Cybercriminals Plant Malicious AI Agents in Open Source Tool Repositories
2026-07-09T08:52:14Z•9a34186d0e31cfd9fe3193148c71543fbefc8be4cbd8103f9e88df6ab0326940
adobe-coldfusionagentic-aiagentic-ransomwareai-malwareandroid-spywarecloud-compromisecritical-vulnerabilitymemory-only-infostealermillenium-ratmirainetnutopen-source supply-chainoracle-peoplesoftphishingprompt-injectionproxy-networkransomware-as-a-serviceredwingroundcube-exploitscattered-spidersimplehelp-rmmtinyRCTvidarxmr-minerzero-day
What happened
A broad wave of active malicious activity and high-risk vulnerabilities was reported across multiple sectors. Researchers observed a surge in malicious/agentic AI tooling (including the first reported agentic ransomware 'JadePuffer') and prompt-injection abuse targeting AI agents; open-source repositories and web content are being poisoned. Multiple actively exploited critical vulnerabilities and zero-days (notably an Adobe ColdFusion flaw with CVSS 10.0 and Oracle PeopleSoft zero-day impacting organizations including Nissan and US insurance bodies) have led to data breaches and malware/wiper/
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- infosecurity_magazine
- Record identifier
- 9a34186d0e31cfd9fe3193148c71543fbefc8be4cbd8103f9e88df6ab0326940
- Enrichment time
- 2026-07-09T08:52:14Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.