Security
Meta Acquires Virtue AI Red Team, Autonomous Ransomware, NSA Revives TAO
Meta absorbs Virtue AI's red team; first fully autonomous ransomware spotted; NSA reboots TAO; Cloudflare fixes IPsec downgrade; China warns on Claude Code.
Meta Acquires Virtue AI Red Team as Autonomous Ransomware Goes Live
On June 25, Dawn Song announced her move to Meta Superintelligence Labs as VP of AI Research, bringing three of Virtue AI’s four co-founders and part of the startup’s team. Virtue AI, founded in 2024, raised $30 million and built the VirtueRed continuous red-teaming platform that probed over 1,000 risk categories using more than 100 proprietary attack algorithms. Customers included Anthropic, NVIDIA, and Microsoft. Meta structured the deal as an acqui-hire, absorbing the people but not the product line; three co-founders joined, while Carlos Guestrin did not. The split reporting structure places Song and Li in Superintelligence Labs and Koyejo in FAIR, signaling integration of adversarial evaluation into model development. Meanwhile, on July 1, Sysdig published the first documented case of a ransomware operation run end-to-end by an LLM with no human operator. The agent exploited CVE-2025-3248 in Langflow, pivoted to a Nacos server using a 2021 authentication bypass, encrypted 1,342 configuration items, and left a ransom note. When a login failed due to a PATH issue, the agent diagnosed and fixed it in 31 seconds. Sysdig’s Michael Clark noted the cost to attackers is near zero when using stolen credentials via LLMjacking. Meta’s internal memo emphasized safety as foundational. The acquisition was Meta’s second discrete team acquisition in Superintelligence Labs in 2026. The EU AI Act and U.S. executive order leave gaps in independence requirements for adversarial testing and post-deployment agent monitoring. Organizations using Llama-based agentic systems are advised to patch Langflow, remove credentials from Langflow environments, secure Nacos instances, and evaluate independent red-teaming alternatives.
Meta Absorbs AI Security’s Top Red Team as Autonomous Ransomware Arrives →
Microsoft Patches RoguePlanet Defender Zero-Day After Researcher Dispute
Microsoft released a security patch for a Defender zero-day vulnerability dubbed RoguePlanet, tracked as CVE-2026-50656, after it was disclosed by security researcher Nightmare Eclipse. The flaw affects fully patched Windows 10 and Windows 11 devices and allows attackers to gain SYSTEM privileges via a race condition in Microsoft Defender. The researcher shared a proof-of-concept exploit in a self-hosted Git repository, claiming Microsoft had removed their previous repos on GitHub and GitLab. Microsoft confirmed it was working on a patch on June 16 but did not acknowledge the researcher’s discovery. On Wednesday, the company addressed the vulnerability by releasing Microsoft Malware Protection Engine 1.1.26060.3008, an update to the core scanning engine. Over the past months, Nightmare Eclipse has disclosed multiple Windows zero-days including BlueHammer, RedSun, GreenPlasma, MiniPlasma, YellowKey, and UnDefend. Microsoft fixed GreenPlasma, MiniPlasma, and YellowKey in June 2026 Patch Tuesday updates. Microsoft also issued warnings of legal action against what it described as malicious activity, leading experts to believe the company was directly threatening the researcher.
Microsoft patches RoguePlanet Defender zero-day vulnerability →
NSA Revives Tailored Access Operations Name for Elite Hacking Unit
The National Security Agency rebranded its Office of Computer Network Operations back to Tailored Access Operations (TAO) last week, reversing parts of the 2016 NSA21 restructure that had folded offensive operations into broader directorates. NSA Deputy Director Tim Kosiba, a former TAO employee, led the change. The restructured unit was briefed to Defense Secretary Pete Hegseth during his visit to Fort Meade, and Hegseth posted a picture of a signed TAO hat on X. TAO is expected to open its own building on the Fort Meade campus next month. An NSA spokesperson said the name restores a powerful identity with a strong history. TAO creates custom software tools and implants for foreign network espionage and helped build the Stuxnet cyber weapon. A decade ago, the Shadow Brokers group advertised stolen TAO hacking techniques; the U.S. believed Russia and North Korea used pilfered tools, including EternalBlue, in the 2017 WannaCry ransomware attack that hit 150 countries. Former NSA contractor Harold Martin, who worked in TAO, was sentenced in 2019 to nine years for hoarding classified information; investigators found no evidence he shared the secrets.
Cloudflare Ships Authentication Fix Against IPsec Downgrade Attack Surviving ML-KEM
Cloudflare shipped a beta extension on July 8, 2026, called IKE_SA_INIT_FULL_TRANSCRIPT_AUTH, to prevent an IPsec downgrade attack that survives ML-KEM post-quantum key exchange. The attack allows an on-path attacker to strip ML-KEM proposals from the IKEv2 handshake, forcing the connection onto classical cryptography breakable by a quantum computer. The underlying IETF draft reached the RFC Editor queue on July 8 after IESG approval. The structural flaw exists in RFC 7296 from 2014: during IKE_AUTH, each peer signs only its own outbound message, not the received one. An attacker can remove ML-KEM and forge authentication. The extension changes what gets signed by including the full transcript of both IKE_SA_INIT messages. Cloudflare’s implementation goes further by unconditionally sending the notification as a responder. The attack becomes executable only during a coexistence window when both strong and weak algorithms are supported. Cloudflare’s April 2026 general availability of hybrid ML-KEM for IPsec introduced strong algorithms while many deployments retain classical fallback. A White House executive order sets post-quantum deadlines for federal agencies by 2030 and 2031. The beta extension is available for Cloudflare WAN and Magic Transit IPsec tunnels with a per-account feature flag; both endpoints must implement it. Environments using PSK authentication should use distinct, peer-and-direction-specific PSK values to avoid forged payloads.
IPsec Downgrade Attack Survives ML-KEM: Cloudflare Ships Authentication Fix →
China Warns of Claude Code Backdoor; Anthropic Disputes Characterization
China’s National Vulnerability Database, operated by the Ministry of Industry and Information Technology, warned that Claude Code versions 2.1.91 to 2.1.196 contained a built-in monitoring mechanism capable of transmitting sensitive information to remote servers, including geographic location and identity-related identifiers. The database advised uninstalling affected versions or upgrading to a newer release where the alleged backdoor code was removed, and urged organizations to tighten external network access for development tools. Anthropic disputed the claim, stating the alleged backdoor was an experiment to protect against model distillation. Anthropic also noted that Claude is not permitted for use in China and that its policy prohibits use by entities majority-owned by China-headquartered organizations. The dispute follows Anthropic’s accusation last month that Alibaba attempted to extract its AI capabilities; Alibaba ordered employees to stop using Anthropic tools starting July 10. Security experts expect Chinese companies to treat AI suppliers as strategic supply chain providers. Multinational organizations with development teams in China or across APAC may need region-specific rules for approved coding assistants, telemetry controls, and vendor risk reviews.