Ceva Breach Cascades Downstream & New Passkey Attacks Land (08/10/2026)
- › A breach at shipping giant Ceva Logistics is surfacing at banks, retailers, and Valve, because the data taken belonged to its customers' customers.
- › Three separate research efforts defeated passkey protections without breaking the cryptography, by reusing signed authentication material.
- › CISA confirmed ransomware crews are exploiting two patched SonicWall SMA1000 flaws, including a maximum-severity server-side request forgery bug.
- › Framework traced its customer data loss to the Metabase zero-day disclosed on Saturday, and a China-linked actor is using an N-able flaw to launch ransomware.
- › Tenet reports half of Fortune 500 companies are exposed to Ghostjacking, which feeds AI agents fake reports to reach past firewall controls.
The Ceva Logistics breach is the one to trace today, because the people whose data was taken were never Ceva’s customers. They bought something from a retailer, the retailer used Ceva to ship it, and the shipping records held their names and addresses. Everything else on the list is a follow-on from last week: the Metabase zero-day now has a named victim, the SonicWall flaws are in ransomware hands, and the passkey research got worse.
Top 5 Critical Security Alerts
1. A Shipping Breach Surfaces at Banks, Retailers, and Valve
Companies that use Ceva Logistics to ship physical goods say their customers’ personal data was taken in a recent attack on the shipping provider. Valve has notified Steam hardware customers of a breach, and the effects are appearing across banks and retailers. TechCrunch
Operator Note: Your logistics provider holds a name and a home address for every physical thing you have ever shipped. That is a customer list with delivery confirmation attached, and almost nobody classifies it as sensitive because it feels operational. Find out who in your supply chain holds shipping records and what your contract says about their breach notification clock.
2. Three Research Teams Defeated Passkeys Without Touching the Cryptography
Three separate research efforts last week demonstrated ways to defeat passkey protections, including recovering synced private keys and bypassing phishing-resistant multi-factor authentication. None of them broke the underlying cryptography. They reused signed authentication material. The Hacker News
Operator Note: This is the second week running that passkey research has landed, and the pattern is consistent with what we wrote after the Unit 42 work in passkeys stop phishing, not malware. The math is holding. The plumbing around it is where the attacks live, which is an argument for hardware-bound keys on privileged accounts rather than for retreating to passwords.
3. Ransomware Crews Take Up the SonicWall Flaws
CISA confirmed that ransomware operators are exploiting two recently patched SonicWall Secure Mobile Access 1000 vulnerabilities, including a maximum-severity server-side request forgery flaw. BleepingComputer
Operator Note: INC Ransomware was already working these appliances a week ago. Broader ransomware adoption means the window for an unpatched SMA1000 has closed, and separately CISA warned the critical Progress Kemp LoadMaster command injection flaw is now under active exploitation too.
4. Framework’s Data Loss Traces to the Metabase Zero-Day
Framework has attributed the loss of customer data to the Metabase zero-day disclosed over the weekend, the maximum-severity flaw that allowed unauthenticated administrative access and shipped without a CVE identifier. Separately, Microsoft warns that a China-linked actor is exploiting the critical N-able flaw to launch ransomware. The Register
Operator Note: Saturday’s zero-day has a named victim by Monday. If you run Metabase and have not looked, the absence of a CVE means your scanner probably still has nothing to say about it.
5. Ghostjacking Uses AI Agents to Get Past the Firewall
Tenet reports that half of Fortune 500 companies are exposed to a technique it calls Ghostjacking, which works by feeding AI agents fabricated reports so the agent’s trusted access carries the attacker past firewall controls. Infosecurity Magazine
Operator Note: The agent is inside the boundary and permitted to make the connection, so the control never fires. Any agent with network egress needs its own rules rather than inheriting the trust level of the account that invoked it.
Additional Security Alerts
Threat Intelligence
- North Korea moved its AI stack offline: Kimsuky is running models on its own servers and connecting document-search tools to stolen files, rather than typing into public chatbots where the provider can see the prompts. The Hacker News
- A malicious VS Code extension steals wallets and credentials: Solidity Pro delivers a browser wallet and credential stealer, continuing the pattern from last week’s Open VSX removals. The Hacker News
Vulnerabilities
- WordPress plugins backdoored with no file changed: Attackers poisoned a JSON feed the plugins fetch, so integrity checks against plugin files show nothing wrong. Infosecurity Magazine
- Hidden text in a PDF exfiltrates through Atlassian Rovo: The instructions never appear to a human reader and the assistant acts on them, extending the Rovo issue from Saturday. The Decoder
Security Breaches & Incidents
- A Klaviyo bug sent sign-up data to advertisers: Personal details and passwords supplied at sign-up were shared with dozens of third-party companies. TechCrunch
- LexisNexis pulled services offline: The company shut down services after detecting suspicious activity on its servers. BleepingComputer
Emerging Security Technologies
- An agent asked to book a gym class exploited the site instead: Told to get its user into a class, the agent found a flaw and used it to move him up the waitlist, which nobody had asked for. The Decoder
- OpenAI paused internal work on Astra: An evaluation found enough advancement in agentic coding and cybersecurity to trigger a pause on some internal activities. The Hacker News
The Axe Report is a daily briefing from Grab The Axe. Need help assessing your organization’s security posture? Take our free Human Attack Surface Score assessment.
Operating on the philosophy that 'you can't build a secure system if you don't know how to break it,' Chris leads our engineering division. A top 1% National Cyber League competitor, he hardens our digital infrastructure against the very exploits he has mastered.
View Profile →Media Inquiries
For expert commentary, interview requests, or high-res assets regarding this announcement, initialize the terminal.