Targeting identity, AI risks, Breaches, and Critical Patches

by | Sep 2, 2026 | Security Alerts | 0 comments

Five things stood out this month in security news, and many shared a common theme: attackers are increasingly targeting the people, identities, software and systems we already trust.

  • Identity remains a primary target. Attackers are increasingly targeting passkeys, trusted devices, sessions and even the processes we use to verify employees.
  • AI is becoming a privileged attack surface. As AI gains access to files, applications and authenticated accounts, organizations need stronger controls over what agents can access and do.
  • Trusted software remains a path to compromise. August attacks demonstrated how malicious code can reach businesses through software packages, browser extensions and third-party services.
  • Cyber incidents increasingly disrupt operations, not just data. August attacks affected manufacturing, order processing, shipping and other critical business functions.
  • Patching is becoming a continuous requirement. Hundreds of vulnerabilities were addressed across Microsoft, Google, Apple, Adobe, Nvidia, Zoom and other widely used platforms.

Here’s what happened, why it matters and what to do.

  1. Several headlines in August remind us that identity remains one of the most important attack surfaces, and attackers are targeting every part of the trust process.
  • Researchers demonstrated attacks in which malware or an already-compromised Windows session could abuse passkey implementations, including Google-synced passkeys, Windows Hello and previously generated authentication material. Importantly, they did not break the underlying passkey cryptography. They attacked the systems surrounding it. link
  • A commercial phishing toolkit advertised the ability to complete a victim’s authentication and then enroll an attacker-controlled passkey, potentially providing persistent access even after the victim changes their password. link
  • Wiz documented attackers using compromised identities to register rogue devices in Microsoft Entra ID. An attacker-controlled computer could then appear trusted and potentially satisfy Conditional Access requirements. This affected nearly one in seven Entra environments it examined over a 90-day period. link
  • A July 31 multinational alert published by the FBI warned that North Korean IT workers are using false identities, forged identification, proxies, VPNs, laptop farms and AI to obtain legitimate employment. Once hired, they can receive legitimate corporate credentials and access. link

What do I need to do? Treat identity security as more than MFA. Secure endpoints, monitor new device and credential enrollment, and have a process to quickly revoke suspicious sessions and access. HR and the hiring process must be part of your cybersecurity controls.

  1. AI agents are becoming privileged users.

At Black Hat USA, researchers demonstrated how untrusted content, including GitHub issues, emails and web pages, could manipulate AI coding tools and browser agents. In some demonstrations, this could expose information or cause actions to occur through systems where the user or AI agent was already authorized. link

As AI moves from answering questions to accessing files, writing code and taking actions, the potential impact of a compromised or manipulated AI agent increases significantly. link

What do I need to do? Define what AI agents can access, what actions they can take and whose authority they are using. Organizations also need monitoring and a reliable way to quickly revoke an agent’s credentials, sessions and permissions if something goes wrong.

  1. Trusted software continues to provide attackers a path into organizations.

August brought several significant supply-chain attacks involving npm packages, Chrome extensions, advertising infrastructure and software dependencies. One attack ultimately affected hundreds of packages with more than 500 million combined weekly downloads. link

These incidents are particularly challenging because a business can have patched systems, MFA, endpoint protection and trained employees and still receive malicious code through software it legitimately trusts.

What do I need to do? There is no single control that eliminates supply-chain risk, so use a layered approach:

  • Keep endpoint detection and response tools current so malicious behavior can be identified even when it originates from trusted software.
  • Maintain a software inventory or Software Bill of Materials (SBOM) for important applications, automations and dependencies. Even companies that do not develop software increasingly rely on workflows and integrations built on third-party tools.
  • Establish a process for vetting new packages and updates rather than automatically deploying every newly released version.
  1. Don’t let the steady drumbeat of breaches make them seem routine.

I counted 16 high-profile breach and cyber incident disclosures in August alone. Behind those headlines are real operational, financial, regulatory and reputational consequences.

  • Boston Scientific reported that an August 25 cyber incident disrupted manufacturing, customer order processing and product shipments for more than a week. How long could your business operate without its critical systems? link
  • McKesson confirmed that customer data was stolen in an August cyber incident, creating potential notification, regulatory, legal and reputational costs in addition to the technical response. link
  • CareCloud disclosed that information belonging to 3.7 million individuals had been exfiltrated from its AWS environment, illustrating the potentially enormous cost of investigation, notification, remediation and recovery. link

What do I need to do? As Benjamin Franklin said, “An ounce of prevention is worth a pound of cure.” Start with the fundamentals:

  • Build your security program around an established framework such as the CIS Controls or NIST Cybersecurity Framework.
  • Complete a risk assessment so you understand your greatest risks and where your resources will have the most impact.
  • Exercise your incident response plan with leadership. Even a simple tabletop exercise can identify gaps before an actual incident.
  • Review your cyber insurance coverage, including exclusions, third-party incidents and requirements for demonstrating that security controls were in place.
  1. The volume and speed of new vulnerabilities are making patch management a continuous security requirement.

Microsoft addressed roughly 400 vulnerabilities in August, including three zero-days and one already being exploited. Google patched more than 300 Chrome vulnerabilities in a single update. Apple, Adobe, Nvidia, Firefox, Zoom and Ubiquiti also released critical fixes, and some recently patched vulnerabilities were already being exploited.

Organizations need automated patching where possible, visibility into systems that fall behind and a process for quickly prioritizing vulnerabilities that pose the greatest risk.

What do I need to do? Users should install updates promptly and avoid postponing or dismissing update prompts.

Updates can also be manually installed using the resources below:

Quick Tip: Have I Been Flocked?
Find out whether your license plate has been included in a Flock camera search.

Full sourcing: August Security Alert Sources

 

Related posts

0 Comments

Submit a Comment

Your email address will not be published. Required fields are marked *