Issue #015 · August 7, 2026

Cyber Threat Brief — Issue #015

What's active. What matters. What to do about it.

Priority Actions This Week

  1. 01If your organization uses N-able N-central, or if your managed service provider does, patch to version 2026.3.1.7 immediately. CVE-2026-18577 lets an unauthenticated attacker take over administrative accounts and then reach into every customer environment the platform manages. CISA set a three-day federal deadline that has already passed. Nearly all cloud-hosted instances are patched, but roughly a quarter of self-hosted servers remained vulnerable and internet-exposed as of early August. If yours is self-hosted, treat this as an active incident.
  2. 02Brief your entire workforce, technical and non-technical, on fake software update lures. The SMOKE#SCREEN campaign is tricking users into installing a real remote access tool called ScreenConnect through fake Zoom and Adobe update pop-ups, fake document review requests, and fake system maintenance utilities. Because the tool being installed is legitimate, it does not trigger normal malware alarms. The rule for your team: software updates come from the application itself or your IT department, never from a pop-up or a link.
  3. 03Treat the arrival of AI-automated attacks as a present reality, not a future one. A Chinese threat actor was confirmed this month using the DeepSeek AI model to autonomously run intrusions against a security firm's network. Your defensive assumption should shift: the volume, speed, and persistence of opportunistic attacks against any internet-exposed system is now amplified by AI agents that do not tire and do not stop. Anything you have exposed to the internet is being probed more aggressively than it was six months ago.
  4. 04If you run Linux KVM hosts with nested virtualization exposed to untrusted guests, patch for the Zapscape vulnerability CVE-2026-64561. An attacker with root inside a guest virtual machine can escape to the host and execute code with kernel privileges. This matters most for cloud providers and any multi-tenant virtualization environment. No in-the-wild exploitation is confirmed yet, but a working proof of concept exists.
  5. 05If you run cPanel, apply the CVE-2026-58048 patch. CISA added it to the KEV catalog on August 5 alongside active exploitation. An attacker who exploits it can execute database commands with full administrative privileges, which on some configurations extends to full operating system compromise. cPanel runs on a large share of web hosting infrastructure, making this a broad-exposure flaw.

Active Campaigns

[ ESCALATING ]N-able N-central Authentication Bypass — MSP Platform Takeover Under Active Exploitation, Three-Day Federal Deadline
ACTOR: Multiple threat actors — confirmed exploitation, pivot into managed customer environments observedTARGETS: Managed service providers and enterprises running N-able N-central, and by extension every downstream customer those MSPs manage

CISA added CVE-2026-18577, an actively exploited authentication bypass in N-able N-central, to the Known Exploited Vulnerabilities catalog on August 3, 2026, with a three-day federal remediation deadline of August 6 under the accelerated Binding Operational Directive 26-04. N-central is a remote monitoring and management platform used by managed service providers to administer their customers' IT environments, which makes it an extremely high-value target. An attacker who takes over an N-central server does not just compromise one organization. They gain the platform's remote management reach into every customer environment that MSP manages. The flaw is particularly notable because it resulted from an incomplete fix for an earlier vulnerability, CVE-2026-18556. N-able patched that flaw in version 2026.2, then discovered attackers had found an alternative route to the same outcome that the original patch did not close. Security firm Huntress observed successful attacks pivoting into managed endpoints and creating Cloudflare-based tunnels for persistent access to victim networks. As of August 3, nearly all cloud-hosted N-central instances had been patched, but 28.6 percent of observed self-hosted servers remained vulnerable and exposed to the internet.

[ ESCALATING ]SMOKE#SCREEN — Fake Software Updates Deliver Legitimate Remote Access Tool for Silent Takeover
ACTOR: Unknown — financially motivated, RMM abuse, operating a live human-staffed help chat to walk victims through installationTARGETS: Windows and macOS users across enterprise and consumer environments globally

Securonix Threat Research disclosed an active multi-wave campaign called SMOKE#SCREEN that tricks users into installing ConnectWise ScreenConnect, a legitimate remote monitoring and management tool, through a rotating set of social engineering lures. The lures are themed around fake Zoom and Adobe software updates, fake business document review requests, and fake system maintenance utilities. Because ScreenConnect is a legitimate tool used by IT departments worldwide, an attacker-controlled installation grants full remote desktop control, file access, and a persistent foothold that looks exactly like authorized IT activity and does not trigger conventional malware detection. The operation is sophisticated in its infrastructure, rotating payload file hashes to defeat hash-based detection, using Cloudflare Quick Tunnels to obscure where downloads are hosted, and running a staging server with fifteen unique payloads across five reconstructed kill chains. In one observed variant, the phishing site includes a customer service chat box where a real human attacker, not an automated bot, responds to walk victims through the malware installation step by step. The campaign targets both Windows and macOS.

[ ACTIVE ]AI-Automated Intrusions Confirmed in the Wild — Chinese Actor Uses DeepSeek to Run Autonomous Attacks
ACTOR: Chinese threat actor — AI-managed intrusion campaign for proxyjacking and follow-on attacksTARGETS: Internet-exposed infrastructure broadly; confirmed against a security research firm's deliberately exposed network

A Chinese threat actor was confirmed this month using the DeepSeek AI model to autonomously conduct a cyberattack campaign against the network of Tel Aviv-based AI security firm Jesta Security in early July 2026. The activity is one of the clearest confirmed examples to date of threat actors relying on AI agents to break into third-party networks with minimal human direction. Researchers at the firm had deliberately exposed a lab environment behind US-based infrastructure to study AI-driven attackers. Within a week they logged more than 300,000 break-in attempts, the majority ordinary internet background noise of botnets and credential stuffing. What stood out was activity that did not fit the usual pattern, which researchers linked to an AI-managed campaign aimed at proxyjacking and follow-on attacks. This confirmation matters because it moves AI-automated intrusion from theoretical capability, discussed in prior briefs in the context of AI-generated exploits, to documented operational reality. The defensive implication is that the baseline aggression of opportunistic attacks against any internet-exposed system is rising as AI agents take on the labor of scanning, probing, and exploiting at machine speed and scale.

CVE Watch

CVE-2026-18577CVSS 8.2[ ESCALATING ]

PRODUCT: N-able N-central (versions prior to 2026.3.1.7)

WHAT IT MEANS:

An authentication bypass vulnerability in N-able N-central allows an unauthenticated attacker to bypass login and take over administrative accounts on vulnerable servers. N-central is a platform managed service providers use to remotely administer their customers' systems, so an administrative takeover gives the attacker the platform's built-in remote management access into every downstream customer environment. The flaw is an incomplete patch case: it stems from an alternative exploitation route that survived the fix for an earlier vulnerability, CVE-2026-18556. Attackers began abusing the new route in late July. Confirmed post-exploitation activity includes pivoting into managed endpoints and creating Cloudflare tunnels for persistent access. CISA set a three-day federal deadline, faster than the standard fourteen days, reflecting the urgency of an MSP platform compromise.

ACTION:Upgrade N-able N-central to version 2026.3.1.7 immediately. If your organization relies on an MSP, confirm with them that their N-central deployment is patched. Self-hosted internet-exposed instances are the primary remaining risk and should be treated as an active incident.

CVE-2026-58048CVSS 9.4[ ESCALATING ]

PRODUCT: cPanel (multiple builds)

WHAT IT MEANS:

A vulnerability in cPanel, the web hosting control panel software that runs on a large share of the world's web hosting servers, allows an attacker to execute database commands with full administrative privileges. Depending on the operating system and database engine configuration, that access can extend to operating-system-level compromise of the entire server. CISA added this to the Known Exploited Vulnerabilities catalog on August 5, 2026, confirming active exploitation. Because cPanel is so widely deployed across shared hosting environments, a single compromised cPanel server can expose every website, database, and email account hosted on it. This is the second time in 2026 that a widely deployed hosting control panel vulnerability has seen active exploitation, reinforcing that hosting infrastructure remains a high-value target.

ACTION:Update cPanel to a patched build immediately: 11.110.0.137, 11.118.0.71, 11.126.0.78, 11.134.0.48, 11.136.0.32, or 138.1.6 for WP Squared servers, depending on your version. If you cannot update immediately, restrict database administrative access and audit for unauthorized command execution.

CVE-2026-64561CVSS 7[ MONITORING ]

PRODUCT: Linux Kernel KVM/x86 (shadow MMU, nested virtualization)

WHAT IT MEANS:

Named Zapscape, this is a use-after-free vulnerability in the Linux kernel's KVM virtualization subsystem, specifically in the shadow memory management unit that handles nested guest memory translation. An attacker with kernel-level privileges inside a guest virtual machine, which typically means root inside that guest, can escape the virtual machine's isolation and execute code on the underlying host with kernel privileges. The risk applies specifically to KVM hosts that expose nested virtualization to untrusted guests, a configuration most relevant to cloud providers and multi-tenant hosting environments. No in-the-wild exploitation has been confirmed and the researcher's proof of concept was developed against a specific configuration that would require adaptation to reach a production host, but the upstream fix has been merged and should be applied. This is the third KVM escape vulnerability from this research lineage in 2026, following Januscape and ITScape.

ACTION:Update KVM hosts that expose nested virtualization to untrusted guests to a fixed stable kernel or a vendor package that backports the upstream fix. Environments that do not expose nested virtualization to untrusted guests are at substantially lower risk.

Threat Actor Activity

DeepSeek-linked Chinese actor[ ESCALATING ]

Confirmed using the DeepSeek AI model to autonomously run an intrusion campaign against a security firm's exposed network in early July, aimed at proxyjacking and follow-on attacks. One of the clearest documented cases of AI-managed intrusion operating in the wild against third-party networks.

SMOKE#SCREEN operators (unattributed)[ ESCALATING ]

Running an active multi-wave campaign delivering ConnectWise ScreenConnect through fake Zoom and Adobe update lures, fake document reviews, and fake maintenance utilities. Notable for rotating payload hashes, using Cloudflare tunnels, and staffing a live human help chat to walk victims through installation. Targets both Windows and macOS.

TA488[ ACTIVE ]

Abusing the Outlook flaw CVE-2026-42897 to deploy a persistent backdoor called OWAReaper with minimal user interaction, giving the group durable long-term access to victim mailboxes. Organizations running on-premises Exchange should ensure the CVE-2026-42897 patch from June is applied.

Qilin (Agenda)[ ACTIVE ]

Confirmed as the most active ransomware group in the first half of 2026, targeting manufacturing, healthcare, construction, and professional services worldwide through its ransomware-as-a-service operation. Known for rapidly weaponizing newly disclosed entry points.

TeamPCP (UNC6780)[ ACTIVE ]

New analysis revealed TeamPCP has been active since at least 2020, compromising internet-facing infrastructure for years before the 2026 supply chain campaigns covered in prior briefs. Linked to the ShadowRay 2.0 AI infrastructure botnet and Redis server cryptomining campaigns.

FortiBleed operators / INC Ransom / Lynx[ MONITORING ]

No new scale updates. The credential-to-ransomware pipeline confirmed in Issue 013 remains the operative threat for organizations with unrotated Fortinet VPN credentials.

Key Takeaway

The single most important development this week is not a specific vulnerability. It is the confirmation that AI-automated intrusion has arrived in the wild. These briefs have tracked the trajectory across recent months: AI-generated exploits, AI-assisted vulnerability discovery, malware built to fool AI analysis tools. The DeepSeek-managed attack campaign closes the loop. An AI agent is now doing the work of the intrusion itself, at machine speed, without tiring, against exposed infrastructure. The practical consequence for defenders is a rising baseline of aggression against anything internet-facing, and it makes the rest of this week's stories more urgent, not less. The N-able N-central flaw is exactly the kind of high-value, internet-exposed target that AI-driven scanning finds fastest, and a quarter of self-hosted instances sat exposed past the federal deadline. The SMOKE#SCREEN campaign shows the other side of the same coin: where automation cannot yet reach, attackers are still using human operators in live chat to walk victims into installing their own remote access tool. The through-line for mid-2026 is that both ends of the sophistication spectrum are being worked at once. Machines handle the scale. Humans handle the persuasion. The only reliable response is faster patching and better-trained people — because the attacks are coming from both directions simultaneously.

Sources

  • CISA Known Exploited Vulnerabilities Catalog
  • The Hacker News
  • The Register
  • GBHackers
  • Securonix Threat Research
  • Dark Reading
  • Huntress
  • Security Affairs
  • Imperva Threat Intelligence
  • TuxCare
  • Cyber Security News