Sylvaris

Active Exploitation Across Critical Systems

2026-W34 — week of 17 August 2026

Cover illustration for Canopy issue 2026-W34: Active Exploitation Across Critical Systems

Good morning. This week brings a clear signal: vulnerabilities aren't waiting to be exploited—they already are.

From a UK power plant forced offline for four days by Iranian hackers to critical flaws in Windows VPN infrastructure and Microsoft's identity platform under active attack, the pattern is consistent. Nation-state actors and opportunistic attackers alike are moving quickly. Even developer tooling—Ray framework, GitHub's repeated outages—faces pressure, while thousands of leaked AWS credentials from years past remain active and usable.

Two stories offer practical responses: Anthropic's security-focused AI model now available to defensive teams, and hard lessons in supply-chain integrity as car head units arrive pre-infected with proxy malware. Below you'll find the details.

Security · 3 min read

Iranian hackers shut down UK power plant for four days

Iranian hackers shut down UK power plant for four days

A successful four-day shutdown of critical energy infrastructure demonstrates that nation-state actors can now sustain operational disruption of power generation facilities.

Read the full story →
Security · 2 min read

Microsoft Entra ID maximum-severity vulnerability exploited in active attacks

The identity platform controlling access to millions of enterprise cloud resources has a confirmed exploited flaw with the highest possible severity rating.

Read the story →
Security · 3 min read

Windows IKE Extension critical RCE flaw now actively exploited

A critical remote code execution vulnerability in Windows VPN infrastructure is being actively exploited, affecting systems handling encrypted network connections.

Read the story →
Security · 2 min read

Ray framework vulnerability actively exploited through developer targeting

Federal agencies have three days to patch a critical remote code execution flaw in Ray, an AI/ML framework now targeted through phishing campaigns aimed at developers.

Read the story →
Security · 3 min read

Android car head units infected with proxy botnet malware through supply-chain attack

Compromised automotive update infrastructure delivers persistent malware to vehicle entertainment systems, turning cars into proxy network nodes or ad fraud platforms.

Read the story →
Security · 2 min read

Claude Mythos 5 cybersecurity capabilities expanded to security teams

Anthropic's specialized security model now available beyond initial government testing, marking expansion of AI tools designed for defensive cybersecurity work.

Read the story →
Security · 2 min read

TrueConf Server vulnerabilities exploited by Ukrainian hacktivists, CISA issues patch directive

Russian video conferencing platform used beyond Russia faces active exploitation, with US homeland security directing immediate patches.

Read the story →
Security · 3 min read

AWS access keys: 9,300 exposed credentials remain active four years after public leak

Thousands of AWS keys publicly leaked between 2022 and 2026 remain valid, giving anyone who finds them full control over corporate cloud accounts.

Read the story →
Security · 3 min read

Phishing kit adds rogue passkeys for persistent account access after credential theft

Attackers can now plant additional authentication credentials during phishing attacks, maintaining access even after victims change passwords or enable alerts.

Read the story →
Developer Tooling · 3 min read

GitHub pledges architectural overhaul after second August outage

Critical developer infrastructure experiencing repeated failures requires fundamental changes to prevent workflow disruptions affecting millions of users.

Read the story →

Read all stories on Canopy