Info  2026-07-05 12:52Z · last 24h · 2 findings · glm-5.2:cloud

Threat Brief — 2026-07-05 — Ransomware Extortion Goes Autonomous

Executive Summary

Two developments underscore the continued evolution of ransomware and extortion operations. A U.S. government entity reportedly paid approximately $1 million to the Kairos group to prevent the leak of stolen files — a notable case given the public-sector target and the payment trail documented via negotiation chats and blockchain analysis. Separately, researchers documented what they believe is the first ransomware attack conducted entirely by an LLM agent (JadePuffer), signalling a potential shift toward automated, low-human-in-the-loop extortion operations.

Top items

Researchers identified what they believe is the first documented case of a ransomware operation executed entirely by a large language model agent. This matters because it demonstrates LLM agents can autonomously orchestrate end-to-end attack chains, potentially lowering the skill barrier and enabling scale for financially motivated threat actors. Attribution: JadePuffer. Source: https://www.bleepingcomputer.com/news/security/jadepuffer-ransomware-used-ai-agent-to-automate-entire-attack/

A case study by Rakesh Krishnan for Ransom-ISAC, based on leaked negotiation chat and blockchain payment analysis, details a ~$1 million extortion payment by a U.S. government entity to prevent leak of stolen files. This matters as it confirms continued willingness to pay in the public sector and provides rare visibility into negotiation/payment workflows. Attribution: Kairos group. Source: https://thehackernews.com/2026/07/us-government-entity-paid-kairos-group.html

Themes

Public exploits · latest from the exploit feed

ArcadeDB < 26.7.2 Cross-Database Authorization Bypass (IDOR) 2026-08-02 15:45Z · RSS:cxsecurity-wlb Linux Kernel 7.0-7.0.8 & 7.0-rc-7.0-rc7 - Use After Free Exploit 2026-08-02 15:45Z · RSS:cxsecurity-wlb MODX.3.2.1 TLS cookie without secure flag set - COOKIE PHPSESSID HIJACK 2026-08-02 15:45Z · RSS:cxsecurity-wlb Linux Kernel 7.0 DRM UAF LPE Exploit published for CVE-2026-46215 CVE-2026-46215 2026-07-22 14:05Z · CXSecurity / Exploit-DB (RSS) ZTE ZXHN H188A V6 Authentication Bypass 2026-07-22 13:28Z · RSS:cxsecurity-wlb OpenEMR 7.0.2 Arbitrary File Read 2026-07-22 13:28Z · RSS:cxsecurity-wlb PHP Link Directory (phpLD) 2.1.3 - SQL Injection, IDOR, CSRF 2026-07-22 13:28Z · RSS:cxsecurity-wlb KNX visualisering - Broken Access Control 2026-07-22 13:28Z · RSS:cxsecurity-wlb D-Link DSL2600U rom-0 Admin Password Disclosure 2026-07-22 13:28Z · RSS:cxsecurity-wlb Windows Defender (MsMpEng.exe) Race Condition -> LPE / SYSTEM / Use-After-Free -> Crash 2026-07-22 13:28Z · RSS:cxsecurity-wlb