Security
AI Bug Deluge, Water Attacks, and a $1.1B Crypto Hack Half-Year
Microsoft races to patch AI-discovered flaws; Iran hits 30 water plants; crypto hacks triple as North Korea steals $600M.
Microsoft Overwhelmed by AI-Discovered Bugs as Anthropic’s Mythos Uncovers Hundreds of Vulnerabilities
Microsoft has focused on patching critical and important bugs, but internal documents show plans to eventually address moderate-severity flaws, with no mention of low-severity bugs. Vinh Nguyen, a senior technical adviser to Anthropic and former NSA chief AI officer, warned that Mythos can chain together low-level vulnerabilities, meaning unpatched moderate and low flaws could create devastating attack vectors. “If you’re Microsoft, the current triage strategy may be underpricing risks,” Nguyen said. Microsoft defended its approach, stating that triaging decisions consider exploitability and impact, and that chaining techniques have long been part of vulnerability assessment. The company released patches for over 200 bugs in June and over 600 in July—both all-time highs—but only seven were low- or moderate-severity. The broader software industry faces a similar reckoning, with experts describing the situation as “drinking from a fire hose” of vulnerabilities.
Microsoft Struggling With Hundreds of AI-Discovered Security Bugs — ProPublica →
Iranian Hackers Exploit Unpatchable PLC Flaw to Breach 30 Minnesota Water Systems
The attack came four days after federal agencies updated a landmark advisory warning that the same Iranian-affiliated actors had expanded their campaign to include equipment from Siemens and Schneider Electric. CISA, the FBI, NSA, EPA, and the Department of Energy published updated guidance documenting confirmed exfiltration of PLC project files and the insertion of malicious Add-On Instructions that disabled safety shutdown and alarm systems while feeding falsified data to operator displays. The vulnerability, CVE-2021-22681, allows anyone who extracts the embedded cryptographic key from Rockwell’s Studio 5000 software to impersonate legitimate engineering software and gain direct access to any internet-facing Logix controller. As of April 2026, Censys identified 5,219 internet-exposed hosts globally, with the United States accounting for 74.6% of that exposure. No official attribution has been announced, but the operational pattern is consistent with CyberAv3ngers, which has been active since at least 2020 and is tied to Iran’s IRGC Cyber-Electronic Command.
Iranian Hackers Exploited Unpatchable PLC Flaw to Breach 30 Minnesota Water Systems →
Iran Deploys NightLedger Backdoor and WebSocket Relays Across Six Nations
BridgeHead is a SOCKS5 tunnel proxy that converts the infected machine into a covert relay node over an encrypted WebSocket connection, deploying as unbcl.dll in the Visual Studio folder. It checks the current Windows username for a specific hardcoded substring before activating, and can negotiate Windows-integrated authentication if a corporate proxy challenges it. ArcBridge, first identified in April 2026 targeting Middle Eastern victims, embeds its configuration directly and supports two commands: OPEN for establishing a proxy session and DNS for hostname resolution. The initial access vector for most samples remains unconfirmed, but BridgeHead’s deployment followed spear-phishing activity using recruitment-themed lures impersonating trusted brands and hiring platforms, directing targets to fake job portals that redirect to malicious archives on legitimate file-sharing services. The campaign’s C2 infrastructure includes multiple azurewebsites.net domains and Cloudflare-backed domains in newer samples.
Iran Deploys NightLedger Backdoor and WebSocket Relays Across Six Nations →
Dysphoria IoT Botnet Hides on Blockchain to Defy Seizure, Infects 200,000 Devices
Dysphoria descends from the JackSkid malware lineage and uses Ethereum Name Service domains such as m3rnbvs5d.eth, burrberry.eth, and ukranianhorseriding.eth, as well as a Solana Name Service domain, to retrieve relay distribution node addresses. The blockchain records encode command-server addresses through a custom permutation function involving bit rotation and XOR operations. In late June 2026, a variant discarded DDoS functionality entirely and converted infected devices into covert traffic relay nodes, abusing Universal Plug and Play to create 155 port-forwarding rules on the compromised device’s local gateway router. These rules persist even after the malware is removed, until explicitly cleared by a user or a router reboot. Between July 14 and July 20, XLab monitored 4,401 active bots within mainland China and a global peak of 239,000 active simultaneously on a single day. The botnet spreads through brute-forcing weak credentials and exploiting known vulnerabilities, including flaws in Totolink, Linksys, DrayTek, and Huawei routers.
Rebuilt in Six Days: Dysphoria IoT Botnet Hides on Blockchain to Defy Seizure →
Crypto Hacks Hit All-Time High as North Korea Drains Over $600M and AI Agents Become New Target
The Drift Protocol attack on April 1 involved threat actors posing as representatives of a legitimate quantitative trading firm, building credibility over months and socially engineering at least two of five Security Council multisig signers into pre-signing malicious transactions using Solana’s durable nonce feature. The KelpDAO attack on April 18 drained approximately $292 million in under 46 minutes by compromising LayerZero Labs’ verification infrastructure, which was configured as a single Decentralized Verifier Network for high-value transactions. In early May, an attacker exploited Bankr, an AI-powered crypto trading assistant, by gifting it a high-privilege NFT and then sending a message to xAI’s Grok chatbot encoded in Morse code, which bypassed safety filters and triggered an autonomous transfer of approximately $175,000. Blockaid projects that AI agent deployments are growing roughly ten times per year, and expects multiple AI agent incidents in H2 2026, with prompt injection attacks leading. Recovery prospects for DPRK-linked losses remain bleak, with most stolen funds unrecovered.
Crypto Hacks Hit All-Time High as North Korea Drains Over $600M and AI Agents Become New Target →