Weekly Threat Intelligence Summary
Top 10 General Cyber Threats
Generated 2026-08-03T05:00:05.248648+00:00
- Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite (www.cisa.gov, 2026-07-21T19:08:02)
Score: 19.231
Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite Executive summary A group of Russian state-supported cyber actors has been targeting and compromising various Western government and commercial organizations using the Zimbra Collaboration Suite (ZCS) software since at least July 2025. The Russian state-supported advanced persistent threat (APT) group’s activity is tracked in the cybersecurity community under several names (see Cybersecur - Improve Router Hygiene to Protect Against Russian State-Sponsored Targeting (www.cisa.gov, 2026-07-08T18:43:49)
Score: 9.562
Russian Government-Sponsored Activity Targets Poorly Configured and Vulnerable Devices Across Critical Sectors Executive summary Russian Federal Security Service (FSB) Center 16 cyber actors continue to exploit poorly configured and vulnerable networking devices worldwide, opportunistically compromising multiple critical infrastructure sector networks. This joint Cybersecurity Advisory (CSA) builds on FBI’s Russian Government Cyber Actors Targeting Networking Devices, Critical Infrastructure Pub - Sextortion scammers are exploiting ShinyHunters data leaks (www.malwarebytes.com, 2026-07-27T15:00:23)
Score: 9.103
Scammers are posing as ShinyHunters and using leaked email addresses to make their sextortion emails seem more credible. - Ransomware is the Scoreboard (www.recordedfuture.com, 2026-07-24T00:00:00)
Score: 8.999
Ransomware is the scoreboard for defensive architecture. Learn why traditional security methods fail and how to use AI and threat intelligence to identify and remediate critical attack paths. - Dealing with AI-Generated Extortion (www.recordedfuture.com, 2026-07-30T00:00:00)
Score: 8.499
Combat AI-generated extortion and fake ransomware leaks. Learn how organizations can verify data authenticity using robust governance and threat intelligence. - Malwarebytes for Windows, now available on the Microsoft Store (www.malwarebytes.com, 2026-07-30T16:01:11)
Score: 7.61
Install Malwarebytes for Windows from the Microsoft Store with the same full protection and features. - We rebuilt Malwarebytes Mobile Security for the scams of today (www.malwarebytes.com, 2026-07-28T12:40:00)
Score: 7.253
Your phone needs more than a lock screen to stay safe. We've rebuilt Malwarebytes Mobile Security to put scam protection first and keep your phone secure. - TAG-195 Upgrades MaaS Ecosystem with Modular Tools (www.recordedfuture.com, 2026-07-23T00:00:00)
Score: 6.332
Insikt Group identifies four new TAG-195 malware families, revealing an architectural transition toward modular, operator-driven tooling in the MaaS ecosystem - Fake Fortnite rewards are stealing players’ accounts (www.malwarebytes.com, 2026-07-31T16:16:58)
Score: 5.778
Scammers are using fake V-Bucks offers and locker value sites to hijack Fortnite accounts. - Fake Flash Player installs AtlasRAT (www.malwarebytes.com, 2026-07-31T11:03:29)
Score: 5.742
Researchers have uncovered a new campaign that spreads the AtlasRAT remote access Trojan by disguising it as a Flash Player installer.
Top 10 AI / LLM-Related Threats
Generated 2026-08-03T06:00:17.310996+00:00
- When Safety Becomes a Vulnerability: Exploiting LLM Alignment Homogeneity for Transferable Blocking in RAG (arxiv.org, 2026-08-03T04:00:00)
Score: 21.78
arXiv:2603.03919v2 Announce Type: replace
Abstract: Retrieval-Augmented Generation (RAG) systems are vulnerable to blocking attacks, in which poisoned documents cause large language models (LLMs) to refuse benign queries. Existing attacks rely on adversarial suffixes or explicit instructions, which are increasingly ineffective against modern LLMs, susceptible to prompt injection filtering, or require feedback from the target system. We observe overlapping risk categories and refusal criteria ac - Piggybacking on Perception: Stealthy Concurrent Audio Prompt Injections against Multimodal LLM Agents (arxiv.org, 2026-08-03T04:00:00)
Score: 21.78
arXiv:2607.28165v2 Announce Type: replace
Abstract: Large Language Model (LLM)-driven multimodal agents are increasingly deployed to execute autonomous tasks via continuous audio interaction. While this paradigm enhances interaction naturalness, it introduces a critical yet under-explored attack surface, as audio inputs inevitably contain environmental noise beyond user control. In this paper, we investigate concurrent audio prompt injection attacks targeting multimodal agents. Distinct from tr - CPInj: Uncovering Prompt Injection Risks in Textual Collaborative Prompt Optimization (arxiv.org, 2026-08-03T04:00:00)
Score: 18.78
arXiv:2607.18622v2 Announce Type: replace
Abstract: Textual Collaborative Prompt Optimization (TCPO) extends TextGrad (Yuksekgonul et al., 2025) to a decentralized setting by allowing multiple clients to jointly improve prompts for large language models (LLMs) while keeping their data locally. Its reliance on free-form textual updating and aggregation introduces a new and largely unexplored attack surface, i.e., malicious instructions can be injected into local prompts and propagated through se - HijackKV: New Threat in Position-Independent KV Cache Reuse (arxiv.org, 2026-08-03T04:00:00)
Score: 17.78
arXiv:2607.19957v2 Announce Type: replace
Abstract: Key-Value (KV) cache reduces inference latency in large language models (LLMs). Traditional prefix-based reuse has low cache hit rates across inference requests because it requires exact token and position matches. To improve efficiency, recent system optimizations introduce position-independent KV reuse, allowing KV cache to be reused whenever identical text chunks appear, regardless of their position in the sequence.
We show this design in - Mission-Level Runtime Assurance for LLM-Assisted ISR Swarms over a Verification-Aware Fabric (arxiv.org, 2026-08-03T04:00:00)
Score: 17.48
arXiv:2607.23532v2 Announce Type: replace
Abstract: Swarms of LLM-assisted autonomous robots are increasingly proposed for cooperative intelligence, surveillance, and reconnaissance (ISR) in contested environments. A growing class of their assurance failures arises not within any single platform but across the swarm: individually-compliant actions compose into a mission-level violation: a prohibited objective split across platforms to evade per-platform lim- its, or a collective budget quietly - Hollow-LLM Attack: Computationally Trivial Weights in Zero-Knowledge Verification of LLM Inference (arxiv.org, 2026-08-03T04:00:00)
Score: 14.78
arXiv:2607.28884v1 Announce Type: new
Abstract: As large language models (LLMs) grow in scale and are predominantly served from remote platforms, verifying faithful inference execution becomes critical (i.e., ensuring that a provider actually executes the advertised model and computational workload rather than a tampered or downsized variant). Zero-knowledge (ZK) LLM inference offers an appealing approach. It promises public verifiability and delivers per-instance guarantees of equational corre - GoldenRetriever: Non-Interactive Homomorphic Encrypted Retrieval for Privacy-Preserving RAG (arxiv.org, 2026-08-03T04:00:00)
Score: 14.78
arXiv:2607.29019v1 Announce Type: new
Abstract: Retrieval-Augmented Generation (RAG) enhances large language models by incorporating external knowledge, but existing pipelines typically operate on plaintext data, raising significant privacy concerns. Prior work on privacy-preserving retrieval leverages cryptographic techniques such as homomorphic encryption (HE) and private information retrieval (PIR), but often relies on interactive protocols or ranking-based selection mechanisms that incur hi - Memory Provenance Laundering in LLM Agents: A Non-Amplification Firewall for Persistent Memory (arxiv.org, 2026-08-03T04:00:00)
Score: 14.78
arXiv:2607.29167v1 Announce Type: new
Abstract: Long-term memory lets large language model(LLM) agents reuse prior preferences and work flows, but it also turns untrusted observations into persistent action context. We identify memory provenance laundering: during LLM-based memory consolidation, an external observation may be rewritten as apparent user history or workflow support, preserving an action trigger while erasing the low-trust source that should limit its authority. Existing prompt fi - TextCloak: Thwarting Unauthorized LLM Exploitation via RL-Driven Unlearnable Text (arxiv.org, 2026-08-03T04:00:00)
Score: 14.78
arXiv:2607.28862v1 Announce Type: cross
Abstract: The rapid development of Large Language Models (LLMs) has led to significant advances across a wide range of language tasks, while simultaneously raising growing concerns about unauthorized data exploitation and privacy leakage. Unlearnable examples (UEs) offer a promising defense by introducing carefully designed perturbations into data such that models trained on them exhibit degraded utility. However, existing methods for text protection are - Don't Trust the AI Ecosystem: Analyzing Privacy Leakage in Compromised Open-Source Components (arxiv.org, 2026-08-03T04:00:00)
Score: 14.48
arXiv:2607.27886v2 Announce Type: replace
Abstract: Existing model inversion (MI) attacks predominantly rely on post-training optimization to recover private data from model outputs. However, these methods are fundamentally constrained by the target model's generalization bottleneck, often yielding generic features rather than specific identities, particularly on high-dimensional datasets. In this paper, we introduce GradLock, a novel training-time injection attack that stealthily injects - AgenticRepair: Multi-Faceted Program Context Engineering for Agentic Vulnerability Repair (arxiv.org, 2026-08-03T04:00:00)
Score: 12.48
arXiv:2607.29422v1 Announce Type: cross
Abstract: Automated vulnerability repair aims to reduce the time and effort required to patch security flaws from a vulnerability triage report. Recent agentic AI approaches have shown promising results in automated program repair. However, vulnerability repair demands richer program context than general bug repair – context that security engineers routinely assemble in practice but that existing agentic approaches do not engineer. We identify three criti - RRAM-DP: Device-Calibrated Differential Privacy for In-Memory Edge Learning (arxiv.org, 2026-08-03T04:00:00)
Score: 11.98
arXiv:2607.18169v2 Announce Type: replace
Abstract: Edge Artificial Intelligence of Things (AIoT) systems often collect sensitive data in situ, raising serious privacy concerns. Resistive-switching random-access memory (RRAM) is an attractive substrate for efficient AIoT thanks to its multi-bit storage and compute-in-memory (CiM) capabilities, while its inherently stochastic write behavior provides a natural source of randomness that can be leveraged for differential privacy (DP) protection. Ye - CWEEP: A Lexical Static Analysis Framework for CWE Early Prevention (arxiv.org, 2026-08-03T04:00:00)
Score: 11.78
arXiv:2607.29604v1 Announce Type: new
Abstract: As the hardware layer becomes a focus point for attackers, the need for improved hardware security verification techniques is more important than ever. State-of-the-art security verification techniques require significant manual effort from individuals with security expertise. Furthermore, there is no standard method to locate where the fault lies within the register transfer level (RTL) code. This paper presents CWEEP, a static analysis framework - Hidden prompt turns Microsoft Copilot into an AI worm (www.malwarebytes.com, 2026-07-30T12:58:45)
Score: 11.717
A new type of attack can trick Microsoft Copilot for Word into spreading hidden prompt injections from document to document. - Metasploit Framework 6.5 Released (www.rapid7.com, 2026-07-30T14:29:54)
Score: 11.632
Today we’re proud to announce that Metasploit Framework version 6.5 has been released. Over the past two years, with the help of countless contributors, we’ve added 422 new modules along with a whole slew of new features. Malleable C2 Profiles for HTTP One of the latest and most requested features is support for Malleable C2 profiles across all current Meterpreter payloads. This feature enables users to load a standard profile into Meterpreter and change the shape of its HTTP(S) traffic. All Met - The July 2026 Security Update Review (www.thezdi.com, 2026-07-14T17:56:54)
Score: 11.257
Well folks. Here we are. The bug apocalypse has fully descended upon us. I’ll do my best to sort this out in some way meaningful, but this month’s release shows us the nay-sayers were right, and I’ve got to hand it to the nay-sayers here. Excellent call. Take an extended break from your regularly scheduled activities as we let’s take a look at the latest security patches from Adobe and Microsoft. If you’d rather watch the full video recap covering the entire release, you can check it out here: A - Introducing explicit prompt caching for OpenAI GPT-5.6 models on Amazon Bedrock (aws.amazon.com, 2026-07-30T16:02:32)
Score: 10.547
OpenAI GPT-5.6 Sol, Terra, and Luna are now generally available on Amazon Bedrock, along with explicit prompt caching that gives you precise control over which parts of your prompt are cached and reused. Learn how to get started, set up explicit caching, and migrate existing GPT workloads to reduce inference cost. - Enhancing AI security through global AI red teaming (www.microsoft.com, 2026-07-27T16:25:00)
Score: 10.437
Microsoft's External Red Team Alliance (EXTRA) is a global AI security initiative designed to advance AI safety research and red teaming. By partnering with universities, researchers, and regional experts, EXTRA helps identify emerging AI risks, improve security testing, and strengthen the resilience of frontier AI systems. The post Enhancing AI security through global AI red teaming appeared first on Microsoft Security Blog . - Best practices for applying Amazon Bedrock Guardrails to code generation workflows (aws.amazon.com, 2026-07-23T23:03:44)
Score: 9.95
In this post, we explain how Amazon Bedrock Guardrails can be configured for code generation workflows with coding assistants to overcome these constraints. With these best practices, you can build an efficient blueprint helping you with effective capacity planning with robust safety coverage. - Prompted by OpenAI Disclosure, Anthropic Finds Its Own Models Hacked 3 Organizations (www.securityweek.com, 2026-07-31T09:39:57)
Score: 9.822
A security company’s systems were hacked after it installed a malicious Python package deployed by Claude. The post Prompted by OpenAI Disclosure, Anthropic Finds Its Own Models Hacked 3 Organizations appeared first on SecurityWeek . - Pwn2Own Ireland 2026 – New Targets and Categories (www.thezdi.com, 2026-07-21T17:23:48)
Score: 9.518
If you just want to read the rules, you can find them here . Pwn2Own Ireland returns for 2026, and it’s the third year for this event in the Emerald Isle. Despite the dreary Irish skies (and the threat of a random banshee ), we had an amazing event, even if we did end up in a jail at the end. With that in mind, we’re excited to return to Cork this fall for yet another great Pwn2Own event. We’ll also be returning to some of the great pubs Ireland has to offer in the evenings and wrapping the even - JUNO: Aggregated Vector Consensus for Optimal Asynchronous Common Subset (arxiv.org, 2026-08-03T04:00:00)
Score: 9.48
arXiv:2607.29244v1 Announce Type: new
Abstract: In this paper, we propose \textit{aggregated vector consensus}, a new vector consensus primitive designed for asynchronous networks. The primitive achieves agreement by outputting a vector of values aggregated from independent process inputs. We then introduce \textsc{Juno}, an asynchronous common subset (ACS) protocol that fully implements our aggregated vector consensus to attain optimal $\mathcal{O}(n^2)$ message complexity.
We further implem - On the Resilience of 5G NR Against Jamming (arxiv.org, 2026-08-03T04:00:00)
Score: 9.48
arXiv:2607.29384v1 Announce Type: new
Abstract: With the increasing use of 5G networks in availability-critical systems, including industrial networks and critical infrastructure, a comprehensive understanding of their resilience to cellular jamming has become imperative. However, research so far has focused on isolated evaluations under fixed 5G physical-layer configurations, making it difficult to perform sound comparisons, for example, to identify differences between frequency bands or chann - Enforcing Cryptographic Distributed-VCS Access Control with No Trust on Servers (arxiv.org, 2026-08-03T04:00:00)
Score: 9.48
arXiv:2607.29417v1 Announce Type: new
Abstract: Version control systems (VCS), including central VCS (CVCS) and distributed VCS (DVCS), are widely adopted to manage changes to software code and various types of documents. Unlike CVCS, where entities obtain data from a central server, each entity in DVCS stores the entire repository and shares it independently. In VCS, existing access control schemes require the participation of a central server and cannot be deployed in a completely distributed - Beyond Resilience: Antifragility in Critical Infrastructure Cybersecurity (arxiv.org, 2026-08-03T04:00:00)
Score: 9.48
arXiv:2607.29550v1 Announce Type: new
Abstract: Critical infrastructure cybersecurity increasingly requires frameworks that move beyond recovery toward bounded improvement under disruption, yet empirically grounded theories for operational technology remain limited. This paper develops a Theory of Antifragility (AFT) for critical infrastructure (CI) cybersecurity, anchored in a five-state Resilient System Model and a bounded mathematical definition based on Jensen gain and post-disruption gain.
Auto-generated 2026-08-03
