The next security boundary isn’t around systems. It’s around action.
What the first half of July revealed
Agents read repositories, inspect files, open issues, browse pages, invoke tools and use credentials. That makes them useful. It also makes their context a security boundary. This edition tracks what happens when trust stops being a relationship and starts being something an agent, a token, or a package can act on.
The enterprise has spent years approving tools, vendors and integrations. The task now is understanding what those trusted objects can actually do when something goes wrong.
01Executive Overview
Trusted context is starting to drive execution
The strongest signals from 1 to 15 July were not isolated incidents. AI agents were shown to execute unsafe commands through poisoned repositories, comments, images, workflows and browser contexts, across Cursor, Claude Code, GitHub Copilot, Gemini CLI, GitHub agentic workflows, OpenClaw, Dialogflow CX and Writer AI. At the same time, attackers kept exploiting internet-facing enterprise systems: SharePoint, SonicWall SMA, Citrix NetScaler, Progress ShareFile, Gitea, ColdFusion, Joomla, Kemp LoadMaster, BeyondTrust, SAP NetWeaver, RabbitMQ and Ubiquiti. The identity layer stayed under equal pressure, with passkey enrollment vishing, OAuth client ID spoofing, device-code phishing and Gmail API abuse all showing attackers going after delegated trust rather than passwords alone.
The five lead signals
Signal 01 · Ransomware Automation
Agentic ransomware moved from concept to operational warning
JadePuffer was reported as an LLM-agent-driven ransomware operation that used a Langflow flaw to automate intrusion, credential theft, database access and encryption. Some operational details are still being validated, but the signal itself is serious: autonomous reasoning is now entering real ransomware workflows, chaining known weaknesses and stolen credentials into a faster intrusion sequence.
Signal 02 · Coding Environments
AI coding environments became a major execution surface
Cursor DuneSlide, Cursor’s git.exe auto-execution flaw, GhostApproval, Friendly Fire, Ghostcommit and HalluSquatting all showed repeated ways that repositories, comments, images and hallucinated package names can steer AI coding tools toward unsafe execution. Opening a repository is becoming a higher-risk act, because an agent can read the same content very differently from a human reviewer.
Signal 03 · Patch Volume
AI-discovered flaws increased patch and triage pressure
Microsoft’s July Patch Tuesday broke records, with hundreds of vulnerabilities and multiple zero-days, and reporting tied the rising volume partly to AI-assisted discovery. Apple, OpenAI, Anthropic and CISA all appeared through AI-enabled discovery, red-teaming and coordination work. More discovery without matching remediation capacity risks becoming a new kind of backlog.
Signal 04 · Control Planes
Edge and control-plane systems remained emergency priorities
SharePoint, SonicWall SMA, Citrix NetScaler, Progress ShareFile, Kemp LoadMaster, Gitea, ColdFusion, Joomla, SAP NetWeaver, BeyondTrust and Ubiquiti all appeared as exploited, zero-day or critical exposure items. These systems sit close to access, collaboration and business operations, so routine patching is not enough once exploitation is confirmed.
Signal 05 · Identity & Recovery
OAuth, passkeys and recovery flows became frontline attack surfaces
Forg365, DEBULL, Entra passkey enrollment vishing, OAuth client ID spoofing, ToddyCat’s Gmail API abuse and Signal recovery-key targeting all showed attackers working through identity flows built for legitimate access and recovery. Identity security now depends on governing delegated access and device flows, not only passwords and MFA.
02Agentic Execution & AI Trust Failures
The central AI security story this edition is not that AI can produce unsafe text. The stronger issue is that agentic systems can act on unsafe context. Agents are now connected to repositories, browsers, terminals, files, calendars, documents, APIs and credentials, which turns their context into a security boundary.
Confirmed ReportingHighRansomware / AI Agent
JadePuffer agentic ransomware via Langflow
JadePuffer was reported as a ransomware operation in which an AI agent exploited a Langflow flaw, stole data from a production database server and encrypted other systems, described as an end-to-end agentic attack. The lesson is not that every ransomware attack is now autonomous; it is that AI agents can chain known techniques, credentials and live feedback into a faster intrusion workflow.
Cursor DuneSlide vulnerabilities
ConfirmedHighCVE-2026-50548 / 50549
Two critical Cursor flaws, called DuneSlide, could let prompt injection escape the editor sandbox and run commands on a developer’s computer. If the editor can be steered from prompt or project context into host execution, the developer machine itself becomes the target.
Cursor git.exe auto-execution flaw
Public ResearchHigh
Research showed Cursor on Windows could execute a git.exe file placed in the project root when a cloned repository was opened. Opening a repository should not execute attacker-controlled binaries; repository trust needs stronger rules before a project is opened or indexed.
GhostApproval symlink flaws
Public ResearchHigh
Symlink behavior could redirect a malicious repository’s approved file write from an apparently harmless target to a sensitive file, reportedly affecting Amazon Q Developer, Claude Code, Augment, Cursor, Google Antigravity and Windsurf. Approval prompts are weak controls when the approved path can be redirected.
Friendly Fire against AI security agents
Public ResearchHigh
Research described a pattern where AI coding agents asked to inspect open-source code for security issues could be tricked into running attacker code on the analyst’s own machine. AI security agents need the same isolation discipline as malware sandboxes.
Ghostcommit prompt injection in images
Public ResearchHigh
Ghostcommit demonstrated that prompt injection hidden inside images could manipulate coding agents or AI reviewers into exposing repository secrets. The repository is more than source files: images, documentation and metadata can all become instruction-bearing content.
HalluSquatting
Public ResearchHigh
HalluSquatting showed how attackers could register package names that AI coding assistants hallucinate, then wait for users or agents to install them. Dependency governance now needs provenance checks for AI-suggested packages.
Agent data injection
Public ResearchHigh
Planted data in reviews, GitHub comments or other sources could cause an agent to misclick, run commands or follow attacker-controlled instructions while continuing the user’s original task. The agent does not need to be fully hijacked to be dangerous.
MemGhost persistent false memories
Public ResearchMed-High
A single email could cause an AI assistant with memory to store false information and later use it to influence responses. Memory changes the risk model: attackers can now poison future behavior, not just the current session.
03AI Infrastructure, Model Governance & Discovery Pressure
AI security moved in two directions this period. One involved risk: agentic execution, poisoned context, credential leakage. The other involved defense: AI-assisted discovery, automated red-teaming, faster patching. Both create governance pressure.
ConfirmedHighPatch Volume / AI Discovery
Microsoft Patch Tuesday reaches record scale
July’s Patch Tuesday covered a record number of vulnerabilities, including exploited zero-days and many critical issues, with reporting connecting the rising volume to AI-aided discovery. Security teams will need better exposure validation, business-context triage and emergency authority to handle larger vulnerability volumes.
OpenAI GPT-Red and GPT-5.6 Sol
ConfirmedHigh
OpenAI disclosed GPT-Red, an internal automated red-teaming model used to find prompt injection vulnerabilities and harden GPT-5.6 Sol before wider deployment. Adversarial testing is becoming part of release engineering, not a one-time assessment.
CISA and Mythos vulnerability scanning
Confirmed ReportingHigh
Reporting indicated CISA used Anthropic’s Mythos model to scan government software for vulnerabilities as part of its attack-surface evaluation work, validating AI’s defensive value while raising questions about coordinated remediation speed.
White House Gold Eagle initiative
ConfirmedHigh
The White House launched an AI-driven vulnerability coordination initiative called Gold Eagle. AI discovery without coordinated remediation can create risk; the coordination layer is becoming as important as the discovery layer.
Apple and browser patches include AI-discovered bugs
ConfirmedMed-High
Apple patched multiple iOS, macOS and Safari flaws, including WebKit issues reportedly found with AI-assisted tools. Chrome and Firefox also received critical updates, with public exploit code available for some Firefox flaws.
Squidbleed discovered with Claude Mythos Preview
Public ResearchMed-High
A decades-old Squid proxy flaw, Squidbleed, was described as a Heartbleed-style exposure reportedly found with help from Claude Mythos Preview. AI-assisted review may keep pulling long-lived flaws back into the risk queue.
AI data centers built faster than they can be secured
WatchHigh
Reporting warned that AI data centers are being built faster than they can be secured, combining high-density compute, specialized hardware and data movement in ways traditional designs were not built for. This needs a security architecture, not only capacity planning.
04Developer Supply Chain & Repository Trust
The first half of July extended June’s developer ecosystem pattern with more variety, moving through repositories, GitHub APIs, verified commits, browser extensions, package namespaces, developer tools, fake proof-of-concept releases and maintainer accounts, not only package installation.
ConfirmedHighSupply Chain / North Korea
North Korean PolinRider packages
Actors linked to Contagious Interview were reported publishing more than 100 malicious packages and browser extensions across npm, Packagist, Go and Chrome as part of the PolinRider campaign, continuing to target developers as an access path to credentials, code and crypto assets.
Jscrambler npm compromise
ConfirmedHigh
A compromised Jscrambler npm release reportedly dropped a cross-platform Rust infostealer during install, a reminder that even security-oriented packages become delivery vehicles once publisher access is compromised.
AsyncAPI npm packages compromised
ConfirmedHigh
Compromised AsyncAPI packages were reported distributing multi-stage botnet malware and credential-stealing payloads, reaching developers and CI/CD systems through routine install paths.
Injective Labs SDK compromise
ConfirmedHigh
Threat actors compromised the Injective Labs SDK project’s GitHub repository and published a malicious npm package designed to steal wallet private keys and mnemonic seed phrases. Crypto-related developer packages remain especially attractive targets.
Fake GitHub repositories and ChocoPoC
ConfirmedHigh
Attackers published fake GitHub repositories impersonating legitimate software, security projects and proof-of-concept exploits to deliver infostealers and remote access malware. Researchers and developers investigating a vulnerability are themselves targets.
GitHub verified commit weakness
Public ResearchMed-High
Research showed signed Git commits could be rewritten into new hashes without breaking the “Verified” trust signal under certain conditions. A verified badge is useful but not the full provenance story.
GitHub ghost accounts and mass recon
Confirmed ResearchMed-High
Campaigns were reported using dormant or ghost GitHub accounts to map organizations, repositories and members through GitHub APIs, reconnaissance that often precedes credential targeting or package compromise.
npm 12 hardening
Defensive ShiftHigh
npm 12 disables install scripts by default and deprecates granular access tokens designed to bypass two-factor authentication, a meaningful shift, though attackers are already adapting through other execution paths.
05Control-Plane & Internet-Facing Exploitation
Exploitation pressure stayed high across enterprise platforms, edge systems, collaboration infrastructure, DevOps tools and administrative systems. When a system is internet-facing, exploited and close to authority, it needs an emergency lane.
ConfirmedHighCISA KEVCVE-2026-45659
SharePoint RCE exploitation
CISA added a Microsoft SharePoint Server remote code execution vulnerability to KEV after active exploitation, with later reporting noting multiple SharePoint flaws under active exploitation. SharePoint sits close to collaboration, documents and identity, so exploitation can expose sensitive data and enable lateral movement.
SonicWall SMA 1000 zero-days
ConfirmedHighCISA KEVCVE-2026-15409 / 15410
SonicWall warned of active exploitation of two zero-days affecting SMA 1000 appliances, including a critical SSRF issue and command execution risk. Secure remote access appliances stay priority targets because they sit at the entry point to enterprise networks.
Citrix Bleed 2 / NetScaler exploitation
ConfirmedHighCISA KEVCVE-2025-5777
Ransomware groups were reported exploiting Citrix Bleed 2 for initial access, with public PoC activity increasing operational pressure. Memory disclosure flaws in access infrastructure can turn quickly into credential exposure and ransomware entry points.
Progress ShareFile zero-day
ConfirmedHighZero-Day
Progress confirmed a zero-day behind ShareFile Storage Zone Controller disruption, having earlier urged affected customers to shut down Storage Zone Controller servers, an emergency recommendation that is itself a strong severity signal.
Progress Kemp LoadMaster exploitation attempts
ConfirmedHighCVE-2026-8037
A critical pre-authentication command injection flaw in Kemp LoadMaster faced active exploitation attempts. Load balancers sit at the traffic boundary; root-level compromise can affect routing, certificates and internal access.
Gitea Docker authentication bypass
ConfirmedHighCVE-2026-20896
Attackers were reported exploiting a critical Gitea Docker flaw allowing user impersonation, including administrator access, through header trust behavior. Self-hosted Git platforms hold source code, secrets and release authority.
Adobe ColdFusion exploitation
ConfirmedHighCISA KEV
CISA added an actively exploited ColdFusion path traversal vulnerability to KEV; Adobe also patched multiple maximum-severity ColdFusion and Campaign Classic flaws. Internet-facing legacy application platforms keep creating emergency exposure.
Joomla extension zero-days
ConfirmedHighCISA KEV
CISA added maximum-severity Joomla extension flaws to KEV following reported zero-day exploitation. CMS and plugin ecosystems remain high-volume exploitation paths because they are often internet-facing and under-maintained.
SAP NetWeaver ABAP
ConfirmedHighCVE-2026-44747
SAP patched a critical NetWeaver ABAP flaw that could expose, modify or corrupt data. SAP sits near core business processes, so even authenticated vulnerabilities here can create material business risk.
RabbitMQ OAuth secret leakage
Confirmed ResearchHigh
RabbitMQ flaws could leak OAuth client secrets and expose cross-tenant queue metadata. Message brokers carry application traffic and authentication material, so a secret leak here can become broader application compromise.
Ubiquiti UniFi critical flaws
ConfirmedHigh
Ubiquiti patched critical UniFi flaws affecting Connect, Talk, Access, Protect and UniFi OS, including command execution and privilege escalation risks across integrated operational functions.
BeyondTrust Remote Support and PRA flaws
ConfirmedHigh
BeyondTrust patched critical authentication bypass flaws in Remote Support and Privileged Remote Access products, systems of authority where weakness can put endpoint support and privileged sessions at risk.
06Identity, OAuth & Credential Operations
The practical currency of these attacks is trusted access
Tokens, OAuth grants, API keys, recovery keys, browser sessions, device credentials and firewall credentials all appeared in the intake. Organizations that govern tokens with less discipline than they apply to passwords are accepting a gap attackers are actively exploiting.
Confirmed ReportingHighCredential Harvesting / Ransomware
FortiBleed linked to ransomware operations
FortiBleed credential theft was linked to INC and Lynx ransomware operations, indicating that harvested FortiGate credentials were meant for follow-on intrusion. Credential leaks from perimeter devices should be treated as potential initial access events, followed by rotation and threat hunting.
Microsoft Entra passkey enrollment vishing
ConfirmedHighPasskey Abuse
Attackers used voice-based fake security requests to persuade Microsoft 365 users to enroll new Entra passkeys controlled by the attacker. Passkeys improve authentication, but enrollment remains a process that can be socially engineered.
OAuth client ID spoofing in Microsoft Entra
ConfirmedHighCloud Identity
Threat actors were reported using OAuth client ID spoofing to validate stolen Entra credentials while bypassing normal sign-in telemetry. Identity telemetry must cover failed and unusual OAuth flows, not only successful interactive logins.
Forg365 phishing-as-a-service
ConfirmedHighMicrosoft 365 Phishing
Forg365 combined device-code phishing, adversary-in-the-middle tactics, AI-assisted lure creation and post-compromise mailbox operations against Microsoft 365 accounts, packaging the phishing stack into a service offering.
DEBULL device-code phishing
ConfirmedHighMicrosoft 365
DEBULL tooling abused Microsoft’s device-code flow through collaboration-themed lures, pushing users into legitimate Microsoft login experiences. Device-code monitoring and conditional access controls need review.
ToddyCat Umbrij Gmail API abuse
ConfirmedHighGoogle API
ToddyCat-linked Umbrij malware abused OAuth to access Gmail through Google APIs and steal corporate email communications. API-based mailbox access can bypass user-visible signs of compromise.
LastPass and Bitwarden phishing · Microsoft 365 AitM kits
ConfirmedHigh
Password manager users were targeted with fake security alerts designed to capture credentials or recovery material, while new phishing kits including Jalisco and OmegaLord targeted Microsoft 365 accounts with techniques built to defeat MFA.
07Critical Infrastructure, Routers & Regional Signals
The first half of July carried significant signals around infrastructure, routers, embedded systems and government exposure, often through ordinary but strategic systems: routers, bootloaders, firmware, virtualization, tax utilities and government portals.
Russian targeting of critical infrastructure routers
ConfirmedHigh
The U.S. and allies warned that Russian state-sponsored actors were compromising poorly secured routers across critical infrastructure networks, providing persistence, reconnaissance and traffic relay into protected environments.
NetNut / Popa residential proxy disruption
ConfirmedHigh
Google, the FBI and partners disrupted NetNut / Popa, a residential proxy network reportedly powered by millions of compromised home devices, including Android TV boxes and streaming devices.
LONGLEASH and Chinese ORB expansion
ConfirmedHigh
China-linked UAT-7810 expanded an Operational Relay Box network using LONGLEASH and related malware on internet-facing networking devices, giving stealthy staging and reconnaissance infrastructure that looks operationally normal.
Tenda firmware backdoor
ConfirmedHighCVE-2026-11405
CERT/CC warned of a hidden authentication backdoor in several Tenda router firmware versions, allowing administrative access to management interfaces. Routers are trusted, always on and often poorly monitored.
U-Boot and firmware flaws
Confirmed ResearchMed-High
Researchers found U-Boot flaws that could allow malicious images to crash devices or run code during boot, undermining assumptions behind routers, cameras and management controllers.
Januscape Linux KVM flaw
Public ResearchHigh
A 16-year-old Linux KVM flaw, Januscape, could allow guest-to-host escape on Intel and AMD systems under affected conditions. Virtualization boundaries underpin cloud and enterprise infrastructure, so guest-to-host issues need careful review even when exploitation is complex.
Operation DragonReturn targets Indian taxpayers
Confirmed ReportingHighIndia
A suspected China-nexus campaign targeted Indian taxpayers, tax professionals and corporate finance teams using fake Indian tax filing utilities to deliver DcRAT, a direct signal for accountants and finance teams handling sensitive financial data.
Balochistan Police portal weaponized
Confirmed ReportingMed-High
Reports described sustained espionage activity involving compromised Pakistani law-enforcement portals, with suspected China and India-linked activity over a multi-year period. Government portals can become both targets and staging grounds.
08Signals & Patterns
Six patterns define the first half of July
Agents convert trusted context into action Repositories, comments, images, emails, prompts and web pages can now influence systems that execute. Agent security must govern context, permissions, memory, tools and runtime behavior together.
Developer environments are becoming attacker workspaces Cursor, Claude Code, GitHub Copilot, Gemini CLI, GitHub workflows, npm, JetBrains plugins and fake PoC repositories all appeared across the intake. The developer workstation is now a production-adjacent execution environment, not just an endpoint.
OAuth and recovery flows are frontline attack surfaces Passkey enrollment, OAuth spoofing, device-code phishing, recovery keys and API access are now active attack paths. Strong authentication depends on lifecycle governance, not method strength alone.
Edge and control-plane exposure still demands emergency action SharePoint, SonicWall, Citrix, Progress, Kemp, Gitea, ColdFusion, Joomla, SAP, BeyondTrust and Ubiquiti all appeared. Internet-facing control-plane exposure needs a faster response lane than ordinary vulnerability management.
AI-assisted discovery is increasing triage pressure AI is finding more vulnerabilities, including long-lived flaws. That is useful, but it adds to the burden on teams that must decide what matters, what is exposed and what to fix first.
Trust markers are becoming weaker signals Verified commits, marketplace approval, signed packages, familiar extensions and legitimate login flows can all be abused. Trust needs to be backed by behavior, provenance and scope control, not badges alone.
09Defender Actions
Ten actions for the period ahead
Treat AI agents as privileged identities Inventory AI agents, coding assistants and workflow bots. Track ownership, permissions, credentials, data access and retirement.
Separate agent workspaces from production credentials Keep agentic coding tools out of directories holding production secrets, cloud keys or unrestricted SSH access.
Apply repository trust rules before opening in AI tools Treat cloned repositories as untrusted until reviewed. Block auto-execution and inspect symlinks and hidden files.
Govern AI-suggested dependencies Require provenance checks for AI-suggested packages. Do not install because a name looks plausible.
Audit OAuth apps, passkeys and device-code flows Review SaaS integrations. Monitor new grants, consent events, device-code activity and suspicious client IDs.
Build KEV emergency lanes for control-plane systems Pre-authorize action paths for SharePoint, Citrix, Gitea and similar systems, with named approvers and rollback owners.
Monitor developer credentials as production credentials Inventory, rotate and monitor GitHub, npm, AI provider and CI/CD secrets. Compromise should trigger production review.
Review AI infrastructure and model gateways Inventory Langflow, Dify, agent platforms and model routers. Apply authentication, segmentation and patch discipline.
Treat router and firmware exposure as strategic risk Routers, bootloaders and embedded filesystems need inventory and lifecycle planning. Invisible infrastructure still carries risk.
Separate confirmed compromise from claims Keep vendor-confirmed incidents, KEV items, research and actor claims in separate categories to protect decision quality.
10Closing Note
The first half of July made one point clear: the next security boundary is not only around systems. It is around action.
Agents now act on the context they are given. OAuth grants authorize access on their own terms. Passkeys and repositories carry instructions that were never meant to be read as such. Packages execute, extensions observe, and cloud APIs retrieve data quietly in the background. Trust, in other words, has become something that runs.
The enterprise has spent years approving tools, vendors, integrations and automation. The next stage of maturity is understanding what those trusted objects can actually do when something goes wrong, and building the judgment to catch it early.
The organizations that manage this well will not be the ones that ban every new tool or slow every workflow. They will be the ones that map authority clearly, constrain action intelligently, validate exposure quickly, and keep evidence separate from noise. That is the leadership task now.
About The Signal Watchtower
Published by Elytra Security. Signal-only intelligence across security, privacy and AI. Confirmed facts kept rigorously separate from claims and attacker assertions.
Authored by Venkat Mangudi · Founder & CEO, Elytra Security
Integrity. Trust. Clarity.
An ISO/IEC 27001:2022 Certified Company
