The Security Drop- August Edition

Thursday, September 3, 2026

Introduction

Did you know someone can turn a photo of your hand into a fake fingerprint using artificial intelligence and a 3D printer? No hacking is required. A high-resolution photo of your hands posted online could be enough.

That is just the beginning of what unfolded in the August edition of the Security Drop.

A well-known AI research organisation, METR, lost $600,000 worth of AI credits after attackers exploited a tiny flaw in its own system.

Africa did not escape the surge in cyber threats either. Businesses across the continent are being targeted at an alarming rate, with one country now facing an average of 5,714 cyberattacks every week.

From AI-enabled biometric threats to costly system vulnerabilities and the growing wave of cyberattacks across Africa, there is a lot to unpack.

Read the full story in the August edition of the Security Drop below.

A Vibe-Coded App With a Silent Authentication Failure Just Cost $600,000 in AI Credits

The Model Evaluation and Threat Research (METR), a non-profit that evaluates frontier AI models for safety and capability, has disclosed two separate security incidents that happened earlier this year. Although no sensitive information is believed to have been accessed as a result of these incidents in March and May this year, METR noted that the attackers probed their publicly accessible infrastructure in an attempt to gain unauthorised access to internal data via an exposed endpoint.

While the March incident stole an API key for inference and consumed a substantial amount of credits, the May incident seemed more financially motivated, with attackers credential-stuffing authentication providers and trying to phish Research Centre staff.

Although METR has since updated policies around credentials on non-METR infrastructure, this incident reminds organisations that use AI-powered tools to treat them as a top security concern. AI infrastructure should be added to every organisation’s asset inventory and should be monitored with the same rigour as every other infrastructure.

Infostealer Malware is Hijacking Claude AI Sessions to Drain User Usage Limits

As generative AI tools become core to daily workflows, threat actors are pivoting toward a new target: stealing active AI session tokens to leech off paid compute resources.

Anthropic has begun notifying Claude users that widespread infostealer malware is quietly hijacking active login sessions from compromised PCs. Attackers are siphoning stolen browser cookies to bypass standard authentication and two-factor authentication (2FA) entirely. Anthropic emphasised that while force-signing users out halts an attacker’s immediate access, it does not clean the infected host device. This implies that any subsequent login will immediately leak new session cookies right back to the attackers.

Therefore, for individuals, if you notice your Claude usage limits are unexpectedly draining, immediately log out of all active sessions across your account settings. For organisations, ensure endpoint protection (EDR/MDR) solutions are active and configured to detect cookie-stealing behaviour.

Hackers Target Microsoft SharePoint with Critical Two-Stage REC Exploit Chain

Unpatched Microsoft SharePoint servers are facing a surge in targeted probing as threat actors weaponise a newly disclosed, two-stage vulnerability exploit chain.

Defused, a threat intelligence company, confirmed that attackers are actively scanning the internet and probing honeypots by chaining two separate vulnerabilities to achieve full Remote Code Execution (RCE). By combining a flaw in SharePoint’s JSON Web Token (JWT) validation with a bug in its Business Connectivity Services (BCS), unauthenticated attackers can step into administrative roles and execute arbitrary code on vulnerable servers. The two-step sequence involves the JWT bypass (tracked as CVE-2026-55040) and the RCE via BCS Sink (tracked as CVE-2026-63520).

This exposure is significant, as Shadowserver, another intelligence group, continues to track over 8,700 servers that have been exposed directly to the public internet as a result of this incident.

In light of this, organisations need to apply Microsoft's latest security patches immediately to address both vulnerabilities across all on-premises SharePoint installations.

FBI Dismantles Industrialised Cyber “Quartermaster” Fueling Chinese State Espionage

In a major blow to state-sponsored hacking operations, the FBI and federal prosecutors have dismantled the core infrastructure behind a massive Chinese cyber espionage “quartermaster” platform.

The U.S. Department of Justice and Intelligence firm Lumen’s Black Lotus Labs confirmed the takedown of an operation run by a Chinese entity called QTFY (also known as Nanjing Xinjiuwei), of which court documents link directly to China’s Ministry of State Security (MSS) and former military cyber personnel. Acting as a centralised logistics hub for advanced persistent threat (APT) groups, the platform provided commercialised target reconnaissance and custom proxy routing, and operational obfuscation to conduct espionage against U.S. critical infrastructure.

Researchers warned that while seizing the domains and null-routing traffic delivers a significant operational setback, static IP blocking alone may not solve the broader threat. Thus, organisations should shift toward behavioural anomaly detection for outbound connections. For individuals, it is important to keep home routers and network devices updated with the latest software to avoid such intrusion.  

China-Linked ‘Fire Ant’ Hijacks CISCO Routers to Steal Credentials and Blind Security Logs

A China-nexus cyber espionage group is moving deeper into core network security, manipulating the hardware responsible for routing, managing and authenticating enterprise traffic.

An investigation published by cybersecurity incident response firm Sygnia revealed that a sophisticated threat actor tracked as Fire Ant (strongly overlapping with Chinese state-based cluster UNC3886) has expanded its operations beyond VMware hypervisors to directly compromise CISCO IOS XR routers, TACACS authentication servers, and Linux management hosts. By embedding specialised implants beneath the operating system level, the attackers turned core network routers into covert collection platforms. Controlling these devices gives the group a privileged vantage point to inspect network traffic, harvest administrative credentials, and suppress security logging.

This means organisations must reconcile core router configurations against an external, out-of-band source of truth rather than relying strictly on the device’s internal command output. Organisations should also enforce strict memory-level forensic scanning on the Linux management host and audit all running processes against legitimate binaries.

German Cyber Agency Warns AI and 3D Printers Can Spoof Fingerprints from Online Photos

Germany’s Federal Office for Information Security (BSI) issued a warning confirming that attackers can now combine artificial intelligence tools with 3D printers to fabricate synthetic fingerprints using high-resolution online photographs of hands. BSI even warned that common gestures in public photos can expose enough ridge-and-valley detail for generative AI models to extrapolate, enhance and convert into a printable 3D biometric mould. The agency emphasised that unlike compound passwords, biological fingerprints cannot be reset or replaced once leaked, making them a high-risk single point of failure if used without secondary authentication factors.

This implies that organisations need to engage multi-factor authentication (MFA) that pairs biometrics with hardware security keys or time-based one-time passwords (TOTP). Organisations should also upgrade their biometric scanners to devices that are equipped with hardware-level liveness detection capable of distinguishing synthetic moulds from living skin.

Ransomware and Cyberattacks Surge Across African Enterprises with Record Weekly Targeting

African enterprises experienced an alarming escalation in cyber threats, recording an average of 3,237 weekly attacks, a 3% month-on-month increase and a 16% year-on-year increase.

Data released by Check Point Research reveals that ransomware activity across the continent has surged by over 87%, with emerging groups like The Gentlemen, DeadLock and Qilin aggressively targeting regional enterprises. Angola was hard hit with 5,714 weekly attacks per organisation, followed by Nigeria at 4,975, Kenya at 2,915 and South Africa at 2,195 weekly attacks.

This imposes a critical duty on organisations to re-evaluate their perimeter security and ensure strict email authentication protocols to mitigate incoming phishing vectors. Furthermore, GenAI should be deployed in line with appropriate usage policies across the organisation, while Data Loss Prevention (DLP) controls should be engaged to monitor and restrict employee inputs into public AI models.

INTERPOL Report: AI Links to Over 55% of Cybercrime in Africa as Losses Hit $484 Million.

INTERPOL’S official African Cyberthreat Assessment Report 2026 reveals that 55% of reported cybercrime cases in Africa are now AI-enabled. Drawing on survey data from 36 member countries, the assessment highlights how threat actors are using GenAI and automation to scale attacks and bypass legacy security defences.  Consequently, reported financial losses from cybercrime in Africa have more than doubled since 2024, rising from $192 million to $484 million. Despite these staggering losses, multilateral law enforcement agencies have arrested over 1,500 individuals and recovered $100 million in stolen assets over the past year.

For financial institutions within the continent, it is important to implement multi-layered fraud risk engines that combine several factors, such as device fingerprinting and other contextual signals, to detect synthetic identity creation. Moreover, enforcing strict AI usage guidelines helps limit the use of AI to scale these cyberattacks.

These incidents are a reminder to stay alert. Add AI infrastructure to your asset inventory and monitor it closely. If your Claude usage looks off, log out of all active sessions immediately, and patch Microsoft SharePoint without delay.

Organisations should also pair biometrics with multi-factor authentication (MFA) or time-based one-time passwords (TOTP), strengthen email security, set clear GenAI usage policies, and use Data Loss Prevention (DLP) controls to protect what employees share with public AI tools.

In cybersecurity, the smallest habits often stand between safety and a costly breach.