Back to Archive
THREAT INTELLIGENCE BRIEFยทWednesday, August 5, 2026ยทAI-Powered

The most urgent threat this week is the active exploitation of two vulnerabilities in N-able N-central (CVE-2026-18577, CVE-2026-18556), which have been added to the CISA KEV list.

The most urgent threat this week is the active exploitation of two vulnerabilities in N-able N-central (CVE-2026-18577, CVE-2026-18556), which have been added to the CISA KEV list. Immediate patching is required for all federal agencies and recommended for all other organizations. Additionally, a critical flaw in cPanel (CVE-2026-58048) with a 9.4 CVSS score now has public proof-of-concept exploit code available, increasing its risk. Ongoing software supply chain attacks against npm and QuickFox VPN users, alongside a Russian state-sponsored campaign targeting Microsoft 365 credentials via public Wi-Fi, represent significant and broad-based threats to our development and user environments.

46 articles analysed3 CVEs mentioned

Threat Categories

๐Ÿ’€Malware3
๐Ÿ›Vulnerabilities2

Article Analyses (5)

CISA Adds Exploited N-able N-central Flaw to KEV After Customer Compromises

high
CVE-2026-18577CVE-2026-18556
KEVEPSS 2.5%

Details

A high-severity vulnerability in N-able N-central, CVE-2026-18577, has been added to the CISA Known Exploited Vulnerabilities (KEV) catalog due to active exploitation. This flaw is an incomplete patch for a previous vulnerability, CVE-2026-18556, which is also listed on the KEV. The vulnerabilities allow for unauthorized actions on affected systems, leading to customer compromises.

Affected Systems

N-able N-central

Potential Impact

Compromise of the N-central remote monitoring and management platform, potentially leading to widespread unauthorized access to managed downstream customer endpoints, data exfiltration, and ransomware deployment.

Mitigations

Immediately apply patches provided by N-able. Per the CISA KEV directive, federal agencies must patch these vulnerabilities by the specified deadlines. All other organizations are strongly advised to patch immediately.

The Hacker NewsDraft Post

New cPanel Critical Flaw Could Let Hosting Customers Run SQL as Database Root

high
CVE-2026-58048
EPSS 0.5%PoC

Details

A critical vulnerability, CVE-2026-58048, has been discovered in cPanel. The flaw allows an authenticated hosting customer to execute SQL queries in the database's root context. This crosses the privilege boundary between a standard cPanel account and the server's administrative database identity. Public exploit code is available for this vulnerability.

Affected Systems

cPanel (versions prior to the latest security release)

Potential Impact

An attacker with a low-privilege cPanel hosting account could gain root-level database access, potentially leading to a full server compromise, data theft from all other hosted customers on the server, and website defacement.

Mitigations

Update all cPanel instances to the latest version immediately. The vendor has shipped a targeted security release to address this and two other flaws.

The Hacker NewsDraft Post

Massive ChainDrop npm supply-chain attack infects hundreds of packages

high

Details

A self-propagating malware named 'ChainDrop' has compromised over 1,300 packages on the Node Package Manager (npm) registry. These infected packages have a combined total of 2 billion monthly downloads, indicating a massive potential attack surface. The malware is designed to spread to other packages.

Affected Systems

Software development environments and applications utilizing packages from the public npm registry.

Potential Impact

Widespread compromise of CI/CD pipelines and production applications. Malicious code could be injected into software distributed to end-users, leading to further downstream compromises.

Mitigations

Audit npm dependencies for signs of compromise. Utilize package integrity and reputation tools. Enforce strict version pinning and review package updates before integration. Monitor development environments for anomalous activity.

BleepingComputerDraft Post

QuickFox Supply Chain Attack Delivers FDMTP Backdoor via Trojanized Windows Installer

critical

Details

A long-standing supply chain attack, active since at least August 2025, has been identified targeting users of the QuickFox VPN and network acceleration tool. Attackers are distributing a trojanized version of the Windows installer to deliver a backdoor known as FDMTP.

Affected Systems

Users of the QuickFox application, primarily overseas Chinese users.

Potential Impact

Full system compromise for users who have downloaded the trojanized installer. The FDMTP backdoor could allow attackers to steal sensitive information, deploy additional malware, and use the compromised systems in botnets.

Mitigations

Advise employees, particularly those in the targeted demographic, against using QuickFox. Scan systems for indicators of compromise related to FDMTP. Ensure software is only downloaded from official and verified sources.

The Hacker NewsDraft Post

Russian hackers abuse hotel Wi-Fi networks to steal Microsoft 365 credentials and deploy malware

critical

Details

The Russian state-sponsored actor Midnight Blizzard is targeting users on public Wi-Fi networks, such as those in hotels and conference centers, to steal Microsoft 365 credentials. The campaign, named CaptiveCrunch, uses malware strains CornFlake and ChocoShell to intercept traffic and compromise accounts.

Affected Systems

Users of Microsoft 365, particularly those connecting from untrusted public Wi-Fi networks.

Potential Impact

Compromise of corporate Microsoft 365 accounts, leading to business email compromise (BEC), data exfiltration of sensitive emails and files, and lateral movement within the corporate network.

Mitigations

Enforce a strict policy requiring the use of corporate VPNs on all untrusted networks, including public Wi-Fi. Ensure MFA is enabled for all M365 accounts. Educate traveling employees about the risks of captive portals and public Wi-Fi.

Help Net SecurityDraft Post
Generated by gemini-2.5-pro