BagheeraAltered's CyberSecurity Newsletter logo

BagheeraAltered's CyberSecurity Newsletter

Archives
Subscribe
August 3, 2026

Anthropic's Claude went rogue, and a swarm platform left the door wide open

We’re at Black Hat this week

Bagheera Labs founder and CEO, Sherwyn Moodley, is speaking at Black Hat this week with a talk entitled, “Closed Loop: From Autonomous Exploit to Deployed Defense in Under 5 Minutes.” It’s happening on Thursday, August 6, from 11:05am-11:45am at Mandalay Bay G, Level 2. 

Expect an honest operational assessment of where automated closed-loop pipelines work, where they break, and what organizational and contractual changes are required before automated remediation can be deployed in real engagements. If you’re going to be in Vegas, add it to your calendar to learn how AI-powered defense is leveling the playing field against AI offense.

Speaking of AI offense:

This week, we’re leading with two stories about AI systems slipping their leashes. Anthropic disclosed that its Claude models hacked into three separate organisations by mistake, just days after OpenAI reported its own models had autonomously compromised multiple platforms during testing. Anthropic says the intrusions happened because Claude gained access to an internet connection it was never meant to have. 

Meanwhile, Noma Labs uncovered a maximum-severity flaw (CVE-2026-59726, CVSS 10) in Ruflo, the AI agent-swarm platform formerly known as Claude Flow that orchestrates swarms for Codex and Claude Code. The bug let researchers into the platform with no login at all, opening the door to malicious AI agent swarms. 

Two different failure modes, one uncomfortable theme: as we hand more autonomy to AI agents, both the models themselves and the infrastructure running them are becoming attack surfaces we don't fully control.

AI firm Anthropic has discovered its ‘Claude’ AI models hacked into three organisations by mistake, just days after industry rival OpenAI announced its own models had autonomously compromised multiple platforms during testing. The San Francisco-based company said the attacks occurred because Claude gained access to an internet connection it was not supposed to have access to.
https://ia.acs.org.au/article/2026/anthropic-s-ai-escapes-hacks-three-companies.html

Researchers at Noma Security's Noma Labs discovered the flaw, tracked as CVE-2026-59726, in Ruflo, formerly called Claude Flow and which hosts AI agent swarms for Codex and Claude Code, they revealed today. The vulnerability, which received the highest CVSS severity score of 10, allowed them to access the platform without logging in at all, according to Noma Labs.
https://www.darkreading.com/cyber-risk/patch-resistant-rufroot-flaw-malicious-ai-agent-swarms

American Airlines flights are departing again after a brief IT outage led to a nationwide ground stop, according to the airline and federal officials. American Airlines flights not in the air were being held because of an IT outage, according to an advisory from the Federal Aviation Administration. A "technology issue briefly impacted connectivity" for some systems, the airline said in a statement. "Connectivity has been fully restored. We apologize to our customers for the inconvenience. We appreciate the efforts of our team to bring our systems back online so quickly and take care of our customers."
https://abcnews.com/US/american-airlines-grounded-nationwide-due-outage-faa

On July 28, Minnesota IT Services, the central information technology agency for the State of Minnesota, announced that it was coordinating with regional and federal agencies to respond to a significant cyber attack launched on July 26 targeting more than 30 municipal water supplies. The attacks, which locked out users and compromised the ability of operators to monitor and control their systems, caused publicly reported outages in several towns and cities including Braham, Plymouth, South St. Paul and Maple Plain.
https://www.opforjournal.com/p/us-water-systems-hit-by-suspected

Anthropic says Claude Mythos Preview helped derive an end-to-end key-recovery attack against HAWK-256 and a 200- to 800-fold speedup for an attack on seven-round AES-128. The HAWK attack exploits a previously unused symmetry in the lattice behind the signature scheme. Anthropic's released implementation gives an expected end-to-end runtime of about three hours and 42 minutes on a 96-core server. The AES result removes a 256-way guessing step from an existing meet-in-the-middle attack. Anthropic said neither result affects production systems. HAWK remains a candidate in a National Institute of Standards and Technology (NIST) post-quantum standardization process, and the public recovery code only targets the smaller HAWK-256 parameter.
https://thehackernews.com/2026/07/claude-ai-just-cracked-post-quantum.html

The Treasury Inspector General for Tax Administration (TIGTA) found over 100 vulnerabilities in a third-party contractor the IRS was using to digitize tax documents. The TIGTA is an independent government agency responsible for overseeing and auditing the IRS. They looked at two sites at which contractors were using to support the IRS's Zero Paper Initiative (ZPI), a push for the IRS to move all of its paper forms to digital files.
https://www.privacyguides.org/news/2026/07/29/over-100-vulnerabilities-found-in-irs-contractor-handling-americans-tax-information/

Another day another Doom port, but the new DoomPaint stands out from the crowd for a few reasons. Firstly, it has been developed by Mark Russinovich, the Microsoft Azure CTO. Secondly, DoomPaint runs the actual original shareware Doom release using MS Paint as the monitor or viewport for in-game action. That’s different, and it is remarkable to read that the OLE clipboard hack behind this latest Doom escapade allows the game to run at a fair pace, up to 35 FPS, but might also sometimes be “spreadsheet-tier,” according to the author.
https://www.tomshardware.com/video-games/retro-gaming/microsoft-paint-used-as-a-monitor-to-run-doom-at-up-to-35-fps-project-released-by-firms-azure-cto-runs-actual-doom-engine-and-loads-real-shareware-doom1-wad

Russia has unveiled a new electronic warfare system designed to disrupt Starlink communications by interfering directly with satellites instead of attacking ground terminals. The system, dubbed Volna Kupol Garant, directs concentrated radio signals toward Starlink satellites, preventing them from receiving transmissions from users within its operating area.
https://www.techradar.com/pro/russia-debuts-anti-starlink-ew-system-that-can-blind-terminals-by-overloading-satellites-receiving-antennas

STAR Labs has published a Linux kernel exploit that turns an ordinary local user into root on the CentOS Stream 9 build it targeted. The flaw, tracked as CVE-2026-53264 (CVSS score: 7.8), is a use-after-free race in the kernel's network traffic-control subsystem. Researcher Lee Jia Jie said artificial intelligence (AI) helped him find the bug and speed up exploit development. This is local privilege escalation, not remote code execution, so an attacker needs a foothold on the machine before any of it applies.
https://thehackernews.com/2026/07/researcher-says-ai-helped-develop-linux.html

A suspected fourth wave of attacks targeting vulnerable Coldcard-generated Bitcoin wallets may already be underway, with blockchain researcher Alex Thorn warning on August 3 that almost 449 BTC had been swept from hundreds of addresses in about two and a half hours. The latest activity, which was still unfolding as Thorn posted, follows three earlier waves that researchers have linked to the same weak-entropy vulnerability affecting certain Coldcard firmware versions.
https://cryptopotato.com/coldcard-wallet-attacks-enter-fourth-wave-putting-449-btc-at-risk/

Three high-severity security flaws have been disclosed in Hugging Face's Diffusers library that could allow crafted model repositories to stealthily execute arbitrary code on machines that load it, opening the artificial intelligence (AI) supply chain to security risk. "These vulnerabilities are bypassing trust_remote_code, the safeguard designed to stop unreviewed code from running in the custom pipelines loading process," Zafran Labs researchers Gal Zaban and Ido Shani said in an analysis published last week.
https://thehackernews.com/2026/08/hugging-face-diffusers-flaws-could-let.html

Interpol revealed that authorities in Singapore and Oman used a worldwide network of law enforcement agencies and financial organizations to halt a $6.6 million payoff from a business email compromise (BEC) scam, part of Operation First Light 2026, which — among other milestones — blocked more than 31,000 bank accounts linked to fraud.
https://www.darkreading.com/cybersecurity-operations/interpol-leverages-global-system-curtail-fraud-payments

Origin Energy executives argued against tougher new cybersecurity obligations earlier this year, labelling proposed changes to critical infrastructure rules “overly prescriptive” months before a major data breach that affected almost a million of its 4.8 million customers.
https://ia.acs.org.au/article/2026/origin-opposed-tougher-cyber-rules-before-massive-breach.html

Researchers suspect that a vulnerability in COLDCARD hardware wallet firmware was exploited to steal an estimated $88.6 million in Bitcoin from thousands of wallets whose seeds were generated using a flawed random number generator. Digital asset research firm Galaxy Research says it identified an initial wave of transactions that it believes was likely linked to the vulnerability, draining approximately 1,083 BTC, worth $70.2 million, from 1,196 addresses on July 30.
https://www.bleepingcomputer.com/news/security/coldcard-wallet-rng-flaw-likely-linked-to-88-million-bitcoin-theft/

China's National Cybersecurity Reporting Center issued a warning on WeChat to the general public. Cybercriminals were masquerading as provincial public security services, spreading a fake app that promised citizens "one-stop handling" of public safety issues online. Anyone who downloaded the app unwittingly infected their mobile device with information-stealing malware. The warning also listed two IP addresses associated with the campaign.
https://www.darkreading.com/endpoint-security/flying-eagle-mobile-rat-builder-china

Thermo Fisher Scientific has patched a flaw in select Applied Biosystems human identification software that could allow data files to be altered before analysis software loads them. The vendor's July 31 security bulletin says nearly undetectable changes to .fsa and .hid outputs could occur if laboratory controls are circumvented.
https://thehackernews.com/2026/08/thermo-fisher-patches-flaw-that-could.html

Pharmaceutical company Amgen says it suffered a data breach after threat actors stole corporate data and patient information stored in multiple cloud systems operated by third-party service providers. Amgen is a California-based biotechnology company that develops and manufactures medicines for serious illnesses, including cancer, cardiovascular disease, inflammation, and rare diseases. The company said it detected the unauthorized activity in July 2026 and responded by activating its cybersecurity response plan, implementing containment measures, and hiring independent forensic experts to investigate the incident.
https://www.bleepingcomputer.com/news/security/amgen-says-cloud-data-breach-exposed-patient-health-proprietary-info/

Some 24,000 Internet-exposed server management controllers are vulnerable to a more than 20-year-old flaw that gives attackers a way to crack authentication credentials and gain privileged access to the underlying servers. The issue can evade conventional security tools because these management controllers operate independently of the server's operating system, kernel, containers, and workloads, and are therefore nearly invisible at those layers.
https://www.darkreading.com/cyber-risk/flaw-exposes-data-centers-server-takeover

N-able said attackers exploited an authentication bypass in N-central to gain remote administrative access and reach the customer systems managed through those servers. Its first fix was incomplete. CVE-2026-18577 affects N-central builds prior to 2026.3.1.7. N-able shipped build 2026.3.1.7 on August 2 as the first unaffected version.
https://thehackernews.com/2026/08/n-able-says-attackers-take-over-n.html

The Arch Linux project has temporarily disabled adoption of Arch User Repository (AUR) packages after a surge in malicious takeovers of existing packages. The decision was announced on the distribution's mailing list by contributor Robin Candau, who said that the situation is temporary until a solution is found.
https://www.bleepingcomputer.com/news/security/arch-linux-disables-aur-package-adoption-to-stop-malware-flood/

Researchers released a proof-of-concept (PoC) exploit for a now-patched flaw in Microsoft's Active Directory Certificate Services (AD CS) that can allow a low-privileged domain user to impersonate a domain controller and fully compromise an AD environment. The flaw was present due to a defective trust boundary within the certificate-based client authentication aspect of Microsoft AD Services.
https://www.darkreading.com/vulnerabilities-threats/certighost-flaw-microsoft-active-directory-certificates

Attackers modified a JavaScript file served by advertising technology company Adform, turning it into a browser-side tool that rewrites cryptocurrency wallet addresses. Adform detected the incident on July 27, 2026, removed the malicious code, notified affected clients, and reported it to authorities. Anyone who visited a site carrying the affected script on July 27 and copied a Bitcoin, Ethereum, or Tron address may have pasted a different address inserted by the malicious code instead.
https://thehackernews.com/2026/08/hackers-poison-adform-script-to-swap.html

Online advertising firm Adform suffered a supply-chain attack that delivered cryptocurrency-stealing scripts to websites using its ad platform, replacing wallet addresses copied to visitors’ clipboards with ones controlled by an attacker. Adform is one of Europe’s largest adtech firms, providing a full-stack platform that includes Demand-Side Platform (DSP), Supply-Side Platform (SSP), ad servers, and management tools.
https://www.bleepingcomputer.com/news/security/online-ad-firm-adforms-script-compromised-to-steal-cryptocurrency/

Significant cracks in the managed identity trust chains of the world's biggest cloud platforms could put enterprise and government resources at risk. That's according to Justin O'Leary, independent security researcher, who discovered two "confused deputy" vulnerabilities in both Microsoft Azure and the Google Cloud Platform (GCP) earlier this year. Despite reporting them to the cloud giants, neither company acknowledged the vulnerabilities or paid a bug-bounty reward, even though Microsoft appears to have silently patched its flaw.
https://www.darkreading.com/cloud-security/confused-deputy-flaws-google-cloud-microsoft-azure

Adobe has released security updates to address a maximum-severity security flaw in Campaign Classic (ACC), its enterprise-focused marketing automation platform, that could result in arbitrary code execution. The vulnerability, tracked as CVE-2026-48449, carries a severity score of 10.0 on the CVSS scoring system.
https://thehackernews.com/2026/08/adobe-campaign-classic-cvss-100-flaw.html

A Chinese-speaking threat actor is using the DeepSeek AI model and the open-source Hermes Agent to conduct autonomous cyberattacks on exposed servers with limited human involvement. The activity was discovered by Palo Alto Networks' Unit 42 researchers after Hermes accidentally created a web server from its home directory, exposing the attacker's environment, including API keys, exploit scripts, target lists, shell history, and AI attack logs.
https://www.bleepingcomputer.com/news/security/hacker-uses-deepseek-ai-to-autonomously-attack-vulnerable-servers/

Don't miss what's next. Subscribe to BagheeraAltered's CyberSecurity Newsletter:
← Newer A war 6,000 miles away just reached a small-town water tower Older → An Al model hacked a real company to cheat on its own exam
Powered by Buttondown, the easiest way to start and grow your newsletter.