Daily Security Intel

Archives
Log in
Subscribe
August 11, 2026

[SecurityIntel] 11 Aug | Private APN pivot breaches Polish energy sector networks

SECURITYINTEL DAILY BRIEF

■ ThreatIntel Brief

Tuesday, August 11, 2026

INTEL CONFIDENCE  100%

THREAT LEVEL

CRITICAL

THREAT OF THE DAY

Private APN pivot breaches Polish energy sector networks

CRITICAL

5

C2 IPs

97

OTX IOCs

40

ARTICLES

■ ANALYST TLDR

Today's threat landscape is highlighted by active exploitation of critical vulnerabilities in Progress LoadMaster, Metabase, and SonicWall SMA1000 appliances by ransomware and advanced threat actors. Additionally, novel attack vectors have emerged, including the first documented use of private APNs to pivot into Polish energy sector OT networks, and supply-chain compromises affecting WordPress plugins (BdThemes) and developer environments (Solidity Pro VS Code extension). Meanwhile, OpenAI has paused internal activities for its upcoming Astra model due to its advanced autonomous cyberattack capabilities.

■ CRITICAL STORIES

INFO#1

Novel Private APN Pivot Let Hackers Sabotage Second Polish Energy Facility

This marks the first documented instance of threat actors leveraging a private Access Point Name (APN) to breach and sabotage operational technology (OT) networks in critical infrastructure, bypassing traditional perimeter security.

INFO#2

CISA: SonicWall SMA1000 flaws now exploited by ransomware gangs

Ransomware operators are actively exploiting recently patched SonicWall SMA1000 vulnerabilities, including a maximum-severity SSRF flaw, emphasizing the urgent need for immediate edge-device patching.

INFO#3

Metabase Patches Vulnerability Exploited as Zero-Day

A critical zero-day vulnerability in the Metabase business intelligence platform allows unauthenticated remote attackers to gain full administrative access, leading to immediate data exposure and potential server compromise.

INFO#4

Solidity Pro VS Code Extensions Steal Crypto Wallets, API Keys, and Credentials

Threat actors are targeting developers via a malicious Visual Studio Code extension ("solidity-pro") that exfiltrates browser wallets, API keys, and credentials, representing a highly targeted supply-chain risk.

■ CVEs IDENTIFIED

[CVE-TBD] Progress LoadMaster

Critical

Unauthenticated remote command execution

[CVE-TBD] Metabase

Critical

Unauthenticated remote administrative access zero-day

[CVE-TBD] SonicWall SMA1000

Critical

Server-Side Request Forgery (SSRF) and other flaws exploited by ransomware

[CVE-TBD] Cisco ClamAV

High

Denial of Service (DoS) vulnerability with public PoC

■ THREAT ACTORS

Aeternum

Botnet operator

Leveraging Polygon blockchain smart contracts for decentralized C2.

Gunra

Ransomware gang

Targeting critical infrastructure via firewall vulnerabilities.

Storm-1175

Financially motivated threat actor (China-linked)

Deploying StormEncryptor ransomware via N-central flaws.

■ ATT&CK TTPs

T1190
Exploit Public-Facing Application | Exploitation of SonicWall SMA1000, Progress LoadMaster, Metabase, and TrueConf Server.
T1195.002
Supply Chain Compromise: Compromise Software Dependencies and Development Tools | BdThemes plugin supply-chain compromise and Solidity Pro VS Code extension.
T1584.005
Compromise Infrastructure: Botnet | Aeternum botnet using Polygon blockchain smart contracts for decentralized C2.
T1071.001
Application Layer Protocol: Web Protocols | C2 communication over web/blockchain APIs.
T1204.002
User Execution: Malicious File | Ukrainian IT workers targeted with fake recruiter files.
T1588.002
Obtain Capabilities: Tool | Kimsuky building offline AI stacks for automated phishing.

■ PATCH PRIORITY

[P1 PATCH NOW]≤24h

Progress — LoadMaster — Unauthenticated remote command execution [CVE-TBD] — CISA / SW

[P1 PATCH NOW]≤24h

Metabase — Metabase — Unauthenticated remote administrative access zero-day [CVE-TBD] — SW / THN

[P1 PATCH NOW]≤24h

SonicWall — SMA1000 — SSRF and other flaws exploited by ransomware [CVE-TBD] — CISA / BC

[P2 PATCH NOW]≤72h

Cisco — ClamAV — Denial of Service (DoS) vulnerability with public PoC [CVE-TBD] — SW

■ RECOMMENDED ACTIONS TODAY

1[P1] Patch the critical Progress LoadMaster remote command execution vulnerability [CVE-TBD] immediately to prevent active exploitation.
2[P1] Apply the security update for Metabase [CVE-TBD] to address the zero-day vulnerability allowing unauthenticated remote administrative access.
3[P1] Update SonicWall SMA1000 appliances to remediate [CVE-TBD] (SSRF and other flaws) currently exploited by ransomware gangs.
4[P2] Audit and uninstall the malicious "solidity-pro" Visual Studio Code extension from developer environments to prevent credential and crypto wallet theft.
5[P2] Update TrueConf Server to the latest version to mitigate [CVE-TBD] exploited by Head Mare to distribute PhantomCore.
LIVE IOC FEED

C2 IP BLOCKLIST  ·  AbuseCH Feodo  ·  Showing 5 of 5

IP ADDRESS

162.243.103.246

PORT

8080

STATUS

OFFLINE

MALWARE

Emotet

COUNTRY

US

IP ADDRESS

50.16.16.211

PORT

443

STATUS

ONLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

34.204.119.63

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

178.62.3.223

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

GB

IP ADDRESS

27.133.154.218

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

JP

FULL IOC EXPORT — GOOGLE SHEET

All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs
Updated daily · Export as CSV to import directly into your tools

■  Open Full IOC Sheet  →

IOC SOURCES: AbuseCH Feodo  ·  AlienVault OTX
NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB

Don't miss what's next. Subscribe to Daily Security Intel:
← Newer [SecurityIntel] 12 Aug | Active Zero-Day and SharePoint RCE Patched Older → [SecurityIntel] 10 Aug | Active Scanning Targets Ivanti Connect Secure Gateways
Powered by Buttondown, the easiest way to start and grow your newsletter.