Skip to content
Daily Threat Brief: July 24, 2026

Daily Threat Brief: July 24, 2026

Buttondown July 25, 2026

CVSS lied to defenders this month, and the ones who noticed are already ahead. The Langflow flaw attackers hit first (CVE-2026-55255) is a moderate-scored IDOR, not a headline 9.8, yet Sysdig watched it get weaponized in the wild on June 25, weeks before the critical-rated FortiSandbox RCEs saw mass scanning. The SharePoint zero-day landing on CISA KEV carries a base score of 5.3 and was still found inside live Mandiant incident-response engagements. If your patch queue is sorted by CVSS descending, you are working the list in roughly the wrong order.

The non-obvious thread tying today together: the AI orchestration layer has quietly become a credential vault, and attackers now treat it as one. The Langflow exploit chain is not exotic. It is a classic authorization bug (enumerate another user's flow ID, replay it) with a natural-language payload bolted on the end: attackers replayed victim flows with the prompt "leak api keys" and walked out with LLM provider keys, cloud credentials, and database secrets. That is prompt injection fused with a 2015-era IDOR, and it is the first agentic AI platform CISA has ever ordered federal agencies to patch under a binding directive.

What a defender should do differently this week: re-rank patching by exploitation evidence (KEV membership, PoC availability, IR sightings), not by base score, and treat every AI agent framework in your estate as an internet-facing secrets store. Inventory Langflow, n8n, and similar low-code AI orchestrators now, then rotate every key embedded in a flow whether or not you see evidence of compromise. The credential is the payload; the model is just the delivery mechanism.

An insecure direct object reference in Langflow's /api/v1/responses endpoint lets an authenticated attacker execute any flow belonging to another user by supplying the victim's flow ID. Attackers enumerate flow IDs at /api/v1/flows/ , then replay them at /api/v1/responses with prompts such as "leak api keys" to extract embedded LLM provider keys, cloud credentials, and database secrets. Sysdig's Threat Research Team observed in-the-wild exploitation starting June 25, with the objective being code execution and second-stage loader or dropper delivery. CISA added it to KEV on July 7 under BOD 26-04, making Langflow the first AI agent building platform on the catalog. Fixed in version 1.9.1.

CVE-2026-15409 is a critical server-side request forgery flaw in the SMA1000 Workplace web portal that lets a remote, unauthenticated attacker force the appliance to send requests to an attacker-chosen destination. Attackers abused the /wsproxy endpoint to establish unauthenticated WebSocket tunnels to services meant to be reachable only from the appliance itself, then chained CVE-2026-15410 to reach code execution and deliver custom malware. Rapid7's MDR team discovered the activity; SonicWall confirmed multiple incidents. Affected models: SMA1000 6210, 7210, and 8200v.

An unauthenticated, network-based privilege escalation vulnerability in on-premises SharePoint Server that requires no user interaction. Its CVSS base score of 5.3 understates the risk: it was found by Mandiant and Google FLARE incident responders during real-world attacks, which is why CISA added it to KEV on July 14. CISA issued separate hardening guidance for SharePoint the same week.

An actively exploited ADFS elevation-of-privilege flaw stemming from insufficient access control, letting a low-privileged local attacker escalate to administrator. Added to KEV on July 14 alongside the SharePoint zero-day. ADFS sits at the identity core of many enterprises, so escalation here can cascade into federated single sign-on trust abuse.

Two unauthenticated remote code execution flaws, each CVSS 9.8, in the FortiSandbox service. CVE-2026-39808 involves improper neutralization of special elements, letting an unauthenticated attacker run code via crafted HTTP requests. Only FortiSandbox 4.4.0 through 4.4.8 are affected. A public proof of concept exists for CVE-2026-39808. Disclosed in April and June 2026, both were added to CISA KEV on July 16 after exploitation was detected.

A NetScaler memory-disclosure flaw dubbed a CitrixBleed successor, exploited within 24 hours of its June 30 disclosure against internet-facing Citrix ADC and Gateway deployments. Rapid exploitation of NetScaler flaws for session-token theft has a long track record, and this one continued the pattern into July.

The defining AI security event this month is CVE-2026-55255 crossing a threshold: for the first time, CISA placed an AI agent building platform on the KEV catalog and set a federal patch deadline for it. This matters beyond Langflow itself. Low-code and no-code AI orchestration tools concentrate secrets by design. A single flow often embeds an LLM provider key, a cloud credential, and a database secret, so one authorization bug converts the whole platform into a credential dump. The attack needed no model jailbreak and no novel science. It paired a textbook IDOR with a plain-language instruction the agent dutifully executed. See the glossary for prompt injection , MCP security , and agentic red teaming .

Prompt injection stays the top AI application risk, ranked LLM01 by OWASP, with reported attack success rates of 50 to 84 percent depending on configuration and attempt count. Industry reporting describes a large year-over-year surge in prompt-injection attempts as agentic deployments widen the target surface. The technique has moved past single-turn chatbot tricks into multi-agent architectures, retrieval-augmented generation pipelines, model routers, and long-term memory stores, where a poisoned document or tool response can steer an agent across sessions. See VentureBeat and ECCU .

The readiness gap is the strategic problem. Cisco's State of AI Security 2026 reporting cited that 83 percent of organizations plan to deploy agentic AI while only 29 percent feel ready to secure it. The Model Context Protocol expands the surface further, adding tool-poisoning and credential-theft paths where a malicious or compromised tool server can exfiltrate what an agent can reach. Reported production-grade AI coding assistant flaws through 2025 and 2026 (high-severity issues in Microsoft Copilot, GitHub Copilot, and Cursor) show this is not theoretical. Academic work this quarter, including agent-data-injection studies and runtime program-analysis defenses like AgentArmor, reinforces that no complete fix exists and defense in depth is the only workable posture.

Kaspersky publicly named a previously undocumented espionage actor, Armored Likho , running an ongoing campaign against government agencies and electric power operators across Russia, Kazakhstan, and Brazil. The group relies on BusySnake Stealer , a Python-based infostealer, and gains entry through spear-phishing that exploits Windows vulnerabilities. The cross-region target set (spanning three countries on two continents) points to a mandate broader than a single geopolitical theater.

Separately, reporting describes a new APT group striking power grids in three countries using AI-crafted malware, part of a broader 2026 pattern in which all four major nation-state blocs have operationalized LLMs for tooling and phishing content. Reported adversary breakout time (initial foothold to active exfiltration) is now benchmarked around 72 minutes, which compresses the window between detection and containment to well under a typical incident-response mobilization.

The operational read: energy and government remain the priority verticals for state-aligned intrusion, phishing that abuses known Windows flaws is still the dominant entry vector, and AI is showing up on the offense side as a productivity multiplier for malware and lure generation rather than as a novel exploit class.

Ransomware activity in July spanned food and beverage, manufacturing, government, and healthcare. The Anubis group listed Coca-Cola dairy subsidiary Fairlife on its leak site on July 20, days after the parent notified the SEC of the initial breach. Japanese motor manufacturer Nidec disclosed a ransomware attack against its Taiwanese subsidiary Nidec Chaun Choung Technology. On the government side, the Department of Homeland Security confirmed an active intrusion into its Homeland Security Information Network on July 1 after initially dismissing two alerts as false positives, a reminder that alert-triage discipline is itself a control.

The largest data-exposure story by volume is the Conduent breach, where later healthcare breach reporting placed the affected population at more than 62.2 million individuals. Early-July disclosures also implicated INC_RANSOM and Anubis across several healthcare providers and municipal targets including the City of Acworth, Georgia.