Daily Security Intel

Archives
Log in
Subscribe
August 6, 2026

[SecurityIntel] 06 Aug | CISA Warns of Exploited Langflow and Tomcat Flaws

SECURITYINTEL DAILY BRIEF

■ ThreatIntel Brief

Thursday, August 06, 2026

INTEL CONFIDENCE  100%

THREAT LEVEL

CRITICAL

THREAT OF THE DAY

CISA Warns of Exploited Langflow and Tomcat Flaws

CRITICAL

5

C2 IPs

120

OTX IOCs

37

ARTICLES

■ ANALYST TLDR

Today's intelligence landscape highlights critical vulnerabilities being actively exploited in the wild, including flaws in IBM Langflow, N-able N-central, and Apache Tomcat, prompting urgent CISA warnings. Additionally, threat actors are leveraging sophisticated tactics such as the "ClickFix" macOS campaign using browser fingerprinting to deliver malware, and "Pass-ta-key" attacks targeting Google's synchronized passkeys. Furthermore, supply chain and infrastructure threats persist with the discovery of the keyv/cacheable npm worm and ongoing cyberattacks on US water systems linked to Iranian actors.

■ CRITICAL STORIES

INFO#1

CISA Warns of Exploited Langflow, N-central, and Tomcat Vulnerabilities

CISA has added vulnerabilities in IBM Langflow, N-central, and Apache Tomcat to its Known Exploited Vulnerabilities (KEV) catalog, giving federal agencies only three days to patch. These flaws allow for remote code execution and authentication bypass, representing an immediate threat to enterprise infrastructure.

INFO#2

Over 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Lures

A highly sophisticated macOS ClickFix campaign is using browser fingerprinting to selectively serve infostealer malware only to valid targets. This technique allows threat actors to evade automated security scanners and sandbox environments, making detection significantly more difficult.

CRITICAL#3

Veeam, Terraform MCP, Django Patch Critical Flaws, Led by CVSS 10.0 Cross-Tenant Bug

Critical security patches have been released for Veeam Service Provider Console, Terraform MCP Server, and Django, addressing severe vulnerabilities including a CVSS 10.0 unauthenticated cross-tenant access bug in Veeam's console. Organizations must apply these updates immediately to prevent full administrative takeover.

INFO#4

New Attack Methods Enable Malware to Hijack Passkey-Protected Accounts

Palo Alto Networks researchers disclosed "Pass-ta-key" attacks capable of stealing master keys from Google's synchronized passkey implementation. This demonstrates that even passwordless authentication mechanisms remain vulnerable to local credential theft by infostealer malware.

■ CVEs IDENTIFIED

[CVE-TBD]

IBM Langflow — Remote Code Execution

Critical

[CVE-TBD]

N-able N-central — Authentication Bypass

Critical

[CVE-TBD]

Apache Tomcat — EncryptInterceptor Bypass / Remote Code Execution

High

[CVE-TBD]

Veeam Service Provider Console — Unauthenticated Cross-Tenant Access (CVSS 10.0)

Critical

■ THREAT ACTORS

Salt Typhoon

APT

Chinese state-sponsored group maintaining a deep presence in US telecommunications infrastructure.

Poipet Scam Network

Cybercrime

Cambodia-based scam operation utilizing ChatGPT to facilitate romance, investment, and law enforcement impersonation fraud.

Ransom Cartel

Cybercrime

Ransomware group whose creator, Maksim Silnikau, was sentenced to 16 years in prison for attacking 18 companies.

■ ATT&CK TTPs

T1190
Exploit Public-Facing Application | Hackers exploited SQL injection in Oracle database to run khunt toolkit; also used to exploit Langflow and Tomcat.
T1204.001
User Execution: Malicious Link | ClickFix campaign using browser-fingerprinted domains to lure macOS users into downloading malware.
T1195.002
Compromise Software Supply Chain | Trojanized npm packages (keyv/cacheable worm) executing on build hosts.
T1566
Phishing | Kali365 using Microsoft device code phishing; COLDCARD phishing campaign distributing ScreenConnect RAT.
T1068
Exploitation for Privilege Escalation | OVSwrap flaw in Linux Open vSwitch datapath used by local users to gain root.
T1555
Credentials from Password Stores | "Pass-ta-key" attacks targeting Google synced passkeys to hijack accounts.

■ PATCH PRIORITY

[P1 PATCH NOW]≤24h

Veeam — Unauthenticated cross-tenant access flaw (CVSS 10.0) in Service Provider Console — [THN]

[P1 PATCH NOW]≤24h

IBM — Actively exploited Langflow RCE vulnerability — [BC]

[P1 PATCH NOW]≤24h

N-able — Actively exploited N-central authentication bypass vulnerability — [BC]

[P1 PATCH NOW]≤24h

Apache — Actively exploited Tomcat EncryptInterceptor bypass / RCE vulnerability — [BC]

■ RECOMMENDED ACTIONS TODAY

1[P1] Patch the actively exploited vulnerabilities in IBM Langflow, N-able N-central, and Apache Tomcat immediately following the CISA KEV warning.
2[P1] Apply critical security updates released for Veeam Service Provider Console to mitigate the CVSS 10.0 unauthenticated cross-tenant access vulnerability.
3[P1] Update HashiCorp Terraform MCP Server and Django installations to their latest patched versions to resolve critical remote execution and bypass flaws.
4[P2] Audit Linux environments utilizing Open vSwitch and apply kernel patches for the OVSwrap local privilege escalation flaw.
5[P2] Implement technique-based browser detection and block device-code phishing flows (e.g., Kali365) to prevent unauthorized Microsoft session hijacking.
LIVE IOC FEED

C2 IP BLOCKLIST  ·  AbuseCH Feodo  ·  Showing 5 of 5

IP ADDRESS

162.243.103.246

PORT

8080

STATUS

OFFLINE

MALWARE

Emotet

COUNTRY

US

IP ADDRESS

50.16.16.211

PORT

443

STATUS

ONLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

34.204.119.63

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

178.62.3.223

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

GB

IP ADDRESS

27.133.154.218

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

JP

FULL IOC EXPORT — GOOGLE SHEET

All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs
Updated daily · Export as CSV to import directly into your tools

■  Open Full IOC Sheet  →

IOC SOURCES: AbuseCH Feodo  ·  AlienVault OTX
NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB

Don't miss what's next. Subscribe to Daily Security Intel:
← Newer [SecurityIntel] 07 Aug | Active Exploitation of Critical JetBrains TeamCity Vulnerability Older → [SecurityIntel] 05 Aug | ChainDrop Self-Propagating NPM Supply Chain Worm
Powered by Buttondown, the easiest way to start and grow your newsletter.