Between 2025 and 2026 cybersecurity moved on three fronts at once: state-backed espionage against network equipment, attacks on the software supply chain and, above all, artificial intelligence that finds flaws and automates intrusions faster than they can be patched.
What happened and when
FBI warns of Russian attacks on routers
The FBI warned that Russian hackers tied to the FSB were targeting thousands of networking devices in US critical sectors through an old Cisco flaw still unpatched on end-of-life equipment.
Cl0p exploits Oracle E-Business Suite
The Cl0p ransomware group exploited a critical Oracle EBS flaw, and Google warned of extortion emails to executives, though it could not confirm that data had been stolen.
F5 loses BIG-IP source code
F5 suffered an intrusion that exposed BIG-IP source code; a nation-state actor was suspected, raising the risk of new exploits against its customers.
SonicWall blames a nation-state
SonicWall confirmed that a state-sponsored group was behind the breach of its cloud backup systems, without naming the country.
AISURU hits a 29.7 Tbps record
A 29.7 Tbps DDoS attack was attributed to the AISURU botnet, reportedly made up of up to 4 million infected hosts.
AI model finds 100+ Firefox bugs
Mozilla reported that Claude Opus 4.6 found more than 100 bugs in two weeks of January, 14 of them high severity, against the 73 high or critical bugs Firefox patched the previous year.
Trivy compromise unleashes a worm
A supply chain attack compromised the Trivy scanner and spread a worm that infected 47 npm packages.
Law enforcement hits the botnets
The US Justice Department dismantled a botnet of about 3 million IoT devices, SocksEscort was disrupted (369,000 IPs in 163 countries) and INTERPOL took down 45,000 IPs with 94 arrests.
Mozilla fixes 271 flaws with Mythos Preview
Mozilla identified and fixed 271 vulnerabilities in Firefox 150 using Claude Mythos Preview, a leap over fuzzing and manual code review.
UK institute evaluates Mythos
The UK AI Security Institute found Mythos only marginally ahead of other models on single tasks, but the first to complete a simulated 32-step intrusion, in three of ten attempts.
Glasswing: many findings, few patches
In its first month Glasswing flagged more than 10,000 possible flaws; 1,726 were confirmed and only 97 had been patched.
ECB demands patching in days or hours
The European Central Bank asked banks to compress vulnerability management from weeks to days or even hours, given AI tools able to exploit flaws.
ShinyHunters breaches 100+ organizations
ShinyHunters exploited an Oracle PeopleSoft zero-day, with no patch available, to breach more than 100 organizations.
Five Eyes: offensive AI is months away
The Five Eyes agencies warned that models capable of serious cyber damage will be publicly available within months, not years.
First autonomous AI ransomware attack
Sysdig documented what it believes is the first ransomware attack carried out end to end by an AI agent, which got in through a Langflow flaw.
The threads that matter
AI as vulnerability hunter and intrusion tool
In 2026 artificial intelligence moved from promise to auditing tool with measurable results. According to Mozilla, in two weeks of January an Anthropic model found more than 100 bugs in Firefox, 14 of them high severity, in a year when the browser had patched 73 high or critical flaws. Months later, Firefox 150 shipped fixes for 271 vulnerabilities found with Mythos Preview, and a separate agent found 21 zero-day flaws in FFmpeg.
The flip side is the gap between discovering and fixing. In its first month, Project Glasswing flagged more than 10,000 possible critical flaws: 1,726 were confirmed and only 97 had been patched. The UK AI Security Institute tempered the story: on single tasks Mythos barely improves on other models, but it was the first to complete a simulated 32-step intrusion, though only in three of ten attempts. Google, meanwhile, confirmed the first case of an AI that discovered and weaponized a zero-day used in the wild.
Attackers are adopting AI too. CyberStrikeAI, an open-source platform, bundles more than a hundred offensive tools and was used against FortiGate firewalls; the Transparent Tribe group automates malware implant creation against targets in India; and agents built on large language models have been seen handling post-exploitation. A Chinese open-weight model, GLM-5.2, matches or beats an Anthropic model at finding flaws.
- AI Discovers Critical Firefox Security Vulnerabilities Rapidly
- Mozillas AI Discovers 271 Firefox Security Vulnerabilities
- IA Descubre 21 Vulnerabilidades Zero-Day en FFmpeg
- IA Descubre Miles de Vulnerabilidades Podemos Parchearlas
- UK Tests Reveal Mythos AI Cybersecurity Capabilities
- AI Finds 10000 Vulnerabilities China Copies US Worries
AI tooling as a new attack surface
Platforms for building and running AI agents became targets of real attacks. Flowise suffered an actively exploited remote code execution flaw rated 10.0 on the CVSS scale, with more than 12,000 instances exposed on the internet. Langflow, with roughly 7,000 exposed instances, and two other popular frameworks accumulated serious vulnerabilities that let attackers run code and steal credentials.
According to the analysis, these are not exotic threats but classic flaws, such as SQL injection, path traversal and unsafe deserialization, inside infrastructure that security teams have not yet learned to monitor. Ollama (out-of-bounds read), OpenClaw (prompt injection and data exfiltration) and PraisonAI, attacked within hours of its flaw being disclosed, add to the list. Model and agent-skill repositories already host hundreds of malicious entries, and tool registries can be poisoned because agents choose tools by description, with no human verification.
The most telling episode came in July: Sysdig documented what it believes is the first fully autonomous ransomware attack, run by an AI agent that got in by exploiting a Langflow flaw and corrected a failed login in just 31 seconds.
- Flowise AI Bajo Ataque Vulnerabilidad Critica CVSS 100
- 7000 AI Frameworks Under Attack Critical Vulnerabilities Exposed
- Vulnerabilidad Critica en Ollama Expone Memoria Remota
- Fallas en OpenClaw Inyeccion y Exfiltracion de Datos
- Brecha de PraisonAI Ataque Inmediato tras Revelacion
- AI Repositories Under Siege by Malware Attacks
State espionage and edge devices
Network and security appliances were the favorite way in. The FBI warned in August 2025 that Russian hackers linked to the FSB were targeting thousands of networking devices in US critical infrastructure through a Cisco flaw seven years old. Soon after, F5 had BIG-IP source code exposed to a suspected nation-state actor, and SonicWall confirmed a state-backed group was behind its breach. In 2026, Interlock exploited a zero-day in Cisco Secure Firewall Management Center from late January, before the March 4 patch, and another Cisco SD-WAN zero-day gave attackers root access.
Chinese cyber-espionage was constant. UNC5221 used the BRICKSTORM backdoor against the US legal and technology sectors; Mandiant tied it to Beijing's interest in its trade dispute; Palo Alto Networks described a Chinese group that had sat in foreign ministry mail servers for years; and UAT-9244 hit South American telecom operators with three distinct tools. On the Russian side, the FBI and CISA warned of a phishing campaign aimed at Signal recovery keys, and APT28 exploited an MSHTML zero-day before the February patch.
- FBI Warns Russian Hackers Targeting US Critical Infrastructure - Cisco Vulnerability Exploited
- F5 Breach Codigo BIG-IP Expuesto Grave Intrusion
- SonicWall Hackers Estatales Detras de la Brecha de Septiembre
- Cisco FMC Zero-Day Ransomware Interlock Ataca Criticamente
- Vulnerabilidad Zero-Day en Cisco SD-WAN Permite Acceso Root
- UNC5221 Nuevo Backdoor BRICKSTORM Ataca EEUU
Supply chain, identity and trust
The supply chain was the attack path that drew the most attention. The compromise of Trivy, a widely used vulnerability scanner, began on March 19 according to one source and triggered a worm that infected 47 npm packages; in April it emerged that the TeamPCP group, via Trivy, stole 92 GB from the European Commission's cloud infrastructure. Another attack, GlassWorm, abused 72 Open VSX extensions to reach developers' environments.
Identity is the other weak link. The Vercel breach started with an employee who granted broad permissions, from a corporate account, to a third-party AI tool, and the attacker took advantage of environment variables not marked as sensitive. A phishing technique based on OAuth consent bypasses even multi-factor authentication. Trellix, a security company, confirmed access to its source code repositories, and fake Laravel packages and Bitcoin-themed packages repeated the pattern in package registries.
- Trivy Scanner Breach Unleashes Self-Spreading Malware Worm
- Hack de Trivy Propaga Malware via Docker
- Hackers Atacan UE Herramienta Seguridad Compromete Datos
- Ataque GlassWorm Desarrolladores en Peligro
- Vercel Breach Uncovered OAuth Gap Threatens Security Teams
- Phishing con OAuth El Nuevo Peligro Digital Desvelado
Extortion, botnets and the police response
Ransomware sped up and changed method. Cl0p exploited Oracle E-Business Suite and, according to Google, several executives received extortion emails claiming to come from that group, though there was no proof to confirm it. In June, ShinyHunters breached more than 100 organizations with an unpatched Oracle PeopleSoft zero-day. ReliaQuest counted 2,638 victim postings in the first quarter of 2026, up 22% year on year, with The Gentlemen growing 588%.
Botnet scale set records, and the response was just as international. AISURU, with up to 4 million infected hosts, was linked to a 29.7 Tbps DDoS attack; in March the US Justice Department dismantled a network of about 3 million IoT devices behind 31.4 Tbps attacks. Another operation disrupted SocksEscort, with about 369,000 IP addresses in 163 countries, and INTERPOL took down 45,000 IP addresses with 94 arrests. The alleged head of Black Basta joined the EU's most wanted list.
- Cl0p Ataca Oracle EBS CVE-2025-61882 Explotada
- Hackers Extorsionan a Ejecutivos con Datos de Oracle
- ShinyHunters Exploits Oracle Zero-Day Breaching 100 Organisations
- Ransomware Evoluciona Filtraciones Falsas y Sin Encriptacion
- Ataque DDoS Record Botnet AISURU 297 Tbps
- DoJ Desmantela Botnet IoT de 3 Millones
Why it matters and what to watch
Patch in hours, not weeks
The ECB now expects banks to cut remediation times from weeks to days or hours, and Five Eyes places offensive AI months away: the window between disclosure and exploitation is shrinking.
Inventory the AI you already run
Agent frameworks are deployed exposed to the internet with default settings; treat them as critical infrastructure and monitor them accordingly.
Security vendors are targets too
F5, SonicWall, Trellix and Trivy show that whoever sells defense concentrates a risk inherited by its whole customer base.
Regulation is tightening
Spain was preparing to transpose NIS2, which reaches mid-sized companies previously unregulated, while the ECB turns cyber resilience into a supervisory expectation.
What we think
Our takeaway is an uncomfortable one: almost nothing that happened is new in essence. Unpatched equipment, excessive permissions and tools deployed in a hurry are still the way in; what changes is how quickly someone, or something, finds them. We would rather see organizations do the dull work first: an honest inventory, fast patching and fewer privileges. Boasting about defensive AI before fixing those basics is like buying a smoke detector for a house with no fire exit. And we should be wary of miracle narratives, triumphalist or apocalyptic alike, because independent evaluations paint a more measured picture than the headlines do.
Everything we published on this topic
121 stories from Aug 2025 to Jul 2026, by month. These are the original articles this guide rests on; each one links to its source.












































































































