☀️ Good morning. Here's everything that happened in cybersecurity yesterday — in under 5 minutes.

Yesterday was a policy earthquake. The White House authorized vetted private firms to "hack back" at foreign cybercrime gangs — the first time the US has licensed the private sector for offensive operations — while Germany's cabinet cleared its biggest spy-law overhaul since the war, letting its agencies hack, sabotage, and spread disinformation. On the threat side, Dream confirmed the government target of its "near-autonomous" AI attack was Taiwan's nuclear safety agency, and two freshly patched flaws — VMware vCenter and SharePoint — moved into active exploitation. Fortinet, meanwhile, patched authentication bugs that let attackers log in with random credentials or impersonate a FortiGate. Here's what matters.

🔥 Top Stories

01 — Trump Memo Authorizes Private Firms to 'Hack Back' at Foreign Cybercrime Gangs

Policy & Government

President Trump signed a National Security Presidential Memorandum on August 12 that, for the first time, lets vetted private companies run offensive cyber operations against foreign threat actors — surveilling and disrupting criminal networks abroad under government control and oversight. Participating firms may have to post a $1 million bond, forfeited if they break the operational rules. It sweeps away decades of US policy that barred the private sector from "hack back" and offensive operations.

The move is genuinely consequential and genuinely contested. Supporters see scalable pressure on ransomware and fraud crews that have outrun law enforcement; critics warn about escalation, misattribution, and private actors operating in a legal gray zone abroad. Either way, expect a scramble among incident-response and offensive-security vendors to qualify — and expect adversaries to cite it as justification for their own escalation.

02 — Dream Confirms the Taiwan 'Near-Autonomous' AI Target Was a Nuclear Safety Agency

Artificial Intelligence / Nation-State

In a follow-on to its earlier disclosure, Israeli firm Dream — via reporting from The Register — confirmed that the government target hit by its documented near-autonomous agentic swarm was Taiwan's nuclear safety agency. That makes it the highest-stakes autonomous-agent target on public record, even though the attack's ultimate success remains unconfirmed. The framework reportedly adapted mid-operation and expanded scope on its own.

The specificity matters: an AI-driven intrusion aimed at a nuclear regulator moves the autonomous-attack conversation from abstract risk to critical-infrastructure reality. Defenders of high-consequence OT and regulatory environments should assume agentic reconnaissance is now in play and prioritize segmentation, identity hardening, and behavioral detection over signature-based controls that a self-correcting agent will simply route around.

03 — VMware vCenter and SharePoint Flaws Are Both Under Active Attack

Vulnerabilities / Patch Management

Two flaws tied to recent patch cycles are being exploited at once. VMware vCenter CVE-2026-59310 — a directory-traversal bug enabling remote code execution — fell just five days after Broadcom's disclosure, and researchers warn that patching alone may not fully evict an attacker who already gained persistent access. Microsoft SharePoint CVE-2026-55040, an authentication bypass, is being exploited after Rapid7 published proof-of-concept code. Neither is in CISA's KEV catalog yet.

The absence of a KEV listing is not a reason to wait. Prioritize internet-facing vCenter and SharePoint instances first: patch, then hunt for signs of prior compromise rather than assuming the update closed the door. vCenter's blast radius across virtualized estates makes it the more urgent of the two.

04 — Germany Approves Postwar Overhaul of Spy Laws, Clearing Agencies to Hack and Sabotage

Policy & Government / Nation-State

Germany's cabinet approved the biggest overhaul of the country's intelligence laws since the postwar era, clearing the BND and BfV to hack foreign systems, sabotage adversaries' supply chains, and — most controversially — feed false information to extremists inside Germany. The domestic-disinformation power is already drawing the sharpest objections from civil-liberties and legal experts.

Paired with the US hack-back memo the same week, it signals a broader Western pivot toward state-sanctioned offensive cyber and information operations. For multinationals, the practical takeaway is a more crowded and aggressive operating environment: more offensive activity from allied governments, more supply-chain targeting, and more legal complexity around where and how these powers apply.

05 — Fortinet Patches FortiWeb and FortiManager Auth Flaws Enabling Random Logins and FortiGate Impersonation

Vulnerabilities / Network Security

Fortinet patched high-severity authentication flaws in FortiWeb and FortiManager. One lets a remote attacker log in with random usernames and passwords; the other lets an attacker impersonate any FortiGate appliance managed by FortiManager — a foothold that could cascade across an entire managed fleet. No active exploitation has been reported yet.

That "not yet" is the window. Fortinet appliances sit at the network edge and have a long history of rapid post-disclosure targeting, so treat these as patch-now regardless of the current quiet. Update FortiWeb and FortiManager, review management-plane access, and watch for anomalous logins while you roll the fix out.

📊 By The Numbers

  • $1M — the bond private firms may have to post under Trump's hack-back memo, forfeited if they break the operational rules.

  • 421 — CVEs in Microsoft's August Patch Tuesday, the exploitation wave from which is still unfolding across vCenter, SharePoint, and more.

  • 5 days — time from Broadcom's disclosure of VMware vCenter CVE-2026-59310 to active exploitation in the wild.

  • 153 GB — stolen-credential archive surfaced from the LiteLLM supply-chain attack (433,909 files mapped to 2,488 corporate domains).

  • 1,500+ — UK charities exposed after a single leaked AWS access key at CRM provider Beacon.

⚡ The Signal

The dominant story yesterday wasn't a breach — it was governments rewriting the rules of who is allowed to attack. Washington licensed private firms to hack foreign criminals; Berlin cleared its agencies to hack, sabotage, and spread disinformation. Read together, these mark a Western shift from purely defensive posture toward state-sanctioned and state-adjacent offense, with the private sector pulled directly into the fight. That's a structural change, not a news cycle.

It lands at exactly the moment the technical ground is getting shakier. Dream's confirmation that a near-autonomous AI agent targeted a nuclear safety regulator, plus vCenter and SharePoint moving from patch to exploitation within days, shows attackers already compressing timelines faster than most defenders can patch. Adding more offensive actors — private contractors, emboldened intelligence services — to that environment raises the odds of collisions, misattribution, and blowback.

For defenders, the practical posture doesn't change so much as intensify: shrink patch windows on internet-facing infrastructure, assume exploitation precedes KEV listings, and harden identity and segmentation against agentic attackers. But the strategic backdrop just shifted under everyone's feet, and the legal and escalation questions these memos raise won't be answered on a patch cycle.

🔍 What You May Have Missed

📅 What to Watch

Stay sharp. Stay ahead.

Till next time,

The CyberSignal Team