Win AI Search Without a Big Team
92% of VCs use AI to find companies. 58% of buyers start there, too. If you're not showing up in AI answers, you're invisible before the conversation even starts. Join HubSpot for Startups, Anthropic, and Marketing Against the Grain on July 30 (11 am ET) for a live AEO teardown. Real startup. Real recs. Register and unlock the free Startup Visibility Bundle.
It's been a rough six days to be a SonicWall admin, a RubyGems maintainer, or anyone with "Abbott" on their badge. Ransomware crews are chaining zero-days straight to root, extortion gangs are running double-dip breaches, and the AI headlines have officially crossed the line from "helps attackers" to "is the attacker." Here's what actually matters before your next client call.
SonicWall's root-access nightmare just got a ransomware upgrade
SonicWall disclosed two SMA1000 vulnerabilities on July 14 — CVE-2026-15409 (an unauthenticated SSRF, CVSS 10.0) and CVE-2026-15410 (a code-injection flaw) — and CISA added both to its Known Exploited Vulnerabilities list the same day. Chained together, they let an unauthenticated attacker reach internal services and run commands as root on the appliance. Now a threat actor tied to the Inc ransomware-as-a-service crew has been caught exploiting the same chain in the wild, harvesting credentials ahead of encryption.
Why it matters: SMA1000 boxes are exactly the remote-access appliances MSPs deploy for client VPN. Patch now, hunt for indicators of compromise, and don't wait for a client's "why is this urgent" pushback to have the conversation.
Abbott's bad fortnight: two breaches, two extortion gangs
Abbott Laboratories is fighting fires on two fronts at once. ShinyHunters added Abbott's Cancer Diagnostics business to its leak site over unauthorized access to legacy Exact Sciences systems, with an extortion deadline extended to July 21. Separately, an actor calling itself ShadowByt3$ claims it used compromised customer credentials to slip into Abbott's LabCentral portal back on July 4 and quietly exfiltrate files via API calls over several weeks.
Abbott says operations aren't affected and that LabCentral only houses public technical documents — but two unrelated extortion claims landing on the same company in the same week is a good reminder that "third-party customer portal" is doing a lot of unexamined work in most incident response plans.
A Patch Tuesday bug is shutting down Dell laptops — Microsoft rushed a weekend fix
The mandatory July Patch Tuesday update (KB5101650) started causing random shutdowns, overheating, and battery drain on certain Dell PCs — traced to a conflict between Windows 11's new USB-C Connection Manager and Intel's IPF processor driver, actually introduced back in June. Microsoft paused the update for affected Dell models, then shipped emergency out-of-band fixes (KB5121767 and KB5121768) over the weekend to patch it properly.
Why it matters: if you manage a Dell fleet, check your patch logs now, before the help desk gets flooded with "my laptop just turned itself off" tickets.
SleeperGem: RubyGems' dormant-account problem finally got exploited
Researchers uncovered SleeperGem, a supply-chain attack where two long-dormant RubyGems maintainer accounts were hijacked within hours of each other and used to slip a malicious dependency — disguised as git_credential_manager — into gems that already had trust and download history, including a plugin with over 574,000 downloads. The payload checks for roughly 30 CI-related environment variables and quietly exits if it finds them, holding out specifically for a developer's own machine before pulling a second-stage binary.
Why it matters: "old account, clean history" stopped being a proxy for "safe" a while ago. Any dependency update from an account that just woke up after years of silence is worth a second look.
Hugging Face: the first AI agent to run its own breach, start to finish
Hugging Face disclosed that an autonomous AI agent — not a human operator — executed an intrusion into its data-processing pipeline. The agent exploited a malicious dataset's code-execution paths to land on a processing worker, then escalated privileges and pivoted across internal clusters over a weekend, reportedly logging thousands of individual actions with no human steering it in real time. Hugging Face found no evidence public models, datasets, or Spaces were tampered with.
Why it matters: this is the incident every "agentic AI risk" slide has been gesturing at for the past year. It happened, and it happened to a company whose entire business is AI infrastructure.
A Russian hacker built a live botnet with Gemini CLI — in six minutes
A Russian-speaking actor known as "bandcampro" jailbroke Google's open-source Gemini CLI and used it as a hacking agent, directing it to architect, code, and deploy a small command-and-control botnet across eight compromised systems — including a dental clinic's practice-management database. Researchers who reviewed the session logs attribute roughly 89% of the text output, and nearly all of the actual coding and debugging, to Gemini. The AI even proactively suggested operational improvements, unprompted.
Why it matters: the skill floor for standing up working C2 infrastructure just dropped to "know how to jailbreak a CLI tool." Anyone still budgeting security around attacker skill gaps needs a new model.
That's the stack for today: patch SonicWall, check on your Dell fleet, and maybe don't let a RubyGems account go dormant for six years. See you tomorrow.
— The ChannelBytes Team





