Skip to content
feed: live
>_ 0dayNews
Briefing · 2026-07-25-weekly

Week in Review: AI Ops, Certighost, M365 Failure

AI agents confirmed as operational attack tools; Certighost exposes Active Directory domains running default ADCS; Microsoft's own automation took down M365 for a day.

tldr.txt
  • Hermes AI agent deployed against Thailand's Finance Ministry in fully unattended YOLO mode — first confirmed case of an open-source AI agent conducting post-exploitation autonomously on a live government network
  • Certighost: working exploit public as of 2026-07-24 — any low-privilege Active Directory user can obtain a Domain Controller certificate and DCSync all hashes in the domain; no CVE assigned at time of writing
  • Microsoft 365 outage July 23-24 traced to an automation bug that removed IP routes from too many network devices simultaneously — millions affected, root cause published by Microsoft
  • Kimi K3 AI agents discovered seven Redis zero-days and built authenticated RCE PoC chains; Redis shipped seven security releases in a single day on 2026-07-23
  • Void Blizzard (Russia-aligned) exploited a Zimbra zero-click flaw for months to read Western organization mailboxes; CISA and NSA joint advisory issued
  • Clop (Cl0p) confirmed active against PTC Windchill and FlexPLM manufacturing PLM systems; data theft extortion campaign, no file encryptor
  • ChatGPT AgentForger (patched 2026-06-08, disclosed 2026-07-24): a phishing link was sufficient to deploy a rogue AI agent inside a victim's Workspace organization
  • Chaos ransomware group's msaRAT routes C2 through headless Chrome or Edge — no outbound connections from the implant process itself; Talos analysis published 2026-07-23
  • Q2 2026: approximately 200 new CVEs published daily; CISA KEV grew only 13% year-over-year — the gap is where most patch queues go wrong

The week’s signal came from three directions simultaneously: AI agents are operational attack infrastructure, a working exploit lets any domain user own Active Directory, and Microsoft’s own automation took down its cloud for nearly a day. None of these are hypothetical.

AI agents as attack infrastructure — three cases, one week

Hermes / Thai Finance Ministry — Confirmed. A threat actor installed the Hermes open-source AI agent on a rented server, enabled YOLO mode (all tool calls auto-approved, no human in the loop), and pointed it at Thailand’s Ministry of Finance. The agent conducted post-exploitation autonomously: host enumeration, privilege escalation attempts, lateral movement. First documented case of an open-source AI agent running unattended against a live government network. Source: BleepingComputer. Attribution: unconfirmed.

ChatGPT AgentForger — Patched 2026-06-08, disclosed 2026-07-24. A single phishing link was sufficient to build, authorize, and silently deploy a rogue AI agent inside a victim’s ChatGPT Workspace organization. No secondary victim interaction required. Research: Zenity Labs. Confidence: confirmed and fixed. Verify your organization is on a post-patch build.

Kimi K3 / Redis zero-days — Researchers deployed Kimi K3 AI agents against Redis source code. The agents found seven zero-days across Redis 6.2.22, 7.4.9, 8.6.4, and 8.8.0, then built working authenticated RCE PoC chains. Redis shipped seven security releases on 2026-07-23. Patched builds: 6.2.23, 7.2.15, 7.4.10. If untrusted clients have RESTORE access in your Redis deployment, patch immediately.

Vulnerabilities — patch queue

Certighost — no CVE at time of writing — Working exploit published 2026-07-24 by researchers H0j3n and Aniq Fakhrul. Any low-privilege Active Directory user can obtain a certificate for a Domain Controller machine account and authenticate as that DC. DC accounts carry directory replication rights; the resulting Kerberos credential enables DCSync, which yields all NTLM hashes in the domain including krbtgt. Exploitability requires Active Directory Certificate Services with default (non-hardened) configuration. Confidence: confirmed, working PoC public. Full coverage. Assess your ADCS configuration immediately.

RefluXFS — CVE-2026-64600 — Nine-year-old race condition in the Linux kernel’s XFS filesystem. An unprivileged local user can overwrite root-owned files and gain persistent root access. Default installations of RHEL, Fedora Server, and Amazon Linux can meet the conditions for exploitation. Qualys demonstrated the flaw; patch is available in current kernel updates. Full coverage.

Check Point SmartConsole — CVE-2026-16232 (KEV, CVSS 9.1) — Authentication bypass added to CISA KEV this week. An unauthenticated remote attacker can obtain an application login token for SmartConsole. Actively exploited. Patch: July 22 vendor advisory. Coverage.

Snap-confine LPE — Ubuntu Desktop — Local privilege escalation to root via snap-confine on Ubuntu Desktop. Patched. Update if you run Ubuntu Desktop with Snap enabled. Coverage.

NodeBB — eight high-severity flaws — All versions before 4.14.0 affected; all patched in 4.14.2. AI pentest agents (Aikido Security) found all eight in a six-hour review. Administrators: update to 4.14.2. Coverage.

Bing image processing — CVE-2026-32194, CVE-2026-32195 (patched) — Crafted SVG submissions to Bing’s image API executed as NT AUTHORITY\SYSTEM on Windows workers and as root on Linux workers across the production fleet. Microsoft patched both CVEs. Attack surface was Bing’s public image submission endpoint. Coverage.

Infrastructure failure

Microsoft 365 outage — July 23-24 — Root cause confirmed by Microsoft: an automated network maintenance request removed IP routes from significantly more devices than intended. Teams, SharePoint, Exchange Online, and the M365 Admin Center went down simultaneously. Outage window: approximately 23 hours. Millions of users affected. The failure originated from Microsoft’s own automation, not an external attack. Root cause analysis is public. Initial outage report.

Ransomware tracker

Clop / PTC Windchill and FlexPLM — Active campaign confirmed as of 2026-07-24. Clop is targeting internet-exposed PTC Windchill and FlexPLM PLM instances — data theft and extortion, no file encryptor. Both products are standard in manufacturing, aerospace, and defense supply chains. If either is internet-accessible in your environment, restrict exposure and audit access logs now.

Chaos ransomware / msaRAT — Talos published analysis this week. msaRAT is a Rust implant that routes C2 through the victim’s own Chrome or Edge browser in headless mode. The implant process communicates only with 127.0.0.1; the browser handles all external traffic via WebRTC over TURN. No outbound connections from the implant itself. This C2 pattern defeats network-layer detection keyed on process-to-external connections. Attribution: Chaos ransomware group.

Threat intel

Void Blizzard / Zimbra zero-click — Confirmed. Russia-aligned state actor (also tracked as Laundry Bear) exploited a then-unknown flaw in Zimbra’s webmail client to access Western organization mailboxes over an extended period. Opening a malicious message was sufficient to trigger. Payload collected: last 90 days of email, full organizational directory, browser-saved passwords, 2FA recovery codes. CISA, NSA, and partner agencies issued a joint advisory. Zimbra has patched; verify current version. Confidence: confirmed by joint agency advisory.

BlueNoroff / Zoom-Teams phishing kit — North Korean threat actor (DPRK-aligned). Active phishing kit operating via typosquatted Zoom and Microsoft Teams domains. This week’s new detail: the kit profiles target crypto wallet holdings before payload delivery, prioritizing high-value holders. Campaign ongoing. Confidence: confirmed research.

Golden Chickens resurface — Malware-as-a-service operator introduced four new families: TinyEgg, ChonkyChicken, modular ChonkyChicken, and a browser credential stealer. Extensive prior public research into their operations did not disrupt the group. Confirmed via published research.

Breach queue

  • OnTrac — Parcel delivery company notifying customers of a confirmed network breach. Customer PII potentially accessed. Affected record count: not yet disclosed. Confirmed.
  • Origin Energy — Australian energy provider confirmed unauthorized access to customer data; PII leaked online. Scope: not fully disclosed. Confirmed.
  • Chick-fil-A — 13,000 accounts — Final count: 13,000+ accounts accessed via credential stuffing, June 17–19. Prior disclosure cited 2,182 Texas residents. Confirmed by company.

The number

Q2 2026 analysis (Talos): approximately 200 new CVEs published per day. CISA KEV grew 13% year-over-year. Of 3,700+ CVSS 9+ CVEs in Q2: 95% have EPSS below 5%. Of the 32 crossing both CVSS 9+ and EPSS ≥ 50%: 25 are already on KEV. Seven are not. That is the actionable list. CVSS alone does not prioritize. KEV status and EPSS score do.

What to watch

  1. Certighost CVE assignment and patch. Working exploit is public, no vendor patch exists, no CVE assigned at time of writing. Every AD domain with default ADCS is exposed. Track daily.
  2. AI agent operational use. The Thai Finance Ministry case is confirmed. CISA guidance on autonomous AI agent security in production environments is a matter of when, not if.
  3. Clop manufacturing expansion. If Windchill and FlexPLM establish a playbook, other internet-exposed manufacturing PLM and ERP systems are the next surface.
  4. Redis patch adoption. Seven concurrent releases means uptake will be uneven. RESTORE-accessible Redis instances remain at risk until patched.
  5. Void Blizzard scope. Joint advisory issued. Affected organization count not published. Assess any Zimbra deployment and confirm patch status now.

— airgap

Sources