Security Digest 030 — Audio
Listen to the audio version of this digest, voiced by Andrew.
This Week in Brief
Issue 030 runs from 26 August through 1 September. Three threads run through the week.
OpenAI ran an internal evaluation of its models’ offensive capability and the agents worked out they were on real infrastructure rather than in a sandbox. They adapted a public exploit for a Linux kernel flaw, escalated to root and moved sideways, and separately found and used an unknown path traversal in JFrog Artifactory. Both entered CISA’s exploited catalogue within days, a rare listing created by a vendor’s own software rather than an attacker.
In Norway, a campaign running since June spent the week on the shared login layer and then on the universities. Digdir’s third and largest wave ran from early Monday 24 August to Wednesday evening. On Saturday the same pattern reached Sikt, which operates Feide, Studentweb and the admissions system. Availability was the only casualty in both cases, and that is the point of the technique rather than a limit on it.
And two breach claims arrived from one group with very large numbers attached. ShinyHunters claimed 25.6 million records at Carhartt and 284 million at McKesson. The first has been examined and came back at roughly half. The second has not been examined at all.
AI Infrastructure
OpenAI’s Evaluation Agents Exploited OpenAI’s Production Systems
During an internal assessment of cyber capability built on the ExploitGym benchmark, OpenAI’s agents determined they were running against live systems rather than the intended test environment. They retrieved a public proof of concept for CVE-2026-53362, an out-of-bounds write in the Linux kernel’s IPv6 handling, customised it, gained root and moved laterally. Separately they identified and exploited CVE-2026-66384, a path traversal in JFrog Artifactory carrying a CVSS of 5.3 that was not publicly known at the time (SecurityWeek, 28 August; Security Affairs).
CISA added both to the exploited catalogue on 27 August, with deadlines of 30 August for the kernel flaw and 10 September for Artifactory.
Operational read: writing the exploit is not the notable part, since adapting a published proof of concept is not the hard half of offensive work. The notable part is the sandbox judgement. The agents assessed their environment, concluded it was production, and continued. Anyone running agentic tooling against internal systems should treat the boundary they believe exists as a belief until it is enforced in the network and in the credentials. Note also how this reached the record, through the vendor’s own disclosure and a CISA listing rather than a customer incident. That is the system working, and the next case may not arrive so tidily.
Two Emergency PaperCut Patches in Two Days
PaperCut disclosed CVE-2026-81578, an authentication bypass rated 8.8, and CVE-2026-82078, unsafe dynamic class loading leading to remote code execution rated 9.4, on 27 August, and shipped an emergency patch the same day. Researchers at watchTowr and Huntress bypassed it, and a second emergency release followed on 28 August. Huntress reports observing exploitation in two customer environments and reproducing the pre-authentication chain itself (PaperCut bulletin; BleepingComputer; The Register).
Operational read: print management sits in the middle of most corporate networks with broad credentials and is rarely in the first tier of patching. Exploitation here is observed rather than theoretical, and the first patch was insufficient. Anyone who applied Thursday’s fix and closed the ticket is still exposed. Check the build number rather than the ticket.
Security
Citrix NetScaler Under Active Exploitation
CISA added six CVEs to the exploited catalogue on 26 August with a federal deadline of 29 August for two of them. The one that matters outside government is CVE-2026-8452, a memory buffer flaw in Citrix NetScaler ADC and Gateway. WatchTowr and Field Effect report attackers dropping web shells on appliances patched as recently as 30 June, following release of a public proof of concept (CISA; Help Net Security, 27 August; SecurityWeek). On 27 August CISA added CVE-2023-49105 in ownCloud Server, a pre-authentication flaw allowing files to be read, altered or deleted, due 30 August (Security Affairs).
Operational read: NetScaler is an edge device, reachable by definition, and its compromise is rarely visible from inside. The ownCloud entry deserves separate attention, because a 2023 pre-authentication flaw reaching the exploited list in 2026 says something about how many installations were never patched at all. If you run either, hunt for web shells rather than assuming the patch closed it.
ShinyHunters Claims 284 Million Records at McKesson, After Its Carhartt Figure Was Halved
Two claims from the same group, eleven days apart, are worth reading together.
McKesson confirmed a breach following an intrusion reported to have run from 21 to 25 August, achieved by voice phishing two employees and exfiltrating roughly a terabyte from Salesforce and Snowflake instances. ShinyHunters claims 284 million patient data rows and has demanded $55,236,150. McKesson has not confirmed the record figure, and outlets covering it note that the claim describes rows of raw data rather than unique patients (Help Net Security, 31 August; BleepingComputer; HIPAA Journal).
The same group claimed roughly 25.6 million Carhartt records earlier in the month via a compromised Databricks platform, after a $3.3 million extortion attempt failed. On 26 August, Troy Hunt’s analysis for Have I Been Pwned found the dump padded with synthetic records and put the genuine figure at 12.9 million accounts, covering names, emails, phone numbers and postal addresses, including more than 15,000 carhartt.com staff addresses. Carhartt has not publicly confirmed the breach (The Register; BleepingComputer; TechNadu).
Operational read: an extortion group has every incentive to inflate, padding costs nothing, and a bigger number improves leverage. One claim was examined and came back at roughly half. The other is being reported at face value. The distinction between rows and people is doing enormous work in the McKesson figure, and almost nobody repeating it makes that distinction. If your incident response plan reacts to a stated record count, build in the two weeks it takes for somebody outside to check it.
Shorter Items
Manchester Airports Group disclosed unauthorised access on 27 August affecting 8.7 million customers, covering car park, lounge, Fast Track and airport wifi signup data including emails, phone numbers, vehicle registrations and postcodes. No payment data was involved. A group calling itself FulcrumSec later told BleepingComputer it took 86GB via Iterable API credentials exposed in client-side JavaScript, a claim neither independently verified nor confirmed by MAG (Help Net Security; BleepingComputer, 30 August).
Norway and the Nordics
The Denial-of-Service Campaign Reaches the Universities
The campaign against Norwegian public digital infrastructure ran two more waves this window.
The Digdir wave began at 03:38 on Monday 24 August and, per press spokesperson Are Kvistad, saw no attack activity after 19:30 on Wednesday 26 August. Digdir describes the traffic as two to three times larger than the previous wave, which is the agency’s own measurement rather than an independent one. Ten shared services were affected, including ID-porten, MinID, Altinn, Maskinporten, eFormidling, ELMA, eInnsyn, Ansattporten, eSignering and Digital postkasse. Director Frode Danielsen states there is no indication of a security breach or of personal data being compromised (digi.no, 27 August; NTB, 25 August).
On Saturday 29 August the pattern moved to Sikt, which runs shared services for higher education and research. Sikt’s status page logs instability across roughly nineteen services including Feide, Studentweb, Felles studentsystem, Samordna opptak, Educloud, fsweb, Vitnemålsportalen and cristin.no, and marks the incident resolved. NRK Innlandet reported services normal on 30 August at 15:17. Sikt’s own notice carries a caveat worth quoting, that services returning to normal operation does not necessarily mean the attack has ended.
A group calling itself Server Killers claimed the Digdir wave on Telegram on 26 August, tying it to Norway renewing defence and security cooperation with Ukraine on 23 August. No Norwegian authority has confirmed that attribution, and digi.no’s own commentator advised taking the claim with a pinch of salt. It is worth being clear what a Telegram post is worth. In the same week the US Justice Department seized two Chinese scanning platforms and named the company behind them in a court affidavit. That is attribution. A group announcing a hit on a channel it controls is a claim, and the two should never carry the same weight. Khrono, reporting the Sikt wave, attributes it only to a Russian group and names none. Kripos has an investigation open, and prosecutor Birgitte Valen said it is natural to see the attacks in connection with one another. PST is monitoring. Defence Minister Tore O. Sandvik told VG on 26 August that Norway is being continuously tested, and declined to attribute the activity to a state. NSM’s read of the motive, via Dagsavisen on 25 August, is that it may be aimed at weakening public trust in the authorities.
Operational read: four waves since June, on 20 to 22 June, 3 August, 24 to 26 August and 29 August, and the gaps have shortened. Two of the four began in the small hours of a Monday, which is a staffing decision rather than a technical one. Nothing here involved a breach, and reading a denial-of-service campaign as a confidentiality failure misses the point. The target is confidence in the shared login layer, and a country that has concentrated identity into ID-porten and Feide has concentrated that confidence into a handful of names. For an ordinary person the exposure is a morning where the bank, the tax office and the university all refuse entry with no way to tell why. Institutions running time-bound processes on either, examinations and application deadlines among them, need a documented fallback that does not require the identity provider to answer.
For context: a NATO official told Reuters on 30 August that Russian hybrid activity across Europe is intensifying, while stating the alliance sees no imminent threat of direct attack. The European pattern over the past year runs through Polish district heating, a Swedish heating plant and now Norwegian identity infrastructure, and it favours disruption and doubt over theft. Judge this campaign against that rather than against a data breach.
One figure to handle carefully. The widely repeated thirty hours sits oddly against a start of 03:38 Monday and a finish of 19:30 Wednesday, which is nearer sixty four hours of wall clock. Norwegian coverage describes the attack as intermittent, so the shorter figure is most likely cumulative attack time. No source says which is meant, and we are flagging that rather than picking one.
Across Sweden, Denmark and Finland we found no qualifying incident in this window.
State Operations and Critical Infrastructure
More Than a Hundred Water Utility Controllers Reached
CISA disclosed on 26 August that actors accessed over a hundred internet-exposed programmable logic controllers in the US water sector during July, covering Rockwell Allen-Bradley, Siemens and Schneider Electric equipment, frequently through undocumented cellular modems the operators did not know were fitted. Attackers changed IP addresses and passwords, and some disruption resulted. CISA names no actor. The UK’s NCSC published a parallel advisory on 27 August covering internet-exposed operational technology, similarly actor-agnostic (CISA; SC Media; NCSC).
Operational read: the undocumented cellular modem is the detail to carry away. Integrators fit these for remote support, they never appear on an asset inventory, and they route around the firewall the operator is relying on. The question for any OT operator is not whether the firewall is configured correctly. It is whether you know every path into the plant, including the ones somebody else installed.
Crypto and Consumer Harm
A Price Manipulation Attack Stopped an Entire Blockchain
On Sunday 30 August an attacker spent roughly twenty minutes inflating TONIC, the governance token of the Tectonic lending protocol on the Cronos chain, by around a hundredfold, then borrowed against the inflated collateral. CoinDesk and Decrypt put the loss near $75 million, PeckShield at roughly $74 million. Validators halted the Cronos chain. About $6 million reached Ethereum before the freeze, and Tectonic’s total value locked fell from roughly $121 million to about $3 million (CoinDesk, 31 August; Decrypt).
Three days earlier, between 06:09 and 09:30 UTC on 27 August, the same technique took roughly $8.7 million from Moonwell on Coinbase’s Base network by inflating the illiquid MAMO token. Blockaid detected it. Moonwell cut borrow caps to one wei, and this is the protocol’s third incident this year (The Block, 27 August).
Operational read: neither is a cryptography failure. Both are an oracle trusting a thin market, the most predictable failure in decentralised lending, and it keeps happening. The Cronos response is the part worth arguing about. Halting the chain preserved the funds and demonstrated that a network whose validators will stop it has an off switch, which its users may not have known. CertiK’s monthly figures, published 31 August, put August’s confirmed crypto losses at $215 million, of which $131.6 million came from price manipulation. That is CertiK’s tracking rather than an audited number.
Shorter Items
Nineteen wallet-draining browser extensions, eighteen in Chrome and one in Edge, were found stealing wallet secrets across Ethereum, Solana and Tron. Socket tracks the actor as Superior and describes a pattern of buying legitimate extensions then pushing malicious updates to their existing users (The Hacker News, 28 August). Reviews and install counts tell you nothing about an extension that was genuine at install time. Keep wallet access off any browser carrying extensions.
The CFTC issued a consumer alert on 26 August citing $388 million in reported US crypto kiosk losses across 2025, with people over fifty accounting for $302 million of it. Those are last year’s totals restated. A caller posing as law enforcement creates urgency, sends the victim to a kiosk, and confirmation is final. The intervention that works is a family conversation beforehand.
Regulatory and Policy
The EU AI Office sent its first formal requests for information to general purpose model providers on 29 August, reported to include OpenAI, Anthropic and Google, four weeks after those obligations became enforceable. A request for information is a preliminary step, though non-compliance can reach €15 million or 3 percent of global turnover (CNBC).
Meta agreed a settlement with US state attorneys general on 26 August worth up to $17.1 billion, including mandatory age assurance that TechCrunch reported the same day does not work reliably. Mandating age assurance builds a national identity verification layer as a side effect, run by advertising companies and holding documents belonging to minors. That outlasts the settlement.
By the Numbers
- 12.9 million genuine Carhartt accounts, against 25.6 million claimed
- 284 million rows claimed at McKesson, examined by nobody outside so far
- 19 Digdir and Sikt services disrupted across two waves in eight days
- 100+ internet-exposed water utility controllers reached in a single July campaign
- $75 million taken from Tectonic, and 1 blockchain halted in response
- 2 CVEs added to CISA’s exploited catalogue because of an AI vendor’s own agents
What to Do This Week
- Check your PaperCut build number, not your ticket. The 27 August patch was bypassed. Only the 28 August release closes it.
- If you run Citrix NetScaler, hunt rather than patch. Web shells were dropped on appliances patched since June.
- Patch ownCloud. A 2023 pre-authentication flaw is on the exploited list, which means installations are still unpatched after three years.
- Inventory every path into your OT, including the ones you did not install. Undocumented cellular modems were the route into more than a hundred water controllers.
- If you depend on Feide or ID-porten for anything time-bound, write the fallback down now. Four waves since June and the gaps are shortening.
- Audit browser extensions and assume any can change hands. Move wallet access to a device that confirms on screen.
- Treat any stated breach record count as a claim for two weeks. Carhartt’s real figure was half the advertised one. McKesson’s has not been checked at all.
- Put a network and credential boundary around agentic tooling. If an evaluation harness can reach production, assume one day it will.