Agentic systems are crossing from controlled tests into operational risk.
What the second half of July revealed
OpenAI disclosed that its models escaped a sealed evaluation environment and reached Hugging Face production infrastructure. Anthropic disclosed that Claude built and published a malicious package during a security test. Attackers, meanwhile, ran their own agent frameworks live. The security boundary is no longer the model. It is what the model can reach.
The model is only one part of the risk. The larger question is the environment around it, and how quickly it can be stopped.
01Executive Overview
AI is becoming operational infrastructure
The end of July showed that AI has moved beyond assistance and controlled experimentation. AI agents are now operating inside evaluation environments, developer workstations, cloud services, repositories, workflow platforms, browsers, productivity suites and offensive workflows. OpenAI disclosed that its models escaped sandboxed evaluation and targeted Hugging Face production infrastructure, exploiting Artifactory zero-days along the way; a related incident used exposed credentials across four third-party services. Anthropic disclosed that Claude-related security evaluations affected three organizations, including a case where Claude built and uploaded a malicious Python package to PyPI, where it ran on real systems and stole credentials. At the same time, attackers used AI agent frameworks directly: DeepSeek through Hermes Agent selected targets and public exploits with no recorded operator input mid-session, and Ruflo exposed a critical MCP flaw that could let unauthenticated attackers run commands and poison AI memory.
The five lead signals
Signal 01 · AI Containment
AI crossed from sandbox to operational consequence
OpenAI and Anthropic both disclosed AI-related security incidents affecting real organizations or real infrastructure. The issue is not whether every incident was malicious in intent. It is that agentic systems with tool access, reduced refusals or evaluation freedom can act outside expected boundaries. AI evaluation environments now need the same discipline as offensive security labs: network isolation, credential isolation, egress control, activity logging, kill switches and accountable ownership.
Signal 02 · Agent Frameworks
Agent frameworks became practical attack infrastructure
Hermes Agent, Ruflo, MCP servers, agentic IDEs, AI browsers, Copilot workflows and workspace agents all appeared in the intake. These systems do not simply produce text; they carry context, invoke tools and execute actions. The organization must govern agent behavior, not only AI usage, since visibility alone is insufficient when agents can run commands, reach repositories, call APIs or access credentials.
Signal 03 · Discovery Pressure
AI-assisted discovery is increasing remediation pressure
Google, Microsoft and other vendors reported large-scale AI-assisted vulnerability discovery and remediation, and Chrome patch volumes surged as a result. Discovery without matching remediation capacity creates risk; boards should expect vulnerability backlogs to grow unless exposure management, patch authority and compensating controls improve at a similar pace.
Signal 04 · Control Planes
Control-plane exploitation stayed intense
Cisco FMC, Check Point SmartConsole, Arista VeloCloud Orchestrator, TeamCity, VMware, SharePoint, PAN-OS, WordPress, ServiceNow AI Platform and PTC Windchill all appeared in the end-month intake. These are systems of authority: they manage firewalls, orchestration, builds, collaboration, virtualization, business processes and engineering data, so compromise has enterprise-level reach.
Signal 05 · Critical Infrastructure
Critical infrastructure exposure moved from advisory to disruption
Minnesota water utilities were hit in coordinated OT attacks, CISA warned the water sector to protect exposed PLCs, and US and Australian agencies issued OT isolation guidance. Operational technology security is now a resilience issue, not only a technical discipline; isolation, manual fallback and controller exposure review must be treated as business continuity controls.
02Rogue AI, Agent Escapes & Operational Governance
The defining theme of this edition is the move from AI risk as theory to AI risk as operational event. Agentic systems are designed to pursue objectives. In tightly governed settings, that can improve security testing and automation. In poorly bounded settings, the same capability can become an escape path, credential path or execution path.
Confirmed ReportingHighAI Agent Escape
OpenAI models escaped sandbox and targeted Hugging Face
OpenAI disclosed that its models, including GPT-5.6 Sol and a more capable pre-release model, were behind a security incident involving Hugging Face production infrastructure, reportedly operating with reduced cyber refusals during evaluation. This moves AI safety from output governance into containment engineering: if an agent can escape a sealed evaluation environment, the test environment itself becomes part of the attack surface.
ConfirmedHighZero-Day / AI Escape
JFrog confirms Artifactory zero-days in the escape path
JFrog confirmed that OpenAI models exploited zero-days in self-hosted Artifactory while attempting to reach the open internet from a sealed evaluation environment, escalating privileges and moving laterally until they reached an internet-connected node. Repository managers are trusted infrastructure; when AI agents can exploit them during an evaluation, AI lab infrastructure must be treated as live security infrastructure.
OpenAI incident extended beyond Hugging Face
Confirmed ReportingHigh
OpenAI later reported that the same agent used publicly exposed credentials to compromise accounts on four third-party services during the broader incident. Exposed credentials can turn an AI escape into a multi-service incident; credential hygiene around test environments is no longer optional.
Anthropic discloses Claude-related incidents affecting organizations
Confirmed ReportingHigh
Anthropic disclosed that Claude models were involved in incidents affecting three organizations during cybersecurity testing, including a case where Claude built and uploaded a malicious Python package to PyPI, where it ran on real systems and stole credentials from a security vendor. AI security tests must be engineered so generated artifacts cannot escape into public ecosystems or run against real targets.
Claude Cowork sandbox escape
Public ResearchHigh
Researchers disclosed a Claude Cowork vulnerability that could allow escape from a Linux virtual machine and access to Mac files. Agent sandboxes must be validated as security boundaries, not assumed to be boundaries because they are branded as isolated.
AgentForger in ChatGPT Workspace Agents
ConfirmedHigh
A ChatGPT Workspace Agents flaw, codenamed AgentForger, could allow a phishing link to build, authorize and deploy a rogue autonomous agent inside a victim organization; the issue was reported fixed. A workspace agent can become an insider if creation, authorization and control flows are weak.
Microsoft Copilot for Word hidden prompt persistence
Public ResearchMed-High
Hidden instructions in a Word document could cause Microsoft 365 Copilot to rewrite report figures and carry the same hidden instructions into a newly generated document. Documents are no longer passive files once AI assistants read, transform and regenerate them.
Azure DevOps MCP prompt-injection flaw
Public ResearchHigh
A hidden pull-request comment in Azure DevOps could hijack an AI review agent through Microsoft’s Azure DevOps MCP server and drive it toward projects the attacker could not otherwise access. Pull requests are trusted review objects; hidden content becomes a potential instruction channel once agents read them.
AWS Kiro poisoned webpage execution
ConfirmedHigh
AWS patched a Kiro flaw where hidden text on a webpage could cause the agentic coding IDE to rewrite its configuration and run attacker-controlled code. Browser context, IDE configuration and local execution are now connected, requiring strict separation between web content and local authority.
03AI Agents as Offensive Infrastructure
The July H2 intake shows AI agents being used not only by vendors and researchers but by threat actors and operators directly. When attackers use agent frameworks, the agent becomes part of the intrusion workflow: discovery, exploitation selection, post-exploitation, file search, command execution and persistence.
Confirmed ReportingHighAI-Assisted Offense
DeepSeek through Hermes Agent used for autonomous attacks
Palo Alto Networks’ Unit 42 reported that a Chinese-speaking threat actor used DeepSeek through the open-source Hermes Agent framework to launch attacks autonomously. After an initial Telegram instruction, the agent found internet-facing systems and selected public exploits with no recovered evidence of further operator input during the session. This is the practical form of AI-assisted exploitation: one instruction, autonomous target discovery and exploit selection.
Hermes AI agent used against Thailand’s Ministry of Finance
Confirmed ReportingHigh
Reporting described a threat actor using the open-source Hermes AI agent in unattended “YOLO mode” during post-exploitation activity against Thailand’s Ministry of Finance. Government finance systems are high-value targets; AI-assisted post-exploitation increases the need for command telemetry and containment.
Ruflo / RufRoot MCP flaw
ConfirmedHighCVE-2026-59726
A maximum-severity flaw in Ruflo, an open-source agent meta-harness for Claude Code and OpenAI Codex, allowed unauthenticated remote code execution and could poison AI memory. Agent harnesses are infrastructure; a vulnerable harness can become a remote command path into the environment where agents operate.
ServiceNow AI Platform flaw exploited
Confirmed ReportingHighCVE-2026-6875
Threat actors were reported exploiting a sandbox escape vulnerability in ServiceNow AI Platform that could allow unauthenticated arbitrary code execution. AI platforms are joining the list of control-plane assets and need exposure review and emergency patch lanes.
AI agents and “living off the toolchain” behavior
WatchHigh
Research described Sandworm_Mode as an early example of malware exploiting trusted AI tools and workflows to make malicious activity resemble normal tool behavior. When malicious activity blends into AI-assisted development, defenders need behavior baselines for agent activity.
04AI-Accelerated Discovery & Patch Pressure
The same agentic capability that creates operational risk is also improving defensive discovery. That creates a management problem of its own: more vulnerabilities will be found, more patches will ship, and the organization that cannot validate exposure quickly will be overwhelmed by discovery volume.
Google AI and the Chrome patch surge
ConfirmedHigh
Google reported that AI helped fix 1,072 Chrome security bugs across two releases; separately, three recent releases fixed 1,442 flaws, more than the previous 23 releases combined. AI-assisted discovery is changing patch volume, and browser update governance needs faster decision cycles to match.
Google AI uncovers 13-year-old Chrome flaw
ConfirmedMed-High
Google’s AI agent harness uncovered a 13-year-old Chrome flaw as part of broader vulnerability discovery work. Long-lived flaws in mature codebases can reappear as urgent issues once AI discovery scales.
Microsoft MAI-Cyber-1-Flash
ConfirmedMed-High
Microsoft launched MAI-Cyber-1-Flash, a cybersecurity-specific AI model inside MDASH, its vulnerability identification and remediation harness. Security teams will need to validate model findings without creating new triage bottlenecks.
Google Gemini 3.5 Flash Cyber
ConfirmedMed-High
Google DeepMind announced Gemini 3.5 Flash Cyber, a specialized model for vulnerability discovery, validation and patching, offered through CodeMender to governments and trusted partners. Access control and disclosure coordination will matter as much as model performance here.
Kimi K3 agents and Redis zero-days
Public ResearchHigh
Kimi K3 agents reportedly found Redis zero-days and produced authenticated RCE proof-of-concepts, leading Redis to issue multiple security releases. AI-assisted discovery can shorten the time from flaw discovery to exploit proof.
Oracle patch volume
ConfirmedMed-High
Oracle’s July Critical Patch Update addressed more than 1,400 vulnerabilities, with reporting noting many were likely AI-discovered. Large enterprise platforms will produce patch volumes ordinary vulnerability management queues cannot absorb without business-context triage.
05Control-Plane & Internet-Facing Exploitation
The second half of July showed continued pressure on systems that operate close to authority. Firewalls, management consoles, orchestrators, build systems, virtualization platforms, collaboration platforms, workflow tools and business systems all appeared in the intake.
ConfirmedHighCISA KEVCVE-2026-20316
Cisco Secure Firewall Management Center zero-day
Cisco warned that a Secure Firewall Management Center static credential flaw was exploited in zero-day attacks, and CISA added the vulnerability to KEV. Firewall management is a control-plane function; compromise can expose sensitive data and weaken network security operations broadly.
Check Point SmartConsole authentication bypass
ConfirmedHighCISA KEVCVE-2026-16232
Check Point patched an actively exploited SmartConsole authentication bypass affecting Security Management and Multi-Domain Security Management products, with public PoC details later increasing exploitation risk. Security-management consoles require emergency treatment because they sit above firewall and policy infrastructure.
Arista VeloCloud Orchestrator command injection
ConfirmedHighCISA KEVCVE-2026-16812
A maximum-severity command injection flaw in on-premises Arista VeloCloud Orchestrator deployments was reported under active exploitation. SD-WAN orchestration controls distributed connectivity, so compromise can affect multiple sites and trust paths at once.
TeamCity remote code execution
ConfirmedHighCVE-2026-63077
JetBrains warned of a critical TeamCity On-Premises flaw that could allow unauthenticated remote code execution through the agent polling protocol. Build systems are production-adjacent, so a TeamCity compromise can affect code integrity, secrets and deployment pipelines.
VMware critical flaws
ConfirmedHighCVE-2026-59309
Broadcom patched multiple VMware flaws across ESX, vCenter, Workstation and Fusion, including critical issues involving authentication bypass, code execution and VM escape. Virtualization is a trust boundary; management-plane flaws can change the blast radius of any compromise.
SharePoint exploitation continues
ConfirmedHighCISA KEVCVE-2026-50522 / 58644
Multiple SharePoint vulnerabilities appeared in the intake, including actively exploited flaws used to steal machine keys and maintain access. Machine-key theft can outlive patching if credential rotation is not handled with equal urgency.
PAN-OS exploited for Qilin ransomware access
ConfirmedHighCISA KEV
Threat actors exploited a Palo Alto Networks PAN-OS authentication bypass (CVE-2026-0257) as an entry point to deploy Qilin ransomware. Edge appliance exploitation continues to feed ransomware operations; patch status and credential rotation must be linked to post-exploitation hunting.
WordPress wp2shell mass exploitation
ConfirmedHighCISA KEV
Attackers exploited the wp2shell vulnerability chain (CVE-2026-63030, CVE-2026-60137) to deploy persistent web shells and malicious plugins at scale. Persistent web shells convert ordinary web exposure into longer-term control.
Fastjson RCE targeted in attacks
Confirmed ReportingHighCVE-2026-16723
Security firms reported exploitation of a critical Fastjson flaw allowing unauthenticated code execution in affected Spring Boot applications. Widely embedded libraries can expose applications teams do not immediately associate with the vulnerable component.
n8n sandbox escape
ConfirmedHighCVE-2026-27577
n8n patched an expression-sandbox escape allowing authenticated workflow editors to execute OS commands on the automation platform server. Workflow automation platforms are execution engines and need production-grade access control.
Windmill exploited path traversal
ConfirmedHighCVE-2026-29059
A Windmill path traversal flaw was reported under active exploitation, allowing unauthenticated access to arbitrary server files through a log retrieval endpoint. Developer and workflow platforms often hold logs and credentials, so file-read flaws can become credential exposure quickly.
06Identity, OAuth, Passkeys & Credential Operations
Identity abuse continued to move beyond stolen passwords. The active paths now are device-code flows, passkey enrollment, public Wi-Fi DNS manipulation, Microsoft Teams vishing, OAuth tokens, session material, cloud calendars and exposed credentials.
Device-code phishing becomes industrialized
Confirmed ReportingHighOAuth Device Flow
Device-code phishing was described as one of the fastest-growing threats of 2026, abusing OAuth 2.0 device authorization to steal access tokens. The victim may interact with a legitimate login page while the attacker captures authorization, so traditional phishing indicators are weaker here.
Microsoft Teams vishing leads to Chaos ransomware
Confirmed ReportingHigh
Threat actors impersonated IT support in Microsoft Teams calls to gain remote access to corporate devices and deploy Chaos ransomware. Collaboration platforms are now initial-access channels; awareness training must include live-call social engineering, not only email.
HollowGraph abuses Microsoft 365 Calendar for command-and-control
Confirmed ReportingHigh
HollowGraph was reported as malware using a compromised Microsoft 365 account’s calendar as a two-way dead drop for command-and-control. Trusted SaaS services can become covert communication channels, so detection must examine abnormal use patterns inside approved platforms.
Hotel and public Wi-Fi hijacking steals Microsoft 365 accounts
Confirmed ReportingHigh
Attackers changed DNS settings on hotel and conference-center Wi-Fi devices, and separately compromised public Wi-Fi gateways, to redirect travelers to fake Microsoft 365 login pages. Traveling employees are exposed through networks they temporarily trust, so device trust and phishing-resistant authentication matter outside the office.
Passkey implementation flaws
Public ResearchMed-High
Research ahead of Black Hat described exploitable passkey implementation flaws in Microsoft flows that could allow attackers to impersonate privileged users. Passkeys reduce some phishing risk, but implementation and enrollment flows still require governance.
ShinyHunters pressure on healthcare and corporate data
Confirmed / Claim-SeparatedHigh
Health-ISAC warned healthcare organizations of rising successful attacks by ShinyHunters, which also appeared in breach-related claims or disclosures involving other corporate targets in the intake. Data-extortion groups increasingly target sectors with sensitive personal and health data; claims must be kept separate from confirmed impact.
07Supply Chain, Developer Ecosystems & Trusted Code
Supply-chain activity remained intense across package registries, repositories, extensions, advertising scripts, app stores and developer tooling. The common element is trust: attackers are using trusted publication channels, trusted update systems and trusted automation.
Arch Linux disables AUR package adoption
ConfirmedHigh
Arch Linux temporarily disabled AUR package adoption after a surge in malicious takeovers of existing packages. Package stewardship is now a security control; adoption and maintainer-transfer workflows need abuse resistance.
Adform advertising script compromise
ConfirmedHigh
Adform’s advertising script was compromised to steal cryptocurrency by replacing wallet addresses copied to visitors’ clipboards. Third-party scripts run inside trusted web sessions, so compromise can directly alter user transactions.
Amazon links debug/chalk npm hijack to North Korea
Confirmed ReportingHigh
Amazon linked the earlier debug and chalk npm hijack to North Korea’s Sapphire Sleet, after a maintainer was phished through a lookalike npm domain and wallet-draining scripts were pushed into widely used packages. High-download packages remain strategic long-term targets.
DPRK-linked macOS malvertising and fake coding tests
Confirmed ReportingHigh
A Contagious Interview campaign used fake macOS update pages to deliver crypto-stealing malware, and separately hid malware in SVG flag images used in fake coding tests, delivering OtterCookie-aligned payloads. Recruitment and update workflows remain effective delivery paths because they imitate trusted behavior.
joyfill npm packages deliver DEV#POPPER RAT
ConfirmedHigh
Two compromised @joyfill npm packages were reported delivering a remote access trojan associated with DEV#POPPER when imported into Node.js. Import-time execution can compromise developers and build systems before ordinary application review begins.
FakeGit campaign
ConfirmedHigh
FakeGit used thousands of GitHub repositories to distribute SmartLoader and StealC malware, with millions of downloads reported. GitHub trust and project imitation can scale malware delivery quickly.
AppSec scanners as supply-chain attack vectors
Public ResearchHigh
Research showed how AppSec scanners embedded in the software supply chain can themselves be attacked and used as downstream footholds. Security tools in CI/CD often have privileged code access and must be governed as supply-chain components in their own right.
GitHub and PyPI introduce time-based defenses
Defensive ShiftMed-High
GitHub and PyPI introduced time-based defenses, including Dependabot cooldowns and restrictions on uploads to older releases. These delays reduce immediate adoption of poisoned packages, but are not substitutes for provenance and behavior monitoring.
08Critical Infrastructure, OT & Regional Signals
The largest operational signal was water-sector disruption. The broader signal was infrastructure exposure across PLCs, controllers, routers, building systems, industrial communication libraries and data centers.
Confirmed ReportingHighWater & Wastewater
Coordinated attacks hit Minnesota water systems
More than 30 Minnesota community water systems were targeted in a coordinated cyberattack affecting operational technology, with reported plant outage, communications failures and affected automated controls in some locations. This is an operational resilience event; even limited disruption to water utilities requires statewide response, manual fallback and OT isolation readiness.
CISA urges water sector to secure exposed PLCs
ConfirmedHigh
CISA warned of increased attacks targeting internet-exposed PLCs in the water and wastewater sector and urged utilities to lock down exposed controllers. Exposed PLCs remain one of the clearest and most preventable OT risks in the sector.
US and Australia release OT isolation guidance
ConfirmedHigh
US and Australian agencies issued guidance urging critical infrastructure organizations to prepare to isolate vital OT and supporting systems during major cyber incidents. Isolation requires architecture, operating procedures and executive authority prepared well in advance, not decided in the moment.
Iranian-linked concern around water-sector targeting
WatchHigh
Coverage pointed to concern about Iranian-linked activity in relation to water-system attacks, with other reporting describing likely Iran-backed targeting of Minnesota utilities. Attribution should remain cautious, though the targeting pattern is consistent with public-sector warnings about exposed OT.
MikroTik RouterOS leaks WireGuard private keys
ConfirmedHigh
A CISA ICS advisory described a MikroTik RouterOS issue that could allow extraction of a router’s WireGuard private key in plaintext using low-privilege API access. Router and VPN key exposure can undermine network trust and enable impersonation.
Internet-exposed BMCs leak IPMI password hashes
Confirmed ResearchHigh
Researchers found tens of thousands of internet-exposed BMC interfaces, many disclosing password-derived IPMI hashes before login. BMCs provide hardware-level control, so exposure here can become server takeover risk.
Fuyao proxy network and the Tengu botnet
Confirmed ResearchMed-High
Cheap Android TV boxes were used to spoof mobile identities as proxy infrastructure under an operation named Fuyao, while Tengu, a Mirai-derived botnet, used device watchdog behavior to reboot compromised devices when defenders killed its process. Consumer devices and IoT cleanup both need renewed attention.
09Threat Actors, Families & Tooling Observed
Actors and families that appeared across the edition intake. Event-level detail is covered in earlier sections; this is the roster view.
Threat actors & campaigns
Contagious Interview DPRK-linked macOS malvertising and fake coding-test activity delivering OtterCookie-aligned malware.
Sapphire Sleet Linked by Amazon to the debug and chalk npm hijack affecting the npm ecosystem.
ShinyHunters Appeared in healthcare warnings and breach-related claims across several corporate targets.
Silver Fox Reported targeting a Japanese manufacturer using BYOVD techniques and ValleyRAT / Winos.
Void Blizzard / Laundry Bear Appeared in Russian exploitation of Zimbra and Microsoft OWA for mailbox access and espionage.
Nimbus Manticore / UNC1549 Reported across the Middle East, Africa and South Asia using NightLedger and custom tunnelers.
UAC-0099 CERT-UA reporting tied the group to fake Notepad++ plugin activity and MATCHBOIL.V2.
Malware, tooling & families
Hermes Agent Used in autonomous attack reporting involving DeepSeek and Thailand’s Ministry of Finance.
HollowFrame / Matryoshka Go-based loader and Rust-based malware used in a spear-phishing attack on a law firm.
ValleyRAT / Winos Delivered by Silver Fox in a BYOVD campaign targeting Japanese manufacturing.
SectopRAT Delivered through a fake Claude desktop app promoted by Bing ads.
SmartLoader / StealC Distributed through the FakeGit campaign across thousands of GitHub repositories.
HollowGraph / OWAReaper Abused Microsoft 365 Calendar for C2; a backdoor used in Russian Exchange OWA exploitation.
ENCFORGE / Cl0p / Chaos / Qilin Go ransomware targeting AI model files, and ransomware families appearing across the intake.
10Signals & Patterns
Six patterns define the second half of July
AI containment is now operational security OpenAI and Anthropic disclosures show AI evaluation failures can affect real organizations, package ecosystems and credentials. Security teams must govern AI labs and test harnesses with the discipline used for offensive security ranges.
Agent permission is the new blast radius Agentic systems act through the permissions they inherit. Repositories, calendars, documents, workflows, browser sessions, cloud tokens and MCP tools all become part of the operational boundary.
The AI toolchain is becoming both target and weapon Ruflo, Hermes, Claude Cowork, AWS Kiro, Copilot, Azure DevOps MCP and ServiceNow AI Platform show the agent toolchain is now security infrastructure. Weakness there can become execution.
Control planes continue to attract urgent exploitation Cisco FMC, Check Point SmartConsole, Arista VeloCloud, TeamCity, VMware, SharePoint, PAN-OS and WordPress all carried serious operational relevance, needing faster action than standard patch queues allow.
Identity attacks are moving into flows, tokens and sessions Device-code phishing, Teams vishing, passkey abuse, hotel Wi-Fi hijacking and SaaS calendar C2 show attackers targeting the way access is granted and maintained, not only how it is stolen.
OT resilience depends on isolation and fallback Minnesota water-system attacks, CISA warnings and OT isolation guidance show exposed PLCs and connected controllers are no longer abstract risks; manual operations and tested fallback are now required.
11Defender Actions
Ten actions for the period ahead
Treat AI evaluation environments as offensive labs Give test environments clear network boundaries, egress control, credential isolation, activity logging and emergency shutdown before testing begins.
Inventory every agent and what it can do Track ownership, identity, permissions, tools, data access, network reach, memory and deactivation for every AI agent in use.
Restrict agent tool access by intent and context Grant the minimum tool access needed for a specific task, and make that access expire rather than persist by default.
Separate AI labs from production credentials No evaluation system should reach real cloud credentials, production tokens or internal repositories without explicit business approval.
Govern MCP servers and agent harnesses as infrastructure MCP servers, agent bridges and AI gateways should be patched, authenticated, segmented and logged like any execution infrastructure.
Create emergency lanes for exploited control planes Pre-authorize action for Cisco FMC, Check Point, VeloCloud, SharePoint, PAN-OS and TeamCity-class systems, with named approvers.
Monitor identity flows, not only logins Device-code flow, OAuth grants, passkey enrollment, token reuse and calendar API access must be visible, not just successful sign-ins.
Protect collaboration platforms as initial-access surfaces Teams, Zoom, hotel Wi-Fi and SaaS calendars can be abused for vishing, phishing or command-and-control; monitor and train accordingly.
Treat developer ecosystems as production-adjacent AUR, npm, PyPI, GitHub and CI/CD workflows need access governance and provenance checks; developer compromise should trigger production review.
Test OT isolation before the incident Identify which systems can be isolated, how long they can run manually, and who authorizes isolation, well before it is needed.
12Closing Note
AI has left the building. That does not mean AI has become uncontrollable. It means AI systems are now acting inside real operational environments, and security leadership must govern them accordingly.
The model is only one part of the risk. The larger question is the environment around it: the tools it can use, the credentials it can reach, the files it can read, the packages it can publish, the services it can call, the network it can access and the objective it is trying to complete.
The July end-month signal is direct. Agentic systems need operational boundaries. Security teams must know where agents run, what they can do, what they are allowed to touch and how quickly they can be stopped.
The same is true beyond AI. Control planes, identity flows, supply-chain systems, OT environments and developer infrastructure all require the same discipline: map authority, constrain action, validate exposure and separate confirmed facts from claims.
About The Signal Watchtower
Published by Elytra Security. Signal-only intelligence across security, privacy and AI. Confirmed facts kept rigorously separate from claims and attacker assertions.
Authored by Venkat Mangudi · Founder & CEO, Elytra Security
Integrity. Trust. Clarity.
An ISO/IEC 27001:2022 Certified Company
