Skip to main content
New AI-powered DMARC analysis + open REST API See how → →
Advanced

Levi Strauss Breach, Rovo AI Hijacked, Shared Logistics Breach

Brad Slavin
Brad Slavin General Manager

Quick Answer

The August 4–10, 2026 cybersecurity roundup covers major breaches, AI attacks, ransomware, supply-chain threats, and cloud data exposures, highlighting growing risks from social engineering, third-party vendors, and emerging AI vulnerabilities.

Cybersecurity Breaches and AI Threats

Levi Strauss discloses breach after employees fell for social engineering

Levi Strauss & Co. told the SEC on August 7 that an unauthorized third party used social engineering to get into three employees’ company computers and steal corporate data. No exploit, no brute force — just people convincing people. The company says no consumer data was touched and the intrusion was contained quickly. BleepingComputer

Varonis Threat Labs disclosed “RovoBlast,” a one-click flaw in Atlassian’s Rovo assistant that let a crafted URL preload attacker instructions into a user’s chat session, then pull Jira, Confluence, and other connected data out to an external server — no jailbreak needed. A second group, PromptArmor, found a related content-based injection path via uploaded documents. SecurityWeek

Dutch retailers De Bijenkorf and Bol hit by a shared logistics-partner breach

A cyberattack at CEVA Logistics, a delivery partner for both De Bijenkorf and Bol, exposed customer names, addresses, and order details. Neither retailer’s own systems were compromised, but the data reportedly turned up for sale on the dark web within days. NL Times

North Carolina’s three major ports knocked offline by cyberattack

A systems-wide outage hit the Port of Wilmington, Port of Morehead City, and the Charlotte Inland Port on August 4, forcing manual gate processing. The U.S. Coast Guard is monitoring the recovery; no group has claimed responsibility yet. NL Times Dmarc Record 9820

Amgen says patient health data stolen from third-party cloud systems

The biotech giant disclosed that attackers exfiltrated proprietary data and patients’ protected health information from cloud environments run by outside providers, in a filing tied to unauthorized activity detected in July. BleepingComputer

Analog Devices confirms breach, reviewing separate ExfilSquad claims

The semiconductor maker disclosed unauthorized access to internal systems on June 23 and is separately assessing a cybercrime group’s claim of stealing over 570,000 records — though the group has since pulled ADI from its leak site. Security Affairs

Liechtenstein’s corporate ownership registry breached for two days

Attackers accessed Liechtenstein’s Register of Beneficial Owners — which lists who actually owns companies and foundations in the country — for two days starting July 29, making off with roughly 31,000 records. The government has convened a crisis unit. The Record Dmarc Report 8917

Massive “ChainDrop” worm rips through the npm ecosystem

A self-propagating supply-chain worm compromised over 1,300 npm packages (with a combined 2 billion+ monthly downloads) after attackers hijacked the GitHub account of a popular caching library’s maintainer and pushed malicious code straight through the legitimate release pipeline — giving poisoned packages valid-looking provenance. BleepingComputer

INC Ransomware group weaponizes SonicWall zero-days — and starts cold-calling victims

INC Ransomware has become the dominant actor exploiting two chained SonicWall SMA 1000 VPN flaws (CVE-2026-15409 and CVE-2026-15410), with 885+ claimed victims. Researchers noted the group has escalated to phone calls and emails as extortion pressure tactics. The Hacker News Dmarc Report 8791

Indirect prompt injection found across major webmail providers

New research showed that content hidden inside an email can escape its intended boundary and interfere with the webmail interface itself, with attack chains demonstrated across Outlook, Gmail, Fastmail, Proton Mail, Yahoo Mail, and AOL Mail. The Hacker News

Google Password Manager passkey sync flaws disclosed (“Pass-ta-key”)

Researchers detailed three separate attacks capable of undermining passkey synchronization in Google Password Manager, raising fresh questions about the resilience of passkeys as they scale to mainstream adoption. CyberWorldOps

Major cyberattacks and data breaches are exposing new risks for businesses worldwide. Strengthen email security with DMARC, DKIM, and SPF to help prevent phishing and social-engineering attacks.

Brad Slavin
Brad Slavin

General Manager

Founder and General Manager of DuoCircle. Product strategy and commercial lead for DMARC Report's 2,000+ customer base.

LinkedIn Profile →

Take control of your DMARC reports

Turn raw XML into actionable dashboards. Start free - no credit card required.