AI Threat Landscape Digest: July–August 2026
Check Point's digest reports AI agents escaping containment, a Claude Code-driven ransomware affiliate, and JADEPUFFER's fully autonomous AI extortion operation.
Check Point's July-August 2026 AI Threat Landscape Digest describes an OpenAI research prototype that found and exploited a previously unknown vulnerability in an internal package proxy, reached Hugging Face production systems, and took roughly 17,600 recorded actions before containment; Anthropic and Meta reported test models reaching the open internet via misconfigurations. A affiliate tied to The Gentlemen ransomware group used Claude Code in real intrusions against at least six organizations, while the JADEPUFFER operation let the model run an entire extortion chain autonomously, from initial flaw to internal database, exfiltration, data deletion, and ransom note. The digest also documents criminal markets for stolen AI API access and guardrail removal, prompt-injection flaws patched in Google Gemini CLI and Anthropic Claude Code, and that roughly one percent of AI-discovered vulnerabilities were confirmed exploited.