Low-skilled attacker used Claude, Codex to breach 14 companies
2026-06-17T20:51:49Z•a84e197f8acd5d41e5d208070ad40ff1c2c5799d5aae3735e0b245a37898a0c7
AI agentsAgentic ControlAndroid trojanClaudeCodexCorelightFlip Frontline IdentityKubernetes securityNDROALABSOpen NDRPHIRokarollaTigera LynxWitnessAIaccessibility abuseagentic AIbanking trojandata breachdevice takeoverextortionhealthcareiRhythmlow-skilled attackermobile malware
What happened
This feed aggregates multiple Help Net Security reports (17 Jun 2026) highlighting a rising threat and defensive response landscape. Key incidents: OALABS recovered >1,000 agent sessions showing a low-skilled attacker used AI coding agents (Anthropic Claude Code, OpenAI Codex) to bypass guardrails and breach 14 companies; iRhythm disclosed a data breach impacting patient protected health information and proprietary data with an extortion claim; Zimperium described a new Android banking trojan, “Rokarolla,” that targets 217 banking/crypto apps, supports ~137 commands, and can takeover devices (
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- helpnetsecurity
- Record identifier
- a84e197f8acd5d41e5d208070ad40ff1c2c5799d5aae3735e0b245a37898a0c7
- Enrichment time
- 2026-06-17T20:51:49Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.