HeadFlash

Security

AI Agents, Iranian Sabotage, and a 200K-Botnet: Your Security Brief

AI-driven espionage hits Thailand, Iran APT sabotages US PLCs, Dysphoria botnet grows to 200k devices, and Tribeca & Coca-Cola confirm data leaks.

Listen

AI Agent Drives Espionage Attack on Thai Ministry of Finance

Threat actors targeting Thailand‘s Ministry of Finance used an autonomous AI agent via the open-source tool Hermes to carry out portions of a cyber-espionage operation, according to threat intelligence firm Hunt.io. From July 9 to 13, Hunt.io’s platform identified three simultaneous open directories in Hong Kong containing exploit code for multiple CVEs, web shells, and custom scripts. The Hermes Agent operated in unrestricted „YOLO“ mode, functioning without human approval, performing system enumeration, privilege escalation, and network reconnaissance. Hunt.io and researcher Bob Diachenko reported the attack to Thailand‘s national CERT and NCSA on July 15; the government acknowledged receipt, and publication was held for a standard 7-day disclosure window.

AI Agent Drives Espionage Attack on Thai Ministry of Finance →

Iranian APT Sabotages US PLCs Across Three Critical Sectors

CISA, the FBI, NSA, DOE, and EPA issued a joint advisory updated July 22, 2026, on an active campaign by Iranian-affiliated threat actors against internet-exposed programmable logic controllers (PLCs). The activity, observed since March 2026, has hit three US critical sectors: Government Services and Facilities, Water and Wastewater Systems, and Energy. The attackers manipulate PLC project files to overwrite safety instructions and hide abnormal conditions from operators, using legitimate engineering software from Rockwell, Schneider, and Siemens. The advisory notes a shift from public defacement in 2023 to silent sabotage, with targets expanding from Rockwell Automation/Allen-Bradley to Schneider Electric Modicon M340 and Siemens S7-1200. The agencies assess the activity is „intended to cause destructive effects in the United States“ and report victims suffered operational disruption and financial loss.

Iran APT Sabotages US PLCs: CISA Warns of Physical Risk | DeafNews →

New Dysphoria DDoS Botnet Spreads to 200,000 Devices Worldwide

The Dysphoria botnet has compromised approximately 200,000 devices worldwide for distributed denial of service (DDoS) attacks and traffic relay operations, according to QiAnXin XLab researchers. The botnet evolved from the ‚jackskid‘ and ‚fbot‘ malware, adding a covert blockchain-based command-and-control (C2) resolution mechanism using Ethereum ENS and Solana SNS domains. XLab first spotted Dysphoria on March 25 and reported that since the first quarter of 2026, the bot count has exceeded 200,000. The malware spreads through weak Telnet and SSH credentials and known vulnerabilities in routers, cameras, and IoT devices, including recently exploited flaws such as CVE-2025-55182 („React2Shell“) and CVE-2025-9528 (Linksys). XLab monitored the botnet between July 14 and 20 and recorded a peak of 740,000 daily pings from infected hosts; the operators claim a maximum DDoS capacity of 4 Tbps.

New Dysphoria DDoS botnet spreads to 200k devices worldwide →

Tribeca Festival Data Leak Exposes Celebrity Contact Information

The Tribeca Festival suffered a data leak that exposed hundreds of thousands of records, including contact information for celebrities such as Martin Scorsese, Francis Ford Coppola, Jennifer Lawrence, Angelina Jolie, and festival co-founder Robert De Niro. Cybersecurity researcher Jeremiah Fowler revealed the leak, claiming he uncovered 666,369 exposed records with timestamps ranging from 2019 to 2026. The festival issued a statement asserting that none of the talent referenced had personal contact information disclosed, that the vast majority of the information consisted of public-facing business contact information, and that all information was removed promptly upon discovery. Fowler noted a backup .dump file contained a folder named „contacts“ with 13,535 entries, including names, addresses, phone numbers, and emails of prominent filmmakers and actors, and stated the festival committed a human error by leaving the backup file in the database in plain text, unencrypted, and accessible to anyone with an internet connection.

Massive Tribeca Fest Data Leak Exposes Jennifer Lawrence, Robert De Niro and More Celebs‘ Contact Info; Meet the Man Who Discovered the Files →

Coca-Cola Confirms Data Theft in Fairlife Ransomware Attack

The Coca-Cola Company confirmed that hackers stole data from its dairy subsidiary, Fairlife, during a ransomware attack earlier this month. Coca-Cola disclosed the cyberattack in a filing with the U.S. Securities and Exchange Commission on July 16, revealing that a ransomware attack had disrupted production operations at Fairlife, which operates four production facilities in the U.S. and has more than $1 billion in annual retail sales. The Anubis ransomware gang claimed the attack and threatened to leak one terabyte of files allegedly stolen from the company unless Fairlife paid a ransom. Coca-Cola stated that existing inventory helped cover temporary shortages caused by the production disruption, and that product quality and safety were never jeopardized. The timer that Anubis ransomware had set for the public release of the stolen data expired, and the data is now available for download.

Coca-Cola confirms data theft in Fairlife ransomware attack →