Daily cybersecurity briefing

Top 10 Cybersecurity Stories for August 4, 2026

Immediate priority must be given to patching N-able N-central servers following CISA's KEV listing of an actively exploited authentication bypass. The broader landscape shows a critical trend in identity and supply chain risks, ranging from passkey hijacking in Google Password Manager to steganographic malware delivery via browser caches.

Compiled by the Slugnet Editorial System. Published Aug 4, 2026, 8:03 AM EDT

Audio briefing

Listen to this edition

A spoken version of today’s prioritized cybersecurity briefing.

The audio edition is not available yet.

  1. 01
    The Hacker News

    CISA Adds Exploited N-able N-central Flaw to KEV After Customer Compromises

    What happened

    CISA has added CVE-2026-18577 to its Known Exploited Vulnerabilities catalog following reports of active exploitation. This high-severity authentication bypass in N-able N-central allows unauthenticated remote attackers to gain administrative control over management servers.

    Why it ranks #1

    Confirmed active exploitation and inclusion in CISA KEV places this at the highest priority tier for immediate enterprise remediation.

    Who should care

    IT and platform operations, SOC and incident response teams

    What to do

    Apply N-able security updates to address CVE-2026-18577 immediately.

    Impact
    high
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    disclosed
    Read the original source Link to this ranking Share on Bluesky Share by email
  2. 02
    The Hacker News

    New cPanel Critical Flaw Could Let Hosting Customers Run SQL as Database Root

    What happened

    cPanel patched a critical vulnerability, CVE-2026-58048, which allowed authenticated hosting customers to execute SQL commands as the database root. This flaw enables attackers to cross privilege boundaries between individual accounts and the server's administrative identity.

    Why it ranks #2

    Critical severity (CVSS 9.4) in widely used enterprise web hosting infrastructure, though it requires authentication, placing it in tier two.

    Who should care

    Application security teams, IT and platform operations

    What to do

    Update cPanel to the latest targeted security release.

    Impact
    high
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    disclosed
    Read the original source Link to this ranking Share on Bluesky Share by email
  3. 03
    BleepingComputer

    New Pass-ta-key attacks let malware hijack Google-synced passkeys

    What happened

    Researchers discovered 'Pass-ta-key' attacks that allow malware on compromised Windows devices to hijack Google-synced passkeys. This enables attackers to bypass user verification and extract private keys from the Google Password Manager.

    Why it ranks #3

    High-impact vulnerability in a widely used identity and credential management system, affecting enterprise users of Chrome/Google ecosystem.

    Who should care

    Identity and access teams, SOC and incident response teams

    Impact
    high
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    disclosed
    Read the original source Link to this ranking Share on Bluesky Share by email
  4. 04
    SecurityWeek

    Decades-Old BMC Vulnerability Exposes Thousands of Data Centers to Attacks

    What happened

    A long-standing vulnerability in BMC server-management interfaces is exposing authentication hashes before login across approximately 24,000 internet-accessible data centers. This exposure facilitates unauthorized access to critical hardware management layers.

    Why it ranks #4

    Broad enterprise impact affecting thousands of data centers; however, it is a disclosure of existing exposure rather than a new zero-day exploit campaign.

    Who should care

    IT and platform operations, SOC and incident response teams

    What to do

    Audit internet-facing BMC interfaces and ensure they are behind VPNs or restricted access lists.

    Impact
    high
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    disclosed
    Read the original source Link to this ranking Share on Bluesky Share by email
  5. 05
    The Hacker News

    DOUBLECUP Uses ClickFix and Cached PNGs to Deliver CountLoader and DeviceManager RAT

    What happened

    The Russian loader-as-a-service DOUBLECUP is using 'ClickFix' lures to hide malicious code in browser cache PNG images. This technique delivers CountLoader and a new remote access trojan called DeviceManager to target systems.

    Why it ranks #5

    Active malware campaign utilizing novel steganographic delivery techniques, fitting tier three for threat-actor operations.

    Who should care

    SOC and incident response teams

    Impact
    high
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    disclosed
    Read the original source Link to this ranking Share on Bluesky Share by email
  6. 06
    The Hacker News

    18 Malicious npm Packages Deliver Cross-Platform RAT to Alibaba Tool Users

    What happened

    Eighteen malicious npm packages have been identified delivering a cross-platform RAT to users of Alibaba developer tools. The attack utilizes typosquatting, such as the 'lib-mtop' package, to compromise software supply chains in Chinese-speaking environments.

    Why it ranks #6

    Material supply-chain compromise targeting developers, though geographically focused on specific toolsets.

    Who should care

    Application security teams, SOC and incident response teams

    What to do

    Audit npm dependencies for unauthorized or typosquatted packages resembling Alibaba internal libraries.

    Impact
    high
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    disclosed
    Read the original source Link to this ranking Share on Bluesky Share by email
  7. 07
    SecurityWeek

    Gemini Agent-to-Agent Attack Method Exposed Secrets, Enabled Pull Request Tampering

    What happened

    A new attack method targeting Google ADK agents allows a low-privilege agent to pass malicious hand-off comments to a privileged agent via crafted prompts. This vulnerability can lead to the exposure of secrets and unauthorized tampering with pull requests.

    Why it ranks #7

    Novel AI-agent security flaw involving prompt injection and privilege escalation, highly relevant to emerging AI infrastructure risks.

    Who should care

    Application security teams, Cloud security teams

    Impact
    high
    Urgency
    near-term
    Confidence
    medium
    Scope
    enterprise
    Status
    disclosed
    Read the original source Link to this ranking Share on Bluesky Share by email
  8. 08
    Help Net Security

    Microsoft shortens NuGet API key lifetime to improve supply chain security

    What happened

    Microsoft is reducing the lifetime of new NuGet.org API keys from 365 days to 30 days starting August 17, 2026. This change aims to limit the window of opportunity for attackers using leaked keys in software supply chain attacks.

    Why it ranks #8

    Substantial defensive policy change with operational consequences for .NET developers and CI/CD pipelines.

    Who should care

    Application security teams, IT and platform operations

    What to do

    Update NuGet API key rotation schedules to align with the new 30-day limit before August 17.

    Impact
    low
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    disclosed
    Read the original source Link to this ranking Share on Bluesky Share by email
  9. 09
    Schneier on Security

    Some Claude Chats Are Searchable on Google

    What happened

    Private Claude AI conversations, including medical billing data and cryptocurrency wallet keys, have been indexed and made searchable on Google. The exposure is attributed to user data-sharing settings that make conversations public.

    Why it ranks #9

    Material data breach resulting from configuration errors in a widely used AI platform, though the root cause is user-driven.

    Who should care

    CISOs and security leaders, SOC and incident response teams

    What to do

    Review and enforce corporate policies regarding the sharing of sensitive data with LLMs and verify public sharing settings.

    Impact
    high
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    disclosed
    Read the original source Link to this ranking Share on Bluesky Share by email
  10. 10
    Help Net Security

    Uptime Kuma 2.5.0 waits two weeks before trusting a new npm package

    What happened

    Uptime Kuma version 2.5.0 has introduced a 14-day cooldown period before trusting new npm packages. This defensive measure is designed to mitigate the risk of immediate supply chain compromise from malicious package updates.

    Why it ranks #10

    Defensive research/implementation with clear operational consequences for software supply chain security.

    Who should care

    Application security teams, IT and platform operations

    Impact
    low
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    disclosed
    Read the original source Link to this ranking Share on Bluesky Share by email