Summary & highlights
ShipMonk Fulfillment Partner Breach Exposes Data of 13,689 Trezor Customers. Personal GitHub Repositories Are a Major Blind Spot for Corporate Secret Leaks (Wiz Research). Mid-Tier AI Models Close the Gap on Frontier Systems for Offensive Exploitation Tasks (XBOW/Anthropic, Aug 2026).
Highlights
- TL-2026-2002 — Jewelbug APT Runs Espionage and Crypto Fraud Operations Side by Side
- TL-2026-2003 — WindRelay Android NFC Relay Malware Paired With SpyNote RAT Enables Real-Time Bank Card "Ghost Tapping" Fraud
- TL-2026-2004 — Mass Phishing and Scam Campaign Abuses 450+ Compromised Google Workspace Accounts in the Education Sector
- TL-2026-2005 — Kimsuky 'Operation GitPower' Integrates Local AI Tooling into AsyncRAT Espionage Campaign
- TL-2026-2006 — PATCHCORD, SHEETCORD & HACKERAI C2 Agent: New Malware Cluster Targets Afghan Telecom and South Asian Critical Infrastructure (APT36-linked)
Theme of the day
Patch Tuesday's 400 fixes included three zero-days, with Lazarus exploiting an AFD.sys flaw and a critical Metabase SQLi under active attack.
- espionage
- active-exploitation
- data-breach
- social-engineering
- financial-fraud
Threats published
17 threat lines in the 2026-08-13 debrief, most severe first; entries marked (update) revise an earlier report. Each links to its full profile.
- Unpatched GeoServer Zero-Day SQL Injection (jsonArrayContains, GHSA-mqjf-5f49-2fjh) Under Active ExploitationCRITICAL
- Pawn Storm (APT28) Deploys PRISMEX Malware Suite via CVE-2026-21509 and CVE-2026-21513 Zero-Days Targeting Ukrainian Defense Supply Chain (update)CRITICAL
- TeamPCP LiteLLM Supply Chain Attack — Trojaned PyPI Packages (v1.82.7/1.82.8) with Multi-Stage C2 Payload (update)CRITICAL
- CVE-2026-55040: Microsoft SharePoint JWT Token Authentication Bypass (Unpatched Chain Component, PoC Public) (update)CRITICAL
- Anubis Ransomware Group Confirms Data Theft in Coca-Cola Fairlife Attack Tied to CitrixBleed 2 (CVE-2025-5777) Exploitation Wave (update)CRITICAL
- Three Critical VMware Flaws (CVE-2026-59309, CVE-2026-59310, CVE-2026-47876) Allow Auth Bypass, RCE, and VM Escape (update)CRITICAL
- Jewelbug APT Runs Espionage and Crypto Fraud Operations Side by SideHIGH
- WindRelay Android NFC Relay Malware Paired With SpyNote RAT Enables Real-Time Bank Card "Ghost Tapping" FraudHIGH
- Mass Phishing and Scam Campaign Abuses 450+ Compromised Google Workspace Accounts in the Education SectorHIGH
- Kimsuky 'Operation GitPower' Integrates Local AI Tooling into AsyncRAT Espionage CampaignHIGH
- PATCHCORD, SHEETCORD & HACKERAI C2 Agent: New Malware Cluster Targets Afghan Telecom and South Asian Critical Infrastructure (APT36-linked)HIGH
- Crimeware-as-a-Service: Inside the Malware Crypting Services Market and Its Threat ActorsHIGH
- Akira Ransomware Affiliate Forces Windows Safe Mode Reboot to Disable EDR, Exfiltrates Data via AnyDesk/WinRAR/s5cmd but Fails to EncryptHIGH
- ShipMonk Fulfillment Partner Breach Exposes Data of 13,689 Trezor CustomersMEDIUM
- Personal GitHub Repositories Are a Major Blind Spot for Corporate Secret Leaks (Wiz Research)MEDIUM
- Mid-Tier AI Models Close the Gap on Frontier Systems for Offensive Exploitation Tasks (XBOW/Anthropic, Aug 2026)MEDIUM
- White House Authorizes Private US Companies to Conduct Offensive Cyber Operations Against Foreign Criminal Networks (NSPM: "Expanding Capabilities to Combat Transnational Cyber-Enabled Crime")
Techniques observed
207 MITRE ATT&CK and ATLAS techniques appear across the day’s reports.
- T1001
- T1003
- T1003.001
- T1003.003
- T1005
- T1007
- T1010
- T1014
- T1016
- T1018
- T1020
- T1021
- T1021.001
- T1021.002
- T1027
- T1027.002
- T1027.004
- T1033
- T1036
- T1036.005
- T1039
- T1041
- T1048
- T1053
- T1053.003
- T1053.005
- T1055
- T1055.004
- T1055.012
- T1055.013
- T1056.003
- T1057
- T1059
- T1059.001
- T1059.003
- T1059.004
- T1068
- T1069
- T1069.003
- T1070
- T1071
- T1071.001
- T1071.004
- T1074
- T1078
- T1078.002
- T1078.004
- T1080
- T1082
- T1083
- T1087
- T1087.002
- T1087.004
- T1090
- T1090.001
- T1090.002
- T1095
- T1098
- T1098.002
- T1102
- T1102.001
- T1102.002
- T1105
- T1106
- T1110.003
- T1112
- T1113
- T1114
- T1114.003
- T1119
- T1133
- T1134
- T1134.002
- T1136
- T1136.001
- T1137
- T1140
- T1176
- T1190
- T1195
- T1195.002
- T1197
- T1199
- T1203
- T1204
- T1204.002
- T1210
- T1212
- T1213
- T1213.003
- T1217
- T1219
- T1418.001
- T1437
- T1480
- T1482
- T1485
- T1486
- T1489
- T1490
- T1496
- T1497
- T1499.001
- T1499.004
- T1505
- T1505.003
- T1505.004
- T1516
- T1518
- T1526
- T1528
- T1529
- T1530
- T1531
- T1533
- T1539
- T1543
- T1543.003
- T1546
- T1546.003
- T1547
- T1547.001
- T1547.009
- T1548
- T1550
- T1550.001
- T1552
- T1552.001
- T1552.004
- T1553
- T1554
- T1555
- T1555.003
- T1556
- T1556.003
- T1557
- T1560
- T1560.001
- T1561.001
- T1564.008
- T1565
- T1565.001
- T1566
- T1566.001
- T1566.002
- T1566.004
- T1567
- T1567.002
- T1569.002
- T1570
- T1571
- T1572
- T1573
- T1573.002
- T1574
- T1574.001
- T1580
- T1583
- T1583.001
- T1583.006
- T1584
- T1584.004
- T1584.005
- T1585
- T1585.002
- T1586.002
- T1587
- T1587.001
- T1587.003
- T1588
- T1588.002
- T1588.005
- T1588.006
- T1588.007
- T1589
- T1589.002
- T1590
- T1592.002
- T1593.003
- T1595
- T1595.002
- T1596
- T1598
- T1598.004
- T1602.002
- T1606
- T1608
- T1608.001
- T1608.006
- T1610
- T1611
- T1613
- T1620
- T1622
- T1636.003
- T1638
- T1646
- T1649
- T1655
- T1657
- T1660
- T1663
- T1684.001
- T1685
- T1685.005
- T1685.006
- T1688
Threat actors
8 named threat actors across the reports.
Nation-state attribution
- China
- North Korea
- Pakistan
- Russia
- Russia (suspected, unconfirmed)
Threat categories
- DATA_BREACH
- SUPPLY_CHAIN
- THREAT_INTEL
- MALWARE
- PHISHING
- APT
- RANSOMWARE
- VULNERABILITY
Severity breakdown
- critical6
- high7
- medium3
- low0
Indicator & detection coverage
Counts only: the indicator values and detection rule text behind them are tiered.
- network 115
- file 110
- entity 66
- infrastructure 59
- behavioral 47
- tool 38
- malware 33
- package 9
- technique 6
- host 1
- vulnerability 1