Venkat Mangudi

Writing on cybersecurity, AI, resilience, leadership, and risk.

Follow

Signal Watchtower Edition 011: When Trust Executes

The Signal Watchtower: Security, Privacy, AI
Edition 011

The next security boundary isn’t around systems. It’s around action.

FocusSecurity · Privacy · AI

Coverage window1 – 15 July 2026

AuthorVenkat Mangudi, Founder & CEO, Elytra Security

What the first half of July revealed

Agents read repositories, inspect files, open issues, browse pages, invoke tools and use credentials. That makes them useful. It also makes their context a security boundary. This edition tracks what happens when trust stops being a relationship and starts being something an agent, a token, or a package can act on.

The enterprise has spent years approving tools, vendors and integrations. The task now is understanding what those trusted objects can actually do when something goes wrong.

01Executive Overview

Trusted context is starting to drive execution

The strongest signals from 1 to 15 July were not isolated incidents. AI agents were shown to execute unsafe commands through poisoned repositories, comments, images, workflows and browser contexts, across Cursor, Claude Code, GitHub Copilot, Gemini CLI, GitHub agentic workflows, OpenClaw, Dialogflow CX and Writer AI. At the same time, attackers kept exploiting internet-facing enterprise systems: SharePoint, SonicWall SMA, Citrix NetScaler, Progress ShareFile, Gitea, ColdFusion, Joomla, Kemp LoadMaster, BeyondTrust, SAP NetWeaver, RabbitMQ and Ubiquiti. The identity layer stayed under equal pressure, with passkey enrollment vishing, OAuth client ID spoofing, device-code phishing and Gmail API abuse all showing attackers going after delegated trust rather than passwords alone.

The five lead signals

Signal 01 · Ransomware Automation

Agentic ransomware moved from concept to operational warning

JadePuffer was reported as an LLM-agent-driven ransomware operation that used a Langflow flaw to automate intrusion, credential theft, database access and encryption. Some operational details are still being validated, but the signal itself is serious: autonomous reasoning is now entering real ransomware workflows, chaining known weaknesses and stolen credentials into a faster intrusion sequence.

Signal 02 · Coding Environments

AI coding environments became a major execution surface

Cursor DuneSlide, Cursor’s git.exe auto-execution flaw, GhostApproval, Friendly Fire, Ghostcommit and HalluSquatting all showed repeated ways that repositories, comments, images and hallucinated package names can steer AI coding tools toward unsafe execution. Opening a repository is becoming a higher-risk act, because an agent can read the same content very differently from a human reviewer.

Signal 03 · Patch Volume

AI-discovered flaws increased patch and triage pressure

Microsoft’s July Patch Tuesday broke records, with hundreds of vulnerabilities and multiple zero-days, and reporting tied the rising volume partly to AI-assisted discovery. Apple, OpenAI, Anthropic and CISA all appeared through AI-enabled discovery, red-teaming and coordination work. More discovery without matching remediation capacity risks becoming a new kind of backlog.

Signal 04 · Control Planes

Edge and control-plane systems remained emergency priorities

SharePoint, SonicWall SMA, Citrix NetScaler, Progress ShareFile, Kemp LoadMaster, Gitea, ColdFusion, Joomla, SAP NetWeaver, BeyondTrust and Ubiquiti all appeared as exploited, zero-day or critical exposure items. These systems sit close to access, collaboration and business operations, so routine patching is not enough once exploitation is confirmed.

Signal 05 · Identity & Recovery

OAuth, passkeys and recovery flows became frontline attack surfaces

Forg365, DEBULL, Entra passkey enrollment vishing, OAuth client ID spoofing, ToddyCat’s Gmail API abuse and Signal recovery-key targeting all showed attackers working through identity flows built for legitimate access and recovery. Identity security now depends on governing delegated access and device flows, not only passwords and MFA.

02Agentic Execution & AI Trust Failures

The central AI security story this edition is not that AI can produce unsafe text. The stronger issue is that agentic systems can act on unsafe context. Agents are now connected to repositories, browsers, terminals, files, calendars, documents, APIs and credentials, which turns their context into a security boundary.

Confirmed ReportingHighRansomware / AI Agent

JadePuffer agentic ransomware via Langflow

JadePuffer was reported as a ransomware operation in which an AI agent exploited a Langflow flaw, stole data from a production database server and encrypted other systems, described as an end-to-end agentic attack. The lesson is not that every ransomware attack is now autonomous; it is that AI agents can chain known techniques, credentials and live feedback into a faster intrusion workflow.

Cursor DuneSlide vulnerabilities

ConfirmedHighCVE-2026-50548 / 50549

Two critical Cursor flaws, called DuneSlide, could let prompt injection escape the editor sandbox and run commands on a developer’s computer. If the editor can be steered from prompt or project context into host execution, the developer machine itself becomes the target.

Cursor git.exe auto-execution flaw

Public ResearchHigh

Research showed Cursor on Windows could execute a git.exe file placed in the project root when a cloned repository was opened. Opening a repository should not execute attacker-controlled binaries; repository trust needs stronger rules before a project is opened or indexed.

GhostApproval symlink flaws

Public ResearchHigh

Symlink behavior could redirect a malicious repository’s approved file write from an apparently harmless target to a sensitive file, reportedly affecting Amazon Q Developer, Claude Code, Augment, Cursor, Google Antigravity and Windsurf. Approval prompts are weak controls when the approved path can be redirected.

Friendly Fire against AI security agents

Public ResearchHigh

Research described a pattern where AI coding agents asked to inspect open-source code for security issues could be tricked into running attacker code on the analyst’s own machine. AI security agents need the same isolation discipline as malware sandboxes.

Ghostcommit prompt injection in images

Public ResearchHigh

Ghostcommit demonstrated that prompt injection hidden inside images could manipulate coding agents or AI reviewers into exposing repository secrets. The repository is more than source files: images, documentation and metadata can all become instruction-bearing content.

HalluSquatting

Public ResearchHigh

HalluSquatting showed how attackers could register package names that AI coding assistants hallucinate, then wait for users or agents to install them. Dependency governance now needs provenance checks for AI-suggested packages.

Agent data injection

Public ResearchHigh

Planted data in reviews, GitHub comments or other sources could cause an agent to misclick, run commands or follow attacker-controlled instructions while continuing the user’s original task. The agent does not need to be fully hijacked to be dangerous.

MemGhost persistent false memories

Public ResearchMed-High

A single email could cause an AI assistant with memory to store false information and later use it to influence responses. Memory changes the risk model: attackers can now poison future behavior, not just the current session.

03AI Infrastructure, Model Governance & Discovery Pressure

AI security moved in two directions this period. One involved risk: agentic execution, poisoned context, credential leakage. The other involved defense: AI-assisted discovery, automated red-teaming, faster patching. Both create governance pressure.

ConfirmedHighPatch Volume / AI Discovery

Microsoft Patch Tuesday reaches record scale

July’s Patch Tuesday covered a record number of vulnerabilities, including exploited zero-days and many critical issues, with reporting connecting the rising volume to AI-aided discovery. Security teams will need better exposure validation, business-context triage and emergency authority to handle larger vulnerability volumes.

OpenAI GPT-Red and GPT-5.6 Sol

ConfirmedHigh

OpenAI disclosed GPT-Red, an internal automated red-teaming model used to find prompt injection vulnerabilities and harden GPT-5.6 Sol before wider deployment. Adversarial testing is becoming part of release engineering, not a one-time assessment.

CISA and Mythos vulnerability scanning

Confirmed ReportingHigh

Reporting indicated CISA used Anthropic’s Mythos model to scan government software for vulnerabilities as part of its attack-surface evaluation work, validating AI’s defensive value while raising questions about coordinated remediation speed.

White House Gold Eagle initiative

ConfirmedHigh

The White House launched an AI-driven vulnerability coordination initiative called Gold Eagle. AI discovery without coordinated remediation can create risk; the coordination layer is becoming as important as the discovery layer.

Apple and browser patches include AI-discovered bugs

ConfirmedMed-High

Apple patched multiple iOS, macOS and Safari flaws, including WebKit issues reportedly found with AI-assisted tools. Chrome and Firefox also received critical updates, with public exploit code available for some Firefox flaws.

Squidbleed discovered with Claude Mythos Preview

Public ResearchMed-High

A decades-old Squid proxy flaw, Squidbleed, was described as a Heartbleed-style exposure reportedly found with help from Claude Mythos Preview. AI-assisted review may keep pulling long-lived flaws back into the risk queue.

AI data centers built faster than they can be secured

WatchHigh

Reporting warned that AI data centers are being built faster than they can be secured, combining high-density compute, specialized hardware and data movement in ways traditional designs were not built for. This needs a security architecture, not only capacity planning.

04Developer Supply Chain & Repository Trust

The first half of July extended June’s developer ecosystem pattern with more variety, moving through repositories, GitHub APIs, verified commits, browser extensions, package namespaces, developer tools, fake proof-of-concept releases and maintainer accounts, not only package installation.

ConfirmedHighSupply Chain / North Korea

North Korean PolinRider packages

Actors linked to Contagious Interview were reported publishing more than 100 malicious packages and browser extensions across npm, Packagist, Go and Chrome as part of the PolinRider campaign, continuing to target developers as an access path to credentials, code and crypto assets.

Jscrambler npm compromise

ConfirmedHigh

A compromised Jscrambler npm release reportedly dropped a cross-platform Rust infostealer during install, a reminder that even security-oriented packages become delivery vehicles once publisher access is compromised.

AsyncAPI npm packages compromised

ConfirmedHigh

Compromised AsyncAPI packages were reported distributing multi-stage botnet malware and credential-stealing payloads, reaching developers and CI/CD systems through routine install paths.

Injective Labs SDK compromise

ConfirmedHigh

Threat actors compromised the Injective Labs SDK project’s GitHub repository and published a malicious npm package designed to steal wallet private keys and mnemonic seed phrases. Crypto-related developer packages remain especially attractive targets.

Fake GitHub repositories and ChocoPoC

ConfirmedHigh

Attackers published fake GitHub repositories impersonating legitimate software, security projects and proof-of-concept exploits to deliver infostealers and remote access malware. Researchers and developers investigating a vulnerability are themselves targets.

GitHub verified commit weakness

Public ResearchMed-High

Research showed signed Git commits could be rewritten into new hashes without breaking the “Verified” trust signal under certain conditions. A verified badge is useful but not the full provenance story.

GitHub ghost accounts and mass recon

Confirmed ResearchMed-High

Campaigns were reported using dormant or ghost GitHub accounts to map organizations, repositories and members through GitHub APIs, reconnaissance that often precedes credential targeting or package compromise.

npm 12 hardening

Defensive ShiftHigh

npm 12 disables install scripts by default and deprecates granular access tokens designed to bypass two-factor authentication, a meaningful shift, though attackers are already adapting through other execution paths.

05Control-Plane & Internet-Facing Exploitation

Exploitation pressure stayed high across enterprise platforms, edge systems, collaboration infrastructure, DevOps tools and administrative systems. When a system is internet-facing, exploited and close to authority, it needs an emergency lane.

ConfirmedHighCISA KEVCVE-2026-45659

SharePoint RCE exploitation

CISA added a Microsoft SharePoint Server remote code execution vulnerability to KEV after active exploitation, with later reporting noting multiple SharePoint flaws under active exploitation. SharePoint sits close to collaboration, documents and identity, so exploitation can expose sensitive data and enable lateral movement.

SonicWall SMA 1000 zero-days

ConfirmedHighCISA KEVCVE-2026-15409 / 15410

SonicWall warned of active exploitation of two zero-days affecting SMA 1000 appliances, including a critical SSRF issue and command execution risk. Secure remote access appliances stay priority targets because they sit at the entry point to enterprise networks.

Citrix Bleed 2 / NetScaler exploitation

ConfirmedHighCISA KEVCVE-2025-5777

Ransomware groups were reported exploiting Citrix Bleed 2 for initial access, with public PoC activity increasing operational pressure. Memory disclosure flaws in access infrastructure can turn quickly into credential exposure and ransomware entry points.

Progress ShareFile zero-day

ConfirmedHighZero-Day

Progress confirmed a zero-day behind ShareFile Storage Zone Controller disruption, having earlier urged affected customers to shut down Storage Zone Controller servers, an emergency recommendation that is itself a strong severity signal.

Progress Kemp LoadMaster exploitation attempts

ConfirmedHighCVE-2026-8037

A critical pre-authentication command injection flaw in Kemp LoadMaster faced active exploitation attempts. Load balancers sit at the traffic boundary; root-level compromise can affect routing, certificates and internal access.

Gitea Docker authentication bypass

ConfirmedHighCVE-2026-20896

Attackers were reported exploiting a critical Gitea Docker flaw allowing user impersonation, including administrator access, through header trust behavior. Self-hosted Git platforms hold source code, secrets and release authority.

Adobe ColdFusion exploitation

ConfirmedHighCISA KEV

CISA added an actively exploited ColdFusion path traversal vulnerability to KEV; Adobe also patched multiple maximum-severity ColdFusion and Campaign Classic flaws. Internet-facing legacy application platforms keep creating emergency exposure.

Joomla extension zero-days

ConfirmedHighCISA KEV

CISA added maximum-severity Joomla extension flaws to KEV following reported zero-day exploitation. CMS and plugin ecosystems remain high-volume exploitation paths because they are often internet-facing and under-maintained.

SAP NetWeaver ABAP

ConfirmedHighCVE-2026-44747

SAP patched a critical NetWeaver ABAP flaw that could expose, modify or corrupt data. SAP sits near core business processes, so even authenticated vulnerabilities here can create material business risk.

RabbitMQ OAuth secret leakage

Confirmed ResearchHigh

RabbitMQ flaws could leak OAuth client secrets and expose cross-tenant queue metadata. Message brokers carry application traffic and authentication material, so a secret leak here can become broader application compromise.

Ubiquiti UniFi critical flaws

ConfirmedHigh

Ubiquiti patched critical UniFi flaws affecting Connect, Talk, Access, Protect and UniFi OS, including command execution and privilege escalation risks across integrated operational functions.

BeyondTrust Remote Support and PRA flaws

ConfirmedHigh

BeyondTrust patched critical authentication bypass flaws in Remote Support and Privileged Remote Access products, systems of authority where weakness can put endpoint support and privileged sessions at risk.

06Identity, OAuth & Credential Operations

The practical currency of these attacks is trusted access

Tokens, OAuth grants, API keys, recovery keys, browser sessions, device credentials and firewall credentials all appeared in the intake. Organizations that govern tokens with less discipline than they apply to passwords are accepting a gap attackers are actively exploiting.

Confirmed ReportingHighCredential Harvesting / Ransomware

FortiBleed linked to ransomware operations

FortiBleed credential theft was linked to INC and Lynx ransomware operations, indicating that harvested FortiGate credentials were meant for follow-on intrusion. Credential leaks from perimeter devices should be treated as potential initial access events, followed by rotation and threat hunting.

Microsoft Entra passkey enrollment vishing

ConfirmedHighPasskey Abuse

Attackers used voice-based fake security requests to persuade Microsoft 365 users to enroll new Entra passkeys controlled by the attacker. Passkeys improve authentication, but enrollment remains a process that can be socially engineered.

OAuth client ID spoofing in Microsoft Entra

ConfirmedHighCloud Identity

Threat actors were reported using OAuth client ID spoofing to validate stolen Entra credentials while bypassing normal sign-in telemetry. Identity telemetry must cover failed and unusual OAuth flows, not only successful interactive logins.

Forg365 phishing-as-a-service

ConfirmedHighMicrosoft 365 Phishing

Forg365 combined device-code phishing, adversary-in-the-middle tactics, AI-assisted lure creation and post-compromise mailbox operations against Microsoft 365 accounts, packaging the phishing stack into a service offering.

DEBULL device-code phishing

ConfirmedHighMicrosoft 365

DEBULL tooling abused Microsoft’s device-code flow through collaboration-themed lures, pushing users into legitimate Microsoft login experiences. Device-code monitoring and conditional access controls need review.

ToddyCat Umbrij Gmail API abuse

ConfirmedHighGoogle API

ToddyCat-linked Umbrij malware abused OAuth to access Gmail through Google APIs and steal corporate email communications. API-based mailbox access can bypass user-visible signs of compromise.

LastPass and Bitwarden phishing · Microsoft 365 AitM kits

ConfirmedHigh

Password manager users were targeted with fake security alerts designed to capture credentials or recovery material, while new phishing kits including Jalisco and OmegaLord targeted Microsoft 365 accounts with techniques built to defeat MFA.

07Critical Infrastructure, Routers & Regional Signals

The first half of July carried significant signals around infrastructure, routers, embedded systems and government exposure, often through ordinary but strategic systems: routers, bootloaders, firmware, virtualization, tax utilities and government portals.

Russian targeting of critical infrastructure routers

ConfirmedHigh

The U.S. and allies warned that Russian state-sponsored actors were compromising poorly secured routers across critical infrastructure networks, providing persistence, reconnaissance and traffic relay into protected environments.

NetNut / Popa residential proxy disruption

ConfirmedHigh

Google, the FBI and partners disrupted NetNut / Popa, a residential proxy network reportedly powered by millions of compromised home devices, including Android TV boxes and streaming devices.

LONGLEASH and Chinese ORB expansion

ConfirmedHigh

China-linked UAT-7810 expanded an Operational Relay Box network using LONGLEASH and related malware on internet-facing networking devices, giving stealthy staging and reconnaissance infrastructure that looks operationally normal.

Tenda firmware backdoor

ConfirmedHighCVE-2026-11405

CERT/CC warned of a hidden authentication backdoor in several Tenda router firmware versions, allowing administrative access to management interfaces. Routers are trusted, always on and often poorly monitored.

U-Boot and firmware flaws

Confirmed ResearchMed-High

Researchers found U-Boot flaws that could allow malicious images to crash devices or run code during boot, undermining assumptions behind routers, cameras and management controllers.

Januscape Linux KVM flaw

Public ResearchHigh

A 16-year-old Linux KVM flaw, Januscape, could allow guest-to-host escape on Intel and AMD systems under affected conditions. Virtualization boundaries underpin cloud and enterprise infrastructure, so guest-to-host issues need careful review even when exploitation is complex.

Operation DragonReturn targets Indian taxpayers

Confirmed ReportingHighIndia

A suspected China-nexus campaign targeted Indian taxpayers, tax professionals and corporate finance teams using fake Indian tax filing utilities to deliver DcRAT, a direct signal for accountants and finance teams handling sensitive financial data.

Balochistan Police portal weaponized

Confirmed ReportingMed-High

Reports described sustained espionage activity involving compromised Pakistani law-enforcement portals, with suspected China and India-linked activity over a multi-year period. Government portals can become both targets and staging grounds.

08Signals & Patterns

Six patterns define the first half of July

1

Agents convert trusted context into action Repositories, comments, images, emails, prompts and web pages can now influence systems that execute. Agent security must govern context, permissions, memory, tools and runtime behavior together.

2

Developer environments are becoming attacker workspaces Cursor, Claude Code, GitHub Copilot, Gemini CLI, GitHub workflows, npm, JetBrains plugins and fake PoC repositories all appeared across the intake. The developer workstation is now a production-adjacent execution environment, not just an endpoint.

3

OAuth and recovery flows are frontline attack surfaces Passkey enrollment, OAuth spoofing, device-code phishing, recovery keys and API access are now active attack paths. Strong authentication depends on lifecycle governance, not method strength alone.

4

Edge and control-plane exposure still demands emergency action SharePoint, SonicWall, Citrix, Progress, Kemp, Gitea, ColdFusion, Joomla, SAP, BeyondTrust and Ubiquiti all appeared. Internet-facing control-plane exposure needs a faster response lane than ordinary vulnerability management.

5

AI-assisted discovery is increasing triage pressure AI is finding more vulnerabilities, including long-lived flaws. That is useful, but it adds to the burden on teams that must decide what matters, what is exposed and what to fix first.

6

Trust markers are becoming weaker signals Verified commits, marketplace approval, signed packages, familiar extensions and legitimate login flows can all be abused. Trust needs to be backed by behavior, provenance and scope control, not badges alone.

09Defender Actions

Ten actions for the period ahead

01

Treat AI agents as privileged identities Inventory AI agents, coding assistants and workflow bots. Track ownership, permissions, credentials, data access and retirement.

02

Separate agent workspaces from production credentials Keep agentic coding tools out of directories holding production secrets, cloud keys or unrestricted SSH access.

03

Apply repository trust rules before opening in AI tools Treat cloned repositories as untrusted until reviewed. Block auto-execution and inspect symlinks and hidden files.

04

Govern AI-suggested dependencies Require provenance checks for AI-suggested packages. Do not install because a name looks plausible.

05

Audit OAuth apps, passkeys and device-code flows Review SaaS integrations. Monitor new grants, consent events, device-code activity and suspicious client IDs.

06

Build KEV emergency lanes for control-plane systems Pre-authorize action paths for SharePoint, Citrix, Gitea and similar systems, with named approvers and rollback owners.

07

Monitor developer credentials as production credentials Inventory, rotate and monitor GitHub, npm, AI provider and CI/CD secrets. Compromise should trigger production review.

08

Review AI infrastructure and model gateways Inventory Langflow, Dify, agent platforms and model routers. Apply authentication, segmentation and patch discipline.

09

Treat router and firmware exposure as strategic risk Routers, bootloaders and embedded filesystems need inventory and lifecycle planning. Invisible infrastructure still carries risk.

10

Separate confirmed compromise from claims Keep vendor-confirmed incidents, KEV items, research and actor claims in separate categories to protect decision quality.

10Closing Note

The first half of July made one point clear: the next security boundary is not only around systems. It is around action.

Agents now act on the context they are given. OAuth grants authorize access on their own terms. Passkeys and repositories carry instructions that were never meant to be read as such. Packages execute, extensions observe, and cloud APIs retrieve data quietly in the background. Trust, in other words, has become something that runs.

The enterprise has spent years approving tools, vendors, integrations and automation. The next stage of maturity is understanding what those trusted objects can actually do when something goes wrong, and building the judgment to catch it early.

The organizations that manage this well will not be the ones that ban every new tool or slow every workflow. They will be the ones that map authority clearly, constrain action intelligently, validate exposure quickly, and keep evidence separate from noise. That is the leadership task now.

About The Signal Watchtower

Published by Elytra Security. Signal-only intelligence across security, privacy and AI. Confirmed facts kept rigorously separate from claims and attacker assertions.

Authored by Venkat Mangudi · Founder & CEO, Elytra Security

Integrity. Trust. Clarity.

An ISO/IEC 27001:2022 Certified Company


Discover more from Venkat Mangudi

Subscribe now to keep reading and get access to the full archive.

Continue reading