Data pipelines highlighting critical vulnerabilities from AI to network exploits.

Daily Cybersecurity News - July 3, 2026

Critical Cursor AI Code Editor Flaws Could Lead to OS Level Remote Code Execution

Cursor AI code editor has sandbox escape flaws that let attackers run code on the host OS with no user clicks.

The DuneSlide issues allow zero-click prompt injection that breaks out of the editor sandbox and executes arbitrary commands on the underlying system.

The flaws affect Cursor Desktop versions before 3.0. Cursor 3.0 includes the fixes.

Attacks chain malicious prompts directly into OS-level execution without additional user interaction.

Source: SecurityWeek

New CitrixBleed Vulnerability Exploited Immediately

NetScaler admins face fresh memory disclosure attacks right after disclosure.

The flaw, CVE-2026-8451, lets unauthenticated attackers leak memory from vulnerable NetScaler appliances configured as SAML identity providers. Public technical details triggered live exploitation within 24 hours.

Affects Citrix NetScaler ADC and Gateway appliances still running vulnerable firmware versions worldwide.

Attackers began scanning for targets the same day the PoC dropped.

Source: SecurityWeek

Fake Google and Cloudflare Pages Spread Malware

Attackers are pushing fake Google and Cloudflare verification pages to trick users into running malicious PowerShell commands.

The ClickFix technique drops different infostealers plus a newly discovered loader that fetches additional payloads. Victims land on these pages through malvertising and compromised sites.

The approach reuses the same social engineering trick seen in prior campaigns but now bundles multiple malware families behind one lure.

Active since at least May 2026 with dozens of distinct loader samples already observed in the wild.

Source: Malwarebytes

Armored Likho Digs Snake Pit In BusySnake Campaign

Armored Likho is running a fresh campaign with BusySnake Stealer, hitting targets in Russia, Kazakhstan, and Brazil.

They send spear-phishing emails with AI-generated loaders that drop the new Python-based BusySnake tool for credential theft. The group focuses on organizations in those three countries.

The Python stealer itself is the novel piece. Most of their prior work relied on older commodity malware families with less custom code.

The campaign remains active with confirmed victims across all three target countries.

Source: Securelist

FortiBleed Actors Monetizing Fortinet Access

A financially motivated crew behind the FortiBleed campaign has turned thousands of compromised Fortinet firewalls into entry points for ransomware operations.

SOCRadar says the campaign targeted more than 430,000 FortiGate devices, installed sniffers on a smaller subset, and linked the harvested access to INC Ransom and Lynx ransomware activity. The same operators are also exploiting a suspected Nextcloud zero-day to expand footholds.

This marks the first direct link between mass FortiGate credential theft and actual ransomware deployments. One operator tied to FortiBleed infrastructure was logged into both ransomware negotiation panels.

SOCRadar traced 354 completed FortiGate intrusion chains and at least 12 ransomware deployments from the campaign.

Source: Dark Reading

Parliament Member Hacked With Pegasus During Spyware Probe

A former European Parliament member investigating commercial spyware was himself targeted with Pegasus.

Citizen Lab found his phone compromised repeatedly with the NSO Group tool while he sat on the committee examining spyware abuse. The attacks occurred during his official inquiry work.

Pegasus use against oversight figures is familiar, yet the timing here ties directly to active parliamentary scrutiny of the same technology.

Compromises spanned multiple months and coincided with key committee hearings on surveillance vendor practices.

Agentic AI Used in Ransomware Attack

Sysdig says a threat actor exploited Langflow and used an LLM agent to conduct an automated ransomware attack.

The agent chained reconnaissance, credential theft, lateral movement, and encryption using real time reasoning. The attack reached a production server and encrypted 1,342 Nacos service configuration items.

The demonstration relied on known techniques and a publicly available workflow tool. It shows automation potential rather than novel exploits.

This was reported as a real intrusion against exposed infrastructure, not a controlled lab test.

Source: SecurityWeek