Daily Drop (1327)
06-27-26
Saturday, Jun 27, 2026 // Buy Bob a Coffee // Ghostwire
Qihoo 360 Claims Tulongfeng is China’s Answer to Anthropic Mythos
Bottom Line Up Front (BLUF): Qihoo 360 introduced Tulongfeng, an AI-driven vulnerability discovery system positioned as China’s response to Anthropic’s Mythos. Rather than relying on a single frontier model, Tulongfeng uses a swarm of specialized AI agents to model threats, identify risky attack surfaces, trace data flows, generate sandbox environments, and test exploitability.
Analyst Comments: The swarm model is the interesting part. Instead of trying to match U.S. frontier models head-on, Qihoo 360 is arguing that specialized agents backed by years of malware research, attack investigation data, and infrastructure defense experience can close the gap. That is a practical strategy. Security work is often not one big reasoning task; it is a chain of smaller tasks: scope selection, code analysis, data-flow tracing, exploit generation, sandbox testing, and validation. The risk is also clear. A system that can automatically find vulnerabilities, build sandboxes, generate exploit code, and test attack paths is inherently dual-use. In defensive hands, it can accelerate patching and software assurance. In offensive hands, it becomes a vulnerability factory.
READ THE STORY: Orbital Today
Russia Signals Future Security Talks with Europe After Ukraine Objectives Are Met
Bottom Line Up Front (BLUF): TASS reported that Russia plans to reassess its security relationship with Europe after achieving the objectives of its “special military operation” in Ukraine. Moscow is framing any future engagement with European states as part of a broader Eurasian security architecture, with Hungary and Serbia cited as examples of countries open to continued dialogue.
Analyst Comments: The report reflects Moscow’s current diplomatic posture: Russia views the existing European security framework as no longer workable and is positioning Eurasian security cooperation as the next phase after the war in Ukraine. Russian officials continue to argue that Western actions drove the crisis and that Moscow’s military and political response is necessary to protect its security interests.
READ THE STORY: TASS (RU)
Ukraine and FBI Uncover Russian Intelligence Campaign Targeting Messaging Accounts
Bottom Line Up Front (BLUF): Ukraine’s Security Service said it worked with the FBI to uncover a long-running Russian intelligence campaign targeting messaging accounts used by government officials, military personnel, politicians, activists, and Ukrainian nationals across Ukraine, Europe, and the United States. The attackers used fake support-themed SMS messages to trick victims into handing over credentials and account access material.
Analyst Comments: This campaign fits the broader Russian intelligence pattern of targeting secure messaging platforms through social engineering rather than breaking encryption. The goal is simple: get the user to surrender the account. Once attackers obtain confirmation codes, PINs, passwords, QR-pairing access, or recovery keys, they can access sensitive conversations without needing to defeat the underlying security of apps like Signal or WhatsApp.
READ THE STORY: THN
Allegedly China’s GLM-5.2 Self-Audit Finds Vulnerabilities in AI-Generated Parsers (Kanxue)
Bottom Line Up Front (BLUF): A post on Kanxue claims that the GLM-5.2 coding model used the 7884 V12 structural induction engine to autonomously build parsers for 10 file formats, then audit its own generated code. The test reportedly found security flaws in 6 of 10 parser modules, totaling 8 issues, with the full process completed in under five minutes.
Analyst Comments: Parsers are notoriously dangerous code paths because they handle complex, attacker-controlled input. If an AI model is generating parsers quickly and 60% of the resulting modules contain flaws, that reinforces a point security teams already know: AI-generated code cannot be trusted just because it compiles or appears functional. The more interesting claim is the workflow itself. The post frames GLM-5.2 as both the developer and the auditor, using the 7884 engine to guide structure recognition and vulnerability discovery. That kind of self-audit may be valuable for fast triage, but it should not replace human review, fuzzing, SAST, or exploitability validation. AI can accelerate bug discovery, but it can also miss edge cases, misunderstand formats, or produce unsafe fixes.
READ THE STORY: Kanxue
Qihoo 360 Claims Tulongfeng is China’s Answer to Anthropic Mythos
Bottom Line Up Front (BLUF): Qihoo 360 introduced Tulongfeng, an AI-driven vulnerability discovery system positioned as China’s response to Anthropic’s Mythos. Rather than relying on a single frontier model, Tulongfeng uses a swarm of specialized AI agents to model threats, identify risky attack surfaces, trace data flows, generate sandbox environments, and test exploitability.
Analyst Comments: The swarm model is the interesting part. Instead of trying to match U.S. frontier models head-on, Qihoo 360 is arguing that specialized agents backed by years of malware research, attack investigation data, and infrastructure defense experience can close the gap. That is a practical strategy. Security work is often not one big reasoning task; it is a chain of smaller tasks: scope selection, code analysis, data-flow tracing, exploit generation, sandbox testing, and validation. The risk is also clear. A system that can automatically find vulnerabilities, build sandboxes, generate exploit code, and test attack paths is inherently dual-use. In defensive hands, it can accelerate patching and software assurance. In offensive hands, it becomes a vulnerability factory.
READ THE STORY: RHC
Third-Party Breaches Expose Vendor Risk Across the Education Sector
Bottom Line Up Front (BLUF): Dark Reading reports that schools and universities are facing growing exposure from third-party software breaches, especially ransomware and Web application attacks affecting widely used education platforms. Verizon’s 2026 DBIR recorded 1,252 education-sector breaches last year, with more than half involving malware and 65% of those malware incidents involving ransomware.
Analyst Comments: Most districts and universities do not have the budget, staffing, or leverage to fully assess every SaaS provider they depend on. That creates a frustrating situation: the institution may take the public hit for a breach even when the failure starts inside a vendor’s environment. The Canvas incidents show the operational side of the risk. Taking a learning management system offline during finals creates immediate pressure, just like ransomware against hospitals. Attackers understand timing. End-of-school-year disruption gives them maximum leverage over institutions that need systems online to finish exams, grades, and administrative work.
READ THE STORY: DR
Chinese Uni-App Framework Used to Power 200,000+ Scam Sites
Bottom Line Up Front (BLUF): SecurityWeek reported that threat actors are using scam templates built with the legitimate Chinese open source DCloud Uni-App framework to run large-scale investment fraud operations. Infoblox identified more than 236,000 second-level domains tied to the activity, including fake crypto exchanges, gambling impersonation sites, WhatsApp phishing pages, crypto wallet drainers, and pig-butchering infrastructure.
Analyst Comments: Uni-App is a legitimate cross-platform development toolkit. The issue is that criminals have standardized on it because it lets them rapidly build and deploy convincing scam sites across mobile and web formats. That scale matters. When fraud crews can buy ready-made templates and launch thousands of sites quickly, takedowns become a whack-a-mole problem. The infrastructure also appears coordinated in places, with Infoblox observing synchronized dips in new domain registrations across scam sites hosted on different providers. That suggests at least some centralized control or shared disruption response.
READ THE STORY: Security Week
Anthropic Restores Claude Mythos 5 Access for Select U.S. Critical Infrastructure Defenders
Bottom Line Up Front (BLUF): Anthropic has restored access to Claude Mythos 5 for approved U.S. organizations involved in critical infrastructure defense after a two-week suspension that began on June 12, 2026. Access is being reinstated through a phased authorization process coordinated with federal agencies, while broader availability of Fable 5 remains under review.
Analyst Comments: Mythos 5 is being treated less like a commercial SaaS feature and more like a sensitive national security capability. That matters for security teams because access to high-end AI cyber tooling may increasingly depend on authorization, sector, use case, and government risk review. For defenders, the upside is clear: models like Mythos 5 can help process threat telemetry, prioritize vulnerabilities, accelerate incident response, and support analysts during high-tempo operations. That is especially relevant for organizations inside CISA’s 16 critical infrastructure sectors, where attack surfaces are large and response windows are shrinking.
READ THE STORY: GBhackers
OpenAI Previews GPT-5.6 Sol Under Restricted Access for Cyber Defense Use
Bottom Line Up Front (BLUF): OpenAI released a limited preview of GPT-5.6 in three variants: Sol, Terra, and Luna. Sol is positioned as the flagship model and OpenAI’s most capable cybersecurity model to date, but access is restricted to a small group of government-approved companies and partners while OpenAI tests stronger cyber safeguards and misuse controls.
Analyst Comments: OpenAI is clearly trying to thread the needle: give defenders better tools for vulnerability research, patch development, code review, and incident response, while preventing the same model from being used for exploitation, weaponization, or offensive tradecraft. The difficult part is that the boundary is messy. Vulnerability research and exploit development overlap heavily with offensive cyber activity. A model that can identify memory safety issues, generate credible exploit leads, and work with build systems can help defenders move faster, but it also raises the risk of misuse if guardrails fail or access controls are bypassed.
READ THE STORY: THN
Malicious OpenClaw Skills Expose New AI Supply Chain Risks
Bottom Line Up Front (BLUF): Researchers at Palo Alto Networks Unit 42 found five malicious skills on ClawHub, the marketplace for the OpenClaw AI agent ecosystem. The skills bypassed platform security checks and included infostealers, detection evasion, and agent-specific abuse techniques designed to steal data, manipulate recommendations, and exploit AI agents for financial gain.
Analyst Comments: OpenClaw skills are not just plugins with limited functionality; they can access local files, credentials, APIs, and connected workflows. That makes a malicious skill closer to a hostile extension running inside an agent’s trusted execution path. The more concerning development is the shift from classic malware to agentic abuse. Infostealers are bad enough, but skills designed to manipulate recommendations, inject affiliate links, or coordinate financial schemes show how attackers are starting to exploit the decision-making role of AI agents. Once users trust agents to recommend tools, move money, summarize data, or execute workflows, the agent itself becomes a target for manipulation.
READ THE STORY: DR
Critical Veeam Backup & Replication RCE Puts Backup Servers at Risk
Bottom Line Up Front (BLUF): The Centre for Cybersecurity Belgium is urging organizations to patch CVE-2026-44963, a critical remote code execution vulnerability in Veeam Backup & Replication versions 12 through 12.3.2. The flaw affects domain-joined deployments and allows a standard authenticated domain user to execute code on the Veeam Backup Server over the network.
Analyst Comments: If an attacker gains control of the Veeam Backup Server, they may be able to delete or encrypt backups, steal stored credentials, and move laterally before launching ransomware. The authentication requirement should not lower urgency. Standard domain credentials are often available to attackers early in an intrusion through phishing, infostealers, password reuse, or compromised VPN access. In a ransomware scenario, backup infrastructure is usually one of the first targets because attackers want to prevent recovery before encrypting production systems.
READ THE STORY: CCB
Cloud Bucket Hijacking Can Redirect Logs and Sensitive Data Across AWS, GCP, and Azure
Bottom Line Up Front (BLUF): Unit 42 researchers disclosed a cloud storage attack technique called cloud bucket hijacking that can redirect active data streams to attacker-controlled storage. The issue affects common cloud workflows across AWS, Google Cloud, and Microsoft Azure, where bucket or storage account names can become part of the trust model. If an attacker can delete a target bucket and recreate the same name under their control, existing logging, replication, or transfer jobs may continue sending data to the attacker.
Analyst Comments: The attacker changes the destination by deleting and reclaiming the bucket name. From the victim’s side, the pipeline may still look valid because the configured destination name has not changed. That is what makes this dangerous. Security teams tend to monitor changes to logging sinks, replication rules, and transfer jobs. They may not treat bucket deletion as an immediate exfiltration risk. In this case, deletion is the pivot point. Once the name is reclaimed, audit logs, telemetry, replicated objects, and other sensitive data can silently flow into an attacker-controlled account.
READ THE STORY: GBhackers
Cisco SD-WAN Zero-Day Exploitation Used Rogue Peering and Root-Level Account Creation
Bottom Line Up Front (BLUF): Mandiant revealed new details on attacks exploiting CVE-2026-20245, a Cisco Catalyst SD-WAN command injection vulnerability that allowed authenticated attackers to execute commands as root. The attackers used the flaw after gaining access to SD-WAN infrastructure, created a rogue root account named troot, extracted configuration data, and used anti-forensic cleanup to hide activity.
Analyst Comments: Rogue peering connections, access to SD-WAN Manager, configuration extraction, and unauthorized changes pushed to edge devices all point to a campaign focused on control, persistence, and stealth. The root account creation is the loudest technical detail, but the more important operational issue is certificate and peering trust. Mandiant noted that some rogue peering activity occurred on systems not vulnerable to previously disclosed authentication bypass flaws, and Cisco suggested stolen certificates from earlier compromises may have been used. That means patching CVE-2026-20245 is necessary, but not enough. Organizations need to review trust relationships, certificates, peer connections, and historical access.
READ THE STORY: Bleeping Computer
Pedit COW Linux Kernel Flaw Enables Local Root Privilege Escalation
Bottom Line Up Front (BLUF): A newly disclosed Linux kernel vulnerability, tracked as CVE-2026-46331 and dubbed Pedit COW, allows an unprivileged local user to gain full root access on vulnerable systems. A working public proof-of-concept exploit, packet_edit_meme, appeared within 24 hours of CVE assignment, sharply increasing risk for unpatched Linux hosts.
Analyst Comments: This belongs in the same mental bucket as Dirty Pipe, DirtyClone, and Dirty Frag: a kernel fast-path bug that lets an attacker write where they should not be able to write. The difference here is the entry point. Pedit COW abuses the Linux traffic-control subsystem and can be reached from a user namespace, allowing an unprivileged user to obtain namespace-local CAP_NET_ADMIN and then turn that into host-level root. That makes this especially relevant for multi-user and multi-tenant environments: Kubernetes nodes, CI/CD runners, shared build systems, developer workstations, hosting platforms, and research clusters. Anywhere untrusted users or workloads can execute local code should be prioritized.
READ THE STORY: GBhackers
Items of interest
Chinese Users Bypass Anthropic’s Claude Restrictions Through Proxies, Resold Accounts, and API Relay Services
Bottom Line Up Front (BLUF): WIRED reports that Anthropic’s efforts to block Claude access from China are being routinely bypassed through VPNs, foreign phone numbers, resold accounts, fake identities, and “transfer station” API relay services. The workaround economy has grown into a shadow market that gives Chinese users access to Claude while creating new risks around fraud, identity abuse, prompt interception, and unauthorized model access.
Analyst Comments: Anthropic can tighten geofencing, account bans, identity checks, and proxy detection, but as long as Claude remains valuable and publicly accessible elsewhere, users in restricted regions will keep finding paths around the gate. The stronger the restriction, the more the market shifts from casual VPN use to professionalized brokers, relay services, and fake identity vendors. The security risk cuts both ways. For Anthropic and U.S. policymakers, these workarounds undermine export-control and model-access restrictions, especially where advanced coding and agentic capabilities are involved. For Chinese users and companies, using underground relay services means their prompts, source code, credentials, business plans, and research data may pass through untrusted intermediaries that can log, resell, or manipulate traffic.
READ THE STORY: Wired
China’s 97% Off GPT & Claude API Scam Exposed (Video)
FROM THE MEDIA: What if I told you some students in China are reportedly getting access to GPT 5.4 and Claude API keys for up to 97% less than the official price? It sounds like the ultimate AI loophole: spend just a dollar or two, burn through tens of millions of tokens, plug the key into Cursor or VS Code, and start building. On the surface, it looks like a dream for developers, indie hackers, and anyone obsessed with AI coding tools.
Cheap Claude Tokens: The Million-Dollar Scam (Video)
FROM THE MEDIA: Grey-market “Claude” access can look like a huge discount, but the real price may be your prompts, source code, tool outputs, and accepted agent patches.
The selected stories cover a broad range of cyber threats and are intended to help readers frame key publicly discussed threats and improve overall situational awareness. InfoDom Securities does not endorse any third-party claims made in its original material or related links on its sites; the opinions expressed by third parties are theirs alone. For further questions, don’t hesitate to get in touch with InfoDom Securities at dominanceinformation@gmail.com.


