Security Affairs newsletter Round 584 by Pierluigi Paganini – INTERNATIONAL EDITION
2026-07-05T08:51:42Z•fdc813a27225a1b3ae8f17d13e57ec0ecf2e13c31222a802db8f68e8432fef08
AI‑driven attacksCISAJADEPUFFERKairosMicrosoft SharePointNetNutPegasusTeamPCPVercelantitrust/Android finecredential theftdata extortiondeveloper tools compromiseemail securitygovernment sectorhealthcare sectorknown exploited vulnerabilitylaw enforcement takedownransomwareresidential proxyspywaresupply chain
What happened
Weekly Security Affairs roundup covering multiple high‑impact incidents: a U.S. government agency paid $1M to data‑extortion group Kairos; FBI FLASH alerts that TeamPCP poisoned developer/security tools to steal cloud credentials and push malware; Citizen Lab found Pegasus infections against an MEP investigating the spyware; Sysdig documents JADEPUFFER, an end‑to‑end LLM‑driven ransomware operation; a shadow AI supply‑chain breach at Vercel led to data theft and a $2M extortion demand; Google/FBI and partners disrupted the NetNut malicious residential proxy service; research shows government &
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- fdc813a27225a1b3ae8f17d13e57ec0ecf2e13c31222a802db8f68e8432fef08
- Enrichment time
- 2026-07-05T08:51:42Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.