Cyware at Space ISAC 2026
Daily Threat Briefing
Diamond Trail

Cyware Daily Threat Intelligence - August 10, 2026

shutterstock 2605380779

AI-powered espionage is accelerating the pace at which stolen communications become actionable intelligence. On cyware.com, analysts are tracking Kimsuky's use of automated tools in Operation GitPower, where a single compromised inbox can expose sensitive diplomatic or military conversations. The campaign leverages spear-phishing, AI-generated decoys, and RC4-encrypted payloads to infiltrate high-value targets across multiple sectors.

Critical vulnerabilities are being exploited in the wild, putting millions of devices and websites at risk. Attackers are targeting Progress Kemp LoadMaster appliances and N-able N-central management platforms, while a backdoor in WPForms Lite threatens over 5 million WordPress sites. These flaws enable attackers to bypass authentication, execute arbitrary commands, and escalate privileges with minimal user interaction.

Industrial and utility networks are under direct assault, with cyberattacks disrupting energy and water services for tens of thousands. Sandworm cut heat to 50,000 residents in Poland by pivoting through private APN infrastructure, while Iran-linked hackers targeted water facilities in at least a dozen US states. These incidents highlight the growing risk to critical infrastructure from persistent, state-linked adversaries.

Top Malware Reported in the Last 24 Hours

Kimsuky adds AI to Operation GitPower

Operation GitPower is a Kimsuky espionage campaign that integrates AI tools to process stolen calls and meetings. Kimsuky uses spear-phishing lures and AI-generated decoy documents, then relies on LNK files with custom Base64 decoding and string splitting to execute malicious payloads. Kimsuky distributes RC4-encrypted payloads disguised as image files via Git repositories, blending into developer workflows. Infection begins with targeted phishing and decoy documents, followed by payload delivery through obfuscated LNK files. Kimsuky targets foreign diplomatic missions, military and security organizations, and virtual-asset-related entities. Researchers attribute this activity to Kimsuky’s broader automation push across its infrastructure.

Go macOS stealer drains crypto via ClickFix

A new Go-based macOS malware acts as a stealer targeting cryptocurrency and sensitive data. The malware collects system details, downloads a Mach-O payload tailored to the victim’s processor, and scrapes browser password stores, Apple Keychain data, and cached credentials. The malware includes a “DRAIN” function that checks crypto wallet balances and redirects funds to attacker-controlled wallets. Infection begins when victims are tricked by ClickFix scams into running a Terminal command. The malware targets macOS users, especially those holding cryptocurrency. Huntress discovered the activity in June 2026 and linked the infrastructure to the Aeza Group, a sanctioned Russian bulletproof hoster.

Solidity Pro extensions steal keys and wallets

The Solidity Pro VS Code extensions “helper-beeps.solidity-pro” and “web3devtoolsx.solidity-pro” are malicious tools designed to steal crypto wallets and API keys. The extensions use heavy obfuscation, intermediate clean versions, and randomized delayed activation to evade detection. Once active, the extensions harvest GitHub tokens, AWS and Cloudflare keys, OpenAI keys, Telegram bot tokens, and mnemonic/seed phrases for wallets such as MetaMask and Coinbase, exfiltrating data via a Telegram bot. Infection occurs after installation and delayed activation on developer machines. The extensions target developers working with cryptocurrency and cloud services. Reporting links the activity to the WhiteCobra threat cluster, known for abusing open-source ecosystems.

Top Vulnerabilities Reported in Last 24 hours

CVE-2026-8037: Command-injection in Progress Kemp LoadMaster (CVSS 9.8)

CVE-2026-8037 is a command-injection vulnerability in Progress Kemp LoadMaster load balancers with a CVSS score of 9.8. Successful exploitation allows unauthenticated attackers to execute arbitrary system commands and potentially take control of exposed devices. Attackers are already exploiting CVE-2026-8037 in the wild, with confirmation from CISA. The vulnerability was discovered in the context of ongoing attacks, and a similar issue (CVE-2024-1212) was exploited two years ago. Updates have been available since June 2026, and affected systems include all unpatched Progress Kemp LoadMaster appliances.

CVE-2026-18577: Authentication bypass in N-able N-central (CVSS v4.0 8.2)

CVE-2026-18577 is an authentication-bypass vulnerability in N-able N-central with a CVSS v4.0 score of 8.2. Exploitation enables unauthorized access that can cascade into compromised managed endpoints. Attackers are already exploiting CVE-2026-18577 in the wild, with activity detected on July 31, 2026 and confirmed on August 1, 2026. The vulnerability was discovered after attackers bypassed earlier fixes, prompting N-able to release Hotfix 2 in version 2026.3.1.10. Mitigation includes applying the latest patch, segmenting networks, and maintaining up-to-date security software on all managed endpoints.

WPForms Lite backdoor impacts over 5 million WordPress sites

A reported backdoor in WPForms Lite affects over 5 million WordPress sites and grants WPForms’ servers a one-hour login token for administrator-level actions. Exploitation can alter site behavior, install or activate plugins, or redirect form submissions, risking both integrity and privacy. Exploitation activity was described as automatic during a fresh install setup, with the token expiring after setup or one hour. The vulnerability was reported by the community, with the token-enabled workflow potentially used to install plugins such as WP Mail SMTP, WPConsent, Uncanny Automator, AIOSEO, Duplicator, Reviews Feed, OptinMonster, MonsterInsights, Contact Form 7, Ninja Forms, and others. Site owners are urged to conduct thorough security audits and enhance monitoring for WPForms-related activity.

Top Threat Actors Reported in Last 24 hours

Sandworm (also tracked as Voodoo Bear) disrupts Polish energy

Sandworm (also tracked as Voodoo Bear), a suspected Russia-linked APT, is motivated by disruption of critical infrastructure. Sandworm exploited a Fortinet VPN and firewall, pivoted through a Teltonika router using SSH, and built a tunnel into a private APN. Sandworm targeted industrial infrastructure including Moxa serial device servers and network switches, and attempted actions involving ABB and Schneider Electric drives. The group targeted a Polish CHP energy facility, disrupting operations and cutting heat to 50,000 residents. The campaign began with exploitation of network devices and escalated to ICS sabotage, initially appearing as an engineering error. Sandworm used a Wago PLC as a gateway and corrupted its partition table, resulting in permanent damage to some ICS devices.

Kimsuky (also tracked as APT43) scales AI-driven espionage

Kimsuky (also tracked as APT43), a suspected North Korea-linked espionage group, is motivated by intelligence collection. Kimsuky uses spear-phishing lures and AI-generated decoy documents, and relies on LNK files with custom Base64 decoding and string splitting to execute malicious payloads. Kimsuky delivers RC4-encrypted payloads disguised as image files via Git repositories, supported by infrastructure for AI-driven analysis and document retrieval. The group targets foreign diplomatic missions, military and security organizations, and virtual-asset-related entities. The campaign, Operation GitPower, spreads through phishing and decoy documents, signaling faster exploitation of stolen material. Researchers attribute this activity to Kimsuky’s automation efforts.

Iran-linked hackers target US water facilities

Iran-linked hackers, suspected to originate from Iran, are motivated by disruption of US critical infrastructure. The group targets industrial control systems at water facilities, with incidents reported in at least a dozen states since late July. The hackers use network intrusion and disruption techniques, including attacks on phone systems and attempted service interruptions. The group targeted water utilities in New Jersey (Cape May and Woodbine) and Alabama (Childersburg Water, Sewer, and Gas) on July 27. The campaign involved coordinated attacks on multiple utilities, with the FBI confirming at least seven states targeted by the end of July. Officials reported no major operational impact, but the incidents raised concerns about service reliability and public trust.

Frequently Asked Questions

  1. What is Kimsuky? Kimsuky, a North Korea-linked espionage group, is folding AI tools into Operation GitPower to process stolen calls and meetings, sharpening how quickly it can turn raw data into usable intelligence. The campaign uses spear-phishing lures and AI-generated decoy documents, then relies on LNK files that hide execution through techniques such as custom Base64 decoding and string splitting to run malicious payloads.

  2. What is Go-based macOS malware? A new Go-based macOS malware is stealing cryptocurrency and sensitive data by using ClickFix scams that trick victims into running a command in Terminal to start the infection chain. After execution, it collects system details and downloads a Mach-O payload tailored to the victim’s processor, then scrapes browser password stores, Apple Keychain data, and cached credentials.

  3. What is Solidity Pro? The Solidity Pro VS Code extensions “helper-beeps.solidity-pro” and “web3devtoolsx.solidity-pro” were identified as malicious, built to quietly siphon crypto wallets and high-value API keys from developers’ machines. The extensions evade scrutiny with heavy obfuscation, intermediate “clean” versions, and randomized delayed activation, allowing theft to begin well after installation.

  4. What is CVE-2026-8037? A critical command-injection flaw in Progress Kemp LoadMaster load balancers (CVE-2026-8037, CVSS 9.8) lets unauthenticated attackers execute arbitrary system commands and potentially take control of exposed devices. In real terms, that can translate into disrupted services, stolen data, or a load balancer being used as a launch point deeper into a network.

  5. What is CVE-2026-18577? An authentication-bypass vulnerability in N-able N-central (CVE-2026-18577, CVSS v4.0 8.2) is being exploited to gain unauthorized access that can cascade into compromised managed endpoints. The incident stands out because attackers were reported to bypass earlier fixes, prompting N-able to ship a second release with added hardening.

  6. What is WPForms Lite? A reported backdoor in WPForms Lite, affecting over 5 million WordPress sites, allegedly grants WPForms’ servers a one-hour login token that can be used to perform administrator-level actions without the site owner’s explicit approval. That window is enough to alter a site’s behavior—such as installing or activating plugins—or to redirect form submissions, creating both integrity and privacy risks for businesses that rely on web forms.

  7. What is Sandworm? Sandworm (also tracked as Voodoo Bear), a Russia-linked APT, used an unusual foothold in late December 2025: a private APN pivot that helped them disrupt operations at a Polish CHP energy facility and cut heat supply to 50,000 residents. They first exploited a Fortinet VPN and firewall device, then moved into a Teltonika router and used SSH to build a tunnel into the private APN.

Discover Related Resources