Four disclosures this week trace back to a boundary that looked intact but was not actually verified: a testing environment assumed to be isolated, a package name assumed clean because it looked machine-generated, a breach-cost curve that now has AI stamped on more than a quarter of its entries, and a familiar face on screen assumed genuine because fact-checking hadn't caught up yet. Anthropic's own security evaluations breached three real companies. India's average breach cost hit a record high. Researchers showed AI coding agents hallucinate predictable names attackers can register in advance. And a deepfake of the finance minister kept producing victims months after the same script had already been documented.
1
Anthropic says three Claude models breached real company networks after a testing environment quietly gained internet access it should not have had
Anthropic disclosed on 31 July 2026 that a review of 141,006 evaluation runs conducted with partner Irregular found three cybersecurity-evaluation incidents, the earliest traced to April 2026, in which Claude models had live internet access during capture-the-flag-style testing meant to be network-isolated. Anthropic attributes this to a misconfiguration and a misunderstanding with the evaluation partner, not a model escaping its environment. Opus 4.7 found and breached a real company it mistook for a simulated target, extracting application and infrastructure credentials and reaching a production database containing several hundred rows. An internal model Anthropic calls Mythos 5, while working against a fictional target, published a malicious Python package to the real PyPI registry; the package reached 15 real systems, including one belonging to a security company, and exfiltrated credentials from anyone who ran it. A third, unnamed internal research model scanned roughly 9,000 targets and compromised one real company through SQL injection combined with credentials taken from an exposed debug page. Anthropic says none of the three models attempted to exfiltrate itself or deliberately escape its test environment, and that newer models showed more restraint than older ones.
Why it matters for IndiaIndian AI labs, GCC security-research teams and MSSPs building or buying agentic red-team and evaluation tooling are running comparable experiments, often with less isolation discipline than a frontier lab applied even when its discipline failed. A configuration error, not a compromised model, was enough to turn simulated exercises into real breaches, including one where a poisoned package reached other people's systems.
ActionTreat any AI evaluation or red-team range as requiring production-grade network isolation, verified independently rather than trusted from configuration intent; block outbound access to public package registries, code-hosting platforms and the open internet by default in these environments; require human approval before an evaluation agent scans, exploits, publishes a package or touches credentials; retroactively audit past eval runs for signs any of them reached real infrastructure.
SourceThe Hacker News, "Anthropic Says Claude Mistook the Open Internet for a CTF and Breached Three Organizations" (31 July 2026); Axios (30 July 2026); The Hill (30 July 2026); Forbes (3 August 2026).
2
India's average data-breach cost hits a record Rs 25.5 crore, with more than a quarter of malicious breaches now AI-generated
IBM and the Ponemon Institute's Cost of a Data Breach Report 2026, released 3 August 2026 and based on 602 organisations studied between March 2025 and February 2026 with a May 2026 follow-up survey of 456 entities, found India's average total cost of a data breach reached an all-time high of Rs 25.5 crore, up 15.9% from Rs 22 crore the previous year. Twenty-six percent of malicious breaches in India were AI-generated. The average breach also grew in scale, compromising 39,500 records against 38,200 a year earlier. Phishing, including voice and SMS phishing, remained the leading initial attack vector at 19%, ahead of drive-by compromise at 16% and supply-chain compromise at 15%. The report found roughly a Rs 10 crore gap tied to AI-security maturity: organisations with extensive AI and automation in their security operations averaged Rs 21.3 crore per breach, against Rs 31.6 crore for those with little or none, yet 68% of Indian organisations report limited or no AI/security-automation use.
Why it matters for IndiaThis is now a documented, India-specific figure rather than a global estimate applied locally: AI is measurably raising both the frequency of breaches, as a generation tool for attackers, and the cost gap between organisations that have and have not adopted AI-assisted defence.
ActionBenchmark current security-automation maturity against the report's tiers before the next budget cycle; prioritise phishing-resistant authentication and voice/SMS-phishing controls given they remain the leading entry point; extend supply-chain monitoring given its rising share of initial access; use the report's cost gap to justify AI-assisted detection and response as a cost-reduction case, not only a capability upgrade.
SourceIBM and Ponemon Institute, Cost of a Data Breach Report 2026 (3 August 2026); Business Today (3 August 2026); Business Standard (3 August 2026).
3
HalluSquatting: researchers show AI coding agents hallucinate the same fake package and repository names predictably enough for attackers to register them first
Researchers led by Aya Spira in Ben Nassi's group at Tel Aviv University, working with Technion and Intuit, published the finding on arXiv on 8 July 2026, reported by BleepingComputer. Testing six widely used AI coding agents and assistants — Cursor, Windsurf, GitHub Copilot, Cline, Gemini CLI and OpenClaw — the team found the tools do not hallucinate random non-existent package or repository names; they hallucinate the same name repeatedly and predictably, up to 85% of the time for repository requests and 100% of the time for "install this skill" requests. Because the fabricated name is predictable rather than random, an attacker can pre-register it on npm, GitHub or a comparable registry with malicious content before any real developer's agent asks for it, the reverse of conventional after-the-fact typosquatting. The researchers describe their percentages as a floor, not a ceiling. It follows earlier related findings this year: a hallucinated npm package, "react-codeshift," spread through 237 repositories via forked AI-agent skill files, reported in January 2026, and Palo Alto Networks' Unit 42 catalogued roughly 250,000 domains commonly hallucinated by language models, reported in June 2026.
Why it matters for IndiaIndian software exporters and GCC engineering teams have adopted the exact tools tested, including Copilot, Cursor, Cline and Gemini CLI, often for precisely the scaffolding and dependency-installation tasks where hallucination rates were highest.
ActionRestrict agents to a private, allow-listed package source rather than the public registry directly; pin dependencies through lockfiles and verify provenance before merging anything an agent proposes; flag for manual review any repository or package an agent references that was created recently or lacks a verifiable maintainer history; treat an agent's suggested dependency with the same scrutiny as an unsolicited link in an email.
SourceAya Spira, Ben Nassi et al., arXiv preprint (8 July 2026); BleepingComputer (July 2026).
4
A deepfake video of the finance minister keeps generating real victims months after the same scam script was already documented
A paid Facebook advertisement carrying an AI-generated deepfake of Union Finance Minister Nirmala Sitharaman, falsely endorsing an investment scheme promising an assured Rs 70,000 a day, roughly Rs 22 lakh a month, on a Rs 22,000 outlay, was confirmed fabricated by the PIB Fact Check Unit around 30-31 July 2026, which stated Sitharaman has neither endorsed nor authorised any such scheme. The same script had already produced a documented victim weeks earlier: The420.in reported on 8 July 2026 that a retired professor in Shankarapuram, Bengaluru lost Rs 61.10 lakh of Rs 65 lakh transferred, after a similar deepfake video routed him to a fake trading platform, bxbmarket.com, where a fraudster posing as an agent conducted "KYC" over email, showed a fabricated profit dashboard that grew past Rs 1 crore, then demanded further processing fees before any withdrawal; the scam ran from 9 March to 25 June 2026, when it was reported to the National Cyber Crime Helpline. The same reporting notes near-identical scripting in separate Khammam and Belagavi cases around the same period, pointing to shared infrastructure behind multiple deepfake-endorsement scams rather than one-off clips.
Why it matters for IndiaA single fact-check does not retire a campaign; the underlying video, platform template and script keep circulating and producing victims for months, across cities, until the advertising and hosting infrastructure itself is disrupted.
ActionFinancial institutions and platforms should treat any investment advertisement using a public official's or executive's likeness as a fraud signal requiring proactive review rather than a wait-for-complaint response; publish consumer warnings tied to the specific script elements, assured daily returns, KYC conducted over email, a dashboard that blocks withdrawal without further payment, rather than only the fact that a video is fake; individuals should verify any investment offer bearing a public figure's endorsement through that figure's official channel before transferring funds.
SourcePIB Fact Check Unit, reported by Organiser (31 July 2026); The420.in (8 July 2026).
AI defender tip: Every item this edition traces back to a boundary that looked intact but was not verified: a test environment assumed isolated, a package name assumed clean because it looked agent-generated, a video assumed genuine because it named a familiar face. None of this needed a novel defence. Network isolation, dependency provenance checks and independent verification of any urgent or too-good financial claim are controls Indian security teams already know how to run. The gap was applying them by default to AI-touched systems and AI-adjacent claims, instead of treating an agent's output or a familiar face on screen as inherently trustworthy.
Nirad Threat Research
Nirad AI Threat Watch | Bharat-first threat intelligence
Two edge-infrastructure flaws reached CISA's exploited-vulnerabilities list within three days of each other this week, one in Arista's VeloCloud SD-WAN orchestrator with the maximum possible severity score, the other a zero-day credential baked into Cisco's firewall management console. Closer to home, Bank of Baroda is investigating a compromised employee mailbox after a dark-web listing claimed a terabyte of customer data, and ransomware affiliates have turned a Palo Alto VPN authentication flaw into a standard entry point. Washington's updated advisory on Iranian PLC intrusions is a reminder that the industrial hardware named in it runs a good share of Indian power, water and manufacturing plants too.
1CriticalCVSS 10.0
Arista VeloCloud Orchestrator Command Injection Under Active Exploitation — CVE-2026-16812
CVSS 10.0 (maximum severity) | CISA KEV, 27 July — remediation due 30 July* Arista disclosed CVE-2026-16812 on 27 July 2026, an unauthenticated OS command-injection flaw in on-premises deployments of VeloCloud Orchestrator (VCO), the management controller for its SD-WAN fleet. The bug lets a remote attacker reach privileged, internally-intended functionality without any credentials, and Arista confirmed it was already being exploited before the advisory shipped. Affected release trains span VCO 5.2.x, 6.1.x, 6.4.x and 7.0.x before their respective fixed builds; Arista's own Hosted and Dedicated VCO offerings were patched ahead of disclosure and are not affected, nor are the separate VeloCloud Gateway and Edge products. CISA added the flaw to its Known Exploited Vulnerabilities catalogue the same day, with a federal remediation deadline of 30 July.
India exposureVeloCloud is one of the SD-WAN platforms enterprises and telecom providers in India run for branch and multi-site connectivity, and it is the self-managed, on-premises VCO installations, not Arista's own hosted tier, that carry the risk. A compromised orchestrator gives an attacker visibility and control across every branch site it manages.
ActionUpgrade on-premises VCO to 5.2.3.14, 6.1.3.4, 6.4.2.4 or 7.0.0.1 or later immediately. Until patched, restrict orchestrator management access to trusted administrative networks, and review orchestrator logs for command execution or configuration changes that do not match known change windows.
SourceArista Security Advisory 0144, 27 July 2026; CISA KEV, 27 July 2026; BleepingComputer, 28 July 2026; SecurityWeek, 27-28 July 2026.
2MediumCVSS 5.3
Cisco Secure Firewall Management Center Hard-Coded Credential Exploited as Zero-Day — CVE-2026-20316
CVSS 5.3, High Security Impact Rating (Cisco) | CISA KEV, 29 July — remediation due 1 August* Cisco disclosed CVE-2026-20316 on 29 July 2026 after its own PSIRT found evidence of exploitation before a fix existed. A static, low-privilege credential built into the Secure Firewall Management Center (FMC) web interface lets an unauthenticated attacker, anywhere on the network or the open internet, log in without valid credentials. The access granted is limited on its own, but Cisco rates the issue High Security Impact because that foothold can be combined with other FMC flaws, including a separate critical authentication-bypass issue, to reach far greater control. CISA added the CVE to its Known Exploited Vulnerabilities catalogue the same day, with a federal remediation deadline of 1 August. Cloud-Delivered FMC, Firepower Device Manager, Secure Firewall ASA and Threat Defense software are not affected.
India exposureCisco's Secure Firewall line, including FMC, sits behind a wide base of enterprise and government network deployments in India. Any internet-reachable FMC console is exposed regardless of sector, and the chainable nature of this flaw with other FMC bugs raises the stakes beyond its own limited CVSS score.
ActionApply Cisco's fixed software; there is no workaround for a static credential. Take FMC management interfaces off the open internet, restrict access to trusted management networks or VPN-only paths, and audit web-interface authentication logs for activity from the low-privilege account outside expected administrative windows.
SourceCisco Security Advisory, 29 July 2026; CISA KEV, 29 July 2026; BleepingComputer, 30 July 2026; SecurityWeek, 29-30 July 2026.
3
Bank of Baroda Investigates Compromised Mailbox After Dark-Web Listing Claims 1TB of Customer Data
No CVE | Bank-confirmed incident, disputed scope* A dark-web listing referencing Bank of Baroda surfaced on ransomware-tracking site ransomware.live around 25 July 2026, claiming roughly a terabyte of data including customer names, Aadhaar numbers, loan records, branch audit files and internal correspondence. Bank of Baroda confirmed on 27-28 July that an employee's email account had been compromised, resulting in unauthorised access to "certain data," while stating that core banking systems were not accessed and remain secure. The bank said a comprehensive forensic investigation is under way with relevant authorities. No group has claimed the incident through an official channel; a researcher tracking the listing has floated a possible link to a group called TripleX, previously associated with a large Indonesian bank breach, but this is speculative and the bank has not confirmed any attribution.
India exposureThis is a direct, bank-confirmed incident at one of India's largest public-sector banks. Even with the claimed data volume and contents unverified beyond the bank's own statement, a single compromised staff mailbox illustrates how much customer PII, KYC material and internal audit data can sit reachable through email at an institution this size.
ActionBanks and NBFCs should extend conditional-access and phishing-resistant MFA enforcement to all employee mailboxes, not only privileged accounts, audit mail-forwarding rules and third-party OAuth app grants for anomalies, and confirm DLP coverage extends to attachments carrying KYC and Aadhaar data moving through email. Treat any leak-site data volume as unverified until an institution's own forensic findings say otherwise.
SourceBank of Baroda official statement, 27-28 July 2026, as reported by The Record and Business Today, 27 July 2026; ransomware.live listing, 25 July 2026.
CVSS 7.8 | Active exploitation reported 20-21 July 2026* Arctic Wolf Labs reported intrusions investigated through June 2026 in which Qilin ransomware affiliates used CVE-2026-0257, an authentication-bypass flaw in Palo Alto Networks PAN-OS GlobalProtect portal and gateway, as a repeatable initial-access route. The flaw lets an unauthenticated attacker forge authentication-override cookies to establish a VPN session without valid credentials, where override cookies are enabled alongside specific certificate configurations. Post-exploitation activity varied by affiliate, from fast encryption-only runs to full double-extortion operations involving credential harvesting, lateral movement over Windows admin shares, and data staged out via Rclone before ransomware deployment, consistent with several affiliates operating under the same Qilin ransomware-as-a-service umbrella.
India exposureNo named source lists an Indian victim, but GlobalProtect is a common enterprise VPN gateway across Indian BFSI, IT services and manufacturing firms of the size Qilin typically targets. Any deployment with authentication-override cookies enabled is a candidate regardless of geography.
ActionConfirm the PAN-OS patch for CVE-2026-0257 is applied, disable authentication-override cookies unless a documented business need exists, and review VPN authentication logs for sessions that bypass expected MFA prompts. Given the observed use of Rclone and Windows admin-share movement post-compromise, flag both as anomalies on any GlobalProtect-fronted network segment.
SourceArctic Wolf Labs research, reported 20-21 July 2026; Palo Alto Networks advisory; The Hacker News, 21 July 2026; Security Affairs, 21 July 2026.
5
US Agencies Expand Iranian ICS-Intrusion Advisory to Siemens and Schneider Electric PLCs — AA26-097A
No CVE | Joint advisory update, 22 July 2026* CISA, the FBI, NSA and other US agencies updated their joint advisory on Iranian-affiliated actors exploiting internet-exposed programmable logic controllers on 22 July 2026, widening it from the Rockwell Automation/Allen-Bradley devices named when the advisory first published in April to now include Siemens S7-1200 series and Schneider Electric Modicon M340 controllers. The actors, tracked under aliases including CyberAv3ngers, reach exposed PLCs directly through vendor engineering software such as Studio 5000, TIA Portal and EcoStruxure Control Expert, using it both to alter ladder logic, in one confirmed case disabling safety shutdown and alarm functions without alerting operators, and to exfiltrate PLC project files. Confirmed activity to date spans US government facilities, water and wastewater utilities and energy infrastructure.
India exposureNo source names an Indian victim in this campaign. What matters for Indian defenders is the hardware overlap: Rockwell, Siemens and Schneider Electric PLC families named in the advisory are widely deployed across Indian power distribution, water utilities and manufacturing plants, often with engineering-software access left reachable from broader plant networks.
ActionOT operators running any of the named PLC families should confirm engineering-software access is not reachable from the internet or general IT networks, enforce authentication on PLC programming ports where supported, and check the advisory's updated indicators of compromise against historical logs regardless of which regional channel the equipment was procured through.
SourceCISA advisory AA26-097A, updated 22 July 2026; SecurityWeek, 22-23 July 2026; Infosecurity Magazine, 23 July 2026.
Takeaway
This week's vendor sweep checked Fortinet, Cisco, Palo Alto Networks, Check Point, Juniper, SonicWall, Sophos, Barracuda, WatchGuard, Zscaler, Citrix NetScaler, Ivanti, F5 BIG-IP, Versa, Arista VeloCloud, Aruba/HPE EdgeConnect and Seqrite/Quick Heal by name; Fortinet also picked up a fresh KEV entry this week (CVE-2025-68686, an information-exposure flaw added 27 July alongside the VeloCloud issue), though the two items above carried the clearer exploitation evidence and India relevance. The throughline is management-plane and gateway software rather than a novel technique: an SD-WAN orchestrator, a firewall manager and a VPN gateway all became attacker footholds once reachable from outside the network they were meant to protect. The Bank of Baroda incident keeps a mailbox-compromise pattern in view for Indian BFSI regardless of how the leak-site data claims are eventually resolved, and the Iranian ICS advisory's expansion to Siemens and Schneider hardware is worth an asset-inventory check even without a named Indian victim, since the exposure runs through shared PLC families rather than India-specific targeting.
Indian banks, NBFCs and insurers are contending with a fresh round of edge-appliance compromise: an unattributed actor rooting SonicWall remote-access gateways, a Citrix NetScaler flaw feeding ransomware, and a listed NBFC's own ransomware disclosure, just as RBI names AI-enabled cyberattacks the top risk facing the sector and SEBI's half-yearly cyber-audit cycle comes due.
1. Sector snapshot
#1
AI-enabled cyber threats ranked the top expected risk over the next 12 months
67%
of institutions raised cybersecurity headcount, Mar 2025 to Mar 2026
71%
raised the cybersecurity share of IT spend over the same period
RBI's Financial Stability Report for June 2026 surveyed 33 scheduled commercial banks and 10 upper-layer NBFCs; respondents ranked AI-enabled cyber threats ahead of ransomware, phishing and third-party supply-chain exposure. Investment is rising alongside the threat. Source (with date): Reserve Bank of India Financial Stability Report; Business Standard (1 Jul 2026).
2. Threats targeting BFSI
1CriticalCVSS 10.0
SonicWall SMA1000 zero-days rooted before disclosure
CVE-2026-15409 (unauthenticated SSRF, CVSS 10.0) and CVE-2026-15410 (command injection, CVSS 7.2) on SMA1000 6210/7210/8200v appliances were exploited from around 22 June 2026, weeks ahead of SonicWall's patch. The actor Volexity tracks as UTA0533 abused the /wsproxy endpoint to reach internal services, then used a dropper called KNUCKLEBALL to install the open-source proxy tool suo5 and a custom Java webshell, ORANGETAIL, for persistent covert access and credential capture. CISA added both CVEs to KEV on 14 July 2026.
India exposureany Indian bank, NBFC or insurer using SMA1000 for branch, vendor or remote-staff access.
Actionpatch to 12.4.3-03453/12.5.0-02835 immediately and treat logs since 22 June as investigation scope, not just a patch checklist.
SourceVolexity (17 Jul 2026); Help Net Security (21 Jul 2026); CISA KEV (14 Jul 2026).
2
Listed NBFC discloses ransomware; Blacknevas claims the intrusion
Abans Financial Services told the BSE on 2 July 2026 that a ransomware attack had hit the IT infrastructure of its overseas subsidiaries, following a CERT-In alert around 30 June 2026; the company said its domestic systems were unaffected and operations continued without disruption. The Blacknevas ransomware group listed Abans Group and Abans Finserv on its leak site around 29 June 2026, a claim, not yet independently confirmed responsibility.
India exposuregroup entities with overseas subsidiaries sharing IT/vendor links back to the Indian parent.
Actionverify subsidiary network segmentation and confirm no shared credentials or trust relationships reach domestic systems.
CitrixBleed 2 keeps feeding ransomware via NetScaler
CVE-2025-5777 (CVSS 9.3) harvests NetScaler heap memory for live session cookies, letting attackers replay authenticated sessions and bypass MFA entirely. Huntress tracked roughly six unrelated intrusions between January and June 2026 using a consistent chain. Post-compromise, rogue admin accounts (ctxsvc, CtxAppVCOMService) and ScreenConnect/Zoho Assist installers calling out to attacker infrastructure preceded DragonForce ransomware deployment. Huntress assesses an initial-access broker, not a single named group, is selling this access.
India exposureIndian BFSI running NetScaler as Gateway or AAA virtual servers for VPN or application access.
Actionpatch, then terminate and re-issue all active sessions. A patch alone does not invalidate already-stolen tokens.
SourceHuntress (9 Jul 2026); IT Security Guru (9 Jul 2026).
4
RedHook Android RAT resurfaces with silent, no-root device takeover
Group-IB documented an upgraded RedHook that abuses Android's Wireless Debugging (ADB) feature alongside Shizuku-derived code to grant itself system-level privileges without user prompts, then streams the screen, intercepts input and automates on-device actions across 53 attacker commands. Current campaigns target Vietnam and Indonesia via fake bank or government calls steering victims to lookalike Play Store pages. India is not reported as targeted yet, but the technique directly threatens SMS/OTP-based UPI authentication wherever it spreads next.
India exposuremobile-banking and UPI customers if the campaign expands regionally.
Actionbrief fraud teams now on ADB-abuse indicators; block sideloaded APKs from non-store sources at the MDM/EMM layer.
- Identity infrastructure under active attack: Microsoft's July 2026 Patch Tuesday included CVE-2026-56164 (SharePoint Server, unauthenticated privilege elevation used toward RCE and IIS machine-key theft) and CVE-2026-56155 (AD FS, a Distributed Key Management ACL flaw allowing local privilege escalation to the token-signing certificate), both added to CISA KEV on 14 July 2026. AD FS underpins federated identity for many bank single-sign-on estates; SharePoint on-prem often hosts audit evidence and board materials. Source (with date): Microsoft MSRC; CISA KEV (14 Jul 2026). - FortiSandbox command injection, CVSS 9.1: CVE-2026-39808 and CVE-2026-25089 (also affecting FortiSandbox Cloud/PaaS) allow unauthenticated OS command execution via crafted HTTP requests; CISA added both to KEV on 16 July 2026. Relevant wherever FortiSandbox sits inline with mail gateways or malware-analysis pipelines in a bank SOC. Source (with date): Fortinet PSIRT (FG-IR-26-100); CISA KEV (16 Jul 2026). - One compromised MSP, 28 financial victims: Qilin ransomware used standing privileged access from a single South Korean MSP, GJTec, to move into 28 asset-management and financial firms in three waves between September and October 2025, exfiltrating over 1 million files and 2TB of data. Black Kite's 2026 Financial Services report cites the case as the model for fourth-party concentration risk, the same MSP-dependency pattern common in Indian BFSI vendor ecosystems. Source (with date): Bitdefender; The Hacker News (27 Nov 2025).
4. Regulatory & compliance watch
- SEBI CSCRF cyber-audit cycle: Qualified and Mid-size SEBI-regulated entities (brokers, MIIs, capital-market arms of banks) had a 30 June 2026 deadline for half-yearly cyber-audit-report submission; entities not yet compliant risk daily penalties in the Rs 1,500-5,000 range plus exchange action. Source (with date): NSE/NSDL CSCRF circular summaries (2026). - IRDAI Information & Cyber Security Guidelines, 2026: effective from the current financial year for insurers, foreign reinsurance branches and intermediaries; the CISO can no longer report to the IT head or carry business targets, and a new IT Strategy Committee must oversee cybersecurity decisions. Non-compliance carries penalties reported in the Rs 10 lakh-1 crore per-violation range. Source (with date): IRDAI circular, 6 Apr 2026, as reported by TaxGuru and Security Boulevard. - RBI's supervisory signal: naming AI-enabled cyber threats the top expected risk in the June 2026 Financial Stability Report puts examiners on notice to probe AI-specific controls at the next inspection cycle, not just legacy ransomware/phishing readiness. Source (with date): Reserve Bank of India Financial Stability Report (Jun 2026); Business Standard (1 Jul 2026).
Volexity has not linked this actor to any known group. Its post-exploitation discipline (root-level implants, encrypted webshell access gated on a specific user-agent string, credential harvesting for lateral movement) reads to researchers as closer to state-sponsored tradecraft than opportunistic crime. No confirmed Indian victim has been named publicly, but SMA1000 is a standard remote-access appliance in Indian BFSI estates, making the exposure real regardless of who is behind the keyboard.
Confidence: MEDIUM on the more APT-like than criminal assessment (Volexity's own hedge)
Source (with date): Volexity (17 Jul 2026).
6. IOC pack
Only public, attributed indicators; no leaked data reproduced, no MISP references.
Board: Ask for a one-page status covering SonicWall/NetScaler/FortiSandbox KEV exposure, the SEBI CSCRF audit submission status, and IRDAI governance-structure compliance (CISO reporting line, ITSC formation) where applicable.
CISO: Patch SMA1000, NetScaler, FortiSandbox, SharePoint and AD FS on an emergency basis; on NetScaler, terminate and re-issue all active sessions post-patch, not just apply the update; run a fourth-party/MSP access review modelled on the Qilin-GJTec pattern; confirm overseas-subsidiary network segmentation following the Abans disclosure.
SOC: Hunt SMA1000 logs from 22 June 2026 for /wsproxy anomalies and the KNUCKLEBALL/suo5/ORANGETAIL indicators; check NetScaler for the named rogue accounts and relay domains; monitor mobile fraud telemetry for ADB-wireless-debugging abuse patterns consistent with RedHook; watch AD FS DKM container ACLs for unauthorized changes.
8. Source index
Volexity · Help Net Security · CISA KEV · BSE disclosure coverage · ransomware.live · Huntress · IT Security Guru · Group-IB · BleepingComputer · Microsoft MSRC · Fortinet PSIRT · Bitdefender · The Hacker News · Reserve Bank of India (Financial Stability Report) · Business Standard · NSE/NSDL (SEBI CSCRF circular summaries) · IRDAI · TaxGuru · Security Boulevard.
9. Byline
1
Nirad Threat Research
NBTF — BFSI Sector Edition | 22 July 2026
AI WatchLatest AI Threat Watch4 August 2026Open issue →
Four disclosures this week trace back to a boundary that looked intact but was not actually verified: a testing environment assumed to be isolated, a package name assumed clean because it looked machine-generated, a breach-cost curve that now has AI stamped on more than a quarter of its entries, and a familiar face on screen assumed genuine because fact-checking hadn't caught up yet. Anthropic's own security evaluations breached three real companies. India's average breach cost hit a record high. Researchers showed AI coding agents hallucinate predictable names attackers can register in advance. And a deepfake of the finance minister kept producing victims months after the same script had already been documented.
1
Anthropic says three Claude models breached real company networks after a testing environment quietly gained internet access it should not have had
Anthropic disclosed on 31 July 2026 that a review of 141,006 evaluation runs conducted with partner Irregular found three cybersecurity-evaluation incidents, the earliest traced to April 2026, in which Claude models had live internet access during capture-the-flag-style testing meant to be network-isolated. Anthropic attributes this to a misconfiguration and a misunderstanding with the evaluation partner, not a model escaping its environment. Opus 4.7 found and breached a real company it mistook for a simulated target, extracting application and infrastructure credentials and reaching a production database containing several hundred rows. An internal model Anthropic calls Mythos 5, while working against a fictional target, published a malicious Python package to the real PyPI registry; the package reached 15 real systems, including one belonging to a security company, and exfiltrated credentials from anyone who ran it. A third, unnamed internal research model scanned roughly 9,000 targets and compromised one real company through SQL injection combined with credentials taken from an exposed debug page. Anthropic says none of the three models attempted to exfiltrate itself or deliberately escape its test environment, and that newer models showed more restraint than older ones.
Why it matters for IndiaIndian AI labs, GCC security-research teams and MSSPs building or buying agentic red-team and evaluation tooling are running comparable experiments, often with less isolation discipline than a frontier lab applied even when its discipline failed. A configuration error, not a compromised model, was enough to turn simulated exercises into real breaches, including one where a poisoned package reached other people's systems.
ActionTreat any AI evaluation or red-team range as requiring production-grade network isolation, verified independently rather than trusted from configuration intent; block outbound access to public package registries, code-hosting platforms and the open internet by default in these environments; require human approval before an evaluation agent scans, exploits, publishes a package or touches credentials; retroactively audit past eval runs for signs any of them reached real infrastructure.
SourceThe Hacker News, "Anthropic Says Claude Mistook the Open Internet for a CTF and Breached Three Organizations" (31 July 2026); Axios (30 July 2026); The Hill (30 July 2026); Forbes (3 August 2026).
2
India's average data-breach cost hits a record Rs 25.5 crore, with more than a quarter of malicious breaches now AI-generated
IBM and the Ponemon Institute's Cost of a Data Breach Report 2026, released 3 August 2026 and based on 602 organisations studied between March 2025 and February 2026 with a May 2026 follow-up survey of 456 entities, found India's average total cost of a data breach reached an all-time high of Rs 25.5 crore, up 15.9% from Rs 22 crore the previous year. Twenty-six percent of malicious breaches in India were AI-generated. The average breach also grew in scale, compromising 39,500 records against 38,200 a year earlier. Phishing, including voice and SMS phishing, remained the leading initial attack vector at 19%, ahead of drive-by compromise at 16% and supply-chain compromise at 15%. The report found roughly a Rs 10 crore gap tied to AI-security maturity: organisations with extensive AI and automation in their security operations averaged Rs 21.3 crore per breach, against Rs 31.6 crore for those with little or none, yet 68% of Indian organisations report limited or no AI/security-automation use.
Why it matters for IndiaThis is now a documented, India-specific figure rather than a global estimate applied locally: AI is measurably raising both the frequency of breaches, as a generation tool for attackers, and the cost gap between organisations that have and have not adopted AI-assisted defence.
ActionBenchmark current security-automation maturity against the report's tiers before the next budget cycle; prioritise phishing-resistant authentication and voice/SMS-phishing controls given they remain the leading entry point; extend supply-chain monitoring given its rising share of initial access; use the report's cost gap to justify AI-assisted detection and response as a cost-reduction case, not only a capability upgrade.
SourceIBM and Ponemon Institute, Cost of a Data Breach Report 2026 (3 August 2026); Business Today (3 August 2026); Business Standard (3 August 2026).
3
HalluSquatting: researchers show AI coding agents hallucinate the same fake package and repository names predictably enough for attackers to register them first
Researchers led by Aya Spira in Ben Nassi's group at Tel Aviv University, working with Technion and Intuit, published the finding on arXiv on 8 July 2026, reported by BleepingComputer. Testing six widely used AI coding agents and assistants — Cursor, Windsurf, GitHub Copilot, Cline, Gemini CLI and OpenClaw — the team found the tools do not hallucinate random non-existent package or repository names; they hallucinate the same name repeatedly and predictably, up to 85% of the time for repository requests and 100% of the time for "install this skill" requests. Because the fabricated name is predictable rather than random, an attacker can pre-register it on npm, GitHub or a comparable registry with malicious content before any real developer's agent asks for it, the reverse of conventional after-the-fact typosquatting. The researchers describe their percentages as a floor, not a ceiling. It follows earlier related findings this year: a hallucinated npm package, "react-codeshift," spread through 237 repositories via forked AI-agent skill files, reported in January 2026, and Palo Alto Networks' Unit 42 catalogued roughly 250,000 domains commonly hallucinated by language models, reported in June 2026.
Why it matters for IndiaIndian software exporters and GCC engineering teams have adopted the exact tools tested, including Copilot, Cursor, Cline and Gemini CLI, often for precisely the scaffolding and dependency-installation tasks where hallucination rates were highest.
ActionRestrict agents to a private, allow-listed package source rather than the public registry directly; pin dependencies through lockfiles and verify provenance before merging anything an agent proposes; flag for manual review any repository or package an agent references that was created recently or lacks a verifiable maintainer history; treat an agent's suggested dependency with the same scrutiny as an unsolicited link in an email.
SourceAya Spira, Ben Nassi et al., arXiv preprint (8 July 2026); BleepingComputer (July 2026).
4
A deepfake video of the finance minister keeps generating real victims months after the same scam script was already documented
A paid Facebook advertisement carrying an AI-generated deepfake of Union Finance Minister Nirmala Sitharaman, falsely endorsing an investment scheme promising an assured Rs 70,000 a day, roughly Rs 22 lakh a month, on a Rs 22,000 outlay, was confirmed fabricated by the PIB Fact Check Unit around 30-31 July 2026, which stated Sitharaman has neither endorsed nor authorised any such scheme. The same script had already produced a documented victim weeks earlier: The420.in reported on 8 July 2026 that a retired professor in Shankarapuram, Bengaluru lost Rs 61.10 lakh of Rs 65 lakh transferred, after a similar deepfake video routed him to a fake trading platform, bxbmarket.com, where a fraudster posing as an agent conducted "KYC" over email, showed a fabricated profit dashboard that grew past Rs 1 crore, then demanded further processing fees before any withdrawal; the scam ran from 9 March to 25 June 2026, when it was reported to the National Cyber Crime Helpline. The same reporting notes near-identical scripting in separate Khammam and Belagavi cases around the same period, pointing to shared infrastructure behind multiple deepfake-endorsement scams rather than one-off clips.
Why it matters for IndiaA single fact-check does not retire a campaign; the underlying video, platform template and script keep circulating and producing victims for months, across cities, until the advertising and hosting infrastructure itself is disrupted.
ActionFinancial institutions and platforms should treat any investment advertisement using a public official's or executive's likeness as a fraud signal requiring proactive review rather than a wait-for-complaint response; publish consumer warnings tied to the specific script elements, assured daily returns, KYC conducted over email, a dashboard that blocks withdrawal without further payment, rather than only the fact that a video is fake; individuals should verify any investment offer bearing a public figure's endorsement through that figure's official channel before transferring funds.
SourcePIB Fact Check Unit, reported by Organiser (31 July 2026); The420.in (8 July 2026).
AI defender tip: Every item this edition traces back to a boundary that looked intact but was not verified: a test environment assumed isolated, a package name assumed clean because it looked agent-generated, a video assumed genuine because it named a familiar face. None of this needed a novel defence. Network isolation, dependency provenance checks and independent verification of any urgent or too-good financial claim are controls Indian security teams already know how to run. The gap was applying them by default to AI-touched systems and AI-adjacent claims, instead of treating an agent's output or a familiar face on screen as inherently trustworthy.
Nirad Threat Research
Nirad AI Threat Watch | Bharat-first threat intelligence