Cyber Threat Brief — August 11 2026

⚠️ This report is AI-generated. Always validate findings.

1. N-able N-central Auth Bypass — CVE-2026-18577

TL;DR: Unauthenticated RMM platform takeover actively exploited by Storm-1175 for StormEncryptor ransomware. Second hotfix shipped August 10 — Hotfix 1 was insufficient. Upgrade N-central to 2026.3.1.10 immediately.

What’s New:

  • N-able shipped Hotfix 2 (2026.3.1.10) August 10, superseding Hotfix 1 with additional hardening after attackers evolved techniques
  • Microsoft attributes exploitation to Storm-1175 (financially motivated), deploying new StormEncryptor ransomware (successor to Medusa)
  • Post-exploitation chain: Take Control → Cloudflared tunnel persistence → veeam domain account creation → domain admin password resets → LSASS dump via Mimikatz → EDR evasion tool → ransomware deployment within days
  • Sophos confirmed EDR-evasion tool disabling Microsoft Defender and Sophos products; additional C2 and TacticalRMM servers identified
  • Huntress observes multi-org targeting but not yet broad indiscriminate campaign

Actionable Intel

ArtifactTypeATT&CKLog SourceAction
173.249.252.176, 173.249.252.200, 185.156.46.150, 23.234.94.43, 37.153.90.88, 37.19.210.32Attacker IPsT1190Firewall, VPN, proxy logsBlock
68.235.46.214, 68.235.46.235, 87.249.138.34, 92.118.112.181Attacker IPs (VPN exits)T1190Firewall, proxy logsBlock
Windows service named CloudflaredPersistenceT1090.001, T1543.003Windows EID 7045 (service install)Hunt — alert on Cloudflared service creation
svchost.exe in Users\Documents folderMasqueradingT1036.005Sysmon EID 1, EDR process creationHunt — svchost.exe outside System32
Domain account veeam creationPersistenceT1136.002Windows EID 4720, AD auditDetect — rogue account creation
TacticalRMM server connectionsC2T1219DNS, proxy, EDRHunt — unexpected RMM tool connections
Take Control sessions from compromised N-centralLateral movementT1219N-central audit logsHunt — unusual Take Control session origins

Detection

SourceRuleGap
Splunk ESCUWindows Service Creation Using SC.exe (generic)No N-central Take Control abuse rule; no StormEncryptor-specific detection
ElasticCloudflare Tunnel Client Execution (partial)No N-central auth bypass detection
Sigmaproc_creation_win_svchost_outside_system32.ymlNo N-central-specific rules; need Take Control session anomaly detection

Sources: Help Net Security, Rapid7, Huntress, The Hacker News, BleepingComputer


2. Abyssos RAT — New Modular C++ Remote Access Trojan

TL;DR: Zscaler ThreatLabz disclosed Abyssos, a new modular C++ RAT with hidden VNC, browser credential theft, and keylogging — actively evolving across multiple builds with heavy LLVM obfuscation to frustrate analysis.

What’s New:

  • Modular architecture with plugin download capability from C2; custom TCP protocol with AES-GCM encryption
  • Hidden VNC (HVNC_CLONE_START) copies browser data including cookies into fontconfigs directory under Windows temp folder for operator-controlled browser sessions
  • UAC bypass via fodhelper.exe and ICMLuaUtil COM elevation
  • Keylogger stores captures as windows_update_cache.json in temp directory
  • LLVM obfuscation using Pluto: control-flow flattening, bogus control flow, encrypted integer constants, stack-based string obfuscation
  • Dynamic API resolution via CRC32 hash matching for Windows API calls

Actionable Intel

ArtifactTypeATT&CKLog SourceAction
52b400c5be1557a8df146f62fde76d906e7e0a92ed76788717ef61c758f315aaSHA-256 (v2.4F)T1059EDR, AVBlock
ca94d95413210a2a325155740eb8a5c58627ad5c4e704478621e7fc8165fe173SHA-256 (v2.1F)T1059EDR, AVBlock
213.145.86[.]42C2 IP (v2.4F)T1071.001Firewall, proxy, DNSBlock
209.99.184[.]223C2 IP (v2.1F)T1071.001Firewall, proxy, DNSBlock
fodhelper.exe spawning unexpected childrenUAC bypassT1548.002Sysmon EID 1, EDRDetect — fodhelper.exe parent-child anomaly
fontconfigs directory under %TEMP%Browser data stagingT1074.001Sysmon EID 11 (file create)Hunt — unusual temp directory creation
windows_update_cache.json in %TEMP%Keylogger outputT1056.001Sysmon EID 11Hunt — JSON file in temp matching this name
ICMLuaUtil COM object invocationUAC bypassT1548.002Sysmon EID 10/11, COM logsDetect — non-standard ICMLuaUtil callers

Detection

SourceRuleGap
Splunk ESCUWindows UAC Bypass via ICMLuaUtil (partial)No Abyssos-specific detection; need fontconfigs staging and HVNC session rules
ElasticUAC Bypass via Fodhelper (partial)No Abyssos C2 protocol detection; need hidden VNC browser clone detection
Sigmaproc_creation_win_uac_bypass_fodhelper.ymlNo detection for AES-GCM custom TCP C2 or CRC32 API resolution pattern

Sources: Zscaler ThreatLabz, GBHackers, CyberPress


Status Updates

  • CVE-2026-8037 (Progress Kemp LoadMaster): Federal CISA KEV deadline passed August 10. 792 exploitation attempts from 65 IPs across 18 countries. Patch to GA 7.2.63.2 or LTSF 7.2.54.18. Brief: Aug 10.
  • CVE-2026-6875 (ServiceNow): Active exploitation entering 4th week. Two sandbox-escape gadget chains confirmed. Fortune 500 and critical infrastructure victims. Still NOT on CISA KEV. Brief: Jul 21.
  • CVE-2026-15409/15410 (SonicWall SMA1000): INC ransomware exploitation continues via UTA0533. Federal deadline passed July 17. Brief: Jul 15.
  • Metabase Zero-Day: Framework, n8n, Tally, and Kilo Code confirmed breached. Exploitation ongoing since Aug 3. No CVE assigned. Brief: Aug 9.