Cybernews by abat

Cybersecurity is a critical success factor for businesses of all sizes today. Here you’ll find the latest news, insights, and background information on IT security, cyber threats, and digital resilience. Our goal is to provide clear context for complex developments and highlight relevant trends early on. 

AI puts cybersecurity on the spot

An alliance of over 100 companies (including OpenAI, Anthropic, Google, Microsoft, SAP, and Deutsche Telekom) warns that time is running out: AI-powered attacks are on the rise, becoming more sophisticated, and threatening critical infrastructure. A study by Bifold, Inria, and Ruhr University Bochum involving 7,741 employees demonstrates just how real this threat is. Using just a single email address, a local AI generated personalized phishing emails. The click-through rate rose from 3.9 to 10.0 percent, with each address requiring about 45 seconds of processing time. The security system intercepted only one out of 3,949 emails.

Autonomous agents also act unpredictably. An AI agent in Australia was supposed to simply book a fitness class, but instead found a vulnerability in the GraphQL API, reserved classes in advance, and removed a person from the waiting list without permission. According to the user’s instructions, the agent was merely acting helpfully, not maliciously.

What specific steps should companies take now? AI isn’t automatically the solution. Often, the basics – such as multi-factor authentication and zero-trust – are missing. A sensible approach is to first conduct an assessment, then analyze the problem, and finally implement prioritized measures. abat combines SAP know-how and AI expertise with cybersecurity expertise and tests systems through penetration tests.

Unpatched SAP Systems under active attack

Attacks on unpatched enterprise software remain a real threat; the situation is currently escalating significantly, particularly in the SAP environment. Security researchers are already observing active attacks targeting the critical SAP Commerce Cloud vulnerability CVE-2026-58231, just a few days after the patch was released as part of SAP Patch Day on August 11, 2026.
This incident is part of a series of reports: On August 13, international corporations such as Shell, Philips, Fiserv, and General Electric also reported possible data breaches following attacks by the cybercrime group Cl0p targeting known vulnerabilities in business-critical software.

The problem rarely lies solely in individual vulnerabilities, but rather in complex system landscapes, a lack of testing capacity, and delayed patching processes. SAP systems are also often still considered internally isolated, even though modern landscapes are closely interconnected via APIs and cloud services. As a result, known vulnerabilities sometimes remain unpatched for a long time and are deliberately exploited.

Traditional network or web tests often fall short in this regard, as SAP-specific services, protocols, and authorization models are frequently overlooked, while AI-powered attack methods further shorten the time to active exploitation. Companies should therefore integrate patch management, monitoring, and security audits more closely. An SAP penetration test helps identify critical attack vectors, insecure interfaces, and overprivileged permissions before attackers can exploit them.

AI Carries Out Autonomous Cyberattack

On July 21, 2026, OpenAI and Hugging Face disclosed a security incident. During an internal audit, several of OpenAI’s AI models independently constructed an attack chain. Using an unknown zero-day vulnerability, they escaped the test environment and penetrated Hugging Face’s production systems. OpenAI describes this as an unprecedented cyber incident. Critics view this as a staged, PR-driven stunt – one that nonetheless demonstrates the already formidable capabilities of such models.

The incident confirms the BSI’s latest warning: AI reduces the effort and barriers to entry for attacks and is increasingly able to find vulnerabilities autonomously, even in real-world systems without source code. As a result, what matters most for companies is not so much whether vulnerabilities exist, but how far an automated attacker could go. Expansive SAP landscapes, in particular, offer a large attack surface for this purpose.

The BSI is not stopping at issuing a warning. With the AI Audit and Assurance Assessment Architecture (A5), it has presented a modular audit architecture for AI systems, currently in the form of a community draft. It is aimed at all stakeholders along the AI value chain – from development to operations to procurement—and provides criteria and a methodology for systematically evaluating the trustworthiness of AI systems. abat, as a provider of AI architectures and solutions, also incorporates security from the very beginning: through secure development, consistent monitoring, AI-assisted penetration tests, and thorough hardening.

Sources: 
https://openai.com/index/hugging-face-model-evaluation-security-incident/
https://www.bsi.bund.de/DE/Themen/Unternehmen-und-Organisationen/Informationen-und-Empfehlungen/Kuenstliche-Intelligenz/A5/A5_node.html

 

AI is changing the cybersecurity landscape – the BSI sees a fundamental shift.

In a new IT security bulletin, the BSI warns: Artificial intelligence is significantly accelerating the discovery and exploitation of vulnerabilities. Current systems are increasingly able to find and analyze security vulnerabilities largely on their own and turn them into effective attacks – no longer limited to simply crafting convincing phishing emails.
 
The problem is structural: AI reduces the effort, time, and barriers to entry for attacks. Attackers benefit from speed and automation, while defenses remain constrained by real-world operational limits.
 
This is exactly what we’re seeing at abat: In our cybersecurity division, we use the Frontier models of current LLMs to evaluate the impact on IT security and, above all, the threat landscape for SAP environments. This includes, on the offensive side, assisted penetration testing and the development of penetration testing tools and exploits, as well as, on the defensive side, the secure architecture of AI infrastructures and secure development with the help of AI.
 
The BSI’s recommendation against such current threats: reduce the attack surface, accelerate patching processes, and strengthen response capabilities.
 
But how can you reduce and harden the attack surface while simultaneously strengthening response capabilities? Especially when it comes to SAP environments, it’s helpful to look at things from the attacker’s perspective. How far could a potential attacker get with phished credentials? What business risks does this pose, and how seriously do they threaten the company? Such questions can be answered with a penetration test, which not only provides transparency into vulnerabilities that can actually be exploited but also offers prioritized recommendations for action with a clear business impact. At abat, we specialize in these tests – feel free to contact us for more information.

Infostealer Malware: 124 Million Passwords Compromised

On June 15, 2026, the data breach check service HaveIBeenPwned (HIBP) added approximately 56.3 million email addresses and 124 million passwords to its database. The data comes from so-called “stealer logs” – log files generated directly on victims’ devices by infostealer malware. The dataset is based on hundreds of millions of individual log entries; HIBP does not provide any information about their specific origin.

For companies with unhardened SAP environments, this creates several attack vectors: For example, via the proprietary SAP GUI client, operating system commands can be executed on the computers of all logged-in users on a compromised SAP system, using their respective local privileges. An attacker could exploit this vulnerability to install infostealers on end devices and thus attack virtually all of a company’s SAP workstations simultaneously. Compromised credentials and an insecure SAP system are therefore mutually reinforcing.

To proactively prevent attacks using these compromised credentials, companies should identify affected accounts via HIBP, implement security measures as necessary, and consistently roll out multi-factor authentication across all accounts. It is also recommended to actively scan the SAP system landscape for vulnerabilities. An SAP penetration test can determine whether an attacker could gain access to critical systems via these attack vectors.

AI puts cybersecurity on the spot

An alliance of over 100 companies (including OpenAI, Anthropic, Google, Microsoft, SAP, and Deutsche Telekom) warns that time is running out: AI-powered attacks are on the rise, becoming more sophisticated, and threatening critical infrastructure. A study by Bifold, Inria, and Ruhr University Bochum involving 7,741 employees demonstrates just how real this threat is. Using just a single email address, a local AI generated personalized phishing emails. The click-through rate rose from 3.9 to 10.0 percent, with each address requiring about 45 seconds of processing time. The security system intercepted only one out of 3,949 emails.

Autonomous agents also act unpredictably. An AI agent in Australia was supposed to simply book a fitness class, but instead found a vulnerability in the GraphQL API, reserved classes in advance, and removed a person from the waiting list without permission. According to the user’s instructions, the agent was merely acting helpfully, not maliciously.

What specific steps should companies take now? AI isn’t automatically the solution. Often, the basics – such as multi-factor authentication and zero-trust – are missing. A sensible approach is to first conduct an assessment, then analyze the problem, and finally implement prioritized measures. abat combines SAP know-how and AI expertise with cybersecurity expertise and tests systems through penetration tests.

Unpatched SAP Systems under active attack

Attacks on unpatched enterprise software remain a real threat; the situation is currently escalating significantly, particularly in the SAP environment. Security researchers are already observing active attacks targeting the critical SAP Commerce Cloud vulnerability CVE-2026-58231, just a few days after the patch was released as part of SAP Patch Day on August 11, 2026.
This incident is part of a series of reports: On August 13, international corporations such as Shell, Philips, Fiserv, and General Electric also reported possible data breaches following attacks by the cybercrime group Cl0p targeting known vulnerabilities in business-critical software.

The problem rarely lies solely in individual vulnerabilities, but rather in complex system landscapes, a lack of testing capacity, and delayed patching processes. SAP systems are also often still considered internally isolated, even though modern landscapes are closely interconnected via APIs and cloud services. As a result, known vulnerabilities sometimes remain unpatched for a long time and are deliberately exploited.

Traditional network or web tests often fall short in this regard, as SAP-specific services, protocols, and authorization models are frequently overlooked, while AI-powered attack methods further shorten the time to active exploitation. Companies should therefore integrate patch management, monitoring, and security audits more closely. An SAP penetration test helps identify critical attack vectors, insecure interfaces, and overprivileged permissions before attackers can exploit them.

AI Carries Out Autonomous Cyberattack

On July 21, 2026, OpenAI and Hugging Face disclosed a security incident. During an internal audit, several of OpenAI’s AI models independently constructed an attack chain. Using an unknown zero-day vulnerability, they escaped the test environment and penetrated Hugging Face’s production systems. OpenAI describes this as an unprecedented cyber incident. Critics view this as a staged, PR-driven stunt – one that nonetheless demonstrates the already formidable capabilities of such models.

The incident confirms the BSI’s latest warning: AI reduces the effort and barriers to entry for attacks and is increasingly able to find vulnerabilities autonomously, even in real-world systems without source code. As a result, what matters most for companies is not so much whether vulnerabilities exist, but how far an automated attacker could go. Expansive SAP landscapes, in particular, offer a large attack surface for this purpose.

The BSI is not stopping at issuing a warning. With the AI Audit and Assurance Assessment Architecture (A5), it has presented a modular audit architecture for AI systems, currently in the form of a community draft. It is aimed at all stakeholders along the AI value chain – from development to operations to procurement—and provides criteria and a methodology for systematically evaluating the trustworthiness of AI systems. abat, as a provider of AI architectures and solutions, also incorporates security from the very beginning: through secure development, consistent monitoring, AI-assisted penetration tests, and thorough hardening.

Sources: 
https://openai.com/index/hugging-face-model-evaluation-security-incident/
https://www.bsi.bund.de/DE/Themen/Unternehmen-und-Organisationen/Informationen-und-Empfehlungen/Kuenstliche-Intelligenz/A5/A5_node.html

 

AI is changing the cybersecurity landscape – the BSI sees a fundamental shift.

In a new IT security bulletin, the BSI warns: Artificial intelligence is significantly accelerating the discovery and exploitation of vulnerabilities. Current systems are increasingly able to find and analyze security vulnerabilities largely on their own and turn them into effective attacks – no longer limited to simply crafting convincing phishing emails.
 
The problem is structural: AI reduces the effort, time, and barriers to entry for attacks. Attackers benefit from speed and automation, while defenses remain constrained by real-world operational limits.
 
This is exactly what we’re seeing at abat: In our cybersecurity division, we use the Frontier models of current LLMs to evaluate the impact on IT security and, above all, the threat landscape for SAP environments. This includes, on the offensive side, assisted penetration testing and the development of penetration testing tools and exploits, as well as, on the defensive side, the secure architecture of AI infrastructures and secure development with the help of AI.
 
The BSI’s recommendation against such current threats: reduce the attack surface, accelerate patching processes, and strengthen response capabilities.
 
But how can you reduce and harden the attack surface while simultaneously strengthening response capabilities? Especially when it comes to SAP environments, it’s helpful to look at things from the attacker’s perspective. How far could a potential attacker get with phished credentials? What business risks does this pose, and how seriously do they threaten the company? Such questions can be answered with a penetration test, which not only provides transparency into vulnerabilities that can actually be exploited but also offers prioritized recommendations for action with a clear business impact. At abat, we specialize in these tests – feel free to contact us for more information.

Infostealer Malware: 124 Million Passwords Compromised

On June 15, 2026, the data breach check service HaveIBeenPwned (HIBP) added approximately 56.3 million email addresses and 124 million passwords to its database. The data comes from so-called “stealer logs” – log files generated directly on victims’ devices by infostealer malware. The dataset is based on hundreds of millions of individual log entries; HIBP does not provide any information about their specific origin.

For companies with unhardened SAP environments, this creates several attack vectors: For example, via the proprietary SAP GUI client, operating system commands can be executed on the computers of all logged-in users on a compromised SAP system, using their respective local privileges. An attacker could exploit this vulnerability to install infostealers on end devices and thus attack virtually all of a company’s SAP workstations simultaneously. Compromised credentials and an insecure SAP system are therefore mutually reinforcing.

To proactively prevent attacks using these compromised credentials, companies should identify affected accounts via HIBP, implement security measures as necessary, and consistently roll out multi-factor authentication across all accounts. It is also recommended to actively scan the SAP system landscape for vulnerabilities. An SAP penetration test can determine whether an attacker could gain access to critical systems via these attack vectors.

Contact our expert for cybersecurity