daily cyber × ai intelligence

index

tagged

[cloud-security]

6 items

August 1, 2026

When the Attacker Is a Model: AI Lands on Both Sides of the Fight

DeepSeek wired into Hermes Agent autonomous attacks discovers and exploits vulnerable servers on attacker command, marking a concrete expansion of AI-driven offensive operations. Trail of Bits published offensive AI research including multi-agent hijacking, Perplexity Comet Gmail exfiltration, and image-based prompt injection. Google's AI agent fixed 1,072 Chrome security bugs across two releases—more than the prior 23 milestones combined. Iran was assessed by U.S. intelligence as likely behind coordinated attacks on 30+ Minnesota municipal water systems.

July 18, 2026

A Pre-Auth RCE Lands in WordPress Core, Proof-of-Concept and All

WordPress core suffers an unauthenticated remote code execution chain affecting versions 6.9.0–6.9.4 and 7.0.0–7.0.1, exploitable on default installs with working proof-of-concept code now public. Microsoft SharePoint CVE-2026-58644, Oracle E-Business Suite CVE-2026-46817, and Fortinet FortiSandbox zero-days are under active exploitation with CISA remediation deadlines. Finland's security service revealed a multi-year Russian FSB campaign targeting critical infrastructure via internet-exposed legacy devices like Cisco Smart Install. NadMesh Go botnet harvests cloud credentials from exposed AI services including Langflow, Ollama, and Gradio, claiming over 3,800 unique AWS keys and Kubernetes tokens.

July 14, 2026

New PoC Spoofs Callstacks Around Intel CET to Blind Modern EDRs

A new CET-compliant callstack spoofing PoC from @_MrTiz demonstrates how to defeat EDR telemetry despite Intel CET shadow stacks, while AI agents face compound threats from MemGhost memory-poisoning attacks and prompt-injection via steganography. xAI's Grok Build CLI inadvertently uploaded private Git repositories to Google Cloud, exposing AI dev tooling as a fresh supply-chain vector. The FBI and Google dismantled "Outsider," an $88-per-week phishing-as-a-service platform responsible for ~$1.9 billion in losses, and the US Treasury sanctioned 1VPNS and its administrator for enabling ransomware infrastructure targeting hospitals and schools.

July 2, 2026

Scattered Spider Suspect Grabbed at Helsinki Airport, Extradited to the US

A 19-year-old Scattered Spider member was extradited from Finland to face charges linked to 100+ intrusions and ~$100M in ransom payments. DuneSlide critical zero-click prompt-injection flaws in Cursor (CVE-2026-50548, CVE-2026-50549) allow arbitrary command execution on developer machines with no approval. Huntress detected a massive Azure CLI password-spray campaign with 81 million login attempts compromising at least 78 Microsoft accounts across 64–78 organizations, exploiting OAuth ROPC to bypass MFA. DeepSeek was jailbroken into building working in-browser ransomware using the File System Access API, and Claude Desktop hijacking can yield remote code execution, underscoring critical security gaps in agentic AI tools.

June 30, 2026

Edge Appliances Bleed: watchTowr Drops Kemp LoadMaster Pre-Auth RCE as Oracle EBS Joins the Exploited List

watchTowr published a critical pre-auth RCE exploit for Progress Kemp LoadMaster (CVE-2026-8037), a network-edge appliance commonly fronting enterprise services. Oracle E-Business Suite (CVE-2026-46817) and SimpleHelp (CVE-2026-48558) vulnerabilities are being actively exploited in the wild; the latter drops Djinn Stealer, a new cross-platform infostealer targeting cloud and AI credentials. Microsoft removed 119 malicious Edge extensions in the StegoAd campaign (2.6M installs) that used steganography to hide credential-stealing and ad-fraud payloads, while Mustang Panda exploits Zoho WorkDrive against Indian government targets and ShinyHunters breaches Oracle PeopleSoft systems affecting NAIC and Nissan. Coinbase and other major tech companies are shifting internal AI workloads to Chinese open-weight models (GLM 5.2, Kimi 2.7, DeepSeek V4) to reduce costs, raising supply-chain and data-leakage concerns.

June 24, 2026

Two Netlogon Flaws Hit Domain Controllers as FortiBleed Lands in Finland

Critical vulnerabilities hit domain controllers as CVE-2026-41089 (Netlogon RCE) and Onelogon (Zerologon bypass) emerge, while FortiBleed credential-harvesting campaign reaches Finnish organizations after compromising 110M+ credentials from 430K+ Fortinet devices. Major supply-chain threats include Klue OAuth attacks affecting LastPass, malicious npm packages impersonating PostCSS, and Cordyceps malicious pull requests targeting Azure/Google/Apache projects; Anthropic's Mythos model discovered Squidbleed (Heartbleed-style flaw in Squid) and vulnerabilities in classified US systems.