In partnership with

~7 MIN READ
Fact More than 9,300 AWS access keys leaked publicly between 2022 and 2026 are still valid today, and 88% of them still work. (Truffle Security, August 2026)
The Signal
 
This week the story isn't who got breached, it's who almost did and how thin the margin was. A hospital chain, a security vendor, and 99 of the world's 100 biggest companies all found out how fast an attacker can move once they get a foothold, or a patch window.

PS: Was this forwarded to you? Subscribe free at exzeccyber.com/subscribe

In this edition
  📌 Big Cyber News
  🚨 Can't Miss
  🤖 AI in Cyber
  🕵️ Threat Intel
  🛠️ Tools & Tactics
  🧪 Strange Cyber
📌 Big Cyber News
 
SOCIAL ENGINEERING
🎣 ShinyHunters Called ReliaQuest Pretending to Be ReliaQuest's Own Security Team
Intro
Cybersecurity vendor ReliaQuest just survived the trick its own researchers warn clients about. Extortion crew ShinyHunters called ReliaQuest employees claiming to be internal security staff running an urgent audit.
What Happened
Attackers registered the lookalike domain reliaquest.claims and built a fake single sign-on page behind a CDN. One employee entered credentials and approved an MFA push, handing the attacker view-only access to ReliaQuest's identity dashboard. Device-trust controls blocked every further move; no customer data, applications, or systems were touched.
Why It Matters
ReliaQuest sells detection and response to other companies, so an attacker getting even a foothold there is a trust problem for its whole client base, not just an internal embarrassment.
The Other Side
ShinyHunters posted screenshots claiming a real breach, but even the group's own statement admitted no applications were reached and no data was taken, undercutting its own extortion pitch.
 
👉 Takeaway
Segmenting what a compromised identity can reach matters more than stopping the phish itself, because someone will eventually click.
TL;DR: A ransomware crew phished a security vendor's employee and got nothing but a dashboard view, because access controls did the job MFA couldn't.
Further reading: BleepingComputer
🚨 Can't Miss
 
 
DATA BREACH
Nutex Health, a for-profit operator of 28 emergency and specialty facilities across 12 states with $875 million in 2025 revenue, disclosed in an SEC filing that an unauthorized third party accessed and exfiltrated data from its servers. The publicly traded company ($1.28 billion market cap, ticker NUTX) has activated its incident response plan, engaged outside forensic specialists, and notified law enforcement, but still hasn't determined the full scope of what was taken. Potentially affected categories include patient records, employee data, credentialed provider details, and business and financial information. No threat actor has publicly claimed responsibility, and as of August 24 the company reports no material impact on operations or financial reporting.
Healthcare keeps getting hit because it's high-value data behind chronically underfunded IT, and this one is still in its earliest, murkiest hours.
 
ACTIVE EXPLOIT
SAP patched CVE-2026-58231, a maximum-severity CVSS 10.0 flaw in Commerce Cloud's Data Hub Adapter, on August 11, 2026, that let unauthenticated attackers abuse a default authentication client to execute arbitrary code. Threat intelligence firms Defused and KEVIntel independently spotted exploitation attempts starting August 14, just three days after the patch and with no public proof-of-concept exploit in circulation. Shadowserver tracks more than 4,200 internet-exposed instances, concentrated in Europe and North America, and SAP itself says its software runs behind 99 of the world's 100 largest companies, including Samsung, Mercedes-Benz, Shell, and BP. No confirmed victim has been named yet, but the attack surface is enormous.
If your patch cycle assumes a week of runway before criminals show up, this is the week that assumption died.
 
SUPPLY CHAIN
Someone compromised the maintainer account behind three widely used Rust crates, arrayref (245 million lifetime downloads), internment, and append-only-vec, and published poisoned versions alongside a typosquatted package mimicking the legitimate proc-macro2. The malicious build scripts fingerprinted the victim machine's OS and processor architecture, then downloaded and ran a payload targeting Chromium-based browsers and cryptocurrency wallet extensions. The Rust team pulled the releases fast, arrayref was live for 86 minutes, append-only-vec for 107, limiting real-world exposure, though the team hasn't disclosed how many developers actually downloaded the poisoned versions.
Open-source supply chains run on one maintainer's account staying secure, and this is what happens on the days it doesn't.

Hire Ava, the AI BDR built for enterprise

Ava is the first AI BDR to run outbound end to end, and you decide whether she runs autonomously or on copilot.

She finds leads or ingests accounts from your CRM, enriches them, sends personalized emails on behalf of your reps, follows up, handles replies and books meetings. Website visitor de-anonymization, intent signals, and a parallel dialer come built in.

A small team can manage her centrally for thousands of reps who never log in. Everything syncs two-way with Salesforce and HubSpot.

Ava runs outbound for companies like DoorDash and Grammarly, and one customer deploys her across 1,000+ reps. Ava is SOC 2 Type II audited, SSO and GDPR ready. Ava is how revenue teams grow pipeline without growing headcount.

🤖 AI in Cyber
 
 
AI SUPPLY CHAIN
A developer at IT firm Softjourn asked an AI coding agent to recommend a package for a routine task, and it suggested one with a name that sounded like a real, familiar library. It wasn't. Researchers call this slopsquatting: attackers register real packages under the exact plausible-sounding names AI models hallucinate, betting developers will trust the suggestion without checking. Softjourn's policy requires verifying every AI-recommended package before install, so the developer pulled up the source code and found the tell, barely any downloads and a repo created just days earlier.
Treat every AI-suggested dependency like a stranger's USB drive: check it before you plug it in.
 
AI SECURITY
Security researchers at Oasis Security found that NVIDIA's NemoClaw, a reference stack for running local AI agents, starts its underlying Ollama model server listening on every network interface instead of just localhost, despite telling users otherwise. A single visit to a malicious webpage can take unauthenticated control of that exposed server and plant hidden instructions directly into the model's system message template, instructions that persist across every future conversation and survive the agent supplying its own system prompt. An attacker could use that position to make the agent write vulnerable code that passes casual review or quietly exfiltrate conversation contents. NVIDIA shipped a fix for macOS and Linux in version 0.0.35; Windows and WSL users are still running on a version that only adds a warning label.
A local AI agent isn't automatically a private one. Check what its runtime exposes before trusting it with anything sensitive.
🕵️ Threat Intel
 
 
MALWARE
Researchers discovered two new remote access trojans, E4del and PINHOLE, that pull their attack instructions from FTP server banners, the plain greeting text a server sends before login even completes. E4del is a Node.js-based RAT packaged inside a digitally signed Electron app disguised as Discord, capable of running shell commands and streaming a victim's desktop over WebSockets. PINHOLE is the more sophisticated of the two: it retrieves its command-and-control configuration from Pinterest pins and SurveyMonkey survey questions, making it resistant to takedown since killing one server doesn't stop it, and supports 14 distinct commands including browser credential theft. The infection chain starts with phishing emails carrying ZIP archives and shortcut files, and the technique has been active and evolving since early July 2026.
Defenders scanning for malicious infrastructure need to start treating "boring" protocol metadata as a place attackers hide in plain sight.
 
ESPIONAGE
Google's Threat Intelligence Group is tracking three suspected Russian state-linked hacking groups, UNC6293 (believed connected to the SVR's APT29), UNC7005, and UNC5976, running phishing campaigns that abuse OAuth authorization flows instead of just harvesting passwords outright. Victims complete a legitimate login, then get prompted to approve what looks like a routine verification code, a step that actually hands the attacker persistent account access. The groups also use spoofed diplomatic invitations, device-code phishing, and fake file-sharing pages to widen the net. Targets are academics, diplomats, and researchers focused on Russia and the former Soviet states across Europe and the US, typically fewer than 100 people per campaign and under 10 confirmed victims per operation, but the campaigns have run since at least 2025 and remain active.
A login flow that looks completely normal is exactly what makes OAuth abuse work: question unexpected verification requests, not just suspicious links.
🛠️ Tools & Tactics
 
 
Practical play
Truffle Security spent four years tracking AWS access keys leaked publicly since 2022 and found more than 9,300 still active today, 88% of them able to authenticate. Hugging Face, the AI model-sharing platform, was the single biggest source: developers left keys inside notebooks and scripts they thought were private, accounting for over 8,400 exposures. Nearly 800 of the still-valid keys carry full administrator access to their AWS accounts, and fewer than 10% of the affected accounts had budget alerts configured to catch abuse before the bill arrives.
Check your public repos and notebooks for hardcoded credentials today, rotate anything you find, and set a budget alert while you're there.

Watch on demand: Tabs + PwC break down how finance teams are operationalizing usage-based pricing — without the manual overhead.

🧪 Strange Cyber
 
A man reacts to his phone flashing a scam warning while his wife feeds cash into a crypto ATM kiosk visible through the window behind him
Strange but real
🚔 A Fake Cop Almost Got $25,000 From a Florida Woman. Her Husband's Chatbot Stopped It.
Intro
Kimberly Fudge spent nearly 10 hours feeding cash into crypto kiosks because a caller convinced her she'd missed federal jury duty and was about to be arrested.
What Happened
Scammers posing as sheriff's deputies used a spoofed local number, her real Social Security number, and the fact her parents worked for the sheriff's office to sound legitimate. She deposited $25,000, including money borrowed from her husband, before the scammers texted him asking for more. He got suspicious and asked ChatGPT whether a wife would normally make that kind of request.
Why It Matters
The chatbot listed innocent explanations, then flagged it as a likely scam, enough to make him call 911 instead of complying. The local sheriff's office logged 44 similar cases this year, nearly double 2025's count.
The Other Side
AI gets blamed for enabling scams constantly, deepfakes included, so a case where a chatbot's skepticism broke the spell is worth noticing on its own terms.
 
👉 Takeaway
If a request for money arrives with urgency, secrecy, and a threat of arrest attached, that combination is the scam, regardless of who's calling.
TL;DR: A Florida woman lost $25,000 to a fake jury duty scam until her husband's ChatGPT search convinced him to call police instead of sending more money.
Further reading: IBTimes UK

AI changed CX overnight. Three leaders share what shifted, the challenges they faced, and where CX is headed next. Watch on-demand now. Watch now.