Threat Brief — 2026-08-13 — Hack-back green light, Patch Tuesday heat
Patch Tuesday dominates the operational agenda: 421 Microsoft fixes including three zero-days, one already wielded by Lazarus. SharePoint exploitation continues to escalate with a new CVE surfaced. On the policy front, the White House has signed a memo authorising private firms to apply for approval to conduct offensive operations against foreign cybercrime groups — a significant shift in U.S. cyber posture.
Top items
- Microsoft August Patch Tuesday — 421 vulns, 3 zero-days, Lazarus active. August's batch includes CVE-2026-68820KEV, a zero-day already exploited in the wild by the North Korean Lazarus group. With 421 total fixes, patching prioritisation is urgent. This develops the story first reported 2026-08-12 by BleepingComputer. (src: xakep)
- SharePoint RCE (CVE-2026-55040KEV) — auth bypass to admin impersonation, exploit publicly available. This CVSS 9.1 flaw allows attackers to bypass SharePoint login and impersonate an administrator. The vulnerability has been exploited in ransomware attacks since the ongoing story was first reported 2026-08-12 by BleepingComputer. (src: securitylab-ru)
- Adobe Commerce (Magento) — 7 patched, 5 critical, including passwordless account hijack. CVE-2026-71362KEV allows accessing another user's account without credentials. Adobe has now confirmed seven total vulnerabilities with five rated critical, expanding on the initial account-hijack report first published 2026-08-12 by BleepingComputer. (src: securitylab-ru)
- White House memo authorises private-sector offensive hack-back. A presidential memo instructs the National Coordination Center to create a program allowing private security firms to apply for approval to hack foreign cybercrime organisations. This represents a major shift in U.S. offensive cyber policy and could reshape the private-sector threat landscape. (src: bleepingcomputer-main)
- Jewelbug APT — state espionage and cryptocurrency theft from a single panel. A hackers-for-hire group is blending nation-state espionage with financially motivated cryptocurrency heists, operating both from the same web infrastructure. This dual motive makes attribution difficult and increases the range of potential targets. (src: darkreading-all)
- Malicious SIM can open browser on locked smartphone. A SIM card can execute commands that open a browser even when the screen is locked, effectively reverting the device to a 1990s-era attack surface. This extends the malicious-SIM attack story first reported 2026-08-12 by The Hacker News from EV chargers to smartphone exploitation. (src: securitylab-ru)
- Devman extortionist profiled — from rookie to Interpol-wanted. A long-form investigation traces the evolution of an extortionist who proactively contacted a researcher, eventually becoming an Interpol-wanted criminal. Offers insight into extortion-group operational security and psychology. (src: xakep)
- WhatsApp deploys local ML-based "Scam Alert" feature. A new optional feature uses on-device machine learning to flag potential scam messages to users. Relevant for organisations using WhatsApp for business communications. (src: bleepingcomputer-main)
Themes
Offensive shift: The White House hack-back memo and the Lazarus zero-day exploitation underscore an increasingly aggressive landscape where both state and private actors are escalating offensive operations.
Patch fatigue mounting: August is delivering heavy patch loads across Microsoft (421), Adobe Commerce (7), and the already-exploited SharePoint and Magento flaws — teams must triage ruthlessly, prioritising known-exploited CVEs first.
Blurred motives: Jewelbug's simultaneous espionage and cryptocurrency theft, combined with the Devman extortion profile, highlight that threat actors increasingly blend state and criminal objectives, complicating defence and attribution.
