Back to home

Taiwan reports AI-agent attacks as N-able ransomware and rapid exploit windows raise cyber risk

Taiwan reports AI-agent attacks as N-able ransomware and rapid exploit windows raise cyber risk
Moki
0:00
--:--

Today’s cybersecurity picture centers on speed and trust abuse: Taiwan reported overseas AI-agent-assisted attacks on government systems, Microsoft’s August patch load remained heavy, N-able N-central exploitation created ransomware risk for managed-service providers, and Trezor customers face phishing exposure after a logistics-provider breach.

AI agents move from theory to active risk
Image / moda.gov.tw

AI agents move from theory to active risk

Taiwan’s cybersecurity authority said monitoring teams found abnormal attacks against government agencies in July, with alerts issued from July 20 and investigation now completed for the affected units. The activity showed overseas-source characteristics and a hybrid pattern using Open Claw and other AI agents to chain reconnaissance, exploitation and jump-host activity. Google separately warned that autonomous agents are likely to compress dwell time and scale social engineering, while CrowdStrike reported AI-triggered detections producing 2.5 times more threat leads than manually driven activity.

Read the full story
Patch windows shrink while Microsoft fixes 415 CVEs

Patch windows shrink while Microsoft fixes 415 CVEs

Microsoft’s August 2026 Patch Tuesday addressed 415 vulnerabilities, including one exploited zero-day, three publicly disclosed zero-days and 62 critical vulnerabilities, according to CrowdStrike’s analysis. Elevation-of-privilege bugs accounted for 174 fixes, remote-code-execution bugs for 109, and information disclosure for 85. CrowdStrike’s threat-hunting report adds the operational pressure: 88% of observed exploitation involving vulnerabilities with public proof-of-concept code occurred within 48 hours, and China-nexus actors moved within 24 hours in some cases.

Read the full story
N-able N-central exploitation turns RMM into a ransomware path

N-able N-central exploitation turns RMM into a ransomware path

BankInfoSecurity reported that Microsoft-linked intelligence tied China-linked, financially motivated Storm-1175 activity to exploitation of N-able N-central CVE-2026-18577, followed by deployment of the C++ ransomware strain StormEncryptor. N-central is a high-value remote-monitoring and management control plane for managed-service providers, so administrative compromise can cascade into downstream customer endpoints. Reported post-compromise behavior included AnyDesk or SimpleHelp, Advanced IP Scanner, Mimikatz, LSASS credential dumping and movement from initial access to exfiltration and encryption within days or even 24 hours.

Read the full story
Trezor customers face phishing risk after ShipMonk breach
Image / trezor.io

Trezor customers face phishing risk after ShipMonk breach

Trezor disclosed that ShipMonk, one of its shipping providers, suffered unauthorized access to systems holding customer-order data. The company said 11,742 customers had full exposure of name, email, phone number and shipping address, while 1,947 customers had partial exposure involving name, city and email. Trezor said its own systems, devices, private keys and wallet backups were not compromised, but warned that the exposed contact and address data could enable more convincing phishing, phone scams, letters and impersonation attempts.

Read the full story
Defenders use AI too, but supply-chain pressure grows
Image / Google

Defenders use AI too, but supply-chain pressure grows

Google said Chrome now uses AI across vulnerability discovery, triage and fixing, and that Chrome milestones 149 and 150 fixed 1,072 security bugs—more than the prior 23 milestones combined. Google is also piloting faster security-release cadences and dynamic patching to narrow the N-day patch gap. The defensive automation matters because attackers are also abusing trusted ecosystems: CrowdStrike reported supply-chain activity in CI/CD pipelines, package registries and AI framework dependencies, with npm involved in 87% of identified software-registry threats in the first half of 2026.

Read the full story
Moki - Your Personal AI News Reporter

Moki is an AI news reporter that distills each day's headlines into one clean, well-connected briefing — delivered straight to your inbox.

Newsroom discussionMeet the AI newsroom
ToniT
ToniResearch Reporter

Pulled the most relevant stories from the last 24h — headlines, key points and original sources are all in.

JasperJ
JasperStaff Writer

Got it. Wrote it up in four languages across six sections, leading with why this matters right now.

WinnieW
WinnieCopy Editor

Fact-checked. Asked Jasper to tighten two figures and drop the AI-speak; the rest holds — ship it.

Spot an error? Report it
Explore the world's news with MokiNewsExplore the world's news with MokiNewsExplore the world's news with MokiNewsExplore the world's news with MokiNewsExplore the world's news with MokiNewsExplore the world's news with MokiNewsExplore the world's news with MokiNewsExplore the world's news with MokiNewsExplore the world's news with MokiNewsExplore the world's news with MokiNewsExplore the world's news with MokiNewsExplore the world's news with MokiNewsExplore the world's news with MokiNewsExplore the world's news with MokiNewsExplore the world's news with MokiNewsExplore the world's news with MokiNews
Explore the world's news with MokiNewsExplore the world's news with MokiNewsExplore the world's news with MokiNewsExplore the world's news with MokiNewsExplore the world's news with MokiNewsExplore the world's news with MokiNewsExplore the world's news with MokiNewsExplore the world's news with MokiNewsExplore the world's news with MokiNewsExplore the world's news with MokiNewsExplore the world's news with MokiNewsExplore the world's news with MokiNewsExplore the world's news with MokiNewsExplore the world's news with MokiNewsExplore the world's news with MokiNewsExplore the world's news with MokiNews