Cyber Threat Intelligence 21 July 2026
-
New Tooling
- New Index Tracks Material Breaches — And Refuses To Add Up The Losses
"A longtime cybersecurity executive has built a website that tracks disclosed material breaches, aiming to give cybersecurity professionals, journalists, policymakers, and everyday citizens a resource that doesn’t currently exist. The tracker was created by Richard Bird, who is currently Chief Strategy and Chief Security Officer at enterprise AI governance company Singulr AI. He previously held leadership roles at JPMorgan Chase and several cybersecurity companies."
https://www.securityweek.com/new-index-tracks-material-breaches-and-refuses-to-add-up-the-losses/ - Capital One Open Sources AI-Powered ‘VulnHunter’ Security Tool
"Financial services giant Capital One has released an internally developed AI-powered security tool to the public as open source. Dubbed “VulnHunter”, the tool was designed to find and fix software vulnerabilities at the code level, but Capital One says it is not a traditional, passive vulnerability scanner. “We designed VulnHunter with a developer-first mindset to solve a massive industry pain point: overwhelming false positives that create friction and slow down daily workflows,” Chris Nims, EVP & Chief Information Security Officer (CISO) at Capital One, explained in a LinkedIn post."
https://www.securityweek.com/capital-one-open-sources-ai-powered-vulnhunter-security-tool/
https://github.com/capitalone/vulnhunter
Vulnerabilities
- Chrome 150 Update Patches Severe Memory Safety Bugs
"Google has released a Chrome 150 security update that resolves seven memory safety bugs, including critical and high-severity use-after-free vulnerabilities. The browser refresh patches three critical-severity use-after-free flaws impacting Chrome’s CameraCapture, GPU, and Network components. All three weaknesses were discovered by Google. Additionally, the update fixes three high-severity use-after-free issues in Cast, Ozone, and Aura; Google discovered these vulnerabilities as well."
https://www.securityweek.com/chrome-150-update-patches-severe-memory-safety-bugs/ - The Week Of Sandbox Escapes
"Over several months, Pillar Research found and reproduced sandbox escapes and boundary bypasses across Cursor, Codex, Gemini CLI, and Antigravity. In almost every case, the agent did not need to break the sandbox directly. It only had to write something that a trusted component outside the sandbox would later run, load, scan, or treat as safe. In aggregate, these vulnerabilities show that AI coding agents change the endpoint threat model, and that most sandbox designs have not caught up."
https://www.pillar.security/blog/the-week-of-sandbox-escapes
https://www.bleepingcomputer.com/news/security/cursor-codex-gemini-cli-antigravity-hit-by-sandbox-escapes/ - Malicious Cloud Customers Can Bring Down The Power Grid
"AI datacenters wreak havoc on the power grid under normal circumstances, so what happens if a bad actor controls all the GPUs and wants to cause harm? Cybersecurity researchers in China have devised a way for malicious tenants to attack their infrastructure provider, potentially causing blackouts or damaging equipment. The attack, dubbed Bit2Watt, imagines an adversary masquerading as a legitimate cloud tenant to launch GPU workloads that have the potential to damage datacenters and supporting electrical systems. It's intended to demonstrate the need to extend cybersecurity defenses to datacenter workload scheduling."
https://www.theregister.com/ai-and-ml/2026/07/20/malicious-cloud-customers-can-bring-down-the-power-grid/5275193
https://arxiv.org/abs/2607.05993
Malware
- Critical ServiceNow Code Execution Flaw Now Exploited In Attacks
"Attackers have begun exploiting a critical vulnerability (CVE-2026-6875) in the ServiceNow AI Platform, according to threat intelligence company Defused. Formerly known as the Now Platform, ServiceNow AI Platform is an enterprise-grade Platform-as-a-Service (PaaS) that helps businesses integrate AI into core enterprise workflows. Cybersecurity company Searchlight Cyber, which found this critical vulnerability and reported it on April 1st, says that it allows unauthenticated threat actors to escape the sandbox and execute code remotely within the ServiceNow platform in high-complexity attacks."
https://www.bleepingcomputer.com/news/security/critical-servicenow-code-execution-flaw-now-exploited-in-attacks/
https://www.helpnetsecurity.com/2026/07/20/servicenow-cve-2026-6875-exploited/ - HOLLOWGRAPH: Turning Microsoft 365 Calendars Into Covert Command-And-Control Channels
"The Group-IB Threat Intelligence team has identified HOLLOWGRAPH, a new malware sample that we attribute, with high confidence, to the Cavern backdoor framework. This malware is one component of a larger toolkit, and it uses the Microsoft Graph API through a compromised Microsoft 365 account observed in Israel to communicate with its operators — a technique that helps conceal command-and-control traffic within legitimate Microsoft 365 communications. The malware supports just two commands, get and send, and executes both exclusively through trusted Microsoft cloud infrastructure. Using the Microsoft Graph API, it treats the compromised mailbox’s calendar as a two-way dead-drop: operators plant tasking as calendar events, and the implant exfiltrates stolen files by creating its own events with encrypted data attached. To avoid catching the mailbox owner’s attention, every event is dated far into the future — 13 May 2050 — with payloads attached as files to the event."
https://www.group-ib.com/blog/hollowgraph-microsoft-365/
https://thehackernews.com/2026/07/hollowgraph-malware-hides-c2-and-stolen.html
https://www.bleepingcomputer.com/news/security/new-hollowgraph-malware-uses-microsoft-graph-for-stealthy-c2-comms/
https://www.infosecurity-magazine.com/news/hollowgraph-microsoft-calendars/
https://www.theregister.com/security/2026/07/20/microsoft-365-calendars-become-spy-drop-boxes-in-hollowgraph-campaign/5274982
https://www.helpnetsecurity.com/2026/07/20/hollowgraph-malware-microsoft-365-calendar/ - Fake Games Spread Stealers With RenPy Loader, MSBuild And EtherHiding
"We have detected several campaigns using fake downloads of games, mods, cracks, and software to spread RenPy Loader. Once installed, the loader starts a complex, multi-stage infection chain that abuses MSBuild and the EtherHiding technique before ultimately delivering Amatera Stealer. Amatera is an infostealer—a type of malware designed to steal sensitive information from an infected device. It can target passwords and other data stored in browsers, cryptocurrency wallets, browser extensions, messaging apps, and local files. Stolen credentials and session data may also allow attackers to access the victim’s online accounts."
https://www.malwarebytes.com/blog/threat-intel/2026/07/fake-games-spread-stealers-with-renpy-loader-msbuild-and-etherhiding - Unpacking “Cruciferra”: An Analysis Of a Sophisticated Crypter Service
"Proofpoint researchers are tracking Cruciferra, a crypter service that is used by multiple unrelated threat actors. Crypters are commonly used within the cybercriminal ecosystem to conceal malicious payloads, evade security controls, and improve malware delivery success rates. During our analysis, Proofpoint researchers identified both production and apparent testing samples, including variants containing debugging functionality and experimental features. Cruciferra is written in Mono and features numerous techniques designed to evade detection, analysis, and incident response efforts."
https://www.proofpoint.com/us/blog/threat-insight/unpacking-cruciferra-analysis-sophisticated-crypter-service
https://www.infosecurity-magazine.com/news/cruciferra-crypter-process-ghosting/ - SleeperGem: Compromised Git_credential_manager, Dendreo, And Fastlane RubyGems Drop a Persistent Backdoor
"Between July 18 and July 19, 2026, malicious versions of three RubyGems packages were published to RubyGems.org in a coordinated supply chain attack that researchers named SleeperGem. The compromised gems are git_credential_manager, which impersonates the official Microsoft Git Credential Manager, along with Dendreo and fastlane-plugin-run_tests_firebase_testlab. Each malicious release is a loader. It fetches a second stage from an attacker controlled Forgejo host, checks whether it is running in a build system and skips if it is, and on a developer machine it drops a native daemon and installs persistence."
https://www.stepsecurity.io/blog/sleepergem-compromised-rubygems-drop-persistent-backdoor
https://thehackernews.com/2026/07/sleepergem-uses-three-malicious.html - JADEPUFFER Evolves: The Agentic Threat Actor Deploys Ransomware Built To Destroy AI Models
"Ransomware operators make a bet that their victims don’t keep backups. In a new development, the operator behind JADEPUFFER has doubled down on that bet, using ransomware to destroy the one thing an organization can’t simply restore: a trained AI model. For organizations, training a single model can cost upwards of $500,000 in compute and engineering alone. On July 1, 2026, the Sysdig Threat Research Team (TRT) documented JADEPUFFER: an agentic threat actor (ATA) that exploited Langflow through CVE-2025-3248."
https://www.sysdig.com/blog/jadepuffer-evolves-the-agentic-threat-actor-deploys-ransomware-built-to-destroy-ai-models
https://www.bleepingcomputer.com/news/security/jadepuffer-agentic-attacks-now-target-ai-model-data-with-ransomware/
https://www.infosecurity-magazine.com/news/jadepuffer-ai-model-ransomware/ - LG Monitors Silently Install Software Through Windows Update Without User Consent
"Connecting some LG monitors to a Windows PC may automatically install software that promotes McAfee subscriptions. Gamers Nexus reproduced the behavior with an LG UltraGear 34GX900A-B after receiving reports from monitor owners."
https://videocardz.com/newz/lg-monitors-silently-install-software-through-windows-update-without-user-consent
https://hackread.com/lg-monitors-install-adware-app-windows-pcs/ - The Odyssey Piracy Scams Appear Within Hours Of The Movie’s Release
"Christopher Nolan’s The Odyssey is one of the biggest movie releases of the year and scammers wasted no time taking advantage of it. Within hours of the film’s release, we found scams targeting people looking for pirated copies. Some used fake browser warnings on piracy sites, while others disguised malware as movie downloads. Some used fake browser error messages designed to funnel people through malvertising networks. Others offered what appeared to be movie downloads that were actually Windows executables disguised as video files."
https://www.malwarebytes.com/blog/threat-intel/2026/07/the-odyssey-piracy-scams-appear-within-hours-of-the-movies-release
https://www.helpnetsecurity.com/2026/07/20/odyssey-movie-piracy-scams-malware/ - Targeted Attack On Government Entities In The Middle East | Part 1
"In July 2026, Zscaler ThreatLabz observed new activity by a threat actor with links to East Asia targeting government entities in the Middle East. During analysis, ThreatLabz captured post-compromise activity and uncovered previously undocumented malware tooling, including TELESHIM, MIXEDKEY, and BINDCLOAK. The campaign used a multi-stage attack chain to establish and maintain access on infected systems, with TELESHIM abusing the Telegram API for command-and-control (C2) communication to blend in with legitimate internet traffic."
https://www.zscaler.com/blogs/security-research/targeted-attack-government-entities-middle-east-part-1 - AgentBaiting: How 800+ Fake AI Skills And MCP Servers Delivered Malware
"Island security research uncovered about 7,600 malicious GitHub repositories, with more than 800 of them posing as AI Skills or MCP servers in a wave that peaked in April 2026. Those AI capability repositories appeared more than 600 times across public AI registries and catalogs, while the wider FakeGit operation recorded more than 14 million measured downloads. FakeGit uses copied projects, lookalike developer profiles, convincing READMEs, and malicious ZIP files to deliver SmartLoader malware. Once executed, SmartLoader establishes persistence and installs StealC, an information stealer targeting credentials, active sessions, and other sensitive data."
https://www.island.io/blog/agentbaiting-how-800-fake-ai-skills-and-mcp-servers-delivered-malware
https://thehackernews.com/2026/07/fakegit-campaign-uses-7600-github.html - From a Single Alert To 1,000 Files: Inside An Exposed WebDAV Malware Delivery Lab
"An MDR alert recently led our team to an exposed server that was doing more than hosting payloads. It was functioning as a fully operational malware delivery lab. Containing over 1,000 artifacts, the infrastructure served as a QA hub where attackers systematically tested delivery paths, social engineering lures, and WebDAV execution methods. Our analysis reveals an interesting shift in adversary operations: attackers are adopting generative AI to move beyond individual exploits and operate like modern software product teams. By leveraging LLMs for rapid lure generation, detailed README documentation, and automated testing, they are significantly accelerating their development cycle."
https://www.rapid7.com/blog/post/tr-exposed-webdav-malware-delivery-lab-analysis/
https://thehackernews.com/2026/07/exposed-server-reveals-ai-assisted.html - Russian Intelligence Hacks IP Cameras To Spy On Military Logistics Across NATO States And Ukraine
"At least one Russian intelligence service is systematically hijacking internet-connected security cameras across Europe and Ukraine, using the feeds to watch military transport routes, weapons shipments bound for Kyiv, and the locations of Ukrainian troops. That is the finding of a cybersecurity advisory published July 10 by the AIVD and MIVD, the Netherlands' civilian and military intelligence services, which describe the operation as ongoing."
https://thehackernews.com/2026/07/russian-intelligence-hacks-ip-cameras.html
https://english.aivd.nl/documents/2026/07/10/brochure-cybersecurity-advisory-russian-state-actors-are-compromising-ip-cameras
https://securityaffairs.com/195708/intelligence/dutch-intelligence-warns-russia-uses-hacked-ip-cameras-for-military-espionage.html
Breaches/Hacks/Leaks
- Software Provider To More Than 2,000 US Hospitals Says Hackers Stole Employee And Customer Data
"A British company whose software is used by thousands of U.S. hospitals said Monday that hackers broke into its internal network and stole data on employees, customers and business partners. Craneware, which is headquartered in Edinburgh and listed on London's AIM market, told investors it detected unauthorized access to a “subset” of its data environment and has since brought in outside forensic investigators. The company said it has reported the incident to the FBI and to Britain’s Information Commissioner’s Office."
https://therecord.media/software-provider-for-us-hospitals-customer-data-breach - Estée Lauder Discloses Data Breach Via Oracle E-Business Flaw
"Cosmetics giant Estée Lauder is notifying customers of a data breach after hackers exploited a flaw in Oracle E-Business Suite that the company used for human resources (HR) operations. The company says that last month it identified an intrusion that had occurred on August 9, 2025, which led to the threat actor obtaining " personal information of certain individuals." “We became aware of a cybersecurity issue involving a vulnerability in the Oracle E-Business Suite system which is used by the Estee Lauder Companies for HR management purposes,” the notification says."
https://www.bleepingcomputer.com/news/security/est-e-lauder-discloses-data-breach-via-oracle-e-business-flaw/ - Hackers Steal $23.7 Million In Crypto From Ostium In Off-Chain Attack
"The Ostium trading platform announced that an attacker stole $23.75 million from its liquidity provider vault last week, after compromising off-chain infrastructure used to feed prices into the protocol. According to an update from the platform yesterday, the attacker submitted illegitimate price reports disguised as valid ones, then rapidly opened and closed large positions to generate artificial profits. Trader collateral was held in a separate contract and was not affected, while existing positions remain open, the company clarified."
https://www.bleepingcomputer.com/news/security/hackers-steal-237-million-in-crypto-from-ostium-in-off-chain-attack/ - Paidwork Breach Exposes Sensitive Data Of 23 Million User
"Data belonging to more than 23 million users has been exposed following a breach at Paidwork, a platform that pays people for completing online microtasks. Paidwork markets itself as a way to earn money through simple tasks like watching ads, testing apps, and completing surveys, with most jobs paying only a few cents at a time. For its users, many of whom are drawn to the platform for small, incremental earnings, the fallout from this breach could end up costing far more than they ever made."
https://www.helpnetsecurity.com/2026/07/20/paidwork-data-breach-23-million-users/ - India Says Allegedly Leaked Nuclear Plant Files Pose No Safety Risk
"India's state-owned nuclear operator said that documents recently posted online and purportedly linked to the country's largest nuclear power plant contain no information affecting safety or security. The statement came after the media reported last week that the cybercrime group World Leaks had published thousands of files apparently connected to the Kudankulam Nuclear Power Plant (KKNPP)."
https://therecord.media/india-nuclear-plant-kudankulam-world-leaks-documents - Hackers Were Inside South Korea's Diplomat Training System For 9 Months
"Unidentified hackers compromised an online education system used by South Korea's diplomatic academy, stealing personal information belonging to former and current employees of the country's Ministry of Foreign Affairs, the department announced Monday. In a data protection notice, the MoFA said the breach of the Korea National Diplomatic Academy's e-learning platform occurred from April 2025 to February 2026, when a related government authority notified the ministry of abnormal access to the system."
https://therecord.media/south-korea-cyberattack-foreign-ministry
General News
- A Forensic Tool For Backdoored Code Completions In AI Assistants
"Developers lean on AI coding assistants for a growing share of their daily work, letting the tools predict the next few lines and accepting many suggestions with a quick glance. Those tools learn from large collections of code, and some of that code can be tampered with before training starts. A poisoned example teaches a model to write insecure code when it sees a certain cue, and the flaw sits quietly until the right prompt sets it off. Most defenses aim to catch this poisoning early, screening training data or scanning outputs for known problems. A team from the University of Louisville and the University of North Texas built a system called CodeTracer for the moment after those defenses let something slip. Their work starts from a model that has already produced a harmful completion. The job is to trace that completion back to the training examples that taught the behavior."
https://www.helpnetsecurity.com/2026/07/20/tracing-backdoored-code-completions/
https://arxiv.org/pdf/2607.08011 - Nearly Half Of Open-Source AI Projects Never Reach Production
"Open models are moving into production across more organizations, and the work of securing those deployments increasingly extends beyond the model weights. Mozilla’s The State of Open Source AI 2026 identifies deployment, governance and operational tooling as persistent obstacles as model capability improves. “Without investment in the infrastructure, tooling, and governance around open models, we risk locking in a system where only restrictive, closed AI can scale – and that doesn’t serve the public interest, or sovereignty over tech policy decisions,” said Raffi Krikorian, Mozilla’s Chief Technology Officer."
https://www.helpnetsecurity.com/2026/07/20/mozilla-open-source-ai-adoption-report/ - Why Blocking AI Models Won’t Stop The Cyber Threats They Create
"2026 has turned out to be the year when predictions about AI-powered cyberattacks, long hypothesized as a potential risk associated with AI improvement, seem to be coming true. New models have capabilities on par with the best human hackers, marking a pivotal window of opportunity in both AI and cybersecurity policy. This is a transitional period where new technologies are pushing existing American cybersecurity infrastructure to the brink. The real question isn’t whether cybersecurity still matters, but rather: How will the risks that AI introduces be managed before they outpace defenses, and who will step up to lead this challenge?"
https://cyberscoop.com/why-blocking-ai-models-wont-stop-cyber-threats-op-ed/ - Remediating Vulnerabilities With LLMs: Inside Ivanti's Automation Push
"Amid growing concern about threats actors using artificial intelligence for cyberattacks, one software vendor is finding success with deploying large-language models (LLMs) for vulnerability remediation. Last month, Ivanti disclosed CVE-2026-10520, a critical maximum-severity flaw in its Sentry mobile gateway product. But the vulnerability, which received a 10 out of 10 CVSS score, wasn't discovered by a security researcher, a third-party vendor, or even Ivanti's own engineers; rather, an LLM was the finder."
https://www.darkreading.com/cybersecurity-operations/remediating-vulnerabilities-llms-ivanti-automation - CISOs Pressured To Stay Silent About Cyber Attacks Need Evidence-Led Governance For Protection
"CISOs are facing growing pressure to stay quiet about cyber incidents despite stricter regulatory demands for transparency. That’s one of the findings from Splunk’s 2026 CISO report, which shows that one in five security leaders have been pressured by their organization not to report incidents or compliance issues. The situation is proving to be so problematic that almost eight in ten (78%) are now concerned about their own liability for security incidents, a sharp spike compared to last year (56%)."
https://www.techradar.com/pro/cisos-pressured-to-stay-silent-about-cyber-attacks-need-evidence-led-governance-for-protection
https://www.darkreading.com/cybersecurity-operations/cisos-feel-heat-ai-risk - Cybersecurity Keeps Events 'Uneventful'
"The threats surrounding major events often begin long before anyone reaches the gate. A compromised hotel system can reveal where athletes, executives, or delegations are staying. A breach involving government or ministry offices can expose schedules and movements. Threats aimed at fan events, themed gatherings, or transit hubs can target the outer ring of security, where crowds are harder to control and attackers may see more opportunity."
https://www.darkreading.com/cyber-risk/cybersecurity-keeps-events-uneventful - Demystifying AI Exploits: A Blueprint For AI-Assisted Vulnerability Management
"As highlighted in the Mandiant M-Trends 2026 report, the mean time-to-exploit (TTE) has dropped to -7 days, meaning vulnerabilities are often exploited a week before a patch even exists. To keep pace, many security teams are exploring how to integrate large language model (LLM) agents into their codebases, development environments and continuous integration and continuous delivery (CI/CD) pipelines for automated vulnerability discovery and remediation. However, deploying privileged artificial intelligence (AI) agents without mature integration processes introduces new architectural risks."
https://cloud.google.com/blog/topics/threat-intelligence/ai-assisted-vulnerability-management
อ้างอิง
Electronic Transactions Development Agency (ETDA)
- New Index Tracks Material Breaches — And Refuses To Add Up The Losses