In August 2026, there was further evidence of AI moving into active cyber operations, helping adversaries navigate compromised environments and develop capabilities targeting industrial systems.
Multiple incidents showed how attacks against trusted platforms and identities can provide a path into sensitive data without exploiting traditional software vulnerabilities. McKesson investigated a major breach linked to voice phishing and compromised single sign-on accounts, while New Zealand Sotheby’s International Realty disclosed unauthorised access to data held in a third-party CRM platform.
In addition, multiple vulnerabilities were identified in popular products, such as a large-scale npm supply-chain attack, the growing abuse of legitimate AI crawler identities for internet scanning, and Microsoft’s latest security changes addressing external meeting bots, device-code authentication, and attacker persistence.
Happenings
[US] Boston Scientific Cyber Incident
A cyber incident at Boston Scientific, a US-based medical technology company, caused a global network outage and disrupted key operations. Internal systems supporting manufacturing, order processing, and product shipments were affected. The outage prevented remote monitoring from being activated for newly implanted cardiac rhythm management devices, while devices already in use continued to operate as expected.
Boston Scientific has not disclosed how the adversary gained access to its environment or whether a threat actor has been identified. The company said the breach was “isolated to select internal infrastructure” and primarily affected its Information Technology (IT) environment rather than cloud-based systems. However, the incident disrupted automated ordering, packing, and shipping suggesting that parts of its Operational Technology environment may have been impacted.
Boston Scientific engaged CrowdStrike and an external forensic specialist to investigate the incident, contain the disruption and determine whether personal information or other systems had been affected. Operations returned to business as usual within 10 days, suggesting that established incident-response and disaster-recovery arrangements supported a fast recovery. No further comment has been made to suggest that personal information was extracted as part of this breach.
This incident is a reminder for the importance of strong separation and good network design between IT and OT environments. Effective segregation can limit the spread of an incident and help operational systems to continue functioning when IT is compromised.
[Global] AI-Assisted Attacks Move into Real-World Operations
US government agencies issued a joint advisory warning of active reconnaissance and capability development targeting internet-exposed Siemens S7 industrial controllers where attackers had developed AI-generated Python tools built around legitimate snap7.dll and python-snap7 libraries, disguising them as monitoring software. The tools were found to be able to interact directly with programmable logic controllers, including reading memory, configuration, and ladder logic, and could also potentially modify controller data.
In another incident disclosed in August, Taiwan’s Ministry of Digital Affairs confirmed attackers had combined human operators with open-source AI agents while targeting government systems, where the agents were used to investigate newly discovered infrastructure and work through possible attack paths, including the use of backup and testing systems as pivot points.
Gambit Security recovered chat sessions from infrastructure associated with the Russian-speaking Aur0ra ransomware group and Reuters subsequently reviewed portions of the data, confirming in reports that Cursor’s AI coding agent had been used during intrusions affecting at least seven companies. The agent was provided with existing access or credentials and used to help navigate victim environments, identify opportunities for further compromise, and determine what actions to take as the intrusion progressed. When the agent refused some malicious requests, the operators restarted conversations and presented the activity as an authorised security test to bypass the controls. Gambit Security’s Director of Threat Intelligence, Eyal Sela, estimated that use of the AI agent made the attackers 30–50 percent faster during operations.
Rather than fully replacing attackers, AI can increasingly take on much of the research, perform troubleshooting, and undertake decision-making that would otherwise require manual effort as an intrusion develops. This pipeline can make it easier for attackers to recognise useful opportunities within an environment and move between systems without needing the same level of specialist knowledge or time that would previously have been required. We are entering a phase of cybersecurity operations where organisations will increasingly need to use AI to identify vulnerabilities and attack paths before attackers do. As offensive use of AI becomes more capable defenders will need to match that speed by using the same technology to continuously test their environments to identify weaknesses and reduce the opportunities available to attackers.
[US] McKesson Investigates Data Breach Following ShinyHunters Vishing Campaign
Healthcare and pharmaceutical distribution giant McKesson is investigating a cyber security incident involving unauthorised access to third-party applications and the exfiltration of customer data. The company has confirmed that the affected data relates to a subset of customers within its Oncology & Multispecialty and Medical-Surgical business units and says it has reasonable assurance that there is no ongoing unauthorised activity within its systems, although the incident was disclosed in a filing with the US Securities and Exchange Commission.
The ShinyHunters extortion group has claimed responsibility, stating that they had socially engineered multiple McKesson employees through voice phishing to compromise Okta single sign-on accounts, and had used the resulting access to reach McKesson’s Salesforce and Snowflake environments. Attackers used the lookalike mckesson[.]claims domain, consistent with a wider ShinyHunters campaign registering domains following this pattern to impersonate corporate IT and helpdesk teams. ShinyHunters claims to have exfiltrated approximately 1 TB of data between 21 and 25 August, including approximately 284 database records. The group claims that the information includes a wide array of sensitive personal information including names, addresses, dates of birth, Social Security and Medicaid numbers, medical record numbers, medications, appointment information, and other health related information. The data claims have not yet been independently verified, and McKesson are yet to publicly confirm the categories or volume of information stolen.
Social engineering and compromised identity infrastructure can provide attackers with legitimate access to high-value SaaS platforms without exploiting a software vulnerability. Organisations should consider phishing-resistant authentication and device-based access controls, as well as stronger helpdesk identity-verification processes, and should implement monitoring for unusual authentication and bulk data access across federated SaaS applications.
[NZ] Third-Party CRM Data Breach
New Zealand Sotheby’s International Realty (NZSIR) is investigating a cyber security incident involving unauthorised access to data held within a third-party customer relationship management (CRM) platform. A threat actor known as 2019 claimed responsibility for the incident on 18 August and subsequently advertised data allegedly stolen from NZSIR for sale on an underground forum.
NZSIR confirmed that information potentially accessed includes names, physical addresses, phone numbers, and email addresses, but said the affected CRM was used for marketing and operational purposes and did not store information used for customer financial transactions. NZSIR also stated that email exchanges, property documentation, and other substantive property-related information were not accessed.
The threat actor claimed to have obtained 1.6 million contacts, although NZSIR disputes this figure, stating that its database contains nowhere near that number of individual contacts, with Forensic investigators indicating that the figure likely includes duplicate records. The company has engaged independent cyber security specialists and notified both the National Cyber Security Centre and the Office of the Privacy Commissioner, but the initial access method and the number of unique individuals affected have not yet been publicly confirmed.
While the exposed information does not appear to include financial or authentication data, the combination of names and contact details could still be used to support targeted phishing, impersonation, and social engineering attacks, particularly where attackers are able to contextualise communications around property enquiries or real estate transactions.
[Global] ChainDrop npm Attack Spreads Through Compromised Developer Credentials
A major software supply-chain attack affected the npm JavaScript package ecosystem after attackers compromised a maintainer account associated with widely used packages including Keyv, Cacheable, flat-cache, and file-entry-cache. The compromised packages delivered self-propagating malware known as ChainDrop, which executed during package installation and searched developer workstations and CI/CD environments for reusable credentials. The malware targeted the types of secrets that could provide access to source-code repositories, cloud environments, and other development infrastructure.
Stolen npm publishing credentials were then used to modify and publish malicious versions of additional packages, allowing the compromise to spread through the software supply chain, with more than 1,300 malicious package versions found to be associated with the campaign and approximately two billion monthly downloads. A compromised package running inside a trusted development or build environment can inherit access to credentials and downstream systems, allowing an attacker to move from a single dependency into broader development infrastructure. Limiting the credentials available to build processes, using short-lived tokens, and tightly controlling package publishing access can significantly reduce that blast radius.
Techniques and Updates
Attackers Exploit AI Crawlers
GreyNoise, a cybersecurity research and threat intelligence organisation that monitors internet-wide scanning activity and analyses of suspicious IP addresses, identified automated scanning infrastructure impersonating web crawlers associated with organisations including OpenAI, Anthropic, Google, and Perplexity. Rather than crawling normal website content, the scanners attempted to locate exposed secrets, including .env files, cloud access keys, private keys, and password stores. GreyNoise identified one cluster using six forged AI crawler identities across 824 IP addresses, with none of the traffic originating from the legitimate crawler IP ranges published by the organisations being impersonated. Attackers are taking advantage of the increasing presence of legitimate AI crawlers on the internet, as crawler identities are communicated through easily spoofed HTTP User-Agent strings, organisations that allow AI crawler traffic based only on these values could inadvertently provide malicious scanners with improved visibility.
Microsoft Security / Updates
Microsoft announced an extension to their controls for identifying external meeting bots in Microsoft Teams. Microsoft began rolling out Teams controls in May 2026 to detect suspected external meeting assistants, including third-party transcription and note-taking services, and place them in the lobby so organisers can review and explicitly approve their access before they join. A new option will allow administrators to automatically prevent identified external bots from joining meetings. The control is exposed through the ExternalBotAccessMode Teams meeting policy and can be configured through PowerShell using the BlockDetectedBots option. The control is becoming relevant as AI transcription and meeting-assistant services become widely used with tools that can record or transcribe sensitive discussions and potentially store information outside of an organisation’s Microsoft 365 compliance boundary. The rollout was originally expected to begin during August but has since been delayed, with general availability now expected for all tenants by October.
Microsoft has documented increased abuse of device code authentication, where victims are persuaded to authenticate an attacker-controlled session through a legitimate Microsoft sign-in page. Following initial compromise, attackers have been observed registering devices to obtain Primary Refresh Tokens, as well as attempting to register additional authentication methods, including passkeys, to retain access to compromised accounts. This news comes as Microsoft continues to expand legitimate passkey adoption as Microsoft recently announced changes allowing passkeys to become a user’s first registered MFA method, and from 1 September, Microsoft began making passkeys the default authentication experience for users currently enabled for SMS or voice authentication.
Organisations should review Conditional Access policies to ensure that MFA or an appropriate authentication strength is required when registering or changing security information, and when registering or joining devices. Device code authentication should be blocked wherever it is not explicitly required, with tightly scoped exceptions for legitimate use cases.