A Canadian Hacker Pleads Guilty to the Snowflake Campaign That Breached More Than 165 Companies, and the Root Cause Was Missing MFA
Connor Riley Moucka, a 26 year old from Kitchener, Ontario who operated under the aliases Waifu and Judische, pleaded guilty in United States federal court on August 5 to computer fraud, aggravated identity theft, and conspiracy charges for the 2024 campaign that compromised more than 165 Snowflake customer environments using stolen credentials. Victims publicly linked to the campaign include AT&T, Ticketmaster, LendingTree, Santander, Advance Auto Parts, Neiman Marcus, Pure Storage, and Canada's Bausch Health. Moucka and co conspirators collected more than 2.5 million dollars US in ransom payments plus roughly 500,000 dollars from selling stolen data, with victims suffering about 9.5 million dollars in losses. Sentencing is set for October 27, 2026, with a mandatory minimum of two years on the identity theft count and exposure to roughly thirty more on the remaining counts.
The campaign that produced some of 2024's largest breaches required no exploit and no malware at the point of entry: it ran on credentials harvested by infostealers and replayed against cloud data platform tenants that had not enforced multi factor authentication. Moucka was arrested in Canada in October 2024 after a multinational investigation and extradited to the United States in July 2025, a reminder that Canadian based attackers targeting foreign organizations are being prosecuted across the border.
- Guilty plea entered August 5 to computer fraud, aggravated identity theft, and conspiracy for the Snowflake customer compromises
- More than 165 organizations were breached using stolen credentials, with no MFA in the way
- Proceeds exceeded 2.5 million dollars in ransoms plus data sale revenue, against roughly 9.5 million dollars in victim losses
- Sentencing comes October 27, 2026, following arrest in Canada in 2024 and extradition in July 2025
Implications
Every consequence in this story flows from one absent control on third party cloud tenants, and that control is the organization's obligation, not the provider's. Enforce multi factor authentication on every SaaS and cloud data platform tenant per ISO/IEC 27001:2022 A.8.5 secure authentication and A.5.17 authentication information, and verify enforcement by audit rather than policy assertion, since the Snowflake victims had policies too. MFA on cloud services is also a baseline requirement of CyberSecure Canada, which makes this campaign the clearest business case yet for certifying against it. Extend vendor due diligence under A.5.19 and A.5.20 to ask suppliers whether MFA is enforced on the tenants holding your data, and monitor for credential replay per A.8.16, because infostealer harvests are the standing inventory this entire attack class runs on.
A Five Year Old Firmware Flaw in Coinkite's Coldcard Wallets Lets Attackers Drain More Than 140 Million Dollars in Bitcoin
More than 100 million dollars US, about 140 million Canadian, in bitcoin has been stolen from users of Coldcard hardware wallets made by Toronto based Coinkite Inc., BNN Bloomberg reported August 4. The root cause is a March 2021 firmware coding mistake that weakened the randomness used to generate wallet seeds, leaving private keys mathematically reconstructable offline with no physical access to a device. On July 30, more than 1,000 bitcoins were drained from over 1,000 addresses within 41 minutes; by August 3, more than 1,500 coins across roughly 7,300 addresses had been taken in three confirmed waves plus 14 smaller incidents. Coinkite released patched firmware by August 1, destroyed vulnerable inventory, halted shipments, and chief executive Rodolfo Novak issued a public apology.
The instructive detail is the latency: a cryptographic implementation error sat dormant in shipped products for over five years before someone weaponized the mathematics, and when they did, the theft ran at machine speed against thousands of victims at once. Entropy weaknesses do not announce themselves in functional testing; the wallets worked perfectly the entire time.
- A March 2021 firmware flaw weakened seed generation randomness, making private keys reconstructable offline
- Over 1,000 bitcoins moved from more than 1,000 addresses in 41 minutes on July 30
- By August 3 the count reached more than 1,500 coins and roughly 7,300 compromised addresses
- Coinkite shipped patched firmware by August 1, destroyed vulnerable stock, and halted shipments
Implications
For Canadian product companies, this is what deferred secure development cost looks like: a nine figure customer loss and a public apology traceable to one unreviewed implementation decision. Cryptographic code deserves controls beyond ordinary review, which is exactly the ground covered by ISO/IEC 27001:2022 A.8.24 use of cryptography, A.8.25 secure development life cycle, and A.8.29 security testing in development and acceptance, including validation of randomness sources rather than trust in them. Organizations holding digital assets should verify firmware provenance on hardware wallets and rotate any keys generated on affected versions, treating them as compromised regardless of balance. Boards of device makers should note that breach notification, recall logistics, and product liability arrived here as one combined event, not three separate scenarios.
The Cyber Centre Flags Actively Exploited Flaws in the RMM Platform Many Canadian MSPs Run
The Canadian Centre for Cyber Security published advisory AV26 769 on August 4, updated August 6, for two actively exploited vulnerabilities in N central, the remote monitoring and management platform from N able that managed service providers use to administer client fleets. CVE 2026 18577, an authentication bypass rated CVSS 8.2 that stems from an incomplete patch of CVE 2026 18556, allows remote unauthenticated attackers to gain administrative control of N central servers and pivot into managed endpoints through the platform's built in Take Control feature. CISA added the two flaws to its Known Exploited Vulnerabilities catalog on August 3 and August 4, ordering US federal agencies to remediate by August 6. The vendor shipped version 2026.3.1.7 on August 2 and a second hotfix, 2026.3.1.10, on August 6; every version prior to that hotfix is affected, with exploitation observed since August 1.
RMM compromise is a force multiplier: administrative control of one server grants an attacker legitimate remote access tooling into every client the provider manages. The incomplete patch lineage matters too, because organizations that applied the first fix promptly were still exposed until the second one arrived.
- CVE 2026 18577 and CVE 2026 18556, both CVSS 8.2, are under active exploitation since August 1
- The Cyber Centre issued advisory AV26 769 on August 4; CISA added both flaws to the KEV catalog August 3 and 4
- Attackers gaining server control can reach managed endpoints through the Take Control feature
- All versions prior to hotfix 2026.3.1.10, released August 6, are affected
Implications
Canadian organizations that outsource IT should send their provider two questions this week: confirm N central is at 2026.3.1.10 or later, and confirm a review of Take Control session logs back to August 1. Providers running the platform should treat unpatched internet reachable instances as presumed compromised and hunt accordingly rather than patch and move on. The episode maps to ISO/IEC 27001:2022 A.5.22 monitoring, review and change management of supplier services, because an MSP's tooling is inside your trust boundary whether or not it appears on your asset register, and to A.8.8 management of technical vulnerabilities for the compressed patch cycle. For small organizations, patching and vendor oversight are core CyberSecure Canada baseline controls, and this is the scenario they exist for.
Framework Notifies Every Customer of a Breach That Entered Through an Analytics Vendor's Zero Day
Modular laptop maker Framework told all of its customers on August 7 that attackers stole names, email addresses, phone numbers, and physical addresses; payment data was not taken. The intrusion path ran through a zero day vulnerability in Metabase, the business intelligence platform Framework connected to its cloud database. Framework declined to give a customer count, but the company has sold hundreds of thousands of devices. Metabase disclosed its own breach on its blog before Framework's notification went out and did not respond to press inquiries.
This is a textbook fourth party incident: the data lived in Framework's cloud database, the exploited software belonged to an analytics supplier bolted onto it, and the customers belonged to neither. Analytics and business intelligence tools routinely hold standing, privileged connections into production data stores while sitting outside the scrutiny applied to the stores themselves.
- All Framework customers were notified August 7; names, emails, phone numbers, and physical addresses were taken
- The attackers exploited a zero day in Metabase, the analytics platform connected to Framework's cloud database
- Payment data was not compromised, and Framework has not disclosed a customer count
- Metabase disclosed its own breach before Framework's customer notification
Implications
Inventory every analytics, business intelligence, and reporting tool holding a connection into production data this week, and record what each connection can read, because that list is an attack surface catalogue. Constrain those connections to least privilege and monitor them per ISO/IEC 27001:2022 A.8.16, and bring the tools themselves under A.5.21 managing information security in the ICT supply chain and A.5.23 information security for use of cloud services, including a contractual requirement that the vendor notifies you of their incidents on a defined clock. Under PIPEDA, the real risk of significant harm assessment and notification duty is yours even when the exploited software belongs to a supplier, so the vendor's disclosure timeline cannot be the start of yours.
The Privacy Commissioner Puts Automated Decision Rules at the Centre of Privacy Act Modernization
Privacy Commissioner Philippe Dufresne published his submission to the Treasury Board of Canada Secretariat's consultation on modernizing the federal Privacy Act on August 6. The submission calls for recognizing privacy as a fundamental right, embedding contemporary privacy principles in the statute, stronger enforcement mechanisms, mandatory privacy impact assessments for high risk activities, enhanced transparency requirements for automated decision systems, and greater authority to collaborate with other oversight bodies. Dufresne framed strong data governance as contributing to "a more resilient Canadian economy, and a more secure and enriching digital society." No legislative timeline accompanied the submission.
The Privacy Act binds federal institutions, not the private sector, but OPC positions have a track record of previewing what the regulator later expects from everyone: the transparency and impact assessment language here reads as a draft of the expectations an eventual PIPEDA successor will carry for automated decision making.
- The OPC submission responds to Treasury Board's consultation on modernizing the Privacy Act
- It asks for mandatory privacy impact assessments for high risk activities and transparency duties for automated decision systems
- Stronger enforcement mechanisms and recognition of privacy as a fundamental right anchor the position
- No legislative timeline is attached; the consultation continues
Implications
Organizations selling AI enabled services to the federal government should expect transparency and assessment requirements to arrive through procurement clauses well before they arrive in statute, so the compliance clock is a contract cycle, not a legislative one. The low regret move is building AI system impact assessment practice now under ISO/IEC 42001:2023 Clause 6.1.4, which produces exactly the documented, repeatable assessments both the OPC position and federal procurement flow downs point toward. Private sector organizations using automated decisions about individuals should map where those decisions occur and what explanation they could produce today, because that inventory is the first question any future PIPEDA successor obligation will ask.
Trojanized AI Agent Skills Reached 1.7 Million Installs in a Credential Stealing Campaign
Researchers at Zenity disclosed that attackers uploaded malicious AI agent skills to skills.sh, the open agent skills marketplace maintained by Vercel, impersonating the Paperclip agent orchestration platform and the Browser Use automation service, CSO Online reported August 7. Malicious instructions hidden in secondary documentation files directed AI agents to download and install a credential stealer targeting SSH keys, cloud credentials, Git tokens, and Kubernetes configurations. The campaign began July 11 and reached 1.7 million combined downloads by August 2, with individual Paperclip themed skills at roughly 300,000 installs each. Initial payload packages were pulled from npm and PyPI within hours of detection, after which the attackers pivoted to serving payloads from fake GitHub organizations.
The mechanism deserves attention: the malicious instructions targeted the agent, not the human. Skills are documents an AI agent reads and acts on with the developer's credentials and permissions, which makes a skills marketplace an instruction injection channel with an install counter.
- Malicious skills on skills.sh impersonated Paperclip and Browser Use, reaching 1.7 million combined downloads by August 2
- Hidden instructions directed agents to install a stealer targeting SSH keys, cloud credentials, Git tokens, and Kubernetes configurations
- The campaign ran from July 11, with payloads pulled from npm and PyPI within hours and re hosted via fake GitHub organizations
- Individual trojanized skills recorded roughly 300,000 installs each
Implications
Agent skills are an unvetted software supply chain executing with developer level credentials, and most organizations have no inventory of what their staff's AI agents have installed. Extend third party software policy and allow listing to skill marketplaces now, and treat agent installed dependencies as fully in scope for ISO/IEC 27001:2022 A.5.21 managing information security in the ICT supply chain, A.8.7 protection against malware, and A.8.19 installation of software on operational systems. Under ISO/IEC 42001:2023, agent tooling with the ability to fetch and execute third party instructions warrants an impact assessment before deployment, not after the incident, and this campaign is the evidence to attach to that assessment.
NIST Finalizes a Cybersecurity Framework 2.0 Community Profile for the Transit Sector
The National Institute of Standards and Technology's National Cybersecurity Center of Excellence published the final Interagency Report IR 8576 on August 5, a Cybersecurity Framework 2.0 Community Profile for the transit sector. The profile translates transit specific mission needs into prioritized CSF 2.0 outcomes covering both business IT and operational technology, including cyber physical systems such as network connected signalling and fare systems. It was developed with transit agencies, operators, and federal partners, is voluntary and non regulatory, and extends NIST's growing series of sector Community Profiles built on CSF 2.0.
- Final IR 8576 published August 5 as a CSF 2.0 Community Profile for transit
- Scope spans business IT and operational technology, including signalling and fare systems
- Developed with transit agencies, operators, and federal partners; adoption is voluntary
- It joins a growing series of sector profiles built on CSF 2.0
Implications
Canadian transit agencies and transportation authorities routinely borrow NIST profiles in the absence of a Canadian sector equivalent, and this one arrives with regulatory timing attached: interprovincial transport is a named sector under the Critical Cyber Systems Protection Act, which awaits its coming into force order. A CSF 2.0 transit profile is a ready made scaffold for the cybersecurity program designated operators will need to evidence, and its OT inclusive risk framing covers exactly the signalling and fare infrastructure most transit security programs treat thinly today. Mapping an existing ISO/IEC 27001:2022 management system to the profile's prioritized outcomes is a low cost way to find the transit specific gaps before a regulator or assessor does.
NIST Opens Comment on Securing the First Message a Device Sends a 5G Network
NIST's National Cybersecurity Center of Excellence released the initial public draft of Cybersecurity White Paper CSWP 36F, Initial Non Access Stratum Message Security, on August 6, with comments due September 7, 2026. The paper documents how 5G networks encrypt and integrity protect the initial handshake message between a device and the network, a message that 4G sent unprotected, where it was exploitable for subscriber tracking and downgrade attacks. The draft includes a demonstration of the capability on the NCCoE's operational 5G testbed and implementation guidance for network operators.
- CSWP 36F initial public draft released August 6; comments close September 7, 2026
- The paper covers encryption and integrity protection of the initial device to network handshake in 5G
- The equivalent 4G message was unprotected and exploitable for subscriber tracking and downgrade attacks
- Findings are demonstrated on the NCCoE's operational 5G testbed with operator guidance included
Implications
Canadian carriers and any enterprise deploying private 5G can lift CSWP 36F directly into procurement language, requiring initial NAS protection from network vendors rather than assuming the 5G label implies it. Telecommunications is a named sector under the Critical Cyber Systems Protection Act, and documented adoption of recognized security capabilities like this one will be useful evidence when program obligations arrive. The three week comment window is short; operators whose deployments differ from the testbed configuration should say so before September 7, because this class of white paper tends to harden into assessment expectations.
ENISA Scales Up Its CVE Root as NATO's Communications Agency and an AI Security Firm Join as Numbering Authorities
The European Union Agency for Cybersecurity announced August 6 that the NATO Communications and Information Agency and AI cybersecurity firm AISLE have joined the CVE Numbering Authorities operating under the ENISA Root, bringing it to 20 CNAs: 12 onboarded directly by ENISA and 8 transferred from the MITRE Root. ENISA took on its CVE Root role in November 2025 and now acts as the European coordination point for CVE identifier assignment, CNA recruitment, training, and program compliance, alongside CISA and MITRE. Chief Cybersecurity Officer Hans de Vries tied the expansion to the impact of frontier AI models on vulnerability discovery volumes.
- The ENISA Root now spans 20 CVE Numbering Authorities after the NCIA and AISLE joined August 6
- ENISA has held its CVE Root role since November 2025, alongside CISA and MITRE
- The agency coordinates CVE assignment, CNA recruitment, training, and compliance for Europe
- ENISA links the expansion to AI accelerated vulnerability discovery volumes
Implications
The steady Europeanization of CVE infrastructure reduces the single point dependence on US funding that unsettled the program's users in 2025, which is quiet good news for every Canadian vulnerability management pipeline that consumes CVE data daily. The more actionable signal is the stated driver: the program's own operators now plan around AI accelerated vulnerability discovery, which means CVE volumes will keep climbing. Patch management service levels calibrated to human speed disclosure volumes deserve a review under ISO/IEC 27001:2022 A.8.8 management of technical vulnerabilities, with triage capacity and prioritization criteria sized for the volume curve ahead rather than the one behind.