Aug 10, 2026 · Covering Aug 3, 2026 – Aug 9, 2026

This Week in Threats: August 3–August 9, 2026

Active exploitation of critical vulnerabilities, supply chain attacks, and credential-hijacking phishing campaigns dominated the threat landscape this week.

weekly-reportHead MareUNC6671FulcrumSecUNC5537UNC6353

Overview

This week saw widespread exploitation of critical vulnerabilities in widely used software, including Metabase and Kemp LoadMaster, alongside large-scale supply chain attacks on npm. Credential-hijacking phishing campaigns targeting Microsoft 365 users and breaches impacting millions underscored ongoing risks to both public and private sector organizations.

Active Threat Actors

Head Mare, a hacktivist group, breached unpatched TrueConf video conferencing servers to replace legitimate installers with trojanized versions delivering backdoors Hackers breach TrueConf to trojanize client installers with backdoors. TeamPCP, active since at least 2020, evolved from exploiting exposed Redis and Docker infrastructure to conducting supply chain attacks using overlapping infrastructure and tradecraft TeamPCP Linked To Redis Attacks Dating Back To 2020 And Later Supply Chain Campaign.

Notable Malware

PhantomCore, a backdoor used by Head Mare, was deployed via trojanized TrueConf installers to collect victim information including public IP addresses Hackers breach TrueConf to trojanize client installers with backdoors. A large-scale npm supply chain campaign distributed nearly 800 malicious packages delivering a cross-platform RAT and infostealer, with payloads fetched via a downloader named WEL1DROPPER Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer. The ChainDrop malware, based on the SharpStealer variant, infected over 1,300 npm packages after compromising the Keyv maintainer’s GitHub account Massive ChainDrop npm supply-chain attack infects hundreds of packages.

Key CVEs & Campaigns

CVE-2026-8037, a critical command injection vulnerability in Progress Kemp LoadMaster, was added to CISA’s Known Exploited Vulnerabilities catalog after 792 exploit attempts were observed Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit Attempts. N-able released a hotfix for CVE-2026-18577, a critical authentication bypass in its N-central RMM product actively exploited to achieve remote administrative access N-able Issues N-central Hotfix 2 as Attackers Reach Managed Systems and Persist. A zero-day SQL injection vulnerability in Metabase versions 1.58 and above was exploited to gain unauthenticated administrator access, leading to data theft at Framework, Tally, and a LexisNexis vendor Metabase SQLi zero-day exploited in customer data-theft attacks and Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication. A massive npm supply chain attack, dubbed ChainDrop, compromised over 1,300 packages via poisoned CI/CD workflows Massive ChainDrop npm supply-chain attack infects hundreds of packages. An adversary-in-the-middle (AitM) phishing campaign targeted Microsoft 365 users to hijack accounts and harvest payroll and finance emails Microsoft 365 AitM Phishing Hijacks Accounts to Collect Payroll and Finance Emails.

Sources