Open VSX Evil Twins, CISA Flags Langflow & Water Hits 12 States (08/05/2026)
- › Open VSX removed 77 extensions that impersonated legitimate developer tools while exfiltrating system and development environment data, including private repository and build pipeline details.
- › CISA added Langflow, Apache Tomcat, and N-able N-central flaws to its Known Exploited Vulnerabilities catalog and gave federal agencies three days.
- › Water utilities in at least 12 states have now reported cyberattacks on operational technology, up from seven earlier in the week.
- › A CVSS 10.0 cross-tenant flaw led a patch round that also covered Veeam, Terraform MCP, and Django.
- › Kali365 weaponizes Microsoft authentication against US companies, continuing the pattern of attacks that use the login flow rather than break it.
The developer’s machine is having a bad week. Yesterday a worm rode in through npm and wrote itself into editors; today a marketplace pulled 77 extensions that were impersonating real tools and shipping private repository and continuous integration data out the back. Both attacks target the workstation with credentials to everything and the least monitoring in the building. Meanwhile CISA put three actively exploited flaws on the clock, and the water campaign reached 12 states.
Top 5 Critical Security Alerts
1. Open VSX Pulls 77 Extensions Impersonating Real Developer Tools
A cluster of 77 extensions on the Open VSX marketplace impersonated legitimate developer tools while transmitting information about the systems and development environments they were installed on. Infosecurity’s reporting on the same campaign describes private repository and continuous integration data being harvested. Open VSX is the marketplace behind VS Code forks including Cursor and Windsurf. The Hacker News
Operator Note: An editor extension runs with the developer’s full permissions and reads every file in the workspace, including the .env nobody meant to commit. Extension installs on developer machines deserve the same review you give production dependencies, and almost nowhere gives them any.
2. CISA Gives Federal Agencies Three Days on Langflow, Tomcat, and N-central
CISA added three flaws to its Known Exploited Vulnerabilities catalog on August 5, citing evidence of active exploitation: a remote code execution bug in IBM’s Langflow, an Apache Tomcat flaw, and the N-able N-central authentication bypass. Federal agencies have three days to mitigate. BleepingComputer
Operator Note: A three-day federal deadline is CISA’s way of saying the exploitation is broad, not theoretical. Treat KEV additions as your patch priority queue regardless of whether the mandate applies to you.
3. Water System Attacks Reach 12 States
Utilities in at least 12 states have now reported cyberattacks on their operational technology, as South Dakota and Georgia announced incidents. The campaign, which reporting links to Iranian actors, has grown steadily from the Minnesota cluster in late July. The Record
Operator Note: Twelve states in ten days is a scanning campaign finding what is reachable, not twelve separate targeting decisions. The exposure is internet-facing controllers, and the fix has not changed since CISA said it on August 1.
4. A CVSS 10.0 Cross-Tenant Bug Leads a Heavy Patch Round
A maximum-severity cross-tenant vulnerability headlined a patch cycle that also delivered critical fixes for Veeam, Terraform MCP, and Django. Cross-tenant flaws matter disproportionately because the boundary they break is the one your entire multi-tenant risk model assumes holds. The Hacker News
Operator Note: Veeam is a backup platform, which makes it the thing you need working on the worst day of your year. Patch it on the schedule you would use for a domain controller.
5. Kali365 Turns Microsoft Authentication Against Its Users
A toolkit tracked as Kali365 weaponizes Microsoft authentication flows against US companies. It joins device code phishing and the Greatness kit in a category that keeps growing: attacks that use the login process as designed rather than exploiting a flaw in it. The Hacker News
Additional Security Alerts
Threat Intelligence
- Coldcard owners are the phishing target now: A campaign trading on the disclosed wallet flaw offers a security audit and installs ScreenConnect remote access software instead. BleepingComputer
- 250+ ClickFix domains fingerprint the browser to hide: The operators serve the macOS malware lure only to visitors whose browser fingerprint matches, keeping researchers and sandboxes on a clean page. The Hacker News
- QuickFox ships a backdoor in a trojanized Windows installer: The supply chain attack delivers the FDMTP backdoor through a legitimate-looking installer. The Hacker News
Vulnerabilities
- A critical Gitea flaw reads server files without authentication: Attackers can pull files from the server through Org-Mode markup handling. The Hacker News
- OVSwrap gives local users root through Open vSwitch: The Linux kernel flaw turns local access into full privilege on affected hosts. The Hacker News
- Leaked n8n API tokens exposed live automation instances: The exposed tokens allowed credential theft from running workflow instances. The Hacker News
Emerging Security Technologies
- An AI agent went rogue during UK safety testing: During UK government tests, an agent created fake identities and launched social engineering attacks against real developers without being told to. The Record
- A model tried to backdoor a real open source project, then vouched for its own work: Researchers running frontier models off the leash observed an attempt to add malware to a live FOSS project. The Hacker News
- Prompt injection is still the top LLM risk: Despite a limited count of real-world incidents, prompt injection remains the highest-ranked risk in LLM deployments. Infosecurity Magazine
The Axe Report is a daily briefing from Grab The Axe. Need help assessing your organization’s security posture? Take our free Human Attack Surface Score assessment.
Operating on the philosophy that 'you can't build a secure system if you don't know how to break it,' Chris leads our engineering division. A top 1% National Cyber League competitor, he hardens our digital infrastructure against the very exploits he has mastered.
View Profile →Media Inquiries
For expert commentary, interview requests, or high-res assets regarding this announcement, initialize the terminal.