Cyber security developments for Saturday the 1st of August 2026 covering articles added to the BlueTeamSec community on infosec.pub. Today we have 16 articles to cover. All attribution is by the article authors. All article analysis is automated.
Amazon Threat Intelligence have attributed a wave of open-source supply chain attacks to a North Korean group they track as SAPPHIRE SLEET. The attackers compromised maintainers of popular npm packages including axios and chalk through social engineering, then pushed out multi-stage payloads with sophisticated obfuscation. Approximately 10% of cloud environments were affected within hours, which gives you some sense of just how widely these dependencies are deployed.
On a similar note, Socket documented a malicious npm package campaign targeting Web3 developers on macOS. The package masquerades as an AI tool, drops a large obfuscated binary via a post-install script, and sets up persistent backdoor access polling command-and-control every 60 seconds. The attacker has re-published under new scopes after takedowns, and the infrastructure remains active.
And another supply chain incident, this time affecting Joyfill's npm beta release pipeline. Threat actors injected malicious code into two specific beta versions that delivers a remote access trojan and infostealer. The malware retrieves payloads via blockchain infrastructure and tampers with developer tools like VS Code and Discord Desktop to persist, turning development environments into entry points for broader network access.
OpenSourceMalware covered the PolinRider campaign, which compromised dozens of packages across npm, Go, and PHP ecosystems through supply chain attacks. The operation represents a significant cross-language threat, though the write-up itself is light on technical detail.
Kevin Beaumont reported that Adform, an advertising tech company with 30% market share, was compromised in a supply chain attack that injected crypto-stealing code into their legitimate scripts. The malware performed clipboard hijacking to steal wallet addresses from users visiting around 14,000 downstream websites that use Adform's services. It went undetected for at least a week, which is not ideal given the footprint.
Google Threat Intelligence documented a significant uptick in software supply chain compromises through mid-2026, involving multiple threat actors targeting PyPI, npm, and Docker Hub. Attackers compromised popular packages like axios, which has over 100 million weekly downloads, and the Notepad++ distribution infrastructure. Some campaigns used AI coding agents to inject malicious dependencies, which is either impressive tradecraft or a sign that attack automation is getting uncomfortably sophisticated.
CISA, NSA, FBI, and international partners released updated 2026 guidance defining mandatory baseline elements for Software Bill of Materials. The update replaces the 2021 NTIA guidance and modernises requirements to reflect current tooling and ecosystem needs, with notes that AI and SaaS environments may require additional transparency. One for procurement and compliance teams.
AhnLab's security team identified Operation Double Barrel, a campaign from 2025 through mid-2026 where a state-backed group and the Gunra ransomware group exploited vulnerabilities in South Korean financial security software. Both groups shared infrastructure, SSH keys, and malware including watering hole attacks that appear to stem from a suspected supply chain compromise of a web management vendor. The report appears twice in today's queue from the same source, so treat them as a single item.
Palo Alto Networks documented a Chinese-speaking threat actor using the aliases 'knaithe' and 'KnYuan' who deployed an autonomous AI-driven attack framework called Hermes Agent powered by DeepSeek. The actor successfully compromised three organisations via Citrix NetScaler and 11 Marimo notebook instances, though the autonomous AI component was largely unsuccessful. The operation was exposed when the AI agent created an unprotected HTTP server that revealed the actor's logs, tools, and workspace, which is a somewhat ironic ending.
AllSecure documented a campaign attributed to actors from the Democratic People's Republic of Korea combining ClickFix social engineering with a technique called EtherHiding that leverages Ethereum smart contracts for command-and-control infrastructure. The operation targets macOS hosts and demonstrates advanced tradecraft, including blockchain-based infrastructure that's resilient to traditional takedown methods.
InfraWatch identified a network of approximately 73,000 servers operating as unauthorised intermediaries that enable Chinese users to bypass regional restrictions and access Western frontier AI models from OpenAI, Anthropic, and Google. These transfer stations use open-source proxy projects to forward requests and facilitate payments through local methods like Alipay and WeChat Pay. Around a third of the infrastructure is hosted on Chinese cloud providers, and the setup poses data retention risks as operators must parse prompts and responses for billing purposes.
Anthropic disclosed three incidents during AI cybersecurity capability testing where models inadvertently compromised real-world production systems due to a misconfiguration at third-party evaluator Irregular that connected supposedly isolated environments to the live internet. The incidents resulted in credential exfiltration, database access containing production data, and a malicious PyPI package that compromised 15 real systems including a security scanner. This develops the situation we reported on earlier this week concerning the Hugging Face intrusion.
Huntress SOC identified a widespread credential stuffing campaign targeting SonicWall VPNs and firewalls beginning July 25th. At least 30 organisations were affected by the 27th, with automated attacks originating from five IP addresses registered to DigitalOcean, systematically testing stolen credentials against remote access portals. Flag this if you're running SonicWall remote access infrastructure.
The FBI and EPA issued an alert concerning attacks on internet-exposed programmable logic controllers in the water and wastewater sector. Since July 27th, malicious actors have been exploiting Rockwell Automation Allen-Bradley controllers in at least seven U.S. states, gaining unauthorised remote access and modifying configurations and ladder logic. This has caused operational disruptions including loss of water pressure and flooding at utility facilities. The agencies recommend immediately removing these controllers from public internet exposure.
Silent Push released Danglegeddon, research identifying risks in dangling DNS infrastructure where DNS records point to unclaimed or expired cloud resources, creating potential for subdomain takeover attacks. The initiative provides technical methods for identifying vulnerable dangling DNS entries and outlines defensive strategies to detect and remediate these misconfigurations before attackers can exploit them.
That concludes today's briefing.