- Let’s be honest, most threat intel is just noise. You’ve got feeds everywhere, but turning that into detections or hunts is still way harder than it should be.So how do you actually operationalize it?At the Threat Intelligence Virtual Cybersecurity Summit on August 26th, learn how to integrate intel into your workflows and make it useful for real-world detection and response.Security Weekly listeners can register for free at https://securityweekly.com/threatintel using the promo code: CSS26-SW
- InfoSec World brings cybersecurity professionals together across industries, from healthcare and financial services to government and the Fortune 500. Join the community in Orlando, October 12–14, for practical education, new perspectives, and cybersecurity research unveiled live. Listeners save 30% on their pass with code ISW26-SWSAVINGS at securityweekly.com/infosecworld2026.
Joshua Marpet
- AI Governance Study – What standard do you use for what?
We have lots of LLM's, GenAI, SLM's, and other members of the xLM family. What governance systems do you use for them? and Why?
- LiteLLM and PyPi, magic together!!
Malicious LiteLLM releases on PyPI Two poisoned releases of LiteLLM, the popular LLM-gateway library, sat on PyPI briefly and stole credentials. This is the perfect segment for you: it's supply chain and AI tooling in one story, the intersection your Q3 census lives at.
- Kev NPM – Is it always DNS? Nope, it’s always NPM!
Keyv npm worm poisoning hundreds of packages, hooking Claude Code and VS Code extensions. A self-propagating supply-chain compromise in the npm ecosystem reaching into developer tooling.
- State of Software Supply Chain Security – Abandonware is…bad.
classified 13.1 million packages. The abandonment number everyone quotes as a single percentage is really a range, and its width is the finding.
Larry Pesce
- Critical OpenWrt DHCPv6 Flaw Could Let Unauthenticated Attackers Run Code as Root
- Midnight Blizzard Targets Travelers via Captive Portals
- BUGTRAQ IS BACK
- noRecognition : AI Adversarial Clothing
- tl;dv (Too Lazy; Didn’t Validate): 181,874 Meetings Left Wide Open
- A Zoom Screen-Sharing Bug Let Anyone Take Over Other Devices on a Call
- Ⓐ Cyber Security
- Ransomware Attack disrupts Hospital Doors, Elevators, Ventilation and Air Conditioning in Canada
- Microsoft’s massive Patch Tuesday releases continue as AI reshapes bug discovery
- Delta probes Wi-Fi deauth attack on flight carrying DEF CON attendees
- Veracode Finds AI-Generated Code Still Struggles With Security
Lee Neely
- LexisNexis shuts down services after suspicious activity on servers
Summary: LexisNexis took its Diligence, Metabase API, and Newsdesk services offline as part of its response to unusual activity on servers hosted and managed by an unnamed third-party vendor. The company said it is investigating the incident with assistance from a cybersecurity forensic firm and is rebuilding affected systems in a new environment before bringing the services back online.
Lee's Take: Don't get confused connecting Nexus Metabase API to Metabase Cloud, not the same company/product. In this case anomolous activity was detected on third-party hosted services, and LexusNexus elected to disconnect those services rather than wait and see what happened. The takeaway here is to drill down on your monitoring of your third-party services, and your response plan should unexpected activity be detected. That's probably a long conversation, but one you need to nail down before you need it.
- Attackers pick Levi’s pockets in social engineering attack
Summary: In a filing with the US Securities and Exchange Commission (SEC), San Francisco-based Levi Strauss & Co. revealed a cybersecurity breach via social engineering allowed threat actors to access to three company-issued computers. Levi Strauss "initiated response protocols, implemented containment measures, launched an investigation, which remains ongoing and engaged the services of third-party cybersecurity experts." Initial findings from an ongoing investigation indicate that corporate data were exfiltrated, but operations were not disrupted.
Lee's Take: eusable credentials need to go the way of the Dodo bird. And you need to move not just to MFA, but phishing resistant MFA. Coincidentally, I saw an announcement from Microsoft that they are moving phishing resistant authentication. Specifically making passkeys the default authenticator on September 1st for users currently enabled for SMS or Phone prior to retiring SMS and Phone validation next February 1st.
- Metabase Patches Critical SQL Vulnerability, Notifies Framework That Customer Data Were Compromised
Summary: Metabase has released a security update to address a critical SQL injection vulnerability that could lead to administrative access. While Metabase Cloud instances have received the update, users running self-hosted instances need to upgrade to a fixed version. Users whose Metabase instance endpoints are publicly accessible are urged to take the following steps after upgrading to a fixed version: "1) Revoke all active user sessions by accessing the Metabase application database and deleting all rows in core_session table; 2) Review API keys and delete any unrecognized keys; 3) Review administrator accounts for any unexpected changes: 4) Rotate credentials for any of the connected databases; 5) Review data warehouse logs for any sign of unauthorized access; 5) Review Metabase activity and query history for unexpected or unauthorized activity." San Francisco-based laptop company Framework has notified its customers that their names, phone numbers, and email, physical, and login IP addresses have been compromised. Framework learned of the breach from Metabase. https://techcrunch.com/2026/08/07/computer-maker-framework-notifies-all-customers-of-a-data-breach/
Lee's Take: Beyond the update to Metabase, the added steps are critical to invalidate all existing sessions and connections which could then return regardless of the fix. Don't cut corners, you don't want to repeat this exercise because you missed something. Framework computers are popular as they are modular and repairable/upgradable. While the attack path to Framework was via the Metabase flaw, the attackers only accessed customer's personal data, not payment information. Hopefully, their customers already have Credit/ID Monitoring in place.
- Coast Guard says it is monitoring cyberattack that disrupted North Carolina’s ports
Summary: The US Coast Guard and other authorities are investigating a cyberattack that temporarily disrupted operations at the North Carolina Ports Authority, which comprises Port of Wilmington, the Port of Morehead City, and Charlotte Inland Port North Carolina. The North Carolina Ports Authority confirmed that it detected the incident on Tuesday, August 4, and told the media that the attack was the work of an outside threat actor and that the Ports' IT team implemented its Cybersecurity Contingency Plan. As of Wednesday, August 5, the incident was reportedly contained and recovery is now underway.
Lee's Take: North Carolina serves as a trade hub along the southeastern U.S., agricultural exports, retail goods, and raw materials predominantly flow through the port of Wilmington, and when you consider the volume of the three ports, thiscould have been a fairly disruptive supply chain attack. While the details are getting sorted, it's important to note their incident response and contingency plan both appear to be working as planned, to include minimal schedule disruptions. Make sure you're set to do as well when it's your turn in the barrel.
- National Rural Water Association and DEF CON Franklin Launch Water Watch Center
Summary: The US National Rural Water Association (NRWA) and DEF CON Franklin have launched the Water Watch Center (WWC), which provides small water utilities with threat intelligence and support to better protect their systems from cybersecurity attacks. Five managed detection and response providers - Rapid7, Defendify, Legato Security, L1 Secure and Sentinel Technologies - will work with DEF CON Franklin and NRWA to provide cybersecurity services to water utilities serving fewer than 10,000 people, which account for more than 90 percent of the country's water systems.
Lee's Take: Water utilities are being targeted, and compromised, notably via PLCs exposed to the Internet. If you're a small water systems, typically serving fewer than 10,000 people, you need to leverage resources, such as the WWC, from NRWA. NRWA has multiple initiatives and partnerships, including the WaterISAC, SANS, Microsoft and DEFCON Franklin along with a bunch of resources you can leverage to help raise the bar on your utility.
- SonicWall SMA1000 Flaws Exploited in Ransomware
Summary: Two flaws in SonicWall SMA1000 that were added to the KEV and fixed in mid-July 2026 — a server-side request forgery allowing requests to an unintended location (CVE-2026-15409, CVSS score 10.0) and a code injection vulnerability allowing arbitrary OS commands as administrator (CVE-2026-15410, CVSS score 7.2) — have now been observed in use in ransomware campaigns. These flaws affect SMA1000 models 6210, 7210, and 8200v, and users are urged to apply the appropriate hotfix, perform forensic analysis of the system, and take additional actions if indicators of compromise are present: re-image hardware or re-deploy virtual appliances, rotate all passwords, and reset TOTP tokens.
Lee's Take: Apply the hot fix. When you apply the SonicWall hotfix, don't skip the check for IOCs, you need to know if you've got additional work or not.
- Progress Kemp LoadMaster Flaw Exploited
Summary: LoadMaster is a load balancer made by Progress Kemp, and CVE-2026-8037, CVSS score 9.6, allows an unauthenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in command endpoints. Progress Kemp patched this flaw alongside a high-severity flaw not known to be exploited, which allows an attacker to upload files with dangerous extensions by exploiting a lack of whitespace normalization in the OWASP Core Rule Set. These flaws affect Kemp LoadMaster GA v7.2.63.1 and older, and LTSF v7.2.54.17 and older; users should consult the table in the Progress Kemp advisory to update to the appropriate fixed version.
Lee's Take: LoadMaster is another case of unvalidated input, to include whitespace in filenames. Not throwing them under the bus here, it's imperative that you sanitize ALL input, regardless of how hard you think it is to supply invalid input. That can be hard and tedious, but you really need to find and fix this before your adversaries leverage it. Apply the update, make sure that you're on their security alert mailing list
- A data breach at shipping giant Ceva Logistics is rippling across banks, retailers, Steam gamers, and beyond
Summary: CEVA Logistics, one of the biggest shipping and logistics companies in the world, has suffered a major cyberattack, the effects of which are trickling down to many of its clients.
The details of the hack itself, however, are not yet publicly available and what little information is out there came from the affected clients themselves.
CEVA has not yet issued an official statement, or filed a report with the regulators, but confirmed to TechCrunch that the attack most likely started on July 29, 2026, and affected at least eight warehouses across Europe.
Lee's Take: CEVA is a fully owned subsidiary of the CMA CGM group, the world's third-largest shipping company, operates 1,000 warehouses and handled 15 million shipments last year. CEVA has been notifying retailers of the breach, which are, in turn, notifying affected customers. Nobody is taking credit for the attack yet. The data includes the information relating to shipments from May through July - name, address, phone, email and item purchased. Note that CEVA does have an information retention policy and is only collecting the information needed to deliver the shipment; a best practice for third-party integration. That said, this data is a boon for a targeted social engineering attack or other scams, so be on the alert for such activity if you're affected.
- From Screen Share to Root Access: Breaking Down CVE-2026-43760 and CVE-2026-65400 on macOS
Summary: Apple has released out-of-cycle security patches to fix a high-severity flaw in the Screen Sharing service for macOS Sonoma, Sequoia, and Tahoe. CVE-2026-65400, CVSS score 7.1, allows an attacker on the network to authenticate to Screen Sharing without valid credentials, by exploiting a flaw in the implementation of Secure Remote Password.
Lee's Take: It's easy to look at the security update and note only one flaw is fixed. Rather than second guessing where screen sharing is and isn't used, push the update to your macOS 26 (Tahoe), 15 (Sequoia) & 14 (Sonoma) systems. Then get moving on updating those Macos 14 systems - Apple is getting ready to release macOS 27 (Golden Gate), ending support for Sonoma. Plan on a three-year lifecycle for any given macOS version, ideally updating yearly to stay on the latest release.
- Off-by-1 Labs Research: AI-generated vulnerability patches require human review
Summary: We studied what happens when Large Language Models (LLMs) generate vulnerability patches for recently disclosed, complex vulnerabilities. Our data shows that LLMs produce Fix-Like Artifacts with Embedded Defects (FLAWED) 53.9% of the time when complex patches are required.
Lee's Take: With so much of flaw discovery and remediation being driven through the use of AI, it's really tempting to follow suit with your chosen LLM, because if they can do it so can you right? The trick is, just like that new intern, you need to review the work to make sure it's right. It is super tempting, particularly with complex solutions, to forgo that. You know the cliche - work smarter, not harder. Have it create an implementation plan with checkpoints, consciously decide what you're going to do and where you're checking its work. Have it site sources for its work. Make sure the fix doesn't modify application behavior or introduce a new flaw.
