August showed that cyber risk is intensifying on multiple fronts at once. Global attacks continued to rise, ransomware volumes accelerated, and phishing remained a consistent entry point for threat actors. GenAI added a more nuanced but equally important signal: while August recorded the lowest rate of high-risk for data exposure in GenAI prompts in several months, enterprise AI usage continued to expand sharply, with the average number of prompts per user rising from around 78 in June to 95 in July and 106 in August. This suggests that most of the growth is coming from acceptable business use, but sensitive data exposure through prompts remains a persistent risk that organizations can no longer treat as experimental or peripheral.
Cyber Attacks Keep Climbing The global attack curve continued to move upward in August, with organizations facing an average of 2,422 weekly cyber attacks. This marks a 4% increase from July, and a 22% increase compared with August 2025.
The broader four-month trend underlines the scale of the challenge: since May, the global average has climbed from 2,055 to 2,422 weekly attacks per organization, pointing to sustained pressure rather than a short-term seasonal spike.
Education Remains the Top Target as Travel-Related Sectors Rise
Education remained the most targeted sector, averaging 5,354 weekly attacks per organization, up 28% year over year. Government followed with 3,067 weekly attacks, while Hospitality, Travel, and Recreation rose to third place with 3,056 weekly attacks, up 56%. Its move into the top three, ahead of Telecommunications, suggests attackers may be taking advantage of the operational pressure and increased customer activity linked to the peak summer travel season.
Latin America Leads in Volume as Europe Records the Sharpest Increase
Regionally, Latin America continued to face the highest attack volume, with 3,577 weekly attacks per organization on average, up 25% from August 2025. Africa ranked second with 3,335 weekly attacks, followed closely by APAC at 3,325. Europe stood out for its growth rate, recording the highest year-over-year increase at 28%, while North America rose 18%.
Region
Weekly Attacks per Organization
YoY Change
Latin America
3,577
+25%
Africa
3,335
+3%
APAC
3,325
+16%
Europe
2,155
+28%
North America
1,744
+18%
GenAI Risk Remains a Daily Business Reality
GenAI risk is now part of everyday business operations, but the August data points to a shift in the risk profile rather than a simple increase in high-risk activity. High-risk GenAI prompts fell to their lowest level in several months, at 1 in every 43 prompts from enterprise networks posing a data exposure risk. At the same time, overall usage continued to climb, with the average user generating 106 prompts during the month. This means the expansion in GenAI activity appears to be driven largely by acceptable usage, while problematic data exposure prompts have not disappeared: 86% of organizations using GenAI regularly were still affected by high-risk prompt activity, and the wide usage of various AI tools, 7 different tools on average per organization, create a critical governance gap which enhances the potential risk.
For CISOs and business leaders, the message is clear: the risk is not only whether employees are using approved or unapproved AI tools, but what information they enter into them. As teams rely on multiple GenAI applications and generate higher volumes of prompts, sensitive data can move into environments that lack sufficient visibility, governance, or control. This also increases exposure to prompt manipulation and indirect prompt injections, where hidden instructions embedded in external content can influence AI behavior and potentially expose information.
By industry, Healthcare & Medical recorded the highest rate of high-risk GenAI prompt exposure at 4%, or 1 in every 25 prompts, climbing one spot from July. Software followed at 3.6%, or 1 in 28 prompts, while Business Services reached 3.5%, also equivalent to 1 in 28 prompts.
The sensitive data exposure rate for Healthcare & Medical organizations is particularly alarming when considering this is mostly relating to extremely private information, and with users on the medical staff who are less tech-savvy and work under high pressure, potentially neglecting advised usage guidance.
Such an example can be seen below, written in ChatGPT web service, and includes the full patient’s name, symptoms, examination results and diagnosis.
Regionally, Latin America recorded the highest high-risk GenAI prompt rate at 1 in every 29 prompts, or 3.5%, above the global average of 2.3%. North America followed at 1 in 40 prompts, APAC at 1 in 51, and Europe at 1 in 56. Regional differences are significant, but high-risk GenAI exposure across all regions confirms this is a global governance challenge as enterprise AI adoption accelerates.
The type of information being exposed also shifted in August. Network and IT Infrastructure became the most common sensitive data category, appearing in 67% of organizations where GenAI prompts contained sensitive data. Financial Data followed at 65%, Legal and Regulatory at 64%, Employee and HR at 59%, and PII at 57%. This shows that GenAI exposure cuts across core business information, from technical infrastructure to financial, legal, employee, and personal data.
Data Category
% of Organizations
Network & IT Infrastructure
67%
Financial Data
65%
Legal & Regulatory
64%
Employee & HR
59%
PII
57%
Email Phishing Risk Increases
Email remained one of the most reliable entry points for cyber risk in August. One in every 112 emails, or 0.89%, was classified as phishing, up from 1 in 128 in July. Among phishing emails, 72% contained links and 14% contained attachments, confirming that malicious links remain a dominant delivery method. However, not all phishing relies on clickable payloads. Some emails used pure social engineering, such as requesting phone calls, sharing instructions, or encouraging direct engagement between the attacker and the victim.
North America recorded the highest phishing rate, with 1 in every 107 emails, or 0.94%, found to be malicious. By industry, Associations and Nonprofits saw the highest phishing rate at 1.87%, or 1 in 54 emails, around twice the global average. Construction and Engineering followed at 1.74%, and Real Estate, Rental, and Leasing at 1.13%.
Ransomware Activity Continues to Accelerate
* This ransomware data draws from ransomware “shame sites” operated by double-extortion groups, which publicly disclose victim information. While these sources have inherent limitations, they provide valuable insight into the ransomware landscape.
Ransomware activity continued to accelerate in August. A total of 1,042 ransomware attacks were reported, almost double the level recorded in August 2025 and 8% higher than in July. Business Services remained the most targeted industry, accounting for 36% of reported ransomware attacks, followed by Industrial Manufacturing at 13% and Consumer Goods & Services at 12%.
Industry
Ransomware Victims
Business Services
36%
Industrial Manufacturing
13%
Consumer Goods & Services
12%
Financial Services
8%
Healthcare & Medical
7%
Transportation & Logistics
4.1%
Information Technology
4.1%
Government
3.7%
Automotive
3.3%
Education
2.3%
North America remained the most affected region, accounting for 49% of reported ransomware incidents, followed by Europe at 27% and APAC at 16%. At country level, the United States was the most impacted country, accounting for 45% of reported ransomware attacks. Germany and Italy followed, both close to 5% of reported victims, with Canada, the United Kingdom and France also among the top affected countries.
Qilin Leads as Orova Enters the Top Three
Qilin was the most prevalent ransomware group in August, responsible for 15% of published attacks, followed by The Gentlemen with 10%. Orova entered the top three for the first time, accounting for 4% of published attacks.
Qilin: An established Ransomware-as-a-Service group with a consistent record of victim disclosures dating back to 2022. Its mature affiliate model and renewed recruitment efforts have helped it maintain strong momentum in recent months.
The Gentlemen: A fast-growing Ransomware-as-a-Service operation launched in mid-2025. The group combines ransomware operations with initial access brokering, enabling affiliates to scale attacks quickly.
Orova: An emerging ransomware group that surfaced publicly in May 2026 and has quickly gained visibility. Its activity appears access-driven rather than sector-driven, with victims concentrated among small and mid-sized businesses.
What August Tells Us
August reinforces a clear reality for security teams: prevention must now extend across every layer of the enterprise, including the fast-growing AI usage layer. Attacks are rising, ransomware remains highly active, phishing continues to open the door to compromise, and GenAI is creating a new path for sensitive data to leave the organization’s control. The priority is no longer visibility alone, but preventing exposure before it becomes impact through coordinated protection across network, cloud, endpoint, email, and AI usage.
Posted in Commentary with tags Volvo on September 10, 2026 by itnerd
The highly popular Volvo XC40 is getting significant updates to make everyday life on the road easier and more enjoyable, ranging from updates to exterior and interior design to infotainment, advanced driver assistance and active safety.
A refreshed exterior design gives the XC40 a more confident and contemporary presence. The new design of the Thor’s Hammer Matrix LED headlights is one of the most eye-catching updates, with a refined take on the iconic light signature. An upgraded grille and redesigned front bumper, hood and front wings provide a new elegant interpretation of Volvo Cars’ Scandinavian design language.
At the rear, the XC40 features new LED rear lights, an upgraded tailgate, and a redesigned rear bumper. The XC40 also comes with new 18-inch, 19-inch and 20-inch diamond cut wheels.
Intuitive and versatile on the inside The interior is upgraded with a new, larger and crisper 11.2-inch screen, bringing Volvo Cars’ latest user experience. The updated screen makes interacting with the car faster and easier, with fewer taps needed to access key functions, creating a seamlessly connected and intuitive experience for everyday driving.
Featuring Google Gemini, the next-generation AI assistant from Google, the XC40 is a car you can have a natural conversation with. From planning journeys and finding great stops to managing messages on the move, Gemini understands everyday language effortlessly.
Designed with everyday usability in mind, the interior combines smart storage space and thoughtfully integrated features, such as the updated wireless phone charger, to make life on the road more convenient. From busy weekday schedules to spontaneous weekend getaways, the versatile cabin adapts effortlessly to the changing needs of drivers and their families.
The cabin updates also include new premium upholstery and decor options to enhance comfort and design. For the first time, XC40 customers can opt for Arianne Cardamom leather upholstery paired with Brown Ash wood decor elements across the interior. The car also features refined cabin illumination plus the option of Black Ash or aluminium decor, bringing a modern expression to the interior.
Protecting what matters most Built on Volvo Cars’ pioneering safety knowledge from real-world research, the XC40 combines advanced safety technologies to help prevent collisions and protect people. If a potential collision is detected, the cars can respond in real time, warning the driver or stepping in to help avoid or reduce the impact. Whether steering around danger with automatic emergency steering or braking instantly with automatic emergency braking, it’s designed to help choose the safest action in the moment.
These enhanced safety capabilities are made possible by a new advanced software and sensor platform. With new front and corner radars, a new front camera, new rear corner radars, 12 new ultrasonic sensors and new parking cameras, the car gains a more comprehensive view of its surroundings, helping drivers feel more confident behind the wheel.
The upgraded platform also enables several new and upgraded safety and driver support functions:
Door Opening Alert helps protect cyclists and other road users by warning occupants before opening the door into passing traffic.
The optional Pilot Assist is expanded with lane change assist and refined to follow the road more smoothly, providing added support and comfort on longer journeys.
The optional 360 camera is upgraded to a 3D view that makes parking and low‑speed manoeuvres easier.
The small print
Availability of the features and services mentioned above may vary by market. Some features and services mentioned are optional and require customer opt-in.
Google and Gemini are trademarks of Google LLC. Some connected apps require setup. Compatibility and availability vary. 18+
The EU’s Cyber Resilience Act reporting requirements kick in Friday, September 11, and for many manufacturers, the hardest part won’t be filing a report. It will be figuring out what they actually need to report.
Do they have a vulnerability? Is it being actively exploited? Which products are affected? And can they answer those questions fast enough to meet a 24-hour reporting clock?
According to Doc McConnell, Head of Policy and Compliance at Finite State and former CISA Branch Chief and Senior Advisor for Cybersecurity Policy at OMB: “The biggest obstacle isn’t paperwork, it’s visibility. Many companies lack accurate software inventories across their product lines, and have limited insight into third-party components embedded in products.”
With the deadline just a day away, Doc can talk about where manufacturers are most likely to get caught off guard when a vulnerability arises and what happens as the 24-hour cybersecurity reporting mandate clock starts.
The streaming platform Twitch, along with its users, has found itself a victim of an alleged dark web data leak. A new advertisement has appeared on a well-known hacker forum, claiming that a threat actor has stolen information on about 40,000 Twitch users.
At any given moment, more than 2 million viewers are watching streams on Twitch. Even the remote possibility of a data leak or breach could therefore affect a large number of people.
Cybernews researchers investigated the claims, and here is what was found:
The attacker claims to have stolen usernames, URLs, emails, legal names, followers’ numbers, and the status of account verification
The data appears scraped, not taken from a direct Twitch breach.
Some emails were not public, so the attacker may have abused Twitch’s API.
Non-public emails in the sample suggest that the attacker may have exploited Twitch’s API.
“From what I see, this indeed looks like a data scrape, not a breach,” one of our researchers said. It is likely that the attacker compiled the dataset through other means, like collecting information from public streamers’ profiles.
As we’re all learning, in both frontier AI models and enterprise tools now in use, AI can get it wrong.
Most security teams don’t discover that an AI tool was wrong during testing. They find out either when an alert storm starts, their analysts stop trusting the tool, or a real threat slips through undetected.
Teams are asking how they can validate outputs in live environments before they cost time, money or a breach. It’s not yet a publicly discussed issue, but it’s one of the most important ones a security team has to resolve.
AI outputs in live environments can be 45-50% less accurate than vendor tests suggest.
Shadow mode testing, monthly Red Team replays, and metric drift tracking are the three most practical tools for live environment validation.
If the AI cannot explain why it made a call, you can’t verify whether it was right.
Analyst override rates are the most honest feedback signal you have. If analysts are regularly rejecting AI recommendations, that tells you what needs to change.
Validation is ongoing, not a one-time setup task. Model behavior drifts as environments change, and that drift needs to be checked monthly.
Posted in Commentary with tags Harness on September 10, 2026 by itnerd
Harness today released The State of Agent DLC 2026, a new report showing that enterprise confidence in AI agents exceeds the controls organizations have in place to test, secure, and govern them. This lack of control presents a significant risk for enterprises deploying AI agents.
AI agents don’t behave like deterministic software — the same agent can produce different outputs from one run to the next. That means they need controls built for that variability. Most organizations are still relying on controls built for deterministic software, and the report finds that gap is already showing up in production incidents, security breaches, and blown budgets.
Most Enterprises Trust Their AI Agents, Few Can Control Them
Ask organizations if they trust their AI agents, and most say yes. Ask a more specific question — do you have a tool that tells you every agent running in your environment, or a way to shut one off the moment it misbehaves — and the answer is often no. That gap holds across every domain the survey covered: testing, security, inventory, cost, and rollback. Confidence lands in the mid-70s of those surveyed in each case, but the control that would back it up is in place for less than half of organizations, and in some cases fewer than one in five.
Organizations don’t have full visibility into what’s actually running. 77% are confident they have a complete inventory of every agent, MCP server, and LLM in their environment, but only 44% run active discovery tooling to verify it.
Most can’t confirm testing would catch a failure before it ships. 74% are confident their testing would catch a production-impacting failure, but only 19% have a gate that automatically blocks every bad release.
If something does go wrong, most organizations couldn’t stop it fast enough. 76% believe they could disable a misbehaving agent in under 15 minutes, but only 33% have an instant kill switch in place.
Confidence in agent security has almost no relationship to actual resilience. 75% say their agents are secure end to end, but that group had security incidents at almost the same rate (88%) as the overall respondent population (87%).
Visibility into the budget isn’t helping spend control. 74% say they have a complete picture of true spend per agent, while 60% still overran their budget last quarter.
What the Confidence Gap Is Already Costing Organizations
The confidence gap shows up fastest in how changes actually get shipped. Most organizations are routing AI agent changes through pipelines built for code, without adjusting how those changes get tested, approved, or tracked.
There’s no real system for managing agent changes. 42% run prompt edits through the same pipeline as a code change, while just 34% have a dedicated configuration system for AI behavior.
Without dedicated tooling, organizations default to routing agent changes through code pipelines, inconsistently. Just 53% of agent-related changes go through any standard pipeline before production, and 37% run less than half of theirs through one.
With no consistent pipeline in place, whether to trust a given change comes down to judgment. More than 4 in 10 organizations decide case by case whether to trust a change, and among those that do promote agent changes to production, only 58% check every change against a fixed, repeatable standard.
Incidents are only climbing in number as agents scale. 58% of organizations report an increase in production incidents per 100 changes since deploying AI agents, and roughly 7 in 8 had at least one tangible agent-related issue this year.
How Organizations Are Closing the Confidence Gap
The report points to a consistent pattern among organizations closing this gap, and Harness recommends the same sequence to the teams it works with directly:
Treat the agent lifecycle as its own discipline. Build evals, security, inventory, and rollback specifically for agent behavior, rather than routing agent changes through the same pipeline built for non-deterministic software.
Replace ad hoc reviews with a fixed, repeatable standard. Every change promoted to production should be checked against the same standard, whether that check is automated or manual.
Adopt progressive rollout for agents, not just manual gates. Techniques like canary and blue/green deployment limit exposure, but remain far less common for agent changes than for code changes.
Posted in Commentary with tags Fortra on September 10, 2026 by itnerd
Fortra Intelligence and Research Experts (FIRE) are tracking an active phishing campaign, first observed in June, that uses HTA malware to gather detailed intelligence about a victim’s device before determining which payload to deploy next.
Rather than immediately delivering malware, the campaign performs reconnaissance on infected systems, collecting information such as OS, BIOS, and user details that can be used to tailor subsequent attack stages. Researchers found the operation combines HTA malware delivered via mshta.exe with off-screen execution, HTML smuggling, and polymorphic payloads designed to complicate detection.
The campaign appears focused on Spanish-speaking users and organizations, using invoice and judicial-notice phishing lures, while the infrastructure remains active and continues distributing updated samples.
Google created the Early Access program to help developers gather feedback before releasing finished applications. However, the feature appears to have become an attractive destination for some developers who may exploit one important aspect: users cannot leave public reviews or ratings while an app remains in Early Access.
An analysis of Google Play apps installed by Bitdefender users reveals thousands of Early Access applications that appear to include fake casino games and reward apps, as well as titles that may infringe on third-party trademarks and potentially misleading utilities.
Many are aggressively promoted through TikTok, Facebook, and other social media platforms using misleading advertisements that include videos using AI-generated celebrity deepfakes.
The result is an ecosystem in which consumers have almost no way to warn one another before installing questionable software.
Key Takeaways
Google’s Early Access program disables public ratings and reviews.
Many deceptive developers appear to exploit this limitation.
Numerous Early Access listings promise money, rewards, casino winnings, or premium content.
Users cannot publicly warn others if an app is misleading.
Trademark-infringing titles are also appearing inside Early Access.
The lack of transparency makes it significantly harder for consumers to distinguish legitimate beta software from deceptive applications.
What is Google Play Early Access?
Google launched Early Access to give developers a platform to publish unfinished or still-in-development applications and collect feedback from early adopters.
Instead of waiting for a polished release, developers can test features, fix bugs, and improve performance based on user experiences. This platform would also help independent developers avoid poor ratings due to temporary bugs or missing features.
This sounds great, in theory, but the problem is that Early Access removes one of Google Play’s most important trust signals: public reviews and star ratings.
New users can’t see whether previous users faced scams, annoying ads, fake casino payouts, or other misleading claims.
Why scammers are increasingly attracted to Early Access
Several characteristics make Early Access unusually attractive to operators running misleading applications.
Public reviews disappear. The biggest incentive is simple. Users can’t publicly warn one another if the app floods users with ads, if a reward app never actually pays or if a fake utility app demands excessive permissions. And that’s only a handful of “ifs” as there are countless other scenarios in which users cand be tricked.
A normal release would quickly accumulate one-star reviews, which would be a good signal for others to avoid it.
Fake money-making apps become much harder to identify. A recurring pattern among suspicious Early Access apps involves promising cash rewards, PayPal payouts, cryptocurrency earnings, gift cards, free spins or casino jackpots.
Many of these applications rely on the same engagement loop. The user installs the app after watching an advertisement on TikTok or Facebook. They might even receive generous virtual rewards almost immediately, but when they reach a withdrawal threshold, progression slows dramatically. The promised payout will never arrive.
Instead, the application continues serving advertisement after advertisement, which is likely the intended use for the developers: to make money by showing ads to as many people as possible.
The anatomy of an “Early Access ghost casino”
Legitimate gambling applications face strict regulatory requirements. Depending on jurisdiction, they often require licensing, geofencing, age verification and many other regulatory measures.
Many suspicious Early Access casino-style apps avoid those expectations entirely because they don’t necessarily present themselves as regulated gambling products.
Instead, they resemble casual slot games, reward games, or puzzle titles. People are first tricked into installing the apps by being redirected from ads on social media. Many of these ads blatantly use deepfakes of famous athletes, actors or other public figures that tell everyone how you’re getting 250 spins for free. Of how you only need to cross the road as a chicken without being run over.
Random users on TikTok, for example, make videos of themselves instantly receiving the money in their accounts. To be fair, TikTok or Facebook are usually quick to take down these ads and videos, but that doesn’t stop the attackers from coming up with new scenarios.
Here are some screenshots from TikTok ads using deepfakes:
When active, some of these ads pointed to Early Access apps in the Google Play Store or directly to various gambling websites.
Chicken Road or Ice Fishing games
Some of the most abused titles for game are Chicken Road or Ice Fishing (or variations on the same theme) that all promise the same thing: to multiply the money you invest. The ads make it seem like it’s very easy. Just help the chicken cross the road, and every time you don’t get hit by a car, you double your money.
This is just one example, but there are numerous others. This one is still active; others have been deleted and new ones arrive all the time.
Trademark abuse appears surprisingly common
The Early Access catalog also contains applications that appear to borrow well-known intellectual property, some more blatantly than others.
Some titles appear to be designed to resemble legitimate games or established brands, despite having no visible connection to the original publishers.
A popular strategy is to add an app to the Google Play Store using an established name. Let’s take the GTA franchise. As it stands right now, there are at least two games that use this technique. Both of them were uploaded with the name Grand Theft Auto V (Early Access), only to be renamed later, after being indexed by Google search, to something entirely different.
The screenshot below illustrates only a small sample of Early Access listings collected during the investigation, including multiple apps referencing recognizable brands and casino-style mechanics.Here’s another example of a game trying to copy the Grand Theft Auto franchise. It had the actual name for a while, only to change it to something else. The game screenshots in the store are likely from consoles or the PC versions of the game.
Here’s another example of a game trying to copy the Grand Theft Auto franchise. It had the actual name for a while, only to change it to something else. The game screenshots in the store are likely from consoles or the PC versions of the game.
Now, the same game has a completely different title and screenshots (AI-generated, not even representative of gameplay). In fact, the entire game is designed to serve aggressive ads and when or if you actually manage to actually play the game, you will notice it looks nothing like what they are showing in the presentation.
Keep in mind that they boast more than 1 million downloads, but the game has no reviews or ratings, which is usually a good indicator that it’s in the Early Access program.
Evidence suggests the problem is widespread
During this investigation, a review of Early Access listings identified a large number of applications spanning several recurring categories.
These included:
casino games
slot machines
fake reward apps
“earn money” applications
PDF readers
QR scanners
phone trackers
utility apps
trademark-themed games
Some developers appear multiple times under different application names, and many games and apps are virtually identical, with small differences. Several listings also accumulated thousands of installs or more despite remaining in perpetual Early Access.
In fact, we also noticed a large number of PDF readers and QR scanners present in the Early Access program, many of which were actually the same app uploaded by seemingly different developers.
The screenshots collected during the investigation represent only a fraction of the overall catalog.
Why this matters
Google Play’s reputation depends on trust. Ratings and reviews help users make informed decisions, but when those indicators are not present, it makes the users’ job a lot more difficult when they are trying to spot fakes.
Removing the comments and ratings protects legitimate developers from unfair review bombing, but it also removes one of the community’s strongest defenses against deceptive software.
Conclusion
Google’s Early Access program remains a valuable tool for developers testing new ideas. However, our insights suggest that its current implementation also creates an environment where deceptive applications can operate with far less public scrutiny than fully released apps.
When users cannot leave reviews, future users lose one of the most effective warning systems available on any app marketplace.
As fake reward apps, casino-style games, and misleading utilities continue appearing under the Early Access banner, the question is no longer whether the program can be abused.
Users are much quicker to trust an app or game that comes from an official source like the Google Play Store, which is why the Early Access feature is so dangerous.
This article is published for informational and educational purposes only. The information presented is based on technical research conducted by Bitdefender Labs and publicly available sources. Bitdefender does not make any legal determination regarding the activities described herein. The mention of any company, brand, domain, or individual does not constitute an accusation of illegal activity. All trademarks mentioned belong to their respective owners. Readers should exercise their own judgment and consult appropriate authorities or legal counsel if they believe they have been affected by any of the activities described. Domain names and URLs listed in this article are provided solely to help consumers and security professionals identify potentially harmful infrastructure. Bitdefender disclaims any liability for actions taken based on the information in this article.
Following Microsoft’s September 2026 Patch Tuesday security updates, a security researcher uncovered a new Microsoft Defender zero-day exploit named “ShieldCrash,” a bypass for the recently patched ShieldBreak Defender privilege escalation.
Ensar Seker, CISO at cybersecurity threat intelligence company SOCRadar, provided the following comments:
“ShieldCrash is concerning not simply because it affects Microsoft Defender, but because it appears to expose a recurring weakness in how this attack path has been remediated. When researchers can bypass successive fixes for RoguePlanet and ShieldBreak, it suggests the underlying security boundary or attack surface may require a more comprehensive redesign rather than another narrowly targeted patch.
It is important, however, to describe the current impact accurately. The publicly released proof of concept reportedly performs an arbitrary file read under the SYSTEM security context on fully patched Windows systems. That could expose highly sensitive files that an ordinary user cannot access, including configuration data, credentials or other secrets. Based on the information currently available, it does not yet provide an attacker with a full SYSTEM shell or arbitrary write capability. Nevertheless, privileged file disclosure can become an important component of a larger attack chain.
Organizations should not disable Defender as a reaction. Security teams should closely monitor Microsoft’s guidance and Defender intelligence updates, ensure tamper protection is enabled, restrict local execution and administrative access, and hunt for suspicious processes interacting with protected files through Defender-related mechanisms. Because proof-of-concept code is now public, defenders should assume attackers are examining it for ways to expand the primitive into credential theft, persistence or full privilege escalation. Microsoft should also assess the complete vulnerability class and related code paths, not only the specific condition demonstrated by this latest proof of concept.”
Microsoft responded with warnings of legal action against anyone engaging in “malicious activity causing real harm” to its customers, prompting many to believe that the company was directly threatening the security researcher.
Over the past several days, we have been listening to the conversation around coordinated disclosure and the relationship between security researchers and vendors. We recognize that this relationship is both critical and, at times, fragile. We deeply value the security community,…
— Microsoft Security Response Center (@msftsecresponse) June 1, 2026
But the fact is that the cat is out of the bag so to speak. Therefore Microsoft will need to deal with it. So lets see if they actually deal with it or not.
The managed platform, delivered through Parallel Works’ ACTIVATE control plane and built on CoreWeave’s AI cloud platform, provides researchers with immediate access to the large-scale computing, orchestration software, and technical support required for advanced biological modeling and AI, without the delays and complexity of building and managing infrastructure.
The rapid adoption of AI is reshaping scientific research. Delivering AI cloud infrastructure, however, can take months, which can delay research and consume technical resources. By delivering a fully managed environment, Parallel Works and CoreWeave allow researchers to train AI models and run complex simulations within days rather than weeks or months.
NODES addresses complex challenges in the dynamics of biological systems, work that requires large-scale, dependable computing resources. Rapid access to dedicated GPU resources enables program performers to pursue simulation and modeling campaigns without delays associated with accessing and managing infrastructure.
Researchers access the environment through a single sign-on, with the ACTIVATE platform combining direct support, dedicated compute, unified orchestration and operational visibility:
End-to-end support: Parallel Works operates the environment for DARPA through its ACTIVATE platform, which handles user onboarding, identity and access, provisioning, scheduling, and reporting, with around-the-clock direct-to-expert support for both the platform and researcher applications.
Dedicated compute capacity: A dedicated reservation on NVIDIA HGX H100 systems, enterprise-scale storage, and high-speed NVIDIA Quantum InfiniBand networking. Parallel Works ACTIVATE divides the reservation across the NODES research teams, so each team holds a guaranteed allocation and can draw on shared capacity when it is available.
Unified orchestration: Parallel Works ACTIVATE enables DARPA researchers to access SUNK and CoreWeave Kubernetes Service (CKS) uniformly from a single platform. SUNK, CoreWeave’s Slurm on Kubernetes offering, enables researchers to run workloads of different kinds and sizes efficiently in the same underlying compute environment. ACTIVATE manages the accounts, allocations, and sharing policies that determine how the research teams use those resources.
Operational visibility: Parallel Works ACTIVATE provides the program and each research team usage and utilization reporting across the environment, while CoreWeave’s observability stack monitors the health of the underlying fleet, so issues are caught at the infrastructure layer before they cost time on a multi-week run.
August 2026 Cyber Threat Landscape According To Check Point
Posted in Commentary with tags Check Point on September 10, 2026 by itnerdAugust showed that cyber risk is intensifying on multiple fronts at once. Global attacks continued to rise, ransomware volumes accelerated, and phishing remained a consistent entry point for threat actors. GenAI added a more nuanced but equally important signal: while August recorded the lowest rate of high-risk for data exposure in GenAI prompts in several months, enterprise AI usage continued to expand sharply, with the average number of prompts per user rising from around 78 in June to 95 in July and 106 in August. This suggests that most of the growth is coming from acceptable business use, but sensitive data exposure through prompts remains a persistent risk that organizations can no longer treat as experimental or peripheral.
Cyber Attacks Keep Climbing
The global attack curve continued to move upward in August, with organizations facing an average of 2,422 weekly cyber attacks. This marks a 4% increase from July, and a 22% increase compared with August 2025.
The broader four-month trend underlines the scale of the challenge: since May, the global average has climbed from 2,055 to 2,422 weekly attacks per organization, pointing to sustained pressure rather than a short-term seasonal spike.
Education Remains the Top Target as Travel-Related Sectors Rise
Education remained the most targeted sector, averaging 5,354 weekly attacks per organization, up 28% year over year. Government followed with 3,067 weekly attacks, while Hospitality, Travel, and Recreation rose to third place with 3,056 weekly attacks, up 56%. Its move into the top three, ahead of Telecommunications, suggests attackers may be taking advantage of the operational pressure and increased customer activity linked to the peak summer travel season.
Latin America Leads in Volume as Europe Records the Sharpest Increase
Regionally, Latin America continued to face the highest attack volume, with 3,577 weekly attacks per organization on average, up 25% from August 2025. Africa ranked second with 3,335 weekly attacks, followed closely by APAC at 3,325. Europe stood out for its growth rate, recording the highest year-over-year increase at 28%, while North America rose 18%.
GenAI Risk Remains a Daily Business Reality
GenAI risk is now part of everyday business operations, but the August data points to a shift in the risk profile rather than a simple increase in high-risk activity. High-risk GenAI prompts fell to their lowest level in several months, at 1 in every 43 prompts from enterprise networks posing a data exposure risk. At the same time, overall usage continued to climb, with the average user generating 106 prompts during the month. This means the expansion in GenAI activity appears to be driven largely by acceptable usage, while problematic data exposure prompts have not disappeared: 86% of organizations using GenAI regularly were still affected by high-risk prompt activity, and the wide usage of various AI tools, 7 different tools on average per organization, create a critical governance gap which enhances the potential risk.
For CISOs and business leaders, the message is clear: the risk is not only whether employees are using approved or unapproved AI tools, but what information they enter into them. As teams rely on multiple GenAI applications and generate higher volumes of prompts, sensitive data can move into environments that lack sufficient visibility, governance, or control. This also increases exposure to prompt manipulation and indirect prompt injections, where hidden instructions embedded in external content can influence AI behavior and potentially expose information.
By industry, Healthcare & Medical recorded the highest rate of high-risk GenAI prompt exposure at 4%, or 1 in every 25 prompts, climbing one spot from July. Software followed at 3.6%, or 1 in 28 prompts, while Business Services reached 3.5%, also equivalent to 1 in 28 prompts.
The sensitive data exposure rate for Healthcare & Medical organizations is particularly alarming when considering this is mostly relating to extremely private information, and with users on the medical staff who are less tech-savvy and work under high pressure, potentially neglecting advised usage guidance.
Such an example can be seen below, written in ChatGPT web service, and includes the full patient’s name, symptoms, examination results and diagnosis.
Regionally, Latin America recorded the highest high-risk GenAI prompt rate at 1 in every 29 prompts, or 3.5%, above the global average of 2.3%. North America followed at 1 in 40 prompts, APAC at 1 in 51, and Europe at 1 in 56. Regional differences are significant, but high-risk GenAI exposure across all regions confirms this is a global governance challenge as enterprise AI adoption accelerates.
The type of information being exposed also shifted in August. Network and IT Infrastructure became the most common sensitive data category, appearing in 67% of organizations where GenAI prompts contained sensitive data. Financial Data followed at 65%, Legal and Regulatory at 64%, Employee and HR at 59%, and PII at 57%. This shows that GenAI exposure cuts across core business information, from technical infrastructure to financial, legal, employee, and personal data.
Email Phishing Risk Increases
Email remained one of the most reliable entry points for cyber risk in August. One in every 112 emails, or 0.89%, was classified as phishing, up from 1 in 128 in July. Among phishing emails, 72% contained links and 14% contained attachments, confirming that malicious links remain a dominant delivery method. However, not all phishing relies on clickable payloads. Some emails used pure social engineering, such as requesting phone calls, sharing instructions, or encouraging direct engagement between the attacker and the victim.
North America recorded the highest phishing rate, with 1 in every 107 emails, or 0.94%, found to be malicious. By industry, Associations and Nonprofits saw the highest phishing rate at 1.87%, or 1 in 54 emails, around twice the global average. Construction and Engineering followed at 1.74%, and Real Estate, Rental, and Leasing at 1.13%.
Ransomware Activity Continues to Accelerate
* This ransomware data draws from ransomware “shame sites” operated by double-extortion groups, which publicly disclose victim information. While these sources have inherent limitations, they provide valuable insight into the ransomware landscape.
Ransomware activity continued to accelerate in August. A total of 1,042 ransomware attacks were reported, almost double the level recorded in August 2025 and 8% higher than in July. Business Services remained the most targeted industry, accounting for 36% of reported ransomware attacks, followed by Industrial Manufacturing at 13% and Consumer Goods & Services at 12%.
North America remained the most affected region, accounting for 49% of reported ransomware incidents, followed by Europe at 27% and APAC at 16%. At country level, the United States was the most impacted country, accounting for 45% of reported ransomware attacks. Germany and Italy followed, both close to 5% of reported victims, with Canada, the United Kingdom and France also among the top affected countries.
Qilin Leads as Orova Enters the Top Three
Qilin was the most prevalent ransomware group in August, responsible for 15% of published attacks, followed by The Gentlemen with 10%. Orova entered the top three for the first time, accounting for 4% of published attacks.
What August Tells Us
August reinforces a clear reality for security teams: prevention must now extend across every layer of the enterprise, including the fast-growing AI usage layer. Attacks are rising, ransomware remains highly active, phishing continues to open the door to compromise, and GenAI is creating a new path for sensitive data to leave the organization’s control. The priority is no longer visibility alone, but preventing exposure before it becomes impact through coordinated protection across network, cloud, endpoint, email, and AI usage.
Leave a comment »