A South Carolina hospital system reopens its doors with many systems still offline. An IoT botnet moves its command and control onto the blockchain. An autonomous AI agent roams through a national finance ministry. Shared AI chats turn up in Google search results again. And a Swiss trainmaker tells an extortion crew to get lost. This is Cybersecurity Today, and I'm your host, David Shipley. Let's get started. South Carolina's Ann Med reopened its physician offices on Tuesday for scheduled appointments, four days into a ransomware attack that still has some of its phones, internet, and computer systems offline. Patients walking in were asked to bring their own medications in their original containers and were asked to recite their own medical history. Urgent refill requests required showing up in person, and staff were working through a backlog of canceled appointments by hand. At the peak of the disruption, ANMED had to close 80 of its 106 facilities temporarily. Imaging, OBGYN, primary care, oncology, and radiation all went dark on Monday. Every group medical office had to be closed, and every elective procedure had to be canceled. The system runs hospitals and physician practices across upstate South Carolina and northeast Georgia. AnMed first told the public Sunday morning that it had a phone and internet outage. By Sunday afternoon, that had become a cybersecurity disruption involving malware. Patients inside the emergency department describe what happened. Blue-black screens and a countdown. One patient told a reporter that the message on the screens gave AnMed 72 hours to pay before everything was leaked. Another patient was discharged with handwritten paperwork and sent to a different hospital because no tests or scans could be done. Anmed says the forensic review remains in its early stages, and it cannot yet describe the nature or scope of the incident. Healthcare is having a brutal year. Comparatech's ransomware tracker counted 410 attacks on healthcare organizations worldwide in the first half of the year, up 14% from the last six months of 2025. That works out to an average of 2.3 healthcare ransomware attacks every single day. The United States accounted for 225 of the 410 accounts, with Killen, The Gentleman, Lockbit, and the Inc. Ransomware Gang leading the field. At the same time of the onslaught of ransomware attacks, regulatory requirements in the United States for healthcare organizations have been pushed back. The HIPAA security rule update that would have mandated annual penetration testing, a defined risk analysis methodology, and multi-factor authentication was pushed from May of 2026 to July 2027. That decision followed pushback from healthcare organizations on the timeline for the changes and the costs. Meanwhile, Well lawyers aren waiting for the forensics or regulatory rule improvements ClassAction put up an AnMed page within the first 48 hours soliciting current and former patients as well as employees for a potential class action lawsuit. An IoT botnet called Dysphoria has rebuilt its command and control infrastructure around blockchain name services, as well as a mesh of relays running on its own victims. Researchers say the result is a considerably harder-to-take-down botnet. The use of blockchain as a C2 mechanism is a direct response to the takedown of Jackskid, one of four IoT botnets hit by a coordinated American, German, and Canadian law enforcement action on March 19th. What's changing here is that the use of Ethereum name services, or blockchain in general, is going from a secondary redundancy trick to being the primary method to ensure that C2 infrastructure remains free from disruption. xLab, a Chinese threat researching firm, published an analysis on dysphoria on July 25th alongside a notice from China's National CERT, or CNCERT. Over a fast run of builds this spring, dysphoria's operators moved command and control onto blockchain name records that pointed to distribution nodes handing out server lists. Those lists were made entirely of infected machines. So trying to seize a controller now means trying to seize a victim's router. CNCERT and XLAB put the dysphoria botnet population above 200,000 bots. with about 4,400 of those bots active inside China between July 14th and 20th, and a single-day peak of infected devices of about 239,000 observed abroad. The two also published different vulnerability lists, though they both agree that weak Telnet and SSH credentials remain the most reliable way in. The Dysphoria DDoS storefront advertises attacks of up to roughly 4 terabits per second for tens to hundreds of dollars. The capability of the botnet has not been independently confirmed. The biggest botnet to date clocked in at more than 31 terabits per second this year. Defenders should patch exposed IoT gear, retire devices that can no longer be updated, kill default and weak credentials, and switch off remote management and UPnP on devices wherever they are not needed. Shared, clawed conversations turned up in Google search results over the weekend, and reporters who went looking found medical records, internal corporate documents, and the names and phone numbers of primary school-aged children. A Reddit user flagged it on Saturday, noting that a site-restricted Google query against clode.ai's share path returned a long list of conversations. Futurism digging through the results described finding a detailed medical report on a real patient, clinical trial results and employee reviews containing personal information about the workers being reviewed. The mechanism here is Claude's own share feature, which creates a link that can be shared with anyone Anyone with access to the link can find the conversation Anthropik position is that the links themselves are not the problem The company told TechCrunch that a share link only reaches a search index if someone posts it somewhere's crawlable, like a forum or a social media thread, and that a link sent privately stays out of search. An Anthropics spokeswoman said the company does not hand out chat directories or sitemaps to search engines, and that the links are neither guessable nor discoverable on their own. Google, for its part, said search engines do not decide what gets published on the web, and that these pages were indexed across multiple engines. Site owners have controls to prevent crawling. Both statements are technically accurate, but both sidestepped the more useful question, which is whether the user clicking create a public link really understood that they may be creating something that could be caught up in a search index, rather than sending something to a co-worker. Google Docs offers a comparable link sharing feature, but those documents don't show up in search results. By Monday afternoon, the query had stopped returning results, so something was remediated, though no one has said exactly what. And this has all happened before. Forbes reported hundreds of index clode conversations last year, with Google estimating just under 600 pages before they disappeared. In the same period, 404 Media reported a researcher scraping roughly 100,000 publicly shared chat GPT conversations. Nobody has independently confirmed the scale of this weekend's chat exposure. Threat actors ran an autonomous AI agent inside Thailand's Ministry of Finance, and researchers only found out because those operators left their own server wide open while the intrusion was still running. Hunt.io published those findings last week. On infrastructure controlled by the attackers, the firm found hundreds of publicly accessible files. That included malware, stolen credentials, attack scripts, AI agent logs, active authentication cookies, and evidence that multiple ministry systems had already been compromised. The attack used Hermes, an open-source AI agent released earlier this year by Noose Research. The operators turned on the software's YOLO mode, which lets the agent execute commands without pausing for human approval. According to Hunt.io, the agent explored the TIE network on its own, searched internal files, collected system information, and hunted for privilege escalation opportunities. The agent made its own decisions about where to look, and no one was at the keyboard. Earlier this month, Hugging Face disclosed that it had been breached by an autonomous AI agent, and that agent turned out to belong to OpenAI. OpenAI's agent exploited two previously unknown vulnerabilities and used stolen credentials to get into Hugging Face. In the Thailand incident, the Hermes agent infrastructure held exploits for several known vulnerabilities, scripts written specifically against the ministry's administrative web portals, email systems and document management platform as well as tooling built to test ministry email passwords It also included a previously undocumented malware family that Hunt named Hades Both Windows and Linux builds of the malware were found each capable of remote command execution and file transfer, functioning as a custom backdoor for persistence after the initial break-in. How the attackers first got in remains unknown. Hunt.io found no evidence that any data was exfiltrated. The activity looked like reconnaissance, credential theft, and network mapping ahead of something. The firm did not attribute the campaign to a named group, though it said multiple indicators point to Chinese-speaking operators. The malicious activity traces back to at least mid-June, and the Thai CERT and National Cybersecurity Agency were notified on July 15th. The finance ministry has not publicly acknowledged the intrusion and did not respond to a request for comment. Thai cybersecurity officials said Monday they would strengthen national defenses against attacks involving AI agents without referencing the Hunt.io investigation. Swiss train manufacturer Stadler Rail says it won't pay a 10 million Swiss franc ransom demanded after the Everest group stole technical documents from a supplier's file-sharing platform. The company said under no circumstances will it pay the ransom and it can't be extorted. It has filed a criminal complaint and says it won't negotiate. The breach happened in mid-July and did not touch Stadler's own systems. The stolen material consisted of technical documents belonging to a third-party supplier, taken after credentials for a data exchange platform were compromised. Stadler says it lost none of its own data, that no relevant personal information was involved, and that trains running worldwide are unaffected. All production sites remain operational. Stadler is one of Europe's largest rail equipment manufacturers, supplying trains, trams, and metro cars as well as locomotives internationally. It employs almost 18,000 people and generates more than $4.9 billion in revenue. The company has been here before. In 2020, attackers got inside some of its systems, stole internal data and demanded around $6 million in Bitcoin. Stadler refused then as well. The attackers published samples, reportedly financial and administrative documents, and Stadler held its ground. When it comes to paying, Proofpoint said in a survey last week of 953 organizations that 54% had paid, and more than a third of those got hit with a second extortion demand. Everest is a Russian-speaking ransomware crew active since at least 2020 with a track record across energy, transportation, and telecommunications. And that's Cybersecurity Today for Wednesday, July 29th. I've been your host, David Shipley. Thanks for listening. We appreciate all your feedback. Feel free to reach us at technewsday.com or .ca, or you can leave a comment under the YouTube video. I'll be back on Friday with the latest headlines. Until then, I hope you have a great rest of the week and stay safe.