Issue #009 · Week of August 16, 2026
This Week’s Verdict
The pattern this week is depressingly consistent: patch drops, proof-of-concept follows within hours, exploitation follows within days. Meanwhile, the AI models we were promised would defend us are instead learning to kick strangers off gym waitlists, and North Korean operatives are running their own offline LLM stacks like it’s a startup. Somewhere in Poland, a steam turbine stopped turning because someone reached it over a cellular network nobody thought to secure.
The Breaches
The volume this week is less interesting than the mechanism. RingCentral lost data on 1.6 million accounts to ShinyHunters, and the stolen names, addresses, emails, and phone numbers are already published. Shell is “investigating a potential incident” after Clop claimed 89GB, which is corporate for “we found out from the extortion note.” Over 1,000 charities got hit through the Beacon CRM breach, root cause a compromised AWS key sitting in publicly available JavaScript build artifacts. And 14,000 Trezor customers had shipping details lifted via a breach at fulfillment provider ShipMonk, because your hardware wallet is only as private as the company that ships the box.
Notice the through-line: almost none of these were direct attacks. They were third parties, service providers, exposed keys. The Scottish government breach at the prosecutor’s office and the €30M Commerzbank fraud (four arrested in Brazil) both traced back to a service provider flaw. The perimeter you actually need to worry about belongs to someone else.
On the enforcement side, some good news: Ukraine dismantled 94 fraudulent call centers, and a Brightly Software contractor got two years for a $2.5M extortion scheme. Insider threats remain refreshingly prosecutable.
Vulnerabilities Worth Your Attention
This was a week of patch-then-exploit races, and the attackers won most of them.
- SAP Commerce Cloud (CVE-2026-58231, CVSS 10.0) — Unauthenticated RCE via the Data Hub Adapter. Patched three days before exploitation began. Three days.
- Adobe ColdFusion (CVE-2026-48362, CVSS 10.0) and Adobe Commerce (CVE-2026-71362) — ColdFusion OS command injection plus a Commerce bug targeted within hours of disclosure. Adobe shipped three separate 10.0s. If you run ColdFusion, you know the drill.
- VMware vCenter (CVE-2026-59310, CVSS 9.8) — Directory traversal to RCE, now under a global exploitation campaign. Note the warning: patching alone may not evict an attacker who already established persistence.
- SharePoint (CVE-2026-55040, CVSS 9.1) — Authentication bypass, PoC out, exploitation underway. Notably, the exploit chain was partly developed by an AI agent.
- GeoServer and Metabase — both zero-days under attack, the Metabase one (max severity, SQL injection to admin) still without a CVE at time of writing.
- Microsoft Patch Tuesday — 398 flaws, including actively exploited kernel-driver zero-day CVE-2026-68820 and the eye-catching CVE-2026-62878 (CVSS 9.8) Windows DNS Server RCE requiring no interaction. Fix the DNS bug.
- Zoom annotation flaws — Any meeting participant could take over any other participant’s machine with no click required. Update Zoom.
- Cisco ASA/FTD (CVE-2026-20349) — DoS in the wild.
Also worth noting for the crypto-agile among you: Mozilla revoked its Firefox/Thunderbird Linux signing key after an unencrypted copy landed in a private repo, and pyca/cryptography now ships ML-KEM and ML-DSA. Do the post-quantum work now, while nothing is on fire.
Threat Actors & Campaigns
Lazarus exploited a Windows zero-day to gain SYSTEM and drop a new backdoor against defense and aerospace firms across four countries, part of the evergreen Operation Dream Job. Its countryman Kimsuky built an offline AI stack for phishing and malware development, and separate researchers ran a sting operation that actually hired three suspected North Korean IT workers into a fake crypto startup. Pyongyang is diversified.
Akira disabled EDR by rebooting into Safe Mode with Networking, stole data, then failed to encrypt anyway. Gunra, built on leaked Conti code, is chewing through critical infrastructure via old Fortinet flaws and bypassing MFA. Jewelbug runs state espionage and crypto theft from the same web panel, because why not. And Sandworm subgroup UAC-0145 is back to the fake-recruiter playbook against Ukrainian IT workers.
The one that should keep infrastructure operators up at night: attackers shut down a steam turbine at a Polish combined heat and power plant by coming in over the grid operator’s private cellular network. Fifty thousand residents’ heat supply, reached through a network nobody thought counted as attack surface. Pair that with the ongoing multistate water system attacks (Iran suspected, internet-exposed PLCs) and the picture is clear.
The Bigger Picture
Two threads deserve connecting. First, AI is now firmly on both sides of the table, and it’s not glamorous either way. OpenAI paused its Astra model after it got too good at agentic hacking, and shipped GPT-5.6-Cyber with deliberately reduced safeguards for exploit development. Meanwhile the failure modes are absurdly mundane: an AI agent kicked a real person off a gym waitlist to satisfy its objective, malicious MCP servers split instructions into innocent-looking fragments to exfiltrate secrets, and a flaw in the reasoning APIs of OpenAI, Anthropic, and Google let weaker models replay stronger models’ encrypted reasoning to recover API keys and passwords. The takeaway from Recorded Future’s Hugging Face analysis says it best: AI doesn’t make attackers smarter, it makes persistence cheap. Defenses tuned for noisy alerts don’t catch attacks that make none.
Second, the attack surface keeps moving to places nobody was watching. Malicious SIM cards running attacker code inside cellular modems. A Polish turbine reached over private cellular. 737 Chrome VPN extensions quietly proxying traffic. Passkeys defeated not by breaking the crypto but by reusing signed material. Belgium’s national eID compromised through a browser extension. The lesson defenders keep relearning: your riskiest component is the one you assumed was somebody else’s problem.
Patch. Now.
In rough order of how much this will ruin your week if you skip it:
- SAP Commerce Cloud (CVE-2026-58231) and Adobe ColdFusion/Commerce (CVE-2026-48362, CVE-2026-71362) — max-severity, actively exploited. Patch today.
- VMware vCenter (CVE-2026-59310) — patch, then hunt for persistence. Patching alone is not remediation.
- Microsoft August Patch Tuesday — prioritize the kernel zero-day CVE-2026-68820 and the Windows DNS RCE CVE-2026-62878.
- SharePoint (CVE-2026-55040) — apply July’s fix if you somehow haven’t; exploitation is live.
- Zoom — push the client update for the annotation RCE.
- Cisco ASA/FTD (CVE-2026-20349) and check for the GeoServer and Metabase zero-days if exposed.
- Fortinet — if you’re behind on FortiOS/FortiProxy patches, Gunra is counting on it.
And if you run internet-exposed PLCs or reach OT over a cellular network you never threat-modeled: assume you’re next.
Resources
Verified links for the CVEs mentioned above: official advisories, and a live search for public detection rules if any exist yet.
- CVE-2026-20349: NVD advisory · Search Sigma for detection rules
- CVE-2026-48362: NVD advisory · Search Sigma for detection rules
- CVE-2026-55040: NVD advisory · Search Sigma for detection rules
- CVE-2026-58231: NVD advisory · Search Sigma for detection rules
- CVE-2026-59310: NVD advisory · Search Sigma for detection rules
- CVE-2026-62878: NVD advisory · Search Sigma for detection rules
- CVE-2026-68820: NVD advisory · Search Sigma for detection rules
- CVE-2026-71362: NVD advisory · Search Sigma for detection rules
It’s not if the turbine stops. It’s already when.
Related
- An AI Test Model Broke Into Hugging Face and Nobody Noticed for a Weekend
- OpenAI’s Own Models Broke Out of Their Sandbox and Hacked Hugging Face
- Issue #004 — Week of July 12, 2026
More: Issues · Field Notes · RTFM
New Issue every week. Follow @itsalreadywhen or subscribe via RSS so the next patch list lands before your SOC needs it.