Skip to content

CyberSecurity Institute

Security News Curated from across the world

Menu
Menu

Security Operations Weekly — August 16, 2026

Posted on August 17, 2026 by admini

August 16, 2026 · Weekly Edition

Security Operations Weekly

The week after Black Hat belonged to the practitioners: Walmart and Standard Chartered describing what SOC transformation actually costs, the MDR/MXDR market arguing in public about what AI genuinely changes, a 400-flaw Patch Tuesday with a Lazarus-exploited zero-day, and a CVE program openly debating whether it can keep up with machine-pace vulnerability discovery.

This week at a glance

If last week was the vendor keynote, this week was the hallway track. The strongest SOC reporting out of Black Hat USA 2026 came from people who run one: Walmart’s global VP of security operations, Jason O’Dell, describing a decade-long shift from a fear-based gate to an enablement function that answers business requests with “yes, and” — and a purple-teaming model where red and blue sit in the same room as trusted agents rather than scoring points off each other. Standard Chartered’s group CISO, Cezary Piekarski, made the parallel case for a global bank, arguing for “productive worry” and for security leaders who are business-literate first and tool-literate second. Neither story turns on a product. Both turn on whether the operating model around the tools is any good — which is a harder thing to buy and a much harder thing to demo.

The managed-detection market spent the week arguing about what AI actually changes underneath the marketing. TENEX.ai CEO Eric Foster called legacy MDR “a people business dressed up as technology” and pitched an AI-native alternative that investigates 100% of alerts with Tier 1 triage in under a minute; Expel extended MDR into the AI attack surface itself, with live Claude Enterprise telemetry and detections mapped to 13 of MITRE ATLAS’s 16 tactics; ArmorPoint added response and governance tooling for MSPs and MSSPs on the argument that “security without response is just surveillance.” Read alongside this week’s foundational piece on the difference between MSP, MSSP, MDR and MXDR, the pattern is clear: the acronyms have stopped describing distinct services, and the only useful questions left are which telemetry is actually ingested, who investigates it, and what the provider is contractually allowed to do without asking you first.

On the vulnerability side, the numbers did the arguing. Microsoft’s August Patch Tuesday fixed 400 flaws — down from July’s 570, still enormous — including an actively exploited WinSock use-after-free that Lazarus used to drop the FudModule rootkit at defense firms, and Microsoft itself attributed the elevated volume to AI-powered vulnerability discovery running across its own portfolio. CISA gave federal agencies three days to remediate a critical, unauthenticated command injection in Progress LoadMaster under BOD 26-04. Dark Reading made the case that CVSS-driven checklists are the wrong instrument entirely when time-to-exploit has fallen from 771 days in 2018 to roughly four hours, and that choke-point patching against attack chains beats ranking severity scores in a spreadsheet.

Behind all of it, the pipeline that SOC vulnerability workflows depend on is visibly straining. At Black Hat and DEF CON, CVE Program stakeholders debated whether “vulnpocalypse” is a useful word while conceding the underlying condition: Microsoft’s Elizabeth Eigner put it as “these are coming out at an AI pace, but we’re still creating them at a human scale,” GitHub alone published more than 7,000 CVE IDs in 2026, and OpenAI and Anthropic have been granted temporary CNA status to assign IDs for model-discovered bugs. Microsoft’s David Weston went further in a separate CSO Online piece, reporting a 9x increase in MSRC vulnerability volume since March and arguing that “hand-to-hand combat with attackers will cause us to lose in defense” — memory-safe languages and deterministic prevention over faster detection.

Two adversary-side stories closed the loop on the tooling itself. Akamai researchers showed at DEF CON 34 how SentinelOne’s PPL-protected helper service could be turned into a “bring your own EDR” primitive for dumping arbitrary protected processes (fixed in Agent 26.1.1), while a survey of 24 underground crypter sellers documented EDR evasion sold as a tiered subscription with automated re-encryption. And Cloudflare’s H1 2026 DDoS data recorded 805 network-layer attacks above 1 Tbps in Q2 alone — a 519% jump over Q1 — with media and publishing the single most-targeted sector, driven by the Ukraine–Russia and US–Iran conflicts and the FIFA World Cup. This week’s foundational reading extends those threads: vulnerability management in the post-Mythos era, the service-model taxonomy, the DNC’s security-culture playbook, and how USENIX Security is triaging a 3,030-paper submission flood.

Topic map of this week's Security Operations Weekly themes

This week’s topic map — enterprise SOC transformation (Walmart’s Jason O’Dell, Standard Chartered’s Cezary Piekarski, trusted-agent purple teaming), the MDR/MXDR argument over what AI changes (TENEX.ai, Expel, ArmorPoint), Microsoft’s 400-flaw August Patch Tuesday and the Lazarus-exploited WinSock zero-day, the Progress LoadMaster KEV entry under BOD 26-04, choke-point patching versus CVSS checklists, the CVE Program’s automation and globalization push against AI-pace discovery, EDR turned against the defender (bring-your-own-EDR, crypters-as-a-service), and record 1 Tbps+ DDoS against publishers.

View interactive topic map →

Article index

Weekly News

Enterprise SOC transformation: the practitioner track

The strongest Black Hat reporting this week came from people who actually run security operations — a $700 billion retailer, a global bank, and a chief security advisor on how corporate investigations go wrong under pressure.
Article Source Published
1. Walmart Leaders Transform Security Operations Without Going Bananas Dark Reading Aug 12, 2026
2. Walmart Takes a ‘Trusted Agent’ Approach to Purple Teaming Dark Reading Aug 12, 2026
3. Mission-Driven Security: Inside a Global Bank’s Defense Dark Reading Aug 14, 2026
4. Four corporate investigation mistakes organizations make under pressure Help Net Security Aug 13, 2026

Patch Tuesday, a three-day KEV clock, and the patch-gap argument

400 Microsoft flaws, an actively exploited WinSock zero-day, a critical LoadMaster bug with a BOD 26-04 deadline, and a well-argued case that severity checklists are the wrong instrument for a four-hour time-to-exploit world.
Article Source Published
5. Microsoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-days BleepingComputer Aug 11, 2026
6. The Patch Gap: Why Defenders Need to Think in Chains, Not Checklists Dark Reading Aug 10, 2026
7. Progress LoadMaster bug added to CISA list of exploited vulnerabilities SC Media Aug 10, 2026
8. Wireshark 4.6.8 patches 28 security bugs, nine in file parsers Help Net Security Aug 13, 2026

The CVE and NVD pipeline under AI-pace strain

The intake process every SOC vulnerability workflow quietly depends on is being asked to absorb machine-scale discovery with human-scale staffing — and both CISA and Microsoft said so out loud this week.
Article Source Published
9. CVE Program eyes automation and globalization to weather AI ‘vulnpocalypse’ Cybersecurity Dive Aug 11, 2026
10. Microsoft wants you to rethink your approach to cyber defense CSO Online Aug 13, 2026

MDR, MXDR, and what AI actually changes

Three managed-detection announcements in one week, each making a different claim about where AI belongs in the service — AI-native from the ground up, AI as a new attack surface to monitor, or AI as triage assistance bolted onto a response workflow.
Article Source Published
11. TENEX.ai CEO: Legacy MDR is ‘a people business dressed up as technology’ MSSP Alert Aug 13, 2026
12. Expel expands MDR coverage across the AI attack surface MSSP Alert Aug 11, 2026
13. ArmorPoint expands security operations platform for MSPs and MSSPs MSSP Alert Aug 13, 2026

Exposure management and AI in the detection stack

Preemptive exposure management, runtime CNAPP agents built on Falco telemetry, and a $60 million seed round for a defensive foundation model — three bets that prioritization, not collection, is the binding constraint.
Article Source Published
14. Searchlight Cyber combines exposure and threat intelligence in new PTEM platform Help Net Security Aug 13, 2026
15. Sysdig AI CNAPP Agents identify threats and surface remediation recommendations Security Boulevard Aug 14, 2026
16. Corma Raises $60 Million for Defensive Cybersecurity AI Model SecurityWeek Aug 11, 2026

EDR turned against the defender

A DEF CON technique that weaponizes a PPL-protected EDR helper service, a market of 24 vendors selling EDR evasion as a subscription, and a practical guide to spotting compromise in the AI accounts your staff now log into daily.
Article Source Published
17. New Bring Your Own EDR Attack Turns SentinelOne Into Trojan Horse GBHackers Aug 14, 2026
18. 24 Malware Crypter Sellers Turn EDR Evasion Into Paid Services GBHackers Aug 14, 2026
19. How to tell if your AI platforms’ accounts have been hacked TechCrunch Aug 15, 2026

DDoS at record scale

Cloudflare’s H1 2026 numbers and The Register’s read of them: terabit-class attacks are no longer exceptional, and the most-targeted sector this half was media and publishing.
Article Source Published
20. DDoS attacks hit record scale as 1 Tbps+ campaigns become more common Help Net Security Aug 13, 2026
21. Two wars and a World Cup lead to epic DDoS attacks on publishers The Register Aug 11, 2026

Foundational Reading

Vulnerability management and the service-model taxonomy

Two longer reads that sit underneath this week’s news: whether patching still works as a primary control, and what the MSP/MSSP/MDR/MXDR labels are actually selling you.
Article Source Published
22. Is Patching Dead? Vulnerability Management in the Post-Mythos Era SecurityWeek Jul 23, 2026
23. MSP, MSSP, MDR or MXDR: What are you really buying? MSSP Alert Aug 12, 2026

Security culture and the research pipeline

A security-culture playbook that survived a leadership handover, and a look at how the field’s flagship academic conference is coping with an AI-era submission flood.
Article Source Published
24. From Bobmojis to Bobbleheads: How the Democratic Party Built a Security-First Culture Dark Reading Aug 6, 2026
25. How the famed USENIX Security conf is managing a flood of papers in the AI era The Register Aug 7, 2026

Detailed write-ups

1. Walmart and Standard Chartered describe what SOC transformation actually costs

Dark Reading · August 12–14, 2026

Jason O’Dell, Walmart’s global VP of security operations for the past seven years, described to Dark Reading a shift away from a fear-based security function toward an enablement model: instead of answering business requests with “no,” his teams answer with “yes, and” followed by a secure path to the outcome the business wanted. The supporting machinery is deliberately unglamorous. A “Know Your Business Day” program puts security leadership in front of operating teams across a company with more than $700 billion in annual revenue and over two million employees in 19 countries. Executive risk communication is compressed into color-coded one-page summaries showing existing controls, planned defensive measures, and the gaps that remain. And every proposed control gets mapped on a quadrant of security value against operational friction, explicitly to kill the high-drag, low-value controls that teach staff to route around security entirely. Omdia’s Rik Turner and the Information Security Forum’s Steve Durbin supplied the outside view, with Verizon’s 2026 report counting 806 retail data breaches in its sample as the backdrop.

The companion piece covers the same team’s purple-teaming model, which Walmart runs on a “trusted agent” basis: red and blue are colocated rather than adversarial, and blue-team analysts observe attacks in real time, watching telemetry and detections fire while red operates. Scoring is deliberately de-emphasized in favor of shared learning — O’Dell’s framing is that the environment has to feel safe enough for people to ask whether the exercise drove value for the organization, not who won. Standard Chartered group CISO Cezary Piekarski made a structurally similar argument for a global bank in a third Dark Reading piece: shared mission over headcount, “productive worry” channeled into structured mitigation rather than reactive noise-chasing, and CISOs who are business-literate, technically current, and cultural influencers in that order. His forward-looking line — that security professionals are becoming “curators of sophisticated protective systems” as AI reshapes the work — is the connective tissue between this cluster and the vendor arguments further down this issue.

What makes these three worth reading together is that none of the changes described are purchasable. Colocating red and blue, killing friction-heavy controls, getting executives to accept a one-pager with a genuinely red section on it — those are organizational decisions that determine whether any of the tooling in the rest of this bulletin produces an outcome. Help Net Security’s interview with BlackBerry chief security advisor Christine Gadsby is the negative image of the same lesson: the four investigation mistakes she names — treating an investigation as a technical rather than a business problem, losing track of where sensitive conversations are happening, guessing wrong about who is actually receiving information, and limiting chain of custody to devices and logs while leaving findings, interviews, and executive communications undocumented — are all failures of operating model under pressure, not failures of tooling.

Sources: Dark Reading (Walmart SOC transformation) · Dark Reading (trusted-agent purple teaming) · Dark Reading (Standard Chartered) · Help Net Security (investigation mistakes)

2. 400 flaws, a Lazarus zero-day, and a three-day KEV clock

BleepingComputer · SC Media · Help Net Security · August 10–13, 2026

Microsoft’s August 2026 Patch Tuesday addressed 400 vulnerabilities — below July’s 570 but still a volume no SOC absorbs casually — with 42 rated Critical (37 remote code execution, five elevation of privilege). By class the release skews heavily toward privilege escalation: 176 elevation of privilege, 110 RCE, 86 information disclosure, 21 spoofing, 12 denial of service, and 11 security feature bypass. Three zero-days shipped. CVE-2026-68820, a use-after-free in the Windows Ancillary Function Driver for WinSock allowing local privilege escalation, is under active exploitation — North Korea’s Lazarus group used it to deploy the FudModule rootkit against defense firms, with Check Point’s Moshe Marelus and David Driker credited. CVE-2026-62832 (Windows User Profile Service, improper link resolution to admin) and CVE-2026-72971 (Windows Container Isolation FS Filter Driver, registry hive tampering) were both publicly disclosed before the fix. Microsoft itself attributed the sustained patch volume to AI-powered vulnerability discovery now running across its product portfolio — the vendor is finding them faster than the release cadence was designed to absorb.

The sharper operational deadline came from CISA. Progress LoadMaster carries CVE-2026-8037, a CVSS 9.6 unauthenticated command injection stemming from unsanitized input across multiple command endpoints, and it was added to the Known Exploited Vulnerabilities catalog with a three-day remediation deadline under BOD 26-04. The exposure is meaningful: LoadMaster is deployed in more than 100,000 installations and reportedly used by 80% of the Fortune 500, and load balancers sit at the perimeter holding private keys and trusted connections into internal networks. Notably, a vendor patch has existed since June 2026 — the hard part was never patch availability but knowing which devices are actually internet-exposed and getting compensating controls (management interface restrictions, focused monitoring on edge devices) in place inside a 72-hour window. Wireshark 4.6.8 rounded out the week with 28 fixes, nine of them in file parsers including pcapng, Endace ERF, and Tektronix K12xx — a reminder that the analyst workstation is itself an attack surface, since a malicious capture file requires no network access to reach it.

Dark Reading’s patch-gap piece, by EXL security analyst Shubham Paikrao, supplies the argument these three stories imply. Time-to-exploit has collapsed from 771 days in 2018 to roughly four hours in 2024, while average remediation still runs past 60 days — a 12-to-1 gap in the attacker’s favor. CVSS-based ranking handles vulnerabilities in isolation and misses that 28% of exploited flaws carried only medium scores; FIRST executive director Chris Gibson is quoted saying that teams prioritizing on base scores alone are “the least apt and accurate.” The proposed alternative is choke-point patching: find the fixes that break the largest number of attack paths to genuinely critical assets, and take those first even when a higher-scored CVE is sitting unaddressed elsewhere in the queue. For a SOC facing 400 Microsoft patches and a 72-hour federal clock in the same week, that is not a philosophical preference — it is the only triage model that fits the time available.

Sources: BleepingComputer (August Patch Tuesday) · SC Media (LoadMaster KEV) · Help Net Security (Wireshark 4.6.8) · Dark Reading (chains, not checklists)

3. The CVE pipeline meets AI-pace discovery

Cybersecurity Dive · CSO Online · August 11–13, 2026

At Black Hat and DEF CON, the people who run the CVE Program spent part of the week arguing about a word and the rest conceding the condition behind it. Some board members wanted “vulnpocalypse” retired as inaccurate and unhelpful; others pointed out that product security teams are, in fact, overwhelmed. Microsoft’s Elizabeth Eigner gave the cleanest formulation of the mismatch: “These are coming out at an AI pace, but we’re still creating them at a human scale.” Her colleague Lisa Olson described the influx as the new normal rather than a spike. GitHub’s Madison Ficorilli called the platform’s 7,000-plus CVE identifiers published in 2026 “an alarming metric.” CISA’s Lindsey Cerkovnik, whose vulnerability response team juggles 360 to 400 concurrent cases, struck the optimistic note — “CVE is going to continue to flourish and improve” — while Intel board member Katie Noble was openly skeptical that the program can manage current volumes at all.

The program’s answer is automation of triage plus globalization: more than 530 CNAs now, ENISA’s Nuno Rodrigues Carvalho positioning the EU Vulnerability Database as complementary rather than competing, and — the genuinely novel move — temporary CNA status granted to OpenAI and Anthropic so that model-discovered vulnerabilities can be assigned identifiers by the labs finding them. That is the pipeline adapting to its largest new source of submissions by deputizing it. It comes barely a year after the program nearly lost its MITRE contract in April 2025, a scare that concentrated minds on what a 27-year-old identifier system with a single funding dependency actually is: shared infrastructure that every SOC vulnerability workflow, scanner, and ticket queue silently assumes will keep working.

Microsoft used the same week to argue that the whole reactive posture is the wrong bet. In CSO Online, Windows group manager David Weston reported that MSRC is processing vulnerabilities at nine times the volume it saw in March, that Microsoft’s MDASH tool alone surfaced roughly 200 Linux kernel vulnerabilities with 182 of them producing automatic crash-level proofs of concept, and that AI-generated exploits in their testing averaged $3.61 in compute and 21 minutes to produce. His conclusion — “hand-to-hand combat with attackers will cause us to lose in defense” — points at deterministic prevention: memory-safe languages, given that roughly 70% of patched vulnerabilities trace to memory safety issues and Google cut Android memory-safety flaws from 76% in 2019 to under 20% in 2025 using Rust. Arizona State’s Yan Shoshitaishvili provides the academic counterweight. For a SOC lead, the practical read is that the CVE feed is going to get noisier and less complete as a prioritization signal at exactly the moment your vulnerability program most needs it to be authoritative — which is the same conclusion this week’s foundational SecurityWeek piece reaches from the patching side.

Sources: Cybersecurity Dive (CVE Program) · CSO Online (Microsoft on rethinking defense) · SecurityWeek (post-Mythos vulnerability management)

4. The MDR market argues in public about what AI actually changes

MSSP Alert · August 11–13, 2026

TENEX.ai CEO Eric Foster opened the week with the sharpest line in the segment, calling legacy MDR “a people business dressed up as technology” — his argument being that incumbent providers layered automation onto fundamentally people-dependent operations rather than delivering the software-driven security operations the category originally promised. TENEX claims to investigate 100% of alerts with Tier 1 triage completed in under a minute, go-live in as little as seven days for organizations already on Google SecOps or Microsoft Sentinel, and 18 months of production customer deployment behind it. Foster’s framing of the reliability bar is worth quoting because it will come up in every autonomous-SOC procurement conversation this year: “Perfect isn’t the benchmark. The benchmark is, is it better than a human driver?” He also argues, somewhat against his own AI-native thesis, that TENEX’s managed services heritage is an advantage over pure AI-native competitors — which concedes that the people part still matters.

Expel took a different position: rather than arguing about how the service is delivered, it extended what the service covers. Its expansion targets three distinct fronts of AI risk — attacks launched with AI, employee misuse of AI tools, and exposure inside the AI systems an organization builds and runs itself — with a live Claude Enterprise integration pulling usage activity, prompt content, and tool use, and detections mapped to 13 of MITRE ATLAS’s 16 tactics plus AI-focused hunting techniques. Principal product marketing manager Sarah Crone defined “full” coverage as all three fronts; VP of global channel sales Alex Glass held the line on staffing model with “our approach has always kept humans in the loop. The question is not whether AI belongs in the SOC. It does.” ArmorPoint, meanwhile, aimed at the MSP and MSSP channel with incident response, risk management, and compliance additions — AI-assisted alert triage, a Response Center, and a Governance Hub for multi-customer compliance reporting — behind CEO David Trapp’s line that “security without response is just surveillance.”

Three vendors, three incompatible claims about where AI belongs: replacing the analyst tier, extending the monitored surface, or assisting the triage queue. This week’s foundational piece by Corsica Technologies CISO Ross Filipek is the right corrective, because it points out that the labels themselves have stopped discriminating — MDR marketed as broad coverage while only ingesting endpoint telemetry is a live problem, and roughly a third of organizations lack the budget to staff a team capable of catching the discrepancy during evaluation. His three questions cut through the AI framing entirely: what telemetry is actually monitored, how are alerts investigated and correlated, and what can the provider execute immediately versus what requires your approval. Apply those to all three of this week’s announcements and the differences become legible in a way the press releases do not make them.

Sources: MSSP Alert (TENEX.ai) · MSSP Alert (Expel) · MSSP Alert (ArmorPoint) · MSSP Alert (MSP, MSSP, MDR or MXDR)

5. EDR as the attack surface: bring-your-own-EDR and evasion-as-a-subscription

GBHackers · August 14, 2026

Akamai researchers presented a “bring your own EDR” technique at DEF CON 34 that inverts the usual EDR-tampering story. Rather than disabling the agent, the attack uses it: SentinelOne’s SentinelHelper COM interface exposes a diagnostic Dump method that, absent sufficient caller-path validation, can be induced to produce memory dumps of arbitrary processes. Because the helper service runs as a Protected Process Light, this effectively borrows the EDR’s own PPL standing to reach into processes that Windows is supposed to keep off-limits — the researchers demonstrated executing unsigned code inside heavily protected processes including Microsoft Defender’s MsMpEng.exe, using position-independent payloads to get around execution constraints. SentinelOne addressed the issue in Agent version 26.1.1.

The second GBHackers piece maps the commercial layer of the same problem. Drawing on Insikt Group research, it profiles 24 active underground vendors selling malware crypting as a subscription product: payload obfuscation, in-memory execution, reflective loading, process hollowing, API unhooking, syscall-based execution, manual PE mapping, DLL sideloading, and anti-VM/anti-debugger checks, packaged with tiered pricing. The economics are instructive. A shared stub is cheaper but exposes every customer using it to the same detectable wrapper; a private stub costs more and comes with faster re-encryption support when signatures catch up. One vendor, mrlapis, sells “VIP Crypt” with automated re-encryption and file delivery infrastructure; ASMCrypt advertises configurable anti-VM checks, system profiling, attempted Windows Defender exclusions, and signed-application abuse. This is a supply chain with product tiers and customer support, not a hobbyist scene.

Taken together the two stories argue that the endpoint agent should be treated as an asset with its own threat model rather than as the thing that does the threat modeling. Concretely: check your SentinelOne agent version against 26.1.1 and confirm the fleet actually rolled, then ask what telemetry you have that would reveal a legitimate security binary being driven to dump a protected process — because that activity will look, to most detection logic, exactly like your EDR doing its job. On the evasion side, an active market in automated re-encryption means signature-based confidence has a short and shrinking shelf life; behavioral and, ideally, deterministic controls are where the durable coverage is. TechCrunch’s guide to spotting compromise in AI platform accounts — check active sessions in ChatGPT, Claude, and Perplexity, review and revoke logged-in devices, enforce MFA and unique credentials — belongs in the same conversation and is worth passing to staff verbatim, given that Claude uses email login links rather than passwords and therefore behaves differently from what most account-hygiene guidance assumes.

Sources: GBHackers (bring your own EDR) · GBHackers (24 crypter sellers) · TechCrunch (AI account compromise)

6. 805 terabit-class DDoS attacks in a quarter, and publishers take the brunt

Help Net Security · The Register · August 11–13, 2026

Cloudflare’s H1 2026 DDoS report puts hard numbers on a trend that has been directional for years: 805 network-layer attacks exceeded 1 Tbps in Q2 alone, a 519% increase over Q1. April was the peak month at 6.46 trillion requests and 165 petabytes of mitigated traffic. The distribution remains heavily skewed — 96.62% of network-layer attacks stayed under 500 Mbps and 90.6% finished inside ten minutes — which is the part defenders most often misread. A 100 Mbps burst is enough to take an unprotected site down and a 1 Gbps attack can disrupt a datacenter, so the long tail of small, short attacks is where most operational pain actually lands, while the terabit headline events set the ceiling your provider contract needs to cover. On vectors, DNS floods and DNS amplification accounted for 34.3% of network-layer attacks, and CLDAP floods jumped 580% quarter over quarter. China (22.4%) and the United States (18.8%) were the most-targeted locations for mitigated HTTP DDoS requests in Q2, with Turkey rising ahead of the NATO Summit; Brazil led attack sources at 14.9% overall and 21.4% in Q2.

The Register’s read focuses on who is being hit and why. Media, production and publishing absorbed 14.2% of HTTP DDoS requests in H1 — roughly four times the share aimed at gambling and casinos — and the motivation is timing rather than extortion. Cloudflare analysts put it plainly: taking an outlet offline for two hours during an election night, a military conflict, or a breaking news story silences it at peak readership. Blake Darché, head of Cloudforce One, notes that attacks on media organizations pursue goals that differ fundamentally from attacks on other sectors. The drivers this half were the Ukraine–Russia conflict, the US–Iran war that began in February 2026, and the FIFA World Cup, with government targets accounting for 47.8% during Operation Epic Fury. Akamai separately measured a 245% uplift in cybercrime following the Iran war’s outbreak, DDoS specifically up 38%, with hacktivist groups coordinating openly on social media.

For a SOC, this reframes DDoS readiness as a calendar problem rather than a capacity problem. The attacks cluster around scheduled, high-attention events — a match, a summit, an election, a verdict — which means the useful preparation is knowing which of your properties matter most on which dates and pre-staging mitigation and on-call around them. If your organization publishes, broadcasts, or otherwise depends on being reachable at a specific hour, that hour is the threat model. And the CLDAP surge is a reminder to check your own edge for reflectors: some of these attacks are being amplified through infrastructure that belongs to organizations who have no idea they are participating.

Sources: Help Net Security (Cloudflare H1 2026 DDoS) · The Register (DDoS on publishers)

Calls to action

Five things worth doing in the next week, drawn directly from this issue:

  • Verify the LoadMaster clock. CVE-2026-8037 (CVSS 9.6) has been in CISA’s KEV catalog with a three-day BOD 26-04 deadline since August 7, and the vendor patch has existed since June. Confirm which LoadMaster instances you own, which are internet-reachable, and whether the management interface is restricted — the patch being available is not the same as the fleet being covered.
  • Confirm your SentinelOne fleet is on Agent 26.1.1 or later. The Akamai bring-your-own-EDR technique abuses a PPL-protected helper service, so a partially rolled update leaves a privileged primitive live on the stragglers. While you are there, write a detection for your security agent being driven to dump another protected process.
  • Triage August’s Patch Tuesday by chain, not by score. CVE-2026-68820 is actively exploited by Lazarus for FudModule deployment and should move first regardless of ranking. Beyond that, use the choke-point logic from the Dark Reading patch-gap piece — 400 fixes will not clear in a sprint, and 28% of exploited vulnerabilities historically carried only medium CVSS scores.
  • Re-evaluate your MDR contract against three questions, not the acronym. Which telemetry is actually ingested, who investigates and correlates it, and what can the provider act on without your approval. If AI coverage of your own AI systems matters to you, ask specifically about ATLAS-mapped detections and which model providers are integrated today rather than on a roadmap.
  • Patch analyst workstations, not just servers. Nine of Wireshark 4.6.8’s 28 fixes are in file parsers, which are reachable by handing an analyst a capture file — no network access required. The 5G field-decoding corrections in the same release matter too, since silently wrong decode output is worse than a crash.

On our watch list

  • Whether AI-pace CVE intake degrades the feed as a prioritization signal. With OpenAI and Anthropic granted temporary CNA status, GitHub past 7,000 IDs this year, and CISA carrying 360–400 concurrent cases, watching whether triage automation preserves enrichment quality or whether SOCs quietly start treating CVE records as raw intake rather than a prioritized queue.
  • Microsoft’s prevention-over-detection argument meeting a detection-funded market. David Weston’s memory-safety case is directionally hard to argue with, but 9x MSRC volume and $3.61 AI-generated exploits describe a present that no SOC gets to skip. Watching whether “deterministic prevention” shows up in product roadmaps or stays a keynote position.
  • Whether TENEX’s “better than a human driver” benchmark gets independently tested. 100% alert investigation and sub-minute Tier 1 triage are checkable claims. Watching for a customer reference or third-party evaluation rather than another round of vendor framing.
  • Expel’s AI-attack-surface coverage past the first integration. Claude Enterprise is live and 13 of 16 ATLAS tactics are mapped; watching how fast additional model providers land, and whether competitors follow into monitoring customer-built AI systems as a standard MDR inclusion rather than a premium tier.
  • EDR self-protection as its own audited control. The SentinelOne fix is out, but the class of bug — a privileged helper interface with insufficient caller validation — is not vendor-specific. Watching for similar disclosures against other PPL-registered agents, and whether buyers start asking about it in evaluations.
  • Crypter subscriptions with automated re-encryption. Twenty-four vendors selling tiered EDR evasion with re-encryption on demand means signature confidence decays continuously. Watching whether detection vendors publish anything measurable about resilience against commercially crypted payloads.
  • Terabit DDoS around scheduled events. 805 attacks above 1 Tbps in one quarter and a 519% quarter-over-quarter jump, concentrated on media during wars and the World Cup. Watching Q3 data for whether the growth curve holds and whether the CLDAP reflection surge (up 580%) pulls in enterprise edge infrastructure as unwitting amplifiers.
  • Whether the practitioner playbooks survive contact with budget season. Walmart’s friction-versus-value quadrant, Standard Chartered’s mission framing, and the DNC’s culture work all depend on executive backing that is cheap to give in an interview and expensive to sustain. Watching whether any of it is still described the same way a year out.

Security Operations Weekly

A weekly intelligence bulletin from Security Radar LLC.
Curated by Paul Davis · paul.davis@security-radar.com

© 2026 Security Radar LLC. All rights reserved.

Article titles and summaries are excerpted for review and commentary; all linked articles remain the copyright of their respective publishers and authors.

*|LIST:ADDRESS|*

View this email in your browser · Unsubscribe

Recent Posts

  • AI & Machine Learning Security — August 23, 2026 — Interactive Topic Map
  • Agentic NetOps — August 23, 2026
  • Agentic NetOps — August 23, 2026 — Interactive Topic Map
  • Security Operations Weekly — August 23, 2026
  • Security Operations Weekly — August 23, 2026 — Interactive Topic Map

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • November 2025
  • April 2024
  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • April 2023
  • March 2023
  • February 2022
  • January 2022
  • December 2021
  • September 2020
  • October 2019
  • August 2019
  • July 2019
  • December 2018
  • April 2018
  • December 2016
  • September 2016
  • August 2016
  • July 2016
  • April 2015
  • March 2015
  • August 2014
  • March 2014
  • August 2013
  • July 2013
  • June 2013
  • May 2013
  • April 2013
  • March 2013
  • February 2013
  • January 2013
  • October 2012
  • September 2012
  • August 2012
  • February 2012
  • October 2011
  • August 2011
  • June 2011
  • May 2011
  • April 2011
  • February 2011
  • January 2011
  • December 2010
  • November 2010
  • October 2010
  • August 2010
  • July 2010
  • June 2010
  • May 2010
  • April 2010
  • March 2010
  • February 2010
  • January 2010
  • December 2009
  • November 2009
  • October 2009
  • September 2009
  • June 2009
  • May 2009
  • March 2009
  • February 2009
  • January 2009
  • December 2008
  • November 2008
  • October 2008
  • September 2008
  • August 2008
  • July 2008
  • June 2008
  • May 2008
  • April 2008
  • March 2008
  • February 2008
  • January 2008
  • December 2007
  • November 2007
  • October 2007
  • September 2007
  • August 2007
  • July 2007
  • June 2007
  • May 2007
  • April 2007
  • March 2007
  • February 2007
  • January 2007
  • December 2006
  • November 2006
  • October 2006
  • September 2006
  • August 2006
  • July 2006
  • June 2006
  • May 2006
  • April 2006
  • March 2006
  • February 2006
  • January 2006
  • December 2005
  • November 2005
  • October 2005
  • September 2005
  • August 2005
  • July 2005
  • June 2005
  • May 2005
  • April 2005
  • March 2005
  • February 2005
  • January 2005
  • December 2004
  • November 2004
  • October 2004
  • September 2004
  • August 2004
  • July 2004
  • June 2004
  • May 2004
  • April 2004
  • March 2004
  • February 2004
  • January 2004
  • December 2003
  • November 2003
  • October 2003
  • September 2003

Categories

  • AI-ML
  • AI-Ops
  • Augment / Virtual Reality
  • Blogging
  • Cloud
  • Competitive
  • DR/Crisis Response/Crisis Management
  • Editorial
  • Financial
  • IT/OT Security
  • Make You Smile
  • Malware
  • Mobility
  • Motor Industry
  • News
  • OTT Video
  • Pending Review
  • Personal
  • Product
  • Regulations
  • Secure
  • Security Industry News
  • Security Operations
  • Statistics
  • Threat Intel
  • Trends
  • Uncategorized
  • Warnings
  • WebSite News
  • Zero Trust

Meta

  • Log in
  • Entries feed
  • Comments feed
  • WordPress.org
© 2026 CyberSecurity Institute | Powered by Superbs Personal Blog theme