Welcome to the weekly highlights and analysis of the blueteamsec (and my wider reading). Not everything makes it in, but the best bits do. A community member is doing daily AI generated podcast of the last 24hours of posts.
Operationally this week nothing overly of note..
In the high-level this week:
When cyber attacks happen: helping organisations recover - UK NCSC outline - “A highly disruptive incident can feel overwhelming. New guidance provides a framework for response and recovery.”
Making forensic observability the norm for network devices - UK NCSC update - “We are seeing encouraging progress across industry, but there is still some way to go before forensic observability capabilities become standard. Both vendors and buyers have a role to play in making this happen.”
G7 Cyber Expert Group 2026 Cross Border Coordination Exercise (CBCE) - HM Treasury summarise - “The G7 Cyber Expert Group (CEG) successfully concluded its 2026 Cross-border-coordination exercise (CBCE) on May 18 2026. This exercise demonstrates the Group’s ongoing commitment to strengthening cyber resilience across the G7 financial sector.”
G7 Cyber Expert Group: Reconnection Framework Technical Annex - HM Treasury publish - “Reconnection is the process of restoring technical access and integration to an organisation that has been technically quarantined after suffering a material cyber incident. This includes a phased resumption of business operations, beginning with the technical reconnection of stakeholders and entities to the organisation.”
Malicious Cyber Actors Targeting Water and Wastewater Sector Internet- Facing Programmable Logic Controllers, Causing Operational Disruptions - FBI warns - “The Federal Bureau of Investigation (FBI) and Environmental Protection Agency (EPA) are issuing this Public Service Announcement (PSA) to warn critical infrastructure asset owners and operators that malicious cyber actors (MCAs) are conducting cyber attacks targeting Operational Technology (OT) devices, including Rockwell Automation/Allen-Bradley Programmable Logic Controllers (PLCs), specifically MicroLogix 1100 and 1400 series. Since 27 July 2026, Water and Wastewater Sector (WWS) utility companies in at least seven states have reported incidents to the FBI, and some of that activity degraded water operations.”
Open Source Software: Security Principles and Practices - CISA publish - “Open source software (OSS) is embedded in nearly every modern system, from business applications to critical infrastructure. Our new Open Source Software: Security Principles and Practices guidance helps agencies securely use, evaluate, and publish open source software. It covers OSS risk management across the full lifecycle, introduces the C4 Framework for trust assessment, and provides specific recommendations for vulnerability management, software bill of materials use, secure development, and handling open source artificial intelligence systems.”
2026 Minimum Elements for a Software Bill of Materials (SBOM) - CISA publish - “The U.S. Cybersecurity and Infrastructure Security Agency (CISA), in partnership with the co-authoring organizations, updated the Minimum Elements for a Software Bill of Materials (SBOM) to reflect current SBOM needs, while preserving the core principles of the document published in 2021 by the National Telecommunications and Information Administration (NTIA).”
Memory safety requirements - ETSI publish the draft - “The scope of this work item is to develop memory safety assurance levels and specific requirements to meet them. In this regard, the work will entail the formulation of a vocabulary that is independent of any particular vendor, and a systematic classification schema for memory safety technologies. In addition, the work will provide concrete examples that illustrate the extent to which certain technologies fulfil these assurance levels and the corresponding requirements.”
North Korea Taps India for Smartphones - NK North reports - “North Korean smartphone brand Phurunhanal Electronics appears to have sourced one of its latest phones from the Indian company Lava International. This represents the first time a phone on sale inside North Korea has been linked to a non-Chinese manufacturer.”
Commission publishes new guidance to support timely Cyber Resilience Act implementation - European Commission publishes - “The guidance addresses the questions stakeholders have been asking most, including:
Clarifying when certain products fall within the scope of the Cyber Resilience Act, including remote data processing solutions and free and open source software
What constitutes a ‘substantial modification‘
How support periods should be understood and applied
How to meet reporting obligations and risk assessment requirements”
Reporting on/from China
Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks - Andy Piazza details - “Unit 42 identified an AI-enabled autonomous hacking campaign carried out by a Chinese-speaking threat actor. They targeted infrastructure using seven vulnerabilities, combining autonomous AI-driven enumeration with manual exploitation that achieved confirmed impact.”
Puppeteers: Chinese hackers still trick Claude into dirty work - NetAskari details - “An interesting find on hunt.io demontstrates that Chinese operators are still luring Claude to conduct offensive hacking operations, despite Anthropic’s assurance of better guardrails.”
China Cannot Buy Western Frontier AI. 73,000 Servers Sell It Anyway - Infrawatch detail - “Inside the 73,000-server market reselling Western frontier AI into China”
Trump administration bans new Chinese humanoid robots - BBC reports - “The Trump administration on Tuesday announced a ban on new foreign-made humanoid robot imports to the US over “unacceptable risks” to America’s national security.”
The Chinese robot army transforming the UK’s retail industry - BBC reports - “At Geek+’s factory in the eastern Chinese city of Hefei, which the BBC visited, fleets of the robots are built and tested before being shipped to warehouses around the world. Some of Britain’s biggest retailers - including Tesco, Asda and Next - now use the company’s technology.”
China begins mass production of homegrown immersion chipmaking machines in major breakthrough, report claims — first DUV lithography units will be delivered this year to SMIC, Hua Hong, and CXMT - Tom’s Hardware reports - “U.S. House Resolution 8170 designates SMIC, Hua Hong, CXMT, Huawei, and YMTC as restricted entities in law, and three of those five are the named first customers for the domestic scanner.”
AI
The AI That Hacked Its Way Out and the Hype That Followed It - Kate Klonick, Associate Professor at St. John’s University Law School analyses and asserts - “The models didn’t escape because they’re gods. They escaped because someone left the door open. Congress should regulate the door.”
Its AI agent spent days hacking a company, but sources say OpenAI did not notice for a week - Reuters reports - “
The agent first tried escaping OpenAI’s isolated environment around July 9, two people familiar say
Co-founder of victim firm Hugging Face says the intrusion began July 11
OpenAI noticed odd behavior from cutting-edge models before hack-sources”
Anatomy of a Frontier Lab Agent Intrusion: A Technical Timeline of the July 2026 Incident - Hugging Face details - “This post walks through how the intrusion actually worked: the two initial-access vectors, how the agent pivoted and moved laterally, representative examples of the commands that were run and how we investigated with GLM 5.2 (an open-source model). Live credentials, internal hostnames, and specific indicators have been redacted or genericized, while the techniques are described exactly as observed by Hugging Face.”
Investigating three real-world incidents in our cybersecurity evaluations - Antrhopic disclose - “In a review of our cybersecurity evaluation transcripts, we found three incidents in which a Claude model reached the internet from within or while interacting with a third-party evaluation environment, and then gained unauthorized access to the real systems of three different organizations.”
Patchmageddon - Michael Cembalest, J.P. Morgan - “I partnered with JP Morgan’s Cybersecurity Teams to get into the details on this critical national security issue. In “Patchmageddon” we review how cyber risks have changed, the underappreciated breadth and risks from open source code, the risks to physical infrastructure and some guidance what business owners, software developers and the Federal government should be doing to mitigate the potential consequences.”
Context Wash - How AI SOC Vendors Hollowed Out Their Strongest Word - Zach Christensen challenges - “In a single hour at the Gartner Summit I heard “context” used to describe a SIEM query, a session-history thread, a policy-weighted alert score, a UI-aware copilot, and an analyst-typed prompt. Same word. Five products. Five entirely different things. Buyers nodded along, because the word sounds like the same thing.”
Human mathematicians are being outcounterexampled - Kevin Buzzard truth bombs - “Perhaps it was at this point that the penny really dropped for me — large AI-generated developments of mathematics are inevitable. One cannot trust AI-generated code so I ran it in a sandbox on my machine (malicious Lean code can run arbitrary commands on your computer — Lean is a programming language, after all). Indeed, it was proving nontrivial theorems about the cohomology of number fields”
Beyond Zero: Enterprise security for the AI era - Joseph Valente and Michal Zalewski outline - ““
GEO for Geopolitics: What happens when AI and information warfare collide - Demos explores - “As large language models (LLMs) become embedded across every stage of our information supply chain, they are creating a new frontier for information warfare. This report explores what happens when AI and geopolitical competition collide, revealing how hostile states can manipulate the information that AI systems retrieve, cite and present to users.”
Corporate America Has Suddenly Decided to Stop Blowing Money on AI - Wall Street Journal reports - “Fed up with ballooning costs, companies big and small are starting to use lower-priced models, including some built in China. In many cases, they are adding the new, cheaper models alongside OpenAI and Anthropic’s products, shopping a la carte for their artificial intelligence.”
Cyber proliferation
Nothing overly of note this week
Bounty Hunting
How police are trying to divert teen hackers away from crime - BBC reports- “Cyber Choices, also known as Cyber Prevent, is like a hacker rehab course.”
Market Incentives
South Korea fines telco giant KT $39 million for customer data breach - Bleeping Computer reports - “The point of breach was a lost KT cellular base station called a femtocell, which contained a valid authentication certificate.”
Personal Information Protection Commission Decides on Sanctions for 'KT Inc. Personal Information Leak Incident' - South Korea Personal Information Protection Commission outlines
AI firms must answer for rogue bots, says boss of hacked company - BBC reports - “The boss of one of the companies recently hacked by out-of-control artificial intelligence (AI) says bot makers must be accountable for cyber attacks carried out by their creations.”
AI Seed Investors Flock To Cybersecurity - Crunchbase detail - “Notably, the strong cybersecurity seed funding environment coincides with solid overall venture investment levels. In the first half of the year, per Crunchbase data, startups in the sector pulled in $10.6 billion in financing across stages, roughly in line with recent prior comps.”
No reflections this week but Series 3 of the NCSC podcast is out - episode one is on ‘The New AI Reality’
Not getting this via email? Subscribe:
Think someone else would benefit? Share:
All attribution is by others and not the UK Government unless specifically stated as such, please see the legal text at the end.
Have a lovely Saturday…
Ollie
Cyber threat intelligence
Who is doing what to whom and how allegedly.
Reporting on Russia
Russian Global Webmail Espionage
Unit 42 details this alleged Russian campaign which is of note due to the targeting of e-mail and and victimology.
Unit 42 has observed a persistent cyberespionage campaign we track as CL-STA-1114. This activity cluster overlaps with activity from a Russian threat actor tracked by other vendors as Void Blizzard and LAUNDRY BEAR.
The attackers behind this campaign targeted Zimbra webmail in organizations in the following sectors:
Governments
Defense
Transportation
Financial organizations across the following regions:
NATO member states
Ukraine
Commonwealth of Independent States (CIS) countries
Africa
https://unit42.paloaltonetworks.com/russian-webmail-espionage/
Cleaning Out Inboxes: TA488 Comes for Outlook with Another Half-Click Exploit
Greg Lesnewich, Stuart Del Caliz, Nick Attfield, Konstantin Klinger, Saher Naumaan and Mark Kelly detail an alleged zero-day exploitation of a highly novel approach to a web implant allegedly by a Russian threat actor.
On 22 July 2026, one day prior to Proofpoint’s recent joint release with the NSA on Russia-aligned threat actor TA488 (Void Blizzard, Laundry Bear), the actor began a campaign abusing CVE-2026-42897, a cross-site scripting (XSS) vulnerability in Outlook Web Access (OWA).
The campaign targeted US and European government entities, as well as the telecommunications, financial, hospitality, and aerospace sectors.
TA488 is doubling down on the use of “half-click” exploits – where opening the email is enough to trigger compromise – with significantly improved loading mechanisms, techniques, and malware, signaling an improvement in the group’s tradecraft and capability.
This novel infection chain ends with a previously unknown JavaScript browser-based implant we call OWAReaper, purpose-built for persistent access inside OWA.
OWAReaper runs inside the OWA browser context, operating as a stealthy implant with no host footprint, using two C&C communication channels and two data exfiltration protocols. It is capable of surviving browser reboots, credential rotation, and full re-imaging of the victim’s device.
The earliest infrastructure used in this campaign was created in March 2026, two months prior to Microsoft’s out-of-band patch for CVE-2026-42897; it is feasible that TA488 used this vulnerability as a zero-day.
DNS Poisoning Tactics Expand to Hospitality Wi-Fi
Alexander Capraro, Jalen Vaughn, Daxton Wirth, Austin Ritchie, and Connor Short detail this alleged Russian operation targeting hospitality which is noteworthy.
Adversaries have been compromising public Wi-Fi gateways at hotels, conference centers, and other shared venues to hijack the accounts of traveling corporate employees. Once they control the Wi-Fi gateway, they quietly redirect users to attacker-controlled infrastructure to steal credentials, in activity ongoing since at least June 2026.
ReliaQuest assesses this tradecraft is similar to that of “APT28” (also known as “Fancy Bear” and “Forest Blizzard”), a Russian military intelligence group that was previously linked to similar router-based campaigns compromising Microsoft 365 accounts.
Organizations can close the primary exposure with one control: enforce always-on, full-tunnel VPN on corporate devices. This routes all traffic—including DNS—through the corporate network before it ever reaches the hotel gateway, effectively stopping the attack.
https://reliaquest.com/blog/threat-spotlight-dns-poisoning-tactics-expand-to-hospitality/
Reporting on China
Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks
Andy Piazza adds to the increasing evidence base of the adoption of a range of AI tooling and in this instance it is by an alleged Chinese threat actor.
Unit 42 identified an AI-enabled autonomous hacking campaign carried out by a Chinese-speaking threat actor. They targeted infrastructure using seven vulnerabilities, combining autonomous AI-driven enumeration with manual exploitation that achieved confirmed impact.
The actor, operating under the aliases knaithe and KnYuan, leveraged DeepSeek, via the Hermes Agent framework, as their autonomous offensive operator. They orchestrated this operator via Telegram for the following activities:
Independently enumerating targets and their vulnerabilities using FOFA
Sourcing exploit tools
Initiating attacks without human intervention
https://unit42.paloaltonetworks.com/autonomous-ai-cyber-attack-campaign/
Dear Diary, Today I found a Ghost in the Network
Intrusion Truth is back detailing the alleged development of Chinese offensive capability.
Guangdong Chanming. If you were looking for them, you’d be disappointed. No public website, no storefront, and certainly no obvious product line to speak of. It made us wonder what their marketing team spends their days doing – if they even have one.
On the surface, they are a ghost. But for those of us that know how to look for the cracks in the Great Firewall, the breadcrumbs they leave behind are more than enough to suggest that this “ghost” is actually a vital gear in China’s cyber machinery.
While they may lack a marketing strategy, their patent filings and software copyrights speak volumes. And they don’t speak of consumer products — they speak of offence. A few of the registered titles alone would raise the eyebrows of any security professional:• 互联网安全接入系统 – Internet Security Access System
• 多功能安全代理系统 – Multi functional Security Proxy System
• 文件传输密网系统 – File Transfer Network System (FTN)
• Security Tunnel Net防溯源密网系统 – Anti traceability Network System (STN)
• 网络设备脆弱性测试分析系统 – Network Vulnerability Testing System
• Android终端秘取平台 – Android Secret Extraction System
• Telegram数据采集落查系统 – Telegram Data Collection System‘Android Secret Extraction System’? ‘Telegram Data Collection System’? Subtle, Guangdong Chanming. Very subtle.
We scoured the web for a sales page, a demo, or even a single product listing. Nothing. These interesting tools Guangdong Chanming seem to offer clearly aren’t sold to the everyday consumer.
https://intrusiontruth.wordpress.com/2026/07/27/dear-diary-today-i-found-a-ghost-in-the-network/
Reporting on North Korea
Operation Double Barrel
ASEC detail an alleged link between a North Korean threat actor and ransomware.
This technical analysis report was prepared as part of the joint cyber security advisory issued by the National Intelligence Service of the Republic of Korea, the National Police Agency, the Korea Internet & Security Agency, and the Financial Security Institute, titled "Advisory on Hacking Attacks on Korean Citizens and Companies by State-Backed Hacking Organizations."
..
These commonalities suggest that while the state-backed hacking group and the Gunra ransomware group appear to be separate entities with different ultimate goals, they may have shared some techniques, tools, and infrastructure or cooperated to a limited extent during the attack process.
https://asec.ahnlab.com/ko/94695/
ClickFix, EtherHiding & a DPRK Wallet Trail
Christian Papathanasiou walks through the end to end of this alleged North Korean operation. Noteworthy due to the use of ClickFix.
A fake macOS "update" screen convinced a victim to paste one command into Terminal, installing a Node.js backdoor that takes its orders from an Ethereum smart contract. We reverse-engineered every stage, then followed the money on-chain.
https://www.allsecure.io/blog/clickfix-etherhiding-dprk-wallet/
North Korean hacker group behind open-source supply chain attacks
CJ Moses attributes this alleged North Korean operation and highlights how they use AI. Also reminds us the scale of the challenge of protecting the open source eco-system.
… how a threat actor linked to the Democratic People’s Republic of Korea (DPRK) is targeting open source software libraries, the shared building blocks that companies around the world use to develop applications. Amazon Threat Intelligence has linked several recent compromises of popular Node Package Manager (NPM) libraries to the same DPRK-linked threat actor, a connection that hasn’t been publicly reported until now. The analysis also describes how generative AI is already changing what malicious software packages look like and how threat actors are beginning to probe AI-based code systems. We’re sharing this research to help the open source community and security teams better identify and address these types of events.
Reporting on Iran
APT42: AI-Assisted Rapport Phishing and a More Resilient TAMECAT
Darkatlas Squad shows how Iran is allegedly using AI to assist in human influence as part of their cyber operations among various other aspetcs.
Three developments define the current picture. SpearSpecter combined prolonged WhatsApp engagement, Windows
search-msand WebDAV abuse, and a substantially expanded TAMECAT backdoor. APT42 also incorporated generative AI into target research, persona and pretext development, translation, malware engineering, debugging, code generation, and exploitation research. In March 2026, TA453 activity overlapping APT42 targeted a US think tank with a live credential-phishing operation during an active regional conflict.Recent malware samples add a technical view. A 2026-dated PDF-themed shortcut, a batch controller, and an obfuscated PowerShell collection module form a probable TAMECAT-compatible chain. A fourth macro workbook carries 2021 timestamps and provides an older point of comparison.
https://darkatlas.io/blog/apt42-ai-assisted-phishing-tamecat-analysis
Mirage Kitten targets Middle East and Africa region with new malware
Omar Amin details an an alleged Irian implant which uses a variety of command and control
Mirage Kitten – also known as UNC1549, Smoke Sandstorm, and Nimbus Manticore – is an advanced persistent threat (APT) group focused on cyber-espionage operations against aerospace, aviation, defense, and telecommunications sectors across the Middle East and Africa, using highly targeted spear-phishing campaigns, fake recruitment portals, and custom multi-stage malware to gain persistent access and exfiltrate sensitive data.
During recent threat research, we identified a previously undocumented malware set developed and used by Mirage Kitten. The toolset includes NightLedger, a new Windows backdoor for reconnaissance, command execution, file operations, process discovery, and screenshot capture; and two custom WebSocket-based tunnelers, ArcBridge and BridgeHead, for covert network access and operator-controlled tunneling.
https://securelist.com/mirage-kitten-new-tools/120811/
Reporting on Other Actors
Check and Protect: Analysis of Telegram Phishing Operation Targeting Exiled Activist
Resident details an interesting campaign against activists and shows some strong social engineering tradecraft.
In July 2026, RESIDENT.NGO investigated an instance of a cloaked Telegram phishing campaign used against an exiled Belarusian activist living in Lithuania. Delivered in a private Telegram Secret Chat as a fake Telegram security alert, the phishing link led to a convincing Telegram-themed page designed to capture one-time login codes in real time. The operation’s defining feature was not the phishing page itself but its browser- and device-aware cloaking: visitors using browser and platform configurations accepted by the server, together with a syntactically valid token, could receive the phishing interface, while other configurations—including many automated scanners and some common desktop browsers—were shown decoy content or redirected to Telegram’s legitimate website. This report examines the operation’s tradecraft, technical implementation, and defensive implications. RESIDENT.NGO has not attributed the activity to a specific threat actor. However, our investigation identified what appears to be part of a broader Telegram phishing campaign targeting users across several countries. We present our findings on that campaign in a separate publication.
HOLLOWGRAPH Backdoor Turns Microsoft 365 Calendars Into a C2 Channel
Umut Bayram details a command and control technique which is of note to defensive teams.
HOLLOWGRAPH is a Windows espionage backdoor delivered as a .NET NativeAOT DLL masquerading as a Brotli library.
It uses compromised Microsoft 365 calendar events as a two-way dead drop for tasking and exfiltration.
Hybrid RSA-OAEP and AES-256-GCM encryption protects Graph payloads, with separate RSA key pairs for each direction.
DNS tunneling over IPv6 AAAA records refreshes Entra ID credentials and preserves mailbox access after secret rotation.
Picus Platform lets teams simulate HOLLOWGRAPH attacks and validate security controls against the malware.
Helpdesk Hijackers: Teams Vishing, Quick Assist, and GoGRPC Backdoor
ThreatLabz walks through the end to end which has a novel command and control element to it which should aid detection.
Since January 2026, ThreatLabz tracked a cluster of attacks likely associated with a ransomware group that begins with targeted vishing via Microsoft Teams, convincing the victim to launch a Quick Assist remote support session.
After initial access, the threat actors use PowerShell scripts to gather host information and deploy a Go-based backdoor that we named GoGRPC and/or other malware tools.
ThreatLabz observed four variants of GoGRPC that we named Lep, Giver, Pet, and Kind. These variants have overlapping capabilities but notable implementation differences.
GoGRPC is actively evolving. Each variant modifies its payloads and capabilities, adding or removing functionality to better support the threat actor’s objectives. Recent changes indicate an increased targeting of corporate environments, which may be tied to ransomware attacks.
GoGRPC communicates with the C2 server using gRPC, which differs from common C2 frameworks where gRPC is typically used for internal communication between components.
The threat actor also deploys SOCKS proxy tools that also use gRPC or WebSockets to communicate with the C2 server.
Software Supply Chain Incursions
A reminder we issued guidance a number of weeks ago in Software supply chain attacks: check your dependencies for software developers
North Korean hacker group behind open-source supply chain attacks
Two Joyfill npm Beta Releases Compromised to Deliver DEV#POPPER Remote Access Trojan
@copilot-mcp/apex: A macOS Infostealer Re-Published on npm After Takedown
Batten Down Your Packages: Mitigation Guidance for Supply Chain Compromise
Discovery
How we find and understand the latent compromises within our environments.
GraphGulo
Mihir Kumar Batar provides a potentially scaled and efficient solution to this problem area.
GraphGulo is a research prototype that converts raw PCAP captures and network flow logs into an indexed temporal graph, then answers time-respecting traversal queries at low-second latency on commodity hardware. The engine is written in Python with a Rust core compiled via PyO3, and has been validated on a 14 GB PCAP file producing 109.6 million edges across 21.3 million nodes.
https://github.com/Mihir4U-avi/GraphGulo
Project ORBITAL
Will Thomas provides a community power tool with this release.
Project ORBITAL is a centralized matrix for mapping, fingerprinting, and hunting China-nexus Operational Relay Box (ORB) networks and malicious edge-device infrastructure based on Open Source Intelligence (OSINT) public reporting.
https://github.com/BushidoUK/Project-Orbital
Defence
How we proactively defend our environments.
A Data Diode with 2 Raspberry Pi and OpenBSD
Sven Seeberg democratises cross domain with this solution.
This project is an OpenBSD-targeted, Rust-based data diode intended to be deployed on two Raspberry Pis. It transmits files via UDP through a fiber optics cable without a back channel. An Arduino can be used to monitor the traffic and show the status on a 1602 LCD.
https://github.com/svenseeberg/data-diode
Microsoft Power Pages Security Utils
https://github.com/DFE-Digital/power-pages-security-utils
An Automated Framework for Extracting Reachable Attack Chains from Cyber Threat Intelligence Reports
Wenbo Hou, Ning Hu, Xueping Wang, Jiahao Gu and Wenjian Luo provide a small scale experiment of the potential future.
On a dataset of 20 CTI reports containing 334 human-validated annotated steps, our framework achieves higher annotated-step coverage than representative CTI extraction systems in recovering attack behaviors. Moreover, by explicitly generating preconditions and postconditions, it produces attack units that are more complete and consistent than those generated by end-to-end LLM baselines. On the extracted chains, Datalog inference reaches the specified attack goal in 19 of 20 reports, while backward search yields 34 attack paths under the generated rules. The source code and experimental artifacts are available in an anonymized repository. .
https://arxiv.org/abs/2607.19742
Stronger with every update: How we’re making Chrome and the web safer in the AI Era
Chrome Security Team detail and provide a breakdown of the world we find ourselves in.
While this dramatic change in software security brought about by LLMs might be startling, an increase in bugs found and fixed is not a sign of failure. Every bug found and fixed is one less foothold for an attacker. But discovering and fixing a bug is only half the battle — we must also ship the fix and apply the update for users faster than adversaries can exploit the bug, and invest in projects that mitigate or eliminate classes of bugs through accelerated release cadences, dynamic patching, and opportune restarts, we are driving toward a browser that is continuously protected without disrupting the user.
The AI era has undeniably intensified the software security threat landscape, but by combining rapid deployment mechanisms with deep structural defenses, we are ensuring the advantage remains firmly with defenders. With this, Chrome and the broader web become safer with every update.
https://blog.google/security/chrome-stronger-with-every-update/
Incident Writeups & Disclosures
How they got in and what they did.
Anatomy of a Frontier Lab Agent Intrusion: A Technical Timeline of the July 2026 Incident
Hugo Larcher, Adrien Carreira, Raphael G and Christophe Rannou detail their intrusion in glorious Technicolor
A companion technical writeup to our incident disclosure. This post walks through how the intrusion actually worked: the two initial-access vectors, how the agent pivoted and moved laterally, representative examples of the commands that were run and how we investigated with GLM 5.2 (an open-source model). Live credentials, internal hostnames, and specific indicators have been redacted or genericized, while the techniques are described exactly as observed by Hugging Face.
https://huggingface.co/blog/agent-intrusion-technical-timeline
Vulnerability
Our attack surface.
Cisco’s Transition to a Risk-Based Vulnerability Disclosure Model
Cisco details their move..
Starting in July 2026, Cisco will further evolve to a risk-based vulnerability disclosure model to address the rapid evolution of AI-driven cyber threat discovery and mitigation. This evolved model prioritizes critical security information and establishes a predictable cadence for hardening releases and related disclosures, helping ensure customers receive prioritized and actionable security information. The operational process is structured as follows:
https://sec.cloudapps.cisco.com/security/center/resources/risk-based-disclosure
Welcome to Danglegeddon
Silent Push highlight the scale of the challenge..
Our research team conducted a simulation examining dangling DNS infrastructure across four industry sectors: government, banking, automotive manufacturing, and pharmaceuticals.
We applied simple, agent-based instrumentation and AI workflows to find, enumerate, and uncover subdomains that could be exploited.
Using the same single technique over and over produced successful results, leading us to determine we were only scratching the surface of an immense scale of takeover possibilities.
https://www.silentpush.com/blog/danglegeddon/
Going depthfirst: Achieving GitLab RCE via Two Ruby Memory Corruption Vulnerabilities
Yuhang Wu uses AI and then chains vulnerabilities together to gain maximum impact. Noteworthy given all the source code targeting of late.
As part of the Open Defense Initiative, the depthfirst system analyzed Oj, a high-performance JSON parser with a substantial native C implementation, and produced a prioritized queue of potentially exploitable findings. The system surfaced 18 prioritized vulnerabilities, including 7 memory-safety bugs. Two of them, an out-of-bounds write and a heap-pointer disclosure, had survived in Oj for nearly five years. Oj is a low-level dependency used by GitLab, and we combined the two bugs to achieve remote code execution on a default GitLab installation. The resulting chain affected GitLab CE and EE versions 15.2.0 through 18.10.7, 18.11.0 through 18.11.4, and 19.0.0 through 19.0.1. GitLab released patches shortly after receiving our reports. The PoC code is available here. This is the kind of problem depthfirst is built to solve: tracing real applications in depth into overlooked code, identifying high-signal critical bugs, and connecting them back to reachable product impact.
Missing MAC validation in wg(4) packet decryption
FreedBSD disclose this oversight.
After dispatching a decrypt operation to OCF and receiving the result, the wg(4) driver failed to check whether the MAC verification step succeeded. The driver thus silently accepted packets with an invalid Poly1305 authentication tag.
https://lists.freebsd.org/archives/freebsd-announce/2026-July/000301.html
RAPTOR autonomous looping multi-altitude security vulnerability hunt
Nicolas Krassas provides a AI vulnerability hunting improved skill (at extra token cost).
An autonomous, looping, multi-altitude security vulnerability hunt for a codebase, packaged as a Claude Code skill. It replaces the model’s default “single pass, summarize, stop” behaviour with an explicit search procedure: traverse every altitude, generate candidates, adversarially verify them from raw source, run isolated parallel reasoners, and keep a persistent ledger so each loop is net-new coverage instead of rediscovery. In practice it finds far more real bugs than a one-shot scan — the “Karpathy auto-research” methodology.
It triggers whenever you point Claude at source code and want vulnerabilities found — “audit this”, “find every bug”, “security-review it”, “find anything exploitable”.
https://github.com/dinosn/raptor-loop-hunt
From /init to Code Execution - Prompt Injection Experiments with Opus-5 in Claude Code¶
Veganmosfet walks through this unsolved problem but demonstrates an end to end attack chain.
Disclaimer: Prompt injection is an unsolved problem. Use sandbox and human review.
How far would it go, beginning with a simple
/initcommand inClaude Code, in a repo containing only a picture? Would it download and execute untrusted code?Short answer: sometimes, yes.
https://veganmosfet.codeberg.page/posts/2026-07-27-opus5/
Offense
Attack capability, techniques and trade-craft.
The SID that wasn’t there: bypassing KB5014754 to Domain Admin on a fully patched AD CS
Mohamed Alzhrani show how it is done which will be of note to cyber defence teams.
A fully patched AD CS issued me a client-auth certificate with no
szOID_NTDS_CA_SECURITY_EXTin it at all. No requester SID. Not mine, not anyone’s. The extension that is the entire point of KB5014754 was simply absent from the issued certificate.That is one line of output from a thirty-second lab run, and it is the whole finding. Everything else in this post — the disassembly, the two bugs, the Domain Admin TGT at the end — follows from it.
Before you close the tab: yes, this needs an ESC1-shaped template, and no, that doesn’t make it a misconfiguration.
https://0xmaz.me/posts/certsrv-id-cmc-addExtensions-KB5014754-bypass/
AgentHound
Adithyan AK provides a capability uplift for those wrestling with agentic infrastructure security.
Offensive security framework for AI agent infrastructure - recon, credential looting, model exfiltration, poisoning, and attack-path analysis across MCP, A2A, gateways, and AI services. BloodHound for the agentic stack.
https://github.com/adithyan-ak/agenthound
Beignet
Joe and Kyle Avery released this a whilst back but will be of note to detection engineers working in MacOS eco-systems.
Donut for MacOS, converts
darwin/arm64anddarwin/amd64.dylibfiles into MacOS PIC shellcode, can be used as a CLI or imported as a golang library.
https://github.com/sliverarmory/beignet
KernelCallbackTable Process Injection
S12 - 0x12Dark Development ..
We are looking at a process injection variant named Kernel Callback Table process injection.
https://medium.com/@s12deff/kernelcallbacktable-process-injection-22112a0d9822
NoNameAx (NaX)
Maor Sabag releases this beacon detection teams will want to ensure coverage of.
Position-independent C2 beacon for the Adaptix Framework with module stomping, malleable C2 profiles, BOF execution, and a Stardust-pattern UDRL loader.
https://github.com/MaorSabag/NaX
OffsetInspect
Jared Perry releases this work aid which will help both sides of the coin.
PowerShell toolkit for AMSI/Defender detection-boundary analysis and static malware triage maps byte offsets to detection triggers, plus YARA, entropy, string, and PE/imphash analysis. Companion to OffsetScan.
https://github.com/warpedatom/OffsetInspect
Exploitation
What is being exploited..
Cisco Secure Firewall Management Center Software Static Credential Vulnerability
Cisco detail..
In July 2026, the Cisco PSIRT became aware of active exploitation of this vulnerability. Cisco strongly recommends that customers upgrade to a fixed software release to remediate this vulnerability.
Tooling and Techniques
Low level tooling and techniques for attack and defence researchers
Virtualization Internals Part 5 - KVM Internals: From VM Creation to Guest Execution
Ayoub Faouzi walks through the VM process.
This chapter provides you with an insight into hardware virtualization and particularly with KVM. The previous chapter described some technical background on how QEMU works, which is considered as an important foundation for what we will be learning today
Reverse engineering what HyperGuard monitors in ntoskrnl
Ian G details what is monitored.
I wanted to dig deeper into the Secure Kernel, and debugging it
I was curious about Alt Syscalls which I posted about here, and what the state of play is with SKPG. Keep reading to find out!
I was curious what the SKPG actually monitors in
ntoskrnl, anything different to normal Patch Guard?
Technical Details: Const Evaluation and Data Layout - Rust on CHERI
Sarah Harris details how Rust on CHERI manifests in practice.
One of the more interesting places where the quirks of CHERI surface is in Rust’s const evaluation mechanism. This feature allows parts of a program to be run during compilation, and the results stored for use when the program is actually run. The set of operations that are supported is limited: trying to perform IO operations during compilation wouldn’t end well, and calculations that might never finish probably aren’t a good choice either. The operations available do, however, include some forms of pointer arithmetic.
https://rust.cheriot.org/2026/07/06/technical-details.html
Random Windows Things Part 2: Unexpected Clipboard Data Behavior
Yarden Shafir details some unexpected behaviour here which could trip some up.
An application can call
AddClipboardFormatListenerto register a callback that gets called whenever the clipboard contents change, like when you copy a file or some text. The process can then callGetClipboardDatato read the data. No special privileges are needed and any process can register this callback unless it is running in a sandbox.The interesting thing is that when a virtual machine is running is “Enhanced session” mode, processes inside the VM that registered a callback with
AddClipboardFormatListenerwill be notified for clipboard changes on the host, or in other VMs that are also running with “Enhanced session”. Of course, the host machine can also read the clipboard contents of the VMs.
https://windows-internals.com/random-windows-things-part-2-unexpected-clipboard-data-behavior/
Intel ME Firmware Reverse Engineering
Jatinkapilaq provides this researcher work aid..
Talk to your Intel Management Engine directly — zero-dependency Python tool. Finds memory leaks, partition manifest, live MKHI probing. First public HECI Spy.
https://github.com/Jatinkapilaq1/intel-me-research
Footnotes
Some other small (and not so small) bits and bobs which might be of interest.
Annual, quarterly and monthly reports
Nothing overly of note this week, but keep an eye on the Awesome Annual Security Reports 2026 collection and APT report collection
IR Trends Q2 2026: Phishing and weaponized remote management tools drive attack chains
DICOMHawk: A Cyber Deception Framework for Medical Imaging Infrastructure
ThreatForest: Multi-Agent Attack Tree Generation with Pluggable TTP Framework Mapping
Artificial intelligence
if you are a big arxiv.org user - out of China there is alphaxiv.org which is an AI powered incarnation / overlay
Fundamental
From Memory to Skills: Evidence-Grounded Co-Evolution Governance for Long-Horizon LLM Agents
Large Language Models Do Not Always Need Readable Language - one for those relying on English prompt and trace analysis
Applied non-cyber
Can AI agents conduct open-ended AI research? Early evidence from two case studies
DECODE: Tackling Representation and Decision Degradation in Continual AI-Generated Image Detection
Automated Transcript Analysis for Detecting Flaws in Agentic Benchmarks
On AI Safety and Security Technical Debt in Engineering AI-Enabled Systems
RoguePrompt: Dual-Layer Encoding for Self-Reconstruction to Circumvent LLM Moderation
Bits and Memories: Measuring Verbatim Extraction Across LLM Quantization
Applied cyber specific
Stitch: Assertion-Guided Patching of On-Chip Protocol Implementations using LLMs
HoF-Bench: Rediscovering Real AI-Discovered CVEs Without Frontier Models
SecRespond: Benchmarking AI Agents for Real-World Post-Compromise Incident Response
Cyber-Capable AI Agents: Vulnerabilities, Evaluation Containment, and Defensive Response
Open Security Benchmark: Towards Autonomous Enterprise Cyber Defense
Network Reciprocity Shapes Evolutionary Cybersecurity Dynamics
CoGate: Confidence-Gated Co-Decoding for Secure Code Generation
SecDrift: Measuring Sector-Conditioned Security Drift in AI-Generated Code
ALIBI: Adaptive Agentic Attacks on LLM-Based Vulnerability Detectors via Adversarial Code Comments
DeepFaith: Evidence-Grounded LLMs for Faithful Incident Reporting in Multi-Stage APT Defense
Just Testing, Move Along: Evasion of LLM-based System Log Interpretation by Prompt Injection
Agentic Permissions Policy Algebra for Taint Confinement in LLM Agents
Cybersecurity Detection Classification with Reasoning-enabled Language Models
StealthBench: Measuring Operational Stealth in Autonomous Offensive-Security Agents
(EC)2: Event-Centric Explainability for Cybersecurity Through Multi-Agent LLM Investigations
Does Runtime Topology Context Improve LLM-Generated Kubernetes Security Patches?
CHARGE: Leveraging CWE Hierarchies for Hardware Security SystemVerilog Assertion Generation
FAVA: Formal Authorization for Verified Agents with Evidence-Backed Permission Graphs
Impossible to hide secret ...: Uncovering Security and Privacy Issues in LLM-native IDEs
I gave GPT my 20 year old disk decryption challenge. It won. - “It did not crack AES. It did not defeat dm-crypt. It did not brute force a password.
The encryption on my disk is still as strong as the day I set it up. What the AI actually did was more interesting. It read old config files, worked out how a mid-2000s Linux distro wired encryption together and patiently carried out a detailed forensic investigation.”
Books
Nothing overly of note this week
Events
Nothing overly of note this week
Finally finally the NCSC’s podcast series.
Unless stated otherwise, linked or referenced content does not necessarily represent the views of the NCSC and reference to third parties or content on their websites should not be taken as endorsement of any kind by the NCSC. The NCSC has no control over the content of third party websites and consequently accepts no responsibility for your use of them.
This newsletter is subject to the NCSC website terms and conditions which can be found at https://www.ncsc.gov.uk/section/about-this-website/terms-and-conditions and you can find out more about how will treat your personal information in our privacy notice at https://www.ncsc.gov.uk/section/about-this-website/privacy-statement.

