Cyber Risk Brief: 10 - 16 August 2026

CRB-2117 August 2026Sovereign GRC Intel20 min read

Disclaimer:This brief is governance commentary for leadership and risk teams, not incident notification, public attribution, legal advice, or quantitative risk analysis. Threat prioritization, framework mappings, attribution, and risk-zone groupings are informational only. Validate all technical claims against vendor advisories and internal telemetry before operational response.

Threat Intelligence Summary

Three CISA KEV clocks landed on 11 August: Cisco ASA/FTD SSL VPN zero-day CVE-2026-20349, Immediate, deadline passed 14 August, CCCS AL26-018; Metabase CVE-2026-72898, Immediate, deadline passed 14 August, the CVE for last week's unnumbered zero-day, now with ShipMonk and Trezor customers in its blast radius; and Windows AFD CVE-2026-68820, Immediate, due 25 August, a Lazarus zero-day against defense firms. Behind them sit two escalations: SharePoint CVE-2026-45659, Immediate, KEV-listed since July and now flagged for ransomware campaigns, and vCenter CVE-2026-59310, Immediate, exploited from five days after disclosure with reverse_ssh persistence across 47 countries. Adobe Commerce CVE-2026-71362, Immediate, drew blocked account-takeover attempts at disclosure. The post-incident lane carries four governance lessons: LiteLLM's build-chain compromise of 2,500 organizations, Beacon CRM's database export through a key its own investigation traces to public JavaScript, the Gunra ransomware advisory entering through two-year-old Fortinet KEV flaws, and the first real-world private-APN attack on a Polish power plant. What connects them: clocks that expire inside one operating cycle, and blast radii that cross three vendor boundaries before they reach you.

Threat Register

Threat
T1
Cisco Secure Firewall ASA/FTD SSL VPN Zero-Day DoS (CVE-2026-20349)
CVE-2026-20349 lets an unauthenticated remote attacker reload Cisco Secure Firewall ASA and FTD devices through a crafted HTTP request to the Remote Access SSL VPN service (CVSS 3.1 8.6, EPSS 0.87%). Cisco disclosed the flaw on 11 August 2026 with confirmation of active exploitation in the wild, making it a zero-day at disclosure. CISA added it to KEV the same day with remediation due 14 August 2026, a deadline that passed before this brief published. CCCS carries it as AL26-018.
8.6< 1% CriticalImmediate
T2
Metabase Unauthenticated SQL Injection (CVE-2026-72898)
The Metabase zero-day disclosed on 8 August without a CVE identifier now carries one: CVE-2026-72898, NVD CVSS 4.0 10.0, EPSS 10.40%, the same flaw tracked as GHSA-vwf4-m7j8-wcjf in the 10 August brief. CISA added it to KEV on 11 August 2026 with remediation due 14 August, a deadline that passed before publication. On 13 August, Trezor disclosed that nearly 14,000 of its customers were exposed through shipping provider ShipMonk, whose customer notification says attackers exploited a vulnerability in Metabase's software. Framework and Tally data theft, from the prior card, stands.
10.0v4.010.40% CriticalImmediate
T3
Microsoft SharePoint Deserialization RCE in Ransomware Campaigns (CVE-2026-45659)
CISA's KEV update of 11 August 2026 flags CVE-2026-45659, a SharePoint Server deserialization RCE, as used in ransomware campaigns. The flaw has been KEV-listed since 1 July 2026 with remediation due 4 July, a deadline six weeks past (CVSS 3.1 8.8, EPSS 9.86%). Shadowserver counts more than 200 internet-exposed servers still unpatched. Microsoft has not confirmed in-the-wild exploitation; the ransomware attribution is CISA's, and this card carries it as such.
8.89.86% CriticalImmediate
T4
Windows Ancillary Function Driver UAF Zero-Day, Lazarus Operation Dream Job (CVE-2026-68820)
CVE-2026-68820 is a use-after-free in the Windows Ancillary Function Driver for WinSock (afd.sys) that lets a locally authenticated attacker gain SYSTEM privileges (CVSS 3.1 7.0). North Korea's Lazarus Group exploited it as a zero-day since early July 2026 in the Operation Dream Job campaign against defense, aerospace and aviation targets. Microsoft patched it in the 11 August 2026 Patch Tuesday, which fixed 400 flaws and three zero-days: this is the only one of the three under active exploitation, the other two being publicly disclosed only. CISA added it to KEV on 11 August with remediation due 25 August 2026.
7.0< 1% CriticalImmediate
T5
VMware vCenter Syslog Server RCE, Active Campaign (CVE-2026-59310)
CVE-2026-59310, a directory-traversal RCE in the VMware vCenter Syslog server (CVSS 3.1 9.8, EPSS 1.14%), was covered at disclosure on 3 August with no evidence of exploitation. DFIR firm QUIRSO now reports an active campaign from around 3 August deploying the open-source reverse_ssh tool for persistence, with 361 victim IPs across 47 countries by 7 August. The flaw is not KEV-listed. No workarounds exist; patching is the only fix.
9.81.14% CriticalImmediate
T6
Adobe Commerce Session Hijack via Incorrect Authorization (CVE-2026-71362)
CVE-2026-71362 is an incorrect-authorization flaw in Adobe Commerce and Magento (CVSS 3.1 9.1) that lets an attacker switch one customer session to another customer's account, exposing the victim's private data, with no authentication, admin rights or user interaction. Fixed in Adobe's August 2026 update (APSB26-92). Sansec reports its Shield WAF blocked exploitation attempts essentially immediately after disclosure; Adobe states it is not aware of in-the-wild exploitation.
9.1< 1% CriticalImmediate
T7
LiteLLM and Trivy Build-Chain Compromise
Malicious LiteLLM releases 1.82.7 and 1.82.8 sat on PyPI for roughly 40 minutes in March 2026, carrying credential-stealing code, after LiteLLM's CI pipeline installed a compromised build of Aqua Security's Trivy scanner: one unrevoked token, three tools deep. CloudSEK's reconstructed exposure covers more than 2,500 organizations, drawn from a dataset of roughly 434,000 files. Working from its own set of 2,188 identified organizations, SOCRadar found that 2,085 of them, 95 percent, stopped showing collection activity before the LiteLLM packages were published on 24 March, placing the exposure on the Trivy compromise itself.
HighPost-incident
T8
Beacon CRM Database Export via Exposed AWS Key
UK charity-CRM provider Beacon disclosed that attackers downloaded customer database backups after compromising an AWS access key that Beacon says may have been exposed in publicly available JavaScript build artifacts. Beacon assessed, based on data transfer volumes, that the threat actor exported all data contained within the database. More than 1,000 charities are affected. Malicious activity began 27 July 2026; the UK Charity Commission published guidance for affected organizations.
HighPost-incident
T9
Gunra Ransomware Targeting Critical Infrastructure
The FBI, CISA, DC3, NSA, the US Secret Service and South Korea's National Police Agency issued joint advisory AA26-222A on Gunra, a Conti-derived ransomware-as-a-service operation running affiliates since early 2026. The advisory places victims across the Americas, Europe, the Middle East, Africa and the Asia-Pacific; The Hacker News counts roughly 51 listed victims, primarily in South Korea, Brazil, Spain, Thailand and Hong Kong. Initial access runs through Fortinet FortiOS and FortiProxy flaws CVE-2024-55591 and CVE-2025-24472, both KEV-listed since 2024 and 2025. Targets include healthcare, financial services, and government services and facilities.
HighPost-incident
T10
Polish CHP Plant OT Sabotage via Private APN
CERT Polska disclosed on 8 August 2026 a December 2025 intrusion in which attackers shut down a steam turbine and the process-water treatment system at a combined heat and power plant serving roughly 50,000 residents. Entry ran from an internet-exposed FortiGate VPN at a wind farm, through an SSH tunnel onto the grid operator's private APN cellular network, to a WAGO controller still on default credentials. No malware was used; every destructive step relied on native device functions. CERT Polska calls it the first known real-world use of a private APN as an attack vector.
HighPost-incident
Select a row for narrative, affected systems, remediation, and sources.

Strategic context

Three federal clocks landed on one day, and two were already dead

  • CISA added CVE-2026-20349 (Cisco ASA/FTD), CVE-2026-72898 (Metabase) and CVE-2026-68820 (Windows AFD) to KEV on 11 August. The Cisco and Metabase deadlines fell on 14 August, three days before this brief; only the Windows AFD clock, due 25 August, is still live.
  • Under BOD 26-04's three-day cadence, a KEV entry added mid-week expires before the next change window. The Metabase clock ran partly before the CVE even existed: the flaw was disclosed 8 August without an identifier, assigned one, and hit its deadline inside the same week.
  • The decision this forces: emergency-patch SLAs have to assume three-day federal clocks on internet-facing infrastructure, and the KEV catalogue, not vendor severity, is the trigger. The Hermes feed missed one of the three additions; a weekly reconciliation against the KEV feed is now a control, not a convenience.

The blast radius runs through your vendors' vendors

  • Metabase (T2) reached Framework, Tally, and then ShipMonk, whose compromise exposed Trezor's customers: four parties removed from anyone who chose to run Metabase. LiteLLM (T7) reached 2,500 organizations through Trivy's build chain. Beacon (T8) exported a thousand charities' data through one key its own investigation traces to public JavaScript.
  • None of these paths crossed the victim's own perimeter. Vendor-data inventory that stops at direct processors cannot see any of them, and notification obligations arrive through contracts the customer never signed.
  • The decision this forces: extend fourth-party data flows into supplier-risk scope, and require from SaaS and logistics vendors the same attestation you require of software: where do credentials live, and who else's analytics stack touches your customers' data.

Exploitation follows disclosure in days, and waits for no catalogue

  • vCenter CVE-2026-59310 was disclosed 29 July, covered 3 August as having no evidence of exploitation, and was under active campaign by 3 August with 361 victim IPs by 7 August. SharePoint CVE-2026-45659 waited six weeks past its KEV deadline for its ransomware confirmation.
  • Lazarus held CVE-2026-68820 for over a month before Patch Tuesday closed it, and Adobe's CVE-2026-71362 drew blocked exploitation attempts at the moment of disclosure.
  • The decision this forces: 'no confirmed exploitation' is a snapshot with an expiry, not a risk acceptance. Define what reopens a closed card: a KEV status change, a campaign report, or a sector-match on the actor, each within one operating cycle.

Threat Actor Profiling

One threat carries named attribution: Lazarus Group for the Windows AFD zero-day (T4, per BleepingComputer, Check Point Research and The Hacker News), and one campaign carries a named operation, Gunra ransomware (T9, per the CISA/FBI/South Korea advisory). TeamPCP is named for the LiteLLM/Trivy build-chain compromise (T7, per CloudSEK findings reported by SecurityWeek). Cisco (T1), Metabase (T2), SharePoint (T3), vCenter (T5), Adobe Commerce (T6), Beacon (T8) and the Polish plant intrusion (T10) have confirmed exploitation, attempts or impact without a public actor name; QUIRSO suspects an APT behind the vCenter campaign without publishing evidence, and that hedge is carried in the register. MITRE technique codes are shown as hover-to-define abbreviations.

ThreatsActorSectorsMITRE tradecraftKill chain
T1Unattributed threat actor (Cisco ASA/FTD exploitation)SSL VPN edge, firewall infrastructureReconnaissance of SSL VPN endpoints → unauthenticated crafted HTTP requests → device reload and DoS
T2Unattributed threat actor (Metabase zero-day campaign)BI analytics, SaaS, logisticsUnauthenticated SQLi via /api/session/reset_password → admin access → connected-database theft
T3Unattributed ransomware operators (SharePoint CVE-2026-45659)collaboration infrastructureExploit deserialization RCE → establish on farm → ransomware deployment (campaign use per CISA KEV update)
T4Lazarus Group (North Korea)defense, aerospace, aviation, military technologyFraudulent job-offer lure → trojanized content executes → AFD.sys UAF to SYSTEM → FudModule disables EDR → Troy backdoor C2, RelayShell on Roundcube relays
T5Unattributed threat actor, suspected APT (unconfirmed, per QUIRSO)virtualization, enterprise datacentersDirectory traversal RCE on Syslog server → reverse_ssh outbound tunnel → persistence and remote access
T6Unattributed threat actor (Adobe Commerce attempts)e-commerce, retailIncorrect-authorization request at disclosure → session switch to victim account → victim data access (attempts blocked by Sansec WAF)
T7TeamPCPAI infrastructure, CI/CD, open-source ecosystemsTrivy build compromise → one unrevoked token → LiteLLM CI → malicious PyPI releases harvesting secrets
T8Unattributed threat actor (Beacon CRM exfiltration)SaaS, nonprofit, charitiesAWS key harvested from public JavaScript artifacts → cloud environment access → database backup export
T9Gunra ransomware operation (Conti-derived RaaS)healthcare, financial services, governmentFortinet SSL-VPN exploitation → credential interception and VDI MFA tampering → Impacket lateral movement and secretsdump → OneDrive/SharePoint exfiltration to MEGA → backup deletion → encryption
T10Unattributed threat actor (Polish energy intrusion)energy, OT, combined heat and powerWind-farm FortiGate without MFA → Teltonika SSH tunnel onto private APN → client-to-client pivot → WAGO default credentials → PLC STOP and device reset via native functions
Table methodology & sourcing notes
  • CVSS, EPSS and KEV status for scored CVEs were re-derived independently from NVD 2.0, FIRST EPSS and the CISA KEV catalogue on 16 August 2026 via scripts/verify-cve.py, plus a direct KEV-feed query for window additions. The Sheet's KEV column flagged two of the window's three additions and missed CVE-2026-72898, which was recovered from the feed and carried as T2. LiteLLM (T7), Beacon (T8), Gunra (T9) and the Polish CHP intrusion (T10) carry no CVE in retrieved reporting and no scores. Metabase (T2) is a material update of the 10 August card: the same flaw as GHSA-vwf4-m7j8-wcjf, then vendor CVSS 10.0 with no CVE, now CVE-2026-72898 with an NVD CVSS 4.0 10.0. SharePoint (T3) escalates the 6 July card on CISA's ransomware KEV update; Microsoft has not confirmed in-the-wild exploitation, and the ransomware attribution is CISA's. vCenter (T5) escalates the 3 August disclosure card on QUIRSO's campaign reporting; the APT suspicion is QUIRSO's and is unconfirmed. The Gunra advisory's initial-access CVEs (CVE-2024-55591, CVE-2025-24472) are 2024 and 2025 KEV entries, not re-scored this cycle. EPSS is a daily-moving score; all values here are the 16 August 2026 pull.

Control Deficiency & Framework Mapping

ThreatControl gapsISO 27001NIST CSF 2.0CIS ControlsPrivacy Act / PIPEDAITSG-33OSFI B-13ISO 42001
T1Cisco Secure Firewall ASA/FTD SSL VPN Zero-Day DoS (CVE-2026-20349)
  • SSL VPN and ZTNA services on ASA/FTD remained internet-exposed with no exposure ban
  • No monitoring for unexpected device reloads on firewall infrastructure
  • Emergency-patch SLA exceeds the three-day BOD 26-04 clock
  • Edge appliance inventory does not distinguish affected ASA/FTD trains
  • No compensating detection for DoS used as cover for follow-on activity
, , , , , , , , , ,
T2Metabase Unauthenticated SQL Injection (CVE-2026-72898)
  • Self-hosted analytics unpatched past a missed KEV deadline
  • No internet-exposure ban on BI tooling with live database credentials
  • Connected-database credentials not rotated on compromise
  • Fourth-party data flows (vendor's vendor analytics) absent from supplier inventory
  • No phishing-warning playbook for customers exposed through downstream breaches
, , , , , , , , , ,
T3Microsoft SharePoint Deserialization RCE in Ransomware Campaigns (CVE-2026-45659)
  • Patch installation unverified on SharePoint farms (deployment ticket treated as closure)
  • AMSI integration not enabled for SharePoint web applications
  • KEV exception for a passed federal deadline carried no documented risk acceptance
  • Internet-exposed SharePoint still permitted by policy
  • No ransomware-specific hunt coverage on collaboration infrastructure
, , , , , , , ,
T4Windows Ancillary Function Driver UAF Zero-Day, Lazarus Operation Dream Job (CVE-2026-68820)
  • Endpoint patching lags Patch Tuesday for kernel privilege-escalation flaws
  • EDR tamper resistance not assumed defeated in detection design
  • No lure-awareness control for staff targeted by recruitment-themed spear-phishing
  • Self-hosted Roundcube servers unmonitored for web-shell placement
  • Kernel-level compromise not treated as rebuild-required in IR playbooks
, , , , , , , ,
T5VMware vCenter Syslog Server RCE, Active Campaign (CVE-2026-59310)
  • Virtualization estate not patched to current fixed builds despite no-workaround disclosure
  • No egress monitoring for outbound SSH tunnels from hypervisor management planes
  • Hypervisor tier not classified as internet-adjacent emergency-patch infrastructure
  • No re-review trigger when 'no evidence of exploitation' status changes
  • Incident scoping excludes VMs reachable from compromised vCenter hosts
, , , , , , , , ,
T6Adobe Commerce Session Hijack via Incorrect Authorization (CVE-2026-71362)
  • Commerce platforms outside the emergency patch lane despite disclosure-day exploitation attempts
  • Point-release currency behind branch requirements for isolated patch application
  • No anomaly detection on customer session-to-account switching
  • WAF-blocked exploitation attempts not reported to governance as near-miss evidence
, , , , ,
T7LiteLLM and Trivy Build-Chain Compromise
  • Secrets reachable from CI build tools carry no rotation SLA
  • Build-time dependencies (scanners included) outside dependency attestation and pinning scope
  • AI tooling with secret reach not inventoried as production infrastructure
  • Token revocation not verified after upstream supply-chain events
  • No CI egress controls limiting what build processes can reach
, , , , , , , ,
T8Beacon CRM Database Export via Exposed AWS Key
  • Secret scanning scope excludes shipped JavaScript and build artifacts
  • No control preventing credentials from reaching client-delivered code
  • Vendor backup encryption treated as a boundary rather than a delay
  • No attestation of SaaS build hygiene before onboarding
  • Downstream notification playbook absent for breaches at a vendor's vendor
, , , , , , ,
T9Gunra Ransomware Targeting Critical Infrastructure
  • Two-year-old KEV entries (CVE-2024-55591, CVE-2025-24472) unpatched on SSL-VPN edge
  • Default and unused admin credentials on VPN appliances
  • VDI authentication files unmonitored for MFA tampering
  • Backups not immutable or not physically separate; DR copies reachable from primary
  • No detection for Impacket tooling, NTDS dumping, or MEGA egress
  • Overnight administrative sessions (10 p.m. to 6 a.m.) not alertable
, , , , , , , , , ,
T10Polish CHP Plant OT Sabotage via Private APN
  • Default credentials on OT controllers and serial devices
  • Private APN cellular links trusted without client isolation
  • VPN administration on remote sites without MFA
  • PLC state changes and factory resets monitored as faults, not security events
  • Cellular routes into OT absent from segmentation policy and audit scope
, , , , , , , ,

Privacy Act / PIPEDA & OSFI: No entry in this register is itself a confirmed Canadian personal-data breach notification trigger, so every Privacy Act / PIPEDA column reads as a dash rather than an assumed obligation. T2's named casualties (Framework, Tally, ShipMonk, Trezor) include no Canadian-jurisdiction confirmation in retrieved reporting, so exposure there maps to the data subject's own regime until Canadian footprints surface; Beacon (T8) is a UK incident under UK GDPR and Charity Commission guidance. If your estate holds Canadian personal information behind Metabase, SharePoint (T3), Adobe Commerce (T6) or Gunra-affected (T9) infrastructure, Schedule 1 Principle 4.7 safeguards and PIPEDA s.10.1 reporting analysis apply on your own facts. OSFI B-13 patch, access-control, third-party and resilience expectations apply to federally regulated institutions running the edge, virtualization, commerce and CI infrastructure in T1 through T9. Assess all of it against your own data map and regulatory footprint.

Risk Triage

Threats are assigned to primary zones based on their dominant organizational risk characteristic. A threat may appear in a secondary zone when it presents a materially distinct compounding risk dimension.

Exposure Velocity

Active exploitation or weaponized capability with immediate organizational exposure if unaddressed.

  • T1Cisco ASA/FTD zero-day DoS — KEV deadline passed

    Unauthenticated remote reload of the firewall enforcement point, exploited before disclosure; due 14 August. Apply the per-train ASA build or FTD hotfix on internet-facing systems first.

  • T2Metabase CVE-2026-72898 — passed clock, named victims

    CVSS 4.0 10.0, KEV due 14 August, customer data theft at Framework, Tally and now ShipMonk/Trezor downstream. Upgrade self-hosted instances and rotate connected credentials.

  • T3SharePoint CVE-2026-45659 — ransomware-flagged

    Six-week-old KEV entry now flagged by CISA for ransomware campaigns, with 200+ servers still exposed per Shadowserver. Verify patch installation, enable AMSI, hunt farms.

  • T4Windows AFD CVE-2026-68820 — Lazarus zero-day, live clock

    Exploited since early July against defense firms; KEV due 25 August. Deploy August Patch Tuesday and hunt FudModule, Troy and RelayShell indicators.

  • T5vCenter CVE-2026-59310 — active campaign

    reverse_ssh persistence across 361 victim IPs in 47 countries from 3 August, five days after disclosure and with no workaround. Upgrade and hunt outbound SSH.

Incident Pressure

Confirmed campaign or large-scale exposure with direct impact on organizations or their data.

  • T7LiteLLM/Trivy — 2,500 organizations' CI secrets exposed

    Confirmed supply-chain compromise with exposure still being quantified five months on. Validate, then rotate everything a build tool could reach.

  • T9Gunra ransomware — active critical-infrastructure campaign

    Joint FBI/CISA/South Korea advisory; double extortion with ~51 listed victims. Verify Fortinet edge patching, MFA resilience and immutable backups.

  • T2 · T8Fourth-party disclosure pressure — ShipMonk via T2, Beacon via T8

    Secondary zone: named downstream breaches (ShipMonk/Trezor via T2, 1,000+ charities via T8) convert patch status into notification and phishing-warning obligations.

Governance & Control Gaps

Structural control deficiencies revealed by the day's threats, independent of any single exploit.

  • T6Adobe Commerce — exploitation-attempt evidence

    Attempts blocked at disclosure, no confirmed compromise: the gap this exposes is commerce patch cadence and session-anomaly detection, not incident response.

  • T8Beacon CRM — secret-scanning scope failure

    One AWS key, which Beacon's investigation traces to public JavaScript, exported a full database: front-end bundles and build outputs sit outside most secret-scanning programs by scope definition, not by oversight.

  • T10Polish CHP — trusted-connectivity assumption

    No malware and no zero-day: default credentials plus a trusted private APN did all the damage. The control gap is whether cellular OT routes are inside segmentation policy at all.

Strategic Posture

Cross-cutting pattern requiring board-level awareness and programme-level response.

  • T2 · T7 · T8Blast radius crosses three vendor boundaries

    Metabase reached Trezor's customers through a logistics processor; LiteLLM reached 2,500 organizations through Trivy; Beacon reached a thousand charities through one key it believes shipped in public JavaScript. Boards should treat fourth-party data flows as an ungoverned inventory item today.

  • T1 · T3 · T9The clock, not the CVSS, is the risk model

    Two passed deadlines and a ransomware-flagged lapsed entry this week, plus an advisory entering through 2024 CVEs. Governance owns the exception register that explains each one.

Remediation Actions

Consolidated actions across all ten threats, organized by time horizon. T-badges indicate which threat each action addresses.

0 – 24 hours

Immediate response

  • T1Apply the fixed ASA build or FTD hotfix per train on internet-facing Cisco firewalls; the KEV deadline passed 14 August.
  • T2Upgrade self-hosted Metabase to the branch's fixed build or block /api/session/reset_password, then rotate every connected database credential.
  • T4Deploy the 11 August Patch Tuesday to all Windows endpoints for CVE-2026-68820 before the 25 August KEV deadline.
  • T5Upgrade vCenter to 9.1.0.0300, 9.0.2.0100 or 8.0 U3k/U2f; no workaround exists.
  • T3Verify the May 2026 SharePoint update for CVE-2026-45659 is actually installed on every farm and enable AMSI for SharePoint web applications.

7 days

Short-term hardening

  • T6Bring each Adobe Commerce branch to its latest -p release, then apply the isolated APSB26-92 patch file for CVE-2026-71362.
  • T5Hunt vCenter hosts for reverse_ssh binaries using QUIRSO's YARA rule and review outbound SSH from management planes since 3 August.
  • T9Verify Fortinet SSL-VPN edges are past CVE-2024-55591 and CVE-2025-24472, eliminate default admin credentials, and alert on VDI authentication-file changes.
  • T4Hunt defense-facing endpoints for FudModule, Troy and RelayShell indicators; review Roundcube servers for the web shell.
  • T3Hunt farms internet-exposed since 1 July for exploitation signs using Defender detections per CISA guidance.

14 – 30 days

Programme remediation

  • T7Run the secret-rotation program for everything CI build tools can reach, and add build-time dependencies to attestation and pinning scope.
  • T8Extend secret scanning to shipped JavaScript, build artifacts and CI outputs, and rotate any key that has ever reached a client bundle.
  • T10Audit private APNs and cellular OT routes for client isolation, treat them as untrusted from the OT side, and sweep reachable controllers for default credentials.
  • T2T7T8Build the fourth-party data inventory: which vendors' analytics, CI and logistics stacks touch your customers' data, with attestation requirements to match.

Ongoing

Structural controls

  • T1T2T3T5Reconcile the KEV catalogue against your exception register weekly, and price every extension against three-day BOD 26-04 clocks rather than vendor severity.
  • T9T10Maintain immutable, physically separate backups with rehearsed restore, and exercise recovery with the intruder still present, as the Polish plant had to.
  • T4T9Assume EDR tampering and MFA manipulation in detection design: kernel rootkits and VDI authentication-file changes are documented field techniques, not hypotheses.
  • T7Keep AI tooling with secret reach inside the asset register and the ISO 42001 scope, with a standing rule that CI-reachable secrets are scheduled for rotation.

Provenance

Cadence

Published weekly. Each issue distills the week's most material threats from primary security reporting and vendor advisories, cross-referenced against authoritative sources (CVE/NVD, CISA KEV, and MITRE ATT&CK) and mapped to the compliance obligations that govern your response. Use Subscribe or Share on any issue to join the distribution list.

See how this week's threats map to your control gaps.

Book a briefing →