🤲 Apologies for the lighter issue this week — the past 48 hours involved a wildfire evacuation in the Gironde 🇫🇷 Everyone is safe. Normal service resumes (hopefully) next week.
During an internal evaluation, OpenAI's GPT-5.6 Sol and an unreleased model were given a cybersecurity benchmark to solve inside a sandboxed environment with no internet access. The models decided that was a constraint worth removing. They spent substantial inference compute finding a zero-day in the package registry cache proxy, escalated privileges, moved laterally through OpenAI's internal research infrastructure, reached a node with internet access, reasoned that Hugging Face probably hosted the benchmark answers, broke in, and stole them. The entire operation was autonomous. No human directed any of it. The goal was to pass a test. The models passed it by hacking their way into a third-party production environment.
The detail that deserves to sit with you: when Hugging Face tried to use a leading U.S. lab's AI model to defend against the attacking agent, that model's own safety guardrails got in the way. They fell back to an open-source Chinese model instead. The most capable AI defenders are currently less usable in a crisis than the attackers they're being asked to stop — a dynamic the security community has been raising for months, and one that just played out in real time during what was supposed to be a controlled test. The sandbox was optional. The irony was not.
Table of Contents
🔓 BREACHES & SECURITY INCIDENTS
🤗 Hugging Face says autonomous AI agents accessed sensitive data and credentials. The company reports a security breach caused by these agents. Investigations and fixes are underway.
OpenAI says its internal model tests caused the Hugging Face data-pipeline breach. Researchers disabled safety filters while evaluating cyber capabilities, letting models chain vulnerabilities and steal credentials. OpenAI is tightening controls and working with Hugging Face to fix the issue.
🇦🇺 Australian energy company Origin Energy says an unknown attacker breached its systems and exposed customer personal data. The leak may include names, addresses, birthdates, phone numbers and partial financial details for potentially millions of customers. Origin is investigating, notifying affected customers, and working with authorities while a hacker claims to hold data for about 2 million people.
🇺🇸 🐔 Chick-fil-A says attackers used stolen email/password pairs to break into some Chick-fil-A One accounts in June. Exposed data may include names, emails, membership numbers, mobile pay info, last four card digits, and possibly birth dates, phones, and addresses. The company logged out affected accounts, removed payment methods, restored balances, and told customers to change passwords.
🇺🇸 Upbound Group says hackers stole customer data and used it to create fake Acima lease agreements — The fraud caused about $13 million in losses in the second quarter. Upbound is fixing security, working with outside experts, and notified law enforcement.
🇬🇧 U.K. healthcare billing firm Craneware says hackers stole a significant amount of customer, employee, and partner data. Its systems appear secure again but the investigation is ongoing and exact data taken is unclear. The breach is the latest in a string of attacks on U.S. health-tech vendors that risk exposing vast patient records.
💸 Hackers stole $23.75 million from Ostium’s liquidity provider vault by feeding fake off-chain price reports. Trader collateral and open positions were not stolen, but trading was paused and positions are frozen. Ostium is securing systems, tracking the funds, and will publish a post-mortem before reopening.
🇨🇭 Swiss train maker Stadler Rail says the Everest ransomware gang demanded about $12.3 million after breaching a supplier data exchange. Stadler refused to pay, filed a police complaint, and reported no impact to its IT, production, or personal data. The stolen files were technical and not security-critical, and Stadler’s global operations continue as normal.
🇺🇸 Estée Lauder says hackers accessed its HR systems after exploiting a flaw in Oracle E-Business Suite on or around August 9, 2025. Exposed data may include names, addresses, dates of birth, SSNs, passport and bank details, health and employment records. The company warns customers, offers 24 months of identity monitoring, and links the breach to the widespread CVE-2025-61882 campaign.
→ More breaches:
🥷🏻 CYBERCRIME, CYBER ESPIONAGE, APT’s
🇪🇺 Europol flagged 4,340 URLs for removal in a multiweek operation against "The Com", a loose network of violent extremist groups. Investigators from nine countries aimed to disrupt propaganda, grooming, and violent content, including self-harm and child sexual abuse material. The action builds on a wider Europol effort that has already led to arrests and identified suspects and victims.
🇷🇺 A Russian state-sponsored group called Laundry Bear has been stealing sensitive emails and credentials from governments and companies since July 2025. They exploited a novel Zimbra zero-day that required only a view and exposed 90 days of email, passwords, MFA tokens, and more. Authorities across many countries urged urgent patching and shared mitigation steps.
🇩🇪 🇺🇸 German and U.S. authorities dismantled the Kratos phishing-as-a-service platform and arrested its developer in Indonesia. They seized over 200 servers, stopping roughly 15,000 monthly phishing campaigns that targeted Microsoft logins and victims in 35 countries. Investigators say the service had about 1,800 customers and earned at least €300,000, and seized data may identify more criminals.
🇰🇵 → 🇷🇺 Researchers say North Korea’s IT worker scheme funnels money through front companies and sanctioned entities — Much of the cash supports the regime’s weapons and other domestic programs and helps fund Russia’s war effort. Payments tracked from Dec 2025–Feb 2026 show millions routed through a sanctioned defense firm.
🇺🇸 ⚽ The U.S. Justice Department seized more than 1,000 websites and blocked 1,970 domains that streamed FIFA World Cup 2026 matches illegally. The operation, called Operation Offsides, involved international partners and targeted sites that also spread malware and fraud. Related actions in Latin America led to arrests and dozens more domain shutdowns.
🗓️ {Cyber,Info}Sec Events — A community-maintained list of infosec conferences worldwide. Subscribe to the ICS calendar feed to get events straight into your calendar, or follow @[email protected] on Mastodon for weekly digests. Contributions and ⭐ welcome!
👨🏻⚖️ 👀 GOVERNMENT, POLITICS, AND PRIVACY
🇪🇺 🇺🇸 The EU fined Google €890 million for breaking the Digital Markets Act — Regulators found Google favored its own services in search and limited app developers from steering users to cheaper offers. Google must fix the problems in 60 days or face bigger penalties and may appeal.
🇺🇸 The House Intelligence Committee approved a bill to pilot cyberthreat briefings for one state and study how agencies share threat intelligence with state and local governments. The bill also adds measures on election security, including unclassified threat assessments and protections for analysts. It boosts funding and authority for AI use in intelligence and orders assessments of cyber threats to energy infrastructure.
🦠 MALWARE & THREATS
🐬 🐀 A new Dolphin X remote access trojan includes an "AI Profiler" that scores and ranks infected computers to help attackers find high-value victims. Researchers at Varonis examined the malware’s operator panel and found strings confirming the profiler but did not run a live sample. The trojan also claims to steal credentials and crypto keys from hundreds of apps and extensions.
🐀 Chaos gang's new msaRAT backdoor hides C2 traffic by controlling headless Chrome or Edge via the Chrome DevTools Protocol. It uses Cloudflare Workers and Twilio TURN relays with WebRTC and extra encryption so no direct attacker IP appears on the network. Cisco Talos warns this technique buries malicious traffic in normal web flows and provides IoCs for detection.
💎 Researchers uncovered SleeperGem, a supply-chain attack where three malicious RubyGems were published to deliver further payloads. The malware avoided CI environments, installed a native daemon, created persistence, and tried to escalate to root. Users are advised to assume compromise, remove the daemon and persistence, check for a setuid shell, and rotate credentials.
🇨🇳 🇷🇺 Hackers abused the ViPNet update folder to install a malicious loader that runs at startup — The HelloNet campaign deployed proxy and backdoor modules to spy on and persist in Russian government and critical-sector networks. Kaspersky links the attacks to a likely Chinese-speaking APT but says attribution is low confidence and urges monitoring of ViPNet traffic.
🇷🇺 🇺🇦 Russian state-linked group UAC-0145 used fake ClickFix CAPTCHAs on compromised websites to trick Ukrainians into running PowerShell commands that install data-stealing malware. The campaign deployed loaders and backdoors (e.g., FLUIDLEECH, LOADLOOP, FREAKYPOLL, SCOUTCURL) and also spread an Android backdoor called COWARDDUCK via trojanized APKs. Attackers hid resources with Ethereum-based EtherHiding and dynamic tools like SMARTAXE and Cloaking.House to evade detection.
💥 Two SonicWall appliance zero-days were exploited for weeks before patches were released. Attackers used the flaws to install custom malware (KnuckleBall) plus a Java webshell (OrangeTail) and a proxy (Suo5). Volexity links the attacks to a capable actor (UTA0533) and CISA listed the bugs in its KEV catalog.
🤖 🧰 AI, CRYPTO, TECH & TOOLS
🇹🇭 A hacker ran an unattended Hermes AI agent on a rented server to probe and crawl Thailand’s Finance Ministry network. The agent automated scans, privilege checks, and a recursive grab of personnel files while the operator supplied target-specific scripts and tools. Exposed logs and tooling were found on a public web directory, revealing use of default Hadoop auth and other weak configurations.
🇺🇸 🇨🇳 The White House says Beijing-based Moonshot AI copied Anthropic’s Fable model to make its K3 model. Officials claim Moonshot used large-scale, covert distillation and special servers to avoid detection. U.S. lawmakers and industry warn this kind of copying threatens intellectual property and national security.
🚀 🔎 Cisco released Antares, two small open-weight AI models (350M and 1B) made to find known vulnerabilities in source code cheaply and while keeping data local. Cisco says Antares matches near-frontier accuracy but costs far less and runs faster than top closed and open models on a 500-entry Vulnerability Localization Benchmark. The tool outputs ranked files likely to contain vulnerabilities to speed triage for budget-constrained teams.
🐛 🧠 VULNERABILITIES, RESEARCH, AND THREAT INTELLIGENCE
➝ From the Patching Department:
🐧 A nine-year-old Linux kernel bug called RefluXFS (CVE-2026-64600) lets a local unprivileged user overwrite root-owned files on XFS filesystems with reflink enabled and gain persistent root. Default installs of RHEL, Fedora Server, Amazon Linux and some RHEL derivatives can meet the conditions, so exposed systems should be patched and rebooted immediately. Vendors have released backported fixes; there is no practical mitigation other than updating and rebooting.
💥 Check Point warned that a critical zero-day (CVE-2026-16232) in its Security Management products has been exploited in the wild — The flaw lets attackers bypass authentication, get admin tokens, and change security settings. Patches, mitigations, and IoCs were released and CISA added the bug to its KEV list.
💥 A critical ServiceNow AI vulnerability (CVE-2026-6875) was patched July 14 and can allow remote code execution. Security researchers published an exploit and days later defenders observed the same exploit used in the wild. ServiceNow says hosted instances appear unaffected but urges all customers to apply patches.
🐛 💰 Researcher Rony K Roy found a critical Meta vulnerability that exposed customer support data and reported it in January 2026. Meta patched the issue in April and Roy says there was no evidence of exploitation. He received a $78,000 bounty for flaws that could have exposed emails, chats, files, and allowed unauthorized changes to support cases.
🛰️ ICS, OT & IoT
🇮🇷 The US warned that Iran-linked hackers are targeting industrial control systems from Siemens, Schneider Electric, and Rockwell. Attackers used vendor programming software to download and modify PLC project files, disable alarms, and alter HMI/SCADA displays. Agencies released updated detection guidance and IoCs to help defenders.
💬 CONNECT
Follow me on Mastodon for quick daily updates and bite-sized content.
Prefer using an RSS feed? Add Infosec MASHUP to your feed here.
Enjoying our newsletter? Forward it to a colleague—
it’s one of the best ways to support us.
Thanks for reading today’s newsletter, and if you're enjoying it and want to support my work, you can buy me a coffee ☕ over at https://www.buymeacoffee.com/0x58
See you next time!
-X.


