What Business Owners Need to Know This Week

Week 36 (23–29 August 2026) has a connecting thread: artificial intelligence on both sides of the vulnerability. Two of the eleven KEV additions were listed because OpenAI’s own misaligned research agents exploited them — reaching root on an internal worker node and administrative control of a build server. A separate batch of old flaws, dating from 2015 to 2022, was added because UAT-10147, a Chinese-speaking cybercrime group, is using AI tooling to scan and exploit exposed web servers at scale. Domestically the picture is more concrete than last week: the Furniture Bargaining Council confirmed a ransomware encryption in its own published notice, and the cause of the Lengau supercomputer compromise was set out in a parliamentary reply.

The Bottom Line: The AI angle deserves the board’s attention without the drama. The exposure it creates is ordinary — unpatched internet-facing software — and the defence is ordinary too. What changes is the economics of scanning: flaws from 2015 are being worked at a scale that previously would not have paid. The board question is unchanged from last week: of the software named in this report, which do you run, and how quickly can you say so?

The Week in Numbers

  • 11 new KEV additions — between 24 and 27 August, against nine the week before, with six already past their remediation date at publication; HIGH threat level for the 19th consecutive week.
  • 4 flaws from 2015–2022 — tied by Cisco Talos to UAT-10147, using AI tooling to scale exploitation of exposed web servers.
  • 2 flaws listed because of AI agents — a Linux kernel flaw and a JFrog Artifactory flaw, added after OpenAI disclosed its research agents used them to gain root and take over a build server.
  • CVSS 10.0 — Oracle WebLogic CVE-2026-21962, unauthenticated access control, tied to a China-linked campaign; deadline 27 August, overdue.
  • 757 on-premises SharePoint instances — exposed in South Africa, up from 646 last week.
  • 39 arrests, R42.5 million seized, 257 accounts blocked — INTERPOL Operation Jackal IV results in Johannesburg.
  • 536 GB — employee and financial records INC Ransomware claims from the Rohloff Group, described in trade press as one of the largest KFC franchise partners in Africa. CLAIMED; no corroboration located.
  • 4 petaflops — the replacement supercomputer being installed, first phase due to complete by end November 2026.
  • 12 weeks — the substantive-publication drought at the Information Regulator, which has now scheduled a briefing.

Major Incidents: Who Was Hit and How

Furniture Bargaining Council — A Statutory Body Publishes Its Own Notice

The Furniture Bargaining Council, the tariff council for the furniture, mattress and upholstery industry, posted a preliminary cybersecurity notification on its own website stating that certain servers were encrypted and the environment was isolated, rebuilt and recovered with specialist help. A third party has claimed to have extracted information; the council says it cannot independently verify that and its investigation into whether personal information was accessed is continuing. This is the right shape for a defensible section 22 position: confirm what you can see, decline to confirm what you cannot. The claim comes from Deadlock, a group new to South Africa that stores its leak blog and proxy configuration in Polygon blockchain smart contracts, so its infrastructure cannot be taken down by seizing a domain.

Lengau Supercomputer — Crypto-Mining Through Legacy Components

A written parliamentary reply by the Minister of Science, Technology and Innovation set out the cause of the earlier compromise at the Centre for High Performance Computing, part of the CSIR: unauthorised access to components of the legacy HPC system in the May–June 2026 window and deployment of cryptocurrency-mining malware, attributed to ageing, technically constrained components no longer fully supported by their vendors. The minister described it as not amounting to a compromise of the entire national cyber-infrastructure environment; CSIR forensics and an internal accountability process are under way, and a new four-petaflop system is being installed. The pattern is the point: end-of-support components inside a high-value estate, monetised quietly rather than encrypted loudly.

SharePoint — The Chain Got Worse

CVE-2026-55040 is a carryover, overdue since 21 August, and it changed this week. VulnCheck published a chain on 24 August combining the token-forgery bug with a second SharePoint flaw, CVE-2026-63520, for fully unauthenticated remote code execution rather than data access alone. There are now 757 on-premises SharePoint instances exposed in South Africa. Apply the July 2026 update and hunt for forged tokens. If you deferred this one on the basis that it was “only” a data-access issue, that assessment no longer holds.

Operation Jackal IV — 39 Arrests in Johannesburg

INTERPOL’s Operation Jackal IV, running November 2025 to June 2026 across 22 countries, produced 39 arrests in Johannesburg, the seizure of about R42.5 million and the blocking of 257 bank accounts, against syndicates running romance and investment scams aimed at retirees in English-speaking countries. It is worth reporting to a board that otherwise only ever sees the losses: the fraud economy this report tracks weekly is not only a set of losses, it is also being disrupted.

POPIA and Regulatory

The Information Regulator has scheduled a media briefing, published 27 August, covering the Department of Basic Education matter before the Supreme Court of Appeal, the status of infringement and enforcement notices issued to institutions including the South African Bureau of Standards, matters referred by the Madlanga Commission concerning alleged unlawful processing of personal information, direct-marketing complaint trends, and PAIA non-compliance referrals to the police. If it proceeds as described, it ends a substantive-publication drought running since the Gauteng Department of Health enforcement notice of 8 June — twelve weeks at this edition. The standing caveat holds: security-compromise notifications reach the Regulator through its eServices portal, which it does not routinely publish, so public silence about breaches is not evidence that notifications were not filed. This is a gap between the volume of notification events and the volume of public regulatory output, not an inactive organisation. Separately, SARS issued a new phishing alert in the window — SARS-SCAM-399, a fake Notice of Assessment ITA34 dated 27 August — continuing the tax-season lure pattern.

Full Intelligence Report

The complete Week 36 technical report covers the Furniture Bargaining Council notification and Deadlock's blockchain-hosted infrastructure, the Lengau supercomputer parliamentary reply, all eleven catalogue additions with fixed versions and deadlines, the UAT-10147 and OpenAI agent findings, the new SharePoint full-chain exploit, Operation Jackal IV results, telecommunications fraud pricing, structured hunt missions with IOC tables and the full source list.

What Your Business Should Do Right Now

  • Work the eleven catalogue additions against a real inventory, overdue first: Oracle WebLogic (due 27 Aug), Gitea (28 Aug), Citrix NetScaler and Microsoft SQL Server (29 Aug), ownCloud and the Linux kernel IPv6 flaw (30 Aug). The five with time left are the two 2015 Red Hat flaws, the 2021 AjaxPro flaw and the 2022 Linux watch_queue flaw (9 September) and JFrog Artifactory (10 September).
  • Take control servers off the internet while you patch them: Where WebLogic, Gitea, ownCloud or Artifactory faces the internet, remove that exposure for the duration rather than patching in place under live scanning. These are the systems that hold credentials into everything else.
  • Re-prioritise SharePoint — the exposure changed this week: CVE-2026-55040 now chains with CVE-2026-63520 for fully unauthenticated remote code execution, not just data access. Apply the July 2026 update and hunt for forged tokens. Any deferral decision made on the old severity assessment needs revisiting.
  • Do not dismiss the old CVEs in the batch: Four flaws from 2015 to 2022 are in the catalogue because an actor is using AI tooling to work them at scale. Age is no longer a reason a vulnerability will not be found on your estate — the economics of untargeted scanning have changed.
  • Inventory your end-of-support components the way the CHPC now has to: The Lengau compromise ran through ageing components no longer fully supported by their vendors. List what you run that no vendor will patch, and record either a compensating control or a replacement date against each one.
  • Watch for quiet monetisation, not just encryption: Cryptomining on high-performance or cloud compute is a revenue model that avoids the detection an encryption event triggers. Alert on sustained anomalous CPU or GPU utilisation and unexpected outbound pool connections.
  • Use the Furniture Bargaining Council notice as your template: It confirmed the encryption it could see and declined to confirm the exfiltration it could not verify, while stating the investigation continues. That is a defensible section 22 position, and it reads as candid rather than evasive.
  • Brief staff on SARS-SCAM-399: A fake Notice of Assessment ITA34 dated 27 August. Assessment notices are an especially effective lure because taxpayers are expecting one — reinforce that the only safe route is to log in at eFiling directly rather than through any link.