ThreatsDay: AI-Powered Hacking, 370 Chrome Flaws, SonicWall Attacks, DNS Hijacking + 22 More Stories
17:25 · July 30, 2026 · Hacker News AI Section

A lot of security still comes down to trusting the wrong screen. This week, that screen might be a login page, an install guide, a recruiter call, or a familiar service behaving slightly wrong. Behind it: reused credentials, exposed systems, quiet loaders, abused trust, and exploit paths that should have been harder. Some defenses improved. The loose parts still got found first. Anyway,
Summary
This week's threat roundup details an autonomous offensive operation by a Chinese-speaking actor using the Hermes Agent framework and DeepSeek models to scan for and exploit seven vulnerabilities across AI development platforms and infrastructure components, including Langflow, n8n, Marimo Notebook, and Citrix NetScaler. The agent handled target enumeration, exploit sourcing from public repositories, code generation, and decision-making with minimal human input, falling back to additional CVE searches when initial attempts failed due to restrictive configurations. Limited use of Claude Code, Codex, and Qwen Code supplemented the primary DeepSeek reasoning engine.
A separate Russian-speaking campaign, Operation STANDOFF, integrates commodity malware distribution through pay-per-install loaders with a proxy botnet and hands-on intrusion capabilities, while deploying AI-generated personas across Telegram networks to amplify content, promote gambling services, and manipulate engagement. The same infrastructure supports both automated credential theft via tools such as Raccoon Stealer and RedLine and targeted enterprise access.
Attackers have also weaponized searches for AI tooling, serving malicious installers for Claude on macOS that trigger a multi-stage MacSync Stealer chain involving zsh loaders, server-side AppleScript, and TCC permission theft. Parallel activity includes ClickFix lures adapted for WebDAV delivery of non-standard payloads and recruiter-themed campaigns distributing data-stealing apps disguised as AI meeting software.
Additional items cover Google's patching of 370 Chrome vulnerabilities, supply-chain hardening measures at GitHub and npm, and a range of ransomware and loader campaigns affecting manufacturing, finance, and energy sectors.
Why it matters
The article is highly relevant as it details emerging AI-driven offensive capabilities and active exploitation of AI infrastructure that Dutch security professionals must defend against. It also highlights defensive AI advancements and includes a specific mention of Dutch involvement in Europol cyber operations.









