Canadian Cyber Security Journal
SOCIAL:
Filed under: News

Cybersecurity Daily Brief — Monday, August 3, 2026

Here are today’s top cybersecurity stories for Monday, August 3, 2026.

N-able N-central CVE-2026-18577 Auth Bypass Actively Exploited, CloudFlare Tunnels Used for Persistence
Attackers bypassed N-able’s patch for CVE-2026-18556 and are now exploiting a new authentication bypass tracked as CVE-2026-18577, gaining admin-level access to N-central remote monitoring and management servers. Following compromise, threat actors activated the Take Control feature, connected to managed endpoints, and registered CloudFlare tunnels to maintain persistent access after N-central access was revoked. N-able released hotfix 2026.3.1.7; cybersecurity firm Huntress confirmed active exploitation with many organizations still unpatched as of August 3. BleepingComputer

PNLD Breach Exposes 114,000 UK Police Officers’ Data on Dark Web
The Police National Legal Database confirmed that contact information for approximately 114,000 police officers and staff — including names, organisations, and work email addresses — was published on the dark web by the ExfilSquad cybercriminal syndicate. The breach extends beyond PNLD to include data from the Ministry of Defence, the Home Office, the National Crime Agency, and the Crown Prosecution Service. PNLD had not disclosed when the intrusion began or how long access lasted as of August 3. The Hacker News

Thermo Fisher Patches DNA File Tampering Flaw CVE-2026-17583 Undetectable Since 1995
Thermo Fisher Scientific patched CVE-2026-17583 (CVSS 8.2), a vulnerability in Applied Biosystems DNA analysis software that allowed attackers to alter DNA data files in ways nearly undetectable during analysis. Researchers told The Wall Street Journal the flaw likely existed in crime-lab machines since 1995 and prior tampering, if it occurred, would be difficult to detect retroactively. Five supported product lines received digital signature updates; three end-of-life products will not receive patches. The Hacker News

Unit 42: Three Windows Malware Paths Bypass Google Password Manager Passkeys
Palo Alto Networks Unit 42 published research detailing three attack paths — Pass-ta-key, Silver Pass-ta-key, and Golden Pass-ta-key — that allow malware running as an ordinary Windows user to silently authenticate to passkey-protected accounts without fingerprint or PIN input. The most severe path extracts the 32-byte Security Domain Secret used to decrypt all synced passkey private keys from Chrome’s process memory. Every path requires malware already running on the target system. Unit 42 / Palo Alto Networks

CaptiveCrunch: Midnight Blizzard (APT29) Targets Business Travelers via Hotel Wi-Fi
Microsoft Threat Intelligence disclosed CaptiveCrunch, a campaign attributed to Storm-2945, an operational sub-cluster of Midnight Blizzard (APT29), active since May 2026 and targeting business travelers at hotels and conference venues. Attackers manipulate hotel captive-portal DNS and HTTP traffic to redirect guests to fake Microsoft sign-in pages or malware. Two malware families are deployed: CornFlake (a Go-based Windows RAT with keylogging and browser credential theft) and ChocoShell (an in-memory PowerShell infostealer capturing Microsoft 365 tokens and Wi-Fi passwords). Microsoft Security Blog

Anthropic Discloses Claude AI Models Breached Three Organizations During Cyber Testing
Anthropic disclosed that three of its models — Claude Opus 4.7, Mythos 5, and an unnamed research model — accessed real external systems during capture-the-flag exercises after a configuration error at evaluation partner Irregular left the test environments connected to the public internet. The models compromised infrastructure using basic techniques including weak password exploitation and unauthenticated endpoint access. The disclosure follows OpenAI’s similar revelation the prior week involving an autonomous AI agent breaching Hugging Face. The Hacker News

Microsoft MAI-Cyber-1-Flash Cybersecurity AI Model Enters Public Preview
Microsoft’s MAI-Cyber-1-Flash, its first specialized AI model built for autonomous vulnerability detection and remediation, entered public preview on August 3 as part of Project Perception. The sparse mixture-of-experts model carries 137 billion total parameters and achieves 95.95% on the CyberGym benchmark at roughly half the cost of Microsoft’s prior MDASH configuration. The model draws on more than 100 trillion daily security signals across identity, endpoint, cloud, and network. SecurityWeek

Black Hat USA 2026: GPU Rowhammer, Agent Exploitation, and AI Security Research Begin
Black Hat USA 2026 is underway in Las Vegas (August 1–6), with researchers presenting GPUBreach, a Rowhammer-based attack escalating an unprivileged process on an NVIDIA GPU to a root shell on the host even with IOMMU protections active. Novee researchers will present vulnerabilities in Anthropic, OpenAI, and Google systems across four sessions at Black Hat and DEF CON 34. The full Briefings programme runs August 5–6. SecurityWeek

Stay tuned for today’s in-depth analysis posts.

Enjoy this article? Don’t forget to share.