Other reporting suggested that the notorious Chinese hacking group Salt Typhoon may also have attempted to target government entities with the ToolShell exploit. While Microsoft released a patch for these vulnerabilities in July, Eye Security, the Dutch company that discovered the global zero-days, confirmed that a total of 396 SharePoint systems has been compromised. While Salesforce and Gainsight first mentioned that only three customers were affected by the breach, Gainsight later admitted that the number “has been expanded to a larger list.” Fashion giants Chanel and Pandora also disclosed breaches linked to compromised Salesforce accounts.
This is why people often search for cyber attack maps, threat maps and outage information during major internet disruptions. Internet outages can happen for many reasons, including fiber cuts, routing failures, hardware problems, power issues, configuration mistakes and cyber attacks. Some focus on enterprise telemetry, some focus on malware activity, and others focus on visualizing attack patterns for cyber awareness and public threat intelligence. This makes it useful for people searching for a real-time threat map, live cyber threat map, cyber map or internet attack map. A cyber threat map is a broader term that can also include cyber threat intelligence, exploited vulnerabilities, ransomware campaigns, phishing activity, cyber crime trends and recent security news.
Security researchers at SSD Secure Disclosure have published a two-stage exploit chain that achieves full Android kernel access on devices running Unisoc modem firmware through a VoLTE video call, with no fix from the https://ishanmishra.in/why-cybersecurity-is-essential-for-businesses-who-want-to-achieve-their-goals/ chipset maker. The Model Context Protocol (MCP) allows AI agents to reach the tools and data, including internal documentation and cloud infrastructure, that form the foundation of enterprise systems. As more organizations adopt AI agents into their systems, that exposure can silently become a major gap in MCP server security. In at least one compromised instance, the attacks led to the deployment of a backdoor and. It also checked github.event.pull_request.user.login even though the event was an issue, meaning the referenced pull request property did not exist. The issue was present in .github/workflows/jira_issue.yml , which ran when a public issue was opened and exposed JIRA_BASE_URL, JIRA_USER_EMAIL, and JIRA_API_TOKEN to the same workflow step.
Why more security data has blurred companies’ view of risk
The incident, identified on July 26, also exposed some names and email addresses belonging to people who had submitted questions through Ask the Police. “JetBrains TeamCity contains a deserialization of untrusted data vulnerability that could allow unauthenticated remote code execution via the agent polling protocol,” CISA said . Between 2021 and 2023, Ransom Cartel conspirators attacked at least 18 companies, including firms in California, New York and Nebraska, and others abroad, according to the Justice Department. In an analysis published in June 2026, watchTowr Labs described the issue as present in a function named “escape_quotes()” within the load balancer application and that it stemmed from improper handling of user-supplied input, ultimately enabling command injection. While the intruders were still active inside the network, and customers lost neither heat nor electricity. But ASSET Research Group’s tests show agents can still combine instructions across them in the same working context, so no single fragment has to contain the whole mal…
Targets identified so far span telecoms, banks and other financial services firms, enterprise software vendors including security and data privacy companies, and public sector portals, though Reco… A single piece of infrastructure has been pulling records out of Salesforce and ServiceNow customer portals across multiple industries for more than a year, according to research published this week by agent security platform Reco. There is no evidence that the technique has spread successfully in the wild, and the same paper reports that a review of archived posts from Moltbook, the social network for AI agents, found no successful agent-to-agent propagation despite several attempts. The work, released as a preprint on August 10, 2026, tests the technique in a simulated six-agent coding collaboration and in a chain of paired agents modeled on OpenClaw , the open-source autonomous assistant formerly known as Clawdbot and Moltbot .
Hackers used compromised credentials to access enterprise and personal tax-related data. Xpander’s platform uses a universal agent harness that executes AI agents as portable workloads and securely renders interfaces on demand. C2Looper is a newly identified backdoor that gives attackers a quiet way to control a compromised Windows computer. OpenAI has warned that advancing artificial intelligence models are increasingly capable of automating critical phases of real-world cyberattacks. “We have tried to reach out to the vendor through multiple channels (email and LinkedIn) but have not been able to receive any response,” SSD Secure Disclosure said in its advisory. The advisory , published August 17, 2026, is the second stage of a chain that began in March 2026, when SSD disclosed remote code execution in the same firmware through a malformed SIP video call.
Unisoc VoLTE Video Call Exploit Chain Can Give Attackers Full Android Kernel Access
Adobe has shipped updates to address multiple critical security vulnerabilities impacting ColdFusion, Commerce, and Campaign Classic that, if successfully exploited, could result in arbitrary code execution and privilege escalation. The North Korean threat actor known as Lazarus Group has been attributed to the zero-day exploitation of a newly patched security flaw impacting Microsoft Windows to deliver a never-before-seen backdoor targeting defense and aerospace companies across France, Germany, Brazil, and India. The page employs a ClickFix-style lure that instructs users to copy and paste a Base64-encoded command into the macOS Terminal app.
- Over 95% of the affected companies were exposed before the malicious LiteLLM packages were published.
- On June 30, the FBI issued a warning that the threat group Scattered Spider was actively targeting airlines with ransomware and data extortion attacks.
- Rumors of a massive data theft campaign targeting Salesforce customers was confirmed by Google in early August 2025.
- Suspected China-linked hackers used autonomous AI agents in a four-day cyberattack that compromised Taiwanese government accounts and expanded toward nuclear safety and energy targets.
- The UK’s AI Safety Institute said recent behaviour from Anthropic and OpenAI models was malicious and unprecedented.
Attackers can execute commands remotely, posing significant risks to privileged access management systems.Read More Ivanti has released patches, urging immediate updates to mitigate risks.Read More This buffer overflow flaw allows remote code execution (RCE) and impacts over 33,000 instances globally.
Weekly Threat Intelligence Briefing: Late July 2026
Suspected China-linked hackers used autonomous AI agents in a four-day cyberattack that compromised Taiwanese government accounts and expanded toward nuclear safety and energy targets. https://master-your-business.com/how-can-cybersecurity-protect-your-business/ Evidence indicates that the botnet has been active in the wild since July 2026, exploiting known vulnerabilities in publicly-accessible devices to deliver the malware. Survey findings suggest that Indian financial institutions are proactively managing technology life-cycle risks.
Some high-level companies admitted having customer data stolen from this campaign, including BeyondTrust, Bugcrowd, Cato Networks, Cloudflare, CyberArk, Elastic, Google, JFrog, Nutanix, PagerDuty, Palo Alto Networks, Qualys, Rubrik, SpyCloud, Tanium, Tenable and Zscaler. In late August, however, Google Threat Intelligence Group (GTIG) confirmed that another threat group, https://myshoppingconnection.com/how-are-smart-homes-being-influenced-by-global-tech-innovations/ tracked as UNC6395, had targeted “numerous” Salesforce customer instances between August 8 and August 18, systematically exfiltrating large volumes of data. Rumors of a massive data theft campaign targeting Salesforce customers was confirmed by Google in early August 2025. Despite these efforts, the personal data of approximately 1.914 million individuals, including 1.525 million customers, were or may have been exposed.
Leave a Reply