View all sources for this day →

The Signal

Security consequence in this set comes from failures at trust boundaries: trusted accounts, package installation, API session handling, and cloud application components. The Akira case also distinguishes unsuccessful encryption from the credentials, data, and defensive interruption already at issue. [1][2][3][4]

Must Know

Microsoft August security updates

Vulnerability · Exploitation

What happened

Microsoft’s August 2026 Patch Tuesday included fixes for more than 400 vulnerabilities, including CVE-2026-68820, which was exploited in zero-day attacks. [5]

CVE-2026-68820 is a use-after-free vulnerability in the Windows Ancillary Function Driver for WinSock (AFD.sys). [5]

Why it matters

The article identifies CVE-2026-68820 as an actively exploited zero-day, making it the most notable vulnerability among the release’s fixes. [5]

Akira Safe Mode intrusion analysis

Incident · Identity

What happened

In an Akira ransomware intrusion, the affiliate rebooted a computer into Safe Mode with Networking, which stopped the Huntress agent and disabled Microsoft Defender real-time protection, but constrained memory prevented the encryptor from completing. [1]

Before the Safe Mode reboot, the attacker had accessed the environment through a SonicWall SSL VPN account without MFA, queried Active Directory, collected data from mapped file shares, and transferred the archived data to cloud storage. [1]

Why it matters

The incident was not a complete victim win: credentials and data had already been stolen, and the attacker obtained a temporary period in which security tooling was disabled. [1]

LiteLLM malicious release exposure analysis

Supply Chain · Cloud

What happened

Two malicious LiteLLM releases were available on PyPI for about 40 minutes in March and contained code capable of harvesting cloud keys, SSH keys, Kubernetes tokens, database passwords, and other secrets from installing systems. [2]

Why it matters

CloudSEK obtained a dataset built from roughly 434,000 files captured by the attackers; the supplied evidence truncates the statement before describing what exposure the dataset maps. [2]

SAP Commerce Cloud security patch

Vulnerability · Cloud

What happened

SAP released patches for a maximum-severity vulnerability affecting Commerce Cloud’s Data Hub Adapter that could enable arbitrary code execution. [4]

The vulnerability is identified as CVE-2026-58231 and has a CVSS score of 10.0. [4]

Why it matters

The supplied evidence describes code-execution potential and severity, but does not establish exploitation or compromise. [4]

Research on model reasoning exposure through APIs

AI & Agents · Vulnerability

What happened

Researchers reportedly recovered internal reasoning and secrets, including API keys and passwords, from session logs by exploiting a newly disclosed flaw affecting hidden AI reasoning carried between API calls at OpenAI, Anthropic, and Google. [3]

The weakness affected encrypted reasoning objects used by the providers’ reasoning APIs; a block created in one session could be replayed into another during testing. [3]

Why it matters

The research makes cross-session isolation a distinct API security concern, not just the confidentiality of reasoning objects. [3]

Also Worth Knowing

CBTS continuous penetration-testing service

Security · Research

What happened

CBTS launched Penetration Testing as a Service (PTaaS), combining autonomous penetration testing with security expertise to help organizations identify exploitable risks, validate attack paths, and prioritize remediation continuously as environments evolve. [6]

Lazarus recruitment lures and Windows exploit

Exploitation · Research

What happened

Check Point researchers found that the North Korea-linked Lazarus group used fake job offers, trojanized PDF software, and a Windows zero-day in attacks aimed primarily at the defense sector. [7]

VPN and proxy extension research

Research · Platform

What happened

Researchers found 737 free VPN and proxy extensions that mainly targeted Russian-speaking users seeking access to blocked services and routed browser traffic through proxy infrastructure. [8]

Sources (8)
  1. [1] Akira ransomware scum blocked victim's security tools – and broke their own encryptor

    theregister security · August 12, 2026

  2. [2] Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations

    the hacker news · August 12, 2026

  3. [3] OpenAI, Anthropic, Google API Flaw Let Weaker AI Models Decode Stronger Models' Reasoning

    the hacker news · August 12, 2026

  4. [4] SAP Commerce Cloud Flaw Could Let Unauthenticated Attackers Execute Arbitrary Code

    the hacker news · August 12, 2026

  5. [5] Microsoft patches 400+ vulnerabilities, one zero-day under attack (CVE-2026-68820)

    helpnetsecurity · August 12, 2026

  6. [6] CBTS brings continuous penetration testing to enterprise security

    helpnetsecurity · August 12, 2026

  7. [7] Lazarus hackers pair fake job offers with Windows zero-day exploit

    helpnetsecurity · August 12, 2026

  8. [8] 737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One

    the hacker news · August 12, 2026