Threat Vectr Weekly — week of Aug 31
Stories covered this week
Cyberattack on Hachette Australia Leaves Bookshops Without Stock During Peak Season
A breach of the publisher's computer systems on 18 July has frozen book distribution across Australia and New Zealand, hitting authors, retailers, and readers at the worst possible moment in the retail calendar.
Taiwan Charges Nine People Over Illegal AI Server Exports to China, Including Staff From Nvidia and Super Micro
A smuggling case in Taiwan shows how the race for AI hardware has created a black market for restricted chips, with employees at two major American tech companies among those accused.
Microsoft's August .NET patch broke printing in Windows apps. Here's what to do.
A security fix shipped this month is causing crashes when Windows Presentation Foundation apps try to print or export to PDF using common fonts like Calibri.
Anthropic Opens Its Most Powerful AI to More Security Defenders and Puts $35 Million Behind Open-Source Safety
The company behind the Claude AI system is carefully widening access to its strongest models for cybersecurity work, while keeping ordinary users and criminals locked out.
Chinese-speaking crew UAT-10147 hits web servers with AI-built tools and a Linux rootkit
The group targets Windows and Linux servers across education, media, tech and gaming, with victims concentrated in Brazil, Bolivia, China, Canada and Vietnam.
Iran-Linked Hackers Knocked a UK Power Plant Offline for Four Days
A cyberattack tied to Iran shut down a British power station for nearly a working week, raising hard questions about how well the country's energy grid can withstand a determined digital assault.
Seven Ways AI Is Changing How Companies Defend Themselves
Security experts say artificial intelligence is giving overstretched security teams a fighting chance, but only if organisations deploy it carefully and with realistic expectations.
From Months to Minutes: How AI Is Forcing Companies to Rethink Software Security
Criminals once needed two years to turn a software flaw into a working attack. By next year, that window is expected to shrink to four hours. Companies that patch on a quarterly schedule are already behind.
Transcript
Narrated by two AI anchors. Lightly formatted for reading.
Welcome to Threat Vectr Weekly, your ten-minute briefing on the cybersecurity stories that matter most. I'm Marcus, alongside Elena, and this is the episode for the week of August thirty-first. Coming up: a cyberattack freezes book distribution across Australia and New Zealand right before the holiday retail rush, Iran-linked hackers knock a British power plant offline for four days, and we look at how fast the window between a software flaw being found and being weaponised is collapsing — we're talking from two years down to about four hours. A lot to get through, so let's get into it.
We start in Australia, where a cyberattack is causing real, tangible harm — not to data, but to shelves. Hachette Australia and Aotearoa New Zealand detected what they're calling unauthorised activity on their computer systems around the eighteenth of July. Hachette's distribution arm shipped more than sixteen and a half million book titles across Australia last year alone, so when those systems go down, the supply chain stops. Booksellers report that daily restock orders aren't being processed and backlist titles — the steady, reliable sellers that keep the lights on for most bookshops — are simply unavailable. The timing is brutal. Children's Book Week, Father's Day, and the beginning of the Christmas push are all stacking up right now, the period when booksellers earn a huge share of their annual income. Poet and memoirist Maxine Beneba Clarke turned up to events in Geelong and Bendigo last week and found no copies of her own books waiting. As of Friday, Hachette's CEO said the company cannot yet confirm a timeline for a full return to normal. The practical takeaway: if you have a book event, a school order, or a holiday list that depends on Hachette titles right now, plan for delays and call your bookseller directly to check availability. Over to you, Elena.
Thanks, Marcus. Staying in the Asia-Pacific region but moving from books to chips — Taiwan has charged nine people with illegally exporting AI server hardware to China in violation of trade restrictions. And two of those charged are current or former employees of Nvidia and Super Micro Computer, two of the biggest names in American AI infrastructure. Nvidia makes the graphics processing units — the powerful chips that have become the engine of modern AI — and Supermicro assembles the server systems that house them. The United States and Taiwan have export controls in place specifically to limit China's access to this kind of advanced computing technology. The allegation here is that insiders helped those controls get bypassed. This is not a hacking story — no data breach, no intrusion. It's an insider-conduct and trade-law case. But for the security community it's a reminder that the threat doesn't always come through a network port. Sometimes it walks out the door wearing a badge. The takeaway for organisations: export compliance isn't just a legal department problem. It sits squarely in the insider-threat conversation, and that means access controls, monitoring, and culture all matter.
And from hardware smuggling to a much more familiar frustration — a patch that breaks something. Microsoft confirmed on the fifteenth of August that its August Patch Tuesday updates for dot-NET Framework are breaking printing and PDF export in a chunk of Windows desktop applications. The apps affected are built on something called Windows Presentation Foundation — that's Microsoft's toolkit for building graphical Windows desktop software. When users in those apps hit print or try to save as PDF, the application crashes with a file format error. Documents using Calibri, which was the default Office font for years, are among the ones that trigger it. Every current Windows version is affected, from Windows 10 and 11 on desktops to Windows Server 2012 all the way through Windows Server 2025. Here's the painful part: Microsoft's temporary workaround involves turning off part of the very security protection the August update added. So you fix the printing, but you reopen the door the patch was meant to close. No permanent fix has shipped yet. The practical advice: if your business relies on printing or PDF export from Windows desktop apps, check with your IT team before applying the August dot-NET updates, and watch Microsoft's support pages closely for when a proper fix lands.
Good to know. Now, a more forward-looking story. Anthropic, the company behind the Claude AI system, is carefully widening access to its most powerful model for cybersecurity work. The model in question is called Claude Mythos Five, and it's being made available to vetted security teams — but not directly. Instead, it runs quietly in the background inside partner-built security tools and hands back a specific, limited result: think a list of flagged vulnerabilities with severity ratings and suggested fixes, rather than an open-ended conversation. Anthropic is also putting thirty-five million dollars behind a fund called the Defender Advantage Fund — zero-x-D-A-F — which distributes computing credits to organisations protecting open-source software. And its Cyber Verification Program, which relaxes certain AI restrictions for authorised security professionals, is expanding its permissions in the coming weeks. The underlying philosophy here is worth noting: Anthropic says the riskiest thing it could do is give anyone unrestricted access to a very capable AI. So instead of opening the door, they're passing specific answers through a slot in the wall. Whether that model scales to meet defender needs is the open question. Marcus?
That's a really interesting design philosophy, and it connects directly to our next story, which is about what happens when attackers get AI tools of their own. Researchers have identified a new Chinese-speaking cybercrime group they're tracking as UAT-10147. This crew is breaking into internet-facing web servers — not individual laptops, but the servers that run websites and online services — across education, media, technology, and gaming organisations. Most of the confirmed victims are in Brazil, Bolivia, China, Canada, and Vietnam, though the campaign reaches further. The group uses a custom toolkit researchers are calling SPECTRE, along with a Linux rootkit — that's hidden software that gives attackers deep, persistent control of a machine, the kind that's hard to detect and hard to remove. What caught researchers' attention is evidence that UAT-10147 appears to be using AI tools to help write and scale its attacks. They were caught partly because they left an operational server exposed on the open internet. The takeaway: if you run web servers, especially in those four industries, make sure they're patched, hardened, and that you have visibility into what's running on them. Exposed management interfaces are still one of the most common ways groups like this get a foothold.
From a new threat group to a very concrete real-world impact. Iran-linked hackers knocked a UK power plant offline for four consecutive days. Let that sit for a moment — four days. This is not a website going down or customer records leaking. This is physical machinery stopped. Industrial control systems — the specialist computers that tell turbines, generators, and other physical equipment what to do — were designed decades ago for reliability, not for defence against a nation-state cyberattack. Connecting them to modern networks without layering in proper security has been a known risk for years, and this incident is that risk becoming reality. The attack caused what investigators describe as real-world operational disruption. Full technical details are still limited, but SecurityWeek first reported the incident and the concern it's raising is clear: Britain's distributed energy network — a spread-out collection of smaller sites rather than one centralised grid — may be vulnerable to repeated attacks of this kind. Energy operators and regulators are now under pressure to prove they can actually defend critical national infrastructure. The practical message for anyone working in critical infrastructure: assume you are a target, because state-linked actors have demonstrated they will go after physical systems.
Are you at risk? Own or run a business? Then do the maths. One wrong click can cost you your data, your downtime and your customers. Training your whole team costs from $1.59 per user, per month, for under the price of a small cup of coffee. Train2Secure runs the phishing tests, the training and the reporting for you. Get your free trial at Train2Secure dot com. That's Train, the number two, Secure, dot com.
Absolutely, and that story leads naturally into our next one, which is about how artificial intelligence is changing the defender's side of this equation. Security teams today are drowning in alerts — millions of them every day, far more than any human team can meaningfully review. Think of a hospital control room where alarms are going off constantly. Most are false. A handful are genuine emergencies. The nurses can only check so many. That's the daily reality for corporate security teams. AI is increasingly being used to manage that flood. Experts from NTT DATA, TransUnion, and several universities, in reporting by CSO Online, describe what it can actually do: process scale. A skilled analyst might work through hundreds of events in a shift. AI systems can review millions simultaneously, connecting patterns across email logs, login records, cloud files, and network traffic at the same time. The experts are also clear about the limits. Left without oversight, AI models can drift, or be deliberately tricked by attackers who understand how they work. And the data those models learn from is partly shaped by how ordinary employees use company systems — which means security isn't just an IT problem. Every person in an organisation plays a role in the quality of the signal AI is working with. Elena, you want to take us home?
Gladly, and this last story is one I think everyone should hear, because it reframes how urgent the patching problem actually is. In 2018, attackers took an average of seven hundred and seventy-one days to turn a known software flaw into a working attack. That's more than two years. It gave IT teams a real runway — find the flaw, test the fix, apply it, move on. That runway is gone. By 2026, the same process is projected to take roughly four hours. Four hours. AI tools that can automatically scan thousands of systems and write attack code without human help are the main driver. The gap between a flaw being discovered and a flaw being exploited has effectively collapsed. The problem is that patching — applying a software update that closes a security weakness — takes time even in well-run organisations. Testing, change approvals, scheduled maintenance windows. Most companies still operate on quarterly patch cycles, and that is now dangerously out of step with attacker speed. Security experts say the response has to be continuous scanning and real-time risk assessment, not a calendar reminder every three months. And for organisations that genuinely cannot patch fast enough, the advice is to layer in compensating controls — real-time monitoring, threat intelligence feeds, tighter access controls — to reduce how much damage a fast-moving exploit can actually do. The bottom line: if your organisation's security posture assumes attackers need weeks to act, that assumption needs to change today.
That's a sharp note to end on. Thank you for spending ten minutes with us on Threat Vectr Weekly. If you want these stories in your inbox before they hit the podcast, head to threatvectr dot com slash newsletter and sign up — we'll have next week's briefing waiting for you. I'm Marcus, Elena's here too, and we'll see you next week. Stay sharp. If you got something out of this, a thumbs up and a subscribe genuinely helps.
