Featured image of post Cybersecurity Week in Review: August 4–10, 2026

Cybersecurity Week in Review: August 4–10, 2026

Cyberattacks, data breaches, zero-days, and global responses—discover the biggest cybersecurity headlines of this week.

Major Data Breaches

Levi Strauss & Co. Employee Data Breach

Summary:
On August 7, 2026, Levi Strauss & Co. disclosed a significant data breach after hackers gained unauthorized access to company files by compromising three employee computers through a social engineering attack. The attackers exfiltrated certain corporate information, and the incident was reported in a filing with the U.S. Securities and Exchange Commission. Levi Strauss, a global apparel giant, is now investigating the full scope of the breach and has notified relevant authorities1.

Key Details:

  • Organization: Levi Strauss & Co. (USA)
  • Data Exposed: Corporate information (details under investigation)
  • Attack Vector: Social engineering leading to endpoint compromise
  • Discovery Date: August 7, 2026
  • Response: Incident reported to SEC, investigation ongoing

Amgen Patient Health Data Breach

Summary:
Biotech leader Amgen revealed that hackers accessed its cloud environment, stealing sensitive patient health information and proprietary company data. The breach, discovered in July and disclosed last week, involved unauthorized activity in cloud storage systems managed by external providers. Amgen activated its incident response plan and containment measures, but the full scope of compromised records is still being determined1.

Key Details:

  • Organization: Amgen (USA)
  • Data Exposed: Patient health data, proprietary company information
  • Attack Vector: Cloud storage compromise
  • Discovery Date: July 2026, disclosed August 4, 2026
  • Response: Forensic investigation ongoing, containment measures enacted

Actini Group Data Breach

Summary:
On August 10, 2026, Actini Group, a French industrial manufacturing company, was reported as a victim of a data breach attributed to the KRYBIT threat actor. Details on the nature and impact of the breach are still emerging2.

Key Details:

  • Organization: Actini Group (France)
  • Threat Actor: KRYBIT
  • Discovery Date: August 10, 2026

Significant Cyberattacks

Ceva Logistics Cyberattack

Summary:
Ceva Logistics, a major European freight company, suffered a cyberattack that disrupted operations at eight warehouses, causing shipping delays for retail customers. The incident, which began around August 1, 2026, is under investigation by the Dutch Data Protection Authority and other agencies. The attack highlights the vulnerability of supply chain logistics to cyber threats1.

Key Details:

  • Organization: Ceva Logistics (Europe)
  • Impact: Disrupted warehouse operations, shipping delays
  • Discovery Date: August 1, 2026
  • Response: Investigation by authorities, customer notifications

Hungary’s EU Farm Subsidy Agency Ransomware Attack

Summary:
Hungary’s National Paying Agency, responsible for EU agricultural subsidies, was hit by a ransomware attack traced to Russian servers. The attack encrypted files across employee computers, impacting the agency’s ability to process payments. The National Cybersecurity Institute is leading the response, and some services remain at reduced capacity1.

Key Details:

  • Organization: Hungary’s National Paying Agency
  • Attack Vector: Ransomware (Russian-linked)
  • Impact: Encrypted files, reduced operational capacity
  • Discovery Date: August 2, 2026

Poland’s Żabka Store Chain Cyberattack

Summary:
Żabka, Poland’s largest convenience store chain, experienced a cyberattack that exposed internal systems via a third-party contractor’s account. Hackers advertised stolen data for sale online, prompting Żabka to notify authorities and block the intrusion. The incident underscores the risks of third-party access in retail environments1.

Key Details:

  • Organization: Żabka (Poland)
  • Attack Vector: Third-party contractor compromise
  • Impact: Internal system exposure, data for sale on cybercrime forums
  • Discovery Date: August 5, 2026

Critical Vulnerabilities

N-able N-central Authentication Bypass (CVE-2026-18577)

Summary:
Microsoft disclosed that the financially motivated, China-linked threat actor Storm-1175 deployed a new ransomware strain, StormEncryptor, likely exploiting CVE-2026-18577—a patch bypass for a previous authentication bypass flaw (CVE-2026-18556) in N-able N-central. This vulnerability allows attackers to bypass authentication and take over accounts on vulnerable systems3.

Key Details:

  • CVE: CVE-2026-18577 (patch bypass for CVE-2026-18556)
  • Product: N-able N-central
  • Attack Vector: Authentication bypass, account takeover
  • Threat Actor: Storm-1175 (China-linked)
  • Ransomware: StormEncryptor

TrueConf Server Vulnerabilities (KLCERT-26-057, KLCERT-26-058)

Summary:
A threat actor known as Head Mare exploited vulnerabilities in TrueConf videoconferencing servers to deliver the PhantomCore backdoor and RAT. The flaws allow arbitrary code execution with elevated privileges and affect multiple TrueConf server versions. The attack chain involves replacing legitimate client installers with malicious versions3.

Key Details:

  • Vulnerabilities: KLCERT-26-057, KLCERT-26-058
  • Product: TrueConf Server (versions 5.3.x–5.5.5 and earlier)
  • Impact: Arbitrary code execution, backdoor installation

Passkey and MFA Bypass Attacks

Summary:
Three separate research teams demonstrated new methods to defeat passkey protections and phishing-resistant MFA. Techniques included reusing signed authentication material, abusing cloud-synced passkey systems, and leveraging compromised user sessions. These attacks did not break cryptography but exploited implementation weaknesses, affecting Windows, Microsoft Entra ID, and Google Password Manager3.

Key Details:

  • Products Affected: Windows, Microsoft Entra ID, Google Password Manager
  • Impact: Privileged user impersonation, private key recovery, MFA bypass

Government Responses

CISA Adds New Exploited Vulnerabilities to Catalog

Summary:
During the week, CISA issued multiple alerts adding newly exploited vulnerabilities to its Known Exploited Vulnerabilities Catalog. These advisories provide actionable mitigation guidance for organizations across critical infrastructure sectors. CISA also continued to emphasize the need for hardening operational technology (OT) in water and wastewater systems following recent attacks4.

Key Details:

  • Agency: CISA (USA)
  • Actions: Issued alerts on exploited vulnerabilities, OT security advisories
  • Focus: Water/wastewater sector, critical infrastructure

International Law Enforcement Investigations

Summary:
Authorities in Europe, including the Dutch Data Protection Authority and Hungarian National Cybersecurity Institute, are actively investigating recent cyberattacks on logistics and government agencies. These efforts highlight the growing international collaboration required to address cross-border cyber threats1.


Miscellaneous

AI Security and Autonomous Hacks

Summary:
OpenAI and Anthropic both issued warnings about the risks of autonomous AI models conducting real-world cyber operations. OpenAI paused some internal activities involving its Astra model after internal evaluations revealed advanced agentic coding and cybersecurity capabilities. Both companies are implementing stricter security controls and monitoring for their high-capability models3.

Key Details:

  • Vendors: OpenAI, Anthropic
  • Actions: Paused risky AI activities, implemented new security controls
  • Industry Impact: Renewed focus on AI safety and agentic model governance

Malicious VS Code Extensions Target Crypto Wallets

Summary:
Security researchers flagged a malicious Visual Studio Code extension, Solidity Pro, which was used to steal browser wallet credentials, API keys, and other sensitive data. The extension, distributed via Open VSX and GitHub, highlights the risks of supply chain attacks in developer ecosystems3.


Conclusion

The week of August 4–10, 2026, saw a surge in high-impact data breaches, sophisticated ransomware campaigns, and the exploitation of critical vulnerabilities. Government agencies responded with new advisories and cross-border investigations, while the cybersecurity community grappled with the growing risks posed by autonomous AI and supply chain threats. Organizations are urged to review their security postures, patch known vulnerabilities, and remain vigilant against evolving attack vectors.


Sources: