Threat Intel Bi-Weekly + AI Vuln Monitor | Coverage: July 6, 2026 - July 6, 2026 | Sources: NVD • CISA KEV • Microsoft MSRC • Google GTIG • Palo Alto PSIRT • BleepingComputer • OWASP LLM | Published: Monday, July 6, 2026 -33% vs prior run
[!!] ALERT THRESHOLD BREACHED

CVEs & Exploits

[CRITICAL]

CVE-2026-10539 — BMC Control-M/Server

Critical command injection vulnerability (CVSS 9.0) in Control-M/Server where communication commands do not sufficiently filter user-supplied input. Unauthenticated attackers can execute unauthorized commands on affected servers. Affects versions 9.0.20.x to 9.0.21.200 and potentially earlier unsupported versions.

REMEDIATION

Upgrade Control-M/Server to version 9.0.21.201 or later immediately. Restrict network access to Control-M/Server to trusted management networks only. Review server logs for unauthorized command execution attempts. Implement input validation at network perimeter for Control-M communications.

Source: NVD  •  Published: 2026-07-01

[CRITICAL]

MSPT-2026-06 — Microsoft Products (June 2026 Patch Tuesday)

Record-breaking Patch Tuesday addressing 206 vulnerabilities including 37 Critical issues and three publicly disclosed zero-days. Part of trend showing 2026 mid-year forecast revised to 66,000 CVEs annually (up from 59,427) with 6,420 excess CVEs in first four months. Indicates AI-driven vulnerability discovery acceleration.

REMEDIATION

Deploy June 2026 Microsoft security updates across all Windows systems within 72 hours for Critical patches, 30 days for others. Prioritize patches for publicly disclosed zero-days. Test patches in staging environment for business-critical systems. Review vulnerability management processes for machine-speed patch deployment capabilities.

Source: MSRC  •  Published: 2026-06-01

[HIGH]

CVE-2026-33697 — Confidential Computing Attestation Protocols

High severity vulnerability (CVSS 7.5) in confidential computing attestation enabling diversion attacks against attested TLS protocols. Connections intended for one server can be silently redirected to different compromised machines running identical software without client detection. Fundamentally undermines confidential computing trust models in cloud environments.

REMEDIATION

Review confidential computing implementations for attestation validation gaps. Implement additional connection validation beyond attestation. Monitor for unexpected connection redirections. Consult cloud provider security advisories for attestation protocol updates. Consider implementing certificate pinning for critical confidential workloads.

Source: NVD  •  Published: 2026-07-06

AI & Supply Chain

[CRITICAL]

JetBrains-2026-Q2 — JetBrains IDEs (IntelliJ, PyCharm, WebStorm, GoLand, TeamCity, Hub, YouTrack)

Critical vulnerabilities across entire JetBrains IDE ecosystem enabling authentication bypass, account takeover, and remote code execution. Most severe issues affect JetBrains Hub and YouTrack. Represents supply chain risk to developer workstations and source code repositories.

REMEDIATION

Update all JetBrains products to latest versions immediately. Review Hub and YouTrack access logs for unauthorized authentication. Reset credentials for affected systems. Audit installed plugins for malicious extensions. Implement network segmentation for development infrastructure. Enable MFA on all JetBrains accounts.

Source: JetBrains  •  Published: 2026-07-06

[CRITICAL]

IDEsaster-2026 — AI-Enhanced IDEs (Cursor, Windsurf, GitHub Copilot, Zed, Roo Code, Junie)

Comprehensive security analysis uncovered 24 CVE-assigned vulnerabilities across all major AI-enhanced IDEs. 100% of tested AI IDEs vulnerable to prompt injection attacks. Affects developer workstations directly, compromising source code and credentials in local development environments. Developer workstations now high-value targets for IP theft.

REMEDIATION

Audit all AI IDE installations for known vulnerabilities. Implement prompt injection detection at IDE level. Restrict AI IDE network access to approved code repositories only. Enable IDE security logging. Conduct security training for developers on prompt injection risks. Consider air-gapping sensitive development environments from AI services.

Source: GTIG  •  Published: 2026-07-06

[CRITICAL]

npm-Mastra-2026 — npm @mastra AI framework packages

Nation-state supply chain attack by North Korea's Sapphire Sleet (BlueNoroff/APT38) compromising @mastra AI-agent framework on npm. Single stolen developer account used to republish 140+ packages in 19 minutes, each pulling malicious dependencies. First documented nation-state mass npm supply chain attack targeting AI frameworks.

REMEDIATION

Immediately audit package.json for any @mastra scope packages updated on June 17, 2026. Remove compromised versions and reinstall from verified sources. Review npm lockfiles for dependency integrity. Implement npm audit in CI/CD pipelines. Use private npm registry with package verification. Monitor for unusual package updates in AI framework dependencies.

Source: MSRC  •  Published: 2026-06-17

[CRITICAL]

LiteLLM-2026 — LiteLLM Python package

Supply chain compromise of LiteLLM open-source Python package widely used by AI systems. Compromised versions 1.82.7 and 1.82.8 published on PyPI on March 24, available for at least two hours. With three million daily downloads, significant number of potential victims in corporate environments implementing AI systems.

REMEDIATION

Audit Python environments for LiteLLM versions 1.82.7 and 1.82.8. Downgrade to 1.82.6 or upgrade to 1.82.9+. Review pip install logs for compromised version installations. Scan systems for indicators of compromise from malicious package. Implement PyPI package verification. Use private PyPI mirror with security scanning.

Source: BleepingComputer  •  Published: 2026-03-24

[CRITICAL]

Shai-Hulud-2026 — npm/PyPI AI development packages (Mistral AI, TanStack, Guardrails AI, UiPath)

Two-wave AI developer supply chain attack by TeamPCP (Shai-Hulud/Megalodon). Wave 1 self-propagating worm compromised 172 packages across 404 malicious versions targeting AI ecosystems. Persistence mechanisms installed in Claude Code and AI coding assistants. Concrete realization of MAESTRO framework supply chain compromise threats.

REMEDIATION

Audit npm and PyPI dependencies installed between April 29 and May 12, 2026 for affected packages (Mistral AI, TanStack, Guardrails AI, UiPath ecosystems). Remove malicious versions and persistence mechanisms. Review AI coding assistant configurations for unauthorized modifications. Implement dependency pinning. Use software composition analysis tools for AI package verification.

Source: GTIG  •  Published: 2026-05-12

[HIGH]

JetBrains-Malware-2026 — JetBrains Marketplace Plugins

15 malicious third-party plugins on JetBrains Marketplace designed to steal AI provider API keys with combined install count approaching 70,000. Plugins removed and publisher accounts blocked on June 16, 2026. Attack embedded directly into workflow where developers paste AI provider API keys into settings panel.

REMEDIATION

Audit installed JetBrains plugins, especially those installed before June 17, 2026. Rotate all AI provider API keys (OpenAI, Anthropic, etc.) configured in IDE settings. Review plugin permissions before installation. Enable JetBrains plugin verification. Monitor API usage for unauthorized consumption. Implement API key rotation policies.

Source: JetBrains  •  Published: 2026-06-16

Threat Actors & Dark Web

[CRITICAL]

FortiBleed-2026 — Fortinet FortiGate Firewalls

Massive credential theft campaign compromising 73,000+ Fortinet devices with exposed server containing configuration files and credentials. Operation targeted 430,000 FortiGate firewalls worldwide, deployed traffic sniffers on 19,000 devices (now 11,000), linked to INC and Lynx ransomware operations. Custom 'FortiGate Sniffer' tool intercepts VPN credentials from network traffic.

REMEDIATION

Immediately change all Fortinet device credentials. Review firewall logs for unauthorized access patterns. Remove any unauthorized packet capture tools. Implement MFA on all administrative access. Audit VPN user credentials for compromise. Deploy network monitoring for lateral movement from firewall infrastructure.

Source: BleepingComputer  •  Published: 2026-07-06

[CRITICAL]

JadePuffer-2026 — Langflow (CVE-2025-3248) and AI-driven ransomware

First documented fully autonomous AI-driven ransomware operation using LLM agent for entire attack chain: reconnaissance, credential theft, lateral movement, persistence, privilege escalation, and encryption. Exploited CVE-2025-3248 (CVSS 9.8) in internet-exposed Langflow instances. AI agent adapted to failures like human operator, encrypted 1,342 Nacos service configurations, deployed extortion demand with Bitcoin address.

REMEDIATION

Patch Langflow to address CVE-2025-3248 immediately. Remove internet exposure from Langflow instances. Hunt for AI-generated code patterns in ransomware incidents. Monitor for rapid adaptation behaviors during intrusion attempts. Implement behavioral analytics to detect autonomous agent activity. Review Nacos service configurations for encryption attempts.

Source: GTIG  •  Published: 2026-07-06

[CRITICAL]

Iran-Stryker-2026 — Stryker Corporation

Most significant wartime cyberattack by Iran against U.S. targets occurred March 11, 2026, following U.S.-Israel military strikes on February 28. Wiper attack on Stryker Corporation forced tens of thousands of employees offline, disrupting global network and Microsoft environment. Stryker serves 150M+ patients across 61 countries with $25B+ annual revenue.

REMEDIATION

Implement geofencing for critical infrastructure against Iran-origin traffic. Deploy wiper malware detection signatures. Maintain air-gapped backups of critical systems. Conduct incident response planning for nation-state wiper scenarios. Review Microsoft 365 security configurations. Implement privileged access workstations for administrative functions.

Source: GTIG  •  Published: 2026-03-11

[CRITICAL]

UNC3886-Singapore-2026 — Singapore Telecommunications Providers

China-linked APT group UNC3886 breached all four major Singapore telecommunications providers in months-long espionage campaign using zero-day exploits and rootkits for persistent access. Singapore mounted 11-month counteroperation CYBER GUARDIAN (largest ever) to evict attackers. Represents sophisticated supply chain compromise of national telecommunications infrastructure.

REMEDIATION

Telecommunications providers must conduct comprehensive threat hunts for UNC3886 TTPs including rootkit deployment. Review zero-day patch status across telecom infrastructure. Implement hardware-based root of trust. Deploy EDR with rootkit detection on network equipment. Segment management networks from production traffic. Coordinate with national CERT for threat intelligence sharing.

Source: GTIG  •  Published: 2026-07-06

[HIGH]

Ransomware-Q1-2026 — Global Organizations

Q1 2026 ransomware activity reached elevated 'new normal' baseline with consistent volume quarter-over-quarter and year-over-year. The Gentlemen group expanded from 35 victims (Q4 2025) to 182 (Q1 2026), becoming second most active. Established groups Qilin and Akira declined 25% and 22%. Shift toward data theft and extortion-only operations without encryption.

REMEDIATION

Implement data loss prevention controls prioritizing exfiltration detection over encryption prevention. Deploy network traffic monitoring for large data transfers. Segment backup infrastructure with immutable copies. Conduct tabletop exercises for extortion-without-encryption scenarios. Review cyber insurance policies for data theft coverage. Monitor dark web for organizational data exposure.

Source: GTIG  •  Published: 2026-07-06

Priority Action Matrix

01DO NOWFortiBleed-2026 (Fortinet FortiGate Firewalls): Immediately change all Fortinet device credentials. Review firewall logs for unauthorized access patterns. Remove any unauthorized packet capture tools. Implement MFA on all administrative access. Aud...
02DO NOWCVE-2026-10539 (BMC Control-M/Server): Upgrade Control-M/Server to version 9.0.21.201 or later immediately. Restrict network access to Control-M/Server to trusted management networks only. Review server logs for unauthorized command execut...
03DO NOWMSPT-2026-06 (Microsoft Products (June 2026 Patch Tuesday)): Deploy June 2026 Microsoft security updates across all Windows systems within 72 hours for Critical patches, 30 days for others. Prioritize patches for publicly disclosed zero-days. Test patches in st...
04DO NOWJetBrains-2026-Q2 (JetBrains IDEs (IntelliJ, PyCharm, WebStorm, GoLand, TeamCity, Hub, YouTrack)): Update all JetBrains products to latest versions immediately. Review Hub and YouTrack access logs for unauthorized authentication. Reset credentials for affected systems. Audit installed plugins for m...
05DO NOWIDEsaster-2026 (AI-Enhanced IDEs (Cursor, Windsurf, GitHub Copilot, Zed, Roo Code, Junie)): Audit all AI IDE installations for known vulnerabilities. Implement prompt injection detection at IDE level. Restrict AI IDE network access to approved code repositories only. Enable IDE security logg...
06DO NOWnpm-Mastra-2026 (npm @mastra AI framework packages): Immediately audit package.json for any @mastra scope packages updated on June 17, 2026. Remove compromised versions and reinstall from verified sources. Review npm lockfiles for dependency integrity. ...
07DO NOWLiteLLM-2026 (LiteLLM Python package): Audit Python environments for LiteLLM versions 1.82.7 and 1.82.8. Downgrade to 1.82.6 or upgrade to 1.82.9+. Review pip install logs for compromised version installations. Scan systems for indicators ...
08DO NOWShai-Hulud-2026 (npm/PyPI AI development packages (Mistral AI, TanStack, Guardrails AI, UiPath)): Audit npm and PyPI dependencies installed between April 29 and May 12, 2026 for affected packages (Mistral AI, TanStack, Guardrails AI, UiPath ecosystems). Remove malicious versions and persistence me...
09DO NOWJadePuffer-2026 (Langflow (CVE-2025-3248) and AI-driven ransomware): Patch Langflow to address CVE-2025-3248 immediately. Remove internet exposure from Langflow instances. Hunt for AI-generated code patterns in ransomware incidents. Monitor for rapid adaptation behavio...
10DO NOWIran-Stryker-2026 (Stryker Corporation): Implement geofencing for critical infrastructure against Iran-origin traffic. Deploy wiper malware detection signatures. Maintain air-gapped backups of critical systems. Conduct incident response plan...
11DO NOWUNC3886-Singapore-2026 (Singapore Telecommunications Providers): Telecommunications providers must conduct comprehensive threat hunts for UNC3886 TTPs including rootkit deployment. Review zero-day patch status across telecom infrastructure. Implement hardware-based...
12TODAYCVE-2026-33697 (Confidential Computing Attestation Protocols): Review confidential computing implementations for attestation validation gaps. Implement additional connection validation beyond attestation. Monitor for unexpected connection redirections. Consult cl...
13TODAYJetBrains-Malware-2026 (JetBrains Marketplace Plugins): Audit installed JetBrains plugins, especially those installed before June 17, 2026. Rotate all AI provider API keys (OpenAI, Anthropic, etc.) configured in IDE settings. Review plugin permissions befo...
14TODAYRansomware-Q1-2026 (Global Organizations): Implement data loss prevention controls prioritizing exfiltration detection over encryption prevention. Deploy network traffic monitoring for large data transfers. Segment backup infrastructure with i...

Biggest Risk This Period

BIGGEST RISK

FortiBleed-2026: Massive credential theft campaign compromising 73,000+ Fortinet devices with exposed server containing configuration files and credentials. Operation targeted 430,000 FortiGate firewalls worldwide, deployed traffic sniffers on 19,000 devices (now 11,000), linked to INC and Lynx ransomware operations. Custom 'FortiGate Sniffer' tool intercepts VPN credentials from network traffic.