[SecurityIntel] 06 Aug | CISA Warns of Exploited Langflow and Tomcat Flaws
SECURITYINTEL DAILY BRIEF ■ Threat Intel Brief Thursday, August 06, 2026 INTEL CONFIDENCE 100% THREAT LEVEL CRITICAL THREAT OF THE DAY CISA Warns of Exploited Langflow and Tomcat Flaws CRITICAL 5 C2 IPs 120 OTX IOCs 37 ARTICLES ■ ANALYST TLDR Today's intelligence landscape highlights critical vulnerabilities being actively exploited in the wild, including flaws in IBM Langflow, N-able N-central, and Apache Tomcat, prompting urgent CISA warnings. Additionally, threat actors are leveraging sophisticated tactics such as the "ClickFix" macOS campaign using browser fingerprinting to deliver malware, and "Pass-ta-key" attacks targeting Google's synchronized passkeys. Furthermore, supply chain and infrastructure threats persist with the discovery of the keyv/cacheable npm worm and ongoing cyberattacks on US water systems linked to Iranian actors. ■ CRITICAL STORIES INFO #1 CISA Warns of Exploited Langflow, N-central, and Tomcat Vulnerabilities CISA has added vulnerabilities in IBM Langflow, N-central, and Apache Tomcat to its Known Exploited Vulnerabilities (KEV) catalog, giving federal agencies only three days to patch. These flaws allow for remote code execution and authentication bypass, representing an immediate threat to enterprise infrastructure. INFO #2 Over 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Lures A highly sophisticated macOS ClickFix campaign is using browser fingerprinting to selectively serve infostealer malware only to valid targets. This technique allows threat actors to evade automated security scanners and sandbox environments, making detection significantly more difficult. CRITICAL #3 Veeam, Terraform MCP, Django Patch Critical Flaws, Led by CVSS 10.0 Cross-Tenant Bug Critical security patches have been released for Veeam Service Provider Console, Terraform MCP Server, and Django, addressing severe vulnerabilities including a CVSS 10.0 unauthenticated cross-tenant access bug in Veeam's console. Organizations must apply these updates immediately to prevent full administrative takeover. INFO #4 New Attack Methods Enable Malware to Hijack Passkey-Protected Accounts Palo Alto Networks researchers disclosed "Pass-ta-key" attacks capable of stealing master keys from Google's synchronized passkey implementation. This demonstrates that even passwordless authentication mechanisms remain vulnerable to local credential theft by infostealer malware. ■ CVEs IDENTIFIED [CVE-TBD] IBM Langflow — Remote Code Execution Critical [CVE-TBD] N-able N-central — Authentication Bypass Critical [CVE-TBD] Apache Tomcat — EncryptInterceptor Bypass / Remote Code Execution High [CVE-TBD] Veeam Service Provider Console — Unauthenticated Cross-Tenant Access (CVSS 10.0) Critical ■ THREAT ACTORS Salt Typhoon APT Chinese state- group maintaining a deep presence in US telecommunications infrastructure. Poipet Scam Network Cybercrime Cambodia-based scam operation utilizing ChatGPT to facilitate romance, investment, and law enforcement impersonation fraud. Ransom Cartel Cybercrime Ransomware group whose creator, Maksim Silnikau, was sentenced to 16 years in prison for attacking 18 companies. ■ ATT&CK TTPs T1190 Exploit Public-Facing Application | Hackers exploited SQL injection in Oracle database to run khunt toolkit; also used to exploit Langflow and Tomcat. T1204.001 User Execution: Malicious Link | ClickFix campaign using browser-fingerprinted domains to lure macOS users into downloading malware. T1195.002 Compromise Software Supply Chain | Trojanized npm packages (keyv/cacheable worm) executing on build hosts. T1566 Phishing | Kali365 using Microsoft device code phishing; COLDCARD phishing campaign distributing ScreenConnect RAT. T1068 Exploitation for Privilege Escalation | OVSwrap flaw in Linux Open vSwitch datapath used by local users to gain root. T1555 Credentials from Password Stores | "Pass-ta-key" attacks targeting Google synced passkeys to hijack accounts. ■ PATCH PRIORITY [P1 PATCH NOW] ≤24h Veeam — Unauthenticated cross-tenant access flaw (CVSS 10.0) in Service Provider Console — [THN] [P1 PATCH NOW] ≤24h IBM — Actively exploited Langflow RCE vulnerability — [BC] [P1 PATCH NOW] ≤24h N-able — Actively exploited N-central authentication bypass vulnerability — [BC] [P1 PATCH NOW] ≤24h Apache — Actively exploited Tomcat EncryptInterceptor bypass / RCE vulnerability — [BC] ■ RECOMMENDED ACTIONS TODAY 1 [P1] Patch the actively exploited vulnerabilities in IBM Langflow, N-able N-central, and Apache Tomcat immediately following the CISA KEV warning. 2 [P1] Apply critical security updates released for Veeam Service Provider Console to mitigate the CVSS 10.0 unauthenticated cross-tenant access vulnerability. 3 [P1] Update HashiCorp Terraform MCP Server and Django installations to their latest patched versions to resolve critical remote execution and bypass flaws. 4 [P2] Audit Linux environments utilizing Open vSwitch and apply kernel patches for the OVSwrap local privilege escalation flaw. 5 [P2] Implement technique-based browser detection and block device-code phishing flows (e.g., Kali365) to prevent unauthorized Microsoft session hijacking. LIVE IOC FEED C2 IP BLOCKLIST · AbuseCH Feodo · Showing 5 of 5 IP ADDRESS 162.243.103.246 PORT 8080 STATUS OFFLINE MALWARE Emotet COUNTRY US IP ADDRESS 50.16.16.211 PORT 443 STATUS ONLINE MALWARE QakBot COUNTRY US IP ADDRESS 34.204.119.63 PORT 443 STATUS OFFLINE MALWARE QakBot COUNTRY US IP ADDRESS 178.62.3.223 PORT 443 STATUS OFFLINE MALWARE QakBot COUNTRY GB IP ADDRESS 27.133.154.218 PORT 443 STATUS OFFLINE MALWARE QakBot COUNTRY JP FULL IOC EXPORT — GOOGLE SHEET All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs Updated daily · Export as CSV to import directly into your tools ■ Open Full IOC Sheet → IOC SOURCES: AbuseCH Feodo · AlienVault OTX NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB
SECURITYINTEL DAILY BRIEF
Thursday, August 06, 2026
INTEL CONFIDENCE 100%
CISA Warns of Exploited Langflow and Tomcat Flaws
Today's intelligence landscape highlights critical vulnerabilities being actively exploited in the wild, including flaws in IBM Langflow, N-able N-central, and Apache Tomcat, prompting urgent CISA warnings. Additionally, threat actors are leveraging sophisticated tactics such as the "ClickFix" macOS campaign using browser fingerprinting to deliver malware, and "Pass-ta-key" attacks targeting Google's synchronized passkeys. Furthermore, supply chain and infrastructure threats persist with the discovery of the keyv/cacheable npm worm and ongoing cyberattacks on US water systems linked to Iranian actors.
CISA Warns of Exploited Langflow, N-central, and Tomcat Vulnerabilities
CISA has added vulnerabilities in IBM Langflow, N-central, and Apache Tomcat to its Known Exploited Vulnerabilities (KEV) catalog, giving federal agencies only three days to patch. These flaws allow for remote code execution and authentication bypass, representing an immediate threat to enterprise infrastructure.
Over 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Lures
A highly sophisticated macOS ClickFix campaign is using browser fingerprinting to selectively serve infostealer malware only to valid targets. This technique allows threat actors to evade automated security scanners and sandbox environments, making detection significantly more difficult.
Veeam, Terraform MCP, Django Patch Critical Flaws, Led by CVSS 10.0 Cross-Tenant Bug
Critical security patches have been released for Veeam Service Provider Console, Terraform MCP Server, and Django, addressing severe vulnerabilities including a CVSS 10.0 unauthenticated cross-tenant access bug in Veeam's console. Organizations must apply these updates immediately to prevent full administrative takeover.
New Attack Methods Enable Malware to Hijack Passkey-Protected Accounts
Palo Alto Networks researchers disclosed "Pass-ta-key" attacks capable of stealing master keys from Google's synchronized passkey implementation. This demonstrates that even passwordless authentication mechanisms remain vulnerable to local credential theft by infostealer malware.
IBM Langflow — Remote Code Execution
N-able N-central — Authentication Bypass
Apache Tomcat — EncryptInterceptor Bypass / Remote Code Execution
Veeam Service Provider Console — Unauthenticated Cross-Tenant Access (CVSS 10.0)
Chinese state- group maintaining a deep presence in US telecommunications infrastructure.
Cambodia-based scam operation utilizing ChatGPT to facilitate romance, investment, and law enforcement impersonation fraud.
Ransomware group whose creator, Maksim Silnikau, was sentenced to 16 years in prison for attacking 18 companies.
Veeam — Unauthenticated cross-tenant access flaw (CVSS 10.0) in Service Provider Console — [THN]
IBM — Actively exploited Langflow RCE vulnerability — [BC]
N-able — Actively exploited N-central authentication bypass vulnerability — [BC]
Apache — Actively exploited Tomcat EncryptInterceptor bypass / RCE vulnerability — [BC]
■ RECOMMENDED ACTIONS TODAY
C2 IP BLOCKLIST · AbuseCH Feodo · Showing 5 of 5
FULL IOC EXPORT — GOOGLE SHEET
All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs Updated daily · Export as CSV to import directly into your tools
IOC SOURCES: AbuseCH Feodo · AlienVault OTX NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
