SECURITYINTEL DAILY BRIEF ■ ThreatIntel BriefThursday, August 06, 2026 INTEL CONFIDENCE 100% | THREAT LEVEL CRITICAL |
|
THREAT OF THE DAY CISA Warns of Exploited Langflow and Tomcat Flaws | CRITICAL |
|
5 C2 IPs | 120 OTX IOCs | 37 ARTICLES |
|
■ ANALYST TLDR Today's intelligence landscape highlights critical vulnerabilities being actively exploited in the wild, including flaws in IBM Langflow, N-able N-central, and Apache Tomcat, prompting urgent CISA warnings. Additionally, threat actors are leveraging sophisticated tactics such as the "ClickFix" macOS campaign using browser fingerprinting to deliver malware, and "Pass-ta-key" attacks targeting Google's synchronized passkeys. Furthermore, supply chain and infrastructure threats persist with the discovery of the keyv/cacheable npm worm and ongoing cyberattacks on US water systems linked to Iranian actors. |
|
■ CRITICAL STORIES CISA Warns of Exploited Langflow, N-central, and Tomcat Vulnerabilities CISA has added vulnerabilities in IBM Langflow, N-central, and Apache Tomcat to its Known Exploited Vulnerabilities (KEV) catalog, giving federal agencies only three days to patch. These flaws allow for remote code execution and authentication bypass, representing an immediate threat to enterprise infrastructure. |
Over 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Lures A highly sophisticated macOS ClickFix campaign is using browser fingerprinting to selectively serve infostealer malware only to valid targets. This technique allows threat actors to evade automated security scanners and sandbox environments, making detection significantly more difficult. |
Veeam, Terraform MCP, Django Patch Critical Flaws, Led by CVSS 10.0 Cross-Tenant Bug Critical security patches have been released for Veeam Service Provider Console, Terraform MCP Server, and Django, addressing severe vulnerabilities including a CVSS 10.0 unauthenticated cross-tenant access bug in Veeam's console. Organizations must apply these updates immediately to prevent full administrative takeover. |
New Attack Methods Enable Malware to Hijack Passkey-Protected Accounts Palo Alto Networks researchers disclosed "Pass-ta-key" attacks capable of stealing master keys from Google's synchronized passkey implementation. This demonstrates that even passwordless authentication mechanisms remain vulnerable to local credential theft by infostealer malware. |
|
■ CVEs IDENTIFIED [CVE-TBD] IBM Langflow — Remote Code Execution |
[CVE-TBD] N-able N-central — Authentication Bypass |
[CVE-TBD] Apache Tomcat — EncryptInterceptor Bypass / Remote Code Execution |
[CVE-TBD] Veeam Service Provider Console — Unauthenticated Cross-Tenant Access (CVSS 10.0) |
|
■ THREAT ACTORS Chinese state-sponsored group maintaining a deep presence in US telecommunications infrastructure. |
Poipet Scam Network | Cybercrime |
Cambodia-based scam operation utilizing ChatGPT to facilitate romance, investment, and law enforcement impersonation fraud. |
Ransomware group whose creator, Maksim Silnikau, was sentenced to 16 years in prison for attacking 18 companies. |
|
|
|
■ ATT&CK TTPs | T1190 | | Exploit Public-Facing Application | Hackers exploited SQL injection in Oracle database to run khunt toolkit; also used to exploit Langflow and Tomcat. |
| T1204.001 | | User Execution: Malicious Link | ClickFix campaign using browser-fingerprinted domains to lure macOS users into downloading malware. |
| T1195.002 | | Compromise Software Supply Chain | Trojanized npm packages (keyv/cacheable worm) executing on build hosts. |
| T1566 | | Phishing | Kali365 using Microsoft device code phishing; COLDCARD phishing campaign distributing ScreenConnect RAT. |
| T1068 | | Exploitation for Privilege Escalation | OVSwrap flaw in Linux Open vSwitch datapath used by local users to gain root. |
| T1555 | | Credentials from Password Stores | "Pass-ta-key" attacks targeting Google synced passkeys to hijack accounts. |
|
■ PATCH PRIORITY Veeam — Unauthenticated cross-tenant access flaw (CVSS 10.0) in Service Provider Console — [THN] |
IBM — Actively exploited Langflow RCE vulnerability — [BC] |
N-able — Actively exploited N-central authentication bypass vulnerability — [BC] |
Apache — Actively exploited Tomcat EncryptInterceptor bypass / RCE vulnerability — [BC] |
|
|
|
■ RECOMMENDED ACTIONS TODAY | 1 | [P1] Patch the actively exploited vulnerabilities in IBM Langflow, N-able N-central, and Apache Tomcat immediately following the CISA KEV warning. |
| 2 | [P1] Apply critical security updates released for Veeam Service Provider Console to mitigate the CVSS 10.0 unauthenticated cross-tenant access vulnerability. |
| 3 | [P1] Update HashiCorp Terraform MCP Server and Django installations to their latest patched versions to resolve critical remote execution and bypass flaws. |
| 4 | [P2] Audit Linux environments utilizing Open vSwitch and apply kernel patches for the OVSwrap local privilege escalation flaw. |
| 5 | [P2] Implement technique-based browser detection and block device-code phishing flows (e.g., Kali365) to prevent unauthorized Microsoft session hijacking. |
|
|
|
C2 IP BLOCKLIST · AbuseCH Feodo · Showing 5 of 5 IP ADDRESS 162.243.103.246 | PORT 8080 | STATUS OFFLINE | MALWARE Emotet | COUNTRY US |
IP ADDRESS 50.16.16.211 | PORT 443 | STATUS ONLINE | MALWARE QakBot | COUNTRY US |
IP ADDRESS 34.204.119.63 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY US |
IP ADDRESS 178.62.3.223 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY GB |
IP ADDRESS 27.133.154.218 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY JP |
|
FULL IOC EXPORT — GOOGLE SHEET All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs Updated daily · Export as CSV to import directly into your tools ■ Open Full IOC Sheet → |
|
IOC SOURCES: AbuseCH Feodo · AlienVault OTX NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB |