
Please hack responsibly.
President Trump deputizes private-sector companies to target cybercriminals. The LiteLLM supply-chain attack exposed credentials belonging to thousands of organizations. Data-theft campaign targets misconfigured Salesforce and ServiceNow instances. Hackers deploy AI agents to breach Taiwanese government systems. CISA mandates urgent patch for actively exploited Cisco firewall vulnerability. Nightmare Eclipse publishes yet another Windows zero-day exploit. On our Industry Voices segment, Clint Gibler, Cyber Lead at OpenAI, and Robby Winchester, Chief Global Professional Services Officer at SpecterOps, discuss frontier models and the future of cyber defense. And please do not reply. Seriously.
Today is Thursday August 13th, 2026. I’m Maria Varmazis. And this is your CyberWire Intel Briefing.
President Trump deputizes private-sector companies to target cybercriminals.
President Trump has signed a national security memorandum establishing a framework that allows private-sector companies to assist federal law enforcement in offensive hacking operations against transnational criminal organizations. Under this directive, a federal coordination center will oversee “Participating Companies” as they conduct cyber surveillance and effects operations against these groups. The program requires strict vetting, adherence to existing laws such as the Computer Fraud and Abuse Act, and oversight to evaluate companies' technical proficiency. While some cyber experts welcome this as a significant shift in US cyber policy that stops short of full "hack back" authorization, others caution that it sets a risky precedent by expanding private sector involvement in offensive cybersecurity operations.
The LiteLLM supply-chain attack exposed credentials belonging to thousands of organizations.
A supply-chain attack on open-source AI library LiteLLM exposed terabytes' worth of credentials and other secrets belonging to thousands of organizations. The incident took place in March 2026, when the TeamPCP criminal group inserted malicious code into the LiteLLM Python packages on PyPI, which were live for about 40 minutes. The full impact of the attack was unclear at the time, but researchers at CloudSEK and Hudson Rock have now obtained a copy of the data stolen during the attack. The researchers say the breach compromised over 434,000 CI/CD pipelines across nearly 2,500 organizations, including Microsoft, Amazon, Cisco, Samsung, and Salesforce. The exposed data includes active database passwords, API keys, SSH keys, cloud credentials, Kubernetes secrets, package publishing credentials, and more.
The researchers advise affected organizations to immediately audit their environments and rotate all accessible credentials, assuming they were exposed.
Data-theft campaign targets misconfigured Salesforce and ServiceNow instances.
An ongoing data-theft campaign dubbed City-Forum is targeting organizations worldwide by exploiting misconfigured Salesforce and ServiceNow portals. According to researchers at Reco, the attacks use custom tools to enumerate and steal exposed records without needing to exploit underlying software vulnerabilities. Reco explains, “the attacker reaches Salesforce Lightning Web Runtime sites through the UI-API, a data layer we have not seen any public tool or write-up about, and it hammers a native ServiceNow Service Portal search endpoint.”
The attacks have targeted telecoms, banks and financial firms, enterprise software vendors, and public-sector portals. Administrators are advised to review guest-user sharing rules, disable unnecessary public APIs, and enact strict authentication controls on search portals.
Hackers deploy AI agents to breach Taiwanese government systems.
Suspected China-linked hackers launched what researchers call a “near-autonomous” cyberattack targeting Taiwan. Using publicly available AI agents like Hermes and OpenClaw, the attackers built a platform that deployed up to eight agents simultaneously. Over four days, these agents mapped 21 government systems, researched vulnerabilities, and autonomously adapted their tactics when blocked. The attack successfully compromised at least 85 accounts, stole thousands of personnel records, and expanded to hit Taiwan's nuclear safety agency and at least seven energy companies.
CISA mandates urgent patch for actively exploited Cisco firewall vulnerability.
Cisco has issued patches for an actively exploited vulnerability affecting its Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense operating systems. The flaw, caused by improper error handling during HTTP request processing, allows unauthenticated, remote attackers to crash the firewalls by sending error-riddled requests, leading to denial-of-service.
The US Cybersecurity and Infrastructure Security Agency (CISA) has added the flaw to its Known Exploited Vulnerabilities catalog and ordered Federal agencies to apply fixes by tomorrow, August 14th.
Nightmare Eclipse publishes yet another Windows zero-day exploit.
In what’s become a monthly occurrence, Nightmare Eclipse, a disgruntled researcher with an apparent grudge against Microsoft, published a new Windows zero-day exploit hours after Microsoft released its Patch Tuesday updates. The exploit allows attackers to gain SYSTEM privileges on up-to-date Windows 10, Windows 11, and Windows Server systems. Security researcher Kevin Beaumont confirmed that the exploit works, and published detections and hunting queries to help organizations protect themselves until a patch is available.
Stick with us. After the break, Dave Bittner is joined at Black Hat by Clint Gibler of OpenAI and Robby Winchester of SpecterOps to explore frontier models and the future of cyber defense. And please do not reply. Seriously.
On our Industry Voices segment Dave Bittner talks with Clint Gibler, Cyber Lead at OpenAI, and Robby Winchester, Chief Global Professional Services Officer at SpecterOps, about frontier models and the future of cyber defense. Here's their conversation.
That was Clint Gibler, Cyber Lead at OpenAI, and Robby Winchester, Chief Global Professional Services Officer at SpecterOps discussing frontier models and the future of cyber defense. If you want to listen to the full conversation be sure to check out our Special Edition coming out this Sunday wherever you get your favorite podcasts.
Please do not reply. Seriously.
A report by WIRED details how two security researchers purchased inexpensive placeholder domains, such as noreply.net and deleteduser.com, and configured them to receive incoming emails. Doing so revealed a widespread data leakage problem: they began receiving hundreds of thousands of misdirected automated emails from various companies. The messages included sensitive internal communications, human resources documents, hotel bookings, corporate secrets, and confirmation of people’s pizza orders.
And that’s the CyberWire.
For links to all of today’s stories, check out our Daily Briefing at the cyberwire dot com.
We’d love to know what you think of this podcast. Your feedback ensures we deliver the insights that keep you a step ahead in the rapidly changing world of cybersecurity. If you like the show, please share a rating and review in your podcast app. Please also fill out the survey in the show notes or send an email to cyberwire@n2k.com
N2K’s lead producer is Liz Stokes. We’re mixed by Tré Hester, with original music by and sound design Elliott Peltzman. Our contributing host is Maria Varmazis. Our executive producer is Jennifer Eiben. Peter Kilpe is our publisher. And I’m Dave Bittner. Thanks for listening.
