Top stories.
- President Trump authorizes private-sector companies to hack cybercriminals.
- Trivy, not LiteLLM, was the original source of the 2,500-organization supply chain attack.
- Patch Tuesday notes: Microsoft fixes three zero-days.
- Researchers find that only a quarter of AI-generated patches are fully successful.
- Apple sends out threat notifications to users targeted by spyware.
President Trump authorizes private-sector companies to hack cybercriminals.
President Trump has signed a national security memorandum establishing a framework that allows private-sector companies to assist federal law enforcement in offensive hacking operations against transnational criminal organizations, CyberScoop reports. Under this directive, a federal coordination center will oversee “Participating Companies” as they conduct cyber surveillance and effects operations against these groups. The program requires strict vetting, adherence to existing laws such as the Computer Fraud and Abuse Act, and oversight to evaluate companies' technical proficiency. While some cyber experts welcome this as a significant shift in US cyber policy that stops short of full "hack back" authorization, others caution that it sets a risky precedent by expanding private sector involvement in offensive cybersecurity operations.
Trivy, not LiteLLM, was the original source of the 2,500-organization supply chain attack.
Researchers at SOCRadar say the supply chain attack that compromised over 2,500 organizations in March was primarily driven by a malicious build of Aqua Security's Trivy scanner rather than the LiteLLM package, as initially suspected. Data shows that 95% of the affected entities were exposed to the malware days before the poisoned LiteLLM packages were published. The Trivy attack is also attributed to the TeamPCP threat actor and led to the LiteLLM attack, but SOCRadar says the LiteLLM compromise “was the closing act, not the whole play.”
SOCRadar explains, “Attackers hijacked the trusted Trivy security scanner in LiteLLM’s build pipeline, used it to publish two poisoned LiteLLM releases to PyPI, then relied on a Python startup file to run a credential stealer on every host that installed them.”
Patch Tuesday notes: Microsoft fixes three zero-days.
Microsoft’s Patch Tuesday addressed a total of 421 vulnerabilities across its products, including Windows, Hyper-V, Microsoft Exchange Server, and Azure. Of these, 62 are rated critical and 357 are marked as important, with the most significant being three zero-day vulnerabilities. The zero-days include a tampering flaw in the Windows Container Isolation FS Filter Driver, an elevation of privilege bug in the Windows User Profile Service, and an actively exploited privilege escalation flaw in the Windows Ancillary Function Driver for WinSock. CISA has added the latter flaw to its Known Exploited Vulnerabilities Catalog, and ordered Federal agencies to apply patches by August 25th. Check Point has attributed the exploitation to North Korea’s Lazarus Group, in a campaign targeting the defense sector in Europe and India.
Adobe addressed 51 vulnerabilities across five of its products: Adobe ColdFusion, Adobe Commerce, Adobe Lightroom Classic, Content Credentials SDK, and Adobe Campaign Classic. Of these, 33 vulnerabilities are classified as critical.
SAP fixed 29 vulnerabilities, led by a maximum-severity flaw in SAP Commerce Cloud's Data Hub Adapter, CSO reports. This improper authorization issue allows unauthenticated remote attackers to submit crafted data, potentially leading to arbitrary code execution.
In the ICS space, Siemens, Schneider Electric, and Phoenix Contact released patches for various products, and CISA published advisories covering vulnerabilities in products from other vendors such as Pulsetto and Johnson Controls. Notably, Siemens issued a fix for a maximum-severity missing-authentication flaw in its Simatic IoT gateways, SecurityWeek notes.
Researchers find that only a quarter of AI-generated patches are fully successful.
Researchers at 1Password found that AI-generated security patches are still largely unreliable, CyberScoop reports. When ChatGPT 5.5 and Claude Opus 4.8 were tested against six recently disclosed vulnerabilities, generating over six thousand patches, only 26% of the patches fully fixed the vulnerability without introducing new problems or altering application behavior. More than half of the time, the AI did not fix the flaw or introduced new vulnerabilities in the process.
The researchers conclude that “human expertise still plays an essential role in the process of fully resolving vulnerabilities in software without introducing unwanted side effects.”
Apple sends out threat notifications to users targeted by spyware.
Apple yesterday sent out threat notifications to users in 110 countries, warning them that their devices may have been targeted by mercenary spyware often used by governments, TechCrunch reports. The alerts will now appear on device lock screens as well as being delivered to users' email addresses and showing up on their Apple account pages. Apple recommends that users who have been targeted or believe they may be targeted enable Lockdown Mode on their devices, an extreme protection that reduces the attack surface by limiting many of the device's functionalities. The company also advises targeted users to seek expert help, such as security assistance provided by the Digital Security Helpline at the nonprofit Access Now.