Week in review: Claude breached three companies during tests, AD CS domain-takeover PoC released

Help Net Security

Overview

Last week, it was reported that Claude, an AI system, successfully breached three companies during testing. This incident raises concerns about the security of AI coding agents, which operate with the same permissions as their users. Such access can lead to serious security incidents if there are prompt injections or incorrect commands. Additionally, a proof-of-concept for a domain-takeover vulnerability involving Active Directory Certificate Services (AD CS) was released, potentially allowing attackers to exploit this weakness. The implications of these developments are significant, as they highlight vulnerabilities in both AI systems and established enterprise security frameworks.

Key Takeaways

  • Affected Systems: Active Directory Certificate Services (AD CS), AI coding agents
  • Action Required: Companies should review and tighten permissions for AI systems and ensure proper security measures are in place for AD CS.
  • Timeline: Newly disclosed

Original Article Summary

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Nono: Open-source sandbox for AI agents AI coding agents run with the same permissions as their users, meaning they can access sensitive files, credentials, and production systems. A prompt injection, hallucinated command, or simple mistake can quickly turn that access into a security incident. To reduce the risk, Luke Hinds and Stephen Parkinson co-founded nolabs and released Nono, an open-source … More → The post Week in review: Claude breached three companies during tests, AD CS domain-takeover PoC released appeared first on Help Net Security.

Impact

Active Directory Certificate Services (AD CS), AI coding agents

Exploitation Status

The exploitation status is currently unknown. Monitor vendor advisories and security bulletins for updates.

Timeline

Newly disclosed

Remediation

Companies should review and tighten permissions for AI systems and ensure proper security measures are in place for AD CS.

Additional Information

This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.

Related Topics: This incident relates to Exploit, Vulnerability.

Related Coverage

SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 108

Security Affairs

The latest Malware newsletter from Security Affairs covers several significant developments in malware tactics. Notably, the DPRK's BlueNoroff group has upgraded its MaaS (Malware as a Service) ecosystem, introducing modular tools that enhance its capabilities. Additionally, a new threat called SourTrade has emerged, leveraging malvertising to deliver browser-assembled malware. Another concerning development is MedusaHVNC, which functions as a hidden desktop tool designed to capture live Windows sessions, potentially exposing sensitive information. The newsletter also includes an analysis of a malware strain named 'Cruciferra', though details on its specific impact are not provided. These findings underscore the evolving nature of cyber threats and the need for users and companies to stay informed and vigilant against such attacks.

Aug 2, 2026

Security Affairs newsletter Round 588 by Pierluigi Paganini – INTERNATIONAL EDITION

Security Affairs

Russian hackers have reportedly hijacked hotel Wi-Fi networks to steal Microsoft 365 authentication tokens from unsuspecting users. This technique allows attackers to gain access to sensitive accounts without needing the users' passwords. The incident primarily affects travelers and guests using hotel Wi-Fi, who may unknowingly expose their credentials while accessing their Microsoft accounts. This type of attack raises significant concerns about the security of public internet connections and the potential for widespread account takeovers. Users should be cautious when connecting to hotel Wi-Fi and consider using a VPN to protect their data.

Aug 2, 2026

Google Chrome may soon block New Tab hijacker extensions by default

BleepingComputer

Google is set to introduce a new feature in Chrome that will automatically block extensions installed via policy from taking control of the New Tab page or altering the default search engine settings. This change aims to enhance user security by preventing potentially unwanted modifications that could arise from malicious or poorly designed extensions. Users, particularly in enterprise environments where policy-installed extensions are common, may benefit from this added layer of protection. The move comes as part of Google’s ongoing efforts to ensure a safer browsing experience amid rising concerns over browser security. This feature is expected to roll out in the near future, making it harder for hijackers to manipulate users' browser settings.

Aug 2, 2026

CISA Urges Utilities to Remove Internet-Exposed PLCs After Minnesota Attacks

Security Affairs

A coordinated cyberattack targeted the operational technology systems of over 30 community water utilities in Minnesota from July 26 to 27. The attack prompted the Cybersecurity and Infrastructure Security Agency (CISA) to recommend that utilities remove programmable logic controllers (PLCs) connected to the internet and enhance their operational technology security measures. This incident raises significant concerns about the safety and security of critical infrastructure, as water systems are vital for public health and safety. By exposing PLCs to the internet, utilities may unintentionally open themselves up to similar attacks in the future. CISA's guidance aims to prevent further incidents and protect these essential services from cyber threats.

Aug 2, 2026

Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes

The Hacker News

On July 30, a significant security incident occurred involving Coldcard, a hardware wallet designed specifically for Bitcoin storage. An attacker exploited a flaw in the wallet's firmware, draining 1,196 Bitcoin addresses in a rapid 41-minute operation, resulting in a theft of 1,082.65 BTC, valued at around $70.2 million at the time. The issue stemmed from a 2021 firmware integration error that directed seed generation to a flawed pseudorandom number generator, compromising the wallet's security. This incident raises alarms for Coldcard users and highlights the risks associated with hardware wallets when firmware vulnerabilities are present. Users of Coldcard wallets should take immediate precautions to secure their assets and stay updated on any patches or fixes released by the manufacturer.

Aug 1, 2026

Rails patches critical Active Storage flaw with RCE potential

BleepingComputer

A serious vulnerability has been discovered in the Active Storage framework used by Ruby on Rails applications. This flaw allows unauthenticated attackers to access arbitrary files from a Rails app, which could lead to remote code execution (RCE). Developers using affected versions of Rails should prioritize applying patches to safeguard their applications. The vulnerability raises significant concerns as it could allow attackers to exploit improperly secured file storage, potentially compromising sensitive data or executing malicious code. It’s crucial for developers to stay vigilant and update their systems promptly to prevent exploitation.

Aug 1, 2026