Article Read Time

This week the threat landscape sharpened around two themes: the weaponization of AI agents and the exploitation of trusted access. A single link could forge a rogue AI insider, extortion crews leaned on the phone rather than the exploit, and a fired employee’s credentials became a live breach. Here is what mattered, and what to do about it.
1. “AgentForger” Flaw Let a Single Link Forge a Rogue AI Insider Inside ChatGPT
Researchers at Zenity Labs disclosed a critical vulnerability in OpenAI’s ChatGPT Workspace Agents, codenamed AgentForger, that allowed one phishing link to quietly build, authorize, and deploy an attacker-controlled AI agent inside a victim’s organization. The forged agent inherited the victim’s identity and, across a dozen proof-of-concept scenarios, could map the environment, harvest files and credentials, impersonate employees, and launch internal phishing to spawn even more compromised agents. OpenAI remediated the issue after responsible disclosure by removing the URL parameter that enabled the attack.
Source: The Hacker News. https://thehackernews.com/2026/07/chatgpt-agentforger-flaw-could-deploy.html
2. Abbott Laboratories Investigates Twin Cyber Incidents as ShinyHunters Claims Breach
Healthcare and diagnostics giant Abbott Laboratories confirmed it is investigating two cyber incidents after the ShinyHunters extortion group claimed to have stolen internal data. Investigators say the attackers used voice phishing (vishing) against employees in mid-June to compromise a Microsoft Entra single sign-on account, opening a path into legacy Exact Sciences systems within Abbott’s Cancer Diagnostics business. Abbott states the incidents did not affect manufacturing, product availability, or patient services, and it has engaged outside experts and notified law enforcement.
Source: Cybernews. https://cybernews.com/news/abbott-laboratories-breach-shinyhunters/
3. Origin Energy Confirms Breach After Attacker Reuses a Former Employee’s Login
Australian energy provider Origin Energy confirmed unauthorized access to customer data after an attacker logged in using the still-active credentials of a fired former employee to reach the company’s customer management system. Exposed information may include names, addresses, phone numbers, dates of birth, account details, and partial payment card or bank digits, with the threat actor initially claiming roughly two million affected customers. The Australian Federal Police, the Australian Cyber Security Centre, and the Office of the Australian Information Commissioner are assisting with the response.
Source: BleepingComputer. https://www.bleepingcomputer.com/news/security/australian-energy-provider-origin-says-data-breach-exposes-client-data/
4. CISA Adds Check Point and SharePoint Flaws to Its Known Exploited Vulnerabilities Catalog
On July 22, CISA added two actively exploited vulnerabilities to its Known Exploited Vulnerabilities Catalog: CVE-2026-16232, an improper authentication flaw in Check Point SmartConsole, and CVE-2026-50522, a deserialization of untrusted data flaw in Microsoft SharePoint. Both are the kind of high-value targets attackers routinely chain into deeper network access. Federal agencies face binding remediation deadlines, and CISA urges every organization to prioritize patching these products now.
Source: CISA. https://www.cisa.gov/news-events/alerts/2026/07/22/cisa-adds-two-known-exploited-vulnerabilities-catalog
5. New Report: A Fresh Ransomware Crew Is Emerging Every Week
A report published July 21 found the ransomware ecosystem is fragmenting at speed, tracking 146 active ransomware groups with 61 new entrants in 2026 alone, more than one new crew per week. The group known as The Gentlemen ranked as the most prolific operator of the month, trading the top spot back and forth with Qilin in what researchers describe as an active rivalry. The takeaway for defenders: the brand names change constantly, but the playbook of stolen access and data extortion does not.
Source: Infosecurity Magazine. https://www.infosecurity-magazine.com/news/new-ransomware-weekly/
