Clear Infosec weekly Threat Intelligence Bulletin for July 1, 2026. Curated cyber security news, threats, and guidance with links to the original sources.
Cyber Security News
- Fake Bug Report Hijacks AI Coding Agents at Scale “Agentjacking” is the latest demonstration of how easily attackers can exploit an AI agent’s inability to differentiate between content and instructio…
- Attackers Hijack Exposed AI Endpoints to Power Offensive Ops Attackers don’t need any special authentication to reach a target endpoint — they just need to know where it is…
- Vulnerabilities Expose Private Data in Indian Government Systems One critical vulnerability, among many discovered by a researcher, could have allowed anyone to walk in and take over a national government portal…
- In Less Than 24 Hours Attackers Weaponize Cisco CUCM Flaw The flaw enables server-side request forgery (SSRF) and escalates privileges to root, impacting Cisco Unified CM and Unified CM SME deployments…
Best Practices
- Malicious Chromium extension spoofs Perplexity AI to hijack browser searches Google has removed a malicious browser extension masquerading as Perplexity AI after Microsoft researchers found it was intercepting user…
- Proposed US law would make AI risk reporting a legal obligation US lawmakers on Thursday introduced a bill that would require developers of advanced AI models to report major safety and security incide…
- Attackers exploit Cisco Unified CM flaw weeks after patch release A critical Cisco Unified CM vulnerability is now under active exploitation, weeks after the company issued patches warning it could allow…
- How a malicious AI agent skill passed security checks and reached 26000 users A fake AI agent skill that passed security checks reached over 26,000 users through Instagram, highlighting new risks as enterprises rely…
New Threats and Vulnerabilities
- Ransomware Actors Exploit Unpatched SimpleHelp Remote Monitoring and Management to Compromise Utility Billing Software Provider Summary The Cybersecurity and Infrastructure Security Agency (CISA) is releasing this advisory in response to ransomware actors leveraging unpatched instances o…
- Threat Actors Deploy LummaC2 Malware to Exfiltrate Sensitive Data from Organizations Summary The Federal Bureau of Investigation (FBI) and the Cybersecurity and Infrastructure Security Agency (CISA) are releasing this joint advisory to dissemina…
- Ransomware Actors Exploit Unpatched SimpleHelp Remote Monitoring and Management to Compromise Utility Billing Software Provider Summary The Cybersecurity and Infrastructure Security Agency (CISA) is releasing this advisory in response to ransomware actors leveraging unpatched instances o…
Patch Management
- Fake AI Agent Skill Passed Security Scans and Reportedly Reached 26000 Agents Security firm AIR built a fake AI agent skill, pushed it through a popular skill marketplace and an Instagram ad, and says it reached roughly 26,000 a…
- Attackers Exploit Three Fortinet FortiSandbox Flaws One Patched Last Week Bad actors are exploiting multiple security vulnerabilities in Fortinet FortiSandbox, according to threat intelligence firm Defused Cyber. In a post shared on…
- 282 iOS AI Apps Leak API Keys and Open AI Proxy Access in Network Traffic Study Researchers tested 444 AI chatbot apps for iPhone and found that 282 of them, nearly two-thirds, exposed paid AI access through their network traffic. In many…
- Apple Patches 30+ iOS macOS Safari Flaws Including AI-Discovered WebKit Bugs Apple on Monday released security updates for iOS, macOS, and the Safari web browser to address over three dozen flaws, including four vulnerabilities in WebKit…
AI and Security
- Changing AI math could reduce the hardware burden researchers show Sophisticated AI models tend to require a lot of memory and take up a lot of storage space. One of the ways to reduce that footprint involves a process called…
- AI agents: Cause of database sprawl And also the proposed solution Database management work will soon be mostly automated by AI agents, just like coding, according to the CEO of Cockroach Labs, the company behind the distribut…