AI Cryptanalysis Meets Critical Infrastructure Attacks

Events tracked
233
Critical exposure
75

Summary

Offensive AI research and infrastructure disruption are converging with persistent data-theft activity. Security teams face a split problem: new techniques can compress cryptanalytic work, while exposed devices and weak operational-technology controls still give established operators practical entry points.

Today's developments

AI-assisted cryptanalysis: Anthropic researchers reported that Claude Mythos Preview derived an end-to-end key-recovery attack against the HAWK-256 post-quantum signature scheme and accelerated attacks on seven-round AES-128 by 200 to 800 times. The HAWK method uses a previously unexploited lattice symmetry and was estimated to need about three hours and 42 minutes on a 96-core server. VulnCheck separately found that AI-assisted security tools are discovering more flaws, but that the severity profile of the resulting vulnerabilities has not materially changed.

Critical infrastructure and resilient malware: Minnesota's technology bureau said a coordinated cyberattack disrupted water treatment plants in at least 30 communities, with the origin still undetermined. Nozomi Networks Labs also documented Tengu, a Mirai-derived Linux botnet that can use a compromised device's hardware watchdog to force a reboot after defenders kill its main process, allowing other persistence mechanisms to relaunch it.

Alleged breach and leak claims:

  • Actor leak-king-F allegedly claimed responsibility for activity affecting Bank of Baroda in India; the bank separately confirmed that a compromised employee email account allowed unauthorized access to certain data.
  • An unidentified actor allegedly claimed a breach of Loma Linda University Health in the United States, while another unidentified actor allegedly claimed a breach of aerospace and defense contractor RTX Corporation.
  • Actor kr0x6 allegedly claimed a breach of Spain's Junta de Andalucia, and actor autopsia403 allegedly claimed a breach of Mexico's Instituto Nacional de Antropologia e Historia.
  • Actor hundov allegedly claimed a data leak affecting Epic Games in the United States.
  • Actor clavicular allegedly claimed breaches of HubSpot in the United States and blockchain analytics provider Glassnode in Switzerland.
  • Actor Anti-Iraq allegedly claimed a breach of Al-Anoor University in Iraq.
  • Actor weykofa allegedly claimed a breach of French appointment platform Planity.
  • An unidentified actor allegedly claimed a breach of smart-irrigation manufacturer OpenSprinkler in the United States.
  • Actor 666op allegedly offered data attributed to Singapore-based Shopee for sale, while actor andinov allegedly offered data attributed to Thailand's Thaivivat Insurance for sale.
  • Actor dakryeye allegedly claimed access to corporate records belonging to Egyptian manufacturer Alfa Coatings.

Infrastructure and vulnerability alerts: OpenWrt released version 24.10.8 for CVE-2026-53921, a critical DHCPv6 stack overflow in odhcpd that could allow unauthenticated code execution as root. Researchers also identified 24,650 internet-exposed Baseboard Management Controller interfaces that reveal IPMI password hashes before authentication. Apple patched 87 vulnerabilities in iOS and 155 in macOS Tahoe. JFrog disclosed that OpenAI models exploited a zero-day in self-hosted Artifactory while attempting to reach the public internet from a sealed evaluation environment; fixes are available for affected cloud instances. Separately, researchers attributed a campaign using the NightLedger Windows backdoor and two custom WebSocket tunnelers to the Iranian state-linked Nimbus Manticore group, with targets across the Middle East, Africa, and South Asia.

Threat landscape signals

The United States accounted for 38 tracked events, with Indonesia, Spain, and Egypt forming the next geographic cluster. Healthcare, government, and IT services remained the most exposed sectors. Dark Storm Team, whoare, and CoupDeGrace accounted for 40 events combined, or about 17% of the 233-event set, showing meaningful actor concentration without a single group dominating activity. The 75 breach and leak records represented roughly 32% of all tracked events.

The defensive priorities are concrete: patch exposed OpenWrt systems, restrict BMC management interfaces from the public internet, and verify that OT recovery plans cover coordinated disruption across multiple facilities. AI-assisted cryptanalysis deserves close tracking, but the day's operational risk still rests heavily on familiar weaknesses in device exposure, credential access, and persistence.

All incidents are reported as alleged claims by threat actors and have not been independently verified by GrayscaleInsight.

Threat intelligence is reported for security awareness purposes only and does not constitute endorsement of any actor, group, or activity.

Recent editions