2026-08-10
- ot ics
Novel Private APN Pivot Let Hackers Sabotage Second Polish Energy Facility
A second Polish energy facility was targeted using a private APN (Access Point Name) as an attack vector, according to CERT.PL. This marks the first known instance of hackers exploiting a private APN for lateral movement and sabotage in critical infrastructure.
Why it matters: Energy infrastructure operators need to assess private APN security immediately, as this novel attack path could affect any facility using mobile connectivity for industrial systems without proper segmentation.
- vulnerabilities
Critical Progress LoadMaster flaw now actively exploited in attacks
CISA has confirmed active exploitation of a critical command injection vulnerability in Progress Kemp LoadMaster by threat actors. The flaw allows attackers to execute unauthorized commands on affected load balancing appliances.
Why it matters: Organizations running Progress Kemp LoadMaster need to patch immediately, as this vulnerability is under active attack and could lead to full system compromise of a critical network infrastructure component.
- ai security
Anthropic to put AI in charge of reviewing Claude Code actions by default
Anthropic will enable auto mode by default in Claude Code starting August 14, allowing the AI to review and execute code actions without human intervention on Pro, Max, and Team plans. Internal testing showed auto mode detected 89% of dangerous commands compared to 13.6% caught by human reviewers in a controlled experiment with over 1,000 paid users. Enterprise customers retain the option to require manual review.
Why it matters: Developers using Claude Code on paid plans need to understand this change in default behavior and adjust their workflows if they prefer human review of code execution, as the shift moves security responsibility to AI automation.
- breaches incidents
Corporate Data Stolen in Levi Strauss Cyberattack
A threat actor used social engineering to compromise three Levi Strauss employees and exfiltrate corporate data from their computers. The incident represents a supply chain attack vector targeting a major apparel manufacturer through credential-based access.
Why it matters: Levi Strauss and its business partners face exposure of sensitive corporate information; practitioners should review social engineering defenses, employee security training, and data exfiltration controls.
- threat intel
Solidity Pro VS Code Extensions Steal Crypto Wallets, API Keys, and Credentials
Researchers identified malicious VS Code extensions masquerading as Solidity Pro tools that delivered browser wallet and credential stealing malware. The extensions, distributed under the names helper-beeps.solidity-pro and web3devtoolsx.solidity-pro, have been removed from Open VSX but the associated GitHub repository remains active.
Why it matters: Developers using Solidity and web3 tools face credential theft and wallet compromise if they installed these extensions; practitioners should audit installed VS Code extensions and validate legitimacy of development tools before installation.
- ai security
OpenAI locks down Astra over potential critical cyber capabilities
OpenAI's internal evaluation of its Astra model identified significant advances in agentic coding and cybersecurity capabilities, prompting the company to conclude it cannot rule out the model reaching a critical capability level for cybersecurity under its Preparedness Framework. The framework, published in December 2023, guides OpenAI's assessment of frontier artificial intelligence (AI) risks and determines required safeguards before deploying increasingly capable models.
Why it matters: Security practitioners and AI governance teams should monitor OpenAI's deployment decisions and safeguard implementations for Astra, as the model's cybersecurity capabilities may introduce new attack surface or enable more sophisticated threat actors if not properly controlled.
- cloud saas
GitHub Dependabot malware alerts now cover eight ecosystems
GitHub extended its Dependabot malware detection from npm packages to cover seven additional ecosystems: PyPI, Maven, RubyGems, NuGet, Go, crates.io, and PHP Composer. The expansion leverages OpenSSF's malicious-packages repository, which tracks over 15,000 malicious packages including typosquats and dependency-confusion attacks. Developers across these ecosystems now receive alerts when pulling in known malicious dependencies.
Why it matters: Developers in Python, Java, Ruby, .NET, Go, Rust, and PHP projects benefit from earlier detection of malicious dependencies; practitioners should verify that Dependabot alerts are configured and reviewed in projects using these package managers.
- ai security
OpenAI's Next AI Model Astra Shows Cyber Performance Strong Enough to Trigger Pause
OpenAI paused certain internal activities related to its forthcoming Astra AI model after discovering the model demonstrated significant capabilities in agentic coding and cybersecurity. The company stated it is implementing security controls for higher-capability models and related work.
Why it matters: Security teams should monitor AI vendors' safety practices around autonomous coding and offensive security capabilities; OpenAI's transparency here sets expectations for responsible disclosure of AI advancement risks.
- cloud saas
Chainloop: Open-source evidence store and policy engine for the software supply chain
Chainloop is an open source tool that captures software build artifacts and records them in signed in-toto attestations within a content-addressable evidence store. The command line tool integrates with CI/CD platforms including GitHub Actions, GitLab, Jenkins, and Dagger to document build steps and create auditable records that compliance and security teams can query through a control plane.
Why it matters: Software supply chain teams and compliance officers need verifiable, tamper-evident records of build activities; Chainloop provides a standardized mechanism to capture and audit build provenance across multiple CI/CD platforms.
- identity access
Product showcase: Enpass Password Manager breaks away from the proprietary cloud model
Enpass is a password manager that stores encrypted vaults locally on devices or in user-selected cloud storage rather than relying on proprietary cloud infrastructure. The product supports Windows, macOS, Linux, Android, and iOS, with browser extensions across major browsers.
Why it matters: Identity and access practitioners evaluating password managers should consider Enpass if they prefer decentralized storage control and compatibility across platforms.
- vulnerabilities
Critical Flaws Discovered in Belgian eID Software Used by 2 Million People
Security researchers discovered critical vulnerabilities in Belgian eID software that serves approximately 2 million users and is deployed across eight of Belgium's ten largest banks and more than 60 government agencies. The flaws potentially exposed a broad base of financial and governmental systems to compromise.
Why it matters: Financial institutions and government agencies in Belgium face immediate risk of eID authentication bypass or misuse; practitioners should coordinate with affected organizations to assess exposure and apply patches.
- regulatory
71% of CISOs spend 10+ hours on board reports
A survey from Pulse Security AI found that 71 percent of CISOs spend more than 10 hours preparing board reports, with translating technical findings into business language cited as a major time burden. Board members seek evidence that security controls reduce business risk in terms of resilience and consequence, while many organizations lack formally defined cyber risk appetites. CISOs are calling for simpler data delivery frameworks and better context to streamline communication.
Why it matters: CISOs and security leaders need better tools and frameworks to reduce reporting overhead, and boards need standardized methods to assess cyber risk appetite and control effectiveness against business objectives.
- regulatory
How to report an AI Act violation in the EU
On August 2, 2026, the European Commission's AI Office and national authorities began enforcing the EU's AI Act, a comprehensive regulatory framework governing AI systems sold or deployed in the EU. The law establishes rules designed to balance innovation with protection of safety and fundamental rights. The article outlines mechanisms for reporting violations of the AI Act to relevant authorities.
Why it matters: Organizations developing, deploying, or selling AI systems in the EU must now comply with AI Act requirements and understand reporting procedures; practitioners should review their AI systems against the regulatory standards and familiarize themselves with how violations are documented.