August 1, 2026
When the Attacker Is a Model: AI Lands on Both Sides of the Fight
63 of 68 sources → 445 gathered → 400 triaged → 41 clustered → 41 written
AI-driven offense dominated the day, from a Chinese operator pointing DeepSeek at exposed servers to Trail of Bits weaponizing agent frameworks — while Google’s own bug-hunting agent posted record patch numbers on the defensive side. Elsewhere, U.S. spy agencies pinned the Minnesota water attacks on Iran, and Finland’s Veikkaus was caught in the Adform supply-chain compromise.
AI & Offensive Security
- A Chinese-speaking threat actor is running autonomous attacks by wiring the DeepSeek model into the open-source Hermes Agent framework. Palo Alto Unit 42 reports that after a single Telegram instruction, the agent independently discovered internet-facing systems, selected public exploits, and ran the session with no further operator input; the operator is tracked under the aliases knaithe and KnYuan (BleepingComputer, The Hacker News). This is a concrete continuation of the Hermes-driven activity seen against Thailand’s finance ministry.
- Trail of Bits detailed a run of offensive AI research alongside its $3M DARPA AIxCC win. The team says it hijacked multi-agent systems, exfiltrated Gmail data through Perplexity’s Comet browser, and hid prompt injection inside images — all documented publicly, with the AIxCC prize going to an autonomous vuln-finding-and-patching system (Trail of Bits).
- Google credits an AI agent harness with a record patching pace in Chrome, fixing 1,072 security bugs across versions 149 and 150 — more than the prior 23 milestones combined — with 370 more in Chrome 151. The agent also surfaced a 13-year-old flaw buried in the codebase (BleepingComputer, SecurityWeek). (discussion)
- Elastic Security Labs published detection mapping for the Hugging Face AI-agent breach, translating the autonomous agent’s tactics — untrusted-data exploitation to RCE, credential theft, lateral movement, and C2 staging — into outcome-based signals rather than register-based ones (Elastic). Useful purple-team follow-up to the earlier coverage of the incident, with a companion narrative in The New Yorker.
New Tools & Releases
- AMSI Write Raid was released as an alternative to classic AMSI patching for evasion — resolving the remote
AmsiScanBufferaddress and writing to it rather than patching the local process (Salsa12__ via ipurple). - Blacksea is an active honeypot and canary-bait system built to detect LLM-driven attackers — and to turn the tables by exploiting flaws in the attacker’s LLM judgment to gain code execution on their machine and collect attribution intel (GitHub).
- Chrome Remote Desktop weaponized into a full red-team scenario for monitoring and offensive operations, per research shared by 5mukx (via cyb3rops).
Vulnerabilities & Exploits
- MikroTik RouterOS (CVE-2026-14227) lets an attacker with only low-privilege API access extract the router’s WireGuard private key in plaintext, enabling full VPN impersonation and decryption of all associated traffic; CISA notes all versions are affected (CISA).
- COLDCARD hardware wallet firmware contains a predictable RNG fallback and a weak 32-bit reseed in cryptographic operations, per a Block engineering write-up — with concern that many affected users remain unaware (Block Engineering).
Threat Activity
- U.S. intelligence agencies assess Iran was likely behind the coordinated attack on 30+ Minnesota municipal water systems, marking an attribution shift on the campaign tracked in earlier coverage. CISA issued a public alert urging operators to pull internet-exposed PLCs and other OT offline immediately (The Record, Washington Post).
- Adform’s analytics script was compromised to hijack cryptocurrency transactions, affecting sites including Finland’s national lottery Veikkaus. The injected code rewrites clipboard contents and already-filled browser form fields to swap BTC, ETH, and TRON wallet addresses; Kevin Beaumont notes affected clients were only notified after he went public (BleepingComputer, GossiTheDog).
- ShinyHunters claims a breach of residential security firm Brinks Home and is threatening to leak stolen data; the group separately announced a “we’re back” return with new Telegram, X, and PGP channels (BleepingComputer, The Register).
- A member of the European Parliament’s spyware-investigation committee was hacked with Pegasus. Citizen Lab’s forensic analysis found German MEP Daniel Freund’s iPhone compromised with NSO Group’s spyware — while he served on the PEGA follow-up committee examining spyware abuse (Citizen Lab). (discussion)
- HollowFrame loader is delivering the Matryoshka backdoor via spear-phishing aimed at a law firm (The Hacker News).
- Suspected Chinese-speaking hackers are targeting Central Asian governments with OctLurk and SilkLurk, hitting organizations across Afghanistan, Kyrgyzstan, Tajikistan, Uzbekistan, Kazakhstan, and Syria since early 2025 (The Hacker News).
- msaRAT hides its C2 behind Cloudflare so the attacker’s own server address never appears on the wire (via cyb3rops).
Supply Chain
- Unit 42 flagged a fresh wave of malicious npm and PyPI packages, 65% previously unknown, spanning
.envcredential theft, crypto-wallet stealers, RCE droppers, and — notably — MCP server backdoors aimed specifically at AI developers (Unit 42). - A malicious Rust crate,
width-tablev0.1.0, posing as a table-width helper, walks the directory tree and exfiltrates files tocheckenv[.]cloud; it was pulled into a “Polymarket-5min-bot” project, with the campaign amplified by verified X accounts spreading the links (vxunderground). - Arch Linux disabled AUR package adoption to stem a flood of malware being planted in orphaned user-repository packages (BleepingComputer).
Breaches
- Amgen disclosed a cloud data breach in an 8-K filing, saying attackers exfiltrated proprietary data and patient protected health information from multiple third-party cloud environments (BleepingComputer, SEC filing).
- Danish firm Silvi AI allegedly exposed 16,483 researcher records via an API flaw (DarkWebInformer).
Policy
- Finland will disconnect its remaining fiber-optic links to Russia as the lease expires at year-end, following its earlier halt of power transmissions — part of a broader Nordic move to sever critical-infrastructure ties (The Record).
Topics
Vendors
Threat actors
CVEs
Malware
Models