“”We are in the Singularity.” Elon Musk
From the War with Iran front.
- The American Hospital Association News tells us
- “The Cybersecurity and Infrastructure Security Agency and other U.S. and international partners July 22 released an updated advisory on Iranian-affiliated cyber actors targeting internet-connected programmable logic controllers, which are computers used to manage and monitor equipment. PLCs can be found in climate control systems, access control systems and many other applications in healthcare. Agencies first warned of malicious activity targeting Rockwell Automation PLCs in April. The updated advisory expands the scope of incidents to include observed targeting of Schneider Electric, Siemens and potentially other manufacturers of PLCs. It also includes new guidance on detecting malicious changes in reusable code modules exploited within Rockwell Automation PLC programs.”
From the Project Glasswing / the Singularity front,
- Cybersecurity Dive reports on July 22,
- “Two OpenAI large language models, including one not yet released to the public, broke free of their constraints last week and autonomously hacked into the AI application library Hugging Face.
- “The first-of-its-kind event, in which the LLMs tried to steal information that would help them excel on an important test, has highlighted the dangers of the AI industry’s increasingly powerful tools.
- “We consider this incident to be an unprecedented cyber incident, involving state-of-the-art cyber capabilities, and are responding accordingly,” OpenAI said in a blog post on Tuesday that confirmed its models’ responsibility for the attack, which Hugging Face announced on July 16.”
- AI Strategist David Borish, writing in LinkedIn, lets us know,
- “On July 21, Elon Musk quote a message from OpenAI researcher Will Depue that laid out a timeline: a security incident at Hugging Face on July 21, a counterexample to the Jacobian conjecture on July 20, the disproof of Erdős’s unit distance conjecture on May 20, the solution to Erdős problem 1196 on April 14, and Anthropic’s Project Glasswing finding thousands of zero day vulnerabilities on April 7. Depue’s post noted that in “normal” times, these milestones would have been spread across months or years. Compressed into a single week of news cycles, they read differently. Musk’s reply ran five words: “We are in the Singularity.”
- “The claim landed hard because, unlike most Singularity talk, this timeline is not speculative. Each item is a documented event with a paper trail, and the details matter more than the framing.” * * *
- “The skeptical case. Grocery prices, commute times, and most people’s jobs look the same this week as they did a month ago. Every event on Depue’s timeline required a human to set up the evaluation, pose the conjecture, or prompt the model, and in most cases required teams of human experts to verify, formalize, or clean up afterward. Deep learning researcher Yann LeCun has argued current architectures will not reach general intelligence without a different approach entirely. Writer Freddie deBoer has made the broader point that a self-improving AI escaping human oversight remains a speculative scenario without a demonstrated mechanism, distinct from AI systems getting better at specific tasks people assign them.
- “Both things can be true at once. The rate of capability progress across math, security research, and coding is genuinely compressing what used to take years into weeks, and the humans setting the objectives, verifying the outputs, and deciding what gets deployed have not gone anywhere. The more telling test ahead is quieter than another isolated proof or another leaderboard topper: whether formal verification, in Lean or otherwise, keeps pace with the rate of claims, and whether the containment failures at Hugging Face turn out to be a one time embarrassment or the first entry in a longer list.”
- TechTimes adds,
- “Microsoft is preparing to launch Project Perception, an AI-powered security platform that scans enterprise codebases for exploitable vulnerabilities — and is built around a deliberate cost-and-access argument against Anthropic’s Claude Mythos Preview, the most capable vulnerability-hunting AI available and one that most organizations on Earth cannot currently use.
- “The platform is expected to debut before the end of July. It routes security analysis tasks across AI models from Microsoft, OpenAI, and Anthropic, using a model-selection layer that reserves expensive frontier model calls for the steps where they create real value and assigns cheaper, distilled models to high-volume scan passes. That architecture, according to reporting first published by The Information, is designed to bring the cost of running continuous, enterprise-grade vulnerability discovery well below what Anthropic charges for direct Mythos access.”
From the cybersecurity policy front,
- Federal News Network reports,
- “The unprecedented breach of a technology vendor by autonomous artificial intelligence agents is serving to underscore governmentwide efforts to streamline federal cloud security and prioritize faster patching of critical software vulnerabilities.
- “OpenAI confirmed this week that its advanced AI training models broke out of their test environment and then hacked into the networks of start-up vendor Hugging Face. The incident is the latest AI cybersecurity development driving policy conversations across Washington.
- “Pete Waterman, director of the Federal Risk and Authorization Management Program (FedRAMP) at the General Services Administration, pointed to the Hugging Face incident as a landmark moment for cybersecurity during Carahsoft’s FedRAMP Summit on Thursday.
- “Waterman said the incident underscores his program’s shift to the FedRAMP 20x model.”
- Cyberscoop relates,
- “Industry groups who spoke at town halls hosted by the Cybersecurity and Infrastructure Security Agency [(CISA)] about a pending cyber incident notification regulation had a few consistent messages:
- “We want this to apply to fewer of us. We don’t want to report to you on as many incidents. We want to give you less information when we do.
- “CISA last week published transcripts from the town halls, where the agency sought feedback on the delayed rule for the 2022 Cyber Incident Reporting for Critical Infrastructure Act — perhaps the most significant cyber legislation Congress has ever passed. That law required critical infrastructure owners to report major cyberattacks to the federal government within 72 hours, and ransomware payments within 24 hours.” * * *
- “Where the rule specifies what kind of data organizations should report in a major incident, CISA should “seek to collect the least amount of information possible in the easiest to report fashion to facilitate information accuracy and reporting speed,” said Samantha Burch, vice president of technology public policy at government affairs at AHIP, a health insurance industry trade association.” * * *
- “One industry representative told CyberScoop that CISA’s willingness to hold town halls, combined with the Trump administration strategy emphasizing “common sense regulation,” was a good sign about where the rule might be heading.
- ‘They are not picking up on the Biden administration’s approach and tweaking it. They’re thinking, ‘What are the specific pieces of information we need during a cyber incident to help critical infrastructure companies respond?’” said Henry Young, senior director of policy for the Business Software Alliance. “In general, industry is optimistic that what we’ll end up with are a few of the most important pieces of information, so that in the emergency, companies can act quickly and actually respond to an incident rather than completing lots of paperwork.”
- and
- “Seven out of 10 federal cyber regulations requiring written reports to federal agencies are duplicated elsewhere, a report from a government watchdog found in a report to Congress Wednesday.
- “And so far, efforts to de-conflict haven’t had much success, the report from the Government Accountability Office concluded.
- “At the request of two top lawmakers, the GAO examined federal cyber regulations at 37 agencies. It counted 80 out of 117 rules that “either contain the same kind of reporting requirement applicable to a sector or the same reporting requirement as at least one other regulation.”
- “The desire to harmonize those conflicting rules gathered steam under the Biden administration, as it undertook a more aggressive push to regulate cybersecurity than prior administrations. It has continued into the second Trump administration.”
From the cybersecurity breaches and vulnerabilities front,
- HIPAA Journal reports,
- “There has been a general trend of increasing data breaches over the past decade, with this year on track to set a new record. According to the H1 2026 Data Breach Report from the Identity Theft Resource Center (ITRC), there have been at least 1,803 data compromises in H1 2026, which will give an annual total of more than 3,600 data compromises if they continue to occur at a similar rate as the first half of the year.
- “Across those data compromises, there have been 1,394 confirmed data breaches (excluding leaks, exposures, and unknown incidents), accounting for 77% of total events. More than 471 million victim notices have been issued, which already exceeds the total number of victim notices for all of 2025, and there are still six months of the year to go. While at the current rate, this year is unlikely to beat the total for 2024, even with only 6 months of data, 2026 already ranks as one of the worst years to date.
- “As ITRC explains in the report, part of the reason is the return of mega data breaches, the biggest of which involved the Instructure Holdings’ Canvas platform, which accounted for an estimated 275 million notices. A mega data breach at Under Armour involved more than 72.7 million notices, while the SoundCloud data breach saw 29.8 million victim notices issued.
- “There were no healthcare data breaches in the top 10 data compromise list, in contrast to H1, 2025, when three healthcare data breaches made it into the top 5. In fact, based on breach reporting to the HHS’ Office for Civil Rights, there have been relatively few mega data breaches in healthcare. In H1 2026, only 7 healthcare data breaches required more than 1 million notices.”
- Dark Reading relates,
- “Russian state-backed threat actors are compromising networks of Western governments and enterprises through the Zimbra Collaboration Suite (ZCS), according to intelligence and cybersecurity agencies in more than a dozen countries.
- “In a joint advisory Thursday, the US government and several allied nations warned that an advanced persistent threat (APT) dubbed “Laundry Bear” has been targeting ZCS customers since July 2025. Laundry Bear actors used a zero-day vulnerability in ZCS, tracked as CVE-2025-66376, in a phishing campaign that featured what experts describe as a “half-click exploit” to breach Zimbra webmail servers.
- “Unlike traditional phishing campaigns that persuade a user into taking an action, such as clicking a link or opening a file, Laundry Bear’s latest campaign leverages a view-based exploit that only requires a user to view a malicious email within a vulnerable version of the webmail service,” the agencies said in the advisory.
- The campaign is designed “almost certainly to gather sensitive information for the Russian Federation,” according the advisory. The Laundry Bear attacks mark yet another threat from Russian APTs against US organizations.
- Cybersecurity Dive tells us,
- “A critical vulnerability in Check Point Software’s SmartConsole login process is being exploited, with a small number of customers already impacted, according to a security advisory released Wednesday from the company.
- “The authentication bypass flaw, tracked as CVE-2026-16232, allows an attacker to gain full administrative privileges after they access an application login token. An attacker can then make changes to security policy and configurations. The vulnerability has a severity score of 9.1 out of 10.
- Check Point on Wednesday released a jumbo hotfix to address several security issues in its firewall and management products, according to the advisory.
- A vulnerability of this type is particularly concerning, giving an attacker the ability to make a number of changes, according to a blog post released Thursday by Rapid7. A remote hacker can “alter administrator permissions, manipulate VPN configurations, and potentially disable or tamper with logging and monitoring,” Rapid7 said.
- and
- “A critical-severity deserialization vulnerability in Microsoft SharePoint is now under exploitation, according to security researchers at watchTowr and Defused.
- “The flaw, tracked as CVE-2026-50522, has a severity rating of 9.8 out of 10 and could enable an attacker to execute remote code over a network.
- “Hackers are targeting on-premises SharePoint server environments following the release of new exploit code, watchTowr researchers said in a LinkedIn post. Researchers warned that attackers are stealing machine keys to maintain long-term access.”
- CISA added six known exploited vulnerabilities to its catalog this week.
- July 21, 2026
- CVE-2021-27137 DD-WRT Stack-Based Buffer Overflow Vulnerability
- CVE-2026-0770 Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability
- CVE-2026-63030 WordPress Core Interpretation Conflict Vulnerability
- CVE-2026-60137 WordPress Core SQL Injection Vulnerability
- Security Affairs discusses these KVEs here.
- July 22, 2026
- “CVE-2026-16232 Check Point SmartConsole Improper Authentication Vulnerability
- The Hacker News discusses this KVE here.
- “CVE-2026-50522 Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
- Cybersecurity Dive discusses this KVE here.
- “CVE-2026-16232 Check Point SmartConsole Improper Authentication Vulnerability
- July 21, 2026
- Cyberscoop adds,
- “Malware targeting AI coding assistants and software developers’ automated workflows is spreading into more environments with more capabilities, placing defenders at a growing disadvantage.
- “A malware strain dubbed Sandworm_Mode, first discovered by Socket in February, represents a growing threat to software development. According to a CrowdStrike report, the self-propagating worm can spread through code repositories with minimal detection, raising alarms about software supply chains.
- “The malware’s capabilities are extensive, but not especially unique compared to the series of supply-chain worms known as Shai-Hulud, and more recently Mini Shai-Hulud.
- “This is the new trend,” Adam Meyers, senior vice president of counter adversary operations at CrowdStrike, told CyberScoop. “This is something we’re seeing more and more. It’s the new hotness right now.”
From the ransomware front,
- Cybersecurity Dive reports,
- “A threat group called Anubis claimed credit for the ransomware attack against Fairlife, the dairy products unit of Coca-Cola.
- “The group says it locked the servers at Fairlife and obtained 1TB of data from the attack, according to researchers at Arctic Wolf. Anubis is threatening to leak information if its demands are not met within a week. Researchers provided screenshots posted on the group’s data leak site
- “Coca-Cola was forced to suspend U.S. production at Fairlife while it launched an investigation into the attack. Coca-Cola officials noted there was no impact on the safety or quality of its dairy products.” “
- Dark Reading relates,
- “Ransomware is not just growing, it is actually accelerating, with activity surging between October 2025 and March 2026, as more than 60 new groups entered an increasingly crowded criminal ecosystem.
- “For enterprises, the surge means not only more attacks but also a larger and constantly changing pool of adversaries to track and defend against.
- “Black Kite analyzed ransomware incidents between April 1, 2025, and March 31, 2026, and identified 7,551 known victims worldwide. That represented a 25% increase over the previous 12-month period, with much of the growth concentrated in the second half of the year. Black Kite counted 2,904 victims between April and September 2025 and 4,647 between October 2025 and March 2026, marking a 60% increase in reported ransomware victims. March 2026 was the busiest month with as many as 861 organizations — or nearly 28 per day — falling victim to a ransomware attack.
- “This isn’t a problem we’ve contained,” says Ferhat Dikbiyik, chief research and intelligence officer at Black Kite. “It’s still a lucrative business, and the barrier to running one keeps getting lower.”
- The Hacker News tells us,
- “Threat actors have been observed exploiting a now-patched high-severity Palo Alto Networks PAN-OS vulnerability as an entry point to deploy Qilin (aka Agenda) ransomware on victim environments.
- Arctic Wolf Labs said it investigated multiple intrusions in June 2026 that began with the exploitation of CVE-2026-0257 (CVSS score: 7.8), an authentication bypass flaw affecting the portal and gateway components of PAN-OS software.
- Successful exploitation of the flaw allows unauthenticated remote attackers to sidestep authentication and establish VPN sessions without valid credentials when authentication override cookies are enabled with specific certificate configurations.
- “Post-exploitation tradecraft varied across intrusions, from rapid encryption-only operations to full double-extortion, possibly suggesting multiple affiliates operating under the Qilin ransomware-as-a-service (RaaS) umbrella,” the cybersecurity company said.
- Bleeping Computer points out,
- “The Clop ransomware gang (also tracked as Cl0p) is targeting Internet-exposed PTC Windchill and FlexPLM instances in a new data theft extortion campaign.
- “Clop has reportedly been exploiting a critical improper input validation vulnerability tracked as CVE-2026-12569, which allows attackers to execute arbitrary code on vulnerable Windchill and FlexPLM instances.
- “As cybersecurity company ReliaQuest reported on Thursday, Clop operators have been deploying JSP webshells that allow them to exfiltrate sensitive data from targeted companies’ compromised PLM platforms.
- “ReliaQuest has observed threat actors actively exploiting CVE-2026-12569, a critical unsafe deserialization vulnerability (CVSS 9.3) affecting PTC Windchill and FlexPLM. Exploitation enables unauthenticated remote code execution and JSP web shell deployment for remote command execution and sensitive product data exfiltration,” the company said.”
- Per Cisco Talos,
- “Cisco Talos has discovered a new Rust-based remote access trojan (RAT) we call “msaRAT” attributed to the Chaos ransomware group. The name is derived from the binding names found in the binary: “msaOpen,” “msaClose,” “msaError,” and “msaMessage”.
- “msaRAT is implemented using the Tokio asynchronous runtime, with primary capabilities of browser-leveraged remote code execution and covert tunneling to establish command-and-control (C2) communications.
- “This RAT never touches the network directly — it controls its C2 communication channel exclusively through Chrome DevTools Protocol (CDP), a browser debugging API. The binary contains a Cloudflare Workers endpoint, but it never makes HTTP connections to that domain itself; it offloads that work entirely to the browser.
- “msaRAT manipulates the browser via CDP, performs signaling (SDP Offer/Answer exchange) with Cloudflare Workers, and establishes a WebRTC DataChannel between the browser and the C2 server using Twilio TURN (Traversal Using Relays around NAT) as a relay.”
From the cybersecurity business and defenses front,
- The Wall Street Journal reports,
- “The Defense Department signed an up to 10-year, near $7 billion contract with Oracle intended to streamline fragmented licensing and intra-agency efficiency.
- “The Austin-based cloud computing and software company separately maintained different contracts across the agency. The government said the deal will optimize services and deliver hundreds of millions of dollars in taxpayer savings.”
- TechCrunch relates,
- “Glow, a cybersecurity startup founded by former Meta and Snowflake executives, emerged from stealth as a unicorn, betting that artificial intelligence is reshaping how enterprises secure employee devices.
- “The Palo Alto-headquartered startup on Wednesday said it raised $180 million in an all-equity Series A funding round that valued it at $1.2 billion, with backing from Sequoia Capital, Cyberstarts, Greenoaks, and Redpoint Ventures, alongside participation from Index Ventures, Swish Ventures, Lux Capital, Operator Collective, and Holly Ventures. The investment made Glow one of the latest cybersecurity startups to achieve unicorn status before publicly disclosing revenue metrics.”
- Cybersecurity Dive relates,
- “Many ransomware victims remain vulnerable to follow-up cyberattacks, even after they complete their incident response processes, highlighting gaps in mitigation activities that increase their odds of becoming repeat targets, the security firm Black Kite said on Tuesday in its annual ransomware report.
- “The report described how victims fail to patch critical vulnerabilities and properly configure email security tools, underscoring the importance of thorough digital cleanup operations as part of the ransomware recovery period.” * * *
- “Black Kite also shared fresh data on the ransomware ecosystem and its top targets.”
- Because ransomware is a profit-motivated business, cybercriminals prioritize the easiest and most lucrative targets, and if an organization fails to fix the problems that opened the door for hackers in the first place, they are likely to return. That fact makes it imperative for hacked businesses to fix digital liabilities as soon as possible after an incident, lest hackers revictimize them seeking another payout.
- MSN adds, “The next cyber arms race isn’t about finding bugs. It’s about fixing them first.”
- Here is a link to Dark Reading’s CISO Corner.
