TL;DR
CISA added four critical vulnerabilities to its Known Exploited Vulnerabilities catalog with three-day federal remediation deadlines: IBM Langflow (unauthenticated RCE), Apache Tomcat (encryption bypass), and two N-able N-central authentication bypasses. Ransom Cartel creator sentenced to 16 years; Snowflake attacker pleads guilty to breaches affecting 165 organizations.
Executive Summary
- CISA designated four vulnerabilities as actively exploited, issuing federal remediation orders with deadlines as near as August 7, 2026.
- IBM Langflow CVE-2026-9198 enables unauthenticated remote code execution on default deployments; Apache Tomcat CVE-2026-34486 bypasses encryption protections.
- N-able N-central suffered two related authentication bypass vulnerabilities (CVE-2026-18556 and CVE-2026-18577), the latter a bypass of an incomplete patch.
- Criminal prosecutions advanced: Ransom Cartel creator sentenced to 16 years for attacks on 18+ companies; Snowflake attacker pleads guilty to breaches affecting 165 organizations.
- macOS ClickFix campaign expanded to over 250 domains, now using browser fingerprinting to evade detection.
Top Threats Today
1. Four Critical Vulnerabilities Added to CISA KEV with Active Exploitation
Severity: CRITICAL Affected: Government
IBM Langflow CVE-2026-9198 contains a code injection vulnerability allowing unauthenticated attackers to achieve full remote code execution on default deployments [1][4]. Apache Tomcat CVE-2026-34486 is a missing encryption of sensitive data vulnerability that enables bypass of the EncryptInterceptor [1][3]. N-able N-central suffers two authentication bypass flaws: CVE-2026-18556 and CVE-2026-18577, the latter identified as an incomplete patch of the former, both allowing account takeover [1][2][5]. CISA confirmed all four vulnerabilities are actively exploited in the wild and issued federal remediation deadlines of August 7, 2026 for the Langflow and Tomcat ⚠ flaws, and August 6 for the first N-central issue [1][2][3][4][5].
Sources:[1] BleepingComputer[2] CISA KEV[3] CISA KEV[4] CISA KEV[5] CISA KEV
Recommended Action
- Federal agencies and critical infrastructure operators must prioritize patching IBM Langflow, Apache Tomcat, and N-able N-central immediately; consult vendor advisories for patch versions.
- For Langflow: disable or restrict unauthenticated access until patches are applied.
- Monitor for exploitation attempts in server logs and network traffic; segment Langflow and Tomcat instances from the wider network.
2. Snowflake Attacker Pleads Guilty; 165 Organizations Compromised
Severity: HIGH Affected: Technology
A 26-year-old Canadian pleaded guilty to fraud, identity theft, and conspiracy charges related to accessing Snowflake customer accounts and stealing data from at least 165 organizations in an extortion scheme [1][2]. The attacker exploited authentication weaknesses to breach multiple Snowflake tenants and extract customer data for extortion purposes ⚠[1].
Sources:[1] BleepingComputer[2] The Record
Recommended Action
- Snowflake customers should verify MFA enforcement on all service accounts and rotate credentials for compromised tenants.
- Review Snowflake query logs and network access logs for unauthorized activity dating back to 2024.
- Engage legal and incident response teams if your organization was among the 165 breached; monitor for extortion demands.
3. Ransom Cartel Creator Sentenced to 16 Years; 18+ Companies Targeted
Severity: HIGH Affected: Government
Maksim Silnikau, the creator and administrator of the Ransom Cartel ransomware operation, was sentenced to 16 years in prison for ransomware attacks against at least 18 companies worldwide [1]. The conviction represents a significant law enforcement win against a major ransomware-as-a-service operator.
Sources:[1] BleepingComputer
Recommended Action
- Review past incident reports and threat intelligence feeds for Ransom Cartel indicators of compromise; assess whether your organization was targeted.
- Verify backup integrity and test recovery procedures to ensure readiness against ransomware variants still in circulation.
- Monitor for any continued use of Ransom Cartel infrastructure under new operators or aliases.
4. ClickFix Malware Campaign Expands to 250+ Domains with Browser Fingerprinting
Severity: HIGH Affected: Technology
A macOS ClickFix operation now spans over 250 front-end domains and uses server-side browser fingerprinting to selectively show malware lures only to legitimate visitors, hiding the malicious pages from security scanners and crawlers [1]. Microsoft Threat Intelligence tracked this evasion technique on infrastructure it had been monitoring for weeks, indicating an increase in operational sophistication [1].
Sources:[1] The Hacker News
Recommended Action
- macOS users should disable JavaScript execution in browsers for untrusted sites and enable browser-based security notifications.
- Educate staff on ClickFix tactics: fake “security update” prompts requesting manual action; legitimate OS updates never prompt during web browsing.
- Monitor for suspicious browser extensions or installed applications; use endpoint detection and response (EDR) tools to identify infections.
5. Veeam and HashiCorp Patch Critical Flaws; Django Updates Released
Severity: HIGH Affected: Technology
Veeam, HashiCorp, and the Django Software Foundation released patches for 11 critical vulnerabilities [1]. Veeam Service Provider Console contained an unauthenticated flaw rated CVSS 9.5 that hands over managed agent credentials [1]. A Terraform MCP Server flaw was rated CVSS 10.0 as a cross-tenant vulnerability allowing unauthorized access to other customers’ infrastructure [1].
Sources:[1] The Hacker News
Recommended Action
- Veeam customers using Service Provider Console must apply the credential-exposure patch immediately; audit backup agent communications for unauthorized access.
- HashiCorp users must update Terraform MCP Server to the patched version and verify tenant isolation is enforced; review access logs for cross-tenant queries.
- Django application maintainers should apply the latest security updates from the Django Software Foundation.
Ongoing Threats
- TP-Link Omada RCE and related vulnerabilities: Previously reported August 5; no new developments disclosed today.
- Google Password Manager passkey hijacking and an unattributed threat actor activity: Previously reported August 4; no new victim disclosures or escalations today.
Today’s Action Checklist
- ☐ URGENT: Verify patches applied for IBM Langflow CVE-2026-9198, Apache Tomcat CVE-2026-34486, and N-able N-central CVE-2026-18556 & CVE-2026-18577; federal deadline is August 7, 2026.
- ☐ URGENT: Review Snowflake MFA and credential settings; rotate service account passwords if your organization appears in breach notifications.
- ☐ Review Veeam backup console access logs and apply credential-rotation patch; test backup recovery procedures.
- ☐ Audit macOS and cross-platform endpoints for ClickFix-related malware; block 250+ known ClickFix domains at firewall if known.
- ☐ Confirm HashiCorp Terraform MCP Server patch deployment; verify tenant data isolation using access logs.