
Loading summary
A
From the CISO series, it's Cybersecurity Headlines
B
these are the cybersecurity headlines for Friday, July 24, 2026. I'm Steve Prentiss. AI agents become fastest growing exposed attack surface A new AI Security 2026 report from Sophos warns that the rapid adoption of enterprise AI tools has created a major new cybersec security risk. AI Identities as organizations give AI agents coding assistants and large language models privileged access to business systems, attackers are increasingly targeting their credentials, their oauth tokens and access permissions. Poor AI governance and weak identity controls leave enterprises vulnerable to data theft, ransomware and even the manipulation of AI agents to carry out malicious actions. Sophos recommends treating AI agents like human users by enforcing least privilege access, requiring verification for expanded permissions, and monitoring AI identities for suspicious activity and unauthorized data exfiltration. Consumer finance company Upbound Group blames data breach for millions in losses the company, which offers Lease to Own and flexible payment solutions through brands like Rent A Center, stated in a filing with the SEC that non sensitive customer information and other documents were recently obtained by hackers. This stolen information was subsequently used to facilitate fraudulent lease to own agreements, contributing to elevated fraudulent contract losses of approximately $13 million during the second quarter of 2026. However, no known cybercrime group appears to have listed the company on its leak website as of yet. Dolphin X stealer uses AI profiling to prioritize targets According to researchers at Varonis Threat Labs, a newly discovered Windows info stealer and remote access trojan named Dolphin X is using an AI powered profiling system to help cybercriminals identify their most valuable victims. The researchers describe its standout feature as an AI profiler that automatically ranks infected users based on factors such as application usage, browsing activity and installed software assigning scores to these victims, which allows attackers to quickly identify those most likely to provide valuable access or data. This is then packaged as a daily summary to help cybercriminals boost their productivity. Origin Energy suffers cyberattack the Australian power utility says that its customers, addresses, phone numbers and partial bank account data were accessed in a hack. The company has nearly 5 million customer accounts in Australia and provides electricity, LPG, liquid petroleum gas and Internet services to homes and businesses. Representatives have yet to confirm how many customers have been affected, saying they will inform each customer once stolen data has been confirmed as stolen. According to the Guardian, a person claiming to be the hacker has reportedly contacted media outlets with unverified claims that 2 million customers details were accessed, end quote. Huge thanks to our sponsor, Quiller AI AI agents don't ask permission, they act. Moving data, triggering workflows, changing systems. Qwiller AI is the permission layer that they never had. Its decision engine evaluates the content, context and intent of every action before it completes alerts. Tell you later. Quiller AI decides now. Visit Quillerai that is Q U I L R AI Stay safe. Quiller IT. Extortion group claims responsibility for Japanese food logistics cyber attack following up on a story we covered last week, Japan's largest refrigerated logistics company, Nisherei Logistics Group, is restoring operations after a cyberattack that disrupted food deliveries nationwide. The cybercrime group Ransom House has come forward and is threatening to leak the data it stole. The group placed Nishere's name on its Dark Web leak site and urged the company to make contact. In a note addressed to Dear Management of nisheret, the note expressed frustration at the company's refusal to cooperate. Swiss train maker Stadler Rail refuses to pay ransom following an attack that happened just recently. In mid July, the company stated under no circumstances will Stadler pay a ransom and therefore cannot be extorted. The Everest ransomware group claimed responsibility and in an extortion letter demanded 10 million Swiss francs, approximately US$12.3 million. Stadler said it has filed a criminal complaint and will not negotiate with the hackers. The company added the breach did not affect its own systems and all production sites remain fully operational. The stolen information consisted of technical documents belonging to a third party supplier and were obtained after credentials for the data exchange platform were compromised. Kratos Phishing as a service kit taken down by law enforcement German authorities say they have neutralized the main infrastructure supporting the Kratos Fishing as a service kit following an operation supported by the US And Indonesia. Kratos, spelled K R A T O S, has been described as one of the most widespread and dangerous fishing as a service kits on the market. Indonesian authorities said they arrested the Kratos kit's alleged developer and technical administrator. Kratos allowed low skill cybercriminals to harvest credentials including passwords and session cookies to bypass MFA by providing them with convincing Microsoft themed phishing pages. Nuclear Sabotage Malware benchmark trips up most Frontier AI models SentinelOne has created what it describes as the first long horizon benchmark for evaluating AI assisted malware reverse engineering using its investigation Investigation of the Fast 16 malware as a real world test Fast 16, a 2005 Windows malware believed to have targeted Iran's nuclear program, served as a complex challenge requiring AI models to revise conclusions as new evidence emerged. Among the models tested, GPT 5.6 SOL was the only one to successfully complete all eight investigation stages. However, researchers emphasize that even the strongest AI made significant technical mistakes, concluding that experienced human reverse engineers remain essential to validate findings, correct errors, and oversee final analysis. If you have some thoughts on the news from today or about this show in general, please be sure to reach out to us@feedbackisoseries.com we would love to hear from you. I'm Steve Prentiss, reporting for the CISO series.
A
Cybersecurity headlines are available every weekday. Head to CISoseries.com for the full stories behind the headlines.
Host: Steve Prentiss, CISO Series
Episode Theme:
A roundup of the latest information security incidents and threats, with a spotlight on the growing risks posed by AI systems, high-profile data breaches, cyber extortion, and law enforcement actions.
[00:07] Sophos’s 2026 report warns that accelerated enterprise adoption of AI tools—especially coding assistants and large language models (LLMs)—has created a major new cybersecurity risk.
“Attackers are increasingly targeting their [AI agents’] credentials, their OAuth tokens, and access permissions.” – Steve Prentiss [00:16]
[01:02] Upbound Group (parent of Rent-A-Center) reported to the SEC that hackers accessed and stole non-sensitive customer info and other documents.
“This stolen information was subsequently used to facilitate fraudulent lease to own agreements…” – Steve Prentiss [01:10]
[01:48] Varonis Threat Labs identified a new info stealer/remote access trojan: Dolphin X.
“An AI profiler that automatically ranks infected users… assigning scores to these victims…” – Steve Prentiss [02:03]
[02:42] Australian utility giant Origin Energy suffered a breach exposing addresses, phone numbers, and partial bank info.
“A person claiming to be the hacker has reportedly contacted media outlets with unverified claims that 2 million customers’ details were accessed.” – Steve Prentiss [03:13]
[04:47] Swiss train manufacturer Stadler Rail rebuffed a $12.3 million ransom demand from the Everest ransomware group after third-party technical documents were stolen.
“Under no circumstances will Stadler pay a ransom and therefore cannot be extorted.” – Steve Prentiss [04:59]
[06:16] SentinelOne created a “long horizon” benchmark for AI malware analysis, using the complex Fast 16 worm (linked to Iranian nuclear sabotage).
“Even the strongest AI made significant technical mistakes, concluding that experienced human reverse engineers remain essential…” – Steve Prentiss [07:08]
AI Security Urgency:
“Poor AI governance and weak identity controls leave enterprises vulnerable to data theft, ransomware, and even the manipulation of AI agents to carry out malicious actions.” – Steve Prentiss [00:29]
AI vs. Human Analysis:
"Even the strongest AI made significant technical mistakes... experienced human reverse engineers remain essential to validate findings, correct errors, and oversee final analysis." – Steve Prentiss [07:08]
Corporate Stand Against Extortion:
“Under no circumstances will Stadler pay a ransom and therefore cannot be extorted.” – Steve Prentiss [04:59]
This episode captures current cyber threats with a spotlight on the evolving risks of AI technology within enterprise environments. The incidents underline persistent issues: data breaches yielding real-world fraud, ransomware groups growing bolder yet facing increasing corporate resistance, and law enforcement making strides in cybercrime disruption. The discussion balances emerging AI-powered attacks and technical innovation with a consistent message: human expertise and oversight remain pivotal in cybersecurity.