Notes from the Chief Security and Trust Officer: August 2026
August moved fast, and we had some big things this month. Agent 3.1 is now live, our biggest step yet toward a single, faster Windows agent. The rest of the note is stacked with things you’ll use, like three Windows zero-days to patch first (one already in Lazarus’s hands), a pile of attacks your SOC quietly shut down for you, and jaw-dropping new tradecraft APG caught before it hit your clients. Let’s dig in, top down.
Blackpoint: Platform and Trust
Microsoft’s August Patch Tuesday brought 400 fixes, including three zero days. Watch CVE-2026-68820, a Windows elevation of privilege flaw the Lazarus Group used in the wild to deploy a new FudModule rootkit. SAP shipped 28 security notes, and Adobe patched critical arbitrary code execution flaws in ColdFusion, a target all year. We pushed hardening guidance to partners the same day, because a platform is only as trustworthy as how fast it moves when a zero day is already hitting real targets.
We also shipped real platform improvements this month. ITDR now flags device code phishing as its own named event, Potential Device Code Phish, instead of burying it in login noise. Cloud Response now shows exactly who changed an ITDR policy and when, so your team can validate a change without guessing. Application Control got a small but useful fix. If a SOC curated rule flags a legitimate app on a filename match alone, you can now turn off filename matching for that one rule instead of the whole rule.
The bigger news is Agent 3.1, now live as of September 2nd. The Unified Agent for Windows folds MDR and Application Control into one agent and moves ransomware detection onto an integrated Windows driver, so blocking keeps pace with fast-moving attacks. One catch needs action now though. Agent 3.1 supports Windows 10 but drops Server 2012. Those devices stay on Agent 2.17 and keep running, but stop receiving patches.
The SOC: stopping it in real time
We published four Threat Pulses in August with one throughline all month. Attackers keep repackaging old tricks, and the SOC keeps catching them before payload. Week of August 3rd, an AutoIt based worm tried to spread via USB using shortcut files disguised as folders, and we caught and isolated it with no lateral movement, alongside a healthcare phishing campaign running through Discord CDN and Cloudflare Workers that we stopped 100 percent before payload. Week of August 10th, an attacker chained two unauthorized RMM tools behind a fake Adobe installer to plant a hidden ScreenConnect instance, and we isolated it before lateral movement. Week of August 17th, a ClickFix lure delivered AcrStealer through a fake update, and we caught it before any credentials left the building. Week of August 24th, an attacker disguised a payload as a security certificate to install another rogue ScreenConnect client, and APG confirmed the Avalon framework still active after 60 days, now shifting its infrastructure naming to stay ahead of defenders.
Across the four weeks, incidents ran from just over 105 to more than 165 per week, and we disrupted 84 to 91 percent before payload. Different disguises every week, RMM impersonation, fake certificates, fake updates, physical media, one pattern underneath. The SOC keeps catching it because the intelligence behind it already knows what to look for.
APG: The Research Behind the Reflex
One of APG’s busiest research stretches. Three of this month’s findings didn’t come from watching an intrusion unfold, they came from APG going looking.
Start with Miraak. APG found this modular post exploitation framework by hunting exposed infrastructure across the open internet, well before any incident. An operational security slip left Miraak’s loaders and tools sitting in open web directories. It blends in, using malicious DLLs disguised as legitimate .NET runtime components and a command and control channel that rides PostgreSQL and Timescale database traffic instead of a normal web beacon, so it reads as ordinary encrypted database activity. It also speaks Cobalt Strike’s Beacon Object File format, so operators can run a whole ecosystem of existing tools without deploying Cobalt Strike itself. APG even traced a self-signed certificate, which its operator had labeled miraak-socks, back to the wider infrastructure behind it. Capable tooling combined with sloppy operational security is slowly becoming the new standard.
The second finding, HollowFrame and Matryoshka, came out of a real intrusion at a law firm. A spear phishing email led to an encrypted archive, a disguised shortcut, and a Go based loader, HollowFrame, that side loaded through a fake Python runtime component, followed by a Rust based backdoor family, Matryoshka, one variant of which used a private GitHub repository for command and control, giving each victim a dedicated folder for tasking and results. The APG found and name these two previously undocumented tools as HollowFrame and Matryoshaka due to their behavior.
The third is less a single finding than the story under everything else this month. We published a piece pulling together what we’re seeing across Avalon, TaskWeaver and Djinn Stealer, DCRat, and the wider landscape. AI is speeding up the existing playbook and handing it to more people rather than inventing new techniques. A leaked chat log from The Gentlemen ransomware crew showed AI used the way any of us would, for coding help, research, and drafting. And in July, researchers documented what they described as the first fully autonomous, agent run ransomware intrusion, an AI agent that ran an entire attack chain against a live system with no human between the exploit and the encryption, though it fumbled the payout by never saving its own key. The techniques were familiar. What was new was the missing human in the middle, and that’s worth sitting with.
Why the Order Matters
Blackpoint builds the platform partners trust. The SOC uses it to stop attacks in real time, every week. And APG keeps building the frameworks and findings that keep both ahead of what’s next instead of reacting to what already happened. Three layers, one job.
See you next month.
DATE PUBLISHEDSeptember 2, 2026
AUTHORBlackpoint Cyber
SHARE ON
The 2AM Test
Executive Guide
Most MDR evaluations focus on dashboards, not what a provider actually does when something is live. Learn the four questions that matter more than the demo: authority, speed, surface coverage, and proof.
*88–91% of ransomware attacks land outside business hours