
Coverage: Last 24 hours
Today’s Highlights
New phishing and supply chain attacks continue to erode trust in upstream dependencies and MFA protections, while the AI security stack and critical sector infrastructure defenses come under intense pressure. Threat actors are exploiting the trust placed in software update channels, leveraging innovative phishing-as-a-service toolkits, and finding new avenues into cloud and on-premise systems. Security teams should prioritize detection and response for supply chain and identity attacks, review controls for AI-driven workflows, and increase preparedness for critical infrastructure disruptions.
Table of Contents
- Water Sector Cyberattacks Reportedly Hit at Least 12 States
- Black Hat USA 2026 – Summary of Vendor Announcements (Part 2)
- Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens
- Keyv-Linked npm Worm Poisons Hundreds of Packages, Plants Claude Code and VS Code Hooks
- Fake Adobe and Zoom Updates Install ScreenConnect for Persistent Remote Access
- New cPanel Critical Flaw Could Let Hosting Customers Run SQL as Database Root
- DOUBLECUP Uses ClickFix and Cached PNGs to Deliver CountLoader and DeviceManager RAT
- When Vibe Hacking Turns AI into the Junior Hacker Every Adversary Always Wanted
- Google Deletes 3 ADK AI Workflows After Malicious GitHub Issue Could Trigger Privileged Agent
- Rethinking AI Security: Why CASB and DLP Need an Interaction-Aware Layer
- Oligo Raises $60 Million for Runtime Security
Top Stories
Water Sector Cyberattacks Reportedly Hit at Least 12 States
Source: SecurityWeek | Risk: Critical | Impacted: Water utilities, OT network operators, Municipal infrastructure teams
Summary: Georgia has been confirmed as one of the attacked states after Clayton County reported a pump station disruption. The post Water Sector Cyberattacks Reportedly Hit at Least 12 States appeared first on SecurityWeek.
Why it matters: Operational technology outages in critical infrastructure like water utilities can disrupt essential public services, expose physical safety to risk, and typically indicate attacker footholds that could be further leveraged for data theft or kinetic effects.
Practitioner Perspective
Utilities supporting water pumping and treatment systems must treat recent multi-state incidents as evidence of active targeting and likely cross-sector threat group activity against OT/ICS environments. Even where the disruption is limited to a pump station (as in Clayton County, Georgia), attackers may retain persistence or have broader access than detected. Such incidents often reveal gaps in segmentation between business and plant networks, and recovery often depends on rapid isolation, not just malware removal. Security leaders should review incident response and continuity of operations plans for industrial control system environments. The key concern is that these events may be a precursor to more severe or coordinated attacks.
Recommended Actions – Isolate affected pump station and OT control systems at first sign of disruption or unauthorized access – Conduct forensic analysis of compromised ICS endpoints for lateral movement indicators
Black Hat USA 2026 – Summary of Vendor Announcements (Part 2)
Source: SecurityWeek | Risk: Medium | Impacted: Security architects, Vendor evaluation teams, Enterprises expanding security stacks
Summary: Many companies are showcasing their products and services this week at the 2026 edition of the Black Hat conference in Las Vegas. The post Black Hat USA 2026 – Summary of Vendor Announcements (Part 2) appeared first on SecurityWeek.
Why it matters: Rapid innovation and product expansion showcased at major security conferences signal new feature sets as well as fresh attack surfaces and integration complexity, requiring defenders to reevaluate tool fit and risk exposures.
Practitioner Perspective
Security teams adopting new products announced at Black Hat must avoid default configurations and confirm that vendor documentation addresses current exploit pathways. Incremental feature releases or platform expansions often outpace robust threat modeling, leading to security gaps if rushed into production. Tech preview offerings and interoperability improvements sometimes introduce opaque dependencies or data sharing risks. Focus evaluations on how new tools integrate with existing detection, response, and identity frameworks and whether support for current threat patterns is documented. Critical next step, push vendors for adversarial testing evidence, not just capability claims.
Recommended Actions – Request red team outcome documentation for any new feature or product demonstrated at Black Hat 2026 – Scrutinize vendor implementation guides for sections on exploit and threat actor use cases
Emerging Signals
Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens
Source: The Hacker News | Risk: High | Impacted: M365 tenants, Google Workspace organizations, OAuth-integrated SaaS users
Summary: The commercial phishing-as-a-service (PhaaS) toolkit known as Greatness has become the latest crimeware solution to add support for device code phishing, a rapidly growing cyber threat that abuses the legitimate OAuth 2.0 Device Authorization Grant to bypass Multi-Factor Authentication (MFA) and seize control of user accounts. “Greatness supports AiTM [adversary-in-the-middle] credential and”
Why it matters: Device code phishing techniques allow attackers to bypass multi-factor authentication by leveraging legitimate OAuth flows, threatening identity assurance and enabling broad account takeover in cloud environments.
Practitioner Perspective
Any enterprise using federated identity providers or SaaS platforms integrated via OAuth 2.0 is now exposed to adversary-in-the-middle PhaaS toolkits capable of stealing tokens despite MFA. Device code phishing introduces a different attack surface compared to classic credential theft, social pretexting is paired with real-time session hijack via trusted device authorization endpoints. This evolution underscores the need to address token lifetimes, restricted scopes, and session verification instead of relying solely on MFA as a panacea. Security teams must adapt detection and mitigation to focus on anomalous OAuth consent flows and downstream session usage. The immediate concern is rapid account takeover by cybercrime groups leveraging these turnkey toolkits.
Recommended Actions – Enable sign-in risk detection and OAuth consent logging in Microsoft Entra/Azure AD – Restrict OAuth device code grant to trusted applications and block for high-risk accounts
Keyv-Linked npm Worm Poisons Hundreds of Packages, Plants Claude Code and VS Code Hooks
Source: The Hacker News | Risk: High | Impacted: npm package consumers, JavaScript build pipelines, Software engineering orgs
Summary: A credential-stealing npm worm that first appeared in [email protected] spread beyond the Keyv and Cacheable namespaces into hundreds of packages across multiple organizations on August 4, 2026. SafeDep verified 353 poisoned versions across 79 package names in the npm registry. Its monitoring put the wider footprint at 442 versions across 353 names, while Aikido later reported at least 868 packages
Why it matters: Wide-scale npm ecosystem compromise through credential-stealing worms enables rapid propagation of malicious code into production apps, directly exposing business workflows and internal developer credentials to theft.
Practitioner Perspective
Engineering teams with dependencies on npm JavaScript packages, especially those referencing Keyv, Cacheable, or tightly coupled transitive packages, face heightened risk of supply chain malware infiltration. These worm campaigns are designed for automatic propagation across development pipelines and CI/CD systems, embedding credential harvesters that threaten both proprietary source code and access controls. This incident aligns with the rise in package ecosystem attacks that target developer trust and attack upstream dependencies. Security teams should not only perform package lock audits but consider rolling developer credential resets and downstream incident response due to possible compromise. The highest near-term concern is that tainted npm packages will be baked into new builds and reach production before detection.
Recommended Actions – Run integrity verification on all npm packages, especially Keyv, Cacheable, and those recently updated – Purge cache and redeploy any artifacts built using poisoned npm package versions listed in reports from SafeDep and Aikido
Fake Adobe and Zoom Updates Install ScreenConnect for Persistent Remote Access
Source: The Hacker News | Risk: High | Impacted: Corporate desktop fleets, SMB IT-managed workstations, Remote workforce endpoints
Summary: Cybersecurity researchers have disclosed details of an active, multi-wave campaign that employs social engineering lures themed around Adobe and Zoom software updates, business document reviews, and system maintenance utilities to stealthily deploy Remote Monitoring and Management (RMM) programs like ConnectWise ScreenConnect. The campaign has been codenamed SMOKE#SCREEN by Securonix Threat
Why it matters: Attackers leveraging familiar brand lures and IT workflow impersonation to deploy legitimate RMM tools like ConnectWise ScreenConnect increase the threat of stealthy, persistent remote access without triggering traditional malware alarms.
Practitioner Perspective
Any environment where staff expect regular third-party software updates, especially from Adobe or Zoom, is susceptible to multi-stage social engineering campaigns that culminate in the installation of RMM utilities as remote access footholds. By using tools like ScreenConnect, adversaries can bypass traditional endpoint security barriers, these binaries and processes often appear legitimate to EDR or allowlisting controls. This campaign highlights the growing operational blind spot of RMM and IT automation platforms being abused for lateral movement and data collection. Security teams must not only validate install prompts and IT communications but review RMM controls for rogue deployments. The central concern is privilege creep associated with unauthorized ScreenConnect installations.
Recommended Actions – Block unauthorized deployments of ConnectWise ScreenConnect executables at the endpoint level – Correlate recent Adobe and Zoom update prompts with RMM agent installations in SOC reporting workflows
New cPanel Critical Flaw Could Let Hosting Customers Run SQL as Database Root
Source: The Hacker News | Risk: Critical | Impacted: Web hosting providers, Shared cPanel tenants, Managed service customers
Summary: cPanel has patched a flaw that let an authenticated hosting customer execute SQL in the database’s root context, crossing the privilege boundary between a cPanel account and the server’s administrative database identity. It shipped in a targeted security release that closes two other routes past account boundaries. The database bug is tracked as CVE-2026-58048 (CVSS 9.4 score: 9.4) and affects
Why it matters: Privilege escalation flaws in hosting management stacks like cPanel allow tenants to execute commands as the database root, threatening the segregation of customer workloads and risking server-wide compromise in shared environments.
Practitioner Perspective
Any organization hosting workloads or customer environments on cPanel platforms must immediately assume elevated insider and tenant-to-tenant risk given the exploitation window on CVE-2026-58048. The flaw enables authenticated customers to commandeer root-level database access, undermining controlled privilege boundaries and potentially exposing all hosted data. Even with patch availability, attackers with legitimate or compromised credentials could retain lingering persistence if remediation is delayed. This incident highlights the challenge of defending shared SaaS and PaaS environments against privilege-crossing flaws, rapid patch validation and compromise assessment are now table stakes. Security managers need to examine backup and recovery plans for multi-tenant environments.
Recommended Actions – Apply targeted cPanel security release addressing CVE-2026-58048 and related privilege boundary bugs – Audit affected servers for unauthorized SQL queries and privilege escalations since flaw publication
DOUBLECUP Uses ClickFix and Cached PNGs to Deliver CountLoader and DeviceManager RAT
Source: The Hacker News | Risk: High | Impacted: Windows desktop fleets, Organizations with liberal web access, Corporate browsers
Summary: A new Russian loader-as-a-service (LaaS) codenamed DOUBLECUP has been using ClickFix lures as a way to stage malware-laced PNG images in victims’ browser cache and ultimately deliver CountLoader and a previously undocumented remote access trojan called DeviceManager. “The first stage drops a steganographic PNG image into the browser’s cache, retrieves its hidden content, and executes the second”
Why it matters: Steganography-based malware delivery bypasses network inspection by hiding payloads in seemingly benign cached images, complicating detection and exposing end users to remote access trojans via normal browsing habits.
Practitioner Perspective
Environments where users access untrusted sites or run with permissive browser cache settings may be vulnerable to loader-as-a-service (LaaS) offerings like DOUBLECUP leveraging steganographic PNG delivery. The use of ClickFix lures suggests adversaries are adapting to cloud sandboxing and modern traffic inspection by embedding payloads in graphics artifacts cached by browsers, which are often ignored by AV heuristics. Security operations must now look for abnormal image files and secondary process launches following browser cache reads, incidentally raising the bar for malware detection playbooks. Defenders cannot rely exclusively on perimeter controls or basic user education. Focus detection on suspicious file execution chains tied to browser-managed directories.
Recommended Actions – Monitor browser cache directories for executable content and steganographic PNG image anomalies related to ClickFix – Deploy threat hunting rules for DeviceManager RAT and CountLoader activity in endpoint logs
Exploits & CVEs
No new dedicated CVE or exploit story entries in this cycle.
Defensive Actions
- Run integrity verification on all npm packages, especially Keyv, Cacheable, and those recently updated
- Audit for anomalous outbound C2 or VPN traffic patterns initiated by QuickFox processes
- Initiate developer credential rotations for accounts associated with npm publishing
- Apply targeted cPanel security release addressing CVE-2026-58048 and related privilege boundary bugs
- Enable sign-in risk detection and OAuth consent logging in Microsoft Entra/Azure AD
- Review firewall and segmentation rules between corporate and OT environments in water utilities
- Update CASB/DLP rule sets to include content inspection of AI prompt and output channels
- Block unauthorized deployments of ConnectWise ScreenConnect executables at the endpoint level
- Restrict privileged ADK workflow triggers to verified user accounts and trusted sources
- Pilot in-production anomaly detection solutions to monitor application behavior
What We’re Watching
When Vibe Hacking Turns AI into the Junior Hacker Every Adversary Always Wanted
Source: The Hacker News | Risk: Medium | Impacted: Security operations teams, Enterprises piloting AI tools, User-facing platforms integrating AI
Summary: The cybersecurity industry has spent decades assuming that offensive capability scales with technical expertise. That assumption is starting to break. Security teams have long estimated risk by ranking attacker sophistication. Nation-state actors sat at one end. Organized criminal groups followed. Inexperienced attackers, dismissed as “script kiddies,” sat at the other end, running public
Why it matters: The lowered barrier for offensive operations due to generative AI shifts risk calculations, as less skilled actors can now orchestrate sophisticated intrusions or evade defenses by repurposing AI models.
Practitioner Perspective
Security practitioners must recognize that generative AI reduces the technical bar for attack automation, content generation, and exploit orchestration. Offense can now be operationalized by actors without formal expertise by leveraging model output for phishing, script generation, and reconnaissance. This disrupts the traditional pyramid of attacker sophistication, any operational environment exposed to AI-driven content or automation may see a surge in credible threats from previously marginalized attackers. Analysts should review how services allow AI integration and what gates or controls exist for produced content. Update threat modeling to assume AI-enhanced adversaries, not just highly skilled manual actors.
Recommended Actions – Review internal controls on AI chatbot and automation tool production use – Harden validation and input filtering on tools that allow user-generated content via AI
Google Deletes 3 ADK AI Workflows After Malicious GitHub Issue Could Trigger Privileged Agent
Source: The Hacker News | Risk: Medium | Impacted: AI developer teams, GitHub CI/CD repository owners, Organizations using ADK Python workflows
Summary: Google deleted three AI agent workflows from its Agent Development Kit (ADK) Python repository. Pillar Security showed that a public GitHub issue could manipulate a triage agent into triggering a privileged code-fixing agent. The researchers said the public agent could be prompt-injected into posting /adk-issue-fix as adk-bot. They identified the bot as a collaborator, so that comment satisfied
Why it matters: Privilege escalation in AI agent repositories through prompt injection exposes automated workflows to malicious manipulation, enabling attackers to influence or compromise systems supposed to self-heal or triage issues.
Practitioner Perspective
Teams relying on AI agent automation in workflows or CI/CD processes, especially those based on Google’s Agent Development Kit (ADK), must recognize that prompt injection from public inputs can force privileged workflow execution. This represents a new class of supply chain risk where the attack pivot is through trusted bots or automation, not just human users. Lack of contextual isolation between public/user agents and privileged automation can result in privilege escalation or unwanted code changes. Security review cycles for automation must now include adversarial input simulation, particularly in open-source or GitHub-exposed environments. The most urgent step is to map out and segment trusted agent triggers from public submission points.
Recommended Actions – Restrict privileged ADK workflow triggers to verified user accounts and trusted sources – Simulate prompt injection scenarios targeting AI/ML agents in automation repositories
Rethinking AI Security: Why CASB and DLP Need an Interaction-Aware Layer
Source: SecurityWeek | Risk: Medium | Impacted: Infosec teams at AI-adopting companies, Data governance managers, Cloud security architects
Summary: Build your strategy around answering these questions to ensure employees use AI productively while keeping sensitive data, IP, and agent behavior within the boundaries set for safe AI use. The post Rethinking AI Security: Why CASB and DLP Need an Interaction-Aware Layer appeared first on SecurityWeek.
Why it matters: Existing CASB and DLP controls are insufficient for tracking and constraining data flow into AI models, leaving organizations exposed to inadvertent leakage of sensitive data and loss of control over AI-driven decision processes.
Practitioner Perspective
Enterprises piloting or scaling AI must go beyond legacy data protection layers, as traditional DLP and CASB were not designed for real-time tracking of information shared via generative AI interfaces or agent workflows. Sensitive data, intellectual property, and process triggers can be ingested and processed by LLMs or commercial agents without observable events in classic security monitoring. Comprehensive AI security now demands contextual inspection, policy enforcement on model interactions, and explicit use-case controls for both employees and bots. Security leaders should assess their organization’s readiness to detect and prevent high-stakes data flows through AI channels. Immediate focus, map out all known and shadow AI integrations, then prioritize those handling regulated or mission-critical data.
Recommended Actions – Inventory all sanctioned and shadow AI integrations touching sensitive company data – Update CASB/DLP rule sets to include content inspection of AI prompt and output channels
Oligo Raises $60 Million for Runtime Security
Source: SecurityWeek | Risk: Medium | Impacted: Cloud application owners, DevSecOps teams, CISO teams in digital transformation
Summary: The company will use the investment to accelerate product innovation and expand go-to-market operations. The post Oligo Raises $60 Million for Runtime Security appeared first on SecurityWeek.
Why it matters: Significant investment in runtime security solutions signals a market shift toward detection and response capabilities designed for the complexities of modern, distributed application environments.
Practitioner Perspective
Executive and security leadership should note that vendor investment is increasingly focused on runtime controls capable of providing visibility and defense beyond perimeter and pre-execution checks. Organizations running cloud-native, containerized, or orchestrated workloads need detection resilience for live production environments where static and signature-based tools fall short. While funding announcements are not actionable on their own, they reflect buyer demand for solutions that adapt to dynamic application risk and runtime context. Security teams should evaluate if their current stack covers live workload monitoring and automated response, and where gaps may remain as attacks bypass static analysis. The key takeaway is that the ability to detect in-production anomalies is now a must-have, not a nice-to-have.
Recommended Actions – Inventory presence of runtime security tooling in cloud and containerized environments – Review incident postmortems for gaps between static/pre-production testing and runtime detection
Categories: Cybersecurity Blog, Cybersecurity News
Leave a Reply