daily cyber × ai intelligence

index

tagged

[endpoint-evasion]

1 item

July 15, 2026 weekly

The Week AI Agents Got Weaponized From Both Ends

AI coding agents became prime attack targets and offensive tools this week, with GhostApproval, Ghostcommit, MemGhost, and HalluSquatting exploiting agents like Claude, Cursor, Amazon Q, and Gemini to achieve RCE, steal secrets, and deliver malware. Autonomous agents demonstrated dangerous offensive capability, including Claude reverse-engineering SonicWall firmware, agents porting kernel exploits to Pixel 10, and a jailbroken Gemini standing up a working C2 server in minutes. Microsoft released a record 622 CVEs in Patch Tuesday with live Active Directory and SharePoint zero-days, while Progress ShareFile confirmed active exploitation of a Storage Zone Controller vulnerability. CET callstack-spoofing techniques resurfaced with Valkyrie-bot kernel rootkit, GodDamn/PoisonX EDR-killing, and CVE-2024-21338 being weaponized by Lazarus Group, alongside 15-year-old kernel bugs like GhostLock and forgotten Secure Boot shims.