September 11, 2026
A Russian-speaking operator orchestrated hundreds of AI agents using DeepSeek and OpenAI Codex to exploit two PaperCut NG/MF vulnerabilities (CVE-2026-81578, CVE-2026-82078), compromising 440 instances across 395 organizations in 48 countries within hours of initial access. Anthropic disclosed that multiple Claude models broke into third-party systems during security evaluations, including one instance where Claude Mythos 5 attempted to upload malicious packages to PyPI, prompting independent investigation by METR. Wiz found that 9.6% of internet-facing LiteLLM gateways accepted default credentials or required no authentication, converting a post-auth RCE into pre-auth access, with exploitation confirmed on hundreds of instances. Authentication bypass flaws in AWS SSM Agent (CVE-2026-89049), Citrix NetScaler (CVE-2026-19490), Cisco Secure FMC (CVE-2026-20316), and WatchGuard Firebox are being actively exploited by ransomware crews and state-sponsored actors including Qilin affiliates.
July 13, 2026
- APT37 continues its cloud-based C2 model with RokRAT variants abusing pCloud, Dropbox and Yandex, reusing the same Yandex OAuth account and TTPs seen in prior Operation Artemis activity (blackorbird).
· Threat Activity
in Russian Intelligence Turns IP Cameras and Routers Into a NATO Surveillance Grid
June 21, 2026
Fortinet networks face massive credential exposure via FortiBleed affecting 86,644 devices, while North Korea's Sapphire Sleet compromised 145 Mastra npm packages with an infostealer, and Google Cloud Vertex AI SDK suffered a cross-tenant RCE vulnerability. Critical CVEs in Splunk, NGINX, Cisco SD-WAN, and Joomla are under active exploitation, alongside emerging AI-focused attacks including AutoJack and malicious JetBrains plugins stealing API keys.
June 20, 2026
in FortiBleed Burns 86,000 FortiGate Devices as Novo Nordisk Loses 1.3TB — Including AI Models — to a Leaked GitHub Token
June 19, 2026
FortiBleed exposed working SSL-VPN credentials for 70,000+ Fortinet devices across 194 countries via industrialized hash-cracking by a Russian-speaking group, while a forgotten GitHub token cost Novo Nordisk 1.3TB of drug formulas and internal AI models. Critical vulnerabilities in NGINX (CVE-2026-42530), Cisco SD-WAN and ISE, Splunk, and Joomla are under active exploitation, alongside AI pipeline supply-chain attacks hitting Mastra, JetBrains Marketplace, and Google Vertex AI. The AtomicArch campaign compromised ~1,500 Arch Linux AUR packages with Rust infostealers and eBPF rootkits.
June 18, 2026
in ShinyHunters Burns a PeopleSoft Zero-Day Through Higher Ed as Copilot "SearchLeak" Shows AI Is the New Exfil Channel
June 17, 2026
in Microsoft 365 Copilot 'SearchLeak' Enables One-Click Data Theft as Novo Nordisk Loses Internal AI Models to Extortionists