Threat Brief — 2026-07-20 — AI Tooling Under Fire
Executive summary: AI coding assistants and agent platforms are the day's primary attack surface, with sandbox escapes confirmed across Cursor, Codex, Gemini CLI, and Antigravity. JadePuffer—first reported as a proof-of-concept on July 18—has now weaponized into a live ransomware operation targeting AI training assets specifically. Separately, a massive FakeGit campaign weaponizes 7,600 GitHub repositories, over 800 masquerading as AI skills and MCP servers, marking a sharp escalation in supply-chain abuse of the AI ecosystem.
Top Items
- Sandbox escapes in major AI coding tools (Cursor, Codex, Gemini CLI, Antigravity): Researchers escaped sandboxes by having AI agents write files that trusted host tools subsequently executed, yielding code execution on developer machines. Multiple CVEs assigned; patches issued, though Google downgraded two Antigravity findings. This directly threatens any engineering org using these tools for autonomous code generation. (src: BleepingComputer)
- JadePuffer ransomware upgrades with EncForge, now targeting AI model data: The autonomous AI agent first demonstrated on July 18 has deployed custom encrypting malware called EncForge that specifically targets training datasets, vector databases, and model checkpoints—a shift from generic file encryption to AI-asset-focused extortion. This is a tangible operationalization of the AI-driven ransomware concept. (First reported 2026-07-18 by Mandiant GTIG) (src: BleepingComputer)
- FakeGit campaign: 7,600 malicious GitHub repos deliver SmartLoader malware: Over 800 of these repositories impersonate AI skills or MCP servers, exploiting developer trust in AI-adjacent tooling. This is a significant supply-chain vector directly relevant to teams pulling community AI integrations. (src: The Hacker News)
- HollowGraph malware: Microsoft 365 calendar as stealth C2 channel: An espionage implant hijacks compromised M365 mailbox calendars, planting operator commands and exfiltrating stolen files as attachments on calendar events dated to the year 2050. Uses Microsoft Graph APIs for traffic that blends into legitimate cloud activity—difficult to detect without calendar-content inspection. (src: BleepingComputer) · (src: The Hacker News)
- Exposed server reveals AI-assisted phishing toolkit behind WebDAV malware campaign: An operator's misconfigured delivery server exposed 1,048 files including lure templates, filename-spoofing tests, droppers, and builder notes—providing rare visibility into a turnkey phishing operation that leverages AI for lure generation and execution experimentation. (src: The Hacker News)
- ClickLock: macOS infostealer force-terminates apps to coerce password entry: Group-IB identified a macOS stealer that kills Finder, Dock, Terminal, Activity Monitor, and browsers every 210 ms until the victim enters their system password—a brute-force UX attack that bypasses the need for exploit-based privilege escalation on macOS. (src: Xakep)
- BEC phishing "TFF Trap" combines fileless evasion with multi-RAT deployment: A coordinated phishing operation uses fileless techniques and low-detection loaders to deliver Agent Tesla, Remcos, XWorm, and Best Private Logger. The multi-payload approach increases resilience against endpoint defenses that may catch one family but not all. (src: Dark Reading)
- Gemini AI assistant sends SMS from locked Android phones without PIN: A bypass allows the Gemini assistant to initiate SMS messages from a locked smartphone without authentication, exposing a boundary issue between voice-activated AI and device lock-screen controls. (src: SecurityLab.ru)
Themes
AI tooling is now both target and weapon. Across today's findings, AI coding assistants are exploitable (sandbox escapes), AI infrastructure is the ransomware target (EncForge vs. model data), AI is the lure (fake MCP servers on GitHub), and AI assists offensive operations (phishing toolkit, Gemini botnet control). The attack surface expanded faster than the defensive tooling around it.
Legitimate cloud services as C2 infrastructure. HollowGraph's use of Microsoft Graph calendar events mirrors a broader trend of attackers abusing trusted SaaS APIs to hide command channels inside normal organizational traffic—graph/calendar/email API monitoring is becoming essential.
===
