This day 02:07 06:07 10:07 14:04 18:05 22:05
Info  2026-07-22 10:07Z · last 4h · 24 findings · glm-5.2:cloud

Threat Brief — 2026-07-22 — AI Agents Turn Against Their Owners

Executive summary: A flaw in Microsoft's Azure DevOps MCP lets attackers hijack AI code-review agents via invisible pull-request comments — the most significant new finding, as it weaponises the AI-assisted development pipeline itself. Kaspersky disclosed a passwordless Microsoft 365 takeover technique ("ConsentFix"), and the Awaken Likho APT resurfaced with a new AutoIt backdoor for targeted espionage. A trojanized Newtonsoft.Json NuGet package and a fresh NGINX SSI module vulnerability round out the actionable items.

Top items

Themes

AI agents as both attack vector and target. The Azure DevOps MCP hijack and Claude Cowork's new screen-recording training feature (id 4018) highlight a widening attack surface: AI agents now handle privileged dev workflows and ingest sensitive user behaviour data, but their input channels remain insufficiently guarded. This builds on the pattern seen in last week's sandbox-escape and invisible-text-injection findings.

Supply-chain attacks diversify in motive. The trojanized Newtonsoft.Json package — aimed at game rigging rather than data theft — demonstrates that package-registry abuse is branching beyond traditional info-stealer payloads, making motive prediction and detection harder for defenders.

===

Public exploits · latest from the exploit feed

ArcadeDB < 26.7.2 Cross-Database Authorization Bypass (IDOR) 2026-08-02 15:45Z · RSS:cxsecurity-wlb Linux Kernel 7.0-7.0.8 & 7.0-rc-7.0-rc7 - Use After Free Exploit 2026-08-02 15:45Z · RSS:cxsecurity-wlb MODX.3.2.1 TLS cookie without secure flag set - COOKIE PHPSESSID HIJACK 2026-08-02 15:45Z · RSS:cxsecurity-wlb Linux Kernel 7.0 DRM UAF LPE Exploit published for CVE-2026-46215 CVE-2026-46215 2026-07-22 14:05Z · CXSecurity / Exploit-DB (RSS) ZTE ZXHN H188A V6 Authentication Bypass 2026-07-22 13:28Z · RSS:cxsecurity-wlb OpenEMR 7.0.2 Arbitrary File Read 2026-07-22 13:28Z · RSS:cxsecurity-wlb PHP Link Directory (phpLD) 2.1.3 - SQL Injection, IDOR, CSRF 2026-07-22 13:28Z · RSS:cxsecurity-wlb KNX visualisering - Broken Access Control 2026-07-22 13:28Z · RSS:cxsecurity-wlb D-Link DSL2600U rom-0 Admin Password Disclosure 2026-07-22 13:28Z · RSS:cxsecurity-wlb Windows Defender (MsMpEng.exe) Race Condition -> LPE / SYSTEM / Use-After-Free -> Crash 2026-07-22 13:28Z · RSS:cxsecurity-wlb