Loading summary
A
You're listening to the Cyberwire Network powered by N2K.
B
Maybe that's an urgent email from your CEO, or maybe it's a deepfake targeting your business. Doppel is the AI native social engineering defense platform, fighting back against impersonation and manipulation. As attackers use AI to make their tactics more sophisticated, Doppel uses it to fight back, automatically dismantling cross channel attacks, building team resilience and providing agentic email protection. Doppel outpacing what's next in social engineering? Learn more@doppel.com that'S-O-P-P-E-L.com.
A
We've got your patch Tuesday Notes attackers target Microsoft SharePoint vulnerability while following POC release Cyber attack on Siva logistics causes ongoing supply chain disruptions Wesco confirms data breach following extortion claims Akira ransomware bypasses EDR in safe mode California announces AI Cybersecurity Fund N2K's lead analyst Ethan Cook shares more about Cyber Weapons for space Dave Bittner sits down with Michael Leland, VP and Field CTO at Island at Black Hat usa, to discuss the growing risks of the AI supply chain and fasten your seatbelts and ignore the fake WI fi. Is Wednesday, August 12, 2026. I'm Maria Varmazas and this is your Cyberwire Intel Briefing. Thank you for joining me today. Let's get started. Microsoft's Patch Tuesday addressed a total of 421 vulnerabilities across its products, including Windows Hyper V, Microsoft Exchange Server and azure. Of these, 62 are rated critical and 357 are marked as important, with the most significant being three zero day vulnerabilities. The zero days include a tampering flaw in the Windows Container Isolation FS Filter driver, an elevation of privilege bug in the Windows User Profile service, and an actively exploited privilege escalation flaw in the Windows ancillary function driver for Winsock. CISA has added the latter flaw to its known exploited vulnerabilities catalog and ordered federal agencies to apply patches by August 25th. Check Point has attributed the exploitation to North Korea's Lazarus Group. In a campaign targeting the defense sector in Europe and India, Adobe addressed 51 vulnerabilities across five of its products Adobe ColdFusion, Adobe Commerce, Adobe Lightroom Classic Content Credentials SDK and Adobe Campaign Classic. Of these, 33 vulnerabilities are classified as critical SAP fixed 29 vulnerabilities led by a maximum severity flaw in SAP Commerce Cloud's Data Hub adapter. This improper authorization issue allowed unauthenticated remote attackers to submit crafted data, potentially leading to arbitrary code execution in the ICS space. Siemens, Schneider Electric and Phoenix Contact released patches for various products and and CISA published advisories covering vulnerabilities in products from other vendors, including Pulsetto and Johnson Controls. Notably, Siemens issued a fix for a maximum severity missing authentication flaw in its Somatic IOT gateways. Threat actors have already started weaponizing a proof of concept exploit for a critical Microsoft SharePoint flaw that was published by Rapid7 yesterday. The flaw is an authentication bypass vulnerability that affects the JWT token validation pipeline in in SharePoint Enterprise Server 2016 and 2019. It allows attackers without privileges to impersonate users or administrators to disclose files and modify data. Microsoft issued a patch for the flaw on July 14 following a responsible disclosure by Rapid7. Administrators who haven't already applied patches are urged to do so promptly. A cyber attack at shipping giant Ceva Logistics is continuing to cause significant disruptions for its clients across Europe. The attack, which likely began on July 29, 2026, affected at least eight warehouses, and while the full extent of the breach has not been disclosed, affected clients report that customer names, contact details and delivery information may have been compromised. Dutch retailers Boll and Debian Corp. Along with gaming giant Valve have disclosed that they were impacted. Global supply chain and distribution giant Wesco has confirmed a cybersecurity incident involving its cloud CRM environment after the data extortion group Exfil Squad claimed credit for the attack. Exfil Squad says that it stole and leaked 2.6 million records containing customer and employee data. Wesco asserts that there has been no business disruption or evidence of ransomware, and believes sensitive data like payment cards or financial accounts are not at risk. Details of the attack are still unclear, but bleeping computer notes that Exfil Squad has in the past targeted improperly configured Microsoft Power Pages data tables. Huntress has published a report on an attack by an Akira ransomware affiliate in which the attackers rebooted a compromised host into Safe mode with networking to bypass EDR tools. After gaining initial access through an exposed SonicWall VPN without multi factor authentication, the attacker enumerated active directory and exfiltrated sensitive data. By forcing the reboot into safe mode, the attacker intended to freely execute the ransomware. However, the stripped down memory environment of Safe mode ironically caused the Akira process to crash from an out of virtual memory error preventing encryption. Unfortunately, the prior data theft still left the victim vulnerable to extortion. The state of California is launching an AI cyber defense program to protect its critical infrastructure after recent incidents revealed AI systems from major tech companies autonomously hacking into third party organizations. The initiative will use AI tools to rapidly identify and patch security vulnerabilities supervised by newly appointed AI cybersecurity officers across state agencies. Governor Gavin Newsom said that the state's approach serves as a direct response to the Trump administration's proposed $707 million budget cuts to the Cybersecurity and Infrastructure Security agency for the 2027 fiscal year. And on Wednesdays we take a look at what's going on in the world of space cyber and this week we'll hear from T minus Space Cyber Briefing producer Ethan Cook on the US Military setting its sights on on advanced cyber weaponry to take down satellite constellations. Over to you, Ethan.
C
On Tuesday, the U.S. held its annual Army Space and Missile Defense Symposium. At the event, Lt. Col. Rick Zelman, deputy commander of U.S. space Command, said adversaries are unlikely to try and take thousands of satellites offline using an anti satellite weapon. Instead, they could target people and compromise the nodes that provide one to many services. Zellman noted that these threats include cyber and directed energy weapons, with attacks often focused on the ground systems supporting satellite networks. Given the potential of these weapons as both threats and tools for the US Military, officials are considering directed energy and other capabilities as potential counter space weapons while also exploring ways to diversify ground infrastructure for the T minus Space Cyber Briefing, this is producer Ethan Cook. Back to you Maria.
A
Thank you Ethan. Stick with us after the break now as Michael Leland, VP and Field CTO at Island, sits down with Dave Bittner at Black Hat USA to discuss the growing risks of the AI supply chain. And fasten your seatbelts everybody, and ignore the fake wi fi. Stay with us.
B
AI is making phishing attacks faster, more convincing and harder for people to spot, and traditional security awareness and phishing training weren't designed for this level of attack. HOX Hunt helps security teams prepare employees for the attacks they face every day with personalized phishing training that adapts to each employee and reduces risky behavior over time for IT and security leaders looking to strengthen their human layer of defense without adding more manual work. Visit hoxhunt.com cyberwire to learn more. That's h o-x h u n t.com cyberwire foreign.
A
Voices Segment Today, Dave Bittner sits down with Michael Leland, who is the Vice President and Field CTO at Island at Black Hat USA to discuss the growing risks of the AI supply chain, including agent baiting, where fake AI skills and MCP servers were used to deliver malware and Hidden instructions that can influence AI agents. Here's their conversation.
D
We know AI is already trying to find a way around it. Humans do the same thing. If you tell them they can't use a tool, they'll find a plugin that uses the tool behind the scenes. If you tell them they they're not allowed to use their, their personal AI, they'll load a new browser and try logging in from there. So one of the best things is visibility first, analytics second, and then governance. But I think adoption has so quickly outpaced governance in the AI world that many of us are trying to play catch up.
E
And we are continuing our conversations here at Black Hat 2026. And joining me is Michael Leland. He is field CTO at Island. Michael, thanks for joining us.
D
Thanks for having me.
E
So we are digging into supply chain issues with AI today. Can we start with just some foundational types of things for folks who may not be living in that world every day? What are the specific things that you all have your eye on?
D
So we architected something that we like to call the agentic control plane. And I think that's an important conversation we're dealing with. Supply chain. First of all, AI is coming at us in so many different modalities, right? Generative AI via chat interfaces, in the browser, via desktop applications, we've got Claude Code and cowork codex, various AI plugins to your IDEs. And the way most people would think about handling both visibility and inspection is waiting till all that traffic hits the network. Right? A SASE vendor might funnel it all through a pop where they're going to try to do break and inspect. That's been great for years, but AI has changed that architecture. AI is now being used by users on the desktop and by applications that we never even imagined a year ago. Claude Cowork has just as much access to the local file system data as it does to a cloud tenant. And so when you think about supply chain, the first thing you have to think about is where are these agents getting their skills, where are they getting their packages? And more importantly, is there a spot where you can provide both visibility and enforcement at runtime? And for most organizations, they've got a slew of tech that they've invested in over the course of the last decade or more. On the endpoint, they've got EDR in the cloud, they've got sase, they may have CASB or aspms. Each of those do a great job in their swim lane. But all of them have blind spots to all the various points that users are now interacting with AI. I saw last week Claude Code, his coworker, actually, it got stuck. It couldn't do what I asked it to do. And so it decided the best course of action was to write a Python script that would then go out and pull an NPM package from a source that I didn't authorize.
B
Right.
D
We saw, you know, just this past week with things like sandbox escapes from the various AI providers. If you set AI to a goal, it will find any way possible to get there, not always by means that we've authorized and certainly not staying in their swim lanes.
E
So what are you all, what are you all proposing then as a solution to that reality?
D
So because of the multiple modalities of AI, we need to have as many control points as possible. Island is a architected a solution with about nine different control points.
E
Okay.
D
We started off building a browser six years ago and that handles all user interactions with AI and SaaS applications via a web. We then decided that our customers aren't always going to use our browser. They might still use their own. So that same functionality has to exist as an extension into an existing consumer browser. But about three years ago, our customers told us what about my thick apps? And what they meant three years ago was Word, Outlook, Visual Studio. Most of those apps have long gone to the cloud, the great sassification of the desktop apps. But in the last nine months to 12 months, AI has dragged us back in the other direction, away from sassification, because now these desktop apps have to be in scope as well. So in addition to the browser and the extension, we introduced a desktop component that sits outside the browser as an enforcement point for all thick app and AI activity. We also introduced a network component where the SASE vendors started by building large cloud infrastructures and then pushing out to the edge that relied on break and inspect in the middle at these juncture points where all of my traffic funnels through a proxy. Sure it creates a poor user experience and as we're getting closer to post quantum encryption and with certificate pinning, a lot of traffic can no longer be inspected in the cloud. So that last access point that we added, so browser extension, desktop and network, those were the four. But in the next three months will be introducing an MCP gateway which allows you to do things like token brokering in the middle. That means that if an agent needs to access an application via an OAuth token, you don't give the agent the actual OAuth token to the app. You give them a temporary one issued by an ahi, a non human identity. Right. That means you can then also pass off various restricted privileges to that if the agent specifically asks for. Let's say read write privilege to Salesforce. And I say, you know what, I'm only going to grant you read only privilege to Salesforce. I can now do that in the token swap. Then we use something called the Compliance API frameworks. Every AI vendor delivers a set of APIs that we call that they call the compliance APIs. That's how a desktop application like Island Desktop can hook into those applications and provide the same level of visibility and enforcement, as well as a runtime policy. And then lastly, LLM gateway integrations are pretty common these days, but we also fully support what's called the Open Telemetry platform, the OTEL standard. OTEL allows us to connect to the major AI providers and collect telemetry and statistics about things like token utilization and cost per user per session, per skill performance metrics about how the AI is performing, what's the time to first token, time to last token, and then more importantly, AI adoption strategies. All of that has to align to the same data restriction or data protection policy that you've built for the enterprise. Because the biggest gap people have right now is shadow AI and AI governance.
E
How do you balance that visibility without overloading the team with information?
D
It's a great question. We are generating more telemetry now than we ever have. And once we start seeing agentic transactions generating telemetry at machine speed, we'll probably hit 1000 to 1 ratio of human or agentic telemetry to human telemetry. Which means you've got to think differently about the way that telemetry is both being collected and analyzed. The only way to analyze AI generated telemetry is, is with AI. So if we collect a million events, we need to summarize those using an analytic engine that describes exactly what those events mean. This user tried copying sensitive data into this model. This user has an excessive use of AI token usage this week. Right. And a human's not going to be able to catch those things. But AI does a really good job of summarization and so we generate what's called an insight from those. So you're going to see a lot more of that consolidated effort of providing this analytic engine on top of AI utilization.
E
I'm curious, do you have any specific examples of use cases or folks that you've worked with to try to get through some of these issues together?
D
Yeah, I think one of the best examples that I've Used a few times anecdotally because it actually happened from a customer. We had a customer trying to solve their shadow AI problem. Right. And they, they insisted they only had eight sanctioned AI applications in use. We did an assessment. Some users had the full browser. Many of the other users just had the. The island extension. We found 243 AI applications.
E
Wow.
D
So I think it proves that if you, if you put a roadblock in front of customers and just. Or. Or users and say a hard no, they're going to say, I'll find a way around it. We know AI is already trying to find a way around it. Humans do the same thing. If you tell them they can't use a tool, they'll find a plugin that uses the tool behind the scenes. If you tell them they're not allowed to use their personal AI, they'll load a new browser and try logging in from there. So one of the best things is visibility first, analytics second, and then governance. But I think adoption has so quickly outpaced governance in the AI world that, that many of us are trying to play catch up. Many customers, you know the analogy. If you can't put the toothpaste back in the tube. Yeah. The toothpaste is out.
E
It's all over the counter.
D
That's right.
E
Well, so what's your advice to folks who feel like they're playing a game of catch up now, you know, their employees are doing the things they need to do to get their jobs done. How do you. How do you find equilibrium?
D
So there's a really interesting dichotomy between the fact that the executives and the board are telling people, thou must use AI.
E
Right.
D
Because it's going to improve our productivity, it's going to help our innovation, it'll help us streamline our operations. But then you get the legal team and the compliance team saying, be careful using AI. And so the user's caught in the middle of should I or shouldn't I?
E
As we look towards the horizon, let's say, over the next year or so, what does success look like to you? What does it look like when folks are using these tools in the proper way and seeing good results?
D
So I think success is really two things. One, it's giving your users the trust and confidence to use AI to fit their outcome needs. And the trust piece is, I don't worry when that new button pops up in my SaaS application, because my organization has built a guardrailed policy that if that button were dangerous, it wouldn't be there. Or if it's there, it's not going to let me put sensitive data into it. I have to stop making the end user second guess what their AI usage should be in terms of utilizing these tools. Because if you leave it up to the user, there's two camps. I'm not going to touch it because I don't want the legal ramifications or the government's dribble. Exactly. Or you know, the other ones that are just going to go full force into AI and risks be damned.
E
Right, right.
D
So I think, I think instilling a sense of confidence and trust in the, in the user population that the guardrails are in place, that even if they make a mistake, they can't put sensitive data at risk.
E
Michael Leland is Field CTO at Island. Michael, thanks so much for joining us.
D
Thanks for having me.
A
That was Dave Bittner sitting down with Michael Leland, VP and Field CTO at Island, discussing the growing risks of the AI supply chain. And if you enjoyed this conversation and want to learn more about it, make sure to check out the links in our show Notes.
C
Foreign
B
what's the one thing in business that's spreading as fast as AI? AI risk. Every new tool your team signs up for, every vendor that turns on AI features, every new integration, each one is another opportunity for something to go wrong. And most security programs weren't built to keep up with AI's pace of growth. Enter Vanta. Vanta is the number one agentic trust platform trusted by more than 16,000 fast moving companies like Ramp, Purser and Harvey to help them stay audit ready. And now Vanta helps companies like yours keep an eye on the risks that appear between audits across your vendors, your AI tools and your entire environment. The Vanta agent works like a 24.7grc engineer. In the background it finds, issues, drafts, fixes for you and can cut vendor assessment time by up to 50%. Whether you're a fast growing startup or a global enterprise, Vanta is here to help you automate your security and compliance and earn and prove trust. Get started today@vanta.com cyber. That's V A N T A.com cyber.
A
And lastly, a DEFCON attendee is suspected of jamming the in flight Wi Fi on a Delta flight out of Vegas on Monday. The exact details of the incident are still unclear, though the flight crew informed air traffic control that a passenger had set up a spoofed network called Delta Wi Fi Fast and was trying to scam the other passengers. The individual likely used a Wi Fi, pineapple or similar device for spoofing networks. Delta is investigating the incident and working with law enforcement, but stated that the aircraft's operating systems and flight safety were never compromised. Federal authorities, on the other hand, met the plane upon landing to question the passengers, as the incident may amount to a federal offense, And that is the Cyber Wire. For links to all of today's stories, check out our daily briefing@thecyberwire.com as always, we would love to know what you think of this podcast. Your feedback ensures that we deliver the insights that keep you a step ahead in the rapidly changing world of cybersecurity. If you like the show, please share a rating and review in your podcast app. Please also fill out the survey in the show notes or send an email to cyberwire2k.com N2K's lead producer is Liz Stokes. We're mixed by Trey Hester with original music and sound design by Elliot Peltzman. Our executive producer is Jennifer Ibin. Vera Kilpe is our publisher and I'm Maria Varmazes in for Dave Bittner this week. Thanks for listening. We'll see you tomorrow.
B
It.
Date: August 12, 2026
Host: Maria Varmazas (for Dave Bittner)
Podcast Network: N2K Networks
This episode delivers a comprehensive rundown of the latest cybersecurity news, zeroing in on a significant Patch Tuesday, newly exploited vulnerabilities, major supply chain cyberattacks, ransomware tactics, and government-backed AI cybersecurity initiatives. The show features an in-depth interview with Michael Leland, VP and Field CTO at Island, from Black Hat USA, focusing on the growing risks of the AI supply chain. Other notable topics include an update on cyber threats in space and a bizarre case of Wi-Fi spoofing on a Delta flight post-DEFCON.
[01:05]
Microsoft: Patched 421 vulnerabilities across multiple products (Windows Hyper V, Exchange Server, Azure).
Adobe: Fixed 51 vulnerabilities; 33 critical, across products like ColdFusion, Commerce, Lightroom, and more.
SAP: Resolved 29 vulnerabilities, notably a severe flaw in Commerce Cloud's Data Hub adapter allowing unauthenticated attacks.
ICS Vendors: Siemens, Schneider Electric, Phoenix Contact released patches.
[01:05]
[03:16]
Ceva Logistics: Ongoing cyberattack disrupting clients' operations across Europe.
Wesco: Confirms data breach post extortion claims from Exfil Squad, who claims 2.6M records stolen (customers, employees).
[04:55]
[06:29]
Featuring Ethan Cook [07:48]
"Adversaries are unlikely to try and take thousands of satellites offline using an anti satellite weapon. Instead, they could target people and compromise the nodes that provide one to many services."
— Lt. Col. Rick Zelman ([07:59])
Dave Bittner with Michael Leland, VP & Field CTO, Island at Black Hat USA
[10:03–21:27]
The AI Governance Challenge:
Technical Gaps & Solution Architecture:
AI-Generated Telemetry Overload:
Case Study: Shadow AI Proliferation:
Balancing Trust & Guardrails:
[23:24]
"Success is really two things: giving your users the trust and confidence to use AI... and the trust piece is, I don't worry when that new button pops up in my SaaS application, because my organization has built a guardrailed policy..."
— Michael Leland ([20:19])
"If you tell them they're not allowed to use their personal AI, they'll load a new browser and try logging in from there."
— Michael Leland ([10:27], [18:42])
This episode provides essential insights into the ongoing arms race between attackers and defenders in AI-driven cybersecurity, reveals real-world consequences of underestimating shadow AI, and highlights both government and industry responses to emerging threats. The conversation with Michael Leland is especially valuable for those seeking practical strategies to regain control and governance in a rapidly shifting AI landscape.
Find more details and links in the episode’s daily briefing at thecyberwire.com.