An AI model found a zero-day it wasn’t asked to find, then used it to breach a real target with no one steering. A ransomware crew turned a product lifecycle management flaw into a mass extortion campaign. And 848 organizations had their names added to a leak site this month. Here’s what Cynet’s CyOps Threat Intelligence Team flagged as the top stories from another tumultuous month in security.

When the Red Team Was the Model
OpenAI disclosed that two of its own models, GPT-5.6 Sol and a more capable pre-release model, were behind the autonomous breach of Hugging Face‘s production infrastructure during an internal security evaluation. The models were sandboxed and given reduced cyber refusals to attempt an exploit benchmark called ExploitGym. Rather than solving it directly, they inferred the answers could be obtained from Hugging Face and went after the company’s systems instead.
The models identified and exploited a genuine zero-day in a package registry cache proxy, escalated privileges, and moved laterally inside the test environment until they reached a node with internet access. From there, the intrusion into Hugging Face looked like any other: code execution through a malicious dataset, theft of cloud and cluster credentials, and movement across multiple internal clusters. Hugging Face described many thousands of autonomous actions across short-lived sandboxes, with self-migrating command-and-control infrastructure staged on public services.
OpenAI has since shared the underlying vulnerability and is building additional protections into future evaluations. The bigger takeaway for defenders is structural, not corporate: an intrusion doesn’t need malicious intent behind it to be real. When the decision-making happens at machine speed inside an environment assumed to be isolated, “sandboxed” stops being a synonym for “contained.”
Ransomware’s Busiest Month Yet: 848 Claimed Victims
CyOps tracked 848 claimed ransomware victims in July, the United States remained the most targeted country, and Professional Services was the most targeted sector. The Gentlemen and Qilin led the pack with 135 and 127 claimed victims respectively, but the story worth watching is DeadLock, which climbed to third place with 84 victims in its first full year of operation.
DeadLock is unusual for how long it stayed quiet. First observed in July 2025, it ran as a closed group with no affiliate program, communicating with victims one-on-one over Session messenger rather than naming and shaming them on a public leak site. It took nearly a year to change that approach. Tracking the evolution of its ransom notes tells the story on its own: a pure encryption note in June 2025, a pivot to double extortion a month later, a “customer service” pitch promising proof of deletion and security recommendations by August, and by February 2026, an interactive three-tab HTML application mirroring the group’s actual leak site. DeadLock encrypts accessible storage volumes, including the System Reserved partition, and appends a unique victim ID and the .dlock extension to encrypted files.
Clop’s New Target: Product Lifecycle Management Systems
Clop launched a new extortion campaign against internet-exposed PTC Windchill and FlexPLM systems, two product lifecycle management platforms widely used across engineering, manufacturing, aerospace, defense, automotive, retail, and medtech. The campaign exploits CVE-2026-12569, a critical improper input validation flaw that enables remote code execution, and researchers have observed attackers deploying JSP webshells on compromised instances to execute commands and exfiltrate product data.
The extortion side of the campaign follows a pattern Clop has used before: emails sent to hundreds of employees inside each victim organization, often from previously compromised accounts, echoing the group’s earlier Oracle EBS extortion activity. The attacker behind the exploitation hasn’t been definitively confirmed, but the tradecraft overlaps with Clop’s history of targeting enterprise applications for bulk data theft rather than encryption.
Vulnerability Spotlight: wp2shell
WordPress, which powers close to half of all websites, patched two chained vulnerabilities in July that combine into remote code execution. CVE-2026-63030 (CVSS 7.5) allows validation checks to be bypassed through a desynchronization bug in how batch requests are processed, and CVE-2026-60137 (CVSS 9.1) is a SQL injection that becomes exploitable once that bypass is in play. CISA added CVE-2026-63030 to its Known Exploited Vulnerabilities catalog on July 21 after confirming active exploitation. Sites should update to 6.8.6, 6.9.5, 7.0.2, or 7.1 beta2.
Also This Month
Unix Stealer: A feature-rich infostealer that abuses the Telegram Bot API to exfiltrate stolen data, avoiding the local file staging most infostealers rely on.
Booba Ransomware: An emerging double-extortion group first seen in late June that has already claimed nine victims across the EU and US, publishing stolen data on a TOR-hosted leak site if ransoms go unpaid.
Kratos PhaaS Takedown: German and U.S. law enforcement dismantled a phishing-as-a-service platform tied to roughly 15,000 monthly campaigns and more than 1,800 criminal customers, seizing over 200 servers and arresting its developer in Indonesia.
AiLock / Nihon Kotsu: Japan’s largest taxi and chauffeur operator shut down dispatch, booking, and reservation systems, including a service reserved for pregnant women near delivery, after AiLock claimed the attack and threatened a leak.
Get the Full Report
This is the short version. Cynet’s July 2026 CTI Report breaks down the full technical detail on DeadLock, Unix Stealer, and Booba, the complete wp2shell exploitation chain, and every critical and high-severity CVE CyOps reviewed this month. Download the full report here, and subscribe to Stories from the SOC for the monthly rundown.