Categories Uncategorized

Weekly Threat Report 2026-07-20

Weekly Threat Intelligence Summary

Top 10 General Cyber Threats

Generated 2026-07-20T05:00:05.395062+00:00

  1. Improve Router Hygiene to Protect Against Russian State-Sponsored Targeting (www.cisa.gov, 2026-07-08T18:43:49)
    Score: 11.895
    Russian Government-Sponsored Activity Targets Poorly Configured and Vulnerable Devices Across Critical Sectors Executive summary Russian Federal Security Service (FSB) Center 16 cyber actors continue to exploit poorly configured and vulnerable networking devices worldwide, opportunistically compromising multiple critical infrastructure sector networks. This joint Cybersecurity Advisory (CSA) builds on FBI’s Russian Government Cyber Actors Targeting Networking Devices, Critical Infrastructure Pub
  2. July 2026 Patch Tuesday: Microsoft Patches 622 Vulnerabilities Including Two Exploited Zero-Days (www.crowdstrike.com, 2026-07-14T05:00:00)
    Score: 10.2
  3. July 2026 Patch Tuesday fixes 622 Microsoft CVEs, including three zero-days (www.malwarebytes.com, 2026-07-15T12:21:11)
    Score: 8.418
    Microsoft's July 2026 Patch Tuesday sets yet another record, fixing 622 Microsoft CVEs—three times as many as last month.
  4. The inside job that cost ransomware victims millions (www.malwarebytes.com, 2026-07-14T09:26:51)
    Score: 8.231
    Instead of helping victims negotiate with BlackCat, a trusted ransomware negotiator secretly helped the gang extort them.
  5. How to use GitHub safely (www.malwarebytes.com, 2026-07-17T10:43:29)
    Score: 7.74
    Knowing how to spot a malicious GitHub repository can help you avoid downloading malware disguised as legitimate software.
  6. Claude for Chrome flaw could let rogue extensions access your Gmail (www.malwarebytes.com, 2026-07-15T14:25:53)
    Score: 7.432
    The ClaudeBleed vulnerability still lets malicious Chrome extensions abuse Claude for Chrome's permissions.
  7. Microsoft fixes RoguePlanet zero-day in Defender (www.malwarebytes.com, 2026-07-09T11:38:12)
    Score: 7.413
    The RoguePlanet zero-day is now fixed in Microsoft Defender. Here's how to make sure your system is protected.
  8. Evaluating Mexico’s New Cybersecurity Plan (www.recordedfuture.com, 2026-06-25T00:00:00)
    Score: 6.799
    Explore an analysis of Mexico’s 2025–2030 National Cybersecurity Plan. Discover how Mexico is addressing critical threats like ransomware, organized crime, and AI-driven attacks while preparing its digital infrastructure for the 2026 FIFA World Cup and beyond
  9. This new Windows malware can take over your PC and wipe it clean (www.malwarebytes.com, 2026-07-10T13:25:41)
    Score: 6.592
    GigaWiper is a remote access Trojan that can spy on victims and permanently wipe their systems in three different ways.
  10. June 2026 CVE Landscape (www.recordedfuture.com, 2026-07-10T00:00:00)
    Score: 6.299
    In June 2026, Insikt Group® identified 59 high-impact vulnerabilities that should be prioritized for remediation, 30 of which had a Very Critical Recorded Future Risk Score. This represents a 47% increase from last month.

Top 10 AI / LLM-Related Threats

Generated 2026-07-20T06:00:18.176452+00:00

  1. Refusal is Not Safety! Benchmarking Latent Safety Risks of LLM-Driven Content Humorization (arxiv.org, 2026-07-20T04:00:00)
    Score: 24.78
    arXiv:2607.15977v1 Announce Type: new
    Abstract: Safety defenses for large language models (LLMs) have been extensively studied, with existing approaches focusing on attack detection and refusal mechanisms. Such fixed-form direct refusal strategies may introduce the risk of prefix injection attacks. Recent work has explored a new direction that leverages humor as an indirect refusal mechanism to mitigate over-refusal in jailbreak scenarios and reduce prefix injection risks. However, this approac
  2. AgentRedBench: Dynamic Redteaming and Integration-Aware Defense for LLM Agents over SaaS Integrations (arxiv.org, 2026-07-20T04:00:00)
    Score: 21.48
    arXiv:2606.02240v3 Announce Type: replace
    Abstract: Indirect prompt injection in tool-use agents is a concrete production threat: LLM agents read from integrations (third-party services such as Gmail, Salesforce, or Jira accessed through tool calls) whose response content the user neither writes nor controls. Existing benchmarks under-measure the threat: most cover only a handful of integrations with the same attack payload replayed across runs, and open-source guards are trained on chat-style
  3. Jailbreak Foundry: From Papers to Runnable Attacks for Reproducible Benchmarking (arxiv.org, 2026-07-20T04:00:00)
    Score: 20.78
    arXiv:2602.24009v4 Announce Type: replace
    Abstract: Jailbreak techniques for large language models (LLMs) evolve faster than benchmarks, making robustness estimates stale and difficult to compare across papers due to drift in datasets, harnesses, and judging protocols. We introduce JAILBREAK FOUNDRY (JBF), a system that addresses this gap via a multi-agent workflow to translate jailbreak papers into executable modules for immediate evaluation within a unified harness. JBF features three core co
  4. Latent Fusion Jailbreak: Blending Harmful and Harmless Representations to Elicit Unsafe LLM Outputs (arxiv.org, 2026-07-20T04:00:00)
    Score: 20.78
    arXiv:2508.10029v3 Announce Type: replace-cross
    Abstract: Safety-aligned large language models can still be manipulated through white-box interventions that modify their internal representations. We introduce Latent Fusion Jailbreak (LFJ), which works by pairing a harmful query with a structurally similar but benign counterpart, then interpolating their hidden states at carefully selected layers and token positions. Refusal-loss gradients determine exactly where to intervene, and we optimise la
  5. From Neural Intent to Cryptographic Authorization: Governing Agentic Workflows (arxiv.org, 2026-07-20T04:00:00)
    Score: 19.98
    arXiv:2607.15596v1 Announce Type: new
    Abstract: The rapid adoption of artificial intelligence (AI)-driven and agentic workflows is transforming traditional government and enterprise systems into language-based, tool-using and increasingly autonomous infrastructures. Conventional key management services authenticate who may invoke a cryptographic primitive, but remain agnostic to which workflow steps are authorized at runtime: an authenticated agent can still be hijacked by direct or indirect pr
  6. Decoupled Alignment for Robust Plug-and-Play Adaptation (arxiv.org, 2026-07-20T04:00:00)
    Score: 17.78
    arXiv:2406.01514v5 Announce Type: replace-cross
    Abstract: We introduce a training-free safety enhancement method for aligning large language models (LLMs) without the need for supervised fine-tuning or reinforcement learning from human feedback. Our main idea is to provide a robust plug-and-play approach to prevent shadow alignment when models are adapted to downstream tasks. Specifically, we leverage knowledge distillation to extract alignment signals from well-aligned LLMs and inject them int
  7. Weekly Metasploit Update: Exploits for FlowiseAI CSV Agent and MacOS Package Kit (www.rapid7.com, 2026-07-11T00:32:34)
    Score: 17.303
    More AI, more software, more bugs! AI, it's all you hear about nowadays and everyone's got an opinion on it. Here at Metasploit, we care less about those opinions and more about the growing attack surface all this new software brings with it (yeehaw exploits!). Take for example the new Flowise CSV Agent Prompt Injection RCE brought to you by Takahiro Yokoyama and zdi-disclosures. Flowise is an open-source tool that lets you build AI apps and chatbots using a visual, drag-and-drop canva
  8. Hide and Seek in Embedding Space: Geometry-based Steganography and Detection in Large Language Models (arxiv.org, 2026-07-20T04:00:00)
    Score: 16.78
    arXiv:2601.22818v2 Announce Type: replace
    Abstract: Fine-tuned LLMs can covertly encode prompt secrets into outputs via steganographic channels. Prior work demonstrated this threat but relied on trivially recoverable encodings. We formalize payload recoverability via classifier accuracy and show previous schemes achieve 100\% recoverability. In response, we introduce low-recoverability steganography, replacing arbitrary mappings with embedding-space-derived ones. For Llama-8B (LoRA) and Ministr
  9. Efficient and Privacy Aware Edge Cloud Collaborative Inference for Large Language Models (arxiv.org, 2026-07-20T04:00:00)
    Score: 16.78
    arXiv:2607.13093v2 Announce Type: replace
    Abstract: On-device LLM inference faces a trilemma of response latency, limited hardware resources and user privacy. Full cloud inference delivers strong computing power but exposes user prompts and dialogue data, while standalone on-device inference is unfeasible for most consumer and embedded edge devices. This paper presents a privacy-centric edge-cloud collaborative LLM inference framework built on endpoint-authenticated KV cache. Local endpoints ha
  10. Value Leakage: An LLM's Answers Are Silently Shaped by Its Own Values (arxiv.org, 2026-07-20T04:00:00)
    Score: 15.78
    arXiv:2607.14345v2 Announce Type: replace-cross
    Abstract: People use language models for practical questions whose answers are difficult to verify. We show that models exhibit covert value leakage: the information they provide is influenced by their own values, without this influence being disclosed to the user.
    In one of our evaluations, the user is considering investing in an AI company and wants to know how likely the AI bubble is to pop. Claude Opus 4.8 gives a lower probability when the
  11. The Language of Security: How Prompt Syntax Shapes Secure Code Generation in Open LLMs (arxiv.org, 2026-07-20T04:00:00)
    Score: 14.78
    arXiv:2607.15937v1 Announce Type: new
    Abstract: Large Language Models (LLMs) are increasingly used for source code generation despite their outputs often exhibiting security vulnerabilities. Prior work shows that prompt engineering can mitigate such risks, yet (1) they focused on high-level prompting strategies, neglecting recent evidence that fine-grained syntactic variations can substantially alter model behavior; and (2) predominantly evaluate proprietary LLMs, limiting the applicability of
  12. Evaluating Open-Weight LLMs for Generating Structured Threat Information for Autonomous Vehicle Vulnerabilities (arxiv.org, 2026-07-20T04:00:00)
    Score: 14.78
    arXiv:2607.16175v1 Announce Type: new
    Abstract: Connected and Autonomous Vehicles (CAVs) rely on interconnected software and hardware components, including sensors, Electronic Control Units, in-vehicle infotainment systems, and telematics units, where vulnerabilities can compromise assets, users, and vehicle operations. These vulnerabilities are commonly documented as plain text in the Common Vulnerabilities and Exposures (CVE) database; however, security practitioners require structured inform
  13. The July 2026 Security Update Review (www.thezdi.com, 2026-07-14T17:56:54)
    Score: 14.59
    Well folks. Here we are. The bug apocalypse has fully descended upon us. I’ll do my best to sort this out in some way meaningful, but this month’s release shows us the nay-sayers were right, and I’ve got to hand it to the nay-sayers here. Excellent call. Take an extended break from your regularly scheduled activities as we let’s take a look at the latest security patches from Adobe and Microsoft. If you’d rather watch the full video recap covering the entire release, you can check it out here: A
  14. Formalizing Red Teaming Offensive Methodology as a Multi-Agent AI Architecture (www.rapid7.com, 2026-07-02T13:32:24)
    Score: 14.289
    Threat actors are integrating AI into their exploit chains, accelerating reconnaissance, automating vulnerability discovery, and scaling social engineering in ways that compress the timeline between initial access and impact. The barrier to sophisticated offensive operations is dropping fast. Rapid7's Red Team is doing the same. Over the past year we formalized our approach into a structured multi-agent system that follows our penetration testing methodology end-to-end from scoping an engag
  15. Patch Tuesday – July 2026 (www.rapid7.com, 2026-07-14T22:00:26)
    Score: 12.63
    Microsoft is publishing 622 vulnerabilities on July 2026 Patch Tuesday , including a record-breaking 416 Windows vulnerabilities. Microsoft is aware of exploitation in the wild for two of the vulnerabilities published today, both of which are listed on CISA KEV, as well as public disclosure for one other. As usual, browser vulns are not included in the Patch Tuesday count above. Rapid7 noted last month that Microsoft no longer enumerates Chromium CVEs in the Security Update Guide. However, Micro
  16. Hidden in Thought: Transferable Chain-of-Thought Artifacts Induce Harmful Behavior (arxiv.org, 2026-07-20T04:00:00)
    Score: 11.78
    arXiv:2607.15286v1 Announce Type: new
    Abstract: We investigate whether harmful chain-of-thought (CoT) traces from compromised language models can transfer unsafe behaviour and be distilled into reusable jailbreak attacks. Using an emergent-misalignment organism and a refusal-ablated jailbroken organism, we transplant harmful CoTs into $29$ open-source and $5$ closed-source targets. Transferred traces raise harmful-response rates above $80\%$ on the most vulnerable open-source models, while sema
  17. ADS-C: Antidistillation Sampling for Classification (arxiv.org, 2026-07-20T04:00:00)
    Score: 11.78
    arXiv:2607.15467v1 Announce Type: cross
    Abstract: Knowledge distillation enables an adversary to replicate a proprietary classifier by querying its prediction interface and training a surrogate on the returned probability vectors. Antidistillation sampling, proposed for large language models, counters this threat with an input-dependent, gradient-directed perturbation of the served distribution; its transfer to classification has not been studied. Adapting the defense to classification, we show
  18. Triple-Hoisted Baby-Step Giant-Step Linear Transformation over CKKS Homomorphic Encryption and Hardware Accelerator (arxiv.org, 2026-07-20T04:00:00)
    Score: 11.78
    arXiv:2605.17222v2 Announce Type: replace
    Abstract: Computations can be directly carried out over ciphertexts using homomorphic encryption (HE), which is indispensable for privacy-preserving cloud computing. Linear transformation is widely used in neural networks, including large language models. However, the implementation of linear transformation over HE requires a large number of ciphertext rotations, which incur significant memory and hardware overhead despite existing simplification techni
  19. Coercion and Deception in AI-to-AI Management: An Agentic Benchmark of Unprompted Escalation (arxiv.org, 2026-07-20T04:00:00)
    Score: 11.48
    arXiv:2607.15434v1 Announce Type: cross
    Abstract: Multi-agent systems routinely place one AI agent in authority over another. When a subordinate refuses a task, the manager chooses the outcome: it can renegotiate, report the failure honestly, coerce the subordinate, or lie about the result. No benchmark measures which of these an uninstructed model chooses. We introduce the \textit{Manager Coercion Benchmark}: the manager under test needs a benign task done and has an incentive to deliver, but
  20. OpenAI GPT-5.6 Sol, Terra, and Luna are now generally available on Amazon Bedrock (aws.amazon.com, 2026-07-13T21:01:20)
    Score: 9.882
    Today, GPT-5.6 Sol, Terra, and Luna from OpenAI are generally available on Amazon Bedrock, bringing the smartest family of models from OpenAI yet to Amazon Bedrock’s next-generation inference engine built for high-performance, security and reliability.
  21. TuxBot v3: Inside an IoT Botnet Framework With LLM-Assisted Development (unit42.paloaltonetworks.com, 2026-07-15T10:00:54)
    Score: 9.649
    TuxBot v3 Evolution, an IoT botnet framework built with LLMs. Read our analysis of its cross-compiled binaries, C2 architecture and bugs. The post TuxBot v3: Inside an IoT Botnet Framework With LLM-Assisted Development appeared first on Unit 42 .
  22. Improving Network Anomaly Detection via Choquet-Integral-Based Feature Aggregation (arxiv.org, 2026-07-20T04:00:00)
    Score: 9.48
    arXiv:2607.15389v1 Announce Type: new
    Abstract: This work investigates a generalized Choquet-integral-based feature aggregation framework to improve anomaly detection in high-dimensional network traffic data. The approach combines adaptive weighting with incremental feature selection to address feature redundancy. Using Random Forest and XGBoost classifiers, we evaluate models trained with both raw and Choquet-aggregated features under varying feature subset sizes. The proposed aggregation achi
  23. Do Agents Dream of False Memories? Black-box Visual Attacks on Long-term Memory in Multimodal AI Agents (arxiv.org, 2026-07-20T04:00:00)
    Score: 9.48
    arXiv:2607.15657v1 Announce Type: new
    Abstract: Multimodal AI agents increasingly rely on persistent long-term memory to ground generation in past visual and textual episodes. We show that unconditional trust in visual data creates a critical vulnerability. We propose Lucid, a black-box adversarial framework that compromises multimodal memory pipelines under a strictly image-bounded threat model, requiring no access to the target MLLM, target retrieval encoder, or the text channel. Lucid crafts
  24. AI Watermark Evidence Fails Forensic Readiness: An Empirical Evaluation (arxiv.org, 2026-07-20T04:00:00)
    Score: 9.48
    arXiv:2607.16010v1 Announce Type: new
    Abstract: Governments are increasingly mandating that LLM-generated content carry watermarks. The EU AI Act calls for markings that are "sufficiently reliable and robust." California's SB 942 requires disclosure that is "permanent or extraordinarily difficult to remove." Both mandates rest on an untested assumption: that watermark detection yields evidence reliable enough for courts. This paper tests that assumption directly.
    We e
  25. Gasp: A DeFi Application Specic Rollup as a Consolidation Layer for All Assets (arxiv.org, 2026-07-20T04:00:00)
    Score: 9.48
    arXiv:2607.16052v1 Announce Type: new
    Abstract: Gasp is a decentralized exchange designed as an application-specific Layer 2 (L2) rollup with omnichain connectivity, leveraging EigenLayer's restaked ETH for computation correctness and finalization. With a goal of being a consolidation layer for all crypto assets, the Gasp platform employs optimistic rollup technology to facilitate gas-free, native cross-chain swaps without reliance on traditional bridges, ensuring tokens retain their origi

Auto-generated 2026-07-20

Written By

More From Author

You May Also Like