Cybersecurity Brief
Exploited ServiceNow flaw and stealthy Microsoft 365 C2 rise
Today’s reporting highlights two converging operational risks: critical enterprise platform exploitation and increasing stealth in command-and-control. Attackers are already leveraging a critical ServiceNow code execution vulnerability, indicating rapid weaponization and fast-moving defensive urgency for ServiceNow environments. In parallel, new malware uses Microsoft Graph via compromised Microsoft 365 mailboxes as a covert C2 pathway, which increases the likelihood that traditional network detections may underperform.
A third, more forward-looking risk signal is the expansion of ransomware/agentic attack focus toward AI model and dataset assets. JadePuffer’s updated “agentic” behavior reportedly targets AI training data and model checkpoints for encryption, suggesting threat actors are adapting to protect not only user data but also the organizations’ ability to train, fine-tune, and operate AI systems. Finally, a separate incident in Romania demonstrates how cyber disruption can directly impact national economic/operational continuity (land registry), reinforcing the need for resilient incident response and prioritized recovery planning.
Top Signals
1. Critical ServiceNow code execution flaw is actively exploited
Signal strength: Early
Active exploitation of a critical ServiceNow code execution vulnerability raises the likelihood of near-term compromise at scale through widely deployed enterprise workflows. Executives should treat ServiceNow hardening and patch verification as an immediate priority to reduce ransomware, data theft, and lateral movement risk.
Supporting evidence
- Critical ServiceNow code execution flaw now exploited in attacks — BleepingComputer, 2026-07-20. States attackers have begun exploiting a critical ServiceNow AI Platform vulnerability (CVE-2026-6875), indicating weaponized access rather than theoretical risk.
2. Microsoft 365 Graph used for stealthy C2 and exfiltration
Signal strength: Early
Malware that leverages Microsoft Graph and mailbox features for C2 can blend into normal cloud traffic patterns and reduce visibility for perimeter-based controls. Security leaders should reassess detections around Microsoft 365/Graph usage, mailbox-triggered behaviors, and anomalous exfiltration paths.
Supporting evidence
- New HollowGraph malware uses Microsoft Graph for stealthy C2 comms — BleepingComputer, 2026-07-20. Describes HollowGraph using calendar features in compromised Microsoft 365 mailboxes as a command-and-control channel for receiving commands and exfiltrating stolen data.
3. Agentic ransomware targets AI training data and checkpoints
Signal strength: Early
Targeting AI model data (training datasets, vector databases, model checkpoints) expands ransomware impact from confidentiality to availability and operational capability. This creates a business continuity and recovery challenge for organizations using AI for core functions, requiring AI asset inventorying and restore strategies.
Supporting evidence
- JadePuffer agentic attacks now target AI model data with ransomware — BleepingComputer, 2026-07-20. Reports JadePuffer’s autonomous agent upgrade with malware that encrypts AI assets such as training datasets, vector databases, and model checkpoints.
4. Cyberattacks increasingly disrupt critical national services
Signal strength: Early
A disrupted land registry can directly affect property transactions and economic operations, demonstrating the real-world consequences of cyber incidents beyond data breaches. Executives should ensure recovery plans include service-specific continuity, priority data restoration, and operational coordination across stakeholders.
Supporting evidence
- Romania races to restore land registry after cyberattack disrupts property market — The Record, 2026-07-20. Indicates the land registry agency is still recovering after what it called a major technical incident, disrupting property-market operations.
5. Abuse of legitimate networking update paths for targeting
Signal strength: Early
Using the update mechanism of private networking software to deliver malicious activity suggests attackers are targeting trust boundaries in software supply/update channels. This increases the need for rigorous vendor/update verification, integrity controls, and monitoring for tampered update behavior—especially in government-facing environments.
Supporting evidence
- Hackers abuse ViPNet software to target Russian govt agencies — BleepingComputer, 2026-07-19. Reports abuse of the ViPNet private networking product suite update mechanism to target Russian organizations, including government agencies.
Sources
- Critical ServiceNow code execution flaw now exploited in attacks — BleepingComputer
- New HollowGraph malware uses Microsoft Graph for stealthy C2 comms — BleepingComputer
- JadePuffer agentic attacks now target AI model data with ransomware — BleepingComputer
- Romania races to restore land registry after cyberattack disrupts property market — The Record
- Hackers abuse ViPNet software to target Russian govt agencies — BleepingComputer