Newsletter - August 2026

Cybersecurity Newsletter for August 2026
Japan’s latest cybersecurity news, incidents & research — in 2 minutes.
🚨 Major Incidents in Japan
🇯🇵 Sakura Internet — up to 1.36 million accounts potentially affected
Japanese cloud provider Sakura Internet disclosed unauthorized access to a sales-management system that may have exposed information associated with up to 1,360,563 customer accounts. A separate investigation also found unauthorized access involving 583 rental-server accounts.
📖 Read more
🇯🇵 RIZAP / APORITO — customer and payment information potentially exposed
RIZAP disclosed unauthorized access involving the APORITO Online Store. A malicious external-transmission program may have exposed personal information and credit-card information entered by customers between May 1 and August 5, 2026.
📖 Read more
🇯🇵 Chubu Electric — unauthorized access affecting potentially 74,000 people
Chubu Electric Power confirmed unauthorized access to systems using misused credentials. The company said approximately 2,400 employee/executive emails and group contact information may have been accessed, with the broader potentially affected population reported at around 74,000 people. No electricity or gas customer information leakage had been confirmed at the time of the announcement.
📖 Read more
🇯🇵 Nichirei — July attack continues to unfold
The impact of Nichirei’s July cyberattack continued into August. The incident disrupted its logistics operations, while subsequent investigation indicated that employee information stored on compromised servers may also have been exposed.
📖 Read more
📧 KDDI — 12.2 million email addresses exposed
KDDI disclosed that a cyberattack against an email platform operated for ISPs exposed more than 12.2 million email addresses and 7.6 million passwords.
📖 Read more
🐞 Vulnerability Watch
August vulnerability disclosures include issues affecting SKYSEA Client View, Sakura Editor, UNIVERGE routers and other products used in Japan.
For researchers, JVN remains an essential source for Japan-specific vulnerability intelligence.
📖 Read more
🤖 For Bug Bounty Hunters
AI Won’t Replace Bug Hunters — But It Is Raising the Bar
AI is rapidly changing vulnerability research. It can automate reconnaissance, analyze code, generate test cases and help researchers explore attack paths.
But human expertise remains critical.
At Black Hat 2026, researcher James Kettle demonstrated how AI-assisted research helped uncover a novel web attack technique. His work suggests that the strongest results currently come from human researchers directing AI, rather than fully autonomous systems.
At the same time, AI-generated submissions are creating a new challenge for bug bounty programs. Apple has reportedly introduced limits on vulnerability submissions after receiving a surge of low-quality or unverified AI-generated reports.
Research is also moving beyond finding vulnerabilities toward automatically exploiting them. The ExploitGym benchmark evaluated AI agents against 898 real-world vulnerabilities, testing whether they could turn known vulnerabilities into working exploits.
The takeaway
Use AI to increase your speed — not to replace your thinking.
The skills that matter increasingly are:
- 🧠 Understanding application logic
- 🔗 Chaining vulnerabilities
- 🎯 Finding unusual attack paths
- ✅ Validating findings and impact
- 📝 Producing clear, reproducible reports
As AI increases the volume of vulnerability discovery, signal becomes more valuable than noise.
📖 Recommended Reading
- WIRED — The Most Dangerous AI Hacking Techniques Still Have Humans in the Loop
- WIRED — The AI Era Is Creating a Bug-Hunting Arms Race
- Financial Times — Apple struggles to keep pace with AI ‘bug’ hunters
- ExploitGym — Can AI Agents Turn Security Vulnerabilities into Real Attacks?
- Financial Times — ‘Never-ending’ AI slop strains corporate hacking reward programmes
💡 Security Tip
August’s incidents show that security doesn’t stop at your own network. Assess SaaS providers, e-commerce platforms, cloud infrastructure, suppliers and third-party credentials as part of your attack surface.
🚀 BBHunt Japan
📬 Subscribe to our newsletter: https://bbhunt.jp/index.html#newsletter
Follow us for the latest cybersecurity news, vulnerability disclosures, and platform updates.