Weekly Cyber Briefing 07.08.2026

Weekly Cyber Update: 7 August 2026

Hackers exploit N-central vulnerability; ChainDrop worm wreaks havoc across the software supply chain; prompt injection remains the biggest LLM risk; and utilities come under attack from Iran.

The Cyber Threat Intelligence Briefing is a weekly round-up of the latest cybersecurity news, trends and indicators, curated by our CISO, Nick Harris. Here’s our pick of the top stories, and why you should care


N-able warns authentication bypass bug is being exploited in attacks

N-able has urged customers to update their software after revealing its N-central remote monitoring and management (RMM) platform was targeted by hackers. The company released a hotfix (2026.3.1.7) on Sunday to address authentication bypass vulnerability CVE-2026-18577, which impacts hosted and on-premises versions of the tool. The firm has shared few other details so far except to confirm that the flaw is under active exploitation.

Why it matters

N-central is used by MSPs and corporate IT departments to manage countless endpoints, meaning the blast radius of a single compromise could be extensive. With RMM access, threat actors could move through environments, performing reconnaissance, achieving persistence, deploying malware, and stealing data.  

Assured’s recommended action

Audit for N-central use by the in-house IT department and any MSPs. Patch affected versions in line with vendor guidance where relevant. Hunt for signs of compromise including unusual admin activity, authentication logs, unusual scripts, and lateral movement indicators.


ChainDrop supply chain worm impacts packages with over two billion weekly installs

Security researchers have discovered a new npm worm modelled on the infamous Shai-Hulud campaign. It has already compromised over 430 packages with over two billion monthly installs between them. The credential-stealing malware is hidden in popular packages and designed to harvest npm and GitHub tokens, AWS credentials, Kubernetes secrets, HashiCorp Vault tokens, Stripe and Slack tokens, and perform a generic file system scan. Its worm-like capabilities enable it to spread to other maintainers and repositories via stolen npm and GitHub tokens.

Why it matters

CI/CD pipelines and developer environments are often a security blind spot for CISOs. The secrets ChainDrop steals could enable broader enterprise access to source code, cloud environments and other internal systems. It could also enable attackers to modify software builds with malicious code, increasing the reputational risk from distributing malicious software.

Assured’s recommended action

Security teams should identify and remove affected package versions from developer environments, rebuild affected systems, rotate exposed credentials and monitor published IoCs.

In the longer term, improve dependency governance via software composition analysis (SCA), version pinning, dependency scanning and other best practices. Update incident response plans to include possible compromise by a Shai-Hulud-style worm. Improve CI/CD security with short-lived credentials, least privilege and isolated/segmented environments.


Prompt injection is biggest LLM risk, says OWASP

Prompt injection has been named the most prominent LLM risk in the latest OWASP Top 10 report. This is the third year in a row the threat has been named as the number one risk, although actual incident reports are still relatively low. The National Cyber Security Centre (NCSC) warned in December that the prompt injection category may never be fully mitigated, and defenders should instead focus on reducing impact.

Why it matters

Prompt injection is effectively social engineering of AI. It can help attackers direct AI systems to do their bidding, whether it’s by directly feeding in malicious prompts or hiding instructions in content which they calculate an AI will interact with. It could result in anything from data theft and credential compromise to fraud, malicious code execution and unauthorised actions. The risks increase as AI becomes more privileged.

Assured’s recommended action

Defence in depth is key. Follow OWASP’s advice, which means designing surrounding systems on the assumption that prompt injection will occur. Limit what the model is permitted to do and what its outputs are allowed to reach so that “a successful injection does not translate into a successful exploit”.


Water utilities hit in suspected Iranian attack

Suspected Iranian threat actors have compromised water and wastewater utilities in at least a dozen US states. Attacks began at the end of July with a series of coordinated strikes against more than 30 water systems in Minnesota. Vulnerable programmable logic controllers (PLCs) from Rockwell Automation, Schneider Electric and Siemens were targeted, with hackers locking operators out of their own OT networks by modifying passwords and changing IP addresses.

Why it matters

PLCs in water utilities are frequently exposed directly to the internet with no authentication required; a problem that the sector has struggled to address for years. The FBI has confirmed flooding and water pressure loss in certain incidents, highlighting the real-world impact of attacks on utilities and their OT systems.

Assured’s recommended action

Audit exposed OT systems (including PLCs) and remove internet access where possible. Segment IT and OT networks and back up configurations offline. Follow best practices for identity and access management including strong, unique passwords, multi-factor authentication, and least privilege. Continuously monitor networks for anomalous behaviour.

Latest articles

Be an insider. Sign up now!