As cited
Copy frozen at (site build).
threat intel
10th August - Threat Intelligence Report
This threat intelligence bulletin covers major incidents from the week of August 10, including cyberattacks on North Carolina Ports and data breaches at Ryde (4.5 million accounts), Coinkite (1,367 bitcoin stolen via firmware vulnerability), and Beacon (1,500 nonprofit customers). The report also highlights critical vulnerabilities in Cisco SD-WAN and IOS XE, WordPress Core (XSS2Shell), and TP-Link Omada devices, plus emerging threats including AI-powered identity fraud kits, supply chain compromises of npm packages, and malware campaigns targeting macOS and financial institutions.
Why it matters: North Carolina Ports and Coinkite customers face operational disruption and direct financial loss; Ryde and Beacon customers should monitor for identity theft and fraud given exposed contact and donation data. Organizations using Cisco network products, WordPress, and TP-Link infrastructure must apply patches for critical privilege escalation and code execution vulnerabilities. Development teams relying on npm packages need to audit dependencies for backdoors from the Shai-Hulud CHAINDROP campaign affecting 1.3 billion monthly downloads. Financial services practitioners should harden voice authentication and MFA workflows against UNC6671's coworker impersonation tactics, and macOS users and administrators should block ClickFix malware domains.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
10th August - Threat Intelligence Report
This weekly threat intelligence bulletin covers breaches at North Carolina Ports and Ryde (4.5 million customer records), theft of $88.6 million in bitcoin from Coinkake hardware wallet users via a firmware vulnerability, and data compromises at UK charity software provider Beacon. The report also documents critical vulnerabilities in Cisco SD-WAN and IOS XE (CVSS 9.9), WordPress Core (CVE-2026-64638 XSS2Shell), TP-Link Omada devices, and Zbtlink routers with vendor-installed backdoors, alongside active supply-chain campaigns targeting npm packages and macOS systems.
Why it matters: North Carolina Ports, Ryde, and Coinkake customers should assess exposure from account compromise, payment card data, and cryptocurrency theft; enterprise security teams must patch Cisco, WordPress, and TP-Link systems immediately given critical severity scores and active exploitation; developers using npm packages face supply-chain infection risk from the Shai-Hulud CHAINDROP and WEL1DROPPER campaigns affecting billions of monthly downloads; financial institutions and macOS users are targeted by social engineering and malware distribution campaigns requiring credential controls and endpoint hardening.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
10th August - Threat Intelligence Report
This weekly threat intelligence bulletin covers breaches at North Carolina Ports and Ryde (4.5 million customer records), theft of $88.6 million in bitcoin from Coinkake hardware wallet users via a firmware vulnerability, and data compromises at UK charity software provider Beacon. The report also documents critical vulnerabilities in Cisco SD-WAN and IOS XE (CVSS 9.9), WordPress Core (CVE-2026-64638 XSS2Shell), TP-Link Omada devices, and Zbtlink routers with vendor-installed backdoors, alongside active supply-chain campaigns targeting npm packages and macOS systems.
Why it matters: North Carolina Ports, Ryde, and Coinkake customers should assess exposure from account compromise, payment card data, and cryptocurrency theft; enterprise security teams must patch Cisco, WordPress, and TP-Link systems immediately given critical severity scores and active exploitation; developers using npm packages face supply-chain infection risk from the Shai-Hulud CHAINDROP and WEL1DROPPER campaigns affecting billions of monthly downloads; financial institutions and macOS users are targeted by social engineering and malware distribution campaigns requiring credential controls and endpoint hardening.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
10th August - Threat Intelligence Report
This weekly threat intelligence bulletin covers breaches at North Carolina Ports and Ryde (4.5 million customer records), theft of $88.6 million in bitcoin from Coinkake hardware wallet users via a firmware vulnerability, and data compromises at UK charity software provider Beacon. The report also documents critical vulnerabilities in Cisco SD-WAN and IOS XE (CVSS 9.9), WordPress Core (CVE-2026-64638 XSS2Shell), TP-Link Omada devices, and Zbtlink routers with vendor-installed backdoors, alongside active supply-chain campaigns targeting npm packages and macOS systems.
Why it matters: North Carolina Ports, Ryde, and Coinkake customers should assess exposure from account compromise, payment card data, and cryptocurrency theft; enterprise security teams must patch Cisco, WordPress, and TP-Link systems immediately given critical severity scores and active exploitation; developers using npm packages face supply-chain infection risk from the Shai-Hulud CHAINDROP and WEL1DROPPER campaigns affecting billions of monthly downloads; financial institutions and macOS users are targeted by social engineering and malware distribution campaigns requiring credential controls and endpoint hardening.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
10th August – Threat Intelligence Report
This weekly threat intelligence bulletin covers breaches at North Carolina Ports and Ryde (4.5 million customer records), theft of $88.6 million in bitcoin from Coinkake hardware wallet users via a firmware vulnerability, and data compromises at UK charity software provider Beacon. The report also documents critical vulnerabilities in Cisco SD-WAN and IOS XE (CVSS 9.9), WordPress Core (CVE-2026-64638 XSS2Shell), TP-Link Omada devices, and Zbtlink routers with vendor-installed backdoors, alongside active supply-chain campaigns targeting npm packages and macOS systems.
Why it matters: North Carolina Ports, Ryde, and Coinkake customers should assess exposure from account compromise, payment card data, and cryptocurrency theft; enterprise security teams must patch Cisco, WordPress, and TP-Link systems immediately given critical severity scores and active exploitation; developers using npm packages face supply-chain infection risk from the Shai-Hulud CHAINDROP and WEL1DROPPER campaigns affecting billions of monthly downloads; financial institutions and macOS users are targeted by social engineering and malware distribution campaigns requiring credential controls and endpoint hardening.
- Source published
- First seen by Cybersecurity Tracker