LodeHQSubscribe →

Claude Cowork escapes VM, Starlink enables $114B scam

Infosec · 2026-07-25

Vulnerabilities & Exploits
Cl0p affiliates leverage Windchill/FlexPLM RCE chain for data extortion3 MIN

Ransom-ISAC’s advisory details how Cl0p affiliates chain a pre‑auth FlexPLM WSDL disclosure with a critical Windchill login servlet flaw (CVE‑2026‑12569) to achieve unauthenticated remote code execution and drop JSP web shells. The campaign targets internet‑exposed engineering data in manufacturing, automotive, aerospace and retail, enabling double‑extortion theft.

Claude Cowork’s ‘SharedRoot’ lets AI break out of its VM and read any Mac file7 MIN

Accomplish AI discovered that Claude Cowork’s macOS app shares the host filesystem read‑write into its Linux VM, allowing an agent to exploit CVE‑2026‑46331, gain guest‑root, and traverse the entire Mac file system. About 500,000 users running local sessions were exposed, exposing SSH keys, cloud credentials and other sensitive data.

AgentForger lets a phishing link spawn a rogue ChatGPT workspace agent8 MIN

Zenity Labs discovered AgentForger, a CSRF bug in OpenAI’s ChatGPT Workspace Agents that lets a malicious URL create, configure, and publish an autonomous AI agent inside a victim’s organization, inheriting the user’s credentials. The flaw was fixed by OpenAI days after disclosure, closing the path for silent insider attacks.

Threats & Malware
UN Report Shows Starlink Makes $114 B Scam Empire Nearly Untouchable5 MIN

UNODC's 2026 threat assessment details how transnational scammers in SE Asia use Starlink terminals to bypass government internet shutdowns, keeping massive scam operations alive. With 300,000 workers and $88‑$114 billion in annual losses, disrupting them is far harder because satellite internet decouples them from terrestrial infrastructure.

AI Agent Hermes Automates Post‑Exploitation in Thailand Finance Ministry Breach43 MIN

Hunt.io discovered open directories on a Hong Kong server showing Hermes AI running in unattended YOLO mode, automating privilege escalation, enumeration, and deployment of a custom Go implant called Hades, compromising multiple systems in Thailand's Ministry of Finance. This marks the first known use of an autonomous AI agent for espionage‑scale post‑exploitation, highlighting new threat vectors as AI tools become weaponized.

Global takedown of Tycoon2FA slashes MFA‑bypass phishing by over 90%8 MIN

Law enforcement and a consortium of security firms dismantled the Tycoon2FA phishing‑as‑a‑service platform, cutting its phishing volume by 92% and disabling its adversary‑in‑the‑middle MFA‑bypass kit. The operation seized more than 300 domains and forces attackers to rebuild costly infrastructure, reshaping the phishing threat landscape.

Privacy, Policy & Governance
Vatican Prayer App Exposes 700K Users' Personal Data via Unprotected API5 MIN

A vulnerable API in the Vatican’s Click‑to‑Pray app let anyone enumerate over 700,000 users, revealing names, emails, country and staff status. The IDOR flaw required no authentication, exposing global worshippers’ PII and raising concerns for a religious organization’s data hygiene.

Get Infosec in your inbox, every issue.
Subscribe free
Get the app · Privacy · Terms · About · Contact
© 2026 LodeHQ