2026-07-17
- threat intel
New North Korean campaign uses fake coding interviews to steal developer credentials
Elastic Security Labs discovered a North Korean-aligned campaign, tracked as REF9403, that uses fake job postings and coding challenges to distribute malware hidden in SVG image files via steganography. The trojanized code repositories appear functional but install a four-stage payload including credential and wallet stealers, file exfiltration, a Socket.IO-based remote access trojan, and clipboard stealing capabilities. The campaign demonstrates how threat actors target developers to establish initial access for downstream supply chain attacks.
Why it matters: Developers are at direct risk from social engineering in forums and job boards; compromising a single developer can provide attackers entry into their employer's systems and supply chain, making this a critical threat for security teams managing developer access and code review processes.
- vulnerabilitiesCVE-2026-15409CVE-2026-15410
Proxying to Compromise: SonicWall Secure Mobile Access 0-day Exploitation
In early July 2026, incident responders at Volexity discovered that threat actor UTA0533 had exploited multiple zero-day vulnerabilities in SonicWall Secure Mobile Access VPN appliances, including a server-side request forgery (SSRF) flaw and command injection vulnerability affecting the 1000 series models. Analysis of compromised devices revealed the attacker had deployed custom malware and gained remote code execution through a chain of exploits beginning in late June 2026. SonicWall released patches addressing CVE-2026-15409 and CVE-2026-15410 in versions 12.4.3-03453 and 12.5.0-02835.
Why it matters: Organizations running SonicWall SMA VPN appliances face active exploitation of zero-day vulnerabilities by a tracked threat actor; immediate patching to the latest firmware versions and investigation of logs for suspicious /wsproxy requests are required to detect and remediate potential compromises.
- cloud saas
The Zoom hack that says, ‘Don’t record me’
A commentary on the proliferation of recording and transcription features in video conferencing platforms like Zoom, questioning whether ubiquitous automated transcription and summarization serves practical value or creates information overload.
Why it matters: Practitioners managing security policies and employee monitoring tools should consider the risk exposure and compliance implications of automatic recording and transcription across their communication platforms.
- vulnerabilitiesCVE-2026-63030
New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code
A critical vulnerability in WordPress core versions 6.9 and 7.0 allowed unauthenticated attackers to execute arbitrary code on unpatched installations. WordPress released patches (6.9.5 and 7.0.2) on Friday and deployed forced updates through its auto-update mechanism. Adam Kues at Assetnote discovered the flaw and coordinated its disclosure.
Why it matters: WordPress site operators must verify they are running 6.9.5, 7.0.2, or newer immediately, as this unauthenticated remote code execution affects core installations with no plugins and requires only a bare HTTP request to exploit.
Friday Squid Blogging: Squid Washing Up on Cape Cod Beach
This post covers squid washing up on Cape Cod beaches and invites readers to discuss recent security news not covered elsewhere on the blog. The article provides minimal substantive security content and primarily serves as an open forum for community discussion.
Why it matters: Not applicable; this is a community discussion thread without specific security events or findings requiring practitioner action.
- breaches incidents
Abbott Laboratories probes two cyber incidents amid extortion claims
Abbott Laboratories is investigating two separate cybersecurity incidents involving unauthorized access to internal legacy Exact Sciences systems within its Cancer Diagnostics business and alleged breaches of its LabCentral portal with claims of data theft and extortion. The company has confirmed one incident while evaluating the second claim. Both events underscore vulnerabilities in legacy systems and third-party integrated platforms used by healthcare organizations.
Why it matters: Healthcare providers, diagnostic labs, and patients whose medical data may be stored in these systems face potential data exposure and disruption of cancer diagnostic services; Abbott should immediately notify affected parties and assess the scope of stolen data.
- ransomware
Inc Ransomware Exploits SonicWall SMA Zero-Days
Two zero-day vulnerabilities in SonicWall Secure Mobile Access (SMA) appliances can be chained together to grant attackers root-level access. The Inc ransomware group is actively exploiting these flaws against targeted organizations.
Why it matters: Organizations using SonicWall SMA appliances face immediate compromise risk; prioritize applying patches and monitoring for unauthorized access if you operate these devices.
- vulnerabilities
Metasploit Wrap Up: An HTTP to SMB relay plus Payload Improvements
Rapid7 announced a shift to bi-weekly Metasploit Wrap Up posts to allow time for demo recording. The team enhanced the Fetch Payloads implementation with a new Linux Fetch Multi family that automatically detects target architecture and serves the appropriate ELF binary, eliminating the need for users to manually select the correct architecture payload.
Why it matters: Red teamers and penetration testers using Metasploit can now deploy single payloads across multiple Linux targets with different architectures, reducing operational friction and payload configuration errors during engagements.
- threat intel
Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RAT
Researchers identified seven malicious npm packages targeting the Vite frontend build tool ecosystem. The attack, labeled ViteVenom, leverages a blockchain-based command-and-control infrastructure across multiple chains as part of a broader ChainVeil campaign.
Why it matters: JavaScript developers using Vite are at immediate risk of supply chain compromise through dependency installation; teams should audit npm dependencies and verify package sources.
- vulnerabilities
HollowByte DDoS flaw bloats OpenSSL server memory with 11-byte payload
A vulnerability called HollowByte enables unauthenticated attackers to trigger denial-of-service conditions on OpenSSL servers using an 11-byte malicious payload. The flaw causes excessive memory consumption on affected servers, degrading availability without requiring authentication or complex exploitation techniques.
Why it matters: OpenSSL operators and infrastructure teams need to assess exposure immediately, as any internet-facing OpenSSL service can be targeted with minimal network overhead by remote attackers.
- threat intel
New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens
A Go-based botnet named NadMesh emerged in early July 2024, targeting exposed AI services to harvest AWS keys and Kubernetes tokens. The malware uses Shodan scanning to identify vulnerable instances of tools like ComfyUI, Ollama, and Gradio that are often deployed without adequate firewall protection. The operator's dashboard reportedly tracks over 3,800 unique AWS credentials stolen from these compromised systems.
Why it matters: Organizations deploying AI services and container orchestration platforms need immediate inventory and network segmentation of these tools, as exposed credentials grant direct access to cloud infrastructure and data stores.
- ai security
The Real AI Threat Is Blind Trust
The article contends that AI systems given authority to both understand and act on commands without human intervention create security risks by removing accountability checkpoints. This combination of interpretation and execution capabilities bypasses traditional cybersecurity controls designed to catch errors or malicious behavior before they occur.
Why it matters: Security practitioners should evaluate AI deployment architectures to ensure human oversight remains in place for critical decisions, particularly when AI systems control sensitive systems or resources.
- threat intel
GoldenEyeDog Subgroup Linked to DigiCert Breach and Code-Signing Certificate Theft
Cybersecurity researchers have attributed the April 2026 DigiCert security incident to a threat activity cluster called CylindricalCanine, identified as a subgroup of GoldenEyeDog, a Chinese cybercrime group known for targeting gambling and gaming sectors. The breach resulted in the theft of code-signing certificates from the certificate authority. Expel published technical details of the incident and the threat actor's methods.
Why it matters: Organizations relying on DigiCert-issued code-signing certificates face elevated risk of supply chain attacks, as stolen certificates can be used to sign malicious software; practitioners should audit certificate usage and implement additional code-signing verification controls.
- threat intel
FBI arrests man accused of using Steam games to drain victims’ crypto wallets
A 21-year-old student was arrested for distributing malware-laden fake games on Steam that infected thousands of users and stole cryptocurrency from victims. The scheme involved publishing multiple fraudulent titles on the platform to deliver the malicious payload at scale.
Why it matters: Organizations and users need awareness that legitimate game distribution platforms can host malware; practitioners should monitor for compromised accounts and advise clients on vetting software sources and enabling transaction monitoring for crypto wallets.
- threat intel
Microsoft at Black Hat USA 2026: Defending trust in the age of AI and supply chain attacks
Microsoft is presenting at Black Hat USA 2026 on August 4-6 in Las Vegas, highlighting how threat actors exploit trusted software, services, and developer tools to scale attacks across supply chains and AI systems. Key sessions include David Weston's keynote on defense when offensive capability becomes scalable, and a presentation on active npm (Node package manager) supply chain attacks. Microsoft will showcase new expert-led threat intelligence services and multicloud coverage for its Defender Experts offering.
Why it matters: Security teams and SOC leaders need to understand how threat actors abuse trusted paths in software ecosystems and developer workflows to prioritize their defense strategies before these vulnerabilities become active attack vectors in their environments.
- government policy
State officials, election experts pan Trump speech: ‘This is what desperation looks like’
President Trump delivered a primetime speech on Thursday making claims about election interference and noncitizen voter registration, but election officials and security experts dismissed the allegations as recycled, debunked theories with no supporting evidence. Declassified documents reviewed thus far have not validated claims about Chinese interference affecting the 2020 election, and Trump's assertion about hundreds of thousands of noncitizen voters contradicts state audits consistently finding only single or double-digit numbers. Election officials and experts noted the administration provided little methodology for its citizenship verification process and criticized the approach as unreliable.
Why it matters: Election security practitioners and state officials should be prepared to respond to these claims with factual corrections, as repeated unsubstantiated allegations undermine public confidence in election systems and may trigger resource-intensive fact-checking and communication efforts.
- cloud saas
Amazon fixing bug that billed some AWS customers billions of dollars
Amazon Web Services experienced a billing calculation error that generated inflated bill estimates for some customers, showing charges in the billions of dollars. The company is working to resolve the issue. The error appears to have been temporary and affected bill display rather than actual charges.
Why it matters: AWS customers should verify their actual billing records and contact AWS support if they see unexplained large charges or estimates, as this bug may affect cost visibility and financial planning.
- breaches incidents
Ernst & Young discloses data breach after support system hack
Ernst & Young discovered and is notifying customers of a data breach stemming from a compromise of a third-party support ticket system used by its IT staff. The breach exposed customer information through the compromised support platform. Ernst & Young is working to address the incident and notify affected parties.
Why it matters: Ernst & Young clients and prospects should determine what data was exposed in the support system breach and verify whether their information was affected, as a major consulting and audit firm's customer database represents a high-value target for further attacks.
- threat intel
In Other News: Iran Tracks US Military Phones, CrashStealer macOS Malware, CVD Blueprint
A roundup of security news includes OpenClaw artificial intelligence (AI) agents being exploited through WhatsApp, ransomware targeting naval defense contractor TKMS, and a data breach disclosure from Lidl. Additionally, reports cover Iranian tracking of US military phones, CrashStealer malware affecting macOS systems, and developments in coordinated vulnerability disclosure (CVD) practices.
Why it matters: Security teams should monitor AI agent vulnerabilities in consumer messaging platforms, track ransomware campaigns against defense suppliers, assess exposure from retail breaches, and understand nation-state phone tracking capabilities alongside emerging malware and disclosure frameworks.
- threat intel
Leading members of Scattered Spider sentenced in UK to 66 months in jail
Two young men, Thalha Jubair and Owen Flowers, were sentenced to 66 months in jail by UK courts for their roles in a 2024 cyberattack on Transport for London. Both were leading members of Scattered Spider, a cybercriminal group responsible for at least 120 attacks including extortion targeting 47 U.S. organizations, the federal court system, and healthcare companies, with traced cryptocurrency payments exceeding $89.5 million. UK authorities claimed the arrests effectively halted the group's operations, though the FBI noted other cybercriminals continue to exploit the Scattered Spider brand in ongoing attacks.
Why it matters: Organizations globally remain targeted by Scattered Spider members and copycat actors using the group's social engineering and extortion playbook; security teams should expect continued attacks despite these arrests and monitor for actors claiming Scattered Spider affiliation.
- threat intel
Inside the Search for "Clean" Residential Proxies for Carding
Residential proxies have become less effective for carding attacks as fraud detection systems have evolved. Cybercriminals now seek "clean" residential proxies and layer them with browser fingerprints, device profiles, and other identity signals to bypass modern defenses.
Why it matters: Fraud and risk teams must understand how attackers combine multiple evasion techniques beyond basic proxies to protect payment systems and e-commerce platforms from carding attacks.
- threat intel
Fake Coding Tests Deliver OtterCookie-Aligned Malware Hidden in SVG Flag Images
North Korean threat actors conducting the Contagious Interview campaign are using fake job postings and coding challenges to deliver malware hidden within SVG image files through steganography. Users executing the malicious projects receive a four-stage payload aligned with OtterCookie, which steals browser credentials, cryptocurrency wallets, and files.
Why it matters: Development teams and job seekers are targeted through recruiting fraud; practitioners should educate staff on vetting coding challenges and reviewing suspicious project files before execution.
- ai security
Gold Eagle Clearinghouse Targets Security Gap, But How Is Unclear
The White House launched Gold Eagle, a clearinghouse designed to coordinate vulnerability response in AI systems, though implementation details remain uncertain. The initiative addresses gaps in how security vulnerabilities are managed as artificial intelligence becomes more prevalent across infrastructure.
Why it matters: Practitioners should understand how Gold Eagle will affect vulnerability disclosure, reporting, and remediation timelines for AI-related security issues in their systems and third-party tools.
- ransomware
Spirals ransomware locks down victim systems in under 24 hours
Symantec researchers discovered a previously unknown ransomware variant called Spirals used in an attack against an IT services company in South Asia last month. The attackers achieved data theft and network encryption in under 24 hours from initial access. Spirals is written in Rust and uses AES-128 encryption with per-file keys wrapped using ECDH.
Why it matters: IT services companies and their customers in South Asia face rapid encryption attacks; practitioners should monitor for Spirals indicators of compromise and review detection capabilities for Rust-based malware that moves quickly through networks.
- ai security
Podcast: Broken Governance, Agentic AI, and the MindStone Agent Exclusive
SecurityWeek published a podcast discussing how artificial intelligence, particularly agentic AI systems, is transforming cybersecurity while governance, compliance, and security practices may lag behind the pace of change.
Why it matters: Security leaders and governance teams need to understand emerging AI deployment risks and evaluate whether current compliance frameworks and security controls are adequate for autonomous AI agents in their environments.
- cloud saas
Google Bets 'Agentic Defense' Strategy Can Outpace Attackers
Google Cloud has integrated Wiz capabilities into a platform designed to automate threat detection and remediation using agentic approaches. The integration aims to address emerging AI-driven attacks through automated defense mechanisms.
Why it matters: Cloud security practitioners need to understand how automated defense systems may detect and respond to modern threats, particularly those leveraging AI, to evaluate whether these tools fit their incident response workflows.
- government policy
E.U. Orders Google to Open Android Mic, Camera and Screen to Rival AI Assistants
The European Commission has ordered Google to grant rival AI assistants the same access to Android hardware and functionality that Gemini currently enjoys, including camera, microphone, screen content, wake-word activation, and the ability to control other applications. Google must implement these changes in Android 18, with a compliance deadline of August 1, 2027.
Why it matters: Device manufacturers, app developers, and competing AI assistant providers need to understand this interoperability mandate will reshape Android's feature access and competitive dynamics in the EU market.
- industry
Beacon Security Raises $13 Million for Security Data Platform
Beacon Security, a startup focused on security data platforms, has raised $13 million in funding. The company provides detection, hunting, and asset protection capabilities across multiple environments at scale.
Why it matters: Security teams evaluating data-driven threat detection platforms should monitor Beacon's product roadmap, as increased funding typically accelerates feature development and integration options.
- government policy
The Race to Field Military Autonomy Is On, Can Trusted Information Infrastructure Keep Pace?
Military organizations across the U.S., UK, and NATO are accelerating deployment of autonomous capabilities through increased investment and streamlined acquisition processes. The article introduces a shift in focus toward trusted information infrastructure to support rapid fielding of these systems.
Why it matters: Security practitioners supporting defense and military operations need to understand how accelerated autonomous capability deployment affects the security architecture, threat surface, and validation requirements for critical military systems.
- regulatory
Industry Reactions to Pentagon Suspending CMMC Phase 2: Feedback Friday
The Department of Defense suspended the Cybersecurity Maturity Model Certification (CMMC) Phase 2 program, which paused third-party audits of defense contractors. Industry stakeholders acknowledged that while the audit moratorium is in effect, the legal requirement to protect controlled unclassified information (CUI) remains in force.
Why it matters: Defense contractors must maintain CUI protection controls and compliance posture despite the pause in formal CMMC Phase 2 audits, as the underlying obligation persists and audits may resume.
- vulnerabilities
New Windows LegacyHive zero-day gives hackers admin privileges
A security researcher has disclosed a Windows zero-day vulnerability called LegacyHive that enables privilege escalation to administrator level on current Windows systems. The exploit was published publicly by the researcher operating under the alias Nightmare Eclipse.
Why it matters: Windows administrators and security teams must assess exposure immediately, as the vulnerability affects supported systems and public exploit code is now available; patching or mitigation should be prioritized pending a vendor response.
- research
Details of Alan Turing’s Voice Encryption System
In November 2023, a collection of Alan Turing's wartime papers sold at auction in London for approximately half a million US dollars. The cache, known as the Bayley papers, includes handwritten materials documenting Turing's classified Delilah project from 1943 to 1945, a portable voice-encryption system. The papers survived because Donald Bayley, a colleague who worked with Turing, preserved them until his death in 2020.
Why it matters: Practitioners studying cryptographic history and defense systems can examine original source materials on early voice encryption techniques and wartime engineering approaches to secure communications.
- ransomware
Armenia Detains Russian Tourist on U.S. Warrant for REvil Hacker, Lawyers Say Wrong Man
Armenia detained a Russian tourist named Aleksandr Ermakov at Yerevan airport on June 28 based on a U.S. extradition request for a REvil ransomware suspect also named Aleksandr Ermakov. His wife and legal representatives claim the detained individual is the wrong person, as the name match appears coincidental rather than evidence of identity.
Why it matters: Organizations and security teams tracking REvil threat actors should monitor extradition outcomes, though practitioners should be aware that name-based matches can lead to mistaken detentions and false leads in attribution efforts.
- threat intel
Scammers weaponize FaceTime to drain bank accounts
Apple is warning users that scammers exploit FaceTime to conduct social engineering attacks, impersonating representatives of trusted organizations to extract login credentials, security codes, and financial information. Attackers use caller ID spoofing to mask their identity, making it difficult for victims to verify legitimacy.
Why it matters: iPhone and iPad users face direct risk of account compromise and financial fraud through FaceTime-based social engineering; practitioners should alert end users to verify caller identity through independent channels before sharing any credentials or codes.
- ot ics
Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy
Three chained zero-day vulnerabilities were discovered in Siemens ROX II operational technology switches that enable privilege escalation and persistent root access when exploited together. The vulnerabilities form a complete attack chain affecting industrial control systems that rely on these network switches. Unit 42 published a technical analysis detailing the flaw sequence.
Why it matters: Organizations operating Siemens ROX II switches face active exploitation risk if these devices are internet-facing or accessible to untrusted networks; patch availability and mitigation steps should be evaluated immediately.
- government policy
San Francisco Demands Apple and Google Delete AI ‘Nudify’ Apps From App Stores
San Francisco's City Attorney sent cease-and-desist letters to Apple and Google demanding they remove 13 face-swap applications from their app stores. The apps are designed to generate non-consensual intimate imagery targeting women and girls, generating revenue for the platforms hosting them.
Why it matters: Women and girls are being targeted with non-consensual deepfake intimate imagery at scale; app store operators and security practitioners should understand the evolving legal pressure on platforms to police this content category and the technical challenges in detecting such abuse.
- identity access
Claude can now sign into websites with 1Password without exposing your credentials
1Password has released a beta integration for Claude that allows the AI assistant to complete authentication-required browser tasks while keeping user passwords and secrets protected. The feature is available to paid Claude subscribers using Claude Desktop on macOS and compatible with 1Password individual, family, and business plan customers. The integration requires specific software components including Claude Desktop, the 1Password desktop app, and browser extension.
Why it matters: Security teams and developers using Claude for automated tasks can now grant AI assistants temporary, scoped access to web services without sharing actual credentials, reducing credential exposure and simplifying access management for AI workflows.
- regulatory
Windows Server 2022 reach end of mainstream support in 90 days
Windows Server 2022 enters the final 90 days of mainstream support and will transition to extended support in October 2026, continuing to receive security updates through 2031. Microsoft's support model ensures organizations have a multi-year window to plan upgrades or transitions to newer server versions.
Why it matters: IT operations teams managing Windows Server 2022 environments should begin migration planning now to avoid the loss of non-security fixes and reduced support responsiveness after October 2026.
- breaches incidents
Cyberattack Disrupts Operations of Japanese Frozen Food Giant Nichirei
A cyberattack forced Japanese frozen food manufacturer Nichirei to disconnect its systems on July 13, 2024. The company is working to gradually restore operations following the incident.
Why it matters: Food supply chain operators and their customers should monitor for potential disruptions or product availability issues, and assess whether similar vulnerabilities exist in their own operational technology environments.
- threat intel
ACR Stealer Uses ClickFix Lures to Steal Browser Tokens and Microsoft 365 Files
ACR Stealer, an infostealer active since 2024, infiltrates networks through ClickFix social engineering tactics that trick users into executing commands via the Windows Run dialog. Once inside, the malware harvests browser passwords, session tokens, PDFs, Microsoft 365 documents, and files from OneDrive and SharePoint folders.
Why it matters: Enterprise security teams need to detect and block ClickFix lures immediately, as ACR Stealer can exfiltrate authentication tokens and sensitive cloud documents that grant attackers persistent access to email, collaboration platforms, and file repositories.
- threat intel
New GoSerpent Malware Targets Southeast Asian Governments and Diplomats for Espionage
Kaspersky discovered a new malware called GoSerpent used in cyberattacks against Southeast Asian government and diplomatic entities beginning in late 2025. The malware appears designed to establish persistent access for intelligence gathering purposes.
Why it matters: Government agencies and diplomatic missions in Southeast Asia need to assess their network exposure to this espionage-focused malware and coordinate incident response with regional allies.
- industry
Risk Ledger Raises $32 Million in Series B Funding
Risk Ledger, a British firm, secured $32 million in Series B funding for its collaborative platform designed to help organizations manage supply chain security risks.
Why it matters: Security practitioners and procurement teams use supply chain risk platforms to reduce third-party exposure; funding increases availability of tooling in this space.
- threat intel
US charges two over laundering $43 million from investment fraud
U.S. prosecutors charged two individuals from New York with money laundering related to a cyber investment fraud scheme that stole approximately 43 million dollars. The charges target their involvement in a larger criminal operation that moved stolen funds through the financial system.
Why it matters: Practitioners managing fraud detection and financial crime compliance should track enforcement trends against money laundering networks supporting investment fraud, as this illustrates how stolen funds flow and where interception points exist.
- vulnerabilities
Fresh SharePoint Vulnerability Exploited Soon After Disclosure
A critical vulnerability in SharePoint permits authenticated remote attackers to execute arbitrary code on affected servers. Exploitation began shortly after the security flaw entered public disclosure.
Why it matters: Organizations running SharePoint installations need immediate awareness and patching plans, as the vulnerability is actively exploited in the wild post-disclosure.
- vulnerabilities
CISA urges immediate action on actively exploited Fortinet flaws
The Cybersecurity and Infrastructure Security Agency (CISA) issued a directive requiring federal agencies to patch two actively exploited vulnerabilities affecting Fortinet FortiSandbox. The vulnerabilities are being leveraged in active attacks and warrant urgent remediation.
Why it matters: Federal agencies and organizations using FortiSandbox face immediate risk from active exploitation; patch deployment should be prioritized to prevent compromise of threat detection capabilities.
- vulnerabilitiesCVE-2026-58644
CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV
CISA added CVE-2026-58644, a critical remote code execution vulnerability in Microsoft SharePoint Server, to its Known Exploited Vulnerabilities catalog on Thursday. The flaw carries a CVSS score of 9.8 and involves a deserialization issue. Federal civilian agencies must patch the vulnerability by July 19, 2026.
Why it matters: Federal civilian executive branch agencies are mandated to remediate this critical SharePoint RCE by July 19, 2026, and private organizations running SharePoint Server should prioritize patching to prevent active exploitation.
- ai security
Prompt injection is becoming the XSS of the web agent era
Researchers at UC Berkeley have identified Cross-Site Prompting (XSP) as a new attack vector that exploits autonomous web agents by injecting malicious prompts through untrusted content displayed on web pages, such as product reviews and advertisements. The attack mirrors Cross-Site Scripting (XSS) vulnerabilities in that it leverages mixed trusted and untrusted content to manipulate agent behavior. The team developed Prismata, a system designed to sit between a web agent and its targets to mitigate these risks.
Why it matters: Security teams deploying autonomous web agents need to understand this emerging injection threat and evaluate defenses like Prismata before agents process pages containing user-generated content or ads, as adversaries can now steer agent actions through visible text.
- threat intel
The script, not the voice, is what makes AI voice phishing work
Researchers from Harvard Kennedy School, Meta, and other institutions conducted a study of over 4,100 US adults to evaluate the effectiveness of voice phishing attacks. The research tested commercial voice systems and human callers using a scenario where an attacker poses as a senior manager requesting credential information, finding that the scripted social engineering approach was the primary factor in attack success rather than the voice synthesis quality.
Why it matters: Security awareness and identity teams need to know that attackers can achieve high phishing success rates regardless of voice quality, making script-based social engineering training and caller verification procedures critical defenses against both synthetic and human voice attacks.
- industry
The five step plan that cuts security budget waste
A security leader outlines how organizations waste budget by organizing spending around vendor categories, compliance requirements, and reactive headlines rather than attacker paths. The inefficiencies stem from tool overlap, redundant detections, and unused software licenses covering significant portions of infrastructure at full cost.
Why it matters: Security practitioners managing stretched budgets need to realign spending away from compliance theater and overlapping tools toward risk-driven allocation to maximize protection per dollar spent.
- research
A hard drive reliability check on 341,263 drives, from 4TB to past 20TB
Backblaze released a Q1 2026 reliability report covering 341,263 hard drives ranging from 4TB to over 20TB capacity in its cloud storage fleet. The analysis tracks real-world failure rates across a diverse range of drive sizes operating in continuous-use conditions, excluding boot drives and units below reporting thresholds.
Why it matters: Infrastructure teams and procurement managers selecting bulk storage hardware should review manufacturer and capacity-specific failure rates to optimize reliability and cost in their own deployments.
- industry
New infosec products of the week: July 17, 2026
A weekly roundup highlighting new security product releases from vendors including Cloudflare, Lineation.ai, Nudge Security, and Polygraf AI. Polygraf AI's Meeting Guard is featured as a real-time deepfake detection solution for enterprise meetings that joins sessions as a participant to provide security analysis to attendees.
Why it matters: Security teams evaluating new tools should monitor this weekly digest to stay current with emerging products, though the article provides only product names and one brief example rather than detailed comparative analysis.
- threat intel
Tracking Advanced Persistent Threat Groups | Recorded Future
Advanced Persistent Threats (APTs) are sophisticated, long-term cyber campaigns by well-funded adversaries, often nation-states, targeting specific organizations for espionage or data theft. APT groups use customized malware, Living-off-the-Land tactics, and legitimate credentials to evade traditional signature-based defenses and remain undetected for extended periods. Organizations must shift from reactive internal monitoring to proactive threat intelligence tracking of adversary infrastructure across open, deep, and dark web sources to intercept attacks before they establish persistence.
Why it matters: Security teams and threat hunters need to understand APT operational patterns and reduce breakout time to detect and respond to sophisticated nation-state threats before they move laterally through networks and achieve their strategic objectives.