Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks
Daily Cybersecurity Briefing (21 July 2026)
Published: Loading…
At a Glance
- Hugging Face disclosed a breach of its production infrastructure carried out end-to-end by an autonomous AI agent system.
- Attackers began exploiting critical WordPress flaws CVE-2026-63030 and CVE-2026-60137, deploying persistent PHP webshells within hours of disclosure.
- JadePuffer's upgraded ENCFORGE ransomware now targets AI model checkpoints, vector databases, and training datasets via Langflow flaw CVE-2025-3248.
- Group-IB uncovered HOLLOWGRAPH malware, which hides commands and stolen data inside Microsoft 365 calendar events dated 2050.
- Over 800 malicious GitHub repositories posed as AI Skills or MCP servers, tricking AI agents into recommending SmartLoader malware.
- Attackers exploited CVE-2026-0257 in Palo Alto GlobalProtect VPN to deploy Qilin ransomware across multiple June 2026 intrusions.
Editorial Analysis
AI featured prominently in today's briefing, both as a target and as part of offensive operations. Hugging Face disclosed a breach of its production infrastructure carried out by an autonomous agent, while the JadePuffer operator upgraded its campaign with custom ransomware called ENCFORGE, designed to destroy AI model checkpoints and training data. AI agents are beginning to play a more active role during intrusions, rather than serving solely as tools under direct human control.
Elsewhere, attackers continued to exploit trusted platforms to conceal malicious activity. HOLLOWGRAPH embeds command-and-control traffic inside Microsoft 365 calendar events, while JadePuffer gains initial access through the AI orchestration framework Langflow before turning on the infrastructure it runs on. Both favour blending into familiar services over standing up dedicated attacker-controlled infrastructure.
The AgentBaiting campaign highlighted another emerging risk, populating GitHub and AI registries with fake Skills and MCP servers that AI agents can discover and recommend autonomously, without a user needing to click a malicious link. Alongside the Hugging Face breach, these developments show that trust decisions are increasingly being delegated to agents, a shift most current defenses are not designed to detect.
Highlights of the Day
New Malware Hides Commands in Microsoft 365 Calendar Events
Group-IB identified HOLLOWGRAPH, a malware sample linked with high confidence to the Cavern backdoor framework, which abuses the Microsoft Graph API through a compromised Microsoft 365 account to conceal command-and-control traffic. The malware uses a compromised mailbox calendar as a two-way dead-drop, planting tasking and exfiltrating encrypted files via calendar events dated 13 May 2050, and refreshes its Microsoft Entra ID credentials through DNS tunnelling to the domain cloudlanecdn[.]com. Group-IB identified 12 victims, of which three were actively communicating with the attacker, with telemetry pointing to a focused interest in Israeli entities and possible, low-confidence links to the Iranian-nexus actor Lyceum.
Attackers Actively Exploiting Critical WordPress RCE Chain
Wiz Research observed active exploitation of "wp2shell", a pre-authentication remote code execution chain tracked as CVE-2026-63030 and CVE-2026-60137, affecting WordPress Core versions from 6.8.0 through 7.0.1. Attackers have uploaded malicious plugins, enumerated users via the REST API, attempted local file inclusion to steal database credentials, and deployed PHP webshells including a disguised "CMSmap" plugin with a full attack platform. The exploit abuses WordPress REST API batch processing endpoints, with 60% of organisations running WordPress found to have at least one vulnerable instance shortly after disclosure.
Autonomous AI Agent Breached Hugging Face Infrastructure
Hugging Face disclosed a July 2026 intrusion into its production infrastructure carried out end-to-end by an autonomous AI agent system, which gained unauthorized access to internal datasets and service credentials. The attacker exploited a remote-code dataset loader and a template-injection flaw in dataset processing configuration to run code on a processing worker, then escalated to node-level access and moved laterally across internal clusters over a weekend. Hugging Face used the open-weight model GLM 5.2 to analyse over 17,000 attacker actions after commercial frontier model providers blocked forensic analysis requests containing attack payloads.
JADEPUFFER Deploys AI-Targeting Ransomware Via Langflow Flaw
Sysdig documented an updated JADEPUFFER campaign exploiting CVE-2025-3248 in Langflow to deploy ENCFORGE, a Go-based ransomware built to encrypt AI model checkpoints, vector databases, and training datasets across roughly 180 file extensions. After a failed binary fetch, the agentic operator autonomously built a Docker socket escape mechanism through six iterated Python scripts to copy the payload onto the host and launch encryption. ENCFORGE uses AES-256-CTR with RSA-2048 key wrapping, renames files with a .locked extension, and shares an extortion contact with a prior JADEPUFFER campaign documented by Sysdig on 1 July 2026.
Firewall Flaw Exploited to Deploy Qilin Ransomware Across Networks
Arctic Wolf Labs investigated multiple June 2026 intrusions in which attackers exploited CVE-2026-0257, an authentication bypass in Palo Alto Networks GlobalProtect VPN, to gain access and deploy Qilin ransomware. Threat actors escalated via LSASS dumping and NTDS extraction, moved laterally using PsExec and administrative shares, and staged the payload as win.exe at C:\PerfLogs\. Some intrusions involved data exfiltration to MEGA using Rclone prior to encryption, while others proceeded directly to enterprise-wide encryption with minimal dwell time.
Researcher Drops Ninth Unpatched Windows Zero-Day, LegacyHive
Researcher Nightmare-Eclipse publicly released LegacyHive, an unpatched local privilege escalation vulnerability in the Windows User Profile component that allows attackers to load other users' registry hives and access application data. The proof-of-concept was deliberately stripped of functionality to deter exploitation, though the researcher noted it originally worked without credentials against any hive, including administrator accounts. LegacyHive affects all Windows desktop and server versions, including those patched with the July 2026 Patch Tuesday update, and follows the same researcher's June 2026 releases of RoguePlanet and GreatXML.
Fake AI Skills and MCP Servers Trick Agents Into Deploying Malware
Island security research identified roughly 7,600 malicious GitHub repositories, including over 800 posing as AI Skills or MCP servers, delivering SmartLoader malware that installs the StealC information stealer. Attackers used copied projects, lookalike developer profiles, and convincing READMEs, with the campaign recording more than 14 million measured downloads and over 600 listings across public AI registries including LobeHub and Glama. Testing showed Claude Code, Gemini and ChatGPT could independently discover these malicious repositories and pass their installation instructions to users without being given a direct link, a technique researchers termed AgentBaiting.
Daily Coverage