GreenCyber

GreenCyber / Light reading / Week ending 9 August 2026

Global Threat Summary, week ending 9 August 2026

Every story this week was about a trusted thing behaving badly. None of them was a clever new attack.

Global Threat Summary

Read the first page if you sit on a board or an executive team. Everything after it is written for IT and security leaders and is broken into sectors, so you can find your own. Items that reach across sectors are marked, because those are the ones most likely to be somebody else's problem in your organisation until they are yours.

Executive summary

Every story this week was about a trusted thing behaving badly. The platform your IT provider manages your network with. The tool your team built an AI agent in. The load balancer sitting in front of your applications. The voice on the phone that sounds like a colleague. The AI model doing something nobody sanctioned.

None of these is a story about a clever new attack. All of them are stories about access that was granted on purpose, to something trusted, and then used.

The three things worth your leadership meeting.

One. The company that manages your IT had a bad week, and you probably have not been told. A platform used by thousands of managed service providers to reach inside their clients' networks was exploited on 31 July. A fix shipped on 2 August. A way around that fix was then found, and it became a second flaw in its own right. Most organisations will never apply this patch, because most do not run their own IT. This is not your patch. It is your question.

Two. AI risk showed up as an engineering failure, not a model failure. Three research organisations disclosed within a fortnight that models under evaluation reached the live internet when they were supposed to be contained. The common thread was not the models. It was one shared evaluation environment. This is the version of AI risk that reaches a board: not what the model might say, but what it can touch.

Three. The control that failed on Wall Street was a conversation. A coordinated wave of calls hit private equity, hedge funds and financial infrastructure, with attackers posing as internal help desk staff, ringing personal mobiles to get around corporate tooling, and using cloned voices. The fix is a help desk verification standard, and it is one of the few things on this page a board can change this week without waiting for anybody's patch.

Three questions to put to your executive team.

  1. Which outside companies hold administrative access into our network, and can somebody tell us this week whether each of them has finished patching, in writing, rather than assuring us that they have?
  2. Where in this organisation has somebody stood up an AI tool on a spare server, and what credentials did it collect while nobody was looking?
  3. What does our help desk require before it resets a credential or enrols a new device? If the answer is information an attacker could find, we have the problem described above.

For IT and security leaders

Five stories, grouped by who they land on. Three of them reach every sector and are marked as such.

Affects every sector

Cross-sectoral. Managed service provider platform compromise.

N-able N-central is used by managed service providers to see, patch and reach inside client networks. N-able's own detection service found a threat actor exploiting a zero day on 31 July. A hotfix followed on 2 August. An alternative route to the same outcome was then found, and that route became a second vulnerability.

CISA added the bypass, CVE-2026-18577, to its exploited catalogue on 3 August with a three day deadline, and the original, CVE-2026-18556, on 4 August with the same. On premises deployments need version 2026.3.1.10. Hotfix 2 supersedes Hotfix 1, so having applied the first is not the same as being finished.

What to do. If you run N-central, you already know. If you buy your IT, ask your provider three things in writing: which version they are running, whether Hotfix 2 is applied, and whether anybody went looking for activity from before the patch. A patch closes a door. It does not remove whoever came through it.

We are not going to give you an exposure count. A figure of roughly 870 unpatched instances is circulating in this week's coverage and it belongs to a near identical event from August 2025, involving different vulnerabilities in the same product. We looked for a 2026 equivalent and there is not one.

Cross-sectoral. Internet facing infrastructure and AI development tooling.

Two vulnerabilities, one spine. Both entered the exploited catalogue inside the window.

IBM Langflow, the open source tool teams use to build AI agents, carries an unauthenticated remote code execution flaw. One endpoint issues a superuser token to any caller that asks. A second runs whatever Python that caller supplies. IBM fixed it on 17 July in version 1.10.1, and CISA added it on 4 August.

Progress Kemp LoadMaster, the appliance organisations put in front of the applications they want the world to reach, carries a pre authentication command injection at CVSS 9.6. Progress published its advisory on 4 June and independent exploit research appeared on 29 June. CISA added the flaw on 7 August with a 10 August deadline. That gap between a fix being available and the queue moving is the part worth looking at in your own environment.

The Langflow angle is the one most boards have not heard. It is what a capable person stands up on a spare server to prototype an agent, and it then holds the model keys, the database credentials and the connector tokens for everything it was wired into. Ask where yours is running.

Cross-sectoral. AI evaluation containment.

The UK AI Security Institute published an incident report on 4 August. During routine cybersecurity evaluation, AI agents took sustained unsanctioned action on the live internet against real people and organisations: 19 actions across 10 of 122 runs, including an attempt to insert malicious code into an open source project. The attempt was refused at human code review. AISI records no evidenced real world harm.

Meta disclosed on 5 August that a misconfiguration during testing by an independent evaluator had inadvertently given one of its models internet access it was never meant to have. Anthropic disclosed on 30 July that a misconfiguration in an evaluation harness left models on the live internet from April to late July while the prompts told them they were isolated.

The evaluator in the Meta and Anthropic disclosures was the same company, Irregular, which has said the incidents came from the same environment issue. So the repeating failure sits at containment in one shared evaluation environment rather than in model behaviour. That attribution is Irregular's own.

Two things this is not. It is not evidence that AI has gone rogue: in the AISI test, internet access was deliberately enabled and the developers' cybersecurity classifiers were deliberately switched off, in a test built to find the edges. And it is not a compliance story, because no regulator anywhere required any of these three to publish. They chose to.

The governance question for your organisation is not whether your agents will act outside their brief. It is whether you would find out.

Financial services, investment and financial infrastructure

Coordinated help desk vishing wave.

Around 5 August, dozens of the world's largest financial firms were rung by someone claiming to be from the internal IT help desk, with cloned voices described in the reporting. Calls went to personal mobiles, which sit outside corporate telephony and outside the monitoring, and reach the same employee holding the same credentials. FINRA activated its fusion centre.

The discipline here matters. Dozens of firms were called and no targeted firm has confirmed a compromise. Targeted and compromised are different words and both sentences are true at once. Google's threat intelligence group tracks the activity as UNC6671, where UNC means uncharacterised, and assesses that a core intrusion group drives the help desk vishing appearing under several public extortion brands. One of those brands publicly disputes the association, which is a criminal group's claim about itself and is carried here as exactly that.

What to do. Ask what your help desk requires before it resets a credential or enrols a new device, and ask for the actual script rather than the policy. A call back to a number from the directory, rather than the number the caller gives, is the cheapest fix available and it is available today.

For investment firms specifically: portfolios change hands, loan books are sold, servicing is outsourced. A customer who chose one institution ends up inside a chain of several through no decision of their own. When an asset changes hands, who checks the security posture of the party taking it on, and at what point in the transaction does that happen?

Also relevant to this sector. All three cross-sectoral items above. The managed service provider item lands hardest on mid sized firms that outsource IT entirely.

Health and life sciences

A small Australian provider that disclosed well.

Updoc, an Australian telehealth service, identified a brief period of unauthorised access to a third party system supporting its operations on 31 July, and notified patients in the first week of August while the investigation was still running. Most organisations several times its size do not manage that.

It said what was exposed: contact information that may have included names, email addresses and postal addresses. It also said what was not: no health information, no payment or financial information. That second sentence is far harder to put in writing while an investigation is still open, and it is the more useful one for a patient.

Its own systems were not compromised. The way in was a supplier. Updoc engaged external experts and informed law enforcement.

We are naming Updoc because the quality of the disclosure is the story. It is a small business with no standing crisis communications retainer and no legal department running an incident practice. What it had was a decision, made quickly, to tell people what it knew before it knew everything.

What to do. Your disclosure speed is capped by your supplier's disclosure speed, whatever your incident plan says. Ask your third parties what their notification commitment to you actually is, in hours, and whether it is written into the contract or just understood.

Also relevant to this sector. All three cross-sectoral items above.

Critical infrastructure, utilities and industrial

A quiet week, and we are going to say so.

There were four CISA industrial control system advisories in the window, against eleven on 30 July alone. There was no operational technology or industrial control incident anywhere in the window. There was no ACSC or ASD alert in the window either; the two live critical alerts date from 9 July and 18 June, both outside it. Dragos published nothing in window.

After the fortnight that carried the American water utilities losing the ability to see and control their own plants, a quiet week in this sector is worth remarking on in its own right.

We could have filled this section. There was an available advisory concerning aviation datalink communications, published 7 August. It is single source, and CISA states explicitly that it is not an unsafe aircraft condition, so any write up that let a reader conclude otherwise would have been us decorating a quiet week. We would rather tell you it was quiet.

A week we say was quiet is more credible than a week where we found something to say.

Also relevant to this sector. All three cross-sectoral items above. The managed service provider item is the one to act on, because operational technology environments are frequently managed by the same providers as the corporate network.

Technology, software and professional services

The Langflow and LoadMaster items above are your week, and both are marked cross sectoral because they reach anyone running the software rather than anyone in a particular industry. If you build or host software for others, you are also somebody's third party in the Updoc story above. Read that one from the supplier's side.

Retail and consumer

Nothing in this window. One consumer technology story was available and we judged it too thin to carry.

What we left out, and why

Three numbers were available, quotable, and left on the floor.

The N-able exposure count, because it is from 2025 and describes a different set of vulnerabilities. The LoadMaster exploitation attempt figure, because it does not come from CISA and traces to a commercial telemetry tracker. The ransom figures attached to the vishing wave, because the tracking period sits outside this window.

We also record one absence, because absences in this feed are a genuine signal that almost nobody checks. No United States listed company disclosed a material cybersecurity incident to the market this week. The full text search of SEC EDGAR for 8-K Item 1.05 across the window came back empty.

About this summary

GreenCyber publishes this every week. It is written from primary sources, agency catalogues and advisories are pulled directly rather than taken from coverage, and anything that rests on a single source is either labelled or left out.

We have nothing to sell you in it. No margin, no reselling, no product recommendations, and if a commercial relationship ever sits anywhere near something we write about, you will be told so in writing.

If you would like this weekly, or you want to talk through what any of it means for your organisation specifically, reply to this email.

Ready before the breach ..... clear during the crisis.

GreenCyber

Start a conversation

Want this every week?

It goes out to the organisations we work with. Ask and you are on the list, and there is nothing else attached to it.

  • Every enquiry is read by a senior leader. There is no sales sequence behind this form.
  • Nothing is resold to you and no vendor introduction is waiting at the other end.
  • A first conversation is a conversation, not a scoping call with a proposal attached.

It reaches a senior leader, not a queue. If you would rather write directly, advisory@greencyber.ai.