“”We are in the Singularity.” Elon Musk
From the Project Glasswing front,
- Cybersecurity Dive reports,
- “Versions of Anthropic’s Claude AI model broke out of their testing environments and hacked into other organizations on three separate occasions, Anthropic said on Thursday [July 30].
- “The frontier AI lab’s announcement came roughly one week after OpenAI disclosed a similar incident involving its models, a revelation that has set off a new round of consternation about whether AI developers are adequately overseeing their sophisticated AI products.
- “In the three incidents that Anthropic disclosed, Claude conducted the intrusions while believing that it was participating in a capture-the-flag exercise in which it did not have access to the internet and all available systems were part of the test. “Due to a misunderstanding between us and our evaluation partner,” Anthropic explained in a blog post, “this was not the case, and internet access was available.”
- “As a result, when Claude encountered the three victim organizations, it believed that they were simulated targets and broke into them using basic attack techniques such as exploiting weak passwords.
- The article describes the incursions which is worth a click.
- Cyberscoop adds,
- “We almost never get both sides of an intrusion. This time we did.
- “Last month, Hugging Face disclosed a breach into part of its production infrastructure, saying an autonomous AI agent system ran the attack from start to finish. Five days later, OpenAI revealed that its own models, including GPT-5.6 Sol along with an unreleased one, were responsible for the breach. OpenAI called it an unprecedented cyber incident.
- “Most of the commentary since has been about AI capability. That is the least useful part of the story, because the capability was doing what it was destined to do. Security teams should look at a simpler truth: in both systems, the key defenses sat behind untrusted code that was already running.”
- Cybersecurity Dive notes,
- “Businesses are more concerned about AI-fueled threats than traditional cybersecurity dangers, potentially undermining their ability to prepare for the attacks they are most likely to face, researchers at the security firm Arctic Wolf said on Tuesday.
- “Roughly a third of organizations said AI topped their list of cybersecurity concerns, while concerns about malware, credential theft and cloud misconfigurations dropped from their 2025 numbers, according to Arctic Wolf’s annual AI and cybersecurity trends report.
- “The report also delved into organizations’ use of AI for their security programs, their reasons for reporting cybersecurity incidents and regional trends in cybersecurity challenges.”
- and
- “AI agents remain a major cybersecurity risk for businesses, with 81% of CISOs worrying that their AI systems aren’t properly governed, according to a report Okta published on Wednesday.
- “Only 47% of companies Okta surveyed said they knew all the AI agents on their networks, and only 46% reported controlling those agents’ access to corporate data.
- “Okta’s findings highlight a complicated and dangerous environment in which companies aren’t properly balancing the risks and benefits of agentic AI.”
- Security Week points out,
- “Anthropic on Friday [July 24] rolled out Claude Opus 5, pitching it as a cheaper alternative to its top-tier Fable 5 model. In terms of cybersecurity, the new model is nearly as good as the AI giant’s most capable system, Mythos 5, at spotting software vulnerabilities, but remains well behind it in turning those findings into working exploits.”
- “The difference comes from Anthropic’s own OSS-Fuzz-based evaluation, which measures how well a model can locate and then exploit vulnerabilities with minimal human steering. According to the company, Opus 5 identifies vulnerabilities at a rate close to Mythos 5, but its exploit-development score trails considerably.
- “Anthropic frames this as a deliberate outcome, noting that it has avoided training Opus 5 directly on offensive cyber tasks. The gains it does show, the company says, are a byproduct of broader capability improvements.”
- Per a July 28, 2026, SonicWall news release,
- SonicWall today confirmed it is a participant in Anthropic’s Project Glasswing and is testing Claude Mythos 5 for defensive cybersecurity work. Through the initiative, SonicWall is applying the model to vulnerability discovery and code review across its own software to find and remediate security issues before they can be exploited.
- Project Glasswing is an Anthropic-led industry effort that gives participating security teams access to Claude Mythos 5, a frontier model not available to the general public, for defensive security research. Anthropic launched the program to help close the gap between attackers using AI to accelerate vulnerability discovery and defenders’ ability to find and fix those same issues first.
- “Security vendors are not exempt from the pressure every software maker is under right now,” said Chandro Prasad, SonicWall Chief Product Officer. “Vulnerabilities move from disclosure to exploitation faster than most patch cycles can keep up with. Participating in Project Glasswing gives our security team another way to find and close gaps in our own code before an attacker does. That is the standard we hold ourselves to, and this program is a meaningful way to raise it further.”
From the cybersecurity policy and law enforcement front,
- Bleeping Computer reports,
- “The U.S. and Australian governments have released new guidance urging critical infrastructure organizations to prepare to isolate vital operational technology systems in the event of a cyberattack or other major disruptions.
- “The guidance, titled “CI Fortify – Advice for isolating vital systems,” was developed by the U.S. Cybersecurity and Infrastructure Security Agency (CISA), the Australian Signals Directorate’s Australian Cyber Security Centre (ACSC), the FBI, and international partners.
- “It provides recommendations for disconnecting critical operational technology (OT) and associated systems from corporate, Internet-facing, and other less-trusted networks while continuing to provide essential services for an extended period.”
- Cyberscoop relates
- “The Cybersecurity and Infrastructure Security Agency published a guidebook for federal agencies Thursday to aid them on managing security risks with open-source software, touching on topics like patching and open-source AI models.
- “An executive order President Joe Biden signed and that President Donald Trump amended ordered CISA and other agencies to issue open-source security recommendations to federal agencies. But the guidance is also timely, given a recent slew of attacks on open-source software (OSS).
- “As part of our statutory mission, CISA remains laser-focused on enhancing the nation’s cybersecurity by collaborating with government, industry and the open-source community to understand and securely use OSS,” said Chris Butera, acting executive assistant director for cybersecurity. “CISA encourages federal civilian agencies to review this guide and implement the principles and practices to improve risk management, better execute their mission, and better serve the public.”
- “The document, “Open Source Software: Security Principles and Practices,” touts the advantages of open-source software — which anyone can use, modify and share — as offering benefits in efficiency, cost, security transparency and more, but notes that it also has unique tradeoffs.”
- “All software carries risk, and OSS is no more or less risky than other software. The key distinction is that, with OSS, agencies can directly assess code quality and security, rather than relying solely on vendor assurances,” the guidance reads. “OSS is increasingly intertwined with emerging technologies such as artificial intelligence. Agencies that adapt to OSS’s unique characteristics will position themselves to meet future challenges and leverage new innovations.”
- Dark Reading tells us,
- “A gaggle of government partners from around the world has released new guidelines for the minimum elements that organizations should include in a software bill of materials (SBOM).
- “The document, published this week, was authored by the US Cybersecurity and Infrastructure Security Agency (CISA) and 16 other government entities spread across four continents. It supersedes the National Telecommunications and Information Administration’s (NTIA) 2021 guidelines, which laid out what an SBOM had to contain as far as the US government was concerned. This updated version was first drafted in 2025, and was then informed by suggestions from 90 commenters, including major organizations like Google, Microsoft, and Amazon Web Services (AWS) to create the resulting document.
- An SBOM is essentially an “ingredients list,” detailing the building blocks and supply chains that make up a given piece of software. This could include proprietary or open source software components, APIs, utilities, and more. As a risk management tool, it aims to provide visibility into where vulnerabilities exist in a software stack and how to prioritize patching, among other things.
- “There’s nothing revolutionary in this latest spruced-up framework, which follows SBOM policy revisions earlier this year, but it introduces 10 new data fields, and a dozen or so updates to existing elements, which range from major to minor significance. Though the changes might be directionally positive, Jeff Williams, founder of OWASP and founder and CTO of Contrast Security, argues that these minor procedural changes miss the bigger picture.”
- Per a Health and Human Services Department news release,
- “The U.S. Department of Health and Human Services (HHS), Office for Civil Rights (OCR) today announced a settlement with OSF Healthcare System and its Affiliated Covered Entities (OSF), concerning potential violations of the Health Insurance Portability and Accountability Act of 1996 (HIPAA) Privacy, Security, and Breach Notification Rules. OSF is headquartered in Illinois and has providers located in Illinois and Michigan.
- “An accurate and thorough HIPAA risk analysis is not only required by law, but it is also necessary to protect health information and prevent or mitigate ransomware attacks,” said OCR Director Paula M. Stannard. “If a HIPAA regulated entity doesn’t know what threats and vulnerabilities exist to its electronic protected health information (ePHI), they will often learn the hard way when their systems are hacked.” * * *
- “The settlement resolves an investigation that OCR initiated after OSF filed a breach report in October 2021. In April of 2021, OSF discovered that its files had been infected with the “Nephilim” variant of ransomware. The PHI of 53,907 individuals was exfiltrated by the threat actor. Affected PHI included driver’s license numbers, diagnosis and treatment information, prescription information, medical record numbers, provider names, dates of services, financial account information, and health insurance information.” * * *
- “Under the terms of the resolution agreement, OSF agreed to implement a corrective action plan that OCR will monitor for two years and paid $552,250 to OCR. Under the corrective action plan, OSF has committed to taking steps to ensure compliance with the HIPAA Rules and protect the security of ePHI, including:
- “Conduct an accurate and thorough risk analysis to determine the potential risks and vulnerabilities to the confidentiality, integrity, and availability of its ePHI; and
- “Develop and implement a risk management plan to address and mitigate security risks and vulnerabilities identified in its risk analysis.
- “Read the resolution agreement and corrective action plan.”
From the cybersecurity breaches and vulnerabilities front,
- Dark Reading reports,
- “A coordinated cyberattack targeting more than 30 community water systems in Minnesota this week underscored the growing threat to often poorly protected operational technology (OT) from adversaries seeking to disrupt critical infrastructure services across the US.
- “The attacks, which US government officials have reportedly attributed to Iran, disrupted automated systems in some Minnesota communities, forcing them to switch to manual operations for brief periods. However, the attacks don’t appear to have affected water supply, water safety, or wastewater services in a major way, based on public statements by community officials and Minnesota’s IT Services (MNIT) unit.” * * *
- In an advisory Thursday [July 30], the FBI described the attacks as broader and impacting water and wastewater systems in at least seven states with some of the attacks degrading water operations. The FBI advisory said attackers were targeting OT devices including Rockwell Automation/Allen-Bradley PLCs, specifically MicroLogix 1100 and 1400 series devices. “After remotely accessing internet-facing devices, the actors changed the IP addresses and passwords, resulting in a loss of monitoring and control functionality,” the FBI said. It recommended that affected organizations remove PLCs “from direct Internet exposure via secure gateway and firewalls, setting up strong, unique passwords, and utilizing access control list (ACL) to allow only authorized communication between expected control system devices.”
- Bleeping Computer adds,
- “Pharmaceutical company Amgen says it suffered a data breach after threat actors stole corporate data and patient information stored in multiple cloud systems operated by third-party service providers.
- “Amgen is a California-based biotechnology company that develops and manufactures medicines for serious illnesses, including cancer, cardiovascular disease, inflammation, and rare diseases.
- “The company said it detected the unauthorized activity in July 2026 and responded by activating its cybersecurity response plan, implementing containment measures, and hiring independent forensic experts to investigate the incident.
- “The investigation found that the attackers stole sensitive data from the cloud environments.
- “The Company has since learned that some of its data, including proprietary data, patient protected health information, and other information, has been exfiltrated from these cloud environments,” Amgen said in a Form 8-K filing with the SEC.”
- Cyberscoop tells us,
- “Huntress researchers spotted an active and ongoing series of attacks targeting SonicWall VPN and firewall accounts, which compromised 30 organizations in less than two days, the company said in a threat advisory Tuesday [July 28].
- The credential stuffing campaign started Saturday and grew rapidly, ultimately compromising 92 unique user accounts during the next 41 hours, according to Huntress. Researchers said the attacks were broad and opportunistic, hitting various SonicWall devices, rather than targeting specific types of organizations.
- SonicWall hasn’t released a security advisory about the malicious activity as of press time. A spokesperson told CyberScoop the company is still investigating and hopes to have more information soon.
- The attacks ended — at least for now — as abruptly as they began. The last compromise occurred Monday, according to Michael Tigges, principal tactical response analyst at Huntress.
- Bleeping Computer informs us,
- “Hackers are actively exploiting a vulnerability in the FastJson open-source Java library, allowing remote code execution without user interaction or elevated privileges.
- “The security issue affects FastJson versions 1.2.68 through 1.2.83 and is leveraged in attacks targeting various organizations in the U.S.
- “The malicious activity was observed last week by the agentic security company ThreatBook, and researchers at the business protection company Imperva confirmed that it was “targeting a wide range of organizations, across Financial Services, Healthcare, Computing, Retail, Business, and other industries.” * * *
- “FastJson is an open-source Java library developed by Alibaba, used for serializing Java objects to JSON, and vice versa.” * * *
- “In its security bulletin, Alibaba confirmed the critical severity of the vulnerability and warned that it is exploitable on “the most common Spring Boot deployment model.”
- CISA added three known exploited vulnerabilities to its catalog this week.
- July 27, 2026
- CVE-2025-68686 Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability
- CVE-2026-16812 Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability
- July 29, 2026
- 2026-20316. Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability
- Cybersecurity News discusses this KVE here.
- 2026-20316. Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability
- July 27, 2026
- Bleeping Computer notes,
- “Broadcom has released security updates to fix five vulnerabilities in VMware vCenter, ESX, Workstation, and Fusion, including three critical flaws that allow attackers to bypass authentication, execute arbitrary code, or escape from a virtual machine to the host.
- “The vulnerabilities also affect products containing vCenter or ESX, including VMware Cloud Foundation, VMware vSphere Foundation, VMware Telco Cloud Platform, and VMware Telco Cloud Infrastructure.
- “Broadcom says organizations running versions released before those listed as fixed in its advisory should assume they are vulnerable and take immediate action.”
- Dark Reading adds,
- “A maximum-severity vulnerability in the open source AI agent platform Ruflo puts enterprise AI deployments at risk by letting attackers conduct various malicious activities from inside the orchestration framework. The flaw also can leave agents behaviorally compromised even after it’s been patched.
- “Researchers at Noma Security’s Noma Labs discovered the flaw, tracked as CVE-2026-59726, in Ruflo, formerly called Claude Flow and which hosts AI agent swarms for Codex and Claude Code, they revealed today. The vulnerability, which received the highest CVSS severity score of 10, allowed them to access the platform without logging in at all, according to Noma Labs.”
- “The weakness is a lack of authentication coupled with command execution capabilities, enabling complete control over the container and exposure of sensitive credentials,” according to details about the flaw posted on OpenCVE.”
- ZDNet notes,
- “Forty-three percent of organizations have experienced AI-enhanced or AI-generated phishing attacks, and 37% have encountered AI-augmented malware, according to a new survey.
- “CDW’s 2026 Security Research Report is based on a survey of 951 IT decision-makers across a variety of industries. Published Monday, the research reveals what appears to be an AI arms race between cyberattackers and defenders. Many organizations are considering investing in AI threat detection, training, and controls to combat the new face of modern cyber threats: AI techniques, tactics, and technologies.”
From the ransomware front,
- Inc.com reports,
- “The hackers behind the Fairlife ransomware attack have identified themselves, and experts are sounding the alarm.
- “A hacking group known as Anubis has claimed responsibility for the ransomware attack that hit Fairlife, Coca-Cola’s dairy products unit, saying it locked the company’s servers and stole about one terabyte of confidential data.
- “Coca-Cola first confirmed the attack on July 17, noting that the incident had affected Fairlife’s production systems and forced a temporary suspension of its U.S. operations. At the time, the company said it expected the disruption to continue for the foreseeable future. It said that there was no impact on the safety or quality of its products.
- “Upon revealing its identity, Anubis threatened to leak the stolen data unless Fairlife paid a ransom. Despite that, Coca-Cola announced this week that much of production had resumed. The company did not disclose how it managed to restore operations or share any details about how the hackers initially gained access to Fairlife’s systems. Coca-Cola has not disclosed whether it paid the ransom.
- Zach Lewis, chief information officer and chief information security officer at a private higher education institution, told Inc. that this was a case of double extortion: Attackers encrypt a company’s systems and demand payment for a decryption key, and then come back with a second demand, threatening to leak stolen data unless they’re paid again.
- He described the process as an oddly formal one, with negotiations often playing out through dedicated portals set up by the hackers themselves. “It’s really bizarre working with these criminals who are running a really good support site to navigate through this negotiation,” he said. “They want the transaction to be successful, because if they don’t hold up their end of the bargain, they don’t get that good reputation, and when they go to hit someone else, they won’t get paid either.”
- Health Exec relates,
- “A 2025 data breach on a medical billing company, first revealed in late June, exposed sensitive protected health data on 1.3 million people to hackers.
- “In an announcement, Medical Computer Business Services (MCBS) said the September 2025 incident stemmed from an unauthorized third party gaining access to its network, though it revealed few details about the nature of the attack, saying online that personal information on individuals stored on its network may have been “accessed or removed.”
- “Soon after, an updated filing with the U.S. Department of Health and Human Services’ Office of Civil Rights Healthcare Data Breach Tracker showed the official number of victims, meaning that hackers at the very least accessed files on 1,261,464 patients.
- “The company did not confirm that files were moved offsite. However, BleepingComputer reports—complete with a screenshot from the dark web—that a data trove from the incident is available online, with a ransomware group called PEAR (Pure Extraction and Ransom) taking credit.
- “The data is available for download, which typically means a ransom wasn’t paid.
- “The trove was discovered by researchers at the outlet sometime this week.”
- Bleeping Computer tells us,
- “Health-ISAC, a cybersecurity information-sharing organization for the health sector, is warning healthcare and medical technology organizations of an observed increase in successful attacks by ShinyHunters.
- “ShinyHunters is an extortion gang that primarily conducts supply chain and identity attacks to breach cloud SaaS and storage platforms in data theft attacks,
- “Over the past two years, the threat actors have become notorious for conducting numerous supply chain attacks on third-party integration partners. These breaches give them access to OAuth tokens that are used to integrate with SaaS providers like Salesforce and Snowflake.
- “The threat actors are known for identity attacks, where they target employees through social engineering, including vishing and phishing, to compromise corporate single-sign-on accounts. Once they gain access to an account, they log in to an organization’s Okta, Microsoft Entra, or Google SSO dashboard, which acts as a centralized hub listing all SaaS applications the user has permission to access.” * * *
- “Health-ISAC says the most important defensive step is breaking the attack chain between the initial vishing call and the takeover of an SSO account.
- “Organizations are advised to require out-of-band identity verification for password resets, MFA resets, and device re-enrollment requests.
- “This can include calling users back using a previously verified phone number and requiring manager approval for privileged accounts.”
- Cybersecurity Dive adds,
- “Dozens of North American companies have been targeted in a social engineering campaign that abuses Microsoft Teams to deploy ransomware, according to a report by cybersecurity firm Sophos.
- “A threat group, tracked as STAC4749, has initiated chats or calls through Microsoft Teams under the guise of providing help desk or IT support to companies in the U.S. and Canada.
- “After initiating a remote session through Microsoft Quick Assist or the cloud-based RemSupp tool, hackers deploy PowerShell in order to establish persistence and execute malicious payloads.” * * *
- “In at least three cases, the hackers deployed Chaos ransomware on a compromised system. Researchers said in one of the cases, the time between initial access to deployment of ransomware was 17 hours, which is consistent with prior Chaos cases.
- “The observed attacks ran between February and June, targeting organizations in the services, manufacturing, energy, construction and engineering sectors.”
- Cybersecurity News informs us,
- “The Gentlemen ransomware operation is drawing attention for its aggressive effort to disable security software before locking files. Instead of relying only on fast encryption, the attackers attempt to remove the tools that could detect, block, or contain the attack.
- “This approach raises the risk for businesses because antivirus and endpoint monitoring tools may be silenced when they are needed most.
- “The campaign’s exact initial access method was not detailed, but the activity shows attackers preparing systems for encryption after obtaining a foothold.
- “Catalyst analysts identified the malware component as
anticheatG13.sys, a kernel-level driver with broad capabilities for manipulating processes, networking, files, and system memory.”
- Per Dark Trace,
- “Darktrace detected a multi-stage ransomware intrusion from its earliest stages, identifying reconnaissance, privilege escalation, lateral movement, command-and-control communications, and data exfiltration before encryption occurred. This analysis highlights how behavioral detection exposed attacker activity using legitimate tools and infrastructure, providing multiple opportunities for early intervention and containment. “
From the cybersecurity business and defenses front,
- Security Week reports,
- “Nvidia and a large group of technology, cybersecurity, and enterprise software companies announced on Monday the launch of the Open Secure AI Alliance, a new initiative aimed at developing and sharing open source tools, models, and techniques for securing AI systems and agents.
- “The effort builds on existing work from the Linux Foundation’s recently launched Akrites initiative and the OpenSSF community.
- “Inaugural partners of the Open Secure AI Alliance also include Adobe, Cadence, Capital One, Cisco, Cloudera, Cloudflare, Cognition, CrowdStrike, Databricks, Dell, DoorDash, Elastic, HPE, Hugging Face, IBM, LangChain, Microsoft, Naver, NetApp, Nous Research, OpenClaw, Palantir, Palo Alto Networks, Red Hat, Reflection AI, Salesforce, SAP, SK Telecom, ServiceNow, Siemens, Snowflake, SpaceXAI, Synopsys, Thinking Machines Lab, and TrendAI.”
- Cybersecurity Dive adds,
- “Microsoft on Monday announced the launch of Project Perception, an agentic security system designed to help defenders combat a rapidly evolving threat of AI-based attacks by malicious actors.
- “The company also introduced MAI-Cyber-1-Flash, an AI model that helps users identify and remediate vulnerabilities through an integration with the company’s MDASH code-scanning harness.
- “The launch is part of a major industry push to implement AI-based security that can protect corporate IT and critical infrastructure systems from sophisticated attacks. In the past year, threat actors have demonstrated the ability to speed and scale attacks in a way that traditional security technologies cannot match.”
- Forresters offers its take on how Project Perception should be implemented.
- The Wall Street Journal reports,’
- “Data-security company Cyera has agreed to acquire startup Oasis Security for $1 billion, the latest large deal in a wave of consolidation across the cybersecurity industry fueled by artificial intelligence.
- “The cash-and-stock acquisition would help Cyera bridge its data-protection platform with Oasis’s technology for managing nonhuman identities, such as AI agents and automated software, as companies grapple with the risks of deploying autonomous tools across their businesses. The companies expect the deal to close later this year.
- “The biggest catalyst for this acquisition is the customers,” said Yotam Segev, Cyera’s chief executive, who co-founded the company in 2021. “Our customers, and especially our shared customers, have been telling us that these capabilities belong together.”
- “The transaction between the two New York-based companies is among the largest cybersecurity acquisitions of the year, underscoring how AI is reshaping the industry.”
- Cyberscoop adds,
- “Okta announced Thursday it has signed a deal to buy Permiso Security, a cloud-based firm that tracks threats tied to human, machine, and AI-driven digital identities.
- “Permiso specializes in spotting risks after a user or system has already logged in, an area the industry refers to as identity threat detection and response. The company draws on more than 2,500 signals gathered from over 70 identity-related partners to flag issues such as excessive access permissions, unused credentials, unusual behavior from AI agents, and violations of internal security policies.
- “Ely Kahn, Okta’s chief product officer, told CyberScoop that Permiso will allow Okta to merge two functions that have operated separately: real-time threat detection and identity security posture management. “Today those are two separate products that don’t really talk to each other,” he said.”
- The American Hospital Association offers “Lessons Learned from Conversations with the FBI: Healthcare Cyberthreats and Best-practice Defense.”
- The Health Sector Coordinating Council provides a summary recap of the Operation Vital Signs National Cybersecurity Exercise which took place on July 21 an 22, 2026.
- The HIPAA Journal shares its HIPAA Audit Checklist.
- Tech Target gives us a CISO’s guide to privileged identity management.
- SC Media explains why “effective incident response plans elusive for most cybersecurity teams.”
- Here is a link to Dark Reading’s CISO Corner.
