Cyber Threat Intelligence 30 July 2026
-
Energy Sector
- The Energy Sector’s OT Cybersecurity Talent Is Retiring Faster Than It Can Be Replaced
"A ransomware hit lands a chemical plant in a safe state. Nobody is hurt, the site holds steady, and the operators begin the restart. The systems stay down. Every attempt to bring them online meets encrypted processes and altered configurations. The outage runs into weeks, and the losses travel down the supply chain in both directions. Refineries, chemical plants and pipeline operators carry this exposure across control systems that run 20 to 40 years."
https://www.helpnetsecurity.com/2026/07/29/ot-cybersecurity-in-energy/
Healthcare Sector
- Health-ISAC Warns Of Rising ShinyHunters Data Theft Attacks On Healthcare
"Health-ISAC, a cybersecurity information-sharing organization for the health sector, is warning healthcare and medical technology organizations of an observed increase in successful attacks by ShinyHunters. ShinyHunters is an extortion gang that primarily conducts supply chain and identity attacks to breach cloud SaaS and storage platforms in data theft attacks. Over the past two years, the threat actors have become notorious for conducting numerous supply chain attacks on third-party integration partners. These breaches give them access to OAuth tokens that are used to integrate with SaaS providers like Salesforce and Snowflake."
https://www.bleepingcomputer.com/news/security/health-isac-warns-of-rising-shinyhunters-data-theft-attacks-on-healthcare/
https://health-isac.org/shiny-hunters-impact-to-health-sector-and-recommended-mitigation-strategies/
Industrial Sector
- Siemens Desigo CC
"OpenSSL has published a stack based buffer overflow vulnerability that allows a remote attacker to cause a denial of service (DoS) or potentially allow for remote code execution. Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends countermeasures for products where fixes are not, or not yet available."
https://www.cisa.gov/news-events/ics-advisories/icsa-26-209-01 - Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP
"Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.6 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant). Siemens is preparing fix versions and recommends specific countermeasures for products where fixes are not, or not yet available."
https://www.cisa.gov/news-events/ics-advisories/icsa-26-209-04 - Siemens Mendix Runtime
"Mendix documentation for access rules does not adequately describe the special behavior of the System.User entity, leaving developers without sufficient guidance to configure access rules securely. This documentation gap may lead application developers to unknowingly apply overly permissive access rules to System.User, resulting in unintended exposure of sensitive user data or privilege escalation within deployed Mendix applications. A common misconfiguration identified is with the anonymous user role with a System.User entity to gain access to all stored records, even though no access rights are explicitly configured on that role. Siemens recommends Mendix developers to review their access rules based on updated documentation."
https://www.cisa.gov/news-events/ics-advisories/icsa-26-209-02 - MikroTik RouterOS And Cloud Hosted Router
"Successful exploitation of this vulnerability could allow attackers to rapidly guess passwords and gain unauthorized system access."
https://www.cisa.gov/news-events/ics-advisories/icsa-26-209-05 - Siemens SIMATIC S7-PLCSIM Advanced
"SIMATIC S7-PLCSIM Advanced contains a vulnerability that could allow an attacker to cause a denial of service condition. Siemens is preparing fix versions and recommends specific countermeasures for products where fixes are not, or not yet available."
https://www.cisa.gov/news-events/ics-advisories/icsa-26-209-03 - Igloohome Smart Lock Mobile Application
"Successful exploitation of this vulnerability could allow an unauthorized actor to access functions or backend services."
https://www.cisa.gov/news-events/ics-advisories/icsa-26-209-06 - ABB KNX Update Tool
"ABB has been contacted by a researcher who identified a vulnerability in one of its products. ABB has been contacted by a researcher who identified a vulnerability in one of its products. The vulnerability report has been shared in responsible disclosure. An attacker who successfully exploited this vulnerability could cause the product to become unusable. ABB confirms the vulnerability but at the same time acknowledges that the issue affects exclusively classic KNX devices that are not supporting the latest KNX Secure standard. Due to a lack of security in legacy KNX devices, the issue cannot be resolved via a software change. In order to actively exploit this vulnerability, an attacker requires physical access to the bus, the affected device is connected to. ABB has no plans of corrective measures."
https://www.cisa.gov/news-events/ics-advisories/icsa-26-209-07
New Tooling
- Specter: Open-Source NFC Reader Bug Sweep For Flipper Zero
"Specter is a Flipper Zero app that finds powered NFC readers by listening for the radio field they give off. The readers it hunts work at 13.56 MHz. The onboard ST25R3916 carries a hardware external-field detector, the same circuit that lets the device emulate a card and register when a reader starts talking to it. Specter reads that one bit, hundreds of times a second, with its own transmitter dark."
https://www.helpnetsecurity.com/2026/07/29/specter-flipper-zero-skimmer-detector/
https://github.com/at0m-b0mb/Specter-FlipperZero
Vulnerabilities
- RufRoot: The MCP Bridge Vulnerability That Turns Agents Into Rogue Admins (CVE-2026-59726)
"Noma Labs found a critical (10 CVSS) vulnerability in Ruflo, an open source AI agent orchestration platform with more than 67,000 GitHub stars at the time of this writing and ranked #2 on MCPMarket. Ruflo ships with a chat UI, agent swarms, persistent memory, and MCP-based tool calling. The platform’s MCP Bridge, the Express.js server that handles all tool invocations, exposes 233 tools over HTTP with zero authentication. Noma Labs researchers got one of those tools to run arbitrary shell commands. A single unauthenticated HTTP POST request to port 3001 gave full command execution inside the container. No token, no API key, no header check, no IP allowlist. Nothing."
https://noma.security/blog/rufroot-the-mcp-bridge-vulnerability-that-turns-agents-into-rogue-admins-cve-2026-59726/
https://www.darkreading.com/cyber-risk/patch-resistant-rufroot-flaw-malicious-ai-agent-swarms
https://thehackernews.com/2026/07/ruflo-mcp-flaw-lets-unauthenticated.html
https://hackread.com/rufroot-vulnerability-attackers-hijack-ruflo-login/ - Three Critical VMware Flaws Allow Auth Bypass, Code Execution, And VM Escape
"Broadcom has released security updates to address multiple security flaws impacting VMware ESX, vCenter, Workstation, and Fusion, three of which have been designated as critical in severity. The first of the three critical-rated flaws is CVE-2026-59309 (CVSS score: 9.8), which has been described as an authentication bypass in VMware vCenter. "A malicious actor with network access to vCenter may exploit this issue to bypass authentication and gain unauthorized access to the system," Broadcom said."
https://thehackernews.com/2026/07/three-critical-vmware-flaws-allow-auth.html
https://www.securityweek.com/critical-vm-escape-vulnerability-patched-in-vmware-esxi/
https://securityaffairs.com/196231/security/broadcom-patches-critical-vmware-esxi-vulnerability-enabling-host-code-execution.html - Critical Rails Flaw Could Let Unauthenticated Attackers Read Server Files Via Image Uploads
"Ruby on Rails has released fixes for a critical Active Storage vulnerability that could let unauthenticated attackers read arbitrary files from application servers through crafted image uploads. Tracked as CVE-2026-66066 (CVSS score: 9.5), the flaw can expose the Rails process environment and secrets such as secret_key_base, the Rails master key, database passwords, cloud storage credentials, and API tokens. Those secrets may enable remote code execution (RCE) or lateral movement into connected systems. Affected applications use libvips for Active Storage image processing and accept image uploads from untrusted users. Rails selects Vips under load_defaults 7.0, and later defaults retain it."
https://thehackernews.com/2026/07/critical-rails-flaw-could-let.html - New Gitea RCE Lets Repository Writers Plant a Git Hook To Run Shell Commands
"Gitea, the self-hosted Git platform, has patched a critical remote code execution vulnerability. A user with ordinary repository write access can turn attacker-controlled patch content into a live Git hook and run shell commands as the Gitea service account. Tracked as CVE-2026-60004 (CVSS score: 9.8), the flaw affects Gitea versions 1.17 and later before 1.27.1 and is fixed in 1.27.1. The vulnerable API call requires authentication and repository write permission. But Gitea enables registration by default, so an outside visitor can create a normal account and repository on an unchanged installation, then exploit the bug without pre-existing credentials."
https://thehackernews.com/2026/07/new-gitea-rce-lets-repository-writers.html - CISA Adds One Known Exploited Vulnerability To Catalog
"CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
CVE-2026-20316 Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability"
https://www.cisa.gov/news-events/alerts/2026/07/29/cisa-adds-one-known-exploited-vulnerability-catalog - Cisco Warns Of FMC Static Credential Flaw Exploited In Zero-Day Attacks
"Cisco is warning that a high-severity Secure Firewall Management Center (FMC) static credential vulnerability, tracked as CVE-2026-20316, was actively exploited in zero-day attacks to gain unauthorized access to vulnerable devices. The vulnerability is caused by static credentials for a low-privilege account built into Cisco Secure FMC Software. Cisco says an unauthenticated, remote attacker can use these credentials to log in to an affected system and access sensitive data available to the account."
https://www.bleepingcomputer.com/news/security/cisco-warns-of-fmc-static-credential-flaw-exploited-in-zero-day-attacks/ - An AI Agent Can Pass Every Safety Check And Still Leak Secrets
"A pull request lands with a tidy bug report in the description. A bot reads it before any person does, pulls a few shell commands out of it, gets them approved, and posts the output back on the thread. The maintainer reads the whole exchange the next morning. Elad Meged, a founding engineer at Novee Security, ran that sequence against three vendors’ own repositories, in the configurations those vendors ship by default. Anthropic’s pipeline handed over secrets. Any organization running one of these agents out of the box carries the same exposure."
https://www.helpnetsecurity.com/2026/07/29/ai-agent-security-safety-check/ - Android Malware Detection Collapses When The Context Stage Comes Out
"A phone backup app asks for storage, contacts, SMS, and call logs. A device-management tool asks for more than that. Run either one past a machine learning malware scanner and it comes back flagged. Six Android detectors in wide research use, including Drebin, MalScan, and MaskDroid, produced that result on more than half the apps in a benign test set assembled from 49 Google Play categories. The worst performer, an LLM-based detector called LAMD, flagged 80% of them. Anyone gating an app store, an enterprise deployment, or a build pipeline on those verdicts is working a queue made mostly of legitimate software."
https://www.helpnetsecurity.com/2026/07/29/android-malware-detection-research/
https://arxiv.org/pdf/2607.23272 - Researchers Show a Single Malicious Webpage Visit Can Compromise Tor Browser
"Nebula Security says a patched Firefox JIT flaw could be triggered by simply visiting a malicious webpage and was also used to compromise Tor Browser. Tracked as CVE-2026-10702, the bug provides arbitrary code execution inside the browser's renderer process. Mozilla rated it High and fixed it in the Firefox 151.0.3 update. "No settings or additional user interaction are required," Eten Zou, CEO of Nebula Security, told The Hacker News. "Visiting a malicious webpage is enough to trigger it," Zou said every Tor Browser release that incorporated a vulnerable Firefox version was affected, though researchers have not identified the exact Tor releases."
https://thehackernews.com/2026/07/researchers-show-single-malicious.html - Check Point SmartConsole Authentication Bypass Technical Analysis (CVE-2026-16232)
"On July 22, 2026, Check Point published a security advisory for CVE-2026-16232, an authentication bypass in the SmartConsole login process affecting Security Management Server and Multi-Domain Security Management Server (MDS). By leveraging CVE-2026-16232, an unauthenticated attacker can obtain an application login token, use this token to log in through SmartConsole with full administrator privileges, and modify the security policy or security configuration. Exploitation requires network access to the Management Server and for a Trusted Clients configuration that does not restrict GUI clients, which in our testing was a default setting. This vulnerability was reported as being exploited in the wild as a zero-day vulnerability at the time of disclosure."
https://www.rapid7.com/blog/post/ra-check-point-smartconsole-authentication-bypass-technical-analysis-cve-2026-16232/
https://thehackernews.com/2026/07/rapid7-releases-poc-for-exploited-check.html
Malware
- Case Study: Targeted Attack Case On An MS-SQL Server Involving The Installation Of GotoHTTP And SoftEther VPN
"While monitoring attack cases targeting MS-SQL servers, the AhnLab SEcurity intelligence Center (ASEC) identified an instance in which the Larva-26009 threat actor installed the XMRig CoinMiner. While the installation of CoinMiner is common in attack cases targeting MS-SQL servers, in this particular attack case, the attacker installed VShell and GotoHTTP to gain control over the infected system and also installed SoftEther to use it as a VPN server."
https://asec.ahnlab.com/en/94685/ - Cleaning Out Inboxes: TA488 Comes For Outlook With Another Half-Click Exploit
"On 22 July 2026 (the day prior to Proofpoint’s joint release with the NSA), TA488 initiated a new wave of exploitation abusing a cross-site scripting (XSS) vulnerability, CVE-2026-42897, in Outlook Web Access (OWA). Proofpoint did not have sufficient time to analyze, action, and incorporate the new activity into existing reporting, so we are issuing a rapid follow-up to highlight this activity. TA488 used a series of compromised accounts to send emails exploiting a vulnerability in Outlook Webmail. The campaign targeted entities in the government, telecommunications, finance, hospitality, and aerospace sectors. The volume of messages and breadth of targeting is unusual for TA488 and may have been intentionally broad to blend in with mass-mailing spam and avoid scrutiny."
https://www.proofpoint.com/us/blog/threat-insight/cleaning-out-inboxes-ta488-comes-outlook-another-half-click-exploit
https://www.bleepingcomputer.com/news/security/russian-hackers-exploit-exchange-owa-zero-day-for-long-term-mailbox-access/
https://therecord.media/russia-hackers-outlook-webmail-malware
https://www.infosecurity-magazine.com/news/ta488-outlook-half-click-owareaper/ - Amazon Identifies North Korean Hacker Group Behind Open-Source Supply Chain Attacks
"Amazon is sharing new findings about how a threat actor linked to the Democratic People’s Republic of Korea (DPRK) is targeting open source software libraries, the shared building blocks that companies around the world use to develop applications. Amazon Threat Intelligence has linked several recent compromises of popular Node Package Manager (NPM) libraries to the same DPRK-linked threat actor, a connection that hasn’t been publicly reported until now. The analysis also describes how generative AI is already changing what malicious software packages look like and how threat actors are beginning to probe AI-based code systems. We’re sharing this research to help the open source community and security teams better identify and address these types of events."
https://aws.amazon.com/blogs/security/amazon-identifies-north-korean-hacker-group-behind-open-source-supply-chain-attacks/
https://www.bankinfosecurity.com/north-korea-behind-slew-javascript-supply-chain-hacks-a-32366
https://cyberscoop.com/amazon-north-korea-open-source-software-attacks/ - Attackers Are Turning Microsoft’s Trusted Login System Into Their Latest Phishing Weapon
"Attackers are increasingly abandoning fake Microsoft login pages in favor of abusing Microsoft’s legitimate authentication infrastructure, allowing phishing campaigns to bypass many of the warning signs employees have been trained to recognize. Starting on June 25th through the second week of July, we identified more than 200 phishing emails targeting users across approximately 120 organizations, spanning a wide range of industries and countries worldwide. The messages impersonated Microsoft Teams task notifications from HR and directed recipients to a legitimate Microsoft sign-in page."
https://blog.checkpoint.com/email-security/attackers-are-turning-microsofts-trusted-login-system-into-their-latest-phishing-weapon/ - Huntress Threat Advisory: Widespread SonicWall Credential Stuffing Campaign
"Starting on July 25, 2026, at approximately 18:02:21 UTC, the Huntress SOC detected an out-of-the-ordinary spike in successful SonicWall VPN and firewall logins. These logins originated from a suspicious Autonomous System Number (ASN). We did not observe any post-compromise hands-on-keyboard activity from these attacks. Rather than a highly targeted strike on a single entity, our analysis indicates that this campaign is a broad, opportunistic attack. The threat actors are casting a wide net, systematically validating credentials against remote access portals to compromise as many vulnerable accounts as possible across unrelated organizations."
https://www.huntress.com/blog/sonicwall-credential-stuffing-campaign
https://cyberscoop.com/sonicwall-credential-attacks-vpn-firewall/ - Ad Account Theft: The Digital Advertising Commodity Fueling Global Fraud
"Over four years, Mimecast has tracked 6.4 million detections of the systematic theft of Meta Business Manager and Google Ads accounts. This is a widespread commodity crime in the advertising ecosystem where threat actors drain business budgets, when possible, but what they really trade on is account reputation. Aged Business Managers and Google Ads accounts with clean spend history are graded, sold, and reused in a mature underground market with tiered pricing, escrow, and money-back warranties. Unlike card fraud, where chargeback and zero-liability protections exist, platforms offer no equivalent — and have a structural financial incentive not to act quickly."
https://www.mimecast.com/threat-intelligence-hub/ad-account-theft/
https://www.helpnetsecurity.com/2026/07/29/ad-account-theft-meta-google/ - Threat Spotlight: LogoKit Phishing Service Becomes a Cloud-Based, Real-Time Deception Platform
"The evolution of LogoKit highlights how phishing platforms continue to evolve and what this means for defenders and their security strategies. Barracuda researchers have analyzed recent LogoKit campaigns. The attacks feature common phishing themes, such as warnings about passwords or certificates expiring or other access restrictions, delivery failures, timesheet updates, and ICANN email verification notices — but the techniques used are very different."
https://blog.barracuda.com/2026/07/29/logokit-phishing-service-real-time-deception-platform
https://www.infosecurity-magazine.com/news/logokit-phishing-real-time/ - FunFoneFarm And The Off-The-Shelf Scam Economy
"New research from HUMAN’s Satori Threat Intelligence and Research Team exposes a deep ecosystem enabling threat actors to design, launch, and automate common scams, including romance and adult-content scams, pig-butchering scams, and astroturfed social media accounts. These scams are operated on phone farms sold as kits on open and dark web marketplaces, the farms are automated with AI interfaces, and the scams often use AI in their design and operation, significantly lowering the barrier to entry for would-be threat actors and commoditizing cybercrime."
https://www.humansecurity.com/learn/blog/funfonefarm-off-the-shelf-scam-economy/
https://www.infosecurity-magazine.com/news/researchers-aienhanced-phone-fraud/ - Flying Eagle Android RAT: Leaked Source Code, 170 Active Servers, And a New Platform Called Night Dragon
"While conducting routine open-source research, NetAskari identified a malicious Android APK impersonating a Chinese Provincial Public Security Bureau service app. Analysis of the malware led to a Telegram channel distributing the source code for an undocumented Android application builder and device control framework called Flying Eagle (飞鹰). Hunt.io researchers pivoted on TLS certificates and panel fingerprints to identify 170 servers running the framework, and uncovered a fractured criminal ecosystem built around its leaked codebase."
https://hunt.io/blog/flying-eagle-android-rat-170-servers-night-dragon
https://thehackernews.com/2026/07/flying-eagle-android-rat-traces-found.html
https://www.darkreading.com/endpoint-security/flying-eagle-mobile-rat-builder-china - Nine-Year Fraud Campaign Clones Russian Company Sites To Steal Advance Payments
"Cybersecurity researchers have disclosed details of a large-scale fraud campaign that involves creating lookalike websites of major Russian companies with an aim to siphon funds from international firms for more than nine years. According to Russian cybersecurity vendor F6, the threat actors have set up clone websites of Russian companies across fertilizer manufacturers, petrochemical companies, metallurgical plants, logistics operators, and banks. The operation has been ongoing since 2017."
https://thehackernews.com/2026/07/nine-year-fraud-campaign.html - Two Joyfill Npm Beta Releases Compromised To Deliver DEV#POPPER Remote Access Trojan
"Two npm beta releases in the @joyfill namespace contain an import-time JavaScript implant that resolves encrypted code through Tron, Aptos, and BNB Smart Chain transactions. Static analysis shows that its primary branch reaches a 77 KB Node.js remote-access trojan. A parallel branch launches a detached Node.js process, requests a separate boot payload from 23[.]27[.]13[.]43/$/boot, sends the marker header Sec-V: A9-0135-3, decrypts the response, and evaluates it."
https://socket.dev/blog/joyfill-npm-beta-releases-compromised
https://thehackernews.com/2026/07/two-compromised-joyfill-npm-packages.html - Distributed Npm Package Cluster Delivers Cross-Platform RAT Targeting Alibaba Developers
"Analysis of a malicious npm package lib-mtop containing a simple downloader malware led to an investigation into a targeted campaign that remained undetected for 3 months. The lib-mtop package, originally published three years ago, had three new versions published at the end of March, 2026. This indicates a potential maintainer account takeover, but the possibility of a maintainer going rogue can’t be excluded. Whichever the case, it is not that relevant for the story, since there was only one version of the lib-mtop package initially published, with no functionality and an insignificant number of downloads."
https://socket.dev/blog/npm-rat-targets-alibaba - Tracking Over 35,000 Fake Sites In The 2026 World Cup Scam Wave
"From June 11 to July 19, 2026, the 2026 FIFA World Cup took place, co-hosted by the United States, Canada, and Mexico, drawing attention from fans around the world. Large-scale events like this are prime targets for cybercriminals, and online scams exploiting the tournament have been observed worldwide. This article explains the scam techniques TrendAI
has identified and what internet users should watch out for. It bears emphasizing that these scams merely impersonate FIFA, its affiliated organizations, official tournament partners, and legitimate broadcasters and video streaming services, none of which are in any way involved in the scams themselves."
https://www.trendmicro.com/en_us/research/26/g/tracking-fake-sites-in-the-2026-world-cup-scam-wave.html
Breaches/Hacks/Leaks
- Cloud ShutterGap: Millions Of Cloud Resources Exposed - The Blind Spot CSPM/CNAPP Tools Don’t Cover
"Aryon's research reveals millions of misconfigured ephemeral cloud resources, publicly exposed for only moments before being removed. Often, these exposures last only a few minutes, long enough for attackers to discover and exploit them, but too short for traditional CSPM and CNAPP tools to detect. Many of these resources contain highly sensitive information."
https://www.aryon.security/resource/shuttergap-millions-cloud-resources-exposed
https://www.helpnetsecurity.com/2026/07/29/cspm-blind-spot-report/ - A “No-Logs” VPN That Kept 58 Million Connection Logs: Inside The NotVPN / SplitVPN Breach
"On the carding and data-leak forum Altenen (ATN), a long-tenured user operating under the handle vhacker51 posted a thread titled “SplitVPN (NotVPN) 23.4M users, 58M logs, 13.6M devices.” The listing describes the target as “a Russian VPN service for bypassing blocks, with users from Russia, Iran, India, Myanmar,” gives a dump date of 21 July 2026, and offers a compressed SQL file for download. The leak has since been picked up publicly by breach-tracking accounts such as Dark Web Informer. We don’t link to the download, name victims, or reproduce personal data in this write-up. What follows is a verification exercise: does the stolen database actually contain what the seller claims, and what does it reveal about how the service treated its users?"
https://www.mysteriumvpn.com/blog/news/notvpn-splitvpn-breach-58-million-logs
https://securityaffairs.com/196197/security/vpn-breach-exposes-58-million-connection-logs-despite-no-logs-claims.html - Cyberattack Hits Angola’s Largest Telco Hours Before Landmark Stock Debut
"Angola’s largest telecommunications operator, Unitel, said Tuesday it was hit by a cyberattack in the early hours of the morning that has left millions of people nationwide without voice services, mobile data, and internet access. The attack struck less than 24 hours before the formerly state-owned company was due to make its landmark debut on the country’s stock exchange. Unitel said it detected the incident shortly after 2 a.m. local time. “Response and containment mechanisms were immediately activated, and technical and cybersecurity teams were mobilized” to mitigate the incident and restore services, the company said."
https://therecord.media/angola-unitel-cyberattack-outage
General News
- OpenAI Agent Used Exposed Credentials At 4 Services In Hugging Face Breach
"In a new update, OpenAI says its AI models also used publicly exposed credentials to compromise accounts on four third-party services during the recent attack on Hugging Face, expanding the scope of the four-day security incident to other organizations. One account was used as an outbound relay and staging server during the attack, while another was used for data storage. The remaining two accounts were accessed in a read-only manner and were not used to compromise Hugging Face further. Overall, the agent assembled attack infrastructure similar to what human threat actors commonly use during intrusions to host tools and scripts, relay traffic, and route malicious activity through legitimate online services."
https://www.bleepingcomputer.com/news/security/openai-agent-used-exposed-credentials-at-4-services-in-hugging-face-breach/
https://www.reuters.com/business/openais-rogue-agent-compromised-an-account-second-tech-firm-sources-say-2026-07-28/
https://thehackernews.com/2026/07/openai-agent-used-exposed-credentials.html
https://www.darkreading.com/application-security/openai-rogue-model-claims-more-victims-beyond-hugging-face
https://therecord.media/openai-says-rogue-agent-behind-hugging-face-hack-broke-into-additional-services
https://www.securityweek.com/openais-rogue-ai-ventured-beyond-hugging-face/
https://securityaffairs.com/196209/ai/openais-rogue-ai-agent-breached-second-company-report-says.html - The Evolution Of Remote Access Tool Abuse: From Single Payloads To Multi-Stage Campaigns
"Cofense Intelligence has observed threat actors abusing legitimate remote access tools (RATs) using multiple attack stages to gain malicious access to victim machines, establish persistence in enterprise networks, and sell access to infected machines and networks. This type of attack has become increasingly common in early 2026. The attack chain for these multi-stage attacks typically starts with a phishing email containing an embedded link that leads to a malicious website. The malicious website then delivers the RAT onto the victim’s machine. When the RAT is installed, it reaches out to a command-and-control (C2) server."
https://cofense.com/blog/the-evolution-of-remote-access-tool-abuse - Red Agents Vs. Blue Agents: How To Make AI Better At Defense
"Testing AI-based security systems can be tough amid growing fears about agents cheating, hallucinating, and escaping containment, but a group of researchers believe they've found a way to better measure the effectiveness of agentic defenders. Earlier this year, Dreadnode, an AI offensive security startup, released two open source tools designed to help users evaluate the security agents deployed in their networks. The first is DreadGOAD, a reproducible Active Directory training environment that's designed to replicate "the messy deployments still common in large organizations," according to the company."
https://www.darkreading.com/cybersecurity-operations/red-agents-vs-blue-agents-make-ai-better-defense - When AppSec Scanners Become a Supply Chain Attack Vector
"Specialized application security scanning tools embedded in the development pipeline can do wonders to harden code and bolster software supply chain security. But if engineering teams aren't careful, these security scanners can also become a gateway for attacks deep in the supply chain. Last spring, the development and security worlds saw that scenario play out with broad supply chain attacks that compromised development environments for two different security open source projects, which served up poisoned versions of Trivy and KICS to unsuspecting software engineering teams. The attacks were part of broader supply chain attacks by TeamPCP to commit widespread credential theft and fraud."
https://www.darkreading.com/application-security/when-appsec-scanners-become-supply-chain-attack-vector
อ้างอิง
Electronic Transactions Development Agency (ETDA)
- The Energy Sector’s OT Cybersecurity Talent Is Retiring Faster Than It Can Be Replaced