Content 

01. News Bites
  • Microsoft’s August Patch Tuesday fixes 400 flaws and three Zero-Days

  • Cyberattack on Polish heat plant exposes critical infrastructure risks

  • Californian city declares emergency after cyberattack disrupts 911 and dispatch systems

  • Cisco warns of actively exploited secure Firewall Vulnerability

  • Nearly one in three UK manufacturers hit by cyber incidents

  • AI Agents used in near-autonomous cyberattack on Taiwanese government systems


02. Conclusion

Quick News Bites

Microsoft’s August Patch Tuesday fixes 400 flaws and three Zero-Days

Microsoft has released its August 2026 Patch Tuesday updates, addressing around 400 vulnerabilities, including one actively exploited zero-day and two publicly disclosed flaws.

The update fixes 42 critical vulnerabilities, including 37 remote code execution issues and five elevation of privilege flaws. Overall, the patches cover 176 elevation of privilege vulnerabilities, 110 remote code execution flaws, 86 information disclosure issues and 21 spoofing vulnerabilities.

The most urgent issue is CVE-2026-68820, an elevation of privilege vulnerability in the Windows Ancillary Function Driver for WinSock. The flaw has reportedly been exploited by the North Korean Lazarus threat group to gain SYSTEM privileges and deploy a kernel-mode rootkit.

Microsoft also patched two publicly disclosed zero-days affecting Windows User Profile Service and the Windows Container Isolation FS Filter Driver.

Organisations should prioritise testing and deploying the latest security updates, particularly on internet-facing and high-value Windows systems.

Cyberattack on Polish heat plant exposes critical infrastructure risks

Poland’s cybersecurity authorities have revealed that a previously unknown cyberattack disrupted systems at a combined heat and power plant serving around 50,000 residents during last winter’s cold snap.

CERT Polska said attackers gained access by moving from compromised wind farm firewalls into a private cellular data network, before reaching a controller at the heat plant that was still using factory-default credentials.

The attackers spent 11 days conducting reconnaissance before disabling Siemens controllers operating the steam turbine and water treatment system. They also changed passwords, wiped network configurations and attempted to destroy forensic evidence.

Operators restored systems quickly enough to prevent disruption to customer heating.

CERT Polska warned that the attack highlights the danger of treating private cellular networks as inherently trusted infrastructure. Energy operators are being urged to audit network configurations, remove default credentials and include private cellular connections within regular cybersecurity testing and monitoring programmes.

Californian city declares emergency after cyberattack disrupts 911 and dispatch systems

Suisun City in California has declared a local emergency after a cyberattack disrupted critical public safety and municipal services, including 911 routing, police and fire dispatch.

Officials said malicious software compromised city IT systems on Friday morning, forcing authorities to shut down the entire network to contain the attack and preserve evidence for a federal investigation.

Despite the disruption, emergency services have remained operational, with calls being routed through the Solano County dispatch centre while police and fire teams continue responding to incidents.

The city is working with the FBI, Department of Homeland Security and California Office of Emergency Services to investigate the attack and maintain essential services.

It remains unclear whether ransomware was involved. The emergency declaration is intended to help Suisun City access additional support and recover costs associated with the incident while restoration and investigative work continues.

Cisco warns of actively exploited secure Firewall Vulnerability

Cisco has warned that attackers are actively exploiting a high-severity vulnerability affecting Secure Firewall ASA and Threat Defense software.

Tracked as CVE-2026-20349, the flaw carries a severity score of 8.6 and can allow an unauthenticated remote attacker to crash vulnerable devices, causing a denial-of-service condition.

The issue stems from insufficient error checking when processing HTTP requests. Attackers can exploit it by sending a specially crafted request to the Remote Access SSL VPN service on affected devices.

Vulnerable configurations include SSL VPN, IKEv2 Remote Access VPN with client services, and Zero Trust Network Access on FTD devices. Cisco Secure Firewall Management Center is not affected.

Cisco confirmed active exploitation in August but has not disclosed details about the attackers or targeted organisations. There are no workarounds, so customers are being urged to install the available hot fixes or upgrade to a fixed software release as soon as possible.

Nearly one in three UK manufacturers hit by cyber incidents

Almost one third of UK manufacturers suffered a cyber incident in the past year, either directly or through attacks on suppliers, according to research from Make UK.

The survey found that 30% of manufacturers had been affected, with incidents increasingly disrupting production, customer deliveries and access to components and materials. Among firms hit through their supply chains, around 30% experienced delivery delays or reduced output.

Despite the growing threat, only around half of manufacturers have a formal incident response plan, while almost a third either lack cyber insurance or are unsure whether they are covered.

Supply chain security is also becoming a bigger concern. Nearly a quarter of manufacturers now require suppliers to demonstrate that they meet cybersecurity requirements, while 25% have faced similar demands from customers.

Make UK is urging manufacturers to treat cybersecurity as a board-level priority, strengthen supplier assurance and regularly test recovery plans.

AI Agents used in near-autonomous cyberattack on Taiwanese government systems

Hackers reportedly used publicly available AI agents to target Taiwanese government infrastructure and steal thousands of sensitive files during a four-day cyberattack.

Cybersecurity company Dream said the campaign used a framework built around the Hermes and OpenClaw agentic AI systems, deploying up to eight autonomous sub-agents at a time across multiple attack waves.

Researchers claim the attackers obtained 1,395 files, 85 compromised credentials and thousands of personnel records. The AI agents reportedly identified vulnerable APIs, discovered a flaw in a government authentication service and installed backdoors on web applications.

According to Dream, the framework could also adapt when attack methods failed, using publicly available information to identify alternative infiltration techniques.

The researchers said safeguards within the AI tools were bypassed by presenting the activity as authorised penetration testing. The original documentation was reportedly written in Simplified Chinese, although the attackers have not been formally attributed.

 

Closing Summary

If you are worried about any of the threats outlined in this bulletin or need help in determining what steps you should take to protect yourself from the most material threats facing your organisation, please contact your account manager, or alternatively Get in touch to find out how you can protect your organisation. 

Disclaimer

The Threat Intel Roundup was prepared by Integrity360 summarising threat news as we observe it, current at the date of publishing. It should not be considered to be legal, consulting or any other professional advice. Any recommendations should be considered in the context of your own organisation. Integrity360 does not take any political stance in the information that we share. Moreover, the opinions expressed may not necessarily be the views of Integrity360.