LoadMaster CVE-2026-8037: 792 exploitation attempts over six weeks, CISA KEV deadline today, unauthenticated command injection at the network edge      800 npm packages in 48 hours: WEL1DROPPER installs a RAT and infostealer with no preinstall script, falls back to DNS TXT through wel1.ru if HTTPS is blocked      RovoBlast: one crafted link turns Atlassian Rovo into a data exfiltration tool across Jira, Confluence, SharePoint, and Slack      LoadMaster CVE-2026-8037: 792 exploitation attempts over six weeks, CISA KEV deadline today, unauthenticated command injection at the network edge      800 npm packages in 48 hours: WEL1DROPPER installs a RAT and infostealer with no preinstall script, falls back to DNS TXT through wel1.ru if HTTPS is blocked      RovoBlast: one crafted link turns Atlassian Rovo into a data exfiltration tool across Jira, Confluence, SharePoint, and Slack     
CyberSipTM
Intelligence without the noise
Issue No. 104
August 10, 2026
3 items · past 72h
<5 min read
Weekend picture

CISA added Progress Kemp LoadMaster CVE-2026-8037 to its Known Exploited Vulnerabilities catalog on Friday and set the federal remediation deadline for today, after telemetry from 65 unique IP addresses across 18 countries confirmed 792 unauthenticated exploitation attempts over six weeks against a command injection flaw in a network-edge load balancer. A threat actor published nearly 800 malicious npm packages over 48 hours on August 6 and 7, all delivering WEL1DROPPER, a downloader that profiles the host operating system, fetches a cross-platform RAT and infostealer compatible with Windows, macOS, and Linux, and falls back to DNS TXT record delivery through wel1.ru if standard HTTPS channels are blocked. And Varonis Threat Labs disclosed RovoBlast, a now-patched vulnerability in Atlassian Rovo where a single crafted link preloads attacker instructions into a logged-in user's AI session, causing Rovo to search Jira, Confluence, SharePoint, and Slack with the victim's own credentials and exfiltrate the results to an attacker-controlled server.

Weekend intelligence
3 items
01 CriticalProgress LoadMasterCISA KEV
Progress LoadMaster CVE-2026-8037 is confirmed exploited and on CISA KEV with a deadline of today, after 792 attempts from 65 IP addresses over six weeks
LoadMaster is a network-edge application delivery controller. An unauthenticated attacker reaches the command injection through the API, and the appliance sits in front of every service it balances. CISA's KEV entry includes a forensics triage requirement alongside the patch. The deadline lands today.
CVECVE-2026-8037
CVSS 9.6
KEV addedAugust 7, 2026
Fed deadlineAugust 10, 2026
(today)
Attempts792 over 41 days
65 IPs, 18 countries
Fixed inGA 7.2.63.2
LTSF 7.2.54.18
CISA added CVE-2026-8037 to its Known Exploited Vulnerabilities catalog on August 7, 2026, and set a federal remediation deadline of August 10. Progress disclosed the vulnerability on June 4 alongside CVE-2026-33691. WatchTowr Labs published a technical analysis in June describing the root cause as an improper null-termination in a function named escape_quotes(), which fails to properly bound-check sanitized strings, causing an out-of-bounds read into adjacent heap memory. That read allows an attacker to issue specially crafted requests to the /accessv2 endpoint and achieve command injection without any credentials. eSentire's Threat Response Unit observed the first exploitation attempts on June 29, the day WatchTowr published its analysis. Those early attempts failed and produced no confirmed post-compromise activity. KEVIntel telemetry captured 792 exploitation attempts from 65 unique IP addresses across 18 countries between June 29 and August 4, with the last recorded activity on August 4. CISA's KEV record pairs the patch requirement with its forensics triage guidance, treating this as an incident response item rather than a routine patch event. LoadMaster is an application delivery controller positioned at the network edge in front of web applications, IIS deployments, Exchange environments, and other internal services. Compromise of the appliance gives an attacker a foothold with visibility into internal service topology and the potential for lateral movement into any service LoadMaster proxies. CVE-2026-8037 also affects ECS Connection Manager, Connection Manager for ObjectScale, and MOVEit WAF. Fixed versions are GA 7.2.63.2 and LTSF 7.2.54.18.
LoadMaster appliances sit between the internet and internal services by design. An attacker who compromises a LoadMaster before reaching any internal application has gained a position from which every backend service is directly reachable. The 792 documented attempts span six weeks across 65 different source addresses, indicating sustained, distributed probing rather than a single actor's opportunistic scan. The June 29 start date, coinciding with the public technical analysis, is the clearest possible demonstration of what CISA has termed the collapsing exploitation window: the time between disclosure and active probing was effectively zero.
Progress has a documented history of high-severity vulnerabilities in network-edge products. MOVEit Transfer CVE-2023-34362 was exploited as a zero-day in the Cl0p campaign that affected hundreds of organizations. WS_FTP Server had critical authenticated and unauthenticated vulnerabilities disclosed in 2023. LoadMaster is the third Progress product to reach CISA KEV with active exploitation in three years. Organizations running multiple Progress products should treat this as a pattern requiring a broader audit of their Progress deployments rather than a single appliance patch event. CISA's addition of forensics triage requirements to the LoadMaster KEV entry indicates an expectation that some organizations may already be compromised.
  • Update LoadMaster to GA 7.2.63.2 or LTSF 7.2.54.18 immediately. The federal deadline is today. Confirm the update applied and verify the API is no longer exposing the /accessv2 endpoint with unsanitized input handling.
  • Follow CISA's forensics triage guidance for this KEV entry. Review LoadMaster access logs for the /accessv2 endpoint from June 29 onward for anomalous requests. Check for unexpected outbound connections, new rules or configuration changes, and access to backend services that originated from the LoadMaster appliance rather than legitimate client sessions.
  • Audit all other Progress products in your environment, including any MOVEit Transfer, WS_FTP, or ECS Connection Manager deployments, for current patch status given the vendor's history of critical vulnerabilities in network-edge products.
Seven hundred and ninety-two attempts. Six weeks. The first try came the same day the technical analysis went public. The deadline is today. CISA says patch and triage, not just patch. Check what the appliance saw between June 29 and now before closing this one out.
02 Highnpm Supply ChainWEL1DROPPER
Nearly 800 malicious npm packages published over 48 hours deliver a cross-platform RAT and infostealer with no preinstall script and a DNS fallback
The packages do not use lifecycle hooks. The README tells developers to load the library with require(). That single call starts the infection chain. A fallback through DNS TXT records at wel1.ru delivers the payload even when HTTPS to the primary Cloudflare Workers hosts is blocked. If any of these packages reached a build environment, treat it as a host compromise.
MalwareWEL1DROPPER
RAT and infostealer
Packages~800 published
over 48 hours
PublishedAugust 6 to 7, 2026
PlatformsWindows, macOS
Linux
C2 fallbackDNS TXT records
via wel1.ru
Between August 6 and August 7, 2026, a threat actor published nearly 800 packages to the npm registry within 48 hours. OpenSourceMalware researcher Paul McCarty disclosed the campaign and described the package names as AI-slop squatted, meaning they use AI-generated combinations that resemble plausible package names without targeting specific well-known ones, a technique that avoids triggering typosquat detection tools keyed to known package names. All packages deliver a downloader named WEL1DROPPER. Unlike most malicious npm packages that use preinstall or postinstall lifecycle hooks to run code automatically, WEL1DROPPER loads through the main module entrypoint. The README instructs developers to import the package with require(), and that single call starts the infection chain with no hook required. Upon execution, WEL1DROPPER identifies the host operating system and processor architecture and fetches the appropriate payload from one of three Cloudflare Workers hosts. If those HTTPS downloads fail, the malware switches to DNS TXT record delivery through subdomains of wel1.ru, reconstructing the payload from record contents to bypass network controls that block the primary delivery channels. The final payload is a cross-platform RAT and infostealer compatible with Windows, macOS, and Linux. On macOS the malware drops a fake runtime binary and a LaunchAgent for persistence. The beacon payload was not fully available for analysis at disclosure time, meaning the complete range of post-installation behavior remains uncharacterized.
Most npm supply chain defenses focus on lifecycle hooks because automated execution through preinstall and postinstall scripts is the most direct attack path. WEL1DROPPER skips those hooks and loads through the module entrypoint instead. Security tooling that detects malicious npm packages by scanning for suspicious lifecycle scripts will not catch this campaign. The DNS TXT fallback is the second structural problem: a security team that blocks the Cloudflare Workers delivery hosts may believe they have contained the threat when the malware has already pivoted to an alternative delivery channel. A developer or build system that ran require() on any of these packages should be treated as potentially compromised regardless of whether the HTTPS delivery was blocked.
This campaign is the third significant npm malicious package event in about two weeks, following the two North Korea-linked npm packages from August 6 covered alongside the TeamCity story in Issue 102 and the Open VSX evil twin campaign from Issue 101. The npm registry and other open-source repositories are under sustained pressure from multiple actors using different techniques simultaneously. OpenSourceMalware's guidance is explicit: if any of these packages appears in a lockfile, software bill of materials, package manager cache, build log, or deployed application, removing the dependency is not sufficient. Determine whether require() was ever called against the package and hunt DNS logs for TXT queries to wel1.ru and proxy logs for the Cloudflare Workers hosts before concluding no compromise occurred.
  • Run a dependency audit across all projects, CI environments, and build caches against the package list published by OpenSourceMalware and check lockfiles and package-lock.json files for any of the approximately 800 identified package names. The presence in a lockfile is sufficient grounds for investigation even if the package was never executed.
  • Hunt DNS logs for TXT record queries to subdomains of wel1.ru and proxy or egress logs for connections to the three Cloudflare Workers delivery hosts listed in the OpenSourceMalware disclosure. A successful DNS TXT query to wel1.ru from a build host is a strong indicator of WEL1DROPPER execution regardless of whether the HTTPS delivery was logged.
  • On macOS endpoints where the packages may have been imported, hunt specifically for unexpected LaunchAgent entries and unfamiliar runtime executables in application support directories, as those are the documented macOS persistence mechanisms for this campaign.
No preinstall script. No postinstall script. One require() call and the infection chain starts. Block the Cloudflare hosts and it falls back to DNS TXT records. Removing the package is not cleanup. It is the start of an investigation.
03 HighAtlassian RovoAI Prompt Injection
RovoBlast: one crafted link turned Atlassian Rovo into a data exfiltration tool across every system it could access
Atlassian patched the URL parameter path on July 8 with no customer action required. A second content-borne injection chain reported by PromptArmor in May remained unpatched when the disclosure published on August 5. Both attacks required no jailbreak, no permission bypass, and no warnings to the user.
NamedRovoBlast
(Varonis)
TypePrompt injection
via URL parameter
PatchedJuly 8, 2026
server-side
(no action needed)
Second pathContent-borne
PromptArmor
Status unconfirmed
Varonis Threat Labs disclosed RovoBlast at DEF CON and published the full write-up on August 5. Rovo is Atlassian's enterprise AI assistant, spanning Jira, Confluence, Bitbucket, and more than 50 third-party platforms through Rovo Connectors, including Slack, Microsoft 365, and Google Workspace. The vulnerability was a URL parameter named rovoChatPrompt that pre-filled content into Rovo Chat before a user opened a session. An attacker could craft a link placing a complete set of attacker instructions into that parameter. When an authenticated user clicked the link, Rovo treated the parameter contents as trusted input within that user's active session and executed the instructions with the user's credentials and permissions. Varonis' proof of concept showed Rovo enumerating accessible Jira tickets, Confluence pages, and SharePoint documents and exfiltrating their contents by embedding the data in requests to an attacker-controlled image URL, which Rovo fetched as part of its research workflow. The attack required no jailbreak, no bypass of Rovo's guardrails, and generated no warning to the user. Atlassian patched the rovoChatPrompt issue server-side on July 8, 2026, after disclosure through Bugcrowd. No customer action is required; all Atlassian Cloud tenants with Rovo enabled received the fix automatically. A separate content-borne prompt injection chain was reported to Atlassian by PromptArmor in May 2026 and disclosed publicly on August 5. That chain uses attacker instructions embedded in documents or pages Rovo processes, rather than a URL parameter. PromptArmor stated that chain was still unpatched at the time of publication. Atlassian's remediation status for the content-borne path has not been confirmed as of August 10.
Rovo's value to enterprises comes from the same property that made RovoBlast possible: it has read access to everything a user can access across Jira, Confluence, and dozens of connected tools. An AI assistant with that level of access that accepts external instructions without treating them as untrusted is an exfiltration tool waiting to be weaponized. The blast radius of a successful attack scales directly with how broadly an organization has connected Rovo to its internal systems. An organization with Rovo connected to Jira, Confluence, Slack, Microsoft 365, and a CRM is not just exposing one platform. It is exposing everything those platforms hold for the user who clicked the link.
The RovoBlast URL parameter path is patched. The content-borne path documented by PromptArmor may not be. Disabling Rovo's web search option does not eliminate the content-borne attack surface: PromptArmor confirmed that chain worked with web search switched off because Rovo's underlying ability to open external URLs persists independent of that setting. Organizations that believe they have reduced their Rovo attack surface by disabling web search should reassess that assumption. The practical mitigation for the remaining exposure is scoping: restrict which Atlassian apps and user groups can use Rovo, and audit what external platforms are connected through Rovo Connectors, limiting the surface area of any session that could be hijacked through a crafted document or page.
  • No action is required for the RovoBlast URL parameter path. Atlassian applied the server-side fix on July 8 to all Atlassian Cloud tenants with Rovo enabled. Verify your organization uses Atlassian Cloud rather than a self-hosted Jira or Confluence Data Center deployment, as the server-side fix applies to Cloud only.
  • Scope Rovo access to only the user groups and Atlassian apps that have a current business need for AI assistance. Each connected platform multiplies the data a RovoBlast-style attack can reach. Rovo Connectors to Slack, Microsoft 365, Google Workspace, and other platforms should be reviewed and limited to what is actively used.
  • Audit Rovo Chat logs for any sessions that accessed an unexpectedly wide range of content or opened external image URLs in quick succession. Those patterns are consistent with a RovoBlast-style exfiltration attempt and would have been visible before the July 8 patch.
One link. Rovo searches everything the victim can access and sends it to an attacker's server. No jailbreak, no warning. The URL parameter path is patched. The content-borne path that works with web search disabled may not be. Scope Rovo access tightly until Atlassian confirms both chains are closed.
Cross-source standouts
01
Progress LoadMaster and the pattern of network-edge product exploitation: a shorter window each time
eSentire observed the first LoadMaster exploitation attempts on June 29, 2026, the same day WatchTowr published its technical analysis. The patch had been available since June 4. That means the exploitation window opened not when the vulnerability was disclosed in June but when the detailed attack methodology became public in late June. This is not a novel observation; it has been documented across dozens of CVEs over several years. What makes it worth naming again is the pattern in Progress's own product portfolio. MOVEit Transfer CVE-2023-34362 was exploited as a zero-day, before any patch existed. WS_FTP Server vulnerabilities in 2023 went from disclosure to exploitation in days. LoadMaster CVE-2026-8037 was exploited within hours of a public technical analysis. The window is compressing with each product and each disclosure. For organizations running network-edge products from any vendor with a history of critical CVEs, the operational question is not whether to patch promptly. It is whether the gap between disclosure and patch deployment is shorter than the gap between disclosure and first exploitation attempt, and whether that gap was already closed before the eSentire telemetry started counting.
02
RovoBlast, M365 Copilot, and the structural problem with AI assistants that hold broad workspace access
Issue 98 covered the M365 Copilot prompt injection where hidden text in a Word document caused Copilot to rewrite figures in a report and propagate the instructions into the output. RovoBlast used a URL parameter instead of a document. Both exploited the same structural property: an AI assistant with read access to a broad enterprise workspace that accepts external inputs without treating them as untrusted. The M365 Copilot issue remained unpatched 144 days after reporting at the time of its disclosure. The content-borne PromptArmor path in Rovo was reported in May and remained unpatched when it published in August, roughly 75 days. Neither timeline reflects a security-critical patch pace for a vulnerability that can exfiltrate an organization's Jira tickets, Confluence pages, emails, and Slack messages in a single session. The pattern runs across multiple AI assistant products from multiple vendors. The common element is not vendor negligence or a specific implementation flaw. It is the category: any AI assistant with federated access to enterprise content that processes external inputs will have this attack surface until the industry develops and deploys a consistent model for treating external content as untrusted regardless of how it arrives.
Still watching
Days 2–5
US water campaign, 12 states (Issue 103 · Iranian attribution preliminary) — investigation ongoing, no public attribution confirmed. Georgia Clayton County boil water advisory resolved. Water utilities in any state should review CISA AA26-097A and CI Fortify guidance and report anomalous OT activity to the FBI and CISA regardless of state.
Day 3
TeamCity CVE-2026-63077 (Issue 102 · CISA KEV, deadline passed August 8) — confirmed actively exploited. Upgrade to 2025.11.7 or 2026.1.3. Audit administrator accounts created since July 28 and review build configuration history for unexpected changes. Prior TeamCity breaches produced persistence that survived initial patching.
Day 4
SonicWall SMA1000 CVE-2026-15409 and INC Ransomware (Issue 100 · MFA seed theft confirmed) — patch to 12.4.3-03453 or 12.5.0-02835. Rotate all TOTP seeds for enrolled VPN users. Patching does not invalidate seeds already stolen from the appliance between June 22 and the patch date.
Day 6
LegacyHive (Issue 88 · Nightmare Eclipse, no patch) — Windows User Profile Service privilege escalation with working proof of concept on fully patched systems. No CVE, no fix. Now at Day 23. Three prior disclosures in this series were exploited before patches arrived.
Day 7+