Cyware at Space ISAC 2026
Daily Threat Briefing
Diamond Trail

Cyware Daily Threat Intelligence - August 06, 2026

shutterstock 2048595065

A surge of website hijackings is turning trusted domains into malware launchpads, as DriveSurge quietly redirects everyday browsing sessions to malicious payloads. Cyware spotlights how thousands of legitimate sites now serve as infection vectors, with both Windows and macOS users at risk from sophisticated obfuscation and fingerprinting tactics.

A critical flaw in IBM’s Langflow platform is exposing AI workflow servers to full takeover. Attackers are already exploiting CVE-2026-9198, leveraging auto-login and code validation endpoints to run arbitrary Python code on default deployments. Organizations relying on watsonx.ai must patch immediately to avoid compromise.

North Korean hackers have breached over 1,640 companies across 57 countries, siphoning off 5 terabytes of stolen data in a campaign that targets cryptocurrency wallets and high-profile organizations. The operation’s global reach and cash-driven focus underscore the evolving threat landscape tracked by cyware.com.

Top Malware Reported in the Last 24 Hours

DriveSurge hijacks trusted sites for installs

DriveSurge is a newly identified threat actor operating a large-scale malware distribution campaign. DriveSurge compromises thousands of legitimate websites to push malware through ClickFix prompts and fake browser update lures. DriveSurge quietly redirects visitors from trusted pages to malicious payloads using a traffic distribution system called zTDS, targeting both Windows and macOS users. DriveSurge leverages obfuscation and fingerprinting to deliver payloads to selected targets and evade detection. Infection occurs via routine web browsing, with users redirected to malware without warning. Silent Push researchers attribute the campaign to a pay-per-install scheme, urging organizations to monitor for suspicious redirections and strengthen web filtering.

SMOKE#SCREEN quietly installs ScreenConnect backdoors

SMOKE#SCREEN is an ongoing campaign that uses trusted-software themes, such as Zoom updates and business documents, to trick Windows and macOS users into installing ScreenConnect remote management agents. SMOKE#SCREEN relies on VBScript droppers protected with XOR encryption and uses WMI-based execution to run subsequent stages while remaining covert. SMOKE#SCREEN employs Cloudflare tunnels for communications and delivers payloads via Dropbox links and a WsgiDAV server, enabling persistent remote access. Infection is achieved through deceptive installer flows that appear legitimate to victims. Securonix documented the campaign, highlighting the use of loaders and batch scripts to disable security features and recommending strict UAC policies and behavioral EDR rules.

ENDLESSDOORS implant leaves routers hijackable

ENDLESSDOORS is an implant discovered in Zbtlink routers that enables remote control by connecting to command-and-control servers. ENDLESSDOORS lacks a handshake or key exchange, allowing any attacker on the network path to hijack the connection. ENDLESSDOORS can execute commands as root and open a root shell, turning edge devices into attacker-controlled footholds. ENDLESSDOORS targets multiple Zbtlink models, including AX3000, CPE2801, and WE1326. VulnCheck researchers describe the risk as a device-trust problem, recommending organizations inventory affected models, block known endpoints, and segment or replace compromised devices.

Top Vulnerabilities Reported in Last 24 hours

Hackers exploit IBM Langflow RCE (CVE-2026-9198)

CVE-2026-9198 is a critical remote code execution vulnerability in the IBM Langflow platform, affecting Langflow OSS versions 1.0.0 through 1.10.0, with a CVSS score not specified in the source. Successful exploitation allows unauthenticated attackers to run arbitrary Python code, resulting in full server takeover. CVE-2026-9198 is actively exploited in the wild, with attackers abusing auto-login and code validation endpoints. The issue was disclosed by IBM, which urges immediate patching to version 1.10.1 or later and securing default configurations. Organizations using IBM’s watsonx.ai ecosystem are at risk if running affected versions.

Cisco fixes seven serious IOS XE bugs (CVE-2026-20272 and others)

CVE-2026-20272 is a critical command injection vulnerability in Cisco IOS XE Software, with a CVSS score of 9.8. Successful exploitation allows unauthenticated attackers to execute arbitrary system commands. No active exploitation or public disclosure is known for CVE-2026-20272 or related vulnerabilities, including CVE-2026-20267 (CVSS 9.0) and five others scored 8.6. Cisco’s internal review, using advanced AI models, identified the flaws, which are reachable over the network without privileges. Affected IOS XE trains include 17.9, 17.12, 17.15, 17.18, and 26.1 (excluding Catalyst 3650 and 3850), with fixes in 17.9.10, 17.12.8, 17.15.6, 17.18.4, or 26.1.2. Cisco recommends enforcing strict administrative access controls.

Linux Open vSwitch bug enables root (CVE-2026-64531)

CVE-2026-64531 is a Linux kernel Open vSwitch datapath vulnerability, dubbed OVSwrap, with a CVSS score of 7.8. Successful exploitation allows a local user to escalate privileges to root and take over the server. A proof of concept exists and has been tested across multiple distributions, requiring OVS conntrack support and sudo, and triggers memory corruption via a crafted CLONE action. Security researcher Asim Manizada disclosed the flaw, which affects kernels prior to 5.15.212, 6.1.178, 6.6.145, 6.12.97, 6.18.40, and 7.1.5. Vendor-patched kernels are the primary fix, with mitigations including blocking future Open vSwitch module loads and disabling unprivileged user namespaces.

Top Threat Actors Reported in Last 24 hours

North Korean hackers breach 1,640 companies

North Korean hackers (suspected origin) are financially motivated and have been linked to a campaign impacting over 1,640 companies across 57 countries. North Korean hackers use fake job offers to lure developers into installing malware, focusing on raiding cryptocurrency wallets while ignoring other sensitive data. North Korean hackers target organizations such as AEON Smart Technology, Oppo, Uniswap Labs, the Flemish Government, and Boston Children’s Hospital. The campaign, known as “Contagious Interview,” leverages social engineering to gain access. Researcher Vangelis Stykas accessed 5 terabytes of stolen data, highlighting the campaign’s scale and North Korea’s economic and military objectives.

Silent Ransom sends fake IT staff

Silent Ransom (suspected origin) is a financially motivated group extending ransomware-style extortion by sending operatives to victim offices while posing as IT technicians. Silent Ransom begins with phishing emails or calls to install remote-access software or capture credentials, escalating to in-person impersonation if initial attempts fail. Silent Ransom targets U.S. law firms, focusing on confidential client files to increase ransom pressure. Silent Ransom’s recent campaigns have resulted in significant ransom payments, even as overall ransom payments have declined. The FBI has issued warnings about the group’s activity since spring 2023.

DriveSurge hijacks websites to spread malware

DriveSurge (suspected origin) is a newly identified threat actor running a large malware distribution operation by compromising thousands of legitimate websites. DriveSurge uses ClickFix and fake browser update lures, routing visitors through a traffic distribution system called zTDS to deliver malicious payloads. DriveSurge targets both Windows and macOS users, expanding the campaign’s reach. DriveSurge leverages obfuscation and fingerprinting to evade detection and operate at scale. Researchers describe DriveSurge’s operation as sophisticated, with routine browsing of trusted sites becoming an entry point for malware.

Frequently Asked Questions

  1. What is DriveSurge? DriveSurge is a newly identified threat actor that has compromised thousands of legitimate websites to push malware through ClickFix prompts and fake browser update lures. It quietly redirects visitors from otherwise trusted pages to malicious payloads using a traffic distribution system called zTDS, hitting both Windows and macOS users.

  2. What is SMOKE#SCREEN? SMOKE#SCREEN is an ongoing campaign that uses trusted-software themes—like Zoom updates and business documents—to trick Windows and macOS users into installing ScreenConnect remote management agents. It relies on VBScript droppers protected with XOR encryption and uses WMI-based execution to run the next stages while staying out of sight.

  3. What is ENDLESSDOORS? ENDLESSDOORS is an implant found in Zbtlink routers that enables remote control by phoning home to command-and-control servers—and it can be hijacked by anyone positioned along the network path. It lacks a handshake or key exchange, meaning neither side verifies who it is talking to, and attackers can exploit that weakness to seize control.

  4. What is CVE-2026-9198? A critical remote code execution bug in IBM’s Langflow platform (CVE-2026-9198) lets unauthenticated attackers run arbitrary Python code on default deployments, opening the door to full server takeover. The attack chain abuses an auto-login endpoint to obtain superuser tokens and then uses a code validation endpoint to execute attacker-supplied code.

  5. What is CVE-2026-20272? Cisco patched seven IOS XE Software vulnerability classes, led by a critical command injection flaw (CVE-2026-20272, CVSS 9.8) that can allow unauthenticated attackers to execute arbitrary system commands. The broader update also addresses CVE-2026-20267 (CVSS 9.0) and five additional issues scored 8.6: CVE-2026-20268, CVE-2026-20269, CVE-2026-20270, CVE-2026-20271, and CVE-2026-20273.

  6. What is CVE-2026-64531? A Linux kernel Open vSwitch datapath vulnerability (CVE-2026-64531, CVSS 7.8), dubbed OVSwrap, allows a local user to escalate to root and take over an affected server. In practical terms, that means a low-privileged account or untrusted workload could jump to full system control, putting shared environments and multi-user systems at risk.

  7. What is North Korean hackers? North Korean hackers have been tied to a sprawling campaign that hit over 1,640 companies across 57 countries, after researcher Vangelis Stykas accessed about 5 terabytes of their stolen data. The operation, known as “Contagious Interview”, used fake job offers to lure developers into installing malware.

  8. What is Silent Ransom? Silent Ransom is pushing ransomware-style extortion beyond email and phone scams by sending operatives to victim offices while posing as IT technicians. They typically begin with phishing emails or calls meant to install remote-access software or capture credentials, then escalate to in-person impersonation if those attempts fail.

Discover Related Resources