Security.io Daily Headlines — Tuesday, August 4, 2026
Five equally weighted developments: what happened and the leadership decision each creates.
Listen to today’s episode
The audio matches the frozen transcript below.
Episode transcript
619 words · Sponsor after story threeThis is Max Vogal from Security.io with today’s Daily Headlines for Tuesday, August 4, 2026. Here are the top five security developments shaping today’s decisions—what happened, why each matters now, and the leadership action to consider.
N-central patch bypass turns one RMM server into many access paths
What happened
N-able and Huntress have confirmed active exploitation of CVE-2026-18577, an alternative path around an earlier N-central remediation. Attackers obtained administrative control, invoked Take Control against managed systems and established Cloudflare-based persistence. On August 2, 2026, the company identified an alternative exploitation path around the remediation for CVE-2026-18556 and issued CVE-2026-18577.
The leadership decision
Security leaders should inventory every hosted and self-hosted N-central instance. Assign a single incident owner to reconcile the N-central asset inventory, deployment model, build number, exposure path and customer or business-service dependency. Hosted customers should obtain confirmation of upgrade completion and timing from N-able or their MSP.
INC ransomware activity raises the bar for SonicWall SMA closure
What happened
Resecurity reports that INC Ransomware has become the dominant operator using the SonicWall SMA 1000 exploit chain, adding ransomware and extortion consequences to zero-day activity first disclosed in July. New incident-response reporting connects exploitation of two already patched SMA 1000 flaws with ransomware access, credential capture and extortion pressure.
The leadership decision
Security leaders should upgrade every affected SMA 1000 appliance. Direct network operations to prove firmware state and reconstruct external exposure from June 22 until remediation. Incident response should acquire appliance artefacts before replacement or reimaging, then review the published paths, malware names, /wsproxy behaviour and internal connections.
Liechtenstein ownership-register theft creates downstream identity risk
What happened
Liechtenstein’s government said attackers accessed its beneficial-ownership register and exfiltrated information concerning 31,000 entities. No alteration or deletion was identified. Attackers exfiltrated records covering 31,000 legal entities from a government register used for ownership transparency and financial-crime controls.
The leadership decision
Security leaders should identify business relationships represented in the register. Assign data protection and financial-crime teams to map customers, legal structures and beneficial owners potentially represented in the stolen dataset. Prioritise relationships involving high-value transactions, politically exposed persons or complex ownership arrangements without inferring that any listed party was individually targeted.
Amgen disclosure exposes a third-party cloud assurance gap
What happened
Amgen’s Form 8-K confirms unauthorised activity in externally hosted cloud environments and exfiltration of proprietary data, protected health information and other sensitive records. Amgen confirmed exfiltration of proprietary and patient information from cloud environments operated by unnamed external providers, while operational impact remains limited.
The leadership decision
Security leaders should identify equivalent third-party cloud data concentrations. Third-party risk teams should identify cloud processors holding both regulated personal information and high-value proprietary or research data. Require each relationship owner to document isolation, privileged-access controls, log availability, incident notification commitments and responsibility for evidence preservation.
Reported AI-managed proxyjacking campaign needs verification, not dismissal
What happened
Jesta reports observing an attacking system conducting 871 short SSH sessions, using supplied credentials and attempting to deploy MicroSocks proxies across a target list of 1,283 hosts. Jesta published huntable SSH and proxy-deployment behaviour from a five-day campaign, but its model identification, attribution and campaign scale remain uncorroborated.
The leadership decision
Security leaders should hunt for repeated single-command SSH sessions. Direct detection engineering to analyse SSH telemetry for high-frequency sessions with single-command execution, repeated reconnects and subsequent SOCKS5 activity. Correlate behaviour with account provenance, source infrastructure and endpoint process creation rather than using timing alone as proof.
That’s Security.io Daily Headlines for Tuesday, August 4, 2026. Full reporting, sources, executive actions and today’s comic are available in the complete edition at Security.io. I’m Max Vogal. Thanks for listening.