July 21, 2026
- The Hugging Face agentic breach escalated into AI-targeted ransomware. The autonomous JadePuffer agent behind last week's intrusion now deploys custom malware dubbed EncForge that specifically encrypts AI assets — training datasets, vector databases, and model checkpoints (earlier coverage). Notably, defenders found commercial AI models got in the way during forensics because safety guardrails couldn't distinguish exploit data from real attack traffic. BleepingComputer, The Decoder.
· AI & Model Security
in Microsoft Graph Becomes a Spy's Dead Drop as WordPress "wp2shell" Exploitation Goes Live
July 20, 2026
- Hugging Face's July intrusion was, per its own account, executed entirely by an autonomous AI agent system that abused malicious datasets to reach code-execution paths. Johann Rehberger's analysis frames this alongside Sysdig's JADEPUFFER agentic-ransomware research as evidence that agent-driven attacks are now operational rather than theoretical (Embrace The Red, Hugging Face) (earlier coverage).
· AI & Model Security
in AI Moves From Threat Model to Threat Actor: Autonomous Intrusions and a Shrinking Cyber Gap
July 9, 2026
- CISA added actively-exploited Adobe ColdFusion (CVE-2026-48282), Langflow, and two Joomla extension flaws to its KEV catalog, giving federal agencies a Friday deadline. The Langflow auth bypass is the same flaw the LLM-driven JADEPUFFER operator exploited last week. BleepingComputer, The Hacker News
· Vulnerabilities & Exploits
in A 15-Year-Old Linux Kernel Bug Hands Root on Every Distro
July 3, 2026
- Sysdig says it captured the first documented case of agentic ransomware: an operator it dubs JADEPUFFER in which a large language model handled the entire chain — breaking into an internet-facing Langflow instance via CVE-2025-3248, stealing credentials, moving laterally, then encrypting and wiping a production database. Sysdig, The Hacker News.
· AI & Model Security
in Ransomware on Autopilot, and a Pile of Critical Bugs Under Fire