CyberWire Daily - A flurry of fixes.
Episode Date: August 12, 2026We got your Patch Tuesday notes. Attackers target Microsoft SharePoint vulnerability following PoC release. Cyberattack on CEVA Logistics causes ongoing supply chain disruptions. Wesco confirms data b...reach following extortion claims. Akira ransomware bypasses EDR in Safe Mode. California announces AI cybersecurity fund. N2K’s Lead Analyst Ethan Cook shares about cyber weapons for space. Dave Bittner sits down with Michael Leland, VP and Field CTO at Island, at Black Hat USA to discuss the growing risks of the AI supply chain. And fasten your seatbelts and ignore the fake Wi-Fi. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn. CyberWire Guest On today’s Industry Voices, Dave Bittner sits down with Michael Leland, VP and Field CTO at Island, at Black Hat USA to discuss the growing risks of the AI supply chain, including AgentBaiting, where fake AI Skills and MCP servers were used to deliver malware, and hidden instructions that can influence AI agents. If you enjoyed the conversation, be sure to check out the full interview here. Selected Reading Microsoft and Adobe Patch Tuesday, August 2026 Security Update Review (Qualys) Shattering the Dream - When a Job Offer Becomes a Zero-Day Attack (Check Point Research) Patch Tuesday August 2026: A zero-day WinSock driver hole under exploit, and a maximum severity SAP vulnerability CSO Online ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Phoenix Contact (SecurityWeek) Hackers leverage new Microsoft SharePoint exploit in attacks (BleepingComputer) The CEVA Logistics data breach is having major knock-on effects across Europe - here's what we know (TechRadar) Wesco confirms security incident after ExfilSquad claims data theft (BleepingComputer) Akira Hits Safe Mode: Ransomware Rebooting Around EDR (Huntress) California Building ‘AI Cyber Defense Fund’ to Protect Critical Infrastructure From Hackers (Gizmodo) Laser weapons for space? US officials see threat, opportunity (BREAKING DEFENSE) DEF CON dingus suspected of trying to take over Delta in-flight Wi-Fi (The Register) Share your feedback. What do you think about CyberWire Daily? Please take a few minutes to share your thoughts with us by completing our brief listener survey. Thank you for helping us continue to improve our show. Want to hear your company in the show? N2K CyberWire helps you reach the industry’s most influential leaders and operators, while building visibility, authority, and connectivity across the cybersecurity community. Learn more at sponsor.thecyberwire.com. The CyberWire is a production of N2K Networks, your source for strategic workforce intelligence. © N2K Networks, Inc.
Transcript
Discussion (0)
You're listening to the Cyberwire Network, powered by N2K.
Maybe that's an urgent email from your CEO, or maybe it's a deep fake targeting your business.
Dopple is the AI-native social engineering defense platform fighting back against impersonation and manipulation.
As attackers use AI to make their tactics more sophisticated,
Dopple uses it to fight back, automatically dismantling cross-channel attacks,
building team resilience and providing agentic email protection.
Dopple, outpacing what's next in social engineering.
Learn more at doppel.com.
That's do p-p-p-el.com.
We've got your patch Tuesday notes.
Attackers target Microsoft SharePoint vulnerability while following POC release.
Cyber attack on CIVA logistics causes ongoing supply chain disruptions.
Wesco confirms data breach following extortion claims.
Acura ransomware bypasses EDR in safe mode.
California announces AI cybersecurity fund.
And 2K's lead analyst Ethan Cook shares more about cyber weapons for space.
Dave Bittner sits down with Michael Leland, VP and Field CTO at Island at Black Hat USA,
to discuss the growing risks of the AI supply chain and fasten your seatbelts and ignore the fake Wi-Fi.
Today is Wednesday, August 12, 26.
I'm Maria Varmazes, and this is your Cyberwire Intel Briefing.
Thank you for joining me today. Let's get started.
Microsoft's Patch Tuesday addressed a total of 421 vulnerabilities across its products,
including Windows, HyperV, Microsoft Exchange Server, and Azure.
Of these, 62 are rated critical, and 357 are marked as important,
with the most significant being three zero-day vulnerabilities.
The zero days include a tampering flaw in the Windows container isolation FS filter driver,
an elevation of privilege bug in the Windows user profile service,
and an actively exploited privilege escalation flaw in the Windows ancillary function driver for Winsock.
SISA has added the latter flaw to its known exploited vulnerabilities catalog
and ordered federal agencies to apply patches by August 25th.
Checkpoint has attributed the exploitation to North Korea's Lazarus Group
in a campaign targeting the defense sector in Europe and India.
Adobe addressed 51 vulnerabilities across five of its products,
Adobe Cold Fusion, Adobe Commerce, Adobe Lightroom Classic,
content credentials SDK, and Adobe Campaign Classic.
Of these 33 vulnerabilities are classified as critical.
SAP fixed 29 vulnerabilities led by a maximum severity flaw
in SAP Commerce Cloud's Data Hub adapter.
This improper authorization is,
issue allowed unauthenticated remote attackers to submit crafted data, potentially leading
to arbitrary code execution.
In the ICS space, Siemens, Schneider, Electric, and Phoenix Contact released patches for various
products, and Sissup-published advisories covering vulnerabilities and products from other
vendors, including Pulsetto and Johnson controls.
Notably, Siemens issued a fix for a maximum severity missing authentication flaw in its
somatic IoT gateways.
Threat actors have already started weaponizing a proof-of-concept exploit for a critical Microsoft
SharePoint flaw that was published by Rapid 7 yesterday. The flaw is an authentication bypass
vulnerability that affects the JWT token validation pipeline in SharePoint Enterprise Server
2016 and 2019. It allows attackers without privileges to impersonate users or administrators to
disclose files and modify data.
Microsoft issued a patch for the flaw on July 14th following a responsible disclosure by Rapid 7.
Administrators who haven't already applied patches are urged to do so promptly.
A cyber attack at shipping giant Siva logistics is continuing to cause significant disruptions for its clients across Europe.
The attack, which likely began on July 29, 26, affected at least eight warehouses.
And while the full extent of the breach has not been disclosed, affected clients' reports,
that customer names, contact details, and delivery information may have been compromised.
Dutch retailers' Bull and DeBan Corp, along with Gaming Giant Valve, have disclosed that they were
impacted.
Global supply chain and distribution giant Wesco has confirmed a cybersecurity incident involving
its cloud CRM environment after the Data Extortion Group, Exfil Squad, claimed credit for the attack.
X-FELS squad says that it stole and leaked 2.6 million records containing customer and employee data.
Wesco asserts that there has been no business disruption or evidence of ransomware
and believes sensitive data like payment cards or financial accounts are not at risk.
Details of the attack are still unclear, but bleeping computer notes that XFEL squad has in the past
targeted improperly configured Microsoft PowerPages data tables.
Huntress has published a report
on an attack by an Akira ransomware affiliate in which the attackers rebooted a compromised host
into safe mode with networking to bypass EDR tools. After gaining initial access through an exposed
Sonic Wall VPN without multi-factor authentication, the attacker enumerated active directory
and exfiltrated sensitive data. By forcing the reboot into safe mode, the attacker intended
to freely execute the ransomware. However, the stripped-down memory environment,
of safe mode, ironically, caused the Akira process to crash from an out-of-virtual memory error,
preventing encryption. Unfortunately, the prior data theft still left the victim vulnerable to extortion.
The state of California is launching an AI cyber defense program to protect its critical infrastructure
after recent incidents revealed AI systems from major tech companies autonomously hacking into third-party
organizations. The initiative will use.
use AI tools to rapidly identify and patch security vulnerabilities supervised by newly appointed
AI cybersecurity officers across state agencies. Governor Gavin Newsom said that the state's approach
serves as a direct response to the Trump administration's proposed $707 million budget cuts
to the cybersecurity and infrastructure security agency for the 27 fiscal year.
And on Wednesdays, we take a look at what's going on in the world of space.
cyber. And this week, we'll hear from T-minus space cyber briefing producer Ethan Cook on the U.S.
military setting its sights on advanced cyber weaponry to take down satellite constellations.
Over to you, Ethan. On Tuesday, the U.S. held its annual Army Space and Missile Defense Symposium.
At the event, Lieutenant Colonel Rick Zellman, deputy commander of U.S. Space Command,
at said adversaries are unlikely to try and take thousands of satellites offline using an
anti-satellite weapon. Instead, they could target people and compromise the nodes that
provide one to many services. Zellman noted that these threats include cyber and directed energy weapons,
with attacks often focused on the ground systems supporting satellite networks.
Given the potential of these weapons as both threats and tools for the U.S. military,
officials are considering directed energy and other capabilities as potential counterspace weapons
while also exploring ways to diversify ground infrastructure.
For the T-minus space cyber briefing, this is producer Ethan Cook. Back to you, Maria.
Thank you, Ethan.
Stick with us after the break now.
As Michael Leland, VP and Field CTO at Island, sits down with Dave Bittner at Black Hat USA to discuss the growing risks of the AI supply chain.
And fasten your seatbelt, everybody, and ignore the fake Wi-Fi.
Stay with us.
AI is making fishing attacks faster, more convincing, and harder for people to spot.
And traditional security awareness and fishing training weren't designed for this level of.
attack. Hoxhunt helps security teams prepare employees for the attacks they face every day,
with personalized fishing training that adapts to each employee and reduces risky behavior over
time. For IT and security leaders looking to strengthen their human layer of defense, without
adding more manual work, visit hoxhunt.com slash cyberwire to learn more. That's H-O-X-H-U-N-T dot com slash
cyberwire.
On our industry voices segment today, Dave Bittner sits down with Michael Leland,
who is the vice president and field CTO at Island at Black Hat USA to discuss the growing risks of the AI supply chain,
including agent baiting, where fake AI skills and MCP servers were used to deliver malware
and hidden instructions that can influence AI agents.
Here's their conversation.
We know AI is already trying to find a way around it.
Humans do the same thing.
If you tell them they can't use a tool, they'll find out.
find a plugin that uses the tool behind the scenes. If you tell them they're not allowed to use
their personal AI, they'll load a new browser and try logging in from there. So one of the
best things is visibility first, analytic second, and then governance. But I think adoption has
so quickly outpaced governance in the AI world that many of us are trying to play catch up.
And we are continuing our conversations here at Black Hat 2026. And joining me is Michael Leland,
He is field CTO at Ireland.
Michael, thanks for joining us.
Thanks for having me.
So we are digging into supply chain issues with AI today.
Can we start with just some foundational types of things
for folks who may not be living in that world every day?
What are the specific things that you all have your eye on?
So we architected something that we like to call the agentic control plane.
And I think that's an important conversation we're doing with supply chain.
First of all, AI is coming at us in so many different modalities, right?
Generative AI via chat interfaces in the browser, via desktop applications.
We've got ClaudeCode and Co-Work, Codex, various AI plug-ins to your IDs.
And the way most people would think about handling both visibility and inspection is waiting
until all that traffic hits the network, right?
A Sassie vendor might funnel it all through a pop where they're going to try to do break and inspect.
right? That's been great for years.
But AI has changed that architecture.
AI is now being used by users on the desktop
and by applications that we never even imagined a year ago.
Claude Co-Work has just as much access
to the local file system data as it does to a cloud tenant.
And so when you think about supply chain,
the first thing you get to think about is where are these agents
getting their skills?
Where are they getting their packages?
and more importantly, is there a spot where you can provide both visibility and enforcement at runtime?
And for most organizations, they've got a slew of tech that they've invested in of the course of the last decade or more.
On the end point, they've got EDR and the cloud they've got Sassy.
They may have Casby or ASPMs.
Each of those do a great job in their swim lane, but all of them have blind spots to all the various points that users are now interacting with AI.
I saw last week, Claude, it's co-work actually.
It got stuck.
It couldn't do what I asked it to do.
And so it decided the best course of action was to write a Python script
that would then go out and pull an NPM package from a source that I didn't authorize.
We saw, you know, just this past week with things like sandbox escapes from the various AI providers.
If you set AI to a goal, it will find any way possible to get there.
not always by means that we've authorized
and certainly not staying in their swim lanes.
So what are you all proposing, then,
as a solution to that reality?
So because of the multiple modalities of AI,
we need to have as many control points as possible.
Island is an architected a solution
with about nine different control points.
Okay.
We started off building a browser six years ago,
and that handles all user interactions
with AI and SaaS applications
via a web.
We then decided that our customers
aren't always going to use our browser.
They might still use their own,
so that same functionality has to exist
as an extension into an existing
consumer browser.
But about three years ago,
our customers told us,
what about my thick apps?
And what they meant three years ago
was Word, Outlook,
Visual Studio.
Right.
Most of those apps have long gone
to the cloud, right?
The great SaaSification of the desktop apps.
But in the last nine months to 12 months,
AI has dragged us back
in the other direction away from SaaSification, because now these desktop apps have to be in scope as well.
So in addition to the browser and the extension, we introduce a desktop component that sits
outside the browser as an enforcement point for all Thick app and AI activity.
We also introduced a network component, where the Sassie vendors started by building large cloud
infrastructures and then pushing out to the edge. That relied on break and inspect in the middle at
these juncture points where all of my traffic funnels through a proxy.
Sure. It creates a poor user experience, and as we're getting closer to post-quadum encryption, and with certificate pinning, a lot of traffic can no longer be inspected in the cloud. So that last access point that we added, so browser, extension, desktop, and network. Those were the four. But in the next three months, we'll be introducing an MCP gateway, which allows you to do things like token brokering in the middle. That means that if an agent needs to access an application via an AWOTH token, you'll be introducing an MCP gateway, which allows you to do things like token, which allows you to do things like token,
don't give the agent the actual Oath token to the app, you give them a temporary one issued by
an AHA, a non-human identity, right? That means you can then also pass off various restricted
privileges to that. If the agent specifically asks for, let's say, read-write privilege to
Salesforce, and I say, you know what, I'm only going to grant you read-only privilege to Salesforce.
I can now do that in the token swap. Then we use something called the compliance API frameworks.
Every AI vendor delivers a set of APIs that they call the compliance APIs.
That's how a desktop application like Island Desktop can hook into those applications
and provide the same level of visibility and enforcement as well as a runtime policy.
And then lastly, LLM Gateway integrations are pretty common these days,
but we also fully support what's called the Open Telemetry Platform, the O'Tel standard.
O'Tel allows us to connect to the major AI providers and collect
telemetry and statistics about things like token utilization and cost per user, per session, per skill.
Performance metrics about how the AI is performing. What's the time to first token, time to last token.
And then more importantly, AI adoption strategies. All of that has to align to the same data restriction or data protection policy that you've built for the enterprise,
because the biggest gap people have right now is Shadow AI and AI governance.
How do you balance that visibility without overloading the team with information?
It's a great question.
We are generating more telemetry now than we ever have,
and once we start seeing agentic transactions,
generating telemetry at machine speed,
we'll probably hit a thousand to one ratio of human or agentic telemetry
to human telemetry,
which means you've got to think differently about the way that telemetry is
both being collected and analyzed.
The only way to analyze AI-generated telemetry is with AI.
So if we collect a million events,
we need to summarize those using an analytic engine
that describes exactly what those events mean.
This user tried copying sensitive data into this model.
This user has an excessive use of AI token usage this week, right?
And a human's not going to be able to catch those things.
But AI does a really good job of summarization.
And so we generate what's called an insight from those.
So you're going to see a lot more of that consolidated effort of providing this analytic engine on top of AI utilization.
I'm curious, do you have any specific examples of use cases or folks that you've worked with to try to get through some of these issues together?
Yeah, one of the best examples that I've used a few times anecdotally, because it actually happened from a customer.
We had a customer trying to solve their shadow AI problem.
And they insisted.
They only had eight sanctioned AI applications in use.
We did an assessment.
Some users had the full browser.
Many of the other users just had the island extension.
We found 243 AI applications.
Wow.
So I think it proves that if you put a roadblock in front of customers or users and say a hard no,
they're going to say, I'll find a way around it.
We know AI is already trying to find a way around.
it, humans do the same thing. If you tell them they can't use a tool, they'll find a
plug-in that uses the tool behind the scenes. If you tell them they're not allowed to use their
personal AI, they'll load a new browser and try logging in from there. So one of the best
things is visibility first, analytics second, and then governance. But I think adoption has so
quickly outpaced governance in the AI world that many of us are trying to play catch-up.
Many customers, you know, the analogy if you can't put the toothpaste back in the tube,
the toothpaste is out.
That's all over the counter.
That's right.
Well, so what's your advice to folks who feel like they're playing a game of ketchup now?
You know, their employees are doing the things they need to do to get their jobs done.
How do you find equilibrium?
So there's a really interesting dichotomy between the fact that the executives and the board are telling people,
thou must use AI.
Right, because it's going to improve our productivity,
it's going to help our innovation.
It'll help us streamline our operations.
But then you get the legal team and the compliance team saying,
be carefully using AI.
And so the user's caught in the middle of should I or shouldn't I?
As we look towards the horizon,
let's say over the next year or so,
what does success look like to you?
What does it look like when folks are using these tools
in the proper way?
seeing good results. So I think success is really two things. One, it's giving your users the
trust and confidence to use AI to fit their outcome needs. And the trust piece is, I don't worry
when that new button pops up in my SaaS application, because my organization has built a guardrailed
policy that if that button were dangerous, it wouldn't be there. Or if it's there, it's not going to
let me put sensitive data into it. I have to stop making the end-user.
second-guess what their AI usage should be
in terms of utilizing these tools.
Because if you leave it up to the user,
there's two camps.
I'm not going to touch it because I don't want the legal
ramifications or the government dribble.
Exactly.
Or, you know, the other ones that are just going to go
full force into AI and risks be damned, right?
Right.
So I think instilling a sense of confidence
and trust in the user population
that the guardrails are in place,
that even if they make a mistake,
they can't put sensitive data at risk.
Michael Leeland is FieldCTO at Island.
Michael, thanks so much for joining us.
Thanks for having me.
That was Dave Bittner,
sitting down with Michael Leeland,
VP and Field CTO at Island,
discussing the growing risks of the AI supply chain.
And if you enjoyed this conversation
and want to learn more about it,
make sure to check out the links in our show notes.
What's the one thing in business
that's spreading as fast as AI?
AI risk.
Every new tool your team signs up for,
every vendor that turns on AI features,
every new integration,
each one is another opportunity for something to go wrong.
And most security programs weren't built
to keep up with AI's pace of growth.
Enter Vanta.
Vanta is the number one agentic trust platform,
trusted by more than 16,000 fast-moving companies
like Ramp, Hurser, and Harvey
to help them stay audit-ready.
And now Vanta helps companies like yours keep an eye on the risks that appear between audits across your vendors, your AI tools, and your entire environment.
The Vanta agent works like a 24-7 GRC engineer in the background.
It finds issues, drafts fixes for you, and can cut vendor assessment time by up to 50%.
Whether you're a fast-growing startup or a global enterprise, Vanta is here to help you automate your security and compliance and earn,
and prove trust.
It started today at vanta.com slash cyber.
That's v-a-t-a-com slash cyber.
And lastly, a Defcon attendee is suspected of jamming the in-flight
Wi-Fi on a Delta flight out of Vegas on Monday.
The exact details of the incident are still unclear,
though the flight crew informed air traffic control
that a passenger had set up a spoofed network called
Delta Wi-Fi fast and was trying to scam the other passengers. The individual likely used a Wi-Fi
pineapple or similar device for spoofing networks. Delta is investigating the incident and working with
law enforcement, but stated that the aircraft's operating systems and flight safety were never
compromised. Federal authorities, on the other hand, met the plane upon landing to question the
passengers as the incident may amount to a federal offense. And that is the Cyberwire. For links to all
today's stories, check out our daily briefing at thecyberwire.com. As always, we would love to know
what you think of this podcast. Your feedback ensures that we deliver the insights that keep you a step
ahead in the rapidly changing world of cybersecurity. If you like the show, please share a rating
and review in your podcast app. Please also fill out the survey in the show notes or send an email
to Cyberwire at N2K.com. N2K's lead producer is Liz Stokes. We're mixed by Tray Hester with
original music and sound design by Elliot Peltzman.
Our executive producer is Jennifer Iben.
Fear Kilpy is our publisher.
And I'm Maria Vermasus in for Dave Vittner this week.
Thanks for listening.
We'll see you tomorrow.
