Threat Brief — 2026-08-03 — Actively Exploited Edge Appliances and a 100K-Officer Leak
Executive summary. Today's highest-impact items centre on externally exposed infrastructure: a critical unauthenticated RCE in OpenWrt's DHCPv6 server and INC Ransomware cementing its position as the dominant exploiter of SonicWall SMA 1000 zero-days. A breach at the UK's Police National Legal Database has exposed contact data for over 100,000 officers and criminal-justice staff. On the supply-chain side, NPM has tightened package-upload rules and a five-year-old logic bug in a Nuclei template library has surfaced.
Top items
- OpenWrt DHCPv6 unauthenticated root RCE. A critical flaw in the OpenWrt DHCPv6 server allows an unauthenticated attacker to achieve root-level code execution, potentially fully compromising the router. Patches are now available. Any OpenWrt deployment exposing DHCPv6 to untrusted networks should update immediately. (src: Xakep)
- INC Ransomware now dominant actor exploiting SonicWall SMA 1000 flaws. Resecurity reports INC Ransomware has become the primary threat actor weaponising the recently disclosed SonicWall Secure Mobile Access 1000-series vulnerabilities for root access. This is a genuine development in an ongoing story first reported 2026-07-17 by Dark Reading. (src: The Hacker News) — first reported 2026-07-17 by Dark Reading
- ExfilSquad leaks data of 100K+ UK police officers. A cyberattack on the UK's Police National Legal Database (PNLD) has compromised contact details of more than 100,000 police officers and criminal-justice professionals, with data appearing on the dark web. The scale makes this one of the largest law-enforcement personnel breaches on record. (src: BleepingComputer)
- Android BTMOB RAT underground ecosystem mapped. Flare researchers analysed thousands of underground forum posts revealing BTMOB Android malware has evolved into a fragmented ecosystem of resellers, source-code vendors, custom builds, and competing sales channels. The commoditisation lowers the barrier to deploying capable Android surveillance tooling. (src: BleepingComputer)
- NPM tightens package-upload security rules. NPM has converted package uploads into a rigorous security review process, defaulting to suspicion and enforcing strict safety rules that constrain author freedom. This represents a significant supply-chain hardening step for the JavaScript ecosystem. (src: SecurityLab)
- Five-year-old bug in Nuclei Blackrock library found. CyberOK researchers discovered a five-year-old logic error — a single misplaced minus sign breaking permutation logic — in the Blackrock library used by Nuclei template authors. The bug could cause false negatives in vulnerability scanning output. (src: SecurityLab)
- Privileged Docker container escape via web panel (HTB Kobold). A Hack The Box write-up demonstrates how a web container-management panel with privileged-container creation rights reduces host takeover to a single dangerous action, chaining remote code execution to full host compromise. Relevant for any team running self-hosted container orchestration UIs. (src: Xakep)
Themes
Edge-appliance attack surface keeps expanding. OpenWrt DHCPv6, SonicWall SMA, and container management panels all illustrate that perimeter and embedded devices remain the soft underbelly — unauthenticated RCE on a router or VPN appliance is often one request away from root.
Supply-chain pressure from both sides. NPM's upload crackdown and the five-year-old Nuclei library bug show the push-and-pull: platforms are tightening gates while long-dormant code continues to surface quietly dangerous flaws.
