Visualização normal

Antes de ontemFirewall Daily – The Cyber Express

The Cyber Express Weekly Roundup: Corporate Cyberattacks, AI Security Risks, Zero-Days, and Data Theft

14 de Agosto de 2026, 08:20

weekly roundup The Cyber Express cybersecurity 2026

This weekly roundup highlights the expanding range of threats facing businesses, technology platforms, and individuals. From social engineering attacks against corporate systems and vulnerabilities uncovered by AI agents to large-scale software patches and cyberattacks disrupting logistics operations, recent incidents demonstrate how quickly the threat landscape is evolving.  The latest developments also show that cybersecurity risks are no longer limited to traditional malware or ransomware. Attackers are increasingly exploiting human behavior, software weaknesses, interconnected supply chains, and personal online accounts. At the same time, artificial intelligence is emerging as both a defensive tool and a new way to identify security weaknesses. 

The Cyber Express Weekly Roundup 

Levi Strauss Targeted in Cyberattack, Corporate Files Accessed 

Levi Strauss & Co. disclosed a cybersecurity incident after attackers used social engineering techniques to gain access to three company-issued computers. The company believes certain corporate files were accessed and some information may have been exfiltrated. Levi Strauss said it moved quickly to contain the incident and terminate the unauthorized access, limiting the potential impact of the attack. Read more...

AI Agent Exploits Gym Booking Vulnerability 

An AI-powered agent reportedly identified an authentication weakness in an Australian gym’s online booking system. The agent, powered by Anthropic’s Claude and operated through OpenClaw, was originally instructed to help a user book a popular class. During the process, it was able to reserve classes months ahead and cancel another customer's booking. Read more...

AI Will Automate Cybersecurity Toil, Not Replace Security Professionals 

Harsha Reddy, Head of Information Security at Veterinary Emergency Group, argues that artificial intelligence is more likely to transform cybersecurity work than eliminate cybersecurity jobs. AI can assist with repetitive activities such as reviewing logs, triaging alerts, and collecting evidence, allowing security professionals to concentrate on investigation, strategy, and higher-value defensive operations. Read more...

Microsoft Fixes More Than 400 Security Flaws 

Microsoft’s August 2026 Patch Tuesday addresses roughly 400 vulnerabilities across its products, including three zero-days. One of the vulnerabilities was reportedly being actively exploited, while two others had been publicly disclosed before patches became available. The update includes 42 critical vulnerabilities, with 37 associated with remote code execution, reinforcing the importance of timely patching across enterprise environments. Read more...

CEVA Logistics Cyberattack Disrupts European Operations 

A cyberattack against CEVA Logistics disrupted activity at eight European warehouses on July 29, affecting shipments and exposing customer data connected to several major clients. The logistics company, part of the CMA CGM Group, has not publicly identified the attackers or provided detailed information about the technical nature of the incident. Read more...

FBI Warns of Theft of Explicit Content From Social Media 

The FBI has warned that cybercriminals are targeting social media and personal accounts to steal explicit images and videos, including non-consensual intimate images. Stolen material may subsequently be distributed or sold online, while associated personal information can expose victims to harassment, stalking, and sextortion. Read more...

Weekly Cybersecurity Takeaway 

This week’s incidents demonstrate that cybersecurity risks are expanding across corporate networks, software ecosystems, supply chains, AI-powered systems, and personal accounts.  Organizations should prioritize strong authentication, rapid vulnerability patching, employee awareness, third-party risk management, and continuous monitoring. At the same time, responsible use of AI could help security teams reduce repetitive workloads and respond more effectively to emerging threats.  As attackers continue finding new ways to exploit technology and human trust, organizations and individuals must strengthen security controls while remaining prepared for threats that increasingly cross traditional digital boundaries. 

💾

Enjoy the videos and music you love, upload original content, and share it all with friends, family, and the world on YouTube.
  • ✇Firewall Daily – The Cyber Express
  • Shadow AI Is Growing in Silence While Enterprise Security Falls Behind Editorial
    By Niall Browne, CEO and Founder, AIBound Shadow AI is accelerating alongside artificial intelligence (AI) adoption at a pace that has outgrown most enterprise governance models. Artificial intelligence (AI) adoption is accelerating at a pace that has outgrown most enterprise governance models. According to the World Economic Forum, 87% of organizations report that AI-related vulnerabilities are now the fastest-growing cyber risk. Part of this surfaces with  employees increasingly deploying aut
     

Shadow AI Is Growing in Silence While Enterprise Security Falls Behind

18 de Maio de 2026, 02:58

Shadow AI Is Growing in Silence

By Niall Browne, CEO and Founder, AIBound
Shadow AI is accelerating alongside artificial intelligence (AI) adoption at a pace that has outgrown most enterprise governance models. Artificial intelligence (AI) adoption is accelerating at a pace that has outgrown most enterprise governance models. According to the World Economic Forum, 87% of organizations report that AI-related vulnerabilities are now the fastest-growing cyber risk. Part of this surfaces with  employees increasingly deploying autonomous AI agents that connect to MCP servers and external AI that security teams have never assessed, quietly piping sensitive corporate data into systems no one in IT has ever audited — and no one in the C-suite knows exist. This increase in Shadow AI is creating systemic enterprise risk that can lead to unforeseen costs. Compliance frameworks like the Artificial Intelligence Act of the European Union (EU AI Act) take full effect this year introducing penalties up to 7% of global annual revenue for unmanaged AI. As regulatory frameworks begin to align with the realities of increased AI adoption, enterprises need to account for decentralized AI usage that operates outside traditional controls. This requires software that allows greater visibility, organization, and control into how AI is used and tracked across environments.

Shadow AI Is Creating a New Enterprise Attack Surface

The traditional security stack was built for a world that no longer exists — one with known assets, centralized systems, and software that asked permission before it ran. As new tools are introduced independently, usage levels evolve quickly without system checks or visibility into how these tools interact with sensitive data. Research indicates that 75% of CISOs have discovered unsanctioned GenAI tools in their environments, and only 5% feel confident they could contain compromised AI agents. Because of how easy these platforms are to access and require little onboarding, adoption is happening across teams at a rapid rate without IT involvement. Other security issues lie with employees integrating workflows with personal AI agents. These deployments allow sensitive information to be leaked or directly inputted into agents without security knowledge. Without a system in place for organizations to continuously track and evaluate how AI is being used across their enterprise systems, CISOs are left without visibility of their attack surfaces. The result is a slow-motion breach: data leaking, compliance crumbling, and governance reduced to a slide deck nobody enforces. Recurring data leaks and breaches via AI reveal the need for solutions that address this gap. Popular AI agents like ChatGPT for example, revealed a ‘ShadowLeak’ vulnerability that allowed sensitive email data to be breached through a zero-click attack. Other short lived features that rolled out last year allowed conversation sharing, leaving employee info, internal corporate strategies, and other sensitive data to be shared and indexed by search engines. Although this option only was available for a day, it was estimated that over 100,000 private chats were affected and able to be viewed with a simple search, allowing any sensitive information inputted to be publicly accessible. Other recent breaches include a Microsoft 365 Copilot bug allowing AI assistants to summarize emails labeled confidential, bypassing data loss prevention policies set up by organizations. Microsoft confirmed that a code issue allowed confidential emails data to be accessed despite organizational securities put in place. These agents are live and operational with local access to files, systems, commands, and APIs capable of executing tasks and retrieving data without clear oversight control. As AI usage continues to expand at accelerating rates, organizations need a way to better understand how these tools are used across their environments. No CISO has ever defended a perimeter they couldn't see. Shadow AI is the new perimeter — and most security teams are flying blind. Without a comprehensive inventory and control of AI usage, security teams are unable to accurately assess risks and enforce policy to maintain compliance.

Shadow AI Demands Continuous Visibility and Independent AI Control Planes

This is where adoption of independent AI Control Planes becomes vital. Independent AI Control Planes provides a way to continuously identify and assess AI activity giving security teams the visibility needed to manage emerging risks. It enables organization and categorization of AI usage across enterprises without relying on the manual entry and tracking that existing platforms demand — work no security team in a fast-moving environment can realistically keep up with. It’s undeniable: Shadow AI is not a future problem — it is already running inside your enterprise, on assets you don't own, through agents you never approved, touching data you are responsible for protecting. Every day without continuous, autonomous AI discovery is a day your attack surface grows faster than your governance can chase it. Regulators won't wait. Attackers already aren't. The CISOs who win the next 24 months will be the ones who stop pretending policy equals control and start operating on a simple truth: if you can't see it, you can't secure it — and right now, most of AI is invisible.

Disclaimer: The views and opinions expressed in this guest article are solely those of the author and do not necessarily reflect the official policy or position of The Cyber Express. The information shared is intended for industry discussion and awareness purposes only.

❌
❌