Sappers DFIR
Weekly Threat Watch
August 31, 2026
2
MIN READ
ServiceNow Criticals, Ghost SPN Kerberoasting, and Agentic AI Intrusions

A weekly threat watch detailing detailing ServiceNow CVSS 10.0 flaws, Ghost SPN identity evasion, Kaido Panel MaaS, UAT-10147's AI operations, and critical edge zero-days.

Share this post

TABLE OF CONTENT

This week’s intelligence highlights an aggressive evolution in both attacker methodology and targeting. Adversaries are integrating semi-autonomous AI directly into their post-compromise workflows, weaponizing unauthenticated public package mirrors for phishing, and exploiting stealthy Active Directory misconfigurations to execute untraceable Kerberoasting. Simultaneously, maximum-severity vulnerabilities in core ITSM, collaboration, and VPN platforms demand immediate enterprise patching.

SISA Weekly Threat Watch – our weekly feature brings to you a quick snapshot of all the major security vulnerabilities that posed a threat to organizations worldwide. These recurring actionable threat advisories will also provide information and recommendations that will help security teams take appropriate actions to defend against the latest and critical threats.

1. Critical Enterprise & Infrastructure Vulnerabilities

Core enterprise workflows, backup systems, and collaboration platforms are exposed to maximum-severity vulnerabilities allowing unauthenticated system takeover and authentication coercion.

  • ServiceNow CVSS 10.0 Vulnerabilities (KB3152242) — ServiceNow addressed four high-risk flaws, three of which carry a CVSS 10.0 rating. These pre-authentication flaws in the ServiceNow AI Platform allow remote attackers to execute arbitrary code via the GraphQL Composite Data API, bypass access controls, and execute raw SQL queries using dynamic-schema ORDER BY parameters.
  • SharePoint, NemoClaw & SonicWall Vulnerabilities — Microsoft SharePoint Server faces a critical attack chain combining a JWT authentication bypass (CVE-2026-55040) with a Business Data Connectivity RCE (CVE-2026-63520). Concurrently, NVIDIA NemoClaw deployments are vulnerable to DNS rebinding attacks (CVE-2026-65105) that poison local Ollama AI agents, while SonicWall NetExtender Linux clients suffer from root-level path traversal and symlink flaws (CVE-2026-66152/3).
  • Veeam ONE, Apache Tomcat & Log4j2 Flaws — A critical authentication coercion flaw in Veeam ONE (CVE-2026-65641) allows unauthenticated attackers to force outbound NTLM authentication for relay attacks. Additionally, Apache Tomcat resolved multiple access bypass and HTTP/2 DoS flaws (11.0.25), and Apache Log4j2 faces an unpatched deserialization bypass via java.rmi.MarshalledObject (Issue #4255) leading to RCE.
  • Palo Alto GlobalProtect LPE & Oracle HTTP Server KEV — Palo Alto Networks disclosed local privilege escalation (LPE) flaws allowing standard users to elevate to NT AUTHORITY\SYSTEM or root in GlobalProtect apps, potentially exposing Active Directory passwords in memory. Additionally, CISA has mandated the patching of CVE-2026-21962, an actively exploited improper access control flaw in Oracle HTTP Server.

2. Identity Subversion & Defense Evasion

Threat actors are leveraging deep architectural misconfigurations and vulnerable signed drivers to bypass traditional endpoint security and Active Directory logging.

  • Ghost SPN (Stealthy Kerberoasting) — Attackers are exploiting delegated AD administrative permissions (like GenericWrite) to temporarily attach Service Principal Names (SPNs) to standard user accounts. They request an RC4-HMAC TGS ticket, extract it, and immediately strip the SPN to erase persistent directory artifacts. This allows offline password cracking without triggering failed logins or account lockouts.
  • Cambodia-Focused Threat Cluster (BYOVD) — Disguised as COVID-19 prevention notices, this multi-stage infection chain targets Cambodian entities. The malware drops a vulnerable signed driver (ardrv.sys) to conduct Bring Your Own Vulnerable Driver (BYOVD) attacks, effectively terminating EDR and antivirus agents from kernel mode before establishing C2 communication.

3. AI-Driven Intrusions & Malware-as-a-Service

Adversaries are actively operationalizing AI to scale their attacks and abusing highly trusted public infrastructure to host evasive malware payloads.

  • UAT-10147 Agentic AI Operations — This Chinese-speaking threat actor is systematically exploiting 1-day web vulnerabilities (Zimbra, AjaxPro, Nacos) across 170,000 URLs. Uniquely, the group integrates agentic AI frameworks (PentestGPT, DeepAudit) into post-compromise workflows to autonomously refine local privilege escalation scripts, audit source code, and generate operational playbooks on the fly before deploying implants like NoodleRAT and QuasarRAT.
  • "Kaido Panel" MaaS Infrastructure — Disguised under an Adobe-themed domain (acrobatreaderonline[.]com), the Kaido Panel operates a modular Malware-as-a-Service builder via WebSockets/SignalR. The platform heavily relies on the native Windows WebClient service to deliver batch scripts directly from remote WebDAV shares, bypassing browser download warnings to drop banking overlays and info-stealers.
  • npm Public Mirror Exploitation (ClickFix) — Attackers uploaded 24 malicious packages to the npm registry to abuse public ecosystem mirrors (unpkg, yarn, npmmirror). Instead of executing upon installation, these packages host static HTML files that mimic Cloudflare security checks. When users visit the trusted mirror URLs, dynamic scripts pull redirection directives to deliver ClickFix social engineering and phishing campaigns.

Proactive Steps for the Week

  • Remediate Critical Platforms & Edge Devices: Immediately apply ServiceNow vendor-supplied hotfixes (e.g., Xanadu Patch 11 HF 7a) for self-hosted instances. Deploy Microsoft’s security updates for SharePoint Server to patch the JWT bypass, and prioritize the rollout of patched Palo Alto GlobalProtect clients (>= 6.3.3-h11, >= 6.2.8-h10) across all enterprise endpoints.
  • Audit Active Directory for Ghost SPNs: Continuously audit AD for standard user accounts containing a servicePrincipalName attribute. Enforce AES-128/256 encryption for Kerberos authentication domain-wide via Group Policy to mathematically neutralize the RC4-HMAC offline cracking leveraged in Ghost SPN attacks.
  • Harden WebDAV & WebClient Services: To mitigate Kaido Panel delivery chains, disable the native WebClient Windows service via GPO on endpoints where remote WebDAV connectivity is not explicitly required, and block outbound connections on TCP ports 80, 443, and 445 directed toward non-standard external WebDAV infrastructure.
  • Defend Against BYOVD and AI-Assisted Implants: Turn on Hypervisor-Protected Code Integrity (HVCI) and ensure the Microsoft Vulnerable Driver Blocklist is enabled to prevent execution of BYOVD drivers like ardrv.sys. Configure EDR behavioral telemetry to flag rapid, automated sequences of local reconnaissance and scheduled task creations indicative of UAT-10147’s AI-driven agentic tooling.
  • Secure Public Mirror Traffic: Implement web gateway and proxy controls to monitor and restrict direct browser navigation to standalone HTML files hosted on open public package mirrors (such as unpkg or yarn), neutralizing the npm-based ClickFix phishing infrastructure.

Explore our DFIR Solutions to discover how our advanced incident response support, compromise assessments, and threat hunting frameworks can insulate your enterprise infrastructure against these campaigns.

SHARE THIS POST

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Suspendisse varius enim in eros elementum tristique. Duis cursus, mi quis viverra ornare, eros dolor interdum nulla, ut commodo diam libero vitae erat. Aenean faucibus nibh et justo cursus id rutrum lorem imperdiet. Nunc ut sem vitae risus tristique posuere.