Jul 6's Top Cyber News NOW! - Ep 1167
At a glance
Jade Puffer becomes the first documented ransomware operation run entirely by an autonomous AI agent, exploiting a 14-month-old vulnerability with a 99.97% exploitation probability. Separately, Google and law enforcement dismantle the Netnut residential proxy botnet, while Oracle EBS faces another critical vulnerability being actively exploited by cyber criminals.
Stories covered
How is Jade Puffer ransomware automating the entire cyber kill chain with AI agents?
What happened: Researchers at Cyig identified Jade Puffer, the first documented ransomware operation conducted entirely by an autonomous AI agent. The agent performed reconnaissance, credential theft, lateral movement, persistence, privilege escalation, and encryption—adapting to failures in real time, including recovering from a failed login in 31 seconds. Initial access came via CVE in Langflow, an open-source LLM framework, a vulnerability 14 months old with an EPSS score of 99.97%.
Why it matters: This demonstrates that threat actors can now automate full attack chains without human intervention. The exploitation of an ancient, highly-exploitable flaw underscores that vulnerability management is no longer optional—the time between discovery and compromise is shrinking as attackers leverage AI to iterate and refine attacks.
What to do: Treat vulnerability management and exposure management as your top operational priority. Patch high-EPSS vulns aggressively; a 99.97% exploitation score means it's effectively guaranteed to be hit. Review your patching SLAs and enforce them, especially for public exploits in your tech stack.
---
Why should third-party contractor access be treated like employee access?
What happened: Adapt Health suffered a breach when attackers socially engineered a third-party contractor into divulging credentials, gaining access to patient management systems, document storage, and EHR portals. No extortion demand or group claim has been reported yet.
Why it matters: Third-party access is a common attack vector; threat actors know contractors often have network access but may lack awareness training. A weak link in the supply chain becomes your incident.
What to do: Enforce mandatory security awareness training for all third-party contractors before provisioning credentials, regardless of engagement length. Set automatic account termination dates aligned with contract end. Implement least-privilege access—don't grant blanket permissions. Document training completion to establish a paper trail for potential legal recourse.
---
How did Google dismantle the Netnut residential proxy botnet?
What happened: Google, the FBI, Lumen Technologies, Shadow Server Foundation, and industry partners coordinated to take down Netnut (POPA), a botnet of millions of compromised Android devices, smart TVs, and streaming boxes. The residential proxy service allowed attackers and espionage groups to mask malicious traffic behind legitimate home IP addresses.
Why it matters: Residential proxies defeat IP geofencing controls—a common but insufficient defensive strategy. Threat actors could route through compromised devices to appear as legitimate users from any geography. Disrupting this infrastructure removes a key evasion capability.
What to do: Don't rely solely on IP-based geofencing. Implement behavioral analytics, device fingerprinting, and additional authentication controls. Recognize this is a tactical win but not permanent—threat actors will rebuild using other compromised IoT devices as the botnet returns.
---
When will the UK's National Cyber Action Plan be published?
What happened: The UK government delayed publication of its National Cyber Action Plan, originally scheduled for Monday, July 6, due to Prime Minister Kier Starmer's resignation. A related cyber resilience pledge involving FTSE 350 companies is still expected to launch the following day.
Why it matters: The UK cyber program has been accelerating rapidly, signaling serious government commitment to national cyber defense. The decision to pause rather than proceed despite political turmoil suggests genuine intent to execute well rather than issue performative directives.
What to do: Monitor for now. If you operate in or serve UK entities, expect heightened compliance and resilience requirements once the plan publishes.
---
Is spyware a threat to high-profile individuals and organizations?
What happened: Stellas Koglu, a former European Parliament member on the committee investigating spyware misuse, was infected with Pegasus spyware twice (October 2022 and March 2023) while conducting sensitive work on commercial spyware regulation. Citizen Lab reports no evidence supporting Koglu's claim that Greece was responsible.
Why it matters: Pegasus is reserved for high-value targets where ROI justifies half-million-dollar deployment costs. This incident highlights that espionage-grade malware targets power brokers, policymakers, and business executives—not commodity threats.
What to do: If you support VIPs or executives, implement enhanced device security, network segmentation, and behavioral monitoring. For most organizations, standard controls suffice; Pegasus is not a broad-based risk. Focus defensive resources proportional to likelihood and impact.
---
Should you patch Oracle EBS again after the critical vulnerability disclosure?
What happened: Threat intelligence firm Defused detected exploitation of a critical CVE (9.8 CVSS) in Oracle EBusiness Suite's payment processing module within a 2-hour window on Saturday. Oracle patched the flaw in late May with low exploitation complexity, and threat actors are already weaponizing it.
Why it matters: Oracle EBS has been hit repeatedly (most notably by KOP ransomware last spring). If your organization runs EBS, you should still have operational knowledge of its dependencies and patching processes from previous incidents.
What to do: Verify Oracle EBS is patched immediately. Confirm you know where all instances live, who owns them, and test your patching workflow. No excuses—this is the second major EBS flaw in 18 months.
---
What happened to Aubrey Cottle and the Texas GOP breach?
What happened: Aubrey Cottle, a 39-year-old Canadian hacker affiliated with Anonymous, was sentenced to 18 months in prison for defacing the Texas Republican Party website and exfiltrating data in September 2021. He pleaded guilty to data theft and publication.
Why it matters: Hacktivism—ideologically motivated attacks—remains a persistent threat vector often overlooked in threat modeling. This case illustrates that political and activist targets face distinct risk profiles.
What to do: Include hacktivism in your threat model if your organization holds political, social, or controversial positions. Expect defacement, data exfil, and public shaming as primary attack objectives, not financial extortion.
---
How much did a US government entity pay to prevent data leak?
What happened: Ransomware ISAC reported that an unnamed US entity paid approximately $1 million to the Kyros ransomware gang to suppress leaked files. Evidence suggests the victim was Union County, Ohio, which suffered a May 2025 ransomware attack, though neither party has confirmed.
Why it matters: Ransomware negotiations follow predictable stages—initial demand, verification, haggling, payment, and proof of deletion. Municipalities rarely have million-dollar ransoms available, suggesting either significant reserves or insurance coverage footing the bill.
What to do: If ransomed, understand the negotiation workflow: attackers typically accept 10–30% of initial demands. Never assume deletion; require proof. Consult counsel and your insurer before paying. Document all communications for law enforcement.
Key takeaways
- Vulnerability management is now a matter of hours, not months—Jade Puffer exploited a 14-month-old flaw with 99.97% EPSS, proving AI agents compress the window between discovery and compromise.
- Third-party contractor access requires the same security controls and awareness training as employees; social engineering a contractor is now a standard attack vector.
- Geofencing and IP-based controls are insufficient; residential proxy botnets prove attackers can mask their origin, so layer behavioral, device, and authentication controls.
- Pegasus spyware and nation-state tools target high-value individuals; standard controls suffice for most; focus resources on likelihood and impact.
- Patch Oracle EBS immediately if deployed; multiple critical flaws in 18 months indicate sustained attacker interest and low barriers to exploitation.
Topics covered
Want the live experience? The Daily Cyber Threat Brief airs live every weekday at 5am PT / 8am ET on YouTube. 400+ practitioners join the chat in real time.