July Threat Rundown
BLOG

July Threat Rundown: Autonomous AI Ransomware, Accelerated Exploitation, and Backup Telemetry Insights

PUBLISHED AUG 4, 2026 BY Amit Malik

Rubrik Zero Labs presents insights from late June through late July 2026, highlighting critical shifts in the cybersecurity landscape.

Rubrik Zero Labs presents insights from late June through late July 2026, highlighting critical shifts in the cybersecurity landscape. All threat intelligence is available via the Rubrik Zero Labs threat feed for detection in Rubrik products.

Major Stories of the Month

  1. JADEPUFFER Autonomous AI Ransomware Escapes Containment
  • The reporting period saw the first documented fully autonomous ransomware attack executed entirely by an LLM agent without human intervention.
  • The JADEPUFFER operator exploited the Langflow RCE vulnerability (CVE-2025-3248), mapped the environment, stole cloud credentials, and successfully encrypted 1,342 production database settings on a MySQL-backed Nacos instance in mere minutes.
  • In later iterations, the malware upgraded to ENCFORGE, specifically targeting 180+ AI model artifact extensions (such as training datasets and vector databases) with unrecoverable encryption to force costly model retraining.
  1. AI-Accelerated Vulnerability Discovery Triggers Unprecedented Patch Flood
  • Microsoft's July Patch Tuesday broke records by delivering 622 CVEs—more than triple the volume of June—which the vendor directly attributed to frontier AI models accelerating vulnerability discovery.
  • This AI-powered discovery compressed attacker weaponization timelines to hours rather than weeks; maximum-severity vulnerabilities like Adobe ColdFusion (CVE-2026-48282) and WordPress Core (CVE-2026-63030) were actively exploited in the wild within hours of public disclosure.
  • The speed of exploitation has forced CISA to issue strict three-day federal patch deadlines, signaling an existential crisis for organizations reliant on traditional, multi-week patch testing and deployment cycles.
  1. Zimbra Zero-Click Email Theft by Russian State Actors
  • The Russian GRU-linked APT group "Laundry Bear" systematically exploited a zero-click vulnerability (CVE-2025-66376) in the Zimbra Collaboration Suite for a full five months before a patch was issued.
  • Requiring no user interaction beyond an email preview, the attack deployed ZimReaper malware to silently exfiltrate the last 90 days of emails, complete active directories, browser-saved passwords, and 2FA recovery codes via DNS tunneling.
  • The prolonged espionage campaign successfully compromised high-value targets across the U.S. government, Ukrainian agencies, nuclear facilities, and the defense industrial base.

Top Ransomware Groups

Note: Ransomware operators in July demonstrated a significant pivot toward operational sophistication, leveraging autonomous LLM agents and extremely rapid network-wide encryption capabilities.

  1. CMD – The group successfully hit Mount Royal University, exfiltrating 10TB of institutional data and issuing a $1.9M (30 BTC) extortion demand.
  2. Anubis – Affiliates of this group leveraged vulnerabilities like CitrixBleed 2 and tools like RDP and PsExec for lateral movement, ultimately claiming a major attack on Coca-Cola Fairlife Dairy that halted all U.S. nationwide dairy production and resulted in 1TB of stolen data.
  3. Blackfield – This group targeted the global electric motor manufacturer Nidec Corporation, issuing a direct extortion demand of $2M.
  4. JADEPUFFER – Representing the first documented fully autonomous ransomware executed entirely by an AI agent, this threat actor exploited a Langflow vulnerability to encrypt 1,342 Nacos settings without human intervention. In later operations, the group upgraded to ENCFORGE, specifically targeting over 180 AI model artifact extensions with unrecoverable encryption to force costly model retraining.
  5. Spirals – This new Rust-based ransomware family achieved complete network encryption of a South Asian IT firm in under 24 hours, utilizing IIS webshells for entry, credential dumping, and PsExec for lateral movement.

Linux / Cloud / Identity Attacks: Top Threats

These threats are prioritized based on their critical severity (CVSS scores), immediate widespread impact, and observed mass exploitation in enterprise environments.

  1. SimpleHelp RMM Maximum-Severity Exploitation (CVE-2026-48558)
  • Type: Cloud Infrastructure / Identity
  • Impact: A critical authentication bypass allows threat actors to gain unauthorized technician access to SimpleHelp Remote Monitoring and Management (RMM) software.
  • CVSS 10.0 / Statistics: Holding the maximum severity score, this flaw was actively leveraged to deploy Djinn Stealer, a malware variant specifically designed to aggressively harvest credentials for cloud platforms (AWS, Azure, GCP) and AI development assistants across Windows, macOS, and Linux endpoints.
  1. SonicWall SMA1000 Zero-Day Chain (CVE-2026-15409 / CVE-2026-15410)
  • Type: Identity / Network Infrastructure
  • Impact: Attackers chained an unauthenticated Server-Side Request Forgery (SSRF) with authenticated admin command execution to completely hijack Secure Mobile Access VPN appliances.
  • CVSS 10.0 / Statistics: Attackers exploited this chain for three weeks before vendor disclosure to successfully steal administrator session tokens, user credentials, and TOTP MFA seeds. The severity of the compromise requires hardware to be completely re-imaged, as patching alone cannot remove the attacker's persistence.
  1. GhostLock Linux Kernel Privilege Escalation (CVE-2026-43499)
  • Type: Linux Operating System
  • Impact: A 15-year-old use-after-free vulnerability in the Linux kernel rtmutex futex code allows an unprivileged local user to attain root privileges and escape container isolation boundaries.
  • Statistics: The exploit operates with 97% reliability and affects virtually all major distributions (Ubuntu, Debian, RHEL, CentOS) utilizing kernel versions 2.6.39 through 7.1 7. Discovered by an AI security model, it represents a critical infrastructure risk to cloud providers where kernel isolation serves as the primary security barrier.

Insights from Rubrik Zero Labs LLM Powered Advanced Analysis Systems

Top Threats Inside Backups: Our advanced analysis systems identify top and trending threats seen in the wild and compare that data with backup telemetry to detect stealthy malware. In this section we present the data for this month.

Beyond the Front Line

3.0% of prevalent threats are identified with high confidence as having bypassed front-line defenses. Behind that cohort stands a concentrated set of named adversaries, each with a distinct catalogue of tooling, whose activity accumulated evidence in environments where successfully-contained threats do not leave a trail. 71.4% of named campaigns tied to the bypass cohort carry adversary attribution. The operators range from state-sponsored intelligence services to ransomware-as-a-service operations, but they share a common capability: the discipline to evade front-line containment long enough for their objectives to complete. The cohort's footprint concentrates in Technology, Cybersecurity, and Financial Services, though the pressure distributes across sectors in patterns that reflect each operator's targeting priorities.

Agenda

IndustryShare of cohort footprint
Technology16.7%
Unknown83.3%

Agenda, also tracked as Qilin, is a financially-motivated cybercrime group known for ransomware campaigns targeting enterprise networks. AGENDA/Qilin is a ransomware family with variants written in both Go and Rust that are highly configurable through command-line arguments, accounting for 0.7% of the bypass cohort's alert activity.

Clop

IndustryShare of cohort footprint
Technology100%

Clop is a financially-motivated cybercrime group known for ransomware campaigns and data extortion targeting enterprise networks. This period, Clop deployed CLOP, ransomware written in C++ that encrypts files by generating a unique RC4 key for each file, which is then encrypted with an embedded RSA public key, accounting for 0.8% of the bypass cohort's alert activity.

Water Kurita

IndustryShare of cohort footprint
Technology100%

Water Kurita is known for targeted intrusion campaigns. The group operates under campaign banners including FakeGit. During this period, Water Kurita deployed STEALC, a data miner written in C that targets data from multiple web browsers, chat software,and various other applications and uploads collected data to command and control infrastructure, accounting for 0.1% of the bypass cohort's alert activity.

Sector composition of the high-confidence bypass cohort, shown as share of cohort-wide environment footprint.

Bypass cohort

Ransomware

Ransomware families made up 15.4% of identified threats this period, surfacing seven distinct ransomware families across the dataset. WASTEDLOCKER dominated the chart with 18.0% of ransomware activity, followed by SODINOKIBI at 2.4% and DAVESHELL at 2.0%.

Technology environments absorbed 56% of the period's ransomware footprint, a concentration driven by high-value target profiles with critical digital infrastructure, customer data, and operational dependencies. Cybersecurity environments accounted for 38%, demonstrating that mature security postures reduce but do not eliminate ransomware risk, as operators actively engage with organizations equipped to respond aggressively.

Ransomware familiesSector composition

LATEST BLOGS