August 10 Threat Intelligence Update

0
1

Key Takeaways

  • North Carolina Ports experienced a cyberattack that forced manual operations and caused service delays, though the intrusion was contained.
  • Ryde disclosed a breach exposing 4.5 million Scandinavian customers’ personal data, but full payment card numbers and ride histories remained safe.
  • Coinkite reported a Coldcard firmware exploit that led to the theft of ≈1,367 BTC (~$88.6 M) from thousands of addresses; the company halted shipments, destroyed vulnerable inventory, and released patched firmware.
  • Beacon, a UK charity‑CRM provider, warned 1,500 nonprofits that an access‑key compromise may have exposed donation records and attachments, though payment data was not affected.
  • Researchers found five vulnerabilities in Cloudflare’s Code Mode (inherited from the workerd runtime) that could allow sandbox escape and cross‑tenant data exposure; two were rated Critical and patched.
  • Gemini CLI and Anthropic Claude Code were shown to leak automation environments and API keys via CVEs 2026‑12537 (CVSS 10.0) and 2026‑54316; both vendors issued fixes.
  • AI‑enabled identity‑fraud kits such as ProKYC automate KYC bypasses by generating forged documents, selfies, location data, and deep‑fake videos for banks, fintechs, and crypto exchanges.
  • Cisco released patches for multiple critical flaws in Catalyst SD‑WAN and IOS XE (CVSS up to 9.9) that could enable privilege escalation, code execution, or system compromise, plus additional fixes for other network‑management products.
  • WordPress 7.0.3 addressed CVE‑2026‑64638 (XSS2Shell), a high‑severity pre‑authentication XSS that could lead to remote code execution under certain conditions; backports were provided for supported branches back to 4.7.
  • TP‑Link fixed 15 vulnerabilities in its Omada provisioning ecosystem (controllers, devices, apps, VIGI cameras), including device impersonation, credential exposure, and RCE; 11 received CVEs and patched firmware is available.
  • A hard‑coded backdoor was discovered in at least 20 Zbtlink router models (sold as Wiflyer, ZBT, etc.), allowing unauthenticated root‑level commands via a hidden management component contacting vendor servers.
  • The Shai‑Hulud CHAINDROP campaign compromised the maintainer of the popular npm library keyv, backdooring >400 packages; malware uses a pre‑install hook to steal developer tokens and republish tainted packages, impacting ~1.3 billion monthly downloads.
  • Threat group UNC6671 targets large US financial firms with vishing calls that impersonate coworkers or IT staff, directing victims to spoofed sites to harvest passwords and MFA codes, then extorting ransoms of $750 k–$3 M.
  • A macOS ClickFix operation uses >250 look‑alike domains to distribute MacSync and Atomic Stealer malware, fingerprinting visitors before showing malicious instructions to evade automated scanners while infecting genuine Mac users.
  • Researchers uncovered a campaign that uploaded nearly 800 malicious npm packages delivering a cross‑platform RAT and infostealer; the WEL1DROPPER downloader retrieves payloads via Cloudflare Workers or DNS TXT records, establishes persistence, and deploys additional tools.

North Carolina Ports Cyberattack
The authority that manages the ports of Wilmington, Morehead City and several other North Carolina facilities suffered a cyber intrusion that forced affected systems onto manual processes. While officials say the breach has been contained, the degradation of IT services caused noticeable delays as teams worked to restore normal operations. The incident underscores the growing risk to critical maritime infrastructure and the need for resilient incident‑response plans that can maintain essential functions even when networks are compromised.

Ryde Data Breach
Electric‑scooter operator Ryde disclosed that attackers accessed the personal information of all 4.5 million customer accounts across Norway, Sweden, Finland, and Germany. Exposed data included phone numbers, email addresses, birth dates, partial payment‑card numbers, and payment histories. Importantly, full card numbers and detailed ride histories were not compromised. Ryde has notified affected users, recommended password changes, and is working with regulators to mitigate further risk and improve its data‑protection controls.

Coinkite Coldcard Theft Campaign
Coinkite, a Canadian maker of hardware Bitcoin wallets, revealed that a vulnerability in Coldcard firmware was actively exploited, resulting in the theft of approximately 1,367 BTC—valued at about $88.6 million—from thousands of addresses. Upon confirmation of the exploit, the company halted shipments of the affected units, destroyed vulnerable inventory, and released a patched firmware version. Users are urged to upgrade their devices immediately and to verify the integrity of any Coldcard hardware before use.

Beacon Charity CRM Breach
Beacon, a United Kingdom provider of customer‑relationship‑management software for charities, reported that an access‑key compromise may have allowed attackers to download database information, donation records, and stored attachments from roughly 1,500 nonprofit customers. Payment and bank details were not exposed. Beacon has advised its clients to rotate any shared credentials, monitor for unusual activity, and has implemented additional monitoring and key‑rotation mechanisms to prevent recurrence.

Cloudflare Code Mode Vulnerabilities
Check Point Research demonstrated that Cloudflare’s Code Mode—which lets AI agents write TypeScript against the Workers platform—inherited five security flaws from the underlying workerd runtime. The flaws could enable sandbox escape and cross‑tenant data exposure. Cloudflare rated two of the vulnerabilities as Critical and has patched its managed Workers environment; users are advised to ensure they are running the latest version and to review any custom Code Mode scripts for abnormal behavior.

Gemini CLI and Claude Code Exposures
Researchers disclosed separate vulnerabilities in Google’s Gemini CLI and Anthropic’s Claude Code that could leak automation environments and API keys. The Gemini CLI flaw (CVE‑2026‑12537) carries a CVSS score of 10.0, allowing unauthenticated code execution; the Claude Code issue (CVE‑2026‑54316) similarly permits key theft. Both vendors have released updated versions that address the flaws, and developers should upgrade immediately and audit any stored credentials for possible exposure.

AI‑Enabled Identity Fraud Kits
A new class of AI‑driven identity‑fraud kits, exemplified by the tool ProKYC, automates the bypass of know‑your‑customer (KYC) checks at banks, fintechs, and cryptocurrency exchanges. These kits can generate realistic forged identification documents, selfie‑with‑ID images, spoofed geolocation data, and synthetic video to defeat document verification, selfie matching, and liveness detection. Organizations are urged to adopt multi‑layered verification—including device fingerprinting, behavioral analytics, and out‑of‑band confirmation—to counter such sophisticated attacks.

Cisco Catalyst SD‑WAN and IOS XE Patches
Cisco issued security updates for multiple critical vulnerabilities affecting its Catalyst SD‑WAN and IOS XE platforms. The highest‑severity flaws carry CVSS scores up to 9.9 and could permit privilege escalation, arbitrary code execution, or full system compromise. In addition, Cisco patched several high‑ and medium‑severity issues across other network‑management products. Administrators should apply the updates promptly and review configuration hardening guides to reduce attack surface.

WordPress 7.0.3 Security Update
WordPress released version 7.0.3 to fix CVE‑2026‑64638, dubbed XSS2Shell, a high‑severity pre‑authentication cross‑site‑scripting vulnerability that can, under certain conditions, lead to remote code execution. The flaw stemmed from improper handling of failed login attempts. The patch is also backported to supported branches dating back to WordPress 4.7. Site owners are urged to upgrade immediately and to enforce strong password policies and regular plugin/theme audits.

TP‑Link Omada Provisioning Flaws
TP‑Link addressed 15 vulnerabilities within its Omada provisioning ecosystem, which spans controllers, network devices, mobile apps, and VIGI cameras. The flaws include device impersonation, credential exposure, and remote‑code‑execution risks during the provisioning process. Eleven of the issues received CVE identifiers, and patched firmware has been made available for all affected products. Users should update their Omada controllers and associated devices to the latest firmware and review network segmentation to limit lateral movement.

Zbtlink Router Backdoor
Security researchers identified a vendor‑installed backdoor present in at least 20 router models sold under brands such as Wiflyer and ZBT. The backdoor resides in a remote‑management component that contacts hard‑coded servers and accepts unauthenticated commands with root privileges. By impersonating the vendor server, analysts were able to obtain a root shell on the devices. Affected users should replace the firmware with a clean version from a trusted source or discard the hardware, and disable any remote‑management features unless absolutely necessary.

Shai‑Hulud CHAINDROP Supply‑Chain Attack
The Shai‑Hulud CHAINDROP campaign compromised the maintainer of the widely used npm library keyv, enabling attackers to backdoor more than 400 downstream packages. The malware executes via a pre‑install hook, steals developer authentication tokens, and republishes tainted versions, thereby propagating through the npm ecosystem that sees roughly 1.3 billion monthly downloads. Developers are advised to lock dependencies, monitor for unexpected changes in package scripts, and employ software‑bill‑of‑materials (SBOM) tools to detect malicious updates.

UNC6671 Financial Firm Social‑Engineering Campaign
Threat group UNC6671 has been targeting large US financial institutions with voice‑phishing (vishing) calls that impersonate coworkers or IT support staff. Victims are lured to spoofed websites where they enter passwords and multi‑factor authentication codes, which the attackers then harvest. After credential theft, the group threatens data leaks and issues ransom demands ranging from $750 k to $3 million. Organizations should enforce strict call‑verification procedures, educate staff about social‑engineering tactics, and deploy phishing‑resistant MFA wherever possible.

macOS ClickFix Campaign with Look‑Alike Domains
A macOS‑focused ClickFix operation leverages more than 250 look‑alike domains to distribute MacSync and Atomic Stealer malware. The campaign first fingerprints visitors to ensure they are genuine macOS users before presenting malicious instructions, thereby evading automated security scanners and analysis systems. Once executed, the stealers harvest credentials, browser data, and cryptocurrency wallets. Users should avoid downloading software from unverified sources, keep Gatekeeper enabled, and regularly audit installed applications for signs of tampering.

Malicious npm Packages Delivering Cross‑Platform RAT
Researchers uncovered a campaign that uploaded nearly 800 malicious npm packages designed to deliver a cross‑platform remote‑access trojan (RAT) and infostealer. The packages rely on a WEL1DROPPER downloader that, once imported, retrieves payloads via Cloudflare Workers or DNS TXT records, establishes persistence on the host, and deploys additional malicious tools. Developers should scrutinize third‑party packages, enable integrity checks (e.g., npm audit, lockfiles), and consider using provenance verification to prevent supply‑chain compromise.

SignUpSignUp form

LEAVE A REPLY

Please enter your comment!
Please enter your name here