CyberNews: 20/07/2026 Edition

Published by Dunateo on 2026-07-20

Today’s roundup

  • AI Agents Turned Into Attackers: Hugging Face Reveals Autonomous Intrusion Campaign
  • Critical ServiceNow code execution flaw now exploited in attacks
  • Hackers abuse ViPNet software to target Russian govt agencies
  • Russian-Speaking Hacker Uses Google Gemini CLI to Control Botnet of Eight Dental Clinic PCs
  • SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines
  • CVE-2026-42533: Critical NGINX Bug Could Turn HTTP Requests Into Server Takeovers
  • Police Chiefs Cite TfL Hack in Push for Cybercrime Risk Orders
  • Volexity Uncovers Zero-Day Campaign Targeting SonicWall VPN Appliances
  • Apps Marketed to US Troops Are Shipping Chinese and Russian Code
  • Summary

    Hugging Face, a major AI platform, disclosed a breach initiated by an autonomous AI agent. The attack exploited two code execution flaws via a malicious dataset in their data-processing pipeline, leading to compromised credentials and internal datasets. The AI agent executed thousands of actions across sandboxes, utilizing public services for command-and-control, marking a new frontier in AI-powered attacks.


    A critical remote code execution vulnerability, CVE-2026-6875, in the ServiceNow AI Platform is now actively being exploited. Cybersecurity professionals are urged to apply immediate patches to counter this high-impact threat.


    An advanced threat actor is abusing the update mechanism of the ViPNet private networking suite to target Russian government agencies, employing a sophisticated supply chain attack. This highlights ongoing risks to critical infrastructure through trusted software channels.


    A Russian-speaking hacker, "bandcampro," leveraged Google's open-source Gemini CLI AI to manage a botnet of eight dental clinic PCs. The AI was used for password cracking and setting up proxies, illustrating AI's growing role in cybercrime.


    The "SleeperGem" software supply chain attack is targeting the Ruby ecosystem through three malicious RubyGems packages—"git_credential_manager" and "Dendreo"—published to the RubyGems repository, aiming to deploy additional payloads on developer machines.


    F5 has issued patches for CVE-2026-42533, a critical NGINX vulnerability (CVSS 9.2). This heap buffer overflow allows unauthenticated attackers to trigger worker process crashes, denial of service, and potentially remote code execution with crafted HTTP requests. Affected versions 0.9.6 through 1.31.2 are fixed in NGINX 1.30.4, 1.31.3, and NGINX Plus 37.0.3.1.


    Following the significant £29 million cyberattack on Transport for London, UK police chiefs are advocating for new Cybercrime Risk Orders to enhance law enforcement capabilities in managing and mitigating cybercrime threats.


    Volexity has revealed an active zero-day campaign by threat actor UTA0533 targeting SonicWall SMA 1000 VPN appliances since June 22, 2026. The campaign exploits CVE-2026-15409 (SSRF, CVSS 10.0) and CVE-2026-15410 (code injection, CVSS 7.2) to gain root access, deploy custom malware for persistence and credential interception. SonicWall has released necessary patches.


    A recent analysis indicates that over one in eight applications marketed to US service members contain code from foreign entities, including firms in adversary nations. This poses significant national security and supply chain risks to military personnel.

    Want to dig deeper?

    IP Address Details

    37.0.3.1 0/91