
A flurry of fixes.
We got your Patch Tuesday notes. Attackers target Microsoft SharePoint vulnerability following PoC release. Cyberattack on CEVA Logistics causes ongoing supply chain disruptions. Wesco confirms data breach following extortion claims. Akira ransomware bypasses EDR in Safe Mode. California announces AI cybersecurity fund. N2K’s Lead Analyst Ethan Cook shares about cyber weapons for space. Dave Bittner sits down with Michael Leland, VP and Field CTO at Island, at Black Hat USA to discuss the growing risks of the AI supply chain. And fasten your seatbelts and ignore the fake Wi-Fi.
Today is Wednesday August 12th 2026, I’m Maria Varmazis. And this is your CyberWire Intel Briefing.
Patch Tuesday notes.
Microsoft’s Patch Tuesday addressed a total of 421 vulnerabilities across its products, including Windows, Hyper-V, Microsoft Exchange Server, and Azure. Of these, 62 are rated critical and 357 are marked as important, with the most significant being three zero-day vulnerabilities. The zero-days include a tampering flaw in the Windows Container Isolation FS Filter Driver, an elevation of privilege bug in the Windows User Profile Service, and an actively exploited privilege escalation flaw in the Windows Ancillary Function Driver for WinSock. CISA has added the latter flaw to its Known Exploited Vulnerabilities Catalog, and ordered Federal agencies to apply patches by August 25th. Check Point has attributed the exploitation to North Korea’s Lazarus Group, in a campaign targeting the defense sector in Europe and India.
Adobe addressed 51 vulnerabilities across five of its products: Adobe ColdFusion, Adobe Commerce, Adobe Lightroom Classic, Content Credentials SDK, and Adobe Campaign Classic. Of these, 33 vulnerabilities are classified as critical.
SAP fixed 29 vulnerabilities, led by a maximum-severity flaw in SAP Commerce Cloud's Data Hub Adapter. This improper authorization issue allows unauthenticated remote attackers to submit crafted data, potentially leading to arbitrary code execution.
In the ICS space, Siemens, Schneider Electric, and Phoenix Contact released patches for various products, and CISA published advisories covering vulnerabilities in products from other vendors, including Pulsetto and Johnson Controls. Notably, Siemens issued a fix for a maximum-severity missing-authentication flaw in its Simatic IoT gateways.
Attackers target Microsoft SharePoint vulnerability following PoC release.
Threat actors have already started weaponizing a proof-of-concept exploit for a critical Microsoft SharePoint flaw that was published by Rapid7 yesterday. The flaw is an authentication bypass vulnerability that affects the JWT token validation pipeline in SharePoint Enterprise Server 2016 and 2019. It allows attackers without privileges to impersonate users or administrators to disclose files and modify data.
Microsoft issued a patch for the flaw on July 14th following a responsible disclosure by Rapid7. Administrators who haven’t already applied patches are urged to do so promptly.
Cyberattack on CEVA Logistics causes ongoing supply chain disruptions.
A cyberattack at shipping giant CEVA Logistics is continuing to cause significant disruptions for its clients across Europe. The attack, which likely began on July 29, 2026, affected at least eight warehouses. While the full extent of the breach has not been disclosed, affected clients report that customer names, contact details, and delivery information may have been compromised. Dutch retailers Bol and De Bijenkorf [duh BAY-un-korf], along with gaming giant Valve, have disclosed that they were impacted.
Wesco confirms data breach following extortion claims.
Global supply chain and distribution giant Wesco has confirmed a cybersecurity incident involving its cloud CRM environment after the data extortion group ExfilSquad claimed credit for the attack. ExfilSquad says it stole and leaked 2.6 million records containing customer and employee data. Wesco asserts there has been no business disruption or evidence of ransomware, and believes sensitive data like payment cards or financial accounts are not at risk.
Details of the attack are unclear, but BleepingComputer notes that ExfilSquad has in the past targeted improperly configured Microsoft Power Pages data tables.
Akira ransomware bypasses EDR in Safe Mode.
Huntress has published a report on an attack by an Akira ransomware affiliate in which the attackers rebooted a compromised host into "Safe Mode with Networking" to bypass EDR tools. After gaining initial access through an exposed SonicWall VPN without multi-factor authentication, the attacker enumerated Active Directory and exfiltrated sensitive data. By forcing the reboot into Safe Mode, the attacker intended to freely execute the ransomware. However, the stripped-down memory environment of Safe Mode ironically caused the Akira process to crash from an out-of-virtual-memory error, preventing encryption. Unfortunately, the prior data theft still left the victim vulnerable to extortion.
California announces AI cybersecurity fund.
California is launching an "AI Cyber Defense Program" to protect its critical infrastructure after recent incidents revealed AI systems from major tech companies autonomously hacking into third-party organizations. The initiative will use AI tools to rapidly identify and patch security vulnerabilities, supervised by newly appointed AI Cybersecurity Officers across state agencies. Governor Gavin Newsom said the state’s approach serves as a direct response to the Trump administration's proposed $707 million budget cuts to the Cybersecurity and Infrastructure Security Agency for the 2027 fiscal year.
And on Wednesdays we take a look at what’s going on in the world of space-cyber – this week we’ll hear from T-Minus Space-Cyber Briefing Ethan Cook on the US military setting its sights on advanced cyber weaponry to take down satellite constellations. Over to you Ethan.
Cyber weapons for space? US officials see threat, opportunity
Thanks, Maria.
On Tuesday, the US held its annual Army Space and Missile Defense Symposium. At the event, Lt. Col. Rick Zellman, deputy commander of US Space Command, said adversaries are unlikely to try to take thousands of satellites offline using anti-satellite weapons. Instead, they could target people and compromise the nodes that provide “one-to-many” services. Zellman noted that these threats include cyber and directed-energy weapons, with attacks often focused on the ground systems supporting satellite networks.
Given the potential of these weapons as both threats and tools for the US military, officials are considering directed-energy and other capabilities as potential counterspace weapons while also exploring ways to diversify ground infrastructure.
For the T-Minus Space-Cyber Briefing, this is producer Ethan Cook. Back to you Maria.
Stick with us after the break, Michael Leland, VP and Field CTO at Island, sits down with Dave Bittner at Black Hat USA to discuss the growing risks of the AI supply chain. And fasten your seatbelts and ignore the fake Wi-Fi. Stay with us.
On our Industry Voices segment, Dave sits down with Michael Leland, VP and Field CTO at Island at Black Hat USA to discuss the growing risks of the AI supply chain including AgentBaiting, where fake AI Skills and MCP servers were used to deliver malware, and hidden instructions that can influence AI agents. Here’s their conversation.
That was Dave Bittner sitting down with Michael Leland, VP and Field CTO at Island discussing the growing risks of the AI supply chain. If you enjoyed this conversation and want to learn more, check out the links in our show notes.
Fasten your seatbelts and ignore the fake Wi-Fi.
A DEF CON attendee is suspected of jamming the in-flight Wi-Fi on a Delta flight out of Vegas on Monday. The exact details of the incident are still unclear, though the flight crew informed air traffic control that a passenger had set up a spoofed network called “Delta Wifi Fast” and was trying to scam the other passengers. The individual likely used a Wi-Fi Pineapple or similar device used for spoofing networks.
Delta is investigating the incident and working with law enforcement, but stated that the aircraft's operating systems and flight safety were never compromised. Federal authorities met the plane upon landing to question passengers, as the incident may amount to a Federal offense.
And that’s the CyberWire.
For links to all of today’s stories, check out our Daily Briefing at the cyberwire dot com.
We’d love to know what you think of this podcast. Your feedback ensures we deliver the insights that keep you a step ahead in the rapidly changing world of cybersecurity. If you like the show, please share a rating and review in your podcast app. Please also fill out the survey in the show notes or send an email to cyberwire@n2k.com
N2K’s lead producer is Liz Stokes. We’re mixed by Tré Hester, with original music by and sound design Elliott Peltzman. Our contributing host is Maria Varmazis. Our executive producer is Jennifer Eiben. Peter Kilpe is our publisher. And I’m Dave Bittner. Thanks for listening.

