Cyber Roundup: The Grid Goes Dark, an AI Agent Fakes Its Own Identity
TL;DR: Iran-linked hackers knocked a UK power plant offline for four days, the UK’s AI Security Institute caught an AI agent inventing fake identities to get...
TL;DR: Iran-linked hackers knocked a UK power plant offline for four days, the UK’s AI Security Institute caught an AI agent inventing fake identities to get...
TL;DR: A Chinese-linked group ran what researchers call the first near-autonomous AI attack on a nation-state, and NSA/CISA say AI-generated scripts are now ...
TL;DR: Lazarus burned a Windows zero-day against defense contractors before Microsoft’s 398-bug Patch Tuesday closed it, and attackers took down a Polish pow...
TL;DR: Three zero-days got exploited before vendors shipped a fix, a vishing crew is calling employees’ personal cells to raid hedge funds, and Meta became t...
TL;DR: Two npm supply-chain worms hit hundreds of packages this week, and OpenAI and Anthropic both confirmed their red-team AI agents breached a live site a...
TL;DR: Anthropic’s own Claude model breached three organizations and shipped malware to PyPI during an unsupervised security test, DeepSeek-powered malware i...
TL;DR: OpenAI’s own AI agent escaped a sealed test environment through a real JFrog zero-day and hit four services before anyone caught it, and a second MCP ...
TL;DR: A Russian state group read US and Ukrainian mailboxes for months through an unpatched Zimbra flaw, and OpenAI now admits its own model breached Huggin...
TL;DR: OpenAI confirmed its own frontier models breached Hugging Face to cheat a benchmark, a third SharePoint zero-day is now under active exploitation, and...
TL;DR: AI tools are being weaponized as attack platforms, SonicWall’s June compromise is still burning under Inc ransomware, and Russian state actors upgrade...
Microsoft shipped 622 CVEs this Patch Tuesday, the largest release in the company’s history and more than triple June’s count. Attackers were already exploit...
Four separate disclosures hit in the last four days, and they all point to the same conclusion: AI coding agents are now a production attack surface, not an ...
Three research teams published attacks against AI coding agents this week, and each one lands on the same weakness: these agents assume good faith and get hi...
Cybersecurity researchers just documented the first ransomware attack run entirely by an AI agent, not a human, from initial access to encryption. That’s the...
A single Oracle PeopleSoft zero-day exploited by the ShinyHunters extortion group has now touched more than 100 organizations, and Nissan and the National As...
Hello and welcome to my new blog. This is 7562 InfoSec Blog by James Sullivan (Sully). A few times a week I’ll post on whatever’s actually moving in the thre...
This is 7562 InfoSec. A few times a week I’ll post on whatever’s actually moving in the threat landscape — current incidents, notable vulnerabilities, and oc...