Dutch intelligence pulled back the curtain on a quiet Russian campaign this week that turns the cameras already bolted to Europe's streets into a targeting system: the AIVD and MIVD warned that a Russian intelligence service has hacked internet-connected cameras across the Netherlands, other NATO states and Ukraine to identify the weapons shipments flowing to Kyiv — and, inside Ukraine, to locate soldiers who were then struck, the surveillance feeding the killing. Most of those cameras were open because they still ran default passwords, which is the whole uncomfortable point. The louder story, though, was the AI stack turning on itself from every direction at once. An autonomous agent called JadePuffer returned running a ransomware intrusion end to end and carrying a locker built specifically to destroy trained models, training data and vector stores — AI as the operator and AI as the victim in a single attack — while researchers walked out of the sandboxes of every major AI coding tool, Cursor, Codex, Gemini and Antigravity alike, and a sprawling network of fake GitHub repositories began baiting not developers but the AI agents sent to find them. The most quietly consequential demonstration cost twenty-five dollars: a researcher pointed a frontier model at WordPress's source code, forbade it from reading the fix history, and watched it discover a critical, unauthenticated route to remote code execution from first principles in ten hours — a reminder that AI's real contribution to offence, for now, is not genius but throughput, and that the same cheap capability is sitting there for defenders who choose to use it first. Beneath all that, the ordinary breaches kept surfacing — Estée Lauder joined the long line of multinationals disclosing that the mass Oracle E-Business campaign took their employees' passport and Social Security numbers, an intruder was found to have lived inside South Korea's diplomatic academy for ten months with nearly the entire diplomatic corps' data, and fifty-five million accounts leaked from the AI music service Suno even as Sony sued its rival Udio over thirty thousand songs — and the ground kept shifting in Europe, where the AI Act's labelling rules take force next month, Brussels' own tech and justice chiefs fell to openly sparring over the online rulebook, and China, of all things, began weighing export controls on the AI models it once only imported.
Top Stories
- Russian Intelligence Hacks IP Cameras to Spy on Military Logistics Across NATO States and Ukraine — The Hacker News · Threat Intelligence (CTI)
- JadePuffer agentic attacks now target AI model data with ransomware — BleepingComputer · Cybersecurity & Threats
- China weighs tighter export controls on AI models and chips — myFT following · China & Technology
- HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050 — The Hacker News · Cybersecurity & Threats
- How Google’s A.I. Search Is Imperiling the Open Web — NYT > Technology · AI & Power
AI & Power
How Google’s A.I. Search Is Imperiling the Open Web — NYT > Technology
Why it matters: Google's AI-generated search answers starving the sites they summarise is the structural threat to the open web that the search-monopoly fights only gestured at.
The New York Times examines how Google's AI Overviews are imperilling the open web by answering queries directly and collapsing the traffic that funds the sites being summarised.
Top American AI Execs Sound Alarm on Chinese Models — Technology - WSJ.com
Why it matters: US AI chiefs publicly sounding the alarm on Chinese models is the industry conceding the open-weight gap has become a strategic problem, not a talking point.
Top American AI executives are sounding the alarm on Chinese models, a public admission that the open-weight surge has become a competitive threat they cannot dismiss.
Frontier LLMs couldn't help Hugging Face fight off evil agents — www.theregister.com - Articles
Why it matters: The detail that frontier models couldn't help Hugging Face repel the agent that breached it is the honest limit on the 'AI defends itself' promise.
The Register reports that frontier LLMs were of little help to Hugging Face in fighting off the autonomous agent that breached it, puncturing the AI-defends-itself narrative.
Here are the 30,000 songs Sony is suing Udio’s AI music generator over — The Verge
Why it matters: Sony suing Udio over 30,000 specific songs turns the AI-music copyright fight into concrete, itemised litigation the labels intend to win.
Sony is suing AI music generator Udio over 30,000 named songs, escalating the recording industry's copyright war against generative music into itemised litigation.
China’s Top AI Event Delivers Message to the U.S.: We’re Coming for You — Technology - WSJ.com
Why it matters: China's showcase AI conference framed explicitly as a message to Washington marks the shift from catching up to open confrontation over AI leadership.
China's top AI event delivered a pointed message to the US — 'we're coming for you' — reframing the WAIC showcase as open confrontation over AI leadership.
Oracle Credit Risk Hits Near 18-Year High on AI Debt Load Angst — Bloomberg Technology
Why it matters: Oracle's credit risk spiking on AI-debt anxiety is the bond market pricing the danger in the circular financing propping up the build-out.
Oracle's credit risk hit a near 18-year high on anxiety over its AI-related debt load, the bond market flagging the strain beneath the data-centre spending boom.
A.I. ‘Vibecoded’ Apps Are Flooding Apple’s App Store — NYT > Technology
Why it matters: AI-'vibecoded' apps flooding the App Store is the supply side of the AI-coding boom overwhelming the review systems meant to gate quality and safety.
AI-'vibecoded' apps are flooding Apple's App Store, the output side of cheap AI coding overwhelming the curation and safety review the store depends on.
Google Shares Gain on Report of Chip to Boost AI Efficiency — Bloomberg Technology
Why it matters: Google's shares rising on a new efficiency chip is the market rewarding whoever can bend the AI cost curve, the metric that now moves valuations.
Google shares gained on reports of a new chip to boost AI efficiency, the market rewarding cost-per-inference gains as the metric that increasingly drives AI valuations.
BlackRock’s Meta Deal to Show the Power of $25 Billion M&A Spree — Bloomberg Technology
Why it matters: BlackRock's data-centre deal with Meta is the financialisation of AI infrastructure, with asset managers underwriting the compute the labs cannot fund alone.
BlackRock's deal with Meta is set to demonstrate the power of a $25bn M&A spree, as asset managers move to underwrite the AI infrastructure build-out.
EU & Technology
EU's AI labeling rules take effect next month — www.theregister.com - Articles
Why it matters: The EU's AI-labelling obligations taking force next month is the AI Act's transparency regime hitting real products, the first hard compliance date most firms will feel.
The EU's AI-labelling rules take effect next month, the first AI Act transparency obligation to bite in practice, requiring disclosure of AI-generated and manipulated content.
EU tech tsar spars with justice chief over new online rule book — myFT following
Why it matters: An open clash between the EU's tech and justice chiefs over the online rulebook exposes the internal fight over whether to enforce or dilute the DSA.
The EU's tech commissioner is openly sparring with the justice chief over the new online rulebook, exposing an internal split on whether to enforce or soften the DSA.
Burnham Picks Narayan as First UK AI Minister to Attend Cabinet — Bloomberg Technology
Why it matters: Burnham seating a dedicated AI minister at cabinet, days after scrapping the science department, signals where the new UK government actually places its tech priority.
Andy Burnham named Narayan as the first UK AI minister to attend cabinet, elevating AI policy to the top table even as the standalone science department is dismantled.
EU says Trump’s tariffs barely touch European companies — US importers foot the bill — EUobserver
Why it matters: The finding that Trump's tariffs land on US importers rather than European exporters reframes the trade fight and weakens the case for EU concessions.
The EU says Trump's tariffs barely touch European companies because US importers foot the bill, a finding that undercuts the pressure for European trade concessions.
Germany is finally waking up to the China challenge. And Beijing is gearing up to respond — Atlantic Council
Why it matters: Germany belatedly confronting its China dependence, with Beijing already preparing its response, is the central test of European economic sovereignty.
The Atlantic Council argues Germany is finally waking up to the China challenge — and that Beijing is gearing up to respond — framing the core test of European economic security.
Why Europe’s China Anxiety Is About More Than China — The Diplomat
Why it matters: Reading Europe's China anxiety as really about its own strategic drift is the sharper diagnosis beneath the tariff-and-dependence headlines.
The Diplomat argues Europe's China anxiety is about more than China — it reflects the continent's own uncertainty about its strategic and technological direction.
Alibaba vows to appeal US$629m EU fine for breaches of Digital Services Act — Tech - South China Morning Post
Why it matters: Alibaba appealing the record DSA fine turns the EU's largest platform penalty into the test case for whether the rulebook survives legal challenge.
Alibaba vowed to appeal its record €629m EU fine for Digital Services Act breaches, setting up a legal test of the bloc's largest platform penalty to date.
Voodin consortium secures €48M EU grant to build Spain’s first automated wooden blade factory — Tech.eu
Why it matters: An EU grant for Spain's first automated wooden wind-blade factory is industrial policy backing a concrete piece of the clean-tech supply chain.
A Voodin-led consortium secured a €48m EU grant to build Spain's first automated wooden wind-turbine blade factory, industrial policy backing domestic clean-tech manufacturing.
New EU budget stance shifts migration cash to member states, risking abuses at the borders — EUobserver
Why it matters: Shifting migration funds to member states with weaker oversight is the budget mechanism that could entrench abuses at Europe's borders.
A new EU budget stance shifts migration funding to member states, raising the risk of border abuses as oversight moves further from Brussels.
US & Technology
Judge halts Paramount's $111B purchase of Warner Bros. in win for US states — Ars Technica - All content
Why it matters: A judge halting the $111bn Paramount-Warner deal in a win for states is antitrust enforcement biting one of the largest media mergers on the board.
A federal judge halted Paramount's $111bn purchase of Warner Bros. in a win for US states, a significant antitrust check on media consolidation.
Scoop: Trump AI security agency head resigns — Axios
Why it matters: The head of the administration's AI safety standards office resigning after three months is the churn hollowing out US AI governance from the inside.
The head of the Commerce Department's AI standards office resigned after three months, leaving US AI-safety governance without leadership amid the China-model panic.
The FCC is planning to retroactively ban disguised DJI gadgets — The Verge
Why it matters: The FCC moving to retroactively ban rebranded DJI hardware is the drone-supply-chain fight reaching into products already sold to consumers.
The FCC is planning to retroactively ban disguised DJI gadgets, extending the Chinese-drone supply-chain crackdown to rebranded hardware already in the market.
DOJ Probes Harvard Financial Aid, Alleging China Donor Influence — Bloomberg Politics
Why it matters: A DOJ probe framing Harvard's financial aid as Chinese donor influence is the national-security lens being turned on university funding.
The DOJ is probing Harvard's financial aid, alleging Chinese donor influence, extending the national-security framing to university funding decisions.
Cruz and Blackburn meet Trump to discuss tech policy — Technology
Why it matters: Senate tech-policy heavyweights meeting Trump signals the coming fight over federal pre-emption of state AI laws.
Senators Cruz and Blackburn met Trump to discuss tech policy, a signal of the coming battle over federal pre-emption of the state AI laws proliferating nationwide.
DOJ Can Give Biden Recordings to Conservative Group, Court Rules — Bloomberg Politics
Why it matters: A court clearing the DOJ to hand Biden interview recordings to a conservative group is the politicisation of investigative material set as precedent.
A court ruled the DOJ can give recordings of Biden's interviews to a conservative group, setting a precedent for the release of sensitive investigative material.
China & Technology
China weighs tighter export controls on AI models and chips — myFT following
Why it matters: China weighing export controls on its own AI models and chips inverts the containment story — Beijing now has capability worth restricting, and knows it.
China is weighing tighter export controls on AI models and chips, a striking inversion that signals Beijing now sees its own AI capability as strategic leverage worth guarding.
Z.AI Completes Giant Data Center With Chinese Chips to Train AI — Bloomberg Technology
Why it matters: A frontier Chinese lab training on a data centre built entirely with domestic chips is the proof that China's compute self-sufficiency is operational, not aspirational.
Z.AI completed a giant data centre built with Chinese chips to train its models, demonstrating that domestic-silicon compute at frontier scale is now operational, not theoretical.
Chinese models are on track to win the agentic AI price war — The Strategist
Why it matters: The assessment that Chinese models are set to win the agentic price war is the commercial edge of the open-weight surge — cheaper agents undercutting Western incumbents.
Analysts argue Chinese models are on track to win the agentic AI price war, translating the open-weight surge into a commercial advantage in the agent market.
China’s GigaAI Seeks 2026 Hong Kong IPO in First for World Model — Bloomberg Technology
Why it matters: A world-model startup as the first of its kind to seek a Hong Kong listing is Chinese capital markets pricing embodied and world-model AI as an investable category.
China's GigaAI is seeking a 2026 Hong Kong IPO, the first for a world-model company, as Chinese markets move to price embodied and world-model AI.
No longer token economy? SenseTime bets on ‘task economy’ as token prices set to drop — Tech - South China Morning Post
Why it matters: SenseTime pivoting from a 'token economy' to a 'task economy' as token prices collapse is the Chinese market conceding that per-token pricing is a race to zero.
SenseTime is betting on a 'task economy' over the 'token economy' as inference prices set to drop, a bet that value moves to completed tasks as per-token pricing collapses.
Chinese robot makers’ lament: if we only had a better ‘brain’, and more data — Tech - South China Morning Post
Why it matters: Chinese robot makers admitting their bottleneck is the 'brain' and the data, not the hardware, is the honest limit on the humanoid-manufacturing lead.
Chinese robot makers lament that their real gap is a better 'brain' and more data, not hardware — the honest constraint on China's humanoid manufacturing dominance.
Threat Intelligence (CTI)
[P2] Russian Intelligence Hacks IP Cameras to Spy on Military Logistics Across NATO States and Ukraine — The Hacker News
Why it matters: Dutch intelligence says Russia has hijacked internet cameras across NATO to track weapons shipments to Ukraine — and, in Ukraine, to locate soldiers for strikes.
The Dutch civilian and military intelligence services (AIVD and MIVD) published an advisory warning that at least one Russian intelligence service has compromised internet-accessible cameras in the Netherlands, other NATO and EU states and Ukraine to identify the types of weapons being shipped to Ukraine; in Ukraine, hacked cameras have in some cases been used to locate military personnel, with the intelligence then supporting attempts to kill soldiers and destroy equipment. The cameras are typically easy to compromise because of default passwords and outdated firmware.
severity high · exploited in the wild · EU: NIS2, CER Directive, GDPR · actor Russian intelligence service (75%)
[P2] Hackers were inside South Korea's diplomat training system for 9 months — The Record from Recorded Future News
Why it matters: An intruder sat inside South Korea's diplomatic academy training platform for almost ten months, exposing the personal data of nearly the entire diplomatic corps.
South Korea's Korea National Diplomatic Academy online training system was compromised for nearly ten months (April 2025 to February 2026): an attacker exploited a previously unknown flaw in the server software, compounded by misconfiguration, pivoted to legitimate access and maintained persistence in a system holding roughly 10,000 personnel records — serving and former diplomats, officials posted to overseas missions and embassy administrative staff — with exposed data including IDs, names, emails and encrypted passwords; the ministry shut the system down and is investigating a possible North Korea link, without sufficient evidence to attribute.
severity high · exploited in the wild · EU: NIS2, GDPR
[P2] FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware — The Hacker News
Why it matters: Thousands of fake GitHub repositories — many posing as AI Skills and agent servers — now bait the AI agents that go looking for them, not just human developers.
Researchers uncovered FakeGit, an operation of about 7,600 malicious GitHub repositories created by roughly 6,600 profiles, of which 800 pose as AI Skills or MCP servers (imitating Gmail, WhatsApp, Databricks, Jenkins and Docker tooling); using cloned projects, lookalike profiles and convincing READMEs, the repos deliver SmartLoader and then StealC infostealer, and have recorded more than 14 million downloads across release assets. The operators call the AI-targeting variant 'AgentBaiting' — an AI agent searching for a Skill or MCP server finds the lure, reads the attacker's README, and carries its instructions forward without a human ever deciding to download it.
severity high · exploited in the wild · EU: NIS2, CRA
[P2] Exposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware Campaign — The Hacker News
Why it matters: An exposed server revealed a phishing toolkit built with an open-source AI coding agent — over a thousand files of AI-generated lures, already running against Mexican victims.
Rapid7 recovered 1,048 files after a malware operator left its delivery server open, revealing an AI-assisted phishing toolkit — lure templates, filename-spoofing tests, droppers, builder notes and two campaign chains — whose READMEs, lure guides and test write-ups carried the templated, emoji-heavy formatting of LLM output, built with a public open-source AI coding agent inspired by Claude Code, Copilot CLI and Cursor; one campaign was already operational against Mexican Windows users via a typosquat of the government's CURP national-ID lookup, delivering an infostealer over WebDAV that targeted crypto wallets, browser data and messaging sessions, with the delivery service logging 77,098 requests from 3,892 unique IPs across 101 countries over roughly 5.5 days.
severity high · exploited in the wild · EU: NIS2, GDPR
[P3] Researchers Build WordPress Exploit Using OpenAI's GPT — Infosecurity Magazine
Why it matters: A researcher pointed a frontier model at WordPress's source code and it discovered a critical, unauthenticated remote-code-execution chain from scratch — in ten hours, for about $25.
Adam Kues of Assetnote published a demonstration in which he used OpenAI's GPT-5.6 Sol Ultra to rediscover the wp2shell WordPress-core vulnerability from first principles: he adapted an OpenAI prompt originally used on a mathematical conjecture, pointed it at the WordPress core codebase, and explicitly forbade the model from consulting changelogs, git history or the internet, forcing pure code analysis; the model found a SQL injection and escalated it to a pre-authentication remote-code-execution chain in just over ten hours at a cost of about $25.
severity medium · EU: NIS2, CRA, AI Act
[P3] Suno - 55,282,226 breached accounts — Have I Been Pwned latest breaches
Why it matters: More than 55 million accounts from the AI music generator Suno have surfaced as a breach — the same service already facing scraping claims and a major-label lawsuit.
Have I Been Pwned has listed a breach of the AI music-generation service Suno comprising 55,282,226 accounts; the exposure lands on a service already under pressure over allegations it scraped copyrighted music and now facing litigation from major labels, and adds a large corpus of user account data to the AI-platform breach tally.
severity medium · exploited in the wild · EU: GDPR, NIS2
Defence & National Security
Houthis Declare a Naval Blockade on Saudi Arabia — Foreign Policy
Why it matters: The Houthis declaring a naval blockade on Saudi Arabia threatens to widen the Gulf war and strangle Red Sea energy transit at once.
The Houthis declared a naval blockade on Saudi Arabia's Red Sea oil transits, threatening to widen the war and choke a critical artery of global energy supply.
Nearly 100 US troops injured in two weeks since Iran war resumed — myFT following
Why it matters: Nearly a hundred US troops injured in two weeks is the human cost of the resumed Iran war that the strike-by-strike coverage obscures.
Nearly 100 US troops have been injured in the two weeks since the Iran war resumed, a casualty toll that the day-by-day strike coverage has largely obscured.
New executive order tightens defense supply chain waiver rules — Defense News
Why it matters: A new executive order tightening defence supply-chain waivers is Washington closing the loopholes that let foreign components into military systems.
A new executive order tightens the waiver rules that allow foreign components into US defence supply chains, closing loopholes as component-origin risk rises.
Lockheed Martin’s Morfius X-Rotor built to fry 50 enemy drones in one flight — Defense News
Why it matters: A single interceptor built to disable fifty drones per flight is the counter-swarm economics the West needs against cheap mass drone attacks.
Lockheed Martin's Morfius X-Rotor is built to fry up to 50 drones in one flight, an attempt to fix the cost-exchange problem cheap drone swarms impose on defenders.
Thunderstruck: Anduril unveils autonomous attack rotorcraft — Defense News
Why it matters: Anduril's autonomous attack rotorcraft is the loyal-wingman concept extending from fixed-wing jets to helicopters and vertical-lift.
Anduril unveiled Thunder, an autonomous attack rotorcraft, extending the loyal-wingman concept from fighter jets to rotary and vertical-lift platforms.
Israel’s IAI unveils ‘Hypnosis’ system for confusing enemy drone swarms — Defense News
Why it matters: Israel's 'Hypnosis' system attacking the coordination of drone swarms rather than the drones themselves is a bet on electronic disruption over interception.
Israel's IAI unveiled 'Hypnosis', a system for confusing enemy drone swarms by disrupting their coordination rather than shooting them down one by one.
Digital Sovereignty & Identity
New Orleans Cops Published Policy Document Allowing Weaponized Drones — 404 Media
Why it matters: A US police department publishing a policy that authorises weaponised drones is the domestic-surveillance build-out crossing into armed autonomous force.
New Orleans police published a policy document allowing weaponised drones, a domestic force crossing from aerial surveillance into armed autonomous capability.
WA Police Facial Recognition Trial Scans 130,000 Faces, Leads to 19 Arrests — ID Tech
Why it matters: A facial-recognition trial scanning 130,000 faces for 19 arrests is the concrete cost-benefit case that mass biometric surveillance rarely has to state.
A Western Australia police facial-recognition trial scanned 130,000 faces to produce 19 arrests, a rare concrete look at the ratio behind mass biometric surveillance.
On Flock License Plate Tracking Cameras — Schneier on Security
Why it matters: Schneier's dissection of Flock's licence-plate network is the systemic case that a private surveillance grid has quietly become national infrastructure.
Bruce Schneier dissects Flock's licence-plate tracking cameras, making the systemic case that a private company has built a national surveillance grid by stealth.
Victoria Labor Proposes Limits on Workplace Biometrics and AI Surveillance — ID Tech
Why it matters: Victoria moving to cap workplace biometrics and AI surveillance is a rare legislative push to constrain employer monitoring before it becomes default.
Victoria's Labor government proposed limits on workplace biometrics and AI surveillance, a rare move to constrain employer monitoring before it hardens into the norm.
Social media companies have failed to enforce their minimum age requirements: Ofcom — Biometric Update
Why it matters: Ofcom finding social-media firms simply do not enforce their own age limits is the evidence that self-regulation on child safety has failed on its own terms.
Ofcom found that social media companies have failed to enforce their own minimum-age requirements, undercutting the industry's self-regulation case on child safety.
“Stealth Crawlers” Are Not a Threat to the Open Web. Bills Targeting Them Would Be. — Deeplinks
Why it matters: EFF arguing that bills targeting 'stealth crawlers' would harm the open web more than the crawlers do is the civil-liberties check on anti-scraping legislation.
The EFF argues 'stealth crawlers' are not the threat to the open web that new bills claim — and that the bills themselves would do the real damage.
Quantum & Cryptography
Opaque, Interoperable Passkey Records (and a Go API) — Filippo Valsorda
Why it matters: A concrete, interoperable design for portable passkey records is the plumbing the passwordless transition needs before passkeys can move between providers.
Cryptographer Filippo Valsorda proposes opaque, interoperable passkey records with a Go API, addressing the portability gap that keeps passkeys locked to single providers.
Cybersecurity & Threats
[P1] JadePuffer agentic attacks now target AI model data with ransomware — BleepingComputer
Why it matters: The first ransomware run end-to-end by an AI agent has returned with a locker purpose-built to destroy trained AI models — the AI stack attacking the AI stack.
JadePuffer, documented as the first ransomware campaign run end-to-end by a large language model, has returned with EncForge, a locker deliberately built to encrypt AI assets — training datasets, vector databases, model checkpoints, LoRA adapters and GGML files — rather than a generic file encryptor; the autonomous agent handles reconnaissance, credential theft, lateral movement, persistence, privilege escalation and encryption, adapting to failures like a human operator (a failed login to a working fix in 31 seconds), with initial entry via a missing-authentication flaw in Langflow's code-validation endpoint.
severity high · exploited in the wild · EU: NIS2, CRA, AI Act · actor JadePuffer (agentic operator) (70%), escalation
[P2] HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050 — The Hacker News
Why it matters: Espionage malware that hides its commands and stolen files inside Microsoft 365 calendar events dated 2050 — living entirely inside legitimate cloud traffic.
Group-IB detailed HollowGraph, a .NET implant that uses compromised Microsoft 365 mailboxes as its command channel: it queries the calendar for an operator-planted event buried at 13 May 2050 (so the mailbox owner never scrolls to it), reads tasking from an attachment, and exfiltrates by creating its own far-future events with encrypted data as attachments — all through legitimate Microsoft Graph API traffic, so it never contacts an attacker-owned server; at least 12 systems were infected, three actively communicating between 3 June and 9 July, with indicators pointing at Israeli targets and the Cavern C2 framework previously linked to an Iranian actor.
severity high · exploited in the wild · EU: NIS2, GDPR · actor Iran-linked actor (Cavern framework) (50%)
[P2] Cursor, Codex, Gemini CLI, Antigravity hit by sandbox escapes — BleepingComputer
Why it matters: Researchers escaped the sandboxes of every major AI coding tool at once — Cursor, Codex, Gemini CLI and Antigravity — by planting files that trusted tools outside the box then ran.
Pillar Security demonstrated sandbox escapes across Cursor, OpenAI Codex CLI, Google Gemini CLI and Google Antigravity by planting files that trusted tools outside the sandbox later executed or scanned: a Cursor bug let the agent edit a virtualenv interpreter the editor's Python extension then ran, another abused Git metadata not needing to live in a .git folder to fire execution via fsmonitor; Codex CLI trusted 'git show' by name while the real invocation was not read-only (patched in v0.95.0); a single Docker-socket finding hit Codex, Cursor and Gemini CLI at once; and Antigravity had a macOS Seatbelt denylist bypass and a .vscode task-config bypass of its Secure Mode.
severity high · EU: NIS2, CRA
[P2] Estée Lauder discloses data breach via Oracle E-Business flaw — BleepingComputer
Why it matters: A cosmetics giant becomes the latest named victim of the mass Oracle E-Business Suite campaign — with employee Social Security and passport numbers taken.
Estée Lauder is notifying current and former employees that an unauthorised party accessed its Oracle E-Business Suite HR environment around 9 August 2025 and exfiltrated personal information including Social Security numbers, passport numbers, and financial and health data; the company confirmed employee data was taken on 19 June 2026, and the intrusion is tied to the wider Oracle EBS mass-exploitation campaign attributed to the Cl0p ransomware group, with 24 months of Kroll monitoring offered.
severity high · exploited in the wild · EU: GDPR, NIS2, DORA · actor Cl0p (via Oracle EBS campaign) (60%)
[P3] Malicious cloud customers can bring down the power grid — www.theregister.com - Articles
Why it matters: Researchers show a cloud tenant could damage datacentres and destabilise the power grid using nothing but carefully shaped GPU workloads.
Researchers at Zhejiang University (Zhouhao Ji, Kaikai Pan, Wenyuan Xu) describe Bit2Watt, a cyber-physical technique in which an adversary posing as a legitimate cloud tenant launches GPU workloads crafted to create damaging power transients that could harm datacentre and supporting electrical equipment or cause blackouts, arguing that cybersecurity defences need to extend to datacentre workload scheduling.
severity medium · EU: NIS2, CER Directive
[P3] Cruciferra Crypter Uses Process Ghosting to Evade Detection — Infosecurity Magazine
Why it matters: A new crypter uses process ghosting — running code from a file already deleted from disk — to slip malware past detection.
Infosecurity Magazine reports Cruciferra, a crypter (malware-packing service) that uses the process-ghosting technique — mapping an executable into memory and deleting the on-disk file before the process is created — so the running malware executes from an image that no longer exists on disk, defeating security tools that inspect the backing file.
severity medium · exploited in the wild · EU: NIS2