STORIES LAST WEEK
Agentic ransomware automates cloud credential theft and extortion
AI agent Jade Puffer independently explored a compromised environment, harvested cloud credentials, and generated extortion instructions. The case shows attackers can automate post-exploitation work that previously required human direction. Business Insider, July 7, 2026
HalluSquatting turns invented AI recommendations into malware delivery paths
Researchers registered repository names that AI agents were likely to hallucinate, then demonstrated how automated tools could retrieve and execute malicious code. The technique creates a software supply chain risk unique to agent-directed development workflows. Tom’s Hardware, July 9, 2026
Microsoft expands security patching as AI accelerates vulnerability discovery
Microsoft is integrating AI more deeply into vulnerability detection, patch generation, and validation, potentially increasing Patch Tuesday volume. Faster discovery by defenders and attackers will put more pressure on enterprise testing and deployment processes. The Verge, July 10, 2026
KDDI breach exposes data tied to 12 million email accounts
Attackers exploited a zero-day in a third-party system connected to KDDI infrastructure serving five Japanese internet providers. The incident illustrates how one supplier weakness can expose communications data across multiple service providers. The Record, July 7, 2026
Cisco SD-WAN attacks raise concern for government and critical infrastructure networks
An ongoing campaign has repeatedly targeted Cisco SD-WAN vulnerabilities, with researchers reporting effects on government and critical infrastructure environments. Operators face elevated risk from edge devices that provide privileged access across distributed networks. Cybersecurity Dive, July 7, 2026
CISA adds three actively exploited vulnerabilities to federal patch list
CISA added three flaws with confirmed exploitation to its Known Exploited Vulnerabilities catalog, triggering remediation deadlines for federal agencies. The additions give private-sector teams a prioritized signal for patching internet-facing, and high-value systems. CISA, July 7, 2026
Linux GhostLock flaw enables root access across major distributions
A Linux kernel vulnerability present since 2011 can allow local attackers to gain root privileges. Its reach across major distributions makes inventory, kernel update planning, and mitigation validation important for server and appliance operators. SecurityWeek, July 9, 2026
Zimbra patches critical stored XSS flaw triggered by malicious email
A crafted message can execute code when opened in Zimbra’s Classic Web Client, potentially exposing session data, mailbox contents, and account settings. Organizations using the older interface should deploy version 10.1.19 promptly. BleepingComputer, July 10, 2026
Palo Alto Networks fixes authentication bypass and command injection flaws
Palo Alto Networks released advisories for 13 vulnerabilities spanning PAN-OS and related products, including authentication bypass, command injection, server-side request forgery, and denial-of-service issues. Firewall administrators should review exposure and software dependencies before deployment. SecurityWeek, July 9, 2026
Google patches Dialogflow CX flaw that exposed chatbot conversations
A Dialogflow CX weakness could have let attackers intercept or manipulate customer-service chatbot sessions containing credentials, financial information, or other sensitive data. The finding highlights risks where enterprise AI agents connect directly to customer records and workflows. Axios, July 7, 2026
Dutch police trace telecom breach to suspected local accomplice
Investigators linked the Odido telecom intrusion to a suspected accomplice inside the Netherlands, adding a local access dimension to the attack. Telecom operators must account for blended campaigns combining remote attackers with trusted or nearby facilitators. The Record, July 9, 2026
Cash App owner agrees to $45 million settlement over security failures
Block agreed to settle allegations that weak safeguards contributed to unauthorized access and fraud affecting Cash App users. The action underscores the operational and financial consequences of inadequate identity controls, monitoring, and incident response. The Record, July 8, 2026
Chrome 150 update fixes two critical use-after-free vulnerabilities
Google’s Chrome 150 security release addressed 27 vulnerabilities, including critical memory-safety flaws in the Ozone and Views components. Enterprises should accelerate browser updates because use-after-free bugs can support code execution through malicious web content. SecurityWeek, July 9, 2026
More cybersecurity news
- Last week’s news roundup
- More cybersecurity news
- All articles sponsored by NetworkTigers
About NetworkTigers

NetworkTigers is the leader in the secondary market for Grade A, seller-refurbished networking equipment. Founded in January 1996 as Andover Consulting Group, the company originally built and re-architected data centers for Fortune 500 firms. Today, NetworkTigers provides consulting and network equipment to global government agencies, Fortune 2000 companies, and healthcare companies. Visit www.networktigers.com
