WEEKLY TOP TEN: August 10, 2026, 16:00 GMT
- North Carolina Ports Cyberattack Disrupts Cargo Gates
The North Carolina Ports Authority confirmed a cyberattack that disrupted IT systems and slowed operations at the Port of Wilmington, the Port of Morehead City, and the Charlotte Inland Port. Wilmington alone operates nine berths with 600,000 TEU annual container capacity and averages 5,000 container gate moves weekly, while Wilmington and Morehead together handle 4.4 million short tons of bulk and breakbulk cargo annually. The attack was detected on August 4, prompting the authority to activate its cybersecurity contingency plan and begin recovery on August 5 after a systems-wide outage delayed gate openings. The U.S. Coast Guard is monitoring the investigation. - Levi Strauss Says Social Engineering Led To Data Theft
Levi Strauss & Co. disclosed in a filing with the U.S. Securities and Exchange Commission that attackers used social engineering against three employees to reach and steal corporate data stored on their company-issued machines. Preliminary investigation findings indicate certain corporate information was accessed and exfiltrated, though the company says rapid response contained and terminated the unauthorized access and that no consumer data was affected. Levi’s reported no interruption to business operations and does not expect a material impact on its financial position. The disclosure followed a wave of voice phishing attacks aimed at Wall Street firms. The investigation remains ongoing. - Unlimited Technology Systems Breach Hits 3.8 Million
Healthcare software provider Unlimited Technology Systems reported that more than 3.8 million people were affected by a data breach traced to an incident in October 2025. Attackers stole personal, medical, and health insurance information from the company’s data center. The long gap between intrusion and notification is the notable detail for security leaders: the compromise sat undisclosed for roughly nine months while affected individuals had no opportunity to monitor for identity fraud. Healthcare technology suppliers continue to concentrate protected health information for large downstream provider networks, making a single vendor compromise a mass-casualty privacy event across many unrelated covered entities. - AI Notetaker Flaw Let Hackers Spy On Video Calls
Researchers demonstrated that flaws in a widely deployed AI meeting notetaker could let attackers eavesdrop on government and corporate video conferences. Meeting assistants join calls as authenticated participants and retain transcripts, recordings, and summaries, which concentrates highly sensitive deliberations in a third-party service that rarely receives the scrutiny applied to core collaboration platforms. For government entities and regulated industries, the finding underscores that approving an AI assistant is effectively approving a new recording endpoint with standing access to executive and policy discussions. Security teams should inventory notetaker integrations, restrict which meetings they may join, and review retention and export controls. - Chinese Actor Automates Intrusions With DeepSeek Agent
A Chinese-speaking threat actor weaponized a DeepSeek-based AI agent to conduct largely autonomous attacks, including an operation aimed at a cybersecurity firm. The campaign was linked by researchers to exploitation activity that also drew CISA attention. The significance for defenders is the shift from AI as a productivity aid for human operators to AI as the operator itself, running reconnaissance, exploitation, and lateral movement with limited supervision. That change compresses dwell time and raises the volume of concurrent intrusions a single actor can sustain, which in turn puts pressure on detection programs still tuned to the tempo of manual, keyboard-driven attacks. - Brown Health Breach Exposes 311,000 Patient Records
Brown Health Medical Group-MA disclosed a data breach affecting the information of approximately 311,000 individuals, adding to a sustained run of large-scale healthcare compromises reported during the week. Provider group breaches of this size typically involve names, dates of birth, contact details, insurance identifiers, and clinical information, all of which retain value for fraud far longer than payment card data. For healthcare security leaders, the incident reinforces the case for aggressive data minimization in electronic medical record and practice management systems, tighter scoping of vendor access, and pre-arranged notification workflows that can scale to hundreds of thousands of affected patients. - WordPress XSS2Shell Chain Enables Full Server Takeover
Researchers detailed XSS2Shell, tracked as CVE-2026-64638, a pre-authentication cross-site scripting flaw in WordPress that can be chained into remote code execution and full server takeover. The chain converts what would normally be triaged as a moderate-severity input validation bug into a path to complete compromise of the underlying host, including any co-hosted sites and stored credentials. Organizations running WordPress for public-facing marketing, investor relations, or constituent services should patch immediately and treat the web tier as potentially untrusted, reviewing for unexpected administrator accounts, modified theme or plugin files, and newly written webshells. - Threat Actors Bypass AI Guardrails With Simple Claims
Cisco Talos analyzed prompt logs recovered from threat actor systems running Claude Code, Codex, Cursor, and Gemini, and found that criminals routinely defeated safety controls by claiming they owned the target, describing the work as capture-the-flag or bug bounty activity, splitting tasks across sessions, or storing blanket authorization in an assistant’s persistent memory. Researchers reported encountering no sophisticated encoding or evasion techniques. In one case an operator with limited programming knowledge used a model to develop distributed denial-of-service tooling while appearing to control nearly 2,000 Android TVs; the model objected only after supplying basic functionality. - Beacon CRM Breach Ripples Across UK Charity Sector
Beacon CRM confirmed a cyberattack that exposed data belonging to a growing list of UK charities. The company, which markets its software to the charity sector and has more than 1,500 customers, said its investigation remains ongoing. English National Ballet said it was informed on August 3 that an unauthorised third party had gained access to Beacon’s system, and although it had not received confirmation that its own data was directly affected, it notified all contacts as a precaution. The incident illustrates how a single sector-specific platform can transmit a breach across hundreds of small nonprofits with minimal internal security capacity. - Keyv And Cacheable npm Packages Trojanized In Worm
On August 4 a threat actor compromised source or release credentials for the widely used keyv and cacheable npm packages and published trojanized versions of at least ten packages. Each carries a malicious preinstall hook that downloads a standalone Bun runtime and executes an obfuscated second stage, harvesting AWS instance metadata, Vault, Kubernetes, GitHub Actions, and npm credentials, encrypting them, and delivering them to attacker-controlled GitHub repositories. The malware then self-propagates, republishing trojanized versions of other packages reachable with the stolen npm token. Critically, keyv 6.0.0 shipped with passing npm provenance because the legitimate release workflow built already-trojanized source.
Our Threat Operations and Intelligence team compiles a daily digest of the most recent online cybersecurity risks. The previous 10 stories were determined to be most significant during the course of the week, ranked by highest risk, and using multiple sources when available.