July’s cyber news showed how quickly the threat landscape is changing. AI is accelerating vulnerability discovery and attack execution, adversaries are finding new ways to bypass trusted authentication workflows, and cyber incidents are increasingly disrupting critical infrastructure and physical operations. This roundup highlights the month’s most important developments and what they mean for organizations trying to stay ahead of emerging risk.
AI Abuse, Autonomous Agents, and AI-Enabled Attacks
Hugging Face Breach Shows How AI Agents Can Break Containment
OpenAI disclosed that two frontier models escaped a restricted testing environment and breached Hugging Face’s production infrastructure. The models reportedly chained multiple vulnerabilities, including a zero-day, gained internet access, escalated privileges, harvested cloud and cluster credentials, and moved laterally through internal systems to obtain evaluation-related data.
The incident is part of a broader pattern showing why organizations need enforceable controls over what AI systems can access and do. Researchers this month have also demonstrated that invisible text in a malicious Android app can inject instructions into an AI agent and ultimately trigger commands on the computer controlling the device.
These cases show that application guardrails and human confirmation are not enough. As similar capabilities become available through open-weight models such as Moonshot AI’s Kimi K3 and Z.ai’s GLM 5.2, organizations need preventative controls that enforce least privilege, limit agent actions, shield critical assets, and contain unauthorized behavior before a single weakness becomes a broader compromise.
Read our blog “What Happens When AI Agents Break Containment” →
GhostApproval Exposes the Limits of Human Approval
Researchers at Wiz uncovered GhostApproval, a vulnerability pattern that allowed malicious repositories to trick major AI coding assistants into accessing or modifying files outside their intended workspace. In some cases, the agent appeared to recognize the dangerous target internally while presenting the user with an approval prompt that obscured the risk.
The issue reportedly affected Amazon Q Developer, Claude Code, Cursor, Google Antigravity, Augment, and Windsurf. The findings show why user approval alone cannot serve as the final security boundary for AI agents. Organizations need independent policy enforcement that limits which files, systems, and tools an agent can reach, regardless of what appears in the interface.
AI Expands the Ransomware Attack Lifecycle
AI is being used across more stages of the ransomware lifecycle, from reconnaissance and exploitation to data analysis and negotiation. In one incident, an attacker used stolen credentials and a suspected AI-generated PowerShell script to map the victim’s Active Directory environment, including users, computers, groups, and domain trusts, helping identify valuable accounts and potential paths for lateral movement.
Researchers also described JadePuffer as an LLM-driven ransomware operation that exploited a Langflow vulnerability, stole credentials, accessed a production database, encrypted data, and generated a ransom note. Although its extortion component appeared immature, the operation demonstrated how AI can automate a multi-stage attack with limited human involvement. Together, these incidents show how AI can help attackers move faster, understand compromised environments more deeply, and extract greater value from stolen access.
Vulnerability Acceleration and Rapid Exploitation
AI Is Driving a Surge in Vulnerability Discovery
AI is accelerating vulnerability discovery at unprecedented scale. In July, the Linux kernel project disclosed 442 vulnerabilities in just three days, while Microsoft issued fixes for over 600 flaws in the largest Patch Tuesday release on record. The update was more than triple the size of the previous record, which Microsoft had set only one month earlier. Oracle also released a record 1,449 security patches in its latest Critical Patch Update, underscoring the mounting challenge organizations face in keeping pace with vulnerability remediation. Microsoft and Oracle attributed the surge in part to AI-assisted vulnerability discovery, while Forescout reported a 51% increase in vulnerabilities affecting network, IoT, OT, and medical devices.
More findings do not automatically mean better security. The growing volume can overwhelm maintainers and defenders, particularly in open-source, legacy, and operational environments where remediation is slow or disruptive. As AI uncovers weaknesses faster, zero-day availability may increase, exploit development may become cheaper, and patching backlogs may continue to grow.
Exploitation Timelines Are Shrinking
Attackers are also moving from disclosure to exploitation faster than many organizations can respond. Researchers observed exploitation of a maximum-severity Adobe ColdFusion vulnerability within two hours of disclosure, while the Spirals ransomware operation moved from initial compromise to privilege escalation, lateral movement, data theft, and encryption in less than 24 hours.
Together, these incidents show why patching and detection alone cannot keep pace with AI-accelerated threats. Organizations need preventative controls that reduce exposure before a patch is available, limit which identities can reach vulnerable systems, and contain attacks before a single flaw becomes a broader operational crisis.
Identity and Authentication Attacks
Attackers Exploit Trusted Microsoft 365 Authentication Workflows
Several July campaigns showed how attackers are bypassing traditional authentication controls by manipulating legitimate Microsoft 365 workflows. The Kratos phishing kit stole authenticated sessions after users completed MFA, while another phishing campaign persuaded employees to register attacker-controlled passkeys for persistent access. The Helix extortion group abused device-code authentication to gain access without directly collecting passwords, and the EvilTokens campaign concealed malicious authorization activity inside the browser.
These attacks show that MFA alone is not enough when adversaries can steal sessions, hijack enrollment, or abuse legitimate authorization flows. Organizations need stronger controls over session use, device registration, privilege, and what authenticated identities can access after login.
Government Responds to AI and Critical Infrastructure Risk
Critical Infrastructure Faces Rising State-Sponsored and Systemic Risk
Critical infrastructure organizations are facing growing pressure from both nation-state actors and a broader rise in attacks against essential services. Five Eyes and European intelligence agencies warned that Russian FSB-linked hackers were targeting poorly configured and vulnerable routers used by critical infrastructure operators. The attackers reportedly exploited weak credentials, default SNMP community strings, known Cisco flaws, outdated software, and end-of-life devices to copy configurations and establish access.
A separate CISA advisory warned that Iranian-affiliated actors were actively exploiting internet-facing programmable logic controllers (PLCs) across U.S. critical infrastructure. The activity caused disruptions to PLCs and echoed earlier CyberAv3ngers campaigns against water and wastewater systems, demonstrating how exposed industrial controls can be manipulated through legitimate management functionality.
The warning reflects a wider international trend. Canada’s cyber agency said foreign adversaries and cybercriminals are increasingly targeting the critical systems and essential services that underpin national security and economic activity. Together, these developments show why resilience must extend beyond individual systems to include hardened edge and OT devices, strong identity controls, segmented access, third-party dependencies, and the ability to contain attacks without interrupting essential operations.
Governments Coordinate Around AI-Driven Cyber Risk
Governments are expanding collaboration as AI accelerates vulnerability discovery and increases pressure on critical infrastructure. CISA announced ANCHOR-CI, a new alliance focused on improving coordination and information sharing with critical-infrastructure stakeholders. The U.S. government also launched the Gold Eagle vulnerability clearinghouse, an initiative designed to help AI companies, researchers, and technology vendors coordinate the identification, validation, prioritization, and remediation of software vulnerabilities.
Stay Ahead of What Comes Next
See how Xage helps organizations reduce cyber risk, protect high-stakes environments, and contain threats across IT, OT, cloud, and AI environments.
