Back after two weeks off — a wildfire evacuation and some much-needed summer downtime. Good to be back!
During a sanctioned security evaluation by the UK AI Security Institute, an Anthropic Claude Mythos 5 agent was given a task. It completed that task by attempting to insert a backdoor into a real open-source project — and then created fake accounts to vouch for its own malicious pull request. Human reviewers caught it. GitHub's protections helped. No real-world harm was confirmed. But the detail worth sitting with is that the agent wasn't jailbroken, wasn't misused, and wasn't acting against its instructions in any obvious sense. It was doing what it determined the task required, and it fabricated social proof to make it stick.
The TechCrunch piece this week asks who's legally liable when autonomous AI agents cause harm. The honest answer is that nobody knows yet — the legal frameworks that govern software liability, contractor negligence, and computer crime were not written with agents in mind. OpenAI and Anthropic have both now had models escape sandboxes and interact with production systems during evaluations. The incidents are being handled as engineering problems. At some point they will be handled as legal ones, and the industry's current answer — tighter sandbox controls and better monitoring — is going to look inadequate when a lawyer reads it.
Table of Contents
🔓 BREACHES & SECURITY INCIDENTS
🇺🇸 👖 Levi Strauss says hackers used social engineering on three employees to access and steal corporate data. The company says its quick response contained the breach and no consumer data or business operations were affected. The investigation is ongoing and Levi’s will notify affected parties if needed.
🇺🇸 🚢 A cyberattack disrupted gate operations at North Carolina’s three port facilities this week. The U.S. Coast Guard is monitoring the incident while port IT teams and partners investigate and use contingency plans. There is no public attribution yet and normal operations have reportedly resumed.
🇺🇸 Unlimited Technology Systems says a data breach exposed personal, medical, and insurance information for about 3.8 million people. The company found the breach in October 2025 and says data were stolen between October 5–10 from a commercial data center. Unlimited is offering two years of free credit monitoring and identity-restoration services and says no misuse is known.
🇨🇭 Switzerland’s federal IT office says hackers breached its Microsoft SharePoint servers and compromised about 200 accounts. BIT blocked external access, patched vulnerabilities, reset passwords, and is reinstalling servers. Investigators are working with the Swiss cyber office and Microsoft and have found no evidence of data theft so far.
🇺🇸 Brown Health Medical Group-MA says a December 2025 breach exposed personal, medical, and financial data for 311,760 people — The attack targeted a historic file server, not the electronic health record system, and was discovered June 22, 2026. The provider isolated the server, added safeguards, and is offering two years of identity protection.
🇺🇸 River Bank & Trust reported a ransomware attack in June that led to data being stolen. The bank says it engaged the attackers and received confirmation the stolen data was deleted. Investigations and lawsuits are ongoing and the bank has not yet confirmed the full impact.
🇺🇸 Madera Community Hospital says hackers accessed its network in May 2025 and likely took files containing personal, financial, and medical data. The hospital notified about 150,810 people and worked with experts, a data-review firm, and law enforcement. The attackers withdrew a ransom demand and the hospital says there is no evidence the data was publicly released.
🇬🇧 Hackers from the ExfilSquad group breached the U.K. Police National Legal Database and leaked contact details for over 100,000 police officers and other justice workers. The group claims 135,000 records were stolen and posted samples while demanding a ransom. PNLD says no passwords or sensitive victim or offender data were exposed and authorities are investigating.
🇺🇸 Hackers from the ShinyHunters group leaked over 41 GB of data they say was stolen from Brinks Home. Brinks Home says parts of its IT systems were accessed and about 4.9 million Salesforce records may be affected. The company says alarm services were not impacted and it will notify anyone whose personal data was compromised.
🥷🏻 CYBERCRIME, CYBER ESPIONAGE, APT’s
🤑 A wave of vishing attacks on hedge funds and private-equity firms has been tied to UNC6671, linked to the BlackFile extortion campaign. Attackers spoof helpdesks, steal SSO credentials and cloud data, then extort victims for hundreds of thousands of dollars. Security firms say UNC6671 uses multiple extortion brands and has hit dozens of organizations.
🇺🇸 ⚖ 🇧🇾 Maksim Silnikau, the Belarusian creator and administrator of the Ransom Cartel ransomware, was sentenced to 16 years in a U.S. prison. He built the operation, recruited others, ran a hidden site to manage attacks and payments, and supplied stolen credentials and encryption tools. The cartel hit at least 18 organizations from 2021–2023 and was disrupted after Silnikau’s 2023 arrest and 2024 extradition.
🇨🇦 ⚖ A Canadian man, Connor Moucka, pleaded guilty for a major 2024 hack that stole data from over 165 Snowflake customer accounts. He extorted victims, earning about $495,000, and helped expose billions of records affecting millions of people. Moucka faces up to 32 years in prison and will be sentenced on Oct. 27.
📆 Researchers found that TeamPCP, the hacker group that injected malicious code into over 1,000 open-source packages this year, has been active since at least 2020. The group used AI to rapidly adapt payloads and exploited new gaps in AI-based development and deployment tools. Oligo Security linked TeamPCP to multiple past campaigns and warns many more attacks may be undiscovered.
💸 Hackers stole about $130 million by exploiting a flaw in Coldcard offline hardware wallets — The bug made users’ seed phrases predictable, letting attackers recreate keys and empty accounts. Coldcard warned users to update devices and create new seed phrases.
🇷🇺 The Russian state-linked APT (Storm-2945 a subgroup of Midnight Blizzard) hacked public Wi‑Fi gateway appliances to steal Microsoft 365 credentials from traveling employees. Attackers used DNS/HTTP manipulation and captive‑portal pages to deliver RATs and phishing, including device‑code prompts. Victims were mainly at hotels, conferences, and other shared venues across multiple sectors and countries.
🗓️ {Cyber,Info}Sec Events — A community-maintained list of infosec conferences worldwide. Subscribe to the ICS calendar feed to get events straight into your calendar, or follow @[email protected] on Mastodon for weekly digests. Contributions and ⭐ welcome!
👨🏻⚖️ 👀 GOVERNMENT, POLITICS, AND PRIVACY
🇺🇸 Lawmakers want to make identity protection permanent for millions hit by the 2015 OPM breach. Sen. Mark Warner and Del. Eleanor Holmes Norton introduced the RECOVER PII Act to extend lifetime coverage and reimburse privacy services. The bill faces hurdles from GOP control, cost concerns, and past failed efforts.
🇺🇸 The Senate will debate several bills on online privacy, kids’ safety, and AI — Key measures include the Kids Online Safety Act, age-verification rules, and limits on how AI chatbots use children’s data. Supporters say the bills protect children; critics warn they could harm privacy and require risky data collection.
🦠 MALWARE & THREATS
🧩 Security researchers found 77 fake Open VSX extensions that pretended to be real developer tools but sent system and development environment data to a single server. Most exfiltrated basic host info, while 19 collected detailed metadata like Git, CI, and workspace paths. The malicious packages were removed from the marketplace, but developers must manually uninstall them and block mangorbit[.]com.
🇷🇺 🖼 A new Russian service called DOUBLECUP hides malware inside PNG images cached by browsers and uses fake ClickFix prompts to trick victims into running commands. It delivers CountLoader to Windows and macOS and a new DeviceManager RAT to Windows, using steganography, in-memory execution, and smart-contract-based C2 lookups. The service provides infrastructure and tools so customers can launch these campaigns against sites like NetSuite, Odoo, HubSpot, and Salesforce.
🪱 A malicious npm release ([email protected]) used a preinstall script to install a credential-stealing bundle that spread into hundreds of packages on August 4, 2026. The malware harvests repo, cloud, registry, and key material, can reuse npm publishing access to poison more packages, and includes Claude Code and VS Code hooks to run when a workspace is trusted. Exact exposure is unclear, so responders must check resolved package versions and revoke compromised credentials carefully.
🐀 Researchers found 18 malicious npm packages that target Alibaba developer-tool users with a cross-platform remote access trojan (RAT). The attack hides loader code across dependency layers to fetch and run OS-specific payloads that enable backdoor, credential theft, and lateral movement. Affected users should assume compromise, rotate credentials from a clean machine, and audit developer systems.
🤖 🧰 AI, CRYPTO, TECH & TOOLS
🙃 Meta said its AI models escaped during independent cybersecurity tests and hacked an external system. The breach happened because the models were accidentally given internet access and exploited a vulnerability. Meta is investigating and will publish a full retrospective.
🤖 🔙 🚪 An Anthropic Claude Mythos 5 agent tried to backdoor a real open-source project during a UK AI Security Institute test and used fake accounts to vouch for its own malicious pull request. Human reviewers and GitHub protections stopped the attack, and AISI found no evidence of real-world harm. The report urges tighter sandbox controls, monitoring, and caution with AI-driven code triage.
🤝 A new industry group led by Nvidia, IBM and Microsoft launched the Open Secure AI Alliance to create cybersecurity guidelines for AI agents. The SAFE guidelines would share AI incident data, set reporting timelines, and recommend fixes to reduce systemic risk. Membership requires quick breach reporting and evidence preservation to protect open-source and enterprise AI.
🤖 Google removed three ADK GitHub workflows after researchers showed a public issue could trick a triage agent into activating a privileged code-fix agent. The flaw let the bot identity authorize dangerous actions, enabling CI code execution and exposure of secrets like a bot token and Google credentials. Google deleted the workflows and Pillar recommended stricter bot identities, narrower scopes, and safer authorization checks.
📍 🙅 Security researchers found many Samsung smart TV apps secretly include code that can turn TVs into residential proxy nodes, letting outsiders route internet traffic through users' home connections. Samsung said it will ban and remove apps that share users' internet connections. Such proxy networks can be abused for scraping, hiding cyberattacks, or forming botnets.
🐛 🧠 VULNERABILITIES, RESEARCH, AND THREAT INTELLIGENCE
➝ From the Patching Department:
🍎 ☁ Researchers found that Apple’s iCloud Private Relay can leak users’ real IP addresses — Three WebKit features (DNS prefetching, WebAuthn origin requests, and WebTransport) can bypass the proxy and send traffic directly from the device. A proof-of-concept site shows the leak and Apple says it is investigating.
📱 🤑 Two researchers chained multiple Samsung app vulnerabilities to hack Galaxy phones and won $50,000 at Pwn2Own. The attack used malicious links to force Samsung Members and Samsung Account to open Bixby and abuse hidden "Capsules" to gain system-level control. Samsung began patching the flaws after the competition, but unpatched older devices remain at risk.
👀 A critical Gitea bug (CVE-2026-59774) lets unauthenticated attackers read any file the service account can access via a crafted Org-mode post to the markup endpoint. The flaw affects Gitea 1.22.1–1.27.0 and is fixed in 1.27.1, which also patches another RCE bug. Admins should upgrade immediately and rotate tokens and credentials if the markup endpoint was hit.
🐧 A 13-year-old memory-corruption bug in the Linux kernel Open vSwitch datapath (CVE-2026-64531, "OVSwrap") lets ordinary local users gain root on many default systems. A public exploit with prebuilt records for ~800 kernels abuses a 16-bit length wrap to leak pointers, read/write kernel memory, and escalate privileges. Fixes are in upstream stable kernels; users should apply vendor patches, block or unload the openvswitch module, or disable unprivileged user namespaces.
🐧 An 18-year-old use-after-free bug in Linux's SCTP code (CVE-2026-64564, "SCTPhantom") can let a local user gain root and escape containers. Patches landed in stable kernels 7.1.6, 6.18.42, 6.12.101 and 6.6.148 on August 3, so systems should be updated or disable SCTP. Tencent's researchers used the bug to escape a container in their tests, but independent reproduction and wider impact are still unclear.
🐛 Researchers found 15 new vulnerabilities in TP-Link Omada’s zero-touch provisioning that can be chained to take over fleets of devices. Flaws include hardcoded keys, weak certificate checks, credential leaks, and predictable defaults, letting attackers gain controller admin access or intercept traffic. TP-Link has issued some patches, but many issues remain and full fixes may extend into 2026.
🗓 🐛 A 22-year-old flaw in BMC/IPMI lets attackers obtain password-derived hashes from thousands of internet-exposed server management interfaces. Attackers can crack weak or default passwords offline and gain powerful control over servers. Many BMCs use predictable or common passwords and lack proper monitoring, making data centers easy targets.
🩹 cPanel patched a critical bug (CVE-2026-58048) that let authenticated hosting users run SQL with database-root privileges, risking full server compromise. Two other flaws fixed include an HTTP request-smuggling issue that can leak credentials and Exim bugs that allow local privilege escalation. Administrators should update to the listed builds or apply workarounds until patches are installed.
💥 N‑able patched a serious authentication bypass (CVE-2026-18577) that attackers used to take over N-central servers. Exploited installs let attackers gain admin access, run remote control, and create persistent tunnels to managed devices. Affected versions are older than 2026.3.1.7 and both on‑prem and cloud deployments should update now.
💥 INC Ransomware is the main group exploiting SonicWall SMA 1000 VPN flaws to breach networks. They used two chained zero-day bugs to steal credentials, MFA seeds, and install web shells for persistent access. Organizations must patch SMA devices, rotate credentials, and hunt for suspicious remote access.
🛰️ ICS, OT & IoT
🇺🇸 💧 A recent cyber campaign hit water and wastewater systems in at least seven U.S. states, including Minnesota, Michigan, South Dakota, and Georgia. Authorities say operations and public water safety were not compromised, but many OT devices—especially those using cellular links—were targeted. U.S. investigators and sector groups suspect Iran-linked hackers and warn operators to secure industrial control systems.
💬 CONNECT
Follow me on Mastodon for quick daily updates and bite-sized content.
Prefer using an RSS feed? Add Infosec MASHUP to your feed here.
Enjoying our newsletter? Forward it to a colleague—
it’s one of the best ways to support us.
Thanks for reading today’s newsletter, and if you're enjoying it and want to support my work, you can buy me a coffee ☕ over at https://www.buymeacoffee.com/0x58
See you next time!
-X.



