July 17, 2026
Live SonicWall Exploitation, a New C2 Release, and AI Agents Tricked Into Running Attacker Commands
66 of 68 sources → 479 gathered → 400 triaged → 46 clustered → 46 written
Broad-scale exploitation of a SonicWall SSL-VPN flaw kicked off overnight off the back of a public PoC. Elsewhere, Nighthawk shipped a major C2 update, two of the UK’s leading Scattered Spider members were sent to prison, and fresh research showed how planted “facts” can steer AI agents into clicking and executing on an attacker’s behalf.
Vulnerabilities & Exploits
- SonicWall SMA1000 SSL-VPN appliances are under broad-scale exploitation via CVE-2026-15409, with watchTowr’s honeypot network logging activity from ~03:00 UTC leveraging publicly available PoC code (watchTowr); Rapid7 published a working non-root RCE PoC (GitHub). This follows the SMA1000 zero-days added to CISA KEV earlier this week (earlier coverage). watchTowr’s advice: patch immediately and hunt logs for successful exploitation.
- SonicWall’s July patch for the in-the-wild ADFS bug CVE-2026-56155 does not actually fix the vulnerability — it only adds an audit log, with the hardening enforcement deferred, per Kevin Beaumont (Gossi) (discussion).
- CISA ordered federal agencies to patch an actively exploited critical Oracle E-Business Suite flaw by Saturday (BleepingComputer).
- A local privilege escalation PoC dropped for CVE-2026-58635, a Windows Narrator Braille bug (GitHub).
- Shark robot vacuums are exposed to region-wide RCE: pulling the certificate off an RV2320EDUS’s flash lets an attacker run root commands on other Sharks across the same AWS region — camera, movement, house maps, and plaintext Wi-Fi passwords. Still unpatched (tokay0, The Hacker News) (discussion).
- OpenSSL “HollowByte” is a remote DoS triggered by an 11-byte malformed TLS header that drives memory exhaustion and server lockup; fixed in v4.0.1 and backports (Okta Security).
- An n8n token-exchange flaw could let an attacker log in as a user from another issuer (The Hacker News).
New Tools & Releases
- Nighthawk 1.0 “Apex” shipped with a cross-platform Avalonia UI (split consoles, team-shared XML themes), new CET-compatible call-stack masking modes (
gadgetsandsyscalls) with customizable synthetic frames, an improved BOF/PE/COFF loader, and new payload and persistence options (Nighthawk C2). - A curated collection of Windows process-injection techniques was published — a handy reference for offensive tooling and detection engineering alike (GitHub).
- LLMVault, an offline Flask-based CTF platform for the OWASP LLM Top 10, offers tiered labs across prompt injection, RAG, and agent security for hands-on AI-security training (GitHub, write-up).
- Cynative is an open-source, read-only, sandboxed “deep research” agent that uses frontier LLMs to analyze cloud, code, and Kubernetes with strict access controls and evidence-based findings (GitHub, Help Net Security).
Detection & Purple Team
- iPurpleTeam published a detection approach and emulation playbook for abusing QoS policies to throttle EDR traffic — the latest in a line of legitimate-functionality abuses (AppLocker, firewall rules) that starve telemetry (ipurple.team).
AI & Model Security
- New research on agent data injection shows AI agents can be steered without hijacking their task: a single planted product review can make a shopping agent click “Buy Now,” and a fake GitHub comment can make a coding assistant run a stranger’s command — the attack corrupts the facts the agent trusts (The Hacker News). Related, Embrace The Red detailed an indirect-prompt-injection-to-DNS-exfiltration chain via ANSI escape codes, and noted Apple has now fixed the underlying macOS Terminal behavior (Embrace The Red).
- A flaw in Anthropic’s Claude for Chrome extension lets a malicious extension simulate user clicks to trigger predefined AI actions, abusing Claude’s access to Gmail, Google Docs, Calendar, and Salesforce (BleepingComputer).
- Hidden text “salting” is quietly beating AI/LLM email filters at scale, with 1M+ phishing emails using invisible characters to slip past inspection (Dark Reading).
- Leaked Suno source code allegedly reveals the AI music generator scraped decades of music and podcasts from YouTube, Deezer, and Genius for training (404 Media, SC Media) (discussion).
- xAI open-sourced its 844K-line Rust Grok Build CLI under Apache 2.0 and says it deleted retained user data, after the tool was caught silently uploading entire repos — including SSH keys and password databases — to a Google Cloud bucket (The Decoder, CyberInsider) (earlier coverage) (discussion).
- Moonshot’s Kimi K3 (2.8T params, 1M context) is topping arenas and closing on GPT-5.6 Sol and Fable 5, with full open weights due by July 27 — reviving open-weights governance questions (jailbreak resistance, pre-clearance) that Ethan Mollick notes remain entirely unsettled for open models (The Decoder, Simon Willison) (discussion). Separately, Mira Murati’s Thinking Machines Lab released Inkling, a 975B open-weights model leading US open models but still trailing top Chinese labs (The Decoder).
Threat Activity
- Scattered Spider members Owen Flowers (18) and Thalha Jubair (20) were each sentenced to 5.5 years — the UK’s largest cybercrime prosecution — for the 2024 Transport for London ransomware attack that hit 7 million users and cost TfL £29M (The Record, BleepingComputer, The Register).
- Sandworm is using a fake-CAPTCHA lure against Ukrainian victims — instead of verifying they’re human, users are instructed to paste a malicious PowerShell command into Windows (The Record).
- UAT-11795, a Russian-speaking financially motivated actor, is trojanizing WebEx and Zoom installers to deploy the new in-memory Python Starland RAT and a bespoke PowerShell C2 implant (WLDR), targeting US and European victims for credential and crypto theft (Cisco Talos, BleepingComputer).
- The China-linked Daxin kernel rootkit has resurfaced after four years inside a Taiwan manufacturer, paired with a previously unreported pre-login SYSTEM backdoor dubbed Stupig (The Hacker News, SC Media).
- A new ClickFix campaign delivering the modular TELEPUZ malware leverages on-the-fly WebAssembly and SVG steganography from compromised legitimate sites, using fake verification pages that instruct victims to paste into the Run dialog (Unit 42, Elastic Security Labs, The Hacker News).
- Microsoft Defender Experts reported an ACR Stealer surge (late April–mid-June) using ClickFix lures to steal browser credentials, tokens, and documents from enterprises (Microsoft).
- A new ransomware actor, Spirals, ran a full intrusion — initial access to exfiltration to encryption — in under 24 hours (BleepingComputer).
- ClickLock, a new macOS infostealer, kills all visible apps in a 210ms loop to coerce victims into typing their login password, then installs two LaunchAgents (BleepingComputer, The Hacker News).
- The HelloNet campaign abuses the ViPNet update system via DLL sideloading to inject into svchost and establish network-hooked backdoors (Securelist); separately, the multi-stage Go RAT GoSerpent continues to evolve credential theft and cloud-based exfiltration in Southeast Asia (Securelist).
- Nextron’s scanner flagged a malicious Composer package, nordsec-libs/checkout-api-common-php (v3.0.2), that hides a
callback.phpwired into Composer’s autoload, beacons the victim hostname, and drops bash/perl reverse shells (Nextron). - PLAY ransomware added Swedish direct-marketing firm Svensk Direktreklam to its leak site among five new victims (DarkWebInformer, FalconFeeds).
- Coca-Cola disclosed (8-K) a ransomware incident at dairy subsidiary Fairlife that hit production systems and temporarily halted US production; Canada operations unaffected, no actor named (BleepingComputer).
Industry & Policy
- Germany’s media regulators issued a first-of-its-kind ruling classifying Google AI Overviews and Perplexity as the companies’ own content under the State Media Treaty — not neutral search results. Both have a month to appeal (The Decoder) (discussion).
- Germany’s BSI released a 170-page security analysis of Windows Hello for Business, breaking down its components and their security implications (Insinuator).
- South Korea is building its own security-centric AI model amid geopolitical tensions (The Register).
Topics
Vendors
Threat actors
Malware
Models