Threat Brief — 2026-07-27 — Public Exploits and AI Leaks
Three plaintiffs are suing Apple after a fraudulent Sparrow Wallet app on the App Store drained $1.8M in Bitcoin, challenging assumptions about app-store curation as a security boundary. Meanwhile, a public exploit for a patched vBulletin pre-auth RCE is now in the wild, and ShinyHunters claims a supply-chain foothold at Ernst & Young. On the AI front, Anthropic's Claude chats were found leaking sensitive user data — including crypto wallets and trade secrets — directly into search engine indexes.
Top items
- Public exploit released for patched vBulletin pre-auth code execution. An unauthenticated attacker can reach PHP's
eval()via a crafted request to a vBulletin forum server, achieving remote code execution without credentials or admin access. The flaw is patched but unpatched forums are now trivially exploitable; a public exploit is already available. (src: The Hacker News)
- ShinyHunters claims Ernst & Young breach via supply-chain attack. The extortion gang says it obtained credentials for EY systems through a supply-chain compromise, enabling a data breach at the Big Four firm. This signals ShinyHunters' continued pivot toward supply-chain entry points and high-profile professional-services targets. (src: BleepingComputer)
- Coca-Cola confirms data theft in Fairlife ransomware attack. Hackers stole data from the dairy subsidiary during a ransomware intrusion earlier this month, now confirmed by the company. Confirms data exfiltration occurred; extortion leverage is likely in play. (src: BleepingComputer)
- Apple sued over fake App Store crypto wallet app that stole $1.8M in Bitcoin. Three users downloaded a fraudulent "Sparrow Wallet" from the official App Store and lost approximately $1.8M collectively. The lawsuit challenges Apple's app-review process as a security control and could set precedent for platform-liability in app-store malware cases. (src: BleepingComputer)
- Claude chats leaked secrets — crypto wallets, trade secrets, intimate conversations — into search engines. Anthropic's AI chat platform exposed user conversations to Google indexing, leaking sensitive data that should have remained private. This follows the DeepSeek executive-data-exfiltration story reported earlier today and extends the pattern to Anthropic. (src: SecurityLab)
- Shadow AI agents proliferating across enterprise platforms without IT visibility. Nudge Security reports that autonomous AI agents with broad permissions are spreading unchecked inside enterprises, often with no security oversight. Unmanaged permissions and autonomous actions create an expanding attack surface that is difficult to inventory or control. (src: BleepingComputer)
- CVE-2026-50333: Windows Spaceport.sys elevation of privilege — informational update only. Microsoft updated an acknowledgement for this vulnerability; no new technical details or exploit activity. Low immediate impact. (src: Microsoft Update Guide)
Themes
AI platforms are leaking their own users' secrets. Both DeepSeek (reported earlier today) and now Anthropic/Claude have exposed private conversations to search engine indexing, including crypto wallet details and trade secrets. The pattern suggests AI providers are shipping consumer-facing products without basic web-crawl isolation for sensitive chat content. Combined with the shadow-AI-agent governance gap, uncontrolled AI tooling is becoming a primary exfiltration vector across enterprises.
Trust boundaries under legal pressure. The Apple lawsuit over a fraudulent App Store wallet app directly challenges the assumption that curated app stores are a reliable security boundary. If the plaintiffs succeed, platform operators may face new liability for malware distributed through their stores — a shift that could force more aggressive vetting and faster takedowns.
===
