Info  2026-07-09 22:34Z · last 24h · 59 findings · glm-5.2:cloud

Threat Brief — 2026-07-09 — AI Agents Under Siege

Executive Summary

Today's intelligence is dominated by a wave of research exposing systemic security weaknesses in AI coding assistants — from symlink bypass tricks to hallucination-driven malware delivery — signaling that the developer tooling stack is now a primary attack surface. Meanwhile, Microsoft patched the public RoguePlanet Defender zero-day (CVE-2026-50656) that grants SYSTEM privileges, and the GodDamn ransomware operation is actively abusing a Microsoft-signed malicious kernel driver (PoisonX) to kill endpoint defenses. On the identity front, multiple vishing and phishing-as-a-service campaigns (Forg365, Helix, Entra passkey enrollment) are converging on Microsoft 365 and SharePoint environments.

Top Items

Themes

AI coding assistants are the薄弱环节 of the week. At least five distinct findings — GhostApproval symlink exploits, HalluSquatting, AI agents running malicious code instead of scanning it, Copilot bypassing chat safety via code-step decomposition, and Sophos data showing AI coding agents triggering endpoint detection rules — collectively paint a picture of an emerging attack surface that most organizations have not yet instrumented or governed. Treat AI agents as a new identity class, not service accounts.

Identity-focused attacks are converging on Microsoft 365. Forg365 (PhaaS), Helix (vishing + SharePoint extortion), and Entra passkey enrollment vishing all target the same identity stack. The verification step — not the password — is now the primary ATO battleground. Ensure service-desk verification workflows are resilient to AI-powered impersonation.

Supply-chain integrity remains under sustained pressure. npm package compromise, fake payment SDKs, GitHub verified-commit hash collisions, dormant GitHub account enumeration of corporate orgs, and npm 12's decision to disable install scripts by default all point to a maturing attacker playbook targeting developer trust pathways.

Destructive malware is rebranding as ransomware. GigaWiper's bundling of wiper, fake ransomware, and spyware — alongside GodDamn's driver-based defense evasion — suggests financially motivated actors are increasingly comfortable with destructive payloads, blurring the line between extortion and sabotage.

Public exploits · latest from the exploit feed

ArcadeDB < 26.7.2 Cross-Database Authorization Bypass (IDOR) 2026-08-02 15:45Z · RSS:cxsecurity-wlb Linux Kernel 7.0-7.0.8 & 7.0-rc-7.0-rc7 - Use After Free Exploit 2026-08-02 15:45Z · RSS:cxsecurity-wlb MODX.3.2.1 TLS cookie without secure flag set - COOKIE PHPSESSID HIJACK 2026-08-02 15:45Z · RSS:cxsecurity-wlb Linux Kernel 7.0 DRM UAF LPE Exploit published for CVE-2026-46215 CVE-2026-46215 2026-07-22 14:05Z · CXSecurity / Exploit-DB (RSS) ZTE ZXHN H188A V6 Authentication Bypass 2026-07-22 13:28Z · RSS:cxsecurity-wlb OpenEMR 7.0.2 Arbitrary File Read 2026-07-22 13:28Z · RSS:cxsecurity-wlb PHP Link Directory (phpLD) 2.1.3 - SQL Injection, IDOR, CSRF 2026-07-22 13:28Z · RSS:cxsecurity-wlb KNX visualisering - Broken Access Control 2026-07-22 13:28Z · RSS:cxsecurity-wlb D-Link DSL2600U rom-0 Admin Password Disclosure 2026-07-22 13:28Z · RSS:cxsecurity-wlb Windows Defender (MsMpEng.exe) Race Condition -> LPE / SYSTEM / Use-After-Free -> Crash 2026-07-22 13:28Z · RSS:cxsecurity-wlb