Cyber News Bytes: Critical Mac Exploit, North Korea IT Hacker, & More

This week's latest cybersecurity news and industry updates

This was a week where the threats got more autonomous and the entry points got more human.

An AI agent swarm ran an intrusion nearly on its own, a maximum severity bug got exploited within days of the patch, a basic Mac setting became a live attack surface, and a hiring process let a sanctioned operative walk right through the front door.

Leveling up your practical skills is what separates candidates who can talk about security from candidates who can actually do it.

My 5 Technical Cybersecurity Projects course walks you through five real, resume ready technical projects, perfect if you are breaking in or leveling up and want something concrete to show instead of just telling.

This week's stories are a great reminder of why hands on skills matter more than ever.

Now, four stories worth your time.

1. Suspected Chinese hackers ran the first known "near autonomous" AI attack on a government

Israeli cybersecurity firm Dream uncovered a 160MB archive of 1,395 files revealing an autonomous AI hacking framework built entirely from two free, open source tools, Hermes and OpenClaw. Between July 1 and July 4, the system deployed up to eight AI sub-agents in parallel across 12 attack waves, mapping 21 connected government systems and compromising 85 accounts. The agents exfiltrated more than 2,564 personnel records along with SSO client secrets and internal database credentials, then expanded into Taiwan's nuclear safety agency and at least seven energy companies.

The hackers bypassed the AI frameworks' built in safety guardrails by framing the entire operation as authorized penetration testing. The system ran at a pace and breadth that would strain a human red team, researching new techniques and re-prioritizing attack paths whenever one route failed. Taiwan's Ministry of Digital Affairs confirmed the attack on August 13.

Why it matters: This was not a lab accident like the recent OpenAI, Anthropic, and Meta disclosures. Someone deliberately weaponized free AI agent tools into a functioning cyberweapon capable of running a real intrusion largely on its own. The barrier to running a sophisticated, multi-stage attack just dropped dramatically, and defenders need to start planning for adversaries that move and adapt at machine speed.

Read more at The Register

2. A maximum severity SAP flaw is already under attack, just days after the patch dropped

CVE-2026-58231, rated a perfect 10.0 on the CVSS scale, affects the Data Hub Adapter extension in SAP Commerce Cloud and lets unauthenticated attackers run arbitrary code with no user interaction required. The vulnerability lets adversaries execute code remotely without needing any existing privileges, and because SAP Commerce Cloud powers major online storefronts and supply chain operations, a successful hit could hand attackers full control of backend databases and transaction pipelines.

Threat intelligence firm Defused confirmed exploitation attempts hitting its honeypots just three days after SAP's August patch day. Shadowserver is tracking more than 4,200 internet exposed systems carrying a SAP Commerce Cloud fingerprint, most in Europe and North America.

Why it matters: A perfect 10 severity score on an unauthenticated remote code execution bug is about as bad as it gets, and attackers moved almost immediately. If your organization runs SAP Commerce Cloud, this is a patch today situation, not a patch this sprint situation.

Read more at BleepingComputer

3. Every Mac with Screen Sharing exposed to the internet is being actively targeted

The Dutch National Cyber Security Centre confirmed active exploitation of CVE-2026-65400, a critical macOS authentication flaw carrying a CVSS score of 9.8, in the built in Screen Sharing feature that ships on every Mac. The bug lets an attacker on the network authenticate without valid credentials at all, and in every confirmed case researchers observed, the attacker reached root access and planted a Monero cryptocurrency miner.

Standard hardening steps like rotating VNC passwords or removing approved users have zero effect on this flaw, since the vulnerability sits upstream of that authentication path entirely. Apple patched the issue on August 6 across macOS Tahoe, Sequoia, and Sonoma, and anyone who cannot update immediately can disable Screen Sharing under General, then Sharing.

Why it matters: This is about as close to a "check your own settings right now" story as it gets. If you or anyone you support has Screen Sharing turned on and exposed to the internet, that machine is a live target today, not hypothetically.

Read more at Security Affairs

4. The FBI confirms a North Korean IT worker was secretly employed at a US federal agency

The FBI is investigating how a North Korean national secured remote employment with a US federal agency, marking a rare confirmed instance of a sanctioned North Korean operative working inside a government organization rather than a private company. The disclosure came from a senior FBI Cyber Capabilities Branch official during a July 28 conference, and the case is part of a wider, years long campaign in which North Korean workers use false identities to land remote IT jobs.

CrowdStrike reports the North Korea linked group it tracks as Famous Chollima accounted for 47 percent of all state backed hands on keyboard intrusions against the technology sector over the past year. Officials say these workers pose a genuine insider threat, engaging in data exfiltration and theft of sensitive information while funneling wages back to fund North Korea's weapons programs.

Why it matters: This is a hiring and vetting problem as much as a technical one, and it should matter to anyone in cybersecurity hiring, remote IT, or contracting. If a sanctioned foreign operative can pass a federal agency's screening process, private sector background checks need a serious second look too.

Read more at TechCrunch

Four stories, one thread running through all of them: the gap between having the right controls on paper and actually testing whether they hold up in practice.

None of these needed a genius attacker, they needed a defender who never got around to verifying the basics.

Stay secure out there!

- Sandra [Cyber With Sandra]