SECURITYINTEL DAILY BRIEF ■ ThreatIntel BriefTuesday, August 04, 2026 INTEL CONFIDENCE 100% | THREAT LEVEL CRITICAL |
|
THREAT OF THE DAY Midnight Blizzard Hijacks Hotel Wi-Fi Networks Globally | CRITICAL |
|
5 C2 IPs | 11 OTX IOCs | 33 ARTICLES |
|
■ ANALYST TLDR Active exploitation of an authentication bypass vulnerability (CVE-2026-18577) in N-able N-central servers and vulnerabilities in SonicWall SMA 1000 series VPN appliances highlights the severe risk to enterprise perimeters. Concurrently, Russian state-sponsored group Midnight Blizzard is targeting global hotel Wi-Fi networks to compromise Microsoft 365 accounts, while novel "Pass-ta-key" techniques exploit Google Password Manager to bypass passkey-based MFA. Organizations must prioritize patching edge appliances and enforcing secure remote access policies for traveling staff. |
|
■ CRITICAL STORIES N-able warns of N-central auth bypass flaw exploited in attacks Threat actors are actively exploiting CVE-2026-18577, an authentication bypass vulnerability affecting both hosted and on-premises N-central servers, after bypassing a previous patch attempt. This allows attackers to gain unauthorized administrative access to managed service provider (MSP) environments. |
Hotel Wi-Fi attacks use custom malware to breach Microsoft 365 accounts Russian state-sponsored threat actor Midnight Blizzard (APT29) is compromising hotel Wi-Fi networks globally to target high-profile travelers, deploying custom malware to harvest credentials and hijack Microsoft 365 accounts. |
Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts Security researchers have disclosed "Pass-ta-key" attacks where malware running on compromised Windows devices can abuse Google Password Manager's synced passkeys. By exploiting relying parties' failure to validate the "User Verified" flag, attackers bypass MFA without triggering any user prompts. |
INC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 Flaws INC Ransomware has become the primary threat actor actively exploiting recently disclosed security vulnerabilities in SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances to breach corporate networks and deploy ransomware. |
|
■ CVEs IDENTIFIED CVE-2026-18577 N-able N-central Server — Authentication Bypass |
[CVE-TBD] SonicWall Secure Mobile Access (SMA) 1000 Series — Security Bypass / Remote Code Execution (exploited by INC Ransomware) |
[CVE-TBD] Google Password Manager (Chrome) — Passkey Hijacking / Authentication Bypass |
[CVE-TBD] Thermo Fisher Applied Biosystems Human Identification Software — DNA File Tampering / Data Integrity Bypass |
|
■ THREAT ACTORS Midnight Blizzard (APT29) | Nation-State (Russia) |
Compromising hotel Wi-Fi networks globally to steal credentials and hijack Microsoft 365 accounts. |
INC Ransomware | Cybercrime / Ransomware |
Actively exploiting SonicWall SMA 1000 series VPN vulnerabilities to gain initial access. |
ExfilSquad | Cybercrime / Hacktivism |
Leaked contact data of over 100,000 UK police officers and staff from the Police National Legal Database (PNLD). |
|
|
|
■ ATT&CK TTPs | T1133 | | External Remote Services | INC Ransomware exploiting SonicWall SMA 1000 VPNs. |
| T1556 | | Modify Authentication Process | Google Password Manager passkey bypass ("Pass-ta-key") neglecting User Verified flags. |
| T1557.002 | | Adversary-in-the-Middle: Wi-Fi Spoofing | Midnight Blizzard hijacking hotel Wi-Fi networks to intercept traffic and steal M365 credentials. |
| T1195.002 | | Supply Chain Compromise: Malicious Software Dependency | 18 malicious npm packages targeting Alibaba developer tools. |
| T1027.011 | | Obfuscated Files or Information: Steganography | DOUBLECUP ClickFix service hiding malicious code in browser-cached PNG images. |
| T1204.002 | | User Execution: Malicious File | Fake Roblox Xeno script launchers executing infostealers on victim machines. |
|
■ PATCH PRIORITY N-able N-central Server — Authentication bypass vulnerability (CVE-2026-18577) actively exploited in the wild due to patch bypass — BleepingComputer |
SonicWall Secure Mobile Access (SMA) 1000 Series — Actively exploited by INC Ransomware to compromise networks — The Hacker News |
Thermo Fisher Applied Biosystems Human Identification Software — Flaw allows nearly undetectable DNA file tampering before analysis — The Hacker News |
Google Password Manager / Chrome — Passkey extraction and MFA bypass vulnerability ("Pass-ta-key") — Unit 42 |
|
|
|
■ RECOMMENDED ACTIONS TODAY | 1 | [P1] Immediately apply the latest security patches for N-able N-central (CVE-2026-18577) to prevent active authentication bypass exploitation. |
| 2 | [P1] Patch all SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances immediately to mitigate active exploitation by the INC Ransomware group. |
| 3 | [P2] Implement strict validation of the "User Verified" flag for passkey authentications on all relying party applications to block "Pass-ta-key" bypass techniques. |
| 4 | [P2] Apply the July 31 security update from Thermo Fisher Scientific for Applied Biosystems human identification software to prevent unauthorized DNA file tampering. |
| 5 | [P2] Enforce corporate VPN usage and multi-factor authentication (MFA) for all employees traveling and utilizing untrusted hotel Wi-Fi networks to counter Midnight Blizzard campaigns. |
|
|
|
C2 IP BLOCKLIST · AbuseCH Feodo · Showing 5 of 5 IP ADDRESS 162.243.103.246 | PORT 8080 | STATUS OFFLINE | MALWARE Emotet | COUNTRY US |
IP ADDRESS 50.16.16.211 | PORT 443 | STATUS ONLINE | MALWARE QakBot | COUNTRY US |
IP ADDRESS 34.204.119.63 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY US |
IP ADDRESS 178.62.3.223 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY GB |
IP ADDRESS 27.133.154.218 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY JP |
|
FULL IOC EXPORT — GOOGLE SHEET All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs Updated daily · Export as CSV to import directly into your tools ■ Open Full IOC Sheet → |
|
IOC SOURCES: AbuseCH Feodo · AlienVault OTX NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB |