In partnership with

~7 MIN READ
Fact A newly disclosed "Ghostjacking" attack hijacked Claude Code 9 times out of 10 by planting malicious instructions inside trusted logs from tools like Cloudflare, Datadog, and Sentry. (Tenet Security research via SecurityWeek, August 2026)
The Signal
 
This week's theme: attackers are getting better at using the infrastructure you already trust against you, your vendors, your AI agents, even your social accounts. Here's what changed, and one patch you cannot skip.

PS: Was this forwarded to you? Subscribe free at exzeccyber.com/subscribe

In this edition
  📌 Big Cyber News
  🚨 Can't Miss
  🤖 AI in Cyber
  🕵️ Threat Intel
  🛠️ Tools & Tactics
  🧪 Strange Cyber
📌 Big Cyber News
 
Data Breach
A Hacked Shipping Company Just Exposed Steam Gamers, a Dutch Bank, and a Pro Soccer Club
Intro
You don't usually think about who ships your Steam Deck. Now you might have to.
What Happened
Ceva Logistics, a French freight giant, discovered a cyber intrusion across eight European warehouses in early August. Valve confirmed hackers stole names, addresses, phone numbers, and purchase details for European Steam customers, data Ceva keeps 90 days after a sale. Dutch platform Bol, department store De Bijenkorf, eyewear brand Ace & Tate, and football club Ajax confirmed the same breach hit their customers too.
Why It Matters
This is one compromised vendor rippling into ten-plus breach notifications and millions of customers who never dealt with Ceva directly.
The Other Side
No ransom note or claim of credit has surfaced, so this may be quiet data theft rather than extortion. Ceva still hasn't explained how attackers got in.
 
👉 Takeaway
If a vendor stores your order data, ask how long they keep it. Ninety days of purchase history was enough to expose it here.
TL;DR: A shipping vendor's breach hit Steam, a Dutch bank, a department store, and a soccer club through one supply chain.
Further reading: TechCrunch
🚨 Can't Miss
 
 
Ransomware
The FBI and South Korea warned about Gunra, a ransomware-as-a-service gang hitting healthcare, finance, and government targets by exploiting two known Fortinet firewall bugs. Built on leaked Conti source code, the group now operates as "Golden Community" and demands over $10 million on tight deadlines. Dragos counted four Q2 attacks on industrial targets alone.
Running Fortinet firewalls? Confirm CVE-2024-55591 and CVE-2025-24472 are patched today.
 
Data Breach
Britain's ACRO Criminal Records Office ran an outdated content system for four years and ignored antivirus alerts flagging credential-theft tools, catching three intrusions only after regulators dug in. Attackers had seven months of access at one point, staging data on nearly 11,000 people, some domestic violence victims. ACRO notified over 84,000 people.
The ICO's punishment was a reprimand, no fine. Unread AV alerts remain a top way in.
 
Data Breach
Extortion group ExfilSquad, behind last week's UK police legal database breach, claims it stole 2.6 million records from Wesco International's cloud CRM. Wesco says there's no ransomware, no disruption, no financial data exposed, but confirms the incident is real, its third named target in three weeks after Analog Devices and UK police.
Cloud CRM platforms are now a standard entry point, not an edge case.

Make Tax Season Simple

Tax season doesn't have to mean wondering if you have the right forms, second-guessing your deductions, or scrambling to pull everything together before the deadline.

With BELAY’s tax prep support, you can approach tax season with confidence. Stay organized with one centralized place to gather and check off your documents, keep track of valuable deductions like HSA contributions and education expenses while leaning on experienced professionals who make tax preparation accurate, efficient, and completely hands-off.

Download BELAY's free Personal Tax Checklist and start preparing with confidence, today.

🤖 AI in Cyber
 
 
AI Risk
OpenAI's upcoming Astra model tripped the company's own "critical" cybersecurity risk threshold, reserved for AI that can autonomously build zero-days or run a full cyberattack from one instruction. OpenAI suspended internal projects lacking new security controls ahead of release. Astra hasn't shipped, and OpenAI says it wasn't behind the recent Hugging Face incident.
A "critical" label is a first for OpenAI. When the model's own maker is worried, take it seriously.
 
AI Security
Tenet researchers found that planting malicious instructions inside logs from tools like Cloudflare, Datadog, and Sentry hijacks an AI agent that later reads them, no sandbox escape required. It worked against Claude Code 9 times out of 10, exploiting the fact that blocked-request logs get quoted back to the agent verbatim.
Audit what your AI agents read automatically, not just what they're allowed to do.
🕵️ Threat Intel
 
 
Nation-State
Lazarus Group is running Operation Dream Job against defense contractors in Western Europe, India, and South America, luring targets with fake recruiter outreach. One infection path used a previously unknown Windows flaw (CVE-2026-68820) for SYSTEM privileges and a kernel-mode rootkit, active since early July before this week's patch. A second drops a backdoor called Troy via a fake PDF viewer.
Defense-sector recruiting teams are now a security surface. Treat unsolicited job offers like phishing.
 
Critical Infrastructure
Attackers compromised a Fortinet VPN at a Polish wind farm, then used a misconfigured private cellular network meant only for utility gear to jump into a heat plant serving 50,000 residents. They shut down a steam turbine and water treatment using standard admin tools, no malware needed. Staff recovered while attackers were still active; heat and power never went out.
A shared private cellular APN between facilities is now a documented attack path, not a theory.
🛠️ Tools & Tactics
 
 
Practical play
A high-severity Cisco ASA/FTD flaw (CVE-2026-20349) is being actively exploited to crash devices remotely, no authentication needed, just a crafted HTTP request to the VPN service. CISA added it to the Known Exploited Vulnerabilities catalog with a federal deadline of August 14. If your device runs IKEv2, SSL-VPN, or Zero Trust Network Access, check your version now; there's no workaround, only the patch.

Porkbun is the domain registrar trusted by folks who want low prices without the nonsense. Get most domains at cost, free features like WHOIS privacy & SSL certificates, plus real 24/7 human support. Get $1 Off Your Domain

🧪 Strange Cyber
 
Strange but real
A Ransomware Gang Hijacked a Hospital's Facebook Page to Make Its Ransom Demand
Intro
Most ransomware notes stay on the dark web. This one went straight to Facebook.
What Happened
Two weeks after breaching AnMed's hospital network, the group calling itself The Gentlemen took over its Facebook page and posted a ransom demand directly to it, claiming 6 terabytes of stolen patient data including records tied to sexual assault, mental health, and abortion care. AnMed locked the account within hours, but ten facilities stayed closed to appointments during the response.
Why It Matters
Social accounts are usually an afterthought in incident response, right up until they become the extortion channel itself, broadcasting a threat to patients before anyone can control the message.
The Other Side
Ransomware groups routinely inflate theft claims for leverage, and AnMed hasn't verified the 6 terabyte figure.
 
👉 Takeaway
If your incident response plan doesn't cover who holds admin access to your social accounts, add it today. Attackers already thought of it.
TL;DR: A ransomware gang posted its ransom demand directly to a breached hospital's own Facebook page.
Further reading: The Record

The best candidate for your next role might not live in the same country. Oyster helps you hire globally in 180+ countries. Payroll, compliance, and benefits included.