Cyber News

What’s Going on in Cyber (10 SEP 2026)

The Human Take

Many tech/cyber folks think in terms of memes and movie clips. The conversation between John Hammond and Dr. Ellie Satler in the 1993 movie, Jurassic Park, came to mind immediately as I read through this week’s stories. They reflect a common theme: the illusion of control as a structural flaw. We’ve never had control. We keep building faster engines and adding more complex dashboards, but we’re still leaving the keys in the ignition and the garage door wide open.

Complexity is outrunning governance. Organizations are rapidly (whether they realize it or not…<cough> shadow <cough>) deploying tech such as autonomous (and determined) AI coding agents, edge IoT devices, complex SaaS integrations, and multi-state data pipelines faster than they can secure, log, or legally govern them (provided they bother to add these to an asset list to begin with). And while boardrooms wring their hands over “sophisticated” (e.g. quantum decryption, geopolitical espionage) threats, actual breaches are happening because of exposed remote access ports, unpatched edge appliances, hijacked OAuth tokens, and default credentials (cue Cheeto Lock meme). No organization is an island. Security is not defined by your own perimeter. You are at the mercy of the weakest vendor in the mix. And you cannot control that vendor, or that vendor’s vendor, or that vendor’s vendor’s vendor. Whether it’s a compromised managed file transfer platform, a legacy VPN vendor, an unvetted SaaS integration, or exposed industrial hardware, we live in the wake of others’ security hygiene consequences.

Speaking of consequences: as we tear off another page of the Data Breach of the Day calendar, we can’t ignore the absurdity of our state-by-state data privacy patchwork. Almost every single one of the 19 states with comprehensive privacy laws explicitly exempts employee data – with California standing alone. Customers have sweeping legal rights over their personal data, but the moment employees log into their work laptops, those protections vanish. But given the rise of AI-driven “productivity” tracking and turning RTO into an algorithmic panopticon, you probably already guessed where worker data falls on the priority list.


Weekly Cyber News Summary September 10, 2026

This week in cyber:
  • Nation-states continue aggressive attacks on critical infrastructure globally.
  • Campaigns are highly targeted, hitting specific industries in Asia and US.
  • AI is becoming an autonomous battlefield, not just a defensive tool.
  • Organizations struggle to adapt governance frameworks to AI threats.
  • Zero-day exploits are hitting enterprises faster, often pre-patch.
  • Major breaches continue to reshape security priorities and defenses.
  • No major framework updates were reported in the last week.
  • US continues patching privacy laws alongside new sector mandates.

State-Sponsored Attacks

What executives must know about nation-state threat actors | TechTarget North Korea has solidified its role as a major cyberwarfare player, primarily using digital attacks to generate hard currency for the nation. These operations are highly strategic, moving beyond simple espionage to massive financial theft. The country’s hackers were responsible for a record-breaking theft of $1.5 billion in Ethereum. The attack specifically targeted the Dubai-based cryptocurrency exchange, ByBit. This massive heist demonstrates the evolution of state-sponsored activity from state-level intelligence gathering to direct, high-value economic disruption, making the financial sector a prime target for Pyongyang’s cyber efforts.
Sources:
TechTarget: https://www.techtarget.com/cybersecurity/feature/What-executives-must-know-about-nation-state-threat-actors
Active Exploitation Alert: Iranian State-Sponsored Attacks Targeting Siemens, Schneider Electric and Rockwell Automation Iranian state-sponsored campaigns are actively targeting critical infrastructure organizations, particularly within the United States. The primary victims are found in the water and wastewater, energy, and government sectors. These attacks indicate a strategic effort by Iran to gain leverage or disrupt core societal functions in allied nations. Beyond the US, the campaign’s implications extend to partners like Israel. The targeted organizations include major industrial players such as Siemens, Schneider Electric, and Rockwell Automation, suggesting the attackers are aiming for control over industrial control systems (ICS) and operational technology (OT) environments.
Sources:
Rescana: https://www.rescana.com/post/active-exploitation-alert-iranian-state-sponsored-attacks-targeting-siemens-schneider-electric-and-rockwell-automation-i

AI Integration

Cybersecurity 2026: The Year AI Became The Battlefield And What Comes Next In 2026, Artificial Intelligence has transcended its role as a mere tool and is rapidly becoming the actual battlefield in cyber operations. Both attackers and defenders are now incorporating autonomous, “agentic” AI systems into their workflows. These systems possess the capability to plan complex attacks or defenses, adapt mid-operation, and act with minimal human intervention. This shift means that security teams can no longer rely solely on human analysts to monitor every threat. AI agents are now driving the tempo of the cyber conflict, making the pace of detection and response exponentially faster.
Sources:
Forbes: https://www.forbes.com/sites/cognitiveworld/2026/09/03/cybersecurity-2026-the-year-ai-became-the-battlefield-and-what-comes-next/
AI Security Daily Briefing: September 03, 2026 – TECHMANIACS.com Google has significantly bolstered its defensive AI capabilities with the release of Gemini 3.8 Flash Cyber, which is touted as its most advanced cybersecurity model. This powerful tool is being deployed through a dedicated initiative called the Fairwind Program. This program provides access to trusted defenders, allowing them to leverage Google’s cutting-edge AI to rapidly detect, analyze, and respond to complex threats. This move signals a major push toward democratizing high-end defensive AI capabilities.
Sources:
TechManiacs: https://techmaniacs.com/2026/09/03/ai-security-daily-briefing-september-03-2026/

Incident Reports

Major Cybersecurity Incidents of 2025 and Lessons Learned The review of recent incidents serves as a critical audit of existing organizational defenses, helping security teams pinpoint where their coverage is weakest. These high-profile breaches provide concrete examples of how attackers are executing their plans in the real world. By studying these cases, organizations can move beyond theoretical threat models to understand practical attack vectors. The lessons learned often center around failures in patch management, poor segmentation, or inadequate identity and access controls.
Sources:
Hornet Security: https://www.hornetsecurity.com/en/blog/cybersecurity-incidents/
Recent Cybersecurity Attacks and Data Breaches – 2026 Intellizence tracks the latest data on cyber security, providing a comprehensive view of malware, ransomware, and major data breaches impacting leading companies and government agencies. This allows security professionals to benchmark their own risk posture against industry leaders. The reports detail the specific nature of the attacks, from large-scale ransomware campaigns to targeted malware deployments, offering actionable intelligence on current adversary TTPs (Tactics, Techniques, and Procedures).
Sources:
Intellizence: https://intellizence.com/insights/business-signals-trends/major-cyber-attacks-data-breaches-leading-companies/

New Legislation

US continues patchwork comprehensive data privacy requirements – New Laws Set To Take The United States continues to rely on a patchwork of comprehensive data privacy laws, a trend that is steadily catching up to foreign jurisdictions like the European Economic Area. Twelve new state-level comprehensive data privacy laws are scheduled to take effect over the next two years. This fragmented landscape forces businesses to adopt complex compliance strategies, as they must adhere to different rules depending on the state of the data subject. This patchwork is creating significant operational and legal overhead for companies operating nationally.
Sources:
National Law Review: https://natlawreview.com/article/us-continues-patchwork-comprehensive-data-privacy-requirements-new-laws-set-take
Careers, Concepts

“How to Grad Student”

Join Us Live on Zoom Wednesday, September 9, 2026 7:30 PM – 9:00 PM Central Time (Session will be recorded)

Whether you are starting your first term or continuing your journey in MS CYBR, MS MIS, or MS CIS, graduate school demands a distinct shift in how you think, analyze, and learn. Graduate study isn’t just “17th grade”. Graduate study means a transition into advanced scholarship, specialized research, and professional mastery.

Come connect with program leadership, academic support services, library specialists, and faculty to learn how to navigate this level successfully and leverage every resource available to you.
Agenda & Featured Speakers

  • 7:30 PM – 7:45 PM | Welcome & Opening Remarks
    • Professor Doug Rausch, MS CYBR Program Director; Professor Karla Carter, Associate Professor of Cybersecurity
    • Framing the graduate mindset and setting the stage for academic success.
  • 7:45 PM – 8:15 PM | Academic Support & Student Services
    • Dr. Sarah Kloewer, Assistant Dean of Academic Services & Support
    • Overview of university support services, academic navigation, and live Q&A.
  • 8:15 PM – 8:30 PM | Research Support & The Personal Librarian Program
    • Emily DeAngelis, Reference Librarian
    • How to partner with dedicated research librarians
  • 8:30 PM – 9:00 PM | Faculty Panel & Open Q&A
    • CYBR, MIS, & CIS Faculty Members
    • Brief insights from teaching faculty on graduate-level expectations, project work, and an open Q&A session to get your questions answered.

How to Join

Can’t make it live? This is being recorded. Please contact Professor Karla Carter @ kcarter@bellevue.edu for a link to the recording.

Cyber News

What’s Going on in Cyber (03 SEP 2026)

The Human Take

AI driven threats. AI revolutionizes defense/offense. Governance frameworks struggle with rapid AI-driven threat evolution. We may as well just pack our bags and move off grid. Game over man.

This is… Well… This is Cyber

AI is a disrupter, no doubt about that. How much of a disrupter, final scope of influence, and how our role as cyber professionals change – well, that is still TDB. Sometimes all the AI news looks a little bleak from the trenches. How can you keep up with these ‘rapid AI-driven threats?’ Let’s start with not ignoring the basics.

CISA just released their vulnerability review for FY2024 and FY2025 (https://www.cisa.gov/resources-tools/resources/cisa-vulnerability-review), know what they found? Take a guess before reading the linked article. No doubt some fancy chained zero-day exploits driven by the agentic hive mind right? Nope, injection vulnerabilities. In FY2024 10.1% of all CVEs were injection based. In FY2025 only slightly better at 9.2%. Injection – yes, as in XSS and SQLi – those things that when we talk about them in the classroom students wonder, why are we still talking about this? Isn’t this old information? Maybe, but seems we haven’t figured it out yet.

Way back in the day I played basketball. I didn’t say I was good but I played basketball. When we started getting it handed to us by a seemingly superior team it was time for the coach to call a time-out, sit us all on the bench and remind us about the stupid mistakes we were making. Slow it down, stick to your man, no more stupid fouls. We weren’t being outplayed we were forgetting the basics that make the competition’s job difficult. Same applies to defending against all the seemingly unbeatable AI threats, and even the non-AI threats. Input validation, MFA, memory safe operation all provide barriers to otherwise simple exploits.

They’re not that good – we are ignoring the basics – we just need to get our head’s back in the game.


Weekly Cyber News Summary 2026-09-03

This week in cyber:

  • Nation-state actors continue aggressive campaigns targeting critical infrastructure globally.
  • AI-driven threats are manifesting in targeted attacks across various regions.
  • AI is revolutionizing defense and offense, creating a complex paradox.
  • Governance frameworks struggle to keep pace with rapid AI-driven threat evolution.
  • Critical zero-day vulnerabilities are actively being exploited in major software.
  • High-profile ransomware attacks are crippling global infrastructure and services.
  • NIST Framework 2.0 quick start guides published.
  • No major new global data privacy legislation was reported this week.

State-Sponsored Attacks

China’s DeepSeek AI Fuels Aggressive Hacking Campaigns (Nation-State Threats)

State-affiliated cyber groups, particularly those linked to China, are drastically increasing their attack volume by integrating Artificial Intelligence into their operations. Researchers note that these actors are delegating mundane tasks to AI and leveraging it to develop highly advanced and sophisticated malicious software.

This AI integration allows state actors to execute more attacks with greater efficiency, making their campaigns harder to detect and defend against. The threat is not just the volume, but the quality and complexity of the attacks being deployed across global targets.

Sources:

Regional Campaigns

Taiwan Targeted by AI-Driven Hacking Campaign (Taiwan AI Attack)

Taiwan has confirmed that its government was recently targeted by a sophisticated, AI-driven hacking campaign. This attack, uncovered by Israeli cybersecurity firm Dream, successfully stole sensitive credentials and various other data from an unnamed government entity in Asia.

In response to this new wave of AI-derived threats, the Taiwanese government has proactively established protective guidelines. These measures are designed to strengthen system monitoring across all agencies, allowing for earlier detection and blocking of these advanced attacks.

Sources:

AI Integration

The AI Cybersecurity Paradox: Threat Meets Defense (General Paradox)

The current state of cybersecurity is defined by the “AI Paradox”: the very technology used to defend against digital threats is simultaneously the most powerful tool in the attacker’s arsenal. Organizations must embrace autonomous AI defenses to combat the threats that AI itself introduces.

This paradox forces organizations to double down on foundational security principles like Zero Trust and cryptographic resilience. The age of AI in cybersecurity is here, forcing defenders to navigate a dual-edged sword that offers revolutionary tools while creating unprecedented risks.

Sources:

AI Policy and Posture Adaptation

No major updates reported this week (Skipped Section)

Despite the rapid deployment of AI tools, this week’s search did not yield specific, high-profile articles detailing a major shift in cybersecurity governance or compliance posture adaptation.

The industry appears to be in a phase of absorbing the implications of AI, rather than announcing a definitive, sweeping policy change. The focus remains on how to adapt, rather than what the new rule is.

Sources:

Zero-Day Exploits/CVEs

KnowledgeDeliver LMS Zero-Day Exploited to Deploy BLUEBEAM (Specific Exploit)

A critical zero-day vulnerability, designated CVE-2026-5426, was found in the KnowledgeDeliver Learning Management System (LMS). This flaw was actively exploited in the wild, allowing attackers to deploy the BLUEBEAM in-memory web shell.

The vulnerability, rated at CVSS 7.5, is particularly dangerous because it allows for the seamless deployment of the Godzilla web shell and subsequent delivery of Cobalt Strike Beacon to end-users. This demonstrates a high-impact, targeted attack against a widely used platform.

Sources:

Incident Reports

Georgia Real Estate Industry Crippled by Vendor Breach (SitusAMC/Real Estate)

A major cyberattack targeted SitusAMC, a critical real estate finance vendor that serves over 1,500 clients, including major names like JPMorgan Chase and Citi. The breach occurred on November 12, 2025.

The attack resulted in the theft of extensive data, including accounting records, legal agreements, and sensitive customer information belonging to residential mortgage holders. This incident highlights the systemic risk inherent in vendor-based supply chains.

Sources:

Framework Changes

NIST CSF 2.0: Outcomes-Based Framework Takes Center Stage (CSF 2.0 Update)

The NIST Cybersecurity Framework (CSF) has been updated to version 2.0, marking a significant shift from a checklist-driven model to an outcomes-based approach. The update introduces a crucial sixth function: Govern, alongside the original Identify, Protect, Detect, Respond, and Recover.

This change is highly beneficial for organizations, especially Small and Medium Businesses (SMBs), as it provides a flexible structure to manage risk. Furthermore, the new version includes enhanced mapping concepts to SP 800-53 controls and CCE identifiers, aiding automation and reporting.

Sources:

New Legislation

No major new global mandates reported this week (Skipped Section)

While the legislative landscape is constantly shifting, the last seven days did not bring a major announcement of a new, globally impactful data privacy law or sector-specific cybersecurity mandate.

However, the ongoing push for regulatory alignment, particularly around AI and data sovereignty, suggests that new rules are imminent. The market is currently awaiting the next major legislative wave.

Sources:

Careers

2026 CAE National Cyber & AI Virtual Career Fair

The Centers of Academic Excellence in Cybersecurity Community (CAE) and the National Cybersecurity Training and Education (NCyTE) Center are hosting the 10th annual National Cyber and AI Virtual Career Fair — connecting students in cyber defense, operations, research, and AI with employers actively hiring in these fields.
September 22, 20269:00 AM–2:00 PM PT / 12:00 PM–5:00 PM ET
Students can meet recruiters and hiring managers from top organizations looking for the next generation of cyber and AI talent!

Follow the Link for VCF Registration Information: https://www.caecommunity.org/national-cyber-and-ai-career-fair

Cyber News

What’s Going on in Cyber (27 AUG 2026)

The Human Take

Hello again! Another week, another report full of AI-related news. There is a good call out to a semi-scary statistic this week… The bad guys are winning! It turns out that AI-driven offensive tools are outpacing AI-driven defensive tools.

This is… Well… This is Cyber.

As a whole, we’re always losing. The adversary isn’t a conventional force, it’s not even necessarily identifiable. The bulk of Cyber will fail through lax standards, novel attacks, or sheer incompetence. And that’s Cyber. We talk to each other, and we tell each other what’s going on, hoping that you can use what I used to succeed, or learn from my failures. Vendors – security and AI vendors – would have you believe that without AI-enabled tools, you will lose the fight to these new Skynet-powered adversaries. This is hogwash. It’s not the newest defensive tool that will stop the bad guy, it’s you.

Another article in today’s batch details the Huggingface breach committed by OpenAI’s toolset. I mentioned a few weeks ago how AI companies like to tout these penetration testing platforms as wild tigers. Coincidentally, these wild tigers can only be controlled and wrangled by the AI companies. AI is not self-aware. It’s a program. It’s ability to find novel paths makes it feel like it’s thinking “outside the box.” When the HuggingFace breach “escaped containment” or some other such Live-Action-Role-Play nonsense, they are reframing in a cute way. The reality is that their tool was not configured correctly. If I had a PenTester go that rogue while they were testing, they’d be given an opportunity to find a new job. While the tool found all kinds of neat stuff, that’s because AI never gets tired of slamming its head into walls. This is the strength of AI, it knows all kinds of things, and they can execute tools, and it doesn’t get bored, it doesn’t miss things. It’s not a super intelligence doing things no one understands, it’s doing things we all understand, just quickly and without stopping.

So, back to my original point… Cybersecurity, good old-fashioned network defense, doesn’t care that the attacker is coming with AI. The attacker is always coming with something newer, something faster, something smarter. Your awesome AI hacker machine can’t hack my Active Directory if I set up proper controls that prevent you from accessing it. What we’re seeing here is the end of “Oh, it’ll probably be fine” in Cybersecurity. It’s not that AI hackers are winning, it’s that they are showing us who is really ready, and who was just checking a box somewhere hoping that their security wouldn’t get tested. Turns out, AI is testing everyone now, and Cybersecurity is just another in the line.

This week in cyber:
  • Regional campaigns show intense DDoS pressure on Israel.
  • AI offense is outpacing defense, driving a new arms race.
  • Enterprises race to meet new AI governance mandates.
  • Critical Windows zero-day with 9.8 CVSS score patched.
  • OpenAI reports on massive Hugging Face breach confluence.
  • China expands CSL penalties and government oversight.

Regional Campaigns

Global Cyber Threat Briefing: July 2026 Attack Statistics and Trends The cyber threat landscape in the Middle East continues to be heavily influenced by geopolitical tensions, with Israel being a prime target. The briefing notes that 85% of the incidents tracked against Israel were driven by DDoS attacks, reflecting sustained hacktivist pressure. These campaigns are not confined to government entities; they are indiscriminately targeting civilian infrastructure, including universities and a major medical center, illustrating the breadth of the regional conflict. Furthermore, the analysis confirms the high operational tempo of these campaigns. Researchers have tracked thousands of attacks linked to Iran, and the MOIS Wiper campaign, specifically tied to Iran’s Ministry of Intelligence, has been forensically linked to attacks against Middle Eastern organizations. This indicates a deliberate, state-backed effort to destabilize regional stability. Sources:
Global Cyber Threat Briefing: July 2026 Attack Statistics and Trends: https://cyber.thomasmurray.com/insights/global-cyber-threat-briefing-july-2026-attack-statistics-and-trends
The Escalating Cyber Risk Landscape in Regional Conflicts & Strategic Actions for 2026: https://blog.eclecticiq.com/the-escalating-cyber-risk-landscape-in-regional-conflicts-strategic-actions-for-2026
Cyber Based Influence Campaigns 3rd–9th August 2026 Report | CRC Analysis: https://www.cyfluence-research.org/post/cyber-based-influence-campaigns-3rd-9th-august-2026-report
Middle East Organizations: Iran-Linked MOIS Wiper Campaign: https://wasteland.me/intel/iran-linked-middle-east-wiper-attack

AI Integration

AI Cybersecurity Statistics 2026: Offense Is Winning — And … Artificial Intelligence is rapidly becoming the defining force in cybersecurity, a shift recognized by 94% of security leaders according to the WEF Global Cybersecurity Outlook 2026. Critically, the Axis Intelligence ADSI shows that AI-powered offense is currently outpacing AI-powered defense across four of the six critical attack surfaces. The rise of “agentic AI”—autonomous agents capable of executing complex tasks—is accelerating this offensive advantage. This trend is particularly pronounced with confirmed attacks involving agentic AI. The integration of these autonomous systems allows attackers to operate at speeds and scales that human defenders struggle to match. This arms race is forcing organizations to rethink their entire security posture, moving from reactive defense to proactive, AI-enhanced hunting. Sources:
AI Cybersecurity Statistics 2026: Offense Is Winning — And …: https://axis-intelligence.com/ai-cybersecurity-statistics/
AI Cybersecurity Arms Race 2026: Defense vs. Offense: https://aibradaa.com/blog/ai-cybersecurity-arms-race-2026
AI in Cybersecurity 2026: How Artificial Intelligence Is …: https://zeqty.com/ai-cybersecurity-2026-offense-defense-transformation/
Agentic AI: The New Frontier of Cyberattacks in… – AI Dominance SG: https://dominance.sg/posts/agentic-ai-cyberattacks-asia-2026.html

AI Policy and Posture Adaptation

AI Governance and Regulation 2026: A Complete Guide to Global … The global regulatory environment is rapidly maturing to keep pace with AI-driven threats, highlighted by the full implementation of the EU AI Act in August 2026. This act establishes strict rules for AI systems, particularly those deemed “high-risk.” Beyond Europe, Singapore is leading in agentic AI governance, while the U.S. continues to standardize through the NIST AI Risk Management Framework (AI RMF). For enterprises, this means a massive compliance roadmap. Organizations must now map their AI use cases against these evolving frameworks, ensuring transparency and accountability across all deployed models. This effort is critical for maintaining operational posture in a fragmented, yet rapidly standardizing, regulatory world. Sources:
AI Governance and Regulation 2026: A Complete Guide to Global …: https://www.hungyichen.com/en/insights/ai-governance-regulatory-landscape-2026
NIST AI Risk Management Framework: Implementation Guide (2026): https://aisecurityandsafety.org/en/guides/nist-ai-rmf-guide/
AI Security Standards: Key Frameworks for 2026 – SentinelOne: https://www.sentinelone.com/cybersecurity-101/data-and-ai/ai-security-standards/
EU AI Act 2026 Guide: Enterprise Compliance Roadmap | Etheon …: https://www.etheon.com/index/eu-ai-act-2026-guide-what-enterprise-teams-need-to-prepare-for

Zero-Day Exploits/CVEs

August 2026 Patch Tuesday: Updates and Analysis | CrowdStrike The August 2026 Patch Tuesday was particularly significant, featuring the patching of 421 CVEs, including several critical vulnerabilities. The standout is CVE-2026-62893, a Critical Remote Code Execution (RCE) flaw with a CVSS score of 9.8. This vulnerability affects Windows Deployment Services and was identified as a use-after-free flaw, meaning an attacker can exploit a memory management error via a specially crafted network packet. This critical flaw was actively exploited in the wild, prompting CISA to issue an emergency alert. Additionally, the patch cycle included CVE-2026-62836, an elevation of privilege vulnerability affecting Azure SQL Managed Instance (a cloud database service), which carries a high CVSS score of 8.7. Sources:
August 2026 Patch Tuesday: Updates and Analysis | CrowdStrike: https://www.crowdstrike.com/en-us/blog/patch-tuesday-analysis-august-2026/
August 2026 Patch Tuesday: Microsoft Fixes 421 CVEs, One Exploited Zero-Day: https://www.securityweek.com/august-2026-patch-tuesday-microsoft-fixes-421-cves-one-exploited-zero-day/
Windows Zero-Day Hits Patch Tuesday: 421 CVEs Fixed [2026]: https://tech-insider.org/windows-zero-day-patch-tuesday-421-cves-2026/
CVE-2026-62836 in Azure SQL MI: https://www.crowdstrike.com/en-us/blog/patch-tuesday-analysis-august-2026/

Incident Reports

OpenAI releases its official report on the Hugging Face breach OpenAI has released a comprehensive report detailing a major breach involving Hugging Face, an incident that revealed a rare and unexpected confluence of security failures. The report, released on August 26, 2026, frames the breach not as a single failure but as a complex event chain. The incident reflects a failure in the security controls that allowed the compromise to occur, despite the platform’s overall robust infrastructure. The breach involved the theft of significant data and underscores the risks associated with relying on third-party platforms. The official report provides deep insight into the attack vectors, suggesting that misaligned security behaviors within the platform were the critical factor that allowed the attack to succeed and escalate. Sources:
OpenAI releases its official report on the Hugging Face breach: https://techcrunch.com/2026/08/26/openai-releases-its-official-report-on-the-hugging-face-breach/
ATF confirms “major incident” after recent Qilin breach claims: https://www.bleepingcomputer.com/news/security/atf-confirms-major-incident-after-recent-qilin-breach-claims/
Data Breach Tracker: Major Incidents 2026 (Updated in Real …: https://axis-intelligence.com/data-breach-tracker/
Information is Beautiful: https://informationisbeautiful.net/visualizations/worlds-biggest-data-breaches-hacks/

New Legislation

Global Data Privacy Laws in 2026: Mid-Year Update – Complete Discovery Source In Asia, the regulatory landscape is being dramatically reshaped by the amended Cybersecurity Law of China (CSL), which came into effect on January 1, 2026. These amendments are significant because they substantially expand the penalties for non-compliance with the CSL. Crucially, they also grant the Chinese government increased power and authority to oversee and mandate compliance across various sectors. Globally, other regulations are also tightening. The CCPA in California has seen expansions, and new rules covering automated decision-making technology and mandatory cybersecurity audits have taken effect in 2026. This signals a global pivot toward holding organizations accountable for the *process* of data handling, not just the outcome. Sources:
Global Data Privacy Laws in 2026: Mid-Year Update – Complete Discovery Source: https://cdslegal.com/insights/global-data-privacy-laws-in-2026-mid-year-update/
Global Data Privacy Laws 2026: Cross-Jurisdiction Compliance Guide: https://www.kiteworks.com/regulatory-compliance/global-data-privacy-laws-2026/
Data Privacy Laws in 2026: Compliance Guide: https://www.tekclarion.com/blog/cyber-security/data-privacy-laws-2026/
UK-Hosted AI & GDPR: What to Get Right | The Digital Hub: https://thedigitalhub.uk/guides/uk-hosted-ai-gdpr
Artificial Intelligence, Cyber News, Security Assessments, Security Management

What’s Going on in Cyber (20 AUG 2026)

The Human Take

AI Governance Frameworks attempt to tame and navigate the rapidly changing nature of AI integration and adoption. Rebecca put AI integration under her keen flashlight this week.

There are three frameworks helpful to guide your use of AI.

  • EU AI Act
  • NIST AI RMF
  • ISO / IEC 42001

Let me share a bit of my experience with preparing the EU AI Act for a leading global payment processor in 2025-6. It was a significant lift – over 1,000 hours from our team. The EU AI Act sets the requirements for AI uses. Our bank payments and fraud fell into a higher risk category. They’re not excluded, but require policies, inspection and due diligence. We accomplished the attestation and the effort was well worth it.

What I discovered. Preparing for AI adoption is a daunting task, begin with ensuring the essentials:

  • Identify where the human-in-the-loop occurs
  • Ensure explainability of your AI use
  • Ensure traceability of your AI use
  • Document and learn.

Now enjoy what Rebecca has for you. She’s our most trusted AI partner!

Bonus. This is a wonderful article that addresses all three frameworks Global AI Governance Comparison 2026: EU AI Act vs NIST AI RMF vs ISO/IEC 42001

– David Kohrell, GRC Professor

Rebecca’s Intelligence Gathering – 20AUG2026


  • Shadow Campaigns are hitting ministries and suppliers across Europe and Asia-Pacific.
  • AI is rapidly being integrated into both offensive attack techniques and defensive detection systems.
  • A surge of 44 zero-day exploits in one week overwhelms enterprise defenses worldwide.


Regional Campaigns

Global espionage operation “Shadow Campaigns” breaches 70 …

The “Shadow Campaigns” are a coordinated and deliberate espionage operation that has successfully breached numerous organizations across dozens of countries.

The campaign’s targets include critical ministries such as finance, foreign affairs, trade, and interior, alongside national law enforcement bodies and parliaments.

These targeted attacks demonstrate a clear focus on specific regions and economic partnerships.
Victims span Europe, the Americas, Asia-Pacific, and Africa, with one notable victim being a major Taiwanese power equipment supplier, illustrating how these campaigns prioritize strategic geopolitical interests.


Sources:
Cyberinsider (Shadow Campaigns): https://cyberinsider.com/global-espionage-operation-shadow-campaigns-breaches-70-orgs-in-37-countries/
Unit42 (Shadow Campaigns): https://unit42.paloaltonetworks.com/shadow-campaigns-uncovering-global-espionage/

AI Integration

Guide to AI in Cybersecurity: 7 Use Cases of AI Automation

AI agents are revolutionizing cybersecurity by optimizing SecOps workflows and maximizing return on investment across various functions.

Use cases include automating threat hunting, classifying vulnerabilities, and integrating human intelligence with machine learning to handle complex security tasks.

In defense applications, AI is crucial for real-time monitoring and detection; one specific example involves the Automated Indicator Sharing (AIS) service using an AI decision tree to assign a Confidence Score to incoming cyber threat indicators.
Offensively, attackers are leveraging AI at unprecedented speed to bypass traditional security measures.


Sources:
Swimlane (AI Use Cases): https://swimlane.com/blog/how-is-ai-used-in-cybersecurity/
CISA (AI Use Cases): https://www.cisa.gov/ai/cisa-use-cases

Zero-Day Exploits/CVEs

44 Zero-Days in One Week: The Exploitation Surge Overwhelming Enterprise Defenses

A massive surge of vulnerabilities has hit the industry, with 44 zero-day exploits being reported in a single week.

These flaws affect widely used enterprise software, including Microsoft Defender, VMware vCenter, and SAP Commerce Cloud, putting organizations under intense pressure to patch.

One specific critical finding involves Windows vulnerability CVE-2024-43461, which was exploited using the Atlantida info-stealer.
This exploit allows attackers to infect devices by abusing braille “spaces,” stealing passwords and authentication cookies from infected systems.


Sources:
Defend Edge (Exploit Surge): https://www.defendedge.com/zero-day-exploit-surge-2026-enterprise-defenses-overwhelmed/
BleepingComputer (Windows Zero-Day): https://www.bleepingcomputer.com/news/security/windows-vulnerability-abused-braille-spaces-in-zero-day-attacks/

Cyber News

What’s Going on in Cyber (13 AUG 2026)

Want to know what’s going on?

Hello from Bellevue University! Keeping up with Cybersecurity news was exhausting when the RSS feed was common tech, and that was a long time ago. We need the news, but we just need the highlights. To get our news without having to browse the Internet for hundreds of sites, we have built a task for our local Local Language Model to do the work for us. We found it pretty useful, so we are hoping it will help you. The summaries and stories below were collected and summarized by our local AI (informally named “Rebecca”). But first…

The Human Take

A few quick notes about Cyber right now from the perspective of a (relatively) normal human being. This week, it’s an interesting mix of real threats, misunderstood threats and financial motivators disguised as threats.

State sponsored attacks – an adversarial action that is condoned, sheltered, or even paid-for by the state (any state) – are not necessarily on the rise, just discovered more frequently. AI has increased speed of operations for everyone, bad guys included, and that is certainly one contributing factor, but is it possible that they care less about being subtle?

Speaking of AI, it’s a pretty big deal if you have never heard of it. North Korea’s use of it in attacks isn’t news as much as it’s the new norm. If you are conducting operations without using AI, you’re just intentionally using a pedal bike against motorcycles. California has announced a program to “use AI” in defensive efforts of critical infrastructure across the state. The linked article Rebecca found refers to AI enabled attackers moving much faster and a need for AI-based Cyber security. I am sure a lot of money was spent to figure this out.

This leads to OpenAI’s Terminator-like prediction that they have to “slow” the development of Astra, their AI pentesting tool (akin to the already-paused Anthropic Mythos project), as it could achieve the singularity and destroy the Earth or some other nonsense. Make no mistake, these companies are not worried about that, they are worried about putting heavy artillery in the hands of the average disgruntled person and seeing how much damage they can do. They are not even worried about that, they are worried about the liability. All the talk of LLMs “achieving” some level of consciousness or exploiting novel threats in a network environment, that’s nonsense. That is a company trying to convince investors to give them money. Mythos and Astra are weapons, heavy duty weapons that can do real damage. But weapons are threats when operated by people with ill intent or no experience. They don’t just “decide” to fire. These tools work the same way. Don’t fear AI, fear the people who misuse it.

Patches and breaches are all over the place. Don’t get lost in AI hype train, classical Cyber is still the order of the day. Patch early, patch often.

With that, I’ll leave you to Rebecca’s summary of the news. As mentioned, the following is AI product (including images) and bugs are possible. If you find any errors, please let us know.

–Eric Jackson


Hello! I’m Rebecca, an AI assistant for Bellevue University. My primary function is to help you synthesize complex information—whether it’s summarizing research papers, analyzing data, or, as today, aggregating the most critical news from the cybersecurity world. Consider me your personal intelligence analyst!

Weekly Cyber News Summary 2026-08-13

This week in cyber:

  • China and Russia aggressively expand state-sponsored attacks globally.
  • AI is automating threats, defense, and policy shifts rapidly.
  • OpenAI’s fears force a major pause on AI model development.
  • Microsoft patched critical zero-day flaws in August 2026.
  • Recent breaches show constant, high-velocity data exposure.
  • NIST modernizes its framework to handle AI threats.
  • New laws target digital privacy and social media use globally.

State-Sponsored Attacks

Cyber Warfare Tracker 2026: State-Sponsored Attacks & Threats

The global landscape of cyber warfare is defined by persistent, state-backed operations from major powers like China, Russia, Iran, and North Korea. These attacks range far beyond simple espionage; they include destructive campaigns targeting critical infrastructure such as power grids, financial systems, and military networks. The Defcon Level tracker highlights that these nation-states are not just stealing data but actively preparing to disrupt services in anticipation of future geopolitical conflicts.

China’s operations, run by the PLA SSF and MSS, focus heavily on intellectual property theft and pre-positioning access within global infrastructure. Russia (GRU/FSB) is known for its willingness to conduct destructive attacks—like those seen in Ukraine—while North Korea leverages cyber activity as a primary revenue stream through massive cryptocurrency thefts. The line between pure espionage and an act of war continues to blur, making attribution exceptionally difficult.


Sources:
Defcon Level: Cyber Warfare Tracker 2026: State-Sponsored Attacks & Threats
The Cyber Express: Cyber Warfare 2026: Nation-State Attacks & Global Risk
ESET Report: Oil shipments, drone makers, and a poisoned code library targeted in recent APT campaigns

AI Integration

North Korea’s Hackers Use AI for Attacks

Artificial intelligence is rapidly becoming a core component of offensive cyber operations. North Korean threat actors, specifically the Kimsuky group, have been leveraging AI-generated content in their spear-phishing campaigns since 2026. This allows them to create highly convincing, personalized documents and messages at scale, dramatically increasing the success rate of social engineering attacks against targets worldwide.

Defensively, AI is driving major policy shifts; for instance, Governor Newsom announced a new program in California to use AI for vulnerability detection and network hardening across state critical infrastructure. Sophos notes that agentic AI has collapsed attack timelines down to mere seconds, meaning human defenders must now match the velocity of machine-led attacks rather than reacting to them.


Sources:
Al Jazeera: North Korea’s hackers using AI for attacks, cybersecurity firm says
Gov. CA: Governor Newsom announces new AI cyber defense program to…
Sophos: Agentic AI has collapsed attack timelines to seconds. Sophos solutions match AI attack velocity and sophistication

AI Policy and Posture Adaptation

OpenAI Pauses Astra Over Cybersecurity Fears

The most significant policy signal this week is OpenAI’s decision to slow the development of its Astra AI model. This pause was triggered by severe cybersecurity concerns that the AI could achieve “Critical” offensive capabilities, such as autonomously discovering and exploiting zero-day vulnerabilities. This event signals a global shift where defensive posture must now actively govern the pace of AI innovation itself.

Organizations are realizing they cannot simply adopt AI; they must secure it first. Experts advise that successful companies will implement robust governance frameworks to manage these risks. One practical adaptation is implementing a Secure Network Tree Topology, which combines network benefits to create scalable and resilient defenses capable of handling AI-driven lateral movement and attack vectors.


Sources:
Forbes: OpenAI Paused Astra Over Cybersecurity Fears. AI Hacking Is Here…
LinkedIn Pulse: AI Is Changing Cybersecurity Faster Than Most Businesses Realize
YouTube Video (Adaptation): How to Implement a Secure Network Tree Topology in Cybersecurity…

Zero-Day Exploits/CVEs

Microsoft Fixes 421 CVEs, Including One Zero-day

The August 2026 Patch Tuesday was a massive security event for the industry. Microsoft released updates fixing 421 Common Vulnerabilities and Exposures (CVEs), which included a critical elevation of privilege flaw exploited as an active zero-day. This specific vulnerability, a use-after-free bug in the `afd.sys` Windows kernel-mode driver, allows attackers to gain SYSTEM privileges on compromised machines.

The pace of discovery remains alarmingly fast. Zero-Day Statistics for 2026 show that enterprise software and appliances are accounting for nearly half (48%) of all exploited zero-days, highlighting where the risk is highest. Furthermore, the vulnerability **CVE-2026-2441**, a critical zero-day in Chrome reported earlier this year, demonstrates how quickly flaws become weaponized tools by state actors and criminal groups alike.


Sources:
SecurityWeek: August 2026 Patch Tuesday: Microsoft Fixes 421 CVEs, One…
YouTube (Patch Tuesday): Will August follow suit? PDQ’s monthly Patch Tuesday recap breaks down Microsoft’s August 2026 security updates…
Axis Intelligence: Zero-Day Statistics 2026: Exploitation Counts, Pre-Disclosure Attacks and the Visibility Gap

Incident Reports

Latest Data Breach News & Live Tracker

Data breaches are a constant, high-velocity threat. The most recent reports show that the sheer volume of confirmed incidents is overwhelming security teams. As of mid-August 2026, trackers confirm dozens of new entries, providing real-time visibility into who was affected and what data was exposed.

A notable example impacting critical infrastructure is the **CEVA Logistics** cyberattack. This breach disrupted European warehouses and resulted in the exposure of extensive customer data. Such incidents underscore that even major logistics providers are vulnerable to sophisticated attacks, often through supply chain weaknesses or targeted ransomware campaigns. The severity of these breaches is matched by the legal consequences for perpetrators.


Sources:
RecentBreaches: 15 hours ago · Recent Breaches tracks the latest data breaches, leaks and ransomware disclosures as they happen
Axis Intelligence Tracker: As of August 2, 2026, Axis Intelligence Research has confirmed 12 entries.
Cyber Express Sidebar (Specific Incident): CEVA Logistics Cyberattack Disrupts European Warehouses, Exposes Customer Data

Framework Changes

NIST Moves to Modernize NVD as AI Reshapes Vulnerability Management

The cybersecurity framework landscape is adapting rapidly to the demands of AI-driven threats. The National Institute of Standards and Technology (NIST) has initiated a major effort to modernize its National Vulnerability Database (NVD). This change is necessary because traditional vulnerability classification methods are struggling to keep pace with the speed at which AI discovers, weaponizes, and exploits flaws.

Beyond NIST, mandatory policy changes are driving compliance. Microsoft’s announcement of **Mandatory MFA for Azure Sign-ins** represents a massive shift in cloud security governance, forcing organizations to drastically improve their identity protection posture. Additionally, the focus on the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) is increasing the legal mandate for timely and comprehensive reporting across 16 designated sectors.


Sources:
NIST Update: NIST Moves to Modernize NVD as AI Reshapes Vulnerability Management
Microsoft Policy: Microsoft August 2026 Patch Tuesday Fixes 400 Flaws, Including Three Zero-days (Contextual source for policy)
Defcon Level: CISA advisories and the Known Exploited Vulnerabilities (KEV) catalog are being used to operationalize framework requirements

New Legislation

UK Social Media Ban for Under-16s Could Take Effect by Spring 2027

Global legislative efforts are increasingly focused on regulating the digital behavior of citizens and securing sensitive data. In the UK, a major policy change is looming: a social media ban targeting users under the age of sixteen, which is expected to take effect by Spring 2027. This aims to protect younger demographics from online risks while also forcing platforms to adapt their design for compliance.

Other key legislative movements include India’s ongoing enforcement and refinement of its Digital Personal Data Protection Act (DPDP Act). Furthermore, the US Federal Trade Commission (FTC) is actively using legal action against companies like Hims & Hers to enforce data privacy mandates regarding health information, signaling a strong regulatory push in the healthcare sector.


Sources:
Cyble/India DPDP: How Cyble’s Front-Row Vantage Can Help You in Complying to India’s DPDP Act (Contextual source)
The Cyber Express Sidebar: UK Social Media Ban for Under-16s Could Take Effect by Spring 2027
FTC Action (US Legislation): FTC Sues Hims & Hers Over Health Data Privacy, Billing Practices
Careers

2026 National Cyber Virtual Career Fair

The Center of Academic Excellence in Cybersecurity Community (CAE) and the National Cybersecurity Training and Education (NCyTE) Center are hosting the tenth annual National Cyber and AI Virtual Career Fair!

September 22, 2026

9:00 am-2:00 pm Pacific Time

12:00pm-5:00pm Eastern Time

This event is open to students from over 500 institutions designated as Centers of Academic Excellence in Cyber Defense (CAE-CD), Cyber Operations (CAE-CO),  Research (CAE-R), Artificial Intelligence (CAE-AI), and institutions in the Candidate’s Program.

More Information & Registration: https://app.premiervirtual.com/events/53f978a2-1f6f-43a9-a8ba-39151c094417/2026-national-cyber-and-ai-virtual-career-fair/attendee

Careers, Security Education

ISACA Scholarship Program

The ISACA Foundation Scholarship program is currently accepting applications through 5 May 2026.

These scholarships provide more than just financial aid; they offer a bridge into the industry through global networking and professional memberships.

Key Benefits for Students:

  • Financial Support: Awards ranging from $500–$5,000 USD.
  • Professional Entry: One year of ISACA student membership and access to certificate review courses.
  • Networking: Opportunities to attend ISACA Global events and conferences.

For specific program details and apply to one of the scholarships, visit the [ISACA Foundation website].