Ticker feed
Check Point has released hotfix updates for a critical authentication bypass flaw (CVE-2026-18574, CVSS 9.3) affecting its Security Management Server and Multi-Domain Security Management Server products. An unauthenticated attacker with network access can bypass authentication and execute arbitrary commands — potentially taking complete control of firewall policies, gateway configurations, and admin access.
Supported versions R81.20, R82 and R82.10 are fixed via Jumbo Hotfix Accumulator updates, listed in Check Point advisory sk185222. Smart-1 Cloud customers are already protected. Older R80 and early R81 releases are also affected but have hit end-of-support and will not receive patches — those instances need upgrading to a supported version.
Until you can patch, Check Point advises restricting Trusted Clients to approved administrative IP addresses and never using "Any" as a client definition. Check Point found the flaw internally and has seen no active exploitation yet — but given the stakes, patching now is non-negotiable.
Source: Cybersecurity News
Check Point has released hotfix updates for a critical authentication bypass flaw (CVE-2026-18574, CVSS 9.3) affecting its Security Management Server and Multi-Domain Security Management Server products. An unauthenticated attacker with network access can bypass authentication and execute arbitrary commands — potentially taking complete control of firewall policies, gateway configurations, and admin access.
Supported versions R81.20, R82 and R82.10 are fixed via Jumbo Hotfix Accumulator updates, listed in Check Point advisory sk185222. Smart-1 Cloud customers are already protected. Older R80 and early R81 releases are also affected but have hit end-of-support and will not receive patches — those instances need upgrading to a supported version.
Until you can patch, Check Point advises restricting Trusted Clients to approved administrative IP addresses and never using "Any" as a client definition. Check Point found the flaw internally and has seen no active exploitation yet — but given the stakes, patching now is non-negotiable.
Source: Cybersecurity News
A single attacker hijacked a GitHub maintainer account on 4 August and unleashed self-replicating malware. More than 440 npm packages were compromised in under four hours, rising to over 860 in total, with more than 2 billion combined monthly installs.
The worm first hit keyv, a package with 600 million monthly downloads, then spread to flat-cache, file-entry-cache and hundreds more. Built on the Mini Shai-Hulud framework, it steals npm, GitHub, AWS and CI credentials, plus crypto wallets and AI config files.
Compromised packages appear in 46% of all cloud environments — up from around 28% in earlier Shai-Hulud campaigns. Researchers from Wiz, Aikido, Microsoft and Socket are tracking the attack and have published indicators of compromise.
Rotate npm, GitHub and AWS credentials immediately. Infected packages carry setup.mjs and Math_Symbol.js plus a preinstall hook, and the worm persists through VS Code and Claude Code config files — so removing the package alone won't evict it.
Source: CyberScoop
A single attacker hijacked a GitHub maintainer account on 4 August and unleashed self-replicating malware. More than 440 npm packages were compromised in under four hours, rising to over 860 in total, with more than 2 billion combined monthly installs.
The worm first hit keyv, a package with 600 million monthly downloads, then spread to flat-cache, file-entry-cache and hundreds more. Built on the Mini Shai-Hulud framework, it steals npm, GitHub, AWS and CI credentials, plus crypto wallets and AI config files.
Compromised packages appear in 46% of all cloud environments — up from around 28% in earlier Shai-Hulud campaigns. Researchers from Wiz, Aikido, Microsoft and Socket are tracking the attack and have published indicators of compromise.
Rotate npm, GitHub and AWS credentials immediately. Infected packages carry setup.mjs and Math_Symbol.js plus a preinstall hook, and the worm persists through VS Code and Claude Code config files — so removing the package alone won't evict it.
Source: CyberScoop
In late July 2025, St. Paul, Minnesota discovered what the city called a "deliberate, coordinated" cyberattack on its systems. Online services went down, including water bill payments. Emergency 911 and trash collection kept running. The city declared a local state of emergency and later extended it as recovery dragged on.
Governor Tim Walz activated the Minnesota National Guard to assist — the first time the state had deployed it for a cyber incident. Mayor Melvin Carter said the risk to residents' personal data was low, since the city held little sensitive resident information, but could not rule out exposure of employee data.
The incident was later confirmed as ransomware. The Interlock group published roughly 43GB of stolen city data. Fraudulent invoices posing as city bills circulated during the response, and officials warned residents not to click unfamiliar links or attachments.
City systems were restored over the following weeks. Carter's line at the time still holds up as the useful lesson: rushing systems back online would have made the problem worse.
Source: CBS News Minnesota
In late July 2025, St. Paul, Minnesota discovered what the city called a "deliberate, coordinated" cyberattack on its systems. Online services went down, including water bill payments. Emergency 911 and trash collection kept running. The city declared a local state of emergency and later extended it as recovery dragged on.
Governor Tim Walz activated the Minnesota National Guard to assist — the first time the state had deployed it for a cyber incident. Mayor Melvin Carter said the risk to residents' personal data was low, since the city held little sensitive resident information, but could not rule out exposure of employee data.
The incident was later confirmed as ransomware. The Interlock group published roughly 43GB of stolen city data. Fraudulent invoices posing as city bills circulated during the response, and officials warned residents not to click unfamiliar links or attachments.
City systems were restored over the following weeks. Carter's line at the time still holds up as the useful lesson: rushing systems back online would have made the problem worse.
Source: CBS News Minnesota
Cybersecurity firm Darktrace says cloud and SaaS environments were attackers' top targets in the first half of 2026 — and increasingly their preferred operating environment, not just their destination. The shift is notable: threat actors have moved away from malware and vulnerability exploitation toward identity compromise, now extending attacks to email authentication, AI gateways, and software supply chains.
One compromised SaaS account triggered malicious activity across email, SaaS, and network layers simultaneously — the kind of attack that's hard to catch because no single indicator looks alarming alone. Attackers also hijacked Axios, a JavaScript library downloaded 100 million times weekly, to spread remote access trojans.
Email phishing is getting sharper too — two-thirds of phishing emails now pass DMARC validation. Meanwhile AI-generated malware, and JadePuffer — which researchers at Sysdig claim is the first ransomware campaign driven entirely by a large language model — signal that AI is closing the gap between vulnerability discovery and exploitation.
Source: Infosecurity Magazine
Cybersecurity firm Darktrace says cloud and SaaS environments were attackers' top targets in the first half of 2026 — and increasingly their preferred operating environment, not just their destination. The shift is notable: threat actors have moved away from malware and vulnerability exploitation toward identity compromise, now extending attacks to email authentication, AI gateways, and software supply chains.
One compromised SaaS account triggered malicious activity across email, SaaS, and network layers simultaneously — the kind of attack that's hard to catch because no single indicator looks alarming alone. Attackers also hijacked Axios, a JavaScript library downloaded 100 million times weekly, to spread remote access trojans.
Email phishing is getting sharper too — two-thirds of phishing emails now pass DMARC validation. Meanwhile AI-generated malware, and JadePuffer — which researchers at Sysdig claim is the first ransomware campaign driven entirely by a large language model — signal that AI is closing the gap between vulnerability discovery and exploitation.
Source: Infosecurity Magazine
A maximum-severity command injection flaw (CVE-2026-16812, CVSS 10.0) in on-premises Arista VeloCloud Orchestrator — formerly VeloCloud Orchestrator by Broadcom — is being actively exploited in the wild, and was exploited as a zero-day. Attackers need no credentials, just network access to the VCO web interface, to take control of the orchestrator and the SD-WAN fabric it manages.
Affected versions span VCO 5.2.x, 6.1.x, 6.4.x and 7.0.x. Fixes are available in 5.2.3.14, 6.1.3.4, 6.4.2.4 and 7.0.0.1. Hosted and Dedicated VCO instances were already patched by Arista.
Three attacker IPs have been identified: 8.19.75.217, 206.72.242.124, and 206.72.242.162. Admins should patch immediately, block those addresses and restrict web interface access. Arista also requires rotating credentials and validating device state after remediation — not only where compromise is suspected.
Source: Cybersecurity News
A maximum-severity command injection flaw (CVE-2026-16812, CVSS 10.0) in on-premises Arista VeloCloud Orchestrator — formerly VeloCloud Orchestrator by Broadcom — is being actively exploited in the wild, and was exploited as a zero-day. Attackers need no credentials, just network access to the VCO web interface, to take control of the orchestrator and the SD-WAN fabric it manages.
Affected versions span VCO 5.2.x, 6.1.x, 6.4.x and 7.0.x. Fixes are available in 5.2.3.14, 6.1.3.4, 6.4.2.4 and 7.0.0.1. Hosted and Dedicated VCO instances were already patched by Arista.
Three attacker IPs have been identified: 8.19.75.217, 206.72.242.124, and 206.72.242.162. Admins should patch immediately, block those addresses and restrict web interface access. Arista also requires rotating credentials and validating device state after remediation — not only where compromise is suspected.
Source: Cybersecurity News
N-able has disclosed a critical vulnerability in its N-central RMM platform — tracked as CVE-2026-18577 — that lets unauthenticated attackers gain full administrative access to the console. It is actively being exploited, and it exists because the earlier fix for CVE-2026-18556 left another exploitable path: partners who patched that flaw are not covered.
Every instance not running 2026.3.1 is affected. N-able is upgrading its hosted NCOD instances automatically, with no customer action needed, but self-hosted partners must apply the hotfix themselves.
Because MSPs use N-central to manage thousands of customer endpoints, a single compromised server can trigger a massive supply-chain incident. Attackers can push scripts, deploy tools, and hijack remote sessions across every managed device — including domain controllers.
N-able released hotfix version 2026.3.1.7 on August 2. Patch immediately, restrict console access, enforce MFA, and hunt for the published indicators: a svchost.exe file in managed devices' Documents folders, a registered service named Cloudflared, and any unfamiliar admin accounts or unexpected remote sessions.
Updated 11 Aug 2026: N-able released Hotfix 2 (2026.3.1.10) on 6 August, adding further hardening after identifying a related attack path. It supersedes Hotfix 1 — apply it if you haven't already.
Source: Cybersecurity News
N-able has disclosed a critical vulnerability in its N-central RMM platform — tracked as CVE-2026-18577 — that lets unauthenticated attackers gain full administrative access to the console. It is actively being exploited, and it exists because the earlier fix for CVE-2026-18556 left another exploitable path: partners who patched that flaw are not covered.
Every instance not running 2026.3.1 is affected. N-able is upgrading its hosted NCOD instances automatically, with no customer action needed, but self-hosted partners must apply the hotfix themselves.
Because MSPs use N-central to manage thousands of customer endpoints, a single compromised server can trigger a massive supply-chain incident. Attackers can push scripts, deploy tools, and hijack remote sessions across every managed device — including domain controllers.
N-able released hotfix version 2026.3.1.7 on August 2. Patch immediately, restrict console access, enforce MFA, and hunt for the published indicators: a svchost.exe file in managed devices' Documents folders, a registered service named Cloudflared, and any unfamiliar admin accounts or unexpected remote sessions.
Updated 11 Aug 2026: N-able released Hotfix 2 (2026.3.1.10) on 6 August, adding further hardening after identifying a related attack path. It supersedes Hotfix 1 — apply it if you haven't already.
Source: Cybersecurity News
UK Government Investments (UKGI), the agency managing taxpayer stakes in companies like Channel 4 and the Post Office, has disclosed a data breach in its annual report for 2025–26. An internal file of high-level management information, including the names and work email addresses of 51 government officials, was left publicly accessible for nearly 40 hours.
A staff member failed to follow established information security policies, triggering the exposure. UKGI reported the incident to the Information Commissioner's Office voluntarily — it did not meet the mandatory notification threshold — and escalated it to its board.
UKGI also brought in external security specialists, who recommended stronger internal controls and better incident preparedness. The overwhelming majority of those recommendations have already been implemented, with the rest scheduled. The disclosure lands as public agencies grapple with growing cybersecurity risks, particularly as AI tools make it faster and easier to exploit security gaps.
Source: The Guardian
UK Government Investments (UKGI), the agency managing taxpayer stakes in companies like Channel 4 and the Post Office, has disclosed a data breach in its annual report for 2025–26. An internal file of high-level management information, including the names and work email addresses of 51 government officials, was left publicly accessible for nearly 40 hours.
A staff member failed to follow established information security policies, triggering the exposure. UKGI reported the incident to the Information Commissioner's Office voluntarily — it did not meet the mandatory notification threshold — and escalated it to its board.
UKGI also brought in external security specialists, who recommended stronger internal controls and better incident preparedness. The overwhelming majority of those recommendations have already been implemented, with the rest scheduled. The disclosure lands as public agencies grapple with growing cybersecurity risks, particularly as AI tools make it faster and easier to exploit security gaps.
Source: The Guardian
Ruby on Rails has patched a critical vulnerability (CVE-2026-66066, CVSS 9.5) that could let unauthenticated attackers read arbitrary files and achieve remote code execution. The flaw affects applications using the libvips library for Active Storage image processing that accept uploads from untrusted users — a very common setup.
Attackers could upload a crafted file to expose secrets like secret_key_base, then escalate to full RCE or lateral movement. Fixes are available in Active Storage versions 7.2.3.2, 8.0.5.1 and 8.1.3.1. You also need libvips 8.13 or later and, where ruby-vips is installed, ruby-vips 2.2.1 or later.
No active exploitation had been detected as of July 30, but proof-of-concept exploit code is already public — researchers reverse-engineered the flaw and published working chains, prompting Rails to bring its full technical disclosure forward from August 28.
Rotate everything the application process could reach: secret_key_base, the Rails master key and the credentials it decrypts, storage service and database credentials, and third-party service tokens.
Updated 11 Aug 2026: A Metasploit module for this flaw was published on 3 August, putting a working exploit in the hands of any attacker with the framework installed. Patch and rotate immediately if you haven't.
Source: SecurityWeek
Ruby on Rails has patched a critical vulnerability (CVE-2026-66066, CVSS 9.5) that could let unauthenticated attackers read arbitrary files and achieve remote code execution. The flaw affects applications using the libvips library for Active Storage image processing that accept uploads from untrusted users — a very common setup.
Attackers could upload a crafted file to expose secrets like secret_key_base, then escalate to full RCE or lateral movement. Fixes are available in Active Storage versions 7.2.3.2, 8.0.5.1 and 8.1.3.1. You also need libvips 8.13 or later and, where ruby-vips is installed, ruby-vips 2.2.1 or later.
No active exploitation had been detected as of July 30, but proof-of-concept exploit code is already public — researchers reverse-engineered the flaw and published working chains, prompting Rails to bring its full technical disclosure forward from August 28.
Rotate everything the application process could reach: secret_key_base, the Rails master key and the credentials it decrypts, storage service and database credentials, and third-party service tokens.
Updated 11 Aug 2026: A Metasploit module for this flaw was published on 3 August, putting a working exploit in the hands of any attacker with the framework installed. Patch and rotate immediately if you haven't.
Source: SecurityWeek
JetBrains has patched a critical vulnerability (CVE-2026-63077, CVSS 9.8) in TeamCity On-Premises that lets attackers execute OS commands remotely — no credentials required. All versions are affected. An attacker only needs HTTP or HTTPS access to exploit the flaw, which lives in the TeamCity agent polling protocol.
A successful attack could expose stored credentials, build secrets, and configuration files, or allow code injection into software releases. Security researcher Antoni Tremblay privately reported the issue on July 10, 2026.
Fixed versions 2025.11.7 and 2026.1.3 are available now. Admins who can't upgrade immediately can install a temporary security patch plugin, which supports TeamCity 2017.1 and later. TeamCity Cloud is unaffected, so cloud customers need take no action.
Updated 11 Aug 2026: CISA added CVE-2026-63077 to its Known Exploited Vulnerabilities catalog on 5 August, and JetBrains issued a follow-up advisory on 7 August confirming reports of attacks against unpatched servers.
Source: Cybersecurity News
JetBrains has patched a critical vulnerability (CVE-2026-63077, CVSS 9.8) in TeamCity On-Premises that lets attackers execute OS commands remotely — no credentials required. All versions are affected. An attacker only needs HTTP or HTTPS access to exploit the flaw, which lives in the TeamCity agent polling protocol.
A successful attack could expose stored credentials, build secrets, and configuration files, or allow code injection into software releases. Security researcher Antoni Tremblay privately reported the issue on July 10, 2026.
Fixed versions 2025.11.7 and 2026.1.3 are available now. Admins who can't upgrade immediately can install a temporary security patch plugin, which supports TeamCity 2017.1 and later. TeamCity Cloud is unaffected, so cloud customers need take no action.
Updated 11 Aug 2026: CISA added CVE-2026-63077 to its Known Exploited Vulnerabilities catalog on 5 August, and JetBrains issued a follow-up advisory on 7 August confirming reports of attacks against unpatched servers.
Source: Cybersecurity News
AWS assesses with medium confidence that a series of npm supply chain attacks — targeting popular libraries including axios, debug, chalk, and typo-crypto — was the work of a North Korean threat group known as Sapphire Sleet or BlueNoroff. The group socially engineered package maintainers, then pushed malicious updates that automatically executed on installation.
Axios alone sees over 100 million weekly downloads, and according to Wiz Research the debug and chalk attacks hit roughly 1 in 10 cloud environments within just two hours. AWS CISO CJ Moses noted the typo-crypto compromise in March 2025 appears to have been a test run. Attackers are also now exploiting AI-hallucinated package names to expand their reach.
Source: Infosecurity Magazine
AWS assesses with medium confidence that a series of npm supply chain attacks — targeting popular libraries including axios, debug, chalk, and typo-crypto — was the work of a North Korean threat group known as Sapphire Sleet or BlueNoroff. The group socially engineered package maintainers, then pushed malicious updates that automatically executed on installation.
Axios alone sees over 100 million weekly downloads, and according to Wiz Research the debug and chalk attacks hit roughly 1 in 10 cloud environments within just two hours. AWS CISO CJ Moses noted the typo-crypto compromise in March 2025 appears to have been a test run. Attackers are also now exploiting AI-hallucinated package names to expand their reach.
Source: Infosecurity Magazine