In partnership with

~7 MIN READ
Fact A single poisoned open-source dependency gave attackers a 40-minute window to harvest secrets from more than 430,000 build pipeline runs, exposing credentials tied to roughly 2,500 companies. (Hudson Rock via Help Net Security, August 2026)
The Signal
 
This week's biggest story didn't involve a single line of malicious code. Someone just walked in the front door because nobody remembered to lock it, for a year and a half. This week the threats aren't zero-days, they're settings nobody double-checked: a guest account with too much access, a supply chain dependency nobody audited, a maintenance port left unlocked. Here's what slipped through.

PS: Was this forwarded to you? Subscribe free at exzeccyber.com/subscribe

In this edition
  📌 Big Cyber News
  🚨 Can't Miss
  🤖 AI in Cyber
  🏛️ Privacy, Power & Policy
  🛠️ Tools & Tactics
  🧪 Strange Cyber
📌 Big Cyber News
 
Data Exposure
🕵️ The Guest Account That Read Your CRM for 17 Months
Intro
No malware. No stolen password. No CVE. Just a guest account nobody remembered existed, and it worked for a year and a half.
What Happened
Researchers at Reco found a single attacker, operating from one rented German server since at least March 2025, quietly scraping Salesforce and ServiceNow customer portals worldwide. The technique, dubbed City-Forum, exploits the automatic "guest user" account both platforms create for unauthenticated visitors, an account that can't be deleted and often ships with far more access than it needs. Targets span telecoms, banks, enterprise software vendors, and public sector portals.
Why It Matters
There's no patch for this because there's no vulnerability, just a default configuration nobody audited, which means every org running these platforms should check its own guest permissions today, not wait on a vendor fix.
The Other Side
Reco hasn't attributed the campaign to a named group, and without confirmed data exfiltration at any single victim, it's hard to say yet how damaging 17 months of scraping actually was.
 
👉 Takeaway
If you run Salesforce Experience Cloud or ServiceNow with public-facing portals, audit your guest user permissions this week. That review is free and takes an afternoon.
TL;DR: A mystery attacker has been silently scraping global Salesforce and ServiceNow data for 17 months by abusing an unaudited guest account.
Further reading: The Hacker News
🚨 Can't Miss
 
 
Zero-Day
A critical auth bypass in on-prem SharePoint (CVE-2026-55040) lets attackers forge admin access with no login at all. Microsoft patched it in July, but once Rapid7 published a working proof-of-concept on August 12, honeypots recorded live attacks within hours. More than 8,500 SharePoint servers are still exposed online.
Running on-prem SharePoint 2016, 2019, or Subscription Edition? Confirm July's patch is actually installed, this one is being actively used.
 
Hardware Hack
Researchers built a sub-$100 gadget that plugs into an unlocked maintenance port beneath a 737's nose and hijacks its flight computers, feeding pilots false altitude, airspeed, or engine data in about 60 seconds. They flagged the flaw to Boeing back in 2020 and still don't know if it's fixed.
Ground crew and airport access control just became part of your aviation threat model, not just IT.
 
ICS Security
Claroty found 23 vulnerabilities, 21 high severity, in Copeland's XWEB Pro refrigeration controllers, plus related Danfoss flaws. Chained together, they give root access and let an attacker kill cooling while the display keeps showing normal temperatures. Both vendors have shipped patches.
Running Copeland XWEB Pro or Danfoss AK-SM 800A? Update now, this is a silent-failure bug.

Stop making AI decisions in the dark.

Leadership is asking: are we getting value from AI? Which tools are worth the spend? Where are we exposed? Right now, most teams have no idea.

You get a complete picture of how your organization uses AI, automatically categorized into custom tasks and use cases.

You’ll see the projects being worked on, who’s using what tools, where AI investments are driving value, and where employees are engaging in risky behavior.

CIOs can rationalize spending and cut wasted licenses. CISOs can pinpoint where risk exists and neutralize it. AI committees can show exactly how their efforts are paying off.

🤖 AI in Cyber
 
 
Supply Chain
In March, a group called TeamPCP compromised the scanner Trivy and used it to poison two releases of LiteLLM, a popular open-source proxy for AI model calls, stealing build-pipeline secrets and API keys from AWS, Samsung, Cisco, Salesforce, NVIDIA, and Microsoft. The 153GB archive only surfaced publicly this month.
Audit your AI tooling dependencies like any other production package. A poisoned build tool is a supply chain attack either way.
 
Threat Research
Rapid7 found high and critical vulnerability disclosures nearly doubled year over year, from 4,268 to 8,539 in Q2, while attackers actually exploited only 40. But 25 of those 40 needed zero authentication, up nine points from last year, exactly the kind of bug AI tools are getting fast at finding.
Stop triaging purely by CVSS score. Map which internet-facing systems are actually reachable and patch those first.
🏛️ Privacy, Power & Policy
 
 
Policy
Trump signed a National Security Presidential Memorandum on August 12 authorizing vetted private companies to run offensive cyber operations, intelligence-gathering and disruptive attacks alike, against foreign criminal groups under direct federal oversight. It's the first time in US history private firms have been formally authorized to do this. Implementation guidance is due by mid-October.
Watch for a new category of vetted "participating companies," and the liability questions that come with it.
 
Regulation
ETSI released 17 draft standards to help manufacturers comply with the EU's Cyber Resilience Act, covering higher-risk products like password managers, antivirus software, and smart home devices. Following them grants a legal "presumption of conformity." Every manufacturer selling connected products in Europe has until December 31, 2027 to comply.
If your product touches the EU market in a higher-risk category, get someone reading these standards now.
🛠️ Tools & Tactics
 
 
Practical play
CISA added a critical command-injection flaw in Progress's Kemp LoadMaster (CVE-2026-8037, CVSS 9.6) to its Known Exploited Vulnerabilities catalog after confirming active exploitation, giving federal agencies a hard three-day patch deadline. LoadMaster sits at the network edge, exactly where attackers want a foothold. Running GA 7.2.63.1, LTSF 7.2.54.17, or earlier? Patch now, attackers already have the exploit.
Confirm your LoadMaster firmware version today, this one is being actively exploited, not just theoretically vulnerable.

Avoid Tax Season Scramble

Don’t wait until spring to scramble through deductions, documents, and expenses. BELAY’s experienced tax prep professionals can help you get organized before it turns into an emergency.

Download the free Personal Tax Prep Checklist to start today.

🧪 Strange Cyber
 
Strange but real
🎭 The Deepfake That Glitched at the Worst Possible Moment
Intro
A man spent months building an elaborate deepfake operation to steal other people's identities. He got caught because his face-swap software lagged for less than a second.
What Happened
Spanish police say the suspect made 38 attempts to fraudulently obtain digital certificates in other people's names, targeting a certificate-issuing security company, and succeeded more than once. His setup: forged ID documents, altered photos, a custom lighting rig to fake hologram security features, and real-time deepfake software to swap his face for his victims' during live video checks. Investigators say the software lagged during one call, and for under a second, his real face appeared instead of the mask.
Why It Matters
Live video identity verification is supposed to be the strong option, the fallback when a photo or ID scan alone isn't trustworthy enough. This case is a reminder that real-time deepfake tools are good enough to beat it, most of the time.
The Other Side
The system did eventually work: the verification company flagged the suspicious pattern of requests and reported it, which is what actually led to the arrest, not the software glitch alone.
 
👉 Takeaway
If your org relies on live video identity checks as a security control, assume a well-resourced attacker can beat it on a good day, and build in the kind of pattern-detection that caught this guy on a bad one.
TL;DR: A deepfake identity fraudster who spoofed 38 live video verification checks got caught when his face-swap software glitched for under a second.
Further reading: The Register

The best candidate for your next role might not live in the same country. Oyster helps you hire globally in 180+ countries. Payroll, compliance, and benefits included.