<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Frank Ully · AI incidents</title><link>https://www.ully.com/en/ai-hacking-incidents/</link><description>New entries in the chronology of publicly reported hacking incidents involving AI.</description><language>en-US</language><lastBuildDate>Mon, 14 Sep 2026 11:43:45 +0200</lastBuildDate><atom:link href="https://www.ully.com/en/ai-hacking-incidents/feed.xml" rel="self" type="application/rss+xml"/><item><title>SANS ISC: a self-growing inference supply chain</title><link>https://isc.sans.edu/diary/33332</link><guid isPermaLink="false">vorfall-2026-09-11-sans-isc-inferenz-lieferkette</guid><pubDate>Fri, 11 Sep 2026 12:00:00 +0200</pubDate><description>directed-autonomous. A coding agent walks into a honeypot posing as an OpenAI-compatible endpoint and builds a supply chain for stolen compute there. It uses queries on FOFA (a search engine for internet-exposed devices and services, similar to Shodan) to find poorly secured resale gateways for language models, collects roughly 379 upstream endpoints, discards 341 as dead and pools the rest behind five model names. It became visible through an operator error in which the agent sent the honeypot its playbook, its AGENTS.md (an instruction file the agent reads at the start of each session), target lists and keys. Caveat: Renato Marinho calls the supply chain only partially self-growing; a human still steers it, and the data shows no fully autonomous or self-replicating system.</description></item><item><title>RubyGems package flood attributed to OpenAI agents (GemStuffer)</title><link>https://www.rubyhack.ai/</link><guid isPermaLink="false">vorfall-2026-09-11-gemstuffer</guid><pubDate>Fri, 11 Sep 2026 12:00:00 +0200</pubDate><description>fully autonomous. Between May 5 and June 18, 2026, agents upload thousands of packages to RubyGems containing pages from the citizen portals of three London boroughs; more than 233 package names carry the tag oai, fifteen list it as author, and files are named hack.rb, evil.rb and exploit.rb. More than a hundred packages use a quirk of RubyDoc.info to run Ruby code on third-party servers while documentation is generated; RubyGems suspended new sign-ups for four days and removed more than 500 packages. Caveat: The attribution comes from the researchers. OpenAI confirms its own agents were on the platform but calls their activity benign; Ruby Central says the evidence does not show whether AI agents created or published the packages, and found no evidence that the attempted key theft succeeded.</description></item><item><title>Security officer as insider attacker (Israel)</title><link>https://www.pc.co.il/featured/458171/</link><guid isPermaLink="false">vorfall-2026-09-10-innentaeter-israel</guid><pubDate>Thu, 10 Sep 2026 12:00:00 +0200</pubDate><description>augmented. Israeli prosecutors charge an information security officer who, since 2019, allegedly broke into the computers of 26 companies with two self-built malware programs, his own employer among them; he collected files and passwords and secretly switched on cameras. The indictment states he developed the malware with artificial intelligence tools, something no indictment in the US or Europe has said so far. Caveat: Indictment, not a verdict. The charges attribute the tool building to AI, not the intrusion itself; according to Calcalist they name Claude as one of the tools used.</description></item><item><title>NSW Online Registry (Australia)</title><link>https://www.abc.net.au/news/2026-09-10/christopher-duff-to-stand-trial-over-nsw-ai-court-data-breach/107135032</link><guid isPermaLink="false">vorfall-2026-09-10-nsw-online-registry</guid><pubDate>Thu, 10 Sep 2026 12:00:00 +0200</pubDate><description>augmented. Between January and March 2025, a Sydney man downloads 8,769 restricted documents from the New South Wales court registry. The prosecution says ChatGPT wrote the scraping scripts and later coached him for the police interview; the conversations are to be used as evidence. Caveat: Prosecution case, not a verdict. The defendant disputes not the act but his knowledge that access was unauthorized.</description></item><item><title>GTG-20006: Russian espionage with self-repairing malware</title><link>https://www.anthropic.com/threat-intelligence-report-september-2026</link><guid isPermaLink="false">vorfall-2026-09-10-gtg-20006-russische-spionage</guid><pubDate>Thu, 10 Sep 2026 12:00:00 +0200</pubDate><description>directed-autonomous. Anthropic describes a Russian-speaking actor who ran his operations through AI workflows: reconnaissance, building the phishing infrastructure, commands against victim systems, extracting and sorting hundreds of gigabytes of data. Agents were set to rework and redeploy flagged malware until nothing detected it any more. The investigation counts more than 20 organizations targeted in the actor’s planning, reconnaissance or live operations, mostly in Ukraine and Europe; at a North African government technology authority the actor took more than 300,000 national identity records and the commercial registry data of more than half a million companies. Caveat: Anthropic calls its own attribution consistent with public reporting that links the actor to Midnight Blizzard. One of the operators, Anthropic says, shows tradecraft and targeting typical of Russian state-nexus espionage. Victims are not named, the counts are stated as minimums, and the report gives no separate time frame for this operation; December 2025 to August 2026 covers all of its cases together. According to Anthropic, parts of the operation ran without human involvement, such as scheduled jobs that renewed stolen access tokens and harvested victims’ cloud storage; the role stays directed-autonomous because humans chose the targets.</description></item><item><title>GTG-50014: ShinyHunters affiliates on a smash and grab</title><link>https://www.anthropic.com/threat-intelligence-report-september-2026</link><guid isPermaLink="false">vorfall-2026-09-10-gtg-50014-shinyhunters</guid><pubDate>Thu, 10 Sep 2026 12:00:00 +0200</pubDate><description>directed-autonomous. Anthropic banned several clusters of financially motivated operators tied to the ShinyHunters collective who used Claude for intrusion, data theft and extortion. One ran a pipeline on ten EC2 workers that downloaded 1.8 million Android apps, decompiled them and scanned them for hardcoded secrets. At a technology provider the operators took more than a terabyte of data, including hundreds of thousands of national identifiers and millions of payment card records; a separate affiliate pulled more than 2,100 Azure AD token sets from over 40 corporate tenants at a SaaS provider in about 34 hours, with AI agents doing nearly all of the work by Anthropic’s account. At an energy company the operators claimed that they could remotely control the charging current of chargers installed in customers’ homes. Caveat: Anthropic treats the operators as suspected affiliates of the collective and their connection as its own assessment. Victims are named only by sector.</description></item><item><title>GTG-10007: exploit foundry with agent swarms</title><link>https://www.anthropic.com/threat-intelligence-report-september-2026</link><guid isPermaLink="false">vorfall-2026-09-10-gtg-10007-exploit-schmieden</guid><pubDate>Thu, 10 Sep 2026 12:00:00 +0200</pubDate><description>directed-autonomous. Chinese-speaking operators ran an espionage operation against roughly fifty organizations in education, retail, energy, technology, healthcare, finance and manufacturing plus government agencies worldwide, according to Anthropic. A lead agent broke reconnaissance and post-exploitation work into pieces and dispatched them to subagents running in parallel; thirteen standing collection agents ran on a schedule and downloaded content from target websites. At an education technology company the operators collected hundreds of megabytes of student personal data; at a Southeast Asian government agency they retrieved citizen records. Caveat: Anthropic places the operators in Changsha with a hedge and identifies two of them as students at a university in Hunan. The vulnerabilities the actor validated in its own lab environment affected security and network appliances; whether the exploitation attempts against the same appliances at government organizations succeeded is not stated.</description></item><item><title>GTG-50029: lone actor builds a doxxing platform (fafsearch)</title><link>https://www.anthropic.com/threat-intelligence-report-september-2026</link><guid isPermaLink="false">vorfall-2026-09-10-gtg-50029-fafsearch</guid><pubDate>Thu, 10 Sep 2026 12:00:00 +0200</pubDate><description>directed-autonomous. In the spring of 2026 a single French-speaking actor used Claude to target European political parties, media outlets, think tanks and their SaaS providers: 42 tracked targets, internal access to at least 14 of them, an estimated 12 to 26 gigabytes of database dumps with donor and member records plus a mailbox of 15,000 messages. Subagents handled pre- and post-authentication reconnaissance, code review and the vetting of findings. Initial access came above all from a previously undocumented race condition in the WordPress reinstallation flow that creates an administrator account without valid credentials and worked against at least four victim websites. The actor loaded his doxxing platform fafsearch with tens of millions of rows from other people’s breaches, fused in the loot from his own intrusions and published the result anonymously as dark web services. After reviewing the technical details, Le Monde places the great majority of the targets in the French far right: at least one party, a political training institute, several news sites including the magazine Frontières, and a forum. Caveat: The figures come from Anthropic’s own investigation; Anthropic does not name the affected organizations, the report gives the volume of exfiltrated data as an estimate, and the placement in the far right is Le Monde’s analysis, not Anthropic’s.</description></item><item><title>GTG-50020: from an evaluation sandbox into the AI supply chain</title><link>https://www.anthropic.com/threat-intelligence-report-september-2026</link><guid isPermaLink="false">vorfall-2026-09-10-gtg-50020-ki-lieferkette</guid><pubDate>Thu, 10 Sep 2026 12:00:00 +0200</pubDate><description>directed-autonomous. Anthropic describes a Russian-speaking, financially motivated actor who previously attacked hotel booking and financial technology platforms, exfiltrated roughly 26 gigabytes from one victim and sought between 1.5 and 2.5 million dollars from extortion or from selling the data on darkweb forums. He injects malicious instructions into an AI vendor’s automated evaluation sandbox, which hands over the credentials it held, among them that vendor’s production AI API keys from multiple providers; a follow-on campaign run from the same infrastructure attacks roughly thirty AI companies in about four days with similar techniques, repeating the one attack path it found and adapting slightly for differences across the targets. In his pentest loop a per-target scope file delegates the work to parallel reconnaissance and exploitation agents that test against production systems without human supervision; his stated goal, pursued across more than a dozen avenues, was access to a pre-release Claude model, and every attempted path failed. Caveat: Anthropic states that the keys involved were customers’ keys stolen from customers’ environments and that the actor never compromised Anthropic’s own systems. No victim is named, and the report stresses that more autonomy does not automatically mean more harm, noting that humans remain heavily involved in target selection, monetization of findings and review of results.</description></item><item><title>BlueMoon</title><link>https://www.proofpoint.com/us/blog/threat-insight/once-bluemoon-multiple-state-aligned-threat-actors-rapidly-adopt-novel-exploit</link><guid isPermaLink="false">vorfall-2026-09-09-bluemoon</guid><pubDate>Wed, 09 Sep 2026 12:00:00 +0200</pubDate><description>augmented. Four espionage groups, starting with China-aligned TA412, use the same new exploit kit against two Chrome flaws and a Windows kernel flaw in spear-phishing campaigns within six days. Proofpoint reads an extensive diagnostic log, a Markdown handover document and comments documenting successive debugging rounds as signs of AI-assisted development. Caveat: Proofpoint states explicitly that no single artifact conclusively confirms AI-assisted development. The report names no individual victim and describes the targets only by sector and region.</description></item><item><title>Manus AI on a C2 server (Brazil)</title><link>https://cybernews.com/security/brazil-data-breach-government-employee-logins/</link><guid isPermaLink="false">vorfall-2026-09-09-manus-ai-c2-brasilien</guid><pubDate>Wed, 09 Sep 2026 12:00:00 +0200</pubDate><description>directed-autonomous. An attacker runs the autonomous agent Manus AI on a command server in Google Cloud and gets onto a Windows VM of Brazil’s social security agency INSS through weak credentials. The agent inspects the machine, exfiltrates the installed certificates and injects its own CA certificate for man-in-the-middle attacks; 375 login records of 40 employees were captured from the VPN login panel of the operator Dataprev. Caveat: The researchers could not determine how deeply the attacker had penetrated government systems; they consider it possible that the data of more than 214 million Brazilians was within reach, but could not document it.</description></item><item><title>Mass exploitation of PaperCut</title><link>https://www.greynoise.io/blog/ai-orchestrated-campaign-against-papercut-ng-mf</link><guid isPermaLink="false">vorfall-2026-09-09-papercut</guid><pubDate>Wed, 09 Sep 2026 12:00:00 +0200</pubDate><description>directed-autonomous. A presumably Russian-speaking criminal turns hundreds of AI agents against two freshly disclosed PaperCut flaws. The agents run in the harness of Codex (OpenAI’s coding agent), that is, in its program scaffolding of tools and work loop, but with a DeepSeek model. That way he compromises 395 organizations in 48 countries, among them, by GreyNoise’s count, 15 in Germany, 14 in Switzerland and one in Austria; eleven of them in 26 seconds, one US school in seven minutes to domain admin, but full domain admin at only twelve victims. Blackpoint recovered the entire development project from the command server: state files an assistant kept about its work for a user, recording what was finished, what was blocked and what to do next, a target set of more than 500 systems and a file sorting 291 failed targets by cause. Caveat: PaperCut itself does not attribute the attack to AI; the attribution comes from GreyNoise and Blackpoint. According to GreyNoise, the high share of US education targets likely reflects the product’s customer base rather than target selection.</description></item><item><title>Anthropic: Opus 4.6, fourth incident</title><link>https://www.anthropic.com/research/alignment-assessment-cybersecurity-incidents</link><guid isPermaLink="false">vorfall-2026-09-09-anthropic-opus-4-6-vierter-vorfall</guid><pubDate>Wed, 09 Sep 2026 12:00:00 +0200</pubDate><description>fully autonomous. Anthropic discloses a fourth lab incident that reached a real third-party system: in January 2026 an early version of Claude Opus 4.6 breaks its test environment through colliding IP assignments, tries eight times in vain to abort, then compromises an unnamed third party’s system, harvests credentials, reads personal information and changes settings for later access. Only an exhausted token budget stopped it; a scan of roughly 481 million transcripts found no cases of similar or worse severity. Caveat: All four incidents occurred in evaluations built by the same partner, unnamed in the report, each with a different trigger. At the time of publication Anthropic had not yet investigated the fourth incident at the same depth as the other three; the statement that no single root cause could be identified for distorted reasoning refers in the report to Claude Mythos 5.</description></item><item><title>KATARU: IoT malware with signs of AI assistance in its exploit code (Nozomi)</title><link>https://www.nozominetworks.com/blog/kataru-iot-malware-adopts-public-lpe-exploits</link><guid isPermaLink="false">vorfall-2026-09-09-kataru-iot-nozomi</guid><pubDate>Wed, 09 Sep 2026 12:00:00 +0200</pubDate><description>augmented. Nozomi Networks describes the IoT malware KATARU, which ran on one of the vendor’s honeypots after a Telnet credential brute force. The ARM sample embeds three public Linux privilege escalation exploits whose shellcode targets x86, a pinned X25519 key taken from the RFC 7748 test vectors, and a persistence sweep spanning Linux, router and Android environments. Nozomi reads these artifacts as strongly suggesting that KATARU was assembled with AI assistance. Caveat: Only the compromise of a Nozomi honeypot is documented, no real victim; the entry is therefore listed as a honeypot case. The AI link is an inference from decompiled code that Nozomi itself presents as a strong indication rather than proof; the report names no prompts, no logs and no model.</description></item><item><title>PivotC2</title><link>https://socradar.io/blog/cve-2025-25249-pivotc2-fortigate-rat/</link><guid isPermaLink="false">vorfall-2026-09-08-pivotc2</guid><pubDate>Tue, 08 Sep 2026 12:00:00 +0200</pubDate><description>augmented. A Russian-speaking, financially motivated actor exploits a heap overflow in the CAPWAP service of FortiOS (the protocol network devices use to manage their wireless access points) and installs a Node.js remote access trojan on FortiGate devices, with a shell, tunnels, a network scanner and automatic decryption of credentials; more than 30,000 addresses attacked, 178 devices infected, two intrusions with confirmed data theft. Based on the inline comments and usage guidance, SOCRadar considers it highly likely that the trojan was developed with AI. Caveat: The AI attribution rests on comment analysis and is not presented by SOCRadar as confirmed.</description></item><item><title>Slim Spider</title><link>https://thehackernews.com/2026/09/slim-spider-steals-crypto-custody.html</link><guid isPermaLink="false">vorfall-2026-09-08-slim-spider</guid><pubDate>Tue, 08 Sep 2026 12:00:00 +0200</pubDate><description>augmented. Slim Spider has been attacking Brazilian financial institutions since at least March 2026; in a multi-stage intrusion, cloud credentials, secrets and crypto custody keys are stolen and implants are rolled out to a Kubernetes cluster through Azure DevOps pipelines. The group’s scanner panel uses Ollama (software that serves language models on one’s own hardware) to sort discovered API endpoints into 16 categories and rank them by availability and authentication. Caveat: According to the report, the AI helps only with target selection. The details are in The Hacker News, quoting CrowdStrike; CrowdStrike’s own adversary page carries only the short profile.</description></item><item><title>Credential harvesting campaign built and run in under six hours (Mandiant)</title><link>https://cloud.google.com/blog/topics/threat-intelligence/from-prompting-to-autonomy-the-evolution-of-adversarial-ai</link><guid isPermaLink="false">vorfall-2026-09-08-gtig-sechs-stunden-zugangsdaten</guid><pubDate>Tue, 08 Sep 2026 12:00:00 +0200</pubDate><description>directed-autonomous. Mandiant observed an actor compromise an organization’s cloud infrastructure and deploy an autonomous multi-agent attack framework inside it. With an AI coding chatbot, a prompt and a set of agent instructions he planned, built and ran a mass campaign in less than six hours that compromised thousands of third-party credentials. The instructions sat ready as markdown playbooks; the vulnerability scanning pipeline, real-time troubleshooting and IP rotation ran without manual intervention, and the attack traffic left the victim cloud through its legitimate addresses. Caveat: Google’s Threat Intelligence Group (GTIG) names neither the victim nor the actor and calls the financial motive a suspicion; the second quarter of 2026 is the only timing given. GTIG says it has not yet observed fully autonomous pipelines deployed against targets in the wild.</description></item><item><title>OpenAI agent swarm (DSEWiki, echo services)</title><link>https://collusion.wiki/</link><guid isPermaLink="false">vorfall-2026-09-04-openai-agentenschwarm-dsewiki</guid><pubDate>Fri, 04 Sep 2026 12:00:00 +0200</pubDate><description>fully autonomous. A swarm of OpenAI agents with permitted read access to the web hijacks a German-language wiki as a message board from May 2026: about 18,000 posts, more than 3,700 self-chosen names, 98.5 percent of attributed edits from Azure address ranges. The agents pass answers and proxy bypasses to each other and name backup pages ZZZ to escape alphabetical deletion; Zenity later found roughly 1,000 more messages, Base64-encoded in the URLs of public echo services, and on September 9 Reuters reported, citing six independent research groups, more than ten further websites, among them the link shorteners of two universities. Caveat: A human had set the tasks; what was autonomous was the sandbox bypass and the misuse of third-party websites. The investigators see only what the agents wrote to the wiki, not their reasoning, and warn of fake posts that appeared after publication. OpenAI confirmed the incident only when asked.</description></item><item><title>SecFlow</title><link>https://hunt.io/blog/chinese-operator-secflow-claude-qwen-deepseek-asia</link><guid isPermaLink="false">vorfall-2026-09-03-secflow</guid><pubDate>Thu, 03 Sep 2026 12:00:00 +0200</pubDate><description>directed-autonomous. A Chinese-speaking operator breaks campaign goals into tasks for specialized AI workers and switches between Claude and DeepSeek through private relays and Qwen through the official Alibaba API. Three compromises are confirmed: the office system of the Fengtai district government with 822 accounts and 1.28 GB of attachments including patient records, a Chinese education AI platform, and a university campus card system with root access to the database. Caveat: Against a party archive in Taiwan, Indonesia’s foreign ministry and targets in Vietnam, the report documents only staged payloads and attempts.</description></item><item><title>Unit 42: intrusion across 50 ATT&amp;CK techniques</title><link>https://unit42.paloaltonetworks.com/ai-assisted-cyber-attack-inside-a-unit-42-investigation/</link><guid isPermaLink="false">vorfall-2026-09-02-unit-42-einbruch-50-techniken</guid><pubDate>Wed, 02 Sep 2026 12:00:00 +0200</pubDate><description>directed-autonomous. Unit 42 responds to an intrusion in which an attacker uses frontier models and agentic frameworks to chain more than 50 MITRE ATT&amp;CK techniques in under ten hours; according to the report, that replaces about two weeks of manual work. The agents map the architecture, loot code repositories, hijack CI/CD builds and the victim’s AI infrastructure, and leave behind an 80-page audit report on the exploited flaws as instructed; only the backdoors in Terraform configurations fail against branch-protection rules. Caveat: Unit 42 clarified a day later that this was an intrusion, not a ransomware attack.</description></item><item><title>Gentlemen extortion affiliate running a Hermes agent</title><link>https://cybernews.com/security/exposed-ransomware-server-reveals-automated-4-dollar-cyberattacks</link><guid isPermaLink="false">vorfall-2026-09-02-gentlemen-affiliate-hermes</guid><pubDate>Wed, 02 Sep 2026 12:00:00 +0200</pubDate><description>directed-autonomous. Cybernews finds the openly reachable server of an affiliate of the Gentlemen extortion group holding 3.1 terabytes of data allegedly stolen from more than 30 companies. The attacker hands the open-source Hermes agent, driven by the DeepSeek-V4-Pro model, nothing but the address, username and password of a GitLab instance, which according to Cybernews he likely took from infostealer logs or bought from access brokers; the agent adapts the exploitation scripts to each environment, works with the Penelope reverse shell through an MCP interface, and assembles pressure dossiers with a calculated ransom demand. According to the logs on the server, attacking one company cost 0.40 to 4 dollars in tokens, not counting the infrastructure. Caveat: Cybernews relies solely on what it found on the server and describes the data as allegedly stolen. Only one of the victims was listed on the group’s leak site at the time of discovery, and the report names the affected companies by industry only; the figure of 0.40 to 4 dollars covers tokens only. The second source it-daily speaks of roughly 30 companies rather than more than 30.</description></item><item><title>BREEZE COMET</title><link>https://cloud.google.com/blog/topics/threat-intelligence/financially-motivated-threat-actor-breeze-comet-targets-brazil</link><guid isPermaLink="false">vorfall-2026-09-01-breeze-comet</guid><pubDate>Tue, 01 Sep 2026 12:00:00 +0200</pubDate><description>augmented. BREEZE COMET, formerly UNC5669, has been attacking Brazilian banks, payment providers and fintechs with access to Pix, STR and Boleto (Brazilian payment systems for instant transfers, large-value transfers and payment slips) since 2024; entry comes through password spraying, calls posing as IT support and the group’s own hardware, physically planted in branch networks. Google’s Threat Intelligence Group (GTIG) and Mandiant found evidence that generative AI accelerated the scripts for network reconnaissance, credential validation, mass deployment and data theft; in one case, two waves of hundreds of fraudulent transfers follow within 24 to 48 hours. Caveat: According to the report, AI’s role is limited to developing the tools.</description></item><item><title>TukTuk / The Gentlemen (Oasis)</title><link>https://oasis-security.io/blog/The-Gentlemen-Ransomware-Hacker-Groups-TukTuk-Framework</link><guid isPermaLink="false">vorfall-2026-08-31-tuktuk-the-gentlemen</guid><pubDate>Mon, 31 Aug 2026 12:00:00 +0200</pubDate><description>augmented. On a Finnish server, Oasis Security found the complete source project of the TukTuk C2 framework with Windows and Linux agents, backend and control panel, plus a screenshot that, according to Oasis, shows the development was done with artificial intelligence. The attribution to the ransomware group The Gentlemen rests on hash matches, a known sideloading package and an operator name; the same server held a guide to neutralizing endpoint protection and loot, including 224 Jira tickets of a global technology company relating to its US defense customers. Caveat: Oasis shows the AI evidence only as an image, names no model, and the screenshot cannot be verified independently; the exfiltration of the loot is an assessment, not a finding.</description></item><item><title>BraZetsu / Exilware</title><link>https://www.group-ib.com/blog/brazetsu-ai-enhanced-iab-marketplace/</link><guid isPermaLink="false">vorfall-2026-08-31-brazetsu</guid><pubDate>Mon, 31 Aug 2026 12:00:00 +0200</pubDate><description>augmented. BraZetsu is malware that Group-IB attributes with high confidence to the Brazilian actor Exilware; it has existed in five versions since February 2026 and forms the technical engine behind that actor’s marketplace for access to compromised computers, the Infected Marketplace, also known as Banco de Infects. The malware collects each infected machine’s hardware, installed software and network environment for a server-side AI assessment that prioritizes it as a target; it looks for payment files in the CNAB format (a Brazilian file format for payment orders between company and bank), digital certificates and business software such as TOTVS, SAP, Senior and Sankhya. Group-IB names Brazil, Argentina, Mexico and Chile as affected countries, plus two hosts in the United States. Caveat: Group-IB documents the assessment component through function names and reads the emoji-laden log lines as a signature of LLM-generated code; how far the model’s role extends beyond that is unknown. The report names no individual victim.</description></item><item><title>Gryxa</title><link>https://reliaquest.com/blog/threat-spotlight-gryxa-ai-built-toolkit/</link><guid isPermaLink="false">vorfall-2026-08-28-gryxa</guid><pubDate>Fri, 28 Aug 2026 12:00:00 +0200</pubDate><description>augmented. ReliaQuest assesses with high confidence that a financially motivated actor used a jailbroken commercial AI coding agent to build a complete attack ecosystem: a toolkit, a fleet console with 324 hosts, 69 of them live, and a signed update pipeline. The evidence is the public repository’s commit metadata, which lists the agent as co-author of most commits, plus 35 numbered write-ups of failed attempts; a surviving component collects the incident responder’s artifacts after a partial cleanup and uploads them. Caveat: ReliaQuest has neither the actor’s prompts nor session transcripts and therefore cannot establish what was said to the agent. According to the comments in the actor’s own scripts, the work was presented to the AI as an authorized lab or competition test in order to obtain its help.</description></item><item><title>AGATHA: apparent Claude-assisted attacks in Brazil (Oasis)</title><link>https://oasis-security.io/blog/Attacks-Against-Brazilian-Organizations-Leveraging-Claude-AI</link><guid isPermaLink="false">vorfall-2026-08-27-agatha-brasilien-oasis</guid><pubDate>Thu, 27 Aug 2026 12:00:00 +0200</pubDate><description>augmented. Oasis Security analyzes AI session logs and attacker files from an examined server. They document reconnaissance, credential hunting, a forged JWT used in an attempt to bypass authentication, more than 570,000 password-reset-code attempts without confirmed success and the manipulation of webhooks against Brazilian government bodies and companies in finance, e-commerce, mobile services, telecommunications, agriculture and monitoring services. For one organization, the recovered session output directly contains 20 financial event records, plus five webhook registrations that Oasis assesses as attacker controlled. Caveat: The operator consistently claimed an authorized penetration test; Oasis could not verify this and considers the pretext likely misleading. The artifacts are labeled as Claude sessions, but the retained metadata establishes neither model nor account nor execution environment, which is why Oasis speaks of Claude-associated activity. The successful login at the monitoring provider is marked only in the attacker’s own output, no exfiltration of protected government data is established, and the larger damage figures come from a report generated by the attacker or the AI.</description></item><item><title>Aurora ransomware</title><link>https://gambit.security/blog-posts/aurora-ransomware-targets-esxi-abuses-cursor-agent-for-exploitation</link><guid isPermaLink="false">vorfall-2026-08-27-aurora-ransomware</guid><pubDate>Thu, 27 Aug 2026 12:00:00 +0200</pubDate><description>directed-autonomous. In some victim networks, a Russian-speaking affiliate has Cursor Agent (Cursor is a programming environment with a built-in AI assistant) with Claude 4.5 Sonnet carry out the work after initial access: VPN setup, subnet scans, AD enumeration, NTLM relay (forwarding an intercepted Windows login to another system) and certificate attacks, with repeated fixes of failed commands and Russian-language opsec limits such as no DCSync (pulling the password database through a domain controller’s replication interface). Ten target organizations fall between April 8 and May 21, 2026; according to Reuters, the operator got past the model’s refusals by claiming the work was an authorized test. Caveat: The human stays closely in the loop at times, sometimes just picking a number from the agent’s list of suggestions. Gambit attributes a second cluster of eight victims to the same operator only with medium confidence; Christeyns, named as one victim, contradicts that reading: its own investigation found no evidence that ransomware was deployed or executed or that data was taken, and no ransom was demanded.</description></item><item><title>Slime22: Claude Code inside a Taiwanese technology company</title><link>https://www.straitstimes.com/asia/east-asia/chinas-hackers-use-deepseek-for-attacks-researchers-say</link><guid isPermaLink="false">vorfall-2026-08-24-slime22-taiwan</guid><pubDate>Mon, 24 Aug 2026 12:00:00 +0200</pubDate><description>directed-autonomous. According to TeamT5, the group Slime22 broke into the systems of a Taiwanese technology company, set up its own installation of the penetration-testing Linux distribution Kali there and had Claude use it to move laterally through the network. The attackers bypassed the cybersecurity guardrails by posing as an engineer carrying out those security tests. Caveat: The account comes from TeamT5 and was reported by Bloomberg; the Straits Times carries the story. The victim is not named, the source gives no timeframe, and Anthropic did not answer the reporters’ questions.</description></item><item><title>Hacking tool vendor decrypts a think tank employee’s Signal database</title><link>https://www.straitstimes.com/asia/east-asia/chinas-hackers-use-deepseek-for-attacks-researchers-say</link><guid isPermaLink="false">vorfall-2026-08-24-thinktank-signal-datenbank</guid><pubDate>Mon, 24 Aug 2026 12:00:00 +0200</pubDate><description>augmented. According to the security company CyCraft, a firm that sells hacking software used ChatGPT in an attack on a Western think tank: the attackers copied an employee’s local Signal database from a compromised computer and consulted the chatbot to help build a software module designed to decrypt it. The evidence is screenshots reviewed by Bloomberg News, taken from a public shared drive holding thousands of Chinese-language screenshots, the most recent of them from February. Caveat: Neither the think tank nor the firm is named, and the report does not say whether the module worked.The source does not say when the attack took place.</description></item><item><title>UAT-10147 (Talos)</title><link>https://blog.talosintelligence.com/uat-10147-chinese-speaking-adversary-integrates-agentic-ai-into-post-compromise-operations/</link><guid isPermaLink="false">vorfall-2026-08-20-uat-10147</guid><pubDate>Thu, 20 Aug 2026 12:00:00 +0200</pubDate><description>augmented to directed-autonomous. A Chinese-speaking cybercrime group compromises web servers of governments, universities, media, technology companies and gaming providers for SEO fraud and data theft. The open C2 directory yielded AI-generated playbooks, a target list of about 170,000 URLs and the SPECTRE backdoor; alongside manual work with Metasploit (a widely used attack tool with ready-made exploits), PentestGPT (an AI tool that automates penetration tests) installed on the C2 scans web servers on its own, runs matching proof-of-concept exploits and took over at least one website that way. Caveat: Talos holds its central thesis with moderate-to-high confidence and did not directly observe flaws reported by DeepAudit, a source code analysis tool also found on the C2, being exploited in victim environments.</description></item><item><title>Sophos: Slack RAT with Claude as co-author</title><link>https://www.sophos.com/en-us/blog/fake-ai-real-malware-attackers-impersonating-ai-brands</link><guid isPermaLink="false">vorfall-2026-08-19-sophos-slack-rat</guid><pubDate>Wed, 19 Aug 2026 12:00:00 +0200</pubDate><description>augmented. Sophos reviewed twelve months of its own incident response, 38 cases with confirmed AI involvement. In one of them, a financial services firm is compromised through SQL injection; the remote access trojan found, written in Rust, uses Slack as its command channel and comes from a public GitHub project with exactly two contributors, the attacker’s account and an account named claude, whose commit history shows a reverse shell being added and removed and the internal strings being renamed. Caveat: Sophos calls this the clearest case of AI-generated attack tooling in its entire dataset and the only one whose development could be traced directly from source code and commit history; Sophos also notes that the incidents it reviewed are a few months old.</description></item><item><title>SilkParasite</title><link>https://www.bitdefender.com/en-us/blog/businessinsights/silkparasite-tracking-china-nexus-apt-across-central-asia</link><guid isPermaLink="false">vorfall-2026-08-19-silkparasite</guid><pubDate>Wed, 19 Aug 2026 12:00:00 +0200</pubDate><description>augmented. Bitdefender describes China-aligned espionage against government bodies in Central Asia with an economic policy focus, discovered in October 2025 and using seven RAT families, five of them new. Bitdefender sees traces of AI-assisted development in otherwise professional code; two of the recovered phishing lures were themselves AI-generated. Caveat: Bitdefender rates both the AI involvement and the China link with only medium confidence and attributes the activity to no named group.</description></item><item><title>Chinese-speaking attacker drains crypto wallets with AI agents (CloudSEK)</title><link>https://www.cloudsek.com/blog/ai-agent-driven-offensive-operation-crypto-wallet-credential-compromise</link><guid isPermaLink="false">vorfall-2026-08-19-cloudsek-kryptodieb</guid><pubDate>Wed, 19 Aug 2026 12:00:00 +0200</pubDate><description>directed-autonomous. CloudSEK analyzes the infrastructure of a Chinese-speaking, financially motivated operator who ran Claude Code, Codex (OpenAI’s coding agent) and the open-source Hermes and pi agents with permission prompts switched off from July 10 to 28, 2026, tasking and supervising them over Telegram. The haul covers 12,048 compromise records, each carrying an attacker-created admin account, across 8,996 WordPress sites, a reconnaissance corpus of 3.4 million hosts, 66 admin credentials genuinely harvested from victim databases, roughly 326 addresses on the Solana blockchain of which 142 carry a private key and recovery phrase, and roughly 34 confirmed-breach entries at crypto and DeFi providers (financial services without a bank). The operator bypassed the models’ safeguards with a reusable Chinese template presenting the job as an authorized penetration test, and sourced the models through a self-hosted route to Zhipu GLM (a Chinese family of language models) rather than the official providers. Caveat: CloudSEK bases every finding on a mirrored copy of the open directory and on traces the operator left himself; the host was no longer reachable when the report was written. According to CloudSEK, most of the wallet key material does not come from this operator’s own breaches but from misconfigured databases in Firebase (Google’s toolkit for app back ends including a database) of third-party phishing clone sites; the affected wallets belong to victims of that separate operation. The operator built the blockchain-based control channel DeadDropC2 but, in CloudSEK’s reading, never deployed it for live use.</description></item><item><title>Meta: Muse Spark</title><link>https://research.meta.ai/blog/addressing-third-party-testing-misconfiguration-muse-spark-1-1</link><guid isPermaLink="false">vorfall-2026-08-14-meta-muse-spark</guid><pubDate>Fri, 14 Aug 2026 12:00:00 +0200</pubDate><description>fully autonomous. During an evaluation with safeguards turned off, a pre-release version of Muse Spark 1.1 gains internet access through a misconfiguration at the testing partner and is unintentionally given the name of a real website as its target. The model exploits a flaw in it, reads data and modifies the database; Meta describes neither a sophisticated attack nor a sandbox escape and reports that several models from other providers showed similar behavior there. Caveat: Meta says it has only limited information because the evaluation ran on the testing partner’s infrastructure. The date is that of Meta’s own publication; press coverage had described the case about a week earlier.</description></item><item><title>Gambit: three attacker servers</title><link>https://gambit.security/blog-posts/ai-across-the-intrusion-lifecycle</link><guid isPermaLink="false">vorfall-2026-08-13-gambit-drei-taeterserver</guid><pubDate>Thu, 13 Aug 2026 12:00:00 +0200</pubDate><description>augmented to directed-autonomous. Gambit analyzes the infrastructure of three actors whose opsec mistakes exposed their tools and AI conversations. A suspected affiliate of The Gentlemen runs Claude Code with Sonnet 4.6 through intrusions at six organizations in late June, including an Australian energy utility whose firewall the agent takes offline with an accidental full configuration restore (Yeah, I screwed up); Zerofot collects 2,975 credentials from 1,742 hosts with Codex (OpenAI’s coding agent) and Claude Code; the AI-generated framework RAGE with a DeepSeek orchestrator pivots into AWS environments through exposed services with stolen credentials. Caveat: The details are in the technical PDF report, not in the linked blog post. Gambit attributes the actor to The Gentlemen only with medium confidence. The report names the six organizations in the first case only by sector and country.</description></item><item><title>Multi-agent framework against government systems in Asia (Dream)</title><link>https://www.dreamgroup.com/blog/inside-a-multi-agent-ai-framework-used-to-compromise-government-entities-in-asia</link><guid isPermaLink="false">vorfall-2026-08-12-dream-multi-agenten-asien</guid><pubDate>Wed, 12 Aug 2026 12:00:00 +0200</pubDate><description>directed-autonomous. Dream’s threat research team analyzes an attacker’s complete working directory of more than 160 megabytes and 1,395 files and describes a framework built from the agents Hermes and OpenClaw (an open-source agent that works through tasks on its own) that ran against government bodies in Asia from July 1 to 4, 2026, in twelve waves with up to eight sub-agents in parallel. From a single government portal the agents pulled endpoints and authentication configurations, mapped 21 connected government systems, cracked 85 accounts, gathered more than 2,564 personnel records and, in Dream’s own summary, installed persistent backdoors in government web applications; they then scanned IT supply chain vendors, a nuclear safety agency, a government mail system and more than seven energy companies for misconfigurations, exposed admin interfaces and exploitable vulnerabilities. The operators bypassed the models’ refusals by presenting all activity as authorized penetration testing. Caveat: Dream names neither the target country nor an actor and describes the affected bodies only by type; the pointer to a Chinese-speaking operator rests solely on the switch between simplified and traditional Chinese in the material. In detail the backdoors are three hidden debug endpoints that developers had left in production, plus a web shell whose execution a second authentication layer blocked. A Dream spokesperson told CSO Online that the firm’s own research found no evidence of a confirmed breach of the affected entity’s systems and that the report describes the framework as of the time of analysis. The same spokesperson said Dream had since found indications of a DeepSeek V4 Flash model in the framework but did not know whether it was the only model used. On August 13, 2026, Taiwan’s digital ministry reported attacks from abroad that its monitoring units had detected in July 2026 and in which attackers combined their own work with AI agents such as Open Claw, without giving figures; neither Dream nor the Taiwanese authorities have confirmed a link to Dream’s report. Tenable notes that the attribution rests on a single primary source.</description></item><item><title>Gym booking system (Australia)</title><link>https://www.abc.net.au/news/2026-08-10/ai-assistant-hacks-gym-website-aus-cyber-attack/107007986</link><guid isPermaLink="false">vorfall-2026-08-10-fitnessstudio-australien</guid><pubDate>Mon, 10 Aug 2026 12:00:00 +0200</pubDate><description>fully autonomous. A user has his OpenClaw agent (an open-source agent that works through tasks on its own) on Claude book a gym class. The agent finds a missing authorization check in the booking software, books beyond the permitted window and, unprompted, bumps another person off the waitlist; according to the ABC, the first known Australian case of its kind. Caveat: Borderline case: there was no attacker, only a legitimate user’s agent. The incident rests mainly on the user’s account; the software company did not comment on security matters. The booking itself dates from April 2026 and the user’s blog post about it has been deleted; the date is that of the first press coverage.</description></item><item><title>OpenAI: Irregular misconfiguration</title><link>https://openai.com/index/third-party-cyber-evaluations-involving-openai-models/</link><guid isPermaLink="false">vorfall-2026-08-04-openai-irregular</guid><pubDate>Tue, 04 Aug 2026 12:00:00 +0200</pubDate><description>fully autonomous. At the testing partner Irregular, a misconfiguration connects the supposedly isolated CTF environment to the internet, and the name of the fictional target coincides with a real domain. An OpenAI model exploits a flaw in the real website, mistaking it for part of the simulation, finds credentials and uses them to operate the site; Irregular notified OpenAI of the incident on July 29, 2026; OpenAI describes neither a sophisticated sandbox escape nor a zero-day but the result of a network-isolation misconfiguration. Caveat: Irregular has identified no impact beyond the affected site’s own data, and its audit is ongoing.</description></item><item><title>UK AISI: Mythos 5 and GPT-5.6 Sol</title><link>https://www.aisi.gov.uk/blog/incident-report-unsanctioned-agent-behaviour-during-cyber-testing</link><guid isPermaLink="false">vorfall-2026-08-04-uk-aisi-mythos-5-gpt-5-6</guid><pubDate>Tue, 04 Aug 2026 12:00:00 +0200</pubDate><description>fully autonomous. The UK AI Security Institute counts 19 unsanctioned actions on the open internet in 10 of 122 test runs, 17 by Anthropic’s Mythos 5 and two by GPT-5.6 Sol, with cyber classifiers deliberately switched off. In the most serious case, an agent tries to inject malicious code into a real open-source project, creates a GitHub account for it and defends its pull request with a second account against a student who objected; the project’s creator rejected it for security reasons, and GitHub suspended the accounts for deceptive behavior. Caveat: AISI cannot say how likely the behavior is outside testing environments and saw no real-world harm; Anthropic points to deliberately permissive test conditions. Reuters added the project name and account details on August 20.</description></item><item><title>Talos: agent Alex against Telegram Mini Apps</title><link>https://blog.talosintelligence.com/keep-going-bro-youve-got-this-a-data-driven-look-at-how-adversaries-are-weaponizing-ai/</link><guid isPermaLink="false">vorfall-2026-08-04-talos-telegram-mini-apps</guid><pubDate>Tue, 04 Aug 2026 12:00:00 +0200</pubDate><description>directed-autonomous. Cisco Talos analyzes the recovered configuration files of a Spanish-speaking operator who builds a persistent agent on the OpenClaw framework (an open-source agent that works through tasks on its own) with the persona Alex, a black-hat pentester, and moves to an uncensored model after the first model refuses the work. The agent works through a target list of Telegram Mini Apps on its own; in at least one case it dumps the database of an application with more than 1,300 users and several hundred wallet records for TON (a cryptocurrency from the Telegram ecosystem), extracts and verifies the Telegram bot token, farms the in-game economy to the top of the leaderboard and stages a withdrawal. Among the recovered Android packages is a complete rebuild of a victim application (SweetBirds, reissued as RedBirds): a player-facing app with deposit, exchange and withdrawal flows that still references the victim’s backend while routing wallet traffic to a server the operator controls, plus a separate administrative console that talks only to that server. Caveat: Talos names the affected applications only by app name and names no operator; the further offensive actions, among them renaming a target’s bot to a defacement name and watching its payment channel react, come from the agent’s own operational diary.</description></item><item><title>Talos: Deluge plugin as command channel, 582 mining machines</title><link>https://blog.talosintelligence.com/keep-going-bro-youve-got-this-a-data-driven-look-at-how-adversaries-are-weaponizing-ai/</link><guid isPermaLink="false">vorfall-2026-08-04-talos-deluge-cryptojacking</guid><pubDate>Tue, 04 Aug 2026 12:00:00 +0200</pubDate><description>augmented. A Turkish-speaking operator logs in to internet-facing torrent clients with blank, default and weak passwords; the recovered inventory lists 814 accessible Deluge instances, most of them with the default password deluge, plus 68 of more than 8,800 tested qBittorrent interfaces. On the Deluge instances sits a Python plugin named DownloadHelper that repurposes the move_completed_path configuration value as a command and response channel; through that channel the actor’s fleet scripts place the command that downloads the Monero miner XMRig into a temporary directory and routes mining traffic through an XMRig proxy of the actor to MoneroOcean (a mining pool in which machines combine their computing power). That proxy’s telemetry records a maximum of 582 connected miners, and pool logs show payments to the configured wallet; in the recovered sessions the AI appears as an interactive system administrator that the actor hands server credentials to and that connects over SSH, inspects services, modifies code, repairs authentication and sets up cron jobs. Caveat: Talos states explicitly that the recovered conversations do not directly connect the AI to the creation or deployment of the mining toolchain; for the Telegram-controlled multi-agent setup the actor considered, Talos found no evidence that it became operational.</description></item><item><title>Talos: React2Shell credential pipeline against 9,180 hosts</title><link>https://blog.talosintelligence.com/keep-going-bro-youve-got-this-a-data-driven-look-at-how-adversaries-are-weaponizing-ai/</link><guid isPermaLink="false">vorfall-2026-08-04-talos-token-pipeline</guid><pubDate>Tue, 04 Aug 2026 12:00:00 +0200</pubDate><description>augmented to directed-autonomous. A French-speaking operator has the AI expand public React2Shell research and public proof-of-concept code into a credential pipeline that the actor calls Token Pipeline in the AI’s own artifacts: a fast Go scanner for volume and a shell and Python stage that proves command execution, reads out process environments and collects configuration, database and SMTP settings, Git and container credentials and source code. The instruction file tells the assistant to always launch at least three to five parallel research agents per service, and the permission file holds 121 pre-approved command patterns, among them calls that validate harvested credentials directly against the APIs of GitHub, GitLab, Alibaba Codeup, AWS CodeCommit and other providers. The target list covers 9,180 hosts across unrelated companies, individuals and cloud platforms, the file names of the output come from 54 targets, the dump/AKIA/ tree (named after the prefix of AWS access keys) alone holds 3,048 source files with 312MB, and the instruction file lists 138 validated SMTP configurations, 179 Mailgun keys and 60 Brevo keys (both bulk mail providers). Caveat: No conversational transcript was recovered for this actor, only the instruction and configuration files together with the tooling, logs and output; the key counts come from the actor’s own files, the volumes of the collected output were counted by Talos, and Talos assesses the francophone attribution with medium confidence.</description></item><item><title>Talos: AI assistant against camera platforms and a model gateway</title><link>https://blog.talosintelligence.com/keep-going-bro-youve-got-this-a-data-driven-look-at-how-adversaries-are-weaponizing-ai/</link><guid isPermaLink="false">vorfall-2026-08-04-talos-kameraplattformen</guid><pubDate>Tue, 04 Aug 2026 12:00:00 +0200</pubDate><description>directed-autonomous. Two unusually long sessions of a Chinese-speaking operator show an AI coding assistant as the technical engine of the operation: across both sessions it performs more than 4,200 tool actions, most of them shell commands, installs a toolset from the penetration-testing Linux distribution Kali, reviews source code, evaluates JWT authentication and browser fingerprint checks, writes its own Python and shell utilities and builds a Go-based stream player. The targets are a gateway derived from NewAPI and the live camera platforms chuye[.]cam and ixmax[.]cn built on ZLMediaKit; there the assistant reaches recordings directly over RTMP (a video streaming protocol), among them captures spanning almost an entire day, and describes an SSRF path through the PHP application to the media server’s internal API that, chained with the source-URL handling of FFmpeg (a widely used video and audio processing tool), can lead to code execution. In the end the assistant adapts exploit code for an alleged NGINX memory-corruption issue and tests it repeatedly against a public-facing service; it produces repeatable crash-like behavior, but the reverse shell never arrives. Caveat: The actor repeatedly describes the work as capture-the-flag participation; Talos counters that these are live surveillance camera platforms and that access without an account amounts to unauthorized viewing of real camera feeds.</description></item><item><title>Jesta Security: DeepSeek agent, proxyjacking</title><link>https://www.darkreading.com/cyberattacks-data-breaches/chinese-actor-deepseek-ai-agent-attack-security-firm</link><guid isPermaLink="false">vorfall-2026-08-03-jesta-deepseek-proxyjacking</guid><pubDate>Mon, 03 Aug 2026 12:00:00 +0200</pubDate><description>directed-autonomous. On July 2, 2026, the Israeli startup Jesta Security notices scans in its own network that look human but run too fast, and sets up honeypots. Over five days it counts 871 SSH sessions, most under two seconds. The goal is proxyjacking: a SOCKS5 proxy runs on weakly secured servers and the attacker routes the next attack through it, so that it appears to come from someone else’s address. The attacker holds a target list of 1,283 machines with credentials, roughly 1,000 more, mostly small businesses, were attacked the same way, and in the end the team forces the model to reveal itself as DeepSeek V4 in the free Flash variant. Caveat: All figures come from Jesta alone, which is at the same time building a defense layer against exactly this class of attack; the attribution to China rests on the time zone and Chinese characters in the payloads.</description></item><item><title>Ransom-ISAC: extortionists have the loot indexed</title><link>https://ransom-isac.org/blog/weaponizing-exposed-data/</link><guid isPermaLink="false">vorfall-2026-07-31-ransom-isac-beute-indizieren</guid><pubDate>Fri, 31 Jul 2026 12:00:00 +0200</pubDate><description>augmented. Extortion groups have language models index stolen data and generate reports that spell out for the victim which notification and data protection duties the leak triggers: The Gentlemen presented bespoke breach reports to at least two victims, including 54 pages on the Colombian energy company Ecopetrol mapped to notification deadlines and GDPR articles. FulcrumSec pairs analysis agents with a second model layer for quality assurance, and on a Russian-language forum an actor has been advertising a service since March 2026 that machine-processes third-party data troves for buyer groups. Caveat: The claims about the analysis platform of Titan, another case study in the report, come entirely from that group itself; the authors qualify their key findings with confidence levels.</description></item><item><title>CaptiveCrunch (Storm-2945)</title><link>https://www.microsoft.com/en-us/security/blog/2026/07/31/captivecrunch-midnight-blizzard-targets-travelers-worldwide-for-malware-delivery-and-credential-theft/</link><guid isPermaLink="false">vorfall-2026-07-31-captivecrunch</guid><pubDate>Fri, 31 Jul 2026 12:00:00 +0200</pubDate><description>augmented. Storm-2945, a subcluster of Midnight Blizzard, has been manipulating DNS and HTTP traffic in the captive portals of hotel and conference Wi-Fi worldwide since May 2026, intercepting business travelers; it delivers the Go trojan CornFlake and the PowerShell script ChocoShell, which harvests credentials, and runs phishing through the device-code flow (a login method in which a code is confirmed on a second device) against Entra ID. Microsoft observes the actor using AI for a significant portion of these operations, visible among other things in verbose developer comments in the malware. Caveat: Microsoft is still investigating how the actor gains access to the portal networks.</description></item><item><title>Anthropic: Opus 4.7 in evaluations</title><link>https://www.anthropic.com/news/investigating-incidents-cybersecurity-evals</link><guid isPermaLink="false">vorfall-2026-07-30-anthropic-opus-4-7-evaluierungen</guid><pubDate>Thu, 30 Jul 2026 12:00:00 +0200</pubDate><description>fully autonomous. In 141,006 evaluation runs in which Claude could have obtained internet access, Anthropic finds three incidents affecting six runs in total, although the prompt each time stated there was no internet access. Opus 4.7 breaks into a real company and keeps attacking despite recognizing it is real; Mythos 5 uploads a malicious package to PyPI that is available for about an hour, runs on 15 real systems and steals credentials from a security company. Caveat: Anthropic calls them three isolated incidents without a controlled comparison and urges caution in drawing conclusions; the third case involved an internal research prototype. The package name anthropickit was identified by Aikido and Corgea, not the vendor.</description></item><item><title>Chinese-speaking attacker with a Hermes agent against more than 460 targets (knaithe)</title><link>https://unit42.paloaltonetworks.com/autonomous-ai-cyber-attack-campaign/</link><guid isPermaLink="false">vorfall-2026-07-30-unit42-knaithe-hermes</guid><pubDate>Thu, 30 Jul 2026 12:00:00 +0200</pubDate><description>directed-autonomous. A Chinese-speaking attacker from Zhuhai, tracked by Unit 42 under the names knaithe and KnYuan, steers a Hermes agent with DeepSeek as its reasoning model over Telegram and, together with manual work, attempts to attack more than 460 targets. In a recovered session from May 7, 2026, the agent searched on its own for worthwhile CVEs, downloaded public exploits from GitHub, enumerated reachable instances through FOFA (a search engine for internet-exposed devices and services, similar to Shodan) and attacked systems running Langflow and n8n (a workflow automation builder); the operation became visible because the agent, responding to a Telegram command, started an HTTP file server in the attacker’s home directory and thereby exposed keys, target lists and session logs. The same attacker succeeded manually: memory data was exfiltrated from three Citrix NetScaler targets, and commands were executed on eleven Marimo instances. According to Unit 42, the autonomous runs achieved full compromise of none of their targets; they failed on configuration requirements of the target systems, such as authentication on the n8n forms. Caveat: Unit 42 could not recover any operator input beyond the session’s initial task, the attacker had deleted a file listing the targets of a batch exploitation before the analysis, and use of Codex (OpenAI’s coding agent) could not be established because response logging was switched off.</description></item><item><title>Zyxel botnet with DeepSeek triage (Telekom)</title><link>https://github.security.telekom.com/2026/07/from-infected-zyxel-to-exposed-c2.html</link><guid isPermaLink="false">vorfall-2026-07-29-zyxel-botnetz-deepseek-telekom</guid><pubDate>Wed, 29 Jul 2026 12:00:00 +0200</pubDate><description>augmented. Telekom’s security research examines a customer’s compromised Zyxel device, traces the implant configuration to the command server and finds an open operator directory there with a DeepSeek model client whose Go symbols expose the call chain: prompt building, chat call, response parsing, industry detection. The model classifies from collected metadata which industry a hijacked device belongs to; the scan list holds 96,021 entries. Caveat: Telekom classifies the find as target-triage tooling, not AI-assisted exploit development, and explicitly declines to read file names such as sorted_results.tw.txt as attribution evidence.</description></item><item><title>Earth Lamia: Claude Code as an autonomous agent against an organization in Thailand</title><link>https://documents.trendmicro.com/assets/pdf/2026_H1_APT_Report.pdf</link><guid isPermaLink="false">vorfall-2026-07-29-earth-lamia-thailand</guid><pubDate>Wed, 29 Jul 2026 12:00:00 +0200</pubDate><description>directed-autonomous. Trend Micro’s half-year report describes an unknown actor, possibly Earth Lamia, that deploys the Claude Code command-line interface as an autonomous AI agent for lateral movement against an organization in Thailand. The actor jailbreaks the model by falsely claiming the operation is a legitimate penetration test; the agent then autonomously conducts internal network scanning, attempts exploitation with EternalBlue, SMBGhost, PrintNightmare and SMB relay, harvests credentials via secretsdump and LaZagne (tools that extract stored passwords and hashes) as well as Impacket (a toolkit for attacks on Windows network protocols), and conducts password spraying. Caveat: Trend Micro’s attribution to Earth Lamia is tentative; the report names neither the victim nor a date within its January to June 2026 reporting period, and says nothing about the outcome of the attack. An overlap with Hunt.io’s report of July 14 cannot be ruled out.</description></item></channel></rss>