2026-07-13
- ai security
AI Security Report 2026
Check Point Research's 2026 AI Security Report documents a shift in how attackers use artificial intelligence, moving from a force multiplier for existing techniques to an active operator conducting live intrusions. The report finds that AI now builds malware and attack frameworks independently, powers phishing-as-a-service and voice-based social engineering at scale, and introduces new attack vectors including indirect prompt injection and model manipulation. Organizations face growing risks of data leakage through GenAI applications, with high-risk prompts doubling year-over-year and detection of malicious payloads increasing fivefold between March and May 2026.
Why it matters: Security practitioners must reassess threat modeling for AI-driven attacks affecting all organizations: attackers now deploy AI as an autonomous operator in intrusions, criminals abuse commercial AI models via jailbreaks and planted configs, and enterprise data exposure through unsanctioned GenAI use has doubled, requiring immediate inventory and policy controls.
- cloud saas
Defending SaaS-based applications against ShinyHunters OAuth abuse
Microsoft identified ShinyHunters-associated threat actors conducting campaigns from mid-2025 to mid-2026 that abused OAuth relationships to compromise Salesforce and other SaaS applications across retail, education, and manufacturing sectors. The attackers used voice phishing to trick users into authorizing malicious apps, exploited supply chain compromises in third-party integrations like Salesloft, and leveraged misconfigured guest access to gain persistence and exfiltrate customer relationship management data. These intrusion paths operated within legitimate OAuth workflows, allowing the threat actors to inherit user privileges and evade conventional authentication detection without exploiting any Salesforce vulnerability.
Why it matters: Security teams managing Salesforce and integrated SaaS applications need to immediately review OAuth-connected applications, validate third-party integrations, audit guest access configurations, and implement advanced monitoring to detect unauthorized OAuth consent flows and suspicious API activity that could result in large-scale data exfiltration.
- government policy
States are building their own election defense networks as federal support evaporates
State election officials are building independent security networks after the Trump administration fired Election Assistance Commission (EAC) commissioners and the Department of Justice issued threats of criminal prosecution against election officials. Federal agencies like the Cybersecurity and Infrastructure Security Agency (CISA) have reduced technical support and threat intelligence sharing with states, forcing secretaries of state to develop their own election security resources and training for county and local jurisdictions.
Why it matters: Election officials and security professionals supporting voting infrastructure now face legal uncertainty and reduced federal assistance, requiring them to independently secure election systems and reassure voters while defending against both technical threats and federal policy pressure.
- regulatory
EU leaders eye social media ban for children under age 13
European Commission President Ursula von der Leyen indicates that EU leaders are moving toward establishing a minimum age requirement for social media access, potentially around 13 years old, though final decisions remain with parents and member states. The statement reflects growing consensus among European policymakers that age-based restrictions on social media use warrant coordinated action.
Why it matters: Organizations operating social media platforms in the EU should monitor upcoming legislative proposals, as age-gating requirements could trigger significant compliance obligations and potentially affect user acquisition strategies in European markets.
- breaches incidents
Japan's largest taxi operator shuts systems after cyberattack
Japan's largest taxi operator, Nihon Kotsu, experienced a cyberattack that compromised its systems, prompting the company to shut down portions of its infrastructure.
Why it matters: Transportation operators and critical service providers need to monitor this incident as a model for response procedures and potential cascading effects on public mobility infrastructure.
- breaches incidents
Apple says former employee exploited ‘rare’ bug to download confidential files after leaving for OpenAI
Apple says a former employee who departed for OpenAI exploited a rare bug to download confidential files from Apple's network after leaving the company. Apple declined to comment further on the incident.
Why it matters: Enterprise security teams should assess whether similar authentication or privilege-management bugs exist in their systems, as extended post-departure access to sensitive data represents a critical control failure.
- threat intel
Hackers backdoor Jscrambler npm package with infostealer malware
A malicious version of the Jscrambler npm package was published containing infostealer malware and downloaded approximately 1,500 times before discovery. Jscrambler, a client-side web security company, disclosed the compromise of its package distribution on npm.
Why it matters: Developers who downloaded the compromised Jscrambler npm package between the malicious release and its removal face exposure to infostealer malware; immediate verification of installed versions and audit of any systems that ran the package is critical.
- threat intel
New CrashStealer malware poses as Apple crash reporting tool
CrashStealer is a new macOS information stealer that masquerades as Apple's crash-reporting tool to harvest credentials, keychain data, and cryptocurrency wallet information. The malware achieves persistence through social engineering by disguising itself as a legitimate system component.
Why it matters: Mac users and organizations managing macOS environments need to monitor for this threat, as it targets sensitive credentials and financial assets through a trusted-appearing system utility.
- ransomware
VPN service favored by ransomware groups is sanctioned by US
The U.S. Treasury Department sanctioned First VPN Service (1VPNS) and its Ukrainian administrator for facilitating ransomware operations. In a separate action, a Belarusian individual was also sanctioned for distributing malware encryption tools.
Why it matters: Organizations using 1VPNS or interacting with sanctioned parties face legal and operational risk; practitioners should audit VPN usage and ensure compliance with Treasury sanctions to avoid secondary penalties.
- breaches incidents
NG: Zenith Bank, Others To Be Arraigned Over Alleged Data Breach
The Federal High Court in Abuja scheduled July 21, 2026, for the arraignment of Zenith Bank and three individuals accused of unlawfully accessing and disclosing confidential financial records belonging to Makers Island Company Limited. The case involves allegations of data breach and improper disclosure of sensitive information.
Why it matters: Financial institutions and their employees face legal exposure for data handling practices; practitioners should monitor this case for precedent on corporate and individual liability for unauthorized access to customer financial data.
- ai security
'Yellow Teams' Are Defining the Future of AI Security
Some companies are deploying engineers to build both defensive and offensive tools that test artificial intelligence capabilities in cybersecurity contexts. These 'yellow teams' evaluate AI's potential to strengthen security postures while identifying risks and vulnerabilities in AI systems themselves.
Why it matters: Security practitioners need to understand how AI is being weaponized and defended against, as yellow teams are shaping the defensive standards and threat models that will determine organizational AI security maturity.
- breaches incidents
Google and Microsoft Pull ModHeader With 1.6 Million Installs After Dormant Collector Found
Google and Microsoft removed ModHeader, a browser extension with approximately 1.6 million installations, after security researchers discovered a dormant data collector embedded in the official store version. The collector remained inactive due to an empty allowlist and showed no evidence of having transmitted any user browsing data.
Why it matters: Users of ModHeader on Chrome and Edge face potential privacy exposure if the extension's developer activates the collection mechanism in future updates; practitioners should audit installed extensions and verify legitimate functionality.
- breaches incidents
Russian celebrity journalist Ksenia Sobchak says hackers accessed Telegram channels via email breach
Russian journalist Ksenia Sobchak reported a breach of her Telegram channels through a compromised email account and disputed the authenticity of published correspondence screenshots with political figures. The incident follows unauthorized access to her accounts and the subsequent circulation of disputed communications.
Why it matters: Practitioners managing high-profile accounts should review email security controls and Telegram session management, as account compromise via email remains a common pivot point to messaging platforms used by public figures.
- cloud saas
Microsoft Entra ID security updates: Passkeys are the default authentication method in Entra ID
Microsoft Entra ID will make passkeys the default authentication method beginning September 1, 2026, automatically enrolling users currently using SMS or voice authentication. SMS and voice authentication will be retired as native Microsoft Entra capabilities on February 1, 2027, though organizations can continue using these methods through third-party telecom partners via the Microsoft Security Store at additional cost.
Why it matters: Identity and access practitioners must plan user migration to passkeys before September 2026 to avoid service disruptions and reduce phishing and credential theft risk, particularly as AI-enabled attacks grow more effective.
- threat intel
GigaWiper Lets Threat Actors Choose Their Own Destructive Attack
Security researchers identified GigaWiper, a modular implant that combines backdoor and wiper capabilities from multiple malware families to enable flexible destructive attacks. The tool allows attackers to customize their operations while reducing the need for separate tools and coordinating multiple distinct malware deployments.
Why it matters: Organizations and defenders need visibility into this modular threat because it reduces attacker overhead and increases the risk of rapid, tailored destruction following initial compromise, requiring enhanced detection and response capabilities.
- threat intelCVE-2008-4128CVE-2018-0171
Officials once again warn defenders that Russian hackers are targeting network devices
Russian FSB Center 16 (tracked under multiple names including Berserk Bear and Dragonfly) has conducted sustained targeting of critical infrastructure globally by exploiting poorly configured and outdated networking devices, particularly Cisco routers with default credentials and unpatched vulnerabilities. A joint cybersecurity advisory from the United States and 12 allied nations on Monday detailed the group's tactics and recommended defenses including disabling Cisco Smart Install, enforcing strong authentication, and monitoring local account activity. The warning follows a December 2025 attack attributed to FSB Center 16 on Poland's energy grid and comes nearly a year after similar alerts.
Why it matters: Critical infrastructure defenders across defense, energy, communications, financial services, healthcare and government sectors must urgently review Cisco device configurations and apply defensive measures, as this Russian state-sponsored group has demonstrated both capability and intent to disrupt essential services in allied nations.
- ai security
Now, defenders are embracing the prompt injection, too
Researchers from Tracebit discovered that defenders can embed prompt injections into stored secrets on AWS to disable attacking AI agents. By placing specially crafted prompts alongside passwords and cryptographic keys, the LLM encounters instructions that violate its safety guardrails and halts its operation.
Why it matters: Organizations defending against AI-powered attacks can adopt this technique to neutralize automated agents, providing a new layer of protection for systems storing sensitive credentials on cloud platforms.
- ransomware
⚡ Weekly Recap: ShareFile Threat, Citrix Bleed 2 Ransomware, AI Coding Attacks, and More
A weekly security recap highlights multiple threats including ShareFile vulnerabilities, Citrix Bleed 2 ransomware activity, and AI-powered coding attacks. The piece emphasizes that while security tools automate vulnerability discovery, attackers similarly leverage automation to find and exploit weaknesses, and many organizations remain unpatched against known issues from prior years.
Why it matters: Security teams need to prioritize patching ShareFile and Citrix systems immediately, monitor for Citrix Bleed 2 ransomware indicators, and assess exposure to AI-assisted vulnerability discovery attacks; delayed patching of known bugs creates direct exploitable gaps.
- breaches incidents
Lessons Learned from CISA’s Recent GitHub Leak
CISA experienced a six-month exposure of internal credentials, including AWS GovCloud administrative keys, after a contractor published sensitive data to a public GitHub repository in May 2026. The agency's postmortem identified delays in secret rotation, unclear incident reporting channels, and gaps in monitoring public code repositories as contributing factors. CISA has since committed to improving key management practices, establishing clearer reporting procedures, and implementing continuous scanning for exposed secrets.
Why it matters: Security teams managing sensitive credentials and cloud infrastructure should learn from CISA's failures: establish multiple, prominent reporting channels for security researchers, implement continuous secret scanning across public repositories, develop incident response playbooks that cover cloud services like GitHub, and ensure key rotation can execute quickly when exposure occurs.
- vulnerabilities
Effective Patch Management Strategies: 7 Best Practices | Huntress
This article presents guidance on patch management strategies, offering seven best practices for organizations to address vulnerabilities systematically and reduce the attack surface available to threat actors.
Why it matters: Security teams and infrastructure managers need effective patch management to prevent exploitation of known vulnerabilities, which remains a primary attack vector across most environments.
- government policy
EU and UK blacklist Russia’s cyber operators over efforts to destabilize Europe
The EU and UK jointly imposed sanctions against Russian individuals and entities accused of coordinating a cyber ecosystem targeting Europe and its allies. The UK sanctioned 24 targets while the EU restricted nine individuals and four entities involved in cyber operations to destabilize the region.
Why it matters: Organizations and governments across Europe and allied nations should monitor for connections to these sanctioned actors and enforce compliance with new restrictions; practitioners need to assess exposure to Russian cyber operations and update threat intelligence feeds accordingly.
- industry
Hacker Conversations: Jesse McGraw (GhostExodus), From Blackhat Hacker to Redemption
Jesse McGraw, formerly known as GhostExodus, transitioned from a career as a blackhat hacker involving high school-era hacking and imprisonment to working as a cybersecurity advocate. The piece chronicles his personal journey and redemption arc in the security field.
Why it matters: Security practitioners may find value in understanding attacker mindsets and motivations through the perspective of a reformed hacker now working in defense.
- breaches incidents
Lidl discloses online shop breach after service provider hack
Lidl disclosed a breach affecting its online shop customers in Germany, Belgium, and the Netherlands after attackers compromised a service provider. The incident resulted in the theft of customer personal information.
Why it matters: Customers in affected regions should monitor for identity theft and fraud; practitioners managing third-party risk must treat this as a validation that vendor compromises cascade quickly to downstream users.
- government policy
LAPD lets contract with surveillance giant Flock expire, citing ‘serious concerns’ over civil liberties and privacy
The Los Angeles Police Department allowed its contract with surveillance company Flock to expire, citing civil liberties and privacy concerns. This represents a significant break from one of Flock's largest government customers over the company's surveillance capabilities.
Why it matters: Law enforcement agencies, government procurement teams, and civil liberties advocates should monitor this precedent for how major departments are reassessing surveillance technology partnerships based on privacy and civil liberties impacts.
- identity access
Breach at the Beach: Play the Ultimate Entra ID CTF
Varonis has released a free Capture the Flag (CTF) exercise called Breach at the Beach that demonstrates how attackers abuse Microsoft Entra ID through hands-on, realistic scenarios. The CTF is designed to teach security defenders how to investigate and respond to Entra ID attacks using practical attack techniques.
Why it matters: Identity and access practitioners need to understand current Entra ID attack vectors and detection techniques; this CTF provides hands-on training in a safe environment without the cost of commercial courses.
- government policy
Why cloud security is mission-critical for federal civilian and defense agencies
Cloud security has become critical for federal civilian and defense agencies as environments grow more complex, shifting from adoption decisions to securing what is already deployed at scale. Modern federal cloud infrastructures featuring multi-cloud architectures, containerized workloads, and AI applications create significant risk gaps that adversaries exploit, including misconfigured storage, overprivileged accounts, and hidden lateral movement paths. Achieving mature zero trust architecture requires deep, real-time visibility across seven pillars (users, devices, applications, data, network, automation, and analytics) to enable continuous operational discipline rather than reactive risk management.
Why it matters: Federal civilian and defense agency practitioners must prioritize cloud security visibility and zero trust implementation to prevent operational disruption, citizen data compromise, and mission degradation from configuration errors and privilege escalation.
- ai security
New MemGhost Attack Plants Persistent False Memories in AI Agents Through One Email
Researchers identified MemGhost, an attack that uses a single email to inject false memories into AI agents with email access and persistent storage. The attack hides the modification from detection and causes the agent to provide misleading information in subsequent interactions while appearing legitimate to the user.
Why it matters: Organizations deploying AI agents with email and memory capabilities face a new injection vector that undermines trust in agent-generated responses; practitioners should evaluate whether their AI systems validate and authenticate information sources before storing them as facts.
- vulnerabilities
Tidal Cyber connects assets, vulnerabilities, and threats through Threat-Led Defense
Tidal Cyber announced new capabilities for its Threat-Led Defense platform that integrate asset visibility, vulnerability prioritization, and threat intelligence based on actual adversary tactics and procedures across the attack chain. The update shifts the industry focus from static asset management and CVSS scoring toward an execution-centric approach that prioritizes exposures according to how attackers operate in practice.
Why it matters: Security teams evaluating vulnerability management tools should consider whether threat-informed prioritization helps them focus remediation efforts on the exposures adversaries are most likely to exploit.
- cloud saas
Cloudflare Precursor uses continuous behavioral analysis to stop advanced bots
Cloudflare announced general availability of Precursor, a bot management tool that uses continuous behavioral analysis running in web browsers to detect sophisticated bot automation in real time. The system monitors entire user sessions rather than relying on static CAPTCHAs, aiming to catch advanced bots while minimizing disruption to legitimate users.
Why it matters: Web administrators and security teams need to evaluate this defense against bot traffic, which now comprises 57% of all internet activity and threatens application availability, data integrity, and performance.
- threat intel
UK charges suspects linked to Russian Coms call spoofing platform
The UK's National Crime Agency investigated Russian Coms, a caller ID spoofing platform that facilitated over 1.8 million scam calls, resulting in criminal charges against five individuals. The platform enabled fraudsters to mask their identities during phone-based attacks against victims.
Why it matters: Practitioners managing fraud prevention and security operations should track this enforcement action as evidence that spoofing platforms face legal consequences, and update phone security controls to detect and block similar caller ID manipulation tactics used in current fraud campaigns.
- cloud saas
Lumen expands managed detection and response with Cortex XSIAM integration
Lumen Technologies announced Lumen Defender Advanced Managed Detection and Response for Palo Alto Networks Cortex XSIAM, combining its managed detection and response capabilities with threat intelligence from Black Lotus Labs and Cortex XSIAM's AI-driven security operations platform. The service aims to help enterprises modernize security operations and manage the accelerating threat landscape.
Why it matters: Security operations teams using Cortex XSIAM can now leverage Lumen's integrated threat intelligence and managed detection services to improve incident detection and response efficiency.
- vulnerabilitiesCVE-2025-3248CVE-2026-11405
13th July – Threat Intelligence Report
A weekly threat intelligence bulletin covering significant incidents from July 13 including data breaches at AssuranceAmerica (7 million people), Latvijas Valsts Meži (ransomware exploiting two-year-old vulnerability), Injective Labs (supply chain compromise via malicious npm packages), and Moody Bible Institute (2.3 million donors and supporters). The report also details emerging AI threats such as autonomous ransomware using language models and malicious code injection attacks against coding agents, along with critical vulnerabilities in Tenda routers, Linux KVM hypervisor, U-Boot bootloader, and Opera GX browser.
Why it matters: Organizations managing employee access, unpatched systems, and open-source dependencies face imminent compromise; cloud infrastructure operators and device manufacturers must patch critical hypervisor and bootloader vulnerabilities; developers using AI-powered coding tools need to validate and review generated code to prevent malicious instruction execution.
- threat intel
Forg365 PhaaS Targets Microsoft 365 with Device Code and AitM Session Theft
Forg365, a phishing-as-a-service operation, targets Microsoft 365 accounts using device code phishing, adversary-in-the-middle tactics, antibot evasion, and AI-generated lures distributed via Telegram. The service is available for $400 monthly or $3,800 annually and chains multiple compromise techniques.
Why it matters: Microsoft 365 administrators and security teams must monitor for device code phishing and AitM attacks, as this commercially available threat increases the likelihood that organizations will face these compromise techniques at scale.
- vulnerabilities
Threat Actors Achieve Persistence After SQL Injection
Threat actors exploited SQL injection vulnerabilities to deploy BadIIS, a persistence mechanism that allowed them to disable Windows Defender and install cryptocurrency mining software. The attack chain demonstrates how initial access through database vulnerabilities can lead to system compromise and unauthorized resource consumption.
Why it matters: Organizations running internet-facing SQL databases face immediate risk of cryptomining and system compromise if SQL injection flaws are not patched, requiring immediate vulnerability scanning and Web Application Firewall (WAF) deployment.
- threat intel
Turning the Tables on Email Scammers With 'ScamBuster'
A new open source system called ScamBuster uses artificial intelligence and victim personas to engage with phishing attackers and collect intelligence on their operations. The tool enables organizations and law enforcement to gather data on cybercriminal infrastructure and tactics.
Why it matters: Security teams and law enforcement can use this tool to disrupt phishing operations by collecting operational intelligence on attackers, reducing the success rate of social engineering campaigns targeting their organizations.
- cloud saas
Why IaC Coverage Belongs on Your Security Dashboard
Infrastructure as Code (IaC) coverage represents a funnel that tracks what portion of an organization's infrastructure is governed, traceable, and ready for rapid remediation. The article proposes reconceptualizing IaC coverage as a key security metric that should appear alongside other indicators on security dashboards.
Why it matters: Security teams need visibility into how much infrastructure is actually managed through code and auditable processes. Including IaC coverage on dashboards helps practitioners identify ungovernened infrastructure and prioritize remediation workflows.
- industry
Cybersecurity M&A Roundup: 37 Deals Announced in June 2026
A total of 37 cybersecurity mergers and acquisitions were announced during June 2026, involving major companies including 1Password, Accenture, Cisco, F5, Rubrik, and SailPoint. The article provides a roundup of these transaction announcements in the cybersecurity sector.
Why it matters: Security practitioners and vendors should track M&A activity to understand market consolidation, potential product integration timelines, and shifts in competitive landscape that may affect tool selection and partnership strategies.
- cloud saas
Fake OAuth client IDs are helping attackers slip past sign-in logs
Attackers conducting account enumeration against Microsoft cloud tenants are spoofing OAuth client IDs to evade detection in sign-in logs. By using fake identifiers in authentication requests, the attackers' probing activity avoids appearing in the normal telemetry that Microsoft Entra ID records. Microsoft and operators are working to address this detection gap.
Why it matters: Cloud administrators relying on Entra ID sign-in logs to detect unauthorized access attempts may miss account enumeration activity if attackers use spoofed OAuth client IDs, requiring review of detection rules and logging configuration today.
- threat intel
Improve Router Hygiene to Protect Against Russian State-Sponsored Targeting
Russian Federal Security Service (FSB) Center 16 cyber actors exploit poorly configured and vulnerable networking devices, particularly routers, across critical infrastructure sectors worldwide. A joint cybersecurity advisory from the NSA, CISA, FBI, and international partners details tactics used by the group, including scanning for devices with default SNMP credentials and other misconfigurations. The advisory urges network defenders to implement router hygiene measures to counter this decade-long threat.
Why it matters: Operators of critical infrastructure in communications, energy, financial services, government, and healthcare face active exploitation by a persistent Russian state-sponsored group; implementing basic router hygiene and disabling default credentials should be prioritized today.
- vulnerabilities
RabbitMQ Vulnerability Threatens Enterprise Systems
A vulnerability in RabbitMQ allows unauthenticated attackers to extract the OAuth client secret from the message broker, potentially enabling takeover of the broker itself. The flaw affects enterprise deployments relying on RabbitMQ for message handling and could allow an attacker to impersonate the broker or gain administrative access.
Why it matters: Any organization running RabbitMQ should assess exposure immediately, as unauthenticated remote exploitation could lead to full broker compromise and lateral movement within dependent applications.
- ai security
Meta Files Patent for AI That Can Listen All Day and Track How You're Feeling
Meta has filed a patent for an artificial intelligence system that continuously monitors voice patterns to infer emotional states and maintains detailed logs with timestamps, locations, and activity context. The system design includes variants ranging from continuous all-day listening to event-triggered recording modes.
Why it matters: Users and privacy advocates should monitor Meta's AI capabilities and data collection intentions, as deployed voice surveillance at scale would create persistent emotional and behavioral profiles usable for manipulation, targeted advertising, or regulatory exposure.
- breaches incidents
A cyberattack in March resulted in ZEGO filing for insolvency
ZEGO Textilveredelungszentrum GmbH, a German textile processing company, filed for insolvency following a cyberattack in March. The company announced the insolvency proceedings on its website, attributing the filing directly to the security incident.
Why it matters: Textile and manufacturing companies face operational risks from cyberattacks that can escalate to business failure; practitioners should assess whether their organizations have equivalent resilience planning and incident response protocols to prevent similar outcomes.
- ai security
Thinking Fast and Slow in the SOC: The Case for Combining Autonomous AI with Analyst Copilots
A security leader discusses integrating AI agents into security operations centers, specifically using Claude connected to detection tools for investigations. The article examines architectural considerations for combining autonomous AI with analyst copilots in SOC environments.
Why it matters: SOC leaders and security practitioners evaluating AI tooling should understand the tradeoffs between autonomous agents and human-in-the-loop copilots when designing detection and response workflows.
- government policy
EU sanctions Russian GRU military hackers over cyberattacks
The European Union and the United Kingdom announced joint sanctions against dozens of Russian individuals and entities, alleging that Russia coordinated a network of hacking groups conducting cyberattacks across Europe. The action represents an escalation in Western responses to Russian state-sponsored cyber operations.
Why it matters: Organizations across Europe should track these designated entities and individuals for potential connections to past or future attacks; the coordination acknowledgment suggests broader attribution and motive intelligence for defensive planning.
- threat intel
Attacker Uses Suspected AI-Generated PowerShell Script to Map Active Directory
Researchers identified an intrusion where an attacker deployed a suspected AI-generated PowerShell script to enumerate Active Directory, mapping domain controllers, users, computers, and domains, then exported findings to an HTML report. The actor's tooling suggests an intent to gather reconnaissance for lateral movement or further compromise within the target environment.
Why it matters: Active Directory administrators and incident responders need to monitor for suspicious PowerShell execution and AD enumeration activities, as this technique precedes lateral movement and privilege escalation attacks in Windows environments.
- ai security
AI Data Centers and the Concentration of Wealth
An essay argues that while local opposition to AI data center construction raises legitimate concerns about resource allocation, environmental impact, and job creation, this focus may distract from AI companies' larger goal of capturing value across major industries like software development, healthcare, and law. The authors contend that despite some successful campaigns against early-stage projects, well-capitalized proposals continue to advance through litigation and political support, while the real strategic prize for AI companies lies in displacing professionals across multiple sectors.
Why it matters: Technology leaders and policymakers should understand that data center opposition, while addressing real local harms, may be insufficient to address broader questions about AI's role in professional services and workforce displacement; practitioners in affected industries should prepare for AI companies' expansion beyond infrastructure into their domains.
- vulnerabilities
Zimbra Patches Critical Code Execution Vulnerability
Zimbra released a patch for a critical vulnerability that allows arbitrary code execution when users open specially crafted emails. The flaw enables attackers to embed malicious code in email messages that executes upon opening.
Why it matters: Organizations running Zimbra mail servers face immediate risk of compromise if attackers send crafted emails to users; apply the patch without delay.
- breaches incidents
A Leak of San Francisco Police Drone Footage Exposes the New Reality of Urban Surveillance
San Francisco Police Department (SFPD) experienced a leak of drone footage captured by a Skydio platform, exposing the extent of aerial surveillance operations conducted over the city. The incident demonstrates how sensitive video data from law enforcement surveillance systems can be inadvertently exposed online.
Why it matters: Urban residents and civil liberties advocates need to understand the scope of surveillance infrastructure now in use and the data security risks when footage becomes public.
- government policy
EU Targets Russian Intelligence Officers Accused of Running a Yearslong Cyber Spying Campaign
The European Union imposed sanctions against Russian intelligence officers accused of operating a prolonged cyber espionage and sabotage campaign. The targeted network allegedly conducted surveillance against government entities and critical infrastructure operations.
Why it matters: Organizations managing critical infrastructure, government agencies, and EU member states need to assess their exposure to Russian state-sponsored cyber operations and strengthen defensive measures accordingly.
- threat intel
US and allies warn of Russian critical infrastructure attacks
Cybersecurity agencies from the United States and eight allied nations released a joint warning that Russian state-sponsored hackers are exploiting vulnerable and misconfigured routers to gain access to critical infrastructure networks. The campaign represents a continued effort by Russian threat actors to establish footholds in essential systems that could be leveraged for future attacks or disruptions.
Why it matters: Critical infrastructure operators and network defenders need to audit router configurations, apply patches, and monitor for unauthorized access to prevent espionage, operational disruption, or sabotage by a well-resourced adversary.
- cloud saas
FastNetMon eliminates third-party bgp lookups with Netomics
FastNetMon launched Netomics, a self-hosted platform that consolidates BGP routing intelligence, including live routing data, registry information, RPKI validation, routing history, and AI-assisted querying. The tool is designed for ISPs, cloud providers, Internet Exchange Points, and enterprises to gain visibility into global internet routing without relying on external lookup services. Network engineers can investigate routing incidents and validate prefixes from a single application.
Why it matters: Network operators responsible for large IP networks benefit from reducing dependency on third-party services and gaining faster incident response capabilities for routing issues.
- vulnerabilities
Organizations Warned of Exploited Joomla Extension Vulnerabilities
Threat actors are actively exploiting vulnerabilities in two Joomla extensions, Balbooa Forms and iCagenda, to achieve remote code execution. Security agencies have issued warnings about these attacks targeting organizations using the affected components.
Why it matters: Joomla administrators and organizations running these extensions face immediate risk of code execution and system compromise; patching or removing affected extensions should be prioritized.
- cloud saas
Claude Code users keep 50% higher limits until July 19
Anthropic has extended a promotional offer that grants Claude Code users on Pro, Max, and Team plans 50% higher weekly usage limits through July 19, 2026. After the promotion concludes, usage limits will revert to standard levels without affecting plan terms or costs. Free and consumption-based Enterprise plans are excluded from the offer.
Why it matters: Claude Code users on qualifying plans should plan for reduced capacity after mid-July 2026 if they depend on the elevated limits for their development workflows.
- ai security
AI-generated code has made security debt a governance problem
AI-generated code accelerates software development but creates security governance challenges as the volume of code changes outpaces organizations' ability to review, test, and remediate issues. Security teams face a mismatch between machine-speed code generation and human-scale security processes, allowing security debt to accumulate rapidly through insecure patterns, unsafe dependencies, and supply chain risks that AI tools reproduce from training data. Organizations must establish controls for AI-generated code as high-risk input, shift from measuring vulnerabilities to measuring risk velocity, and pair shift-left approaches with automation and remediation capacity.
Why it matters: CISOs and security leaders must urgently assess whether their application security programs can govern AI-assisted development at scale; failure to do so results in compounding security debt that will eventually constrain business operations and expose supply chains to compromise.
- vulnerabilities
Progress Prompts ShareFile Storage Zone Controller Shutdown Amid Security Concerns
Progress Software advised customers to manually shut down their ShareFile Storage Zone Controller servers while the company investigates a credible security threat. The advisory represents a significant disruption requiring immediate operator intervention across affected deployments.
Why it matters: Organizations running ShareFile Storage Zone Controller need to execute an emergency shutdown now to mitigate the active threat; delay increases risk of compromise.
- breaches incidents
Centers Laboratory Data Breach Affects 540,000 Individuals
WorldLeaks extortion group claims to have stolen 720 GB of data from healthcare testing and laboratory services provider Centers Laboratory, affecting approximately 540,000 individuals.
Why it matters: Healthcare customers and patients whose laboratory records may have been exposed face identity theft and medical fraud risks; organizations should prepare breach notification and forensic investigation procedures.
- threat intel
Misconfigured Server Reveals Three Evilginx Phishing Operations Targeting Microsoft 365
A misconfigured Python web server exposed the toolkit of an attacker conducting Microsoft 365 phishing operations. The exposed directory listing and bash history allowed Lexfo to recover the operator's files and pivot to identify two additional related phishing campaigns using Evilginx, a credential-theft framework.
Why it matters: Practitioners should review their incident response procedures for phishing attacks targeting Microsoft 365 accounts, as this exposure indicates active, multi-operation credential harvesting infrastructure in use.
- vulnerabilities
Why SBOMs, signing, and provenance still don’t tell you if software is safe
Software supply chain security has improved through adoption of SBOMs (Software Bill of Materials), code signing, and provenance tracking, largely driven by Executive Order 14028. However, these measures provide visibility and authenticity verification without addressing the core question of what code can actually do at runtime and what behavioral risks it poses.
Why it matters: Security practitioners relying solely on SBOMs, signatures, and provenance data may have a false sense of confidence; organizations need additional runtime behavior analysis and permissions-based controls to fully assess software risk before deployment.
- ai security
Cynative: Open-source deep research agent
Cynative is an open-source security research agent designed to safely use large language models for cloud security assessments. The tool mitigates the risk of an AI agent accidentally modifying cloud resources or exposing secrets by defaulting to read-only operations and enforcing those restrictions on every API call.
Why it matters: Security teams evaluating automated cloud security scanning need safe tools that can audit infrastructure without risk of unintended modification or credential exposure.
- vulnerabilitiesCVE-2026-48939
iCagenda and Balbooa Forms Joomla Flaws Reportedly Exploited as Zero-Days
The Cybersecurity and Infrastructure Security Agency (CISA) added two maximum-severity flaws affecting iCagenda and Balbooa extensions for Joomla to its Known Exploited Vulnerabilities catalog after reports of active exploitation in the wild. Both vulnerabilities received a CVSS score of 10.0, the highest severity rating.
Why it matters: Joomla administrators running iCagenda or Balbooa extensions face immediate risk from active exploitation; patching or disabling these extensions should be prioritized today.
- vulnerabilities
Microsoft demystifies how Windows updates work
Microsoft published a guide explaining its Windows servicing model, including the cadence and types of updates such as monthly security patches on the second Tuesday, optional preview releases, and hotpatch mechanisms. The documentation outlines how the company delivers security fixes and new features to Windows systems throughout the year.
Why it matters: IT administrators and security teams should review this guide to understand Microsoft's update schedule and plan patch management cycles accordingly.
- ai security
A hardware security AI assistant that checks chips for hidden backdoors
Researchers at the University of Florida developed an AI-based tool to detect hidden backdoors in semiconductor designs by analyzing circuitry from third-party vendors that is incorporated into larger chips. The approach addresses the supply chain risk where malicious suppliers could embed dormant circuits that activate only under specific conditions. The tool aims to identify such compromised components before chips reach production.
Why it matters: Chip designers and semiconductor manufacturers need visibility into third-party IP blocks to prevent supply chain attacks that could compromise millions of deployed devices; this detection method offers practical security for complex processor designs.
- ai security
99.9% of fixable AI vulnerabilities remain unpatched
Orca Security's 2026 State of AI Security Report reveals that 81.2% of organizations running AI packages contain at least one known vulnerability, with 99.9% of fixable AI vulnerability alerts remaining unpatched. The research indicates that firms prioritize speed over basic security practices when building and deploying AI in cloud environments, and more than half have already moved agent frameworks and custom AI applications into production.
Why it matters: Security teams and cloud practitioners need to assess their AI deployments for known vulnerabilities immediately, as the vast majority of fixable issues remain unaddressed across the industry and create exploitable gaps in production systems.
- ai security
Someone Is Scanning for Your MCP Servers and AI Assistant Credentials
Distributed scanners at internet scale are systematically probing for Model Context Protocol (MCP) servers, AI assistant configuration files, and locally exposed large language model endpoints, including sending valid JSON-RPC 2.0 handshakes to test for functional MCP implementations. The scanning activity, originating from 49 distinct IP addresses over a two-week period, also targets AI assistant credential and configuration files from tools like Claude and Cursor that developers may accidentally expose in web roots.
Why it matters: Organizations running MCP servers or accidentally exposing AI assistant configuration files face immediate risk of credential theft and unauthorized access to databases, file systems, and internal APIs that connected agents can reach; practitioners should audit web roots for .claude, .cursor, and .mcp files and ensure any internet-exposed MCP servers require authentication.
- cloud saas
Enterprises are rethinking where their AI applications run
Enterprises are reassessing infrastructure choices for AI applications based on compute, power, cooling, and latency requirements. Public cloud remains popular for experimentation and fast deployment, while colocation facilities are gaining adoption for workloads demanding predictable performance and dedicated resources. More than half of surveyed organizations have implemented or are upgrading AI technologies.
Why it matters: Infrastructure and operations teams should evaluate whether current cloud deployments meet AI workload performance and cost requirements, and consider colocation as a complement for latency-sensitive or resource-intensive applications.
- threat intel
Now Available: The Threat Brief Library in the GreyNoise Platform
GreyNoise launched a Threat Brief Library within its Visualizer platform that allows users to access, search, and download weekly threat intelligence reports and executive summaries derived from its sensor network data.
Why it matters: Security teams using GreyNoise can now consolidate threat intelligence consumption within the platform, potentially reducing time spent gathering and reviewing external threat reports.
- government policy
Russia's FSB blamed for Poland grid attack as UK and EU impose first joint cyber sanctions
The UK and EU have jointly sanctioned Center 16, Russia's FSB signals intelligence unit, for conducting cyber attacks against Poland's energy sector and water treatment facilities. The sanctions represent the allies' first coordinated response to Russian cyber threats and encompass a broader pattern of escalating malicious cyber activity.
Why it matters: Energy and water infrastructure operators in Poland and similar targets elsewhere face active nation-state threats; practitioners should review defensive postures against FSB-attributed techniques and monitor for related attack indicators.
- research
Guide to System Hardening: Checklist & Best Practices [2026] | Huntress
A Huntress guide presents a checklist and best practices for system hardening to reduce vulnerabilities that threat actors can exploit. The resource covers practical steps to secure computing environments and address common security gaps.
Why it matters: Security practitioners implementing endpoint and infrastructure hardening need current guidance on which configurations provide the most protection against common attack vectors.
- threat intel
Cybersecurity Awareness Month is Ending, but Holiday Threats Are Just Getting Started | Huntress
This article advocates for maintaining cybersecurity awareness beyond October and offers guidance for protecting organizations during the holiday season, when threat activity typically increases.
Why it matters: Security practitioners and end users should refresh their awareness practices and implement holiday-specific defenses as adversaries intensify social engineering and exploitation campaigns during year-end periods.