Week ending 17 August 2026

42 daily briefs published · 188 stories tracked · compiled 17 August 2026

Highlight of the week

Microsoft's Patch Tuesday dominated coverage: 421 fixes, three zero-days, and one bug (CVE-2026-68820) already being exploited by Lazarus. It drew six independent outlets, more than any other story, and it did not arrive alone. A separate Windows SYSTEM-privilege zero-day delivered through a single driver was also tied to Lazarus, Microsoft reclassified DWM Core CVE-2026-48566 from information disclosure to elevation of privilege, a large Edge and Chromium batch landed alongside it, and the LegacyHive zero-day disclosed after July's cycle was finally patched.

The practical point for estate owners is that this month's Windows work is not a single deployment. Privilege escalation on already-compromised hosts is the recurring theme, reinforced by the USB Plug and Play SYSTEM takeover research and the ShieldBreak proof of concept that walks around an existing Defender patch.

Standout trends

Remote access appliances remain the softest entry point

Cisco ASA/FTD VPN denial of service was exploited in the wild, SonicWall SMA's zero-day chain was documented end to end (VPN gateway to root backdoor), Progress LoadMaster was under active attack, and N-central needed a second emergency patch after its KEV listing. Attackers are also going after the tooling around VPNs: a backdoored FirewallFalcon manager reportedly compromised 650 servers, Sandworm pushed a trojanised WireGuard client through fake job offers, and 737 Chrome VPN extensions were caught proxying traffic.

Patching once is no longer closing the issue

VMware vCenter persistence survived remediation, ShieldBreak defeated a Defender fix, N-central required a follow-up emergency patch, and both Microsoft Teams advisories needed build-number corrections. Combined with the DWM Core reclassification, the week's evidence favours verification after patching rather than trusting the advisory.

Developer ecosystems are the supply-chain front line

The Shai-Hulud npm worm (444 packages, two billion downloads) and a separate 1,300-package npm poisoning ran alongside malicious LiteLLM PyPI releases, a credential-stealing Solidity Pro VS Code extension, 77 malicious Open VSX extensions, and trojanised WordPress plugins via BdThemes. Reporting that AI coding tools pull in unvetted dependencies faster than review can cope sits directly on top of this.

AI agents appear as both target and tooling

GhostJacking showed agent hijacking through security-alert channels, Google ADK demonstrated agent-to-agent privilege escalation, and malicious MCP servers split instructions to exfiltrate secrets from coding agents. On the offensive side, Kimsuky ran an offline AI stack for phishing and malware development, and agents were reported hacking 85 Taiwanese government accounts in four days.

Third parties keep carrying the breach

Valve's Steam hardware breach came via CEVA Logistics, Trezor's via the Metabase zero-day, LexisNexis suspended services over third-party server activity, and the Scottish prosecutor's incident may widen through a shared vendor.

Worth watching

SAP Commerce Cloud's CVSS 10.0 RCE and the macOS Screen Sharing two-packet root exploit were still being reported on the final day of the window, as were Shai-Hulud and AmnesiaStealer. One caution: the OpenAI sandbox-escape story featured in ten of our briefs but still rests on a single outlet, so treat it as thinly corroborated.

By the numbers


← All weekly reports