daily cyber × ai intelligence

index

August 13, 2026

ShieldBreak Turns a "Patched" Defender Bug Back Into SYSTEM

64 of 70 sources 438 gathered 400 triaged 41 clustered 41 written

A fresh proof-of-concept claims to defeat Microsoft’s patch for a Defender privilege-escalation flaw, handing any user SYSTEM on fully updated Windows 11 and Server 2025. A malicious-release supply-chain hit on LiteLLM is now mapped to 2,100+ organizations with terabytes of harvested secrets in circulation.

Offensive & Exploitation

  • The “ShieldBreak” zero-day PoC bypasses Microsoft’s fix for CVE-2026-50656 (RoguePlanet), a Defender flaw, and grants SYSTEM from any user account. The researcher — going by Nightmare Eclipse / Chaotic Eclipse / MSNightmare — published working code, and where RoguePlanet was a quarantine filesystem race condition, ShieldBreak instead abuses a user-mode callback hook, per BleepingComputer and The Hacker News. Kevin Beaumont has already published a ShieldBreak hunting KQL query; the PoC is on GitHub. (discussion)
  • SharePoint auth-bypass CVE-2026-55040 is now being exploited in the wild shortly after Rapid7 dropped a PoC on Patch Tuesday. The flaw stems from improper JWT validation that lets an attacker forge unsigned tokens and impersonate any user, including admins, and chains with the RCE flaw CVE-2026-63520 (earlier coverage). See BleepingComputer, Rapid7’s technical analysis, and Viettel’s writeup.
  • A stack-pivot that “shouldn’t work” exposed a kernel-wide SMAP design compromise on Windows, with the researcher detailing how Supervisor Mode Access Prevention is effectively pre-disarmed across the kernel (sibouzitoun.tech).
  • A KVM SEV-SNP guest-to-host heap OOB (CVE-2026-53360) was documented alongside analysis of the upstream fix — another confidential-computing boundary that didn’t hold (blog.himanshuanand.com).

Cloud & Identity

  • Midnight Blizzard (APT29 / Storm-2945) is weaponizing hotel Wi-Fi captive portals in a campaign Microsoft tracks as CaptiveCrunch. The group manipulates DNS and HTTP traffic on hospitality-venue captive networks to redirect guests to attacker infrastructure for Microsoft 365 credential harvesting, device-code phishing, and malware delivery — with evidence it compromised shared captive-portal servers, per Zscaler.

Threat Activity

  • Researchers built a fake DeFi crypto startup, advertised dev jobs, and hired three suspected North Korean IT workers — recording every VM the company issued to capture their toolkit and tradecraft. The onboarding paperwork (a Texas address paired with a California license and New York bank account) is directly reusable by hiring teams, per The Hacker News on the ANY.RUN research.
  • The “City-Forum” campaign is quietly exfiltrating data from Salesforce and ServiceNow by abusing unauthenticated guest access to enumerate and pull exposed records. Active since at least March 2025 across multiple sectors, it uses custom tooling, per Dark Reading and SecurityWeek.
  • An Akira affiliate rebooted a victim into Safe Mode to strip EDR before encrypting — then broke its own encryptor in the process. The intrusion started with a VPN credential-spray, and defenders should watch for Safe Mode and boot-configuration changes alongside MFA enforcement, per The Register and SC Media.
  • Kimwolf v7 (aka AISURU) makes HTTP/2 DDoS traffic look like normal browsing, adding Ethereum ENS-based C2 resolution and Tor backup routing to survive takedowns, per Unit 42 and The Hacker News. (discussion)
  • A new “SaassyCode” campaign is pushing malicious VS Code extensions: Nextron’s scanner flagged “Trello Board” (TrelloWorks.trello-board), which downloads and runs a BAT loader on startup, sets scheduled-task persistence, and injects shellcode into trusted Windows processes — part of the same wave of Marketplace abuse that has also carried XWorm, per Knostic’s analysis.
  • 737 Chrome “VPN” extensions were caught routing browser traffic through proxy infrastructure, largely targeting Russian-speaking users; 274 impersonate 66 legitimate brands and racked up ~75,000 installs across 40+ developer accounts, per The Hacker News and BleepingComputer.
  • A fake CCleaner download page installs “GhostDesk,” a malicious Chrome extension acting as in-browser spyware, per Malwarebytes.
  • ShinyHunters leaked data from Sharecare after publicly branding the victim’s negotiator “incompetent and unskilled,” per Dark Web Informer.

AI & Model Security

  • Two malicious LiteLLM releases — traced to the earlier Trivy compromise — mapped potential exposure to 2,100+ organizations. The rogue PyPI packages sat live ~40 minutes in March but carried credential-stealing code that harvested cloud keys, SSH keys, Kubernetes tokens, and database passwords; CloudSEK’s dataset was built from ~434,000 captured files, per The Hacker News and SecurityWeek. Kevin Beaumont, who confirmed the leak against multiple victim orgs, calls it a “massive supply chain” incident rooted in orgs adopting GenAI tooling without secrets hygiene. (discussion)
  • An inverse language model reconstructs a proprietary prompt from an LLM’s output with near-perfect accuracy. Researchers at IIT Bombay and Adobe Research say their “Previous-Token Prediction” method needs no model weights and generalizes across models — a direct threat to organizations relying on secret system prompts, per The Decoder.
  • DeepSeek V4 Pro is drawing attention as a security-research model, with one researcher reporting an open-source RCE found in under 30 minutes using it, per @whoareme33 — a claim worth treating as anecdote until reproduced.
  • A prompt-injection attempt showed up in a real court filing: a pro se plaintiff embedded injection text in a Connecticut Superior Court motion for default, apparently aiming to trick an opponent’s AI into filing a deficient response. The court revoked his e-filing privileges, per @RobertFreundLaw.

New Tools & Releases

  • Signal shipped Automatic Key Verification (AKV), using a transparent key-transparency ledger with third-party auditors to detect man-in-the-middle attacks without users manually comparing safety numbers, per BleepingComputer and Trail of Bits, who helped verify the design.
  • DEF CON 34 published all slides and videos, now mirrored on the official media server for offline review (media.defcon.org).

Vulnerabilities & Research

  • “Zoomsday” — three annotation flaws (CVE-2026-53413/53414/53415) let any Zoom meeting participant attack another through malicious collaboration data. No click or download is required beyond being in the meeting; a presenter could take over viewers, or vice versa, per The Hacker News and Malwarebytes.
  • A Windows SMBv3 Server heap overflow (CVE-2026-62800) enabling RCE was patched this month after a June report to MSRC; the finder confirms it, per MSRC.

Threat Intelligence

  • Check Point’s July 2026 telemetry shows ransomware attacks roughly doubling year-over-year, with weekly attacks hitting 2,336 per organization (up 16% YoY) and Europe among the sharpest regional increases at 18%. GenAI adoption widened data-exposure risk, with roughly 1 in 36 prompts flagged as high-risk for leaking sensitive data, per the Check Point report surfaced by NCSC-FI.