AI Weekly Digest
Claude AI# Weekly IT Digest for UK Business IT Managers
• **August 2026 Patch Tuesday – 415 CVEs Including Exploited Zero-Day**: Microsoft released patches for one actively exploited zero-day and 62 critical vulnerabilities this week. Prioritise testing and deployment immediately, particularly for internet-facing systems; this is a mandatory patch cycle.
• **Azure Account Credentials Compromised at Scale**: 3.6 million Azure account records allegedly stolen from major organisations; threat actors are actively targeting cloud identities. Review your Entra ID logs for suspicious sign-ins, enforce MFA universally, and consider conditional access policies blocking high-risk logins.
• **CrowdStrike Falcon AIDR Extends to Copilot Studio and Claude Code Protection**: Falcon Artificial Intelligence and Detection Response now shields Microsoft Copilot Studio agents and Anthropic Claude Code from threats. If you're deploying AI assistants in production, verify your CrowdStrike agent versions cover these new integration points.
• **GitHub Outage Confirms Global Access Issues**: Microsoft confirmed GitHub experienced worldwide downtime this week. Test your git backup and failover procedures now; don't wait for the next incident to discover gaps in your source control resilience.
• **VMware ESX Shell Command Obfuscation Attacks Detected**: CrowdStrike threat hunters identified attacks exploiting shell command obfuscation on VMware ESX environments. Review ESX host logs for suspicious shell activity and ensure your hypervisor estate is fully patched; virtualisation infrastructure remains a high-value target.
Latest News
All news →Expanded multistage chain of thought monitoring makes frontier model work more expensive
Gaps in expiry checks could let dead plastic make purchases again
Comcast is promoting WiFi-based motion detection as a part of its new Xfinity Shield home protection platform, allowing routers and wireless devices to detect people moving through a home without cameras or motion sensors. [...]
Executive Summary CVE-2026-68820 is an actively exploited Windows vulnerability listed in CISA’s Known Exploited Vulnerabilities (KEV) Catalog, with a remediation deadline as suggested by CISA BOD 26-04. CISA BOD 26-04 introduces risk-based remediation timelines ranging from 3 to 14 days, increasing…
A custom Java web shell likely linked to the Clop ransomware gang was designed specifically for PTC Windchill and FlexPLM servers, with built-in features to decrypt credentials, enumerate file repositories, and steal files. [...]
Partners need to be able to confidently answer key client questions relating to supply chain security going forward...
New dynamic model routing capabilities aim to help customers box clever when it comes to their AI model choice