The Lyceum: Cyber Intelligence Daily — Jul 31, 2026
Photo: lyceumnews.com
Friday, July 31, 2026
The Big Picture
The common failure running through Friday’s intelligence is misplaced trust: AI agents trusted a broken sandbox, developers trusted poisoned packages, employees trusted fake help-desk calls, and water utilities trusted internet-facing controls. None of this requires science-fiction defenses—just harder boundaries around operational technology, software dependencies, remote support and AI testing.
What Just Dropped
- CVE-2026-63077 — JetBrains TeamCity On-Premises: patched; no NVD score yet; an unauthenticated attacker can abuse the agent-polling protocol to execute code on the server.
- CVE-2026-18452 — Rich Source DMS+ Non-Mobile 5.63 and earlier: patched in 5.64; no NVD score yet; a fixed API key lets an unauthenticated remote attacker control vulnerable installations.
- CVE-2026-14919 — ShopMonitor.io for WordPress before 1.2.0: patched; no NVD score yet; attackers can redirect administrator password-reset emails and take over the site.
Today's Stories
Claude’s Security Test Reached the Real Internet
The nightmare is not that an artificial-intelligence model became evil. It is that everyone told the model it was inside a simulation—and nobody verified that the door to the real internet was locked.
Anthropic reviewed 141,006 cybersecurity-evaluation runs and identified three incidents in which Claude models reached production systems through a misconfigured third-party testing environment. One model accessed several hundred rows of production data. Another created a malicious Python package and uploaded it to the real Python Package Index, where it remained available for roughly an hour and ran on 15 systems.
Anthropic says the models were following instructions to retrieve fictional “flags,” not deliberately attempting to escape containment. The company halted the evaluations, sent notifications and is discussing an independent review with the Model Evaluation and Threat Research organization, or METR.
If laboratories respond by placing agentic security tests behind independently verified network isolation, the incidents become an expensive but useful warning. If similar cases emerge from historical evaluation logs, live-internet leakage is a systemic laboratory-control problem. The signal to watch is whether other AI developers audit old runs rather than merely tightening future prompts. (Claude’s Security Test Accidentally Hacked Three Real Organizations)
Amazon Connects Major npm Compromises to North Korea
A developer can review every line their team writes and still inherit malware through a trusted library several dependencies away. Amazon Threat Intelligence now says the compromises of debug, chalk, axios and typo-crypto belonged to one financially motivated North Korean operation.
Amazon attributes the activity with medium confidence to Sapphire Sleet, also tracked as BlueNoroff and Stardust Chollima. According to Amazon, the assessment rests on shared command infrastructure, code reuse and social engineering directed at software maintainers. Amazon also says roughly one in ten cloud environments it observed encountered the poisoned debug and chalk releases within two hours.
The new finding turns several package compromises into a sustained campaign against the humans who publish open-source software. Teams that retained lockfiles, package caches and build logs can reconstruct exposure; teams that kept only current dependency inventories may have erased their best evidence.
If Amazon or the Open Source Security Foundation publishes broader indicators, historical build records could become breach artifacts. Without that follow-through, many organizations will know the packages were poisoned but remain unable to determine whether their own software consumed them.
A Fake Teams Support Call Can Become Ransomware by Dinner
If someone claiming to be IT support unexpectedly calls through Microsoft Teams, hanging up is not rude. It is incident prevention. (A Two-Minute Teams Call Can Become Ransomware by Dinner)
Sophos documented a campaign it calls STAC4749 in which attackers used external Teams accounts, IT-themed domains and fake support identities to persuade employees to launch Microsoft Quick Assist or install remote-management software. The attackers then deployed a backdoor, established disguised persistence and installed AnyDesk or DWAgent as backup access.
Sophos observed the operation against dozens of organizations between February and June, with nearly 95% of cases in Canada and the United States. At least three intrusions ended in Chaos ransomware; one moved from the initial conversation to encryption in under 17 hours. Sophos says it found no connection to the Iranian group MuddyWater, despite earlier reporting about separate Chaos activity.
Organizations that restrict external Teams contact, block unauthorized support tools and require independent verification can break the attack before malware arrives. Failure looks like the same script migrating to Zoom, Slack or ordinary phone calls. That migration would confirm that Microsoft Teams was merely the costume, not the weapon. (A Two-Minute Teams Call Can Become Ransomware by Dinner)
Minnesota’s Water Attacks Turn an OT Warning Into an Operating Problem
The City of Braham temporarily lost computerized control of its well and treatment plant during cyber activity reported on July 26 and 27. The City of Plymouth lost communications with parts of its water infrastructure but continued operating manually. Drinking water remained safe, according to reporting by The Associated Press. (apnews.com)
The fresh development is the federal and state response. The Cybersecurity and Infrastructure Security Agency issued a July 30 warning about increased targeting of programmable logic controllers—the small industrial computers that operate pumps, valves and treatment equipment. Minnesota IT Services said related malicious activity touched more than 30 community water systems. (apnews.com)
The Federal Bureau of Investigation has not attributed the incidents. The timing resembles previously documented activity by Iranian-affiliated actors against internet-accessible controllers, but resemblance is not attribution: Iran remains an investigative lead, not a confirmed perpetrator.
Utilities that remove controllers from direct internet access, replace default credentials and rehearse manual operation can turn this into a contained disruption. If the FBI attributes the incidents to one operator, the attack becomes evidence that opportunistic controller access has evolved into coordinated physical disruption.
⚡ What Most People Missed
- Codex Security reaches the command line: OpenAI released a Codex Security CLI and TypeScript SDK for local scans and continuous-integration workflows. OpenAI says the software builds threat models, attempts to reproduce suspected vulnerabilities in a sandbox and proposes patches; independent evidence of its precision remains limited.
- Sourcetree becomes a developer-workstation risk: CYFIRMA’s July 31 report flags CVE-2026-21575 in Atlassian Sourcetree for Windows, saying crafted content can lead to code execution when opened by a developer. The target matters: developer laptops often hold repository access, signing keys and production credentials.
- Three urgent alerts are still urgent—but not fresh: The Fortinet action dates to July 17, the latest Langflow emergency reporting to July 22, and Microsoft Office CVE-2026-21509 to January 26. They remain patch priorities, but no confirmed exploitation or incident delta placed them inside this edition’s 24-hour window.
From the Foreign Press
Dysphoria Has Reportedly Infected More Than 200,000 Devices
Russian security publication Xakep reports that the Dysphoria distributed-denial-of-service botnet has infected more than 200,000 devices worldwide. That scale would make Dysphoria useful for sustained disruption rather than short-lived nuisance attacks, although Xakep’s figure has not received independent English-language confirmation. Defenders should watch for infrastructure indicators or sinkhole measurements that validate the reported population. Source: Xakep — Russian. No English-language coverage confirmed at time of publication.
Apple Faces a $1.8 Million Claim Over Fake Crypto Wallets
Xakep reports that Apple is facing a $1.8 million lawsuit connected to fraudulent cryptocurrency-wallet applications distributed through the App Store. The larger question is whether attackers can repeatedly exploit application-review trust to impersonate financial software—the mobile equivalent of poisoning a familiar package repository. Court filings or an Apple response would establish whether the case exposes a repeatable review failure or a narrower fraud dispute. Source: Xakep — Russian. No English-language coverage confirmed at time of publication.
📅 What to Watch
- If other AI laboratories uncover real-world access in archived evaluations, containment audits will become as important as model-safety testing itself.
- If Sapphire Sleet indicators appear in historical lockfiles beyond Amazon’s observed environments, software bills of materials will become forensic records rather than compliance paperwork.
- If STAC4749 shifts to Zoom or Slack without changing its script, collaboration-platform controls alone will prove insufficient against help-desk impersonation.
- If the Federal Bureau of Investigation attributes Minnesota’s incidents to one Iranian-affiliated operator, exposed water controllers will have crossed from opportunistic targets into a coordinated disruption campaign.
- If Dysphoria’s reported device count is independently validated, defenders should expect its access to be rented or shared rather than reserved for one operator.
The Closer
A chatbot picked a lock outside its pretend prison, a poisoned package rode through the build system wearing a maintainer badge, and fake IT support arrived through Teams with ransomware in the glovebox.
Meanwhile, a WordPress plugin discovered that password-reset email is apparently just mail forwarding with catastrophic consequences.
Keep the controllers offline.
Forward this to whoever still answers unsolicited calls from “IT.”
⚡ EDGE Signals
The following signals appeared in the adversarial edge sweep but were not carried forward in the primary synthesis:
- [3] TLP:CLEAR
Co-Authored by:
Product ID: AA26-097A
URL: https://media.defense.gov/2026/Apr/07/2003907538/-1/-1/0/AA26-097A-IRANIAN-AFFILIATED-CYBER-ACTORS-EXPLOIT-PROGRAMMABLE-LOGIC-CONTROLLERS-ACROSS-US-CRITICAL-INFRASTRUCTURE_508C.PDF