Welcome to Threat Thursday, Galactic’s weekly threat intelligence roundup.
Every Thursday, we cover the cybersecurity stories that matter most for protecting organizations from emerging threats, and we break each one down into what happened, what it could mean for your organization, and what to do about it.
The pattern this week is what attackers chose to aim at: the console you use to run every client, the appliance guarding the network edge, the vendor holding the data, and the administrator holding the passwords. Take one of those and the rest comes with it. A strong lock on one door counts for little once someone has a copy of the master key.
1. The Ransomware Crew Behind Last Week’s N-central Flaw Now Has a Name: CVE-2026-18577
Last week we flagged an authentication bypass in N-able N-central, the console MSPs use to manage client machines at scale, and warned that a fix on the server would not undo what attackers left on the endpoints below it. This week the group behind it has a name. Microsoft Threat Intelligence attributes the ransomware to Storm-1175, a financially motivated crew it links to China and to earlier Medusa ransomware operations, now deploying a new strain called StormEncryptor. Microsoft assesses the crew likely got in through the same flaw, CVE-2026-18577. Once on an N-central server, the attackers use its own remote-support feature to reach managed endpoints, pull credentials from memory with a tool called Mimikatz, steal data, and encrypt, sometimes moving from first access to ransomware within a few days.
Potential impact: An RMM console is the closest thing to a master key, which is exactly why this crew went for it. One compromised server can open the door to every organization behind it, turning a single break-in into dozens of ransomware incidents at once. Because the attackers plant their foothold on the managed machines rather than the console, updating N-central closes the entry point without removing anyone already inside. Neither N-able nor Huntress has put a number on how many downstream businesses were hit, and that count is likely still moving.
What to do: Move N-central to the latest hotfix, build 2026.3.1.10 or newer, and update the agents afterward, treating any server still on 2026.3 as exposed. Run N-able’s published indicators of compromise across the estate and hunt managed endpoints for the persistence the attackers leave, including unexpected Cloudflare tunnel services and stray files in user document folders. Pull authentication logs, admin account changes, and remote-session history back to the end of July, then rotate the credentials and keys the platform uses to reach client systems. Where you find persistence, treat that endpoint as compromised and investigate rather than deleting the service and moving on.
Sources: The Hacker News and BleepingComputer
2. Ransomware Is Exploiting a Top-Severity SonicWall VPN Flaw and Stealing the Secret Behind Login Codes: CVE-2026-15409
CISA confirmed on August 10 that ransomware gangs are exploiting two flaws in SonicWall’s SMA1000 remote-access appliances, the boxes that sit at the network edge and let staff connect in from outside. The more serious of the pair, CVE-2026-15409, carries the maximum severity score of 10.0. Rapid7 discovered the zero-days and observed actors pivoting into networks; Resecurity separately attributes the activity to INC Ransomware, though ransomware attribution is rarely settled. Along with credentials, the attackers copy the appliance’s active session records and the secret seeds behind multi-factor authentication, the shared values a phone app uses to generate login codes. Only the SMA1000 line is affected; SonicWall’s SMA 100 series and its SSL-VPN service are not.
Potential impact: Stealing the MFA seeds is what makes this worse than an ordinary appliance flaw. Those seeds are the shared secret a phone app uses to produce login codes, so an attacker who copies them can generate valid codes at will, and a stolen live session lets them return as a trusted user. Installing the patch closes the hole in the appliance, but it does nothing about seeds and sessions already taken. An organization can be fully up to date and still have an intruder holding working keys.
What to do: Patch affected SMA1000 appliances to the fixed builds, 12.4.3-03453 or later and 12.5.0-02835 or later, since there is no workaround. Then treat the patch as step one. Reset every credential the appliance handled, invalidate active sessions, and reissue the MFA seeds for affected accounts so the stolen ones stop producing valid codes. Review appliance and authentication logs for logins that satisfied MFA but arrived from unfamiliar locations, and warn staff about coercive calls and emails pressuring victims, a tactic this group has used to intensify extortion against organizations already under attack.
Sources: CISA via BleepingComputer and The Hacker News
3. Cisco’s Firewall Console Shipped With a Password Attackers Already Know: CVE-2026-20316
Cisco disclosed a flaw in its Secure Firewall Management Center, the console used to run several Cisco firewalls from one place, and CISA added it to its catalog of vulnerabilities under active attack. The problem, CVE-2026-20316, is a built-in account with a fixed password shipped inside the software, so a remote attacker who knows it can log in without any credentials of their own. On its own the account is low-privilege, but Cisco warns it can be paired with other flaws to gain deeper control, and severity ratings vary between Cisco’s own 5.3 and Horizon3.ai’s 8.9. A reference to /var/tmp/license.tmp in the device logs is a sign the flaw has been used.
Potential impact: A firewall management console decides what every firewall under it allows and blocks, so quiet access to it is quiet access to the rules protecting the whole network. A hard-coded password is a key the vendor shipped to everyone, attackers included, and no amount of good password practice on your side changes that. If the account has been used to reach further, the concern is not just the console but whatever an intruder did with the visibility and control it granted.
What to do: Apply Cisco’s hot fix, since there is no workaround, and check device logs for the license.tmp indicator. Because active exploitation is confirmed, Cisco recommends rotating all credentials, keys, and certificates the appliance stored, on the assumption they may already be exposed. Where the management interface is reachable from the internet, close that exposure so the built-in account cannot be reached from outside.
Source: BleepingComputer
4. Ransomware Reaches an On-Premises SharePoint Flaw, With Attackers Forging Their Own Keys: CVE-2026-45659
CISA confirmed on August 11 that ransomware groups are now exploiting a Microsoft SharePoint flaw, CVE-2026-45659, that Microsoft patched back in May. SharePoint is the server many organizations use to store and share internal documents, and this bug lets a user with only modest access run their own code on an unpatched on-premises server. The part worth noting is how attackers keep their foothold. They steal the server’s machine keys, the cryptographic secrets SharePoint uses to confirm that a request is trusted, which lets them forge valid access even after the patch lands. The flaw affects on-premises SharePoint Server; the Microsoft 365 cloud service is not in scope. A separate research team also disclosed a new SharePoint exploit chain the same day.
Potential impact: Stealing the machine keys turns a one-time break-in into lasting access, because forged requests signed with those keys look legitimate to the server. That is why patching alone can leave the problem in place: the fix stops the original entry, but the keys are already gone. For any client still running SharePoint on their own hardware rather than in Microsoft 365, this is an active ransomware route, not a theoretical one.
What to do: Confirm on-premises SharePoint servers carry Microsoft’s updates through at least the current month, since the fix for the newly disclosed chain arrived more recently than May. Where a server may have been exposed, rotate the machine keys so any stolen copies stop working, and hunt for persistence and unfamiliar administrative activity. Clients whose document storage lives in Microsoft 365 rather than on their own hardware are not affected by this one.
Source: The Hacker News
5. Amgen Says Patient Data Was Stolen From Cloud Systems It Trusted a Vendor to Run
Amgen, one of the largest biotechnology companies in the US, told regulators in an SEC filing that attackers stole data from cloud systems operated by outside providers, not from Amgen’s own network. The company detected the activity in July and found that proprietary information and patients’ protected health records had been taken. Amgen has not named the providers involved, said how the environments were breached, put a figure on those affected, or tied the theft to a known group, and it reported no disruption to its products or operations. There is no ransomware here, only quiet data theft.
Potential impact: The exposure lived somewhere Amgen did not run and could not directly watch, which is the uncomfortable part for anyone who hands data to a vendor. Responsibility for the records does not transfer with the storage; when the data leaks, it is still the original company’s patients and reputation on the line. Most organizations know where their own servers sit and have far less visibility into the third parties holding copies of the same information.
What to do: Map where regulated and sensitive client data actually lives, including the vendors and cloud services holding copies outside your direct control. For each of those third parties, confirm the basics you would expect on your own systems: multi-factor authentication, least-privilege access, and logging that someone reviews. Build the question of who is accountable when a vendor is breached into contracts and incident plans, before an incident forces the conversation.
Sources: Amgen SEC filing, via The Record and BleepingComputer
6. Russian Military Hackers Posed as Recruiters to Target the People Who Hold the Keys
Ukraine’s national cyber agency, CERT-UA, described a campaign that skips technology at the start and goes after people instead. A group tied to Russia’s military intelligence, tracked as Sandworm, spent about three months posing as recruiters on legitimate job sites, reviewing the resumes of system administrators and IT staff, and walking them through a convincing hiring process. The final step is a request to install a VPN tool for a technical assessment. The tool is a modified copy of WireGuard, a trusted open-source VPN, altered so that hidden commands ride inside its configuration file rather than the program itself, which helps it slip past inspection. CERT-UA has not disclosed the ultimate objective of the campaign, and Sandworm's history of destructive operations is worth keeping in mind as the story develops.
Potential impact: The target is the person holding the keys rather than the software guarding them. System administrators carry broad access by design, so convincing one to run something is often faster than breaking a lock. The campaign focuses on Ukraine, but the method travels. Any IT professional who has ever received VPN settings or onboarding software during a hiring process has been in the situation this abuses, and a fake recruiter costs far less to run than a zero-day.
What to do: Treat unsolicited recruitment that ends in installing software as a security event, and give technical staff an easy way to report it. Onboarding tools and VPN configuration files from an outside party deserve the same scrutiny as any untrusted download, checked and run on managed, monitored devices rather than personal machines. CERT-UA’s guidance is to keep corporate access on equipment protected by endpoint detection and continuous monitoring, so that one tricked employee cannot hand over a clear path inside.
Sources: CERT-UA, via The Record and BleepingComputer
The Big Picture
What connects this week's stories is what the fixes don't address. Patching the console doesn't remove the foothold the attackers planted on the machines below it. Patching the VPN appliance doesn't invalidate the MFA seeds already copied. Resetting a password doesn't revoke a session that's still active. The work worth prioritizing this week is an inventory of your own master keys, the platforms, credentials, and people that reach the rest of the estate, and a check that none of them have quietly changed hands.
Make sure to check back here each week for another Threat Thursday update. See you then!


