August Patch Tuesday delivered a materially different story than Monday's preview suggested: Lazarus Group deployed the FudModule kernel rootkit via an actively exploited WinSock zero-day, while VMware vCenter reached 361 victims in 47 countries within five days of disclosure.
The LAUNDRY BEAR Zimbra campaign reveals that MFA protects the authentication step but not the authenticated session, and email clients are a reliable path around that distinction.
Microsoft's July Patch Tuesday landed at 570 CVEs with two actively exploited zero-days, more than four times the forecasted volume, because AI code scanning is now generating vulnerabilities faster than the industry can triage them. Gold Eagle is the government's acknowledgment that the system is breaking.
The first confirmed autonomous LLM agent attack, a critical auth bypass in the Python framework underpinning most MCP infrastructure, and two AI platforms under active exploitation this week represent a structural shift: AI attack surface is not emerging, it is operational.