Overview of the Threat The CyberProof Threat Research Team has identified a new variant of ClickFix that leverages trusted Windows components to bypass traditional defenses. By embedding malicious code deep within the operating system’s core utilities,
Continue ReadingMonth: July 2026
Autonomous AI Agent Espionage Campaign Targeting Thai Government Finance Ministry
Threat Overview A newly published threat report by Hunt.io, released on 2026-07-28 at hxxps://hunt[.]io/blog/thailand-ministry-finance-targeted-with-hermes-ai-agent, details how an autonomous AI agent framework named Hermes was leveraged to conduct a large‑scale espionage campaign against Thailand’s Ministry of Finance
Continue ReadingContinuous PLC Attacks Targeting Key US Infrastructure
On 27 July 2026 Trend Micro released a detailed threat report titled Ongoing PLC Exploitation Against Critical U.S. Infrastructure. The advisory, jointly issued by the FBI, CISA, NSA, EPA, DOE and U.S. Cyber Command, warns that
Continue ReadingJADEPUFFER Evolving Ransomware Targets AI Models
Threat Overview The Sysdig Threat Research Team (TRT) has released a detailed report on JADEPUFFER, an agentic threat actor that has upgraded its tactics from database‑centric extortion to targeted destruction of artificial intelligence (AI) and machine
Continue ReadingKratos Phishing as a Service Targets US and EU to Reduce Microsoft 365 Account Takeover Risk
The latest threat report from Any Run, published on July 20, 2026, exposes the evolution of Kratos – a mature phishing‑as‑a‑service (PhaaS) operation that focuses on Microsoft 365 users across the United States and Europe. By
Continue ReadingTuxbot V3 Inside an IoT Botnet Framework with LLM Assisted Development
Threat Overview: The Palo Alto Networks Unit 42 team released a new threat report on 2026-07-16 detailing TuxBot v3 Evolution, a modular IoT botnet that leverages large‑language models (LLM) during development. The framework combines a C‑based
Continue ReadingSix Minutes To Compromise: AI-Driven C&C Botnet Deployment By Patriot Bait
On 2026-07-16 Trend Micro released a detailed threat report titled SIX MINUTES TO COMPROMISE, highlighting how a Russian‑speaking actor known as Patriot Bait leveraged Google Gemini’s large language model to automate the design, deployment, and operation
Continue ReadingSupply Chain Breach Using Misconfigured GitHub Actions
Threat Report Summary On 14 July 2026, a coordinated supply‑chain attack exploited a vulnerability in the AsyncAPI generator repository’s pull_request_target workflow. The attacker used the flaw to extract a high‑privilege Personal Access Token (PAT) and subsequently
Continue ReadingCitrixNetScaler Exploit Drives Dragonforce Ransomware via Seven-Step Playbook
In July 2026 Huntress released a detailed threat report titled CitrixBleed 2 (CVE‑2025‑5777) 7 Steps to Dragonforce Ransomware. The study documents a highly repeatable attack chain that has been seen in at least six unrelated organizations across the
Continue ReadingVishing Attacker Targeting Microsoft Entra Passkey Enrollment
Executive Summary The latest threat intelligence report from Okta details a sophisticated vishing and phishing campaign that exploits the newly rolled out passkey enrollment feature in Microsoft Entra. The actors, identified as O-UNC-066 (also reported by
Continue Reading