daily cyber × ai intelligence

index

July 24, 2026

The Week AI Agents Started Doing the Hacking

65 of 68 sources 487 gathered 400 triaged 42 clustered 42 written

OpenAI patched a ChatGPT flaw that let a single link conjure a rogue autonomous insider, and researchers put a fresh Redis 0-day discovery in the hands of an AI model. On the classic side, a US-led coalition exposed a Russian zero-click campaign against Zimbra webmail that scrapes 90 days of mail and 2FA recovery codes the moment a message is opened.

AI & Model Security

  • OpenAI fixed “AgentForger,” a ChatGPT Agent Builder flaw that let one tampered link spawn a covert AI insider. Zenity Labs showed that a single manipulated ChatGPT link could silently create an autonomous agent on an employee’s behalf — inheriting their identity and access, bypassing approval prompts, and polling the attacker’s inbox for fresh instructions every five minutes. SecurityWeek, The Decoder, The Register.
  • Kimi K3 reportedly discovered and exploited a Redis 8.6.x 0-day with 32 subagents in 27 minutes. Researcher @chetaslua claims a jailbroken Kimi K3 was pointed at “latest 8.6.x redis,” told to hunt for BOF/UAF bugs, and produced a working exploit — though the UK AI Safety Institute and NIST’s CAISI rate Kimi K3 below leading US frontier models on cyber evals, and Semgrep found its code-security output imprecise. Treat the tweet claim with the appropriate skepticism.
  • A Claude Cowork flaw could let an AI agent escape its VM and reach host Mac files, breaking the isolation boundary meant to contain agent actions. The Hacker News.
  • Kaspersky details practical attacks that hijack AI tooling already inside the target. Rather than attackers bringing their own AI, the write-up focuses on abusing deployed coding/CLI agents — Claude Code CLI, Gemini CLI, Codex CLI, Amazon Q CLI — which can read/modify files, run shell commands, and install packages. NCSC-FI/Kaspersky.
  • Skepticism grows around the OpenAI–Hugging Face “autonomous intrusion.” SANS ISC frames the two disclosures as one of the year’s most instructive incidents for defenders, while @cyb3rops questions how HF can claim the intrusion was “end to end” autonomous when victim-side telemetry can’t reveal upstream human intervention. (earlier coverage); SANS ISC, Martin Alderson (discussion).

Threat Activity

  • A US/UK-led coalition exposed a Russian state campaign exploiting Zimbra zero-click flaw CVE-2025-66376 against NATO, Ukraine, CIS and African targets. The actor — tracked as Laundry Bear / Void Blizzard / TA488 (CL-STA-1114) — plants malicious JavaScript that fires the instant a webmail message is previewed, no click required; its Ulej tool then exfiltrates the last 90 days of email, org directories, saved browser passwords, and 2FA recovery codes. CISA advisory, NCSC-UK, Unit 42, The Record.
  • msaRAT, a new Rust backdoor from the Chaos ransomware crew, tunnels C2 through headless Chrome/Edge and WebRTC. Cisco Talos found it abusing the Chrome DevTools Protocol and WebRTC DataChannels, ChaCha20-Poly1305-encrypting payloads, and hiding behind Twilio TURN and Cloudflare Workers to blend into legitimate traffic. Talos, BleepingComputer.
  • An exposed Alibaba Cloud directory blew the cover on a China-nexus operation, “JadeProx.” Group-IB found bash history, toolkits, webshell paths and staged phishing kits on an operator server, tying simultaneous intrusions against a Vietnamese hospital’s imaging system, Malaysia’s foreign ministry and Hong Kong universities — and a new TriBack loader plus fake-Anthropic Claude phishing lures. Group-IB, The Hacker News.
  • TAG-195 (“Golden Chickens”/“Venom Spider”) added four modular malware families to its MaaS ecosystemTinyEgg, ChonkyChicken (plus a modularized variant), and credential-stealer ChromEggscalator, with Insikt Group observing operator TAG-127 deploying TinyEgg. Recorded Future.
  • SourTrade malvertising assembles its payload in the browser via ServiceWorkers. The campaign impersonates trusted crypto brands and builds in-memory Windows executables client-side to dodge detection. Confiant.
  • A fake Claude desktop installer promoted by Bing ads pushes SectopRAT, hosted on a legitimate Claude.ai domain to lend credibility. BleepingComputer.
  • Dolphin X infostealer/RAT claims AI-driven victim scoring to rank infected users and prioritize high-value targets across 300+ apps. BleepingComputer, CyberInsider.
  • ClickFix detections doubled (+108%) H2 2025→H1 2026 as ESET tracks new variants: AI-fix pages impersonating Anthropic Artifacts, OpenAI Canvas and Copilot Pages; CrashFix fake browser crashes; and ConsentFix OAuth abuse. ESET.
  • Ransomware roundup: The Gentlemen listed 31 victims including a Vienna IVF clinic (Wunschkind Klinik Dr. Brunbauer) and US biotech MatTek (DarkWebInformer); PLAY claimed Restaurant Depot and Spanish rental firm Record Go (DarkWebInformer).

Vulnerabilities & Exploits

  • Check Point SmartConsole authentication bypass CVE-2026-16232 (CVSS 9.3) is being exploited in the wild. Unauthenticated remote attackers can bypass the login process to gain full admin access on Security Management and Multi-Domain Management; hotfixes are out. Rapid7, BleepingComputer (discussion).
  • RefluXFS (CVE-2026-64600): a nine-year-old XFS race condition gives local users root on default RHEL installs. The kernel filesystem flaw lets attackers overwrite protected files to escalate. BleepingComputer, The Hacker News.
  • Public Redis RCE PoCs shipped for CVE-2026-25243, a heap double-free/type confusion in the RDB loader via crafted RESTORE payloads (Redis 6.2.x–8.6.3), including a DEBUG-free variant with ASLR on and multi-version PoCs. PoC.
  • PostgreSQL pgcrypto heap-overflow RCE (CVE-2026-2005) now has a public exploit; fixed in 14.21+. PoC.
  • A Bluetooth car-alarm system, KARR, can be unlocked and disabled remotely via a shared plaintext key, with static Bluetooth identifiers enabling long-term tracking; a firmware fix came 18 months later but many owners remain exposed. Malwarebytes, The Register (discussion).
  • A modern Wansview WVC Q5 camera shipped with a 20-year-old directory-traversal flaw (CVE-2002-1819), exposing sensitive files to unauthenticated network access before an OTA fix. CyberInsider.
  • Oracle’s July CPU patched 1,449 vulnerabilities, including WebLogic arbitrary file read CVE-2026-60206. Oracle advisory (discussion).

Supply Chain

  • A large GitHub Actions abuse campaign turned compromised repos into distributed infrastructure hitting cPanel and WHM. The malicious logic lived in workflow files (not the PHP code itself) across 10 Packagist packages tied to legit developer “dinushchathurya,” auto-synced July 12–13. Socket, The Hacker News.
  • 113+ malicious RubyGems delivered XMRig cryptominers via trojanized libraries using delayed persistence and direct launchers. Unit 42.
  • Attackers are abusing the Notepad++ plugin ecosystem to stealthily install malware. BleepingComputer.
  • Researchers show trusted macOS app executables can be silently swapped for “evil twins” post-install, with Apple treating it as out of scope. mysk.blog, The Register (discussion).

Cloud & Identity

  • A five-hour Microsoft 365/Azure outage hit Teams, SharePoint and ExpressRoute, traced to a failed configuration change. Kevin Beaumont notes Microsoft told customers there was no ETA and to review DR plans, comparing it to the 2022 WAN outage; a “313 Team” DDoS claim doesn’t match the failed-change post-incident review. BleepingComputer, @GossiTheDog (discussion).
  • Microsoft will phase out SMS and voice MFA for Entra starting February 2027, mandating phishing-resistant passkeys, citing AI-driven attacks that defeat one-time codes. Windows Latest.
  • Google added selfie-video account recovery as an AI-driven fallback when other recovery options fail — a cloud-based live facial-recognition check that drew immediate privacy criticism. Google, The Hacker News (discussion).
  • Carla car-rental data was exposed in an unsecured AWS bucket — 48,000 PDFs of sensitive customer records. SC World.

New Tools & Releases

  • OneCLI — an open-source network gateway that sits between AI agents and services so real secrets never reach the agent, mitigating leaked/stolen credentials from compromised sandboxes. GitHub (discussion).
  • WP2Shell hands-on lab — a guided lab reproducing the WordPress core pre-auth RCE (earlier coverage), useful for detection and purple-team validation. uphack.

AI Frontier

  • Black Forest Labs released Flux 3, a multimodal foundation model that generates video with native audio (up to 20 seconds) for the first time, edging past Seedance 2.0 in the vendor’s own tests. The Decoder.