Future TechnologyFuture Technology
← Back to archive
Security Digest

[Security Digest] The AI ran the ransomware. A human still asked.

10 July 2026

An AI agent broke into a MySQL server, encrypted more than 1,300 records, and left a Bitcoin ransom note without a human touching a keyboard during the attack itself. Meanwhile, Accenture is calling the theft of 35GB of its own source code an "isolated matter." One of those stories is about where security is heading. The other is about a company that still hasn't learned to talk about a breach honestly.

The Big 3

Accenture confirms breach, 35GB of source code stolen

Accenture has confirmed an intrusion after a hacker put roughly 35GB of stolen data up for sale, including source code, RSA and SSH keys, Azure personal access tokens, and Azure Storage access keys. The company says it's "aware of this isolated matter" and has "remediated its source," but it hasn't said what data actually left the building. That vagueness matters more than usual here: Accenture builds and manages IT systems for governments and Fortune 500 companies worldwide, so stolen credentials from its own environment are a supply-chain risk for everyone downstream, not just Accenture.

What to do: If your organisation uses Accenture-managed infrastructure or shares Azure credentials with them, ask your account team directly what was exposed. Don't wait for a press release that may never come.

Read more →

SimpleHelp RMM zero-day (CVSS 10.0) hits MSP supply chain

A maximum-severity vulnerability in SimpleHelp's remote monitoring and management software, CVE-2026-48558, is being actively exploited to deploy a loader called TaskWeaver. CISA added it to the Known Exploited Vulnerabilities catalog with a 4 July deadline for federal agencies, but plenty of managed service providers and their clients are still exposed. RMM tools sit at the centre of an MSP's access to every network it manages, so one unpatched SimpleHelp instance can become a launchpad into dozens of businesses at once.

What to do: If your business outsources IT to an MSP, ask them directly whether they run SimpleHelp and whether it's patched. If you run it yourself, patch today, don't wait for a maintenance window.

Read more →

The first AI-run ransomware attack still needed a human

Researchers at Sysdig documented what they're calling the first fully agentic ransomware attack, nicknamed JadePuffer. An AI agent exploited a known bug in Langflow, worked its way into a production MySQL server, encrypted more than 1,300 configuration records, and left behind a Bitcoin address demanding payment, largely without a human directing each step. The catch: a person still had to point the agent at the target and set the objective. This isn't autonomous machines declaring war on your database, it's a familiar attack chain that got faster and cheaper to run.

Why this matters: The skill barrier for running a competent ransomware operation just dropped. Security teams should assume attackers with far less expertise can now pull off attacks that used to require a specialist.

Read more →


Quick Hits

KDDI's breach hit 14.22 million people, and it's not even all KDDI's fault
Japanese telecom giant KDDI disclosed a breach of its email system that exposed email addresses and passwords for up to 14.22 million customers, spanning its own users and those of five other Japanese internet providers who relied on KDDI's infrastructure. If you use a Japanese ISP, it's worth checking whether yours was one of the five.
Read more → (3 minute read)

Ransomware gangs are exploiting a Windows Defender flaw called BlueHammer
CVE-2026-33825, a privilege-escalation bug in Microsoft Defender, is being actively used by ransomware operators to jump from limited access to full control of a machine. Windows Update patches it automatically, but only if automatic updates are actually switched on. Worth checking rather than assuming.
Read more → (2 minute read)

PTC Windchill users: attackers are dropping webshells right now
CVE-2026-12569 is an unauthenticated remote code execution flaw in PTC Windchill PDMLink and FlexPLM, meaning attackers don't need a password to use it. Confirmed exploitation includes JSP webshells planted on compromised servers. If you run Windchill, this is a patch-today situation.
Read more → (2 minute read)

CISA and the UK's NCSC put a name to the "covert networks" warning
A joint advisory from CISA, the NCSC, and international partners details how Chinese government-linked actors are using large networks of compromised routers and IoT devices to mask intrusions into critical infrastructure. Most readers can't do much about this directly, but it's a good reminder to change the default password on anything with a web login screen facing your router.
Read more → (4 minute read)


Tool of the Week

YubiKey 5 series

A physical security key that plugs into USB-C or taps via NFC to prove it's really you logging in. No code to type, nothing for an attacker to intercept over SMS.

Who it's for: If you've ever had a "verify it's you" text arrive at a moment you weren't trying to log in, this is for you, especially if you manage admin accounts, a business email address, or crypto.

Caveat: Buy two. Lose your only key without a backup method set up and you can lock yourself out of your own accounts.


Protect Yourself

Given BlueHammer is being actively exploited through Windows Defender right now: go to Settings, then Windows Update, then Advanced options, and confirm "Receive updates for other Microsoft products" is switched on. That's the setting that patches Defender itself, separately from regular OS updates. Takes thirty seconds and closes the exact gap ransomware crews are using this week.


Forward this to someone who cares about staying secure. They'll thank you.

Free weekly security briefing: futuretechnologyhq.com/newsletter

Some links in this newsletter may be affiliate links. We only recommend products we genuinely think are worth your time.