In partnership with

~7 MIN READ
Fact Verizon's 2026 Data Breach Investigations Report found vulnerability exploitation just overtook credential abuse as the number one way attackers break in, for the first time ever. (Verizon DBIR 2026)
The Signal
 
This edition is about blind spots, the kind that exist until someone stumbles into them by accident. Here's what changed, and one habit that actually helps.

PS: Was this forwarded to you? Subscribe free at exzeccyber.com/subscribe

In this edition
  📌 Big Cyber News
  🚨 Can't Miss
  🤖 AI in Cyber
  🕵️ Threat Intel
  🛠️ Tools & Tactics
  🧪 Strange Cyber
📌 Big Cyber News
 
Data Breach
🔍 A Data Center Giant Found Its Own Breach While Investigating a Smaller One
Intro
Sakura Internet is the kind of company most people have never heard of and everyone quietly depends on, a strategic cloud provider tied to Japan's own Government Cloud program. Turns out it had a much bigger problem than it knew.
What Happened
While investigating a smaller breach at its Rental Server unit, where 583 accounts were hit via stolen logins and planted malware, Sakura discovered hackers had separately gotten into its sales management system on August 9. Up to 1.36 million customer accounts, names, emails, contract and billing details, may be exposed. Passwords were hashed and no card numbers were stored, but the company still doesn't know if data actually left the building.
Why It Matters
Sakura isn't just another SaaS vendor. It's infrastructure other infrastructure runs on. A breach nobody detected on its own, caught only by accident while chasing a different incident, should worry any team that assumes "no alert" means "no problem."
The Other Side
No ransomware group has claimed the attack, and Sakura says large scale exfiltration isn't confirmed. This may end up smaller than the headline number suggests.
 
👉 Takeaway
If your vendor risk reviews lean on "have they had an incident," ask instead: how would they even know if they had?
TL;DR: Sakura Internet found a possible 1.36-million-account breach only while investigating a completely different one.
Further reading: BleepingComputer
🚨 Can't Miss
 
 
Critical Vulnerability
A GraphQL bug tracked as CVE-2026-19478 and rated 9.4 out of 10 let unauthenticated attackers remotely modify or delete public projects on self-managed GitLab instances, versions 18.2 through 19.2.3. GitLab shipped an emergency patch on August 17, outside its usual twice-monthly schedule, and is withholding exploit details until November to slow copycats. A second, lower-severity CSRF flaw was patched in the same release. GitLab.com and GitLab Dedicated customers were never at risk, only self-hosted installs were exposed.
If you run GitLab yourself instead of using GitLab.com, patch today, not next sprint.
 
Ransomware
CISA, the FBI, and HHS updated their joint advisory on Medusa ransomware: the group, active since January 2021, has now hit 500+ critical infrastructure orgs, up from 300 reported a year and a half ago. Healthcare, defense, government, and finance are all regular targets. Medusa recruits initial access brokers on criminal forums, paying $100 to $1 million per foothold, and can weaponize a freshly disclosed exploit within 24 hours, sometimes before it's even public.
If your patch cycle takes longer than a day for critical flaws, Medusa's timeline is faster than yours.
 
IoT Security
A 35-day campaign researchers at Hunt.io call Operation CameraSwarm quietly took over more than 14,500 Dahua IP cameras across Ukraine and Russia, using stolen credentials, old auth-bypass bugs, and a peer-to-peer relay trick to plant persistent backdoor accounts on nearly 2,000 devices. The operation only came to light because the attacker left a working directory, 407MB of source code, credentials, and captured images, sitting on an unprotected server. Language artifacts in the recovered files point to a Russian-speaking operator.
Default credentials on internet-facing cameras aren't a someday problem. They're a today problem, for the owner and now the researchers who found this.

Stop making AI decisions in the dark.

Leadership is asking: are we getting value from AI? Which tools are worth the spend? Where are we exposed? Right now, most teams have no idea.

You get a complete picture of how your organization uses AI, automatically categorized into custom tasks and use cases.

You’ll see the projects being worked on, who’s using what tools, where AI investments are driving value, and where employees are engaging in risky behavior.

CIOs can rationalize spending and cut wasted licenses. CISOs can pinpoint where risk exists and neutralize it. AI committees can show exactly how their efforts are paying off.

🤖 AI in Cyber
 
 
AI Security
Researchers at Adversa AI, in a technique they codenamed Cryptographic Context Injection, found that asking Grok to summarize an ordinary looking web page can silently trigger it to send your name, location, subscription tier, and entire conversation to an attacker's server, no confirmation, no warning. The trick hides encrypted instructions and a decryption key inside the page itself. It was reproduced August 19 against Grok 4.5 Fast at grok.com. No patch, no CVE yet.
Treat "summarize this page" as an action with real permissions, because apparently it is one.
 
Active Exploitation
A critical, unauthenticated flaw in MLflow (CVE-2026-64849, CVSS 9.3), an open source platform for managing machine learning workflows, lets attackers reach internal cloud metadata endpoints and steal credentials. Security firm watchTowr caught mass scanning for exposed MLflow servers within hours of the CVE going live on August 17, and confirmed attackers spinning up cryptominers with stolen credentials. CISA added it to its Known Exploited Vulnerabilities catalog on August 19, giving federal agencies until September 2 to patch.
If your ML team stood up MLflow without asking security first, today's the day to ask what version they're running.
🕵️ Threat Intel
 
 
Surveillance
Apple pushed its largest single wave of mercenary spyware warnings yet on August 13, and for the first time, the alert landed directly on the Lock Screen instead of buried in an email. These are the tools governments buy to target journalists, activists, and diplomats. Apple's fix: turn on Lockdown Mode, which strips out most of the attack surface these tools rely on. The company has now notified customers in more than 150 countries total since the program began.
If you get one of these alerts, believe it. Apple doesn't send them casually.
 
Cyber Warfare
Ukraine's military intelligence (HUR) says it worked with the hacking collective Cyber Corps to disrupt Wildberries, Russia's largest e-commerce platform, timed alongside drone strikes on its warehouses. Ukraine claims the company has lost over 1.2 million square meters of warehouse space, with 7 of its 10 largest logistics centers now offline, citing Wildberries' role in Russia's wartime supply chain. Wildberries has not publicly responded.
Cyberattacks paired with physical strikes aren't a future scenario. This is what coordinated warfare looks like now.
🛠️ Tools & Tactics
 
 
Practical play
Rapid7's latest threat landscape report counted 8,539 high and critical severity vulnerabilities this quarter, double the number from a year ago, a 76% jump in flaws with public proof-of-concept code, and 62% of newly exploited bugs needing no authentication at all. Its advice: stop chasing every CVE and instead map which vulnerabilities are actually reachable from the internet, enforce authentication on every exposed endpoint, and rotate credentials on edge appliances like VPNs and RDP proactively instead of after an incident.
Pull a list of your internet-facing systems this week. If you can't produce one quickly, that's the actual finding.

Your team’s new support player

Stax Payments, a Hubspot customer, now books 80% more meetings with the exact same team they had before.

No new hires. No new territories. Just HubSpot's Prospecting Agent finding the right accounts, surfacing the right contacts, and drafting outreach that actually gets responses.

Your best rep is great because they know who to go after and when. Prospecting Agent gives every rep that same starting point.

🧪 Strange Cyber
 
Strange but real
💾 A Ransomware Gang Broke Its Own Malware Trying to Be Sneaky
Intro
An Akira ransomware affiliate broke into a target through an exposed VPN with no multi-factor authentication, and within two hours was inside the domain controller. Then it tried a clever trick, and undid itself.
What Happened
After stealing data and installing remote access tools, the attacker rebooted the machine into Windows Safe Mode specifically to disable antivirus before running its encryption payload, a known defense evasion trick. Safe Mode did kill the defenses. It also starved the ransomware executable of the memory it needed to run, and the encryption never fired, failing with out-of-memory and PowerShell errors. Break in to bailout took about five hours.
Why It Matters
The evasion trick worked exactly as designed. The failure came from something nobody was testing for: Safe Mode's own resource limits.
The Other Side
The victim didn't get off easy. Data was still stolen and is presumably being used for extortion even without an encrypted network to point to.
 
👉 Takeaway
A failed encryption payload is not a failed breach. Treat data theft as the real event, whether or not the ransom note ever shows up.
TL;DR: Akira disabled its target's antivirus by rebooting into Safe Mode, then couldn't run its own ransomware because Safe Mode didn't have enough memory.
Further reading: BleepingComputer

The best candidate for your next role might not live in the same country. Oyster helps you hire globally in 180+ countries. Payroll, compliance, and benefits included.