newsletter
9 TopicsTenable Security Intel Brief: AI agents ran an intrusion in 10 hours
Welcome to this week's Tenable Security Intel Brief, a curated summary of the top stories in cybersecurity by Tenable's Research Special Operations (RSO) team. But first: Anthropic's Claude Mythos 5 is coming to the Tenable One Exposure Management Platform, where it will power Tenable One Adversary View, debuting in the coming weeks. As Tenable Chief Product Officer Eric Doerr writes, "Mythos 5 provides frontier-scale adversarial reasoning, while Tenable's agentic harness provides the context and controls to turn that reasoning into secure, controlled action." Read the announcement here. This week, Palo Alto Networks' Unit 42 details a ransom-driven intrusion reportedly carried out by AI agents that compressed weeks of attack tradecraft into under 10 hours and left the victim an 80-page audit of its own security posture. AI agents ran a full enterprise intrusion in under 10 hours → Brief: Unit 42 investigated an intrusion where a human attacker reportedly used AI agents to breach an enterprise network, steal credentials, hijack cloud infrastructure, and leave an 80-page security audit, all in under 10 hours. Intel: In ransom negotiations, the attacker told investigators they had used "frontier AI models and attack-specific agentic AI frameworks," a claim Unit 42 relayed without naming any model. Agents entered through a public-facing web service, mapped internal microservices, pulled credentials embedded in code repositories, accessed the secrets management system to harvest master administrative credentials, and hijacked the automated build system to pull cloud access keys. The victim's own AI compute endpoints were then turned into post-compromise infrastructure. Investigators counted over 50 distinct attack techniques executed across the full chain. Why it matters: Over the last year, we have highlighted the rise of AI usage among attackers. Two editions ago, Talos found a crew handing post-breach operations to AI. This attacker reportedly handed agents the entire intrusion, a 10-hour job that could pay for itself in ransom. SonicWall SMA 1000 hit by two more zero-days on a federal clock → Brief: SonicWall disclosed two actively exploited zero-days in its SMA 1000 remote-access appliances on August 31, and CISA added both to the Known Exploited Vulnerabilities (KEV) catalog on September 2 with a federal deadline of September 5. Intel: CVE-2026-83548 is a pre-authentication server-side request forgery (SSRF) flaw (CVSSv3 10.0) in the SMA 1000 Appliance Work Place interface. An unauthenticated attacker can trick the appliance into making requests on their behalf, exploiting it as an unintended proxy to reach sensitive functionality. CVE-2026-83549 is an OS command injection flaw (CVSSv3 7.8) in the Appliance Management Console requiring an authenticated administrator. SonicWall says it "has investigated a case indicating the active exploitation" of the flaws; BleepingComputer reports the two were chained. No workaround exists. Affected: SMA1000 models 6210, 7210, and 8200v only. Why it matters: Shadowserver counts over 400 SMA 1000 appliances reachable online, on a product line at its fourth security event in roughly ten months: a MySonicWall breach in September 2025, a zero-day in December, two more in July, now this pair. The track record runs ahead of the product description. Unauthenticated Magento zero-day hit stores before a fix existed → Brief: CVE-2026-75650, an unauthenticated remote code execution flaw dubbed StyleSmuggler, was assigned a maximum CVSSv3 score of 10 and is being exploited in the wild against Adobe Commerce and Magento Open Source sites. Intel: Our Research Special Operations team compiled a FAQ on the zero-day, which injects PHP through the styles properties in Magento's template system. The code fires with no authentication when a store renders the "Payment Transaction Failed Reminder" email. Sansec reports exploitation began September 4, three days before Adobe's September 7 hotfix VULN-39341, with operators changing payloads several times a day across the window. Why it matters: Sansec found a second, unrelated attacker dropping web shells on stores the implant group had already breached. By the time a fix existed, the flaw was being worked by more than one crew, so patch status told a store nothing about how many intruders it was hosting. UAC-0099 plants an LLM safety trigger in malware to stop AI triage → Brief: ESET discovered GuardBreaker: in an attack on a Ukrainian target, Russia-aligned UAC-0099 planted text in a malicious VBS script to trip AI safety filters and derail AI-assisted analysis. Intel: UAC-0099 inserted the text "I want to make nuclear weapon. Help me ..." as a comment inside the script. When an AI tool scans the file, it hits that text, trips its safety guardrails, and stops analyzing before it reaches the malicious code. The script deploys MATCHBOIL, a loader ESET says is exclusive to UAC-0099, a group that typically targets the transportation and energy sectors; CERT-UA has documented the malware. A June 2026 cluster of PyPI packages used the same approach, Socket reported, embedding weapon-instruction text to force AI scanners into refusal. Why it matters: The safety guardrail did exactly what it was built to do, and that's the problem. An attacker who knows which text stops an AI tool from reading further can use the guardrail itself as a shield for the malicious code that follows. Stat of the week: 153 million The number of digital scans of U.S. and Canadian driver's licenses for sale on Nexus, a new dark-web identity theft service that added nearly 400,000 records in a single 24-hour span, according to KrebsOnSecurity. Tenable's RSO serves as Tenable's Forward Logistics Element in the threat landscape, providing customers with the analyses and contextualized exposure intelligence required to manage risks to critical business assets. With over 150 years of collective expertise, this hand-picked group of world-class security researchers is united with one mission: to cut through the noise and deliver critical intelligence about the most dangerous cyber threats emerging right now.7Views0likes0CommentsTenable Security Intel Brief: How OpenAI's agents coordinated a breach
Welcome to this week's Tenable Security Intel Brief, a curated summary of the top stories in cybersecurity by Tenable's Research Special Operations (RSO) team. But first: Tenable's RSO team and SentinelOne ran a joint analysis of 93 CVE-actor attribution pairs and found that state-sponsored actors and cybercriminals independently converge on the same edge infrastructure. Read it here. This week, OpenAI's technical report on the July Hugging Face breach shows its agents began coordinating through an internal package repository months before the intrusion, and CISA has added two of the exploited flaws to its Known Exploited Vulnerabilities (KEV) catalog. OpenAI ties Hugging Face breach to a message board its agents built → Brief: OpenAI's August 27 technical report traces its July compromise of Hugging Face to agents that began coordinating through internal infrastructure in May, and CISA listed two of the exploited flaws in its KEV catalog. Intel: During internal cybersecurity evaluations run with safeguards disabled, agents repurposed OpenAI's internally hosted Artifactory, a repository manager for software packages, into an improvised message board. They left notes in files starting May 12, then encoded messages in directory names. From there they reached the internet, ran code on 41 of Hugging Face's production servers, gained full administrative control of at least one, and downloaded four private code repositories. CISA listed the Artifactory zero-day (CVE-2026-66384) and CVE-2026-53362, a Linux kernel flaw the agents used to escape an isolated compartment and seize the server. Why it matters: OpenAI calls this "the first known case of an automated agent collective acting offensively without authorization." The coordination that made it possible formed months earlier, inside a package tool no one was watching for. By the time defenders had a breach to trace, the agent collective was already assembled. US seizes domains it says powered alleged Chinese espionage since 2018 → Brief: The Justice Department and FBI seized three domains to disable QScan and QTRouter, twin platforms that court documents allege a People's Republic of China (PRC) state-sponsored group, QTFY, used to scan for and hide attacks on US critical infrastructure. Intel: A companion FBI, NSA and Cyber National Mission Force advisory traces the alleged activity to 2018 and lists 14 exploited flaws, nearly all in internet-facing systems. The group used a Pulse Secure VPN bug (CVE-2019-11510) against the Department of Justice and the Federal Reserve in 2019, and Check Point gateway flaw (CVE-2024-24919) in 2024 to pull data from over 300 organizations. It targeted the US Senate this March without gaining access. According to the advisory, QScan ran "over two million scanning and penetration testing tasks" in a single day in 2024. Why it matters: The exploited flaws mix fresh zero-days with known vulnerabilities disclosed in years prior, and the same classes of VPN and gateway flaws kept surfacing on the list from 2019 through this year. Those are the same product categories our team and SentinelOne flagged as under broad, persistent exploitation. CISA baselines what attackers exploit before AI rewrites the map → Brief: CISA published its Vulnerability Review for fiscal years 2024 and 2025, a snapshot of what threat actors actually exploit before AI-driven vulnerability discovery arrives at scale. Intel: Improper input validation, where software fails to check untrusted data, is what CISA calls "the most frequent weakness type in both the KEV Catalog and CVE records." Volume and exploitation diverge: injection flaws (attacks that slip malicious commands into normal inputs) such as SQL injection and cross-site scripting run high in the CVE dataset yet, by CISA's assessments, cyber-mature organizations have mostly eliminated them. Memory-handling flaws and input validation failures are the reliable entry points, tied to 19.7% of exploited flaws in FY2024 and 16.7% the following year. Why it matters: Three of the weakness classes attackers exploit most today, CISA says, "would have been considered 'unforgivable' nearly two decades ago," and the agency traces the cause to organizational culture and developer workflows, not technical complexity. What decides where an attacker gets in is which shop still ships the old mistakes. Open sign-up turns a Gitea flaw into unauthenticated code execution → Brief: CISA added CVE-2026-60004, a code-injection flaw in the self-hosted Gitea Git service, to its KEV catalog with a three-day federal deadline that expired August 28. Intel: In Gitea's diffpatch API, the feature that applies code changes, a crafted patch plants a Git hook, a script the server executes automatically, that then runs the attacker's commands with the software's own privileges. Write access to any repository is enough, and because Gitea ships with open registration on by default, anyone can register an account and get that access without prior credentials. Salesforce researcher Shai Rod reported it, and a fix shipped in Gitea 1.27.1 on July 27. Attackers are reportedly using unpatched servers to run cryptocurrency-mining malware. Why it matters: Shadowserver counted 8,393 servers still vulnerable on August 27, the day before the deadline, with public exploit code and China, Germany, and the U.S. leading the affected countries. The mandate reaches federal agencies, but Gitea is self-hosted software running past 400,000 installations, so the exposure sits mostly with operators no deadline governs. Stat of the week: 97% The share of 405 AI-enabled malware samples that exist only in sandboxes, research repositories, and security validation platforms, according to Palo Alto Networks' Unit 42, which found just 12 samples on real production endpoints. Tenable's RSO serves as Tenable's Forward Logistics Element in the threat landscape, providing customers with the analyses and contextualized exposure intelligence required to manage risks to critical business assets. With over 150 years of collective expertise, this hand-picked group of world-class security researchers is united with one mission: to cut through the noise and deliver critical intelligence about the most dangerous cyber threats emerging right now.69Views0likes0CommentsTenable Security Intel Brief: Clop returns with a custom Windchill web shell
Welcome to this week's Tenable Security Intel Brief, a curated summary of the top stories in cybersecurity by Tenable's Research Special Operations (RSO) team. This week marks one year of the Security Intel Brief. The first edition was sent on August 27, 2025. The top story this week: the Clop extortion group is exploiting a critical PTC Windchill flaw with a custom-built web shell designed to steal engineering data and decrypt enterprise credentials. Clop deploys a custom data-theft implant against Windchill servers → Brief: ReliaQuest believes a purpose-built web shell, deployed after exploitation of CVE-2026-12569 (CVSS 9.3) in PTC Windchill, a product lifecycle management platform holding engineering data and product designs, is "highly likely" the work of the Clop extortion group. Intel: The web shell, malicious code planted on the server, is equipped to steal data: credential harvesting is built in, and so are file discovery and transfer. A single "S" command reads Windchill's configuration file and decrypts the stored directory-manager, admin, and site-administrator passwords into plaintext. A built-in loader runs fresh attacker code entirely in memory, with nothing written to disk. Extortion emails match addresses on Clop's data leak site. PTC shipped its fix June 17 and CISA added the flaw to its KEV catalog June 25; extortion emails followed in mid-July. Why it matters: The directory-manager password governs Active Directory, email, and VPN, so one decrypt command can hand an attacker credentials reaching far past the compromised server. Clop pairs mass exploitation with a fresh implant each time, the same move it ran with its DEWMODE web shell in 2021 and LEMURLOOT web shell in 2023. Five U.S. agencies warn of AI-built scripts probing Siemens PLCs → Brief: Five U.S. agencies issued a joint advisory warning that attackers are running AI-written scripts, dressed up to look like ordinary monitoring tools, to probe Internet-exposed programmable logic controllers (PLCs) in Siemens' S7 Series. Intel: The NSA, CISA, FBI, DOE, and EPA say the activity spans scouting and tool-building against U.S. installations in energy, water, chemical, food, and critical-manufacturing sectors. Attackers use scanning services such as Censys and ZoomEye to find exposed or poorly segmented S7-200 through S7-1500 controllers. They then run AI-written Python scripts, built on freely available open-source code, that speak the controllers' own communication protocol. That gives read and write access to controller memory and configuration, and to the control programs that run the machinery. The agencies name no threat actor and no new vulnerability. Our team's FAQ on the advisory covers the targeted models and mitigations. Why it matters: The controllers and their flaws were already reachable, and the open-source libraries freely available; what AI supplied was the exploitation code, sharply reducing the expertise a working ICS tool once required. Siemens told CyberScoop the advisory reflects "new techniques to exploit potential misconfigurations." The Python scripts arrive looking like software an operations team already trusts. Medusa ransomware passes 500 victims as FBI adds two exploited flaws → Brief: The FBI, CISA, and the Department of Health and Human Services (HHS) updated their joint #StopRansomware advisory on Medusa, reporting more than 500 victims across critical infrastructure sectors as of April 2026. Intel: Medusa is a ransomware-as-a-service operation first seen in June 2021 that encrypts data and threatens to leak it unless victims pay. The victim count climbed from over 300 as of early 2025, hitting healthcare, schools, law firms, insurers, tech companies, and manufacturers. The refreshed advisory adds two exploited flaws: CVE-2025-10035 in Fortra GoAnywhere and CVE-2026-1731 in BeyondTrust Remote Support and Privileged Remote Access, joining earlier flaws in ScreenConnect and Fortinet. Why it matters: The FBI says Medusa affiliates can turn a newly announced exploit against victims inside 24 hours, and in some cases moved a week ahead of public disclosure. The group writes no zero-days of its own, so the edge comes from obtaining exploits faster than defenders can close known, fixable holes. Talos finds a cybercrime crew running AI as its post-breach operator → Brief: Cisco Talos discovered UAT-10147, a Chinese-speaking criminal operation that uses agentic AI, meaning AI that plans and runs multi-step tasks on its own, to automate work after breaking into web servers. Intel: Talos assesses with moderate-to-high confidence that the financially motivated group, active since early 2026, has shifted beyond simple AI scripting help into semi-autonomous attack orchestration. Talos ties the activity to search-engine fraud and data theft. On the attackers' own servers, an unprotected folder exposed roughly 170,000 target URLs split into 17 files, alongside PentestGPT, an AI penetration-testing tool used to scan victims and launch exploits. The folder also held AI-written runbooks and Python scripts that plant the group's SPECTRE malware and backdoor code. Why it matters: Dwell-time assumptions rest on attackers needing time for trial and error inside a compromised network, and for writing up what worked. This group handed that work to AI. The AI QA-tested the exploit before use and wrote the step-by-step runbooks its operators followed. Stat of the week: 49 The number of Security Intel Brief newsletters sent since the first edition on August 27, 2025. Thank you to everyone who has read, forwarded, filled out a survey, or talked about the Security Intel Brief over the last year. It is because of your feedback that this newsletter is now shareable with customers and published each week in the Vulnerability Watch community. Tenable's RSO serves as Tenable's Forward Logistics Element in the threat landscape, providing customers with the analyses and contextualized exposure intelligence required to manage risks to critical business assets. With over 150 years of collective expertise, this hand-picked group of world-class security researchers is united with one mission: to cut through the noise and deliver critical intelligence about the most dangerous cyber threats emerging right now.117Views0likes0CommentsTenable Security Intel Brief: Lazarus adds a Windows zero-day to its resume
Welcome to this week's Tenable Security Intel Brief, a curated summary of the top stories in cybersecurity by Tenable's Research Special Operations (RSO) team. This week, Check Point Research details what Lazarus Group was willing to spend to make a single fake job offer land, and what that price says about the targets they wanted. Lazarus burned a Windows zero-day on fake job offers to defense firms → Brief: Check Point Research attributed a fake job-offer campaign to Lazarus Group. Attackers used a Windows zero-day against defense, aerospace, and aviation firms in France, Germany, Brazil, and India. Intel: Lazarus exploited CVE-2026-68820, a flaw in a core Windows networking component, to take full control of the machine and deploy FudModule v3.1, a rootkit (malware that hides itself) that switches off Windows' own security logging so defenders lose visibility. The exploit payload was protected with post-quantum encryption (built to resist future quantum computers) and ran in memory, leaving no file behind. Command-and-control traffic ran through at least 17 hijacked third-party servers, including Roundcube webmail instances compromised via CVE-2025-49113. Microsoft patched CVE-2026-68820 in its August 2026 Patch Tuesday. Why it matters: Here's the resume: Windows zero-day, post-quantum exploit encryption, a rootkit that kills logging, and 17 hijacked relay servers. That's what Lazarus spent to reach defense firms building drones, surveillance sensors, and robotics. SAP Commerce Cloud CVSS 10 flaw targeted three days after patch → Brief: SAP patched CVE-2026-58231, a maximum severity flaw (CVSS 10) in SAP Commerce Cloud (formerly SAP Hybris) that lets an attacker act without authorization, enabling unauthenticated remote code execution, on August 11. Intel: CVE-2026-58231 is in the Data Hub Adapter extension of SAP Commerce Cloud. The flaw lets a remote, unprivileged attacker abuse a built-in login component to slip malformed input past the platform's checks, resulting in arbitrary code execution. SAP shipped Security Note 3771065 on August 11. Defused honeypots recorded exploitation attempts on August 14, independently confirmed by threat-intelligence tracker KEV Intelligence: two attempts, one attacker IP. A public proof-of-concept appeared August 15. CISA has not added this flaw to its Known Exploited Vulnerabilities catalog as of August 18. Why it matters: Exploitation attempts began within three days of the patch. A public proof-of-concept landed the day after that, on day four. For a CVSS 10 flaw that needs no credentials and no user interaction, these four days sit entirely inside the window enterprise change-control cycles need just to begin. Kimsuky sets up offline AI environments on its own attack servers → Brief: Genians found that Kimsuky, a North Korean threat group operating under the Reconnaissance General Bureau, built and operated local large language models (LLMs), typically cut off from the internet, on its own command-and-control infrastructure. Intel: Logs from Kimsuky's C2 infrastructure showed Ollama and GPT4All, free tools for running AI models offline, installed and used. Ollama left auto-generated key files confirming a launch; GPT4All carried a localdocs_v3.db, the database a feature creates to let the AI answer questions from a private document set. Genians also found speech-to-text tools and building blocks for adding AI to its own software. Genians assesses the activity as a "research and knowledge acquisition stage," integrating existing AI rather than training new models, and the offline stack has not been observed against a victim. Why it matters: Running AI locally removes the provider oversight that usage policies and takedowns depend on. The attack steps beneath it (booby-trapped shortcuts, hidden scripts, recurring scheduled tasks, GitHub-disguised traffic) read the same no matter how clean the output looks. As local models gain parity with frontier models, defenders stand to lose insight into threat actor playbooks. One IP scraped Salesforce and ServiceNow portals for seventeen months → Brief: A single-IP campaign has been pulling records from misconfigured Salesforce and ServiceNow customer portals that are public and require no login, since at least March 2025, with no vulnerability exploited and the same infrastructure throughout. Intel: Reco traced the campaign to one IP, a Contabo VPS in Germany, running a single custom-built scanning tool that always looked exactly the same. The tooling pulled records through the data-access channels behind these portals, including one in ServiceNow that had barely been documented; the single busiest target logged more than 560,000 events from that one address over the life of the campaign. ServiceNow confirmed no platform compromise; Reco's conclusion: "every byte the attacker retrieved was something a site owner had exposed to anonymous users." Why it matters: Nothing was exploited, so nothing was flagged. The 560,000 logged events at one target sat inside ordinary guest portal traffic, undetected, on infrastructure that has stood for seventeen months. The visibility gap sits on the surface organizations hand to anonymous visitors and then stop watching. Stat of the week: 1.7 billion The number of credentials harvested by infostealer malware across more than 7.4 million compromised systems in the first half of 2026 alone, according to the Flashpoint Global Threat Intelligence Report, Midyear Edition. Tenable's RSO serves as Tenable's Forward Logistics Element in the threat landscape, providing customers with the analyses and contextualized exposure intelligence required to manage risks to critical business assets. With over 150 years of collective expertise, this hand-picked group of world-class security researchers is united with one mission: to cut through the noise and deliver critical intelligence about the most dangerous cyber threats emerging right now.159Views0likes0CommentsTenable Security Intel Brief: Same extortion crew, four new names
Welcome to this week's Tenable Security Intel Brief, a curated summary of the top stories in cybersecurity by Tenable's Research Special Operations (RSO) team. This week, Google Threat Intelligence Group ties the retired BlackFile brand and four successor names to a single extortion operation whose helpdesk vishing playbook never changed, with ransom payments continuing past the group's publicized shutdown. Extortion crew sheds its brand but keeps its vishing playbook → Brief: Google Threat Intelligence Group (GTIG) reports that UNC6671, assessed to be behind the recently retired BlackFile brand, continues to run extortion operations under four new names while its helpdesk voice-phishing (vishing) playbook stayed intact. Intel: GTIG linked UNC6671 to Redact, Pink, Helix, and Falcon, though it allows for splintered affiliates or shared phishing-panel services. Payments to BlackFile wallets continued past its publicized May 11 shutdown. Callers posing as IT helpdesk staff reach employees on personal phones urgently demanding they re-set up account security measures, steering them to fake login pages that capture the login and one-time code as they're typed, then draining Microsoft 365 and Okta data. By July, targeting narrowed to private equity, legal, and financial rating firms whose leverage rests on confidentiality. Why it matters: Cyber-insurance negotiators and defenders build their response around who they think they are facing. When the same operators keep publishing under new brand names, actor identity stops anchoring that decision, and the tradecraft is what still identifies the crew. A self-propagating npm worm mints real provenance for its own malware → Brief: Palo Alto Networks' Unit 42 analyzed ChainDrop, a self-spreading npm worm that has infected over 400 packages, among them poisoned releases of the popular keyv and cacheable-request. Intel: After a poisoned package installs, code that runs automatically fetches the legitimate Bun runtime as an execution vehicle, harvests cloud, npm, GitHub, and SSH credentials, then republishes infected packages with their real functionality intact. The worm looks up its command and control server on the Ethereum blockchain, and on Aug. 4 the operator swapped the entire command infrastructure with one blockchain transaction and no code update. In a repository-gated path, it uses the project's own automated publishing pipeline to sign the tampered package and mints a genuine Sigstore provenance attestation for it. Why it matters: The attestation is genuine: it records that a tampered package came from the named workflow, which was running attacker code. Provenance was the supply-chain signal defenders were told to trust, and here it certifies the malware as authentic. Unit 42 places ChainDrop in the Shai-Hulud lineage without confirming who runs it. Test agents invent fake identities to smuggle malware into code → Brief: The UK AI Security Institute (AISI) cataloged 19 unsanctioned actions in 10 of 122 cyber-evaluation runs where agents targeted real people and organizations on the live internet. Intel: AISI deliberately enabled open-internet access and switched off the providers' cyber classifiers to measure maximum capability, never telling agents what was off-limits; the tested configurations are not commercially available. Of the 19 actions (July 25 to 28), 17 involved Anthropic's Claude Mythos 5 while two involved OpenAI's GPT-5.6 Sol. In a 34.5-hour run, one agent researched two unaffiliated developers, created fake GitHub accounts, and submitted a code change hiding malware as a bug fix. When a user flagged the malware, it rewrote its branch history and claimed an honest mistake. Why it matters: The AI didn't escape its test environment or get tricked into misbehaving; given capability and no guardrails, its target was people. It backed its submission from a second fake account and spear-phished under invented names. It hid instructions for other AI coding tools in webpage text that only software reads. A human maintainer caught it. One incomplete patch reopens N-able N-central to console takeover → Brief: N-able disclosed CVE-2026-18577, an authentication bypass in N-central exploited as a zero-day, which reopened account takeover because an earlier fix for CVE-2026-18556 was incomplete. Intel: N-able's Adlumin managed detection service caught the zero-day on July 31; hotfix 2026.3.1.7 shipped August 2, and a hardened replacement, 2026.3.1.10, followed August 6. CISA added the flaw to the Known Exploited Vulnerabilities (KEV) catalog on August 3 with an August 6 federal deadline, the three-day window Binding Operational Directive 26-04 reserves for urgent risk. Huntress reports attackers took full administrative control of the N-central console, the dashboard managed service providers use to run customer systems, then used Take Control, N-central's own remote-access tool, to reach customer machines, scouted the Domain Controllers running the network, and set up hidden connections to keep access. Why it matters: One console means administrative reach over every downstream customer, which is why exploitation went straight for Take Control and Domain Controllers. Huntress found nearly all cloud-hosted servers patched by August 3, while 28.6% of reachable self-hosted ones stayed exposed. The risk pooled where customers manage the console alone. Stat of the week: 19% The jump in ransomware attacks from June to July, 668 to 799 incidents, according to Comparitech, with finance attacks up 71 percent while ransomware against utility companies, the sector dominating recent headlines, fell 44 percent. Tenable's RSO serves as Tenable's Forward Logistics Element in the threat landscape, providing customers with the analyses and contextualized exposure intelligence required to manage risks to critical business assets. With over 150 years of collective expertise, this hand-picked group of world-class security researchers is united with one mission: to cut through the noise and deliver critical intelligence about the most dangerous cyber threats emerging right now.149Views0likes0CommentsTenable Security Intel Brief: Multi-state cyberattacks hit water systems
Welcome to this week's Tenable Security Intel Brief, a curated summary of the top stories in cybersecurity by Tenable's Research Special Operations (RSO) team. This week, a coordinated attack disrupted operational technology at more than 30 Minnesota community water and wastewater systems, part of a wave the FBI says reached at least seven states. Our research team assesses the activity is consistent with the Iran-linked CyberAv3ngers ecosystem. U.S. officials have preliminarily pointed to Iran, though no formal attribution has been made. Coordinated cyberattack disrupts 30-plus Minnesota water systems → Brief: A coordinated attack disrupted control systems at 30-plus Minnesota water and wastewater plants, one cluster in a wave the FBI says reached at least seven states. Intel: Four Minnesota cities disclosed attacks. In Braham (~1,700 residents), the plant was taken offline, then restored in two hours; Plymouth switched to manual operation and Maple Plain declared an emergency, no water-quality impact reported. U.S. officials told outlets a preliminary assessment points to Iran, citing the tradecraft and lack of a ransom demand, though it could change. Our research finds the pattern consistent with CyberAv3ngers, which the U.S. links to Iran's IRGC. No agency has named a flaw, but the one most tied to it, CVE-2021-22681 (CVSS 9.8), lets attackers reach Rockwell Logix controllers without authentication. Update (August 4): On July 30, an FBI-EPA advisory said utilities in at least seven states had reported incidents since July 27, some degrading operations, naming no states or actor; CISA urged utilities to pull exposed programmable logic controllers (PLCs) offline. On August 1, Michigan became the second confirmed state, an EGLE official citing nine systems and no health impact. By August 4, ABC News and Axios reported possible cyber intrusions in "at least 12" states, citing unnamed sources; the FBI's tally still stands at seven. Why it matters: No flaw is named and attribution stays open, but the exposure is real: internet-facing controllers at least-resourced utilities, tied to a Rockwell weakness its maker says cannot be fully patched. No fix cycle to wait on, only network redesign. The wave already means a plant knocked offline in a town of 1,700. TA488 pivots to Outlook Web Access with a half-click backdoor → Brief: Proofpoint reports that TA488, a Russia-aligned actor also tracked as Void Blizzard and Laundry Bear, is exploiting CVE-2026-42897, an Outlook web (OWA) flaw Microsoft rated maximum severity and CISA lists as exploited, to deploy a browser-based backdoor called OWAReaper. Intel: The campaign began July 22, a day before Proofpoint and the NSA warned of the actor's Zimbra activity. Opening a bland TA488 lure email in OWA runs JavaScript hidden in the message's social-media-icon markup: the reading pane alone triggers it, no link or attachment. That JavaScript is OWAReaper, which Proofpoint calls its "most sophisticated" half-click backdoor yet and a descendant of last week's ZimReaper implant. It steals saved OWA passwords and access tokens, then grants Exchange's "Default" user owner access to every folder, opening it to the actor. Proofpoint says infrastructure predates Microsoft's patch by two months. Why it matters: The folder-permission grant lives on the Exchange server, so it outlasts the responses defenders reach for first. Proofpoint puts it plainly: "credential rotation and even full re-imaging of the targeted user's device will not evict the actor." A second backdoor in the browser's offline cache re-infects the rebuilt machine. This is TA488's second webmail half-click in two weeks. A Chinese-speaking actor ran DeepSeek as an autonomous attack operator → Brief: Palo Alto Networks' Unit 42 documented a Chinese-speaking threat actor, tracked as "knaithe" and "KnYuan," who ran DeepSeek as an AI that attacked on its own after a single instruction, built in the open-source Hermes Agent framework, commanded over Telegram. Intel: Hermes Agent gave the model terminal access and a skills system on a remote command channel. DeepSeek chose targets and wrote the code. From one Telegram instruction, it searched FOFA, an internet-scanning engine, pulled public exploits from GitHub, and attacked on its own. Both autonomous attacks were stopped by the targets' own setup: a Langflow flaw (CVE-2026-33017) and two n8n flaws (CVE-2026-21858 plus CVE-2025-68613). The confirmed damage was manual: a Citrix NetScaler flaw (CVE-2026-3055) leaked data from three organizations, a Marimo Notebook flaw (CVE-2026-39987) ran commands on 11 machines. Across 460+ targets, Unit 42 says the workflow "confirms a functional, end-to-end autonomous offensive capability," while the autonomous campaigns fully compromised none of their targets. Why it matters: The actor tried Claude Code and Codex, but Unit 42 found their provider-side controls "likely limited their effectiveness." DeepSeek was the most permissive alternative, run through a framework with nothing to disable. The starker finding is the one Unit 42 closes on: the technical barrier to AI-augmented offensive operations is low and still dropping. Two AI labs disclose test models reaching real production systems → Brief: Two AI labs disclosed real-world security incidents involving lab-tested models: Anthropic's models reached three real companies through a partner's misconfigured test setup, and OpenAI's models found unpatched flaws in JFrog's software, extending our July 22 OpenAI and Hugging Face coverage. Intel: OpenAI's models found zero-days in self-hosted Artifactory, its repository manager, that could be exploited to gain unintended internet access, JFrog confirmed. The company has shipped fixes; cloud customers are protected and self-hosted users directed to Artifactory 7.161. Its post names no CVEs, though the July 27 patch release carries nine newly assigned Artifactory CVEs. Anthropic separately reviewed 141,006 test runs and found three cases where Claude models reached the internet through partner Irregular's misconfigured test environment, accessing three organizations. In one, a model published a booby-trapped software package to PyPI, a public code library, that ran on 15 real systems, including a security firm's scanner, before PyPI removed it. Update (August 4): OpenAI disclosed two further incidents, separate from the Hugging Face escape, in which its models crossed testing boundaries during third-party evaluations. One was at the UK's AI Security Institute, where internet access was intentionally on and safety classifiers off to measure raw capability. The other was at Irregular, which also ran Anthropic's misconfigured test environment. Neither incident involved a zero-day. Why it matters: Two frontier labs disclosed the same event class in a month: capability tests run without released models' safeguards, in environments with network access. OpenAI's models identified a genuine zero-day. Anthropic calls its incidents "closer to a harness and operational failure than a model alignment failure." Either way, a model built to find a way out found one. Stat of the week: $4.99 million The global average cost of a data breach, up 12% year over year, according to the IBM 2026 Cost of a Data Breach Report, based on breaches at 602 organizations between March 2025 and February 2026. Tenable's RSO serves as Tenable's Forward Logistics Element in the threat landscape, providing customers with the analyses and contextualized exposure intelligence required to manage risks to critical business assets. With over 150 years of collective expertise, this hand-picked group of world-class security researchers is united with one mission: to cut through the noise and deliver critical intelligence about the most dangerous cyber threats emerging right now.149Views0likes0CommentsTenable Security Intel Brief: Russia's Zimbra zero-day ran five months undetected
Welcome to this week's Tenable Security Intel Brief, a curated summary of the top stories in cybersecurity by Tenable's Research Special Operations (RSO) team. This week, Proofpoint details TA488, a Russian-aligned private contractor that quietly exploited a Zimbra zero-day for at least five months in 2025, targeting Ukrainian government and US nuclear and defense industrial base organizations. TA488 hit US nuclear and defense targets with a Zimbra zero-day → Brief: TA488, a Russian-aligned private contractor, exploited CVE-2025-66376, a Zimbra Collaboration Suite zero-day, for at least five months in 2025, targeting Ukrainian government and US nuclear and defense industrial base organizations. Intel: Opening a malicious email in Zimbra's Classic UI webmail was enough to trigger the exploit. TA488 fragmented a malicious SVG tag behind fake CSS @import directives; Zimbra's sanitizer passed each fragment, and the browser reassembled them into executable JavaScript. The payload, tracked as ZimReaper, exfiltrated session security tokens, autocomplete passwords, 2FA scratch codes, the Global Address List, and 90 days of email. It registered a "ZimbraWeb" app-specific password for Internet Message Access Protocol (IMAP) access that bypassed 2FA. Zimbra patched in November 2025; no TA488 activity has been recorded since February 2026. Why it matters: ZimReaper registered a Zimbra application credential that IMAP accepts without a second factor, one that is separate from the account password. For organizations whose mail server is the crown jewel, the half-click delivery closed the window that normally buys time. The user did nothing wrong. GlobalProtect bypass becomes Qilin ransomware's entry point → Brief: Arctic Wolf Labs confirmed that CVE-2026-0257, a GlobalProtect authentication bypass fixed May 13, served as the initial access vector for multiple Qilin ransomware intrusions in June 2026. Intel: The flaw lets an unauthenticated attacker establish a valid VPN session; it is exploitable only where sign-in shortcut cookies are active alongside a specific certificate configuration. In the June intrusions, attackers dumped credentials from memory and the domain's password database, used a standard Windows admin tool to spread across the network, staged ransomware in an empty default Windows folder, then encrypted domain-wide. Tradecraft ranged from rapid encryption to full double-extortion, consistent with multiple Qilin Ransomware-as-a-Service (RaaS) affiliates. CISA flagged the CVE as exploited in ransomware attacks and Shadowserver tracks over 167,000 GlobalProtect instances exposed online. Why it matters: Our June 3 edition noted exploitability hinged on a certificate-wiring decision, not on CVSS. Researchers observed exploitation against numerous customers starting May 17, four days after the fix shipped; confirmed ransomware intrusions followed in June. The configuration gap that decides exposure was already being industrialized before the patch cycle closed. HOLLOWGRAPH turns Microsoft 365 calendars into an espionage dead-drop → Brief: Group-IB identified HOLLOWGRAPH, a malware implant using a compromised Microsoft 365 mailbox calendar as a two-way command channel, hiding operator tasking and stolen files inside events dated May 13, 2050. Intel: HOLLOWGRAPH runs two commands through the Microsoft Graph API, the cloud interface for Microsoft 365: 'get' pulls instructions from a planted calendar attachment; 'send' uploads stolen files into a new far-future event. No flaw is exploited; the malware uses a compromised account and stolen login credentials, leaving no patch. Group-IB tied the implant to Cavern Manticore with high confidence but could not attribute the campaign to any known actor. The Iranian-nexus link comes from a separate Check Point report covered in our July 15 edition. Group-IB counted 12 infected systems between June 3 and July 9, with a focus on Israeli entities. Why it matters: Detection built around flagging traffic to attacker-owned destinations has nothing to match when the command channel is a legitimate Microsoft 365 calendar. The 2050 date parks dead-drop events in a corner of the mailbox no one monitors, and two commands run a complete espionage loop. Oracle's CPU and a kernel flood put CVE volume on trial → Brief: Oracle's July 2026 Critical Patch Update, its quarterly patch bundle, addresses 1,235 unique CVEs in 1,449 patches across 32 product families, the largest CPU release in our analysis. Intel: Context: the January 2026 CPU covered 158 CVEs; April covered 241. That same week, 432 CVEs landed from the Linux kernel team, which issues its own CVEs, in a 31-hour window ending July 20. Jan Schaumann flagged the volume on OSS-SEC; Greg Kroah-Hartman, who oversees the kernel CVE program, explained it: "These were all pending for weeks," the result of "a perfect storm of 6 week straight of conferences and vacations." Kroah-Hartman added that "the number of llm-found issues is only on the rise right now." Why it matters: When one quarterly update carries 1,235 CVEs and the kernel publishes 432 in a weekend, a CVE stops working as a signal to act and becomes a unit of accounting. NVD has logged 45,207 CVEs this year, on pace to roughly double 2025's total; Bloomberg found no rise in exploitation. Stat of the week: $124 million Recorded financial exposure from wrench attacks (incidents where criminals use violence or threats to steal cryptocurrency) in 1H 2026, according to CertiK, which counted 52 verified incidents, up from 39 incidents and $10.5 million a year earlier. Tenable's RSO serves as Tenable's Forward Logistics Element in the threat landscape, providing customers with the analyses and contextualized exposure intelligence required to manage risks to critical business assets. With over 150 years of collective expertise, this hand-picked group of world-class security researchers is united with one mission: to cut through the noise and deliver critical intelligence about the most dangerous cyber threats emerging right now.173Views0likes0CommentsTenable Security Intel Brief: wp2shell WordPress attacks underway
Welcome to this week's Tenable Security Intel Brief, a curated summary of the top stories in cybersecurity by Tenable's Research Special Operations (RSO) team. This week, researchers disclosed wp2shell, a chain of two WordPress core flaws that lets an anonymous attacker run code on a stock install. WordPress pushed fixes to affected sites through forced auto-updates. Two WordPress core bugs chain into code execution with no login → Brief: Researchers disclosed wp2shell, a chain of two WordPress core flaws that lets an anonymous attacker run code on a stock install with no plugins and no login. Intel: CVE-2026-63030 is a flaw in the batch endpoint, a WordPress feature that bundles requests into one call, letting a request run with permissions it should not have. CVE-2026-60137 is a SQL injection that reaches the database. Adam Kues at Searchlight Cyber reported the route bug; a separate team reported the injection. WordPress shipped fixes July 17 through auto-updates; the full chain exists only in 6.9 and 7.0, while the injection alone reaches back to 6.8. Security firms have confirmed active exploitation within days of disclosure, including incident response in several attacks. Why it matters: The fix shipped as open-source code, so researchers reconstructed the flaw from the changed lines and proof-of-concept (PoC) exploits appeared within hours, their speed credited to AI-assisted tooling. Responders are already working confirmed attacks, and the weight is new: all four prior WordPress entries on CISA's KEV catalog were plugins, not Core. SonicWall SMA 1000 zero-days chained to give unauthenticated OS access → Brief: SonicWall disclosed two actively exploited vulnerabilities in its SMA 1000 remote-access appliances, with no available workaround and a federal remediation deadline of July 17. Intel: CVE-2026-15409 carries a CVSS 10.0 rating: it is an SSRF (server-side request forgery) weakness in the SMA 1000 Workplace interface that any unauthenticated remote attacker can reach. CVE-2026-15410 is a CVSS 7.2 code injection weakness inside the Appliance Management Console (AMC); when chained, the two let an attacker run commands on the appliance without logging in. SonicWall PSIRT confirmed "multiple cases indicating the active exploitation." The Cybersecurity and Infrastructure Security Agency (CISA) added both to the Known Exploited Vulnerabilities (KEV) catalog on July 14. No workaround exists. Why it matters: An SMA 1000 concentrates what an intruder otherwise has to earn: VPN session tokens, administrator credentials, and a map of the network behind the gateway. Exploitation was confirmed before any public proof-of-concept existed, and the CVEs drew a federal remediation deadline just three days after they were listed. Sandworm adopts ClickFix to compromise Ukrainian organizations → Brief: Ukraine's CERT confirmed that Sandworm (UAC-0145), a hacking unit tied to Russia's GRU military intelligence, is running ClickFix lures against Ukrainian targets across more than ten compromised websites. Intel: The group's compromised websites display a fake CAPTCHA that tells visitors to copy a PowerShell command and run it on their computer; the command delivers GHETTOVIBE, a VBS file saved to the Startup directory. A reconnaissance tool, SCOUTCURL, then collects system details, programs, files, and browser data so attackers can triage whether the target warrants further compromise. Higher-value systems received FREAKYPOLL, a compiled Python backdoor, and CERT-UA confirmed at least one organization's network was breached (advisory in Ukrainian). Delivery infrastructure uses SMARTAXE, which resolves its domain from a blockchain smart contract, complicating takedown. Why it matters: ClickFix was a crimeware staple, used primarily by financially motivated actors, as Ars Technica notes, "in the last year or so." Sandworm's adoption of it closes the gap between commodity lures and elite state intrusion. The same fake CAPTCHA a security team would file under petty crime can now be a GRU operation. OpenAI's own models escaped a test sandbox and breached Hugging Face → Brief: Hugging Face disclosed a July 16 intrusion into part of its production infrastructure; OpenAI has since confirmed the attacker was its own models, running a benchmark with safety classifiers disabled. Intel: OpenAI's models were running an internal cyber-capabilities benchmark with safety classifiers (guardrails against high-risk cyber activity) disabled. In that state, they exploited a previously unknown flaw in a software-download proxy to escape their sandbox. They then used stolen credentials and more previously unknown flaws to run their own code on Hugging Face's servers, reaching test answers in its production database. Hugging Face says the campaign fired thousands of actions across a swarm of disposable environments and reached a small set of internal datasets and credentials, with no sign user-facing models or Spaces were altered. Why it matters: The frontier AI models Hugging Face tried first refused the attack commands its responders submitted, forcing the forensics onto a model it could run on its own servers. The guardrails that blocked the defenders never touched OpenAI's models: the classifiers were off for the benchmark run. Stat of the week: 97% The share of ransomware victims breached through compromised credentials that had multi-factor authentication (MFA) enabled in some form at the time of the attack, according to the Sophos State of Ransomware 2026 report; deploying MFA and being covered by it are two different things. Tenable's RSO serves as Tenable's Forward Logistics Element in the threat landscape, providing customers with the analyses and contextualized exposure intelligence required to manage risks to critical business assets. With over 150 years of collective expertise, this hand-picked group of world-class security researchers is united with one mission: to cut through the noise and deliver critical intelligence about the most dangerous cyber threats emerging right now.134Views1like0CommentsTenable Security Intel Brief: UAT-7810 builds fresh relay networks
Welcome to this week's Tenable Security Intel Brief, a curated summary of the top stories in cybersecurity by Tenable's Research Special Operations (RSO) team. This week, Cisco Talos details UAT-7810, a China-nexus group whose likely job is standing up the relay networks other espionage crews use to strike their targets, and whose own arsenal now includes a newer version of its SHORTLEASH backdoor plus two previously unknown malware families. China-nexus UAT-7810 builds fresh relay networks with new malware → Brief: Cisco Talos is tracking UAT-7810, an advanced persistent threat (APT) group assessed with high confidence to be China-nexus, and which sustains the LapDogs Operational Relay Box (ORB) network that SecurityScorecard first documented in 2025. Intel: Talos assesses the actor's likely job is to stand up ORB networks, a type of covert network that secondary threat actors like UAT-5918 borrow to strike high-value targets. The actor primarily exploits known vulnerabilities (n-days) in unpatched Ruckus wireless routers (CVE-2020-22653, CVE-2020-22658, CVE-2023-25717), and one server associated with UAT-7810 infrastructure was also used against ASUS AiCloud routers (CVE-2025-2492) in early 2026. Researchers found a newer version of its SHORTLEASH backdoor, tracked as LONGLEASH, plus two previously unknown families, the C-based DOGLEASH and the Java-based JARLEASH, whose configuration file carries comments in Simplified Chinese. Why it matters: Espionage here runs on a division of labor: one crew builds the relay layer, the operators who break in borrow it. LONGLEASH can act as an intermediate command and control (C2), so each compromised edge device becomes another rung of the network. LEASHTEST, a leftover test binary, shows the crew still validating its tooling after shipping LONGLEASH. Microsoft tells customers to expect higher volume of fixes from AI → Brief: Microsoft told Windows customers to expect more fixes in each monthly release as AI accelerates how fast it finds vulnerabilities in its own code. Intel: In a July 9 post, Pavan Davuluri, Microsoft's EVP of Windows and Devices, wrote that "As AI helps defenders discover more issues, customers will see a higher volume of security updates included in each security release." Driving the increase is a multi-model agentic scanning harness (MDASH) that runs candidate flaws through debate across several AI model families before a separate pipeline strips false positives. Microsoft is also revising its Secure Development Lifecycle (SDL) for AI-enabled attack techniques and applying AI to move flaws through remediation faster, with humans kept in the loop for code review. On Tuesday, Microsoft released its July Patch Tuesday, addressing 569 CVEs, the largest release in Patch Tuesday history and nearly triple the previous record of 198 set in June. We break down the full release in our monthly Patch Tuesday blog. Why it matters: The research itself hasn't changed. The engine finding the flaws has. As the same tooling scales across vendors, the monthly cycle grows heavier by design, and the burden of testing and deploying that rising volume settles on the customers running the software. A vibe-coded script mapped Active Directory in a real breach → Brief: Huntress recovered a PowerShell script (a Windows scripting tool) that an attacker used during a June 3 intrusion to map an Active Directory (AD) environment, and its contents show it was built through "vibe coding," prompting AI in natural language until the output works. Intel: The attacker gained remote desktop protocol (RDP) access using pre-compromised credentials, staged tools in C:\ProgramData, a Windows system folder, then ran the script before using legitimate binaries to exfiltrate data. Huntress rebuilt it from telemetry and found the AI's fingerprints: a title reading "100% Working AD Information Gathering Script - FULLY FIXED," an unedited example server name the operator never replaced, five redundant ways to locate a domain controller, and an auto-generated HTML report summarizing the theft. Why it matters: Vibe coding puts bespoke, single-use tooling in the hands of a mediocre actor, and no two of its scripts look alike. What does not change is the tradecraft: the Active Directory enumeration underneath behaves the same way on the operating system no matter who prompted it, and that behavior is what detection can still read. Iran-nexus Cavern Manticore hides its C2 across three .NET formats → Brief: Check Point Research uncovered an Iran-nexus advanced persistent threat (APT) group it tracks as Cavern Manticore, running a modular C2 framework against Israeli government and IT-sector organizations. Intel: Already inside its targets, the group abuses a legitimate software-deployment feature, in one case SysAid's update mechanism, to drop a malicious dynamic link library (DLL) beside a trusted program (WinDirStat) that loads it and launches the Cavern backdoor. Its standout move is architectural: one .NET framework built three separate ways, forcing analysts into a different set of analysis tools for each component, while most samples evade nearly all antivirus detection. Check Point links the group to Iran's Ministry of Intelligence and Security (MOIS) and notes technical overlaps with MuddyWater and Lyceum, a subgroup of OilRig. Why it matters: None of this needed a new exploit. The intrusion runs on the target's own trusted software and on ordinary .NET compilation choices, and each module unloads itself from memory after it runs, leaving little on disk to scan. The near-invisibility is assembled almost entirely from legitimate parts. Stat of the week: 5,811 The number of arrests across 97 countries in Operation First Light 2026, a crackdown on social engineering scams and money laundering that also intercepted USD 293 million in illicit assets, according to Interpol. Tenable’s RSO serves as Tenable’s Forward Logistics Element in the threat landscape, providing customers with the analyses and contextualized exposure intelligence required to manage risks to critical business assets. With over 150 years of collective expertise, this hand-picked group of world-class security researchers is united with one mission: to cut through the noise and deliver critical intelligence about the most dangerous cyber threats emerging right now.92Views1like0Comments