Risky Bulletin: Linux kernel discloses 442 CVEs as AI bugpocalypse settles in

In other news: OpenAI was behind the Hugging Face breach; France passes kids social media ban; Germany takes down Kratos PhaaS.

Share
Risky Bulletin: Linux kernel discloses 442 CVEs as AI bugpocalypse settles in

This newsletter is brought to you by Thinkst, the makers of the much-loved Thinkst Canary. You can subscribe to an audio version of this newsletter as a podcast by searching for "Risky Business" in your podcatcher or subscribing via this RSS feed. You can also add the Risky Business newsletter as a Preferred Source to your Google search results by going here.

The Linux kernel project has disclosed 442 vulnerabilities over the past three days, in a massive dump of CVEs on its security mailing list.

Although not confirmed, the bugs were likely discovered using AI tools. Over the past months, projects like Anthropic's Glasswing and OpenAI's Daybreak have been granting access to advanced frontier cybersecurity models to top-tier security firms and researchers to find bugs with AI in major open-source projects.

Most of the bugs are low-severity issues, so nothing world-ending for the internet today.

The sudden bursts of security bugs comes after two similar ones at Microsoft and Google, which also released huge patch notes this past month.

Microsoft patched 620 bugs last week while Google patched another 433 in its Chrome browser at the start of July.

Companies like Adobe and Oracle also increased the frequency of patching cycles citing the rise of AI bug discovery. Oracle went from a quarterly security patch cycle to a monthly one, while Adobe went from a monthly to twice-monthly releases.

"Twice-monthly bulletins will enable us to keep pace with the era of frontier AI. More vulnerabilities found means more fixes to deploy and a once-a-month publication window is no longer fast enough to stay ahead of our adversaries," Adobe Chief Security Officer Aanchal Gupta wrote at the time.

But in a SRB piece last week, my colleague Tom Uren argued that the "cleansing blast of AI" won't actually help but a few, since most companies rarely apply security updates to begin with. All it's likely to do is to provide more vulnerabilities to attackers and widen a company's exposure to threats.

Larger products like the Linux kernel can probably handle an increased rate of bug reports, like it saw right now, but that doesn't mean its team is happy. Linux creator Linus Torvalds said back in May that most AI-found bugs were usually duplicates that were causing "pointless churn" and were "a waste of time for everybody involved," as the AI bugpocalypse had made the Linux security list "almost entirely unmanageable."

On the other side, smaller open-source projects are likely to be inundated going forward, as developers lack the resources and time of a larger project. This is why both Anthropic and OpenAI promised funding to the open-source ecosystem to sponsor projects and help them deal with some of the bug avalanche they are sending their way.

In April, Manifest Cyber warned about the impact on the open-source (OSS) ecosystem and made a pretty poignant but truthful prediction of what they expect to see in the coming months, some of which is already taking place, as predicted.

"AI will accelerate vulnerability discovery. OSS maintainers will struggle to keep pace. The zero-day market will grow and prices will fall. Exploitation timelines will shrink."

Risky Business Podcasts

In this edition of Between Two Nerds, Tom Uren and The Grugq discuss what mainland Chinese analysts think about Russia’s use of cyber operations in the war in Ukraine.


Breaches, hacks, and security incidents

Hackers breached South Korea's MFA for months: Unknown hackers have breached South Korea's diplomat training system in April of last year. The attackers exploited a zero-day and remained in the network for almost 10 months until February. The National Diplomatic Service's network has been down since as officials investigate the aftermath. The South Korean Ministry of Foreign Affairs believes sensitive data on more than 6,000 current and past diplomats might have been stolen. [South Korea MFA // Donga // Korea JoongAng Daily]

Kenyan presidential site defaced: Hackers have defaced the website of the Kenyan presidency with offensive messages and a ransom demand of $320,000. [BBC]

Craneware hack: Hackers have stolen a "significant volume" of customer data from healthcare billing software provider Craneware. The company said it has since expelled the hackers from its network. Craneware software is used by thousands of hospitals and pharmacies across the US to bill patients for medical services. No outage of the billing software was reported. [TechCrunch // London Stock Exchange]

Allbridge crypto-heist: Hackers have stolen $1.66 million worth of crypto assets from the Allbridge cross-chain bridge. The company claims it detected and stopped the attack 25 minutes after it happened. [Allbridge post-mortem]

DeepSeek shared chats leak online: More than 850 DeepSeek shared chats have leaked online after they've been indexed by the Google search engine. The same issue also happened to ChatGPT last year. [David Konitzny on LinkedIn]

Ttareungyi to compensate hack victims: Seoul's public bike sharing service will compensate users affected by a 2024 data breach. Affected users will receive a 30-day pass on all Ttareungyi bikes. Users will be able to use the bikes for free one hour a day for a month. More than 6.4 million users had their data stolen in the hack and are eligible. Two high-school students were arrested for the hack earlier this year in February. [Seoul Economic Daily] [h/t DataBreaches.net]

Nextcloud dismisses hack rumors: EU cloud service provider Nextcloud says that the maintenance of its main website over the weekend was not caused by a hack but was just "a basic infrastructure issue," despite screenshots published online of what appears to be a defacement.

Post by @nextcloud@mastodon.xyz
View on Mastodon

OpenAI takes responsibility for Hugging Face breach: OpenAI has taken credit for the hack of the Hugging Face AI model hosting platform last week. The company says some of its models escaped their sandbox during a test evaluation of their cyber capabilities and breached Hugging Face's servers. The involved models included GPT‑5.6 Sol and an unreleased one. OpenAI says it's now working with Hugging Face to investigate the incident. [OpenAI]

We have now reached the "AI models escaping their test environments to conduct autonomous cyberattacks" part of the story

[image or embed]

— Casey Newton (@caseynewton.bsky.social) July 21, 2026 at 11:03 PM

General tech and privacy

Parental controls coming to Threads: Meta is rolling out parental controls for Threads, the social media networks most people forget it exists. [Meta]

App Store down in Russia: The Apple App Store was down on Monday in Russia, with users reporting hanging connections to servers and failed app downloads. The country's internet watchdog denied blocking the service, but they have a history of throttling traffic to super slow speeds, which is not a block, but not a free internet either. [Meduza]

LG monitors silently installs apps: LG monitors are silently installing adware on their users' PCs. The LG Monitor App Installer is automatically installed when users connect an LG monitor to a Windows PC. The app is installed for both new and old monitors alike. According to reports, the app shows a wave of popups in the bottom-right corner of users' screens. [Gizmodo]

Government, politics, and policy

Canada signs new UN cybercrime convention: The Canadian government has signed the recent UN Convention against Cybercrime. The treaty was adopted in 2024 and offers a legal basis for international cooperation in the fight against online crime. Despite being highly controversial the treaty has now been signed by 78 of the UN's 193 members. The convention will come into force once it has been ratified by 40 states. Only three states have ratified so far. [Government of Canada] [h/t Alex Rudolph]

New White House EO covers software supply chains: US President Donald Trump signed an executive order on Monday that will require defense contractors to map out their supply chains. The order covers hardware equipment, raw materials, but also software supply chains. The EO is meant to reinforce the prohibition of using components from US geopolitical adversaries. [White House EO // EO fact sheet // Seeking Alpha]

France passes social media kids ban: The French parliament has passed a law banning kids under 15 from social media networks. President Macro intends to sign the bill into law. The law would apply in two phases. Social media companies would have to ban kids under 15 from registering new accounts starting in September and remove existing under-15 accounts starting January. France is the first EU country to pass such a law. [RTE]

In this Risky Business sponsor interview, Casey Ellis chats with Haroon Meer from Thinkst about building companies customers don’t hate. Haroon explains why Thinkst still offers Canary tokens for free and why it has avoided annual price hikes on its paid products. They talk about Eric Ries’s “Incorruptible”, Rob Lee’s 100-year-company approach at Dragos, and why keeping customers happy is a better business strategy than chasing easy sugar highs. 

Arrests, cybercrime, and threat intel

Kratos PhaaS takedown: German and US authorities have seize the Kratos Phishing-as-a-Service platform. The service has been active since 2024 and was used in more than 15,000 phishing campaigns. It was primarily used to target Microsoft 365 accounts. Indonesian authorities have also arrested the site's administrator. [BKA // ANY.RUN]

NSO owner had diplomatic passport: New evidence uncovered by investigative journalists shows that former NSO Group co-founder and CEO Shalev Hulio used an Israeli diplomatic passport to enter at least one country back in 2013, raising serious questions about the Israeli state's involvement and protection for the embattled spyware vendor. [OCCRP]

WC piracy: The US Justice Department said it seized more than 1,000 domains that were being used to broadcast pirated streams for World Cup matches. [DOJ]

AgentBaiting campaign: A threat actor has published more than 7,600 malicious GitHub repositories designed to pose as legitimate software projects but infect users with an infostealer. Almost a fifth of all the projects targeted users of AI and MCP-related technologies. The campaign has been live since April and received more than 14 million downloads. [Island]

Operation STANDOFF: VMRay have spotted new Russian-speaking threat actor going by "GG Influence" or "ggstandoff" that is carrying out hands-on-keyboard intrusions using commodity malware and other tools. [VMRay]

More leaky servers: Another internet-exposed server has exposed the playbook of another threat actor. The server exposed its adoption of AI to automate certain parts of their attack chain, such as "rapid lure generation, detailed README documentation, and automated testing." [Rapid7]

Scammers impersonate FBI, says FBI: The FBI says scammers are impersonating its Internet Crime Complaint Center (IC3) division to approach previous victims of cybercrime and revictimize them. [FBI IC3]

PAN OS bug used to push Qilin ransomware: Qilin ransomware affiliates are exploiting a May 2026 bug in Palo Alto Networks GlobalProtect VPN gateways to breach networks. [Arctic Wolf // CVE-2026-0257]

DevMan (Funky Mantis) profile: Security firm Prodaft has published a profile on a highly controversial RaaS operation, the Funky Mantis group, also known as DevMan. Per the report's conclusion, the RaaS has now reached a pretty mature level and appears to be popular with the ransomware affiliate crowd. [Prodaft]

"The evolution from the December 2025 portal to the January 2026 v3 platform shows increasing operational maturity. The first portal focused on builders, finance, chats, support, and program rules. The later version added victim records, deadlines, lifecycle states, team creation, invitation controls, shared resources, and per-victim build options. These changes formalized processes that had previously depended more heavily on administrator and curator coordination through private chat. They also gave management greater visibility into affiliate activity, victim status, and expected revenue."

Malware technical reports

AI Pentest Checker: A user on a Russian-speaking hacking forum has released AI Pentest Checker, a fully automated web vulnerability scanning platform that sits on top of publicly available frontier AI models like Claude Opus and Claude Fable. [Cato Networks]

JadePuffer updated to target LLMs: A hacking campaign that used an autonomous AI agent to deploy ransomware earlier this month received a major update last week. The JadePuffer agent now deploys ransomware that specifically targets files that are part of LLM models. The ransomware now encrypts files related to TensorFlow, PyTorch, Apache Arrow, Hugging Face, and other AI-related infrastructure. Sysdig tracks this specific ransomware strain as ENCFORGE. [Sysdig]

HOLLOWGRAPH: A new strain of Windows malware named HOLLOWGRAPH uses M365 calendar events as its backend C&C channel. HOLLOWGRAPH appears to be part of the Cavern backdoor framework and the work of an advanced espionage group targeting Israeli entities. [Group-IB // Kaspersky]

More Lampion shenanigans: Acronis looks at recent changes in the Lampion banking trojan, which made a comeback earlier last year via ClickFix campaigns. Its main focus is still Portuguese-speaking users, with most being actually in Portugal this time, while the initial Lampion version from the 2010s was highly active in Brazil. [Acronis]

Cruciferra crypter: Proofpoint looks at Cruciferra, a sophisticated crypter-as-a-service used by multiple cybercrime threat clusters. [Proofpoint]

• Cruciferra can use one of 90+ different encryption algorithms to encrypt and decrypt stored payloads. Its sophisticated technology is enabling the cybercrime ecosystem. We will continue to monitor Cruciferra and provide updates as new capabilities and campaigns are observed.

— ThreatInsight (@threatinsight.proofpoint.com) July 20, 2026 at 7:06 PM

In this Soap Box edition of the podcast, Patrick Gray chats with Thinkst Canary founder Haroon Meer about his "decade of deception." 

APTs, cyber-espionage, and info-ops

DPRK money trail: DTEX analyzes a recent dump of financial transactions linked to a cluster of North Korean IT workers who work Western companies. In its report, the company also makes an argument that some of the money paid to these workers makes its way back to North Korea's weapons program, and then munitions from this program are sent to Russia for its war in Ukraine. It's kind of a stretch, but technically and logically plausible at the same time. [DTEX // CyberScoop]

More DPRK remote worker stuff: And while DTEX was looking at money transfers, Kudelski researchers were looking at new server infrastructure that prop up these operations. [Kudelski Security]

Vulnerabilities, security research, and bug bounty

Security updates: Honeywell, Ubuntu, Zimbra, Zyxel.

Vulnerable car alarm system: At least two million cars across the US can be hacked via a vulnerability in their car alarm system's Bluetooth feature. [WIRED]

WP RCE enters active exploitation: Just as it was widely expected, threat actors are now exploiting a recently disclosed remote code execution in WordPress sites. The vulnerability was disclosed and patched on Friday and is one of the worst bugs disclosed in the highly-popular WordPress CMS over the past decade. It allows remote attackers to take over WordPress sites in their default configurations. Reconnaissance activity was detected shortly after the disclosure, which has now moved into planting web shells. [SANS ISC // Wiz]

New SharePoint exploitation: Hackers are exploiting a recently disclosed vulnerability to take over Microsoft SharePoint servers. Attacks began on Monday, hours after proof-of-concept exploit code was published online. The vulnerability is a remote code execution bug that Microsoft fixed last week in its July Patch Tuesday. [WatchTowr on LinkedIn // CVE-2026-50522]

KEV update: CISA has updated its KEV database with four vulnerabilities that are currently exploited in the wild. This includes the two WordPress bugs that form that RCE exploit chain (see above), a Langflow AI server bug, and a 2021 bug in the DD-WRT open-source router framework.

Azure DevOps MCP server bug: An invisible comment in an Azure DevOps pull request could have hijacked a company's MCP server and AI agent. [Manifold Security]

Kiro vulnerability: Security researchers have found a vulnerability in AWS' Kiro agentic IDE that can lead to RCE attacks against its users. [Intezer // Kodem Security]

"By planting hidden instructions in a web page Kiro reads, an attacker can make Kiro rewrite its own MCP (Model Context Protocol) server configuration file and gain arbitrary code execution on the developer’s machine. No suspicious approval prompt is ever shown to the user. All the developer asked Kiro to do was perform a legitimate action."

AI sandbox escapes: Security researchers have discovered sandbox escapes and boundary bypasses for some of today's top AI agents, such as Cursor, Codex, Gemini CLI, and Antigravity. [Pillar Security]

AI models like to cheat: A report from the UK's AI research center has found that AI models will often break the rules to cheat and cut corners when tasked with performing an action. All the tested models did this. [AISI]

Gemini 3.5 Flash Cyber: Google has released Gemini 3.5 Flash Cyber, a cybersecurity model to find and patch vulnerabilities. The company has positioned the model as a lightweight alternative to frontier cyber models like Mythos. Google says the model was already used internally at the company to find bugs in Chrome, Android, YouTube, and other services. [Google]

Cisco releases Antares: Cisco has open-sourced Antares, a local AI model for finding vulnerabilities in codebases. Cisco describes Antares as a small language model (SLM) due to its small size and focus on only one specific task. The model is intended for local deployment in environments prioritizing data security, regulatory compliance, and operational control. Antares was released in two versions, one with 350 million parameters, and another one with one billion. A third version with three billion model parameters is also scheduled for release later. [Cisco // Hugging Face]

Infosec industry

Threat/trend reports: Aikido Security, Black Kite, Emsisoft, F5, PwC, Secure Code Warrior, ThreatDown, and ThreatMon have recently published reports and summaries covering various threats and infosec industry trends.

via Emsisoft

New tool—Furtex: A Russian security researcher has released Furtex, a post-exploitation and evasion research toolkit for Linux.

AIEWF 2026 videos: Talks from the AI Engineer World's Fair 2026 conference, which took place in June, are available on YouTube.

SteelCon 2026 videos: Talks from the SteelCon 2026 security conference, which took place earlier this month, are available on YouTube.

Risky Business podcasts

In this episode of Risky Business Features, James Wilson chats with SOCRadar CISO Ensar Seker and James Wilson chat about the company’s deep dive into the Fortibleed campaign. A small investigation into a curiously open directory on an unknown server expanded into the discovery of an attack that targeted 400,000 Fortinet devices.