
Coverage: Last 24 hours
Today’s Highlights
This cycle signals steadily increasing risk for defenders of AI and SaaS environments, with active ransomware targeting AI assets, mass malware propagation through GitHub, and confirmed exploitation of a critical ServiceNow flaw. Operational visibility gaps, rapid exploit chains, and unreliable AI outputs all compound organizations’ risk exposure. Key themes include the emergence of AI-targeted ransomware, the wide abuse of open-source and cloud platforms for malware delivery, accelerating SaaS exploit cycles, and amplified operational risk stemming from unvalidated AI integrations.
Table of Contents
- Critical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code Execution
- ⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More
- Mythos Didn’t Break Your Security Program. Your Exposure Window Could.
- Not enough water for UK’s datacentre plans, trade body says
- New ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attack
- FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware
- Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign
- Russian-Speaking Hacker Uses Google Gemini CLI to Control Botnet of Eight Dental Clinic PCs
- Election voting advice from AI chatbots ‘inaccurate and unreliable’
- Man of his word: Pope Leo speeches declared human-authored by Australian AI detection tool
- Nine to axe 30 jobs at the Age and SMH due to ‘extreme’ AI disruption
- Jeff Bezos and UK government invest in £2bn British startup CuspAI
Top Stories
Critical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code Execution
Source: The Hacker News | Risk: Critical | Impacted: ServiceNow AI Platform tenants, Enterprises with integrated SaaS workflows, Business units automating with ServiceNow AI
Summary: Threat actors are now exploiting a recently disclosed critical security flaw impacting ServiceNow AI Platform, according to Defused Cyber. In a post shared on X, the threat intelligence firm said it’s observing in-the-wild exploitation of CVE-2026-6875 (CVSS score: 9.5), a sandbox escape vulnerability that could allow an unauthenticated user to run arbitrary code. Patches for the flaw were
Why it matters: Active exploitation of this sandbox escape puts all code, data, and integrations in affected ServiceNow AI Platform instances at risk, potentially leading to full tenant compromise or supply chain attacks.
Practitioner Perspective
Any organization using ServiceNow AI Platform should assume exploitation is possible or already underway. The CVE-2026-6875 issue enables unauthenticated remote code execution and defeats key containerization boundaries on SaaS AI services. Dependence on platform-supplied security controls is insufficient, and integrations or automated workflows could be abused for lateral movement. Incident responders need to prepare for visibility gaps in SaaS audit trails for surfacing unauthorized actions post-compromise.
Recommended Actions
- Apply the official CVE-2026-6875 patch to all ServiceNow AI Platform instances without delay.
- Review audit logs for unusual execution or unauthorized user actions since vulnerability disclosure.
⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More
Source: The Hacker News | Risk: High | Impacted: Organizations with public SaaS or WordPress deployments, Teams using SonicWall or SharePoint, Infrastructure management teams
Summary: A single request should not be able to do this much. But this week, small inputs led to code execution, memory loss, stolen keys, and disabled security tools. The paths were often simple: exposed systems, weak checks, old drivers, fake prompts, and public code used for malware delivery. Some bugs were new. Others were already being used before defenders had
Why it matters: Fast-moving exploit cycles and vulnerable defaults in major platforms increase the chance that attackers will land code execution or credential access before security teams can detect and respond on critical infrastructure.
Practitioner Perspective
The volume and operational diversity of this week’s exploit news points to an urgent need for minimizing exposure windows. Common paths to compromise are through public-facing SaaS apps, outdated drivers, and misconfigurations. These trends reinforce that security response must prioritize rapid remediation for newly disclosed vulnerabilities. Organizations stuck in static patch cycles or relying just on preventive controls will not keep pace with emerging threats.
Recommended Actions
- Immediately review recent WordPress and SonicWall vulnerability advisories and apply mitigations for any in-use versions.
- Scrutinize authentication flows and key management for SharePoint deployments for signs of abuse.
Emerging Signals
Mythos Didn’t Break Your Security Program. Your Exposure Window Could.
Source: The Hacker News | Risk: Medium | Impacted: Vulnerability management teams, Organizations tracking Mythos findings, Risk managers
Summary: The industry spent the initial months after Anthropic’s April 7 Mythos reveal focused on volume. How many new CVEs would Mythos add to an already overloaded pipeline? How quickly would the flood of AI-driven discovery overwhelm triage capabilities? How long would it take adversaries to weaponize Mythos findings at scale? Those questions were and remain valid. Yet they all stop
Why it matters: Unchecked exposure windows leave organizations vulnerable to newly weaponized vulnerabilities, regardless of how quickly they triage CVEs or add detection rules.
Practitioner Perspective
The scale and speed of CVE publication, especially via automated AI-driven discovery like Mythos, is overwhelming traditional vulnerability management workflows. Attackers exploit the lag between vulnerability disclosure, patch development, and deployment. Security teams must focus not only on ingesting threat intelligence but on reducing the effective time systems are left exposed after a finding is published. Prioritize process automation, rollback readiness, and communication so that response keeps up with discovery velocity.
Recommended Actions
- Map out exposure windows from CVE disclosure to remediation for your most critical systems.
- Automate playbooks for applying patches or mitigations when high-priority Mythos-driven vulnerabilities emerge.
Not enough water for UK’s datacentre plans, trade body says
Source: The Guardian | Risk: Medium | Impacted: UK-based data center operators, Cloud service providers, Organizations with colocation dependencies
Summary: Industry says government’s failure to address cooling demands means AI growth plans are ‘fatally flawed’ The UK will not have enough water for future datacentres, the water industry has said in stark criticism of the government’s AI growth plans. Datacentres rely on large amounts of water to manage the heat generated by densely packed servers. Cooling towers, chillers and humidification
Why it matters: Physical supply constraints, such as water for cooling, directly threaten continuity and resilience of both hosting and security infrastructure in hyperscale and critical data centers.
Practitioner Perspective
Security and risk teams should not overlook environmental and physical limitations when assessing overall cyber risk. Planned AI and cloud expansion may be stalled or rendered unreliable if water shortages disrupt data center operations. Risk models and incident response plans must now factor in loss of cooling and related cascading failures, especially as denser compute workloads accelerate utility dependencies.
Recommended Actions
- Engage with facilities partners to verify alternate cooling contingency plans for your hosted infrastructure.
- Map critical business services to affected data centers and pre-plan failover for loss-of-cooling scenarios.
Exploits & CVEs
Critical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code Execution
Source: The Hacker News | Risk: Critical | Impacted: ServiceNow AI Platform tenants, Enterprises with integrated SaaS workflows, Business units automating with ServiceNow AI
Summary: Threat actors are now exploiting a recently disclosed critical security flaw impacting ServiceNow AI Platform, according to Defused Cyber. In a post shared on X, the threat intelligence firm said it’s observing in-the-wild exploitation of CVE-2026-6875 (CVSS score: 9.5), a sandbox escape vulnerability that could allow an unauthenticated user to run arbitrary code. Patches for the flaw were
Why it matters: Active exploitation of this sandbox escape puts all code, data, and integrations in affected ServiceNow AI Platform instances at risk, potentially leading to full tenant compromise or supply chain attacks.
Practitioner Perspective
Any organization using ServiceNow AI Platform should assume exploitation is possible or already underway. The CVE-2026-6875 issue enables unauthenticated remote code execution and defeats key containerization boundaries on SaaS AI services. Dependence on platform-supplied security controls is insufficient, and integrations or automated workflows could be abused for lateral movement. Incident responders need to prepare for visibility gaps in SaaS audit trails for surfacing unauthorized actions post-compromise.
Recommended Actions
- Apply the official CVE-2026-6875 patch to all ServiceNow AI Platform instances without delay.
- Review audit logs for unusual execution or unauthorized user actions since vulnerability disclosure.
⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More
Source: The Hacker News | Risk: High | Impacted: Organizations with public SaaS or WordPress deployments, Teams using SonicWall or SharePoint, Infrastructure management teams
Summary: A single request should not be able to do this much. But this week, small inputs led to code execution, memory loss, stolen keys, and disabled security tools. The paths were often simple: exposed systems, weak checks, old drivers, fake prompts, and public code used for malware delivery. Some bugs were new. Others were already being used before defenders had
Why it matters: Fast-moving exploit cycles and vulnerable defaults in major platforms increase the chance that attackers will land code execution or credential access before security teams can detect and respond on critical infrastructure.
Practitioner Perspective
The volume and operational diversity of this week’s exploit news points to an urgent need for minimizing exposure windows. Common paths to compromise are through public-facing SaaS apps, outdated drivers, and misconfigurations. These trends reinforce that security response must prioritize rapid remediation for newly disclosed vulnerabilities. Organizations stuck in static patch cycles or relying just on preventive controls will not keep pace with emerging threats.
Recommended Actions
- Immediately review recent WordPress and SonicWall vulnerability advisories and apply mitigations for any in-use versions.
- Scrutinize authentication flows and key management for SharePoint deployments for signs of abuse.
AI Security
New ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attack
Source: The Hacker News | Risk: High | Impacted: AI/ML infrastructure operators, Langflow server admins, Organizations with self-hosted AI models
Summary: Researchers at Sysdig have linked a second attack on the same Langflow server to JADEPUFFER, the AI-agent-driven operator it first documented earlier this month. The same operator has now been spotted deploying ENCFORGE, a new compiled Go ransomware designed to encrypt model weights, vector indexes, training datasets, and other AI infrastructure files across the host filesystem. The entry
Why it matters: AI infrastructure files are now explicitly targeted by ransomware operators, placing intellectual property and operational capability at direct risk of business disruption and potential extortion.
Practitioner Perspective
If your environment relies on Langflow or hosts AI model weights, datasets, or vector indexes, this campaign marks a clear escalation in the risk of data loss and operational downtime. Attackers recognize the value and often irreplaceability of AI assets, which may lack robust, routine offline backups. The use of Go-based ransomware like ENCFORGE can complicate EDR detection and speed up compromise in cloud or on-prem infrastructure. Prioritize tightening access controls and backup coverage specifically for AI infrastructure files.
Recommended Actions
- Restrict external access to Langflow servers and monitor for unauthorized RCE attempts.
- Implement immutable snapshots of model weights, vector indexes, and training datasets with tested restore procedures.
FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware
Source: The Hacker News | Risk: High | Impacted: Software developers, ML/AI engineering teams, Organizations relying on third-party GitHub code
Summary: Cybersecurity researchers have discovered nearly 7,600 malicious GitHub repositories, out of which more than 800 pose as artificial intelligence (AI) skills or Model Context Protocol (MCP) servers to deliver a malware family known as SmartLoader as part of an ongoing campaign codenamed FakeGit. “FakeGit uses copied projects, lookalike developer profiles, convincing READMEs, and malicious ZIP
Why it matters: The abuse of GitHub to distribute tailored loader malware at scale raises the likelihood of trusted developer workflow compromise and widespread downstream infection.
Practitioner Perspective
If your teams use GitHub or dependencies sourced from public code repositories, this campaign exposes real risks of trojaned codebases and surreptitious malware delivery, particularly through purported AI tools and MCP server projects. The volume and credibility of these malicious repos make manual vetting impractical. Relying solely on repo reputation or download counts is increasingly unsafe. Defenders need high-fidelity source provenance validation and automated scanning for untrusted project artifacts.
Recommended Actions
- Block or sandbox download and execution of ZIP archives from unverified GitHub sources.
- Scan all AI skill and MCP server imports for SmartLoader IOCs before deployment.
Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign
Source: The Hacker News | Risk: High | Impacted: Organizations with remote or distributed Windows hosts, Users in targeted regions (e.g., Mexico), Enterprises relying on perimeter detection
Summary: A malware operator left its delivery server wide open, and Rapid7 pulled down the whole toolkit: 1,048 files spanning lure templates, filename-spoofing tests, execution experiments, droppers, builder notes, and two campaign chains. One was already live against Windows users in Mexico, delivering an infostealer through a fake government ID-lookup site over WebDAV. What makes it more than a
Why it matters: Malware toolkits incorporating AI-generated lures and customizable evasion techniques can rapidly enable more effective, region-specific credential theft, challenging traditional detection approaches.
Practitioner Perspective
Phishing and malware operations are becoming more automated and context-aware via AI-assisted toolkits, as shown by the exposed WebDAV campaign data. This enables scalable, targeted lures, often mimicking local government sites, pushing infostealers to broad user bases. Standard signature-based defenses are outpaced by rapid churn in templates and file names. Security teams should assume that attackers will continue leveraging generative AI to optimize social engineering and payload delivery, particularly over trusted protocols like WebDAV.
Recommended Actions
- Block unneeded WebDAV connections at network edges using protocol filtering.
- Hunt for campaign IOCs in email gateways and web proxies, focusing on fake government lures.
Russian-Speaking Hacker Uses Google Gemini CLI to Control Botnet of Eight Dental Clinic PCs
Source: The Hacker News | Risk: Medium | Impacted: Small business IT environments, Medical and dental practices, Teams experimenting with AI CLI tools
Summary: A solo Russian-speaking threat actor known as “bandcampro” outsourced a chunk of their operations to Google’s open-source Gemini CLI artificial intelligence (AI) and commandeered a live botnet. The findings come from an analysis of 200 Gemini CLI session logs between March 19 and April 21, 2026, which found the threat actor using AI, among other things, to crack passwords, set
Why it matters: Attackers are leveraging public open-source AI CLI tools to automate intrusion, persistence, and lateral movement, lowering barriers for less skilled actors and expanding the threat surface.
Practitioner Perspective
The Gemini CLI example demonstrates that attackers now efficiently script common post-intrusion tasks, such as password cracking and remote control, through AI-powered interfaces. This convergence of AI tooling and traditional botnet management could speed up attack cycles and complicate detection by blurring the line between legitimate and malicious automation in enterprise environments. Defenders should treat AI CLI adoption as a critical risk factor for tool abuse and traceability loss.
Recommended Actions
- Audit use of Gemini CLI and similar AI-enabled scripts on business PCs.
- Search for anomalous network or admin activity correlated with Gemini CLI session times.
Election voting advice from AI chatbots ‘inaccurate and unreliable’
Source: The Guardian | Risk: Medium | Impacted: Government/webmasters hosting AI chatbots, Election oversight organizations, Companies using AI for critical user support
Summary: Research during Hungary election shows AI recommended parties not running and gave highly volatile answers to identical prompts AI chatbots provide inaccurate, inconsistent and unreliable guidance to voters asking which party they should back, a study suggests, often recommending the wrong party, not mentioning the right one, or listing parties not even running. “The results raise serious concerns about the
Why it matters: Reliance on AI chatbots for critical public decision guidance introduces unpredictable errors or manipulation, risking reputational damage and downstream social consequences for organizations deploying or endorsing such systems.
Practitioner Perspective
AI chatbots providing inaccurate or inconsistent election advice illustrate the real dangers of automating public-facing informational services without robust content validation and override mechanisms. For organizations fielding similar bots in any regulated or mission-critical context, lapses in reliability can undermine trust or even cause legal exposure. Security teams have a responsibility to test outputs, monitor usage for anomalies, and mitigate both technical and social engineering risks stemming from misinformation.
Recommended Actions
- Continuously pen-test and red-team AI chatbot outputs, focus on edge cases relevant to public guidance.
- Deploy monitoring to detect high-variance or nonsensical responses provided to users.
Man of his word: Pope Leo speeches declared human-authored by Australian AI detection tool
Source: The Guardian | Risk: Low | Impacted: Editors and regulatory compliance teams, Media organizations verifying human authorship, Legal departments
Summary: Maps of Hope has been certified by Proudly Human, a company led by former chief scientist, Dr Alan Finkel Follow our Australia news live blog for latest updates Get our breaking news email, free app or daily news podcast A collection of speeches and writings by Pope Leo XIV has been certified as human-authored less than two months after Leo
Why it matters: Misclassification or over-reliance on AI-authorship detection tools may create false assurance in data provenance, with tangible consequences for information authenticity and regulatory compliance.
Practitioner Perspective
Organizations seeking to confirm human authorship in sensitive documents, such as legal or regulatory submissions, should not place blind trust in AI detection tools. Tool validation and periodic recalibration are required to minimize risks of false positives or negatives. Falsely certifying content as human-authored could be weaponized in fraud or disinformation campaigns. Defenders must treat AI-authorship detection as a probabilistic signal rather than a guarantee and apply layered validation.
Recommended Actions
- Supplement AI-authorship verdicts with multi-factor content provenance checks.
- Document limitations and operational accuracy of current detection tools in internal policy.
Nine to axe 30 jobs at the Age and SMH due to ‘extreme’ AI disruption
Source: The Guardian | Risk: Low | Impacted: Media organizations deploying AI-driven processes, HR and IT administrators during layoffs, Business units integrating new AI workflows
Summary: Staff told positions will be cut via voluntary and targeted redundancies as part of ‘evolution’ Follow our Australia news live blog for latest updates Get our breaking news email, free app or daily news podcast Australia’s biggest media company, Nine Entertainment, has blamed the “extreme state of disruption” from AI for its decision to cut another 30 newsroom jobs at
Why it matters: AI-driven disruption to business processes can trigger rapid workforce and operational changes, escalating insider risk during organizational transitions and raising exposure to supply chain threats.
Practitioner Perspective
When companies undertake layoffs or restructure due to AI adoption, they risk increased disengagement and potential malicious behavior by affected staff. Such transitions are also periods where adversaries may exploit reduced oversight or rush to adopt untested AI integrations. Defenders must be vigilant about access reviews, privilege reductions, and cultural risks that accompany rapid AI-driven transformation.
Recommended Actions
- Initiate comprehensive offboarding and access review processes during workforce reductions tied to AI adoption.
- Increase insider threat monitoring during periods of organizational disruption.
Jeff Bezos and UK government invest in £2bn British startup CuspAI
Source: The Guardian | Risk: Medium | Impacted: AI tech startups focusing on supply chain optimization, Research and development teams, Supply chain data aggregators
Summary: Company aims to develop AI software that cuts research times and use of rare metals in chipmakers’ supply chains Business live – latest updates Amazon’s founder, Jeff Bezos, and the UK government have invested in a £2bn British artificial intelligence startup that is aiming to become the “search engine for rare materials” that accelerates the next wave of technological breakthroughs.
Why it matters: Significant new investment in AI for rare material discovery increases the strategic value of intellectual property and may drive new types of targeting by cybercriminals or state-affiliated actors.
Practitioner Perspective
Startups aiming to monopolize AI-facilitated supply chain intelligence must expect heightened interest from both commercial competitors and well-resourced threat actors. The aggregation of sensitive research and supply chain data heightens the risk profile, turning such entities into lucrative attack targets. Security programs must balance growth with proportional controls over access, monitoring, and third-party integrations.
Recommended Actions
- Classify and apply advanced DLP to all sensitive AI models and supply chain datasets.
- Conduct threat modeling for espionage and sabotage scenarios targeting CuspAI-type organizations.
Defensive Actions
- Apply the official CVE-2026-6875 patch to all ServiceNow AI Platform instances without delay.
- Restrict external access to Langflow servers and monitor for unauthorized RCE attempts.
- Implement immutable backups and tested restore procedures for model weights and datasets in AI environments.
- Block or sandbox download and execution of ZIP archives from unverified GitHub sources.
- Audit for infostealer payload execution and phishing lures leveraging fake government sites or WebDAV delivery.
- Increase insider threat monitoring and initiate comprehensive access reviews during workforce transitions tied to AI adoption.
- Continuously pen-test and red-team AI chatbot outputs and monitor for unreliable or misleading responses, especially in regulated contexts.
- Map out and automate remediation for exposure windows from CVE disclosure to patch deployment.
- Engage with facilities partners to verify alternate cooling and failover plans for data centers facing water shortages.
What We’re Watching
Key risks remain from ransomware attacks focused on AI infrastructure, evolving SaaS exploits, and the mass seeding of malicious open-source repositories. Stay alert for further escalation in insider risk linked to workforce disruption, and emerging threats where business continuity depends on physical resource resilience and the reliability of AI-driven platforms.
Categories: Artificial Intelligence, Cybersecurity Blog
Leave a Reply