SECURITYINTEL DAILY BRIEF ■ ThreatIntel BriefTuesday, August 11, 2026 INTEL CONFIDENCE 100% | THREAT LEVEL CRITICAL |
|
THREAT OF THE DAY Private APN pivot breaches Polish energy sector networks | CRITICAL |
|
5 C2 IPs | 97 OTX IOCs | 40 ARTICLES |
|
■ ANALYST TLDR Today's threat landscape is highlighted by active exploitation of critical vulnerabilities in Progress LoadMaster, Metabase, and SonicWall SMA1000 appliances by ransomware and advanced threat actors. Additionally, novel attack vectors have emerged, including the first documented use of private APNs to pivot into Polish energy sector OT networks, and supply-chain compromises affecting WordPress plugins (BdThemes) and developer environments (Solidity Pro VS Code extension). Meanwhile, OpenAI has paused internal activities for its upcoming Astra model due to its advanced autonomous cyberattack capabilities. |
|
■ CRITICAL STORIES Novel Private APN Pivot Let Hackers Sabotage Second Polish Energy Facility This marks the first documented instance of threat actors leveraging a private Access Point Name (APN) to breach and sabotage operational technology (OT) networks in critical infrastructure, bypassing traditional perimeter security. |
CISA: SonicWall SMA1000 flaws now exploited by ransomware gangs Ransomware operators are actively exploiting recently patched SonicWall SMA1000 vulnerabilities, including a maximum-severity SSRF flaw, emphasizing the urgent need for immediate edge-device patching. |
Metabase Patches Vulnerability Exploited as Zero-Day A critical zero-day vulnerability in the Metabase business intelligence platform allows unauthenticated remote attackers to gain full administrative access, leading to immediate data exposure and potential server compromise. |
Solidity Pro VS Code Extensions Steal Crypto Wallets, API Keys, and Credentials Threat actors are targeting developers via a malicious Visual Studio Code extension ("solidity-pro") that exfiltrates browser wallets, API keys, and credentials, representing a highly targeted supply-chain risk. |
|
■ CVEs IDENTIFIED [CVE-TBD] Progress LoadMaster Critical | Unauthenticated remote command execution |
|
[CVE-TBD] Metabase Critical | Unauthenticated remote administrative access zero-day |
|
[CVE-TBD] SonicWall SMA1000 Critical | Server-Side Request Forgery (SSRF) and other flaws exploited by ransomware |
|
[CVE-TBD] Cisco ClamAV High | Denial of Service (DoS) vulnerability with public PoC |
|
|
■ THREAT ACTORS Leveraging Polygon blockchain smart contracts for decentralized C2. |
Targeting critical infrastructure via firewall vulnerabilities. |
Storm-1175 | Financially motivated threat actor (China-linked) |
Deploying StormEncryptor ransomware via N-central flaws. |
|
|
|
■ ATT&CK TTPs | T1190 | | Exploit Public-Facing Application | Exploitation of SonicWall SMA1000, Progress LoadMaster, Metabase, and TrueConf Server. |
| T1195.002 | | Supply Chain Compromise: Compromise Software Dependencies and Development Tools | BdThemes plugin supply-chain compromise and Solidity Pro VS Code extension. |
| T1584.005 | | Compromise Infrastructure: Botnet | Aeternum botnet using Polygon blockchain smart contracts for decentralized C2. |
| T1071.001 | | Application Layer Protocol: Web Protocols | C2 communication over web/blockchain APIs. |
| T1204.002 | | User Execution: Malicious File | Ukrainian IT workers targeted with fake recruiter files. |
| T1588.002 | | Obtain Capabilities: Tool | Kimsuky building offline AI stacks for automated phishing. |
|
■ PATCH PRIORITY Progress — LoadMaster — Unauthenticated remote command execution [CVE-TBD] — CISA / SW |
Metabase — Metabase — Unauthenticated remote administrative access zero-day [CVE-TBD] — SW / THN |
SonicWall — SMA1000 — SSRF and other flaws exploited by ransomware [CVE-TBD] — CISA / BC |
Cisco — ClamAV — Denial of Service (DoS) vulnerability with public PoC [CVE-TBD] — SW |
|
|
|
■ RECOMMENDED ACTIONS TODAY | 1 | [P1] Patch the critical Progress LoadMaster remote command execution vulnerability [CVE-TBD] immediately to prevent active exploitation. |
| 2 | [P1] Apply the security update for Metabase [CVE-TBD] to address the zero-day vulnerability allowing unauthenticated remote administrative access. |
| 3 | [P1] Update SonicWall SMA1000 appliances to remediate [CVE-TBD] (SSRF and other flaws) currently exploited by ransomware gangs. |
| 4 | [P2] Audit and uninstall the malicious "solidity-pro" Visual Studio Code extension from developer environments to prevent credential and crypto wallet theft. |
| 5 | [P2] Update TrueConf Server to the latest version to mitigate [CVE-TBD] exploited by Head Mare to distribute PhantomCore. |
|
|
|
C2 IP BLOCKLIST · AbuseCH Feodo · Showing 5 of 5 IP ADDRESS 162.243.103.246 | PORT 8080 | STATUS OFFLINE | MALWARE Emotet | COUNTRY US |
IP ADDRESS 50.16.16.211 | PORT 443 | STATUS ONLINE | MALWARE QakBot | COUNTRY US |
IP ADDRESS 34.204.119.63 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY US |
IP ADDRESS 178.62.3.223 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY GB |
IP ADDRESS 27.133.154.218 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY JP |
|
FULL IOC EXPORT — GOOGLE SHEET All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs Updated daily · Export as CSV to import directly into your tools ■ Open Full IOC Sheet → |
|
IOC SOURCES: AbuseCH Feodo · AlienVault OTX NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB |