Threat Brief — 2026-08-10 — AD Zero-Days and Ransomware Surge
Executive summary. Two new Active Directory vulnerability classes — ResetNightmare and KerberLoss — can hand attackers corporate network access through misconfigured naming conventions. Separately, CISA dropped a Gunra ransomware advisory targeting critical infrastructure, and a new StormEncryptor strain emerged from both a China-linked actor and a former Medusa affiliate. On the supply-chain front, BdThemes WordPress plugins were backdoored to silently create rogue admin accounts. Nation-state activity escalates: Kimsuky is now running an offline AI stack for phishing and malware automation, and Polish authorities blame Russian hackers for shutting down a CHP turbine serving 50,000 people.
Top items
- ResetNightmare & KerberLoss: Active Directory flaws enable corporate network access. Two newly named vulnerability classes in AD exploit naming-configuration errors to defeat authentication protections. A single misconfiguration in naming conventions can render all downstream security controls meaningless. No CVEs yet published. Affected: Microsoft Active Directory environments. (src: SecurityLab)
- NTFS vulnerabilities let malware hide in ZIP-like files across 40M Windows users. Three vulnerabilities spanning 30 Windows versions allow attackers to conceal malicious payloads inside files that appear as legitimate ZIP archives, evading detection across an estimated 40 million systems. Affected: Windows NTFS across multiple versions. (src: SecurityLab)
- BdThemes WordPress plugins supply-chain attack creates rogue admin accounts. A threat actor compromised BdThemes' upstream infrastructure and modified a remote JSON feed delivered to administrators' browsers, silently creating rogue WordPress admin accounts. Any site running premium BdThemes plugins should audit for unexpected admin users and rotate credentials. Affected: BdThemes premium WordPress plugins. (src: BleepingComputer)
- CISA issues #StopRansomware advisory for Gunra RaaS targeting critical infrastructure. Gunra operates as ransomware-as-a-service with affiliates targeting government and critical infrastructure sectors. The advisory includes IOCs and TTPs for detection. Affected: government and critical infrastructure organizations. (src: CISA)
- StormEncryptor: new ransomware deployed by both China-linked Storm-1175 and a former Medusa affiliate. Microsoft disclosed that Storm-1175 (China-linked, financially motivated) has shifted to deploying the previously undocumented StormEncryptor strain. Separately, a former Medusa affiliate is using the same ransomware, suggesting shared infrastructure or code leasing. Affected: organizations targeted by Storm-1175 and former Medusa affiliates. (src: The Hacker News, BleepingComputer)
- Kimsuky builds offline AI stack to automate phishing and malware development. North Korea's Kimsuky group is now running AI models on its own servers — outside public API monitoring — connected to document-search tools to generate targeted phishing content and automate malware development. This removes the dependency on commercial AI APIs that could detect or throttle malicious use. Affected: Kimsuky phishing targets (government, academia, defense). (src: The Hacker News)
- Russian hackers blamed for shutting down turbine at Polish CHP plant. Polish authorities accuse Russian-linked hackers of disabling controllers at a combined heat and power plant, potentially leaving 50,000 people without heat. The attack demonstrates ICS-specific controller compromise rather than generic network intrusion. Affected: Polish critical infrastructure / ICS environments. (src: SecurityLab)
- Windows Hello for Business key abuse enables persistent Entra ID access without admin rights. Newly presented exploit technique abuses WHfB keys through an already-open user session — no administrator privileges required — turning Windows Hello into a long-term network persistence mechanism for Entra ID. Affected: Microsoft Entra ID / Windows Hello for Business deployments. (src: SecurityLab)
- Cameras on British military vessels sent signals to a Chinese IP address. Surveillance cameras installed on Royal Navy boats were found communicating with an IP address in China, raising supply-chain and hardware-integrity concerns for military-grade surveillance equipment. Affected: British military maritime surveillance systems. (src: SecurityLab)
- OpenAI releases ChatGPT 5.6 Cyber — restricted to approved users. OpenAI has deployed a cybersecurity-focused model designed for vulnerability research, penetration testing, incident response, and remediation. Access is limited to approved users, but the existence of a purpose-built offensive-security AI model raises questions about eventual leak or misuse potential. Affected: approved cybersecurity professionals (for now). (src: BleepingComputer)
Themes
Ransomware ecosystem diversification. Three distinct ransomware threads surfaced today — Gunra (CISA advisory), StormEncryptor (two independent actors), and ongoing SonicWall-exploitation campaigns — signaling continued fragmentation of the RaaS model across both nation-state-linked and purely criminal operators.
AI weaponization maturing beyond API dependence. Kimsuky's offline AI stack and OpenAI's purpose-built cyber model represent opposite ends of the same trend: AI is becoming embedded in offensive workflows in ways that are harder to monitor, detect, or interrupt at the API level.
Supply-chain attacks on trusted update channels. BdThemes' compromised JSON feed and the British military camera telemetry both exploit the implicit trust placed in vendor-controlled infrastructure — the attack surface isn't the code itself but the delivery mechanism.
