This week’s cybersecurity landscape highlights how artificial intelligence is both a tool for attackers and defenders. A ransomware-affiliated actor used Claude Code to auto-steal LDAP credentials, backdoor VPNs, and exfiltrate SQL data. On the other side, Anthropic broadened Claude Security’s vulnerability scanning to help defenders. Identity and access management hogged much of the headlines: a remote-code-execution bug in Entra ID, MFA bypasses, and BEC draining trust and finances.
Major Breaches and Threat Vectors
A critical Entra ID vulnerability (CVE-2026-69836) tied to untrusted-data deserialization allowed unauthenticated remote code execution—patched server-side by Microsoft under its transparency initiative. Despite earlier misreporting, it was never exploited in the wild.([cybersecuritynews.com](https://cybersecuritynews.com/cyber-security-newsletter-bulletin-august/))
The Gentlemen ransomware affiliate deployed Anthropic’s Claude Sonnet 4.6 to mount full-scale attacks on at least eight organizations across the U.S., Australia, Thailand, and Mauritius. Tasks ranged from stealing LDAP passwords via FortiGate tricks to staging SQL databases for theft after creating hidden VPN backdoors.([cybersecuritynews.com](https://cybersecuritynews.com/cyber-security-newsletter-bulletin-august/))
Microsoft is readying a passkey-first era: starting September 1, 2026, users in Entra ID using SMS or voice MFA will begin default passkey registration. SMS/voice authentication will be retired completely by February 1, 2027.([cybersecuritynews.com](https://cybersecuritynews.com/cyber-security-newsletter-bulletin-august/))
Enterprise Infrastructure Under Fire
Azure AD data theft impacted Fortune 500 companies. An actor named “TheHatman” listed large org charts for several firms like McDonald’s, Vodafone, and TCS, exposing emails, job titles, manager hierarchies, and Global Admin accounts. Likely the result of credential abuse rather than a platform flaw.([cybersecuritynews.com](https://cybersecuritynews.com/cyber-security-newsletter-bulletin-august/))
Critical vulnerabilities were weaponized in SCCM and VMware vCenter. The SCCM flaw (CVE-2026-47301) chains path traversal, broken access control, DLL hijacking, and weak signature validation to let low-privileged domain users gain SYSTEM-level access.([cybersecuritynews.com](https://cybersecuritynews.com/cyber-security-newsletter-bulletin-august/)) Meanwhile, a path traversal flaw in VMware vCenter (CVE-2026-59310) enabled root execution without auth. Attackers dropped JSP web shells and deployed ransomware targeting ESXi hosts.([cybersecuritynews.com](https://cybersecuritynews.com/cyber-security-newsletter-bulletin-august/))
A novel MFA bypass campaign dubbed Mirage2FA stole Microsoft 365 session cookies via Adversary-in-the-Middle proxies after users completed legit MFA login flows. Over 9,000 accounts across more than 3,500 domains were hit—mostly in the U.S.([cybersecuritynews.com](https://cybersecuritynews.com/cyber-security-newsletter-bulletin-august/))
Other High-Profile Incidents
T-Mobile’s security team physically severed a network cable to kick Salt Typhoon hackers—a Chinese state-backed threat group—out of its systems after months of intrusion trails.([cybersecuritynews.com](https://cybersecuritynews.com/cyber-security-newsletter-bulletin-august/))
Shell is investigating after Cl0p claimed theft of ~89 GB of data including engineering drawings and facility images. No operational disruption has been confirmed.([cybersecuritynews.com](https://cybersecuritynews.com/cyber-security-newsletter-bulletin-august/))
Medusa ransomware continues trampling on critical sectors—education, healthcare, manufacturing. It leverages known exploits and credential brokers to deploy encryptors that demand up to $15 million.([cybersecuritynews.com](https://cybersecuritynews.com/cyber-security-newsletter-bulletin-august/))
Emerging risks include: a stealthy backdoor in Windows camouflaged as Realtek audio using whitespace tricks and WMI triggers; the “Zombie Card” NFC attack that lets expired Visa cards purchase goods due to how expiry is handled in Visa’s EMV protocol; an uncensored criminal AI service, MessiahGPT, selling malware, phishing kits, and rootkits—available for as little as $8/month.([cybersecuritynews.com](https://cybersecuritynews.com/cyber-security-newsletter-bulletin-august/))
Defensive Pushes and Mitigations
Anthropic launched code-scanning through its Claude Mythos 5 model in public beta for enterprise clients. It surfaces CWE-classified findings with severity and suggested fixes. Also introduced: a $35 million fund for open-source security fixes.([cybersecuritynews.com](https://cybersecuritynews.com/cyber-security-newsletter-bulletin-august/))
Other mitigations include Microsoft’s patching of the CoSnitch vulnerability in Copilot Personal, detecting that certain undocumented URL parameters could lead to data exfiltration; hotfixes in Microsoft Defender after crashes linked to recent updates; and warnings for NetScaler users to patch critical authentication bypass and memory overflow flaws.([cybersecuritynews.com](https://cybersecuritynews.com/cyber-security-newsletter-bulletin-august/))
Security teams are urged to review Entra ID logs, role assignments, and conditional access policies; invalidate active sessions; enforce continuous access evaluation; segment networks; deploy phishing-resistant MFA; and audit internet-facing management interfaces.([cybersecuritynews.com](https://cybersecuritynews.com/cyber-security-newsletter-bulletin-august/))
This week underscores a stark reality: AI tools are empowering both attackers and defenders, and identity systems remain a lucrative target. As credentials and session tokens are weaponized, reliance on legacy MFA and exposed admin paths simply won’t be enough. What to watch: enforcement of passkeys, how AI-driven exploit tooling evolves, and whether defenders can stay ahead of public proof-of-concept leaks.