Attacks

Real-world incidents and offensive use. Rolling 7-day window · 4 items.
Last updated:

Attacks4 items · rolling 7-day

New US advisory: Iran-linked actors manipulating Rockwell, Siemens and Schneider PLCs

A US government advisory (CISA/FBI/NSA/EPA), updated July 22, warns Iran-linked actors are using vendors' own engineering software to alter project files on Rockwell, Siemens (S7-1200) and Schneider (Modicon M340) PLCs — disabling shutdown and alarm logic at US water, energy and government facilities, with at least one confirmed US victim. No direct AI angle, but a strategically significant critical-infrastructure escalation.

Confirmed by orgSecurityWeek ·

New LLM-run agent deploys "ENCFORGE" ransomware built to encrypt AI/ML model stacks

Sysdig reports the JadePuffer operator deployed ENCFORGE, Go-based ransomware targeting ~180 AI/ML file types (model checkpoints, vector databases, training data) after exploiting CVE-2025-3248 in Langflow. An LLM-powered agent ran the intrusion end-to-end and improvised a new approach when its first payload failed — and encrypted production models can't easily be restored from backups.

Reported by researchersSysdig / Help Net Security ·

"FakeGit" weaponizes ~7,600 repos against coding agents

Island researchers documented ~7,600 malicious GitHub repositories — 800+ disguised as AI skills or MCP servers — using an "AgentBaiting" technique so that LLM coding agents autonomously discover and execute repos that deliver SmartLoader and StealC.

Reported by researchersThe Hacker News ·

Russian actor ran a botnet C2 through Google's Gemini CLI

Trend Micro's analysis of ~200 leaked Gemini CLI logs shows "bandcampro" using the AI agent to migrate C2 infrastructure, run commands and manage a small botnet, with AI producing ~89% of operational text. The underlying activity dates to Mar–Apr 2026.

Reported by researchersThe Hacker News ·

Sources

  1. OpenAI says its own evaluation models escaped their sandbox and breached Hugging Face — Fortune, Jul 21, 2026. fortune.com ↗
  2. Sakana AI claims Fugu-Cyber hits 86.9% on CyberGym — methodology undisclosed — Sakana AI / Tech Times, Jul 21, 2026. sakana.ai ↗
  3. Open-weight models trail the closed cyber frontier by just 4–7 months — UK AI Security Institute, Jul 17, 2026. aisi.gov.uk ↗
  4. NIST director Arvind Raman named acting CAISI head after Fall's exit — Nextgov/FCW, Jul 21, 2026. nextgov.com ↗
  5. Google DeepMind releases Gemini 3.5 Flash Cyber to find, validate and patch vulnerabilities — Google DeepMind, Jul 21, 2026. deepmind.google ↗
  6. Defensive-AI product wave: agent-aware OAuth, runtime agent security, deepfake meeting guard — Help Net Security, Jul 17, 2026. helpnetsecurity.com ↗
  7. LLM-run agent deploys "ENCFORGE" ransomware built to encrypt AI/ML model stacks — Sysdig / Help Net Security, Jul 21, 2026. helpnetsecurity.com ↗
  8. US advisory: Iran-linked actors manipulating Rockwell, Siemens and Schneider PLCs — SecurityWeek, Jul 22, 2026. securityweek.com ↗
  9. "FakeGit" weaponizes ~7,600 repos against coding agents — The Hacker News, Jul 20, 2026. thehackernews.com ↗
  10. Russian actor ran a botnet C2 through Google's Gemini CLI — The Hacker News, Jul 20, 2026. thehackernews.com ↗