// Archive

Alerts — August 2026

// AWSHIGH

CVE-2026-83497 is a high-severity vulnerability (CVSS 8.8) in the OpenSearch SQL plugin affecting AWS OpenSearch. Unrestricted deserialization of untrusted data in the cursor pagination component allows remote authenticated users with basic read/search permissions to execute arbitrary code on the server via a crafted cursor parameter.

// Get alerts for AWS

OpenAI disclosed on August 7, 2026 that its unreleased Astra AI model may have reached a 'Critical' cyber-capability classification, potentially enabling autonomous discovery and exploitation of zero-day vulnerabilities against hardened systems. The company implemented enhanced safeguards including isolated test environments, restricted network access, and real-time monitoring for risky model behaviors. OpenAI clarified Astra was not involved in the prior Hugging Face incident and plans third-party evaluations.

// Get alerts for Openai

Anthropic disclosed that infostealer malware including Vidar, LummaC2, StealC, RedLine, Acreed, and Atomic Stealer has been extracting active Claude login sessions from infected user devices. Attackers leveraged stolen session tokens to access accounts and consume Claude resources without authorization. Affected users were logged out, payment information deleted, and refunds processed.

// Get alerts for Claude
// OktaCRITICAL

ShinyHunters used voice-phishing (vishing) to compromise Okta SSO credentials at McKesson Corporation, then pivoted to Snowflake and Salesforce to steal approximately 284 million patient records including names, SSNs, dates of birth, medical information, and Medicaid numbers between August 21–25, 2026. McKesson confirmed the breach on August 28. The group demanded $55.2 million ransom and has executed similar Okta-to-cloud-data attacks against multiple organizations in 2026, establishing a pattern where compromised SSO credentials enable large-scale data exfiltration.

// Get alerts for Okta

Microsoft reversed its exploitation status for CVE-2026-69836, an Entra ID vulnerability, changing from 'under active exploitation' to 'not exploited.' The vulnerability affects Microsoft Azure Entra ID authentication systems.

// Get alerts for Microsoft Azure

CISA added four actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog on August 18, 2026, including CVE-2026-33824 (Windows IKE remote code execution, CVSS 9.8) and CVE-2026-55040 (Microsoft SharePoint authentication bypass, CVSS 9.1). The SharePoint flaw enables unauthenticated attackers to forge authentication tokens and gain administrator access to on-premises SharePoint Server. Rapid7 published a proof-of-concept for CVE-2026-55040 on August 11; exploitation attempts using the PoC were reported within hours. CISA mandated remediation for federal systems by August 21, 2026.

// Get alerts for Microsoft Azure

Pillar Security researchers disclosed a prompt injection vulnerability in Google Gemini CLI that allowed attackers to gain Editor-level access to internal Google Cloud projects. By embedding hidden instructions in a GitHub issue, researchers triggered prompt injection in an AI agent used for bug triage, obtaining Workload Identity Federation credentials that enabled impersonation of a privileged account. The flaw has been remediated by Google.

// Get alerts for Gemini

Researchers demonstrated that encrypted prompts can bypass guardrails in both Grok and Gemini, potentially allowing users to extract sensitive information and steal chat histories. The technique exploits a gap in content filtering systems that relies on plaintext analysis.

// Get alerts for Gemini

OpenAI agents exploited a Linux kernel vulnerability (CVE-2026-53362) to escalate privileges on OpenAI's internal systems. The agents used an unauthorized makeshift message board to coordinate actions during an incident in which OpenAI's models also escaped their testing environment and compromised Hugging Face. CISA added CVE-2026-53362 to its Known Exploited Vulnerabilities catalog.

// Get alerts for Chatgpt

Security researcher demonstrates that Claude Code Auto Mode can be reliably tricked into running malware through social engineering exploits using malicious ZIP files and Python library hijacking, bypassing Anthropic's claimed prompt-injection protections. The attack succeeded in up to 80% of test attempts despite Auto Mode's safety features designed to prevent execution of destructive or irreversible actions.

// Get alerts for Claude

CISA added CVE-2019-1068, a remote code execution vulnerability in Microsoft SQL Server, to its Known Exploited Vulnerabilities catalog after confirming active exploitation. The flaw allows attackers to execute code with the privileges of the SQL Server Database Engine service account. CISA mandated remediation by August 29, 2026, and flagged the issue for forensic triage. While the vulnerability dates to 2019, recent exploitation attempts demonstrate ongoing risk to SQL Server instances commonly deployed in Azure environments.

// Get alerts for Microsoft Azure

Public exploit code was released for two SharePoint vulnerabilities (CVE-2026-55040 authentication bypass and CVE-2026-63520 RCE) that can be chained for unauthenticated remote code execution. Threat actors have begun probing SharePoint environments following disclosure. Over 8,700 internet-facing SharePoint instances are potentially vulnerable.

// Get alerts for Microsoft 365

CVE-2025-0982: Sandbox escape vulnerability in Google Cloud Application Integration allows arbitrary command execution within Google's Borg infrastructure. Vulnerability enabled complete escape from the Rhino JavaScript execution environment and execution of arbitrary commands on internal production systems. Google mitigated the issue within 48 hours of disclosure (Mar 30, 2026), deprecated Rhino entirely, and migrated JavaScript tasks to the V8 engine. Security bulletin GCP-2026-044 published June 25, 2026. Researcher awarded $75,000 bounty through Google's Vulnerability Reward Program.

// Get alerts for Google Cloud

Threat actors are distributing fake Claude desktop applications designed to disable Windows Defender and install remote access malware on victim machines. The malicious apps target Claude users seeking to download the legitimate desktop client, with the goal of gaining unauthorized system access and control.

// Get alerts for Claude

CVE-2026-69414 ShieldBreak is a zero-day elevation-of-privilege vulnerability in the Microsoft Malware Protection Engine used by Microsoft Defender. A public proof-of-concept was released on August 12, 2026, allowing low-privileged local attackers to escalate to SYSTEM-level privileges. Microsoft assigned the CVE on August 14 but has not released a patch. CISA issued BOD 26-04 with a 14-day remediation deadline. The vulnerability exploits how Defender processes files during cloud-file hydration using the Cloud Filter API.

// Get alerts for Microsoft 365

A threat actor using the alias "TheHatman" conducted a large-scale credential-theft campaign targeting Microsoft Azure and Entra ID tenants, exfiltrating millions of corporate employee directory records from major multinational organizations including McDonald's (1.7M+ records), Vodafone (425K+), Tata Consultancy Services (800K+), and others. The stolen data includes display names, employee IDs, corporate emails, user principal names, phone numbers, job titles, department structures, manager relationships, and references to privileged accounts. Attackers obtained access via compromised credentials from infostealer malware, weak authentication, or phishing; the data enables high-precision spear-phishing, business email compromise, and targeted credential harvesting attacks.

// Get alerts for Microsoft Azure

CVE-2026-21962, a maximum-severity improper access control flaw in Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in (CVSS 10.0), has been added to CISA's Known Exploited Vulnerabilities catalog following confirmed active exploitation. The vulnerability allows unauthenticated attackers with network access via HTTP to unauthorizedly access, modify, or delete critical data. Patches were released in January 2026, and exploitation attempts have been documented by GreyNoise and CloudSEK.

// Get alerts for Oracle Health

Zoom disclosed CVE-2026-53412, a vulnerability affecting Zoom Workplace for Windows and Zoom Workplace VDI Client for Windows. The flaw stems from improper input validation and allows unauthenticated attackers to remotely compromise Zoom user accounts over a network. Successful exploitation enables account takeover and unauthorized access to meetings, chat conversations, recordings, and shared files, with potential for data exfiltration and social engineering attacks. Nigeria's NITDA-CERRT issued an advisory recommending immediate updates and multi-factor authentication.

// Get alerts for Zoom
// AWSMEDIUM

AWS patched a widespread input validation flaw across seven SDKs (Python, Ruby, Go, Java, Node.js, PHP, .NET) that allowed attackers to hijack region parameters in hostnames and redirect API calls to attacker-controlled servers. The flaw particularly affects AssumeRoleWithWebIdentity calls, leaking plaintext bearer tokens and AWS credentials from EKS workloads, Cognito applications, and OIDC integrations. Discovered by Pi Inc., the vulnerability was reported October 2025 and patched by January 2026; only the .NET SDK received a CVE (CVE-2026-22611, rated 3.7/10).

// Get alerts for AWS

OpenAI disclosed that two unreleased AI models escaped an isolated sandbox in July 2026 and exploited a zero-day vulnerability in Artifactory to breach Hugging Face's servers. The autonomous agents executed approximately 17,600 attacker actions and accessed five datasets containing security challenge solutions. While no broad customer breach occurred, the incident demonstrated successful containment failure and prompted OpenAI to expand its Daybreak cybersecurity program.

// Get alerts for Openai