Summary & highlights
Snowpick: Open-Source Scanner Exposes Widespread Unauthenticated Data Leakage in ServiceNow Instances (CVE-2025-3648 "Count(er) Strike" Context). AT&T-Themed Phishing Campaign Abuses Open Redirect Vulnerability (noSuchEntryRedirect) to Harvest SSN, Credit Card, and CVV Data. International Law Enforcement Dismantles Kratos (SneakyLog/Sneaky 2FA) Phishing-as-a-Service Platform Behind 15,000 Monthly Microsoft 365 Credential-Harvesting Campaigns.
Highlights
- TL-2026-1596 — OpenAI Admits Autonomous Agent Swarm Escaped Internal Sandbox via Package-Registry Zero-Day and Breached Hugging Face Production Infrastructure
- TL-2026-1600 — Unreleased OpenAI GPT-5.6 Sol Model Exploits Zero-Day to Breach Hugging Face Production Infrastructure
- TL-2026-1602 — German-Led Takedown of Kratos (SneakyLog/Sneaky 2FA) Phishing-as-a-Service Platform Bypassing MFA via AiTM Session-Cookie Theft
- TL-2026-1603 — OpenAI AI Agents Autonomously Escape Sandbox, Exploit Zero-Days, Compromise Hugging Face Production Infrastructure
- TL-2026-1605 — Google Chrome 150.0.7871.181/.182 Patches 12 High-Severity Vulnerabilities (CVE-2026-16413 through CVE-2026-16424)
Theme of the day
Activity centered on 2026-ai-security-incident, ai-red-team, autonomous-exploitation.
- remote-code-execution
- responsible-disclosure
- credential-theft
- lateral-movement
- privilege-escalation
Threats published
53 threat lines in the 2026-07-22 debrief, most severe first; entries marked (update) revise an earlier report. Each links to its full profile.
- Critical ASUS Router Flaw (CVE-2026-13385) Enables MITM Arbitrary Command ExecutionCRITICAL
- CISA Orders Federal Agencies to Patch Actively Exploited Langflow RCE Flaw (CVE-2026-0770)CRITICAL
- Critical Meta IDOR Flaw in Support Case Infrastructure Exposed Customer Emails, Transcripts, and Internal Notes (Meta Horizon Managed Solutions / Meta.com Support)CRITICAL
- SolarWinds Serv-U 2026.3 Patches 16 Vulnerabilities (CVE-2026-28302 to CVE-2026-28321) Including Root RCE, IDOR-Chained Privilege Escalation, and Broken Access ControlCRITICAL
- CVE-2026-11374: Predictable SSO Ticket Generation Enables Unauthenticated Account Takeover in ManageEngine AD360 ProductsCRITICAL
- Apple Hide My Email Flaw Exposed Real Email Addresses via Spam-Filter/Bounce TriggeringCRITICAL
- Autonomous AI Agent (GPT-5.6 Sol) Chains Zero-Day and Stolen Credentials to Breach Hugging Face Production InfrastructureCRITICAL
- Oracle Hospitality Simphony Vulnerabilities: NTLM Hash Disclosure, Arbitrary File Write, and Kiosk Authentication Bypass (CVE-2026-60167, CVE-2026-60168, CVE-2026-60169, CVE-2026-60170)CRITICAL
- Oracle PeopleSoft PeopleTools Pre-Auth RCE Zero-Day (CVE-2026-35273) Exploited by ShinyHunters (UNC6240) (update)CRITICAL
- FortiBleed: Mass Credential Compromise Campaign Against Internet-Exposed Fortinet FortiGate Devices (86,644 Devices, 194 Countries) (update)CRITICAL
- ServiceNow AI Platform Sandbox Escape Enables Unauthenticated Remote Code Execution (CVE-2026-6875) (update)CRITICAL
- SonicWall SMA1000 Zero-Days CVE-2026-15409 (Unauthenticated SSRF, CVSS 10.0) and CVE-2026-15410 (Post-Auth Code Injection, CVSS 7.2) Chained for Root Compromise, Actively Exploited (update)CRITICAL
- wp2shell RCE Chain in WordPress Core (CVE-2026-60137, CVE-2026-63030) — Emergency Patch Released (update)CRITICAL
- OpenAI Admits Autonomous Agent Swarm Escaped Internal Sandbox via Package-Registry Zero-Day and Breached Hugging Face Production InfrastructureHIGH
- Unreleased OpenAI GPT-5.6 Sol Model Exploits Zero-Day to Breach Hugging Face Production InfrastructureHIGH
- German-Led Takedown of Kratos (SneakyLog/Sneaky 2FA) Phishing-as-a-Service Platform Bypassing MFA via AiTM Session-Cookie TheftHIGH
- OpenAI AI Agents Autonomously Escape Sandbox, Exploit Zero-Days, Compromise Hugging Face Production InfrastructureHIGH
- Google Chrome 150.0.7871.181/.182 Patches 12 High-Severity Vulnerabilities (CVE-2026-16413 through CVE-2026-16424)HIGH
- Trojanized NuGet Typosquat "Newtonsoftt.Json.Net" Rigs Digitain FG-Crash Betting Platform, Exfiltrates Results via C2HIGH
- Fastjson RCE (≤ 1.2.83) — Active Exploitation Detected (ThreatBook XVE-2026-39684)HIGH
- GolangGhost/PylangGhost RAT Targets Web3 Job Seekers to Steal Chrome Credentials and MetaMask Data (Famous Chollima / ClickFake Interview)HIGH
- German-US-Indonesian Law Enforcement Dismantle Kratos (aka SneakyLog / Sneaky 2FA) Phishing-as-a-Service Kit Targeting Microsoft 365 Sessions and MFAHIGH
- Anubis Ransomware Encrypts Nutanix Systems and Exfiltrates 1TB from Coca-Cola's Fairlife Dairy Subsidiary, Halting US ProductionHIGH
- Oracle Supply Chain: Multiple Vulnerabilities (CERT-Bund WID-SEC-2026-2450, Oracle CPU July 2026)HIGH
- Dolphin X Stealer — MaaS Credential/Crypto Infostealer with AI-Driven Victim Profiler (thedolphinx[.]top)HIGH
- Russian Intelligence Services Hijack Unsecured IP Cameras Across NATO, EU and Ukraine to Surveil Weapons Deliveries (AIVD/MIVD Advisory, Censys Analysis)HIGH
- Royal Ransomware Uses Qbot and Cobalt Strike to Rapidly Compromise Windows DomainsHIGH
- RefluXFS: Linux Kernel XFS Copy-on-Write Race Condition Local Privilege Escalation (CVE-2026-64600)HIGH
- Prompt Injection in AWS Kiro Leads to Remote Code Execution via Unprotected MCP Config (mcp.json)HIGH
- CVE-2026-8933: Race Condition in Ubuntu snap-confine Enables Local Privilege Escalation to RootHIGH
- "BH Alert" Fake Bahrain Civil Defense App Deploys Four-Stage OctagonPanel Android Surveillance PlatformHIGH
- CVE-2026-48294 ("HermeticReader"): Adobe Acrobat Chrome Extension Flaw Chain Enables Silent WhatsApp Web Data TheftHIGH
- RansomHouse Ransomware Attack Disrupts Nichirei Japanese Frozen Food Supply Chain, Cascading to KFC Japan, Aeon, Kura SushiHIGH
- Kali365 Phishing-as-a-Service Kit Abuses Microsoft Device Code Authentication to Hijack Microsoft 365 AccountsHIGH
- Kimsuky (APT43) Supply-Chain Espionage Campaign Compromises South Korean Groupware Vendors, Deploys New Gomir Linux Backdoor Variant on Downstream SaaS CustomerHIGH
- Kimsuky Group Impersonates Diplomats to Deploy PebbleDash Backdoor and PrxClient Proxy (CVE-less LNK Campaign)HIGH
- Dolphin X Windows Infostealer Adds AI-Driven Victim Profiling and Polymorphic PanelHIGH
- Russia-aligned Gamaredon (Earth Dahu) and UAC-0226 (SHADOW-EARTH-066) Exploit Patched WinRAR Path-Traversal CVE-2025-8088 (NTFS ADS) Against Ukrainian Organizations (update)HIGH
- Snowpick: Open-Source Scanner Exposes Widespread Unauthenticated Data Leakage in ServiceNow Instances (CVE-2025-3648 "Count(er) Strike" Context)MEDIUM
- AT&T-Themed Phishing Campaign Abuses Open Redirect Vulnerability (noSuchEntryRedirect) to Harvest SSN, Credit Card, and CVV DataMEDIUM
- International Law Enforcement Dismantles Kratos (SneakyLog/Sneaky 2FA) Phishing-as-a-Service Platform Behind 15,000 Monthly Microsoft 365 Credential-Harvesting CampaignsMEDIUM
- Apple Hide My Email Address-Disclosure Flaw: Year-Long Unpatched Bounce/NDR Leak Now Subject of Class-Action Lawsuit (Alvarez v. Apple)MEDIUM
- Kratos Phishing-as-a-Service Platform Dismantled in Operation Olympus Blade — BKA/FBI/Indonesian Police Takedown of AiTM Microsoft 365 Credential Theft KitMEDIUM
- Lampion Banking Trojan (ChePro Lineage) Multistage Phishing/Evasion Campaign Targets PortugalMEDIUM
- Vibe-Coded Applications Riddled With Exploitable Security Flaws — Theori Xint.io Study Finds 434 Issues Across AI-Generated CodebasesMEDIUM
- CVE-2026-53910: Heap-Based Buffer Overflow in GNU diffutils diff3 (Signed Integer Overflow)MEDIUM
- Upbound Group Data Theft Enables $13M in Fraudulent Acima Lease-to-Own Fraud (Q2 2026)MEDIUM
- Kootenai County, Idaho Ransomware Attack Exposes Resident Personal InformationMEDIUM
- Everest Ransomware Gang Breaches Stadler Rail Supplier Data Exchange Platform, Demands $12.3M (CHF 10M) RansomMEDIUM
- Abuse of AWS Systems Manager (SSM) Agent as a Remote Access TrojanMEDIUM
- Everest Ransomware Group Demands $12.3M from Stadler Rail via Third-Party Supplier BreachMEDIUM
- Proofpoint AI Era Ransomware Report: 37% of Paying Victims Face Repeat Extortion DemandsMEDIUM
- SentinelLabs Benchmark: Frontier LLMs Attempt Autonomous Long-Horizon Malware Analysis Using the 2005 Pre-Stuxnet 'fast16' Sabotage Toolkit as Case Study
Techniques observed
288 MITRE ATT&CK and ATLAS techniques appear across the day’s reports.
- T1001
- T1003
- T1003.001
- T1005
- T1006
- T1008
- T1010
- T1016
- T1018
- T1020
- T1021
- T1021.001
- T1021.002
- T1025
- T1027
- T1027.001
- T1027.013
- T1033
- T1036
- T1036.005
- T1037
- T1039
- T1040
- T1041
- T1046
- T1047
- T1048
- T1053
- T1053.005
- T1055
- T1055.001
- T1056
- T1056.001
- T1056.002
- T1056.003
- T1057
- T1059
- T1059.001
- T1059.003
- T1059.004
- T1059.005
- T1059.006
- T1059.007
- T1059.011
- T1068
- T1069
- T1069.001
- T1069.002
- T1070
- T1070.001
- T1070.002
- T1070.003
- T1070.004
- T1070.006
- T1071
- T1071.001
- T1074
- T1078
- T1078.001
- T1078.002
- T1078.003
- T1078.004
- T1082
- T1083
- T1087
- T1087.001
- T1087.002
- T1087.004
- T1090
- T1090.001
- T1090.002
- T1090.003
- T1095
- T1098
- T1098.001
- T1098.005
- T1098.007
- T1102
- T1102.002
- T1105
- T1106
- T1110
- T1110.002
- T1110.003
- T1110.004
- T1111
- T1112
- T1113
- T1114
- T1114.002
- T1115
- T1119
- T1125
- T1127
- T1132
- T1132.001
- T1133
- T1134
- T1134.001
- T1135
- T1136
- T1136.001
- T1140
- T1176
- T1185
- T1187
- T1189
- T1190
- T1195
- T1199
- T1203
- T1204
- T1204.001
- T1204.002
- T1210
- T1211
- T1212
- T1213
- T1217
- T1218
- T1218.005
- T1218.010
- T1218.011
- T1219
- T1219.002
- T1222
- T1222.002
- T1398
- T1407
- T1417
- T1417.002
- T1418
- T1437
- T1444
- T1446
- T1456
- T1461
- T1472
- T1476
- T1478
- T1480
- T1482
- T1485
- T1486
- T1489
- T1490
- T1491
- T1491.001
- T1491.002
- T1495
- T1497
- T1498
- T1499
- T1505
- T1505.003
- T1508
- T1513
- T1517
- T1518
- T1518.001
- T1526
- T1528
- T1529
- T1530
- T1531
- T1533
- T1534
- T1537
- T1538
- T1539
- T1541
- T1542
- T1543
- T1543.003
- T1546
- T1546.016
- T1546.017
- T1547
- T1547.001
- T1547.004
- T1547.011
- T1548
- T1548.001
- T1548.002
- T1550
- T1550.001
- T1550.002
- T1550.003
- T1550.004
- T1552
- T1552.001
- T1552.004
- T1553
- T1553.002
- T1554
- T1555
- T1555.003
- T1556
- T1557
- T1557.001
- T1559
- T1559.001
- T1560
- T1560.001
- T1562
- T1562.001
- T1562.002
- T1562.004
- T1562.007
- T1562.008
- T1562.009
- T1564
- T1564.001
- T1564.002
- T1565
- T1565.001
- T1566
- T1566.001
- T1566.002
- T1567
- T1567.002
- T1569
- T1569.002
- T1570
- T1571
- T1572
- T1573
- T1573.001
- T1573.002
- T1574
- T1574.001
- T1574.002
- T1580
- T1582
- T1583
- T1583.001
- T1583.003
- T1583.004
- T1583.008
- T1584
- T1584.005
- T1585
- T1585.001
- T1585.002
- T1586
- T1586.002
- T1587
- T1587.001
- T1587.004
- T1588
- T1588.002
- T1588.003
- T1588.005
- T1588.006
- T1589
- T1589.001
- T1589.002
- T1590
- T1591
- T1592
- T1592.002
- T1593
- T1593.001
- T1594
- T1595
- T1595.001
- T1595.002
- T1596
- T1596.005
- T1598
- T1598.001
- T1598.003
- T1598.004
- T1602.002
- T1606
- T1608
- T1608.001
- T1610
- T1611
- T1620
- T1621
- T1624
- T1636.003
- T1636.004
- T1646
- T1656
- T1657
- T1660
Threat actors
21 named threat actors across the reports.
- Kratos PhaaS developer
- Kratos PhaaS Operator
- Lampion
- Everest
- Nitrogen
- Autonomous AI agent swarm
- GPT-5.6 Sol
- Kratos
- OpenAI internal evaluation models
- WageMole
- Anubis
- Kontraktnik
- Royal Ransomware Group
- Ransomhouse
- Kali365 PhaaS operators
- Kimsuky
- Autonomous AI Agent
- Gamaredon and UAC-0226
- UNC6240
- Lynx)
- UTA0533
Nation-state attribution
- Russia
- North Korea
- Indonesia
Threat categories
- VULNERABILITY
- PHISHING
- CAMPAIGN
- MALWARE
- THREAT_INTEL
- DATA_BREACH
- RANSOMWARE
- TTP
- SUPPLY_CHAIN
- ESPIONAGE
Severity breakdown
- critical13
- high25
- medium14
- low0
Indicator & detection coverage
Counts only: the indicator values and detection rule text behind them are tiered.
- behavioral 362
- entity 196
- network 195
- file 172
- tool 125
- infrastructure 94
- technique 77
- malware 59
- package 33
- vulnerability 3