[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$feowaMmsF4G3DXNTsXsLFT8joUPa-sxhrZwry8ZcvYlI":3},{"article":4,"iocs":55},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":32,"category":33,"article_tags":37},"e20a2ee9-617c-4ff7-82e9-e2daeb9dfa58","⚡ Weekly Recap: Rogue AI Models, $88M Bitcoin Theft, Water-System Attacks and Dangling DNS Hijacks","weekly-recap-rogue-ai-models-88m-bitcoin-theft-water-system-attacks-and-dangling-05bc92","This week kept coming back to permission. A model crossed a boundary. A wallet trusted bad randomness. Webmail kept an intruder around. Public systems, package feeds, hotel networks, and login flows all gave away more than intended. Some of it was clever. Most of it was just access left lying around: old bugs, exposed gear, poisoned dependencies, weak defaults, and tooling that moved from","This week's security recap highlights several incidents, including Anthropic's AI models accessing production systems during testing, a vulnerability in Coldcard hardware wallets leading to an $88.6 million Bitcoin theft, and Russian hackers exploiting a Microsoft OWA flaw for persistent mailbox access. Additionally, a critical Ruby on Rails vulnerability could allow unauthenticated attackers to read arbitrary files.","Weekly recap: Rogue AI models, $88M Bitcoin theft, water-system attacks, and dangling DNS hijacks.","⚡ Weekly Recap: Rogue AI Models, $88M Bitcoin Theft, Water-System Attacks and Dangling DNS Hijacks Ravie LakshmananAug 03, 2026Cybersecurity \u002F Hacking This week kept coming back to permission. A model crossed a boundary. A wallet trusted bad randomness. Webmail kept an intruder around. Public systems, package feeds, hotel networks, and login flows all gave away more than intended. Some of it was clever. Most of it was just access left lying around: old bugs, exposed gear, poisoned dependencies, weak defaults, and tooling that moved from forum chatter to real targets. The full weekly recap report follows. ⚡ Threat of the Week Anthropic Disclosed its Models Targeted 3 Organizations - Anthropic revealed that three of its models, including Claude Opus 4.7, Mythos 5, and an unnamed research model, breached three unnamed organizations during cybersecurity testing without its knowledge. The AI firm said the earliest incidents date back to April 2026, adding it made the discoveries after launching a \"large-scale retrospective review\" in response to the recent Hugging Face incident. \"After reviewing 141,006 evaluation runs where Claude could have obtained internet access, we identified three incidents in which a model accessed the internet from within or while interacting with the evaluation environment of Irregular, one of our third-party evaluation partners, and then gained unauthorized access to the production infrastructure of three different organizations,\" it said. Mythos: Map Attack Paths to Collapse Lateral Breach Routes Access the Gartner® CTEM report to see how the Mythos platform continuously maps cross-domain attack paths and isolates key choke points to break active lateral movement to critical assets. Get the full report ➝ 🔔 Top News Coldcard Hardware Wallet Flaw Linked to $88.6M Bitcoin Theft - A vulnerability in Coldcard hardware wallet firmware is said to have been exploited to steal an estimated $88.6 million in Bitcoin from thousands of wallets whose seed phrases were generated using a flawed random number generator. \"Coldcard firmware contains an RNG integration error that causes ngu.random to use MicroPython's deterministic Yasmarang fallback instead of the STM32 hardware RNG,\" Square Engineering said. \"This does not mean every remote attacker can immediately recover every seed. Practical cost depends on available UID information, boot timing, prior RNG calls, and derivation cost.\" Russian Hackers Exploit Microsoft OWA Flaw to Maintain Mailbox Access - Russian threat actors exploited a security flaw in Microsoft Outlook Web Access (OWA), to target U.S. and European government entities, as well as the telecommunications, financial, hospitality, and aerospace sectors. The activity, which began on July 22, 2026, involves the weaponization of CVE-2026-42897 (CVSS score: 8.1), a cross-site scripting (XSS) vulnerability in OWA. It was flagged by Microsoft as having been exploited in attacks as far back as May 2026. The activity has been attributed to Laundry Bear. The new wave of exploitation revolving around CVE-2026-42897 culminates with the deployment of a previously unknown JavaScript browser-based implant codenamed OWAReaper that's specifically built for persistent access within Microsoft's webmail client. Critical Rails Flaw Leads to Arbitrary File Read - Ruby on Rails shipped patches for a critical Active Storage vulnerability (CVE-2026-66066, CVSS score: 9.5) that could let unauthenticated attackers read arbitrary files from application servers through crafted image uploads. The flaw can be exploited to expose Rails process environment and secrets such as secret_key_base, master key, database passwords, cloud storage credentials, and API tokens, which may enable remote code execution or lateral movement into connected systems. CVE-2026-66066 is exploitable when libvips is used, enabling an attacker to upload a specially crafted image to a vulnerable application and read arbitrary files on the server. A key prerequisite for the attack is that the server must allow image uploads from untrusted users. Additional details of the flaw have been released by the Rails team, along with tools to help assess vulnerable applications. \"Because this vulnerability requires no authentication and targets the default image processor in modern Rails environments, it is essential to apply vendor patches and rotate secrets immediately,\" Akamai said. Coordinated Attacks Target 30+ Minnesota Water Systems - A coordinated cyber attack campaign targeted over 30 water systems in Minnesota on July 26 and 27, 2026. \"The nature and extent of the impact varied by system, and the investigation is still determining how many experienced operational disruptions,\" Minnesota IT Services (MNIT) said. The activity has not been officially attributed to any known threat actor, although Iranian threat actors have been previously implicated in similar attacks targeting water facilities in the U.S. \"At this time, there are no active requests from Minnesota communities for residents to modify their drinking water use,\" MNIT added. The development has prompted the U.S. government to issue an advisory, urging \"critical infrastructure owners, operators, and integrators to remove publicly exposed PLCs and other operational technology (OT) from the internet as soon as possible.\" Threat actors targeting exposed PLCs have modified passwords to lock out operators and disconnected the PLCs by changing their IP addresses, resulting in boil water notices and sustained manual operations. Organizations are advised to disconnect the PLC from the internet, enable password protection and change default passwords, and allowlist IPs to only allow remote access from known engineering laptops or other critical OT assets. Censys said it identified 4,148 internet-exposed hosts that respond to EtherNet\u002FIP and self-identify as Rockwell Automation\u002FAllen-Bradley, with more than 70% of them located in the U.S. Similarly, there are 4,117 internet-exposed hosts that fingerprint as Siemens SIMATIC S7-1200 and 2,072 internet-exposed hosts that fingerprint as Schneider Electric hardware. Over the weekend, Michigan reported cyber attacks on nine of the state's water systems but an official told Associated Press that all systems were operating \"safely.\" The campaign underscores the escalating threat to poorly protected operational technology (OT) assets from adversaries seeking to disrupt critical infrastructure services across the U.S. and elsewhere. Hijacked Wi-Fi Networks Lead to CornFlake Malware - Storm-2945, a sub-cluster associated with Midnight Blizzard (aka APT29), has been conducting \"widespread but targeted traffic manipulation attacks\" involving hospitality sector networks served by captive portals across the world. The campaign, ongoing since May 2026, has been codenamed CaptiveCrunch by Microsoft. This involves manipulating DNS and HTTP traffic from networks served by captive portals to redirect user traffic through actor-controlled infrastructure. \"As part of the CaptiveCrunch campaign, Storm-2945 has leveraged their AitM position to redirect users through actor-controlled phishing infrastructure and has also delivered malware purporting to be browser or operating system updates in response to automated connectivity checks issued by users' browsers,\" Microsoft said. This includes a fully-featured Windows remote access trojan (RAT) called CornFlake with capabilities to conduct system enumeration, collect files and keystrokes, steal credentials and session tokens, conduct audio and video surveillance, monitor for removable media, and provide the threat actor a remote shell on infected systems. Also delivered via the trojan is a PowerShell-based infostealer called ChocoShell to harvest browser session cookies, saved passwords, Microsoft 365 Single Sign-On (SSO) tokens, and Wi-Fi credentials from compromised systems. The campaign is orchestrated via a web-based C2 panel called FruitStone. The infr","https:\u002F\u002Fthehackernews.com\u002F2026\u002F08\u002Fweekly-recap-rogue-ai-models-88m.html","https:\u002F\u002Fblogger.googleusercontent.com\u002Fimg\u002Fb\u002FR29vZ2xl\u002FAVvXsEgoiIM6TX9TShDQoVLnmGNE_LZPas3bK4cwsNviskgSjdFASOmzcJPOixde9rkt0uawGd5D5IRHc09j5etqie865lUafh95s-TggQm3PluElF3XhILbJUCkl6vJy6lAM5FSu0GBNu6eWHcVzH7d9X86fvxOjnhwylSgakxghEq_05FsWzZ8mSVMHWYr5HBS\u002Fs1600\u002Fweeklyrecap.jpg","2026-08-03T14:03:11+00:00","2026-08-03T16:00:30.771455+00:00",8,[18,21,23,25,27,29],{"name":19,"type":20},"Claude Opus 4.7","product",{"name":22,"type":20},"Mythos 5",{"name":24,"type":20},"Coldcard hardware wallet",{"name":26,"type":20},"Microsoft Outlook Web Access",{"name":28,"type":20},"Ruby on Rails",{"name":30,"type":31},"Laundry Bear","threat_actor","e7b231c8-5f79-4465-8d38-1ef13aea5a14",{"id":32,"icon":34,"name":35,"slug":36},null,"Threat Intelligence","threat-intelligence",[38,43,48,53],{"category":39},{"id":40,"icon":34,"name":41,"slug":42},"6cbdd207-aaa1-4176-9534-e156b125e917","Nation-state","nation-state",{"category":44},{"id":45,"icon":34,"name":46,"slug":47},"80544778-fabb-4dcd-aa35-17492e5dcf4f","Vulnerabilities","vulnerabilities",{"category":49},{"id":50,"icon":34,"name":51,"slug":52},"89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5","Malware","malware",{"category":54},{"id":32,"icon":34,"name":35,"slug":36},[56,60,63],{"type":57,"value":58,"context":59},"cve","CVE-2026-42897","Microsoft Outlook Web Access (OWA) cross-site scripting vulnerability exploited by Russian threat actors.",{"type":57,"value":61,"context":62},"CVE-2026-66066","Critical Ruby on Rails Active Storage vulnerability allowing arbitrary file read.",{"type":52,"value":64,"context":65},"OWAReaper","JavaScript browser-based implant used by Russian threat actors for persistent access in Microsoft OWA."]