Cyber Digest
A daily roundup of key cybersecurity developments across sectors
Executive Summary
A Monday digest centred on active vulnerability exploitation, a large consumer-brand breach and a regulatory inflection point โ with the week's defining patterns (RMM/mgmt-appliance exploitation, automated financial credential theft) holding firm. First, N-able released Hotfix 2 for N-central as attackers who exploited CVE-2026-18577 (CVSS 8.2) continue reaching managed systems and establishing persistence โ escalating the week's theme of internet-exposed management-appliance exploitation. Second, a new study finds more than half of AI-generated security patches are broken, a cautionary finding for the AI-assisted remediation strategies many Australian and NZ programmes are trialling. Third, Levi Strauss disclosed a breach in which hackers accessed employee computers and corporate data โ a consumer-brand breach confirmed by first-party disclosure. Fourth, a coalition of US water utilities partnered with a DEF CON offshoot to launch the community-run Water Watch Center, extending the critical-infrastructure OT-defence theme.
The N-able N-central exploitation is directly relevant to Australian managed service providers, which rely heavily on RMM tooling to manage client endpoints โ a compromised RMM server grants attackers the same elevated access legitimate technicians use, so one compromised instance can expose many client environments. Australian MSPs running the platform should apply Hotfix 2 under the Essential Eight patching schedule and prioritise alerting on N-central server access. The AI-generated patch reliability finding matters for Australian enterprises and ASD/ACSC-referenced AI adoption: machine-suggested fixes still require human verification before production or OT deployment. CVE-2026-8037 in Progress Kemp LoadMaster (CISA KEV, 792 reported exploit attempts) is a Five Eyes-aligned warning for AU network teams running critical appliances exposed at the perimeter. ACSC has released no new advisories since the weekend; it continues to feature joint board-level guidance on frontier AI cyber threats and secure adoption of agentic AI in defence.
Today's digest tightens established weekly themes. Active exploitation in privileged management software extends the week's defining pattern โ the N-able second hotfix follows the Kemp LoadMaster KEV listing (CVE-2026-8037, CVSS 9.6, added after 792 exploit attempts) and sustained RMM/tooling targeting (including the Metabase CVSS 10.0 zero-day exploited against cloud and self-hosted instances); unattended patch velocity on internet-exposed management appliances remains the highest-yield control. The Levi Strauss breach and the persistent Microsoft 365 AitM payroll-phishing campaign (Arctic Wolf Labs) reinforce financially motivated targeting of corporate credentials and financial-role accounts, now a mainstream automated adversary play. The Water Watch Center connects directly to CISA's warnings about PLC-targeting in the Water and Wastewater Sectors โ community-driven OT defence is hardening in organised form. Across the week the convergence of RMM exploitation, AitM credential harvesting, AI-tooling reliability concerns, and critical-infrastructure OT defence confirms CISOs should prioritise patch velocity, phishing-resistant MFA, AI-remediation human review, and OT/ICS visibility heading into mid-August.
Incident Map
Global (Macro) 2 stories
N-able Issues N-central Hotfix 2 as Attackers Reach Managed Systems and Persist
N-able released a required second hotfix for N-central, superseding Hotfix 1 with additional hardening, as threat actors continue exploiting CVE-2026-18577 (CVSS 8.2) in the RMM product. The company detected unusual activity in a customer's environment on July 31, leading to discovery of an exploited zero-day impacting N-central server versions prior to 2026.3.1.7. N-able states Hotfix 2 is required even if the earlier hotfix was applied, reflecting continued monitoring of adversaries as they evolve techniques and establish persistence. **Verification: Verified** (vendor advisory + active-exploitation reporting).
More Than Half of AI-Generated Security Patches Are Broken, Study Finds
New research reports that more than half of AI-generated security patches are broken โ failing to remediate the vulnerability, introducing regressions, or breaking functionality. A cautionary signal for teams adopting AI-assisted vulnerability remediation, underscoring that machine-suggested fixes still require human verification before production or OT deployment.
- Metabase Zero-Day (CVSS 10.0) Exploited in Wild, Admin Access Without Authentication โ Maximum-severity flaw in Metabase business-intelligence software exploited as a zero-day; unauth remote SQL injection granting admin access, DB-credential theft and data export. Cloud updated; self-hosted must patch. (The Hacker News, 2026-08-08)
- Progress Kemp LoadMaster Flaw Added to CISA KEV After 792 Reported Exploit Attempts โ Critical command-injection (CVE-2026-8037, CVSS 9.6) in the load-balancer appliance added to KEV after active-exploitation reports; allows unauth remote code execution. (The Hacker News, 2026-08-08)
- Widespread Microsoft 365 AitM Phishing Harvests Payroll and Finance Emails โ Arctic Wolf Labs detailed an active AitM campaign using residential proxies and ~8-hour automated session maintenance, targeting financial-role staff across US/Canada/Europe; overlaps Payroll Pirate cluster (Storm-2755). (The Hacker News, 2026-08-07)
- Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer โ npm cluster (~800 packages) delivers cross-platform malware via a README trick loading a WEL1DROPPER downloader from Cloudflare Workers. (The Hacker News, 2026-08-07)
- New CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens โ PortSwigger Black Hat USA research: email content escaping its boundary interferes with Outlook/Gmail/Proton/etc.; PoC, not yet malicious exploitation. (The Hacker News, 2026-08-08)
Retail & Entertainment & Sport 1 story
Levi Strauss Says Hackers Breached Employee Computers, Accessed Corporate Data
Levi Strauss disclosed that hackers breached employee computers and accessed corporate data. **Breach Triage: Confirmed** โ the company disclosed the incident first-party (disclosure-check passed); it is a direct system compromise, not a circulating-dataset claim, so no combolist/recycled indicators apply.
Legal Services 0 stories
- New Mexico Judge Orders Meta to Pay $567 Million in Kids Online Safety Case โ A New Mexico judge ordered Meta to pay $567 million over its handling of minors' safety, a landmark state-level consumer-protection judgment with regulatory-precedent implications for platform duty-of-care and privacy enforcement. (The Record, 2026-08-07)
Energy & Utilities 0 stories
- Water Utilities Partner With DEF CON Offshoot for Community-Run 'Water Watch Center' โ A coalition of US water utilities partnered with a DEF CON offshoot to launch a community-driven monitoring initiative for the Water and Wastewater Systems Sector, responding to CISA warnings about PLC-targeting โ extending the OT-defence theme. (The Record, 2026-08-07)
Defence 0 stories
- Military Device Manufacturer Discloses Cyber Incident to SEC โ An unnamed military device manufacturer disclosed a cyber incident to the US SEC, a defence supply-chain disclosure with downstream implications for the defence industrial base. (The Record, 2026-08-07)
Government 0 stories
- US Cyber Ambassador Nominee Cassady Confirmed in Senate โ The US Senate confirmed Adam Cassady as US cyber ambassador, with implications for international cyber norms and Five Eyes cyber-cooperation relevant to Australia and New Zealand. (The Record, 2026-08-07)
Analytics
Source Reliability Index
| Tier | Label | Description |
|---|---|---|
| โ Tier 1 | Very High | Official / first-party |
| โ Tier 2 | High | Established cyber journalism |
| โ Tier 3 | Moderate | General tech/news media |
| โ Tier 4 | Low | Social / unverified |