Threat Brief — 2026-08-12 — Zero-days traded, passkeys punctured
Attackers are rapidly weaponising this week's patch drops: a SharePoint RCE PoC is already in the wild, Adobe shipped three CVSS 10.0 fixes, and a new Windows Defender bypass ("ShieldBreak") grants SYSTEM. A novel attack against Windows passkeys shows phishing-resistant authentication isn't living up to its name, and an AI API flaw exposed hidden reasoning traces containing API keys and passwords. Meanwhile, the MyDr hospital breach may impact up to 18.8 million people.
Top items
- SharePoint RCE under active attack with public PoC. Rapid7 published a proof-of-concept exploit for a critical Microsoft SharePoint vulnerability on Tuesday, and threat actors have already begun leveraging it in attacks. The vulnerability allows unauthenticated remote code execution, making it a prime candidate for ransomware crews. A public exploit is already available. (src: BleepingComputer)
- Adobe patches three CVSS 10.0 flaws in ColdFusion and Campaign Classic. Critical vulnerabilities allowing arbitrary code execution and privilege escalation have been patched in ColdFusion, Commerce, and Campaign Classic. Organisations running these products should prioritise immediate patching. (src: The Hacker News)
- Windows passkeys stealable by impersonating a new iPhone. A demonstrated attack dubbed "Pass-ta-key" shows that Windows passkeys can be stolen without hacking anything — simply by pretending to be the owner's new iPhone. This undermines the phishing-resistant promise of passkeys and highlights registration-flow weaknesses. (src: SecurityLab)
- AI API flaw exposed hidden reasoning and secrets across OpenAI, Anthropic, and Google. A weakness in how hidden AI reasoning was carried between API calls let researchers recover internal chain-of-thought traces, including API keys and passwords, from session logs. All three providers were affected. This was first reported today. (src: The Hacker News)
- MyDr hospital system breach could reach 18.8 million victims. The scope of the MyDr hospital system compromise continues to expand, with potential victim counts reaching 18.8 million people — though MyDr has reportedly not yet acknowledged the full extent. This was first reported today. (src: SecurityLab)
- Windows SYSTEM-privilege zero-day via single system driver, linked to Lazarus. A zero-day at the heart of Windows allows attackers to gain SYSTEM privileges through a single system driver. The arsenal is attributed to the North Korean Lazarus group, indicating state-level exploitation. (src: SecurityLab)
- PT identifies four August vulnerabilities already exploited in the wild. A monthly digest from Positive Technologies highlights four vulnerabilities from August patches that are already being actively exploited, reinforcing the need for rapid patching of high-profile CVEs. (src: SecurityLab)
- Picus Blue Report 2026: enterprise edge defenses hold, interior collapses. Analysis of 338+ million attack simulations shows enterprises are tuned to catch noisy attacks but attackers are now winning by making none. Internal segmentation and detection gaps remain the primary failure point. (src: The Hacker News)
- Signal adds automatic key verification to thwart MITM attacks. Signal introduced Automatic Key Verification, giving users a built-in mechanism to ensure encrypted chats haven't been intercepted — a meaningful defensive improvement for the mainstream encrypted-messaging platform. (src: BleepingComputer)
Themes
Patch-and-pounce cycle accelerates: SharePoint PoC, ShieldBreak Defender bypass, and Adobe CVSS 10.0 fixes all dropped within the same Patch Tuesday window, and attackers are exploiting the gap between disclosure and remediation faster than ever. The PT digest confirming four August CVEs already exploited underscores that "patch within 30 days" is no longer a viable SLA.
Authentication assumptions challenged: The passkey theft via iPhone impersonation and the AI API reasoning leak both demonstrate that systems marketed as "phishing-resistant" or "secure by design" still have trust-boundary flaws that can be exploited without traditional hacking techniques.
