Canadian Cyber Security Journal
SOCIAL:
Filed under: News

Cybersecurity Daily Brief — Tuesday, August 4, 2026

Here are today’s top cybersecurity stories for Tuesday, August 4, 2026.

Keyv-Linked npm Worm Poisons Hundreds of Packages, Plants Claude Code and VS Code Hooks
Attackers compromised the GitHub account of the keyv maintainer on August 4 and used it to inject a credential-stealing worm across the entire package family, including keyv (127 million weekly downloads), cacheable, flat-cache (565 million weekly downloads), and file-entry-cache (557 million weekly downloads). The worm spread to between 400 and 868 poisoned packages across nine unrelated organizations in roughly 30 minutes, reaching the full list in under two hours. The payload, a descendant of Mini Shai-Hulud, adds a preinstall hook that harvests .npmrc tokens, AWS credentials, GitHub CLI tokens, Kubernetes configs, and crypto wallets. The malicious release carried valid SLSA and OIDC provenance signatures generated through keyv’s own GitHub Actions workflow, making it appear fully legitimate to supply chain auditing tools. Attackers also modified VS Code and Claude Code repository configuration files so that merely opening a cloned repository triggers malicious code execution, widening the attack surface to developers who inspect source without running it. The Hacker News

INC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA1000 Flaws
Resecurity researchers report that INC Ransomware has become the leading threat actor exploiting CVE-2026-15409 (CVSS 10.0) and CVE-2026-15410 in SonicWall Secure Mobile Access 1000 series VPN appliances, with activity accelerating sharply since the start of August. The chained flaws let unauthenticated attackers open a WebSocket tunnel to restricted services and then escalate to root. Resecurity observed attackers extracting credentials, active session tokens, and TOTP seeds from compromised appliances, providing persistent access even after password resets. The group has claimed 885 victims to date; the most recent were listed on August 2. SonicWall patched both flaws on July 14, the same day they were added to the CISA KEV catalog. The Hacker News | SecurityWeek

cPanel CVE-2026-58048: Critical Flaw Lets Hosting Customers Run SQL as Database Root
cPanel patched CVE-2026-58048 (CVSS 9.4), a privilege escalation flaw in cPanel and WHM’s database management functionality that allows an authenticated account holder to execute arbitrary SQL commands in the database root context. The failure lies in cPanel’s database-renaming process, where the original SQL mode is not preserved during a rename operation, causing SQL to run with elevated privileges. WebPros warned that under certain database engine and feature configurations the vulnerability extends to operating system-level compromise on shared hosting servers, significantly increasing risk for multi-tenant deployments. All supported versions of cPanel and WHM are affected, as well as WP Squared. Patches are available in builds 11.110.0.137, 11.118.0.71, 11.126.0.78, 11.134.0.48, and 11.136.0.32. The Hacker News

US Water Cyberattacks Extend Beyond Minnesota to at Least Six Other States
FBI and EPA officials confirmed that the wave of cyberattacks on US municipal water systems that began with 30-plus Minnesota utilities late July has extended to water facilities in at least six additional states, including Michigan, South Dakota, and Georgia. Attackers gained remote access to internet-connected industrial control systems, altered network addresses and login credentials, and left some utilities temporarily unable to monitor operations. Iran-backed hackers are the leading suspect, consistent with prior IRGC use of default-password exploitation against water and wastewater operators in 2023. No states have reported disruption to water supply or treatment. SecurityWeek

macOS CUPS CVE-2026-39875: Public PoC Released for Root Privilege Escalation Without User Interaction
Security researcher Dallas Dubs published a proof-of-concept exploit for CVE-2026-39875, a macOS local privilege escalation vulnerability in Apple’s CUPS printing daemon. The exploit chains two logic flaws in cupsd’s printer registration and print-job handling: the daemon forwards a privileged Local authentication token to a malicious printer backend, which an attacker then replays to gain a root-level arbitrary file write. No user interaction is required beyond running as a local, unprivileged user. The vulnerability affects macOS Tahoe, Sequoia, and Sonoma releases prior to 26.6, 15.7.8, and 14.8.8, respectively, all of which Apple patched in July 2026. SANS Internet Storm Center

AI Developers Targeted via Trojanized GitHub Repositories Spreading ClickFix Infostealer
Netskope Threat Labs is tracking a campaign, dubbed TroysDen’s, in which attackers clone legitimate GitHub repositories for AI tools and developer frameworks, then embed a Windows infostealer delivered through a ClickFix lure on modified installation instructions. The malware uses XOR-encrypted traffic and hides its command-and-control address using EtherHiding, a technique that stores C2 addresses in blockchain smart contracts to resist takedown. The infrastructure uses two GitHub hosting accounts created five days apart in July 2026. The campaign targets developers in CI/CD pipelines and AI-focused projects, where access to cloud credentials and API keys is a primary objective. Help Net Security

Device Code Phishing Up 1,500% in 2026; Vishing Doubles as Identity Attacks Evolve
CrowdStrike data reported by Dark Reading shows device code phishing rose fifteen-fold in the first half of 2026 compared to the second half of 2025, while voice phishing doubled over the same period. Both techniques let attackers bypass multi-factor authentication by harvesting OAuth tokens or social-engineering victims rather than intercepting one-time codes. The spike in device code phishing coincides with the release of criminal toolkits and multiple phishing-as-a-service offerings that lower the technical barrier for adoption. The data underscores a broad shift among both state-sponsored actors and cybercriminal groups away from credential-based attacks toward session and token theft. Dark Reading

GeoVision GV-AS1620 Firmware Contains Hardcoded RSA Private Key Enabling HTTPS Traffic Decryption
MITRE disclosed CVE-2026-18754, a critical flaw in GeoVision GV-AS1620 access control panel firmware in which the Lighttpd web server uses an embedded, static RSA private key for TLS termination. Any party with knowledge of the key — which is identical across all affected devices — can decrypt HTTPS traffic to or from the panel and conduct server impersonation attacks against enrolled users and administrators. The GV-Cloud and AS-Manager firmware variants are both affected. No patch timeline has been publicly announced by GeoVision. MITRE CVE

Stay tuned for today’s in-depth analysis posts.

Enjoy this article? Don’t forget to share.