Our analyst team shares a few articles each week in our email newsletter which goes every Thursday. Make sure to register! This blog highlights those articles in order of what was the most popular in our newsletter – what our readers found the most intriguing. Stay tuned for a recap every month. We hope sharing these resources and news articles emphasizes the importance of cybersecurity and sheds light on the latest in threat intelligence.

Sysdig researchers have identified a ransomware operation, named JadePuffer, that appears to have been conducted entirely by a large language model (LLM) agent. The autonomous AI agent carried out the full attack lifecycle, including target reconnaissance, credential theft, lateral movement, persistence establishment, privilege escalation, and data encryption. Much like a human operator, the agent adapted to setbacks encountered during the intrusion, refining its approach and adjusting parameters to overcome failures and continue the attack. JadePuffer gained initial access by exploiting CVE-2025-3248, an unauthenticated remote code execution vulnerability in Langflow, a widely used open-source framework for building large language model (LLM) applications. Read full article.
Leaked negotiation transcripts show that a U.S. government entity paid Kairos a $1 million ransom after a credential-based attack in May 2025. Kairos claimed it gained access through a brute-force attack, and the victim was added to the group’s leak site on 21 May 2025. Instead of encrypting systems, Kairos focused on stealing data and threatening to publish it. The group claimed to have stolen 2 TB of data, including more than 1.6 million files. Kairos also shared security recommendations and a claimed list of deleted files after the payment. Read More.

Through its Rewards for Justice program, the U.S. Department of State is offering up to $10 million for information leading to the identification or location of members of the UNC5792 and UNC4221 hacking groups, which are linked to Russia’s intelligence and military services. Officials said UNC5792 has conducted widespread phishing campaigns targeting Signal and WhatsApp accounts belonging to U.S. government officials, military leaders, and allied personnel. As part of its effort, the U.S. government is requesting information on the identities, locations, biographies, and affiliations of UNC5792 members and their support personnel, as well as any links to Russian intelligence services, contractors, or third-party service providers. Information regarding operational infrastructure could also be valuable to officials. Read more here.
Following an investigation, the Spanish Police have announced the dismantling of a “cybercrime and money-laundering organization that made €140 million ($160 million) from investment fraud and business email compromise (BEC) attacks”. Authorities arrested four people in Spain, Portugal, and Panama as part of the international law enforcement operation. Additionally, authorities acquired 15 computers and 170 smartphones believed to have been used in the operations. Investigators described the network as operating on an industrial scale, using more than 800 bank accounts, 120 business accounts, and 67 external accomplices who served as “money mules” to move and conceal illicit funds. Read here.
On July 13, the U.S. Department of the Treasury announced that the Office of Foreign Assets Control (OFAC) had imposed sanctions on 1VPNS, its administrator Dmytro Rashevskyi, and Belarusian national Yegeniy Silayev. According to the Treasury, Rashevskyi operated 1VPNS, a VPN service that allegedly provided infrastructure to ransomware groups, while Silayev supplied encryption and obfuscation services that helped ransomware operators evade detection when targeting U.S. and allied organizations. The sanctions were issued under President Trump’s Executive Order 14390 and existing cyber-related sanctions authorities to combat foreign cybercrime and protect U.S. financial and digital systems. Learn more.

An EvilTokens campaign has been observed exploiting a blind spot in email security through a technique known as “ghost phishing.” The campaign has targeted businesses across the United States and Europe by keeping the malicious phishing page concealed until it is decrypted and rendered within the victim’s browser. The phishing kit leverages Microsoft Device Code Phishing to trick victims into completing a legitimate Microsoft sign-in flow and unknowingly granting attackers access to their accounts, eliminating the need to steal passwords directly. Because the phishing page remains encrypted until it is opened in the browser, traditional email security controls are unable to inspect its contents. The page’s HTML is protected with AES-GCM encryption and is only revealed after the browser decrypts it and renders the phishing content in the Document Object Model (DOM). Read full article.
The Blackfield ransomware gang has asked Nidec Corporation for $2M ransom following an alleged breach of their network. Nidec has acknowledged the possibility of a data breach but has not confirmed that any personal or confidential information has been leaked online. As for the operational impact, Nidec said it is assessing whether the incident could affect production, shipping, or other business activities. At this stage, the company does not expect the disruption to spread to other Nidec Corporation or Nidec Group companies. Meanwhile, the Blackfield ransomware group has claimed responsibility for the attack, giving Nidec more than 15 days to respond and enter negotiations. The group has threatened to publish or sell the allegedly stolen data if its demands are not met. Generating annual revenue of $17.2 billion and employing roughly 100,000 people across manufacturing facilities and subsidiaries in more than 40 countries, Nidec is a global leader in electric motor manufacturing. Read full article.

The Department of Homeland Security is investigating a cyberattack that compromised the Homeland Security Information Network (HSIN), a sensitive information-sharing platform used by government and private-sector partners. The intrusion is believed to have occurred between late May and early June and targeted both HSIN servers and a SharePoint collaboration system. It remains unclear whether any data was exfiltrated or who was responsible for the attack. The Department’s Office of Intelligence and Analysis has conducted a damage assessment to evaluate the scope and potential impact of the breach. Learn more.
Products
Services
Use Cases