The last summer cybersecurity digest brings together the latest developments in the field, from new types of AI agent attacks and service disruptions to a credential theft campaign targeting Fortune 500 companies and significant updates.
1. New type of attack: Google’s AI agent exploits their own
A new type of attack has been identified in multi-agent systems, where one AI agent exploits another, potentially compromising the software supply chain. This was discovered in Google’s adk-python repository. A low-privileged agent can be manipulated via prompt injection to trigger actions from a high-privileged agent, leading to unauthorised operations. Researchers demonstrated this by crafting a pull request comment that was mistakenly assumed reliable due to its association with a human-like collaborator.
After Google's update, a new vulnerability was found that allowed bypassing a command allowlist, leading to remote code execution on the CI runner and risking the exposure of sensitive credentials. Google has acknowledged these issues and is reinforcing security by recommending narrowly scoped identities for agents, strict access controls, and ongoing human oversight.
2. Critical flaws in Claude, Gemini and OpenAI coding agents allow supply-chain attacks
A recent security analysis revealed a common vulnerability pattern in AI coding agents from Anthropic, Google, and OpenAI that allows remote code execution, API credential theft, and software supply chain compromises without privileged access. Researcher Elad Meged found that flaws stem from the surrounding "harness" code managing tool permissions and execution.
1. Anthropic’s Claude: Researchers exploited a command validation mismatch, allowing arbitrary code execution through a malicious git push. Even after a patch, vulnerabilities were found to exfiltrate API keys.
2. Google’s Gemini CLI faced issues due to an unenforced shell tool allowlist and exposure of secrets in parent processes, leading to severe compromises rated CVSS 10.0.
3. OpenAI’s Codex: Attacks could leverage a shared workspace among agent passes, allowing the poisoning of trusted instruction files, leading to compromised execution.
The vulnerabilities were not mere misconfigurations but resulted from security decisions that failed at integration points. These issues were found across over a hundred public repositories, prompting the recommendation to treat all workflow files and inputs as untrusted rather than assuming vendor defaults are secure.
3. Massive Microsoft Patch Tuesday Update August 2026
Microsoft's August 2026 Patch Tuesday brings another substantial update, addressing 394 vulnerabilities, including three zero-day threats. This follows the previous month's record-breaking update that tackled 570 issues. The August security update spans a variety of Microsoft software products, including Windows, Microsoft Office, SharePoint Server, Azure services, .NET, PowerShell, Visual Studio Code, and more. Users are strongly encouraged to update their software immediately, especially considering the significant number of vulnerabilities that have been resolved.
4. Chrome 152 released with 327 security fixes: Update now!
Google has released Chrome 152 for Windows, macOS, and Linux, which includes 327 security fixes, addressing 10 critical vulnerabilities. The update, with version 152.0.7977.64 for Linux and 152.0.7977.64/.65 for Windows and macOS, focuses on memory-safety issues, particularly use-after-free vulnerabilities that could allow attackers to crash the browser or access sensitive information. Key affected components include ANGLE, Aura, Chromecast, and Safe Browsing. Although no current exploits are reported for these vulnerabilities, Google has restricted access to details until most users update. Users are encouraged to do so promptly.
5. Yet another service disruption for Claude AI this August
On August 24, Anthropic’s Claude AI platform encountered significant disruptions, impacting several key models, including Claude Mythos 5 and Claude Fable 5. The incident began at 05:06 UTC, with a root cause identified shortly after at 05:27 UTC; however, full resolution extended past 06:42 UTC. This outage affected various services, such as the Claude API and Claude Code, and is part of a concerning trend of repeated service interruptions throughout 2026. Several notable incidents were reported in August alone: on the 5th, 12th, 13th, 16th, 18th, and 20th, each affecting overlapping sets of models. Anthropic has yet to disclose the technical cause behind this latest disruption.
6. Support end coming soon for Windows 11 24H2 Home and Pro editions
Microsoft has announced that Windows 11 Home, Pro, Pro Education, and Pro for Workstations editions, version 24H2, will end updates on October 13, 2026. After this date, these systems will no longer receive security updates, increasing vulnerability to threats. The version 24H2 feature update was released on October 1, 2024, and provides a standard 24-month support period. Windows 11 24H2 Enterprise and Education editions will be supported until October 12, 2027. Microsoft recommends users upgrade to Windows 11 version 25H2 for continued security.
Additionally, Windows 10 Enterprise LTSB 2016 will also reach the end of extended support on the same date. Organisations can consider Extended Security Updates as a temporary solution but are encouraged to migrate to newer versions for long-term security.
7. Azure credential theft campaign hits 9 Fortune 500 companies
A data exfiltration campaign led by a threat actor known as "TheHatman" is targeting major corporations, selling internal employee directories stolen from their Azure and Entra tenants. The campaign has affected at least nine Fortune 500 companies, with McDonald's Corporation exposing over 1.7 million records, followed by Tata Consultancy Services, Vodafone, and HCL Technologies.
The leaked data includes full names, corporate email addresses, phone numbers, physical addresses, employee IDs, job titles, and privileged account information, presenting significant risks for targeted attacks. The method of intrusion remains unclear, but it's suggested that compromised credentials are involved, possibly due to infostealer malware, phishing, or insufficient multi-factor authentication.
This incident highlights the importance of credential hygiene, continuous monitoring for compromised credentials, enforcing MFA, and reviewing third-party API permissions to mitigate risks.
Staying secure means more than just reacting to headlines. It's about consistent cybersecurity hygiene, timely patching, and keeping an eye on how new technologies are reshaping the risks businesses need to plan for. We hope your systems remain safe and compliant with NIS2 through 2026. If you need assistance, please contact us for expert advice!