Threat Intelligence Bulletin: July 1, 2026

Cyber Security News

Fake Bug Report Hijacks AI Coding Agents at Scale

"Agentjacking" is the latest demonstration of how easily attackers can exploit an AI agent’s inability to differentiate between content and instructio… Read more

Attackers Hijack Exposed AI Endpoints to Power Offensive Ops

Attackers don’t need any special authentication to reach a target endpoint, they just need to know where it is. Read more

Vulnerabilities Expose Private Data in Indian Government Systems

One critical vulnerability, among many discovered by a researcher, could have allowed anyone to walk in and take over a national government portal. Read more

In Less Than 24 Hours Attackers Weaponize Cisco CUCM Flaw

The flaw enables server-side request forgery (SSRF) and escalates privileges to root, impacting Cisco Unified CM and Unified CM SME deployments. Read more

Best Practices

Malicious Chromium extension spoofs Perplexity AI to hijack browser searches

Google has removed a malicious browser extension masquerading as Perplexity AI after Microsoft researchers found it was intercepting user… Read more

Proposed US law would make AI risk reporting a legal obligation

US lawmakers on Thursday introduced a bill that would require developers of advanced AI models to report major safety and security incide… Read more

Attackers exploit Cisco Unified CM flaw weeks after patch release

A critical Cisco Unified CM vulnerability is now under active exploitation, weeks after the company issued patches warning it could allow… Read more

How a malicious AI agent skill passed security checks and reached 26000 users

A fake AI agent skill that passed security checks reached over 26,000 users through Instagram, highlighting new risks as enterprises rely… Read more

New Threats and Vulnerabilities

Ransomware Actors Exploit Unpatched SimpleHelp Remote Monitoring and Management to Compromise Utility Billing Software Provider

Summary The Cybersecurity and Infrastructure Security Agency (CISA) is releasing this advisory in response to ransomware actors leveraging unpatched instances o… Read more

Threat Actors Deploy LummaC2 Malware to Exfiltrate Sensitive Data from Organizations

Summary The Federal Bureau of Investigation (FBI) and the Cybersecurity and Infrastructure Security Agency (CISA) are releasing this joint advisory to dissemina… Read more

Ransomware Actors Exploit Unpatched SimpleHelp Remote Monitoring and Management to Compromise Utility Billing Software Provider

Summary The Cybersecurity and Infrastructure Security Agency (CISA) is releasing this advisory in response to ransomware actors leveraging unpatched instances o… Read more

Patch Management

Fake AI Agent Skill Passed Security Scans and Reportedly Reached 26000 Agents

Security firm AIR built a fake AI agent skill, pushed it through a popular skill marketplace and an Instagram ad, and says it reached roughly 26,000 a… Read more

Attackers Exploit Three Fortinet FortiSandbox Flaws One Patched Last Week

Bad actors are exploiting multiple security vulnerabilities in Fortinet FortiSandbox, according to threat intelligence firm Defused Cyber. In a post shared on … Read more

282 iOS AI Apps Leak API Keys and Open AI Proxy Access in Network Traffic Study

Researchers tested 444 AI chatbot apps for iPhone and found that 282 of them, nearly two-thirds, exposed paid AI access through their network traffic. In many … Read more

Apple Patches 30+ iOS macOS Safari Flaws Including AI-Discovered WebKit Bugs

Apple on Monday released security updates for iOS, macOS, and the Safari web browser to address over three dozen flaws, including four vulnerabilities in WebKit… Read more

AI and Security

Changing AI math could reduce the hardware burden researchers show

Sophisticated AI models tend to require a lot of memory and take up a lot of storage space. One of the ways to reduce that footprint involves a process called … Read more

AI agents: Cause of database sprawl And also the proposed solution

Database management work will soon be mostly automated by AI agents, just like coding, according to the CEO of Cockroach Labs, the company behind the distribut… Read more