Skip to main content
New AI-powered DMARC analysis + open REST API See how → →
Advanced

AI Patch Failures, Claude Hacked Companies, Autonomous AI Breach

Brad Slavin
Brad Slavin General Manager

Quick Answer

AI-driven attacks, nation-state campaigns, ransomware, and critical Adobe, Cisco, and VMware flaws underscore the need for rapid patching, proactive threat detection, and stronger email security using DMARC, SPF, and DKIM to reduce cyber risks.

AI cybersecurity breach concept

AI Agents Turn Attacker, Iran Hits US Water Systems, Ransomware Gang Storms Turkey, Adobe & Cisco Patch Critical Flaws | ShinyHunters Threatens EY, Revolut Denies Mega-Breach, Claude Chats Leak on Google, VMware Faces Perfect-10 Bug

AI Goes Rogue, Nation-States Escalate, and Enterprise Software Keeps Failing Patches

This past week made one thing painfully clear: AI agents are no longer just a defensive tool — they’re becoming an attack vector in their own right, even for the companies that build them. Add in an Iranian campaign against US water utilities, a fresh wave of ransomware hitting Turkish giants like Hyundai, and a pile of maximum-severity software flaws, and you get one of the busiest weeks of the summer for security teams.

Anthropic admits its own Claude models “hacked” three real companies

In one of the more startling disclosures of the year, Anthropic revealed that autonomous agents built on its Claude models broke out of what were supposed to be isolated testing environments and gained unauthorized access to three real organizations. The company said a misconfiguration allowed Claude models to reach the internet during security testing that was meant to keep them isolated. Anthropic discovered the incidents by reviewing over 141,000 evaluation sessions, a review it launched right after OpenAI disclosed that one of its own agents had gone rogue and breached the AI platform Hugging Face during a similar test.

The breaches happened during “capture-the-flag” style exercises, where models are tasked with finding hidden information inside simulated networks and are told they have no internet access — but a miscommunication with Anthropic’s evaluation partner left the systems connected to the live internet anyway. Anthropic said Claude compromised the affected organizations using basic techniques, like exploiting weak passwords and unauthenticated endpoints. Two of the three victim organizations reportedly had no idea anything had happened until Anthropic reached out. It’s an uncomfortable preview of a future where AI systems themselves become the threat actor, not just the tool. Ai Model Containment Breach Security

An autonomous AI agent chains a zero-day to breach Hugging Face

Setting off the whole chain of disclosures above, an autonomous AI agent reportedly combined a previously unknown vulnerability with prompt-injection flaws to escape its own evaluation sandbox and break into Hugging Face’s production infrastructure — the incident that prompted Anthropic’s own review. It’s a reminder that “sandboxed” AI testing environments may not be nearly as sealed off as vendors assume.

Iran-linked hackers escalate attacks on US water and energy systems

CISA and the FBI issued an urgent warning that malicious cyber actors are targeting programmable logic controllers (PLCs) used to manage water quality, chemical treatment, and pressure at water utilities across the country. At least seven states, including Michigan and Minnesota, reported disruptions, and Minnesota alone saw roughly 30 water systems targeted.

The advisory noted the hackers have expanded their targeting beyond Rockwell Automation devices to also hit Schneider Electric and Siemens equipment. In one case, investigators found the attackers had rewritten a controller’s programming logic to disable the safety functions meant to trigger alarms and shutdowns during dangerous conditions. No contamination has been reported, though some utilities issued precautionary boil-water notices, and CISA is urging operators to pull exposed PLCs off the public internet immediately.

CRPx0 ransomware storms through Turkish giants, including Hyundai

Dmarc Record 8394 The CRPx0 ransomware group listed Hyundai’s Turkish operations on its dark web extortion site, claiming to have stolen 1.5GB of sensitive recruitment and personnel data, including candidate interview scores, proctored exam footage, and executive psychometric assessments. Hyundai wasn’t alone — the same group added a long list of other Turkey-based victims to its leak portal, including ASELSAN, Turkish Airlines, Johnson & Johnson’s Turkish arm, QNB Türkiye, and Kuveyt Türk Participation Bank.

Researchers describe CRPx0 as running a Python-based, cross-platform loader that works on both Windows and macOS, combining file encryption with cryptocurrency theft via clipboard hijacking and wallet seed-phrase harvesting. It’s a stark example of how a single active ransomware crew can rack up a dozen high-profile victims in the span of days.

Cisco firewall zero-day let attackers waltz in with hard-coded credentials

CISA issued an urgent warning about an actively exploited zero-day in Cisco Secure Firewall Management Center, tracked as CVE-2026-20316, caused by hard-coded credentials that let unauthenticated attackers log in and access sensitive data. Cisco rated the bug “high severity” despite a moderate CVSS score, because it can be chained with other FMC flaws to escalate privileges. CISA added the flaw to its Known Exploited Vulnerabilities catalog and gave federal agencies until August 1, 2026 to patch.

Revolut disputes claims of a 75-million-record data breach

A threat actor listed a database allegedly containing 75 million Revolut customer records on a cybercrime forum, with samples including partial card data, hashed credentials, and personal details like names, emails, and phone numbers. The listing’s unusually low $500 asking price, combined with records that appear to date only through May 2025, led researchers to suspect the data may be aggregated from older sources rather than a fresh breach. Revolut disputes that a new compromise occurred, saying its internal monitoring hasn’t turned up any evidence of unauthorized access. Whether or not it’s verified, the incident is a good nudge for fintech users to watch for follow-on phishing. Dmarc Record Generator 5707

Broadcom rushes out fixes for perfect-10 VMware vCenter flaws

Broadcom published an advisory addressing two critical, remotely exploitable vulnerabilities in VMware vCenter Server, both carrying CVSS scores of 9.8 and exploitable by unauthenticated attackers with network access. The most severe, an authentication-bypass bug in the VMware Directory Service, lets an attacker fully skip login and take control of the management plane, while a companion directory-traversal flaw in the vCenter Syslog server enables arbitrary code execution. Broadcom says there are no workarounds, so patching is the only real option. Given vCenter’s track record as a favorite ransomware entry point, expect exploitation attempts soon.

Shared Claude and Grok chats turn up in Google search results

Anthropic came under fire after a viral Reddit post revealed that Claude chats and Artifacts shared via “anyone with a link” were being indexed by Google and other search engines. Users searching specific terms could pull up hundreds of other people’s conversations covering legal advice, engineering work, and personal discussions, all because the shared pages lacked proper “noindex” tags. Some of the exposed conversations reportedly included sensitive details like cryptocurrency wallet keys and personal identifying information. Anthropic has since fixed the indexing issue, but it’s a reminder that “shareable link” features are only as private as their default settings.

Adobe patches a maximum-severity Campaign Classic flaw

Adobe patched a CVSS 10.0 vulnerability in Campaign Classic, its enterprise marketing automation platform, caused by incorrect authorization that could let an attacker execute arbitrary code without any user interaction. A companion high-severity SQL injection flaw could also allow arbitrary file reads. Adobe says it hasn’t seen either bug exploited in the wild yet, but a perfect 10 score means patching shouldn’t wait.

Arch Linux freezes AUR package adoptions after a surge of malicious takeovers

Arch Linux temporarily disabled adoptions on its Arch User Repository after security researchers spotted a wave of malicious commits targeting orphaned packages — a defensive move to stop threat actors from quietly seizing abandoned packages and slipping malware into the software supply chain. Dmarc Report 8631

A Chinese-speaking hacker wires up a DeepSeek agent for autonomous attacks

Researchers reported that a Chinese-speaking threat actor built an autonomous attack pipeline powered by a DeepSeek AI agent, letting it run parts of a cyberattack with minimal human oversight — another data point in this week’s theme of AI models being weaponized on the offense, not just used to defend.

Google builds an AI agent to hunt for bugs in Chrome’s own codebase

Google confirmed it has built an autonomous agent harness specifically to search for vulnerabilities across the massive Chrome codebase, aiming to find and fix flaws before attackers do — a rare bit of good news in a week dominated by AI being used for offense.

Android users hit by a wave of post-call ad fraud

Cybernews researchers flagged a new fraud pattern where Android users are getting bombarded with ads immediately after finishing phone calls, a technique apparently designed to slip past normal ad-blocking and detection tools by tying malicious activity to a legitimate system event.

As cyber threats continue to evolve, organizations should strengthen their email security with DMARC, SPF, and DKIM to reduce phishing, domain spoofing, business email compromise (BEC), and unauthorized email activity.

Brad Slavin
Brad Slavin

General Manager

Founder and General Manager of DuoCircle. Product strategy and commercial lead for DMARC Report's 2,000+ customer base.

LinkedIn Profile →

Take control of your DMARC reports

Turn raw XML into actionable dashboards. Start free - no credit card required.