In partnership with

~7 MIN READ
Fact OpenAI's new GPT-5.6-Cyber model completes 95% of exploit-chain-development prompts that its general-purpose model refuses outright, and it already found a real vulnerability in Chrome's V8 engine within weeks of training. (SecurityWeek, August 2026)
The Signal
 
Microsoft warned a security researcher about "legal action." He responded by breaking Windows Defender on every patched machine in existence. This week's other stories share a theme: the weak link wasn't the big-name target, it was the vendor quietly holding everyone else's data, a CRM, a cold-storage shipper, a data broker feeding a deportation dragnet. Here's what broke, what got exposed, and one habit that'll save your team a bad patch week.

PS: Was this forwarded to you? Subscribe free at exzeccyber.com/subscribe

In this edition
  📌 Big Cyber News
  🚨 Can't Miss
  🤖 AI in Cyber
  🏛️ Privacy, Power & Policy
  🛠️ Tools & Tactics
  🧪 Strange Cyber
📌 Big Cyber News
 
Zero-day
🛡️ Microsoft Threatened Him With "Legal Action." He Responded With a Windows Defender Exploit That Works Every Time.
Intro
A security researcher just proved you probably shouldn't threaten a hacker who has eight more zero-days sitting in his back pocket.
What Happened
Days after Microsoft's August Patch Tuesday, a researcher going by "Nightmare Eclipse" released ShieldBreak, a working exploit that bypasses Microsoft Defender protections and grants full SYSTEM privileges on fully patched Windows 10, 11, and Server machines. Independent researchers confirmed it works with a claimed 100% success rate. It's the ninth Windows or Defender zero-day this same researcher has dropped since April.
Why It Matters
SYSTEM access is the ballgame: once an attacker has it, your antivirus, your logging, and your endpoint protection all answer to them instead of you.
The Other Side
Microsoft says it's "actively investigating" and stands by "coordinated vulnerability disclosure," but the researcher says the company's public warning about "legal action against people engaging in malicious activity" was aimed squarely at him for the disclosures, not at actual attackers.
 
👉 Takeaway
If Windows Defender is your only line of defense, you're not as protected as Patch Tuesday made you feel this week. Watch for Microsoft's next out-of-band patch.
TL;DR: A researcher Microsoft appeared to threaten just dropped a working Defender bypass that grants SYSTEM access on fully patched Windows machines.
Further reading: BleepingComputer
🚨 Can't Miss
 
 
Fraud
A phishing operation impersonating Credit Agricole, Europe's largest cooperative bank, used 149 stolen SendGrid API keys and three hijacked AWS accounts to blast roughly 7,000 fraudulent emails a day through trusted infrastructure. Researchers found the operators tested rate limits and subscription tiers on the stolen accounts first, to figure out which ones could send the most messages before getting flagged. The panel behind the campaign had a leaderboard where seven registered "phishing operators" competed for a 3,000 euro cash prize, and collected victims' account balance, branch, and advisor name to make follow-up scam calls more convincing. It worked: 912 people handed over banking credentials, and 83 of them actually lost money.
Criminals gamifying their own fraud isn't just funny, it's a sign these operations are scaling like real businesses.
 
Ransomware
A ransomware attack on Winnipeg's Health Sciences Centre, Manitoba's largest hospital, took down building-maintenance systems controlling door access, heating, and air conditioning on August 10. Staff reported doors that wouldn't unlock, prompting the hospital to post additional security and institutional safety officers at entrances while the issue persisted. Shared Health, which operates HSC, said clinical care and patient records were not affected and it has found no indication that patients were harmed. The hospital has launched an investigation to determine the scope of the attack, and no threat actor has publicly claimed responsibility.
Ransomware doesn't need to touch patient data to be dangerous. Physical building systems are IT systems now, and hospitals keep learning that the hard way.
 
Data breach
Beacon CRM, a platform used by more than 1,500 UK charities, confirmed attackers used compromised credentials to access its systems starting July 29 and copied, and likely downloaded, its customers' database backups. The exposed data spans names, addresses, phone numbers, dates of birth, gender, and donation and payment histories, and Beacon warned that even encrypted fields may have been decrypted and read. Named affected organizations include the Molly Rose Foundation, Victim Support, Macmillan Cancer Support Jersey, and the English National Ballet. Beacon didn't disclose the breach publicly until August 5, nearly a week after first becoming aware of it.
One vendor breach just became a data-protection headache for over a thousand separate nonprofits that did nothing wrong.

Your employees are connecting AI to everything. Now what?

ChatGPT and Claude don't just answer questions anymore. Employees are connecting them directly to Notion, Linear, Jira, and the rest of your stack. The AI can read, write, and take actions on company data. Most IT and security teams have no visibility into any of it.

Harmonic Security Connectors changes that. It sits inline with every AI-to-app connection, so you see each call, control what data moves, and block destructive actions before they happen. Employees notice nothing different.

See what's actually running across your business in a live demo.

🤖 AI in Cyber
 
 
AI security
OpenAI launched GPT-5.6-Cyber, a model trained specifically for "advanced, authorized" offensive security work like zero-day discovery and building exploit chains. It completes 95% of dual-use security prompts that its general-purpose GPT-5.6-Sol model refuses outright, up from GPT-5.5-Cyber's 57.3% completion rate on the same category of requests. OpenAI says the model has already found real vulnerabilities on its own, including a high-severity flaw in Chrome's V8 JavaScript engine and undisclosed bugs in mobile operating systems and databases. Access is restricted to trusted partners, including Accenture, IBM, Palo Alto Networks, and CrowdStrike, through an expanded "Daybreak Red" partner tier.
The model already found a real Chrome vulnerability. The gates around who gets to use it are the whole ballgame now.
 
AI vulnerability
Varonis Threat Labs, presenting at DEF CON 34, disclosed RovoBlast, a critical flaw in Atlassian's Rovo enterprise AI assistant that let a single crafted link inject malicious instructions directly into a user's live chat session, no jailbreak or permission bypass required. Once triggered, Rovo's ResearchAgent tool could autonomously pull data from Confluence, Jira, SharePoint, Slack, Google Workspace, Microsoft 365, and connected databases in one automated chain. Atlassian fixed the issue before the findings were published, so there's no evidence it was exploited against real customers. It's a reminder that AI agents with broad tool access inherit every permission a user has, all at once.
Enterprise AI assistants with broad tool access are only as safe as the links your employees click. Treat AI chat prompts like email attachments.
🏛️ Privacy, Power & Policy
 
 
Surveillance
New procurement records reviewed by 404 Media show Immigration and Customs Enforcement plans to keep paying LexisNexis millions of dollars for data that flows into Palantir's "ELITE" system, which helps the agency decide which neighborhoods to target for enforcement operations. The renewed spending comes as ICE reports arresting more than 51,000 people in July alone, with a significant share of apprehensions happening at airports. This is a separate, unrelated business relationship from the Metabase-linked breach that exposed LexisNexis customer data back in our August 10 edition. It illustrates how commercial data aggregation, built for marketing and fraud prevention, keeps getting repurposed for immigration enforcement.
Commercial data brokers aren't neutral utilities anymore. Every dataset a company sells can become an enforcement tool.
 
Privacy
EFF identified several widely embedded Android advertising SDKs, including ones from InMobi, BidMachine, Verve, and Huawei's Petal Ads, that openly acknowledge collecting and sharing users' location by default whenever an app has location permission granted. Because these SDKs are bundled inside otherwise ordinary apps, many developers embedding them likely don't realize their app is quietly feeding a location-data pipeline. That pipeline has previously been traced, in EFF's own past reporting, to tracking union organizers, monitoring military personnel, and outing a gay priest. EFF's report follows the 2025 breach of data broker Gravy Analytics, which exposed thousands of apps as hidden sources feeding the real-time-bidding location economy.
The privacy leak usually isn't the app you installed. It's the invisible ad library riding inside it.
🛠️ Tools & Tactics
 
 
Practical play
This month's Patch Tuesday guidance, from Ivanti's Todd Schell, makes a simple case: flat CVSS scoring wastes your team's limited patching time on vulnerabilities that don't actually threaten you. Prioritize known-exploited and internet-facing vulnerabilities first, and match risk to what each system actually touches, its network location, the data it processes, and its business criticality, rather than treating every CVE the same. For your highest-risk patches, aim for a three-day turnaround instead of the weeks-long cycles many teams default to, and build a quick test pass before deployment so a fast patch doesn't become a fast outage.
Rank your patch backlog by exploitability and exposure this week, not by CVSS score alone.

Avoid Tax Season Scramble

Don’t wait until spring to scramble through deductions, documents, and expenses. BELAY’s experienced tax prep professionals can help you get organized before it turns into an emergency.

Download the free Personal Tax Prep Checklist to start today.

🧪 Strange Cyber
 
A hooded hacker typing at a terminal in a dark cold-storage warehouse as a neon bucket-of-chicken sign flickers and dies in the background
Strange but real
🍗 Somewhere in Japan, a KFC Ran Out of Chicken Because of a Cyberattack
Intro
This story is a month old, but "a hacker took down fried chicken" doesn't get less good with age. Somewhere in Japan, a KFC employee had to explain to customers that the chicken shortage wasn't a supply problem. It was a cyberattack, and yes, it really was that specific.
What Happened
In July 2026, Nichirei Logistics, Japan's largest cold-chain shipping company, serving about 5,000 customers across 140 distribution centers, got hit by a cyberattack that forced it to disconnect key systems. The fallout hit KFC Japan's 1,300+ locations hardest: no online ordering, ingredient shortages, and warnings of shorter hours or temporary closures. Kura Sushi, Aeon, and several other chains felt it too.
Why It Matters
"Critical infrastructure" doesn't always mean power grids and pipelines. Sometimes it's the refrigerated trucks that keep fast food chains stocked, and one logistics vendor going dark can ripple across an entire country's dinner plans.
The Other Side
Nichirei never confirmed whether ransomware was involved and withheld technical details, so the exact mechanism of the attack is still unclear a month later.
 
👉 Takeaway
If your business depends on one logistics or supply-chain vendor with no backup plan, you're one bad week away from your own version of a chicken shortage.
TL;DR: A cyberattack on Japan's biggest cold-chain shipping company disrupted KFC and half a dozen other chains nationwide.
Further reading: The Record

The best candidate for your next role might not live in the same country. Oyster helps you hire globally in 180+ countries. Payroll, compliance, and benefits included.