Smooth AI criminal drives 'first' end-to-end agentic ransomware attack

2026-07-02T19:24:11Zc4e01060cd35a0433d959b529926fe1016074097857cbd69fac3532d6848f142
0-day-repoCVE-2026-20230agentic-ransomwareamazon-qcisa-kevciscocredential-exposuredeepseekdevice-code-phishingeviltokensexploitation-in-the-wildfortibleedgit-repo-code-executionin-browser-ransomwarellm-abusemedtronic-data-breachmiasmanpm-poisoningoracle-e-business-suitephishingransomwaresharepoint-rcesupply-chain-attack

What happened

A broad, high-tempo security pulse: researchers reported what may be the first end-to-end agentic AI-driven ransomware operation and multiple cases of LLM abuse (prompt-injection, red-team hijacks). Active, high-impact exploitation was observed for enterprise products — Microsoft SharePoint RCE was added to CISA’s KEV, Oracle E‑Business Suite was attacked before public exploit code, and Cisco’s CVE-2026-20230 is under active exploitation. Major breaches and supply-chain attacks continue (Medtronic data exposure tied to ShinyHunters, npm poisoning by the Miasma campaign), while new phishing/UBE

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
theregister_security
Record identifier
c4e01060cd35a0433d959b529926fe1016074097857cbd69fac3532d6848f142
Enrichment time
2026-07-02T19:24:11Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.