Security news from last month shows a clear pattern, attackers are targeting the systems businesses rely on every day, including firewalls, remote access tools, SaaS platforms, vendor integrations, browsers, AI tools, and open-source software.
Many of these incidents are technical on the surface, but they often point back to operational gaps around visibility, ownership, access control, patching, vendor oversight, and decision-making.
Consumer routers and unmanaged systems under fire:
Several recent incidents show attackers continuing to abuse home routers, smart devices, and other consumer-grade equipment as part of criminal infrastructure. These devices may not directly breach your business, but they can be used to hide attacker activity, relay malicious traffic, conduct reconnaissance, or launch attacks.
Remote employees often depend on home networks, personal routers, smart TVs, streaming devices, cameras, and other unmanaged equipment. Even when corporate laptops are secured, the surrounding home network can still create risk.
AI security is moving from theory to real-world abuse:
Examples from the last month show that AI is creating practical business risk. Attackers are using AI tools to move faster, automate tasks, and lower the skill level required to conduct sophisticated attacks.
Simultaneously employees are adopting AI browsers, meeting bots, coding assistants, app builders, and automation tools faster than many organizations can govern them.
In June it came to light an unskilled attacker used AI throughout an entire attack process to compromise 14 companies. We also learned of an attacker leveraging an LLM to ransom an internet exposed AI system, AI browsers being manipulated to reveal passwords and secrets, and employees using unauthorized AI tools to automate business operations outside normal governance.
Business leaders should be asking what AI tools employees are using, what company data those tools can access, whether AI meeting bots are allowed in sensitive meetings, and who approves new AI tools before they are used with business information. Organizations should also prepare for incidents where attackers use AI to move faster, leaving less time to detect, contain, and make decisions.
Data breaches and third-party SaaS integrations are creating breach chains:
Recent incidents show how an organization can face a business-impacting breach, customer notification issue, regulatory exposure, or loss of trust through a third-party SaaS platform or integration.
This month included two high-profile examples. Klue, a Salesforce add-on used by many security-related companies, became part of a compromise affecting well-known organizations such as LastPass, Huntress, BeyondTrust, Tanium, Snyk, HackerOne, OneTrust, and Jamf. Oracle also issued a June 11 patch for PeopleSoft that was quickly exploited, with reported compromises involving the National Association of Insurance Commissioners and Nissan Americas, among others.
These examples should prompt business leaders to ask:
- Which vendors and integrations can access our customer data, support cases, sales records, financial information, or regulated data?
- Can access to sensitive data be limited?
- Who owns the review of vendor permissions and SaaS integrations?
- Are we monitoring these systems closely enough to detect suspicious activity?
The FortiBleed attack this month is another reminder that even large organizations can miss basic exposure risks. Thousands of enterprises were reportedly affected, including major names such as Comcast, Harley-Davidson, Medtronic, Samsung, Spotify, Oracle, Lenovo, and Huawei. The attack depended on exposed firewall administrative interfaces, which should not have been publicly accessible.
Critical patching windows are shrinking:
AI and automation are shortening the time businesses have to patch internet-facing systems, browsers, operating systems, and remote access tools. The recent PeopleSoft compromises are a good example, with exploitation following shortly after disclosure and patch release.
In the last month alone, critical vulnerabilities were reported across widely used systems, including Ubiquiti UniFi networking software, Google Chrome, Android devices, Apple devices, and Microsoft systems.
Timely, regular patching remains one of the most important security fundamentals, especially for internet-facing systems and tools with broad access.
Supply chain attacks continue to escalate:
Supply chain attacks remain one of the most impactful risks facing businesses. Last month, thousands of common packages and extensions across public online repositories were found to be compromised and attributed to North Korean attackers. Microsoft also removed 119 malicious browser extensions that hid malware in fonts and images.
In ancient times, soldiers might poison an enemy’s well by dropping an animal carcass into the water supply. Today, attackers are using a similar strategy by poisoning the shared software, tools, repositories, and extensions that modern businesses rely on.
The lesson for business leaders is clear; security is no longer limited to the systems you directly own. You also need visibility into the vendors, integrations, tools, code, and platforms your business depends on.
What do I need to do?
- Consumer Routers:
Develop basic work-from-home security guidance for staff. This should include:
-
- Replace out of support home routers.
- Disable remote administration unless explicitly needed.
- Use unique router administrator passwords.
- Keep router firmware updated.
- Consider business-managed network equipment for high-risk users, such as executives, finance staff, IT administrators, or users with access to sensitive data.
- AI Security:
Create a basic safe use of AI policy that covers more than chatbots. It should address:
-
- Approved and unapproved AI tools and what data classes can be used with each.
- Use of AI browsers, meeting bots, coding assistants, app builders, and automation tools.
- Review requirements for AI-generated code.
- Approval requirements before AI tools connect to repositories, cloud systems, customer data, or production systems.
- Data Breaches:
- Inform staff that recent breaches may increase the risk of fraud, impersonation, and targeted phishing. Employees should be cautious with inbound requests from financial institutions, healthcare organizations, vendors, or support providers.
- When validating a request, staff should use known phone numbers from official documentation or the institution’s website. They should not rely on phone numbers from emails, text messages, ads, or unfamiliar search results.
- Employees should also consider freezing their credit with the three major credit bureaus.
- Equifax Credit Freeze: https://www.equifax.com/personal/credit-report-services/credit-freeze/
- Experian Credit Freeze: https://www.experian.com/freeze/center.html
- TransUnion Credit Freeze: https://www.transunion.com/credit-freeze
- Employees should also consider freezing their credit with the three major credit bureaus.
- Critical Patching:
Microsoft/Apple/Google/Firefox: For clients using our security and management tools, supported computers should already be receiving updates. Users should complete patch installations when prompted and avoid delaying or deferring updates. Updates can be manually installed following the directions below:
-
-
- Apple: https://support.apple.com/en-us/108382
- Microsoft Windows: https://support.microsoft.com/en-us/windows/update-windows-3c5ae7fc-9fb6-9af1-1984-b5e0412c556a
- Google Chrome: https://support.google.com/chrome/answer/95414?hl=en&co=GENIE.Platform%3DDesktop
- Ubiquiti UniFi: https://help.ui.com/hc/en-us/articles/7605005245975-UniFi-Updates
-
- Supply Chain Attacks and Public Repositories:
Educate staff and technical teams about the risks of public repositories, open-source packages, browser extensions, and AI-generated code. Organizations should have a process to evaluate, record, and respond to future disclosures involving public code or shared software tools.
- Record the use of online source code, including the tool, package, code, and version used.
- Maintain a Software Bill of Materials, or SBOM, if your team develops software.
- Avoid newly released packages unless they have been reviewed.
- Regularly review code logs and SBOMs to determine whether affected software has been used.
- Do not share credentials, secrets, API keys, or sensitive data with AI tools unless the tool and its integrations have been reviewed.
QuickTip: Windows Sandbox is a free utility that’s built into Windows operating system. It’s a great tool to help you evaluate risky links and downloads! https://www.neowin.net/guides/guide-how-to-enable-windows-sandbox-in-windows-10-and-11/
Sources and Additional Reading:
- Consumer Routers:
- NetNut: https://thehackernews.com/2026/07/google-disrupts-netnut-residential.html?utm_source=chatgpt.com
- NetNut: https://www.bleepingcomputer.com/news/security/netnut-proxy-network-disrupted-2-million-infected-devices-cut-off/
- RustDuck: https://thehackernews.com/2026/06/rustduck-botnet-rebuilds-in-rust-to.html?utm_source=chatgpt.com
- AryStinger: https://thehackernews.com/2026/06/arystinger-malware-infects-4300-legacy.html?utm_source=chatgpt.com
- C0XMO botnet: https://www.bleepingcomputer.com/news/security/c0xmo-botnet-spreads-via-dd-wrt-router-flaw-kills-rival-malware/
- AI Security:
- AI Agents assisting in an attack: https://www.helpnetsecurity.com/2026/06/17/ai-agents-offensive-cyber-operations-claude-codex/
- AI Agents assisting in an attack: https://thehackernews.com/2026/07/ai-agent-exploits-langflow-rce-to.html
- AI Agents assisting in an attack: https://www.securityweek.com/agentic-ai-used-to-conduct-ransomware-attack-via-langflow/
- AI Browser Manipulated: https://www.securityweek.com/bioshocking-attack-tricks-ai-browsers-into-stealing-credentials/
- AI Browser Manipulated: https://thehackernews.com/2026/06/new-bioshocking-attack-tricks-ai.html
- AI Meeting Bot Risk: https://www.securityweek.com/microsoft-adds-new-teams-controls-to-block-unauthorized-ai-bots-from-meetings/
- Shadow AI Report: https://info.redaccess.io/hubfs/1627The%20Shadow%20Builders%20Inside%20Your%20Organization%20%E2%80%94%20Red%20Access%20Research%20(1).pdf
- Data Breach :
- Klue Breach: https://techcrunch.com/2026/06/22/klue-hack-results-in-data-breach-at-several-cybersecurity-firms/
- Klue Breach: https://www.securityweek.com/beyondtrust-lastpass-impacted-by-klue-salesforce-incident/
- Klue Breach: https://www.securityweek.com/more-klue-breach-victims-identified-as-hackers-get-hacked/
- Klue Breach: https://www.bleepingcomputer.com/news/security/lastpass-confirms-data-breach-in-klue-supply-chain-attack/
- PeopleSoft: https://www.securityweek.com/insurance-regulators-group-naic-hit-in-oracle-peoplesoft-hack/
- PeopleSoft: https://www.securityweek.com/nissan-employee-data-breached-in-oracle-peoplesoft-hack/
- PeopleSoft: https://thehackernews.com/2026/06/shinyhunters-exploits-oracle-peoplesoft.html
- FortiBleed: https://techcrunch.com/2026/06/17/cybercriminals-allegedly-hacked-tens-of-thousands-of-fortinet-firewalls-used-by-major-companies-all-over-the-world/?utm_source=chatgpt.com
- FortiBleed: https://doublepulsar.com/an-update-on-fortibleed-whats-happening-with-victim-orgs-c0671a50e7f4
- Critical Patching:
- Ubiquiti: https://www.bleepingcomputer.com/news/security/cisa-warns-of-max-severity-ubiquiti-flaws-exploited-in-attacks/amp/
- Ubiquiti: https://www.securityweek.com/critical-ubiquiti-vulnerabilities-in-attackers-crosshairs/
- SimpleHelp: https://www.securityweek.com/critical-simplehelp-vulnerability-exploited-for-malware-delivery/
- Apple: https://www.securityweek.com/apple-patches-dozens-of-vulnerabilities-across-ios-macos-and-safari/
- Apple: https://www.helpnetsecurity.com/2026/06/30/apple-airdrop-google-samsung-quick-share-vulnerabilities/
- Apple: https://www.securityweek.com/macos-weaknesses-chained-to-silently-disable-endpoint-security-agents/
- Apple: https://www.securityweek.com/new-exploit-bypasses-apples-boot-defenses-affects-millions-of-iphones/
- Google: https://www.securityweek.com/google-patches-382-chrome-vulnerabilities/
- FFmpeg: https://www.securityweek.com/ffmpeg-pixelsmash-flaw-allows-rce-on-video-players-media-servers-nas-appliances/
- Samsung: https://www.securityweek.com/eight-year-old-samsung-knox-flaw-exposed-millions-of-galaxy-devices-to-kernel-attacks/
- Supply Chain:
- NPM Packages: https://thehackernews.com/2026/06/hijacked-npm-and-go-packages-use-vs.html
- Arch Linux: https://www.securityweek.com/atomic-arch-supply-chain-attack-hits-1500-aur-packages/
- North Korean Attack: https://thehackernews.com/2026/07/north-korean-hackers-publish-108.html
- MS Edge: https://thehackernews.com/2026/06/microsoft-removes-119-edge-extensions.html
The volume of security news is becoming overwhelming, and not all of it is equally useful. My goal is to boil it down to the most actionable and relevant information so you can make timely decisions.













0 Comments