Private Firms Cleared for Offensive Cyber & an AWS Key Hits 1,500 Charities (08/13/2026)
- › A presidential memorandum issued today lets vetted private firms run offensive cyber operations against transnational criminal groups under Justice Department and Homeland Security approval.
- › The policy stops short of authorizing companies to hack back at their own attackers, which most headlines have wrong.
- › An AWS access key left in JavaScript is linked to a breach at Beacon that reached more than 1,500 UK charities.
- › Attackers began exploiting the VMware vCenter flaw five days after disclosure.
- › Trezor disclosed a breach affecting nearly 14,000 customers.
The memorandum signed today is the story, and the framing around it is already drifting. Vetted private firms can now run offensive operations against transnational criminal organizations, under federal supervision, with a million dollars in escrow and per-operation approval from two departments. What it does not do is let a company strike back at whoever hit them last week, which is what most of the coverage is implying.
Top 5 Critical Security Alerts
1. Private Firms Get Offensive Authority, With Conditions
A presidential memorandum titled Expanding Capabilities to Combat Transnational Cyber-Enabled Crime, issued today, allows private companies to conduct offensive cyber operations against international criminal organizations, including surveillance using spyware and disruptive attacks intended to destroy criminal data or systems. Participation is voluntary. Firms post a $1 million escrow deposit that is forfeitable for non-compliance, need Justice Department and Homeland Security approval before each operation, and are prohibited from targeting Americans or US systems. Guidance on eligibility is expected within two months and is said to contemplate companies of all sizes. TechCrunch
Operator Note: The policy stops short of permitting hack back, which is the part worth holding onto when someone forwards you a headline. Security veteran Jake Williams called it half-baked and flagged that American participants could be treated as non-uniformed combatants while traveling abroad. We take apart what it means for organizations who are not participating in what the memorandum actually says.
2. One AWS Key in JavaScript Reaches 1,500 Charities
An exposed AWS access key found in client-side JavaScript is linked to the breach at Beacon, the customer relationship platform used by UK charities, affecting more than 1,500 organizations. Infosecurity Magazine
Operator Note: A key in JavaScript is a key you published. Anyone who loaded the page had it. This is the same Beacon incident we covered on August 7, and the root cause turning out to be a credential in front-end code is worth a search of your own bundles this afternoon.
3. vCenter Went From Disclosure to Exploitation in Five Days
Attackers began exploiting the VMware vCenter flaw five days after it was disclosed. We covered the active exploitation yesterday; the interval is the new detail. Infosecurity Magazine
Operator Note: Five days is the planning number now for anything internet-reachable with a management plane behind it. If your change process cannot move a vCenter patch inside a week, the process is the finding.
4. SharePoint Exploitation Follows the Public Proof of Concept
Attackers are exploiting a SharePoint authentication bypass following the release of a public proof of concept. The Hacker News
Operator Note: This is the third SharePoint item in two weeks and the second where publication of working code preceded the wave. Treat a public proof of concept for anything you expose as the start of the clock.
5. Trezor Discloses a Breach Affecting 14,000 Customers
The hardware wallet maker disclosed a data breach affecting nearly 14,000 customers. BleepingComputer
Operator Note: Customer lists for hardware wallet vendors are targeting data, not just personal data. Coldcard owners learned this two weeks ago when a phishing campaign built on the disclosure showed up offering security audits.
Additional Security Alerts
Government & Policy
- Germany moves to give its agencies hacking and sabotage powers: The proposal would extend offensive authority to German intelligence services. The Record
- Google Cloud sets 2027 for its first major post-quantum milestone: A concrete date from a major provider, which helps anyone building a migration plan. Infosecurity Magazine
Vulnerabilities
- Belgium’s eID authentication opens citizen accounts to code execution: The flaw reaches remote code execution through the national identity authentication path. Dark Reading
- Chinese Loongson processors leak through their caches: Researchers found side-channel leakage in the domestically produced chips. The Register
Threat Intelligence
- Jewelbug runs state espionage and steals cryptocurrency: The group balances intelligence collection against straightforward theft, which complicates attribution and motive. Dark Reading
- An Akira affiliate crashed its own ransomware trying to evade endpoint detection: The evasion attempt broke the payload. Infosecurity Magazine
- Passwords in a public Google Doc turned up in search results: Indexing did the rest. The Register
The Axe Report is a daily briefing from Grab The Axe. Need help assessing your organization’s security posture? Take our free Human Attack Surface Score assessment.
Operating on the philosophy that 'you can't build a secure system if you don't know how to break it,' Chris leads our engineering division. A top 1% National Cyber League competitor, he hardens our digital infrastructure against the very exploits he has mastered.
View Profile →Media Inquiries
For expert commentary, interview requests, or high-res assets regarding this announcement, initialize the terminal.