DJBSEC's CyberNews 2026-08-13

Today’s daily news covers the following categories: Vulnerability Threat Intelligence Malware Nation-State/APT Data Breach Authentication Ransomware


AI API Flaw Exposed Hidden Reasoning and Secrets Across OpenAI, Anthropic, and Google

Vulnerability

Researchers disclosed a flaw affecting reasoning APIs from OpenAI, Anthropic, and Google that allowed encrypted reasoning blocks to be replayed across sessions and, in some cases, decoded by weaker models from the same provider. Researchers analyzed 6,708 publicly available agent trajectories and recovered hundreds of privacy-sensitive artifacts, including API keys, passwords, access tokens, and private keys hidden inside reasoning traces. The technique did not break the underlying encryption or provide arbitrary access to private conversations, but instead abused the way opaque reasoning objects were accepted and processed when they had been exposed through shared agent logs. Researchers also demonstrated that malicious instructions could be concealed inside reasoning blocks and later replayed as a form of invisible prompt injection. The affected providers were notified, and the researchers say the demonstrated extraction attacks no longer worked following mitigations.

Read More

Walmart Reworks Security Operations Around Trust, Transparency, and Less Friction

Threat Intelligence

Walmart’s security leadership is reshaping its security operations program around the idea that cybersecurity should enable the business rather than simply tell employees what they cannot do. Global VP of Security Operations Jason O’Dell says his team evaluates controls based on the security value they provide versus the operational friction they create, seeking strong protection without unnecessarily slowing business operations. Walmart has also emphasized transparency with executives, proactive threat planning, and programs that help security teams better understand the challenges faced by other parts of the company. O’Dell says executive-friendly summaries showing existing controls, planned improvements, and known gaps help leadership quickly understand the company’s exposure when major threats emerge. The strategy illustrates how large enterprises can treat security operations as a strategic business partner rather than solely a defensive function.

Read More

ChainDrop Worm Compromises More Than 400 npm Packages

Malware

Microsoft Threat Intelligence has analyzed ChainDrop, a large-scale software supply chain attack that compromised more than 400 npm packages with a self-propagating credential-stealing worm known as Mini Shai-Hulud. Once installed, the malware searches developer workstations and CI/CD environments for npm, GitHub, cloud, Kubernetes, and HashiCorp Vault credentials and then uses those identities to access additional secrets. Its most dangerous capability is automated propagation: stolen npm publishing credentials allow the worm to modify legitimate packages, increment their version numbers, and republish infected releases. The malware can also use compromised GitHub credentials to insert malicious Claude and Visual Studio Code configuration files into repositories, creating another route for infection and persistence. Microsoft recommends organizations that installed affected packages treat associated developer systems or build runners as compromised, rotate exposed credentials, and rebuild affected systems from trusted sources.

Read More

Lazarus Exploits Windows Zero-Day Against Defense and Aerospace Targets

Nation-State/APT

North Korea’s Lazarus Group has been linked to exploitation of a Windows zero-day as part of its long-running Operation Dream Job espionage campaign targeting defense and aerospace organizations. The vulnerability, CVE-2026-68820, affects the Windows Ancillary Function Driver for WinSock and allows attackers to elevate privileges to SYSTEM after gaining initial access. Victims in France, Germany, Brazil, and India were approached with convincing fake employment opportunities and then tricked into opening malicious PDFs or installing a trojanized PDF viewer. The attacks ultimately deployed a previously undocumented backdoor called Troy, giving the hackers remote control over compromised computers. Microsoft patched the vulnerability as part of its August 2026 Patch Tuesday release.

Read More

Palo Alto Networks Patches 11 Vulnerabilities Across Security Products

Vulnerability

Palo Alto Networks has disclosed 11 vulnerabilities affecting PAN-OS, GlobalProtect, Prisma Access Agent, and Prisma Browser as part of its August security update. The vulnerabilities include local privilege escalation, information disclosure, buffer overflow, certificate validation bypass, code execution, and anti-tamper bypass issues, although none of the newly disclosed flaws are rated critical. GlobalProtect received six separate fixes, while several Prisma Access Agent vulnerabilities have patches scheduled for later in August. Palo Alto Networks also issued a Chromium vulnerability rollup for Prisma Browser, which carries the highest CVSS score in the update at 7.2. No vulnerabilities in the release are currently known to be actively exploited, but administrators are advised to review affected versions and prioritize updates across exposed and endpoint systems.

Read More

CEVA Logistics Cyberattack Disrupts Warehouses and Exposes Customer Data

Data Breach

CEVA Logistics is recovering from a cyberattack that disrupted eight European warehouses and temporarily prevented shipments from leaving affected facilities. The July 29 incident directly affected supply chain operations, and customers were notified that goods stored at impacted locations could not be shipped while recovery work continued. Customer information associated with major clients was reportedly exposed, while Dutch retailer De Bijenkorf warned that names, addresses, email addresses, phone numbers, and online order details may have been compromised. CEVA has not publicly identified the attack method or threat actor, and no ransomware group has claimed responsibility for the incident. The exposed information could also create secondary phishing and impersonation risks for customers whose data was involved.

Read More

City-Forum Campaign Steals Data From Salesforce and ServiceNow

Data Breach

An unidentified threat actor has spent more than a year targeting Salesforce and ServiceNow environments that expose information through overly permissive guest access configurations. Researchers at Reco have named the campaign City-Forum and say it has targeted telecommunications, financial services, software, cybersecurity, privacy, and public-sector organizations worldwide since at least March 2025. Instead of relying only on commonly available scanning tools, the attackers developed custom techniques to identify and extract records from less-documented interfaces, including Salesforce’s Lightning Web Runtime data-access layer. The activity highlights how legitimate guest-access functionality can become a significant data exposure risk when permissions are configured too broadly. Organizations using Salesforce and ServiceNow should therefore review anonymous and guest permissions and identify data that can be accessed without authentication.

Read More

Researcher Claims Bypass of Microsoft’s Defender Security Patch

Vulnerability

A security researcher known as Nightmare Eclipse has published a proof-of-concept technique that reportedly bypasses Microsoft’s recent fix for a Microsoft Defender vulnerability. According to the researcher, an attacker who has already obtained any level of access to a Windows system could use the bypass to escalate privileges and gain SYSTEM-level control. The disclosure arrived only weeks after Microsoft attempted to address the underlying Defender security issue, raising questions about whether the original remediation fully closed the attack path. Microsoft says it is aware of the report and is investigating both the validity and potential applicability of the researcher’s claims. Until that investigation is complete, organizations should treat the bypass as an emerging security issue rather than a fully confirmed new vulnerability.

Read More

Mozilla Revokes Firefox Signing Key Accidentally Exposed on GitHub

Authentication

Mozilla revoked and replaced a cryptographic signing key after discovering that an unencrypted copy of the private key had accidentally been committed to a private GitHub repository. The affected subkey was used to sign Firefox and Thunderbird Linux tarballs, RPM packages, and checksum files, allowing users and package managers to verify that releases were legitimately produced by Mozilla. The repository was accessible only to a limited number of Mozilla employees who were already authorized to use the key, and an audit found no evidence that an unauthorized person accessed it. Mozilla nevertheless revoked the key as a precaution and introduced additional safeguards intended to prevent similar incidents. Most Firefox and Thunderbird users do not need to take action, although users who manually verify GPG signatures will need Mozilla’s replacement key.

Read More

Signal Adds Automatic Key Verification to Fight Man-in-the-Middle Attacks

Authentication

Signal has introduced Automatic Key Verification, or AKV, to make it easier for users to confirm that their encrypted conversations are actually connected to the intended person. Signal already uses safety numbers as cryptographic fingerprints, but an attacker who somehow manipulated the service’s account directory could theoretically redirect encrypted communications to the wrong recipient. The new feature uses Signal’s key-transparency infrastructure to automatically verify that a contact’s public encryption key matches the expected value and displays a green checkmark when verification succeeds. This reduces the need for users to manually compare long safety numbers while providing another defense against man-in-the-middle attacks. The feature strengthens identity verification without changing Signal’s existing end-to-end encryption model.

Read More

Akira Ransomware Attackers Disable Security Tools — Then Break Their Own Encryptor

Ransomware

An Akira ransomware affiliate attempted to defeat endpoint security by rebooting a victim’s computer into Windows Safe Mode, but the technique unexpectedly prevented the gang’s own ransomware from working properly. Safe Mode successfully disabled many of the victim’s security tools, but its limited drivers and system resources interfered with Akira’s high-performance, multithreaded encryption process. The failure prevented the attackers from successfully encrypting the victim’s files, but the organization was not completely spared because credentials and data had already been stolen from file shares. Huntress researchers caution that intentionally using Safe Mode should not be viewed as a practical defense against Akira because the encryption failure appears to have resulted from the specific system configuration. The incident demonstrates that stopping file encryption does not necessarily stop the broader impact of a modern ransomware and data-extortion attack.

Read More

Uber Freight Investigates Breach After Helix Claims Theft of Nearly One Million Files

Data Breach

Uber Freight has confirmed that it is investigating unauthorized access to a portion of its systems and data repositories after the Helix extortion group claimed responsibility for an attack. Helix says it stole nearly one million files from sources including employee mailboxes, OneDrive accounts, and accounts receivable systems, although Uber Freight has not confirmed the authenticity or scope of the group’s claims. The company says it identified, contained, and remediated the incident and has engaged federal law enforcement as part of its investigation. Uber Freight also says the breach did not disrupt business operations and that its systems remain fully operational. The incident is significant given the company’s role in managing millions of shipments and billions of dollars in goods across its transportation network.

Read More




Enjoy Reading This Article?

Here are some more articles you might like to read next:

  • DJBSEC's CyberNews 2026-08-28
  • DJBSEC's CyberNews 2026-08-27
  • DJBSEC's CyberNews 2026-08-26
  • DJBSEC's CyberNews 2026-08-25
  • DJBSEC's CyberNews 2026-08-24