August Patch Tuesday delivered a materially different story than Monday's preview suggested: Lazarus Group deployed the FudModule kernel rootkit via an actively exploited WinSock zero-day, while VMware vCenter reached 361 victims in 47 countries within five days of disclosure.
The economic case for DLP rested on a stable ratio between attacker cost per exfiltration event and defender cost per prevented event. Six weeks of pipeline data show that ratio fully inverted. Large language models collapsed attacker cost to a prompt; defender cost has not moved. DLP programs that have not restructured their architecture are now structurally underwater, and five independent exfiltration channels are the evidence.
The rapid exploitation of CVE-2026-42208 in LiteLLM marks the first confirmed weaponization of the AI API proxy layer, while TeamPCP's new ransomware partnership turns out to be a wiper with no recovery path.