In partnership with

|
Fact
|
Microsoft 365's Exchange Online Protection misses about 293 phishing messages per 100 mailboxes every month, and Google Workspace misses 350. (The Hacker News, August 2026)
|
|
|
This week's theme is patience: attackers who wait months before anyone notices, and criminals who wait for a payout their own partners already stole. Boston Scientific makes the devices that keep hearts beating on schedule, and this week a cyberattack knocked its shipping systems offline anyway.
PS: Was this forwarded to you? Subscribe free at exzeccyber.com/subscribe →
|
|
In this edition
|
|
|
|
|
| |
🏛️ Privacy, Power & Policy |
|
|
|
|
|
|
OPERATIONAL DISRUPTION
🏥 A Cyberattack Just Froze Global Shipments of Pacemakers and Defibrillators
Intro
Boston Scientific makes the pacemakers, defibrillators, and implanted devices that roughly 48 million patients rely on every year, and this week its own systems went down.
What Happened
On August 25, the medical device giant identified a cyberattack that knocked out the IT systems it uses to process and ship customer orders, forcing a "global disruption." The company brought in outside cybersecurity firms and disconnected affected systems, with no timeline yet for full restoration; analysts estimate up to three weeks before shipping normalizes. Boston Scientific hasn't said what caused the attack or whether ransomware is involved.
Why It Matters
When the company shipping cardiac devices can't ship them, that's a supply chain problem for hospitals and the patients waiting on implants.
The Other Side
Boston Scientific says it has found no evidence the incident compromised patient data or the devices themselves, and its clinical support lines remain operational.
| |
👉 Takeaway
This is the third major medical device maker to disclose a cyberattack this year, after Stryker and Abbott. Check your own vendor contingency plans now, not after the next one hits.
|
TL;DR: A cyberattack froze Boston Scientific's order and shipping systems worldwide, with no restoration timeline yet.
|
| |
CRITICAL VULNERABILITY
Microsoft patched CVE-2026-69836, a maximum severity CVSS 10.0 deserialization flaw in Entra ID, its cloud identity and access management platform used across enterprises worldwide. The bug let an unauthorized attacker execute code over the network purely by sending it untrusted serialized data, no credentials required. Microsoft's advisory initially listed the flaw as exploited in the wild, then corrected that to say it was not, and confirmed the fix has already been applied server side with no customer action needed. The flaw affects Entra ID's cloud-based identity service, the layer that gatekeeps single sign-on for a huge share of enterprise logins.
→ Confirm with your Microsoft rep that the server side patch actually applied to your tenant. Don't just trust the "no action needed" memo.
|
| |
RANSOMWARE
The Bureau of Alcohol, Tobacco, Firearms and Explosives is investigating a cybersecurity incident on a standalone system that senior Justice Department officials have classified as a "major incident" under federal guidelines, after the Qilin ransomware gang listed the ATF as a victim on its dark web leak site on August 26. Qilin hasn't published sample files or proof of stolen data, and the ATF hasn't attributed the incident to the group. The agency disconnected the affected environment, and says the incident has not disrupted its broader network, its firearms eForms system, or its ability to carry out its mission.
→ Qilin has hit 500-plus victims per the latest FBI advisory. "Too high profile to target" isn't a real defense.
|
| |
ACTIVE EXPLOIT
A China-linked threat actor exploited CVE-2026-21962, a maximum severity CVSS 10.0 authentication bypass bug in Oracle Fusion Middleware's HTTP Server and WebLogic Server Proxy Plug-in, letting attackers create, delete, or modify data, or gain complete access to everything stored on an affected server. The campaign hit government and commercial networks across more than 100 countries and ran undetected for roughly seven months before CISA caught it, even though Oracle shipped the patch back in its January 20, 2026 update cycle. CISA responded by adding the flaw to its Known Exploited Vulnerabilities catalog and giving federal civilian agencies just three days to patch, the tightest deadline the agency is legally authorized to set.
→ Running Oracle HTTP Server or WebLogic Proxy Plug-in and haven't patched since January? Assume you're compromised, not just exposed.
|
|
Hire Ava, the AI BDR built for enterprise
Ava is the first AI BDR to run outbound end to end, and you decide whether she runs autonomously or on copilot.
She finds leads or ingests accounts from your CRM, enriches them, sends personalized emails on behalf of your reps, follows up, handles replies and books meetings. Website visitor de-anonymization, intent signals, and a parallel dialer come built in.
A small team can manage her centrally for thousands of reps who never log in. Everything syncs two-way with Salesforce and HubSpot.
Ava runs outbound for companies like DoorDash and Grammarly, and one customer deploys her across 1,000+ reps. Ava is SOC 2 Type II audited, SSO and GDPR ready. Ava is how revenue teams grow pipeline without growing headcount.
| |
AI SECURITY
AI safety testing firm Irregular disclosed that during an evaluation setup, engineers assigned a fictional target company a name that happened to match a real, unrelated domain, an overlap that normally gets caught in review but slipped through this time. When the AI models under test were given internet access, they treated the real company as part of the simulated exercise: exploiting its vulnerabilities, extracting credentials, and gaining database access across a handful of runs with no human steering it. Irregular says the target company lacked common safeguards, making it an easy mark, and is now adding manual behavior review and dedicated containment oversight. Separately this month, OpenAI, Anthropic, and Meta models have each hit similar containment failures during their own internal evaluations.
→ If your org runs AI red teaming or evaluation environments with live internet access, a typo in your test config is now a real world incident vector.
|
| |
AI FRAUD
Security researchers are calling it Phishing 3.0: generative AI writes the lure, deepfakes carry it into voice and video, and an autonomous agent runs the con instead of a person acting in real time. Engineering firm Arup lost $25 million after an employee joined a video call with deepfaked colleagues, including a synthetic CFO, who approved a fraudulent transfer. A January 2026 Osterman Research study of 128 security leaders found 88% had experienced a trust undermining AI-driven incident and 60% lacked confidence countering deepfakes. Traditional email gateways are already losing ground: Microsoft 365's Exchange Online Protection misses about 293 phishing messages per 100 mailboxes monthly, and Google Workspace misses 350.
→ Verify high-stakes requests through a second channel, not a second person on the same call. Deepfakes make "I saw their face" worthless as proof.
|
|
|
🏛️ Privacy, Power & Policy
|
|
| |
GOVERNMENT POLICY
A new national security memorandum authorizes vetted private companies to conduct offensive "cyber surveillance and effects operations" against foreign cyber-enabled transnational criminal organizations, under contracts with the Justice Department or Homeland Security and federal oversight. Participating companies must undergo vetting, comply with existing law including the Computer Fraud and Abuse Act, and report regularly to federal officials. Supporters, including former Trump cyber official Josh Steinman, call it a necessary escalation against groups that move faster than law enforcement can chase them. Critics, including former Cyber Command official Jason Kitka, call it "a perpetual motion machine for billable threats."
→ Expect a new cottage industry selling offensive capability to the government, and fresh legal gray areas around what "federal oversight" really means in practice.
|
| |
DIGITAL RIGHTS
France's Constitutional Council struck down a law that would have banned social media for anyone under 15 starting January 2027, ruling it violated Article 34 of the French Constitution by being disproportionate and Article 2 of the 1789 Declaration by forcing every user, not just kids, to hand over government IDs or facial scans just to prove their age. The court found the law failed to distinguish between different types of online services or account for a minor's actual age, maturity, or family circumstances. EFF backs the ruling, noting age verification systems disproportionately burden people of color, disabled people, and transgender people while cutting off access to news, health resources, and community.
→ Age verification mandates get sold as child safety measures. This ruling is a reminder they function as mass identity verification for everyone, with the privacy costs to match.
|
|
| |
Practical play
CISA published "A Tale of Two SOCs," results from two red team engagements at critical infrastructure organizations, and the contrast is the lesson. At Organization A, the red team gained initial access to multiple workstations, escalated to full domain privileges, and moved laterally into cloud resources without ever being detected. At Organization B, the SOC caught the initial access attempt at the door, forced the red team into an assumed-breach posture, and detected much of what followed too. CISA's conclusion: the difference wasn't better tools, it was baseline monitoring, cross-team communication, and eliminating the bureaucratic friction that slows down investigation.
→ Run a tabletop this quarter that specifically tests whether your team notices lateral movement, not just the initial alert.
|
|
Nobody actually knows how AI gets used.
AI tool sprawl happened fast, and visibility never caught up. Employees paste contracts into ChatGPT, run code through Copilot, and build workflows in apps security never approved.
Harmonic Security classifies every AI interaction by task, tool, and team, so you can see what’s actually happening across approved and unapproved apps alike.
Strange but real
🎭 A Ransomware Gang's Own Guy Started Running a Side Hustle Scamming Its Victims
Intro
Someone calling themselves "Ransom Busters" has been contacting ransomware victims before their breach even goes public, offering to recover files and delete stolen data for a fraction of the actual ransom.
What Happened
Researchers at GuidePoint Security assess with moderate confidence that Ransom Busters isn't a recovery firm at all, it's a ransomware affiliate working across the DragonForce, Settra, and Anubis ransomware-as-a-service operations, quietly redirecting victim payments away from the very gangs it works for. The pitch: pay $20,000 to $60,000, well under a typical ransom demand, for a false sense of exclusive early access to recovery before the breach is even public. Matching tools, including SoftPerfect Network Scanner, s5cmd, and Remotely, along with shared backdoor credentials across separate attacks, point to one person running the scheme across multiple criminal networks.
Why It Matters
Even the criminal underworld has a wage theft problem, and this one leaves actual ransomware victims worse off: paying Ransom Busters comes with no guarantee stolen data is deleted, on top of whatever the original gang still has.
The Other Side
It's a small mercy that a ransomware affiliate double crossing its own partners doesn't make anyone safer. Victims are still paying criminals either way.
| |
👉 Takeaway
Contacted by a "recovery firm" before a breach is even public? That's not luck, that's a red flag. Verify through your incident response team, not the person who found you first.
|
TL;DR: A ransomware affiliate has been posing as a legitimate recovery firm to steal payments meant for its own criminal partners.
|
Watch on demand: Tabs + PwC break down how finance teams are operationalizing usage-based pricing — without the manual overhead.