Signal from the Grid

Industry News

A running log of the threat intelligence, breaches, and AI-security developments D2 tracks daily — the signal, filtered from the noise.

Updated every weekday morning
Jul 2 Thursday
★ Top Read

AI-Generated Browser Ransomware Bridges Theory to a Working Attack

Check Point found malware built with DeepSeek that combined a previously dismissed browser-malware concept with a real Chromium capability into working ransomware on both Windows and Android.

Unpatched Argo CD Repo-Server Flaw Enables Full Kubernetes Cluster Takeover
Progress Kemp LoadMaster Flaw Moves to Active In-the-Wild Exploitation
Adobe Patches Seven CVSS 10.0 Flaws in ColdFusion and Campaign Classic
SEO-Poisoned Software Sites Abuse ScreenConnect to Deploy AsyncRAT
VEIL#DROP Delivers PureLogs Stealer via Blogger; Ousaban Trojan Hits Iberian Banks
19-Year-Old Scattered Spider Suspect Extradited to Face US Hacking Charges
'DuneSlide' Zero-Click Prompt Injection Escapes Cursor's Sandbox to Achieve RCE
'Phantom Squatting': Attackers Register AI-Hallucinated Domains for Phishing
US Lifts Jailbreak-Linked Export Controls on Anthropic's Claude Fable 5
View full brief →
Jul 1 Wednesday
★ Top Read

Poisoned MCP Tool Descriptions Can Turn AI Agents Into a Silent Data-Exfiltration Channel

Microsoft found that a malicious server can rewrite a hidden AI tool description to direct an agent to quietly collect and ship out sensitive data — with every step looking routine and no policy ever broken.

Pre-Auth Root RCE Found in Progress Kemp LoadMaster (CVE-2026-8037)
Oracle E-Business Suite Payments Flaw Under Active Exploitation (CVE-2026-46817)
SimpleHelp Auth Bypass Exploited to Drop TaskWeaver and Djinn Stealer
RustDuck Botnet Rebuilds in Rust to Hijack Routers for DDoS
'Silent Swap' Crypto Clipper Ships as Fake Google Notes Chrome Extension
'GuardFall' Shell Trick Bypasses Safety Checks in 10 of 11 AI Coding Agents
'BioShocking' Attack Tricks Six AI Browsers Into Leaking User Credentials
282 of 444 iOS AI Apps Found Leaking API Keys in Network Traffic Study
View full brief →
Jun 30 Tuesday
★ Top Read

Public PoC Released for Critical libssh2 Client-Side SSH Flaw (CVE-2026-55200)

A CVSS 9.2 memory-corruption bug in libssh2 is statically linked into curl, Git, PHP, backup agents, and countless appliances — and a distro update won't fix most copies.

New 'DirtyClone' Linux Kernel Flaw Enables Local Root Escalation
Hijacked npm and Go Packages Deploy Python Infostealer via VS Code Tasks
Mustang Panda Turns Zoho WorkDrive Into a Covert C2 Channel in Indian Government Networks
Malicious 'Perplexity' Chrome Extension Intercepted Searches and Address-Bar Input
Microsoft Removes 119 Edge Extensions Hiding Malware in Images and Fonts
Cisco Catalyst SD-WAN Zero-Day Stays a Federal Must-Fix Under CISA KEV
View full brief →
Jun 29 Monday
★ Top Read

GPT-5.6 Sol Preview Advances AI's Vulnerability-Research Capability

OpenAI's new GPT-5.6 'Sol' model discovered previously unknown vulnerabilities in widely used software and mobile devices during third-party testing, though it still couldn't complete full attacks against well-defended targets.

Nintendo Employee Data Exposed via TinyPulse HR-SaaS Breach
Novel SharkLoader Dropper Targets Governments and Software Developers
US Offers $10M Reward for Russian FSB-Linked Hackers Behind Signal Recovery-Key Phishing
Active Cryptomining Campaign Exploits Langflow AI Platform Flaw
June 2 AI Executive Order's 60-Day Deadlines Land in Early July
View full brief →
Jun 28 Sunday
★ Top Read

Cisco to acquire WideField Security to bring AI-agent identity into Splunk

Cisco's planned acquisition folds non-human and AI-agent identity discovery, exposure mapping, and live session monitoring into Splunk, aimed at the exact failure mode the agentic SOC introduces: authorized entities taking unsafe actions in the wrong context.

ShinyHunters Oracle PeopleSoft extortion spree hits higher education hardest
Critical Splunk Enterprise RCE added to CISA KEV
Polymarket frontend supply-chain theft drains user wallets
"Gaslight" macOS malware targets the AI analysis layer itself
June 2 AI Executive Order deadlines now landing
Splunk ES Premier reaches FedRAMP Moderate
View full brief →
Jun 27 Saturday
★ Top Read

FortiBleed campaign escalates against internet-facing Fortinet gear

Attackers are harvesting configuration files from exposed FortiGate devices and cracking the stored credential hashes into working administrator logins, at a scale researchers estimate between roughly 30,000 and 86,000 devices worldwide.

PTC Windchill/FlexPLM RCE added to CISA KEV amid active web-shell exploitation
"DirtyClone" Linux kernel privilege-escalation flaw gets a public exploit
Agentic-SOC research surfaces a cascading-failure risk
CISA's Binding Operational Directive 26-04 passes its first real test date
View full brief →
Jun 25 Thursday
★ Top Read

"Cordyceps": a systemic class of exploitable CI/CD weaknesses across the open-source supply chain

Scanning roughly 30,000 high-impact repositories, researchers validated hundreds of full exploit chains and confirmed fixes at Microsoft, Google, Apache, Cloudflare, and the Python Software Foundation.

Cisco Unified CM SSRF flaw now actively exploited to root
Amadey and StealC malware infrastructure seized in coordinated takedown
Agentic coding is now a vulnerability-propagation vector, not just a productivity story
CIRCIA reporting-rule timeline back in focus
View full brief →
Jun 24 Wednesday
★ Top Read

Four actively exploited flaws in Ubiquiti UniFi OS and Lantronix added to CISA KEV

The worst, CVE-2026-34908, is a CVSS 10.0 improper-access-control bug that lets an unauthenticated attacker on the network reconfigure or pivot through UniFi gear.

Tata Electronics confirms breach; World Leaks dumps 200k+ files tagged to Apple and Tesla
"Squidbleed": a 29-year-old Squid proxy bug leaks cleartext requests
libssh2 unauthenticated RCE affects a library embedded almost everywhere
Klue/Icarus OAuth-token supply-chain campaign keeps widening
OWASP ships "State of Agentic AI Security & Governance"; prompt injection still unsolved
BOD 26-04 is now operative, not theoretical
View full brief →
Jun 23 Tuesday
★ Top Read

FortiBleed: 74k-86k FortiGate devices with compromised credentials

Attackers harvested working administrator and SSL-VPN credentials from internet-facing FortiGate firewalls at scale by cracking weakly hashed secrets pulled from device configs, and CISA has issued a hardening advisory.

"The Gentlemen" ships a standardized EDR-killer suite to affiliates
Roughly 24 billion credential records found in an exposed database
Apple "usbliter8" SecureROM proof-of-concept goes public
Agentic-SOC tooling keeps moving from demo to default
CISA issues Binding Operational Directive 26-04
View full brief →
Jun 22 Monday
★ Top Read

Klue OAuth Breach Spreads Across the Security Industry via Salesforce

A single dormant legacy credential at market-intelligence vendor Klue let attackers harvest customer OAuth tokens, breaching Salesforce data at Recorded Future, Tanium, Jamf, Gong, and other security-industry names.

WordPress Plugin Flaw Under Mass Exploitation, 17M+ Attempts Blocked
Splunk RCE Deadline Passes — Exploited Eight Days After Patch
New "Prinz Eugen" Ransomware Runs Quiet, Skips the Ransom Note
Conti Loader Developer Pleads Guilty
Microsoft Ties Mastra npm Supply-Chain Attack to North Korea
SolarWinds Serv-U Flaw Actively Exploited
AI Executive Order's CISA Mandates Begin Shaping the Patch Regime
View full brief →