14 Aug 2026
Week in review
Greetings,
A routine attempt to secure a place in a popular gym class has highlighted a growing challenge in the age of artificial intelligence. In what is believed to be Australia's first known case of an autonomous AI-powered cyber attack, an AI assistant tasked with booking a gym session discovered and exploited a vulnerability in the gym’s online booking system without being instructed to do so.
The incident involved an Australian technology professional who used an AI agent powered by Anthropic’s Claude model through the OpenClaw platform. After being asked to book a class, the AI found a way to bypass booking restrictions and reserve places weeks earlier than the system was designed to allow. More concerningly, when the user asked whether it could improve his position on a waiting list, the AI removed another member’s booking as part of what it described as testing its capabilities. It later admitted it could not restore that person's place.
Experts say the case demonstrates a key risk associated with increasingly autonomous AI agents. Unlike traditional chatbots, these systems can independently plan and execute tasks across websites and software platforms. While designed to achieve a user's goal, they may choose methods the user neither expected nor authorised. Researchers refer to the challenge of ensuring AI systems act within human intentions and boundaries as the “alignment problem.”
The incident follows recent reports of advanced AI models autonomously hacking systems during testing, raising concerns among cyber security professionals and policymakers. Legal experts also note that responsibility remains unclear when an AI agent causes harm, with questions lingering over whether liability rests with the user, software developer, AI provider, or the operator of the vulnerable system.
For businesses and consumers alike, this situation serves as a reminder that while AI agents offer powerful productivity benefits, they also introduce new risks that organisations, regulators and technology providers are only beginning to understand.
…
Researchers Disclose AI-Assisted SharePoint Exploit Chain Reaching Unauthenticated RCE
Date: 2026-08-11
Author: The Hacker News
Security researchers found a way to enter Microsoft SharePoint servers as any user, including an administrator, with no valid account. A significant part of the work that found it was done through an AI agent.
The flaw, tracked as CVE-2026-55040 (CVSS 9.1), affects SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Server 2016. Microsoft's affected-product list covers only those three on-premises editions, and SharePoint Online is not among them.
Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack
Date: 2026-08-11
Author: The Hacker News
[AUSCERT has published security bulletins for these Microsoft updates]
Microsoft released its monthly security updates on Tuesday, and one of the flaws it closed is already being used in attacks.
The bug sits in a core Windows kernel driver that handles network socket operations. An attacker with code already running on a machine can use it to escalate to SYSTEM. That patch goes out first.
The flaw is tracked as CVE-2026-68820 (CVSS score: 7.0) and is the only one in this month's release Microsoft flags as under active exploitation. Exploitation depends on triggering a race condition in the driver. Microsoft has not publicly attributed the exploitation. Check Point Research says Lazarus used the zero-day in its Operation Dream Job campaign.
SAP Commerce Cloud Flaw Could Let Unauthenticated Attackers Execute Arbitrary Code
Date: 2026-08-12
Author: The Hacker News
SAP has released patches to address a maximum-severity security flaw impacting Commerce Cloud (Data Hub Adapter) that could result in arbitrary code execution.
The vulnerability, assigned the CVE identifier CVE-2026-58231, is rated 10.0 on the CVSS scoring system. It has been described as a case of insufficient authorization checks and input validation.
"SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to certain functions lacking sufficient validation," according to a description of the flaw on CVE.org.
Critical One-Click Vulnerability in Atlassian’s Rovo AI Exposed Enterprise Data
Date: 2026-08-08
Author: Security Week
Varonis Threat Labs has disclosed a one-click vulnerability in Rovo, Atlassian’s enterprise AI assistant, that let a specially crafted link seed attacker-controlled instructions directly into a user’s live AI session.
Dubbed RovoBlast, the flaw required no jailbreak and no permission bypass, relying on the fact that the assistant simply treated externally supplied parameters as trusted input.
Foreign control of AI vendors a board-level risk, ASD says
Date: 2026-08-07
Author: IT News
Australian boards should treat the foreign ownership, control and influence of their artificial intelligence (AI) providers as a cyber risk in its own right, the Australian Signals Directorate advises.
That is one of the four key action points in new guidance from the ASD, co-written with the Australian Institute of Company Directors (AICD), that asks boards to assess the risks of relying on AI providers.
ESB-2026.9350 – Zoom: CVSS (Max): 8.3
Zoom patched a high-severity zero-click flaw (CVE-2026-53413) that could enable remote code execution on meeting participants’ devices.
ESB-2026.9366 – Adobe Campaign Classic: CVSS (Max): 10.0
Adobe patched critical vulnerabilities in Campaign Classic that could allow arbitrary code execution, including two CVSS 10.0 flaws.
ESB-2026.9378 – CTI-Transmute 1.5: CVSS (Max): 8.8
CTI-Transmute 1.5 adds 16 security fixes, a public API, and other improvements to MISP/STIX threat intelligence conversion.
ESB-2026.9500 – Intel Chipset Firmware: CVSS (Max): 8.5
Intel addressed a high-severity CSME and SPS firmware flaw (CVE-2026-6727) that could allow local privilege escalation.
ESB-2026.9519 – Palo Alto GlobalProtect App: CVSS (Max): 8.5
Palo Alto Networks fixed a medium-severity GlobalProtect flaw (CVE-2026-0299) that could allow local privilege escalation to SYSTEM/root.
Stay safe, stay patched and have a good weekend!
The AUSCERT team