Weekly Threat Intelligence Summary
Top 10 General Cyber Threats
Generated 2026-07-27T05:00:05.898205+00:00
- Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite (www.cisa.gov, 2026-07-21T19:08:02)
Score: 20.398
Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite Executive summary A group of Russian state-supported cyber actors has been targeting and compromising various Western government and commercial organizations using the Zimbra Collaboration Suite (ZCS) software since at least July 2025. The Russian state-supported advanced persistent threat (APT) group’s activity is tracked in the cybersecurity community under several names (see Cybersecur - What happens if you visit a WordPress site hacked through wp2shell? (www.malwarebytes.com, 2026-07-21T14:57:27)
Score: 10.769
Attackers started exploiting the critical wp2shell vulnerability chain within hours of patches being released, putting sites and their visitors at risk. - Improve Router Hygiene to Protect Against Russian State-Sponsored Targeting (www.cisa.gov, 2026-07-08T18:43:49)
Score: 10.729
Russian Government-Sponsored Activity Targets Poorly Configured and Vulnerable Devices Across Critical Sectors Executive summary Russian Federal Security Service (FSB) Center 16 cyber actors continue to exploit poorly configured and vulnerable networking devices worldwide, opportunistically compromising multiple critical infrastructure sector networks. This joint Cybersecurity Advisory (CSA) builds on FBI’s Russian Government Cyber Actors Targeting Networking Devices, Critical Infrastructure Pub - Ransomware is the Scoreboard (www.recordedfuture.com, 2026-07-24T00:00:00)
Score: 10.165
Ransomware is the scoreboard for defensive architecture. Learn why traditional security methods fail and how to use AI and threat intelligence to identify and remediate critical attack paths. - July 2026 Patch Tuesday: Microsoft Patches 622 Vulnerabilities Including Two Exploited Zero-Days (www.crowdstrike.com, 2026-07-14T05:00:00)
Score: 9.033 - Beyond the Play Store: How Android threats really spread (www.malwarebytes.com, 2026-07-24T12:00:00)
Score: 7.749
Some threats never pass through the Play Store. Others arrive later in seemingly legitimate updates. Here's how Malwarebytes detects both. - WhatsApp Web chats exposed by Adobe’s Acrobat extension flaw (www.malwarebytes.com, 2026-07-23T11:24:04)
Score: 7.578
HermeticReader is a now-patched vulnerability in Adobe's popular Acrobat Chrome extension that could have been used to spy on WhatsApp Web users. - TAG-195 Upgrades MaaS Ecosystem with Modular Tools (www.recordedfuture.com, 2026-07-23T00:00:00)
Score: 7.499
Insikt Group identifies four new TAG-195 malware families, revealing an architectural transition toward modular, operator-driven tooling in the MaaS ecosystem - The Odyssey piracy scams appear within hours of the movie’s release (www.malwarebytes.com, 2026-07-20T15:41:26)
Score: 7.108
The release of The Odyssey has already sparked a wave of piracy scams, from fake browser errors to malware masquerading as movie files. - Fake games spread stealers with RenPy Loader, MSBuild and EtherHiding (www.malwarebytes.com, 2026-07-20T10:59:45)
Score: 7.075
We look into how attackers are using the legitimate Ren'Py game engine to spread a malware loader that ultimately delivers Amatera Stealer.
Top 10 AI / LLM-Related Threats
Generated 2026-07-27T06:00:17.947537+00:00
- SIREN (Luring LLMs onto the Rocks): PAIR-Driven Preference Manipulation in Web-RAG Recommenders (arxiv.org, 2026-07-27T04:00:00)
Score: 22.78
arXiv:2607.21951v1 Announce Type: cross
Abstract: This paper investigates the adversarial manipulation of the ranked recommendations produced by web-augmented large language models (LLMs). When an LLM answers a recommendation query by retrieving and reading live webpages, it acts as a recommender, and each retrieved page becomes a potential attack surface. Prior work has examined fabricated products, retrieval poisoning, and rank promotion. However, these studies do not compare how different ed - DeFiScreener: Efficient DeFi Attack Pre-screening in Smart Contracts via Historical Case Matching (arxiv.org, 2026-07-27T04:00:00)
Score: 19.78
arXiv:2607.22184v1 Announce Type: new
Abstract: Blockchain and its killer applications, particularly decentralized finance (DeFi), are gaining widespread adoption, with over 5,200 DeFi projects deployed on mainstream blockchains as of January 2026. At the same time, security risks in DeFi are becoming increasingly serious. However, existing DeFi detection tools usually cover only specific attack types, exhibiting severely limited detection coverage.
In this paper, we argue that an effective w - HarnessLLM: Rust Verification Harness Generation with Large Language Models (arxiv.org, 2026-07-27T04:00:00)
Score: 17.78
arXiv:2607.22161v1 Announce Type: cross
Abstract: Rust's ownership model and type system offer strong memory safety guarantees, but unsafe code and runtime panics still present significant risks. Formal verification is essential to ensure memory safety, but developing verification harnesses remains a challenging and manual task. Although large language models (LLMs) have shown strong performance in various code analysis tasks, directly applying them to harness generation often results in i - Building trade assistant: How Jefferies optimized front office trading operations with AI (aws.amazon.com, 2026-07-23T16:42:54)
Score: 16.854
In this post, we explore how Jefferies overcame these challenges with a solution built on Strands Agents, an agent harness SDK for building AI agents that can reason, plan, and act by orchestrating calls to foundation models (FMs) and external tools. The solution uses large language models (LLMs), Amazon Bedrock, and Amazon Bedrock Knowledge Bases. It also uses Model Context Protocol (MCP), an open standard that helps AI agents securely connect to diverse data sources and tools through a unified - Weekly Metasploit Update: Exploits for FlowiseAI CSV Agent and MacOS Package Kit (www.rapid7.com, 2026-07-11T00:32:34)
Score: 15.636
More AI, more software, more bugs! AI, it's all you hear about nowadays and everyone's got an opinion on it. Here at Metasploit, we care less about those opinions and more about the growing attack surface all this new software brings with it (yeehaw exploits!). Take for example the new Flowise CSV Agent Prompt Injection RCE brought to you by Takahiro Yokoyama and zdi-disclosures. Flowise is an open-source tool that lets you build AI apps and chatbots using a visual, drag-and-drop canva - CARE: Pre-Execution Command Verification for Shell-Executing LLM Agents (arxiv.org, 2026-07-27T04:00:00)
Score: 14.78
arXiv:2607.21642v1 Announce Type: new
Abstract: Large Language Model (LLM) agents are increasingly used for coding and terminal automation, making shell-command dispatch a high-stakes runtime control point. We study command-level pre-execution mediation for individual shell commands produced by LLM agents under bounded path context. Existing safeguards remain limited: generic guardrails do not model shell structure in sufficient detail, always-on LLM judges are relatively costly and variable, a - Every Model Cheats: Prompt-Level Mitigation of Cheating on Offensive Cyber Tasks (arxiv.org, 2026-07-27T04:00:00)
Score: 14.78
arXiv:2607.21763v1 Announce Type: new
Abstract: Large language model (LLM) agents routinely cheat on cybersecurity benchmarks, inflating reported pass rates far beyond genuine capability. Prior audits of Cybench found cheating in 0.3-3.4% of traces, implicating only a handful of models. We present a controlled prompt-ablation study across 22 frontier models from 7 providers on 23 Cybench capture-the-flag (CTF) challenges under three prompt conditions (no anti-cheat, standard, severe). All 1,518 - Ethereum NFT Smart Contracts: Knowledge-Guided Vulnerability Detection with LLM and Code Slicing (arxiv.org, 2026-07-27T04:00:00)
Score: 14.78
arXiv:2607.21983v1 Announce Type: new
Abstract: Ethereum non-fungible tokens (NFTs) implement ownership, transfer, authorization, and metadata operations through smart contracts, making contract vulnerabilities a direct risk to digital assets. Existing static analyzers provide efficient rule-based screening but can struggle with application-specific logic, whereas unconstrained large language model analysis may be distracted by irrelevant code or produce inconsistent outputs. We present a vulne - KaPilot: LLM-Assisted Generation of Kani Specifications for Unsafe Rust Verification (arxiv.org, 2026-07-27T04:00:00)
Score: 14.78
arXiv:2607.21957v1 Announce Type: cross
Abstract: Rust's ownership and type system provide strong memory safety guarantees, but unsafe code still presents memory safety risks. Formal verification is crucial for ensuring memory safety, but writing precise specifications for unsafe Rust is challenging and largely manual. Large language models (LLMs) have shown promise in generating formal specifications but are often code-centric, prone to inheriting implementation flaws, and lack systematic - REFORGE: A Method for Benchmarking LLMs' Reverse Engineering Capabilities in Decompiled Binary Function Naming (arxiv.org, 2026-07-27T04:00:00)
Score: 14.78
arXiv:2607.07738v2 Announce Type: replace-cross
Abstract: Large language models (LLMs) are increasingly applied to reverse-engineering tasks, and recent threat-intelligence reporting shows them operating inside live offensive-security workflows. Claims about their capability, however, outpace our ability to measure it. Existing benchmarks for LLM-assisted binary analysis treat the construction of function-level ground truth as a solved pre-processing step and report accuracy without disclosing - Agent Security Needs Redefinition through a Holistic Framework (arxiv.org, 2026-07-27T04:00:00)
Score: 14.48
arXiv:2607.22024v1 Announce Type: new
Abstract: Agent security is widely treated as a question about action content. Defenses ask whether an instruction looks malicious. Benchmarks ask whether an agent performs a harmful sounding action. \textbf{We argue that agent security is fundamentally a contextual problem, and that the current content based framing systematically misdefines it.} A command to “delete user data'' might be a routine administrative request or a prompt injection att - The July 2026 Security Update Review (www.thezdi.com, 2026-07-14T17:56:54)
Score: 12.923
Well folks. Here we are. The bug apocalypse has fully descended upon us. I’ll do my best to sort this out in some way meaningful, but this month’s release shows us the nay-sayers were right, and I’ve got to hand it to the nay-sayers here. Excellent call. Take an extended break from your regularly scheduled activities as we let’s take a look at the latest security patches from Adobe and Microsoft. If you’d rather watch the full video recap covering the entire release, you can check it out here: A - PoCEvolve: Generating Proof-of-Concept Exploits from Security Patches with Vulnerability-Aware Prompt Evolution (arxiv.org, 2026-07-27T04:00:00)
Score: 12.48
arXiv:2607.22076v1 Announce Type: new
Abstract: Ideally, the detailed information about a vulnerability should be made available together with the fixing commit. In practice, however, such details often become available only long after the commit, even when a CVE has already been published. During this window, the patch is already public, so attackers can reverse-engineer it, yet defenders lack the details needed to assess exposure, prioritize, and validate the fix. Executable evidence, such as - NWaaS: A Non-Intrusive and Privacy-Preserving Watermarking-as-a-Service System with Adaptive Resource Scheduling (arxiv.org, 2026-07-27T04:00:00)
Score: 12.48
arXiv:2507.18036v2 Announce Type: replace
Abstract: Securing intellectual property (IP) in Machine Learning as a Service is critical yet challenging. While deep neural network watermarking serves as a standard defense against model extraction, existing Watermarking-as-a-Service paradigms face a triple challenge of intrusiveness, privacy risks, and inefficiency. To address these challenges, we propose Non-intrusive Watermarking as a Service (NWaaS), a holistic framework enabling trustworthy and - ASEval: Automated Trajectory-Level Security Testing for Autonomous Agents (arxiv.org, 2026-07-27T04:00:00)
Score: 12.48
arXiv:2605.22321v2 Announce Type: replace
Abstract: As autonomous agents (e.g., OpenClaw) increasingly operate with deep system-level privileges to execute complex tasks, they introduce severe, unmitigated security risks. Existing LLM safety testing methods are largely built around prompt-level inputs and response-level judgments, while recent agent benchmarks remain limited in automation, trajectory coverage, and action-grounded judgment. In this work, we present ASEval, a novel automated secu - Decentralized Compute on Untrusted Hardware Using Intel TDX and Encrypted CVMs (arxiv.org, 2026-07-27T04:00:00)
Score: 11.98
arXiv:2607.21865v1 Announce Type: new
Abstract: The rapid growth of artificial intelligence workloads has generated an unprecedented demand for secure and scalable compute resources. However, centralized cloud providers continue to dominate both pricing and security models. In an increasingly competitive AI landscape, where the compromise of training data or model weights can confer a significant advantage, there is a critical need for a computing infrastructure that safeguards data at rest, in - Best practices for applying Amazon Bedrock Guardrails to code generation workflows (aws.amazon.com, 2026-07-23T23:03:44)
Score: 11.617
In this post, we explain how Amazon Bedrock Guardrails can be configured for code generation workflows with coding assistants to overcome these constraints. With these best practices, you can build an efficient blueprint helping you with effective capacity planning with robust safety coverage. - ToolGuardian: Declarative Security for AI Agent-Tool Interactions (arxiv.org, 2026-07-27T04:00:00)
Score: 11.48
arXiv:2607.21835v1 Announce Type: new
Abstract: LLM agents increasingly rely on external tools, expanding capability while creating a new security boundary: third-party tools may appear benign at the interface level while embedding unsafe behavior in implementation. Existing defenses rely on weak metadata, collapse characterization and policy judgment into a single decision, or use heuristic/LLM enforcement that lacks deterministic, auditable reasoning over task context and multi-tool compositi - BioZKFHE: Scalable Encrypted Biometric Identification via Verifiable Homomorphic Similarity Evaluation (arxiv.org, 2026-07-27T04:00:00)
Score: 11.48
arXiv:2607.22065v1 Announce Type: new
Abstract: Large-scale biometric identification in outsourced settings requires two properties simultaneously: biometric templates and queries must remain protected during computation, and the encrypted similarity outputs produced by an untrusted compute node must be verifiably correct before any application result is released. Existing FHE-based biometric systems primarily address confidentiality, while practical verifiability introduces two bottlenecks in - Pwn2Own Ireland 2026 – New Targets and Categories (www.thezdi.com, 2026-07-21T17:23:48)
Score: 11.184
If you just want to read the rules, you can find them here . Pwn2Own Ireland returns for 2026, and it’s the third year for this event in the Emerald Isle. Despite the dreary Irish skies (and the threat of a random banshee ), we had an amazing event, even if we did end up in a jail at the end. With that in mind, we’re excited to return to Cork this fall for yet another great Pwn2Own event. We’ll also be returning to some of the great pubs Ireland has to offer in the evenings and wrapping the even - Patch Tuesday – July 2026 (www.rapid7.com, 2026-07-14T22:00:26)
Score: 10.964
Microsoft is publishing 622 vulnerabilities on July 2026 Patch Tuesday , including a record-breaking 416 Windows vulnerabilities. Microsoft is aware of exploitation in the wild for two of the vulnerabilities published today, both of which are listed on CISA KEV, as well as public disclosure for one other. As usual, browser vulns are not included in the Patch Tuesday count above. Rapid7 noted last month that Microsoft no longer enumerates Chromium CVEs in the Security Update Guide. However, Micro - From a Single Alert to 1,000 Files: Inside an Exposed WebDAV Malware Delivery Lab (www.rapid7.com, 2026-07-20T13:00:00)
Score: 10.903
Executive summary An MDR alert recently led our team to an exposed server that was doing more than hosting payloads. It was functioning as a fully operational malware delivery lab. Containing over 1,000 artifacts, the infrastructure served as a QA hub where attackers systematically tested delivery paths, social engineering lures, and WebDAV execution methods. Our analysis reveals an interesting shift in adversary operations: attackers are adopting generative AI to move beyond individual exploits - Introducing Claude Opus 5 on AWS: Anthropic’s most capable Opus model (aws.amazon.com, 2026-07-24T17:59:03)
Score: 10.805
This post covers Opus 5’s improvements and practical guidance for AI engineers integrating the model into agentic systems and production inference workloads on Amazon Bedrock. See the documentation for Claude Platform on AWS. - Get started with OpenAI GPT-5.6 Sol, Terra, and Luna on Amazon Bedrock (aws.amazon.com, 2026-07-24T15:40:08)
Score: 10.782
OpenAI GPT-5.6 Sol, Terra, and Luna are now generally available on Amazon Bedrock. Learn how to select a model, run inference through the Responses API on the bedrock-mantle endpoint, reduce cost with prompt caching, connect the OpenAI Codex coding agent, and plan for quotas and scaling. - Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite (www.cisa.gov, 2026-07-21T19:08:02)
Score: 10.702
Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite Executive summary A group of Russian state-supported cyber actors has been targeting and compromising various Western government and commercial organizations using the Zimbra Collaboration Suite (ZCS) software since at least July 2025. The Russian state-supported advanced persistent threat (APT) group’s activity is tracked in the cybersecurity community under several names (see Cybersecur
Auto-generated 2026-07-27
