Security Check-in Quick Hits: LoadMaster Exploits, Malicious VS Code Stealers & OpenAI’s Astra Cyber Pause
For August 10, 2026
Critical Progress Kemp LoadMaster Flaw Now Under Active Exploitation
CISA has added a critical command-injection vulnerability in Progress Kemp LoadMaster (CVE-2026-8037, CVSS 9.6) to its Known Exploited Vulnerabilities catalog after evidence of real-world attacks.
The flaw lets unauthenticated attackers execute arbitrary commands on vulnerable appliances by abusing unsanitized input in management endpoints. Hundreds of exploitation attempts have already been logged. Federal civilian agencies face a tight remediation deadline (around August 10 under the latest BOD guidance). Organizations running LoadMaster should immediately identify exposed instances (especially those with API access enabled), apply the fixed builds (GA 7.2.63.2 / LTSF 7.2.54.18 or later), and review logs for suspicious activity. Load balancers sit at a high-value network position—compromise here can cascade quickly.
Malicious “Solidity Pro” VS Code Extensions Steal Crypto Wallets, Keys & Credentials
Researchers flagged malicious Visual Studio Code extensions published under names including “Solidity Pro” (publisher variants such as helper-beeps and web3devtoolsx). These targeted blockchain/Solidity developers.
Early versions fetched encrypted Python payloads; later ones act as full information stealers, harvesting browser profiles, crypto wallet vaults (MetaMask, Phantom, etc.), seed phrases, GitHub/GitLab tokens, AWS/Cloudflare/OpenAI keys, SSH keys, and more—then exfiltrating via Telegram bots. The extensions used obfuscation, delayed activation, and trust-building clean versions to evade marketplace review. They have since been removed from major registries, but the GitHub repo for at least one remained accessible at the time of reporting. Developers should audit installed extensions, rotate any exposed credentials/wallets, and treat “helpful” Solidity tooling with heightened scrutiny.
OpenAI Pauses Internal Work on Astra Model Over Critical Cyber Capabilities
OpenAI announced it is pausing certain internal activities involving its upcoming Astra model after evaluations showed significant advances in agentic coding and cybersecurity—enough that the company “cannot rule out” reaching its “Critical” threshold under the Preparedness Framework.
That threshold includes the ability to autonomously find and exploit zero-days in hardened systems or execute novel end-to-end attack strategies from only a high-level goal. In response, OpenAI is implementing stricter controls: isolated test environments, restricted network/tool access, enhanced weight protection, universal monitoring of chain-of-thought for risky actions, and sandboxed execution. Astra was not linked to prior agent-escape incidents involving other models. This marks one of the more explicit public slowdowns by a frontier lab driven by offensive cyber risk.
These three stories highlight the usual mix of unpatched enterprise infrastructure, supply-chain/developer-tooling risks, and the accelerating dual-use challenge of advanced AI. Patch aggressively, verify your tooling sources, and keep an eye on how labs handle capability thresholds.



