News 2026-08-15
IAM & Security Weekly Briefing
Microsoft's August Patch Tuesday closed 398 flaws, including a Windows kernel driver zero-day (CVE-2026-68820) already exploited for SYSTEM compromise.
Open report
IAM & Security Weekly Briefing
Week of: 2026-08-09 to 2026-08-15 Reporting window: Most recently completed Sunday–Saturday (excludes the in-progress week).
1. Executive Summary (TL;DR)
- Microsoft's August Patch Tuesday closed 398 flaws, including a Windows kernel driver zero-day (CVE-2026-68820) already exploited for SYSTEM compromise.
- A CVSS 10.0 SAP Commerce Cloud flaw (CVE-2026-58231) that abuses a default authentication client is being actively exploited days after the patch.
- A publicly disclosed SharePoint authentication bypass (CVE-2026-55040) is now under attack following PoC release, with an AI-assisted exploit chain also disclosed.
- Ransomware and phishing operators are eroding MFA assurance: Gunra bypasses MFA on Fortinet devices, and the RecruitTrap campaign relays MFA prompts in real time.
- Identity remained the common thread — OAuth token theft, authenticated session hijacking, default-credential scanning, and stolen identities drove most incidents.
- AI introduced new identity risks: malicious MCP servers exfiltrated secrets from coding agents, and a reasoning-API flaw exposed API keys and passwords.
- Cyera's $1B Oasis Security acquisition signals a market shift toward converging data security and identity for AI agent control.
- Google Cloud published a post-quantum roadmap targeting 2029 readiness, pushing crypto agility onto the planning horizon.
2. Top IAM & Security News
Microsoft Patches 398 Flaws Including Actively Exploited Windows Kernel Driver Zero-Day
- Source: The Hacker News
- Link: The Hacker News
- Date: 2026-08-11
- What happened: Microsoft's August updates remediated 398 vulnerabilities, including CVE-2026-68820, a Windows kernel driver flaw already used by attackers to escalate to SYSTEM.
- Why it matters: An exploited privilege-escalation zero-day in a core Windows component makes this patch cycle urgent for all Windows fleets.
Max-Severity SAP Commerce Cloud Flaw Under Active Exploitation Days After Patch
- Source: The Hacker News
- Link: The Hacker News
- Date: 2026-08-15
- What happened: CVE-2026-58231 (CVSS 10.0), an unauthenticated RCE caused by insufficient authorization checks and abuse of a default authentication client, is being exploited in the wild.
- Why it matters: Organizations running SAP Commerce Cloud must assume the default authentication path can be abused and apply the patch or compensating controls immediately.
Attackers Exploit SharePoint Authentication Bypass After Public PoC Release
- Source: The Hacker News
- Link: The Hacker News
- Date: 2026-08-13
- What happened: CVE-2026-55040 (CVSS 9.1), a SharePoint security feature bypass rooted in weak authentication, is being exploited after PoC code was published; researchers also demonstrated an AI-assisted chain reaching unauthenticated RCE.
- Why it matters: SharePoint's broad enterprise reach means this authentication bypass can expose sensitive documents and enable lateral movement.
Global Exploitation of VMware vCenter Vulnerability Grants Persistent Remote Access
- Source: The Hacker News
- Link: The Hacker News
- Date: 2026-08-12
- What happened: Threat actors are actively exploiting CVE-2026-59310 (CVSS 9.8), a vCenter directory-traversal flaw allowing unauthenticated remote code execution.
- Why it matters: vCenter is a control point for virtualized infrastructure; compromise can lead to persistent access across the entire datacenter environment.
macOS Screen Sharing Authentication Bypass Exploited to Deploy Monero Miner
- Source: The Hacker News
- Link: The Hacker News
- Date: 2026-08-15
- What happened: CVE-2026-65400 (CVSS 9.8), an authentication flaw in macOS Screen Sharing, is being actively exploited on internet-exposed Macs after public exploit code emerged.
- Why it matters: An authentication bypass in a built-in remote-access service underscores the risk of internet-exposed management interfaces.
Gunra Ransomware Exploits Fortinet Flaws and Bypasses MFA
- Source: Dark Reading
- Link: Dark Reading
- Date: 2026-08-11
- What happened: The Gunra ransomware-as-a-service operation is breaching critical infrastructure by exploiting Fortinet FortiOS/FortiProxy flaws and bypassing MFA.
- Why it matters: VPN and firewall appliances are the perimeter identity boundary; MFA bypass here defeats a core Zero Trust control.
RingCentral Data Breach Likely Impacts 1.6 Million
- Source: SecurityWeek
- Link: SecurityWeek
- Date: 2026-08-14
- What happened: Hackers published allegedly stolen RingCentral data — including names, addresses, email addresses, and phone numbers — affecting an estimated 1.6 million people.
- Why it matters: Identity and contact data at this scale feeds phishing, SIM-swapping, and credential-stuffing campaigns.
France Investigates Tax Authority Breach After Stolen Identity Used
- Source: The Record
- Link: The Record
- Date: 2026-08-14
- What happened: Unauthorized access to France's DGFiP tax systems occurred in late June after the attacker stole or misused someone's identity; a hacker claims 600,000 victims.
- Why it matters: A government breach built on a single stolen identity shows how identity compromise can cascade into mass exposure of citizen data.
3. AI, Identity & Emerging Tech
Reasoning-API Flaw Lets Weaker AI Models Recover Secrets From OpenAI, Anthropic, and Google
- Source: The Hacker News
- Link: The Hacker News
- Date: 2026-08-12
- What happened: Researchers recovered internal reasoning and secrets — including API keys and passwords — from session logs by replaying encrypted reasoning objects between API sessions.
- Why it matters: AI reasoning sessions must be treated as sensitive identity and secret stores; session isolation and log hygiene are now security controls.
Malicious MCP Servers Split Instructions to Steal Secrets From AI Coding Agents
- Source: The Hacker News
- Link: The Hacker News
- Date: 2026-08-11
- What happened: A malicious tool server connected to an AI coding assistant can exfiltrate SSH keys, environment secrets, source code, and customer data by splitting the theft into seemingly routine requests.
- Why it matters: MCP servers are effectively new privileged identities; organizations must inventory, trust-scope, and apply least privilege to them like any other service account.
'GhostJacking' Highlights Identity Governance Gaps in AI Agents
- Source: Dark Reading
- Link: Dark Reading
- Date: 2026-08-10
- What happened: New research shows attackers can use security alerts and blocked events to manipulate and hijack AI agents.
- Why it matters: AI agents need identity governance, session integrity, and least privilege just like human users and service accounts.
Kimsuky Builds Offline AI Stack to Boost Phishing and Automate Malware Development
- Source: The Hacker News
- Link: The Hacker News
- Date: 2026-08-10
- What happened: North Korea's Kimsuky group is running AI on its own servers, connecting document-search tools to files in its possession, and assembling components to build AI into malware.
- Why it matters: Nation-state adversaries are operationalizing AI for phishing and malware production, raising the bar for email and identity defenses.
NIST Looks to AI to Manage the AI-Driven Vulnerability Surge
- Source: Dark Reading
- Link: Dark Reading
- Date: 2026-08-14
- What happened: Vulnerability volumes continue to surge due to AI-augmented research and scanning, prompting NIST to explore AI-based mitigation.
- Why it matters: AI is accelerating both vulnerability discovery and remediation pressure; security teams should expect faster exploit timelines for identity-adjacent flaws.
4. Cyber Threats & Attack Trends
RecruitTrap Campaign Uses Browser-in-the-Browser and Real-Time MFA Relay
- Source: The Hacker News
- Link: The Hacker News
- Date: 2026-08-14
- What happened: A global recruitment-themed campaign with over 3,000 phishing URLs uses fake interview pages and Browser-in-the-Browser (BitB) windows to steal Google/Facebook credentials and relay MFA prompts in real time.
- Why it matters: Job-themed lures combined with live MFA relay defeat both user awareness and standard one-time-code MFA.
Chrome DevTools Technique Enables Authenticated Session Hijacking on Windows
- Source: The Hacker News
- Link: The Hacker News
- Date: 2026-08-14
- What happened: Researchers detailed a post-exploitation method that enables the Chrome DevTools Protocol inside running Chrome/Edge processes on Windows to access cookies, saved data, and authenticated browser sessions.
- Why it matters: Authenticated browser sessions are high-value targets; endpoint controls and browser session hardening are needed to protect them.
Long-Running 'City-Forum' Campaign Targets Salesforce and ServiceNow Tenants
- Source: Dark Reading
- Link: Dark Reading
- Date: 2026-08-12
- What happened: A data-theft campaign active since at least March 2025 uses custom tooling to target Salesforce and ServiceNow across multiple sectors.
- Why it matters: SaaS identity planes hold crown-jewel data; organizations must audit OAuth grants, API tokens, and privileged roles in these platforms.
WindRelay Android Malware Turns Phones Into NFC Relays for Payment Fraud
- Source: The Hacker News
- Link: The Hacker News
- Date: 2026-08-13
- What happened: WindRelay, deployed alongside the SpyNote RAT, captures live card data via NFC and transmits it to fraudsters in real time for contactless payment fraud.
- Why it matters: Mobile device compromise now bypasses physical card-present controls, adding urgency to device trust and fraud detection.
New Mirai Variant Adds Credential Sniffing for Default Access Credentials
- Source: The Record
- Link: The Record
- Date: 2026-08-13
- What happened: A new Mirai-based variant features encrypted command-and-control communications and a sniffer that looks for default access credentials on internet-facing devices.
- Why it matters: Default-credential scanning remains a reliable botnet technique; eliminating default credentials on edge and IoT devices is a basic but critical control.
Google Workspace Attack Chain Rethought Around Stolen OAuth Tokens
- Source: BleepingComputer
- Link: BleepingComputer
- Date: 2026-08-14
- What happened: Material Security highlights that Google Workspace attacks do not always begin with phishing — stolen OAuth tokens provide a path into Gmail, Drive, and connected systems.
- Why it matters: Token theft defeats password-based controls; session and token risk monitoring must cover the entire Workspace ecosystem.
5. Product Updates & Vendor News
Cyera to Acquire Oasis Security in $1B Move Toward AI Agent Control
- Source: Dark Reading
- Link: Dark Reading
- Date: 2026-08-14
- What happened: Cyera's acquisition of Oasis Security aims to converge data security and identity into a single control plane for agents, redefining privileged access around business context rather than static roles.
- Why it matters: This signals a market shift toward identity-aware data security designed for AI and non-human identities.
OpenAI Launches GPT-5.6-Cyber for Vulnerability Research and Exploit Development
- Source: The Hacker News
- Link: The Hacker News
- Date: 2026-08-11
- What happened: OpenAI unveiled GPT-5.6-Cyber, a cybersecurity-focused model trained for vulnerability research, penetration testing, and incident response with reduced refusals for higher-risk tasks.
- Why it matters: Cyber-specific AI models will change both offensive and defensive workflows; security teams must define acceptable-use and oversight policies.
Google Cloud Sets Post-Quantum Cryptography Roadmap With 2029 Readiness Goal
- Source: SecurityWeek
- Link: SecurityWeek
- Date: 2026-08-14
- What happened: Google Cloud outlined a roadmap to full post-quantum cryptography readiness, with key milestones targeted for 2027 and 2028.
- Why it matters: Identity and authentication systems must begin crypto-agility assessments now to meet post-quantum timelines without breaking trust infrastructure.
Mozilla Revokes Firefox and Thunderbird Linux Signing Key After Accidental Exposure
- Source: The Hacker News
- Link: The Hacker News
- Date: 2026-08-11
- What happened: Mozilla revoked the key that signs Firefox and Thunderbird Linux downloads after an unencrypted copy was committed by mistake to a private repository.
- Why it matters: Signing-key exposure has direct supply-chain and trust implications for software distribution; rotate keys proactively on any suspected leak.
Anthropic Details Plans to Watermark Claude's AI-Generated Text
- Source: BleepingComputer
- Link: BleepingComputer
- Date: 2026-08-14
- What happened: Anthropic outlined how it plans to watermark AI-generated text from Claude to make AI-generated content easier to identify.
- Why it matters: Content provenance is becoming a security feature as AI-generated phishing and disinformation scale.
6. Practical Security Takeaways
- Patch the actively exploited set first: CVE-2026-68820 (Windows kernel driver), CVE-2026-55040 (SharePoint), CVE-2026-58231 (SAP Commerce Cloud), CVE-2026-59310 (VMware vCenter), and CVE-2026-65400 (macOS Screen Sharing).
- Treat legacy OTP/factor MFA as insufficient — real-time MFA relay (RecruitTrap) and MFA bypass on VPN appliances (Gunra) were both observed; begin migrating to phishing-resistant credentials such as passkeys/FIDO2.
- Audit OAuth grants, API tokens, and privileged roles in Google Workspace, Salesforce, and ServiceNow; revoke unused or overprivileged tokens and monitor for abnormal token use.
- Harden and segment internet-exposed edge devices: disable default credentials, patch Fortinet/Cisco/vCenter appliances, and monitor management-plane access.
- Inventory non-human identities (NHIs) and AI agent integrations such as MCP servers; apply least privilege and secrets-management controls, and rotate cloud/SSH/Kubernetes credentials where exposure is suspected.
- Add identity verification, document forensics, and credential checks to remote hiring workflows to counter North Korean IT worker infiltration.
- Restrict and continuously audit browser extensions — 737 malicious VPN/proxy extensions and the Belgium eID extension compromise show the risk extensions pose to authentication.
- Shift from periodic access reviews to continuous, evidence-backed IAM compliance verification.
- Begin post-quantum crypto-agility assessments for identity and PKI infrastructure, aligned to Google Cloud's 2029 readiness target.
- Validate software signing keys and supply-chain integrity; any suspected key exposure should trigger immediate revocation and re-signing (see Mozilla and BdThemes cases).
7. Trends to Watch
- Real-time MFA relay and bypass are eroding legacy MFA assurance, pushing phishing-resistant credentials toward baseline status.
- AI agents, MCP servers, and other non-human identities are emerging as a new identity class requiring governance, secrets management, and least privilege.
- Exploit-to-attack timelines are collapsing to days after patch or PoC release, making continuous patch prioritization by attack chain critical.
- Data security and identity are converging into unified control planes for AI agent governance, as signaled by the Cyera–Oasis deal.
- Nation-states are industrializing AI for espionage and malware while vendors ship cyber-specific AI models — expect AI-versus-AI defenses to become table stakes.
Sources
- Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack — https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html
- SAP Commerce Cloud CVE-2026-58231 Targeted in Exploitation Attempts Days After Patch — https://thehackernews.com/2026/08/sap-commerce-cloud-cve-2026-58231.html
- Attackers Exploit SharePoint Authentication Bypass After Public PoC Release — https://thehackernews.com/2026/08/attackers-exploit-sharepoint.html
- Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access — https://thehackernews.com/2026/08/attackers-exploit-vmware-vcenter.html
- Apple macOS Screen Sharing Flaw Exploited on Internet-Exposed Macs to Install Monero Miner — https://thehackernews.com/2026/08/apple-macos-screen-sharing-flaw.html
- Gunra Ransomware Gang Exploits Fortinet Flaws, Bypasses MFA — https://www.darkreading.com/cyberattacks-data-breaches/gunra-ransomware-gang-fortinet-flaws-bypasses-mfa
- 1.6 Million Likely Impacted by RingCentral Data Breach — https://www.securityweek.com/1-6-million-likely-impacted-by-ringcentral-data-breach/
- France investigates tax authority breach after hacker claims 600,000 victims — https://therecord.media/french-tax-authority-dgfip-confirms-data-breach
- OpenAI, Anthropic, Google API Flaw Let Weaker AI Models Decode Stronger Models' Reasoning — https://thehackernews.com/2026/08/openai-anthropic-google-api-flaw-let.html
- Malicious MCP Servers Can Split Instructions to Make AI Coding Agents Exfiltrate Secrets — https://thehackernews.com/2026/08/malicious-mcp-servers-can-split.html
- 'GhostJacking' Exposes Identity Governance Gaps in AI Agents — https://www.darkreading.com/cyber-risk/ghostjacking-identity-governance-gaps-ai-agents
- Kimsuky Builds Offline AI Stack to Boost Phishing and Automate Malware Development — https://thehackernews.com/2026/08/kimsuky-builds-offline-ai-stack-that.html
- Amid AI-Driven Bug-Hunt Tsunami, NIST Looks to … AI — https://www.darkreading.com/vulnerabilities-threats/ai-driven-bug-tsunami-nist-looks-to-ai
- CTM360 Uncovers Over 3,000 Recruitment Phishing URLs Using Browser-in-the-Browser (BitB) Credential Traps — https://thehackernews.com/2026/08/ctm360-uncovers-over-3000-recruitment.html
- Chrome DevTools Technique Enables Authenticated Session Hijacking in Live Windows Browsers — https://thehackernews.com/2026/08/chrome-devtools-technique-enables.html
- Long-running Data Theft Campaign Targeting Salesforce, ServiceNow — https://www.darkreading.com/cyberattacks-data-breaches/long-running-data-theft-campaign-salesforce-servicenow
- WindRelay Android Malware Turns Victims' Phones Into NFC Relays for Payment Fraud — https://thehackernews.com/2026/08/windrelay-android-malware-turns-victims.html
- New Mirai variant adds stealth capabilities to notorious botnet code — https://therecord.media/new-mirai-variant-adds-stealth-to-botnet-code
- The Modern Attack Chain: Rethinking Google Workspace Security in the Age of AI — https://www.bleepingcomputer.com/news/security/the-modern-attack-chain-rethinking-google-workspace-security-in-the-age-of-ai/
- Cyera's Oasis Security Buy Is All About AI Agent Control — https://www.darkreading.com/identity-access-management-security/cyera-oasis-security-acquisition-ai-agent-control
- OpenAI Launches GPT-5.6-Cyber with Reduced Safeguards for Exploit Development — https://thehackernews.com/2026/08/openai-launches-gpt-56-cyber-with.html
- Google Cloud Sets Out Post-Quantum Roadmap With 2029 Readiness Goal — https://www.securityweek.com/google-cloud-sets-out-post-quantum-roadmap-with-2029-readiness-goal/
- Mozilla Revokes Firefox and Thunderbird Linux Signing Key After Key Lands in Private Repo — https://thehackernews.com/2026/08/mozilla-revokes-firefox-and-thunderbird.html
- How Anthropic plans to watermark Claude's AI-generated text — https://www.bleepingcomputer.com/news/artificial-intelligence/how-anthropic-plans-to-watermark-claudes-ai-generated-text/
- Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations — https://thehackernews.com/2026/08/malicious-litellm-releases-tied-to.html
- IAM Compliance Requirements and Best Practices — https://thehackernews.com/2026/08/iam-compliance-requirements-and-best.html
- North Korean Remote Workers Are Infiltrating Government and Businesses: How to Expose Them Before Hiring — https://thehackernews.com/2026/08/north-korean-remote-workers-are.html
- 737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One — https://thehackernews.com/2026/08/737-chrome-vpn-extensions-caught.html
- Belgium's eID Authentication Opens Citizen Accounts to RCE — https://www.darkreading.com/application-security/belgium-eid-authentication-citizen-accounts-rce
- BdThemes Supply Chain Attack Poisons JSON to Create Rogue WordPress Admins — https://thehackernews.com/2026/08/bdthemes-supply-chain-attack-poisons.html
More from News
AI Model & Benchmark Watch — August 21, 2026
2026-08-21
AI Projects - August 21, 2026
2026-08-21
AI Tool Updates - August 21, 2026
2026-08-21
General AI News - August 21, 2026
2026-08-21
MCP Protocol News - August 21, 2026
2026-08-21
Science & Space Digest — Aug 21, 2026
2026-08-21
🏛️ Tech Policy & Regulation Watch
2026-08-20
🔬 Emerging Technology Watch
2026-08-20
⚡ Energy Industry Briefing
2026-08-19
🎬 Media & Creator Economy Watch
2026-08-18
🎬 Media & Creator Economy Watch
2026-08-17
🌍 World & Geopolitics Briefing
2026-08-15