From SonicWall to Axios: Attacks and Vulnerabilities of the First Week of August
August cyber attacks recap: SonicWall credential stuffing, npm Axios supply chain compromise, Adobe critical patches, and major data breaches.
Illustrative image generated with AI
Credential Stuffing Campaign Targeting SonicWall Infrastructure
Since July 25, a large-scale automated credential stuffing campaign has been targeting VPN and firewall accounts on SonicWall devices. The malicious traffic originates from five IP addresses hosted on DigitalOcean and has already led to successful logins at thirty organizations. No post-compromise manual activity has been detected, suggesting the primary goal was simply unauthorized access—possibly for resale or network reconnaissance. Huntress is actively monitoring the campaign.
Immediate defensive measures are critical: enable multi-factor authentication, rotate any affected credentials, and block the identified IPs. The absence of follow-on actions does not lower the risk: persistent VPN access effectively hands over control of the corporate perimeter.
npm Supply Chain: North Korean Sapphire Sleet Targets Axios, Debug, and Chalk
Amazon Threat Intelligence has attributed to the North Korean group Sapphire Sleet the compromise of three extremely popular npm packages: Axios, Debug, and Chalk. An additional case of typosquatting aimed at a crypto-related project has also been identified. The operation uses fragmented payloads and malware capable of detecting the execution environment, making automated analysis more difficult.
The potential blast radius is vast: any software project depending on these libraries could execute arbitrary code, leading to data theft or compromise of development environments. Mitigations require immediately updating dependencies to clean versions, verifying hashes and signatures, and monitoring package behavior in staging setups.
Critical Patches: Adobe and the Exposed API of VE Commercial Vehicles
Adobe released fixes addressing a heap buffer overflow in Format Plugins (arbitrary code execution), multiple flaws in Bridge (code execution and privilege escalation), and vulnerabilities in Campaign Classic (code execution and file system read). Patches for on-premise Campaign Classic carry priority 1 and must be applied right away.
A more severe exposure was uncovered by a researcher on the My Eicher platform, run by VE Commercial Vehicles (a Volvo Group / Eicher Motors joint venture). Unauthenticated internal APIs exposed customer, user, and vehicle data, enabled account takeover, and gave full control over fleets in India. Sensitive documents such as Aadhaar cards were also accessible. The primary vulnerabilities were fixed after disclosure, followed by supplementary patches released by the company.
Data Breaches: OnTrac and the UK Department for Education
OnTrac, a parcel logistics company, detected unauthorized network access on March 23 that had occurred between March 20 and 22. Files may have been exfiltrated, but no ransomware claim followed. The company launched a forensic investigation and is notifying customers. Details on the specific data involved have not been made public.
In the UK, the Department for Education suffered the theft of approximately 607,000 records containing email addresses and phone numbers. The incident was contained quickly, and the agency considers the risk to individuals low, since no financial or highly sensitive data was compromised. The possibility of targeted phishing campaigns remains.
AI and Cryptanalysis: Advances by Claude Mythos
With the preview of its Claude Mythos model, Anthropic has developed two new cryptographic attacks. The first cuts the effective security level of the post-quantum signature scheme HAWK—still an evaluation candidate—in half. The second accelerates a meet-in-the-middle attack against 7-round reduced AES.
No immediate threat to real-world systems exists: standard AES uses 10, 12, or 14 rounds, and HAWK is not yet an adopted standard. Still, the results demonstrate an acceleration in AI-assisted cryptanalysis and will be scrutinized by the community to strengthen future security standards.
Sources
This article is an original reworking based on the sources below.




