This briefing covers 20 cybersecurity and geopolitics
stories published around Tuesday, August 4, 2026,
including activity involving APT29, Russia,
and 8 disclosed vulnerabilities
(CVE-2026-18556, CVE-2026-18577, CVE-2026-18685, CVE-2026-18686 and others).
Each entry links to the original reporting.
Microsoft attributes a global hotel Wi-Fi compromise campaign to Russian state-sponsored APT29, targeting travelers' login credentials and infecting devices with espionage malware.
Microsoft links Midnight Blizzard (APT29) to a global campaign using custom malware on hospitality Wi-Fi networks to breach Microsoft 365 accounts. Targeting cloud identity infrastructure through physical network access marks an operational expansion that threatens enterprise credential stores at scale.
Russian intelligence operatives weaponized hotel captive portal systems to deploy keyloggers, audio-visual surveillance tools, and session-token stealers against travelers. The hospitality sector now faces nation-state-grade intrusion infrastructure embedded in routine guest network access points.
An unattributed Chinese-speaking threat actor ran 100-plus fake AWS sign-in pages using the leaked DarkSword exploit kit to deliver GHOSTBLADE malware targeting Apple iOS devices. Weaponizing publicly leaked exploit kits against mobile users lowers the barrier for iOS-targeted espionage and complicates attribution.
European NATO members remain divided on deploying integrated air defense systems as Russia sustains ballistic missile campaigns against Ukrainian cities.
The Trump administration declined to renew USMCA at its July 1 review, using trade leverage to force economic-security concessions from Mexico and Canada targeting Chinese market access.
Tehran denied ongoing nuclear negotiations after the Trump administration canceled planned military strikes, leaving the administration's promised 'imminent' deal in limbo. Iran's public rejection signals it is exploiting U.S. hesitation to harden its negotiating posture and buy time on the nuclear timeline.
Researchers identified 18 npm packages impersonating Alibaba tools โ including 'lib-mtop' โ delivering a cross-platform RAT in a supply chain attack aimed at Chinese-speaking developer environments.
Russian loader-as-a-service DOUBLECUP uses ClickFix lures to stash malicious code inside browser-cached PNG files, delivering CountLoader on Windows and macOS and the new DeviceManager RAT on Windows.
A cyberattack exfiltrated 31,000 records identifying individuals behind Liechtenstein companies, foundations, and trusts, triggering a government crisis unit. Exposure of beneficial ownership data provides adversaries a roadmap for sanctions evasion, blackmail, and financial intelligence.
CISA added CVE-2026-18577 โ an authentication bypass and account takeover flaw in N-able N-central stemming from an incomplete fix for CVE-2026-18556 โ to the Known Exploited Vulnerabilities catalog.
CISA added CVE-2026-18577 (CVSS 8.2), a patch bypass for CVE-2026-18556, to its KEV catalog after confirmed active exploitation against N-able N-central customers. RMM platform compromises grant attackers broad downstream access to managed service provider client networks.
Threat actors bypassed N-able's patch for CVE-2026-18556 via CVE-2026-18577, achieving active exploitation of N-central servers before a fix was issued. Repeated patch bypasses on RMM platforms expose entire MSP client bases to cascading compromise.
CVE-2026-18686 allows remote command injection via the nas-web RPC wrapper in GL.iNet GL-MT3000 firmware through 4.4.5, with a public exploit now available. Edge router compromise enables network pivoting and persistent access to downstream infrastructure.
CVE-2026-18685 enables remote command injection through the set_upgrade function in GL.iNet GL-MT3000 firmware up to 4.4.5, with the exploit publicly disclosed. Paired with CVE-2026-18686, two concurrent public exploits against the same device model significantly raise the attack surface for network-edge compromise.
CVE-2026-48333 (CVSS 9.8) in Adobe Campaign Classic allows unauthenticated privilege escalation via incorrect authorization, requiring no user interaction. Full privilege access to ACC exposes campaign data, customer PII, and integrated marketing infrastructure at enterprise scale.
CVE-2026-48330 in Adobe Campaign Classic permits SQL injection leading to arbitrary code execution without user interaction. Combined with co-disclosed ACC vulnerabilities, attackers have multiple no-interaction paths to full platform compromise.
CVE-2026-48323 (CVSS 10.0) in Adobe Campaign Classic allows arbitrary code execution via template engine injection with changed scope and no user interaction required. A perfect-score, no-interaction RCE in widely deployed enterprise marketing software represents an immediate mass-exploitation risk.
CVE-2026-48317 in Adobe Campaign Classic allows a low-privileged attacker to execute arbitrary code via eval injection with no user interaction and changed scope. Low privilege requirements dramatically widen the exploitable attacker population across ACC deployments.
Attackers exploited CVE-2026-18577, a second authentication bypass vector discovered over the weekend, to gain administrator access to N-able N-central RMM servers. Administrator-level RMM access is a tier-one supply chain threat, enabling lateral movement into every client environment managed through the platform.