Blog
What our latest six threat advisories mean for next quarter's budget
UltraViolet Cyber's Threat Intelligence & Detection Engineering (TIDE) team tracks new malware, vulnerabilities, and active campaigns as they emerge and publishes original research on what we find, usually within days of first observing it in the wild. Over six weeks this summer, that research produced six advisories: Anubis ransomware, HOLLOWGRAPH malware, VibeCoded malware targeting Active Directory, JADEPUFFER, browser extension threats, and DifyTap vulnerabilities.
Each advisory is a practitioner brief with its own indicators and response steps. Read together, the six advisories form a clear picture on where leadership teams should be focusing next quarter's spend. This article pulls the latest UltraViolet TIDE research into three budget priorities ready for your next planning conversation.
Three gaps show up across all six. None of them are new categories of risk. All three are underfunded relative to how fast the threat landscape is moving.
Your AI stack is unmanaged infrastructure
JADEPUFFER was the first documented ransomware operation run entirely by an autonomous AI agent, with no human directing any step. The agent didn't need a novel exploit. It found an unpatched Langflow instance (CVE-2025-3248), a MinIO bucket still on default credentials, and an Alibaba Nacos deployment using a signing key that's been public for years. It chained all three into a full ransomware cycle, correcting its own failed steps in under a minute, with no procurement delay and no approval workflow slowing it down.
Three weeks earlier, our DifyTap advisory covered four vulnerabilities in Dify, an open-source LLM Ops platform running more than one million AI applications at companies including Volvo and Maersk. Two of the four CVEs were unauthenticated. Standard container scanners missed all four, because Dify ships unpackaged source code into its containers rather than installed packages, a structural blind spot in how most vulnerability scanning tools look at AI workloads.
Both incidents share the same root cause: an AI platform that had never gone through a vendor security review. AI orchestration tools accumulate API keys, cloud credentials, and database connections as a normal part of how they function, and most organizations are treating them like internal productivity software instead of infrastructure that needs the same scrutiny as a production database.
Budget priority 1
AI platform inventory and vendor review
Fund an immediate inventory of every AI and LLM platform in the environment, including the ones product or marketing teams adopted without a security review. Require a vendor security review before any new AI procurement and before renewing any platform already in place.
Signature-based detection is buying you less than it used to
Our VibeCoded malware advisory covered a June 2026 intrusion where an attacker used a domain-joined Windows Server, pre-compromised RDP credentials, and a PowerShell script an AI model had written for them on the spot. The script had the tells of AI generation (a leftover placeholder hostname, a five-method fallback chain no human would bother writing), but it worked, and because it was generated fresh, it matched no existing hash or signature. A parallel case at cloud scale showed the same dynamic: an AI-assisted attacker compromised a full AWS environment in about 72 hours using only known techniques, executed faster than a human operator could manage.
HOLLOWGRAPH adds a second version of the same problem. The malware, linked with high confidence to the Cavern backdoor framework, used the Microsoft Graph API to turn a compromised Microsoft 365 calendar into a two-way command channel, hiding stolen data inside calendar events dated to 2050. Network monitoring built to flag connections to unfamiliar infrastructure has nothing to flag, because the command-and-control server is Microsoft's own cloud.
Both point to the same fix: detection engineering built around behavioral rules, including privilege escalation patterns, anomalous Graph API calls, and unusual calendar operations by application identities. Organizations that migrated to a SIEM built around hash and IOC matching are going to keep missing exactly this class of activity.
Budget priority 2
Behavioral detection engineering
Fund dedicated engineering time to build and maintain behavioral detection rules for identity and cloud application activity. UltraViolet's TIDE team builds detection content for every advisory it publishes, including all six referenced here, and works with security teams that want detection engineering support without adding headcount.
Third parties and unreviewed software are still your exposure
Anubis, the ransomware group behind the July attack on Coca-Cola's Fairlife subsidiary, didn't breach Coca-Cola directly. It found Fairlife, a smaller, less centrally managed business unit, stole roughly 1TB of data, and forced an SEC disclosure over an incident that started well outside the parent company's core systems. Materiality thresholds for cyber incidents are lower than most boards assume, and a subsidiary's security posture is now the parent company's disclosure risk.
The same pattern shows up in software choices. Our browser extension threats advisory covered three campaigns disclosed in late June, including one that hid malware in image and font files across up to 2.6 million Edge installs, all abusing permissions that looked legitimate at install time. Extensions are still being treated as personal productivity choices instead of software that needs the same allow-listing and monitoring as anything else running on a managed device.
Budget priority 3
Vendor and subsidiary review
Extend vendor and subsidiary security review to any unit or tool that can reach core systems, and treat browser extensions as managed software, not user preference.
Where this points for next quarter
Next quarter's fix is redirecting spend toward three specific lines: an AI platform inventory and vendor review process, engineering time for behavioral detection rules, and governance that extends to subsidiaries, extensions, and any third-party tool touching production data.
For organizations working toward CMMC compliance windows, two of these three priorities line up well. Vendor and third-party review maps to the Supply Chain Risk Management and related control families under NIST SP 800-171, and behavioral detection maps to the audit, system integrity, and incident response families. AI governance is the piece CMMC does not yet address, and that is where NIST AI RMF and ISO 42001 give security leaders a defensible framework to point to. Building these controls now for the security reasons above means they are already in place, and mapped to the right framework, when the compliance deadline arrives.
Each of these six advisories has the same root cause: an unreviewed AI platform, an unreviewed subsidiary, or an unreviewed extension. Funding that review is where next quarter's budget should go.
All six advisories, including full indicators and response steps, are available in UltraViolet Cyber's threat advisory library.
Get the latest Threat AdvisoryADDITIONAL INSIGHTS
READY TO GET STARTED?
We’re here to help. Get in touch for an initial conversation with one of our security experts and learn more about how UltraViolet Cyber can help you take cyber readiness and resilience to new levels.
AI Governance by Design
UltraViolet Cyber Acquires Black Duck’s Application Security Testing Services Business
UltraViolet Cyber Launches Solstice