W1RETAP Intel Report — 2026-08-10
W1RETAP INTEL REPORT
2026-08-10
================================================================
SEVERITY: 6/10 — ELEVATED
Justification: Three separate critical-severity CVEs (Metabase, TeamCity, N-able N-central) are under active exploitation this week, a U.S. critical infrastructure operator (North Carolina Ports) was disrupted by a cyberattack, and ransomware volume hit its second-busiest month on record, together pushing the day above routine patch-cycle noise without rising to a confirmed mass-casualty single event.
TOP STORY:
CISA and JetBrains confirmed active exploitation of CVE-2026-63077, a critical deserialization flaw in TeamCity (CVSS 9.8) that lets an unauthenticated attacker with network access to a TeamCity server bypass authentication and execute arbitrary code. TeamCity servers sit at the center of software build and CI/CD pipelines, meaning compromise can cascade into source code theft or supply chain poisoning. CISA added the flaw to its Known Exploited Vulnerabilities catalog and set August 8, 2026 as the federal patch deadline, which has now passed. Any organization running an internet-facing TeamCity instance should treat this as urgent.
BREACHES & INCIDENTS:
The North Carolina Ports Authority confirmed a cyberattack detected August 4 that disrupted IT systems and forced manual cargo and gate processing at the Port of Wilmington, Port of Morehead City, and the Charlotte Inland Port. The U.S. Coast Guard and state officials are assisting the investigation. Normal gate schedules resumed August 6, though some systems were still being processed manually as of this week, and the ports authority has not disclosed the attacker, initial access method, or whether customer data was exposed.
Levi Strauss & Co. disclosed that hackers used social engineering against three employees to gain access to internal systems and steal corporate data. In the UK, multiple charities have confirmed data theft tied to a breach at CRM vendor BeaconCRM, with more victims expected to come forward in coming days. Hyundai Motor Türkiye was hit by the CRPx0 ransomware group. Separately, a 26-year-old Canadian man pleaded guilty to computer fraud for hacking and extorting more than 165 organizations through compromised Snowflake cloud accounts, admitting to stealing call and text records for more than 100 million AT&T customers, closing out one of the more consequential breach cases of the past two years.
Ransomware volume climbed roughly 20 percent in July to 799 tracked incidents, the second-busiest month on record after March, according to Comparitech. Fresh claims this week include the Helix group against Canadian real estate firm Morguard, Everest against Allied Telesis in Japan, SafePay against Nask Door, and Dark Project against Brainhunter Companies.
VULNERABILITIES & EXPLOITS:
Metabase disclosed a maximum-severity SQL injection flaw (CVSS 10.0) that was exploited in the wild as a zero-day, allowing unauthenticated attackers to inject arbitrary SQL and pull data from hosted customer instances; Framework and Tally are among the confirmed affected downstream services. CISA also added CVE-2026-18577, an authentication bypass in N-able N-central, to its KEV catalog after confirming it was used to pivot from RMM servers into managed customer endpoints, a serious concern for MSPs and their downstream clients. A Progress Kemp LoadMaster vulnerability has now logged 792 exploitation attempts over 41 days from 65 unique IP addresses and was likewise added to KEV. On the lower-severity side, WordPress patched a pre-authentication reflected XSS flaw in its login screen (CVE-2026-64638, CVSS 8.9) affecting every version of the CMS.
TOOLS & TECH:
Kali Linux 2026.2 shipped with nine new tools for penetration testers, including arsenal-ng, hydra-gtk, legba, and shell-gpt, broadening brute-force and AI-assisted shell capabilities available out of the box. The prior 2026.1 release added MetasploitMCP, a Model Context Protocol server built to let AI agents drive Metasploit workflows directly, alongside AdaptixC2 and SSTImap — a clear sign offensive tooling is being wired directly into AI agent interfaces. On the defensive-turned-offensive side, two independent security firms found that attacker-controlled prompt injection can manipulate Atlassian's Rovo AI assistant into collecting Jira or Confluence data a signed-in user can access and exfiltrating it to an outside server, adding embedded AI assistants to the list of exploitable attack surfaces.
U.S. GOVERNMENT CYBER MOVES:
CISA has been active all week: it added N-able N-central (CVE-2026-18577) and the Progress Kemp LoadMaster flaw to its Known Exploited Vulnerabilities catalog, flagged the TeamCity RCE with a since-passed federal remediation deadline, and issued several new ICS and ICS-Medical advisories (ICSA-26-219-01, ICSA-26-218-01, ICSA-26-218-02, ICSA-26-216-01, ICSMA-26-218-01, ICSMA-26-216-01) covering industrial and medical device flaws. CISA also released guidance specifically warning that threat actors are targeting U.S. municipal water systems "of all sizes." The Coast Guard is actively monitoring and assisting the North Carolina Ports response as a critical infrastructure incident. On the policy side, Senator Mark Warner has proposed legislation that would force CISA to update critical infrastructure cybersecurity plans to account for AI-driven threats. Former NSA cybersecurity directors Rob Joyce and Dave Luber went public this week warning that AI-enabled automation is letting attackers probe for gaps around the clock, and that AI may soon let adversaries weaponize newly disclosed flaws so fast that organizations will need to rethink standard patch timelines.
TRENDS TO WATCH:
AI is reshaping both sides of the fight at once: offensively, automation is compressing the gap between vulnerability disclosure and mass exploitation, prompting former NSA officials to question whether traditional patch-and-test cadences are still safe; defensively and organizationally, AI assistants embedded in everyday tools like Atlassian Rovo are emerging as a new class of attack surface via prompt injection, while offensive frameworks like Metasploit are themselves being fitted with MCP interfaces so AI agents can drive exploitation directly. Layer on record ransomware volume in July and continued critical-infrastructure disruptions like the North Carolina ports incident, and the throughline for defenders is that both attack speed and attack surface are expanding simultaneously.
--
Report window: news gathered from roughly August 8-10, 2026. Compiled via automated search of Krebs on Security, BleepingComputer, The Hacker News, Dark Reading, CISA.gov, The Record, and SecurityWeek, among others.