The break-ins this weekend all came through the front desk. Ernst & Young told clients that a third-party support-ticket system used by its IT staff had been rifled, and that the documents carried out of it included client tax filings down to Social Security numbers; Abbott confirmed the extortion group ShinyHunters had reached its cancer-diagnostics systems through a single phone call that talked its way past single sign-on, even as a second, unrelated intruder claimed a separate portal; and researchers detailing an April breach of the certificate authority DigiCert found it had begun with a chat message to the support desk and a malicious file dressed up as a customer screenshot, five tries until one landed on a machine that happened to have no protection. Three trusted institutions, three help desks, no exploit worth the name — which is the same lesson Sophos put a number on three days ago and the same one Australia's regulator called unforeseeable the day before that: the identity layer is the perimeter now, and the people staffing it are the way in. The other target coming into focus is the AI stack itself, with a new botnet scanning the internet specifically for the model-runners and agent servers that teams stand up in an afternoon and firewall late, hunting the cloud keys behind them, and a North Korean crew now rifling developers' AI-assistant configuration folders alongside their crypto wallets — though the week's most honest finding cuts the other way, as researchers showed the same prompt-injection fragility that plagues defenders is also quietly breaking the autonomous hacking agents everyone spent last week fearing. Abroad, Iran-linked operators spent the opening days of the Gulf war tracking US troops' phones through telecom roaming signals and commercially bought advertising data, geolocation as a prelude to missiles; a China-linked backdoor turned up still running on a Taiwanese manufacturer's network after a dwell time that may reach thirteen years; and the ground kept shifting under all of it as Moonshot's Kimi K3 split the AI race into a Western closed track and a Chinese open-weight insurgency, Meta opened talks to rent Anthropic ten billion dollars of computing power, France and Germany vowed to build a European answer to Palantir, and Britain's incoming prime minister scrapped the national digital ID scheme on his way through the door.
Top Stories
- Meta in Talks to Lease Computing Power to Anthropic in Potential $10 Billion Deal — NYT > Technology · AI & Power
- France, Germany vow to develop Palantir rival — Cybersecurity and Data Protection – POLITICO · EU & Technology
- US Military Smartphones Targeted Through Roaming and Ad Tech — The Citizen Lab · Threat Intelligence (CTI)
- Inc Ransomware Exploits SonicWall SMA Zero-Days — darkreading · Cybersecurity & Threats
- AI race splits in two as China wages open-weight insurgency — Axios · AI & Power
AI & Power
Meta in Talks to Lease Computing Power to Anthropic in Potential $10 Billion Deal — NYT > Technology
Why it matters: A $10bn compute lease from Meta to Anthropic shows the frontier labs now rent capacity from the hyperscalers they compete with, blurring the line between rival and landlord.
Meta is in talks to lease computing power to Anthropic in a deal potentially worth $10bn, an arrangement in which one AI giant becomes the infrastructure landlord of another it competes with.
AI race splits in two as China wages open-weight insurgency — Axios
Why it matters: The framing that the AI race has bifurcated — a Western closed-weight track and a Chinese open-weight insurgency — is the clearest structural read of the Kimi K3 aftermath.
Kimi K3's arrival is being read as splitting the AI race in two: a Western closed, capital-intensive track and a Chinese open-weight insurgency giving frontier capability away.
Prompt Injection Attacks Are Thwarting AI Hacking Agents — WIRED
Why it matters: The honest counterweight to the week's AI-attacker alarm: the same prompt-injection fragility that plagues defenders is also breaking the autonomous attack agents.
Researchers find that prompt injection is thwarting AI hacking agents as often as it aids attackers, the same fragility cutting both ways and puncturing the autonomous-offence narrative.
Backlash against data centers could cost the US its AI edge — Atlantic Council
Why it matters: The argument that domestic data-centre opposition could cost the US its AI lead reframes local siting fights as a national-capability problem.
The Atlantic Council argues the bipartisan backlash against data centres — now a rare point of American agreement — could cost the US its AI edge as build-out stalls.
SpaceX in Talks to Provide Computing Power for Pentagon’s AI Push — Technology - WSJ.com
Why it matters: SpaceX pitching orbital and terrestrial compute for the Pentagon's AI push folds a private space company into the military AI supply chain.
SpaceX is in talks to provide computing power for the Pentagon's AI push, extending Musk's infrastructure reach into military AI.
AI Chip Startup Etched Is in Talks for $20 Billion Valuation — Technology - WSJ.com
Why it matters: A $20bn valuation for a transformer-only chip startup is the market betting that inference economics, not training, decide the next round.
AI chip startup Etched is in talks for a $20bn valuation, a bet that specialised transformer inference silicon can carve share from Nvidia.
AI companies move to protect teens — Semafor
Why it matters: Coordinated teen-safety moves across the AI labs are the industry pre-empting the child-safety regulation already arriving state by state.
AI companies are moving in concert to add protections for teenage users, pre-empting the child-safety rules arriving through state legislatures.
Meta Plans to Hire Top Amazon Computing Executive as It Weighs Cloud Push — Technology - WSJ.com
Why it matters: Meta poaching a senior AWS infrastructure leader as it weighs a cloud push signals it wants to sell compute, not just consume it.
Meta plans to hire a top Amazon computing executive as it weighs a cloud push, positioning to become a compute vendor rather than only a buyer.
Dave Eggers told OpenAI staff that ChatGPT was ‘silencing an entire generation’ — The Verge
Why it matters: A novelist telling OpenAI's own staff the product is silencing a generation is the cultural backlash reaching inside the building.
Author Dave Eggers told OpenAI staff to their faces that ChatGPT was silencing an entire generation, the creative-sector backlash delivered in person.
EU & Technology
France, Germany vow to develop Palantir rival — Cybersecurity and Data Protection – POLITICO
Why it matters: France and Germany committing to build a European Palantir rival is the sovereignty argument moving from cloud to the intelligence-analytics layer where the dependence is most sensitive.
France and Germany vowed to develop a European rival to Palantir, targeting the security-analytics layer where dependence on a single US vendor is most politically acute.
E.U. Orders Google to Open Android Mic, Camera and Screen to Rival AI Assistants — The Hacker News
Why it matters: The DMA order now reaches into device sensors — forcing Google to open the microphone, camera and screen to rival assistants is a far deeper intervention than search-data sharing.
Brussels is ordering Google to open Android's microphone, camera and screen to rival AI assistants, extending last week's DMA remedy from search data down into the device's sensors.
Top EU court clips YouTube's intermediary defense over reviewed content — www.theregister.com - Articles
Why it matters: The EU's top court narrowing YouTube's intermediary immunity for content it has reviewed reopens the platform-liability question the DSA was meant to settle.
The EU's top court clipped YouTube's intermediary defence for content it had actively reviewed, narrowing the liability shield platforms rely on.
Friedrich Merz pitches Germany as ‘Europe’s bedrock of stability’ to investors — myFT following
Why it matters: Merz selling Germany to investors as Europe's bedrock of stability is a sovereignty pitch aimed at capital as much as voters.
Friedrich Merz pitched Germany to investors as Europe's bedrock of stability, courting capital against the backdrop of a potential Le Pen presidency in France.
EU to give boost to prosecutor’s office as part of new anti-corruption measures later this year — EUobserver
Why it matters: Strengthening the European Public Prosecutor's Office is the enforcement muscle the bloc's anti-corruption and fund-integrity rules have lacked.
The EU plans to boost the European Public Prosecutor's Office as part of new anti-corruption measures later this year.
Luxury groups face inventory squeeze under EU destruction ban — myFT following
Why it matters: The EU destruction ban forcing luxury houses to hold unsold stock is a concrete instance of circular-economy rules reshaping a flagship European industry.
Luxury groups face an inventory squeeze under the EU's ban on destroying unsold goods, a circular-economy rule biting a flagship European sector.
Five startups spearhead coalition to put small air quality sensors at the heart of EU clean air policy — Tech.eu
Why it matters: A startup coalition pushing low-cost sensors into EU clean-air policy is a small test of whether European industrial policy can be shaped bottom-up.
Five startups formed a coalition to place low-cost air-quality sensors at the heart of EU clean-air policy.
US & Technology
FCC took pricey gifts from Paramount as the company needed approval for deals — Ars Technica - All content
Why it matters: The FCC accepting valuable gifts from a company awaiting its deal approvals is a concrete conflict-of-interest story beneath the week's louder FCC noise.
The FCC took pricey gifts from Paramount while the company needed the agency's approval for deals, a direct conflict-of-interest at the regulator.
Trump’s rhetoric is more dangerous than voting machine flaws, experts say — Policy – POLITICO
Why it matters: Election experts arguing the president's rhetoric is the real threat, not the machines, reframes the manufactured election-security panic.
Election experts say Trump's rhetoric is more dangerous than any voting-machine flaw, pushing back on the manufactured fraud narrative driving his election-security claims.
AWS Billing Glitch Hits Customers With Billion-Dollar Fees — WIRED
Why it matters: A billing error generating billion-dollar AWS invoices is a reminder that opaque cloud metering can fail spectacularly in the customer's disfavour.
An AWS billing glitch hit customers with billion-dollar fee estimates, exposing how opaque cloud metering can fail without warning.
This Conversation Is Being Recorded. They All Are. — Technology - WSJ.com
Why it matters: The normalisation of always-on AI transcription — every meeting recorded and summarised — is a quiet surveillance shift inside ordinary work.
AI note-takers have made near-universal meeting transcription the default, a quiet normalisation of always-on recording in everyday professional life.
Nvidia, Challenged by Apple, Narrowly Retains Wall Street’s Crown — Technology - WSJ.com
Why it matters: Apple briefly pressuring Nvidia for Wall Street's crown marks how far the AI-trade rotation has run.
Nvidia narrowly retained Wall Street's most-valuable crown as Apple challenged it, a marker of how sharply the AI trade has rotated.
Roblox Faces Investor Suit Tying an Age-Verification Slowdown to Its Growth — ID Tech
Why it matters: An investor suit tying Roblox's growth slowdown to age-verification friction shows compliance costs now move the stock.
Roblox faces an investor lawsuit tying an age-verification slowdown to its growth, a sign that youth-safety compliance now carries market consequences.
China & Technology
Alibaba targets Nvidia’s dominant software ecosystem with open-source AI stack — Tech - South China Morning Post
Why it matters: Alibaba open-sourcing a full AI stack aimed at Nvidia's software moat attacks the CUDA lock-in that has held even as Chinese chips improve.
Alibaba is targeting Nvidia's dominant software ecosystem with an open-source AI stack, going after the CUDA lock-in that outlasts any single hardware gap.
China-Proposed Global AI Organization Launched at WAIC — Sixth Tone RSS
Why it matters: China standing up a proposed global AI governance body positions Beijing to write the multilateral rules while Washington still debates whether to restrict open models.
China launched a proposed global AI organisation at WAIC, with Xi casting himself as leader of a new AI world order and offering the Global South a seat the US has not.
China’s Moonshot Plans IPO in Six Months After AI Breakthrough — Bloomberg Technology
Why it matters: Moonshot moving to IPO within six months of Kimi K3 turns an open-weight capability shock into a capital-markets event.
Moonshot plans an IPO within six months of its Kimi K3 breakthrough, converting an open-weight capability shock into a public-market listing.
Chinese chip start-up Biren bets on light-based ‘supernodes’ to match Nvidia — Tech - South China Morning Post
Why it matters: Biren betting on optical 'supernode' interconnects to match Nvidia is China routing around the chip embargo at the system level rather than the transistor.
Chinese chip start-up Biren is betting on light-based 'supernodes' to match Nvidia, attacking the interconnect layer where export controls bite less.
China’s tech giants fuel the rise of AI tokens as a new corporate currency — Tech - South China Morning Post
Why it matters: Chinese tech giants turning AI compute credits into a tradable corporate currency is a novel financialisation of inference capacity worth watching.
China's tech giants are fuelling the rise of AI 'tokens' as a new corporate currency, financialising compute credits into a tradable instrument.
China AI summit hears Global South needs equal access to avoid digital divide — Tech - South China Morning Post
Why it matters: The Global-South equal-access pitch is the soft-power half of China's open-weight strategy — distribution framed as development.
China's AI summit pressed the case that the Global South needs equal access to avoid a digital divide, pairing open-weight distribution with a development narrative.
Threat Intelligence (CTI)
[P2] US Military Smartphones Targeted Through Roaming and Ad Tech — The Citizen Lab
Why it matters: Iran-linked actors tracking US military phones during the Gulf war by abusing telecom roaming signalling and commercial ad-tech location data.
Citizen Lab and telecoms sources describe a wave of SS7 signalling pings against Middle Eastern mobile networks to geolocate roaming phones of US personnel and contractors, alongside abuse of commercial advertising databases to track devices in Iraqi Kurdistan, in the run-up to and early days of the US-Iran war; Citizen Lab's Gary Miller links at least some attempts to an Iranian mobile operator and characterises it as very specific user targeting.
severity high · exploited in the wild · EU: NIS2, CER Directive, ePrivacy · actor Iran (state-linked operators) (60%)
[P2] GoldenEyeDog Subgroup Linked to DigiCert Breach and Code-Signing Certificate Theft — The Hacker News
Why it matters: A certificate authority breached through its support chat, its stolen code-signing certificates then used to sign malware as legitimately trusted software.
Expel attributes an April 2026 DigiCert breach to CylindricalCanine, a subgroup of the China-linked GoldenEyeDog cluster: on 2 April an operator contacted DigiCert support via customer chat and delivered a ZIP disguised as a screenshot containing a malicious .scr file; four delivery attempts were blocked but a fifth succeeded against an endpoint lacking EDR, and the intrusion went undetected for ten days, exposing initialisation codes for approved EV code-signing certificate orders. DigiCert revoked 60 certificates, 27 linked to the attacker, some used to sign Zhong Stealer.
severity high · exploited in the wild · EU: NIS2, CRA, eIDAS · actor GoldenEyeDog / CylindricalCanine (70%)
[P2] Daxin: 13-Year-Old China-Linked Malware Found Still Active on Manufacturer’s Network — Security Affairs
Why it matters: The most advanced China-linked backdoor ever documented, found still running on a Taiwanese manufacturer's network — with a dwell time that may reach thirteen years.
Symantec's Threat Hunter Team found Daxin — a Windows kernel-mode driver backdoor it first documented in 2022 and once called the most advanced malware it had seen from a China-linked actor — active on a Taiwan-based subsidiary of a multinational high-tech manufacturer in May 2026; sample compile timestamps from early 2013 combined with the actor's stealth pattern suggest the intrusion may have persisted undetected for thirteen years. Daxin hijacks existing legitimate TCP connections to carry encrypted C2, evading conventional network monitoring, and a novel backdoor, Stupig, was found on the same host.
severity high · exploited in the wild · EU: NIS2, CER Directive · actor China-linked actor (Daxin operator) (70%)
[P3] Fake Coding Tests Deliver OtterCookie-Aligned Malware Hidden in SVG Flag Images — The Hacker News
Why it matters: North Korea's fake-job campaign now hides its stealer inside SVG flag images in coding tests — and harvests developers' AI coding-tool configs along with wallets.
Elastic Security Labs details a DPRK-aligned Contagious Interview operation (tracked REF9403) that hides a four-stage OtterCookie payload via steganography in SVG files posing as country-flag images inside fake coding-challenge projects; running the project delivers a browser-credential and crypto-wallet stealer, a file stealer, a Socket.IO RAT and a clipboard stealer, and the file stealer specifically collects AI coding-tool configuration directories including .claude, .cursor, .gemini, .windsurf, .pearai and .llama.
severity medium · exploited in the wild · EU: NIS2, GDPR · actor DPRK (Contagious Interview / REF9403) (75%)
[P2] Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RAT — The Hacker News
Why it matters: Seven malicious npm packages hiding their command-and-control on public blockchains, making the delivery infrastructure effectively impossible to seize.
Checkmarx found seven malicious npm packages (campaign ViteVenom) targeting the Vite frontend ecosystem, an expansion of the ChainVeil operation that uses a four-tier blockchain-based C2 spanning Tron, Aptos and Binance Smart Chain to deliver a RAT capable of reverse shell, credential harvesting, file exfiltration and persistent backdoor injection; the code executes at import time rather than install time to evade endpoint detection, and stores payload pointers as blockchain transaction data rather than on seizable domains.
severity high · exploited in the wild · EU: NIS2, CRA · actor SuccessKey (ViteVenom / ChainVeil) (60%)
[P3] Armenia Detains Russian Tourist on U.S. Warrant for REvil Hacker, Lawyers Say Wrong Man — The Hacker News
Why it matters: A Russian tourist held for extradition to the US as a REvil suspect — who his lawyers say is simply a namesake of the sanctioned hacker.
Armenia has detained a Russian tourist, Aleksandr Ermakov, since 28 June on a US extradition request for a REvil ransomware suspect of the same name; his lawyers say the detained man is Aleksandr Yuryevich Ermakov of Omsk, a former prison-service lawyer who speaks no English, while the wanted man is Aleksandr Gennadievich Ermakov — sanctioned by Australia, the US and UK in January 2024 for the Medibank breach of 9.7 million records and accused of REvil/Sodinokibi attacks on more than 1,000 victims between 2019 and 2021.
severity low · EU: NIS2
Defence & National Security
Helsing secures $1.8B Series E, Uber acquiring Delivery Hero in €13B deal, and Revolut to launch US bank in 2027 — Tech.eu
Why it matters: A $1.8bn round for Helsing is Europe's largest defence-tech raise and the clearest sign the continent is funding sovereign military AI at scale.
Helsing secured a $1.8bn Series E, Europe's largest defence-tech raise, underscoring a continental push to fund sovereign military AI at scale.
Two U.S. troops killed in Iranian missile attack on Jordan — Axios
Why it matters: US troops killed by an Iranian strike on a Jordan base marks a sharp escalation with direct American casualties in the widening Gulf war.
Two US troops were killed and one left missing after an Iranian missile attack on a base in Jordan, a sharp escalation with direct American casualties.
EU, Ukraine sign drone deal to fast-track unmanned systems production — Breaking Defense
Why it matters: An EU-Ukraine deal to fast-track unmanned-systems production ties Kyiv's battlefield drone industry into European defence procurement.
The EU and Ukraine signed a deal to fast-track unmanned-systems production, integrating Kyiv's battle-proven drone industry into European defence supply.
US-Iran conflict is becoming a testbed for the future of warfare — Semafor
Why it matters: Reading the US-Iran conflict as a live testbed for autonomous and cyber-enabled warfare is where the doctrinal lessons are being written now.
The US-Iran conflict is becoming a testbed for the future of warfare, from drone swarms to cyber-enabled targeting of personnel.
Saronic picks Brownsville, Texas, for $3 billion Port Alpha shipyard — Defense News
Why it matters: A $3bn autonomous-shipyard in Texas is the industrial bet that unmanned surface vessels become a mass-produced naval category.
Drone-ship maker Saronic picked Brownsville, Texas, for a $3bn Port Alpha shipyard, betting on mass production of autonomous surface vessels.
Germany Raises Threat Level Over Terror Attack Risk, Welt Says — Bloomberg Politics
Why it matters: Germany raising its terror-threat level is a concrete security-posture shift amid the Gulf war's European spillover.
Germany raised its threat level over terror-attack risk, a posture shift as the Gulf conflict's tensions reach Europe.
Digital Sovereignty & Identity
Burnham to Scrap UK Digital ID to Focus on Cost of Living Policies — Bloomberg Politics
Why it matters: A new UK prime minister scrapping the national digital ID scheme on day one is the sharpest reversal yet of the identity-infrastructure consensus.
Incoming UK prime minister Andy Burnham will scrap the national digital ID scheme to focus on cost-of-living policy, abandoning one of the state's flagship identity projects.
German lawmakers approve live facial recognition use by federal police — Biometric Update
Why it matters: German lawmakers authorising live facial recognition for the federal police crosses a line most of Europe's biometric debate has held against.
German lawmakers approved live facial recognition use by the federal police, authorising real-time biometric surveillance that much of the EU debate has resisted.
ICE Is Using Data Broker Tools to ‘Identify Unaccompanied Minors’ and ‘Fraud’ — WIRED
Why it matters: ICE using commercial data-broker tools to identify unaccompanied minors is the surveillance-purchase loophole applied to children.
ICE is using commercial data-broker tools to 'identify unaccompanied minors' and flag 'fraud', buying its way around collection limits and pointing the capability at children.
Victory! Flock Ends Rollout of Audio “Distress Detection” of Human Voices — Deeplinks
Why it matters: Flock abandoning audio 'distress detection' after pushback is a rare rollback of a surveillance capability before it became infrastructure.
After public pressure, Flock ended its rollout of audio 'distress detection' that listened for human voices, a rare reversal of an expanding surveillance capability.
EUDI What? As wallet deadline looms, awareness remains low — Biometric Update
Why it matters: The EUDI wallet deadline approaching with public awareness near zero is the adoption gap that could hollow out Europe's identity flagship.
As the EUDI wallet deadline looms, public awareness remains low, exposing an adoption gap at the centre of Europe's digital-identity project.
US House Panel Hears That the Federal Identity Model Can’t Keep Up With AI Fraud — ID Tech
Why it matters: A US House panel conceding the federal identity model cannot keep up with AI-driven fraud is the state admitting its verification stack is outmatched.
A US House panel heard that the federal identity model cannot keep pace with AI-enabled fraud, an admission that public verification infrastructure is being outrun.
Quantum & Cryptography
PsiQuantum makes executive appointments — Intelligence Community News
Why it matters: Leadership hires at PsiQuantum are a thin but real signal that the photonic fault-tolerant bet is staffing up for a commercialisation push.
Photonic quantum-computing firm PsiQuantum made a set of senior executive appointments as it builds toward fault-tolerant systems.
Cybersecurity & Threats
[P1] Inc Ransomware Exploits SonicWall SMA Zero-Days — darkreading
Why it matters: A ransomware crew burning two SonicWall remote-access zero-days — one of them a maximum-severity, unauthenticated flaw — to pre-position across enterprise networks.
A threat actor tied to the Inc ransomware-as-a-service operation exploited two SonicWall SMA 1000 zero-days — CVE-2026-15409, an unauthenticated SSRF rated CVSS 10.0, chained with CVE-2026-15410, a post-authentication command injection in the Appliance Management Console — to burrow into multiple enterprise networks, harvest credentials and stage ransomware, per Rapid7 and Volexity telemetry, with active exploitation observed since late June; CISA added both to the KEV catalogue with a 17 July federal deadline.
severity critical (CVSS 10.0) · exploited in the wild · CVE-2026-15409 · EU: NIS2, CRA · actor Inc Ransomware (RaaS affiliate) (60%)
[P1] New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code — The Hacker News
Why it matters: An unauthenticated remote-code-execution chain in WordPress core itself — no plugins, no configuration — with a public proof-of-concept and force-pushed emergency patches.
wp2shell is a pre-authentication RCE in WordPress core (CVE-2026-63030) that chains a SQL injection in WP_Query's author__not_in parameter (CVE-2026-60137) with a REST batch-route confusion in /wp-json/batch/v1, working against a stock install with no plugins; it affects WordPress 6.9.0-6.9.4 and 7.0.0-7.0.1, is fixed in 6.9.5 and 7.0.2, and WordPress.org took the unusual step of force-pushing the update via auto-update as a public proof-of-concept circulated and early exploitation emerged.
severity critical · exploited in the wild · CVE-2026-63030 · EU: NIS2, CRA, GDPR
[P2] Ernst & Young discloses data breach after support system hack — BleepingComputer
Why it matters: A Big Four firm breached through its third-party support-ticket system, with client tax filings — including Social Security numbers — in the exfiltrated documents.
Ernst & Young is notifying clients that an unauthorised party accessed a third-party support-ticket platform used by its IT staff between 28 March and 12 April 2026, downloading documents; support tickets included client tax-preparation files, and the exposed data may include Social Security numbers, financial-account codes and card details tied to individuals' investment holdings at EY's institutional clients. EY filed with the California Attorney General on 15 July and is offering 24 months of identity monitoring.
severity high · exploited in the wild · EU: GDPR, NIS2, DORA
[P2] Abbott probes two cyber incidents amid extortion claims — BleepingComputer
Why it matters: A medical-device and diagnostics giant hit by two separate intrusions in a week — one through a vishing call that compromised a single-sign-on account.
Abbott is investigating two separate incidents: the ShinyHunters extortion group listed its Cancer Diagnostics (Exact Sciences) business after claiming a mid-June vishing attack that compromised a Microsoft Entra SSO account and reached internal systems, threatening to publish data after a deadline extended to 21 July; separately, an actor calling itself ShadowByt3$ claims to have breached the Core Laboratory diagnostics business via the LabCentral customer portal from 4 July, exfiltrating files through API endpoints. Abbott says operations, products and patient care are unaffected.
severity high · exploited in the wild · EU: GDPR, NIS2, MDR · actor ShinyHunters (70%)
[P2] New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens — The Hacker News
Why it matters: A botnet that scans specifically for exposed AI tooling — model runners, workflow builders, MCP servers — to steal the cloud and cluster credentials behind them.
NadMesh is a Go botnet, active since early July, that uses a Shodan-fed scanner to find internet-exposed AI services — ComfyUI, Ollama, n8n, Open WebUI, Langflow, Gradio — and MCP servers, then exploits 20-plus RCE vectors (MCP JSON-RPC command execution, Kubernetes pod escapes, Docker API abuse, Redis/Elasticsearch/Jenkins/WebLogic flaws) to steal AWS keys, cluster-admin Kubernetes service accounts and MCP tools capable of arbitrary SQL or shell; the operator dashboard claims 3,811 unique AWS keys and ships an autonomous scanner preloaded with ranges from 90-plus cloud providers.
severity high · exploited in the wild · EU: NIS2, CRA
[P3] OpenSSL HollowByte Flaw Could Freeze Server Memory with 11-Byte TLS Requests — The Hacker News
Why it matters: A denial-of-service flaw in OpenSSL where an 11-byte request forces the server to reserve outsized memory before any handshake — fixed silently, with no CVE.
HollowByte, found by the Okta Red Team, lets a remote unauthenticated attacker send an 11-byte TLS message whose length header declares a large body; vulnerable OpenSSL versions allocate the declared length — up to 131KB — before receiving or validating the payload, and because glibc does not promptly return freed memory, repeated requests strand memory and degrade the server. OpenSSL shipped fixes (4.0.1, 3.6.3, 3.5.7, 3.4.6, 3.0.21) dated 9 June with no CVE, advisory or changelog note.
severity medium · EU: NIS2, CRA