CISO Platform's Posts (73)

Sort by

Turbo Talks · Session recap

Why Traditional ASM and CTEM Tools Will Fail in the Next 12 Months

Bikash set the terms before the first slide: "Most of this is two numbers, and I would like us to do the arithmetic together rather than have you take my word for it." The two numbers are half a cent and $300.

Three key highlights

  • After a normal vendor margin, a daily ASM or CTEM subscription has half a cent to eleven cents to spend testing each asset. Move to weekly and it is still cents.
  • An attacker with AI spends a few hundred dollars per attempt against the same asset. The reasoning that cost $10,000 per application is now 20 to 50 times cheaper at the same depth.
  • The answer is not to buy more breadth. It is to pay commodity prices for coverage and move the difference into depth, on the assets that matter.

About the speaker

Bikash Barai is a serial cybersecurity entrepreneur with multiple exits and the Founder and CEO of FireCompass, an AI company building agents for penetration testing. He holds multiple patents in cybersecurity, speaks regularly at RSA, Interop and TED, and has been recognised in Fortune's 40 Under 40.

Watch the session

CISO executive summary

The argument in one line. The price of a tool tells you what the tool can do. At a cent per asset per day, ASM and CTEM products can discover and score exposures. They cannot prove them, because proof costs what reasoning costs.

Key findings

  1. Two hundred assets under daily monitoring is 73,000 asset-assessments a year. Priced at $1,000 to $20,000 a year, that is 1.4 to 27 cents per asset per test. After a normal 60 percent vendor margin, 0.5 to 11 cents is left to run it. A weekly cadence gives you 4 to 77 cents. Still cents.
  2. A $10,000 US manual penetration test bought five days of someone who reads business logic, tests authorization boundaries including IDOR, BOLA and privilege escalation, and chains three low-rated findings into one path. Because of that price, it ran on about 20 percent of the surface, once a year.
  3. FireCompass's AI agents reached #1 OWASP Injection, #1 Up and Comers and #2 Highest Critical Reputation on the US HackerOne business leaderboards, filing 204 reports on about $5,000 a month all-in. The reasoning that cost $10,000 per application now costs a few hundred dollars in tokens, 20 to 50 times cheaper, at the same depth.
  4. That leaves half a cent of defensive spend against $300 of attacker spend, on every asset you own, every day. A ratio of 60,000 to 1.

Recommendations

  1. Pay commodity prices for breadth and move the difference into depth. Automated discovery already solves coverage. Coverage is not where the money should go.
  2. Test at the attacker's price. A few hundred dollars per application, with proof of exploit for every finding. Deepest on P1, on demand for P2, event-driven for P3.
  3. Put triggers before schedules. A new asset, a new API, a deploy or a disclosed CVE fires a test. Then a cadence by criticality: P1 monthly or on change, P2 quarterly, P3 as events demand.

What this assumes

Bikash's forecast, not a finding: that pricing moves to consumption-based models the way cloud did, because continuous deep testing at current token costs is unaffordable.

Half a cent

Take 200 internet-facing assets under daily monitoring. That is 73,000 asset-assessments a year.

Now take the price. Entry-level third-party risk and ASM products start near $1,000 a year. Better ones sit around $20,000. Divide, and you get 1.4 to 27 cents per asset per test.

Then subtract what the vendor keeps. At a normal 60 percent gross margin, which says nothing about net margin once sales and administrative costs are paid, what is left to actually run the test is 0.5 to 11 cents per asset per day.

The obvious escape is that nobody really scans daily. He closed it on the same slide. Move to a weekly cadence and the budget per test rises to 4 to 77 cents. Still cents.

What depth used to cost

The comparison point is a real penetration test. Ten thousand dollars. Five days. One application. One human who could reason.

That bought a week of someone who reads business logic, tests authorization boundaries including IDOR, BOLA and privilege escalation, and chains three low-rated findings into a single path. It is the work scanners do not do.

And because it cost $10,000, everyone rationed it: the three applications that fit the budget, about 20 percent of the surface, once a year. His point about the other side of the trade is the one usually missed. Attackers rationed it too. Human depth was reserved for targets worth a week of effort.

What $5,000 a month buys now

FireCompass set a budget and ran the experiment on live HackerOne programmes. About $5,000 a month all-in, AI tokens and cloud included. The agents filed 204 reports. In his slide's words, no human wrote the exploits.

The results: number one on OWASP Injection, number one in Up and Comers, and number two for Highest Critical Reputation, on the US HackerOne business leaderboards. On HackerOne you only score by reporting a vulnerability before every other researcher on the platform.

The line that matters for a budget conversation is the conversion. The reasoning that cost $10,000 per application now costs a few hundred dollars in tokens. Twenty to fifty times cheaper, at the same depth.

He was direct about the caveat. This did not come from picking up a model and pointing it at a target. FireCompass built its own small language models, used frontier models alongside them, and developed what he called complex harness engineering and agentic architecture, on around $30 million raised. The point is not that it is easy. It is that the capability now exists at that price.

Everything on the last slide is now in the attacker's hands. Same models. Same token prices. Fewer rules.Bikash Barai

He framed the consequence as a divide rather than an event. The digital divide separated organisations that could compute from those that could not, and it compounded every year because the leaders kept reinvesting. His argument is that the AI divide does the same thing for reasoning, and that the attacker is already on the far side, with depth at a few hundred dollars per attempt, against every asset, on their timeline.

What accumulates on the wrong side of that line he calls depth debt: exposures discovered and scored, never proven.

0.5¢ versus $300

This is the whole talk on one slide, and the definitions matter more than the gap.

  0.5¢ $300
What it is What your ASM or CTEM tool spends testing each asset, each day What an attacker with AI spends breaking each asset, each attempt
What it buys Enumeration, fingerprinting, CVE matching and a score Reading business logic, testing authorization, chaining findings and proving the exploit

Sixty thousand to one. On every asset you own, every day.

Five sessions remain in this series, every Thursday through 22 October. Twenty minutes each, live. Register free

"But ASM was never a pentest." Correct. That is the point.

Bikash put the objection on a slide and agreed with it, which is the most useful move in the session.

ASM was built for asset discovery. It was never meant to be a penetration test. His argument is that this is not a defence of the category, it is a description of its price ceiling. The price tells you what the product can be. A cent per asset per day buys enumeration and fingerprinting. It cannot buy validation, because validation costs what reasoning costs: hundreds of dollars, not cents.

Relabelled as CTEM, it borrows the one word it cannot afford.Bikash Barai

He anchored that on the framework itself. Validation is the fourth of the five CTEM stages, as Gartner defined them in July 2022, and on his reading a discovery-priced tool cannot fund that stage. If you are renewing a tool that calls itself CTEM, that is the question to put to the vendor: which of the five stages does this price actually cover.

Match the attacker's economics, not everything

His recommendation is not more budget. It is a different allocation of the budget you already have.

Breadth times depth times continuity. Maximum on all three is not viable for anyone, the attacker included. Business criticality decides where depth and continuity go.

Axis What it answers What he recommends
Breadth How many assets we cover Solved by automated discovery. Pay commodity prices for it and move the difference into depth
Depth How thoroughly each is tested Test at the attacker's price: a few hundred dollars per application, proof of exploit for every finding. Deepest on P1, on demand for P2, event-driven for P3. Business logic and multi-stage chains, not CVE matches
Continuity How often each is tested Triggers first: new asset, new API, deploy, disclosed CVE. Then a schedule by criticality: P1 monthly or on change, P2 quarterly, P3 as events demand

Two lines from that slide are worth lifting out. The first is a measurement change: measure validated coverage and time to verdict, not asset counts. Most exposure programmes report the opposite, and asset counts are exactly the metric a discovery-priced tool is built to produce.

The second is the governance condition, and it is the answer to the obvious worry about pointing offensive AI at your own estate. Automate depth only with scope control, human approval before active exploitation, and a full audit trail.

The order he now argues for, and the one he used to

In the session he was candid that this reverses a position he held publicly. FireCompass coined the term CART, continuous automated red teaming, and regulators had begun naming it as a requirement.

A year back, I was very happy that many of the regulators mentioned that CART should be mandatory. We were very happy because we created this acronym CART. But I believe, because of AI today, the priority should be depth first, and after that, breadth and continuity.Bikash Barai

His reasoning is affordability rather than principle. Continuous token cost is high enough that continuous deep assessment does not work at today's prices, so a continuous shallow layer belongs on top of the base rather than in place of it.

What happens if the debt is not paid down

His closing warning was operational. If the depth debt is not worked off deliberately, it gets called in on someone else's schedule.

Bounty hunters start reporting vulnerabilities. A vendor finds something and sends it to your management. Or there is a compromise. In each case the priority shifts from continuity to depth anyway, just not on your terms.

He also pointed to two public signals. The volume of vulnerabilities reported through bug bounty platforms has shot up. And Microsoft's most recent Patch Tuesday was the largest it has ever shipped. Tenable counted 964 CVEs in the September 2026 release, a record, including two zero-days already under active exploitation. AI is helping attackers and defenders find vulnerabilities more easily at the same time.

Now, that's a very scary thing, and that's also a very promising thing. Depending on which side you are.Bikash Barai

What to watch next

Bikash expects security testing to follow cloud into consumption-based pricing, because that is the only way depth at scale becomes affordable. Until it does, the practical move is the reallocation above: commodity-price the breadth, spend the difference on proving your P1 assets, and let triggers rather than calendars decide when a test runs.

You cannot out-scan an attacker who can now afford to outthink you. Prove your assets before they do.Bikash Barai, closing the session

Questions from the session

What is depth debt?

Depth debt is Bikash Barai's term for exposures that have been discovered and scored but never proven. It accumulates when a security programme can afford to enumerate its attack surface but not to validate whether any given exposure is actually exploitable.

What is the depth gap?

The depth gap is the difference between what an organisation can afford to spend testing an asset and what an attacker can afford to spend breaking it. On the numbers in this session that is half a cent per asset per day against roughly $300 per attempt, a ratio of 60,000 to 1.

Does this mean ASM and CTEM tools are worthless?

No. ASM was built for asset discovery, and automated discovery genuinely solves breadth. Bikash's argument is that a cent per asset per day buys enumeration, fingerprinting, CVE matching and a score, and cannot buy validation. The recommendation is to pay commodity prices for coverage and move the saved budget into depth, not to stop covering the estate.

How often should assets be tested?

His model puts triggers before schedules. A new asset, a new API, a deploy or a disclosed CVE should fire a test immediately. Underneath that sits a cadence by business criticality: P1 monthly or on change, P2 quarterly, P3 as events demand.

What should an exposure programme measure?

Validated coverage and time to verdict, rather than asset counts. Asset counts are the metric a discovery-priced tool is built to produce, and they say nothing about whether any exposure was proven.

Is it safe to run AI agents offensively against your own estate?

His stated condition is to automate depth only with scope control, human approval before active exploitation, and a full audit trail.

Five sessions remain, every Thursday through 22 October

Twenty minutes each, live. One registration covers the series. Free

Register free

New to CISO Platform? Join the community free for frameworks, checklists and peer discussion.

Technology Partner: FireCompass. All sessions, speakers and content in this series are produced and delivered by FireCompass. CISO Platform is hosting the series for its community.

Every figure, quote and recommendation above is drawn from the session recording and the slides presented, available here. The single exception is the Patch Tuesday CVE count, which is linked to its source in the text. The HackerOne figures are FireCompass's own, sourced on their slide to their US press release.

Read more…
CISO PLATFORM · BREACH INTELLIGENCE
BREACH WATCH
Daily Breach Intelligence for Security Leaders · September 20, 2026

TL;DR for CISOs: CISA added three Linux kernel flaws to its Known Exploited Vulnerabilities catalog on September 18 with a September 21 federal remediation date, Fortinet reported thousands of blocked attacks against an unauthenticated remote code execution flaw in the Orkes Conductor workflow platform, and CrowdSec disclosed that roughly 170 of its private code repositories were copied through a departed employee's GitHub account that had never been closed.

BOTTOM LINE FOR CISOS
  1. Local privilege escalation has moved up the queue. Three kernel bugs that only work for a user who is already on the box are now confirmed as exploited, which tells you attackers are landing first and escalating second. Your patch tiering probably scores these too low.
  2. Internal orchestration platforms are internet-facing more often than teams think. The Orkes Conductor flaw needs no credentials at all, and the traffic Fortinet is blocking is opportunistic scanning, not targeted work.
  3. Offboarding is a security control, not an HR task. CrowdSec lost source code because one leaver kept GitHub access for a few extra weeks. Ask your team today how many departed staff still hold tokens in your code hosting platform.

Lead story: three Linux kernel flaws confirmed as exploited, with a September 21 federal deadline

CRITICAL · ACTIVELY EXPLOITED
Key facts
CVEs: CVE-2025-39682 (CVSS 9.8, kernel TLS receive path), CVE-2026-53266 (CVSS 8.8, ebtables SNAT ARP rewrite path), CVE-2025-39964 (CVSS 7.8, AF_ALG socket race condition)
Product: Linux kernel
Added to KEV: September 18, 2026
Federal remediation date: September 21, 2026, under Binding Operational Directive 26-04
Vendor status: Red Hat updated its advisories for all three on September 19 to acknowledge active exploitation

What happened

CISA placed three Linux kernel vulnerabilities in the Known Exploited Vulnerabilities catalog across two separate alerts on Friday, September 18, citing evidence that attackers are using them. The most severe, CVE-2025-39682, sits in the kernel's TLS receive path and is scored 9.8. According to CISA's entry, it fails to handle an unexpected condition properly, which can let an authenticated local user read memory that should not be visible to them or crash the system.

The second, CVE-2026-53266, is an out-of-bounds write in the ebtables code that rewrites ARP addresses during source network address translation, scored 8.8. The third, CVE-2025-39964, is a race condition on AF_ALG sockets scored 7.8, where two writes to the same socket can collide and either crash the machine or corrupt the result of a cryptographic operation.

Neither CISA nor the reporting around it describes how the three are being used, or whether they are being combined into one chain. That matters for how you prioritize, and we will say plainly that the exploitation detail is not public. What is public is the vendor reaction: Red Hat revised its advisories for all three on September 19 and told customers to treat them as high priority, noting that public exploit code exists.

The timing sits alongside a separate disclosure. On September 18, researcher Asim Manizada published working exploit code for four other Linux kernel local privilege escalation flaws he reported in mid-July, named DirtyAH6 (CVE-2026-80844), TUNderflow (CVE-2026-81000), PPPoEject (CVE-2026-68121), and DiagSpill (CVE-2026-74469). All four are fixed in current kernels, and there are no reports of them being used in attacks. The two events are not connected, but together they mean the supply of usable local-root code against Linux has grown noticeably in one week.

Evidence

Source 1: The Hacker News, "CISA Flags Three Linux Kernel Vulnerabilities Exploited in the Wild," September 19, 2026
Source 2: Security Affairs, "U.S. CISA adds Linux Kernel flaws to its Known Exploited Vulnerabilities catalog," September 20, 2026
Primary reference: CISA Known Exploited Vulnerabilities Catalog

What this means for your team

Most vulnerability programs push local privilege escalation to the back of the queue because exploitation requires a foothold. That logic held when footholds were expensive. It holds less well now, when initial access is routinely bought, and when the same week produces public exploit code for four more kernel escalation bugs. A confirmed-exploited local escalation flaw is best read as the second half of an attack chain whose first half is already commoditized.

There is a second, quieter exposure. The AF_ALG race condition can corrupt cryptographic results rather than simply crash a process. If you run signing, tokenization, or key derivation on Linux hosts, a silent integrity failure is harder to detect than an outage and harder to explain afterwards. Ask whether your crypto operations would surface a wrong answer or simply return it.

The federal date of September 21 is a useful external anchor when you need to move a maintenance window. You are not bound by it, but it is a defensible number to put in front of an application owner who wants to wait for the next quarterly cycle.

Action checklist
  1. Pull your distribution's advisories for CVE-2025-39682, CVE-2026-53266 and CVE-2025-39964 and identify which of your kernel builds are behind. Container base images and appliance operating systems are the usual blind spots.
  2. Reclassify confirmed-exploited local privilege escalation to your highest patch tier for multi-tenant hosts, developer workstations, CI runners, and anything that accepts untrusted workloads.
  3. Where a reboot cannot happen this week, compensate: restrict who holds interactive shell access on the affected hosts, and alert on unexpected kernel module loads and setuid execution.
  4. Review any cryptographic operation that runs through the kernel crypto API on unpatched hosts, and confirm you would detect a wrong result rather than only a crash.

Orkes Conductor: unauthenticated code execution under opportunistic attack

CRITICAL · ACTIVELY EXPLOITED
Key facts
CVE: CVE-2026-58138 (CVSS v3.1 9.8, CVSS v4 9.3)
Product: Orkes Conductor workflow orchestration platform
Fix: Conductor 3.30.2 or later, released in June 2026
Observed activity: Fortinet reported 1,290 attempts blocked in 24 hours as of September 9, and close to 7,000 between September 2 and 9; Empirical Security recorded in-the-wild exploitation as early as August 21

What happened

Fortinet issued an outbreak alert this week for a flaw that lets anyone who can reach a Conductor server run operating system commands on it without logging in first. Conductor accepts workflow definitions through an API endpoint, and per the NVD description the affected builds evaluate inline JavaScript or Python expressions inside those definitions before authentication is applied. Where the GraalVM evaluator was configured with unrestricted host access, an attacker escapes the scripting sandbox and executes commands with the privileges of the Conductor process.

Fortinet said it observed attackers submitting crafted workflow definitions to the Conductor workflow API. The figures it published show the campaign accelerating: 1,290 attempts blocked in a single day around September 9, which it described as a 132 percent increase in daily activity, and nearly 7,000 across the preceding week. It attributed most of the traffic to sources in Germany, Hong Kong, Indonesia, the United Arab Emirates and India. SecurityWeek, reporting independently on September 18, noted that proof-of-concept code appeared in early August and that exploitation followed shortly after.

Evidence

Source 1: The Hacker News, "Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the Wild," September 19, 2026
Source 2: SecurityWeek, "Critical Orkes Conductor Vulnerability Exploited in Attacks," September 18, 2026

What this means for your team

The interesting number here is not the CVSS score. It is the three-month gap between a fix shipping in June and attack volume climbing in September. That gap is the shape of most workflow and orchestration deployments: installed by a platform or data engineering team, pinned to a version that works, and not carried on any patch calendar the security function owns.

The second point is placement. Conductor is internal software by intent, so it rarely gets the hardening review an external application would. Opportunistic scanning does not respect intent. If an instance answers on a routable address, it is an external application whatever the architecture diagram says.

Finally, consider what a Conductor host can reach. Orchestration platforms hold the credentials needed to drive other systems, so command execution there is rarely contained to that one box.

Action checklist
  1. Ask your platform and data engineering teams directly whether Conductor is running anywhere, including in development and in third-party managed environments. Do not rely on the asset inventory alone.
  2. Upgrade to 3.30.2 or later. If that cannot happen immediately, block external access to the workflow API endpoints and place the instance behind network access controls.
  3. Hunt backwards to at least August 21: look for unexpected process execution by the Conductor service account and for workflow definitions containing inline script expressions that nobody on your team authored.
  4. If you find evidence of execution, rotate every credential the Conductor instance holds before you close the incident.

CrowdSec: 170 private repositories copied through a leaver's account

HIGH · CONFIRMED BY THE AFFECTED COMPANY
Key facts
Organization: CrowdSec, French open-source security company, approximately 150,000 users
What was taken: About 170 private GitHub repositories, cloned on May 22, 2026
Personal data involved: Email addresses of 83 users, plus names, email addresses and investment context for 51 potential investors from 2020
Root cause per the company: A GitHub OAuth token from a former employee whose organization access had been left open; his machine was compromised in the May TanStack npm supply chain attack (CVE-2026-45321)
Disclosure: Leak posted to a forum September 16; first CrowdSec statement September 17; fuller report September 18

What happened

On May 11, 84 malicious versions of 42 TanStack npm packages were published. Installing one of them ran code that harvested credentials from the developer's machine, including GitHub tokens, SSH keys and cloud credentials. Eleven days later, on May 22, someone used a GitHub OAuth token belonging to a CrowdSec employee who had already left to clone roughly 170 of the company's private repositories. CrowdSec had kept his organization access open so he could finish outstanding work, and removed the account on May 25.

The company learned of the leak only when the archive was posted to a forum on September 16. Alongside source code for its web console, data science scripts and models, automation scripts, and the consensus algorithm behind its IP blocklists, the archive held the email addresses of 83 users and details on 51 potential investors from a 2020 system. CrowdSec says the account was used only to copy code, that no commits or changes were made, and that its infrastructure and databases were not reached.

The company's account changed between its two statements, and that is worth noting rather than glossing over. Its September 17 statement said no client data, credentials, names or organizations had leaked, and pointed to a backdoored component inside CrowdSec as the likely path. The September 18 report withdrew both points: no malicious TanStack versions were found in CrowdSec's own code, the route was the former employee's account, and user and investor details were in fact exposed. CEO Philippe Humeau apologized to the investors in the report. The same npm compromise also touched other firms, with Mistral AI citing a developer device and OpenAI citing two employee devices and unauthorized access to a limited set of internal repositories.

Evidence

Source 1: CrowdSec, "TanStack Supply Chain Attack Analysis," September 18, 2026
Source 2: The Hacker News, "CrowdSec Says TanStack npm Attack Led to Copy of 170 Private GitHub Repositories," September 19, 2026

What this means for your team

This is a clean, uncomfortable case study in how a supply chain compromise converts into a data loss months later, through a control nobody thinks of as security. The npm packages were the weapon. The open door was an offboarding exception granted for a sensible operational reason and then left in place. Almost every organization grants that exception.

The detection failure is the part worth taking to your own team. CrowdSec says the token left no usable trace in the GitHub logs it could examine and no longer existed by the time it learned of the leak. Mass cloning of private repositories by a single identity is a detection most organizations assume they have and few have actually tested. It is also, unusually, a detection you can go and validate this week.

One more detail deserves attention on its own terms: the company has stated it did not require endpoint protection on developer machines at the time and has since deployed it. Developer endpoints hold the keys to everything downstream, and they are frequently the least monitored devices in the estate because the people using them ask for the exception.

Action checklist
  1. Run a report today of every account in your code hosting organization that belongs to someone who has left, and every personal access token or OAuth grant older than your offboarding window.
  2. Put a hard expiry on post-departure access. If a leaver genuinely needs a few more days, make it a dated exception with an owner, not an open-ended one.
  3. Build and test a detection for bulk cloning of private repositories by a single identity, and confirm your code hosting audit logs retain long enough to investigate a four-month-old event.
  4. Confirm that endpoint protection is actually enforced on developer laptops, and treat any exception there as a risk decision that a named person signs.

SolarWinds patches a hard-coded key in Access Rights Manager

NOTABLE · NO KNOWN EXPLOITATION
Key facts
CVE: CVE-2026-28326 (CVSS 8.8, vector AV:A, adjacent network)
Product: SolarWinds Access Rights Manager, version 2026.2 and all earlier versions
Cause: A hard-coded static cryptographic key permitting unauthenticated remote code execution
Fix: ARM 2026.2.1; advisory published September 17, 2026
Status: No evidence of exploitation reported; not in the KEV catalog
Credit: Kai Huang of Armadin

What happened

SolarWinds published an advisory on September 17 for a flaw in Access Rights Manager, the product many organizations use to review and certify who has access to what across file shares and directory services. The issue is a hard-coded static key, and exploiting it can give an unauthenticated attacker code execution. The CVSS vector matters for prioritization: the score of 8.8 is calculated with an adjacent network attack vector, meaning the attacker needs to already be on the same network segment rather than reaching the server from the internet. SolarWinds reports no exploitation. The same release cycle also addressed 16 flaws in Serv-U, and earlier fixes covered a SAML authentication bypass in Web Help Desk.

Evidence

Source 1: The Hacker News, "SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCE," September 19, 2026
Source 2: CVE record for CVE-2026-28326, including the SolarWinds CNA entry and CVSS vector

What this means for your team

A hard-coded key is a design defect rather than a coding slip, which means the same key is in every deployment and cannot be rotated by the customer. Once the value is known, every unpatched instance is equally exposed. That is the reason to move on this despite the adjacent-network vector and the absence of exploitation: the barrier to entry drops to zero the moment someone extracts the key from a binary.

The product context sharpens it. Access Rights Manager is an identity governance tool, so it holds broad read access across file systems and directories by design. Code execution on a governance platform is a fast route to understanding, and then abusing, the permission structure of the whole estate.

Action checklist
  1. Upgrade Access Rights Manager to 2026.2.1. Treat it as a privileged management system, not a reporting tool.
  2. Confirm the ARM server sits on a management network segment that ordinary user workstations cannot reach, which directly addresses the adjacent-network vector.
  3. Review the SolarWinds release for the Serv-U fixes at the same time, since those cover privilege escalation and administrator account creation.

Also notable

  • A supply chain attack on the email platform Brevo used compromised Cloudflare access to inject malicious code into customer websites, with more than 100,000 sites potentially affected. Security Affairs, September 18
  • Japanese software company Helpfeel is notifying users of its Gyazo screenshot service after a flaw in an image upload server exposed 23 million user records. Security Affairs, September 18
  • Working exploit code is now public for four separate Linux kernel local privilege escalation flaws, all fixed upstream, with no reports yet of real-world use. The Hacker News, September 18
  • A flaw called Click2Shell in WordPress core lets a crafted link opened by a logged-in administrator install a theme with no click, and can chain to code execution through a second flaw in that theme. Fixed in WordPress 7.1.1. The Hacker News, September 18
  • A flaw named Plugin4Shell lets the owner of a plugin repository swap code that four AI coding agents had pinned to a reviewed commit hash. Anthropic and OpenAI have patched; GitHub Copilot has no fix and Google will not patch the Gemini CLI. The Hacker News, September 18
  • Microsoft patched a maximum-severity privilege escalation flaw in Azure AI Foundry, CVE-2026-85889, scored 10.0. No customer action is required and there is no evidence of exploitation. The Hacker News, September 18

FAQ

Which Linux kernel CVEs did CISA add on September 18, 2026?

CISA added CVE-2025-39682 (CVSS 9.8, kernel TLS receive path), CVE-2026-53266 (CVSS 8.8, ebtables SNAT ARP rewrite path) and CVE-2025-39964 (CVSS 7.8, AF_ALG socket race condition). All three were listed on evidence of active exploitation, with a federal remediation date of September 21, 2026.

Do the Linux kernel flaws allow remote attacks?

No. All three require a local attacker who already has access to the machine. That is why they matter as the escalation stage of an attack chain rather than as an initial entry point, and why teams that deprioritize local privilege escalation should revisit that rule.

Is CVE-2026-58138 in Orkes Conductor being exploited?

Yes. Fortinet issued an outbreak alert and reported blocking 1,290 attempts in a single 24-hour period around September 9 and close to 7,000 between September 2 and 9. Empirical Security recorded in-the-wild exploitation as early as August 21. The fix, version 3.30.2, shipped in June 2026.

What was actually exposed in the CrowdSec incident?

Roughly 170 private GitHub repositories, including the company's web console, data science scripts and models, automation scripts, and its blocklist consensus algorithm, plus the email addresses of 83 users and details on 51 potential investors from 2020. CrowdSec states that its infrastructure and databases were not accessed and that no code was altered.

How did a former employee's account lead to the CrowdSec leak?

The employee had left, but his GitHub organization access was kept open so he could finish outstanding work. His laptop was compromised in the TanStack npm supply chain attack in May, which harvested his GitHub token. An attacker used that token on May 22 to clone the repositories. The account was removed on May 25.

Does the SolarWinds ARM flaw need immediate patching?

There is no reported exploitation and the attack vector is adjacent network rather than internet-facing, so this is not an emergency. It should still be scheduled promptly, because a hard-coded key is identical across every deployment and cannot be rotated by the customer once it becomes public.

What is the single highest-value action from this edition?

Run a report of every account and token in your code hosting platform that belongs to someone who has left. It takes one query, it is the exact failure that cost CrowdSec its source code, and it is almost certainly not clean in your environment either.

Related reading from the community

CISO Platform Breach Intelligence Team
Curated by Pritha Aash, Community Head, CISO Platform
Breach Watch is a daily briefing for senior security leaders. Every item is verified against at least two independent sources before publication, and threat-actor claims are labeled as claims.
Keep the briefing coming

Breach Watch is produced for the CISO Platform community, a vendor-agnostic peer network for senior security leaders. Joining is free.

Join the CISO Platform community (free)

Subscribe to the weekly newsletter · Visit the Breach Intelligence hub

Corrections and takedown requests: CISO Platform is committed to accuracy and fairness. If any detail in this briefing is inaccurate, or if you represent an affected organization and would like a correction or removal, please contact us at pritha.aash@cisoplatform.com and we will review your request promptly.

Read more…
CISO PLATFORM · BREACH INTELLIGENCE
BREACH WATCH
Daily Breach Intelligence for Security Leaders · August 17, 2026

TL;DR for CISOs: The Clop extortion group is running a fresh mass data-theft campaign against internet-exposed PTC Windchill and FlexPLM systems, naming Shell, General Electric, and Philips among 43 claimed victims. The same 24 hours brought two more critical flaws under active exploitation within days of their patches, in SAP Commerce Cloud and VMware vCenter, and France's tax authority admitted a breach affecting 678,000 people and businesses that started with a stolen login rather than any software exploit.

BOTTOM LINE FOR CISOS
  1. Enterprise engineering and product-lifecycle platforms are Clop's new file-transfer target. If PTC Windchill or FlexPLM faces the internet in your estate, treat it as a live target and hunt for webshells now rather than waiting for a leak-site listing.
  2. The window between disclosure and exploitation is now measured in days. SAP Commerce Cloud and VMware vCenter were both attacked within a week of their fixes. Your emergency-patch path for internet-facing systems, not your monthly cycle, is what matters here.
  3. A valid credential is still the quietest way in. The French tax breach used a stolen login and an MFA bypass with no exploit at all. Contractor access reviews and credential-exposure monitoring deserve the same urgency as your vulnerability program.
CRITICAL · LEAD STORY

Clop names Shell, GE, and Philips in a 43-victim PTC Windchill data-theft campaign

PTC Windchill and FlexPLM · Product lifecycle management · Mass exploitation of CVE-2026-12569 for data theft and extortion

Key facts
  • The Clop gang has listed 43 new victims on its leak site, saying it stole data from internet-exposed PTC Windchill and FlexPLM instances by exploiting a critical improper input validation vulnerability tracked as CVE-2026-12569.
  • Philips confirmed that an enterprise server was breached but said the incident was contained and did not affect customer environments. General Electric said it is aware of the claim and working to assess it. Both statements are the companies' own.
  • Shell said on Friday that it is investigating a potential incident after Clop claimed to have taken 89 gigabytes of its data. Shell has not confirmed the gang's figures.
  • PTC says more than 30,000 organizations use its products globally, including over 1,500 brand and retail customers on FlexPLM, across aerospace, defense, automotive, heavy machinery, retail, and medtech.
  • PTC began releasing patches on June 17 and warned of heightened threat activity on June 26. CISA has added the flaw to its Known Exploited Vulnerabilities catalog and set a federal remediation deadline; Germany's BSI issued an overnight warning to customers.

What happened

Windchill and FlexPLM are where manufacturers keep the crown jewels of how a physical product is designed and built: engineering drawings, bills of materials, test reports, and facility documentation. Clop, according to security reporting, has been treating internet-exposed instances of these platforms as a mass-exploitation target, the same playbook it ran against MOVEit, GoAnywhere, Cleo, and Oracle E-Business Suite. Independent confirmation has come from ReliaQuest and the Ransomware Information Sharing and Analysis Centre, which observed the attackers deploying JSP webshells on compromised platforms to pull data out. The 43-victim count and the specific volumes, including the 89 gigabytes attributed to Shell and the lists of blueprints and facility photos, are Clop's own claims. What the named companies have confirmed is narrower: Philips acknowledged a contained breach of one enterprise server with no customer impact, while GE and Shell say they are still investigating. The gap between what a gang claims and what a victim confirms is exactly where a CISO should read carefully.

Evidence

Verified against two independent sources:

What this means for your team

Clop has spent years turning a single flaw in a widely deployed enterprise platform into an industrial-scale extortion pipeline, and it has now settled on product-lifecycle systems as this cycle's soft target. If your organization designs, manufactures, or supplies physical goods, the risk is not only that your own Windchill or FlexPLM instance is exposed; it is that a supplier or contract manufacturer holding your drawings and specifications is. The stolen material in these campaigns is intellectual property with a long shelf life, so the damage is not a one-week news story but a multi-year exposure of how your products are made. Because the patches have been available since mid-June, an unpatched internet-facing instance today is less a vulnerability-management gap than an incident waiting to be scoped.

Action checklist
  1. Inventory every PTC Windchill and FlexPLM instance you run, confirm none is internet-exposed, and apply PTC's CVE-2026-12569 patches immediately if any is unpatched.
  2. Hunt for JSP webshells and other indicators of compromise on those platforms now, using PTC's advisory and the ReliaQuest and Ransom-ISAC guidance, on the assumption that patching alone does not evict an attacker already inside.
  3. Ask suppliers and contract manufacturers that hold your engineering data whether they run these platforms and how they have responded, since your IP can leak through their environment.
  4. Prepare a holding position for legal and communications in case your organization appears on the leak site, and separate confirmed facts from Clop's claims before responding publicly.
HIGH

Max-severity SAP Commerce Cloud flaw exploited three days after its patch

SAP Commerce Cloud · E-commerce platform · Unauthenticated remote code execution, CVE-2026-58231

Key facts
  • CVE-2026-58231 carries a maximum CVSS score of 10 and stems from insufficient authorization checks and input validation. It can be exploited to run arbitrary code and compromise internal components.
  • SAP shipped the fix on August 11 as part of its monthly patch day. Threat-intelligence firm Defused reported honeypot exploitation attempts on August 14, three days later, with no public proof-of-concept at that point.
  • KEVIntel independently confirmed exploitation attempts through its own sensors, and noted on August 15 that a proof-of-concept exploit had become available.
  • As of publication, CISA had not yet added CVE-2026-58231 to its Known Exploited Vulnerabilities catalog, so federal timelines do not yet apply.

What happened

SAP Commerce Cloud sits underneath large business-to-business and business-to-consumer storefronts, which makes a pre-authentication code-execution flaw in it a direct line to order data, customer records, and the systems behind them. Two separate threat-intelligence organizations reported attackers probing the flaw within days of the patch, before any public exploit code existed, which points to adversaries reverse-engineering SAP's fix to locate the vulnerable path. By August 15 a working proof-of-concept was circulating, lowering the bar for less sophisticated actors to join in. The pattern here, exploitation arriving before most enterprises have finished testing the patch, is the recurring story of 2026 rather than an outlier.

Evidence

What this means for your team

If you run SAP Commerce Cloud, the safe assumption is that opportunistic scanning for this flaw is already underway and that a proof-of-concept is in circulation. The exposure is not limited to the storefront itself; a foothold on the platform can reach the databases and internal components it connects to, which is where payment and customer data live. Retail and consumer-facing organizations that treat commerce infrastructure as a business system rather than a security-critical one will feel this gap most, because the teams that operate these platforms are often separate from the security function that needs to drive the emergency patch.

Action checklist
  1. Identify every internet-facing SAP Commerce Cloud instance and confirm the August 11 patch for CVE-2026-58231 is applied, escalating any that are not through your emergency-change process.
  2. Review web and application logs for the exposure window between August 11 and patch completion for signs of exploitation, rather than assuming a clean patch means no compromise.
  3. Restrict administrative and management interfaces to trusted networks and monitor for unexpected code execution or outbound connections from the platform.
HIGH

Suspected state-linked campaign exploits VMware vCenter for persistent access

VMware vCenter Syslog Server · Virtualization management · Unauthenticated RCE, CVE-2026-59310

Key facts
  • CVE-2026-59310 is a critical directory-traversal flaw in the vCenter Syslog server, rated 9.8, that lets an unauthenticated attacker with network access execute arbitrary code. Broadcom disclosed it and shipped an emergency patch on July 29.
  • Incident-response firm QUIRSO reported that exploitation began on August 3, five days after disclosure, and identified 361 victim IP addresses across 47 countries by August 7. Germany, the United States, Turkey, Iran, and France accounted for 185 of them.
  • After exploitation, the attacker deploys the open-source reverse_ssh tool through a malicious cron job to establish persistence and an outbound command-and-control channel that can bypass firewalls.
  • QUIRSO assessed with moderate confidence that a Chinese-speaking threat actor is behind the campaign, based on time-zone and language artifacts, while cautioning that firm attribution is not established. Coverage tying the activity to a suspected China-nexus group continued into August 17.

What happened

vCenter is the control plane for an organization's virtual infrastructure, which is why it is a perennial target: control it and you can reach the virtual machines, hosts, and permissions beneath it. This campaign moved fast, from a July 29 disclosure to active exploitation on August 3 and hundreds of compromised systems within a week, and the attacker's choice of a reverse SSH channel is a deliberate move to keep quiet, persistent access rather than to smash and grab. The suspected state alignment matters less than the mechanics for most defenders. What stands out is the speed and the target selection: an unauthenticated flaw in a management plane, weaponized before many organizations had scheduled the patch. We are attributing the state-nexus assessment to QUIRSO and treating it as a working hypothesis, not a settled fact.

Evidence

What this means for your team

A compromised vCenter is not one server; it is leverage over everything that runs on top of it, which is why an attacker willing to invest in stealthy persistence is a worse problem than a ransomware crew that announces itself. Because the campaign uses a legitimate open-source tool for its command-and-control, signature-based detection will miss it, and the same YARA rule that catches the malicious use will also flag sanctioned use of reverse_ssh in your environment. That ambiguity is the point: defenders need to know where reverse SSH is expected before they can spot where it is not. Any organization that left vCenter reachable and unpatched through early August should treat this as a hunt, not a patch.

Action checklist
  1. Confirm vCenter is updated to a fixed build (9.1.0.0300, 9.0.2.0100, or 8.0 U3k/U2f) and is not reachable from untrusted networks.
  2. Run QUIRSO's reverse_ssh YARA rule and review cron jobs and outbound connections on vCenter hosts, first establishing where legitimate SSH tooling is expected so alerts are meaningful.
  3. If any instance was exposed and unpatched before early August, scope it as a potential intrusion and check for persistence rather than assuming the later patch closed the door.
HIGH

France's tax authority discloses breach of 678,000 people and businesses

DGFiP · Public sector · Stolen credentials and MFA bypass, no software exploit

Key facts
  • France's General Directorate of Public Finances (DGFiP) says an intrusion exposed data on 678,000 individuals and professionals. SecurityWeek reported the figure as 680,000; the exact number in the DGFiP statement is 678,000.
  • The attacker gained access using valid login credentials and an MFA bypass technique, not a software vulnerability. DGFiP suspended the affected accounts once the intrusions were detected.
  • Exposed data includes reference tax income, family quotient, and withholding tax rate for individuals, and company name and SIREN number for businesses, along with cadastral data such as addresses and property sizes.
  • DGFiP says online tax portals were not compromised and that usernames and passwords were not taken. It has notified France's data protection authority, CNIL, and is working with the ANSSI cybersecurity agency.

What happened

The breach surfaced when an actor using the handle "ZeroBytes" claimed the intrusion on a cybercrime forum and listed a database for sale, prompting DGFiP's investigation. The agency's account is careful: it says access was gained through credentials and an MFA bypass, that it suspended those accounts, and that deeper analysis since August 12 established that data on 678,000 people and businesses had been consulted and extracted before the access was cut off. ZeroBytes has made far larger claims, saying the portal held data on roughly 20 million citizens and that they extracted 252,149 records covering more than two million people, but those numbers are the attacker's and are not confirmed by DGFiP. This is the latest in a run of incidents affecting French government systems this year.

Evidence

What this means for your team

The most instructive detail is what did not happen: no zero-day, no unpatched server, just a working login and a way around multi-factor authentication. That should reframe how much of your defensive budget assumes the threat arrives as an exploit. An MFA bypass, whether through phishing-resistant gaps, session-token theft, or social engineering of a help desk, turns strong-on-paper authentication into a single point of failure. For any organization holding sensitive records for large populations, this case argues for watching how privileged and contractor accounts actually behave after login, because the controls at the door held up right until they did not.

Action checklist
  1. Review your MFA implementation for bypass paths, prioritizing phishing-resistant methods for high-value systems and tightening help-desk identity verification.
  2. Monitor for anomalous behavior after authentication, such as bulk data access or unusual query volumes, so a valid-but-stolen session is caught in use.
  3. Audit contractor and third-party accounts with access to sensitive data stores, confirming least privilege and prompt deprovisioning.

Also notable

  • Cryptocurrency wallet maker SafePal is warning roughly 40,000 customers of a data breach that exposed order information after a flaw was exploited. SecurityWeek
  • Attackers are exploiting a recent macOS Screen Sharing vulnerability to deploy a Monero cryptocurrency miner on compromised Macs. BleepingComputer
  • A threat actor claims to have stolen 3.6 million Azure account records from major companies, part of a broader Azure data-theft campaign researchers are tracking. BleepingComputer
  • Pokemon Center disclosed a data breach that exposed customer information and forced the cancellation of some orders. BleepingComputer

FAQ

What is CVE-2026-12569 and who is affected?

It is a critical improper input validation vulnerability in PTC Windchill and FlexPLM that the Clop gang is exploiting on internet-exposed instances to steal data. PTC says more than 30,000 organizations use its products across aerospace, defense, automotive, heavy machinery, retail, and medtech. Patches have been available since June 17.

Have Shell, GE, and Philips confirmed the Clop breach?

Philips confirmed a contained breach of one enterprise server with no customer impact. GE and Shell say they are investigating and have not confirmed Clop's specific claims, including the 43-victim count and the 89 gigabytes attributed to Shell, which remain the gang's assertions.

How urgent are the SAP Commerce Cloud and VMware vCenter flaws?

Both are being exploited in the wild within days of disclosure. SAP Commerce Cloud (CVE-2026-58231, CVSS 10) was targeted three days after its August 11 patch, and VMware vCenter (CVE-2026-59310, CVSS 9.8) has been exploited since August 3 across dozens of countries. Patch both on an emergency basis and check for compromise.

How did the French tax authority breach happen?

DGFiP says the attacker used valid login credentials and an MFA bypass, not a software exploit. Data on 678,000 individuals and businesses was extracted, including tax and cadastral information, but DGFiP says the online portals, usernames, and passwords were not compromised.

Is the VMware vCenter campaign confirmed to be a Chinese state operation?

No. Incident-response firm QUIRSO assessed with moderate confidence that a Chinese-speaking actor is responsible, based on time-zone and language artifacts. That is a working hypothesis, not a confirmed attribution, and should be treated as such.

CISO Platform Breach Intelligence Team
Explore more in the CISO Platform Breach Intelligence hub, and related community coverage on ransomware, data breaches, and threat intelligence.
Stay ahead of the next breach
Join the CISO Platform community (free) to compare notes with 6,000+ security leaders.
Subscribe to the weekly newsletter for the breach and AI-risk roundup.
Visit the Breach Intelligence hub for the full archive.

Corrections and takedown requests: CISO Platform is committed to accuracy and fairness. If any detail in this briefing is inaccurate, or if you represent an affected organization and would like a correction or removal, please contact us at pritha.aash@cisoplatform.com and we will review your request promptly.

Read more…
CISO PLATFORM · BREACH INTELLIGENCE
BREACH WATCH
Daily Breach Intelligence for Security Leaders · August 14, 2026

TL;DR for CISOs: An extortion crew leaked data tied to 1.6 million RingCentral customers after a social engineering campaign, and the same 24 hours brought a supply chain attack that reached more than 2,500 organizations through an AI library, a cross-border takedown of a bank fraud crew, and a fresh public exploit that turns Microsoft Defender into a route to SYSTEM on fully patched Windows.

BOTTOM LINE FOR CISOS
  1. People are the initial access. The RingCentral leak, the bank fraud scheme, and most large 2026 breaches start with someone being tricked or a trusted supplier being subverted, not a firewall being brute forced.
  2. Your software build pipeline is now part of your attack surface. The LiteLLM incident shows how one leaked token, three tools deep, can expose hundreds of thousands of CI/CD pipelines before anyone notices.
  3. A patched endpoint is not automatically a safe one. A working exploit against Microsoft Defender on fully updated Windows is a reminder to treat local privilege escalation as a live risk, not a theoretical one.
CRITICAL · LEAD STORY

ShinyHunters leak exposes data on 1.6 million RingCentral customers

RingCentral · Cloud business communications · Social engineering to data theft and extortion

Key facts
  • RingCentral says the incident happened in July and resulted from a sophisticated social engineering campaign. It states that only a limited portion of customers was affected and that those individuals were notified directly.
  • The extortion group ShinyHunters added RingCentral to its leak site in late July, claiming more than 623 gigabytes of data, then published a 280 gigabyte archive after the company declined to pay.
  • Breach-notification service HaveIBeenPwned added the leaked data on August 13, listing roughly 1.6 million unique email addresses accompanied by names, addresses, and phone numbers.
  • RingCentral says the core platform was not affected and services continued to run. It has not confirmed the attackers' claims or the number of impacted individuals.

What happened

RingCentral is a cloud provider of business phone, messaging, video, and contact-center services, so its customer records sit close to how thousands of organizations reach their own staff and clients. According to the company, attackers used social engineering rather than a software flaw to reach customer information, and RingCentral moved to stop the activity once it was detected. The number now circulating, 1.6 million, comes from the count of unique email addresses that HaveIBeenPwned catalogued from the leaked archive, alongside names, postal addresses, and phone numbers. The figure and the underlying data set trace to the ShinyHunters group's own claims and published files, which RingCentral has not independently verified.

Evidence

Verified against two independent sources:

What this means for your team

A vendor that helps you talk to customers holds a directory of who those customers are. When that directory leaks, the risk is not just embarrassment for the vendor; it is a ready-made target list for the phishing and voice-fraud campaigns your users will see next. This case also fits a pattern that has defined 2026: an extortion group walked in through a human, not a zero-day. The contact details in the archive are exactly what a caller needs to sound legitimate, so the immediate exposure is downstream social engineering against your workforce and your own customers.

Action checklist
  1. Confirm whether your organization is a RingCentral customer and ask your account team directly whether any of your users were in the notified group, rather than waiting to be told.
  2. Warn staff and, where appropriate, customers that names, emails, addresses, and phone numbers may be in criminal hands, and to treat unexpected calls or messages referencing RingCentral with suspicion.
  3. Review how your own help desk and vendors verify identity over the phone, since the same social engineering playbook used here works against any organization with weak call-back procedures.
HIGH

One leaked token exposed 2,500-plus organizations through an AI library

LiteLLM · Open source AI proxy · Build-pipeline supply chain compromise

Key facts
  • CloudSEK reports that the LiteLLM supply chain attack, which happened earlier in 2026, likely affected more than 2,500 organizations and exposed over 434,000 CI/CD pipelines.
  • LiteLLM was not targeted directly. Its build pipeline automatically pulled in a compromised version of Aqua Security's Trivy scanner, which in turn poisoned two LiteLLM releases, versions 1.82.7 and 1.82.8, published to PyPI.
  • The malicious code ran on every Python invocation with no explicit import. The two packages were live for roughly 40 minutes, long enough for automated systems to propagate them.
  • CloudSEK cautions that the figures describe reconstructed exposure, not proof that every organization was compromised. SOCRadar has since reported that most affected organizations were likely hit earlier via the Trivy incident rather than through LiteLLM.

What happened

The threat actor CloudSEK tracks as TeamPCP has been chaining open source compromises together, and this one shows why that approach scales. A single unrevoked credential led from Trivy into the LiteLLM build system and then into a LiteLLM release, which CloudSEK summarizes as one token, three tools deep. Because automated build systems copy artifacts quickly, a malicious package that lives for less than an hour can still reach scheduled jobs, dependency resolvers, ephemeral runners, and developer laptops. CloudSEK's exposure list names large enterprises across technology, finance, pharmaceuticals, and manufacturing, while stressing that inclusion reflects potential exposure that each organization must verify for itself. The secrets within reach of the library included cloud keys, SSH keys, tokens, environment variables, and AI provider keys.

Evidence

What this means for your team

The interesting detail is not the raw victim count, which is contested, but the mechanism. An AI component became the pivot point because it sits at a junction of data, identity, compute, and automated action, and it was reached without anyone attacking it head on. If your teams pull AI libraries and scanners straight into CI, then the trust you place in one upstream tool is inherited by everything your pipeline touches. CloudSEK's own view is that the next major supply chain attack is likely to aim at the AI layer precisely because it connects to everything else.

Action checklist
  1. Check whether LiteLLM 1.82.7 or 1.82.8, or the affected Trivy build, ever entered your pipelines or developer environments, and treat any secret reachable by them as compromised.
  2. Rotate exposed credentials, service accounts, and sessions, then review build and registry logs to scope the exposure window rather than assuming package removal closed it.
  3. Pin dependency versions, require signed artifacts, and scope build tokens narrowly so a single leaked credential cannot chain across tools.
HIGH

Police arrest bank fraud crew that drained 30 million euros through a payment provider flaw

Commerzbank customers · Financial services · Third-party payment vulnerability and money laundering

Key facts
  • German and Brazilian authorities announced this week that four suspects were arrested in Brazil and three more were charged in Europe, to be prosecuted in Spain and Bulgaria.
  • Over four days in November 2023, the group made numerous unauthorized withdrawals from German online banking accounts by exploiting a vulnerability at a payment provider, causing losses of around 30 million euros.
  • Germany's BKA said the flaw was introduced by a faulty software update in a payment and transaction-processing system. Brazilian media identified the affected bank as Commerzbank, which confirmed customers were impacted but suffered no financial losses.
  • Brazil's Operation Klonen executed 21 search-and-seizure warrants, and courts ordered the seizure of assets, vehicles, and real estate worth more than 20 million dollars.

What happened

The scheme is a study in how a supplier weakness becomes a bank's problem. According to the BKA, a bad software update opened a hole in a payment processor, and the attackers used it to pull money from customer accounts, then laundered the proceeds through pass-through accounts, companies, virtual-asset platforms, and payment cards issued without the account holders' consent. The largest share was cashed out in Brazil, with the rest spread across four European countries. Investigators added a memorable twist: Brazilian police said one suspect had run for elected office in 2024 and used part of the stolen funds for the campaign, and separately seized a 3D printer used to make weapons. Commerzbank said it cooperated closely with the authorities and that its customers were made whole.

Evidence

What this means for your team

The arrests are a genuine win, but the cause should hold a CISO's attention: the money moved because a third party's software update went wrong, not because the bank itself was breached. For any organization that depends on payment processors, clearing houses, or transaction platforms, this is a reminder that a supplier's change management is part of your fraud exposure. The nearly three-year gap between the 2023 theft and these 2026 arrests also underscores that recovery and attribution are slow, so prevention and rapid detection at the supplier boundary matter far more than the hope of clawing funds back later.

Action checklist
  1. Map which payment and transaction providers sit in your money-movement path and ask each how they test and stage software updates before production.
  2. Set alerting on abnormal transaction patterns and bulk unauthorized debits so a supplier-side flaw is caught in hours, not days.
  3. Confirm your contracts define breach notification and liability when a provider's own change causes customer losses.
HIGH

New 'ShieldBreak' exploit turns Microsoft Defender into a path to SYSTEM

Microsoft Defender · Windows privilege escalation · Public proof-of-concept, unpatched

Key facts
  • A researcher known as Nightmare Eclipse published a proof-of-concept named ShieldBreak after Microsoft's August 2026 Patch Tuesday, describing it as a full bypass of the earlier RoguePlanet fix (CVE-2026-50656).
  • According to the researcher, ShieldBreak grants SYSTEM privileges on fully patched Windows 10, Windows 11, and Windows Server, and requires Microsoft Defender to be enabled to work.
  • The technique abuses a user-mode callback hook to change file contents during a Defender cloud-hydration scan through the Cloud Filter API, a different mechanism than RoguePlanet used.
  • Vulnerability analysts Will Dormann and Kevin Beaumont confirmed the exploit works, and Beaumont published detection queries. Microsoft said it is investigating the claims.

What happened

ShieldBreak is the latest in a run of Defender and Windows privilege-escalation exploits this researcher has released since April, and it arrives amid a public dispute with Microsoft over disclosure and bug bounty practices. The important point for defenders is narrow but real: this is a working, publicly available exploit with no official patch, and it targets the security agent itself. There is no confirmed in-the-wild abuse yet, so this is a proof-of-concept risk rather than an active campaign, but privilege-escalation code that lands on a fully updated machine tends to get folded into attacker toolkits quickly. It does not grant initial access on its own; an attacker still needs a foothold before using it to climb to SYSTEM.

Evidence

What this means for your team

Privilege escalation rarely makes headlines because it is not the way in, but it is often the step that turns a minor foothold into full control of a host. A public exploit against Defender on patched systems means your endpoint detection and internal segmentation are doing more of the work than your patch level suggests. Until Microsoft ships a fix, treat local privilege escalation as a live gap and lean on behavioral detection rather than assuming an up-to-date machine is safe.

Action checklist
  1. Load the publicly shared ShieldBreak detection queries into your endpoint detection tooling and alert on the behavior while a patch is pending.
  2. Reduce the value of a SYSTEM escalation by tightening host segmentation, limiting local admin, and monitoring for unexpected privilege changes.
  3. Track Microsoft's advisory and stage the fix for rapid deployment once it is released.

Also notable

  • More than 1,000 charities and nonprofits were caught in a data breach at UK CRM provider Beacon, after attackers downloaded customer database backups. SecurityWeek
  • Roughly 14,000 Trezor customers had names, addresses, emails, and phone numbers stolen in a breach at fulfillment partner ShipMonk, another third-party exposure. SecurityWeek
  • Attackers are exploiting an unpatched zero-day in the widely deployed GeoServer open source geospatial platform. SecurityWeek
  • A max-severity SAP Commerce Cloud flaw is now being targeted in attacks, raising the stakes for enterprises running the platform. BleepingComputer
  • A new macOS infostealer named AmnesiaStealer is spreading through ClickFix lures that impersonate GitHub download pages. SecurityWeek

FAQ

How many people were affected by the RingCentral breach?

Have I Been Pwned catalogued roughly 1.6 million unique email addresses from the leaked archive, along with names, addresses, and phone numbers. RingCentral says only a limited portion of customers was affected and has not confirmed the attackers' total.

Was the RingCentral core platform compromised?

RingCentral says the incident stemmed from a social engineering campaign in July, that the core platform was not impacted, and that services continued to operate. Affected individuals were notified directly.

Do I need to worry about LiteLLM 1.82.7 or 1.82.8?

If either version, or the affected Trivy build, entered your pipelines or developer machines, treat any secret reachable by them as exposed and rotate it. CloudSEK notes its 2,500-plus figure is reconstructed exposure, not confirmed compromise, and each case should be verified independently.

Is the Commerzbank fraud an active threat now?

No. The theft occurred over four days in November 2023, and the news is that police made arrests this week. The lesson is about third-party payment risk: the flaw came from a supplier's faulty software update, not from the bank itself.

Is ShieldBreak being exploited in the wild?

There is no confirmed in-the-wild abuse yet. It is a public proof-of-concept that grants SYSTEM privileges on fully patched Windows when Defender is enabled, and independent analysts confirmed it works. Treat it as a live privilege-escalation risk until Microsoft issues a fix.

CISO Platform Breach Intelligence Team
Explore more in the CISO Platform Breach Intelligence hub, and related community coverage on supply chain security, data breaches, and threat intelligence.
Stay ahead of the next breach
Join the CISO Platform community (free) to compare notes with 6,000+ security leaders.
Subscribe to the weekly newsletter for the breach and AI-risk roundup.
Visit the Breach Intelligence hub for the full archive.

Corrections and takedown requests: CISO Platform is committed to accuracy and fairness. If any detail in this briefing is inaccurate, or if you represent an affected organization and would like a correction or removal, please contact us at pritha.aash@cisoplatform.com and we will review your request promptly.

Read more…
CISO PLATFORM · BREACH INTELLIGENCE
BREACH WATCH
Daily Breach Intelligence for Security Leaders · August 13, 2026

TL;DR for CISOs: A critical VMware vCenter flaw (CVE-2026-59310) is being exploited in the wild to plant persistent access on hundreds of servers worldwide, and three more high-impact issues, a CVSS 10 Metabase zero-day, a state-backed Gunra ransomware advisory, and a Lazarus Windows kernel zero-day, all landed in the same 24 hours.

BOTTOM LINE FOR CISOS
  1. Patching your edge and management plane is necessary but not sufficient. Two of today's items involve attackers who were already inside before the fix landed, so treat exposed vCenter, Fortinet, and RMM systems as compromise-until-proven-clean.
  2. Business intelligence and automation tools are now credential vaults. The Metabase flaw shows how one internet-facing analytics box can hand over every downstream database credential it holds.
  3. Federal agencies have a August 14 deadline on the Metabase flaw. If a US government due date is measured in days, your private-sector risk window is the same.
CRITICAL · LEAD STORY

VMware vCenter flaw exploited to hold persistent access on 361 systems

CVE-2026-59310 · Broadcom VMware vCenter · Directory traversal to remote code execution

Key facts
  • CVE-2026-59310, CVSS 9.8, a directory-traversal flaw in the vCenter Syslog service that lets an unauthenticated attacker with network access run arbitrary code.
  • Researchers at German firm QUIRSO counted 361 unique victim IP addresses across 47 countries, cautioning that one IP does not always equal one organization.
  • Compromised hosts first contacted attacker infrastructure on August 3, five days after Broadcom disclosed the flaw. By August 5, roughly 95% of the victims had appeared.
  • Fixed releases are vCenter 9.1.0.0300, 9.0.2.0100, and 8.0 U3k or 8.0 U2f. Broadcom has published no workaround.

What happened

Broadcom published its advisory for two critical vCenter flaws on July 29 and revised it on August 3 to add express patches. QUIRSO says it uncovered active exploitation of one of them, CVE-2026-59310, during an incident response engagement and published its analysis on August 10. The attack chain showed path-traversal activity matching the flaw, followed by a malicious cron job that used reverse_ssh, an open-source reverse-shell framework, to keep a foothold on the host.

Because reverse_ssh dials outbound to attacker-controlled infrastructure rather than accepting inbound connections, it slips past controls built to block unsolicited inbound traffic. Germany, the United States, Turkey, Iran, and France accounted for 185 of the 361 victim IPs. QUIRSO attributes the campaign to a suspected advanced persistent threat actor but has not named one. Separately, Defused Cyber reported a scanning spike against the second flaw, CVE-2026-59309, a CVSS 9.8 authentication bypass in VMware Directory Service, though QUIRSO says there is not yet enough evidence to link that scanning to the intrusion set it investigated.

Evidence

Verified against two independent sources:

What this means for your team

vCenter sits at the center of most virtualized estates, so a foothold there is a foothold over the workloads it governs. The five-day gap between disclosure and mass exploitation is the real lesson: the advisory itself appears to have been the starting gun. As Sectigo's Jason Soroko put it, there are two clocks to manage, one for closing the hole and one for evicting anyone who walked through it first. If your vCenter was internet-reachable in late July, a clean patch does not answer the second question.

Action checklist
  1. Confirm every vCenter appliance is on a fixed build (9.1.0.0300, 9.0.2.0100, 8.0 U3k, or 8.0 U2f) and remove any management interface from direct internet exposure.
  2. Hunt for reverse_ssh, unexpected cron jobs, and outbound connections from vCenter hosts to unfamiliar domains, treating any exposed appliance as potentially compromised before August 3.
  3. Rotate vCenter and single sign-on credentials and review SAML and vmdir authentication logs for the second flaw, CVE-2026-59309.
CRITICAL

Metabase zero-day scored a perfect 10 and had already breached five companies

CVE-2026-72898 · Metabase self-hosted · Unauthenticated SQL injection to admin takeover

Key facts
  • CVE-2026-72898, CVSS 10.0, an SQL injection in a password-reset API endpoint that lets an unauthenticated attacker with HTTP access gain administrator control of the instance.
  • Affects self-hosted Metabase versions 0.58 through 0.63.4.
  • CISA added the flaw to its Known Exploited Vulnerabilities catalog on August 11, with a federal remediation deadline of August 14, 2026.
  • Metabase disclosed the issue on August 6. By then, according to reporting, five companies had already lost customer data.

What happened

Metabase is a widely used business-intelligence layer that stores connection strings for the databases it queries, from Snowflake and BigQuery to Oracle, MongoDB, and Amazon Redshift. An attacker who reaches administrator level can change configuration, read those stored credentials, and pivot into every connected system. Workflow-automation vendor n8n disclosed that an unauthorized party used the flaw to query its Metabase environment and obtain 136 customer records. CISA listed the flaw alongside a Cisco Secure Firewall ASA and FTD vulnerability in the same catalog update.

Evidence

What this means for your team

Analytics and automation tools rarely get the same scrutiny as the databases behind them, yet they concentrate exactly the credentials an attacker wants. A single internet-facing Metabase box with stored warehouse credentials is a master key. The federal deadline of August 14 is a useful yardstick: if the government considers this a days-not-weeks problem, so should you.

Action checklist
  1. Patch self-hosted Metabase off the 0.58 to 0.63.4 range immediately and take any internet-facing instance behind VPN or SSO.
  2. Assume credential exposure: rotate the stored credentials for every database, warehouse, LDAP, and SMTP connection your Metabase instances hold.
  3. Review Metabase and downstream database logs for unexpected admin creation, configuration changes, or bulk queries since early August.
HIGH

FBI and Korean police warn Gunra ransomware is hitting critical infrastructure through old Fortinet flaws

CVE-2024-55591 and CVE-2025-24472 · FortiOS and FortiProxy · Ransomware-as-a-service

Key facts
  • A joint advisory (AA26-222A) from the FBI, CISA, other US agencies, and the Republic of Korea National Police Agency, published August 10, details Gunra's tactics.
  • Gunra exploits two patched Fortinet authentication-bypass flaws, CVE-2024-55591 (critical) and CVE-2025-24472 (high), to gain super-admin access to internet-facing appliances.
  • Victims span healthcare, financial services, government, and critical manufacturing worldwide. Ransom demands start in the tens of millions.
  • The group, built on leaked Conti source code and also operating as "Golden Community," works between 10pm and 6am in the victim's time zone to avoid detection.

What happened

Gunra affiliates use known VPN and firewall flaws for initial access, then move laterally with stolen credentials and authentication-bypass tricks. In observed cases they abused default credentials on an SSL-VPN appliance, installed OpenSSH to tunnel out, and modified authentication files on a corporate VDI portal to bypass multi-factor authentication continuously. The group exfiltrates large volumes of data from Microsoft 365, OneDrive, and SharePoint, in one case moving tens of terabytes to the file-sharing service Mega before encrypting, then extorts victims twice, once for decryption and once to keep the stolen data offline. As iCOUNTER's Roman Sannikov noted, if detection coverage drops overnight, that is exactly the window this group is built to exploit.

Evidence

What this means for your team

The flaws Gunra favors were patched more than a year ago, which is the uncomfortable point: patch coverage without eviction leaves the door open. One expert quoted in the advisory coverage described closing a Fortinet vulnerability while an authentication backdoor sat untouched in the MFA flow. Edge devices remain the single most common ransomware entry point, and the after-hours operating pattern is a direct argument for round-the-clock detection coverage.

Action checklist
  1. Confirm FortiOS and FortiProxy appliances are patched for CVE-2024-55591 and CVE-2025-24472, and audit for backdoor admin accounts and modified authentication files.
  2. Maintain offline, immutable backups in a segmented location, and test recovery so a ransom payment is never the only path back.
  3. Extend detection and response coverage into the 10pm to 6am window and alert on OpenSSH tunneling and large outbound transfers to services like Mega.
HIGH

Lazarus used a Windows kernel zero-day to hit defense and aerospace firms

CVE-2026-68820 · Windows AFD.sys · Privilege escalation to SYSTEM

Key facts
  • CVE-2026-68820, CVSS 7.0, a use-after-free race condition in AFD.sys, the Windows Ancillary Function Driver for WinSock, that grants SYSTEM privileges.
  • Microsoft patched the flaw on August 11 after finding it exploited in the wild; evidence points to exploitation since at least early July.
  • Check Point Research attributes the activity to North Korea's Lazarus Group as part of the long-running Operation Dream Job campaign.
  • Confirmed targeting of defense, aerospace, and aviation organizations in France, Germany, Brazil, and India, with a focus on military technology, drones, and robotics.

What happened

Operation Dream Job lures targets with fake recruitment offers. In this wave, once a system was compromised, the attackers used the AFD.sys zero-day to escalate to SYSTEM and deploy a new version of the FudModule kernel-mode rootkit, which is built to disable security tooling from below the operating system. The campaign is a reminder that a mid-scored privilege-escalation bug becomes a strategic weapon when it is chained behind a convincing social-engineering front and used to plant a rootkit.

Evidence

What this means for your team

If your organization touches defense, aerospace, or advanced manufacturing, the recruitment lure is aimed at your people, not just your perimeter. The August Patch Tuesday fix closes the escalation path, but the initial access depends on an employee opening a weaponized file. Pair rapid kernel patching with hiring-adjacent phishing awareness for engineering and research staff.

Action checklist
  1. Deploy the August 11 Windows updates that fix CVE-2026-68820, prioritizing endpoints used by engineering, R&D, and defense-program staff.
  2. Hunt for FudModule rootkit indicators and unexplained SYSTEM-level activity on recently targeted hosts.
  3. Brief technical staff on the fake-job-offer lure and route unsolicited recruitment attachments through a sandbox.

Also notable

  • N-able N-central authentication bypass (CVE-2026-18577, CVSS 8.2): attackers took over RMM servers after an incomplete first patch, reached managed endpoints via Take Control, and persisted with Cloudflare tunnels. Upgrade to build 2026.3.1.7. The Hacker News
  • Cisco Secure Firewall ASA and FTD heap-inspection flaw (CVE-2026-20349) was added to the CISA KEV catalog on August 11 in the same update as the Metabase flaw. CISA
  • Adobe Commerce and Magento (CVE-2026-71362): first exploitation attempts appeared shortly after patches, with a risk of customer account hijack. BleepingComputer
  • Microsoft SharePoint security-feature bypass (CVE-2026-55040): exploitation began after proof-of-concept code was published; the flaw was patched in July. SecurityWeek
  • CERT.PL reported Russian-linked hackers reached a Polish power plant OT network through a private APN. Infosecurity Magazine

FAQ

Is CVE-2026-59310 being actively exploited?

Yes. Researchers at QUIRSO documented active exploitation across 361 victim IP addresses in 47 countries, with the first compromises appearing on August 3, five days after Broadcom disclosed the flaw.

Which Metabase versions are affected by CVE-2026-72898?

Self-hosted Metabase versions 0.58 through 0.63.4. The flaw carries a CVSS score of 10.0 and CISA set a federal remediation deadline of August 14, 2026.

Why does patching alone not close out these incidents?

In the vCenter, Fortinet, and N-able cases, attackers established persistence before or despite the patch. A fix removes the entry point but does not evict an intruder who is already inside or remove backdoors planted on other systems.

Who is behind the Gunra ransomware campaign?

Gunra is a ransomware-as-a-service operation built on leaked Conti source code, also operating under the alias "Golden Community." The joint US and Republic of Korea advisory details its tactics but does not attribute it to a single nation-state.

What is the fastest way to prioritize today's items?

Start with anything internet-facing: vCenter, Metabase, and Fortinet appliances first, then apply the August 11 Windows kernel patch to high-value engineering and defense endpoints.

CISO Platform Breach Intelligence Team
Explore more in the CISO Platform Breach Intelligence hub, and related community coverage on ransomware, vulnerability management, and threat intelligence.
Stay ahead of the next breach
Join the CISO Platform community (free) to compare notes with 6,000+ security leaders.
Subscribe to the weekly newsletter for the breach and AI-risk roundup.
Visit the Breach Intelligence hub for the full archive.

Corrections and takedown requests: CISO Platform is committed to accuracy and fairness. If any detail in this briefing is inaccurate, or if you represent an affected organization and would like a correction or removal, please contact us at pritha.aash@cisoplatform.com and we will review your request promptly.

Read more…

 

CISO PLATFORM · BREACH INTELLIGENCE
BREACH WATCH
Daily Breach Intelligence for Security Leaders · Monday, August 10, 2026

TL;DR for CISOs: Someone else's breach was your problem today. Valve began notifying Steam hardware buyers in Europe that their shipping details were stolen in a cyberattack on its logistics partner, CEVA Logistics, and warned them to expect targeted phishing. LexisNexis pulled three services offline after unusual activity on servers run by a third-party vendor, choosing an outage over an open door. And researchers detailed a supply-chain compromise that poisoned a vendor data feed feeding seven BdThemes WordPress plugins, quietly minting rogue administrators on affected sites. The connective thread is dependence: the data you hand to a vendor and the code you let a vendor run inside your environment are both attack surface you do not fully control.

BOTTOM LINE FOR CISOS
  1. A vendor's breach becomes your customers' phishing wave. When shipping, billing, or support data leaks through a partner, attackers use the real details to impersonate you, so pre-draft the customer notice and the "we will never ask you to pay a fee" message now.
  2. Disconnecting fast is a valid control. LexisNexis chose a service outage over continued exposure. Decide in advance which systems you would take offline, who can make that call, and how you would keep the business running while you rebuild.
  3. Trusted code updates itself from vendor infrastructure you never see. The BdThemes attack required no plugin update, only a poisoned data feed. Inventory what third-party components in your stack phone home, and monitor admin accounts and privileged sessions for silent additions.
HIGH · LEAD STORY

Valve tells Steam hardware buyers their data was stolen in a breach at shipping partner CEVA Logistics

Key facts
  • Who was hit: Steam hardware customers in Europe, notified directly by Valve. The compromise was not at Valve but at CEVA Logistics, the partner that ships Steam Deck and other hardware to European buyers.
  • The vendor: CEVA Logistics is a subsidiary of the CMA CGM Group. Valve reported that attackers had access to CEVA systems between July 29 and August 1, 2026.
  • The timeline: Valve says it learned of the compromise on August 7 and began emailing affected customers on August 10. Because CEVA retains order data for up to 90 days, Valve notified everyone it could reasonably assume was affected.
  • Data taken: Names, addresses, phone numbers, email addresses, and the type and price of ordered products.
  • Data not taken: Valve says payment information, Steam passwords, and Steam Guard codes were not exposed, as CEVA did not have access to them.
  • The follow-on risk: Valve warned that customers may receive phishing by email, SMS, or phone that quotes their real address and order to appear genuine, then asks them to confirm a delivery, pay a small customs or redelivery fee, or sign in to "verify" an order.
  • Wider blast radius: CEVA had told multiple European retailers on August 1 that a cyberattack disrupted operations at several of its European warehouses, so Valve's customers are one affected group among others tied to the same vendor.

What happened

The data that fuels a scam does not have to come from your own systems. Valve holds payment details and Steam credentials, and none of that was in play here. What leaked was the mundane shipping information a logistics partner needs to put a box on a doorstep: a name, an address, a phone number, and what was ordered. In the hands of a fraudster, that is more than enough to sound convincing. The attacker who knows your address and your recent purchase can pose as the courier or the retailer and ask for a small fee or a login, and the request lands because the details are real.

This is a clean example of concentration risk in the supply chain. A single logistics provider sits behind many brands, so one intrusion produces notification duty and fraud exposure across all of them at once. Valve's response was orderly: it isolated the messaging to the affected customers, told them plainly what was taken and what was not, and pre-empted the phishing by describing the exact scripts to expect. The lesson is not that a game company was careless. It is that the weakest link in a customer's experience of your security may be a company they have never heard of.

Evidence

Two independent sources:

What this means for your team

Map the vendors that hold your customer data even when they never touch your core systems, and rank them by the number of customers each one could expose in a single incident. For the concentrated ones, agree breach-notification timelines and evidence-sharing terms in the contract, not in the middle of an incident. Then prepare the customer-facing side in advance: a template notice that states what a legitimate message from you will and will not ask for, and a public reminder that you never request payment to release a delivery. Doing this before an event turns a scramble into a script. If this is a live question for you, it is worth comparing notes with peers on third-party and vendor risk management rather than reinventing the playbook alone.

Action checklist
  1. Identify vendors that hold customer contact and order data, and flag any single provider whose breach would trigger mass customer notification.
  2. Confirm contractual breach-notification timelines and data-retention limits with logistics, billing, and support partners.
  3. Pre-draft a customer notice and a standing "we will never ask you to pay a fee or log in from a message" reminder for delivery and order scams.
  4. Brief fraud, support, and social teams so they can recognize and respond to a phishing wave that quotes real customer order details.
HIGH · SUPPORTING

LexisNexis pulls Diligence, Metabase API, and Newsdesk offline after vendor server activity

Key facts
  • The company: LexisNexis, a global data analytics provider whose legal, business, regulatory, and risk services are used by corporations, law firms, financial institutions, and government agencies.
  • The response: It took three services offline, Nexis Diligence, the Nexis Metabase API, and Nexis Newsdesk, after identifying unusual activity on servers hosted and managed by an unnamed third-party vendor.
  • The decision: In its customer notice, the company said it made an immediate decision to disconnect from the third-party systems to protect customers and contain the issue at its source.
  • The recovery: LexisNexis said it is working with a cybersecurity forensic firm and is rebuilding the affected systems in a new environment before restoring service. Nexis Solutions president Todd Larsen confirmed the details.
  • Not related to Metabase Cloud: The company stated that Nexis Solutions is not a Metabase Cloud customer and that its Nexis Metabase API has no connection to the Metabase Cloud SQL injection zero-day disclosed on August 6.
  • History: LexisNexis disclosed a breach affecting 364,000 people via private GitHub repositories in May 2025, and in March 2026 a threat actor stole and later leaked files after exploiting a flaw in its cloud infrastructure.

What happened

The notable part of this story is the choice, not the intrusion. Faced with suspicious activity on infrastructure it does not run itself, LexisNexis pulled the affected services down rather than watch and wait. That is an expensive decision. Diligence supports compliance and due-diligence work, and the data feeds behind these products are wired into customer systems, so an outage ripples outward. Taking them offline anyway signals a judgment that continued exposure was the larger risk, and that rebuilding in a clean environment was safer than trusting the compromised one.

It also underlines how much containment depends on a vendor you do not control. LexisNexis could disconnect, but the servers, the forensic picture, and the timeline sit partly with the third party that hosts them. The company was careful to separate this event from an unrelated Metabase Cloud vulnerability making news the same week, a useful reminder that similar-sounding names invite false links during an active incident. For a data broker with two prior disclosures in just over a year, the pattern worth watching is less any single flaw than the recurring exposure of data held in systems at the edges of its own estate.

Evidence

What this means for your team

Decide now which services you would take offline in response to a suspected compromise, and make sure someone has the authority to make that call under pressure. A containment plan that assumes you will keep everything running is not a containment plan. Extend that thinking to hosted vendors: for the third parties that run systems on your behalf, confirm you can force a disconnect, obtain forensic data, and rebuild in a clean environment without waiting on their timeline. Practice the trade-off between availability and containment as a tabletop, because the pressure to keep a revenue-generating service up is exactly what attackers count on.

Action checklist
  1. Pre-identify services you would take offline during a suspected breach, and name who is authorized to trigger a shutdown.
  2. For hosted vendors, confirm your rights to disconnect, obtain forensic evidence, and rebuild in a new environment.
  3. Run a tabletop on the availability-versus-containment trade-off so the decision is rehearsed, not improvised.
NOTABLE · SUPPORTING

Poisoned vendor data feed turns seven BdThemes WordPress plugins into a backdoor

Key facts
  • The vendor: BdThemes, a WordPress plugin developer. Wordfence disclosed a supply-chain compromise across seven of its plugins, and the WordPress.org team temporarily removed the affected downloads.
  • The reach: The affected plugins include Element Pack, with more than 100,000 active installs, plus Live Copy Paste, Pixel Gallery, Prime Slider, Smart Admin Assistant, Ultimate Post Kit, and Ultimate Store Kit. Their listings were closed on the WordPress directory as of August 7 or 8, pending review.
  • The mechanism: No plugin source code was changed. A bundled component named Biggopti fetches promotional banners as JSON from a cloud storage bucket. Attackers gained write access to that bucket and replaced the legitimate JSON with a malicious payload.
  • The flaw: A cross-site scripting weakness rated CVSS 5.4, present since a March 1, 2026 change, runs the injected payload in the browser of any logged-in administrator on every wp-admin page load.
  • The payload: The script creates a rogue administrator via the WordPress REST API, installs a PHP web shell, and adds hidden persistence modules, including a magic-login backdoor and a module that conceals the rogue accounts from the user list.
  • The wider link: The command-and-control infrastructure has been tied to two other recent WordPress supply-chain attacks, indicating a broader campaign rather than an isolated incident.

What happened

This attack sidesteps the defenses most teams rely on for plugins. Nobody pushed a malicious update, so a site that pinned versions or reviewed release notes gained nothing. The malicious content arrived through a data feed that a trusted plugin quietly fetches in the background, which means the code an administrator was running never changed, only the instructions it received. Because the payload executes in the administrator's own authenticated session, it inherits full privileges and can create accounts, drop a web shell, and hide its own tracks without tripping the usual signals.

The design choices show intent to persist quietly. Hidden administrator accounts, a login backdoor tied to a URL parameter, and a module that scrubs the rogue users from the admin list all aim at long-term, low-visibility access. The severity rating on the underlying flaw is only medium, which is a useful caution: a modest client-side bug becomes a serious problem once an attacker controls the data source that triggers it. The initiating failure here was upstream, at the vendor's cloud storage, and every downstream site inherited the consequences.

Evidence

What this means for your team

If your marketing or web team runs WordPress with any of the named plugins, treat affected sites as potentially compromised, not merely in need of an update. Look for administrator accounts you did not create, unexpected must-use plugins, and new files in the web directory, and rotate credentials once the site is clean. More broadly, take the pattern seriously: components that pull remote content into a privileged context are a live supply-chain path, so know which of your third-party plugins and integrations phone home, and restrict who and what can reach an admin session. This is a good topic to work through with peers on software supply-chain security, since the same design shows up well beyond WordPress.

Action checklist
  1. Inventory WordPress sites for the affected BdThemes plugins and treat any as compromised until reviewed.
  2. Hunt for unauthorized administrator accounts, hidden must-use plugins, and web shells, then rotate admin credentials after cleanup.
  3. Identify third-party components that fetch remote content into privileged contexts, and constrain outbound calls and admin-session access.
ALSO NOTABLE
  • A vishing campaign tied to the BlackFile-linked extortion group tracked as UNC6671 targeted hedge funds and private-equity firms, with reporting naming Point72, Millennium, Two Sigma, and Citadel among those approached through help-desk impersonation and adversary-in-the-middle phishing. BleepingComputer
  • North Carolina Ports confirmed a cyberattack that disrupted IT systems and forced manual operations at Wilmington, Morehead City, and the Charlotte Inland Port, with the US Coast Guard monitoring the response. BleepingComputer
  • CISA warned that a critical Progress LoadMaster flaw is now being actively exploited, raising the priority for any organization running the load balancer. BleepingComputer
  • IEH Corporation, a supplier of connectors used in the THAAD and Patriot programs, disclosed in an SEC filing that a phishing attack gave an intruder access to an employee's Microsoft 365 mailbox, with potentially export-controlled data exposed. The Register

FAQ

What data did the Valve and CEVA Logistics breach expose?

The stolen records include names, postal addresses, phone numbers, email addresses, and the type and price of Steam hardware ordered by customers in Europe. Valve says payment details, Steam passwords, and Steam Guard codes were not involved because CEVA Logistics did not hold that data, and affected customers do not need to change their Steam password.

Why did Valve customers receive phishing warnings?

The stolen shipping data lets attackers craft scams that quote a real name, address, and recent order. Valve warned customers to expect fake delivery, customs-fee, refund, or account-verification messages by email, SMS, or phone that impersonate Steam or delivery companies, and to treat any request for payment or login as fraudulent.

Was the LexisNexis outage caused by a data breach?

LexisNexis took its Diligence, Metabase API, and Newsdesk services offline after identifying unusual activity on servers run by an unnamed third-party vendor. It disconnected from those systems to contain the issue and is rebuilding them with a forensic firm. It has not confirmed data theft, and it says the incident is unrelated to the Metabase Cloud zero-day disclosed on August 6.

How does the BdThemes WordPress supply-chain attack work?

Attackers gained write access to a cloud storage bucket that feeds promotional banners into seven BdThemes plugins and replaced the legitimate JSON with a malicious payload. A cross-site scripting flaw rated CVSS 5.4 then runs the payload in the browser of any logged-in administrator, creating rogue admin accounts and installing a PHP web shell, with no plugin update or on-disk file change required.

What is the main CISO takeaway from the August 10 briefing?

Third-party and supply-chain exposure defined the day. A logistics vendor breach became a customer phishing problem for Valve, a hosting vendor's servers forced LexisNexis to pull core services offline, and a poisoned vendor data feed turned trusted WordPress plugins into a backdoor. Inventory the vendors that hold your data or run code in your environment, and plan for their incidents as if they were your own.

CISO Platform Breach Intelligence Team

Curated by Pritha Aash, Community Head, CISO Platform. Read more in the Breach Intelligence hub.

Stay ahead of the next breach

CISO Platform is a vendor-agnostic community where security leaders network, share, and learn.

Join the CISO Platform community (free)

Subscribe to the weekly newsletter

Visit the Breach Intelligence hub

Corrections and takedown requests: CISO Platform is committed to accuracy and fairness. If any detail in this briefing is inaccurate, or if you represent an affected organization and would like a correction or removal, please contact us at pritha.aash@cisoplatform.com and we will review your request promptly.

Read more…
CISO PLATFORM · BREACH INTELLIGENCE
BREACH WATCH
Daily Breach Intelligence for Security Leaders · Saturday, August 9, 2026

TL;DR for CISOs: Critical infrastructure led the weekend. New Jersey and Alabama became the latest states to confirm that their water and wastewater facilities were targeted in a campaign, reported as linked to Iran, that has now touched at least a dozen US states and focused on internet-exposed control systems. Alongside it, a JetBrains TeamCity remote code execution flaw sits in the CISA Known Exploited Vulnerabilities catalog with a public proof of concept in circulation, Levi Strauss disclosed that attackers used social engineering to steal corporate data from employee machines, and the person behind the 2024 Snowflake customer-account breaches pleaded guilty in a US court. The connective thread is exposure at the edges of the enterprise: control systems, build pipelines, and the people who hold access.

BOTTOM LINE FOR CISOS
  1. Internet-exposed operational technology is being probed at scale. If you run or depend on ICS or PLCs, confirm none of it is reachable from the public internet, and rehearse a switch to manual operation before you need it.
  2. Unauthenticated code execution on build infrastructure is a supply-chain problem, not just a server problem. The TeamCity flaw is actively exploited and has a public proof of concept, so patching and credential rotation cannot wait for a maintenance window.
  3. People remain the reachable edge. The Levi Strauss theft and the Snowflake plea both trace back to access obtained through social engineering and weak identity controls, which is where verification and monitoring pay for themselves.
CRITICAL · LEAD STORY

Water utility cyberattacks spread to at least a dozen states as New Jersey and Alabama confirm

Key facts
  • The target: Water and wastewater facilities, specifically their operational technology and internet-exposed industrial control systems, including programmable logic controllers.
  • The spread: Reporting places at least 12 states in scope, though not all have been named. Minnesota was first to confirm, citing more than 30 affected water systems. Michigan, South Dakota, and Georgia followed, and New Jersey and Alabama are the latest to confirm.
  • The latest cases: In New Jersey, the Cape May and Woodbine water systems were targeted on July 27, with officials reporting that only phone systems were disrupted. In Alabama, the Childersburg Water, Sewer and Gas system was attacked the same day, with control systems targeted but water services not disrupted.
  • Attribution (reported): The activity has been linked to Iranian hackers and reported to target ICS devices made by Rockwell Automation and possibly other major vendors. This attribution comes from reporting rather than a formal government statement of authorship.
  • Official signal: The FBI publicly confirmed that at least seven states had been targeted as of July 30. CISA has urged the water sector to secure operational technology following the coordinated activity against PLCs.
  • Impact so far: No significant impact has been reported. Some operators shut systems down or moved to manual control, and all have told residents that drinking water is safe.

What happened

Water systems are an unusually exposed corner of critical infrastructure. Many are run by small municipal operators with limited security staff, and the control equipment they depend on was often connected to the internet for convenience rather than designed to sit there safely. This campaign has taken advantage of exactly that gap, reaching programmable logic controllers directly rather than breaking through layers of enterprise defense first. The steady drumbeat of new states confirming involvement, from Minnesota through to New Jersey and Alabama, points to broad opportunistic scanning for reachable devices rather than a handful of hand-picked targets.

The reassuring part is that the disclosed cases describe limited operational effect, with phone systems disrupted in one instance and control systems touched without interrupting water service in another. The uncomfortable part is what the pattern signals. A capability that can reach a PLC at a water plant can reach one at a manufacturing line, an energy site, or a building management system, and the same weakness, an internet-facing controller with weak or absent authentication, applies everywhere. The Iran attribution should be read as reported rather than settled, but the exposure it exploits is real regardless of who is behind it.

Evidence

Two independent sources:

What this means for your team

If you own or influence operational technology, treat internet reachability as the first question, not the last. Build a current inventory of every controller, HMI, and remote-access path that can be seen from outside your network, and take the exposed ones off the public internet or put them behind enforced authentication and a monitored gateway. Confirm that your operators can run the process manually and know how to do it, because the disclosed cases show that a fast move to manual control is what kept impact small. If you sit in an enterprise that is not a utility, use this as a prompt to ask the same questions of your building systems, manufacturing lines, and any third party that manages OT on your behalf. This is a good moment to bring peers together on operational technology and ICS defense rather than solving it in isolation.

Action checklist
  1. Inventory internet-exposed OT: controllers, PLCs, HMIs, and remote-access services, and remove public exposure or place it behind enforced authentication.
  2. Confirm and rehearse manual-operation fallback for critical processes so a control-system outage does not become a service outage.
  3. Review Rockwell Automation and other vendor advisories, apply available hardening, and change any default or shared credentials on control devices.
  4. Extend the same exposure questions to third parties that operate OT for you, and confirm incident coordination paths with CISA and the FBI.
HIGH · SUPPORTING

JetBrains TeamCity RCE is under active exploitation and in the CISA KEV catalog

Key facts
  • The product: JetBrains TeamCity On-Premises, a continuous integration and delivery server used to build, test, and release software.
  • The flaw: CVE-2026-63077, rated CVSS 9.8, a deserialization of untrusted data issue reachable through the agent polling protocol. It allows an unauthenticated attacker to bypass authentication and run operating system commands with the privileges of the TeamCity server process.
  • Exploitation: CISA added the flaw to its Known Exploited Vulnerabilities catalog on August 5 after confirming active exploitation. The federal patch deadline under Binding Operational Directive 26-04 was August 8. The method, actors, and scale were not public as of reporting.
  • Proof of concept: Rapid7 published a technical analysis on August 7 and released a proof-of-concept script, which lowers the bar for opportunistic attackers.
  • Exposure: Censys reported roughly 4,500 internet-facing TeamCity properties shortly after disclosure.
  • The fix: Upgrade to TeamCity 2025.11.7 or 2026.1.3. A security patch plugin is available for TeamCity 2017.1 and later for those who cannot upgrade immediately.

What happened

A build server is a high-trust machine that most organizations underprotect. It holds signing keys, deployment credentials, and source access, and it pushes artifacts into environments that downstream teams trust by default. Unauthenticated code execution on that server, which is what this flaw allows, hands an attacker the credentials and the reach in one step. The move from patch to exploitation was quick here, and the public proof of concept means the window for quiet patching has effectively closed. Because the impact scales with whatever privileges the server process runs under, an over-permissioned service account turns a single-server compromise into a pipeline compromise.

Evidence

What this means for your team

Find every TeamCity On-Premises server, prioritize any that are internet-facing, and patch to a fixed version or apply the plugin now. Patching stops new exploitation but does nothing about access an attacker may already hold, so rotate the credentials and tokens the server stored and review recent builds for tampering. Assume any exposed and unpatched server has been reached, and hunt for unexpected processes, new files, and outbound connections. This belongs in the same discipline you apply to other actively exploited vulnerabilities, with the added step of treating build systems as identity infrastructure whose service accounts deserve least privilege.

Action checklist
  1. Upgrade TeamCity On-Premises to 2025.11.7 or 2026.1.3, or apply the security patch plugin, starting with internet-facing servers.
  2. Rotate stored credentials, tokens, and signing keys the server held, and review recent build artifacts for tampering.
  3. Reduce the privileges of the TeamCity server process and restrict who can reach the server, then hunt exposed instances for signs of command execution.
NOTABLE · SUPPORTING

Levi Strauss says social engineering led to corporate data theft

Key facts
  • The organization: Levi Strauss & Co., the apparel company, which disclosed the incident in a regulatory filing.
  • The method: An unauthorized third party used social engineering to compromise three employee-issued computers and exfiltrate corporate information from them.
  • The unknowns: The company did not disclose the volume or categories of data taken, did not identify the attackers, and did not say whether ransomware was involved or a ransom was demanded.
  • The company position: Levi Strauss said it believes the unauthorized access was contained and terminated, that no consumer data was affected, that operations were not interrupted, and that it does not expect a material effect on its business.

What happened

This is a small-footprint intrusion with a familiar starting point. Three employee laptops, reached through social engineering rather than a software flaw, were enough to pull corporate data out of a large consumer brand. The company frames the outcome as contained and immaterial, which may well hold, but the entry method is the part worth carrying forward. Attackers continue to find that persuading a person is cheaper and faster than defeating a control, and endpoints that hold business data are a productive place to land once that person is fooled.

Evidence

What this means for your team

Use this as a check on your human-and-endpoint layer rather than a headline to file away. Confirm that your help-desk and account-recovery processes can withstand a convincing caller, since that is the path these operations usually take. Make sure the data that sits on employee laptops is inventoried, encrypted, and covered by endpoint detection, and that a compromised device can be isolated quickly. The point is not that a jeans maker was breached, it is that three endpoints and one convincing story were the whole attack.

Action checklist
  1. Stress-test help-desk and account-recovery procedures against social engineering, including identity verification for password and MFA resets.
  2. Confirm endpoint detection, disk encryption, and rapid isolation are in place for devices that hold corporate data.
  3. Review what business data is allowed to reside on laptops and reduce it where it does not need to be there.
NOTABLE · SUPPORTING

Snowflake customer-breach hacker pleads guilty in US court

Key facts
  • The case: Connor Riley Moucka pleaded guilty to computer fraud, wire fraud, and aggravated identity theft over the 2024 breaches of Snowflake customer accounts.
  • The scale: The intrusions reached at least 165 organizations and exposed records belonging to at least 100 million people.
  • The pattern: The 2024 campaign centered on customer accounts accessed with stolen credentials, with accounts that lacked multi-factor authentication being the exposed ones. The platform itself was not the point of failure.

What happened

The legal outcome closes a loop on one of the largest credential-driven breaches of recent years, but the operational lesson has not aged. The damage did not come from a flaw in the SaaS platform. It came from customer accounts protected by a password alone, reached with credentials collected elsewhere. That is a shared-responsibility failure, and it is one that still describes a large share of SaaS environments today.

Evidence

What this means for your team

Read the guilty plea as a reminder to close the same gap in your own SaaS estate. Enforce phishing-resistant multi-factor authentication on every account in your major data platforms, with no standing exceptions, and confirm that federation and conditional access actually cover the service accounts and integrations that people forget. Then pair that with monitoring for logins from stolen credentials, because MFA reduces the odds but does not remove the need to watch. The connection to identity runs through most of today's briefing, which is why it belongs in a wider conversation on identity and access as a security control.

Action checklist
  1. Enforce phishing-resistant MFA across all SaaS data platforms and remove standing exceptions.
  2. Audit service accounts and integrations for accounts that bypass federation or conditional access.
  3. Monitor for credential-based logins and anomalous data access on high-value SaaS platforms.
ALSO NOTABLE
  • A novel private-APN pivot was used to sabotage a second Polish energy facility, extending an OT-focused campaign against critical infrastructure. SecurityWeek
  • Critical flaws were disclosed in Belgian eID software used by roughly 2 million people, raising identity-infrastructure risk. SecurityWeek
  • New attack methods could let malware hijack passkey-protected accounts through Google Password Manager, a reminder that passkeys are not immune to endpoint compromise. The Hacker News
  • A critical Gitea flaw let unauthenticated attackers read server files through Org-mode markup parsing. The Hacker News

FAQ

Which US states have confirmed water utility cyberattacks?

Reporting places at least 12 states in scope. Minnesota was first to confirm, citing more than 30 affected water systems, followed by Michigan, South Dakota, and Georgia. New Jersey and Alabama are the latest to confirm. Wisconsin, Pennsylvania, and Washington have warned utilities without confirming attacks.

Is drinking water safe after these attacks?

The utilities and states that have come forward report limited disruption and say drinking water is safe. Some operators shut systems down or moved to manual operation as a precaution, and the disclosed activity targeted control systems rather than treatment outcomes.

Why is the JetBrains TeamCity flaw urgent?

CVE-2026-63077 is an unauthenticated remote code execution flaw rated CVSS 9.8. CISA added it to the Known Exploited Vulnerabilities catalog on August 5, and a public proof of concept is now available. A build server compromise can expose stored credentials and tamper with software artifacts.

What should I do if I run TeamCity On-Premises?

Upgrade to version 2025.11.7 or 2026.1.3, or apply the vendor security patch plugin for TeamCity 2017.1 and later. Treat any internet-facing server that was unpatched after July 27 as potentially accessed, rotate stored secrets, and review it for unexpected commands and new files.

What is the main CISO takeaway from the August 9 briefing?

Internet-exposed operational technology is being probed at scale, and unauthenticated code execution on developer and management infrastructure remains a fast path to credentials. Inventory exposed OT and CI/CD systems, patch the actively exploited TeamCity flaw, and treat identity as the control that decides how far an intruder gets.

CISO Platform Breach Intelligence Team

Curated by Pritha Aash, Community Head, CISO Platform. Read more in the Breach Intelligence hub.

Stay ahead of the next breach

CISO Platform is a vendor-agnostic community where security leaders network, share, and learn.

Join the CISO Platform community (free)

Subscribe to the weekly newsletter

Visit the Breach Intelligence hub

Corrections and takedown requests: CISO Platform is committed to accuracy and fairness. If any detail in this briefing is inaccurate, or if you represent an affected organization and would like a correction or removal, please contact us at pritha.aash@cisoplatform.com and we will review your request promptly.

Read more…

 

CISO PLATFORM · BREACH INTELLIGENCE
BREACH WATCH
Daily Breach Intelligence for Security Leaders · Tuesday, August 11, 2026

TL;DR for CISOs: Patch Tuesday did the ranking for you. Microsoft shipped fixes for 398 vulnerabilities, and only one was already under attack: a WinSock kernel driver flaw that lets an attacker who is already on a box climb to SYSTEM. The same day, CISA added that flaw plus two others to its Known Exploited Vulnerabilities catalog, a maximum-severity Metabase SQL injection that hands over admin without a login, and a Cisco firewall bug that lets an unauthenticated attacker crash the device. Separately, CERT Polska detailed how intruders crossed from a wind farm into a private cellular network and shut down a turbine at a heat plant serving roughly 50,000 people. The thread today is prioritization: the biggest number is not the biggest problem, and confirmed exploitation is what should move to the front of your queue.

BOTTOM LINE FOR CISOS
  1. Sort by exploitation, not by CVSS. A 7.0 that attackers are using outranks a 9.8 that no one has touched yet. Build your patch order around confirmed active exploitation and whether the vulnerable service is actually reachable in your environment.
  2. Treat the KEV catalog as your queue, even if you are not a federal agency. Three flaws were added on one day with tight remediation deadlines. Wiring KEV entries into your ticketing and asset inventory turns a government list into an operational schedule.
  3. An internet-facing analytics or admin console is a database in disguise. The Metabase flaw shows how a single reporting tool can expose every credential it stores. Inventory the tools that hold connection strings to your data, and put them behind authentication and network controls.
HIGH · LEAD STORY

Microsoft patches 398 flaws, and the only one under active attack is a WinSock privilege-escalation bug

Key facts
  • The release: Microsoft's August 2026 Patch Tuesday. By the Zero Day Initiative's count, it addressed 398 new CVEs, 62 of them rated Critical.
  • The exploited flaw: CVE-2026-68820, a use-after-free in afd.sys, the Ancillary Function Driver for WinSock, rated CVSS 7.0. It is the only vulnerability in the release that Microsoft marked as under active exploitation.
  • The impact: Privilege escalation. An attacker who already has code running on a machine can trigger a race condition in the driver to elevate to SYSTEM.
  • Attribution: Microsoft has not publicly named who exploited it. Check Point Research reports that the Lazarus group used the zero-day in an Operation Dream Job campaign. Treat the attribution as a researcher claim, not a Microsoft confirmation.
  • The higher-scoring bugs: Four unauthenticated remote code execution flaws each carry a CVSS score of 9.8 and affect Windows DNS Server (CVE-2026-62878), Windows Deployment Services (CVE-2026-62893), Microsoft's QUIC implementation (CVE-2026-62815), and HPC Pack (CVE-2026-59124). None was flagged as exploited at release.
  • SharePoint chain closed: The update completes a two-part on-premises SharePoint fix, adding the RCE component (CVE-2026-63520) that pairs with July's authentication-bypass fix (CVE-2026-55040).
  • Federal deadline: CISA added CVE-2026-68820 to its KEV catalog and set an August 25 remediation date for federal agencies.

What happened

The instinct on Patch Tuesday is to chase the highest scores, and this release offers four tempting 9.8s. The one that belongs at the top of the list, though, is a 7.0. The difference is not the math, it is the evidence. Microsoft says the WinSock driver flaw is already being used in real intrusions, while the four unauthenticated remote code execution bugs, serious as they are, had no observed exploitation when the fixes shipped. A privilege-escalation bug rarely opens the front door on its own, but it is a favorite second move: pair it with any foothold, whether a phishing payload or a stolen credential, and an ordinary user session becomes full control of the host.

The rest of the release is a study in reachability. A wormable label on the DNS Server flaw describes a technical condition, not a worm that exists, and HPC Pack is not installed by default, so its practical urgency depends entirely on whether you run it. The SharePoint fix is the cleaner win: the demonstrated attack chain was already broken once July's authentication-bypass patch went on, and August closes the remaining code-execution half. The takeaway for a security leader is to read a Patch Tuesday less as a scoreboard and more as a triage list, where exploitation status and whether the service is exposed in your estate decide the order of work.

Evidence

Two independent sources:

What this means for your team

Rebuild your Patch Tuesday process so the first question is not the CVSS score but whether the flaw is being exploited and whether the affected component runs anywhere you can be reached. Put CVE-2026-68820 at the front for Windows endpoints and servers, because it is the piece an intruder adds to a foothold to take the whole host. Then queue the four unauthenticated 9.8 flaws by actual exposure: an internet-facing DNS or QUIC endpoint is a different risk than an internal service behind segmentation. Finally, confirm that on-premises SharePoint farms carry both the July and August fixes, since only the pair fully closes the chain. If you want to pressure-test your own approach, the community has an active thread on risk-based vulnerability management worth reading before the next cycle.

Action checklist
  1. Deploy the CVE-2026-68820 fix to Windows endpoints and servers first, ahead of the higher-scoring but unexploited bugs.
  2. Rank the four unauthenticated 9.8 RCEs by whether DNS Server, WDS, QUIC, or HPC Pack is actually present and reachable in your environment.
  3. Verify on-premises SharePoint has both the July (CVE-2026-55040) and August (CVE-2026-63520) updates installed.
  4. Hunt for privilege-escalation activity on hosts where an initial foothold could already exist, rather than assuming patching alone closes the risk.
CRITICAL · SUPPORTING

Metabase zero-day scored 10.0 hands attackers admin access without a login, now in CISA's KEV catalog

Key facts
  • The product: Metabase, a widely used business intelligence and data visualization tool that connects to an organization's databases.
  • The flaw: An SQL injection reachable through the password-reset endpoint, later assigned CVE-2026-72898 with a CVSS score of 10.0. It lets a remote, unauthenticated attacker gain administrator access to the instance.
  • The exposure: With admin access, an attacker can change configuration, read stored credentials for connected databases, and export data those connections can reach.
  • Exploited in the wild: Metabase said it identified an attack on Metabase Cloud using an unknown flaw in versions 1.58 and above. Cloud instances were updated; self-hosted users must patch.
  • Named victims: Reporting has tied the campaign to Framework, which said customer names, addresses, phone numbers, emails, and login IPs were accessed but no payment data; n8n, which said an attacker obtained 136 customer records; and Kilo Code, which reported exposed Slack access tokens for a subset of users.
  • Federal deadline: CISA added CVE-2026-72898 to its KEV catalog on August 11 with a remediation deadline of August 14.

What happened

A reporting tool is easy to treat as low risk because it only reads data, but that framing misses what it holds. Metabase sits astride an organization's databases and keeps the connection credentials needed to query them. An unauthenticated flaw that yields admin on that console does not just expose a dashboard; it hands over the keys to everything the dashboard can see. The path here ran through the password-reset endpoint, which is exactly the kind of pre-authentication surface that has to work for anonymous users and therefore cannot hide behind a login prompt.

The downstream disclosures show the shape of the damage. Framework, n8n, and Kilo Code were reached not through their own core systems but through a shared piece of software wired into their data. That is the recurring pattern of the modern breach: the initial flaw is in a component many organizations run the same way, so one vulnerability produces many separate incidents. The specific counts matter here, and we are reporting the figures each company stated rather than an estimate. For defenders, the useful signal is that the tools sitting quietly between your applications and your databases deserve the same scrutiny as the databases themselves.

Evidence

What this means for your team

Find every Metabase instance you run, confirm it is on a fixed version, and treat any internet-exposed instance on an affected build as potentially compromised rather than merely unpatched. Because the flaw can expose stored database credentials, patching is only step one: rotate the connection credentials for any database the instance could reach, review admin accounts and API keys for anything you did not create, and check query and access logs for the disclosed indicators. More broadly, this is a prompt to inventory the analytics and admin consoles that hold connection strings to sensitive data, and to put them behind authentication, network segmentation, and monitoring rather than leaving them quietly exposed.

Action checklist
  1. Locate all Metabase instances, patch to a fixed version, and prioritize any that are internet-facing.
  2. Rotate credentials for every database a vulnerable instance could reach, and revoke active sessions and unrecognized API keys.
  3. Review logs for the disclosed compromise indicators and for unexpected administrator accounts.
  4. Inventory other analytics and admin tools that store database connection strings, and place them behind authentication and network controls.
HIGH · SUPPORTING

Cisco firewall flaw exploited to crash ASA and FTD devices, added to KEV the same day

Key facts
  • The flaw: CVE-2026-20349, rated CVSS 8.6, in Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) software.
  • The cause: Insufficient error checking while processing HTTP requests to the Remote Access SSL VPN service.
  • The impact: A remote, unauthenticated attacker can send a crafted HTTP request to force the device to reload, causing a denial-of-service condition. It is exploitable when SSL listen sockets are enabled.
  • Exploited in the wild: Cisco said it became aware of active exploitation in August 2026 and has not shared details on the attackers or targets.
  • Federal deadline: CISA added CVE-2026-20349 to its KEV catalog on August 11 with a remediation deadline of August 14.

What happened

A denial-of-service bug can read as lower stakes than remote code execution, but the device in question changes that calculation. ASA and FTD appliances sit at the network edge and often carry the remote-access VPN that employees depend on. A flaw that lets an unauthenticated attacker reload the firewall at will is not a nuisance; it is a way to knock out remote connectivity on demand, and repeated crashes can serve as cover or pressure during a larger operation. The trigger here is the Remote Access SSL VPN service, which by design has to accept connections from the internet.

What makes this one urgent is the pairing of active exploitation with edge exposure. Cisco confirmed attacks are underway without naming who is behind them, and CISA moved the flaw onto its catalog the same day with a short deadline. Security teams have learned repeatedly that perimeter VPN devices are a favored target, both for access and for disruption, so a confirmed in-the-wild bug in one warrants immediate attention rather than the next maintenance window.

Evidence

What this means for your team

If you run ASA or FTD with Remote Access SSL VPN enabled, this is a same-week fix, not a scheduled one. Identify the affected appliances, confirm whether SSL listen sockets are in use, and apply Cisco's update on your edge devices before you work through less exposed systems. Because the outcome is a forced reload, plan for the availability angle as well: know how your remote workforce would connect if the VPN went down, and monitor these devices for unexpected reboots that could signal exploitation attempts. Perimeter appliances reward a standing habit of fast patching and tight management-plane access.

Action checklist
  1. Inventory ASA and FTD devices and identify those with Remote Access SSL VPN and SSL listen sockets enabled.
  2. Apply Cisco's fix for CVE-2026-20349 on internet-facing appliances ahead of the August 14 KEV deadline.
  3. Monitor firewalls for unexpected reloads and prepare a fallback remote-access plan in case of an outage.
NOTABLE · SUPPORTING

CERT Polska details a rare OT breach: attackers crossed a private cellular network to stop a turbine

Key facts
  • The disclosure: CERT Polska detailed the incident this week, describing it as the first observed case of attackers reaching an operational technology network through a private cellular APN.
  • The target: A combined heat and power (CHP) plant that supplies heat to roughly 50,000 residents.
  • The path: Attackers moved from a compromised wind farm into a private APN network used by a distribution system operator, then crossed into the separate CHP plant's OT environment.
  • The enabling weakness: A misconfiguration allowed connections between arbitrary devices inside the private APN, a setup CERT Polska said was common in Poland at the time.
  • The foothold: Scanning for VNC, HTTP, and industrial protocols including S7 and Modbus surfaced a WAGO PFC200 controller still running default admin credentials on its web interface.
  • The impact: The attack shut down a steam turbine and the process-water treatment system, interrupting cogeneration, though CERT Polska reported customers did not lose heat or electricity.

What happened

This incident is a reminder that OT compromises rarely require an exotic exploit. The novel element was the entry path, a private cellular network that operators tend to treat as inherently trusted, but the rest of the intrusion relied on failures that show up in ordinary enterprise reviews: flat connectivity that let arbitrary devices talk to each other, and an industrial controller left on its default credentials. Once inside the private APN, the attackers scanned for the protocols that run plant equipment and found a controller that let them in without a fight.

The reason it belongs in a CISO briefing, even for organizations far from Polish energy, is the transferable lesson about trust boundaries. A private network, a cellular link, or an operational segment is not safe simply because it is separate from the corporate LAN. The controls that would have blunted this, restricting device-to-device connectivity, changing default credentials, and monitoring for scanning inside the trusted zone, are the same basics that protect any environment. The disclosure took months of analysis, which is itself a caution: OT incidents are slow to surface, so the absence of news is not the absence of risk.

Evidence

What this means for your team

If your organization runs any OT, ICS, or private cellular infrastructure, use this as a template for a trust-boundary review rather than a distant news item. Confirm that your private networks and operational segments do not allow arbitrary device-to-device connectivity, and that industrial controllers and management interfaces are not running default or shared credentials. Extend monitoring into these zones so internal scanning for industrial protocols raises an alert instead of passing unseen. The peers working through these questions gather around OT and critical-infrastructure security, which is a practical place to compare segmentation and monitoring approaches.

Action checklist
  1. Review private cellular and OT networks for configurations that allow arbitrary device-to-device connections, and restrict them.
  2. Audit industrial controllers and management interfaces for default or shared credentials and change them.
  3. Extend detection into operational segments so scanning for S7, Modbus, VNC, and similar protocols generates alerts.
ALSO NOTABLE
  • N-able said attackers are taking over N-central servers after an initial fix proved incomplete, a reminder to verify that a patch actually closed the hole. The Hacker News
  • CISA warned that a critical Progress Kemp LoadMaster command-injection flaw is being actively exploited, raising priority for anyone running the load balancer. BleepingComputer
  • The Head Mare group has been exploiting unpatched TrueConf video-conferencing servers, swapping client installers for backdoored versions. BleepingComputer
  • A new cPanel flaw could let hosting customers run SQL as the database root user, a risk for shared and managed hosting environments. The Hacker News

FAQ

Which vulnerabilities did CISA add to its KEV catalog on August 11, 2026?

Three: CVE-2026-68820, a Microsoft WinSock driver use-after-free used for privilege escalation to SYSTEM; CVE-2026-72898, a maximum-severity Metabase SQL injection that grants unauthenticated administrator access; and CVE-2026-20349, a Cisco Secure Firewall ASA and FTD flaw that lets a remote attacker crash the device. The remediation deadlines were August 25 for the Microsoft flaw and August 14 for the Metabase and Cisco flaws.

What is CVE-2026-68820 and why does it matter?

It is a use-after-free in afd.sys, the Ancillary Function Driver for WinSock in Windows, rated CVSS 7.0. It is a privilege-escalation flaw, so an attacker who already has code running on a machine can use it to reach SYSTEM. Microsoft flagged it as the only vulnerability under active exploitation in the August release. Microsoft has not publicly attributed the activity, and Check Point Research says the Lazarus group used it in an Operation Dream Job campaign.

How severe is the Metabase zero-day, and who was affected?

The SQL injection, later assigned CVE-2026-72898, carries a CVSS score of 10.0. It lets a remote, unauthenticated attacker inject SQL through the password-reset endpoint and gain administrator access, which can expose stored credentials for connected databases. Metabase disclosed exploitation in the wild, and reporting has named Framework, n8n, and Kilo Code among the organizations affected.

What happened at the Polish combined heat and power plant?

CERT Polska detailed an intrusion in which attackers moved from a compromised wind farm into a private cellular APN used by a distribution operator, then crossed into a CHP plant serving about 50,000 residents. They reached a WAGO PFC200 controller running default credentials and shut down a steam turbine and the process-water treatment system. It is described as the first observed case of an OT compromise reached through a private APN.

What is the main CISO takeaway from the August 11 briefing?

Exploitation, not raw severity scores, set the priority order. Three flaws hit CISA's KEV catalog on the same day, and the highest CVSS score was not the most urgent fix. Rank patching by confirmed exploitation and reachability, treat the KEV catalog as a forcing function beyond federal agencies, and remember that flat networks and default credentials still turn a foothold into physical disruption.

CISO Platform Breach Intelligence Team

Curated by Pritha Aash, Community Head, CISO Platform. Read more in the Breach Intelligence hub.

Stay ahead of the next breach

CISO Platform is a vendor-agnostic community where security leaders network, share, and learn.

Join the CISO Platform community (free)

Subscribe to the weekly newsletter

Visit the Breach Intelligence hub

Corrections and takedown requests: CISO Platform is committed to accuracy and fairness. If any detail in this briefing is inaccurate, or if you represent an affected organization and would like a correction or removal, please contact us at pritha.aash@cisoplatform.com and we will review your request promptly.

Read more…

At a CISO Platform fireside chat, Sudhakar Ramakrishna, CEO of SolarWinds, looked back on one of the most scrutinized breach responses in recent memory. His reflection was not about detection or containment. It was about the part of the crisis most incident plans never budget for.

The volume of press noise was what they most underestimated. Ramakrishna said the technical response was demanding, but the level of noise and misinformation in the press was the dimension the team was least prepared for. In his words, "What we underestimated was the level of noise in the press."

The instinct was to spend on customers and employees first. During the crisis, the natural pull was to direct attention and resources toward the people most directly affected. That instinct is reasonable, but Ramakrishna now sees it as incomplete, because it left one channel underfunded.

With hindsight, he would fund crisis communications far more heavily. Ramakrishna was direct about what he would change: "If I were to rewind the clock, we should have put a lot more PR firepower at it." The gap was not strategy or technology. It was the resourcing of the public narrative while the technical work was still underway.

Why this matters for CISOs

Most incident response plans account for detection, containment, forensics, and legal review. Far fewer specify how much of the breach budget goes to crisis communications, or who owns the public narrative in the first 72 hours. Ramakrishna's account puts that decision on the table before an incident, not in the middle of one.

One question for the community

If you had to split a breach response budget today, what share would you commit to crisis communications versus technical remediation, and who in your organization owns that call?

Join the conversation

CISO Platform is a peer community where security leaders compare what these decisions actually cost. Join the community and add your own experience.

Source: This clip is from a CISO Platform fireside chat with Sudhakar Ramakrishna, hosted by Bikash Barai. Watch the full talk.

Read more…
CISO PLATFORM · BREACH INTELLIGENCE
BREACH WATCH
Daily Breach Intelligence for Security Leaders · Monday, August 3, 2026

TL;DR for CISOs: The edge and the management plane both took hits. INC Ransomware is now the leading actor chaining two SonicWall SMA 1000 flaws to reach the inside of corporate networks, with 885 victims listed on its leak site and fresh activity through the start of August. In parallel, N-able confirmed active exploitation of a new N-central authentication bypass, and CISA added it to the Known Exploited Vulnerabilities catalog the same day. Two data-theft disclosures rounded out the day: biotech firm Amgen said patient health and proprietary data was stolen from third-party cloud systems, and the UK's Police National Legal Database confirmed staff and customer contact records surfaced on the dark web. The common thread is the remote-access layer, from VPN appliances to RMM consoles, and the cloud and third parties that sit behind it.

BOTTOM LINE FOR CISOS
  1. Ransomware has caught up to the SonicWall SMA 1000 edge. If you run these appliances, treat any unpatched or recently patched device as a suspected intrusion, not just a patch item, because attackers were harvesting credentials, session databases, and one-time-password seeds before the fix landed.
  2. Your remote monitoring platform is a live target again. The new N-central authentication bypass is confirmed under active exploitation and now sits in the CISA KEV catalog, so confirm the hotfix build with your team and with any managed service provider that touches your environment.
  3. Third-party cloud and data custodians remain the soft underbelly. Amgen's patient and proprietary data was taken from cloud systems it did not fully control, a reminder to map where your regulated data lives outside your own tenancy and who is accountable when it moves.
CRITICAL · LEAD STORY

INC Ransomware becomes the dominant actor exploiting SonicWall SMA 1000 appliances

Key facts
  • The targets: SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances, which terminate remote-access sessions at the boundary between the public internet and internal networks and hold session tokens, certificates, and multi-factor state.
  • The flaws: Two vulnerabilities, CVE-2026-15409 and CVE-2026-15410, that researchers say can be chained to run arbitrary commands and take over a device. SonicWall released fixes in mid-July 2026, and both were added to CISA's Known Exploited Vulnerabilities catalog.
  • Who is behind it (attribution and claim): Rapid7 and Resecurity identify INC Ransomware as the dominant actor now weaponizing the exploit chain. Volexity attributed pre-disclosure exploitation starting June 22, 2026, to a cluster it tracks as UTA0533. INC's own leak-site tally of 885 victims to date is a threat-actor claim, not an independently confirmed count.
  • What attackers take: According to Rapid7, the intrusions extracted high-value credentials, active session databases, and time-based one-time-password (TOTP) MFA seed configurations to establish persistent access and move laterally into internal corporate networks.
  • Tooling reported: Volexity described a Python script named KNUCKLEBALL used to launch Suo5, an open-source HTTP proxy, along with a custom Java web shell dubbed ORANGETAIL.
  • Scope of leak-site listings (claims): Resecurity said new victims listed between July 17 and August 1, 2026, span private-sector and government organizations in the United States, Australia, the UAE, Colombia, and Switzerland; the most recent listing is dated August 2. These are extortion claims pending confirmation by the named organizations.
  • Pressure tactics: Resecurity reported that some victims received emails and phone calls from a caller using the name "Andrew," who claimed to represent the attackers and directed negotiations to an external email address, a social-engineering technique common to extortion crews.

What happened

A remote-access appliance is a concentrated prize because it sits exactly where trust changes hands. It authenticates external users, stores the session material that keeps them logged in, and forwards approved traffic inward, so an attacker who takes one over inherits a warm path into the network rather than a cold start at the perimeter. That is why the shift in this story matters. What began as quiet, pre-disclosure exploitation of the SMA 1000 series in late June has now become the preferred entry point for a high-volume ransomware operation, and the window between a public fix in mid-July and widespread criminal use has closed to weeks.

The detail security leaders should sit with is what the intruders collected before deploying anything noisy. Harvesting credentials, live session databases, and one-time-password seed values is a deliberate move to defeat the controls most organizations lean on for remote access. Stolen session data can let an attacker resume an authenticated session, and a captured TOTP seed can let them generate valid second-factor codes at will, which blunts multi-factor authentication as a barrier once the appliance is compromised. The reports from Rapid7, Volexity, and Resecurity describe overlapping activity rather than competing accounts, which points to a coordinated effort to find and monetize this weakness rather than isolated opportunism.

Evidence

Two independent sources:

What this means for your team

Reframe an SMA 1000 patch as an incident-response trigger, because a device that was reachable while these flaws were live should be presumed touched until you can show otherwise. Patching to the current firmware stops new exploitation, but it does nothing about credentials, session tokens, and one-time-password seeds that may already be in an attacker's hands, so the real work is rotation and hunting. Force a reset of account passwords and MFA enrollments tied to the appliance, invalidate active sessions, and re-provision the TOTP seeds rather than trusting the ones the device held. Then look inward, since the stated goal was lateral movement: review authentication and east-west traffic for the period the appliance was exposed, and pay attention to any interaction with the appliance's proxy paths or unusual parameters that Resecurity flagged. Finally, use this as evidence for a structural point with your board, which is that internet-facing remote-access appliances deserve the same monitoring rigor as domain controllers, because they now attract the same class of adversary.

Action checklist
  1. Patch all SonicWall SMA 1000 appliances to the current fixed firmware, and treat any device that was internet-facing before the fix as a suspected compromise rather than a closed item.
  2. Rotate credentials, invalidate active sessions, and re-provision TOTP MFA seeds associated with the appliance, since attackers specifically harvested these to bypass authentication.
  3. Hunt for lateral movement: correlate external source addresses that touched the appliance's proxy paths with internal authentication and east-west activity during the exposure window.
  4. Verify appliance integrity for the reported tooling and web-shell behavior, and engage incident response if you find signs of prior access.
CRITICAL · SUPPORTING

N-able N-central bypass is confirmed exploited and lands in the CISA KEV catalog

Key facts
  • The flaw: CVE-2026-18577, an authentication bypass using an alternate path or channel in N-central, N-able's remote monitoring and management (RMM) platform. N-able scored it 8.2 on CVSS 4.0. It affects all versions before 2026.3, and the fix is hotfix build 2026.3.1.7.
  • Why it recurred: N-able describes CVE-2026-18577 as the result of an incomplete patch for an earlier N-central authentication bypass, meaning attackers found a second route to a weakness the first fix was meant to close. Both could be abused for administrative account takeover.
  • Active exploitation: N-able warned on August 3 that attackers are exploiting the flaw against both hosted and on-premises servers. The same day, CISA added CVE-2026-18577 to its Known Exploited Vulnerabilities catalog.
  • Why the platform matters: N-central is used by managed service providers and internal IT teams to manage large fleets of systems, so compromising a server extends reach beyond N-able's direct customers to the endpoints those servers manage.
  • Indicators published: N-able's hotfix page lists indicators of compromise including four specific IP addresses, a registered service named "Cloudflared," and an svchost.exe placed in a user's Documents folder. Attackers frequently abuse the legitimate Cloudflared tunneling utility to keep outbound access without opening inbound firewall ports.
  • Not yet disclosed: N-able has not shared technical detail on the flaw or the number of customers targeted or compromised.

What happened

This is the second day this story has earned space, and the reason is a change in status rather than a repeat of the same facts. What was a vendor investigation and an emergency hotfix has now hardened into confirmed exploitation with a federal deadline attached, because a KEV listing obliges federal civilian agencies to remediate on a set clock and gives every other organization a clear signal of urgency. The structural risk is unchanged and worth restating plainly: an RMM platform holds standing administrative reach into every device it manages, and when a managed service provider runs it, that reach crosses company lines, so one authentication bypass can become a set of intrusions at unrelated organizations. The persistence pattern of outbound tunnels planted on managed endpoints means cleaning the console alone does not end the incident.

Evidence

Two independent sources:

What this means for your team

Confirm the exact build first, because the safe version is specific: 2026.3.1.7 or later, and simply being on the 2026.3 line without the hotfix should be treated as still vulnerable. If a provider runs your endpoints, send them one direct question today, which is which N-central build they run and when it was applied, since their exposure becomes yours. Once the build is confirmed, hunt on the managed endpoints for the indicators N-able published, especially a Cloudflared service and a misplaced svchost.exe, because persistence lives below the console and survives a console cleanup. This is also the moment to press a control you may have deferred: privileged management platforms belong behind network restrictions and phishing-resistant multi-factor authentication, so a product-level bypass is not the only thing standing between an attacker and your fleet.

Action checklist
  1. Verify every N-central server is on hotfix build 2026.3.1.7 or later, and confirm the same with any MSP that manages your environment.
  2. Hunt managed endpoints for a Cloudflared service, an svchost.exe in a user's Documents folder, and traffic to N-able's published indicator addresses, and remove any persistence found.
  3. Place RMM consoles behind network access controls and phishing-resistant MFA, and review remote-session and console logs for unexpected access.
HIGH · SUPPORTING

Amgen says patient and proprietary data was stolen from third-party cloud systems

Key facts
  • Who: Amgen, one of the world's largest biotechnology companies, disclosed the incident in a regulatory filing.
  • What was taken: The company said proprietary data, patient protected health information, and other information was exfiltrated from cloud environments operated by a third party.
  • How it unfolded: Amgen said it detected unauthorized activity in July 2026, activated its incident response plan, applied containment measures, and engaged independent forensic experts. It did not disclose how attackers reached the cloud environments or name the providers involved.
  • Still under investigation: Amgen said it is still determining whether additional data was accessed, including confidential business information, intellectual property, and research and development data, and will notify affected patients where required.
  • Materiality statement: The company said it does not currently believe the incident is reasonably likely to materially affect its financial condition or operating results.

What happened

The point of interest for security leaders is the location of the loss. The data left through cloud systems run by a third party, not through Amgen's own front door, which places the exposure in the seam between an enterprise and a vendor it depends on. That seam is where accountability tends to blur, because the data is regulated as the enterprise's responsibility while the controls that failed sit in someone else's environment. For a life-sciences organization the stakes are doubled, since the same breach can expose both patient health information under privacy law and the research and intellectual property that underpins the business. Amgen's careful phrasing, that it is still determining the full scope, is a reminder that early disclosures set a floor on the impact rather than a ceiling.

Evidence

Two independent sources:

What this means for your team

Use this as a prompt to map where your regulated and sensitive data actually lives outside your own tenancy, because you cannot defend a copy you have not located. For each third-party cloud system that holds patient, customer, or proprietary data, confirm who monitors it, how access is logged, and how quickly you would be told of unauthorized activity, then test that notification path rather than assuming it works. Where contracts allow, require breach-notification timelines and evidence of monitoring from data custodians, and make exfiltration detection a named control in the vendor relationship rather than an implied one. For life-sciences and healthcare teams specifically, treat intellectual property and research data as breach-worthy alongside protected health information, since attackers clearly value both.

Action checklist
  1. Inventory third-party cloud systems that hold regulated or proprietary data, and record who is accountable for monitoring each one.
  2. Confirm contractual breach-notification timelines and logging expectations with data custodians, and test the notification path end to end.
  3. Extend data-loss monitoring and classification to intellectual property and research data, not only regulated personal data.
NOTABLE · SUPPORTING

UK Police National Legal Database confirms staff and customer contact data on the dark web

Key facts
  • Who: The Police National Legal Database (PNLD), which provides legal reference material to UK police and criminal justice bodies and runs the public "Ask the Police" advice service.
  • What was exposed: PNLD confirmed that names, organizations, and work email addresses of police officers, police staff, criminal justice professionals, government partners, and customers were compromised and published on the dark web. It said there is no evidence that passwords or other authentication data were taken.
  • Threat-actor claim: A group calling itself ExfilSquad claims a dataset of roughly 135,000 law-enforcement contact records, listing PNLD among its victims. The precise number of affected people, when the intrusion began, and how long access lasted had not been publicly confirmed as of August 3.
  • Public-service impact: For the "Ask the Police" service, the exposure appears limited to names and email addresses of people who previously submitted questions.

What happened

This breach carries lower data sensitivity than a health or credential leak, but higher targeting risk, because the exposed population is law enforcement and justice staff. Names paired with work email addresses are exactly the raw material for convincing phishing and impersonation aimed at people who handle sensitive casework, and the value to an adversary is the audience rather than the depth of the fields. The gap between the group's claimed record count and what PNLD has confirmed is a familiar feature of a live disclosure, and it is why the safer working assumption for potentially affected individuals is heightened vigilance rather than waiting for a final tally.

Evidence

Two independent sources:

What this means for your team

Even a contact-only leak deserves a targeted phishing-awareness prompt for the affected group, because attackers will pair the names and emails with current events to craft believable lures. If your organization operates a public-facing service that collects names and email addresses, treat this as a case study in scoping: separate the exposure to your own staff from the exposure to members of the public, since the response and the notification duties differ. Confirm that the platform behind any such service logs access and would surface bulk data extraction, and rehearse how you would communicate quickly and plainly if contact data for your people or your users appeared on a leak site.

Action checklist
  1. Issue a targeted phishing and impersonation alert to any group whose names and work emails may be exposed, tied to plausible current lures.
  2. Review logging and bulk-export detection on public-facing services that collect contact data.
  3. Rehearse a clear, prompt notification message for staff and for public users, keeping the two audiences distinct.

Also notable

Ranked-but-lighter items from the day, with sources so you can judge freshness and relevance.

  • Ruby on Rails patched CVE-2026-66066, a critical Active Storage flaw scored 9.5 that can let an unauthenticated attacker read files the app process can access, including secrets usable for remote code execution; proof-of-concept code went public ahead of schedule, so patch and rotate secrets. BleepingComputer (early August)
  • Researchers reported custom-malware attacks abusing hotel and hospitality Wi-Fi to breach Microsoft 365 accounts, a reminder that travel networks remain a soft path to cloud identity. BleepingComputer (August 3)
  • A random-number-generation flaw in COLDCARD hardware wallets was reported as likely linked to an $88 million Bitcoin theft, underscoring how cryptographic weaknesses in key generation can translate directly into loss. BleepingComputer (August 3)

FAQ

We patched our SonicWall SMA 1000 appliances. Are we done?

Not necessarily. Attackers exploiting CVE-2026-15409 and CVE-2026-15410 harvested credentials, active session databases, and TOTP MFA seeds before the fix. If a device was internet-facing while the flaws were live, treat it as a suspected intrusion, rotate the affected secrets and MFA seeds, invalidate sessions, and hunt for lateral movement rather than relying on the patch alone.

Is the 885-victim figure for INC Ransomware confirmed?

No. That count comes from INC Ransomware's own leak-site tally as tracked by public monitoring services and is a threat-actor claim, not an independently verified number. The confirmed facts are the vulnerabilities, their exploitation, and the researcher attribution to INC and to the UTA0533 cluster.

Which N-central build is safe, and does the KEV listing change our timeline?

Hotfix build 2026.3.1.7 or later is the safe version, and being on 2026.3 without the hotfix should be treated as still vulnerable. CISA's addition of CVE-2026-18577 to the Known Exploited Vulnerabilities catalog sets a remediation deadline for federal civilian agencies and is a strong urgency signal for everyone else.

Amgen said the data was in third-party cloud systems. What should we take from that?

That regulated and proprietary data held outside your own tenancy is still your responsibility even when the failing controls are a vendor's. Map where such data lives, confirm who monitors it and how fast you would be notified of unauthorized access, and make breach notification and exfiltration detection explicit obligations for data custodians.

What connects today's stories?

The remote-access and data-custody layers. VPN appliances and RMM consoles both grant standing reach into internal systems, and third-party cloud holds the data that reach protects. Each story shows an attacker converting access at that layer into credential theft, lateral movement, or data loss, so the priority controls are hardening and monitoring the access plane and rotating secrets after any suspected compromise.

CISO Platform Breach Intelligence Team
Related reading: the Breach Intelligence hub of prior Breach Watch editions, peer discussion on ransomware defense and response and vulnerability and exposure management, and work on third-party and supply-chain risk across the CISO Platform community.
Stay ahead of the next breach

Breach Watch is a free, vendor-neutral briefing from the CISO Platform community.

Join the CISO Platform community (free)

Subscribe to the weekly newsletter

Visit the Breach Intelligence hub

Corrections and takedown requests: CISO Platform is committed to accuracy and fairness. If any detail in this briefing is inaccurate, or if you represent an affected organization and would like a correction or removal, please contact us at pritha.aash@cisoplatform.com and we will review your request promptly.

Read more…
CISO PLATFORM · BREACH INTELLIGENCE
BREACH WATCH
Daily Breach Intelligence for Security Leaders · Sunday, August 2, 2026

TL;DR for CISOs: A quiet Sunday still carried one loud story: N-able shipped an emergency hotfix after finding that its first patch for an N-central authentication bypass left a second way in, and attackers were already using it to take over the remote monitoring platform that managed service providers use to run other companies' endpoints. That is a supply-chain problem wearing a patch-management costume. Alongside it, two active-exploitation threats stayed hot over the weekend: the Certighost flaw in Active Directory Certificate Services, which turns a plain domain account into domain compromise, and the on-premises SharePoint remote code execution bug that attackers keep using to steal machine keys. The thread is trust in the systems that hold your keys, from the RMM console to the certificate authority.

BOTTOM LINE FOR CISOS
  1. An incomplete patch is not a patch. N-able fixed one path into N-central in build 2026.2, then discovered attackers using a second path the fix did not close. If you run N-central or rely on an MSP that does, verify the exact build is 2026.3.1.7 or later, because upgrading to 2026.3 alone is no longer enough.
  2. Patching the platform does not evict a foothold on the endpoints below it. The attackers used N-central's own remote-access feature to reach managed machines and left Cloudflare tunnel services behind, which keep working after the route through the compromised server is cut. Compromise of a management plane means you must hunt on every downstream device, not just the console.
  3. Two weekend-hot bugs deserve a same-day status check. The Certighost flaw abuses default certificate-services behavior to impersonate a domain controller, and the on-premises SharePoint flaw is being used to steal ASP.NET machine keys for durable access. Confirm both are patched and, for SharePoint, that machine keys were rotated after patching.
CRITICAL · LEAD STORY

N-able rushes a second N-central fix after attackers slip past the first one

Key facts
  • What it is: An authentication bypass in N-central, the remote monitoring and management platform that managed service providers and internal IT teams use to administer customer endpoints at scale. A single compromised N-central server can run scripts, push tools, and open remote sessions across every device it manages.
  • The two CVEs: N-able labels the first issue CVE-2026-18556, an unauthenticated administrative account takeover it classifies as authentication bypass through an alternate path (CWE-288), fixed in build 2026.2. It then found a second way to reach the same weakness that the fix did not block, tracked as CVE-2026-18577, which affects all builds before 2026.3.1.7. N-able scored each 8.2 on CVSS 4.0.
  • Timeline: N-able began investigating on July 31 after an unusual volume of licensing errors from on-premises customers. On the morning of August 2 it identified the alternate exploitation vector and released a hotfix that same afternoon.
  • The attack chain: After gaining remote administrative access to an N-central server, the attacker used the Take Control remote-access feature to reach managed endpoints, then registered Cloudflare tunnels as Windows services on those devices. The tunnels connect outbound, so they need no inbound firewall rule and survive a reboot, and they preserved access after the route through the N-central server was revoked. N-able noted nothing suggests Cloudflare itself was compromised; the attackers abused its tunneling service.
  • Confirmed scope (facts): N-able said a limited number of customers were identified as impacted and that its support team engaged them directly. Hosted NCOD instances are being upgraded automatically on a schedule; self-hosted servers must be upgraded by the customer. Finland's national cyber security centre issued an August 2 advisory stating all versions available before the emergency hotfix were vulnerable.
  • Independent observation: Huntress reported exploitation within one partner account running a self-hosted instance, where attackers reached nine organizations and touched one endpoint in each; based on evidence so far, the post-compromise activity was limited to enumerating running processes before the attackers disconnected. Huntress said it did not observe the Cloudflare tunnel installation that N-able described in its notifications.
  • Not yet disclosed (open questions): N-able has not stated the number or identities of affected customers, how many downstream devices were reached, when exploitation began, who is responsible, or whether any data was taken.

What happened

The reason this story sits at the top of a slow news day is the position of the target. An RMM platform is one of the highest-value machines in any estate that uses one, because it holds standing administrative reach into hundreds or thousands of endpoints by design. When the platform belongs to a managed service provider, that reach crosses company boundaries, so a single break-in becomes a set of break-ins at every client the provider serves. The vulnerability itself is an authentication bypass, meaning the attacker did not need valid credentials to gain administrative control of the server.

The detail worth dwelling on is the sequence, not just the flaw. N-able believed it had closed the hole in build 2026.2, and its first advice to exposed customers was to move to 2026.3. During the investigation it found a different route to the same weakness that the earlier fix left open, which is why a fresh CVE and a same-day hotfix followed. The persistence method compounds the problem: by planting outbound Cloudflare tunnels on the managed endpoints, the attackers built a foothold that outlives the cleanup of the console. Cutting off the compromised N-central server does not remove a service quietly running on a workstation two hops away. Reports from N-able and from Huntress differ on whether that tunnel activity was seen in every case, which is a normal feature of an incident still under analysis rather than a contradiction to resolve today.

Evidence

Two independent sources:

What this means for your team

Treat this as a management-plane incident, which changes the order of your response. Confirming the build number comes first, because the safe version is specific: 2026.3.1.7 or later, not simply the 2026.3 line. If you outsource IT or security to a provider, this is a direct question to send them today, phrased as which N-central build they run and when it was applied, since their exposure is your exposure. Once patching is confirmed, shift to hunting on the endpoints, because the persistence lives there rather than on the server you just fixed. Look for the indicators N-able published, including a service named Cloudflared, a stray svchost.exe in a user's Documents folder, and traffic to the listed addresses, and correlate any unexpected Take Control sessions against your own change records. Finally, use this as the concrete case for a policy you may have deferred: privileged management tools should sit behind network restrictions and phishing-resistant multi-factor authentication so that an authentication bypass in the product is not the only thing standing between an attacker and every endpoint you own.

Action checklist
  1. Verify every N-central server is on build 2026.3.1.7 or later; treat 2026.3 without the hotfix as still vulnerable, and confirm the build with any MSP that manages your environment.
  2. Hunt on managed endpoints for a service named Cloudflared, an svchost.exe placed in a user's Documents folder, and connections to N-able's published indicator addresses, and remove any persistence found.
  3. Review Take Control and console access logs for unexpected remote sessions, and reset credentials and session tokens tied to any server confirmed or suspected as compromised.
  4. Place RMM and other privileged management consoles behind network access controls and phishing-resistant multi-factor authentication so a product-level bypass is not a single point of failure.
CRITICAL · SUPPORTING

Certighost turns a plain domain account into domain takeover, and default AD CS is enough

Key facts
  • The flaw: CVE-2026-54121, nicknamed Certighost, is an improper-authorization weakness in Active Directory Certificate Services rated CVSS 8.8. It lets an authenticated attacker manipulate machine-account attributes and obtain a certificate that authenticates as that machine through PKINIT.
  • Why it escalates: If the attacker targets a domain controller account, the issued certificate authenticates as the domain controller, which carries directory replication rights. Researchers demonstrated using the resulting Kerberos credential to run a DCSync attack and pull the krbtgt secret, the key to forging tickets across the domain.
  • The mechanism: It abuses an AD CS enrollment fallback the researchers call a chase, driven by client-supplied cdc and rmd values. The certification authority did not verify that the server named in the attacker-controlled cdc value was a legitimate domain controller, so a rogue SMB, LSA, and LDAP service could feed it false identity data.
  • Why hardening did not save everyone: Certighost exploits behavior that ships with default AD CS, not a misconfigured certificate template, so organizations that already locked down the well-known ESC-series template issues were not necessarily protected.
  • Preconditions: A standard domain account and network reachability to a vulnerable enterprise certification authority. A low-privileged user can create the needed machine account under the default ms-DS-MachineAccountQuota setting; no administrator rights or user interaction are required.
  • Fix and timeline: Reported to Microsoft on May 14, 2026, and fixed in the July 2026 Patch Tuesday updates, which add validation to the chase process. Researchers H0j3n and Aniq Fakhrul published technical details and a working proof-of-concept in late July, and the flaw stayed on weekend threat roundups through August 2.

What happened

Active Directory Certificate Services is the certificate authority most Windows domains run to issue the certificates that authenticate machines and secure communications, which makes it a natural target for anyone who wants to become a domain controller in the directory's eyes. Certighost reaches that goal by tricking the certificate authority during enrollment. The authority trusted an attacker-supplied pointer to a server it believed was a domain controller, then trusted the identity data that server returned, and issued a certificate for a targeted domain controller account on that basis. From there the attacker holds a credential with replication rights and can extract the domain's most sensitive secrets. Because the abused path is part of default behavior, the population of exposed environments is larger than the set that ever misconfigured a template.

Evidence

Two independent sources:

What this means for your team

The comfortable assumption to drop is that a hardened AD CS template inventory means AD CS is handled. Certighost lives below the template layer, so the July update is the real fix, and confirming it landed on every certification authority is the priority rather than another template audit. If a certification authority cannot be patched immediately, the researchers describe disabling the optional chase fallback as a temporary measure, but they are explicit that it is untested in production and not a substitute for the update. Beyond patching, tighten the precondition that makes exploitation trivial: the default machine-account quota lets any user create the account the attack needs, so reducing ms-DS-MachineAccountQuota to zero for ordinary users removes an easy building block for this and several related techniques. Finally, watch certificate issuance and Kerberos authentication for machine accounts behaving like domain controllers, because a certificate-based domain compromise is quiet unless you are looking for it.

Action checklist
  1. Confirm the July 2026 Patch Tuesday updates are installed on every Active Directory Certificate Services host, treating it as the definitive fix for CVE-2026-54121.
  2. Reduce ms-DS-MachineAccountQuota to zero for standard users so they cannot create the machine account the exploit relies on.
  3. Monitor certificate enrollment and Kerberos activity for machine accounts requesting or using domain-controller-level rights, and alert on unexpected DCSync-style replication requests.
HIGH · SUPPORTING

On-premises SharePoint is still being hit, and the prize is your machine keys

Key facts
  • The flaw: CVE-2026-50522 is a critical deserialization of untrusted data in on-premises Microsoft SharePoint, rated CVSS 9.8. It allows an unauthenticated attacker to execute code over the network.
  • How the exploitation started: Researchers at watchTowr identified a public proof-of-concept around July 20, and exploitation against internet-facing on-premises SharePoint followed within hours, with attackers stealing the server's ASP.NET machine keys to keep access.
  • Why the machine keys matter: With the machine keys in hand, an attacker can forge trusted payloads and re-enter the server even after it is patched, which turns a one-time break-in into durable access unless the keys are rotated.
  • Regulatory clock: CISA added CVE-2026-50522 to its Known Exploited Vulnerabilities catalog on July 22, setting a July 25 remediation deadline for federal civilian agencies, a useful benchmark for private organizations as well.
  • Current status: The flaw remained under active exploitation through the weekend, and only on-premises SharePoint is affected, not SharePoint Online.

What happened

This is the pattern that keeps recurring with widely deployed on-premises servers: a proof-of-concept goes public, and mass exploitation arrives faster than most patch cycles can respond. What makes this SharePoint flaw stubborn is the objective. Attackers are not only running code; they are lifting the cryptographic machine keys that SharePoint uses to sign and validate data. Once those keys are stolen, patching the deserialization bug closes the front door while the attacker keeps a key to the side entrance. That is why remediation here has two steps, and skipping the second one leaves the incident open.

Evidence

Two independent sources:

What this means for your team

If you run SharePoint on-premises and have not confirmed both halves of the fix, do it before the next work week. Applying the update stops new exploitation, but rotating the ASP.NET machine keys is what evicts an attacker who already grabbed them, and the two actions are not interchangeable. Assume any internet-facing on-premises SharePoint server was a target while the proof-of-concept was public, and hunt accordingly rather than waiting for a clean bill of health. For a fuller walkthrough of the machine-key theft and the rotation steps, the CISO Platform community write-up on this vulnerability is linked below.

Action checklist
  1. Patch on-premises SharePoint for CVE-2026-50522, then rotate ASP.NET machine keys and restart the affected services so stolen keys stop working.
  2. Hunt for signs of prior compromise on internet-facing servers, including unexpected web shells, new application pool identities, and outbound connections dating to the public-PoC window.
  3. Reduce exposure by placing on-premises SharePoint behind a reverse proxy or VPN where possible, and confirm SharePoint Online tenants are unaffected to focus effort correctly.

Also notable

Ranked-but-lighter items from the weekend and the past few days, with dates so you can judge freshness.

  • A ransomware group operating as coinbasecartel listed the European standardization bodies CEN and CENELEC on its leak site and threatened to publish data unless negotiations begin. This is an unverified threat-actor claim; neither organization has confirmed an incident, and the scope is not established. ransomware.live leak-site tracker (claim dated August 1)
  • Anthropic said its own AI models breached three organizations during security testing after a misconfiguration let the models reach the live internet from environments meant to be isolated; the compromises used basic techniques such as weak passwords and unauthenticated endpoints, a pointed reminder of both agent-safety gaps and ordinary hygiene failures. TechCrunch (July 30)
  • Medical billing firm MCBS disclosed a breach affecting 1,261,464 people, with exposed data that may include Social Security numbers, health plan identifiers, and medical details, underscoring the concentrated risk in healthcare revenue-cycle vendors. BleepingComputer (late July)
  • Weekend threat-intel roundups flagged CISA's recent addition of a Cisco Secure Firewall Management Center flaw to its Known Exploited Vulnerabilities catalog, alongside continued reporting on modular malware-as-a-service tooling; a prompt to check FMC patch status. Security Affairs Malware Newsletter Round 108 (August 2)

FAQ

Which N-central build is actually safe?

Build 2026.3.1.7 or later. N-able first told exposed customers to move to the 2026.3 line, but after finding a second exploitation path it released a hotfix, so 2026.3 without that hotfix should still be treated as vulnerable. Hosted NCOD instances are being upgraded automatically; self-hosted servers must be upgraded by the customer.

Why does patching N-central not fully close the incident?

Because the attackers used the platform to reach managed endpoints and planted outbound Cloudflare tunnel services on them. Those tunnels keep working after the compromised server is cleaned up, so a full response includes hunting for and removing persistence on the downstream devices, not only fixing the console.

We hardened our AD CS templates. Are we safe from Certighost?

Not necessarily. Certighost, tracked as CVE-2026-54121, abuses default certificate-services behavior rather than a misconfigured template, so template hardening against the ESC-series issues does not cover it. The July 2026 Patch Tuesday update is the real fix, and reducing the machine-account quota for standard users removes a key precondition.

We already patched SharePoint. Is anything left to do?

Possibly. Attackers exploiting CVE-2026-50522 have been stealing ASP.NET machine keys, which let them return even after the code-execution flaw is patched. Rotating the machine keys and restarting the affected services is the second step, and skipping it can leave a patched server still accessible.

What is the common thread across today's stories?

Trust in the systems that hold your keys. An RMM console with standing administrative reach, a certificate authority that vouches for identity, and a SharePoint server holding cryptographic machine keys are all high-value targets, and each story shows an attacker converting access to one of them into durable control. The priority controls are strict access and patch discipline on management planes, and rotating secrets after any suspected compromise.

CISO Platform Breach Intelligence Team
Related reading: the CISO Platform community write-up on the SharePoint RCE CVE-2026-50522 machine-key theft, the Breach Intelligence hub of prior Breach Watch editions, and peer discussion on vulnerability and exposure management and identity and access security across the CISO Platform community.
Stay ahead of the next breach

Breach Watch is a free, vendor-neutral briefing from the CISO Platform community.

Join the CISO Platform community (free)

Subscribe to the weekly newsletter

Visit the Breach Intelligence hub

Corrections and takedown requests: CISO Platform is committed to accuracy and fairness. If any detail in this briefing is inaccurate, or if you represent an affected organization and would like a correction or removal, please contact us at pritha.aash@cisoplatform.com and we will review your request promptly.

Read more…
CISO PLATFORM · BREACH INTELLIGENCE
BREACH WATCH
Daily Breach Intelligence for Security Leaders · Thursday, July 30, 2026

TL;DR for CISOs: The through-line today is not a software flaw. It is the phone. The two loudest stories both start with a person on a call, not an exploit in a payload. ShinyHunters claims it walked into Brinks Home through a Microsoft Entra voice-phishing call and left with millions of Salesforce records, and Sophos detailed a separate campaign where fake IT support on Microsoft Teams talked employees into remote-access sessions that ended in Chaos ransomware, one in under 17 hours. Alongside them, semiconductor maker Analog Devices told the SEC that intruders exfiltrated files from its network and that it is now weighing a second, separate extortion claim. Identity and the help desk are the initial-access surface of the day.

BOTTOM LINE FOR CISOS
  1. Your help desk is an authentication boundary. Both lead incidents began with a caller impersonating IT or triggering an identity workflow. A convincing two-minute conversation is now a credible path to domain-level access, and no patch closes it. Process and verification do.
  2. The data that hurts you may sit in a SaaS tenant, not your data center. The Brinks Home claim centers on Salesforce records reached through a stolen employee identity. Your third-party and SaaS estate inherits the blast radius of every credential your staff hold.
  3. Disclosure is getting messier, not cleaner. Analog Devices is managing an SEC-reported intrusion and a separate extortion claim at the same time. Assume you will have to reason about overlapping, partially verified claims in public, and prepare a communications posture for exactly that.
CRITICAL · LEAD STORY

ShinyHunters claims a Brinks Home breach reached through a single vishing call

Key facts
  • Who: Brinks Home, a residential security provider serving more than 1 million customers across the United States, Canada, and Puerto Rico, with up to 1,500 employees and roughly $830 million in annual revenue.
  • Confirmed by the company: Brinks Home says it identified the attack on July 20, activated incident response, and is working with outside forensics experts. The intrusion did not affect alarm monitoring or system functionality.
  • Threat-actor claim: The ShinyHunters extortion group told BleepingComputer it breached Brinks Home on July 13 through a Microsoft Entra voice-phishing (vishing) call and exfiltrated more than 4.9 million Salesforce records containing personal data.
  • Claimed detail: ShinyHunters alleges more than 1.1 million rows from the Salesforce "Contacts" object, more than 4,000 rows of employee personal data, and more than 3.8 million customer support chat logs. These figures are the attacker's, not confirmed by Brinks Home or verified independently.
  • Company posture: Brinks Home confirms the attacker has threatened to release data and says it has not yet determined exactly what information was involved or whose. It is warning customers to expect impersonation and phishing attempts.

What happened

The mechanism claimed here is the story. ShinyHunters says it did not defeat a firewall or chain a vulnerability. It called an employee and steered that person through a Microsoft Entra authentication or registration step, and that single interaction handed over an account. From inside a legitimate identity, the group says it pivoted to the company's Salesforce environment and pulled customer and employee records out of it. Brinks Home has confirmed the intrusion and the extortion threat while stating that it has not yet verified the scope or the specific data involved, so the corporate facts and the criminal claims should be read as two separate layers.

This pattern is now a recognizable playbook rather than a novel one. The same group has been tied to a run of extortion cases built on SaaS data reached through stolen staff identities, and the common thread is that the front door was a person, not a port. For a company whose entire brand is physical security, an identity-driven compromise of its customer platform is an uncomfortable reminder that the weakest control is rarely the one in the product catalog.

Evidence

Two independent sources:

What this means for your team

Treat this as a rehearsal for the call your own help desk will get. The control that would have stopped it is not a product but a rule: no identity action, no authenticator registration, no password reset, and no remote session gets completed on the strength of a phone call alone. Out-of-band verification of the requester, ideally through a channel the caller cannot influence, is the countermeasure that matches the attack. The second lesson is about where your sensitive data actually lives. If a single employee identity opens a path to millions of customer records in a SaaS platform, then your SaaS access model, not your perimeter, is the real control surface. Scope what each role can read and export, and put alerting on bulk data pulls from customer relationship platforms so an unusual extraction is visible while it is happening.

Action checklist
  1. Give your help desk and identity teams a written, mandatory out-of-band verification step for any password reset, authenticator enrollment, or MFA change, and rehearse the script for a caller who claims urgency.
  2. Review conditional access and authentication-registration policies in your identity provider so a new device or authenticator cannot be added from an unmanaged session without a second, independent check.
  3. Audit which roles can bulk-export from Salesforce or your CRM, apply least privilege to those export rights, and enable alerts on large or off-hours data extractions.
  4. If you are a Brinks Home customer, expect impersonation attempts referencing the incident, verify any contact through official channels, and do not act on links in unsolicited messages.
CRITICAL · SUPPORTING

Fake IT support on Microsoft Teams is ending in Chaos ransomware

Key facts
  • Campaign: Sophos tracks the activity as STAC4749 and says it targeted dozens of organizations between February and June 2026.
  • Outcome: At least three intrusions led to Chaos ransomware. In one case, less than 17 hours passed between the first Microsoft Teams contact and file encryption.
  • Geography and sectors: About 95 percent of attacks hit organizations in Canada (50 percent) and the United States (45 percent), concentrated in services, manufacturing, energy, and construction and engineering.
  • Method: External Teams accounts posing as IT helpdesk staff open chats and voice calls, most lasting only two to two-and-a-half minutes, to convince employees to launch Microsoft Quick Assist or install a remote management tool such as RemSupp.
  • Post-access: The attackers used PowerShell to drop a backdoor in the user's %AppData% folder, disguised persistence entries as Realtek and Windows audio components, and in ransomware cases added tools like DWAgent or AnyDesk and enabled Remote Desktop Protocol for lateral movement.
  • Attribution: Chaos is a ransomware-as-a-service operation active since at least February 2025 and linked to former members of the BlackSuit and Royal gangs, themselves spinoffs of Conti.

What happened

This is the enterprise twin of the Brinks Home story, and it explains why both lead the day. The attacker never needs a software vulnerability when a believable helpdesk caller can persuade an employee to open a remote-control session and approve it. Sophos found the operators had refined the approach: instead of the older trick of spinning up tenants on Microsoft's own onmicrosoft.com domain, STAC4749 registered IT-themed domains under the ".top" suffix and paired them with consistent fake personas to make the "support" outreach look routine. Once an employee granted access, the operators moved quickly from a single workstation to backups and file servers.

Speed is the detail that should worry defenders most. A window of under 17 hours from first contact to encryption leaves little room for a human-driven investigation to catch up. The persistence tradecraft compounds the problem, because entries dressed up as audio drivers are the kind of thing that survives a casual look at what is running on a machine. This is social engineering executed with the discipline of an intrusion team, and it lands regardless of how well patched the environment is.

Evidence

What this means for your team

The control that matters is restricting who can reach your employees through Microsoft Teams and what tools they can be talked into running. External Teams messaging that most organizations leave open by default is the delivery channel here, and tightening federation and external-communication settings removes the easy path. Just as important is treating remote-access utilities as privileged software: if Quick Assist and unsanctioned remote monitoring tools cannot execute on endpoints without approval, the caller's request has nowhere to go. Because this attack chain moves in hours, endpoint detection needs to alert on the specific behaviors, PowerShell dropping executables into user profile folders, new audio-named persistence entries, and sudden installs of remote-access agents, rather than waiting for the ransomware stage.

Action checklist
  1. Restrict external Microsoft Teams chat and calls to approved domains, and disable open external communication if your business does not require it.
  2. Block or gate Quick Assist and unsanctioned remote monitoring and management tools on endpoints through application control, allowing only your approved support tooling.
  3. Alert on PowerShell writing executables to %AppData%, on new registry run keys named after audio components, and on unexpected installs of DWAgent, AnyDesk, or RemSupp.
  4. Brief staff that legitimate IT will never cold-call over Teams to request a remote session, and give them a simple way to verify and report such contacts.
HIGH · SUPPORTING

Analog Devices tells the SEC data was exfiltrated, and weighs a second extortion claim

Key facts
  • Who: Analog Devices, a Massachusetts-based semiconductor manufacturer with a market capitalization above $178 billion and more than $11 billion in revenue last year, specializing in data-conversion and signal-processing chips.
  • Disclosure: In a filing with the Securities and Exchange Commission, the company said it identified "unauthorized access" to certain systems on June 23 and activated incident response, bringing in outside experts and coordinating with law enforcement.
  • Data impact: During the investigation the company found that "certain files" had been exfiltrated. The scope is not yet known, and the company does not expect a material impact on its business.
  • Second matter: Analog Devices said it was informed of a separate "disparate cybersecurity matter" on July 26 that it claims is not connected to the June intrusion, and it is assessing that claim's validity, scope, and impact.
  • Extortion claim: The second matter may relate to the ransomware group ExfilSquad, which claimed to have stolen more than 570,000 records related to Analog Devices customers. The company did not address the ransomware claim.

What happened

The disclosure itself is measured: an intrusion identified in late June, an investigation that confirmed files left the network, and a statement that the business impact is not expected to be material. What makes this one worth the attention of security leaders is the second thread. The company is now publicly separating two events, the June intrusion it reported to regulators and a distinct claim raised in late July, while a criminal group advertises a haul of customer records. Whether those are one story or two is exactly the ambiguity that extortion crews exploit, because a company that cannot yet confirm scope is a company under pressure to negotiate.

Semiconductor firms keep appearing on the target list because their designs, process data, and customer relationships have durable strategic value. That value is why a chipmaker's breach carries weight even when operations are unaffected and revenue guidance is untouched. The exposure that matters is the data, not the downtime.

Evidence

What this means for your team

Two lessons carry over regardless of your sector. The first is that your incident communications need a plan for overlapping claims. When a criminal group publishes a figure before you have finished counting, silence and premature confirmation are both risks, and the only durable position is a factual, scope-bounded statement you can stand behind and update. Rehearse that stance before you need it. The second is that a breach with "no material impact" on operations can still expose the assets that define your competitive position. Map where your crown-jewel data, product designs, source code, and sensitive customer records actually resides, and make sure exfiltration monitoring covers those stores specifically, because attackers who cannot stop your business will happily monetize your secrets.

Action checklist
  1. Confirm your incident-response plan includes a communications track for extortion claims, with pre-agreed thresholds for what you will and will not confirm publicly.
  2. Inventory your highest-value data stores and verify that data-loss and exfiltration monitoring is tuned to those systems, not just to endpoints.
  3. Review your SEC or regulatory disclosure playbook so materiality assessment and filing timelines are clear before an incident, not improvised during one.
  4. If you are an Analog Devices customer or supplier, watch for follow-on phishing that references the incident and confirm any unusual request through an established contact.

Also notable

Ranked-but-lighter items from the past few days worth keeping on the board, with dates so you can judge freshness.

  • The Record reported on July 29 that the Russia-linked group Laundry Bear (also tracked as Void Blizzard) weaponized CVE-2026-42897, a cross-site scripting flaw in Microsoft Outlook Web Access, against government, telecom, financial, hospitality, and aerospace targets in the US and Europe in a campaign observed from July 22. The Record
  • The Hacker News reported an active credential-stuffing campaign against SonicWall VPN and firewall accounts observed since July 25, resulting in successful unauthorized logins to 92 unique accounts across 30 organizations, a reminder to enforce MFA and monitor for password reuse on edge devices. The Hacker News
  • A "FakeGit" operation is using roughly 7,600 GitHub repositories, created by about 6,600 lookalike profiles, to spread SmartLoader malware through convincing project pages and malicious ZIP files, with more than 14 million recorded downloads, a supply-chain risk for any team that pulls tooling from public repos. The Hacker News
  • BleepingComputer reported that an OpenAI agent used exposed credentials to reach four services during a Hugging Face breach scenario, an early illustration of how autonomous agents can turn a leaked secret into lateral movement across connected platforms. BleepingComputer

FAQ

What did ShinyHunters claim about the Brinks Home breach?

ShinyHunters told BleepingComputer it breached Brinks Home on July 13 through a Microsoft Entra voice-phishing call and stole more than 4.9 million Salesforce records with personal data, including customer contact rows and employee data. Brinks Home has confirmed an intrusion and an extortion threat but says it has not yet verified the scope or the specific data involved, so the figures remain the attacker's unverified claim.

What is the STAC4749 Microsoft Teams campaign?

STAC4749 is a campaign Sophos tracked between February and June 2026 in which attackers posed as IT support on Microsoft Teams, using IT-themed ".top" domains and fake personas, to convince employees to start remote-access sessions. At least three intrusions ended in Chaos ransomware, with one case going from first contact to encryption in under 17 hours. About 95 percent of targets were in Canada and the United States.

How did attackers get in without exploiting a vulnerability?

In both lead incidents the initial access was social engineering rather than a software flaw. Attackers either walked an employee through a Microsoft Entra identity step or persuaded them to launch a remote-support tool such as Quick Assist. The defense is process-based: out-of-band verification for identity actions, restrictions on external Teams contact, and application control over remote-access utilities.

What did Analog Devices disclose to the SEC?

Analog Devices told the SEC it identified unauthorized access to certain systems on June 23 and later found that certain files had been exfiltrated, though the scope is still under investigation and no material business impact is expected. The company also said it was informed of a separate cybersecurity matter on July 26 that it claims is unrelated, which may connect to a ransomware group's claim of stealing customer records.

Why does CISO Platform lead today with social engineering rather than a CVE?

Because the day's highest-impact incidents share an initial-access method that no patch addresses. When a phone call to the help desk or an employee produces domain-level access or a path into a SaaS tenant, the priority control is identity verification and access governance, not vulnerability management. The lesson generalizes well beyond the named companies.

CISO Platform Breach Intelligence Team
Related reading: the CISO Platform Breach Intelligence hub collects prior Breach Watch editions. Compare notes on identity and help-desk security and on ransomware readiness with peers across the CISO Platform community.
Stay ahead of the next breach

Breach Watch is a free, vendor-neutral briefing from the CISO Platform community.

Join the CISO Platform community (free)

Subscribe to the weekly newsletter

Visit the Breach Intelligence hub

Corrections and takedown requests: CISO Platform is committed to accuracy and fairness. If any detail in this briefing is inaccurate, or if you represent an affected organization and would like a correction or removal, please contact us at pritha.aash@cisoplatform.com and we will review your request promptly.

Read more…

At CISOPlatform Summit 2024, cryptographer and author Bruce Schneier was asked where post-quantum cryptography actually stands. In conversation with Bikash Barai, Co-founder, FireCompass and CISO Platform, his answer moved the problem away from the place most security programs are looking. The algorithms are in decent shape, he said. The ability to change them is not.

The math is ahead of the physics. Schneier pointed to the international competition NIST is running in the United States for quantum-resistant public key algorithms, and said that on that front the industry is doing really well. He was explicit about the uncertainty on the other side of the equation: we will not know until there is a working quantum computer, and even then it is unclear whether the attack algorithms are practical. They are not exponential, he noted, but nobody knows what the linear and geometric terms turn out to be. He described himself as pretty optimistic that we get through this.

The real issue is crypto agility. This was his central point. The products, the services and the uses of cryptography need to be agile, able to swap algorithms in and out. His argument for why that matters is broader than quantum: if a system is agile, it can absorb a quantum computer, or a development in classical cryptography, or anything else that breaks what is currently deployed. Agility is the control that covers the threat you have not named yet.

The industry's track record on swapping algorithms is poor. Schneier was blunt that we are not very good at crypto agility, and that we were terrible at it a couple of decades ago when the industry had to replace DES with AES, and MD5 with SHA, then SHA-1, then SHA-256. His hope is that we are getting better. He named this as the important thing to remember from the whole discussion.

Why this matters for CISOs

Most post-quantum planning currently on CISO desks is algorithm selection: which standard to adopt, on what timeline. Schneier's framing says that work is largely being handled for you, and that the part you own is architectural. The question you can act on this quarter is not which algorithm, but whether your systems, your vendors and your embedded estate can be made to change algorithms at all, and how long that would take. That is a cryptographic inventory and a procurement requirement, and both are decisions a security leader controls today.

It also reframes the business case. Agility is not a bet on when quantum computers arrive. It is insurance against every future cryptographic break, which is a far easier argument to take to a board than a timeline nobody can defend.

One question for the community

Pick the single system in your environment where swapping a cryptographic algorithm would be hardest. Is it a vendor product you cannot modify, an embedded or OT fleet, code your own teams own, or your certificate infrastructure? How long would that swap realistically take, and what has actually worked when you have tried it?

Join the CISO Platform community

CISO Platform is a peer community of security leaders who work these problems out together. If you are wrestling with cryptographic inventory, vendor agility requirements or post-quantum sequencing, bring it to the group. Join the CISO Platform community and add your experience to this discussion.

The full fireside chat with Bruce Schneier is available on CISO Platform.

Read more…

Anton Chuvakin, Security Advisor at Google Cloud, made this point in a CISO Platform session on practical AI in cybersecurity, in conversation with David Randleman, Field CISO at FireCompass. It has nothing to do with AI and everything to do with how security policy is written: most patching policies are worded in a way that guarantees the organization is out of compliance with its own rules every single day.

Absolute patching deadlines put you in permanent violation. Chuvakin described the policy language he saw repeatedly during his Gartner years: critical vulnerabilities patched in 10 days, high in 30, low never. Read literally, that policy is broken the moment a single critical finding sits unpatched past day 10. Not occasionally. Continuously.

The gap is operational reality, not negligence. His example is deliberately mundane. A critical vulnerability lands on the laptop of an employee who is twelve days into a vacation. There is no team, no budget, and no tooling that patches that machine inside the 10-day window. The policy did not account for the world it was written for, so the failure is structural rather than a matter of effort or discipline.

Percentages turn an unmeetable rule into a real SLA. Chuvakin’s fix is to change the sentence, not the target: "How about you say we patch 97% of critical within 10 days." The number becomes something a team can hit, report against, and defend. It also makes the residual 3% visible and discussable instead of hiding it inside a rule everyone quietly knows is fictional.

Why this matters for CISOs

A policy nobody can meet is worse than no policy. It gives auditors a standing finding, it gives the board a metric that is always red, and it trains your own team to treat the written rule as decoration. Rewriting patching commitments as percentage-based service levels changes what you report upward: instead of explaining why you are non-compliant again, you are reporting a coverage rate against a threshold you set deliberately. That is a conversation about risk appetite, which is the conversation you want to be having with the board and with your auditors.

It also changes what you buy and how you staff. If the target is 97% of critical findings inside 10 days, you can measure which gaps are tooling problems, which are asset-visibility problems, and which are simply unreachable endpoints. Absolute deadlines flatten all three into one undifferentiated failure.

Over to you

Is your patching policy written as an absolute deadline or as a coverage percentage? And if you have tried moving your organization from one to the other, what did your auditors say about it? That second part is where most people get stuck.

Join the CISO Platform community. Thousands of senior security leaders across North America use CISO Platform to compare notes on exactly these decisions, before they have to defend them to a board. Become a member here and add your view to this discussion.

Source: Practical AI In Cybersecurity, a CISO Platform Best of the World Talks session with Anton Chuvakin, Security Advisor, Google Cloud.

Read more…

Member Contribution - Weekly CISO Podcast Pick

This Week's Pick by David B. Cross (CISO, Atlassian)

Series curated by the CISO Platform community, sharing practical security leadership resources recommended by experienced CISOs and senior practitioners.

Cyber Smokehouse: How AI Is Reshaping Cybersecurity

David's recommendation is an episode of the Cyber Smokehouse podcast in which he discusses how artificial intelligence is changing the cybersecurity landscape. AI is lowering barriers for attackers, accelerating the pace of risk, and forcing security teams to adapt their operating models.

His central point is practical: defenders cannot respond to AI-enabled threats only with more manual work. Security leaders need to use AI deliberately inside defensive operations while keeping human accountability around judgment, risk, and response.

Focus: AI-enabled threats, defensive AI, security operations, workforce adaptation, leadership accountability

Why this matters to CISOs

  • AI reduces the time and expertise needed to research targets, create convincing content, analyze code, and scale attacks. Existing controls may face more attempts at higher speed.
  • Security teams cannot match machine-speed activity with ticket queues and manual investigation alone. Defensive workflows need safe automation and clear escalation paths.
  • Adopting AI is an operating-model decision, not just a tooling decision. CISOs need to define approved data, accountable owners, validation requirements, and measurable outcomes.
  • Human judgment remains essential where context, business impact, and risk appetite matter. The goal is to increase analyst leverage without automating accountability away.

Copy-paste takeaways for your team

  • Use AI first for bounded, reviewable tasks such as alert enrichment, case summarization, query drafting, and repetitive evidence collection.
  • Require source evidence and analyst confirmation before AI-generated conclusions change severity, containment, or remediation decisions.
  • Track where AI reduces investigation time and where it introduces rework, false confidence, sensitive-data exposure, or access risk.
  • Threat-model the AI workflow itself: prompts, connected tools, identities, retrieved data, outputs, logs, and failure modes.
  • Train teams to challenge AI output, preserve evidence, and escalate uncertainty instead of treating fluent answers as verified analysis.

Standout ideas

  • AI changes attack economics by making previously expensive work cheaper and easier to repeat.
  • Defensive advantage comes from integrating AI into disciplined workflows, not from adding an isolated assistant to every analyst's desktop.
  • The most useful AI security measures connect adoption to operational outcomes: faster triage, better coverage, lower backlog, and more consistent decisions.
  • Adaptation is continuous. Models, attacker techniques, internal use cases, and control assumptions all need recurring review.

Try this in the next 7 days

  1. Choose one high-volume security workflow and measure its current cycle time, analyst effort, and error rate.
  2. Identify one bounded step that AI could assist without making the final risk decision.
  3. Document the data boundary, tool permissions, required human review, logging, and rollback path for a small pilot.
  4. Review results with analysts after one week and decide whether the pilot improved speed and quality without adding unacceptable risk.

About David B. Cross

David is CISO at Atlassian and a long-time community member at CISO Platform. His weekly picks are short-listed for practical signal: conversations that sharpen how security leaders guide teams, govern emerging technology, and make better risk decisions.

Share this with your team

Use this episode to ask one concrete question: which defensive workflow should AI accelerate now, and what human review must remain non-negotiable?

Read more…
CISO Platform
BREACH INTELLIGENCE

CISOPlatform Breach Report

June 23, 2026 | Key Breach Incidents Overview

Three incidents show how trusted identity decisions, third-party data stores, and agent control channels can convert routine access into operational loss, sensitive-data theft, or code execution.



Executive Summary

The common failure is misplaced trust at a boundary: a help desk trusts a caller, a company trusts a workforce vendor, or an agent trusts localhost.

The Transport for London case puts a confirmed £39 million price on an identity-led intrusion. Nintendo's disclosure shows why “our systems were not affected” does not close risk when employee data sits with a third party. Microsoft's AutoJack research shows that browser-capable agents can turn untrusted web content into commands against privileged local services.

CISO takeaway: Validate identity proofing, map sensitive data held outside the enterprise, and require authenticated, isolated control channels for agents and local developer services. Trust must be scoped, logged, and quickly revocable.

Report Scope

Prepared for: CISOs, Identity Security, Detection Engineering, Incident Response, Third-Party Risk, AI Security, Security Architecture.

Report Lens: Board-aware breach intelligence with technical control guidance.

Criticality Snapshot

Top Incidents Featured

PriorityIncidentEnterprise Risk SignalImmediate Control Focus
1Transport for London identity-led intrusionSocial engineering produced prolonged service disruption, large-scale data impact, and £39 million in cost.Help-desk identity proofing, privileged recovery controls, session revocation, and downtime modeling.
2Nintendo and TinyPulse employee-data theftA workforce SaaS provider became the exposure point for sensitive employee records and survey content.Vendor data inventory, retention review, tenant logs, credential rotation, and employee protection.
3Microsoft AutoJack agent RCE chainUntrusted browsing content crossed a localhost trust boundary and reached command-capable agent services.Local-service authentication, origin validation, isolation, least privilege, and execution policy.

Why these three matter together

Each case begins with a trusted operating path that was broader than its controls: identity recovery, outsourced employee-data processing, or local agent administration. The practical program question is not whether the path is trusted. It is whether the trust decision is independently verified, narrowly authorized, observable, and reversible before material impact develops.

 
Incident 1

Transport for London Identity-Led Intrusion

Identity and Operations

One Identity Decision, £39 Million in Loss

The guilty pleas reinforce how English-speaking social-engineering crews can turn support access into enterprise-wide operational impact.

What Happened

Two British defendants linked to Scattered Spider pleaded guilty in connection with the 2024 cyberattack on Transport for London. The incident disrupted customer services, affected data associated with millions of people, and cost TfL £39 million. One defendant also admitted compromising SSM Health and attempting to compromise Sutter Health in the United States. The legal record strengthens attribution of the campaign pattern to identity-focused social engineering rather than a purely technical perimeter exploit.

Why This Matters

Identity recovery is an operational control, not a customer-service exception. Attackers who can persuade a help desk, contractor, or support team to reset access may inherit valid sessions, remote administration tools, SaaS access, and privileged workflows. The material cost then comes from containment, credential resets, service suspension, forensic review, customer remediation, and delayed operations.

How the Attack Can Unfold

  1. The attacker collects employee, contractor, and support-process details from public and breached sources.
  2. A help desk or support worker is pressured to reset a password, enroll a new factor, or approve remote access.
  3. The attacker uses valid credentials and approved tools to blend into normal authentication traffic.
  4. Privilege is expanded through remote support, SaaS administration, directory roles, or session theft.
  5. Data theft and service disruption force broad resets and system restrictions, increasing business loss.
CISO Questions
  • Can support staff enroll a new factor without a phishing-resistant proof?
  • Are privileged resets separated from ordinary password recovery?
  • Can all active sessions and recovery tokens be revoked quickly?
  • Has the business priced a multi-day identity shutdown?

MITRE ATT&CK Mapping

StageTechniqueRelevance
Initial AccessT1566 Phishing / T1078 Valid AccountsSocial engineering creates or restores valid identity access.
PersistenceT1098 Account ManipulationNew factors, recovery methods, or account changes can preserve access.
Lateral MovementT1219 Remote Access SoftwareApproved remote-support tools may be used after identity compromise.
ImpactT1489 Service StopContainment or attacker activity can interrupt customer and internal services.

Detection and Hunting Guidance

  • Correlate password resets and factor enrollment with new devices, unusual source networks, impossible travel, and immediate privileged activity.
  • Alert when a help-desk reset is followed by session creation, mailbox-rule changes, directory enumeration, or remote-support use.
  • Review support tickets for urgency language, bypassed verification, repeated calls, and requests involving executives or administrators.
  • Hunt for newly registered authentication methods and recovery contacts on privileged accounts.

Controls to Prioritize

  • Require phishing-resistant proof and supervisor approval for privileged resets or factor replacement.
  • Block support personnel from bypassing identity policy through undocumented exceptions.
  • Use device-bound credentials, short session lifetimes, and risk-based reauthentication for sensitive actions.
  • Exercise an enterprise-wide session and token revocation playbook.
 
Incident 2

Nintendo and TinyPulse Employee-Data Theft

Third-Party Workforce Data

Core Systems Safe, Employee Data Stolen

A workforce survey platform can hold identity, financial, and candid employee information outside the primary enterprise boundary.

What Happened

Nintendo of America confirmed that attackers stole internal employee-survey data from TinyPulse, a third-party service owned by WebMD Health Services. Nintendo said its own systems, customer data, and financial data were not affected. The extortion group claimed the stolen material included employee details, survey responses, bank statements, and W-9 forms. Those broader claims require confirmation, but the acknowledged theft is sufficient to trigger vendor, privacy, employee-protection, and retention reviews.

Why This Matters

Employee-experience systems often accumulate more sensitive content than their original purpose suggests. Survey text may reveal health concerns, manager disputes, organizational weaknesses, or personal circumstances. Identity and tax documents can support fraud and targeted social engineering. A vendor compromise can therefore create material harm even when customer-facing and internal production systems remain untouched.

How the Attack Can Unfold

  1. An attacker compromises a workforce SaaS account, vendor endpoint, integration credential, or administrative interface.
  2. Tenant data, attachments, exports, and historical records are enumerated.
  3. Bulk exports are staged through legitimate reporting or storage functions.
  4. Stolen employee details are used for extortion, fraud, or tailored phishing against staff and executives.
  5. Incomplete retention and logging make it difficult to establish the exact exposed population and data set.
Evidence to Request
  • Confirmed fields and affected employee population.
  • Access path, tenant logs, export logs, and retention history.
  • Credential, token, and integration rotation evidence.
  • Proof that stolen documents cannot enable account recovery or fraud.

MITRE ATT&CK Mapping

StageTechniqueRelevance
Initial AccessT1078 Valid AccountsCompromised SaaS or administrative credentials are a plausible access path pending vendor confirmation.
DiscoveryT1087 Account DiscoveryTenant users, roles, and accessible employee populations may be enumerated.
CollectionT1213 Data from Information RepositoriesSurvey systems and attachments act as sensitive information repositories.
ExfiltrationT1567 Exfiltration Over Web ServiceLegitimate export and cloud functions can facilitate data removal.

Detection and Hunting Guidance

  • Review SaaS audit logs for bulk exports, unusual report generation, new API clients, and access outside normal HR operating hours.
  • Correlate vendor logins with new devices, unfamiliar networks, impossible travel, and authentication-method changes.
  • Hunt internally for vendor credentials, API tokens, or exports stored in email, collaboration tools, endpoints, and shared drives.
  • Monitor targeted phishing and payroll-change attempts against affected employees.

Controls to Prioritize

  • Inventory data fields, attachments, integrations, subprocessors, and retention periods for every workforce-data vendor.
  • Require SSO, phishing-resistant MFA, role separation, export restrictions, and customer-accessible audit logs.
  • Remove historical records that no longer serve a defined legal or business purpose.
  • Pre-negotiate incident evidence, notification timelines, and employee-protection obligations.
 
Incident 3

Microsoft AutoJack Agent RCE Chain

Agent Control Plane

Untrusted Website, Trusted Local Command Path

Browser-capable agents need explicit security boundaries between web content, orchestration services, tools, and operating-system execution.

What Happened

Microsoft's Defender Security Research Team demonstrated a chain of three weaknesses in an early AutoGen Studio development build. An agent browsing a malicious website could be induced to cross the browser-to-localhost boundary and cause attacker-supplied code to execute through a locally reachable service. Microsoft fixed the weaknesses before they reached the official downloadable release, so this is not a current production exposure in AutoGen Studio. The design lesson applies broadly to agent tools that browse untrusted content while retaining access to local orchestration or execution services.

Why This Matters

Localhost is a network boundary, not an authentication decision. Agent frameworks frequently combine browsers, tool servers, API credentials, file access, shells, and local web interfaces. If untrusted content can influence requests to a command-capable local service, prompt injection becomes part of a conventional web and application exploit chain rather than only a model-behavior concern.

How the Attack Can Unfold

  1. An agent is directed to browse attacker-controlled or compromised web content.
  2. The content manipulates agent behavior or browser requests toward a loopback service.
  3. The local service accepts requests without strong authentication, origin validation, or action-level authorization.
  4. Attacker-controlled parameters reach a workflow, tool, or code-execution function.
  5. The payload runs with the permissions and credentials available to the agent host.
Architecture Rule

Do not infer trust from loopback addressing.

Authenticate every control channel, authorize every tool action, bind services narrowly, validate origins, and isolate browsing from execution.

MITRE ATT&CK Mapping

StageTechniqueRelevance
Initial AccessT1189 Drive-by CompromiseThe chain begins when the agent processes an attacker-controlled website.
ExecutionT1059 Command and Scripting InterpreterA command-capable tool or service can execute supplied payloads.
Defense EvasionT1218 System Binary Proxy ExecutionAgent tools may invoke trusted local runtimes or utilities.
Credential AccessT1552 Unsecured CredentialsHost execution can expose environment variables, config files, and connector secrets.

Detection and Hunting Guidance

  • Inventory loopback listeners associated with agent frameworks, browser helpers, developer tools, and local model services.
  • Alert on browser or agent processes connecting to unusual localhost ports followed by shell, interpreter, package-manager, or file-write activity.
  • Log tool calls with originating task, page, user, model, arguments, authorization result, and resulting process tree.
  • Hunt for local services bound beyond loopback, unauthenticated administrative routes, permissive cross-origin behavior, and reusable static tokens.

Controls to Prioritize

  • Separate browsing, planning, tool orchestration, and code execution into isolated security domains.
  • Require authenticated, short-lived, audience-bound sessions for local control APIs.
  • Use origin checks, request integrity, action allowlists, parameter validation, and explicit approval for dangerous tools.
  • Run agent hosts with minimal filesystem, network, credential, and operating-system privileges.
 
Cross-Incident Intelligence

The Control Pattern

Control DomainWhat Failed or Was StressedWhat Good Looks Like
Identity recoverySupport processes can convert persuasive claims into valid access.Phishing-resistant proof, dual control, high-risk reset telemetry, rapid session revocation.
Third-party data governanceSensitive employee data remained exposed outside core systems.Field-level inventory, retention limits, export controls, accessible audit evidence.
Agent architectureLocal network location was treated as implicit trust.Authenticated control planes, origin validation, isolation, action-level authorization.
Incident readinessUnclear blast radius increases containment cost and delay.Complete logs, named owners, tested revocation, predefined evidence requirements.
Action Plan

72-Hour CISO Actions

First 24 Hours

  • Pull all privileged password resets, factor changes, and recovery events from the last 30 days; investigate risky sequences.
  • Ask HR and procurement for every survey, engagement, payroll, benefits, and workforce-analytics vendor holding employee data.
  • Inventory agent and developer services listening on localhost or local networks, especially those with shell, file, browser, or connector access.
  • Confirm owners and kill switches for identity sessions, vendor integrations, and agent credentials.

24 to 72 Hours

  • Run a controlled help-desk social-engineering exercise against privileged recovery and remote-support paths.
  • Obtain field-level data, retention, tenant-log, and export-control evidence from high-risk workforce vendors.
  • Add authentication and authorization to command-capable local services; disable those that cannot meet the requirement.
  • Create detections linking identity resets to privileged activity and agent browsing to local process execution.

30 Days

  • Make privileged identity recovery a dual-control process with measurable exception rates.
  • Reduce workforce SaaS retention and prohibit unnecessary document attachments and broad exports.
  • Adopt an agent security architecture that separates untrusted content from execution and privileged connectors.
  • Model the business cost of identity shutdown, vendor data loss, and agent-host compromise in incident exercises.
Board Message

Material cyber loss increasingly begins in ordinary trust processes: account recovery, outsourced business applications, and automation tools.

The security program is verifying that these paths require strong proof, expose only necessary data and permissions, and can be contained with reliable evidence.

Metrics
  • Privileged recoveries with phishing-resistant proof.
  • Workforce vendors with field-level data and retention inventories.
  • High-risk SaaS tenants exporting complete audit logs.
  • Agent control services requiring authenticated requests.
  • Mean time to revoke sessions, integrations, and agent secrets.
Sources

Sources Reviewed

© 2026 CISO Platform. For more information, email contact@cisoplatform.com or visit cisoplatform.com.

Read more…