[Cybersecurity Digest] The passkey heist nobody saw coming
The story that was supposed to make password theft obsolete just proved it is not obsolete yet. Malware learned to steal Google's synced passkeys this week, and that was not even the biggest headache in a month already carrying 421 patched Windows CVEs and a fresh Clop ransomware claim against Shell.
The Big 3
A Windows bug Lazarus was already exploiting just got patched
Microsoft's August Patch Tuesday fixed 421 CVEs, including CVE-2026-68820, a use-after-free flaw in the WinSock driver afd.sys that North Korea's Lazarus group had already exploited to deploy the FudModule rootkit. Sixty two of the fixes are rated critical, including remote code execution bugs in Windows DNS, DHCP and Deployment Services.
Why it matters: Lazarus had a working exploit before the fix even shipped, so patching this month is a this week job, not a this month one.
Malware just learned to steal the login method that was supposed to be unstealable
Researchers found malware that can pull synced passkeys straight out of a compromised Google account, not just passwords and cookies. Passkeys are still phishing resistant, but the account managing the sync is now worth guarding like a vault.
Why it matters: reviewing your saved passkeys and adding a hardware key as an offline backup closes the exact gap this attack relies on.
Clop just added Shell to its list of victims
Clop, the group behind 2023's MOVEit mass breach, claimed an attack on Shell on 12 August 2026, exfiltrating engineering drawings and facility photography rather than the usual office files.
Why it matters: engineering and facility data exposes physical infrastructure, a different kind of risk to your organisation than a leaked spreadsheet.
Quick Hits
A hardware wallet firmware flaw drained 70 million dollars in Bitcoin from a single Coldcard holder, proof that cold storage still needs updates. Full story.
A fake VS Code extension called Solidity Pro was caught stealing browser wallet credentials and API keys from smart contract developers. Full story.
California's Delete Act now lets residents wipe their data from every registered data broker through one centralised request, live since 1 August 2026. More on this.
The EU AI Act's transparency obligations took effect on 2 August 2026, forcing clearer disclosure when you are talking to an AI system rather than a person. More on this.
Tool of the Week
YubiKey 5 NFC
Adds a physical, offline backup to your passkeys and two factor logins that malware sitting on your laptop cannot copy remotely.
Who it is for: anyone with an email, bank or crypto account they cannot afford to lose control of.
Protect Yourself
Go to your Google Account security settings, open the passkeys list, and remove anything you do not recognise or no longer use. It takes two minutes and closes the exact gap this week's passkey theft malware exploited.
Forwarded this? Get your own cybersecurity briefing at futuretechnologyhq.com/newsletter.
Stay safe out there.
Nath, Future Technology
Some links in this newsletter may be affiliate links. We only recommend products we genuinely think are worth your time.