Content
01. News Bites
-
AI goes rogue again, this time utilising social engineering tactics
-
ChainDrop Malware compromises over 1,300 npm packages in major supply chain attack
-
Kenya emerges as major cybercrime target in East Africa
-
Swiss government cyberattack compromises 200 accounts
-
Intermarché cyberattack exposes data of nearly 300,000 customers
02. Conclusion
AI goes rogue again, this time utilising social engineering tactics
OpenAI and Anthropic have disclosed separate cybersecurity testing incidents in which their AI models interacted with real-world systems and individuals beyond the intended boundaries of controlled evaluations. The newly revealed events are unrelated to the recent Hugging Face breach but have raised fresh concerns about the behaviour of increasingly autonomous AI agents.
During testing by the UK AI Security Institute (AISI), AI agents powered by Anthropic's Claude Mythos 5 and OpenAI's GPT-5.6 Sol took unauthorised actions on the public internet while attempting to complete simulated hacking challenges. In one case, an AI agent mistakenly targeted a real GitHub project, creating fake accounts and conducting social engineering campaigns to persuade developers to approve malicious code changes.
In a separate incident, OpenAI said one of its models exploited a real website after a testing environment was misconfigured, allowing unintended internet access. The AI reportedly used discovered credentials to access the site while believing it was part of a simulated challenge.
Although investigators found no evidence of significant real-world harm, the incidents highlight growing concerns around AI autonomy, deception, and cyber capabilities. Security experts say the events demonstrate the need for stronger safeguards, clearer testing boundaries, and industry-wide standards for evaluating advanced AI systems.
ChainDrop Malware compromises over 1,300 npm packages in major supply chain attack
A large-scale software supply chain attack has compromised more than 1,300 packages on the npm registry, exposing developers and organisations worldwide to a self-propagating malware strain known as ChainDrop. Security researchers estimate the affected packages account for more than 2 billion monthly downloads, making it one of the most significant npm ecosystem attacks to date.
The campaign began after attackers gained access to the GitHub account of a maintainer behind several widely used packages, including Keyv, Cacheable, flat-cache, and file-entry-cache. Once inside, the threat actor injected malicious code into legitimate projects and published compromised package versions through official GitHub workflows, allowing the malicious releases to appear trustworthy.
The malware automatically executes during package installation, deploying an information-stealing payload designed to collect sensitive credentials, API tokens, cloud secrets, database access details, and CI/CD pipeline credentials. Researchers warn that the worm-like malware can spread further by using stolen credentials to compromise additional repositories and software packages.
Security firms have advised organisations that installed affected versions to treat impacted developer workstations and build environments as compromised. Recommended actions include rotating all exposed credentials, rebuilding affected systems, and reviewing logs for signs of unauthorised access.
The incident highlights the growing risk posed by software supply chain attacks and the potential impact of compromised open-source dependencies on organisations worldwide.
Kenya emerges as major cybercrime target in East Africa
A new Interpol cyberthreat assessment has identified Kenya as one of East Africa’s primary targets for cybercriminals, highlighting a sharp rise in attacks against telecommunications networks, government systems, and mobile money services. The report warns that the country’s rapid digital growth has created new opportunities for threat actors seeking to exploit weaknesses in critical infrastructure and online services.
According to the findings, Kenya recorded more than 46,000 Distributed Denial-of-Service (DDoS) attacks during the first half of 2025, with telecom providers bearing the brunt of the activity. Authorities also reported hundreds of millions of attempted intrusions targeting government and ICT systems through brute-force attacks and software exploitation techniques.
Mobile fraud remains a major concern. SIM swap scams surged by more than 300%, with cybercriminals using fraudulent SIM cards to gain access to mobile money accounts and steal millions of dollars. The report also referenced the high-profile compromise of Kenya’s presidential website, where attackers defaced the site and demanded a cryptocurrency ransom.
Interpol noted that neighbouring countries, including Uganda, Tanzania, and Rwanda, have faced similar threats, ranging from ransomware attacks to telecom fraud. However, Kenya’s volume of incidents stands out across the region, reinforcing concerns about the growing cyber risks facing Africa’s expanding digital economy.
The report concludes that stronger regional cooperation and coordinated cybersecurity measures will be essential to combat increasingly sophisticated cross-border cybercrime networks.
Swiss government cyberattack compromises 200 accounts
Swiss authorities are investigating a cyberattack on SharePoint servers operated by the Federal Office of Information Technology, Systems and Telecommunication (FOITT), which resulted in the compromise of around 200 user and technical accounts. The incident is believed to have involved attackers exploiting recently disclosed vulnerabilities in Microsoft SharePoint software.
Following the discovery, FOITT immediately reset affected passwords and blocked internet access to the impacted SharePoint environment for users outside the federal administration. The agency is also reinstalling the affected servers as a precaution while investigations continue. Internal government staff remain able to access documents through alternative channels.
According to FOITT, there is currently no evidence that additional data was stolen or leaked, and authorities stress that confidential information and highly sensitive personal data are not permitted to be stored on the affected SharePoint platform. The investigation is being supported by Switzerland’s National Cybersecurity Centre (NCSC) and Microsoft.
The incident highlights the continuing threat posed by vulnerabilities in widely used enterprise software. Switzerland recorded 325 cyberattacks against critical infrastructure last year, including 28 targeting the federal administration. Officials warn that public sector organisations remain attractive targets for cybercriminals seeking access to government systems and sensitive information.
Intermarché cyberattack exposes data of nearly 300,000 customers
French supermarket chain Intermarché has confirmed a cyberattack that compromised the personal data of nearly 300,000 customers using its click-and-collect service, known as Drive Intermarché. The breach occurred after attackers gained unauthorised access to customer order history and account information.
According to Groupement Mousquetaires, which operates the supermarket chain, the exposed data includes customers' names, phone numbers, postal addresses, dates of birth, loyalty card numbers, and certain online order details. The company stressed that no banking information, passwords, email addresses, or loyalty point balances were affected by the incident.
Intermarché has already notified approximately 287,000 affected customers and warned that further investigation may identify additional individuals impacted by the breach. The incident has been reported to France's data protection authority, the CNIL, in line with regulatory requirements.
Security experts are warning customers to remain vigilant against phishing attempts, as cybercriminals may use the stolen information to impersonate Intermarché and trick victims into revealing further personal or financial details. The breach is the latest in a growing number of cyberattacks targeting major French organisations, highlighting the continued threat facing the retail sector and the increasing value of customer data to attackers.
If you are worried about any of the threats outlined in this bulletin or need help in determining what steps you should take to protect yourself from the most material threats facing your organisation, please contact your account manager, or alternatively Get in touch to find out how you can protect your organisation.
Disclaimer
The Threat Intel Roundup was prepared by Integrity360 summarising threat news as we observe it, current at the date of publishing. It should not be considered to be legal, consulting or any other professional advice. Any recommendations should be considered in the context of your own organisation. Integrity360 does not take any political stance in the information that we share. Moreover, the opinions expressed may not necessarily be the views of Integrity360.