brands including Pink, Helix, and Falcon. Between January and May 2026, GTIG tracked over $10.6 million in Bitcoin payments to group wallets.

TTPs: Voice phishing (vishing) targeting employees on personal mobile phones while spoofing corporate helpdesks, directing victims to adversary-in-the-middle phishing kits hosted on domains impersonating target companies. The group steals credentials and session cookies in real time, targeting Microsoft 365 and Okta SSO accounts to access all linked cloud platforms. Post-compromise, automated tools exfiltrate data from accessible cloud services while deleting security notifications and password-reset emails.

Targets: Initially focused on retail and hospitality (February 2025), the group expanded to manufacturing, healthcare, real estate, technology, and transportation through mid-2026. In July 2026, targeting shifted toward high-value financial sector entities including Point72 Asset Management, Millennium Management, Two Sigma Investments, Citadel, and unnamed private-equity firms.

Snowflake Breach Campaign

Connor Riley Moucka, a 26-year-old Canadian national, pleaded guilty to computer fraud and conspiracy charges for breaching over 165 organizations using Snowflake cloud storage between February and October 2024. The operation, conducted with co-conspirators including U.S. Army soldier Cameron Wagenius and American fugitive John Erin Binns, resulted in theft of call and text records from over 100 million AT&T customers and more than $9.5 million in victim losses.

TTPs: Credential-based access to Snowflake accounts lacking multi-factor authentication, obtained via infostealer malware infections. Attackers exfiltrated terabytes of sensitive data including call records, financial data, payroll information, and personally identifiable information. Post-compromise activities included extortion via threatened data publication, re-extortion attempts, and harassment of government officials and security researchers.

Targets: High-profile victims across entertainment (TicketMaster), financial services (Santander, Lending Tree), retail (Advance Auto Parts, Neiman Marcus), and telecommunications (AT&T, Verizon). Moucka obtained at least $2.5 million in Bitcoin from extortion payments and approximately $495,000 from data sales.

Kali365 Microsoft Device Code Phishing

Kali365 is a device code phishing campaign targeting US organizations through abuse of legitimate Microsoft authentication mechanisms. The operation shows sustained activity with over 80 public sandbox sessions recorded weekly, primarily focused on US-based enterprises across manufacturing, technology, healthcare, government, consulting, and managed security service providers.

TTPs: Three-stage attack chain involving phishing lures impersonating SharePoint, OneDrive, and DocuSign; credential access through legitimate Microsoft device login portal abuse where victims enter attacker-provided device codes; and persistence via OAuth token theft providing continued access to Microsoft 365 resources. Post-compromise activities include business email compromise, invoice manipulation, and data exfiltration.

Poipet Scam Network Leverages ChatGPT

OpenAI disrupted a Cambodia-based scam operation originating from Poipet that used ChatGPT to facilitate investment, romance, gambling, and law enforcement impersonation fraud schemes. The network demonstrates sophisticated coordination, running parallel campaigns while employing forced labor and human trafficking tactics.

TTPs: Social engineering via WhatsApp and Telegram, leveraging generative AI to create fake dating profiles, investment experts, and law enforcement personas. The operation uses a three-phase "ping-zing-sting" methodology involving initial contact, trust-building through extended engagement, and financial exploitation. AI tools enhance operational speed and scale through automated content generation and translation services.

Targets: Individuals across financial services, online dating platforms, and gambling communities. Primary geographic focus includes Bangladesh and India for recruitment, with victim targeting spanning multiple countries. Hundreds of targets engaged across scam types, with individual losses reaching thousands of dollars per victim.

---

Geopolitical Context

Swiss Government SharePoint Breach

Switzerland's federal IT office disclosed a breach of Microsoft SharePoint servers where attackers exploited vulnerabilities to compromise approximately 200 government accounts. The Federal Office for Information Technology and Telecommunication detected the intrusion within days and responded with network segmentation, credential resets, and full server reinstallation. Swiss authorities stated the affected platform was not authorized for classified or highly sensitive personal data storage. No attribution has been made public, and no ransomware claims or data leaks have emerged as of early August 2026.

The incident underscores persistent challenges even well-resourced governments face in maintaining patch cadence against actively exploited vulnerabilities. Switzerland's role hosting diplomatic missions and international organizations makes its government networks attractive targets for both intelligence collection and pre-positioning operations.

US Water Utility Attacks

Forescout discovered 4,407 internet-facing Rockwell Automation PLCs exposed online globally, with 22 found in US cities targeted by recent water utility cyberattacks. The FBI and EPA issued a joint advisory on incidents across at least seven states since late July 2026. Attackers changed IP addresses and set passwords on internet-reachable controllers without exploiting vulnerabilities, leveraging shared third-party mobile carrier configurations.

Over 70% of US-exposed controllers reside on major mobile networks (Verizon, AT&T, T-Mobile), indicating that third-party remote access solutions have created a distributed attack surface spanning multiple utilities. Primary models affected include MicroLogix 1400 (50%) and discontinued MicroLogix 1100 (8%). Nineteen of 22 controllers in attack-affected cities run firmware vulnerable to CVE-2017-16740.

---

Recommended Actions

Immediate (0–24 hours)

  • Apply Linux kernel patches for CVE-2026-64531 (OVSwrap) on all systems with Open vSwitch; block openvswitch module loading if not required
  • Upgrade Gitea to version 1.27.1 on all self-hosted instances with public repositories
  • Patch Cisco SD-WAN and IOS XE devices to fixed versions; prioritize internet-facing infrastructure
  • Update HashiCorp Terraform MCP Server to 1.1.0 if running Streamable HTTP mode
  • Upgrade Veeam Service Provider Console to build 9.3.0.35057 for all version 9 installations
  • Audit CryptoJS usage in all applications; upgrade to 4.0.0+ and issue wallet migration advisories if affected
  • Block Kali365 infrastructure and hunt for Microsoft device code authentication anomalies in Azure AD logs
  • Remove trojanized npm packages bianira-ui and fluid-type-ui; treat affected systems as compromised

Within 24–72 hours

  • Upgrade Google ADK for Python to 2.5.0+ and Vercel AI SDK packages to patched versions
  • Apply Django patches to 6.0.8 or 5.2.17 if using GeoDjango with spatial fields
  • Patch IBM Langflow, N-able N-central, and Apache Tomcat per CISA KEV catalog guidance
  • Update Paperclip AI control plane to v2026.416.0 or later
  • Rotate credentials for all npm publishing tokens, GitHub PATs, and cloud provider credentials accessible from developer workstations (ChainDrop response)
  • Review Snowflake accounts for MFA enforcement; rotate credentials if accounts lacked MFA during February–October 2024
  • Implement conditional access policies restricting Microsoft device code authentication flows

This week

  • Patch AMD and Intel systems for interrupt injection Spectre v2 bypass (TONTOU); prioritize shared Linux systems
  • Update Linux kernel for Zapscape KVM flaw (CVE-2026-64561) on hosts exposing nested virtualization
  • Remove Rockwell PLCs from direct internet exposure; isolate remote access through VPN or private APN
  • Audit Oracle databases for unauthorized Java sources; revoke CREATE JAVA SOURCE privileges from application accounts
  • Review Apple iCloud Private Relay usage; advise users requiring IP anonymity to use VPN until WebKit patches available
  • Educate users on ClickFix social engineering targeting macOS; never paste Terminal commands from untrusted sources
  • Hunt for COLDCARD phishing indicators; block domains coldcardteamnews.com and coldcardcompliance.com

---

Watch List

  • Veeam Service Provider Console critical vulnerabilities requiring immediate patching per CERT.BE advisory
  • ChainDrop npm worm self-propagation via stolen tokens; monitor for Ethereum smart contract C2 resolution
  • Token jacking campaigns stealing AI API keys for gray market resale through transfer stations
  • macOS ClickFix evolution with browser fingerprinting across 250+ domains evading sandbox detection
  • AI agent infrastructure flaws in AWS Bedrock, Google ADK, and Vercel SDK bypassing model authorization
  • n8n exposed API tokens discovered in public GitHub commits; 321 live instances accepting leaked credentials
  • UNC6671 vishing expansion to financial sector; monitor for helpdesk impersonation targeting SSO accounts

---

Sources

  • The Hacker News: CryptoJS, Linux OVSwrap, Cisco SD-WAN, Gitea, Zapscape KVM, Spectre v2, Rockwell PLCs, iCloud Private Relay, Oracle khunt, AWS/Google/Vercel agents, Paperclip AI, Veeam/Terraform/Django, npm NullReceiver, Kali365, ClickFix, Poipet scam network
  • BleepingComputer: macOS ClickFix, UNC6671, Swiss SharePoint breach, TONTOU, Ransom Cartel sentencing, Snowflake breach, Oracle khunt, COLDCARD phishing, CISA KEV warnings
  • Unit 42 (Palo Alto Networks): ChainDrop npm worm, Token jacking
  • Krebs on Security: Snowflake extortions guilty plea
  • Microsoft Security: macOS ClickFix fingerprinting evolution
  • CERT.BE: Veeam Service Provider Console critical vulnerabilities

---

*This brief covers threats observed through August 7, 2026. Organizations should prioritize patching based on asset exposure, threat actor targeting, and operational risk tolerance. Coordinate with vendors and national CERTs for sector-specific guidance.*