
Loading summary
A
From the CISO series. It's Cybersecurity Headlines
B
these are the cybersecurity headlines for Monday, August 10, 2026. I'm Steve Prentiss. OpenAI slows the release of Astra citing cyber capabilities the company said on Friday that it cannot rule out that its upcoming model Astra, has critical cyber capabilities. This is a condition that has prompted the company to expand safety testing and pause internal activities that do not meet stricter security requirements. Speaking with Axios, a representative stated they will slow down development on Astra until it has the right safeguards in place. This move conforms with the company's preparedness framework, first published in 2023. Irregular won't say if there Were More rogue Incidents the Israel based cybersecurity evaluation firm that conducted the tests in which AI models from Anthropic, OpenAI and Meta all compromised real world computer systems has declined to say whether any of its other clients were also affected by the same underlying flaw. An Irregular spokesperson described these three incidents as the exact same evaluation environment issue, before adding that there were no current open issues. They declined to clarify whether the issues they referred to regarded misconfigurations or AI model cybersecurity incidents that had not yet been disclosed. U.S. cyber Ambassador nominee Cassidy confirmed in the Senate the Senate on Friday confirmed Adam Cassidy to serve as the next U.S. ambassador for Cyber and Digital Policy as part of a 5147 vote on a package of more than 70 nominees. Cassidy becomes only the second person to hold the ambassador at large post. He previously worked at the Federal Communications Commission. He noted that the US should work with trusted partners who share our commitment to secure, resilient and open digital ecosystems. End Quote Ransomware gangs focus on the 40 something manager, not the CEO Researchers at Zscaler's threat labs are suggesting that most ransomware groups that it has tracked are doing their homework when it comes to who to speak to about ransomware demands. The data suggests that the preferred victim now holds a manager level title is a 46 year old Gen Xer and 3/4 of these work in accounting and finance, sales, operation, HR or marketing. The researchers suggest this is because these employees are most likely to influence a company's response and accelerate payment decisions. Huge thanks to our sponsor ThreatLocker. AI is helping attackers research targets create malicious code and adapt faster, but the fundamentals have not changed. Code still needs to execute, applications still need access and attackers still need privileges. Today's control those actions instead of trying to predict every threat. Learn more from threatlocker@threatlocker.com CISO One click vulnerability in Atlassian's Rovoai exposes enterprise data Researchers at Varonis Threat Labs are warning of a one click vulnerability in Rovo, that is Rovo, which is Atlassian's enterprise AI assistant. The vulnerability, named rovoblast, allowed a specially crafted link to seed attacker controlled instructions directly into a user's live AI session. It required no jailbreak and no permission bypass, and relied solely on the fact that the assistant simply treated externally supplied parameters as a trusted input. End quote Rovo works as an AI layer spanning Jira, Confluence, BitBucket, and third party tools like Slack, Microsoft 365, and Google Workspace. It also carries autonomous agent features capable of completing multi step tasks with no further user involvement, which is what enabled the roboblast attack. New Webmail CSS attacks can steal passwords and tokens According to research from security testing firm portswigger, content inside an email can escape its message boundary and interfere with the webmail interface. In a proof of concept, researcher Gareth Hayes showed how attack chains spanning Outlook, Gmail, Fast Mail, protonmail, Yahoo Mail, and AOL Mail can capture passwords, take over third party accounts, leak tokens, hijack trusted UI actions, and manipulate AI tools that read email. End quote the research follows two either abusing HTML and CSS that webmail already allows, or creating a discrepancy between what a sanitizer approves and what the browser or application ultimately creates. Both can cross the boundary between an untrusted message and its trusted interface. A link to a more detailed summary of this process is available in the show Notes to this episode. Levi Strauss says hackers stole corporate data in cyber attack the clothing company says hackers used social engineering on three of its employees to gain access and to steal corporate data stored on their machines. Although there is no belief that the incident will have any significant impact on its business or financial position, the company has also noted that it has not experienced any operational disruptions as a result of this breach. No attacker or group has been formally identified as behind the attack. However, certain media outlets have linked this incident to UNC6671, which Google's threat Intelligence Group associated with a recent wave of voice phishing attacks targeting hundreds of organizations. Unlimited Technology Systems breach affects 3.8 million people this breach happened in October 2025. Unlimited Technology Systems is a healthcare software company that specializes in financial and revenue cycle technology for specialty healthcare providers. Representatives say a company's server was breached and the PII and medical information of almost 4 million people was exposed to an unauthorized party. According to the notifications supplied by the company, no ransomware or data extortion groups have publicly claimed responsibility, and Unlimited Technology Systems has not identified the perpetrators. If you have some thoughts on the news from today or about this show in general, please be sure to reach out to us@feedbackisoseries.com we would love to hear from you. I'm Steve Prentiss reporting for the CISO series.
A
Cybersecurity headlines are available every weekday. Head to CISoseries.com for the full screen stories behind the headlines.
Host: Steve Prentiss, CISO Series
Episode Focus:
A roundup of the most impactful information security stories, including OpenAI’s Astra release pause, ambiguity over AI model test disclosures, a new US cyber ambassador, evolving ransomware targeting, critical vulnerabilities in enterprise tools, emerging webmail attacks, major data breaches, and more.
This episode delivers concise, up-to-date coverage of major cybersecurity developments affecting organizations, government policy, AI, and enterprise security, with an emphasis on new risks, regulatory moves, evolving threat tactics, and significant breaches.
“The US should work with trusted partners who share our commitment to secure, resilient and open digital ecosystems.” (Adam Cassidy, 01:46)
On OpenAI Astra's delay:
“They will slow down development on Astra until it has the right safeguards in place.” (Steve Prentiss, 00:26)
On US international cyber policy:
“The US should work with trusted partners who share our commitment to secure, resilient and open digital ecosystems.” (Adam Cassidy, 01:46)
On ransomware targeting:
“The preferred victim now holds a manager level title, is a 46 year old Gen Xer, and 3/4 of these work in accounting and finance, sales, operation, HR or marketing.” (Steve Prentiss, 02:10)
On AI-powered enterprise vulnerability:
“It required no jailbreak and no permission bypass, and relied solely on the fact that the assistant simply treated externally supplied parameters as a trusted input.” (Steve Prentiss, 03:23)
This episode covers significant advancements and risks in cybersecurity, including AI safety slowdowns (OpenAI's Astra), ambiguity over AI incident disclosures, diplomatic movement on US cyber policy, targeted ransomware strategies focused on influential managers, novel enterprise AI vulnerabilities, the emergence of potent email client attacks, and major data breaches. It illustrates the dynamic threat landscape and the growing overlap between technology, policy, and human factors in cybersecurity.