
Weekly Threat Intelligence Briefing — August 10, 2026
WEEKLY THREAT INTELLIGENCE BRIEFING | MONDAY, AUGUST 10, 2026
Attackers ran the tools you already trust
Two campaigns reached that destination from opposite directions this week. Six KEV additions, every one of them on a three-day clock.
MSP console: the way in
N-able disclosed active exploitation of N-central, the platform managed service providers use to monitor, patch, and remotely access customer endpoints. CVE-2026-18577 (CVSS 8.2) hands an unauthenticated attacker administrative access to the console — what Huntress called god-mode, the control normally reserved for trusted NOC and engineering staff. It is not a new zero-day. It is an incomplete patch for CVE-2026-18556. Attackers found the alternate path and were using it by July 31.
What happened next matters more than how they got in. Per N-able’s own incident notice, the attacker used the Take Control feature to reach systems inside the managed environment, then registered a Cloudflare tunnel as a service on those devices — persistence that survives revoking the N-central server’s access, and survives a reboot. Sophos telemetry shows one victim where the compromised console was used to reach a backup server, domain controllers, and application servers. CISA gave federal agencies three days: due August 6, now passed.
DIB implication: if you outsource IT, your provider’s console carries privileged access inside your CUI boundary whether the SSP names it or not. Two questions for them this week — are you on 2026.3.1.7 or later, and have you reviewed Take Control session logs?
No vulnerability required
Securonix published research on August 4 detailing SMOKE#SCREEN, a campaign that installs a genuine, ConnectWise-signed ScreenConnect agent through fake Zoom and Adobe update pages, business-document lures, and phony system-check utilities — now on macOS as well as Windows. The agent is real software with a valid certificate chain. The only thing wrong with it is who holds the other end. Sessions present as ordinary guest access, and delivery leans on Dropbox links and Cloudflare Quick Tunnels to stay inside allow-listed traffic.
DIB implication: your endpoint tooling is being asked whether the file is malicious, and answering no — correctly. The question that catches this one is whether the agent was ever authorized to run there. That is asset inventory and execution governance, not detection.
📌 Watch: water utilities
CISA’s July 30 alert reports a significant increase in actors targeting internet-exposed PLCs in water and wastewater, describing what the FBI and EPA described: passwords changed to lock operators out, IP addresses changed to disconnect the device. Dozens of Minnesota utilities had automated controls disrupted. Reporting says officials are examining Iranian involvement — CISA names no actor, and neither do we. Forescout’s analysis makes the sharpest point: no CVE is being exploited on these MicroLogix controllers. Exposure and credentials are the whole story. A patch cycle would not have prevented it.
Practitioner takeaway
Confirm N-central is at 2026.3.1.7 or later and review Take Control session logs across July 31 to August 6. Hunt for ScreenConnect and other remote-management agents no administrator approved — inventory every remote-access tool by owner and authorization, not by signature. Look for Cloudflare tunnel services registered on endpoints; they need no inbound rule and survive reboot. Progress LoadMaster CVE-2026-8037 and Fortinet FortiOS CVE-2025-68686 both close today, August 10.
PSYber360: last week we recorded the water-sector PLC activity as an unattributed cluster rather than folding it into a named Iranian actor. CISA’s alert this week attributes it to no one. The record stands as written.
How many remote-access agents are running in your environment right now — and who authorized each one?
Craig Wood | CISM | CCA Lead Assessor | ISO 27001 Lead Auditor
CEO, PSY Logistics Technology Partners
CMMC | Maritime Cybersecurity | vCISO | DIB
#ThreatIntelligence #Cybersecurity #InfoSec #PSYLogistics #DIB #CMMC #CUI #CISA #KEV #MSP #SupplyChainSecurity #OTSecurity #vCISO