Snowflake Plea, 4,407 Exposed PLCs & Three Cisco 9.8s (08/06/2026)

August 6, 2026
Snowflake Plea, 4,407 Exposed PLCs & Three Cisco 9.8s (08/06/2026)
Key Intel / TL;DR
  • Connor Riley Moucka pleaded guilty in Seattle federal court over the 2024 Snowflake customer breaches, which reached at least 165 organizations and 100 million people.
  • Forescout counted 4,407 internet-facing Rockwell controllers on August 3, including 22 in cities hit by the water attacks, 19 of them on the same mobile carrier network.
  • Cisco patched 12 Catalyst SD-WAN and IOS XE flaws, three of them scoring 9.8.
  • Attackers used a SQL injection flaw to compile a post-exploitation toolkit inside an Oracle database, so no executable ever touched disk.
  • VulnCheck found a factory-shipped backdoor opening unauthenticated root shells in at least 20 Zbtlink router models, present in all 21 available firmware images.

The Snowflake case closed today with a guilty plea, and the number attached to it is 100 million people. Worth remembering what that campaign actually required: credentials from infostealer logs, aimed at tenants with no multi-factor authentication. Two years later Forescout counted 4,407 Rockwell controllers sitting on the public internet, and the technique used against the water utilities was not an exploit either. Attackers changed the IP address and set a password.

Top 5 Critical Security Alerts

1. The Snowflake Extortionist Pleads Guilty

Connor Riley Moucka pleaded guilty in Seattle federal court on Wednesday to computer fraud, wire fraud, aggravated identity theft, and a related conspiracy over the 2024 Snowflake customer breaches. The intrusions reached at least 165 organizations and the data of at least 100 million people. The Hacker News

Operator Note: No Snowflake vulnerability was ever involved. The campaign ran on valid credentials pulled from infostealer logs against tenants that had not enforced multi-factor authentication. The largest data theft of its era was a configuration gap, which is worth raising the next time someone frames MFA enforcement as a user experience problem.

2. Forescout Counts 4,407 Rockwell Controllers on the Public Internet

An August 3 scan found 4,407 internet-exposed Rockwell Automation programmable logic controllers, 2,844 of them in the United States. Twenty-two sit in cities hit by the recent water utility attacks, and nineteen of those run on the same mobile carrier network. MicroLogix 1400 devices account for half the exposed population and MicroLogix 1100 another 8%, both families named in FBI and EPA warnings. Nineteen of the 22 run firmware vulnerable to CVE-2017-16740, a Modbus TCP buffer overflow scoring 8.6. Forescout could not confirm any were compromised. The Hacker News

Operator Note: The attackers did not use the 2017 buffer overflow. They modified IP addresses and set passwords on controllers that were reachable and unauthenticated, and the operators lost visibility. Exposing EtherNet/IP on port 44818 is the whole finding.

3. Cisco Ships Three 9.8s Across SD-WAN and IOS XE

Cisco released updates for 12 vulnerabilities in Catalyst SD-WAN and IOS XE Software following an internal security review, including three scoring 9.8. The SD-WAN issues affect the software regardless of device configuration. The Hacker News

Operator Note: Flaws found in a vendor’s own review usually arrive before public exploitation, which gives you a real head start. That advantage lasts about as long as it takes someone to diff the patch.

4. Attackers Turned an Oracle Database Into the Compiler

After breaking in through a SQL injection flaw in a public-facing web application, attackers fed Java source code to the Oracle database, let Oracle compile it, and ran a post-exploitation toolkit called khunt without ever writing an executable to disk. The chain ended in Windows SYSTEM access. The Hacker News

Operator Note: Endpoint tooling watching for a foreign binary sees a trusted database process doing database things. If your detection strategy assumes malicious code arrives as a file, this is the shape of the gap.

5. Chinese Router Firmware Ships With a Root Shell

VulnCheck disclosed a factory-shipped backdoor in at least 20 Zbtlink router models, present in all 21 firmware images currently available from the vendor, opening unauthenticated root shells. The vendor denies its firmware contains backdoors while having paused downloads to address security issues. The Hacker News

Operator Note: Cheap cellular routers turn up in temporary sites, remote cabinets, and pop-up retail, bought by whoever needed connectivity that week. Nobody inventories them and nobody patches them, which is the actual exposure regardless of intent.

Additional Security Alerts

Threat Intelligence

  • Attackers are phoning financial firm employees: Google researchers report groups breaking into large US financial firms to steal data and extort, with voice calls to staff as the entry point. TechCrunch
  • LightSpy spyware surfaces in 13 countries: Researchers tied the China-linked operation to a specific company after one operator placed a KFC order using their real name and office address. TechCrunch

Vulnerabilities

  • CISA flags a TeamCity RCE under active exploitation: CVE-2026-63077 affects on-premises JetBrains TeamCity, which sits in the build pipeline with credentials to everything downstream. The Hacker News
  • TONTOU bypasses Spectre v2 mitigations: Researchers built a working exploit that leaks Linux password hashes despite current speculative execution fixes. BleepingComputer
  • Zapscape lets guest code escape to the host: The KVM flaw allows privileged code in an L1 guest to reach the Linux host underneath it. The Hacker News

Security Breaches & Incidents

  • Swiss government SharePoint breach hits 200 accounts: The compromise affected accounts across government systems. BleepingComputer
  • North Carolina Ports says a cyberattack is contained: The Coast Guard and state officials are investigating. The Record

Standards & Enforcement

  • Ransom Cartel’s creator gets 16 years: A Belarusian cybercriminal was sentenced for operating the ransomware-as-a-service platform. The Hacker News

The Axe Report is a daily briefing from Grab The Axe. Need help assessing your organization’s security posture? Take our free Human Attack Surface Score assessment.

Distribute Intel
Chris Armour
Director of Information Security
Chris Armour
The Breaker & Builder.

Operating on the philosophy that 'you can't build a secure system if you don't know how to break it,' Chris leads our engineering division. A top 1% National Cyber League competitor, he hardens our digital infrastructure against the very exploits he has mastered.

View Profile →
Press & Media

Media Inquiries

For expert commentary, interview requests, or high-res assets regarding this announcement, initialize the terminal.

Initialize Terminal

Initiate
Deployment.

Whether you need a full adversarial facility audit or an executive resilience protocol for your leadership team.

Secure the Facility (Assessments)
Secure the Mind (Coaching/Speaking)