Risky Bulletin: The EU publishes its upcoming cybersecurity standards
In other news: Hackers breach France's tax agency; GeoServer zero-day exploited hours after disclosure; exploit unlocks old AMD CPUs with one instruction.
This newsletter is brought to you by Socket Security. You can subscribe to an audio version of this newsletter as a podcast by searching for "Risky Business" in your podcatcher or subscribing via this RSS feed. You can also add the Risky Business newsletter as a Preferred Source to your Google search results by going here.
The European Telecommunication Standards Institute has released 17 cybersecurity standards that vendors will have to follow to sell products in the EU when the EU Cyber Resilience Act enters into effect in December of 2027.
The standards cover 17 core technologies for major product categories such as:
- Operating systems
- Router, modems, and switches
- Firewalls
- VPNs
- Virtualization containers
- Network management systems
- SIEMs
- Antivirus software
- Boot managers
- Network interfaces
- Browsers
- Password managers
- PKI software
- Smart home appliances
- Smart home security systems
- Internet-connected toys
- Wearables
The standards describe a list of minimum security features each product category must implement to be CRA-compliant.
Most of the standards usually require the same basic features, such as the ability to update the product once it's sold, that devices are sold with an SBOM, that they use modern cryptography, or that they ship with secure-by-default settings.
Obviously, there are requirements unique for each product category, but none of the standards introduce unreasonable requests.
Most cover basic security advice and features that experts have been recommending and advocating for decades, but have rarely been adopted and added to existing product lines.
The standards are "interim drafts" and in a public comments phase until November, until which national standardization bodies across the EU and its economic area can submit feedback.
Their final versions are expected to be available by December, a year before CRA compliance.
The publishing of the actual CRA standards represent the final step before the regulation enters into effect next year.
Barring a few technical aspects here and there, most vendors should have known about what the EU wanted from them. EU lawmakers have been talking about the CRA and the minimum security standards they wanted for years, and many vendors already support features like automatic security updates, default secure configs, and better crypto.
See the full versions of the draft CRA standards here.

Risky Business Podcasts
The main Risky Business podcast is now on YouTube with video versions of our recent episodes. Below is our latest weekly show with Pat, James, and special guest co-host Brad Arkin at the helm!
Breaches, hacks, and security incidents
Irregular explains AI test environment escapes: AI security lab Irregular has taken responsibility for recent incidents where frontier AI models escaped its test environments. The incidents involved AI models from Anthropic and Meta. Irregular says it used target names close to the name of a real company and accidentally left some test environments connected to the internet. Some of the "leading models" hacked the real company but believed they were still in a simulated environment. [Irregular]
Columbus still restoring systems 2 years later: The Columbus Police Department in Ohio has restored its online crime reporting portal two years after it was taken down following a ransomware attack on city systems. [ABC6]
DDoS attacks on Threema: A large-scale DDoS attack has disrupted the Threema secure instant messaging service. The attack targeted Nine, the company's cloud hosting provider. The DDoS attack did not impact customers hosting local Threema servers. [Threema]
Harmony Protocol crypto-heist: Hackers have exploited the Harmony Protocol and stole more than $3.2 million worth of assets. The attackers stole 4 billion of the platform's custom ONE token. The stolen funds represented a quarter of all ONE supply, crashing the token's price by 40%. This is the platform's second hack after it also lost $100 million to North Korean hackers in 2022. [CoinPedia // Harmony Protocol]
Hackers breach French tax agency: A hacker has stolen the tax information of more than 678,000 French citizens. The breach occurred at the French Directorate General of Public Finance between June and July. A hacker named ZeroBytes has taken credit for the intrusion. They claimed they were in the process of downloading the data of 20 million citizens before the intrusion was detected and access was shut down. [French government // FrenchBreaches // RFI]

Kazakhstan eGov portal got hacked: The Kazakhstan government is investigating a breach of its eGov portal after a hacker listed government data for sale on an underground hacking forum. The stolen data covers 15 million citizens, around three-quarters of the country's entire population. Officials deny a breach of actual eGov systems and believe the data was stolen from another government agency allowed to connect to its database. [News.az International]

Ukraine claims Wildberries cyberattack: Ukraine's military intelligence service GUR claims to have disrupted the IT systems of Wildberries, Russia's largest online retailer. The hacks took place days before the Ukrainian army hit the company's largest logistics hub, in Koledino, near Moscow. GUR said the cyberattack disrupted the company's customer service channels and partially destabilised its payment infrastructure. [GUR]
🔥❗️BREAKING: A massive fire has engulfed the entire Wildberries logistics hub in Koledino, Moscow Oblast, following tonight’s drone attack. The 250,000 m² complex was one of Wildberries’ two largest warehouses. The other, in Elektrostal, was destroyed in a strike in July.
— 🦋Special Kherson Cat🐈🇺🇦 (@specialkhersoncat.bsky.social) August 16, 2026 at 3:32 PM
[image or embed]
This is an interesting story as it is not just another tale of Russian humiliation by a capable adversary but it illustrates how companies all across the world need to consider and plan that during a conflict they quickly can be pulled it onto the digital battlefield.
— NetAskari (@NetAskari) August 15, 2026
It is not… https://t.co/oqIsBqcOWf
AI, general tech, and privacy
AI agents had turf wars: Anthropic says agents "consistently" engaged in a turf war when they received the same tasks. Agents deployed self-replicating malware, locked rival accounts, and deployed scripts that ran in a loop to disable a competing agent's processes. Anthropic says the newer models like Mythos won by revoking rivals' access first and then negotiating truces. [Anthropic]

Chinese AI chatbots spew Chinese propaganda: Chinese AI chatbots available to Western users are spewing Chinese propaganda and false claims. Yes, water is still wet. [NewsGuard]
Meta fails to remove harassment videos: Meta promised to remove harassment videos recorded with its stupid spy glasses but months later, the videos are still online. [Business Insider]
Windows licenses are going up: According to rumors from Windows OEMs, Microsoft has allegedly increased the price of a Windows 11 license. [CNET]
Twitter open-sources For You algo: Twitter, now X, has open-sourced the algorithm that powers its For You feed. [GitHub]
twitter open sourced their For You algo, allegedly these are the weights do what you will
— zeu (@zeu.dev) August 14, 2026 at 9:11 AM
[image or embed]
ChatGPT Computer History feature: OpenAI has launched a new ChatGPT feature for macOS. Named Computer History, the feature records the user's activity on the device, such as what users clicked, typed, and opened, and the makes it searchable. Computer History is disabled by default and is similar to Microsoft Recall, a highly controversial feature on Windows 11. [OpenAI]
@OpenAI just launched a new feature last night called Computer History. For DFIR analysts, this is a new artifact class worth knowing about. I turned it on on my MacBook, parsed the artifacts, and it produced about 3,616 timeline events from ~2 hours of normal work.
— Renzon (@r3nzsec) August 14, 2026
While… pic.twitter.com/vCZCiKUhGi
Government, politics, and policy
US government to reveal NIT usage: Starting with 2029, the US Department of Justice will publish how many times judges have approved the use of network investigating techniques (NITs) such as the use of spyware and other hacking tools. [TechCrunch]
Taiwan cuts mobile internet to simulate cyber-attack: Taiwan throttled mobile internet access across the country's northern region to simulate a cyberattack against its communications infrastructure. Mobile internet was throttled for just 30 minutes during Taiwan's annual Han Kuang war games last week. Officials said they wanted to test the public's psychological response and logistical readiness. [The Strait Times]
Sponsor section
In this Risky Business sponsor interview, Casey Ellis chats with Socket founder Feross Aboukhadijeh about npm 12’s move to disable install scripts by default.
Arrests, cybercrime, and threat intel
Bank hackers arrested: German and Brazilian authorities have arrested members of a criminal group who hacked and stole more than €30 million in customer funds. Four suspects were detained in Brazil and three others across Europe. The group allegedly exploited a vulnerability at a payment service provider in late 2023 and stole funds from online banking accounts. [Germany's BKA // Brazilian Federal Police]
PXA Stealer admin arrested: Vietnamese police have arrested twelve suspects who infected more than 94,000 systems with the PXA Stealer malware. The malware's creator was identified as a 12th-grader from the Thanh Hoa province. The group had allegedly made $380,000 from selling the malware, as well as a 15% from the sale of any data stolen with PXA. [VN Express] [h/t Anna Pham]
NC man sentenced for extortion: A US court has sentenced a North Carolina man to two years in prison for extorting his former employer. Cameron Curry worked as a data analyst contractor for Brightly Software until December 2023. The first day after his employment ended, Curry launched an extortion campaign using salary data he stole months before. He threatened to leak salary and employee details unless he was paid $2.5 million. [DOJ // CyberScoop]
ExfilSquad likely hacked Microsoft D365 servers: A new data extortion group that made waves last month most likely stole its data from Microsoft Dynamics 365 instances. Victims of the ExfilSquad group include Allstate, Frontier Airlines, the US cities of Atlanta and House, and the UK Department of Education and national police force. Fortra researchers believe the group exploited misconfigured Microsoft Power Pages and then pivoted to an organization's D365 environment. [Fortra]
Dysphoria botnet explodes: The Dysphoria DDoS botnet has grown 50% in size from 200,000 to 300,000 over just the past two weeks. [Shadowserver Foundation // QiAnXin]
Majinahanashi ransomware: Threat intel analyst Rakesh Krishnan has spotted a new ransomware gang advertising its services and leak site on the dark web. [The Raven File]

CRPx0 launches leak site: The CRPx0 ransomware group has leaked the data of 47 companies on its dark web leak site in the first week after its launch. Most of the victims are from the US and Turkey. They include banks, healthcare organizations, and Hyundai's Turkish branch. The CRPx0 started operations this month and is allegedly run by a known crypto scammer. [DataBreaches.net // The Raven File // Aryaka]

Malware technical reports
AmnesiaStealer: Threat actors are using fake GitHub repositories and ClickFix techniques to infect macOS users with AmnesiaStealer, a new Rust-based infostealer. [Jamf]
DCRat: Security firm Trellix has found new campaigns spreading the DCRat malware this year. No word on the attribution. [Trellix]
"This DCRat campaign demonstrates how attackers blend phishing lures, DLL sideloading, and process hollowing to bypass defenses and gain remote access. By abusing trusted utilities and requiring user interaction, the operation underscores both the persistence of social engineering and the sophistication of modern malware delivery. Such attacks, which disguise malicious components as legitimate libraries, highlight the importance of stronger defensive practices."
New Windows backdoor: Gen Digital's Avast team has spotted a super light Windows backdoor at only 12KB that has a very unique way of hiding its C2 IP address inside desktop.ini files. Avast says the malware was spotted on only one endpoint, which suggests this is either some test or some super stealthy APT tool. [Gen Digital]
"Its most unusual feature was its configuration: the address of its command-and-control server was not stored as readable text or encrypted data, but encoded in the number of spaces on each line of a Windows `desktop.ini` file."
Sponsor section
In this Soap Box edition of the Risky Business podcast Patrick Gray chats with Socket founder Feross Aboukhadijeh about how to measure the reachability of vulnerabilities in applications. It's great to know there's a CVE in a library you're using, but it's even better if you can say whether or not that vulnerability actually impacts your application.
APTs, cyber-espionage, and info-ops
HoneyMyte's CoolClient update: Chinese cyber-espionage group HoneyMyte (Mustang Panda) has a new version of its CoolClient backdoor. [Kaspersky]
"In late 2025 and 2026, our latest investigation revealed another major evolution. The newest CoolClient variant can deploy a signed kernel-mode driver as a Windows service and communicate with it through IOCTL requests. The driver enhances the malware’s stealth by hiding the CoolClient process, protecting related files and registry entries, and preventing them from being inspected or modified."
DPRK remote IT workers operate from within local universities: Security firm Kudelski has discovered clusters of remote IT workers operating from within the buildings of at least two North Korean universities. Clusters have been found at the Kim Chaek University of Technology and the Jinung Institute of IT Development at the Kim Il Sung University. The workers operated from specific floors, suggesting the space was specifically assigned for their work. Another cluster was found operating out of the Pyongyang Information Technology Center, a high-rise office skyscraper in the country's capital close to the headquarters of the North Korean intelligence service. [Kudelski Security]

Vulnerabilities, security research, and bug bounty
Security updates: cPanel, Flatpak, GeoServer, Info-ZIP, MongoDB, Ubuntu.
LoongLeak attack: A new vulnerability can allow attackers to leak data from Loongson CPUs sold on the Chinese internal market. The vulnerability is a CPU hardware architecture bug and cannot be patched. It is not a side-channel or transient-execution attack like the old Meltdown and Spectre bugs discovered in Intel and AMD chips. [LoongLeak]
Exploit unlocks AMD CPUs with one instruction: A security researcher has developed an exploit to unlock closed areas of AMD CPUs. The exploit is just one CPU instruction and can grant access to previously closed areas like the Platform Security Processor (PSP), the System Management Mode (SMM), and every internal processor register. The exploit impacts AMD 15h and 16h families. This includes CPUs released between 2011 and 2015. The most widely used are the Puma and Jaguar families, used for PlayStation 4 and Xbox One consoles. AMD says it won't patch the bug because the CPUs have reached end-of-support many years before. [Christopher Domas on GitHub // Tom's Hardware // List of AMD CPU microarchitectures // AMD security advisory]

GeoServer zero-day exploited hours after disclosure: Hackers started exploiting a zero-day in GeoServer hours after details were disclosed on Twitter. The zero-day allows attackers to run malicious code on the servers via an SQL injection. GeoServer released a patch on Friday. The project is an open-source tool that can display geospatial and map data on the web, such as interactive maps. [Hadrian // Q1uf3ng // GeoServer patch]
SAP Commerce Cloud exploitation: Hackers are exploiting a recently patched vulnerability to access SAP-based online stores. The attacks are targeting a bug patched this month in the SAP Commerce Cloud platform. The vulnerability allows attackers to bypass authentication on some of the platform's components and run malicious code. According to security firm Defused, attacks started three days after SAP patched the bug last week. [Defused // CVE-2026-58231]
OpenCart unpatched bug: A path traversal vulnerability can allow attackers to install webshells and run malicious code on OpenCart online stores. The bug is a classic ../ vulnerability. It can be exploited via malicious extensions that drop files outside their normal folders during the installation process. A patch is not available after security researchers couldn't contact the OpenCart team. [CMU CERT/CC]
New NetScaler RCE: WatchTowr Labs believes a Citrix NetScaler memory corruption bug patched last month can also be abused for remote code execution attacks. [WatchTowr // CVE-2026-8452]
FileRun vulnerabilities: VulnCheck has published a technical write-up on CVE-2026-14863, an OS command injection that can lead to remote code execution in FileRun, a commercial self-hosted file manager. This was patched last month. [VulnCheck]
Infosec industry
Threat/trend reports: BI.ZONE, Gambit Security, HuggingFace, Kaspersky, and ThreatMon have recently published reports and summaries covering various emerging threats and industry trends.

New tool—KernelSight: Security researcher Ahmad Abdillah has launched KernelSight, a portal for tracking the root cause for Windows kernel bugs.
New tool—agentcov: Security firm Trail of Bits has open-sourced agentcov, a tool to track which lines in a repository were read by AI coding agents.
New tool—Blacklight: Security firm SpecterOps has released Blacklight, a toolkit for discovering and analyzing AI agent artifacts left on endpoints.
CactusCon 14 videos: Talks from the CactusCon 14 security conference, which took place in February, are available on YouTube.
PETS 2026 videos: Talks from the Privacy Enhancing Technologies Symposium, which took place earlier this month, are available on YouTube.
Risky Business podcasts
In this edition of Seriously Risky Business, Tom Uren and James Wilson talk about the cybercrime ecosystem shifting towards data theft extortion, stealing sensitive data and extracting ransoms from victims by threatening to leak it.