This day 06:02 09:35 10:11 14:20 14:35 22:19
Info  2026-07-20 22:19Z · last 24h · 20 findings · glm-5.2:cloud

Threat Brief — 2026-07-20 — AI Tooling Under Fire

Executive summary: AI coding assistants and agent platforms are the day's primary attack surface, with sandbox escapes confirmed across Cursor, Codex, Gemini CLI, and Antigravity. JadePuffer—first reported as a proof-of-concept on July 18—has now weaponized into a live ransomware operation targeting AI training assets specifically. Separately, a massive FakeGit campaign weaponizes 7,600 GitHub repositories, over 800 masquerading as AI skills and MCP servers, marking a sharp escalation in supply-chain abuse of the AI ecosystem.

Top Items

Themes

AI tooling is now both target and weapon. Across today's findings, AI coding assistants are exploitable (sandbox escapes), AI infrastructure is the ransomware target (EncForge vs. model data), AI is the lure (fake MCP servers on GitHub), and AI assists offensive operations (phishing toolkit, Gemini botnet control). The attack surface expanded faster than the defensive tooling around it.

Legitimate cloud services as C2 infrastructure. HollowGraph's use of Microsoft Graph calendar events mirrors a broader trend of attackers abusing trusted SaaS APIs to hide command channels inside normal organizational traffic—graph/calendar/email API monitoring is becoming essential.

===

Public exploits · latest from the exploit feed

ArcadeDB < 26.7.2 Cross-Database Authorization Bypass (IDOR) 2026-08-02 15:45Z · RSS:cxsecurity-wlb Linux Kernel 7.0-7.0.8 & 7.0-rc-7.0-rc7 - Use After Free Exploit 2026-08-02 15:45Z · RSS:cxsecurity-wlb MODX.3.2.1 TLS cookie without secure flag set - COOKIE PHPSESSID HIJACK 2026-08-02 15:45Z · RSS:cxsecurity-wlb Linux Kernel 7.0 DRM UAF LPE Exploit published for CVE-2026-46215 CVE-2026-46215 2026-07-22 14:05Z · CXSecurity / Exploit-DB (RSS) ZTE ZXHN H188A V6 Authentication Bypass 2026-07-22 13:28Z · RSS:cxsecurity-wlb OpenEMR 7.0.2 Arbitrary File Read 2026-07-22 13:28Z · RSS:cxsecurity-wlb PHP Link Directory (phpLD) 2.1.3 - SQL Injection, IDOR, CSRF 2026-07-22 13:28Z · RSS:cxsecurity-wlb KNX visualisering - Broken Access Control 2026-07-22 13:28Z · RSS:cxsecurity-wlb D-Link DSL2600U rom-0 Admin Password Disclosure 2026-07-22 13:28Z · RSS:cxsecurity-wlb Windows Defender (MsMpEng.exe) Race Condition -> LPE / SYSTEM / Use-After-Free -> Crash 2026-07-22 13:28Z · RSS:cxsecurity-wlb