The attack surface has moved. Trusted tools are the new execution layer.
What the second half of June revealed
Attacker behavior is following authority. The systems enterprises rely on to build, connect, support and govern their operations are now the first targets — because they carry the credentials, tokens, workflows and trust that travel furthest inside an organization.
The trusted tool is now the execution path. Understanding which tools carry authority, and ensuring that authority is governed, is the leadership discipline this period demands.
01Executive Overview
Trusted tools are becoming execution paths
The second half of June reinforced a structural shift in enterprise security. Attackers are not only targeting business applications. They are moving through the tools that help organizations build, support, connect, observe, recover, authenticate, automate and govern those applications. The period included AI coding-agent bypasses, AI browser credential leakage, remote support exploitation, OAuth abuse, Salesforce data theft, Microsoft Teams relay abuse, supply-chain attacks, Fortinet credential harvesting, Cisco SD-WAN exploitation, Splunk exploitation, Oracle E-Business Suite exploitation, PTC Windchill exploitation and OT device advisories. Trusted tools carry authority. Attackers are following that authority wherever it leads.
The five lead signals
Signal 01 · AI Agents
AI agents turned context into execution risk
GuardFall, BioShocking, Amazon Q Developer, Claude Code repository attacks, AutoJack, DifyTap, malicious AI skills and OpenClaw issues all point to the same gap. AI agents interpret context, invoke tools, run commands and make decisions inside live environments. The context an agent consumes is now part of the security boundary. Repositories, tickets, error reports, browser pages, notifications and plugins can become instruction paths that organizations have not yet defined governance for.
Signal 02 · Developer Tools
Developer tools continued to carry enterprise credentials
Amazon Q Developer, Claude Code, JetBrains Marketplace plugins, npm and Go package compromises, Mastra packages, Cordyceps CI/CD weaknesses and malicious browser extensions showed how developer tooling can become a credential collection and execution layer. A developer workstation carries cloud tokens, GitHub access, AI provider keys and deployment authority. Compromise at this layer moves quickly into production risk without touching a single production server directly.
Signal 03 · Control Planes
Control-plane systems remained high-value targets
SimpleHelp, Oracle E-Business Suite, Progress Kemp LoadMaster, Cisco SD-WAN, Cisco Unified Communications Manager, Splunk Enterprise, FortiSandbox, PTC Windchill, Lantronix EDS5000, Webmin and NGINX all appeared. These systems support access, routing, observability, engineering, payments, administration or recovery. Weakness in these layers creates operational leverage that extends well beyond any single application.
Signal 04 · Identity & Tokens
Identity and token abuse continued to define the practical attack path
FortiBleed, Klue OAuth abuse, Salesforce exposure, Signal backup recovery key phishing, iOS AI app API key leakage and Microsoft Teams relay abuse all point to the same reality. Tokens, OAuth grants, recovery keys, API keys and session material often travel farther inside an enterprise than passwords do, yet are typically monitored with considerably less discipline.
Signal 05 · India & Critical Infrastructure
India and critical infrastructure signals became more prominent
Mustang Panda reportedly used Zoho WorkDrive as a command channel in Indian government and hydropower attacks. Tata Electronics confirmed a cyberattack. OT controller advisories, EV charging systems, medical systems, water-sector reports, telecommunications exposure and industrial device vulnerabilities all appeared in the same fortnight, with cloud services, industrial controllers, energy systems, government portals and manufacturing ecosystems converging into the same risk picture.
02AI Agents, Browsers & Coding Assistants
The AI security story in the second half of June shifted from model capability to tool behavior. Agents, browsers, assistants, extensions and AI development platforms now sit inside real workflows. They read context, access files, execute commands, connect to cloud accounts and influence decisions. This makes the agent environment as important to govern as the model itself.
Public ResearchHighAI Coding Agents
GuardFall bypasses AI coding-agent command safeguards
Research named GuardFall showed that command-safety checks in open-source AI coding and computer-use agents could be bypassed using shell techniques that have been understood for years. The finding reportedly affected ten of eleven tested agents. The issue is not that the shell is new. It is that well-understood command-injection behavior is now meeting autonomous execution. AI coding agents need command isolation, policy enforcement, environment controls and audit trails that go beyond simple string checks.
Public ResearchHighAI Browsers
BioShocking tricks AI browsers into leaking credentials
BioShocking research showed that AI browsers and assistants could be manipulated into copying user credentials and sending them to an attacker under game-like or deceptive framing. Reported targets included AI browser and assistant environments connected to major AI providers. AI browsers combine browsing, interpretation, user context and action in ways that make credential handling and agent governance the same control problem.
ConfirmedHighCVE-2026-12957
Amazon Q Developer flaw allowed malicious repositories to run code
Amazon patched a high-severity flaw where a malicious repository could trigger commands through Model Context Protocol configuration handling and steal cloud credentials. In agentic development workflows, the repository can influence the assistant, configure tools and trigger execution. That turns repository trust into cloud credential risk, a different exposure category from ordinary code review.
Public ResearchHighAI Developer Tooling
Claude Code repository attack
Researchers demonstrated that harmless-looking repositories could contain indirect instructions capable of steering Claude Code toward unsafe behavior, including host command execution in certain conditions. AI coding tools read project files, comments, documentation and setup instructions as useful context. Attackers can place instructions where human reviewers see ordinary project material while the agent treats the same content as operational guidance.
ConfirmedHighAI Agent Execution
AutoJack in Microsoft AutoGen Studio
Microsoft fixed an AutoGen Studio flaw chain named AutoJack that could allow a browsing agent to be manipulated into executing commands on the host by visiting a malicious page. Agentic browsing links web content to local execution, and that connection must be governed with the same seriousness as browser sandboxing, endpoint protection and privileged access.
DifyTap exposes AI chat histories across tenants
ConfirmedHighAI Application Platform
Researchers disclosed DifyTap vulnerabilities in Dify, an open-source agentic workflow platform, that could allow attackers to access AI conversations and application data across tenant boundaries. AI application platforms process business data, user prompts, internal documents and workflow context. Multi-tenant isolation failures here can expose sensitive operational intelligence across customer environments.
OpenClaw and fake AI agent skills
Public ResearchHighAI Supply Chain
Reports described malicious or test AI agent skills passing marketplace checks, including a fake skill that reportedly reached a large number of agents despite scanners marking it safe. Agent marketplaces are becoming software supply chains. A skill is not only a content package; it can extend what an agent can read, request, process or execute.
Malicious JetBrains plugins steal AI API keys
ConfirmedHighDeveloper Tooling
Malicious JetBrains Marketplace plugins posing as AI coding assistants stole AI provider API keys from developers. AI API keys are now high-value developer secrets. They can carry cost exposure, data exposure and access to internal workflows built on AI provider capabilities.
Gaslight macOS malware targets AI-assisted analysis
Public ResearchMed-High
Gaslight, a macOS malware family, reportedly embedded prompt-injection content intended to mislead AI-assisted malware analysis tools and interfere with investigation. Attackers are beginning to account for AI inside the defender workflow, attempting to influence the analyst’s tools rather than only the endpoint being analyzed.
03Supply Chain & Developer Ecosystem Adaptation
The second half of June showed that supply-chain actors are adapting. They are responding to new package-manager controls, using official update channels, abusing CI/CD workflow design, targeting AI frameworks and stealing developer credentials through plugins, extensions and package scripts. The defensive baseline is moving; so are the attack techniques.
Mastra npm packages compromised
ConfirmedHighAI Framework Supply Chain
As many as 145 Mastra npm packages were reported compromised through a hijacked contributor account. AI development frameworks are entering enterprise build paths, and compromise of framework packages can reach applications, developers, credentials and deployment workflows.
Miasma evolves across npm, GitHub Actions and Go
ConfirmedHigh
Miasma-related activity continued to evolve across npm packages, GitHub Actions workflows and Go packages, showing adaptation beyond earlier package lifecycle techniques. Supply-chain attacks are moving across ecosystems. Security teams cannot focus only on one registry or one installation behavior.
Hijacked npm and Go packages avoid common execution paths
ConfirmedHigh
Hijacked npm and Go packages deployed a Python infostealer while avoiding common npm execution paths, in a way that may remain compatible with npm v12 hardening. Security teams need behavior-based monitoring around package use, not only reliance on package-manager defaults.
Cordyceps CI/CD workflow weaknesses
Public ResearchHigh
Cordyceps research described exploitable CI/CD workflow patterns that could expose hundreds of repositories, including prominent open-source projects, to supply-chain compromise. CI/CD workflows are production authority expressed as automation. A misconfiguration can grant attackers the ability to modify builds, steal secrets or influence releases.
ShapedPlugin official update flow compromised
ConfirmedHigh
Multiple WordPress plugins from ShapedPlugin were compromised through the vendor’s official build and distribution pipeline, pushing backdoored updates through licensed update channels. When official channels are compromised, customers receive malicious code through the path they are expected to trust.
Polymarket third-party frontend compromise
ConfirmedHigh
Polymarket reported users lost funds after malicious script injection through a third-party vendor compromise. Frontend supply-chain compromise can directly affect user transactions. Third-party scripts and vendor dependencies are part of the payment and transaction trust boundary.
Malicious Edge and Chrome extensions
ConfirmedHigh
Microsoft removed 119 malicious Edge extensions hiding payloads in images and fonts. Separate reports described malicious Chrome extensions impersonating trusted services including Perplexity and Google Notes. Browser extensions sit close to searches, credentials, sessions, wallets and enterprise SaaS environments. Extension governance must be treated as endpoint and identity governance.
04Control-Plane & Trusted Infrastructure Exploitation
The second half of June was heavy with exploitation against systems that sit close to administrative authority. Remote support, security tools, SD-WAN, communications platforms, observability, ERP, PLM, load balancing, web infrastructure and OT bridge devices all appeared. These platforms are attractive because they hold administrative reach, trusted network position, operational context or recovery authority.
ConfirmedHighCISA KEVCVE-2026-48558
SimpleHelp exploited for TaskWeaver and Djinn Stealer
Attackers exploited a maximum-severity SimpleHelp flaw to deliver TaskWeaver and Djinn Stealer. Reporting described credential, SSH key, cryptocurrency wallet and development tooling collection across Windows, macOS and Linux environments. Remote support platforms carry administrative reach, and once exploited they become a direct channel into endpoints, credentials and developer environments across every organization they support.
ConfirmedHighCISA KEVCVE-2026-33825
BlueHammer: Microsoft Defender exploited by ransomware operators
The Microsoft Defender vulnerability known as BlueHammer was reported as exploited in the wild, including by ransomware operators. Security tools are high-value targets. Exploitation of a defensive control removes a layer of protection at the same moment an attacker needs it removed, which is a compound risk rather than a simple vulnerability.
ConfirmedHighCVE-2026-46817
Oracle E-Business Suite flaw exploited
A critical Oracle E-Business Suite Payments vulnerability came under active exploitation, allowing unauthenticated attackers to take over susceptible instances. ERP and financial application layers hold process authority, sensitive records and payment context. Exploitation here reaches directly into business operations rather than peripheral systems.
Cisco SD-WAN exploitation continued
ConfirmedHighCISA KEVCVE-2026-20245
Cisco SD-WAN exploitation remained a significant signal, with reports of attacks occurring months before public disclosure and additional actively exploited SD-WAN Manager flaws. SD-WAN managers control distributed connectivity. Compromise can create administrative access, rogue accounts and routing-level risk across multiple locations simultaneously.
Cisco Unified Communications Manager exploitation
ConfirmedHighCISA KEVCVE-2026-20230
Cisco Unified Communications Manager flaws moved into active exploitation after public exploit information became available, with file-write paths leading toward root-level access. Communications platforms are identity-adjacent and business-critical. Exploitation affects availability, trust and potential lateral movement inside enterprise networks.
Splunk Enterprise exploitation
ConfirmedHighCISA KEVCVE-2026-20253
Splunk Enterprise exploitation was reported days after disclosure, with CISA requiring rapid federal patching. Splunk holds logs, operational telemetry and security context. Compromise of the monitoring layer affects both detection capability and investigation confidence simultaneously.
Fortinet FortiSandbox exploitation and FortiBleed
ConfirmedHigh
FortiSandbox vulnerabilities were reported under exploitation, while FortiBleed exposed tens of thousands of Fortinet firewall and VPN credentials through a large credential-harvesting campaign. Firewall, VPN and sandbox infrastructure sit inside the defensive stack. Credential theft or exploitation here gives attackers access to systems intended to protect the enterprise, creating a structural inversion of control.
PTC Windchill exploitation
ConfirmedHighCISA KEVCVE-2026-12569
CISA added a critical PTC Windchill vulnerability to KEV after web shell attacks were observed. Product lifecycle management systems hold engineering designs, manufacturing context and product data. Compromise can affect both intellectual property and operational integrity.
Progress Kemp LoadMaster · NGINX · Webmin
ConfirmedHigh
Progress Kemp LoadMaster (CVE-2026-8037) allowed unauthenticated root command execution via crafted API requests. F5 patched critical NGINX Open Source flaws allowing remote code execution in affected configurations. CISA warned of Webmin vulnerabilities enabling unauthenticated user impersonation. Load balancers, reverse proxies and administrative panels are traffic and trust boundaries. Root-level compromise at these layers can affect routing, certificates, availability and internal application access.
05Identity, Tokens & Credential Theft
The practical currency of modern attacks is trusted access
Tokens, OAuth grants, API keys, recovery keys, browser sessions, device credentials, firewall credentials and AI provider keys all appeared in the intake. Organizations that govern tokens and delegated access with less discipline than they apply to passwords are accepting a structural gap that attackers are actively exploiting.
ConfirmedHighSaaS Integration
Klue OAuth and Salesforce data theft
Salesforce disabled the Klue Battlecards integration after attackers abused OAuth access to steal Salesforce data from Klue customers. Victims included several cybersecurity and enterprise software firms. OAuth integrations carry delegated trust. When a connected application is compromised, the attacker can reach customer environments through approved access paths, with no obvious sign of intrusion in the host environment.
FortiBleed credential harvesting
ConfirmedHighFirewall / VPN Credentials
FortiBleed reportedly involved credential harvesting from tens of thousands of Fortinet firewall and VPN devices, with CISA urging customers to secure affected systems. Firewall and VPN credentials provide direct access to perimeter trust. Credential hygiene for network devices must include rotation, exposure review and monitoring for reuse.
Signal backup recovery key phishing
ConfirmedHighMessaging Identity
The FBI and CISA warned that Russian intelligence-linked actors evolved their Signal phishing activity to target backup recovery keys, allowing restoration of message history and account takeover. Recovery keys are identity assets. Once stolen, they can bypass ordinary session controls and expose historic communication, making them more valuable to an attacker than a single compromised session.
iOS AI apps leak API keys and proxy access
Public ResearchHighAI API Exposure
Many iOS AI chatbot apps exposed paid AI access through plaintext API keys, reusable tokens or poorly protected backend endpoints. AI API keys are now business assets. Leakage creates financial exposure, data exposure and abuse of an organization’s AI provider account across its full scope.
Microsoft Teams relay abuse by DragonForce
ConfirmedHighRansomware / Cloud Trust
DragonForce ransomware operators were observed using Microsoft Teams relay infrastructure to hide command-and-control traffic for a custom Go-based backdoor. Trusted collaboration infrastructure can become attacker transport. Defenders need visibility into abnormal SaaS relay behavior, not only known malicious domains.
06Critical Infrastructure, India & Nation-State Signals
The end-month intake carried stronger India and critical infrastructure relevance than the first-half edition. The common thread was not advanced malware. It was trusted access through cloud services, public infrastructure, industrial devices, portals, remote systems and exposed operational technology.
Mustang Panda uses Zoho WorkDrive in Indian government attacks
ConfirmedHighIndia / Nation-State
Mustang Panda reportedly used Zoho WorkDrive as a command channel in attacks against Indian government and hydropower targets, with active compromises observed in government environments. Legitimate cloud services used as command channels cannot simply be blocked; they must be monitored for abnormal behavior patterns.
Vulnerabilities expose Indian government systems
ConfirmedHighIndia / Public Systems
Reporting described vulnerabilities in Indian government systems, including a critical issue that could have allowed takeover of a national government portal. Digital public infrastructure must be governed as critical infrastructure. Vulnerabilities in citizen-facing or administrative platforms can quickly become trust incidents affecting services that citizens and institutions depend on.
Tata Electronics confirms cyberattack
ConfirmedHighIndia / Manufacturing
Tata Electronics confirmed that it was the target of a cyberattack affecting parts of its IT infrastructure. Manufacturing and electronics ecosystems sit inside strategic supply chains. Cyber incidents in this layer carry business, operational and broader economic relevance.
Lantronix EDS5000 exploitation
ConfirmedHighCISA KEVCVE-2025-67038
CISA warned of active exploitation of a critical Lantronix EDS5000 flaw affecting serial-to-Ethernet devices. Serial-to-IP devices connect older operational systems to modern networks. Weakness here can bridge IT and OT environments in ways that are difficult to detect after the fact.
Daktronics controller vulnerabilities
ConfirmedHighOT / Public Infrastructure
CISA published advisories for Daktronics controller firmware vulnerabilities that could provide unauthenticated root-level access and control. Highway signs, billboards and public display infrastructure are operational systems. Compromise can create public safety, misinformation and disruption risks in physical environments.
EV charging and medical-device advisories
ConfirmedMed-HighOT / Healthcare
CISA ICS advisories covered EV charging management systems, medical imaging viewers, medical libraries, glucose monitoring systems and healthcare-related platforms. Healthcare and energy-adjacent devices increasingly depend on software, APIs and remote administration. The security of supporting systems now affects service continuity and public trust.
Russian and Chinese nation-state activity
ConfirmedHighNation-State
The period included reports on Turla’s STOCKSTAY backdoor, Gamaredon activity against Ukraine, SprySOCKS Windows variants, Russian targeting of messaging-app recovery keys, and Chinese-linked campaigns across government, energy, research and Southeast Asian targets. Nation-state operations continue to rely on practical techniques: cloud-service abuse, credential theft, spear-phishing, backdoors and appliance persistence.
Water-sector and utility signals
ConfirmedHighCritical Infrastructure
Cal Water investigated Iranian Handala claims and later confirmed no OT systems were breached. London Hydro disclosed a data breach. Other reporting highlighted water-system targeting through weak passwords, exposed PLCs and poor segmentation. Claims and confirmed operational impact must be kept separate. Exposed utility systems remain high-risk because disruption consequences are physical and public-facing.
07Signals & Patterns
Six patterns define the second half of June
AI agents convert context into action Agents read repositories, tickets, error reports, web pages, notifications, plugins and skills. When they can also execute tools or access credentials, context becomes a control boundary. Security programs must govern the full agent environment: inputs, permissions, execution rights and connected tools, not only the model at the center.
Developer tools are credential-bearing execution surfaces AI coding assistants, IDE plugins, browser extensions, package managers, repositories and CI/CD workflows all appeared in the same period. The developer environment has become one of the highest-value enterprise access layers, with a risk profile that most organizations have not yet fully addressed.
Supply-chain actors are adapting to defensive defaults Attackers are moving beyond old package lifecycle abuse into CI/CD workflows, official update channels, plugin ecosystems, Go packages, AI frameworks and browser extensions. Security controls must detect behavior and trust relationships, not only known bad packages.
Control planes continue to compress breach impact Remote support, VPN, SD-WAN, communications, observability, ERP, PLM, load balancing and administrative panels all appeared in the intake. These systems multiply impact because they already sit where administrators operate, and that is precisely what makes them attractive targets.
Tokens and delegated access are now primary assets OAuth grants, Signal recovery keys, AI API keys, firewall credentials, Salesforce access tokens and browser sessions all appeared. Organizations need token governance that matches the maturity of password governance, including inventory, monitoring and rotation based on risk.
Critical infrastructure risk often starts with ordinary exposure Industrial devices, medical systems, public displays, EV charging platforms, water utilities and government portals continue to show the same underlying problems: exposed interfaces, weak segmentation, outdated systems, poor credential practices and slow operational response. The entry points are often simpler than the consequences suggest.
08Defender Actions
Ten actions for the period ahead
Treat every AI agent as an identity
Create an inventory of AI agents, coding assistants, browser agents, workflow agents and automation bots. Track who authorized them, what credentials they use, what data they can access, what tools they can invoke and how they are retired when no longer needed.
Govern agent context as a security boundary
Repositories, comments, issues, tickets, web pages, notifications, documents and plugin content can all influence agent behavior. Apply trust rules to what agents are allowed to read, summarize, execute or treat as instructions. The boundary is the context, not only the model.
Isolate AI coding tools from production credentials
Claude Code, Codex, Amazon Q, Cursor, Copilot, JetBrains plugins and similar tools should operate in controlled environments separate from production repositories, cloud keys, client secrets and package-publishing credentials.
Move extensions, plugins and skills to explicit trust
Browser extensions, IDE plugins, AI skills and marketplace packages require approval, monitoring and removal processes. Store presence or a familiar brand name is not sufficient evidence of safety.
Audit OAuth integrations and SaaS tokens
Review connected applications across Salesforce, Microsoft 365, Google Workspace, GitHub, Slack, service desks, CRM and security platforms. Remove stale integrations, reduce scopes, rotate secrets and monitor abnormal data access through trusted applications.
Reclassify remote support and control-plane platforms
SimpleHelp, VPN, SD-WAN, ERP, PLM, backup, observability, ITSM, file transfer, load balancing and security platforms are systems of authority. They need stronger access control, emergency patching, logging and exposure review — not utility-software treatment.
Build emergency lanes for exploited control-plane vulnerabilities
KEV-listed and actively exploited vulnerabilities in control-plane systems should not wait for routine maintenance. Pre-define authority, compensating controls, maintenance override criteria, rollback ownership and executive communication before the next event requires them.
Monitor legitimate cloud services used as command channels
Zoho WorkDrive, Microsoft Teams, OneDrive, Dropbox and Google Workspace can be abused for command-and-control, staging or exfiltration. Blocking these services is generally impractical; monitoring them for abnormal usage must not be.
Protect developer credentials as production credentials
AI provider keys, GitHub tokens, npm tokens, cloud keys, SSH keys, package-publishing credentials and CI/CD secrets should be inventoried, monitored and rotated based on risk. Developer credential compromise must trigger production-impact assessment.
Separate breach claims, confirmed compromise and operational impact
Threat-actor claims, leak-site posts, vendor statements, regulatory filings and confirmed operational effects must remain distinct. Decision quality depends on classification discipline.
09Closing Note
The second half of June made one thing clear: trusted tools are becoming the new execution surface.
The platforms that help enterprises move faster now carry the permissions, tokens, workflows and context that attackers seek. AI agents read and act. Developer tools hold credentials. Remote support platforms reach endpoints. OAuth integrations connect SaaS systems. SD-WAN managers shape connectivity. ERP and PLM platforms carry business process and engineering value. Security tools and observability platforms hold the evidence defenders depend on.
Governing these tools according to the authority they carry is not a reason to slow down. It is the condition for moving fast with confidence.
Every organization now needs a clearer map of trusted execution: which tools can act, which identities they use, which data they touch, which systems they can change and which signals would indicate that trust being abused.
The companies that manage this well will not be the ones that restrict everything. They will be the ones that understand where authority lives, where automation acts and where trust requires continuous validation.
About The Signal Watchtower
Published by Elytra Security. Signal-only intelligence across security, privacy and AI. Confirmed facts kept rigorously separate from claims and attacker assertions.
Authored by Venkat Mangudi · Founder & CEO, Elytra Security
Integrity. Trust. Clarity.
An ISO/IEC 27001:2022 Certified Company
