ARTICLE
9 July 2026

Ankura CTIX FLASH Update – July 7, 2026

AC
Ankura Consulting Group LLC

Contributor

Ankura Consulting Group, LLC is an independent global expert services and advisory firm that delivers services and end-to-end solutions to help clients at critical inflection points related to conflict, crisis, performance, risk, strategy, and transformation. Ankura has more than 2,000 professionals serving 3,000+ clients across 55 countries. Collaborative lateral thinking, hard-earned experience, and multidisciplinary capabilities drive results and Ankura is unrivalled in its ability to assist clients to Protect, Create, and Recover ValueTM. For more information, please visit, ankura.com.
Recent cybersecurity research reveals how threat actors are exploiting AI coding assistants, open-source ecosystems, and malware-as-a-service platforms to launch sophisticated attacks on developers and enterprise systems. Meanwhile, Hong Kong's IPO market surges to reclaim its global leadership position, and institutional investors navigate complex technical due diligence for data center conversions as tariff-related class actions reshape retail litigation strategies.
United States Media, Telecoms, IT, Entertainment
Ankura Consulting Group LLC’s articles from Ankura Consulting Group LLC are most popular:
  • in European Union
  • in European Union
  • in European Union

Malware Activity

Emerging Threats Highlight Risks Across Malware-as-a-Service and AI Ecosystems

Recent research highlights how cybercriminals are continuing to expand their capabilities through both traditional malware and emerging AI-driven attack techniques. Researchers identified QuimaRAT, a new cross-platform Remote Access Trojan (RAT) being sold as a Malware-as-a-Service (MaaS) offering, enabling threat actors to easily deploy advanced malware across Windows, Linux, and macOS environments without developing their own tools. The malware uses encrypted plugins, stealth capabilities, and multiple delivery mechanisms to maintain long-term access to compromised systems. At the same time, researchers uncovered SkillCloak, a novel technique that allows malicious AI agent extensions to evade security scanners by disguising harmful code and restoring it only during execution. Testing showed that these hidden payloads were able to bypass detection in the majority of cases, raising concerns about the growing software supply chain risks associated with AI coding assistants and third-party extensions. Together, these findings demonstrate how attackers are leveraging both accessible malware platforms and emerging AI technologies to increase the effectiveness, scalability, and stealth of modern cyberattacks, emphasizing the need for stronger detection, monitoring, and defense strategies. CTIX analysts will continue to report on the latest malware strains and attack methodologies.

Threat Actor Activity

Threat Actors are Using Fully Agentic JadePuffer Ransomware in Attacks

Sysdig reports what appears to be the first fully “agentic” ransomware operation, dubbed JadePuffer, conducted end-to-end by a large language model (LLM) agent rather than a human operator. The attacker exploited CVE-2025-3248, a critical unauthenticated RCE in Langflow, an open-source framework for building LLM apps, to gain code execution on an internet-exposed instance. Once in, the LLM-driven agent autonomously dumped Langflow’s Postgres database, harvested API keys, cloud credentials, wallets, and config files, scanned internal networks, probed MinIO, and set up persistence via a cron job. It then pivoted to a production MySQL server running Alibaba Nacos, abusing root credentials and multiple vectors, including CVE-2021-29441 and forged JWTs, to gain admin control. The agent encrypted 1,342 Nacos configuration items using MySQL’s AES_ENCRYPT(), dropped original tables, and created an extortion table with a ransom note, Bitcoin address, and Proton Mail contact. Payloads contained natural-language commentary and showed the LLM adapting in real time—fixing failed logins in seconds, adjusting to XML vs JSON responses, and narrating its logic. Notably, the randomly generated encryption key was never stored or sent, making recovery impossible, and the Bitcoin address appears lifted from public documentation, which was another signal of LLM behavior. This agentic operated JadePuffer demonstrates that capable models have the ability to be substitute for skilled humans, dramatically lowering the barrier to serious attacks against poorly secured, internet-facing infrastructure, while also creating new detection opportunities in LLM-generated code.

Vulnerabilities

CISA Confirms Active Exploitation of Microsoft SharePoint RCE, Urges Immediate Patching

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that threat actors are actively exploiting a high-severity remote code execution (RCE) vulnerability affecting on-premises Microsoft SharePoint Server. The flaw, tracked as CVE-2026-45659, is caused by insecure deserialization of untrusted data, allowing authenticated attackers with only Site Member permissions to remotely execute arbitrary code on vulnerable SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Enterprise Server 2016 deployments without requiring administrator privileges or user interaction. Although Microsoft released patches in May 2026 after the vulnerability was inadvertently omitted from its original May security updates and initially assessed exploitation as “Less Likely,” attackers rapidly weaponized the flaw, prompting CISA to add it to its Known Exploited Vulnerabilities (KEV) Catalog. In response, the agency ordered U.S. federal civilian agencies to remediate affected systems or discontinue use if mitigations are unavailable. While CISA has not attributed the attacks or disclosed their scale, more than 10,000 internet-exposed SharePoint servers remain visible online, underscoring the significant attack surface. The incident highlights the speed at which threat actors can reverse engineer newly released patches, reinforces SharePoint’s continued role as a common target for ransomware and other intrusion campaigns, and emphasizes the critical importance of rapidly patching internet-facing systems to reduce the risk of compromise. CTIX analysts strongly urge any affected administrators to patch and follow the CISA guidance to prevent compromise.

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

[View Source]

Mondaq uses cookies on this website. By using our website you agree to our use of cookies as set out in our Privacy Policy.

Learn More