Signal from the Grid

Industry News

A running log of the threat intelligence, breaches, and AI-security developments D2 tracks daily — the signal, filtered from the noise.

Updated every weekday morning
Jul 13 Monday
★ Top Read

GhostApproval: When the AI's Approval Prompt Lies to You

Six leading AI coding assistants can show a user one file in the approval dialog while the agent operates on another via symlink — collapsing human oversight into rubber-stamping.

Palo Alto patches 13 PAN-OS flaws, one critical unauthenticated RCE
Crafted GitHub Issues trick AI dev workflows into leaking private-repo data
AssuranceAmerica — 6.99M driver's-license numbers exposed, largest DL exposure of 2026
Accenture confirms "isolated matter" after 35GB source-code-and-secrets sale listing
BOD 26-04: today is the remediation deadline for the July 10 KEV batch
Five Eyes "act now" warning stands — AI models capable of overwhelming defenses are "months, not years" away
View full brief →
Jul 11 Saturday
★ Top Read

"Ill Bloom" Weak-Randomness Flaw Has Drained Over $5 Million From Crypto Wallets

A weak-randomness flaw in how certain older software wallets generated recovery phrases let attackers reconstruct private keys directly, producing seeds with far less entropy than a standard phrase implies.

CISA Adds Two Joomla Extension Flaws to Its Exploited-Vulnerabilities Catalog
SharePoint Flaw Microsoft Called "Less Likely" to Be Exploited Remains a Live Lesson
A Quarter Later, No Major Vendor Has Shipped an AI-Agent Behavioral Baseline
Conduent Breach Confirmed at 62.2 Million — Third-Largest in US Healthcare History
Former Ransomware Negotiator Sentenced for Conspiring With BlackCat Operators
CISA's Risk-Based KEV Cadence Continues to Compress Patch Deadlines
View full brief →
Jul 10 Friday
★ Top Read

Langflow Becomes First AI-Agent Platform Added to CISA's KEV Catalog

A cross-tenant vulnerability in the popular Langflow AI-agent-building framework let an authenticated attacker run another tenant's flows and steal the LLM-provider API keys and cloud credentials those agents hold.

Adobe ColdFusion Flaw Exploited Within Hours of Technical Write-Up
New CitrixBleed-Class Flaw in NetScaler Exploited Within 24 Hours
Fortinet FortiSandbox Hit by Active Unauthenticated RCE Exploitation
Live Campaigns Use Prompt Injection to Trick AI Agents Into Crypto Payments
KDDI Telco Breach Fallout Continues Across Six Japanese ISPs
CISA's Risk-Based Patch Directive Compresses the Compliance Calendar
View full brief →
Jul 9 Thursday
★ Top Read

"GitLost" Tricked GitHub's AI Agent Into Leaking Private Repos

An unauthenticated attacker could open an ordinary public GitHub Issue that, once assigned to GitHub's Agentic Workflows, tricked the AI agent into pulling a private repository's README into a public comment.

Accenture Confirms 35GB Theft of Source Code and Cloud Secrets
Ubiquiti Patches Maximum-Severity UniFi Flaw Exposed on 100,000+ Devices
Microsoft Defender Privilege-Escalation Flaw Now Confirmed in Ransomware Attacks
SharePoint Flaw Slipped Past Teams After Microsoft Omitted It From Patch Notes
Gitea Docker Default Configuration Flaw Remains Under Active Exploitation
EU Unveils Action Plan on Cybersecurity and AI
View full brief →
Jul 8 Wednesday
★ Top Read

JADEPUFFER: the first ransomware operation run entirely by an autonomous AI agent

Sysdig documented an LLM agent that exploited an unauthenticated Langflow RCE, then on its own did recon, harvested credentials, pivoted to a production database, and encrypted 1,342 config items — even rewriting its own parser mid-attack when it hit an unexpected response format.

FortiBleed hardens from credential leak into a confirmed ransomware pipeline (INC Ransom + Lynx)
Medtronic notifies 3.8M people after a ShinyHunters intrusion
Citrix NetScaler "CitrixBleed 2.0" exploited within 24 hours of disclosure
Gitea Docker images shipped a one-header path to admin, now being probed
Tenda router backdoor disclosed with no patch and a public proof-of-concept
A 16-year-old Linux KVM flaw lets a guest VM escape to the host on Intel and AMD
CISA adds three more actively-exploited flaws to its Known Exploited Vulnerabilities catalog
View full brief →
Jul 6 Monday
★ Top Read

SharePoint Flaw Patched in May Is Now a Live Ransomware Campaign

Storm-2603 is exploiting the SharePoint deserialization flaw federal agencies were ordered to patch by July 4 to deploy Warlock ransomware, with Microsoft reporting two unrelated attackers operating inside the same network.

China-Nexus Campaign Clones India's Tax-Filing Utility to Drop DcRAT
Seven Unfixed Bugs Found in a Filesystem Library Embedded in Millions of Devices
New Air-Gap Exfiltration Technique Turns a Video Cable Into a Radio
Researchers Found a Critical Bug Using an AI Coding Assistant in Auto Mode
Congressional Briefings on the DHS HSIN Breach Now "All But Certain"
View full brief →
Jul 5 Sunday
★ Top Read

DHS Confirms Weeks-Long Breach of HSIN During World Cup Security Operations

The Department of Homeland Security has confirmed a cyber incident on HSIN, its sensitive-but-unclassified information-sharing hub — a breach believed to have run undetected for weeks while the platform coordinated live World Cup security operations.

ShinyHunters Escalates Council of Europe Extortion Claim
SharePoint RCE Federal Patch Deadline Passes as Exposure Persists
ColdFusion and "Bad Epoll" Remain Open Risk for Unpatched Fleets
The Week's AI-Attacker Arc Holds: Building and Running Attacks Alike
Congressional Oversight of the HSIN Breach Opens a Federal Accountability Question
View full brief →
Jul 4 Saturday
★ Top Read

AI-Assembled Avalon Malware Framework Built to Evade Every Major EDR

A newly documented malware framework shows clear signs of AI-assisted development, bundling credential theft, lateral movement, remote access, and a ransomware payload into one kit engineered to hide from nine leading endpoint security products.

Pegasus Spyware Infected an EU Lawmaker Investigating Spyware Abuse
"Bad Epoll" Linux/Android Kernel Flaw Offers Near-Certain Root Escalation
Adobe ColdFusion Flaw Exploited Within Hours of Disclosure
Federal Deadline Hits Today for Actively Exploited SharePoint Flaw
The Attacker's AI Now Spans Both Building and Running Intrusions
EU AI Act Transparency Rules Take Effect August 2
View full brief →
Jul 3 Friday
★ Top Read

JADEPUFFER: First Documented End-to-End AI-Run Ransomware Operation

Sysdig captured what it assesses to be the first case of a complete ransomware extortion run driven autonomously by an LLM — from initial access through a Langflow flaw to a fully executed extortion playbook.

Google and FBI Seize NetNut/'Popa,' a 2-Million-Device Residential Proxy Botnet
Anubis Ransomware Turns to Citrix Bleed 2, BYOVD, and Supply-Chain Credentials
FortiBleed Credential Theft Now Tied to INC and Lynx Ransomware
ToddyCat's 'Umbrij' Malware Abuses OAuth Tokens to Read Gmail via Google API
'ChocoPoC' RAT Hides in Fake Exploit Repos to Target Vulnerability Researchers
Identity Lifecycle Management Wasn't Built for AI Agents
ThreatsDay Roundup Flags AI Compute Hijacking and Agent-Abuse Pattern
CISA Adds SharePoint RCE (CVE-2026-45659) to KEV; Federal Deadline July 4
Argo CD's Unpatched Repo-Server RCE Remains Open, No Fix in Sight
View full brief →
Jul 2 Thursday
★ Top Read

AI-Generated Browser Ransomware Bridges Theory to a Working Attack

Check Point found malware built with DeepSeek that combined a previously dismissed browser-malware concept with a real Chromium capability into working ransomware on both Windows and Android.

Unpatched Argo CD Repo-Server Flaw Enables Full Kubernetes Cluster Takeover
Progress Kemp LoadMaster Flaw Moves to Active In-the-Wild Exploitation
Adobe Patches Seven CVSS 10.0 Flaws in ColdFusion and Campaign Classic
SEO-Poisoned Software Sites Abuse ScreenConnect to Deploy AsyncRAT
VEIL#DROP Delivers PureLogs Stealer via Blogger; Ousaban Trojan Hits Iberian Banks
19-Year-Old Scattered Spider Suspect Extradited to Face US Hacking Charges
'DuneSlide' Zero-Click Prompt Injection Escapes Cursor's Sandbox to Achieve RCE
'Phantom Squatting': Attackers Register AI-Hallucinated Domains for Phishing
US Lifts Jailbreak-Linked Export Controls on Anthropic's Claude Fable 5
View full brief →