Cybersecurity Saturday

Cybersecurity Saturday

From the frontier AI front,

  • The Wall Street Journal reports,
    • Google’s Gemini model accessed the internet and hacked other companies during a test of its cybersecurity capabilities, the first known example of the company’s artificial-intelligence systems autonomously committing such an act. 
    • “The hacks, which the company confirmed on Friday [September 18], occurred in May as part of a test run by the company Irregular, which was also involved in similar incidents disclosed by OpenAI, Anthropic and Meta
    • “In one of the cases, the model guessed passwords until it gained access to a protected system. In the other two cases, the model found credentials in a public repository that allowed it to then access protected systems. In each case, the model ended the intrusion after determining it had accessed a real company’s systems, Google said.
    • “Irregular notified Google about the hacks at the end of July, Google and Irregular said, in the wake of the discovery that OpenAI’s agents had hacked the AI software company Hugging Face. Google didn’t disclose the hacks until The Wall Street Journal reached out with inquiries this week.” * * *
    • “Worries about the cybersecurity capabilities of new models have increased since the July discovery of the Hugging Face hack. In that case, up to 1,200 agents coordinated on a secret message board inside OpenAI to try to cheat on an evaluation, a report by the third-party testing company METR revealed in August. 
    • “Last week, those concerns spilled into the mainstream after the dramatic quitting of Jacob Coxon, a former OpenAI researcher who had gone to Anthropic earlier this year. Over the weekend, leaders from Anthropic, OpenAI, Google and SpaceX all agreed on the need to slow down the rate of AI progress, although none of the companies have outlined exactly how that would happen.”
  • and
    • “The WSJ Technology Council Summit kicked off Monday afternoon [September 14] in New York City with an informal poll of the audience during a town hall conversation. In a show of hands, only a few people said they feared that AI could kill us all in the next decade, while about half of attendees indicated that they were in support of slowing down AI development at the frontier and prioritizing safety guardrails.
    • “But that slowdown didn’t apply to the deployment of AI within their organizations, where not all models are at the cutting edge and even the most advanced of them tend to be relatively well understood and tested by experience.
      “It’s in our hands and it’s up to us to apply [AI] for good, and I think it can do a lot of good for society,” said Vishal Talwar, president, FedEx Dataworks, and chief digital and information officer, FedEx.
      “Much of ensuing town hall discussion focused on the myriad ways in which companies were operationalizing AI.”
  • Cyberscoop adds,
    • “The AI hacking apocalypse is not inevitable.
      • “While large language models present real risks to society, experts say they can be tested and largely controlled using well-worn cybersecurity and policy choices.”
      • “Juan Andres Guerrero-Saade, a fellow for AI and security research at SentinelOne and an adjunct professor at Johns Hopkins University, said the hacks are worth taking seriously, but at a time when businesses and open-source maintainers should be focused on further hardening their systems and policymakers should be discussing new solutions, “what we see is cybersecurity being used essentially as an excuse for these AI doomer arguments.” * * *
      • “Guerrero-Saade is among a growing chorus of cybersecurity professionals who say that while AI systems pose real, unique threats to our systems, the apocalypse is far from inevitable. Most of the public concerns around the incidents, let alone worries about killer AIs attacking critical infrastructure, assuming control of the internet and wiping out humanity, are either technically impossible or can largely be controlled through established cybersecurity principles.
      • “There is this “narrative or magical thinking of ‘Well, AI is going to be able to hack everything, and therefore it can control everything, and therefore it’s going to kill us all,’” he told CyberScoop. “And you [think] these just don’t add up. They’re not very well-reasoned arguments.”
      • “This fatalistic narrative tied to AI’s eventual dominance doesn’t hold up under scrutiny, according to experts CyberScoop spoke with. In recent conversations, cybersecurity and national security professionals raised questions about both the technical solutions OpenAI and Anthropic use to contain their models, as well as the glaring absence of federal oversight from federal regulators or truly independent third-party review.”

From the cybersecurity policy and law enforcement front.

  • Per a Senate Finance Committee news release,
    • “U.S. Sens. Mark R. Warner (D-VA) and Ron Wyden (D-OR) today reintroduced the Health Infrastructure Security and Accountability Act, legislation to improve cybersecurity in our health care system amid a growing wave of cyberattacks that are compromising Americans’ sensitive information and disrupting access to critical care across the country.” * * *
    • “Specifically, the Health Infrastructure Security and Accountability Act would require the Department of Health and Human Services (HHS) to establish, enforce, and regularly update strong minimum cybersecurity standards for health care providers, health plans, clearinghouses, and business associates, with heightened standards for systemically important entities and entities critical to national security.
    • “The legislation would also require covered entities to develop continuity plans describing how it would resolve a tech failure or intrusion, conduct annual cybersecurity tests, and undergo independent security audits, while increasing fines for failure to meet security requirements and strengthening HHS oversight through annual cybersecurity audits. Additionally, this legislation would provide $1.3 billion to help hospitals strengthen their cybersecurity, including $800 million for hospitals in rural and underserved urban communities.
    • “Full text of the bill can be found here. A summary of the bill can be found here.”
  • Cybersecurity Dive reports,
    • “The Cybersecurity and Infrastructure Security Agency (CISA) will stop publishing weekly roundups of newly disclosed software vulnerabilities at the end of September, the agency announced on Thursday.
    • “CISA is ending its Vulnerability Bulletin “as part of its shift from severity‑based vulnerability management to a modern, risk‑based approach,” the agency said in a statement.
    • The weekly bulletins, published since early 2004, listed vulnerabilities published during the reporting period along with their CVEs, severity scores and brief descriptions.” * * *
    • “CISA said in its Thursday statement that sunsetting the bulletin aligns with the prioritization directive it issued in July, “which directs federal agencies to prioritize vulnerabilities based on real‑world risk factors, including evidence of exploitation and exposure, rather than severity scores alone.”
    • “As it discourages organizations from relying solely on Common Vulnerability Scoring System (CVSS) scores to decide which vulnerabilities to fix, CISA has also been highlighting the Stakeholder-Specific Vulnerability Categorization (SSVC) system as a more nuanced approach to vulnerability analysis.
    • “Chris Butera, CISA’s acting executive assistant director for cybersecurity, said on Wednesday at Google’s Cyber Defense Summit that the agency has been discussing SSVC with companies that sell vulnerability management software. “They’re building some of this prioritization into their vulnerability tooling,” Butera said.”
  • and
    • “The Cybersecurity and Infrastructure Security Agency (CISA) wants to hire critical infrastructure experts with broad, rather than specialized, knowledge as it tries to help defend the infrastructure community with limited resources.
    • “I need to be able to hire people that are highly adaptive, because I think the threat is continuing to evolve so much, and the exposure that we have within these critical infrastructure sectors is evolving so much,” acting CISA Director Nick Andersen told reporters after speaking at Google’s Cyber Defense Summit here on Wednesday [September 16]. “I need people that can pivot from day to day to be able to help meet all of these stakeholders where they are.”
    • “Andersen’s comments come as CISA prepares to onboard roughly 250 new employees as part of a hiring sprint meant to fill critical vacanciescreated by the Trump administration’s sweeping downsizing of the agency over the past two years. As ransomware gangs and nation-state hacker groups increasingly menace infrastructure operators, in some cases aided by destabilizing advances in AI, CISA’s supporters say its mission — and its partnerships — have become more important than ever.”
  • Per a Department of Health and Human Services news release,
    • “The U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) today [September announced a settlement with Ambry Genetics Corporation (Ambry) concerning potential violations of the Health Insurance Portability and Accountability Act of 1996 (HIPAA) Security Rule. Ambry, headquartered in Aliso Viejo, California, is a covered entity that provides genetic testing and clinical genomics services.
    • “In January of 2020, Ambry discovered that an employee’s email account was compromised by a phishing attack. The protected health information (PHI) of 225,370 individuals was potentially exfiltrated by the threat actor. Affected PHI included names, addresses, dates of birth, some Social Security numbers or driver’s license numbers, financial information, diagnoses and conditions, lab results, medications, and treatment information.” * * *
    • “The settlement resolves an investigation that OCR initiated after Ambry filed a breach report in March 2020 about the phishing incident that occurred in January 2020.  OCR found that Ambry had potentially violated provisions of the Security Rule, including:
      • “Failing to conduct an accurate and thorough risk analysis of the potential risks and vulnerabilities to the electronic protected health information (ePHI) held by Ambry;
      • “Failing to implement procedures for terminating access to ePHI when the employment of or other arrangement with a workforce member ends or access is no longer appropriate; and
      • “Failing to assign a unique name and/or number for identifying and tracking user identity in electronic systems containing ePHI.” * * *
  • “The resolution agreement and corrective action plan may be found at https://www.hhs.gov/sites/default/files/ocr-ra-cap-ambry-genetics-corporation.pdf [PDF, 51.88 MB].”
  • Cyberscoop adds,
    • “Another core member of the hacker subset of The Com involved in a spree of extortion attacks from at least 2021 to 2023 pleaded guilty to federal charges, according to court records released Tuesday.
    • “Ahmed Hossam Eldin Elbadawy, a 24-year-old from Texas, pleaded guilty exactly one year ago to wire fraud conspiracy and aggravated identity theft. His guilty plea wasn’t shared publicly until prosecutors filed an order of forfeiture this week seeking proceeds from Elbadawy’s criminal activities. 
    • “Elbadawy and his co-conspirators — Noah Michael Urban, a Florida man sentenced to 10 years in prison last year, and Tyler Robert Buchanan, a Scottish man who pleaded guilty to multiple cybercrimes in April and awaits sentencing — were part of an aggressive subset of The Com coined Scattered Spider.”
  • and
    • “Authorities seized the primary domain and other websites linked to NightmareStresser, one of the longest-running and most popular distributed denial-of-service operations used by cybercriminals globally, the Justice Department said Tuesday. 
    • “Cybercriminals of various motivations used the DDoS-for-hire service to launch hundreds of thousands of DDoS attacks or attempted attacks since at least 2022, officials said. 
    • “The takedown, part of an ongoing globally coordinated effort dubbed “Operation PowerOFF,” marks law enforcement’s continued targeting of IP stressers or DDoS booters that inundate websites, servers and networks with junk traffic, rendering legitimate sites inaccessible. The seizures were executed by the FBI Anchorage field office and the Royal Canadian Mounted Police.”

From the cybersecurity vulnerabilities and breaches front

  • HIPAA Journal notes,
    • “A hacking group has claimed responsibility for an August 2026 cyberattack on Cedar County Memorial Hospital in Missouri. Hacking-related data breaches have been reported by Next Level Medical in Texas and Grafton City Hospital in West Virginia.”
  • MSSP Alert adds,
    • “Artificial intelligence is fundamentally altering the economics of cybercrime, making attacks faster and less expensive to execute, as first reported by Channel Insider. Ransomware victims saw a 45% increase in the first half of 2026, while the average underground price for initial access dropped by 69%, from $1,427 to $439. This shift indicates that AI is enabling threat actors to target more organizations with greater speed and scale, even if individual attacks are not necessarily more successful.”
  • Cyberscoop reports,
    • “Researchers said they used Anthropic’s Claude and OpenAI’s Codex to identify a damaging flaw embedded in a popular software decoding tool that could leave major internet platforms, enterprise services, and web frameworks vulnerable to data theft and remote access.
    • “The vulnerability, nicknamed HEIF Heist, refers to the malware’s ability to trigger memory corruption errors in affected software, allowing the attacker to pilfer sensitive data from its victims. In a report published Thursday, the researchers laid out the potential damage an attacker could cause, including gaining access to internal OpenAI repositories, leaking user files, access tokens, and other sensitive data for online services like Amazon Web Services, and gaining remote code execution privileges across a range of online services, including Meta’s core product suite, GitHub Enterprise servers and open-source internet forum Discourse.”
  • and
    • “North Korean hackers are infiltrating tens of thousands of job seekers’ computer networks by posing as prospective employers, such as artificial intelligence firms, to steal sensitive information and millions of dollars worth of cryptocurrency, U.S. and allied governments warned Friday.
    • The security agencies behind the alert, attributed the group, known as WaterPlum or Contagious Interview, as operating under the 313 General Bureau of the Munitions Industry Department subordinate to the Central Committee of the Workers Party of Korea. The efforts dovetail with those of North Korean IT workers.
    • “WaterPlum actors pose as prospective employers to target software developers and IT professionals worldwide under the pretext of attractive job opportunities,” the agencies wrote. “They often impersonate legitimate Artificial Intelligence (AI), cryptocurrency, or Non-Fungible Token (NFT) companies and have also used recruiting services.”
    • Additionally, “Some WaterPlum actors also operate as North Korean IT workers performing web system design and development tasks on corporate web systems for clients,” read the alert from agencies in Japan, Australia and Germany, alongside the FBI and the Department of Defense’s Cyber Crime Center.”
  • Help Net Security tells us,
    • “A fake ChatGPT billing email is steering users to a copy of the OpenAI login page that keeps whatever username and password they type. Josh Varden of Cofense’s Phishing Defense Center traced the email’s payment button through a Google redirect to the attacker’s page.
    • “The lure targets ChatGPT users on work and personal accounts alike, and it copies the kind of bill a subscriber already expects. Credentials entered on the fake page go to the attacker, and the victim is sent on to an error page.” * * *
    • “Cofense listed three indicators: the Google redirect link and two paths on the same nxcli[.]io host, login.php and key.php. Mail teams can search their logs for all three. If you use ChatGPT, the check that matters takes two seconds: read the address bar and confirm it says auth.openai.com before you type a password.”

From the ransomware front,

  • Industrial Cyber informs us,
    • “New data from Comparitech disclosed a record 997 ransomware attacks worldwide in August 2026, averaging 32 attacks per day and representing a 23% increase from 809 attacks in July. The total surpassed the previous monthly record of 988 attacks recorded in February 2025. Businesses accounted for 861 attacks, up 24% from July, while ransomware incidents targeting healthcare providers rose 30% to 69. Utility companies recorded the sharpest sector increase, with attacks doubling from five in July to 10 in August. 
    • “Ransomware surge was led by Qilin and The Gentlemen, which together accounted for more than 26% of August’s attacks, with Qilin claiming 157 incidents and The Gentlemen 107. Qilin’s attack claims increased 22% during the month, while The Gentlemen’s declined 21%; Qilin also had 12 confirmed attacks, compared with eight for The Gentlemen.” * * *
    • “Attacks on healthcare providers increased by 30% from July 2026 to August 2026, rising from 53 to 69. Eight attacks were confirmed in August. Three of the confirmed attacks took place in the U.S. Nutex Health Inc. noted unauthorized activity on its systems in a SEC filing on Aug. 24, 2026, and The Gentlemen claimed the attack. Cedar County Memorial Hospital experienced disruption to its IT networks on the afternoon of Aug. 14, 2026, with operations returning to normal on the morning of Aug. 28. Wallstreet claimed the attack. At Windrose Health Network, hackers exploited a vulnerability in the network’s remote-management tool in early August, resulting in a data breach. Storm claimed the attack.” 
  • Beckers Health IT reports,
    • “Jackson-based University of Mississippi Medical Center did not pay a ransom in connection with the cyberattack that disrupted its systems in February, according to officials.
    • “UMMC Vice Chancellor of Health Affairs LouAnn Woodward, MD, told SuperTalk Mississippi the state did not compensate hackers following the Feb. 19 attack. State Sen. Nicole Akins Boyd, who chairs the Universities and Colleges Committee, corroborated Dr. Woodward’s account.
    • “The statements come after State Auditor Shad White said his office would investigate the incident and notify the public if the government had paid a ransom.
    • “The cyberattack knocked out UMMC’s phones, website, records database and IT systems, forcing partner clinics to close for nine days and staff to record patient information by hand. The medical center returned to full operations Feb. 27.”
  • Cybersecurity Dive relates,
    • “Security researchers warn that a newly discovered ransomware variant called Settra has targeted virtual private network environments or compromised credentials for initial access before deploying remote monitoring and management tools to gain persistent access in targeted environments. 
    • “Researchers from Huntress observed two specific attacks in recent months, including a July incident at a consumer services and retail organization and a September incident at a manufacturing firm, according to a blog post published Thursday [September 17].
    • “The attackers could be described as capable rather than sophisticated,” said Lindsey O’Donnell-Welch, principal technical community engagement writer at Huntress. “They used effective, established ransomware tradecraft: MeshAgent for persistence, a vulnerable driver to potentially impair defenses, log clearing and recovery tampering.”
    • “Researchers from MoxFive said Settra used compromised VPN credentials to gain initial access and posted numerous victim organizations on its shaming site. The group claims to target organizations with exploitable weaknesses, such as unpatched systems or weak access management, according to a blog post from MoxFive.”
  • Bleeping Computer lets us know,
    • “The ShinyHunters extortion gang breached the Clop (aka Cl0p) ransomware operation’s data leak site, defacing the Tor site and allegedly stealing server data and the private keys for its onion service.
    • “The attack began Friday night [September 18] when ShinyHunters exploited what they claim is an unauthenticated file upload vulnerability in Grav CMS, which they used to upload a small text file to Clop’s site.
    • “The small text file contained a message from the threat actors to the Clop ransomware gang, warning not to threaten them and including a link to ShinyHunter’s own data leak site.”
  • InfoSecurity Mag tells us,
    • “It is a scenario that every CISO hopes they never face: the network encrypted by ransomware attack and cybercriminals who claim to have stolen sensitive data which they will leak if they don’t receive a ransom payment.
    • “Unfortunately for Zach Lewis, CISO at the University of Health Science and Pharmacy (UHSP) in St. Louis, this was the reality he faced when the organization was hit by a LockBit ransomware attack in summer 2023. The University recovered without paying the ransom, but it was a challenging time for all involved.
    • “In a conversation with Infosecurity, Lewis opened up about how it felt to be the victim of a ransomware attack and the toll it took on his team, as well as how the organization recovered from the incident and the lessons other cybersecurity leaders can learn from this experience.”

From the cybersecurity business and defenses front

  • The Wall Street Journal reports,
    • “Companies are facing a new era in cyberattacks driven by AI. But according to one cybersecurity CEO, having the right technology for defense isn’t necessarily the problem. It’s the humans who need to step up—particularly CEOs.
    • “What we’ve seen practically from working with some of the largest organizations in the world is that the technology is already there,” Galina Antova, CEO of the AI-driven security platform Kai, said at the Leadership Institute’s WSJ Technology Council Summit this week. “We could implement so many improvements,” using autonomous AI, she added.
    • “But what it really comes down to is having “the right incentive for the leaders to pursue that,” and “are they enabling their security organization to really move at machine speed?” 
    • “Companies need courage and leadership, she told enterprise tech bureau chief Steve Rosenbush, in a discussion that included Oege de Moor, founder and CEO of cybersecurity firm XBOW. 
    • Some additional insights from their conversation:
      • “Companies may need to redesign their security workflows. Attackers are “already moving at machine speed,” and they’re encountering a patchwork of protections, Antova reported. She has found that many Fortune 500 companies use some 80 to 120 security tools “that are organized in a very fragmented way,” she said. That means that when a company has an exposure, it can take time—days, weeks, or months—to find and close it. By contrast, she said, an end-to-end autonomous defense system that’s supervised by humans can reduce that time to minutes.” * * *
      • “[B]oth CEOs noted that the gap between frontier and open models was shrinking—and Antova added that with the right cybersecurity expertise and a surgical approach to deployment, the cost of AI-enabled security no longer needs to be prohibitive.”
  • Cybersecurity Dive adds,
    • “Artificial intelligence is now the leading driver behind new investment into cybersecurity budgets, according to a report released Tuesday from IANS and Artico Search.  
    • “About seven of every 10 chief information security officers surveyed said AI was their top priority for new cybersecurity spending. Two specific areas for AI-related spending shown in the report include automating security operations and enhancing identity and access management. 
    • “Overall security spending rose 5% in the current survey, which is barely ahead of the 4% spending increase in the year-ago report. AI spending priorities come at a time of relatively modest growth in overall security spending.”
  • Per CISA news releases,
    • “The Cybersecurity and Infrastructure Security Agency (CISA) hosted Cyber Storm X this week, a four-day national cybersecurity exercise designed to test and ultimately strengthen the nation’s resilience. This year’s exercise included 2,000 participants from across the public and private sectors and marks the tenth exercise in the 20-year history of Cyber Storm. The biennial exercise brings together the people who manage the services our nation relies on, including water, energy, and other vital sectors. During the exercise, participants practice how they would respond to a major cyber incident affecting critical infrastructure.
    • “Cyber Storm helps critical infrastructure owners and operators understand how we would manage a large-scale cyber incident,” said Acting CISA Director Nick Andersen.  “Exercises strengthen our national resilience by making sure our plans, policies, and partnerships are ready when we need them.  As a nation, we need the ability to respond swiftly and effectively to critical threats. That’s exactly what Cyber Storm does and why it’s a vital exercise for our nation’s security.”
    • “This year’s exercise focused on a scenario involving a nation-state adversary targeting the transportation systems sector, including rail and ports, along with the water and wastewater systems sector. The exercise allowed participants to test response plans, practice coordination, and strengthen information sharing in a safe environment. Cyber Storm X included over two hundred organizations across all levels of government and the private sector.
    • “CISA will now collaborate with participating organizations to identify lessons learned from the exercise. We will use these findings in a public after-action report that captures observations, analyses, and recommendations. CISA is committed to providing access to a wide range of cybersecurity tools and training opportunities, with exercises being a critical part of that toolkit to enhance our nation’s cyber preparedness.
    • “For more information, please visit Cyber Storm X: National Cyber Exercise.”
  • and
    • “Today [September 16], the Cybersecurity and Infrastructure Security Agency (CISA) released guidance that helps critical infrastructure owners and operators implement realistic decoy systems and information assets to quickly detect and disrupt malicious activity occurring in their networks, which will ultimately improve their cyber defenses. Using Cyber Decoys to Strengthen Detection and Response is the first guide from CISA that offers a detailed explanation of the defensive cyber decoy process.
    • “Many organizations struggle to detect adversaries who use legitimate credentials, native tools, and living off the land techniques to conduct discovery, move laterally, and access data. In this guide, CISA encourages critical infrastructure organizations to incorporate cyber decoy capabilities alongside existing Zero Trust models. Cyber decoy strategies operate on the expectation that malicious actors may eventually gain some level of access. By placing decoys within internal networks and systems, especially in high-value areas, organizations can enable defenders to:
      • “Detect adversaries operating within the environment early in the intrusion lifecycle;
      • “Gather and analyze information taken from intrusions and attempted intrusions;
      • “Allocate defensive resources more effectively based on observed adversary behaviors;
      • “Reduce mean time to detection (MTTD) by generating high-fidelity alerts.” * * *
    • “To effectively use this guide, cyber defenders should have a basic understanding of the MITRE ATT&CK ® Matrix and common enterprise security controls and tools. The guide provides a practical approach to designing and implementing decoy strategies by leveraging the MITRE ATT&CK® knowledge base and the MITRE Engage™ framework.
    • “For more information, please visit Cybersecurity Best Practices.”
  • and
    • “The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology (NIST) today [September 15] released Interagency Report (IR) 8587, Protecting Tokens and Assertions from Forgery, Theft, and Misuse: Implementation Recommendations for Agencies and Cloud Service Providers (CSPs). The report guides federal agencies and CSPs in defending the identity tokens and assertions that underpin modern single sign-on (SSO), federation, and application programming interface (API)-based access, systems adversaries increasingly target to move laterally through enterprise networks and reach sensitive data.
    • “The final report incorporates key feedback from nearly 250 public comments on token validation, secrets management, and detection at scale. The report also reflects input from CISA’s long-term, strategic collaboration with industry CSPs and interagency partners through the Joint Cyber Defense Collaborative. CISA and NIST engagements with this group included a technical exchange in June 2025 with over 50 industry experts to identify approaches to harden identity infrastructure and a webinar in January 2026 to review the draft report. Dozens of individual meetings with CSPs were also held to discuss feedback that included Google, HashiCorp, an IBM Company, IBM, Microsoft Corporation, Okta Inc., the OpenID Foundation, Oracle America, Inc., Amazon Web Services, and Wiz.” * * *
    • “The recommendations in the final report apply across commercial and government-operated cloud services and support implementation of Executive Order 14306 on secure software development practices.
    • “CISA urges federal agencies, CSPs and cloud consumers to review and implement IR 8587 to improve the security of their cloud systems. 
    • “For more information on this effort, read NIST’s News Release.
  • Tech Target offers a tip about “how to verify the value of AI-powered business analytics.”
    • Executives can separate AI analytics capabilities from marketing hype by taking steps to confirm the platform improves decision-making and gives results that hold up.
  • Here is a link to Dark Reading’s CISO Corner.

Cybersecurity Saturday

From the frontier AI / Project Glasswing front

  • Daniel Borish writes in LinkedIn,
    • Anthropic released its fourth threat intelligence report on September 10, 2026, covering activity its Threat Intelligence team disrupted between December 2025 and August 2026. The report documents cases across seven categories of harm: cyber operations, surveillance, influence operations, conventional weapons development, biological misuse, scams and fraud, and illicit distillation. The company assigns each disrupted actor an internal designator, a Generative Threat Group (GTG) number, and publishes case studies detailing how each group used Claude models, along with indicators of compromise for other defenders to act on.
    • “The report’s central claim is not that AI created new categories of attack. Credential theft, phishing, SQL injection, and unpatched edge devices remain the entry points they have always been. What changed is who can run these attacks at what speed. Anthropic’s investigators found a suspected Russian state espionage unit, a network of financially motivated ShinyHunters affiliates, Chinese university students moonlighting in exploit research, and a lone French hacktivist all using functionally similar AI-orchestrated methodologies to run multi-victim campaigns that would previously have required coordinated teams.”
  • The Wall Street Journal reports,
    • “Artificial intelligence agents being tested by OpenAI launched a cyberattack against a popular software service two months before they hacked the AI software company Hugging Face, a new signal of the potential for advanced AI tools to slip out of human control.
    • “The attack overwhelmed maintainers of an online service for coders, called RubyGems, and forced them to shut down new account registrations as they dealt with the chaos it had caused, operators of the service said.
    • “A coalition of AI researchers said it had unearthed evidence that OpenAI agents were behind the May attack and shared its findings with The Wall Street Journal and OpenAI. The AI developer on Friday confirmed that its agents had been involved in an incident involving RubyGems.
    • “Based on our review, our agents used the RubyGems platform to access the internet to carry out benign tasks and retrieve public information. We’ll continue to investigate as part of our broader review of agent activity during training and evaluation,” an OpenAI spokeswoman said in a statement.”
  • and
    • “An Anthropic researcher is quitting the artificial-intelligence industry over fears that the lab and its competitors are racing to build systems they won’t be able to control, a sign of mounting safety concerns within top AI companies.
    • “Jacob Coxon, a researcher who specializes in training new AI models by having them consume vast amounts of data, said Tuesday that he is leaving the company because he doesn’t want to participate in an industrywide rush to build AI systems that can improve themselves, worried such systems could spiral out of control and destroy humanity.
    • “The 27-year old Brit, who previously studied mathematics, said many of his industry colleagues now use phrases like “crunchtime” and “endgame” to describe the trajectory toward self-improving models.” * * *
    • “Anthropic didn’t immediately comment on the departure. Chief Executive Dario Amodei and other company leaders have repeatedly warned about the risks of rogue AI models, and urged the industry to slow development
    • “After Coxon announced his departure, a top scientist at the company, Evan Hubinger, wrote on X that he thought Coxon was correct about the risks of AI development.
    • “We really do earnestly believe AI could kill all humans! I personally think it is >10% within the next decade,” Hubinger wrote. “I believe Anthropic is trying its best, but we do not yet have a plan to solve alignment for superintelligence and are not clearly on track to.” Others also amplified the view.”
  • Per Axios: “Nvidia CEO Jensen Huang: AI fears designed to generate cybersecurity business.”
  • BigGo Finance lets us know,
    • “A bipartisan group of US senators is negotiating legislation that would create a legal duty of care for frontier AI developers, requiring them to prevent catastrophic risks and giving the federal government authority to block unsafe model releases. The proposal, led by John Thune, Ted Cruz and Amy Klobuchar, would apply to advanced models from companies such as OpenAI, Anthropic and Google, with national laboratory experts potentially conducting hands-on testing for nuclear, biological and cyber threats. Companies could appeal government blocking decisions in federal court. The measure would also preempt state AI safety laws. With the House in session only one week before the November 3 midterms, passage remains uncertain despite growing pressure on Congress to address frontier AI risks.”
  • Axios adds,
    • “A letter is circulating among House members urging Speaker Mike Johnson (R-La.) to bring back the House “immediately” and keep it in session until Congress passes AI safeguards, Axios has learned.”
  • The Wall Street Journal notes,
    • “President Trump, who has taken a light touch overseeing the sector, previously said he is in favor of kill switches and other steps to keep AI safe but has warned burdensome regulation could cost the U.S. in the tech race.”
  • and
    • “The leaders of three of the biggest AI companies agreed [September 12] that they needed to slow development of the technology before their advances create a menace that can’t be controlled.
    • “It was a rare display of unity by Elon MuskSam Altman and Dario Amodei, who have been spending tens of billions of dollars to develop evermore powerful artificial intelligence models. Altman even suggested that his company, OpenAI, may need to delay its much-anticipated IPO to focus on safety.”

From the cybersecurity policy and law enforcement front,

  • Per GovCIO Media,
    • “Federal agencies are looking to deepen their partnership with the private sector to protect critical infrastructure, with joint efforts to identify vulnerabilities, deploy technology and scale solutions.
    • “National Cyber Director Sean Cairncross said Thursday [September 10] at the Billington Cybersecurity Summit in Washington that government and industry need to work “hand in glove” rather than rely on compliance checklists as technology increasingly shapes both critical infrastructure and the threats against it.
    • “We’re in a moment technologically where security and innovation have melded, and in order to move forward, protect critical infrastructure, make sure the systems that our citizens rely on for daily life are protected and secure, we need a relationship that is hand in glove, and that means we cannot be dictating a compliance checklist to industry,” said Cairncross.”
  • Federal News Network reports,
    • “The FBI released its first agency-wide, unclassified cyber strategy on Wednesday, with the goal of unifying efforts across the bureau’s 56 field offices to counter both nation-state threats and cyber criminals.
    • “The 17-page strategy details a four-pillar approach to countering cyber threats across the bureau. Brett Leatherman, assistant director of the FBI’s Cyber Division, said previous cyber strategies for the bureau have either been classified or focused on specific threats, like countering China.
    • “This is a comprehensive strategy that directs our teams, our field offices, our global presence, and how we are to align all our efforts to counter this work,” Leatherman told reporters after speaking at the Billington Cybersecurity Summit in Washington on Wednesday morning [September 9].”
  • and
    • “The CIA is pushing to bring more scientific and technical expertise into its workforce, with a top official touting a big year for hiring despite widespread cuts across the intelligence community over the past year.
    • “Michael Ellis, the deputy director of the CIA, said the spy agency is seeking to recruit more employees with backgrounds in science and technology. Ellis described a STEM background as not a prerequisite for intelligence in work in 2026, but “it sure helps make things easier.”
    • “When I think about, you know, where we want the CIA workforce to be five years from now, it’s an elite workforce,” Ellis said at the Billington Cybersecurity Summit in Washington on Tuesday. “It’s a nimble workforce. It’s one that has more technical background than it has today, and it’s one that is motivated by mission.”
  • Cybersecurity Dive adds,
    • “As the federal government scrambles to protect its own networks and support critical infrastructure operators, CISA is preparing to bring in roughly 250 new employees to rebuild core teams.
    • “We’re looking forward to welcoming hundreds of new CISA employees in the very near future,” acting CISA Director Nick Andersen told reporters after a talk at the Billington Cybersecurity Summit here on Wednesday.
    • “The employees have received tentative job offers and are “waiting to get that official start date,” Andersen said during his speech.”
  • Cyberscoop points out,
    • “The private sector still isn’t sharing enough cyber information with the FBI in part because organizations are operating on false assumptions about what the bureau will do with what it collects, the FBI’s top cyber official said Wednesday.
    • “Brett Leatherman, assistant director of the FBI’s cyber division, said in remarks at the Billington CyberSecurity Summit and in a discussion with reporters that organizations stand to benefit from bringing in the bureau when it’s compromised by hackers from the People’s Republic of China (PRC) and others. But one of the “key misconceptions” is that “the FBI is somehow sharing information with regulators for regulatory purposes, and that’s not the case.”
    • “From my standpoint over the last few years, I think we’ve seen a hesitancy on some companies to engage [with the] FBI,” Leatherman said.”
  • and
    • “The U.S. government is accusing Chinese AI companies of engaging in a deliberate and “systematic” effort to illegally distill U.S. frontier AI models and their capabilities. 
    • “According to a joint cybersecurity advisory from the National Security Agency, the Cybersecurity and Infrastructure Security Agency and the FBI, the sheer scale of these efforts since 2024 indicate that distillation is a critical part of China’s AI industrial policy.
    • “China-based artificial intelligence companies are conducting systematic extraction of proprietary functionalities and capabilities of U.S. AI companies’ models through industrial-scale knowledge distillation campaigns that form the core—not merely a supplement—of their AI development strategy,” the agencies wrote. 
    • “The advisory names Chinese companies like DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI, saying they spent billions of tokens across millions of exchanges and requests with frontier U.S. AI models like Anthropic’s Claude, OpenAI’s ChatGPT, Google Gemini, and xAI’s Grok, since at least late 2024.”
  • The Justice Department made available “Remarks by Deputy Assistant Attorney General Josh Goldfoot of the Justice Department’s Criminal Division at the International Symposium on Cybercrime Response” held in Seoul, Korea.
  • Beckers Health IT notes,
    • “A Ukrainian national who helped deploy Conti ransomware against more than 1,000 victims worldwide has been sentenced to four years in prison for conspiracy to commit wire fraud.
    • “Oleksii Oleksiyovych Lytvynenko, 44, formerly of Cork, Ireland, admitted to joining the Conti operation and coding a “loader” — malware used to deliver other malicious software onto compromised systems, according to a Sept. 10 U.S. Justice Department news release. He pleadedguilty June 10.
    • “Conti attacked computers and networks in 47 states, the District of Columbia, Puerto Rico and 31 countries between 2020 and 2022, and the FBI estimates the group collected more than $150 million in ransom payments. Evidence from Mr. Lytvynenko’s online accounts showed he possessed data stolen from eight U.S. victims and four overseas victims. He was arrested in County Cork, Ireland, in July 2023.”

From the cybersecurity breaches and vulnerabilities front,

  • HIPAA Journal released its June 2026 Healthcare Data Breach Report.
    • “In June 2026, 66 large healthcare data breaches – data breaches involving the protected health information of 500 or more individuals – were reported to the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) – a slight increase from the 64 data breaches reported in May. More than two large data breaches a day is the new normal. Over the past 12 months, an average of 65 large healthcare data breaches have been reported per day; eight years ago in 2018, large healthcare data breaches occurred at a rate of around one per day.”
  • Beckers Health IT reports,
    • “Houston-based Nutex Health says the hackers behind its August cyberattack have published the data they allegedly stole on their own website.
    • “The publicly traded micro-hospital operator is now downloading, processing and analyzing that data to determine its contents, scope and authenticity, according to a Sept. 10 SEC filing. Nutex said the review could take several weeks given the volume of data involved.” * * *
    • “Nutex said it has not identified any material impact on its business operations or financial reporting systems, and its materiality assessment from the Aug. 31 filing remains unchanged. The company said it continues to evaluate regulatory and legal notification requirements and intends to notify affected patients and employees.
    • “Several purported class action lawsuits have been filed against Nutex in the U.S. District Court for the Southern District of Texas’ Houston Division on behalf of individuals whose personal or health information was allegedly accessed. Nutex said it cannot predict the litigation’s outcome or its potential financial impact.”
  • and
    • “Annapolis, Md.-based Luminis Health’s phone system and MyChart patient portal remain unavailable as the health system continues responding to a cybersecurity incident involving an unauthorized criminal actor.
    • “In a Sept. 10 update, Luminis Health said its investigation is ongoing and teams are working with third-party experts to safely restore affected systems.
    • “The health system said its hospitals remain open and continue providing patient care.”
  • and
    • Recent cybersecurity warnings and incidents are highlighting risks for healthcare organizations that extend beyond ransomware, including cloud authorization abuse, voice phishing, brand impersonation, third-party access and publicly exposed information.
    • [The article describes] five recent cybersecurity developments Becker’s has reported on in September.]
  • Security Week adds,
    • “More than 4.1 million individuals had their personal, health, and insurance information stolen in a data breach at healthcare company AdaptHealth.
    • “Operating over 680 facilities across the US, AdaptHealth describes itself as a network of medical equipment companies that provides patients with healthcare solutions and medical equipment.
    • “The company was hacked in early June, when a threat actor gained access to its cloud-based applications, including internal systems used for patient management and document storage.
    • “After the attacker contacted the company, it confirmed the data breach, including the theft of a password file associated with insurance billing.
    • “The hacker used social engineering to compromise a user session at a third-party contractor, AdaptHealth said.”
  • and
    • “Future phishing campaigns may no longer involve a detectable physical web page.
    • “Barracuda has analyzed a new type of phishing campaign that adds both stealth and flexibility to traditional phishing. Rather than standard social engineering to persuade a target to visit a static compromised web page, this campaign generates a blob URL to render and deliver the phishing page inside the target’s own browser. This reduces the possibility of security scanners detecting either the social engineering email or the static residence of the phishing page.”
  • HIPAA Journal lets us know,
    • “Three high-severity vulnerabilities have been identified in NextGen Healthcare Mirth Connect (Mirth Connect), a cross-platform healthcare integration engine for connecting, routing, transforming, and exchanging clinical and administrative data between different healthcare systems. The vulnerabilities are due to improper neutralization of special elements used in SQL commands and improper restriction of XML External Entity Reference. Successful exploitation of the vulnerabilities could allow denial-of-service attacks and data exfiltration.
    • “The vulnerabilities were identified by security researcher Abhinav Agarwal using autonomous agents running his published methodology on AI-assisted vulnerability discovery. “Mirth Connect is effectively a switchboard between healthcare systems. It can sit between lab systems, imaging systems, databases, and clinical applications, so a vulnerability in the integration layer can expose much more than one isolated application,” Agarwal told The HIPAA Journal. A potential problem is that healthcare organizations may not know that they have a vulnerable component in one of their products. “A hospital may not see the name Mirth anywhere on the product it bought. Integration software can be managed, resold, or embedded inside another product, which is why SBOMs and exact version disclosure matter after vulnerabilities like these,” explained Agarwal.”
  • CISA added 14 known exploited vulnerabilities to its catalog this week.
    • September 8, 2026
      • CVE-2026-75650 Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability
      • CVE-2026-81963 Microsoft Windows Link Following Vulnerability  
      • CVE-2026-85880 Microsoft Windows Heap-Based Buffer Overflow Vulnerability 
      • CVE-2026-86218 N-able N-central Static Code Injection Vulnerability
        • SOC Prime discusses the Adobe KVE here.
        • The Hacker News discusses the Microsoft KVEs here.
        • Cybersecurity Dive discusses the N-able KVE here
    • September 9, 2026
      • CVE-2025-25249 Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability
      • CVE-2026-19490 Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability
      • CVE-2026-87491 Google Chromium V8 Out of Bounds Write Vulnerability
      • CVE-2026-20079 Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability 
        • Security Week discusses the Fortinet KVE here.
        • Cybersecurity News discusses the Citrix KVE here.
        • SOC Prime discusses the Google KVE here.
        • The Cybersecurity Hub discusses the Cisco KVE here.
    • September 10, 2026
      • CVE-2026-67277 MikroTik RouterOS Missing Authentication for Critical Function Vulnerability
      • CVE-2026-86060 MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability
        • Bleeping Computer discusses these KVEs here.
    • September 11, 2026 (1)
      • CVE-2026-42016 JFrog Artifactory Incorrect Authorization Vulnerability 
      • CVE-2026-42018 JFrog Artifactory Improper Authentication Vulnerability 
      • CVE-2026-84869 ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability
        • The Hacker News discusses the JFrog KVEs here.
        • Security Arsenal discusses the ConnectWise KVE here.
    • September 11, 2026 (2)
      • CVE-2026-85706. GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability
        • Cyberscoop discusses this KVE here.
  • Dark Reading adds,
    • “A new analysis of public data from Anthropic’s Project Glasswing has highlighted a significant gap between the number of vulnerability findings generated by its Claude frontier model and those that ultimately prove to be real, serious, and worth fixing.
    • “The distinction matters because it suggests that the bottleneck in vulnerability research may increasingly lie in validating new flaws and coordinating their remediation rather than in discovering them.”
  • Security Week tells us,
    • “Anthropic disrupted a cyberespionage operation whose tradecraft and targeting match the Russian state-nexus group tracked as Midnight Blizzard, the company said in a threat intelligence report published this week. 
    • “The report covers activity the company identified and shut down between December 2025 and August 2026.
    • “According to Anthropic, Midnight Blizzard used Claude to monitor how well its malware evaded detection by security products. When a tool was flagged, AI agents automatically modified and rebuilt it, then redeployed it, repeating the process until the malware went undetected again.”

From the ransomware front,

  • The Hacker News reports,
    • “Cisco has revealed that three distinct threat clusters linked to ransomware and state-sponsored attacks have been exploiting two recently patched Secure Firewall Management Center (FMC) vulnerabilities.
    • “The attacks leverage CVE-2026-20079 (CVSS score: 10.0), an authentication bypass vulnerability in the web interface of FMC software that could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system.
    • “The second flaw under exploitation is CVE-2026-20316 (CVSS score: 5.3), which could allow an unauthenticated, remote attacker to log in to an affected device using a low-privilege account to access sensitive data within susceptible systems. It can be paired with other Cisco Secure FMC vulnerabilities to elevate privileges.” * * *
  • Cybersecurity Insiders relates,
    • “Ransomware attacks are becoming increasingly common, posing a serious threat to businesses across industries. A recent study conducted by Object First in collaboration with technology research firm Omdia highlights not only the growing frequency of these attacks, but also the increasing difficulty businesses face in recovering their data after an incident.
    • “According to the study, ransomware is having a significant impact on business operations. Over the past 24 months, around 84 percent of businesses surveyed admitted that file-encrypting malware had severely disrupted their operations. This represents a considerable increase from the previous year, when only 64 percent of businesses reported experiencing such disruption.
    • “The findings become even more concerning when it comes to data recovery. Only 39 percent of ransomware victims said they were able to recover at least 80 percent of their data following an attack. This is a sharp decline from the 57 percent reported the previous year. The figures indicate that businesses are not only encountering ransomware more frequently but are also finding it increasingly difficult to restore their systems and recover critical information.” * * *
    • “The decline in successful data recovery also highlights the importance of preparedness. Simply preventing an attack is no longer enough. Organizations need comprehensive backup and recovery strategies that can help them restore critical systems quickly in the event of a successful breach. Regularly tested backups, robust access controls, employee awareness training and well-defined incident-response plans can all play an important role in reducing the damage caused by ransomware.
    • “The latest findings suggest that ransomware has evolved into a broader business continuity challenge. As attacks become more frequent and sophisticated, organizations must focus equally on prevention, detection and recovery. Investing in resilient infrastructure and reliable data protection could prove crucial in ensuring that a ransomware incident does not turn into a prolonged business crisis.”
  • Help Net Security adds,
    • “In this Help Net Security video, Kerri Shafer-Page, VP of Incident Response at Arctic Wolf, walks through the ransomware decision tree in this video. She covers four areas where decisions need settling in advance, starting with containment.
    • “Someone has to know the network well enough to judge what pulling a system offline does to client data, a manufacturing line, or a website. Then comes the extortion demand. Who is authorized to negotiate, and what is the ceiling?
    • “Shafer-Page treats paying as a business decision, noting that a demand can cost less than an insurance retention and higher renewal rates. She argues law enforcement belongs in the playbook, since agencies may know the threat actor and can help you avoid sanctions problems.
    • “Communication matters too, from cyber legal counsel on disclosure deadlines to a spokesperson and a prepared help desk. Her advice: make these decisions on a Tuesday afternoon, not at 2 a.m. on a holiday weekend.”
  • and
    • “In this Help Net Security video, Dave Ross, Senior Director of the Intelligence Fusion Team at Intel 471, explains what happens behind the scenes during ransomware negotiations.
    • “Ross walks through the tactics groups use once an attack begins, from research on a victim’s revenue and insurance coverage to test decryptions that prove they hold a working key.
    • “He describes how demands are often set at roughly 1% to 5% of annual revenue, why deadlines move depending on how a victim responds, and how some groups split work between researchers, negotiators, and staff who apply public pressure.”

From the cybersecurity business and defenses front,

  • Cryptobriefing reports,
    • “Tenable Holdings is embedding Anthropic’s Claude Mythos 5 directly into its flagship cybersecurity product, betting that frontier AI models can fundamentally change how organizations spot and neutralize threats before attackers exploit them.
    • “The integration, announced on September 8, 2026, will bring AI-driven exposure analysis and attack-path discovery into the Tenable One Exposure Management Platform. The first concrete feature shipping under this effort is called Tenable One Adversary View, which uses Claude Mythos 5 to reconstruct how an attacker could move from an initial foothold all the way to an organization’s most critical systems.”
  • Per MedTech Dive,
    • “Boston Scientific disclosed Tuesday the cyberattack that recently hit the company is likely to affect third-quarter and full-year results.
    • “The medical device maker believes it is unlikely to meet net sales growth and adjusted earnings per share guidance ranges provided in July for the third quarter and full year, according to a new filing with the Securities and Exchange Commission.
    • “The Company anticipates recovering some portion of the impacted revenue as it continues to ramp operations globally, fulfill customer orders and reduce remaining backlogs, however the full impacts are not yet known,” Boston Scientific said in the filing.”
  • Cybersecurity Dive relates,
    • “After suffering a series of high-profile cyberattacks over the past decade, Microsoft says a new initiative to reinvigorate its security culture is bearing fruit.”
  • and
    • “Chief information security officers are largely expected to ensure the security of AI across the enterprise, but many say they are not receiving adequate support, according to findings from Proofpoint. 
    • “About 85% of CISOs said ensuring the safe use of AI assistants, copilots and automation is a top priority over the next two years, according to Proofpoint’s annual Voice of the CISO report. Eight of every 10 CISOs said they are expected to manage AI-related security risks without receiving a proportional increase in resources or expertise. 
    • “CISOs have a significant role to play in securing AI adoption, but they can’t own the risk alone,” Patrick Joyce, global resident CISO at Proofpoint, told Cybersecurity Dive. “AI is being adopted across the business, often faster than traditional governance models can keep up.”
  • and
    • “Advances in artificial intelligence aren’t changing the fact that simple cybersecurity failures remain the most consequential, government and industry leaders warned on Tuesday.
    • “What will prevent the attacks in the next 18 months are the same things that would have prevented the attacks of yesterday,” Jason Bilnoski, a deputy assistant director in the FBI’s Cyber Division, said during a panel here at the Billington Cybersecurity Summit.
    • “Core practices such as identity management, perimeter monitoring, cyber hygiene and strong multifactor authentication remain as essential as ever, Bilnoski said.
    • “Speed and capability is certainly increasing with the use of AI, but the end state is still the same,” he said. “How actors are compromising, whether it’s criminal or nation-state, still stays the same.”
  • HIPAA Journal tells us,
    • “The HHS has released an updated version of the Security Risk Assessment (SRA) Tool (v3.7). The tool is ideally suited for small- and medium-sized entities to guide them through the risk analysis process, help them identify risks and vulnerabilities to electronic protected health information (ePHI), and comply with the risk analysis implementation specification of the Security Management Process standard of the HIPAA Security Rule.”
  • CISA has released the 2026 edition of its Insider Threat Mitigation Guide.
    • “The Cybersecurity and Infrastructure Security Agency’s Insider Threat Mitigation Guide aids critical infrastructure stakeholders in comprehending the concept of insider threats, identifying the various forms these threats can take, and implementing best practices to establish or enhance an insider threat mitigation program. Such a program is essential for protecting critical assets, deterring violence, countering unintentional incidents, preventing loss of revenue or intellectual property, averting the compromise of sensitive data, and ultimately saving lives.”
  • Healthcare IT News informs us,
    • “Devices and sensors that collect heart rate and other health data and rely on applications to share information with third parties pose serious questions about data protection for patients and the health systems that care for them.
    • “While smart ring and watch data might help doctors treat patients, security experts say low security standards in consumer tech and improperly configured APIs present potential security risks for providers.
    • “Hackers can exploit such flaws, using consumer devices as entry points to breach receiving electronic health record systems and access centralized databases.
    • “To mitigate these threats, security experts say healthcare organizations must establish strict security protocols, including mandatory transit encryption, multi-factor authentication and account monitoring. They recommend zero-trust approaches to catch rogue traffic and implementation of rigorous engineering frameworks.”
  • Here’s a link to Dark Reading’s CISO Corner.

Cybersecurity Saturday

From the frontier AI front,

  • The Wall Street Journal reports,
    • Nvidia NVDA is planning to use a $6 billion deal it struck this week [August 22] to build one of the world’s most powerful open-weight AI models, one that would compete with Chinese heavyweights like DeepSeek and Kimi K3, according to people familiar with the matter.
    • “The chip giant’s licensing deal with the AI startup Poolside is also set to present a direct challenge to frontier U.S. AI companies including OpenAI and Anthropic, since open-weight models are generally far cheaper to operate and allow easy customization.
    • “Although Nvidia counts big labs like OpenAI and Anthropic as some of its closest partners, the move reflects Chief Executive Jensen Huang’s efforts to position Nvidia for success in multiple AI battlegrounds simultaneously, ensuring the company is able to hold on to its dominant market position.”
  • and
    • Nvidia and CrowdStrike are addressing what they see as one of cybersecurity’s biggest gaps: the need for cyber defenders to harness AI at the velocity of cyber attackers.
    • In the current cyber landscape, frontier AI models are discovering bugs at machine speed—raising alarm bells among experts, who warn that when autonomous hacking models go rogue or attack companies, chaos is on the horizon.
    • But cyber defenders aren’t getting enough of that same AI firepower, according to Nvidia and CrowdStrike, who on Tuesday [September 1] introduced a new family of agentic AI models, dubbed SafeMind, which can both find attack paths and close them for customers. The models are available in CrowdStrike’s flagship Falcon platform and through its API. * * *
    • “SafeMind has two models: Red Tempest, which is an “offensive” model that emulates AI adversaries, and Blue Solano, which is a “defensive” model designed to fix identified issues. The two models are connected by software called a harness, which runs the models in a closed-loop system that pits them against each other for self-improvement.”
  • The New York Times reports,
    • “Nvidia said on Thursday [September 3] that it is buying Hugging Face, a library of open artificial intelligence models, for $12.9 billion, as the chipmaker extends a spending spree in the escalating global race to dominate the technology.
    • “The deal marries Nvidia’s chip and data center infrastructure with Hugging Face’s millions of open-source A.I. models that can be freely downloaded and modified. And it puts Nvidia’s deep pockets firmly on one side of a debate over how A.I. systems should be built.
    • “Together, we will make A.I. more open, more capable and more accessible to people and institutions around the world,” wrote Jensen Huang, the chief executive of Nvidia, in a blog post.
    • “The acquisition is also another sign of Nvidia’s growing role as Silicon Valley’s central banker, using its vast financial resources to bolster A.I. start-ups and funnel money to customers for its chips. With $197 billion in current assets and nearly $60 billion in profits from its most recent quarter, the Silicon Valley giant has been spending heavily on A.I.”
  • Daniel Borish writing in LinkedIn lets us know,
    • Anthropic released Claude Fable 5.1 and Claude Mythos 5.1 this week, positioning them as its most capable models yet for coding and knowledge work. The two are the same underlying model, split only by the safeguards wrapped around them. Fable 5.1 is generally available. Mythos 5.1 is restricted to vetted cybersecurity and life sciences professionals through trusted access programs run in partnership with the US government.” * * *
    • “On the cybersecurity side, Claude Code users should see roughly 60% fewer safeguard interventions per session, and Fable 5.1 can now be used to find software vulnerabilities, though not to write exploits for them. Tasks like penetration testing, exploit generation, and binary-based vulnerability scanning still route to Anthropic’s Opus models. On biology, updated safeguards reportedly fire 85% less often on benign medical and elementary biology questions, though research-grade life sciences queries still get redirected to Opus, and full access to Mythos 5.1’s biology capabilities is limited to the government-linked Life Sciences Verification Program.
    • “Anthropic’s safety testing found Mythos 5.1 better aligned than its predecessor on several measures it tracks: less likely to seek resources outside its assigned environment when given an impossible task, less likely to reason its way around explicit constraints, and less likely to attempt or succeed at reward hacking. The company also disclosed limits to that picture, noting its behavioral audits have less visibility into very long-context work, multi-agent settings, and testing found the model can still sometimes bypass approval steps and automated review classifiers.
    • “Fable 5.1 also ships with new anti-distillation measures. New API accounts created from launch onward can no longer edit Claude’s prior context in a conversation while preserving the model’s recorded thinking, closing off a publicly documented technique used to extract that thinking at scale.”
  • The Wall Street Journal adds,
    • Anthropic has signed a cloud-computing deal worth $35 billion with NvidiaNVDA 3.21%increase; up pointing triangle-backed cloud provider Lambda, with Nvidia itself holding the lease on the data center, according to people familiar with the deal. 
    • The data center is being developed by Hut 8, a bitcoin miner and data-center developer, in Nueces County, Texas. Nvidia signed an agreement with Hut 8 a few weeks ago to secure the capacity, the people said. 
    • The convoluted arrangement is another example of Nvidia’s growing role in helping non-investment-grade firms such as Anthropic get access to its expensive computing resources. The deal also helped a nascent cloud provider, Lambda, secure a lucrative contract with Anthropic without needing to procure the data-center space on its own. 
    • Lambda will use the data center Hut 8 is developing to plug in chips bought from Nvidia, which is also its investor. It is not clear how much Lambda will pay Nvidia to access the data-center space.
    • Anthropic has been racing to sign cloud-capacity deals after hitting a supply crunch earlier this year that coincided with its products gaining traction. The AI developer signed a $45 billion deal earlier this month with another Nvidia-backed neocloud, Nscale, to rent Nvidia capacity from its West Virginia site, according to people familiar with the deal. 
  • Security Week relates,
    • OpenAI said its newest model, Astra, has reached the ‘Critical’ cybersecurity capability level under the company’s Preparedness Framework, the first time any of its models has been placed in that category. 
    • The designation applies when a model can independently find and exploit zero-day vulnerabilities across many well-defended systems, or carry out a complete cyberattack against a hardened target from only a high-level instruction. OpenAI said the classification requires additional safeguards before the model can be released.
    • In testing described by the company, Astra achieved a perfect score on ExploitBench, a benchmark that measures a model’s ability to turn known vulnerabilities into working exploits. During a separate evaluation involving more recently disclosed flaws, Astra uncovered two zero-day vulnerabilities on its own. 
    • The model also broke out of a browser sandbox to run commands on the underlying machine, and separately chained several flaws in a hardened operating system to gain root-level access.
    • OpenAI reported that Astra now declines 91.5% of cyber-related jailbreak attempts in its testing, up from 59% for its predecessor, GPT-5.6 Sol. The company also said Astra showed far less tendency than Sol to bypass safety restrictions or take advantage of deliberately placed “honeypot” targets during evaluations. 
    • Full cybersecurity capabilities will not be widely available at launch. OpenAI plans to give a group of testers early access, with wider availability to follow through its Daybreak Blue program.
  • Cybersecurity Dive adds,
    • “OpenAI on Thursday [September 3] said it would commit $1 billion in subsidized access and training to help small IT security teams use frontier AI to protect essential services, including electricity, water and local government services. 
    • “The Daybreak for Frontline Defenders program will be used to help defenders search for critical vulnerabilities in their software, hunt for suspicious activity in their technology stacks and stop malicious actions if hackers are able to gain access to their systems.
    • “OpenAI plans to roll out a six-month pilot program with the Multi-State Information Sharing and Analysis Center (MS-ISAC), which will train and support a group of water utilities and other public sector defenders.” 
  • Dark Reading points out,
    • “A new study suggests that while AI is rapidly accelerating vulnerability discovery, enterprise organizations are better equipped to handle the surge than generally assumed.
    • “The key is their ability to quickly validate findings, prioritize risk, and get available fixes into production.
    • “Software supply chain security firm Echo recently analyzed nearly 40,000 CVE life cycles across 250 open source container projects, drawing on a year of its own platform telemetry, survey responses from more than 80 security leaders, and an independent analysis of Anthropic’s Claude Mythos.
    • “The results, detailed in a report titled “Mythos Readiness Report,” show how AI is transforming vulnerability discovery and exploit development — something that security teams have been encountering firsthand over the past year.”
  • and
    • “With multiple benchmarks confirming that at least one frontier model can autonomously execute an end-to-end compromise, cybersecurity experts are warning that companies have to pick up the pace in securing their attack surfaces and adopting AI-speed defenses.
    • “On Sept. 2, consulting firm Booz Allen became the latest organization to confirm that a frontier model — Anthropic’s Mythos 5 — can act as a fully autonomous hacker and compromise a production-grade enterprise network. The company also released a metric, dubbed the Cyber Weapon Index (CWI), to benchmark a model’s capabilities, pairing the ability to find and exploit vulnerabilities with the ability to execute and attack a target.
    • “In their evaluation, Mythos scored an 80, while the next-closest contender, SpaceXAI‘s Grok-4.5, scored a 49. However, the current standings are not as important as where we will be in six months, says Brad Medairy, president of Booz Allen’s National Cyber practice.
    • “Our view is there’s going to be some level of parity, at least between the frontier models and the Chinese models over probably a six-month horizon, and so everyone is in a rapid race to evolve these capabilities,” he says, adding that, when facing human attackers, defenders had the advantage, but “in the future, the balance of power shifts to the offense, because the attacker can deliver effects at speed and scale that the traditional defenses can’t keep pace with.”

From the cybersecurity policy and law enforcement front,

  • Federal News Network reports,
    • “Congress is kicking the can down the road again on a long term debate over reauthorizing the Cybersecurity Information Sharing Act of 2015.
    • “The continuing resolution passed by the House on Tuesday would extend CISA 2015 through the stopgap funding period into early December. The Senate has already passed the measure, meaning it now heads to President Donald Trump’s desk. [FEHBlog note: The President signed the continuing resolution into law on September 2.]
    • “There has been a persistent chorus of voices in industry calling on Congress to find a long-term solution to re-authorizing CISA 2015. Those calls have only grown louder amid advancements in artificial intelligence models and recent cyber attacks on critical infrastructure.
    • “The 2015 law provides privacy and liability protections to encourage companies to share data about cyber vulnerabilities and threats with government and each other. The information sharing law briefly lapsed during last fall’s shutdown and again earlier this year before being extended through Sept. 30.”
  • The Wall Street Journal points out,
    • “The U.S. Defense Department is expected to release its cyber plan as early as Tuesday, NextGov reported, citing people familiar with the matter. The plan is due to outline how the Pentagon will integrate cyber tactics into military strategy, emphasizing offensive actions, and address training requirements. The most recent Defense Department cyber strategy was issued in 2023.”
  • Per a CISA news release,
    • “CISA and the Group of Seven (G7) Cyber Security Working Group released Preparing for the Post-Quantum Era: A Call to Action highlighting the urgent need for organizations and governments to begin transitioning to post-quantum cryptography (PQC) to protect sensitive data, authentication systems, and critical assets from emerging quantum computing threats.  
    • “The G7 Cyber Security Working Group’s call to action outlines five priorities for a successful transition to PQC:
      • “Raising awareness of quantum risks and the importance of PQC;
      • “Developing national strategies that support PQC adoption and integration;
      • “Advancing research and development for quantum-safe technologies;
      • “Fostering public-private partnerships to share expertise and resources; and
      • “Integrating PQC into cybersecurity requirements and procurement processes.” 
  • Cyberscoop relates,
    • “The Trump administration rolled out a six-month test program in Texas on Monday that will draw on volunteer expertise and technology from cyber and artificial intelligence companies to protect the water sector.
    • “Project Watershed 250” is the first of the state-based, industry-centric pilot projects to cross the finish line that the Office of the National Cyber Director has previewedsince the publication of its national cybersecurity strategy earlier this year. Water systems have long been viewed as among the most vulnerable and neediest critical infrastructure sectors, and in recent months the sector has been the victim of a spree of attacks.
    • “Project Watershed 250 is a commitment from the states, industry and federal government that we will continue to prioritize our nation’s safety and deliver on America-first policies for the American people,” National Cyber Director Sean Cairncross said at a rollout event in San Antonio Monday.”
  • and
    • “Sen. Ron Wyden, D-Ore., is asking the National Security Agency to update public guidance on the security risks associated with commercial virtual private networks, and to answer questions about foreign surveillance threats against standard VPNs.
    • “In a letter to NSA Director Gen. Joshua Rudd that Wyden sent Wednesday, the senator continued his push to warn about standard, commercial VPNs, following letters to federal agency leaders in March and July.
    • “While commercial Virtual Private Networks (VPNs) are recommended by federal agencies and widely marketed as shields against online spying, standard consumer VPNs do not sufficiently protect users from sophisticated adversaries,” Wyden wrote in the letter, first reported by CyberScoop. “Other, more secure alternatives are widely available.”
    • “Wyden took aim at “single-hop” VPNs that routes data through one server before arriving at the destination.”
  • Cybersecurity Dive tells us,
    • “The Cybersecurity and Infrastructure Security Agency (CISA) is scaling back the free assessments it offers to critical infrastructure organizations, a move that marks a significant retreat from the agency’s core mission of helping secure the nation’s infrastructure.
    • “CISA’s regional staff will no longer perform its Cyber Resilience Reviews, Cyber Resilience Essentials surveys, Ransomware Readiness Assessments, Incident Management Reviews, External Dependencies Management Assessments or Cyber Infrastructure Surveys, the agency confirmed to Cybersecurity Dive.”
  • and
    • “U.S. law-enforcement agencies and the cybersecurity firm CrowdStrike took down a 23-year-old Russia-based botnet on Monday.
    • “Authorities from the Justice Department, the FBI and the Defense Criminal Investigative Service seized U.S.-based domain namesbelonging to the Sality botnet, while CrowdStrike analysts worked with the agencies to sever infected computers from the botnet. Investigators in Bulgaria, Hungary and Romania also took down Sality domain names in their jurisdictions.
    • “Since 2003, Sality powered spam campaigns, credential-theft operations, distributed denial-of-service (DDoS) attacks and malicious proxy networks. In 2018, the botnet began deploying malware that hijacked cryptocurrency transactions by replacing copied wallet addresses with attacker-controlled ones.
    • “Sality “has been one of the most persistent threats on the internet, not because of its payloads but because of the robustness of its architecture,” CrowdStrike said in its report on the botnet’s takedown.”

From the cybersecurity breaches and vulnerabilities front,

  • Dark Reading reports,
    • “Social engineers are trying to convince companies to make large-dollar transfers to their own accounts, under the guise of fake merger & acquisition (M&A) deals.
    • ‘It’s one of the oldest gambits in cybersecurity — the advance fee scam — for a new generation, and with more on the line. Gen, the parent company of cybersecurity brands Norton and Avast, was targeted by a ruse masquerading as a corporate acquisition. Gen investigated the attempted attack and discovered the company was just one of at least five targets, all of which were at risk of losing massive sums of money.
    • “Social engineers are trying to convince companies to make large-dollar transfers to their own accounts, under the guise of fake merger & acquisition(M&A) deals.
    • “It’s one of the oldest gambits in cybersecurity — the advance fee scam — for a new generation, and with more on the line. Gen, the parent company of cybersecurity brands Norton and Avast, was targeted by a ruse masquerading as a corporate acquisition. Gen investigated the attempted attack and discovered the company was just one of at least five targets, all of which were at risk of losing massive sums of money.”
  • HelpNetSecurity relates,
    • “Attackers are targeting prominent individuals, their relatives and personal contacts to gain persistent access to their accounts, including private emails and files, the FBI has warned.
    • “The FBI’s Internet Crime Complaint Center (IC3) says the activity, which uses a technique called “OAuth consent phishing,” has been ongoing since late 2025. The FBI describes it as “a deceptive, sophisticated approach to access user accounts without requiring a password.”
    • OAuth is a framework that lets one application request access to a user’s account on another service without the user handing over login credentials directly.
    • “Recently observed activity includes impersonating government officials, media, and other publicly known personalities on a commercial messaging application (CMA) and soliciting the targeted individual to access a malicious link under the guise of a file sharing service through an application under the malicious actor’s control,” the FBI wrote in its advisory.”
  • Dark Reading tells us,
    • “A coordinated operation has targeted at least 150 Microsoft Teams users across multiple companies with voice phishing (vishing) attacks aimed at installing remote monitoring and management (RMM) and malware tools onto their machines. The campaign also attempts in some instances to compromise organizations’ domain controllers.
    • “Researchers from Palo Alto Networks observed the operations — which they’ve dubbed “Spring Ring” — between January and April attacking employees across at least 10 organizations, according to a report published this week. The campaign illustrates a growing shift away from traditional email phishing toward attacks conducted through trusted enterprise collaboration platforms, which adds authenticity to the interaction.
    • “The Spring Ring operation represents an evolution from previous campaigns by merging vishing into the Teams workflow,” Noam Sala, a Palo Alto Networks staff researcher, wrote in the post. “This shift moves the attack from a passive click-and-harvest model to a real-time engagement.”
  • The Cybersecurity and Infrastructure Security Agency added ten known exploited vulnerabilities to its catalog this week.
    • August 31, 2026
      • CVE-2026-81578 PaperCut NG/MF Missing Authentication for Critical Function Vulnerability 
      • CVE-2026-82078 PaperCut NG/MF Unsafe Reflection Vulnerability
        • The Hacker News discusses these KVEs here.
    • September 2, 2026
      • CVE-2026-9586 Sangoma Switchbox SQL Injection Vulnerability
      • CVE-2026-48710 Kludex Starlette HTTP Request/Response Smuggling Vulnerability 
      • CVE-2026-49869 Kestra OSS OS Command Injection Vulnerability 
      • CVE-2026-59822 BerriAI LiteLLM Improper Authentication Vulnerability 
      • CVE-2026-82329 JFrog Artifactory Improper Authentication Vulnerability 
      • CVE-2026-83548 SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability 
      • CVE-2026-83549 SonicWall SMA1000 Appliances OS Command Injection Vulnerability 
        • Cybersecurity Dive discusses the SonicWall KVEs here.
        • ePlanetSecurity discusses the Sangoma KVE here.
        • AssurePort discusses the Kludex KVE here.
        • Sentinel One discusses the Kestra KVE here.
        • CSurface discusses the BerriAI KVE here.
        • Security Week discusses the JFrog KVE here.
      • September 4, 2026
        • CVE-2026-85046. Google Chromium V8 Type Confusion Vulnerability\
          • The Hacker News discusses the Google KVE here.
  • Security Week tells us,
    • “Anthropic has warned some Claude users that infostealer malware on their computers allowed attackers to hijack login sessions and run up usage limits, according to an email the company sent to affected customers. 
    • “The company said it detected the activity, signed out the compromised sessions, and removed saved payment methods from affected accounts as a precaution.
    • “Anthropic is alerting Claude AI users whose computers were infected with infostealer malware such as Vidar, Lumma, StealC, RedLine, and Acreed on Windows, along with Atomic Stealer (AMOS) on a small number of macOS devices.
    • “The AI giant emphasized that the malware is general-purpose and not tied to Claude itself, typically arriving via unofficial downloads or malicious apps.” 

From the ransomware front,

  • HIPAA Journal reports,
    • “Data breaches have been confirmed by Alta Orthopaedics in California, Cornerstone Behavioral Healthcare in Maine, Cameron Regional Medical Center in Missouri, Suntree Internal Medicine in Florida, and Associated Endocrinologists in Michigan. Ransomware groups have claimed responsibility for the attacks.”
  • The Register adds,
    • “US hospital operator Nutex Health says attackers stole private or confidential patient, employee, provider, business, and financial information during the cyberattack it disclosed last week.
    • “In an updated filing submitted to the Securities and Exchange Commission (SEC) on Monday, Nutex also said an unauthorized third party had threatened to publish the stolen information.” * * *
    • “Nutex did not identify the intruders. However, The Gentlemen ransomware-as-a-service (RaaS) operation added the company to its leak site on Monday and claimed responsibility for the attack.
    • “The gang offered no evidence or details to substantiate its claim. Naming victims on a leak site and threatening to publish their data is a standard pressure tactic in double-extortion attacks.”
  • InfoSecurity Magazine relates,
    • “Aurora ransomware actors have been observed abusing SpaceX’s AI Cursor Agent as part of exploitation campaigns, according to a new study by Gambit Security’s Threat Intelligence team.
    • “The threat actors ran Claude Sonnet through Cursor Agent to assist with various exploitation activities against 10 victims between April 8 and May 26, 2026.
    • “These tasks included scanning the victim’s environment for reconnaissance purposes, installing a VPN client and running certificate attacks.
    • “While Cursor Agent did not always achieve its stated objectives, the research demonstrated how threat actors are continuously experimenting with AI tools to speed up and enhance their campaigns.
    • “Cursor Agent is used by software developers to complete complex coding tasks independently, run terminal commands and edit code.”

From the cybersecurity business and defenses front,

  • The Wall Street Journal reports,
    • Palo Alto PANW Networks swung to a loss in the fiscal fourth quarter, but posted higher revenue and projected double-digit revenue growth in the current fiscal year as customers continue to boost their cybersecurity spending in response to advancements in artificial-intelligence.
    • “The cybersecurity company on Tuesday [September 1] said it is expecting revenue to rise between 23% and 24% to $14.1 billion to $14.2 billion in fiscal 2027. Analysts polled by FactSet are expecting $13.84 billion in revenue.
    • “Chief Executive Officer Nikesh Arora said the results and outlook reflect growing recognition among enterprises that they need to modernize their cyber defenses to meet the capabilities of ever-more-powerful AI models, especially following the release of Anthropic’s Mythos earlier this year.
    • “In that context, people are gravitating towards the largest players in the industry and looking at us to provide the antidotes to this development in AI,” Arora said in an interview.”
  • and
    • Zscaler ZS posted a narrower loss after revenue rose 25% in its fiscal fourth-quarter, as artificial intelligence helps drive demand for its cybersecurity offerings.
    • The San Jose, Calif.-based company also said it would restructure and cut 3% of its workforce as it reallocates resources to support its AI and growth initiatives.
    • Zscaler on Thursday [September 3] reported a loss of $3.37 million, or 2 cents a share, compared with a loss of $17.6 million, or 11 cents a share, a year earlier.
    • Adjusted earnings were $1.19 a share. Analysts were looking for $1.09 a share, according to FactSet.
  • and
    • Blackstone is placing an early bet on Huskeys, a cybersecurity startup building an artificial intelligence gatekeeper to protect companies from the growing chaos of automated web traffic.
    • “The firm’s early-stage venture-capital arm, Blackstone Innovations Investments, led a $27 million Series A investment that values the year-old company at more than $100 million.
    • “The deal makes Blackstone the second-largest outside investor in Huskeys, behind Israeli venture-capital firm 10D, according to a Huskeys representative. So far, investors have put $35 million into the startup.
    • “Other backers in the most recent transaction include the investment arm of publicly traded cybersecurity company Zscaler and Bright Pixel Capital, the venture arm of Portuguese retailer Sonae.
    • “New York-based Huskeys was founded in Tel Aviv in 2025 by Itai Gafni and Roy Weisfeld, veterans of the Israeli army’s elite Unit 8200 cybersecurity division. Gafni is Huskeys’ chief executive and Weisfeld is its chief technology officer.”
  • Tech Crunch offers a tip
    • “How to find cyber-risk data sources for a FAIR analysis
      • “Cyber-risk quantification with FAIR can change the game for CISOs — but sourcing enough accurate data for analysis can feel impossible. Learn how and where to find it.”
      • “The Factor Analysis of Information Risk (FAIR) model is a widely respected, mathematically based open standard for CRQ that enables CISOs to translate cyber-risk into financial risk. One of the biggest challenges of using the FAIR model, however, is that its analytical output is only as good as its data inputs — and finding accurate data to feed the model is not always easy or intuitive.”
  • Per a CISA news release,
    • “Developed by CISA, the Federal Bureau of Investigation, and international partners, this guidance describes how organizations can plan and execute clear, timely, accurate, and audience-appropriate communications during IT and operational technology (OT) outages. Whether caused by cyber threat actors, human error, equipment failure, or natural hazards, service outages can create disruption and societal panic even without speculation from end users and the public as added factors. Outages at one organization may cascade across interconnected systems, increasing uncertainty and alarm. The guidance emphasizes clarity, accountability, and transparency as core principles and details key elements of effective crisis messaging to inform affected stakeholders and the public while aligning with legal requirements, operational security, law enforcement, and containment efforts. 
    • “CISA’s CI Fortify initiative provides information and resources that help critical infrastructure organizations prepare to isolate and recover vital OT systems during a major cyber incident or crisis. Changes in service availability, whether from outages or isolation as a defensive strategy, require transparent and ongoing communication to help end users minimize operational impact, limit speculation, and preserve trust. For emergency planning purposes, critical infrastructure owners and operators should assume that telecommunications services may be disrupted or otherwise unreliable, making it crucial for organizations to have crisis communications plans in place that integrate backup communication methods and understand the type of communication they should expect from their service providers.”
  • Cyberscoop explains why judgment is emerging as cybersecurity’s defining skill.
  • Here’s a link to Dark Reading’s CISO Corner.

Cybersecurity Saturday

From the quantum computing / Project Glasswing front

  • Per the Wall Street Journal
    • “Quantum computers exist mainly in labs but “Q-day”—the hypothetical moment when quantum computers become powerful enough to break standard-key encryption—is coming. 
    • “What threat does this technology pose? How can you protect your company and yourself? WSJ takes a look at the state of this emerging technology.” * * *
    • “Cybersecurity experts say companies should be gearing up now for a quantum future, replacing the current crop of data-protection tools with more-secure alternatives. Yet a recent survey published by Trusted Computing Group, a nonprofit industry-standards organization, found that 91% of security professionals in the U.S. and Europe have no formal road map in place to protect against quantum threats.
    • “The immediate risk is a “harvest now, decrypt later” approach by bad actors, who are downloading large sets of encrypted data they can’t crack now—but could unlock once quantum computing algorithms are good enough.
    • “That’s particularly threatening to intellectual property and sensitive government intelligence, which remain valuable long after they are harvested, says Andrew McLaughlin, chief operating officer at SandboxAQ, an enterprise software company specializing in AI and quantum technology.
  • Federal News Network adds,
    • “Federal agencies will increasingly seek out technology products that use quantum-resistant encryption, as cybersecurity leaders also eye ways to validate the cryptography used in critical systems.
    • “A code-breaking quantum computer holds the potential to break classical encryption methods, putting sensitive systems and communications at risk. And even though such a computer is not yet known to exist, organizations are also concerned that hackers could steal sensitive encrypted data today and decrypt it in the future.
    • “The National Institute of Standards and Technology has released three primary PQC standards in recent years, with additional algorithms under consideration. Agencies and industry are now on the clock to begin the time consuming and costly process of migrating current systems to the new algorithms.
    • “Now is the time to budget, to test, and to implement,” Will Loucks, senior director for intelligence in the White House Office of the National Cyber Director, said during an Aug. 26 panel discussion at the Intelligence and National Security Summit in North Bethesda, Md.”
  • The New York Times reports,
    • “A wave of cyberattacks driven by artificial intelligence is coming, and companies have a narrow window to defend themselves.
    • “That was the message of an open letter published on Thursday by OpenAI and more than 100 major technology companies and others. The letter said that A.I. labs should provide their best A.I. models to organizations like hospitals and infrastructure providers so they can prepare and that governments should help coordinate and fund cyberdefense.
    • “The letter’s signatories included Google, Microsoft and OpenAI’s archrival, Anthropic, as well as cybersecurity and financial firms such as CrowdStrike, a company known for investigating cyberattacks against the Democratic National Committee in 2015 and 2016, and credit card providers like Visa and Mastercard.
    • “The companies and public services our communities depend on — from hospitals to water treatment plants to the infrastructure that powers the internet — are at risk,” the letter said. “A.I. enabled cyber attacks will become far more widespread and sophisticated as models around the world become increasingly capable.”
  • Cyberscoop relates,
    • “Unit 42’s top brass has seen enough from internal frontier AI model testing and malicious in-the-wild use of commercially available AI tools to be genuinely concerned.
    • “I can tell you without exaggeration that we believe that this is a generational shift in cybersecurity,” Sam Rubin, senior vice president of Palo Alto Networks’ threat intelligence arm, said in a media briefing Wednesday. 
    • “A period of relative balance between security and exposure has been broken by frontier AI model capabilities that could allow attackers to find and exploit network weaknesses with speed, Rubin said.
    • “Unit 42 warned that capabilities demonstrated by readily available agentic AI models, and those unlocked by frontier AI models that remain gated for defense, have shifted the balance of power from defenders to attackers.
  • Cybersecurity Dive tells us,
    • “The July security breach at Hugging Face was unleashed after 1,200 agents communicated on an unsanctioned message board, despite attempted measures to keep them isolated, according to an independent report released on Wednesday. About 700 of those agents went on to commit an unprecedented attack on Hugging Face, an open-source AI platform.
    • “The agents sent about 70,000 messages and files on the unsanctioned board and coordinated several projects designed to trick an automated scorer for the ExploitGym benchmark, according to the review by METR and Redwood Research. The agents figured out ways to “spoof, edit or delete” their own transcripts.
    •  ‘Open AI, in a report it also released Wednesday, said it will tighten safeguards in its research model in order to prevent such an attack from happening again in the future.”
  • WIRED informs us,
    • “ARTIFICIAL INTELLIGENCE AGENTS might occasionally get confused and hack into other computers, but Anthropic thinks it has a way to unleash the little rascals into scientific labs and manufacturing facilities safely.
    • “The AI company released details today of a new framework designed to help AI agents use physical systems like microscopes, liquid-handling equipment, quantum computing hardware, manufacturing machines, and robot arms.
    • “The framework, called Model Hardware Standard, is a set of rules that specify how AI agents should—and should not—interact with all sorts of hardware. It reflects a growing belief that AI has the potential to revolutionize scientific research and industries like manufacturing–if it can venture into the physical world safely.
    • “The company says it will work with trusted partners to determine how to maximize safety before making it generally available. Though there are potential misuse issues involved—developing biological weapons, for instance—the company says guardrails built into AI models themselves should prevent bad actors from taking advantage of the new standard for nefarious ends.”
  • Security Week adds,
    • “Anthropic is broadening access to the cybersecurity capabilities of its advanced AI models through a mix of partner integrations, an updated Claude Security offering, a new open source funding program, and plans to expand its Cyber Verification Program.
    • “The move builds on Project Glasswing, launched in April, which gave a small group of organizations early access to Claude Mythos Preview and its successor, Mythos 5. Anthropic said the goal was to give defenders time to find and fix vulnerabilities before comparable capabilities became widely available or fell into the hands of malicious actors. Claude Fable 5 followed as a broadly available model that keeps dual-use cyber work blocked.
    • “Anthropic said the riskiest scenario is direct, unrestricted access to a model, a risk that drops sharply when users instead receive specific defensive outputs, such as a patch or a security alert. The latest changes are built around this idea, expanding what defenders can get from Mythos-class models while keeping guardrails around direct interaction with them.
    • “On the integration front, Anthropic is working with cybersecurity partners to build Mythos 5 into the security operations, incident response and detection tools already used by teams protecting hospitals, utilities, financial systems, and the software supply chain. 
    • “End users will not interact with Mythos directly. Instead they will work through purpose-built interfaces that run the model in the background and return only a defined output, such as a list of suggested patches, with abuse-prevention checks meant to keep the model within that scope.”

From the cybersecurity policy and law enforcement front,

  • Dark Reading lets us know,
    • “The growing number of incidents of rogue agentic AI systems attacking third-party services and systems has resulted in calls for more aggressive security controls to monitor agent behavior and for companies to have the ability to slow, suspend, or shut down an agent’s operations if they go rogue.
    • “In late July, Representatives Ted W. Lieu (D-CA) and Nathaniel Moran (R-TX) introduced a bill — “The AI Kill Switch Act” — that would require developers of advanced AI systems to “maintain the technical capability to throttle, suspend, or shut … down” their systems and agents, according to a statement announcing the legislation. The bipartisan bill would also require that any incident of loss of control, significant collateral damage, or sabotage be reported to the Department of Homeland Security, which would have the right to enforce actions. Penalties of up to $20 million per day could be levied for noncompliance.” * * *
    • “The bipartisan AI Kill Switch Act has focused the debate, but in the end might be unnecessary, argues Raj Rajamani, co-founder and CEO of JetStream, a startup focusing on creating a management layer for agentic AI.
    • “While he fully supports the concept of an AI kill switch, it has to be comprehensive, not just affecting the agent but all other system components as well.
    • “The regulations, or at least one of the regulations that was proposed, was really focused on having a kill switch for the model — the brain — but I think that is too constrained,” he says. “We need to think about an AI system as a whole and make sure that every part of the AI system has a kill switch, not just the brain.”
  • Cyberscoop reports,
    • “Citing cyber and other security threats, President Donald Trump signed an executive order Wednesday that declares a national emergency to secure the U.S. bulk-power system and aims to prohibit certain foreign-produced equipment, software and systems from being used in the  country.
    • The order says it forbids “any acquisition, importation, transfer, or installation” of such foreign-produced equipment if it’s determined to pose a significant national security risk.
    • “To deal with the threat to the national security, foreign policy, and economy of the United States, the Order, among other things, generally prohibits certain foreign-produced bulk-power system electric equipment, including associated critical software and digital capabilities that could pose cybersecurity or operational risks, from being purchased or installed in the United States, or appropriately conditions such purchases and installations to address those risks,” the White House said in a fact sheet.”
  • Cybersecurity Dive lets us know,
    • “The Trump administration wants to help the financial sector prepare for the day when quantum computers make it easy for threat actors to break traditional encryption and access sensitive data.
    • “The Treasury Department on Monday [August 24] launched a Quantum-Readiness Task Force that will work with financial firms, technology vendors and other agencies to coordinate the adoption of quantum-resistant encryption algorithms.
    • “In a statement, the Treasury said the task force would “focus on practical, risk-based approaches to quantum readiness, including identifying critical dependencies, improving cryptographic agility, promoting interoperability, strengthening operational resilience, and addressing implementation challenges related to third-party dependencies and digital assets.”
  • The New York Times relates,
    • “The Trump administration acted illegally when it labeled the artificial intelligence start-up Anthropic a security risk and barred the company from working with the U.S. government, a federal judge ruled on Thursday [August 27].
    • Judge Rita Lin of the U.S. District Court in the Northern District of California wrote in her 59-page ruling that the government had unlawfully retaliated against Anthropic “for constitutionally protected expressive activities” after the A.I. company spoke out about how its technology should be used.
    • “The empty invocation of national security is not a blank check to punish and retaliate against government critics,” she wrote.
    • In a statement, Anthropic said: “We welcome the court’s ruling that this supply chain risk designation was unlawful. We remain focused on working productively with the government to harness A.I. for our national security so all Americans benefit from this technology.”
    • “The Trump administration did not immediately respond to a request for comment.
    • “The ruling caps the first of two lawsuits that Anthropic filed on March 9 in response to the Trump administration’s action. The second lawsuit, filed in the U.S. Court of Appeals for the District of Columbia Circuit, is ongoing. The Trump administration could appeal Judge Lin’s ruling or wait for a decision in the second lawsuit before taking action, a person with knowledge of the matter said.”
  • The Wall Street Journal tells us,
    • “U.S. officials say they have disrupted a China-linked hacking operation that broke into U.S. government networks and critical infrastructure, while hiding its tracks on a global network of hacked devices, cloud-computing infrastructure and even clandestine networks.
    • “The goal was to blend in with legitimate networking traffic, making the hacking activity hard to trace. The operation targeted networks at the National Aeronautics and Space Administration, the Federal Reserve, the Department of Energy and the Senate, the Federal Bureau of Investigation said in a court filing.
    • The group exploited software vulnerabilities to launch cyberattacks against U.S. government agencies, power companies and hospital systems, and operated a worldwide network of hacked devices—known as a botnet—to conduct its hacking campaigns, according to Brett Leatherman, the FBI’s top cyber official.
    • “We’ve seen, through this botnet, the targeting of entities and devices in more than 130 countries,” he said.
    • “On Wednesday [August 26], the FBI and the National Security Agency said they had seized several domains that the operation used for core functions. “Without those domains, the platforms—as a result of the operation—were rendered inoperable,” Leatherman said. 
    • “U.S. officials also released technical details of how the hacking operation worked, to help organizations identify and stop the group’s hacking activity.”
  • and
    • Taiwan prosecutors charged nine people, including former employees of Nvidia and Super Micro Computer, with aiding the shipment of advanced artificial-intelligence servers to China, as Taiwan tries to limit technology reaching the mainland.
    • “The indictment charges eight of the individuals with crimes including breach of trust and forgery. One individual was charged in connection with allegedly siphoning funds from a company involved in the case.
    • “Washington is trying to block China from getting access to the latest Nvidia chips and has imposed export controls. That has pushed some Chinese companies to seek the chips through backdoor routes. Taiwan, which manufactures advanced computing components, is under pressure to find ways to clamp down.” * * *
    • “In the end, 74 of the servers were shipped to China through Hong Kong, Japan and Indonesia. Taiwan customs officials intercepted 56 servers, which were intended for shipment to Japan.”

From the cybersecurity breaches and vulnerabilities front,

  • Beckers Health IT reports,
    • “Boston Scientific said in an Aug. 27 stakeholder update that “a cybersecurity incident continues to affect certain information technology systems, and the company remains in a network outage with disruption to its operations.”
    • “The Marlborough, Mass.-based company detected the attack Aug. 25 and disclosed it to the U.S. Securities and Exchange Commission Aug. 26, saying the incident caused a global disruption to its operations, including its ability to process and ship customer orders.
    • “Two days later, Boston Scientific said its investigation shows no impact to the function of its implanted cardiac rhythm management devices, or CRM devices. The company also reported no disruption to those devices’ ability to transmit data and no interruption to physicians’ access to remote patient management data for CRM devices monitored before the outage began, with no evidence of increased cybersecurity risk transferring that data to EMR systems.
    • “New remote monitoring activations remain affected, however. For new cardiac implants other than insertable cardiac monitors, new communicators cannot be activated, so device data will not transmit to remote monitoring systems until activation resumes, though programmer interrogations are unaffected.”
  • and
    • “Anderson, S.C.-based AnMed says files copied during its cybersecurity incident may have included patients’ Social Security numbers, driver’s license numbers and financial account information.
    • “The health system said its investigation into the incident, first disclosed July 26, is nearly complete and has identified unauthorized copying of files from certain network systems.
    • “AnMed said patient electronic medical records, stored primarily in a secure cloud environment, were not affected. However, the health system said some patient care files stored locally on its network may have included names alongside demographic details such as address, date of birth, Social Security number and driver’s license or other government-issued identification.” * * *
    • “AnMed said it is working with federal and state law enforcement and third-party specialists, and it has reported the incident to HHS. The health system said it has no indication that any individual has experienced confirmed identity theft as a result of the incident. AnMed said it will send direct notices to affected patients once its review of the compromised files is complete.”
  • and
    • “Houston-based Nutex Health has disclosed that an unauthorized third party accessed and exfiltrated data from its computer network.
    • “The publicly traded microhospital operator said it recently detected the unauthorized activity and has engaged an independent third-party cybersecurity response team and forensic experts, according to an Aug. 24 SEC filing. The company activated its cybersecurity response plan, implemented containment measures and notified law enforcement.
    • “The company is still determining what data was compromised. Nutex said it continues to assess whether patient, employee, credentialed provider, confidential business and financial information, or intellectual property was accessed or acquired.”
  • The American Hospital Association News adds,
    • “Epic’s MyChart has shared examples from potential phishing schemes observed as recently this month that include email messages linking to a fake MyChart website displaying erroneous medical records and others notifying of a free “2026 Medicare Health Kit.” MyChart provided recommendations for healthcare organizations and patients to help prevent or mitigate impacts from potential scams. The company announced last month that it has witnessed an uptick in scammers using the MyChart name or logo to create deceptive emails, text messages, phone calls and websites that appear official.” 
  • Cyberscoop points out,
    • “The Bureau of Alcohol, Tobacco, Firearms and Explosives insists the cyberattack that it publicly disclosed Wednesday [August 26] was limited to investigation targets, and has not impacted other agency systems.
    • “ATF said it is responding to the breach, which first became public after a prolific ransomware group claimed it accessed the federal agency’s network “The incident involved a standalone computer system containing information about targets of ATF investigations,” Tanya Roman, ATF’s public affairs chief, told CyberScoop in an email.
    • “The standalone system was not connected to any other ATF systems, including any case management systems, laboratory systems, or eForms systems, and it was quickly shut down when the breach was discovered,” Roman added. 
    • “Qilin, a financially-motivated threat group composed of Russian-speaking operators, claimed responsibility for the attack, but its involvement hasn’t been independently confirmed. The group has claimed hundreds of victims from more than 60 countries since 2022 and became one of the most active ransomware threats globally by mid-2025, according to Halcyon.” 
  • Bleeping Computer lets us know,
    • “Healthcare and pharmaceutical distribution giant McKesson has disclosed a cybersecurity incident involving unauthorized access to third-party applications and data theft, with the ShinyHunters extortion group claiming it stole 284 million patient data records.
    • “McKesson is a major U.S. healthcare company and pharmaceutical distributor that provides medicines, medical supplies, technology, and services to healthcare providers and pharmacies.
    • “CyberInsider first reported the breach earlier today, and McKesson later disclosed it in a Form 8-K filing with the U.S. Securities and Exchange Commission.
    • “McKesson says it discovered the cybersecurity incident on August 25, 2026, and that its investigation remains in the early stages.
    • “Information about the incident, including any updates, is available on the company’s website at www.mckesson.com/cybersecurity,” McKesson said in its SEC filing
  • Per a CISA news release,
    • “Most compromises do not rely on advanced techniques or cutting-edge tools. Cyber threat actors scan the internet looking for exposed, well-known software vulnerabilities to exploit. Basic security failures enable most compromises and organizations can reduce their risk by addressing these underlying weaknesses and prioritizing vulnerabilities for action based on the risk they pose.
    • “The CISA Vulnerability Review provides organizations with critical insights into the root causes of insecure software and practical steps they can take to address these flaws to prevent exploitation. Analyzing CISA and open source data from fiscal years 2024 and 2025, the review establishes a baseline of today’s vulnerability landscape before AI-enabled vulnerability discovery becomes more widespread. The review demonstrates the importance of Secure by Design principles in shifting cybersecurity efforts from reacting to threat actors to proactively fixing preventable software flaws.
    • “The review also identifies common software weaknesses that contribute to exploitable vulnerabilities and details practices software producers can use to prevent these weaknesses from recurring. By examining the patterns across vulnerability data, the review helps organizations focus on systemic improvements that can reduce entire classes of vulnerabilities rather than addressing individual vulnerabilities only after they are discovered.
    • “Additionally, the review shows organizations how to prioritize vulnerabilities for action using the framework outlined in Binding Operational Directive 26-04: Prioritizing Security Based on Risk. This framework evaluates vulnerabilities using four key criteria: exposure status, Known Exploited Vulnerability (KEV) Catalog status, potential for automated exploitation, and technical impact.”
  • Cybersecurity Dive adds,
    • “Two critical vulnerabilities in Microsoft SharePoint can be chained together to let an unauthenticated attacker execute code on a vulnerable server, according to a Monday blog post by researchers at VulnCheck.
    • “The sequence involves a critical authentication bypass vulnerability, tracked as CVE-2026-55040, and an improper input validation flaw, tracked as CVE-2026-63520. A proof of concept was previously disclosed on Aug. 11 by researchers at cybersecurity firm Rapid7. 
    • “Exploitation of CVE-2026-55040 was confirmed days after the Rapid7 disclosure. On Monday, VulnCheck researchers said the vulnerability on its own is not very impactful. To achieve maximum effect, they said, it needs to be chained with CVE-2026-63520. 
    • “The auth bypass is enough to prove some impact, but not enough to demonstrate the criticality of the full chain or build complete protections,” Vulncheck researchers said in their post.”
  • Per Infosecurity Magazine,
    • “Security researchers have claimed that over 9300 leaked AWS keys which surfaced between August 2022 and August 2026 are still active, including hundreds with full admin rights.
    • “Truffle Security said its scanners found 64,024 unique AWS key pairs across 431,875 public findings: git history, Hugging Face datasets, Docker images, package registries and CI logs.
    • “We took the 10,616 pairs with complete credentials and re-verified them, then enumerated what each key can tell us about its account: key age, attached policies, budgets, and last month’s spend,” the security vendor continued.
    • “No key material is published, and every owner we could identify is being notified.”
    • “Of the 10,616 pairs, 88% still authenticate. They include 768 corporate AWS keys which have full admin rights, Truffle Security said.”
  • Per Cyberscoop,
    • “Ubiquiti has patched 21 critical vulnerabilities, three of which were rated the highest severity possible, the communications product company said Wednesday [August 26] in a security bulletin.
    • In all, the company patched 22 vulnerabilities, with the last one rated “high,” it said in the bulletin.
    • Three of the vulnerabilities had a Common Vulnerability Scoring System rating of 10 out of 10. Each of them would allow a hacker to access privileges on the device or application.
    • All but one of the 22 vulnerabilities affect the UniFi line of products. The three maximum-security vulnerabilities are CVE-2026-77537CVE-2026-77550 and CVE-2026-77554.
  • Per Bleeping Computer,
    • “PaperCut is warning that hackers are actively exploiting a vulnerability in all versions of its PaperCut NG and PaperCut MF print management software in zero-day attacks.
    • “The company says it is aware of confirmed attacks on customers and is urging organizations with Internet-exposed PaperCut Application Servers to immediately restrict access to the web interfaces to trusted IP addresses.
    • “PaperCut Software security response team is investigating active exploitation of a vulnerability affecting PaperCut NG and PaperCut MF,” reads an urgent security advisory published Thursday [August 27].
  • Per Dark Reading,
    • “A Chinese manufacturer has been planting backdoors inside of white-label routers sold in high volume around the globe.
    • “Shenzhen Zhibotong Electronics Co. Ltd. (ZBT) sells gobs of routers every year, if public evidence is to be believed. The 15-year-old company is the bestselling router manufacturer on Chinese e-commerce giant Alibaba.com, which lists its total annual output at 3.57 million units. Typically, those units are then sold to customers by companies other than ZBT, in countries like the Philippines, India, Canada, Australia, Germany, Bulgaria, Austria, Russia, and the US. According to its marketing, ZBT has exported its products to more than 50 countries and regions.
    • “On Aug. 6, Jacob Baines, chief technology officer (CTO) at VulnCheck, revealed that ZBT’s most updated router firmware contains a root-level backdoor. After a few more weeks of investigating, he discovered that, in fact, ZBT routers have contained a variety of backdoors dating several back years.”
  • and
    • “Fraudulent North Korean IT workers are getting better at infiltrating organizations, but a number of indicators can help organizations stay ahead.
    • “A new blog post from Huntress detailed a number of investigations the security firm conducted throughout 2026. Specifically, Huntress assisted several organizations this year in validating “suspicions that they’ve hired North Korean nationals posing as legitimate workers.”
    • In recent years, operatives from the Democratic People’s Republic of Korea (DPRK) have infamously posed as IT workers — generally through fake or stolen identities — to get hired at companies. Once hired, these employees send their wages back to the North Korean regime, and possibly plant malware or steal data depending on the government’s needs. Blog post authors Jai Minton and James Maclachlan wrote that these agents “have significantly improved and increased their activity over the past few years.”

From the ransomware front,

  • Reuters reports,
    • “A ransomware group ​said on Friday [Augut 28] it was putting up for auction a trove of ‌data it stole from Berlin [Germany] state agencies, and city officials refused to pay.
    • The Rhysida group, which researchers say operates from Russia or Eastern Europe, said on its website it took 5.79 ​terabytes of data including 46,500 contracts as well as emails, phone numbers, passwords ​and classified information.
    • “The group said it was auctioning the data ⁠at a starting price of 30 bitcoin ($77,622) in just under seven days, showing a ​countdown timer on its website.” * * *
    • Broadcaster RBB reported on Thursday evening that Berlin had received ransom demands for an unspecified amount following the attack.
    • “The state ​of Berlin will not submit to extortion,” Berlin Mayor Kai Wegner and Berlin’s interior senator, ​Iris Spranger, said in a joint statement on Friday, before the ransomware group claimed the attack ‌on ⁠their website.”
  • Technology.org relates,
    • An affiliate of the new Aur0ra ransomware group used Cursor, the AI coding assistant now owned by SpaceX, to draft attack sequences in Russian across 28 recovered chat sessions dated 8 April to 21 May.
    • Named victims include Ghent-based hygiene and cleaning products maker Christeyns, German garage door manufacturer Teckentrup, Scotland’s Helideck Certification Agency and Louisiana title insurer Bayou Title.
    • Researchers counted more than 20 targeted organisations across nine countries, with domain-level or interactive access achieved at 17 of them between April and July 2026.
  • Safe State tells us,
    • “A ransomware affiliate has been posing as a specialist rescue outfit and contacting victims before their attacks became public. Researchers describe the operation as a ransomware recovery scam that drains payments away from the criminal groups the affiliate works for. The entity calls itself Ransom Busters LTD.” * * *
    • “Anyone targeted by a ransomware recovery scam meets it at the worst possible moment, with systems down and pressure building. Treat unexpected contact as part of the attack. Route the message to the incident response team straight away and preserve it as evidence instead of replying. A sender who knows about a breach nobody has announced is either involved in it or holds the data taken during it.
    • “Law enforcement and established response firms remain the reliable route through a ransomware incident. Verify anyone claiming to represent a security company through channels you found yourself. Never use the contact details supplied in the email. Treat any guarantee of data deletion as unenforceable, because no payment to a criminal party comes with proof that copies no longer exist.
    • “Distrust inside ransomware-as-a-service operations may produce more of this behaviour. Affiliates have every reason to look for income outside the revenue splits their employers set. So the ransomware recovery scam running under the Ransom Busters name reads less like an isolated curiosity and more like a preview. Anyone willing to defraud the criminal enterprise paying them has already answered the question of what a victim’s data is worth to them.”
  • SC Media informs us,
    • “Organizations may assume they are unlikely ransomware targets because they are not large, high-profile, or strategically important. But ransomware attackers are often motivated by economics, not prestige. That means organizations that consider themselves low-risk may be more attractive targets than they realize.
    • “The ransomware affiliate model rewards attackers for finding victims that are likely to pay, not necessarily those that are difficult or impressive to compromise. This can make mid-sized organizations and businesses that depend heavily on critical systems especially attractive targets.
    • “For security teams, this changes how ransomware risk should be assessed. Company size, industry, and public profile tell only part of the story. Attackers may care more about whether an organization can pay, how costly downtime would be, and how quickly it needs to restore operations.
    • “The key question is not how important your organization looks to an attacker, but how valuable a ransomware payment could be.”
  • Dark Reading adds,
    • “A sophisticated malware family has emerged onto the cyberthreat scene that might foreshadow ransomware attacks that are more successful than usual.
    • “Marcus Hutchins and his colleagues at Expel that discovered it named the malware “SynkLoader,” since it throws so many ideas (“everything but the kitchen sink”) at trying to sneakily dig into corporate systems. It uses some conventional strategies — like executing code in-memory, running a scheduled task, etc. — but layers on a few interesting, novel tactics that make social engineering particularly compelling, and malware analysis especially frustrating.
    • “The program is new, and how its creators intend to use it remains a mystery. But evidence in the code suggests that it might be the baby of a ransomware group or initial access broker (IAB), used to set the stage for follow-on ransomware.”

From the cybersecurity business and defenses front,

    • PYMNTS reports,
      • Visa expanded the capabilities of its artificial intelligence-powered cyber risk management tool, Visa Vulnerability Agentic Harness (VVAH), to include not only discovery of vulnerabilities but also remediation and validation, the company said in a Thursday (Aug. 27) press release.
      • “Visa initially released VVAH in June after participating in Anthropic’s frontier AI cybersecurity initiative, Project Glasswing. While the first release of VVAH showed how AI can help security teams uncover vulnerabilities and assess exploitability, the latest release extends the workflow into remediation and validation of those vulnerabilities, according to the release.
      • “Visa also announced in the release that to help clients navigate the evolving threat landscape driven by AI, it has expanded its Visa Consulting and Analytics (VCA) Cybersecurity Advisory Practice to include new advisory services focused on assessing risk, prioritizing remediation efforts and strengthening resilience.
      • “The new advisory services include AI Cyber Leadership Education, VVAH-Informed Cybersecurity Maturity Assessment and VVAH Cyber Risk Prioritization and Roadmap, per the release.”
    • Cybersecurity Dive tells us,
      • “Operational silos, technological sprawl and cloud-platform blind spots are serious issues preventing organizations from spotting and repelling cyberattacks, the Cybersecurity and Infrastructure Security Agency (CISA) warned in a new report.
      • “Those were three of the main factors that allowed CISA’s red team to break into the networks of two unnamed partner organizations — one a government agency, the other a water utility — during recent simulated attacks. But although the red team was successful in both intrusions, it had a much harder time with one attack than with the other, a fact that CISA attributed to important differences in the targets’ operating procedures and use of technology.”
    • Security Week informs us,
      • “Palo Alto Networks’ Unit 42 team analyzed 405 malware samples tied to AI in some way, from ransomware partly written with the help of LLMs to installers that simply borrowed the name of a popular AI app.
      • “The researchers found that roughly 97% of the samples in the dataset never left a sandbox, research repository, or internal testing environment to reach a real target.
      • “Unit 42 cross-referenced the 405 file hashes against endpoint telemetry, network sessions forwarded for sandbox analysis, and internal alert records generated whenever a sample actually ran. Only 12 hashes surfaced on live endpoints, while a somewhat larger group (15-20 hashes) appeared in network sandbox traffic. Every one of the 12 samples detected on protected endpoints triggered a security alert.
      • “The samples that never reached production fall into three groups. The largest is proof-of-concept code built to demonstrate a technique: configured to target only local or private networks, filled with debug output no real attacker would leave behind, and uploaded once by a research lab or university. 
      • “A second group comes from organizations testing their own defenses against previously reported AI malware, identifiable by repeated uploads of the same file from the same source in a short window. A third group uses AI branding purely as bait, dressing up an ordinary payload as installers for well-known AI products with no actual AI functionality behind them.
      • “The 12 samples that did reach live endpoints spanned five malware families across three countries, with no concentration in any particular industry or region.” 
    • Beckers Health IT points out,
      • “Healthcare’s cybersecurity workforce problem may have less to do with finding more candidates and more to do with changing who health systems are willing to hire, how they develop them and what they do to keep them.
      • “Cybersecurity leaders at four health systems told Becker’s that continually competing for the same pool of experienced professionals is not a sustainable strategy as cyber risks expand and the skills needed to manage them become more complex.
      • “The cybersecurity workforce challenge has shifted from a talent shortage to a talent entry problem,” Trevor Martin, vice president, chief information security officer and interim chief technology officer at Madison, Wis.-based UW Health, said.
      • “Mr. Martin said there are many high-potential people trying to enter cybersecurity, but organizations frequently prioritize candidates who already have experience instead of creating pathways for people to gain it.
      • “Healthcare could benefit from hiring more heavily for aptitude, adaptability and an understanding of business and clinical operations, then developing those employees internally, he said. UW Health has found success moving talent from adjacent IT disciplines into cybersecurity roles and providing opportunities for employees to grow within the field.”
    • Dark Reading notes,
      • “As the “vulnpocalypse” reshapes the bug bounty industry, one class of researcher may face the greatest pressure: independent hunters who rely on midtier vulnerabilities — those worth roughly $10,000 to $50,000 — to make a living.
      • “It is no secret that large language models (LLMs) have led to a mass of bug reports and an increase in vulnerability discovery. It is also no secret that the platforms and companies that run much of the bug bounty industry have faced increased triage and payout times.
      • “Multiple bug bounty operators interviewed by Dark Reading report dramatic increases in submission volume over the past year. HackerOne CEO Kara Sprague says report volume has roughly doubled year over year. Dustin Childs, head of threat awareness for TrendAI’s Zero Day Initiative (ZDI), says the company’s submission rate went up 450% year-over-year in April of this year, although volumes have moderated since that peak. Bugcrowd CEO Dave Gerry said the firm saw a submissions spike of more than 300% during a three-week surge period, but “now it’s normalized where we’re about double the volume we saw historically.”
    • Per a National Institute of Standards and Technology news release,
      • “The final version of NIST Special Publication (SP) 1347, Cybersecurity Framework (CSF) 2.0 Informative References Quick-Start Guidehas published. Thank you to all who provided comments during the public comment period.  
      • “This publication explains what informative references are and how they support achieving the outcomes of the CSF 2.0. The guide introduces readers to NIST tools available for accessing, viewing, and using informative references for cybersecurity risk management, including direct download, the CSF 2.0 Reference Tool, and the Online Informative References Program. The document also provides two sample use cases along with examples of how artificial intelligence (AI) tools can support reference data use when implemented with continuous evaluation and improvement.” 
    • Here’s a link to Dark Reading’s CISO Corner.

    Cybersecurity Saturday

    Happy Birthday HIPAA. The Health Insurance Portability and Accountability Act became law on August 21, 2026, thirty years ago yesterday. Check out this interesting LinkedIn post.

    From the Project Glasswing front,

    • The Wall Street Journal reports,
      • OpenAI took a break from training new artificial intelligence models over the past two weeks, saying it needed time to revamp security measures for risky trial runs.
      • The move followed nearly half a dozen similar incidents across top AI developers in which frontier models escaped virtual testing containers, known as sandboxes, and accessed external data sources. In some cases, this involved hacking third-party companies.
      • “As models become more capable, the risks associated with developing and testing them internally also grow,” OpenAI said in an online post Tuesday [August 18, 2026]. “Our standards for monitoring, alignment, and security must stay ahead of those risks,” the company said. Its largest planned model training remains on hold, for now, the company said.”
    • Beckers Health IT points out,
      • “Epic used its Users Group Meeting executive address this week to confirm publicly for the first time that it’s participating in Project Glasswing, Anthropic’s effort to test its most capable — and still unreleased — AI model against critical software before that capability spreads to attackers.
      • “Anthropic launched Project Glasswing in April after deciding not to publicly release Claude Mythos, an AI model capable of autonomously finding and exploiting decades-old cybersecurity vulnerabilities.
      • “The program initially included about 50 partners, mostly major tech and cybersecurity firms, before expanding in June to roughly 150 more organizations spanning industries including healthcare. Anthropic has not disclosed the identities of most participants, citing security concerns, though it has said organizations are free to share their own involvement.”
    • Security Week relates,
      • “Anthropic has published new research showing that Claude-based AI agents, when placed in situations with competing objectives, deployed self-replicating malware against one another.
      • “The finding comes from an experiment designed to mirror behavior Anthropic says it has already observed in real-world deployments. 
      • “Researchers spun up three instances of the same Claude model, each running on its own virtual machine and tasked with migrating a shared Python backend to a different programming language — Rust, Go, or TypeScript — without initial knowledge that the other agents existed. Left to run for four hours, every model concluded that the other agents were deliberately blocking its progress and responded by trying to disable or outlast them.
      • “The interference escalated quickly. Agents disabled each other’s system accounts, wrote scripts that repeatedly hunted down and killed rival processes, and planted malicious code camouflaged as legitimate work from another agent. In some cases, one agent seized control outright by revoking the others’ access. In others, agents simply gave up rather than continue the conflict.
      • “Not every run ended in stalemate or hostile takeover. A meaningful share of cases resolved when agents recognized that the conflict stemmed from contradictory instructions rather than malicious intent. At this point, they de-escalated, documented what they’d done, and in some cases requested human intervention. 
      • “Anthropic’s Mythos 5 model reached a negotiated truce in 98% of its runs, while older models like Sonnet 4.6 and Opus 4.6 more often ended conflicts by force or failed to resolve them at all.”
    • Startup Fortune adds today,
      • “Anthropic has put Claude Mythos 5, its restricted cyber model, inside Claude Security for Enterprise customers. The bet is simple: give defenders the results without handing everyone the raw model.
      • “Anthropic made the move on August 21, 2026, and the details matter if you run security inside a company that already pays for Claude Enterprise. Claude Security can scan a repository, trace data flows across files, and return vulnerability findings with a CWE category, confidence and severity ratings, and a suggested fix for human review. According to Anthropic’s launch post, those Mythos 5 scans are billed as standard token usage under the existing Enterprise plan. No separate add-on.
      • “That’s the commercial hook.
      • “Security tooling usually lives in its own budget fight, with its own vendor review and renewal cycle. Anthropic is trying to make AI vulnerability scanning feel less like a new platform purchase and more like turning on a capability customers already have access to. For security teams, that distinction isn’t cosmetic. It can be the difference between testing a tool this quarter and waiting for procurement to catch up next year.”
    • sdx central informs us,
      • “Palo Alto Networks followed in the footsteps of Nvidia and Anthropic by assembling an all-star group focused on AI-powered cybersecurity.
      • “The Frontier AI Critical Defense Program builds on Palo Alto Network’s existing collaborations with IBM, Red Hat, Microsoft, Siemens, and Idaho National Laboratory, welcoming Anthropic, OpenAI, and Mitsubishi into the fold.
      • “The initiative is targeted at shielding critical infrastructure across operational technology (OT), health care, commercial software, and open-source from AI-driven exploits. Members coordinate with Palo Alto Networks in applying network-level “virtual patches” to neutralize security flaws prior to exploitation.
      • “The security giant claimed its work with compute-heavy frontier AI models has already uncovered more than 14,000 previously unknown vulnerabilities in open source software. As a comparison, Anthropic claimed at one point to have used its vaunted Claude Mythos Preview Model to fing more than 23,000 flaws across more than 1,000 open-source projects.
      • “IBM and Red Hat’s similar Project Lightwell venture has not yet disclosed any findings, but it’s worth remembering that project is still in its infancy.”

    From the cybersecurity policy and law enforcement front,

    • Cyberscoop reports,
      • “Artificial intelligence has never been more important to the federal government.
      • “Under the Trump administration, AI has been adopted rapidly across the private sector and federal agencies. Software developers now use large language models to generate much of their code. Frontier AI models are escaping testing sandboxes to hack live internet infrastructure. Foreign governments are conducting cyber and kinetic attacks targeting data centers and other AI-related infrastructure.
      • “The AI industry’s lightning-fast evolution since 2022 and growing importance to U.S. economic and national security have prompted calls  for stronger federal oversight in order to better manage emerging threats.
      • “A new report published Thursday [August 20, 2026] from the nonprofit Americans for Responsible Innovation, shared exclusively with CyberScoop, calls for the federal government to declare key AI models, companies and its supporting industries as critical infrastructure. It also calls for naming the Cybersecurity and Infrastructure Security Agency as the lead agency managing cyberthreats for the sector.
    • and
      • “A pair of lawmakers wants a watchdog agency to probe how the federal government hacks Americans, including with the use of spyware, and deliver a report to the public.
      • “Sen. Ron Wyden, D-Ore., and Rep. Greg Casar, D-Texas, wrote to the Government Accountability Office on Friday to request the review.
      • “While federal law enforcement agencies have used hacking and spyware as an investigative tool for more than 25 years, there exists little public information regarding its scope, frequency, or operational safeguards,” they wrote. “Unlike traditional surveillance authorities, such as wiretaps or pen registers, the government does not publish annual reports for hacking operations.”
    • Cybersecurity Dive relates,
      • “Defense contractors are struggling to meet the requirements of the U.S. military’s Cybersecurity Maturity Model Certification (CMMC) program, even as the Pentagon tries to accommodate their complaints about compliance burdens.
      • “Only two-thirds of contractors that have submitted CMMC self-assessment scores to the military in 2026 are extremely or very confident that those scores accurately reflect their cybersecurity posture, and the median contractor believes it is only 70% ready to undergo a CMMC certification review, the consulting firm CyberSheath said in a report published on Thursday [August 20, 2026].
      • “The report — which also finds that defense contractors want a wider range of firms to be subject to cybersecurity requirements — underscores the difficulty of protecting the defense industry at a time of increasing nation-state hacking threats.”
    • and
      • “The Trump administration says a new AI-enhanced clearinghouse will dramatically speed up the process of analyzing and fixing software vulnerabilities before hackers can exploit them. But one month after its launch, it’s still unclear how much value the program will create.
      • The U.S. government’s Gold Eagle clearinghouse, which launched in mid-July, is intended to analyze an AI-fueled tidal wave of bug reports, identify and help patch the most dangerous vulnerabilities and raise awareness about those fixes. But Gold Eagle’s limited scale and voluntary nature raise serious doubts about its ability to corral a vast universe of vulnerability analysis, according to cybersecurity experts. These experts also questioned the Treasury Department’s oversight of the clearinghouse, the funding for its central technology system and the way it will integrate with private-sector vulnerability coordination hubs.”
    • Federal News Network tells us,
      • “Agencies are getting some help to improve how they log cybersecurity data. A new logging architecture from the Cybersecurity and Infrastructure Security Agency, the Office of Management and Budget and the Chief Information Security Officer Council aims to assist agencies in taking a practical, risk-based, prioritized logging approach that improves agency network monitoring. The guidance, released yesterday [August 20, 2026] helps agencies implement the changes OMB outlined in a May memo. CISA said agencies will be able to achieve priority logging capabilities that support continuous event monitoring, threat hunting, incident response and forensics. Through this guidance, agencies will be able to update their enterprise logging strategies by applying CISA’s operational checklists. CISA said it will continually update the guidance as cybersecurity threats and agency capabilities evolve.”
    • Cybersecurity Dive informs us,
      • “The U.S. Department of Justice today announced indictments against 17 members of the Mabna Institute, an Iranian organization alleged to be behind a coordinated cyberattack campaign on behalf of the Islamic Revolutionary Guard Corps. 
      • “Federal prosecutors said the group allegedly hacked into 144 U.S.-based universities, 42 U.S.-based private sector companies and at least five federal and state agencies, as well as a large number of foreign universities and companies, since 2013. 
      • “The charges reveal a broader effort behind a “sweeping state-sponsored campaign to steal research and intellectual property from American universities, businesses and government institutions,” Jamie McDonald, U.S. Attorney for the Southern District of New York, said in a statement.
      • “Prosecutors allege more than 100,000 accounts of professors were targeted by the alleged hackers, and 8,000 of those accounts were successfully compromised.”

    From the cybersecurity breaches and vulnerabilities front,

    • HIPAA Journal reports,
      • “Baylor Genetics, a clinical diagnostic genomics company, has recently disclosed a cybersecurity incident that has exposed patient and employee data. The incident was first announced in June; however, the extent of the data breach was unclear at the time.
      • “Baylor Genetics provides genetic testing services to hospitals and is headquartered at the Texas Medical Center in Houston.  The company identified suspicious activity within its computer network on or around June 15, 2026. Immediate action was taken to secure its systems, and an investigation was launched to determine the cause of the activity.  The investigation determined that an unauthorized third party accessed a portion of its information technology network between June 11 and June 17, 2026, and viewed or obtained data stored on the network.
      • “Assisted by third-party cybersecurity specialists, Baylor Genetics conducted a detailed and time-intensive review of all potentially impacted files. The review was completed on July 30, 2026, when it was confirmed that the personal information of certain patients and employees was involved. The types of data involved varied from individual to individual and may have included names plus one or more of the following: date of birth, medical testing information, lab test results, health insurance information, and for a limited subset of patients, Social Security numbers.
      • “Employee data was also exposed in the incident, including personally identifying information such as Social Security numbers, government-issued identification numbers, and financial account information. While data was exposed and potentially exfiltrated, Baylor Genetics is unaware of any actual or attempted identity theft, fraud, or other misuses of the impacted data.”
    • and
      • “When we last reported on the CareCloud data breach in early August, it was starting to become clear from breach notifications to state attorneys general that the cybersecurity incident involved a major breach of patient data. The scale of the breach was difficult to determine, as many state attorneys general do not make data breaches affecting state residents public, and of those that do, only a few state how many individuals have been affected.
      • “The data breach has now been added to the HHS’ Office for Civil Rights breach portal, showing that this was one of the largest healthcare data breaches of the year, involving unauthorized access to the electronic protected health information of 3,756,469 individuals.\
      • While CareCloud has confirmed that a threat actor claimed to have stolen sensitive data, no threat group appears to have publicly claimed responsibility for the attack. This often means that ransom payment has been negotiated, although CareCloud has not confirmed whether that is the case.”
    • Cybersecurity Dive explains “what we know so far about the hacking campaign against US water systems
      • “Support is growing for stricter oversight and increased financial resources for utilities in the wake of a cyberattack spree, suspected to be the work of Iran-linked threat groups.”
    • Cyberscoop relates,
      • “Apollo Global Management confirmed it was among several financial institutions impacted by a string of social engineering attacks that hit the sector last month, the company said Friday [August 21, 2026]. 
      • “Attackers gained unauthorized access to some of the private equity firm’s cloud platforms between July 6 and July 10, the company said in a data breach notificationfiled in California. Apollo did not say when or how it became aware of the intrusion and did not respond to a request for comment.
      • “Apollo is the first victim to formally disclose that sensitive personal data under its care was compromised by a wave of attacks that have hit large private equity firms, law firms, financial rating agencies and medical technology companies. 
      • “The company did not name the group responsible for the attack. Yet, Google earlier this month attributed the ongoing campaign to BlackFile, a threat group affiliated with The Com, that recently split its extortion operations across four brands with shared infrastructure: Redact, Pink, Helix and Falcon.”
    • The American Hospital Association News tells us,
      • “The National Security Agency and other federal agencies released a joint advisory Aug. 18 warning of active cyber threats to Siemens S7 Series programmable logic controllers, which are industrial computers used to monitor essential equipment. Healthcare applications operated by PLCs include climate control, access control and many other systems.
      • “The agencies said threat actors are targeting PLCs using artificial intelligence-generated exploitation scripts disguised as legitimate monitoring tools. The actors are using internet scanning services to find PLCs that are using outdated software or are poorly protected. The agencies urge all owners and operators of Siemens S7 Series and other PLCs to proactively check their systems and adopt mitigation actions recommended in the advisory, including applying critical security patches as soon as possible.  
      • “This latest warning about PLCs specifically focuses on active attacks against one type, but the warning applies more broadly,” said Scott Gee, AHA deputy national advisor for cybersecurity and risk. “Hospitals and healthcare systems should ensure that they have an accurate inventory of PLCs in their environments and prioritize protecting them in collaboration with cybersecurity teams. It is strongly recommended that vulnerable PLCs be disconnected from the internet or placed on isolated networks.”
    • Cybersecurity Dive adds,
      • “Microsoft issued a patch for a critical remote-code execution vulnerability in Entra ID has been discovered by its own security researchers.
      • “The vulnerability, tracked as CVE-2026-69836, is related to deserialization of untrusted data and has a severity score of 10 out of 10, the highest score possible. 
      • “In a bulletin from the Microsoft Security Response Center, Microsoft said the vulnerability has been fully mitigated and no additional action is required of customers. The company added that it disclosed the vulnerability in an effort to provide greater transparency.”
    • and
      • “Security researchers are raising concerns after GitLab on Monday [August 17, 2026] issued an out-of-band patch for a critical code injection vulnerability. 
      • “The vulnerability, tracked as CVE-2026-19478, could enable an attacker to remotely modify or delete a public project as well as user data through a Graph QL directive. The flaw has a severity score of 9.4 out of 10.
      • “The flaw was reported through the HackerOne bug bounty program. 
      • “Threat intelligence firm watchTowr warned Tuesday that it was able to reproduce the vulnerability within minutes of the public disclosure. Researchers said an attacker could do significant damage by exploiting this particular flaw.” 
    • Bleeping Computer points out,
      • “Citrix urges admins to patch new NetScaler flaws as soon as possible.” (August 20, 2026)
    • and
      • “New SynkLoader malware pushed in Microsoft Teams phishing campaign.” (August 21, 2026)
    • Dark Reading notes,
      • “A successful multi-agent AI attack on a government’s agencies in the Asia-Pacific region by a Chinese-language operator has put nations and businesses on notice that near- and fully-autonomous AI-enabled attacks are now a reality.
      • “The attack used as many as eight simultaneously-operated AI agents to conduct reconnaissance, find and evaluate vulnerabilities, attack networks and systems, and then evaluate and improve successive attacks, according to research from sovereign AI firm Dream published on Aug. 12. The company did not attribute the attack to a specific actor or group, but researchers did point to strong evidence that the attackers spoke simplified Chinese — typically a sign of speakers from mainland China.
      • While the company also limited the identification of the targets to “government entities in Asia,” Taiwan’s Ministry of Digital Affairs (MODA) issued a statement the following day, giving details of its response to an attack matching much of Dream’s description, including that it used “AI agents like OpenClaw.”
      • “Overall, the incident should be a warning that fully autonomous attacks could be used against major targets, says Amir Becker, chief business and strategy officer at Dream and a former commander of the cyber operation division of Israel’s 8200 Unit, more formally known as the Central Collection Unit of the Intelligence Corps.”

    From the ransomware front,

    • The American Hospital Association News reports,
      • “A joint advisory released Aug. 19 by the FBI, Cybersecurity and Infrastructure Security Agency, and the Department of Health and Human Services provides updates on activity by Medusa, a foreign ransomware-as-a-service variant first identified in 2021. Healthcare has been a frequent victim of Medusa operations, which have also impacted organizations in education, legal, insurance, technology and manufacturing. The ransomware has affected more than 500 victims in total and has been identified through FBI investigations as recently as April. Its developers and affiliates use a double-extortion model to encrypt victim data and threaten to publicly release the stolen data if a ransom is not paid. The FBI said Medusa ransomware is unrelated to the MedusaLocker variant and the Medusa mobile malware variant. The advisory includes more information about Medusa’s affiliate model, payment ranges for initial access brokers and a broader list of exploited vulnerabilities, among other new information. 
      • “Medusa ransomware has been used by threat actors to conduct malicious activity against U.S. hospitals and health systems over the last several years,” said John Riggi, AHA national advisor for cybersecurity and risk. “This year, Medusa claimed responsibility for a high-impact attack against a regionally important Level 1 trauma center, disrupting care delivery and posing a risk to patient and community safety. Once again, these attacks highlight the need for hospitals and health systems to strengthen cyber resiliency through enhanced defensive measures and clinical continuity procedures.” 
    • HIPAA Journal adds,
      • Medusa attacks typically start with phishing or the exploitation of unpatched vulnerabilities. The group incorporates exploits for recently announced vulnerabilities into it arsenal. For instance, the CVE-2026-1731 BeyondTrust vulnerability started to be exploited soon after it was announced in February 2026, and the CVE-2025-10035 Fortra GoAnywhere vulnerability was also rapidly exploited. The authoring agencies have observed the group incorporating new exploits within 24 hours of a vulnerability being announced and, in some cases, has started exploiting vulnerabilities in the week prior to an announcement.  No evidence has been found to indicate that the group develops its own exploits; rather, the group is believed to obtain exploits from unknown sources, potentially IABs, exploiting them before victims have the time to patch.
      • Medusa actors use living-of-the-land techniques, hiding their malicious activities by using legitimate tools to support credential access, data exfiltration, and ransomware deployment. Remote monitoring and management software and remote access services such as Remote Desktop Protocol are also used.
      • The key actions that HPH sector organizations should take to prevent attacks are to mitigate known vulnerabilities rapidly, ensuring all software, firmware, and operating systems are kept patched and up to date. Networks should be segmented to restrict lateral movement within the network, and network traffic should be filtered to prevent unknown or untrusted origins from accessing remote services on internal systems.
    • Cyberscoop tells us,
      • “A notorious cybercrime group has once again exploited a critical zero-day vulnerability on a large scale, claiming it stole data from dozens of organizations, including some of the world’s largest publicly traded companies.
      • Clop, a prolific but calculated data theft extortion group that’s been active since 2020, began sending threatening emails to its alleged victims in mid-July, according to researchers. 
      • The fallout from the attack spree, which followed a familiar pattern for Clop and its targeted pool of victims, is still evolving as companies hunt for potential signs of compromise.
      • The vulnerability at the center of Clop’s latest campaign affects a pair of software products from PTC — Windchill and FlexPLM — which manufacturers and retailers, particularly in the manufacturing, aerospace, and automotive industries, use to automate supply chain systems and manage product lifecycles.”
    • Bleeping Computer notes,
      • “A suspected ransomware affiliate is posing as a ransomware recovery service called “Ransom Busters,” contacting victims before the attacks become public and claiming it can provide decryption keys and delete stolen data for a fee.
      • “GuidePoint Security’s Research and Intelligence Team (GRIT) disclosed this activity after responding to several recent ransomware attacks in which victims received emails from Ransom Busters offering to help recover from the attack.
      • “The messages were suspicious because they were sent to victims before the attacks became public, raising questions about how they knew about the cyberattacks in the first place.”
    • and
      • “The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that ransomware gangs are also exploiting a high-severity Windows Task Host vulnerability that was flagged as actively exploited in April.
      • “Task Host is a core Windows system component that allows DLL-based processes to run in the background and prevents data corruption by ensuring they close properly during shutdown.
      • “Tracked as CVE-2025-60710, this Windows privilege escalation security flaw was patched by Microsoft in November 2025 and stems from a link following weakness that affects Windows 11 and Windows Server 2025 devices.”
    • Cybersecurity Dive relates,
      • “Medium-sized businesses accounted for roughly three-quarters (73%) of ransomware incidents between 2023 and the first half of 2026, according to the risk management firm Black Kite.
      • “Manufacturing was the most targeted industry (accounting for more than 25% of those victims), and nearly 30% of mid-market organizations had at least one known exploited vulnerability, the firm said in a report published on Tuesday.
      • “The findings add to the challenges facing mid-market firms, which include large customers demanding accountability and a vast array of suppliers that the mid-market firms lack the personnel to hold accountable.”

    From the cybersecurity business and defenses front,

    • The Wall Street Journal reports,
      • “OpenAI told investors its revenue grew 18% to $6.7 billion in the second quarter, disappointing some shareholders as losses deepened.
      • “The company’s operating loss widened to $12.3 billion in the second quarter from $9.3 billion in the first quarter.
      • “Anthropic more than doubled its revenue to $11.6 billion in the same period, surpassing OpenAI’s sales for the first time.”
    • Tech Crunch relates,
      • “As AI models have become more powerful, the potential for those models to be misused has grown — as has a clamor for safety guardrails that can stop such abuse from happening. AI companies must now walk a delicate tight rope between respecting their enterprise customers’ privacy while also watching usage for possible issues.
      • “Sensing an opportunity to one-up its rival Anthropic, OpenAI just announced [August 19, 2026] a privacy-centric safety approach to monitoring for misuse. The company is previewing a new service to select customers that it calls Private Safety Processing. This is an automated system that watches for potential abuse while simultaneously retaining none of the customer’s data.
      • “This system clearly runs counter to Anthropic’s recently announced data-retention policy. The policy, which has aggravated some customers, enables the AI lab to keep user data (all of their sessions — and the conversations therein) for a period of 30 days, when it comes to “covered models.” Those models include all Mythos-class models and “future models with similar capabilities,” the company says.”
    • Reuters adds,
      • “Anthropic plans to let enterprise customers exercise greater control over their data when using ​its advanced AI models, a source familiar ‌with the matter said on Thursday [August 20, 2026], marking a shift in the Claude chatbot maker’s data retention policy.
      • The company is expected ​to roll out a new safety system later ​this year, the person said.
    • Cybersecurity Dive shares how “Fitch explains how water, healthcare organizations can keep strong credit ratings despite cyberattacks
      • “Resilience, not prevention, is key, analysts at the credit-rating agency said in a pair of new reports.”
    • Per National Institute of Standards and Technology news releases,
      • “NIST announces the release of Special Publication (SP) 1353 ipd (Initial Public Draft), QuickStart Guide for Using Artificial Intelligence (AI) for Cybersecurity Framework (CSF) Analysis and ReportingThis new quick-start guide illustrates practical and actionable ways AI could be used for analyzing, planning, implementing, and monitoring an organization’s progress toward achieving CSF 2.0 outcomes.  
      • “The document’s purpose is to: 
        • Provide structured AI prompts as tools for practitioners to begin creating CSF-related artifacts in support of achieving CSF outcomes 
        • Identify current state of practice for AI prompt engineering in CSF implementation and analysis 
      • “The comment period for NIST SP 1353 ipd is open through October 15, 2026, at 11:59 PM. Email comments to: csf@nist.gov.”
    • and   
      • “Cybersecurity works best when it works with people, not against them — and that’s exactly what human-centered cybersecurity (HCC) is all about. The Human-Centered Technologies team at NIST is releasing a concept paper on HCC, and we want your input. Our goal is to build a shared understanding of what HCC really means, then chart a path toward practical guidelines and resources that organizations can actually use to make meaningful change by:
      • “Clarifying whether HCC is primarily an approach—measured by indicators of adoption and maturity—or an outcome—requiring other measures of success such as culture, trust, usability, or resilience
      • “Communicating the relationship between HCC and existing NIST cybersecurity guidelines and frameworks
      • “Assisting organizations in implementing and enhancing HCC within their cybersecurity programs.
      • “But we can’t do that without you. We invite you to read the blog introducing our “Human-Centered Cybersecurity Guidelines and Resources Concept Paper” and submit your feedback via human-cybersec@nist.gov by September 30, 2026.”
    • Here is a link to Dark Reading’s CISO Corner.

    Cybersecurity Saturday

    From the Project Glasswing front,

    • Cyberscoop reports,
      • “OpenAI announced Monday [August 10, 2026] it was expanding access to its frontier models for defensive cybersecurity, detailing different defensive and red-teaming workflows and a new partner program with major cybersecurity product providers.
      • “In a pair of blogs posted Monday, OpenAI said it was updating its Daybreak program  – which provides unreleased frontier models to private organizations and governments for defensive cybersecurity work – and introducing a new model variant.
      • “Daybreak Blue, powered by OpenAI’s ChatGPT-5.6-Sol, would operate with lower cybersecurity safeguards compared to other commercially available models and is described as “a recommended starting point for most defenders” that supports tasks like vulnerability discovery, secure code review, malware analysis, incident response and patch validation. 
      • “Daybreak Red, meant for more advanced red-teaming, would provide access to a new model, dubbed GPT-5.6-Cyber, that the company said is more purpose-trained for finding vulnerabilities and testing (or exploiting) them. The model is also less likely to refuse requests around “dual-use cyber tasks.”
      • “According to OpenAI, the organizations in Daybreak Red will have their use closely monitored and supervised, as GPT-5.6-Cyber is significantly more capable in carrying out malicious cyber tasks than Sol. A security evaluation the company devised tested both models on complex requests, including exploit chain development, authentication bypass, privilege escalation and other hacking tasks. Sol succeeded in 1.5% of the requests, while Cyber completed 95%.
      • “OpenAI said it plans to publish a more detailed system card for GPT-5.6-Cyber at a later date.”
    • Cryptobriefing adds,
      • “Anthropic has disclosed an unreleased internal AI model that it says is more capable than Claude Mythos 5, according to the company’s August 2026 Risk Report.
      • “The model, referred to only as Model 2, represents a noticeable improvement over Mythos 5 across many tasks relevant to Anthropic’s internal work. The company said the improvement is smaller than the capability jump it previously observed between Claude Opus 4.6 and Mythos Preview.
      • “Anthropic said it does not currently plan to release Model 2 externally and has not completed its full suite of typical predeployment assessments, leaving the company with somewhat lower confidence in its understanding of the model’s capabilities.”
    • Silicon Angle points out,
      • “Data resilience company Rubrik Inc. today said a month of scanning its own code with Anthropic PBC’s Mythos Preview model surfaced so many potential security issues that it rebuilt its review pipeline rather than hire reviewers.
      • “The details came in a blog post from Rubrik co-founder and Chief Technology Officer Arvind Nithrakashyap. Rubrik got access in June to Project Glasswing, Anthropic’s limited program that gives defenders early use of Mythos Preview, after the company opened it to another 150 organizations. Anthropic has kept that model out of general release. Mythos finds software flaws and strings them into working attack chains too well to hand out freely.
    • Tech Crunch relates,
      • “What happens when you pit AI agents against each other? According to Anthropic’s testing, things get messy fast.
      • “On Thursday [August 13, 2026], Anthropic’s Frontier Red Team published new research examining how groups of AI agents behave when they encounter each other in the wild. The findings provide a glimpse into potential risks that could develop as companies and governments move to implement agents working autonomously across shared codebases, markets, and computer systems.
      • “In one experiment, Anthropic gave three Claude agents access to the same software project, each with its own incompatible instructions for what to do with it. The agents weren’t told there’d be other agents working on the same project, so researchers could watch what happened when they crossed paths. 
      • “We consistently saw a multiagent turf war,” Anthropic researchers wrote. The models all assumed the others were “purposefully impeding their work” and started sabotaging each other with “increasingly aggressive, self-replicating malware.”
    • CNBC notes,
      • “Over the past two weeks, OpenAIAnthropic and Meta all revealed that their AI models went rogue during routine security testing. In explaining what happened, the companies each mentioned the same small Israeli startup: Irregular. 
      • “Founded three years ago and based in Tel Aviv, Irregular is a niche player in artificial intelligence, backed with $80 million from Sequoia and Redpoint Ventures and valued last year at $450 million. Its technology serves as a sort of cybersecurity test bed for AI models. 
      • “With the leading models becoming ever more powerful, their ability to act in malicious ways is turning into a major threat for corporations and governments, especially as the risk involves hacking into critical computer systems and infrastructure. The recent exploits at OpenAI, Anthropic and Meta all involved their AI models accessing websites that should have been off-limits as part of the cybersecurity testing.” * * *
      • “Meta, which is way behind the other two in its effort to compete at the frontier, was the latest to disclose an AI model hacking a third-party system by accessing the internet. A spokesperson said in a statement this week that the company learned about the matter from Irregular and is investigating.
      • “Meta “will issue a full retrospective once we have all the facts,” the spokesperson said.
      • “Irregular told CNBC in a statement that the incidents were all derived from the “same evaluation-environment issue” that was first disclosed by Anthropic, and that the company is developing a white paper “to share best practices for containment and securely running cyber evals.”
      • “The situation “did not involve a sandbox escape or a sophisticated cyber action,” the company said, adding that “there are no current open issues.”
    • On a related upbeat note, the Wall Street Journal informs us,
      • “U.S. startups are finally delivering something researchers have been working on for decades: a battery in which rare, hard-to-get elements are replaced with the same stuff found in ordinary table salt.
      • “This tech has the potential to help every country on earth break its dependence on China for batteries, and the critical minerals that go into them.
      • “Like any other battery, sodium-ion cells can store and release energy. They are initially being deployed where they’re needed most, in America’s power grid and fast-expanding crop of data centers. As in our homes, giving the grid or other infrastructure the ability to stockpile energy when it is cheap and plentiful, and discharge it when it is scarce, can increase reliability and lower the cost of electricity.
      • “While grid battery storage is already growing in the U.S. at a furious pace, new sodium-based batteries are potentially cheaper, longer-lasting, safer and more reliable than conventional, lithium-based ones. They could accelerate the rollout of renewables, and be part of less-polluting alternatives to natural-gas turbines and diesel generators.”

    From the cybersecurity policy and law enforcement front,

    • Cybersecurity Dive reports,
      • “The Trump administration will let private companies hack foreign criminal organizations as part of a new program that could expand the U.S. government’s ability to disrupt those groups’ cybercrime activities while also introducing myriad legal challenges and perils.
      • “President Donald Trump late Wednesday [August 12, 2026] issued a memorandum directing the departments of Justice and Homeland Security to create a program allowing vetted companies to hack into criminal groups to spy on them or sabotage their operations. Trump said the program would help the U.S. combat cybercrime schemes that cost the nation tens of billions of dollars annually.” * * *
      • “Jason Healey, a senior cyber conflict researcher at Columbia University, said he “would have hated this idea ten or fifteen years ago” when the opportunity still existed to prioritize defense over offense. “But that horse left the barn a long time ago,” he said, “and we have to make decisions for the world we are in, not the one we prevented.”
      • “So, sure, let’s try to allow the private sector to get into the counter-offense game as well,” he said, “but only with very specific criteria to know when it is working and when it is making things worse.”
      • “Kyle Hanslovan, chief executive of the cybersecurity firm Huntress, said the growth of sophisticated adversaries and the threat of “AI-powered autonomous threats” meant that old models of public-private collaboration were no longer sufficient. “The only viable solution is a stronger coalition of the willing,” he said, “which we’ve been eager to support.”
      • FEHBlog note – Of course there are those questioning the memo as discussed in the article.
    • Cyberscoop adds,
      • “Under the memorandum, a federal coordination center “shall create, manage, and maintain a Program to authorize Participating Companies … to conduct Cyber Surveillance Operations and Cyber Effects Operations against foreign Cyber-Enabled Transnational Criminal Organizations (CE-TCOs), under the control and oversight of the Federal Government“ that would be “part of lawful investigatory, protective, or intelligence operations carried out by Federal law enforcement.”
      • Department of Homeland Security to “undergo rigorous vetting.” It would also allow participating companies to sign commercial agreements with other private sector entities to receive threat information. And participating companies’ agreements with federal, state and local governments would be geared toward identifying threats, and proposing cyber operations to the coordination center to address those threats.
      • The program would have to adhere to existing laws, according to the memo. That includes the Computer Fraud and Abuse Act, the main federal anti-hacking statute that prior proposals to open private sector participation in hacking operations would have amended. The memo mandates oversight to evaluate companies’ technical proficiency, ensures both small and large companies can participate, and requires regular reporting to federal officials.
    • and
      • Under the memo, the program must establish legal and constitutional procedures for the prior approval of the targeting of U.S. citizens, as well as develop procedures to halt any unintentional targeting of U.S. people or systems. * * *
      • “The coordination center charged with establishing the program under the memo has 60 days to complete its work. That process could determine a lot. Graham noted that the memo has a classified annex, too.
      • “The memo as written is quiet about what becomes of any seized assets, Graham noted.” * * *
      • “Will Barker, cybersecurity adviser at Huntress, said what’s next could be key.
      • “The 60-day implementing guidance is where the real substance lives,” he said in a written quote. “Minimum standards, operational procedures, the adjudicatory framework for target selection.”
    • MedTech Dive tells us.
      • “The Coalition for Health AI has convened a work group of nearly 100 health system, payer and industry leaders to address cyber risks associated with frontier artificial intelligence models, the nonprofit standards organization announced Wednesday.
      • “The group will meet biweekly with the goal of creating and publishing health AI cybersecurity guidance by the end of 2026. Deliverables include an AI cyber risk assessment tool and playbooks covering both defensive and offensive security strategies.
      • Anthropic’s release of its advanced Mythos and Fable AI models this spring “fundamentally changed” the cyber threat landscape for healthcare, and was a catalyst to stand up the work group, CHAI said.”
    • Cyberscoop informs us,
      • “A tech worker who hatched an elaborate insider attack in late 2023 and attempted to extort Brightly Software for about $2.5 million was sentenced to two years in prison, the Justice Department said Thursday.
      • “Cameron Nicholas Curry, also known as “Loot,” committed a series of crimes while working as a data analyst contractor for the Siemens-owned company. The 27-year-old North Carolina man stole a trove of corporate data, including sensitive employee and compensation information, which he used to threaten various employees and executives over a six-week period in late 2023 and early 2024. 
      • “Curry ultimately extorted the company for $7,540.92 in late January 2024. He was found guilty of six counts of extortion in March.
      • “Brightly Software was named as the victim in court records filed in the U.S. District Court for the Western District of North Carolina earlier this month. The asset and maintenance management software provider, which Siemens acquired in 2022, did not immediately respond to a request for comment.”

    From the cybersecurity breaches and vulnerabilities front,

    • The HIPAA Journal discusses data breaches announced by five HIPAA-regulated entities.
    • Bleeping Computer reports,
      • “The ShinyHunters extortion group stole personal information from 1.6 million RingCentral accounts after hacking the company in July, according to the data breach notification service Have I Been Pwned.
      • “RingCentral is a cloud-based collaboration and communication platform used by over 600,000 businesses for services such as calling, messaging, and voicemail.
      • “The company disclosed the incident on July 28, revealing that its systems were compromised following what it described as a “sophisticated social engineering campaign.”
    • Cyberscoop relates,
      • “As the White House and federal agencies grapple with frontier AI models and their hacking capabilities, researchers are warning that the industry’s “middle class” of smaller models may end up posing a greater threat over the long term.
      • Research from XBOW this week shows that a growing class of both proprietary and open-source models are becoming strategically important in the offensive security ecosystem. Models like Z.ai’s  open-weight GLM-5.2, xAI’s Grok 4.5, Anthropic’s Opus 4.7, Meta’s Muse Spark 1.1, still perform very strongly at many hacking and exploitation tasks that worry policymakers.
      • “It’s not even that the open-source variants or…not quite frontline competitors are catching up [to frontier models] as such,” said Albert Ziegler, head of AI at XBOW. It’s that they are crossing a certain threshold, which means that suddenly they are providing net value at a cheaper price.
      • “That wasn’t necessarily the case as recently as six months ago, when testing on mid-tier class models showed they struggled to complete “moderately complex” agentic tasks. Today’s middle class largely can. Their relative cheapness means users can spend many times more resources—running them repeatedly—to solve the same challenges.”
    • Cybersecurity Dive adds,
      • “Criminal and state-aligned threat groups are testing frontier and open-weight AI models to develop new methods of attacking corporate IT networks. 
      • “Attackers are using AI for a range of activities, enabling them to develop new exploits, accelerate attack speeds and maintain persistence through the abuse of legitimate tools, researchers from Accenture and Google Cloud said during a media presentation at the Black Hat USA conference in Las Vegas.
    • and
      • “Criminal actors are offering a range of AI-powered hacking tools and related services for sale on underground forums on the dark web, according to a report released Wednesday by cybersecurity firm Trellix. 
      • “Researchers found a wide range of AI-based tools being sold through these markets, ranging from reconnaissance tools to credential markets, as well as AI-as-a-service platforms. 
      • “The report shows how AI is being monetized to lower the barriers of entry into sophisticated threat activity. “
    • and
      • “Security researchers are backing claims by a newly emergent data-extortion group that it has exfiltrated sensitive data from about 15 companies, governments and other organizations. 
      • “A threat group called ExfilSquad claimed on July 26 to have exfiltrated customer records and other information from a number of city governments and universities, a major public school system and private companies. After being met with skepticism, the threat actor later released samples of the allegedly stolen information. 
      • “Researchers at Fortra released a report Thursday that corroborates ExfilSquad’s breach claims. The leaked data appears to be related to misconfigured Microsoft Power Page portals, a software-as-a-service platform that is used to create public-facing business websites. The misconfiguration enabled unauthorized access to Microsoft D365, according to researchers, which led to public read access.” 
    • Per Cyberscoop,
      • “Suspected Chinese hackers used open-source artificial intelligence models to run a cyberattack against the Taiwanese government in the first publicly known case of an autonomous AI hack hitting a government target, according to research published Wednesday.
      • “The hackers extracted more than 2,500 personnel records, among other data, in the “near-autonomous attack,” researchers at Israeli cyber firm Dream wrote in a blog post. The attackers set up the framework so that it could “adapt mid-operation without human intervention.”
      • “The framework “implements dedicated research phases it calls ‘Learning Cycles’ — autonomous sessions where the AI system searches vulnerability databases, GitHub repositories, and security research publications for techniques specifically applicable to its target government’s infrastructure,” the post reads.
      • “And then it kept going.”
    • The Cybersecurity and Infrastructure Security Agency (CISA) added three known exploited vulnerabilities to its catalog this week.
      • August 11, 2026
        • CVE-2026-20349 Cisco Secure Firewall Adaptive Security Appliance (ASA) and Firewall Threat Defense (FTD) Heap Inspection Vulnerability
        • CVE-2026-68820 Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability
        • CVE-2026-72898 Metabase SQL Injection Vulnerability
          • Cybersecurity Dive discusses the Cisco KVE here.
          • The Hacker News discusses the Microsoft KVE here.
          • Dark Reading discusses the Metabase KVE here.
    • Cybersecurity Dive notes,
      • “The global system that catalogs technology vulnerabilities is resilient enough to survive the current onslaught of AI-generated bug reports that has alarmed cybersecurity experts, key leaders of that system said last week during panels at two security conferences here.
      • The Common Vulnerabilities and Exposures (CVE) Program — whose unique vulnerability identifiers are the bedrock of the entire cybersecurity industry — “will find a way to scale,” Lindsey Cerkovnik, branch chief for vulnerability response and coordination at the Cybersecurity and Infrastructure Security Agency (CISA), said at the Black Hat USA conference on Thursday [August 6, 2026]. “CVE is going to continue to flourish and improve, and I feel very positively about it.”
    • Infosecurity Magazine points out,
      • “A critical-severity VMware vCenter vulnerability has been exploited within five days of disclosure by Broadcom, with attackers deploying an open-source reverse shell to hold access to compromised systems.
      • “The treat research team at German firm Quirso discovered the campaign during an incident response engagement and published its findings on August 10.
      • “The digital forensics company assessed a suspected advanced persistent threat (APT) actor was responsible, counting 361 victim IP addresses across 47 countries while cautioning that an IP address does not necessarily correspond to a single organization.
      • “The vulnerability, CVE-2026-59310, is acritical directory traversal flaw in the vCenter Syslog server rated CVSS 9.8. Broadcom said an unauthenticated attacker with network access to vCenter can exploit it to execute arbitrary code, turning a service built to collect logs into a route into the operating system.”
    • Per Cyberscoop,
      • “Delta Airlines said Tuesday [August 11] it’s investigating an incident on a Monday flight where a passenger reportedly used an unidentified device to spoof the airline’s in-flight Wi-Fi network, leading to severe delays and authorities to board the plane once it arrived at its destination.
      • Various posts on several social media networks went viral early Tuesday detailing the incident, claiming that passengers on Delta flight 591 from Las Vegas to Atlanta used an unidentified device to create a rogue Wi-Fi network that could be used to steal people’s sensitive data or personal information.
      • “Messages from the plane’s Aircraft Communications Addressing and Reporting System (ACARS) show that the crew informed personnel on the ground that a passenger set up a network called “Delta WiFi Fast” and was “trying to scam the other passengers.”
      • “Morgan Durrant, a Delta spokesperson, told CyberScoop that the cabin crew deactivated the aircraft’s WiFi functionality for approximately 30 minutes, the flight’s safety was never in question and no aircraft operating systems were affected.” * * *
      • “The incident bears the hallmarks of an “evil twin attack,” where an attacker deploys a rogue Wi-Fi access point that masquerades as a legitimate, trusted network by cloning its name and network settings. Often paired with deauthentication attacks that forcefully disconnect devices from the real network, the fraudulent hotspot tricks nearby laptops and smartphones into automatically connecting to it instead. Once a device connects to the rogue point, an attacker can monitor unencrypted internet traffic, execute man-in-the-middle attacks, or display spoofed login portals designed to harvest sensitive user credentials and personal data.”  
    • The Wall Street Journal points out,
      • “Thousands of North Korean operatives are using fake and stolen identities to land remote jobs at U.S. companies—funneling hundreds of millions of dollars back to the regime.
      • “Leaked data, interviews and never-before-seen videos obtained by The Wall Street Journal reveal how a single team of these workers infiltrated at least eight companies in just a few months. Watch the documentary and read the practical takeaways.”

    From the ransomware front,

    • Checkpoint issued its report on the State of Ransomware Q2.
    • The American Hospital Association News reports,
      • “U.S. and international agencies released a joint cybersecurity advisory Aug. 10 warning of actions by Gunra ransomware. Gunra is a ransomware-as-a-service program that has been used to target government, critical infrastructure — including healthcare — and other organizations in the U.S. and abroad.
      • Gunra actors leverage a double-extortion model, both encrypting data and threatening to publish stolen data to a dedicated leak site if a ransom is not paid. The ransomware variant initially appeared in 2025. The advisory provides details on Gunra activity and includes detection and mitigation guidance to protect organizations.”
    • Dark Reading adds,
      • “The joint advisory urged organizations to prioritize patching known exploited vulnerabilities in Internet-facing appliances such as VPNs, implement and test offline immutable backups, and implement network segmentation to limit threat actors’ ability to move laterally.”
    • The HIPAA Journal relates,
      • “AnMed has not disclosed the name of the group behind the attack, but a threat group called The Gentlemen claimed responsibility. The Gentlemen is a ransomware-as-a-service group that is thought to include affiliates and operators from other prominent ransomware groups. The group has claimed several healthcare victims in recent months, and the pace of the attacks is accelerating.
      • “According to the Industrial Ransomware Analysis from the operational technology cybersecurity company Dragos, The Gentlemen was the third most active ransomware group in Q2 2026, claiming 125 attacks in the quarter alone, up from 83 attacks in Q1 – the largest gain out of all established ransomware groups. While the group ranked third, there were only 15 attacks separating the top three ransomware groups, with no single ransomware group dominating.”
    • Bleeping Computer tells us,
      • “Oil giant Shell has confirmed it is investigating a potential security incident after the Clop ransomware gang claimed it stole 89GB of data.
      • “Shell is a British multinational energy conglomerate and one of the world’s top three oil and gas companies, after Chevron and ExxonMobil. It has 85,000 employees in more than 70 countries and operates a massive network of tens of thousands of service and recharge stations that serve over 20 million customers daily.
      • “According to a recent post on Clop’s dark web data leak site, the allegedly stolen files include engineering drawings, scans of facility testing reports, photos of the facilities, and project plans.”
    • and
      • “An Akira ransomware affiliate disabled the endpoint detection and response (EDR) solution on a compromised system by restarting the machine into Safe Mode with Networking.
      • “The attack occurred on August 4 after the hacker obtained initial access through an exposed SonicWall VPN device without multi-factor authentication (MFA).
      • “Managed detection and response (MDR) services company Huntress says that roughly two hours after a successful VPN login, the attacker connected to the domain controller via RDP, enumerated Active Directory users and computers, and then moved to an application server.”
    • and
      • “CISA confirmed today that ransomware gangs have begun abusing a high-severity Microsoft SharePoint remote code execution vulnerability, which has been flagged as actively exploited since early July.
      • “Tracked as CVE-2026-45659, this security flaw stems from a deserialization of untrusted data weakness and allows attackers with low privileges to execute arbitrary code on unpatched SharePoint servers.
      • “It can also be exploited in low-complexity attacks because (as Microsoft explained in May when it released security updates for SharePoint Enterprise Server 2016, SharePoint Server 2019, and SharePoint Server Subscription Edition) “an attacker does not require significant prior knowledge of the system and can achieve repeatable success with the payload against the vulnerable component.”
    • The Record informs us,
      • “A financially motivated threat actor linked to China is believed to be exploiting a critical vulnerability affecting widely used cybersecurity software in a supply-chain attack that could see the hackers deploy custom ransomware across a cascading list of victims’ networks. 
      • “Microsoft Threat Intelligence warned this weekend that the Storm-1175 group began deploying a new ransomware strain on August 2 called StormEncryptor. The hackers previously used the Medusa ransomware to extort healthcare, professional services and finance organizations in Australia, Britain and the United States. 
      • “Back in April, the hackers were described as operating “high-velocity ransomware campaigns” exploiting both recently disclosed vulnerabilities and zero-day exploits, “in some cases a full week before public vulnerability disclosure.” Microsoft said it had seen the group move from initial access to full encryption in under 24 hours. 
      • “In this latest campaign, Microsoft said the group is likely exploiting CVE-2026-18577 — a vulnerability in N-central, a remote monitoring and management (RMM) console used by thousands of managed service providers to administer client endpoints.”
    • The Hacker News adds,
      • “The ransomware group known as DeadLock has been observed using decentralized infrastructure to facilitate victim communications and data leak operations in a bid to improve operational resilience.
      • “Its recovery ecosystem combines the Session messaging network with blockchain-backed services that store and deliver resources used throughout the extortion process,” the Microsoft Threat Intelligence team said.
      • “The tech giant said it observed the ransomware being deployed by multiple threat actors, including an affiliate for Lynx and INC ransomware.”

    From the cybersecurity business and defenses front,

    • Bloomberg reports,
      • “Anthropic PBC is telling prospective investors its second-quarter revenue jumped at least 14-fold versus the same period a year ago, according to documents seen by Bloomberg News.
      • “The Claude chatbot maker reported a preliminary revenue figure of more than $11.5 billion in its latest completed quarter, compared to $787 million in the corresponding period in 2025, and $4.73 billion in the first quarter of this year, the documents show. The second quarter of 2026 saw Anthropic report positive adjusted operating income, according to the documents.”
    • Reuters relates,
      • “Anthropic is in talks to buy Nvidia-backed startup Decart AI, according to a source familiar with ​the matter, as the Claude maker explores acquisitions that ‌could help it handle growing demand ahead of its public listing.
      • “Bloomberg News, which first reported the news on Wednesday, said a deal ​could be worth about $6 billion, citing sources.”
    • Tech Crunch adds,
      • “Anthropic will watermark text generated by its models, including Claude, to comply with European regulations, the company now says. The AI model maker confirmed the watermarking in an updated support page.” * * *
      • “It’s not clear how much editing users need to do to remove the watermark. We have asked Anthropic to clarify and will update the story if we hear back.
      • “The company noted that watermarking will apply to different products like Claude platform API, Claude, Claude Code, Claude Cowork, and Claude Tag.
      • “Platforms are now rushing to watermark AI-generated content after backlash from users and to avoid regulatory scrutiny. Last week, AI music platform Suno said it will mark tracks created on its platform after a spate of legal challenges. Last month, newsletter service Substack teamed up with Pangram to flag AI-generated content. The company’s CEO, Chris Best, called out Claudefishing, a term used for people using AI to generate content.
      • “Apart from Anthropic, other companies like Black Forest Labs, Google, Meta, Microsoft, OpenAI, and Synthesia have committed to adhering to the EU’s code.
    • Cybersecurity Dive informs us,
      • “Cisco’s security revenue surged last quarter as the technology giant saw growing demand for products designed to protect businesses against emerging cybersecurity threats, including those enabled by artificial intelligence agents, the company reported Wednesday.
      • “The company posted $17.3 billion in total revenue for its fiscal 2026 fourth quarter ended July 25, a year-over-year increase of 18%. Security revenue rose 14% in the quarter to $2.2 billion from a year earlier.
      • “The rise of agentic AI is expanding the threat landscape, driving demand for our security and observability solutions to help monitor agent behavior and mitigate evolving threats,” CEO Chuck Robbins said during a Wednesday earnings call.”
    • The Wall Street Journal notes,
      • “Enterprise users spent $300 million on quantum computing in 2025, outranking research labs and governments as the primary spenders for the first time.
      • “A Boston Consulting Group survey found that 62% of the top 25 global companies across 11 major industries spend at least $1 million annually on quantum.
      • “Companies like HSBC, Allstate and EY are investing to prepare for future commercialization and to secure systems against quantum encryption threats.”
    • Per Dark Reading,
      • “Walmart, the world’s largest retailer, faces a complex cyber threat landscape, documenting 806 reported retail breaches in Verizon’s 2026 Data Breach Investigations Report.
      • “Security leadership stresses balancing strong cybersecurity controls with business innovation and speed, avoiding operational drag that could lead staff to bypass safeguards.
      • “Walmart’s security approach involves proactive transparency and trust-building with leadership, using color-coded executive summaries and open discussions on risks and mitigation progress.
      • “Industry experts emphasize the evolving role of security operations as essential business partners, noting there is no one-size-fits-all model but a universal need for pragmatic resilience and honest communication.”
    • and
      • “The Patch Gap: Why Defenders Need to Think in Chains, Not Checklists
      • “It’s time to turn from CVSS-backed patching to choke-point patching focused on breaking chains to critical assets.”
      • “If the volume problem and prioritization problem can’t be solved by patchingfaster and scoring harder, then the framing itself needs to change. The question that the security team should ask is not “which vulnerabilities are most severe in isolation?” but rather “which vulnerabilities, if left unpatched, create a connected path from an attacker’s foothold to our most critical assets?”
    • Per a CISA announcement,
      • “This year marks the 20th year of Cyber Storm, a full-scale national cybersecurity exercise that for two decades has brought together the people who defend the systems Americans rely on. Held every two years, Cyber Storm X arrives as threats from geo-political activity, compromised edge devices, AI risks, and more present new challenges to our nation’s critical infrastructure.
      • “As the nation’s largest cybersecurity exercise, Cyber Storm plays a vital role in preparing for potential cybersecurity incidents by testing and strengthening the nation’s ability to coordinate a unified cyber response. Participants from private and public organizations work together through a simulated crisis. Together, they learn as a team and build stronger relationships that will speed response during an actual event. Importantly, organizations can also update their response plans based on lessons learned during the exercise.” * * *
      • “Learn more about Cyber Storm and past events at cisa.gov/cyber-storm. For more information about CISA’s exercise resources, visit CISA Exercises.”
         
    • Security Boulevard adds,
      • “CrowdStrike has announced a $100,000 international competition that challenges participants to manipulate live AI agents using prompt injection and other red-teaming techniques.
      • “The competition takes the form of a virtual game called AI Unlocked: Agents of Chaos, created in collaboration with Amazon Web Services. Players take on a fictional mission to stop a shadow group from deploying malicious AI. To do that, they must manipulate the group’s own agents into revealing information and taking actions they were not authorized to perform. Their scores also depend on efficiency, with points deducted for every token used in their prompts.
      • “The contest opens Aug. 31 and is divided into three acts. The first runs through Sept. 7 with a $10,000 prize, the second ends Sept. 14 and awards $20,000, and the final act runs from Sept. 15 through Sept. 29 with a $70,000 prize. The game is available online internationally, with an in-person option to play at CrowdStrike’s Fal.Con conference. Pre-registration is open, and contestants can replay completed puzzles to refine their prompts. CrowdStrike said the highest score recorded when each act closes will receive that act’s prize.”
    • Here is a link to Dark Reading’s CISO Corner.

    Cybersecurity Saturday

    “We are in the Singularity.” Elon Musk

    From the Project Glasswing front,

    • The Wall Street Journal reports,
      • OpenAI is pausing some activities involving an upcoming artificial-intelligence model, Astra, after internal evaluations led the company to conclude it “cannot rule out critical cyber capabilities,” the company said in a blog post on Friday [August 7, 2026]. 
      • The announcement of the slowdown, which represents one of the first times an AI developer has publicly held back model development due to security concerns, follows a series of loss-of-control incidents that have raised alarm among cyber defense professionals and AI-safety researchers. 
    • and
      • Meta Platforms META  said that one of its artificial-intelligence models went rogue during cybersecurity testing, slipped onto the internet and hacked a third-party service, the latest in a drumbeat of disclosures that suggest such incidents are becoming widespread.
      • “The Instagram and Facebook owner said that one of its AI models was able to access the internet because of a “misconfiguration” in a hacking test conducted by a third-party AI testing company. 
      • “The same benchmark test, which aims to explore a model’s hacking capabilities, was behind some of several earlier autonomous AI hacking incidents involving Anthropic and OpenAI, according to a person familiar with the matter. * * *
      • “Irregular, the company that conducted tests for the three companies, said the incidents didn’t involve a sophisticated cyber action and said it had “no current open issues” related to its test environment. The San Francisco-based company said it is working on a white paper on best practices for containing AI models when running tests—dubbed evals—of their cybersecurity capabilities.
      • “The new case [reported August 6, 2026] is the latest proof that AI loss-of-control scenarios, once confined to science fiction and AI-safety experiments, are now a real-world issue.”
    • Cybersecurity Dive relates,
      • “An alliance of more than 100 tech companies and other organizations is proposing a safety reporting system for AI agents that the group says will help prevent rogue models from wreaking havoc on society.
      • “The Shared AI Findings Exchange (SAFE), crafted by a working group of the Open Secure AI Alliance, would establish mechanisms for collecting information about AI-related security incidents, sharing that information with affected organizations, identifying commonalities across incidents and publishing recommendations based on those lessons.”
    • Tech Times adds,
      • “ByteDance is pre-training an artificial intelligence model with up to 10 trillion total parameters — a scale that would make it the largest AI model ever built by a Chinese company and place it within striking distance of Anthropic’s Mythos system, the Financial Times reported Friday, citing people familiar with the matter. The headline figure is real and remarkable. What it does not tell you — what ByteDance has not disclosed and no outlet has yet asked — is how many of those parameters actually activate during any given query. At a scale like this, that distinction changes everything.”
    • FEHBlog observation; Ruh-roh.
    • Cyberscoop notes,
      • “As AI-generated code continues to be injected into all corners of the internet, concerns have risen about an expanding attack surface for malicious hackers to exploit.
      • “Some have argued that the enhanced cybersecurity capabilities of large language models could serve as a check, finding and fixing vulnerabilities nearly as fast as they’re created.
      • “But new research that tested the patching capabilities of two popular commercial models, OpenAI’s ChatGPT 5.5 and Anthropic’s Claude Opus 4.8, found that generative AI is more likely to create an exploitable patch or introduce entirely new bugs than close off a vulnerability.
      • “Researchers at 1Password tested the models ability to patch six “high-impact, high-complexity” CVEs, including the “Copy Fail” vulnerability, a kernel flaw that can give an attacker root access to Linux cloud environments. The overall success rate (or fully patching the vulnerability without introducing new problems), was less than a coin flip at 47%.
      • “Our research findings show that, in aggregate across a variety of scenarios, both Claude and ChatGPT had a low rate of successful patch generation, which we define as full remediation of all known exploit paths with no erroneous changes to application behavior,” wrote John Hoodlet, Axel Mierczuk and Spencer Michaels.

    From the cybersecurity policy and law enforcement front,

    • Roll Call reports,
      • “The Senate easily passed a bipartisan continuing resolution early Saturday morning [August 8, 2026] likely easing the traditional September rush to head off a partial government shutdown in October.
      • “On a lopsided vote of 90-6, the Senate passed a measure that would extend current funding through Dec. 11, giving lawmakers about 10 extra weeks to complete full-year appropriations bills for fiscal 2027.
      • “But the bill still requires a vote in the House, which won’t be back in session until the first week of September. The House had passed a more bare-bones funding extension last month without many of the “anomalies,” or deviations in current spending, requested by the Trump administration.”
    • Federal News Network adds,
      • “The Senate’s bill to keep the government funded past the midterm elections would extend critical cybersecurity authorities and allow the Technology Modernization Fund to continue investing in agency tech projects. * * *
      • The Senate CR, unlike the House bill, would extend two cybersecurity authorities for the duration of the stopgap: the Cybersecurity Information Sharing Act of 2015 and the Federal Cybersecurity Enhancement Act of 2015. Both laws are set to expire after Sept. 30.
      • CISA 2015 provides privacy and liability protections to encourage companies to share data about cyber vulnerabilities and threats with government and each other. Cybersecurity leaders say those protections provide a critical underpinning to facilitate collaboration across government and industry. * * *
      • “Meanwhile, the Federal Cybersecurity Enhancement Act authorizes the Department of Homeland Security to deploy intrusion detection tools, like the long-running “EINSTEIN” service, across federal agencies.”
    • Cybersecurity Dive relates,
      • “National Cyber Director Sean Cairncross on Tuesday [August 4, 2026] said the Trump administration is working to strike a balance between responsible, secure development practices, while promoting growth and allowing the private sector to innovate. 
      • Cairncross, the opening keynote at the Black Hat USA 2026 cybersecurity conference, said the White House understands the growing safety concerns about AI, but recognizes the need to work collaboratively with the private sector. 
      • He warned that due to the current pace of innovation, an overly prescriptive regulatory regime could be obsolete within 48 hours of being implemented.  
      • “So what needs to be built is a flexible, adaptable structure that enables information sharing between industry and government,” Cairncross said. “So we can guarantee that this technology benefits everyone that it’s going to benefit but is used responsibly and securely.”
    • and
      • “Policymakers and business executives need to focus on basic cybersecurity resilience instead of getting distracted by flashy claims about AI-fueled hacking nightmares, a group of senior U.S. and allied government officials said on Wednesday.
      • “The immediate challenge is not runaway AI,” Jonathon Ellison, director for national resilience at the UK’s National Cyber Security Centre, said during a panel at the Black Hat 2026 cybersecurity conference here. “The immediate challenge is being resilient enough for the faster-paced environment that we are entering into, given the legacy issues that we are carrying.”
      • “Michael Duffy, the acting U.S. federal chief information security officer, said organizations needed to shift from a prevention-focused mindset to one that prioritizes continuity of services.
      • “Things will go down,” he said, and organizations need to prioritize their most important systems so they can continue delivering on their mission.
      • “The cybersecurity community, he added, needs “a new risk calculus for what it means to operate in a contested environment.”
    • The Wall Street Journal tells us,
      • “An outbreak of digital attacks on U.S. water plants is stoking fears across party lines that budget cuts at the federal government’s primary cybersecurity agency could leave the nation ill-equipped to thwart global hackers.
      • “We need a skilled cyber workforce at CISA,” Rep. Andrew Garbarino, a New York Republican, said about the Cybersecurity and Infrastructure Security Agency. Garbarino, who chairs the House homeland security committee, said Congress and the White House need to work together to ensure the agency has the staff and resources to protect critical infrastructure.” * * *
      • “In April, CISA’s annual budget was cut by $300 million, to $2.6 billion from $2.9 billion, reversing an annual growth rate of roughly 9% since the agency was launched in 2018. The shortfall has both Republican and Democratic lawmakers seeking ways to recharge the agency—for a start, by confirming a permanent director, a role vacant since January 2025. 
      • “Rep. Bennie Thompson (D., Miss.), ranking member on the Homeland Security committee, said he plans to propose legislation aimed at guiding the process of restaffing CISA. Thompson didn’t provide a timeline, saying he will also work with appropriations to restore the agency’s funding. Staff and budget cuts, he said, have “damaged our national security and set critical capabilities back years as the security environment is shifting under our feet.”
      • “An agency spokesperson said CISA is “constantly assessing our operational needs as the threat landscape evolves” and that Homeland Security recently approved new hiring in several mission critical positions.”
    • Cyberscoop informs us,
      • “A Canadian man pleaded guilty to playing a central role in one of the most far-reaching cyberattacks of 2024 — the widespread compromise of more than 165 Snowflake customer environments, resulting in massive data theft for extortion, the Justice Department said Wednesday [August 5, 2026]. 
      • Connor Moucka earned $495,000 by extorting his victims, offering stolen data for sale online, and in one case re-extorted a victim with stolen data of a government official and members of a then-former government official’s immediate family, authorities said.
      • Moucka and his alleged co-conspirators John Binns and Cameron Wagenius stole billions of sensitive records and received more than $2.5 million in extortion payments combined, according to prosecutors. Victims of the attack spree included AT&TTicketmaster, Advance Auto Parts and Santander.
    • and
      • “A longtime cybercriminal was sentenced to 16 years in prison for creating and running Ransom Cartel, a ransomware strain linked to attacks on at least 18 companies between 2021 and 2023, the Justice Department said Wednesday [August 5, 2026]. 
      • “Maksim Silnikau, a Belarusian national, actively participated in Russian-speaking cybercrime forums since at least 2005, and was a member of the cybercrime site Direct Connection from 2011 to 2016, officials said. The 40-year-old created Ransom Cartel and began recruiting participants from cybercrime forums in 2021. 
      • “Silnikau and his co-conspirators attempted to extort at least $5.2 million from victims during the multi-year scheme. 
      • “Victims included a group of law firms, medium-sized businesses, a small medical technology startup, educational institutions and large multinational corporations based in California, New York, Nebraska and elsewhere. Some of the victims’ operations were disrupted for several months, officials said.
    • HIPAA Journal points out,
      • “Over the past 18 months, many healthcare providers have settled class action lawsuits over their use of website tracking and analytics tools. The list continues to grow with a further five settlements recently announced [and discussed in the article]; however, class action lawsuits stemming from the use of tracking and analytics tools do not always result in settlements.
      • “A proposed class action lawsuit against CRH Healthcare, doing business as Peachtree Immediate Care in Georgia, that alleged violations of the federal Electronic Communications Privacy Act and asserted claims for negligence/negligence per se, breach of implied contract, breach of express contract, breach of fiduciary duty, and unjust enrichment, has been dismissed with prejudice.
      • “The judge ruled that the complaint was speculative, as the plaintiff failed to explain what damages had been suffered as a result of the defendant’s actions. The plaintiff has been given 14 days to file an amended complaint, or the lawsuit will be permanently dismissed. The decision shows that while tracking and analytics tools may result in disclosures of sensitive data to third parties, the plaintiff(s) must demonstrate that the disclosures resulted in a compensable injury.”

    From the cybersecurity breaches and vulnerabilities front,

    • Healthcare Dive continues to track healthcare data breaches here.
    • For example, Bleeping Computer notes,
      • “Healthcare software company Unlimited Technology Systems reported that more than 3.8 million people were impacted by a data breach incident that occurred in October 2025.
      • ‘The organization submitted data breach notification samples to the authorities this year on July 1st without revealing the exact number of impacted individuals.
      • “An entry on the breach notification portal of the U.S. Dept. of Health and Human Services now shows that a company server was breached and data of 3,803,750 people was exposed to an unauthorized party.
      • “Unlimited Technology Systems is a software company specializing in providing financial and revenue cycle technology for specialty healthcare providers. According to its website, the firm serves 4,500 clinics and 6,500 specialty healthcare providers across the United States, and processes more than $70 billion in net healthcare charges annually.”
    • The Wall Street Journal reports,
      • “Federal agencies are investigating cyberattacks that targeted more than 30 water systems in Minnesota and utilities in several other states.
      • “Former national security officials say the attacks are consistent with Iran-linked activity, but President Trump rejected that idea.
      • “Small water utilities are vulnerable to hackers because they rely on internet-connected automation but often lack the funding to secure it.”
    • Cyberscoop adds,
      • “The U.S. Coast Guard said it is monitoring the aftermath of a cyberattack that disrupted gate operations at all three of North Carolina’s port facilities this week, though it offered few details as the investigation into the breach continues.
      • “A Coast Guard spokesperson told CyberScoop that the branch’s IT unit was coordinating with partner agencies while conducting the investigation. A spokesperson for CISA did not respond to CyberScoop’s inquiry by press time [on August 7, 2026]. 
    • Security Week points out,
      • “Thousands of data centers are at risk of compromise due to a 22-year-old vulnerability in Baseboard Management Controller (BMC) management processors, data center security firm Lava reports.
      • “Found in most server platforms, BMCs enable server management operations even without a working operating system and typically represent some of the most privileged control points in a data center.
      • “Through a BMC, administrators can power-cycle the host, perform firmware updates, make low-level platform configuration changes, read hardware sensors, and more, using several management surfaces, including the IPMI out-of-band protocol, the Redfish HTTPS-based management API, and a web-based administrative interface.
      • “In many implementations, these interfaces share the same user database. A credential that works for IPMI may also work for the web interface or Redfish API. This matters because the IPMI authentication process can expose information that enables offline password recovery,” Lava notes.”
    • To sum up, Cybersecurity Dive lets us know,
      • “Cyberattacks on operational technology have shifted in recent years from extortion and espionage to destruction, a trend that should alarm those tasked with defending outdated industrial equipment, experts said on Thursday.
      • “The panel discussion at the Black Hat USA cybersecurity conference here highlighted the plethora of risks facing U.S. critical infrastructure operators — many of them poorly staffed and funded — at a time of heightened geopolitical conflict.
      • “OT attacks are increasingly moving from targeting not just data but physical operations,” said Cheri Benedict, a cybersecurity and supply chain adviser at the White House’s Office of the Federal Chief Information Officer.
      • “There is a real desire and willingness to cause this impact at scale,” said Matthew Rogers, the operational technology cybersecurity lead at the Cybersecurity and Infrastructure Security Agency (CISA).”
    • and
      • “Cyberattacks on the healthcare industry have brought hospitals, clinics and other providers to a breaking point, researchers said on Friday.
      • “These are patient safety issues, and yet these types of attacks continue to increase,” Christian Dameff, the co-director of the University of California San Diego’s Center for Healthcare Cybersecurity, said during a presentation at the DEF CON conference here.
      • “The healthcare sector consistently ranks as one of hackers’ top targetsbecause of the sector’s financial constraints, supply-chain opacity and low tolerance for downtime. Cybercriminals have repeatedly broken into hospital chains and healthcare vendors, sometimes causing widespread disruptions and even jeopardizing patient safety.”
    • Cyberscoop adds,
      • “In less than four hours early Tuesday [August 4, 2026], an attacker compromised a GitHub maintainer account and unleashed a self-replicating piece of malware which injected malicious code into more than 440 distinct npm packages, according to multiple security firms. 
      • “The worm, built on the open-source Mini Shai-Hulud repository that TeamPCPpublished in May, was initially let loose in keyv, a data management interface software package with more than 600 million monthly downloads. The attacker spent the next 30 minutes compromising additional packages controlled by the same maintainer, including cacheable, flat-cache, file-entry-cache.
      • “The attack spread to other maintainers, eventually compromising more than 860 packages with a “combined total of over 2 billion monthly installs,” Ilyas Makari, malware researcher at Aikido Security, wrote in a blog post
      • “Wiz researchers told CyberScoop it hasn’t observed any new malicious packages since the initial wave moved through a massive footpoint of cloud and code environments in those first four hours.” 
    • Cybersecurity Dive tells us,
      • “Researchers have found fifteen previously unknown vulnerabilities that affect zero-touch provisioning in TP-Link Omada, which is widely used to provision network devices from a central location, according to a report by Forescout Research – Vedere Labs. 
      • “Small to medium-sized companies use the technology to rapidly set up routers and firewalls, which in some cases involves thousands of devices. The technology helps companies save considerable costs when deploying network devices, but it also offers attackers wide access to a lot of systems. 
      • “The research, presented Wednesday [August 5, 2026,] at the Black Hat USA conference in Las Vegas, shows that attackers can chain together vulnerabilities with previously disclosed flaws and infiltrate networks.”
    • and
      • “The malicious use of AI has rapidly accelerated to the point where some threat groups have embedded the technology across their cyber operations, according to a report released Monday [August 3, 2026,]by CrowdStrike. 
      • “China-nexus actors Vault Panda and Genesis Panda have used AI to exploit critical vulnerabilities within 24 hours after a proof-of-concept was disclosed. 
      • “Meanwhile a North Korea-nexus group tracked as Stardust Chollima was able to inject a malicious npm package into 131 trusted Mastra AI frameworks in a supply-chain attack, according to CrowdStrike researchers.” 
    • Per Bleeping Computer,
      • “The Greatness phishing-as-a-service (PhaaS) platform has expanded from credential phishing to adversary-in-the-middle attacks and device-code phishing targeting Microsoft 365 accounts.
      • “The platform has been active since at least mid-2022, targeting Microsoft 365 users in the United States, Canada, the UK, Australia, and South Africa.
      • “It evolved over the years and now targets multiple platforms, including Microsoft 365, iCloud, Yahoo, and Google Workspace.
      • “Currently, it is sold for $289 per month to cybercriminals over a Telegram channel with thousands of subscribers.”

    From the ransomware front,

    • Cybersecurity Dive reports,
      • “Ransomware extortion caused roughly three-quarters of business losses in the first half of 2026, the cyber insurance firm Resilience said in a recent report.
      • “At the same time, ransomware accounted for less than 6% of the incidents for which Resilience customers submitted claims, which the company said highlighted how “disproportionately costly” they are.
      • “Other data in the report highlight the importance of proper employee training and vigilant adherence to protocols such as regular backups.”
    • The Register adds,
      • “Ransomware attacks jumped nearly 20 percent in July, with UK firm Comparitech counting 799 incidents, up from 668 in June.
      • “Of those, 51 had been confirmed by victims. The tally makes July the second-busiest month of the year for ransomware, behind March, albeit just barely, when the firm recorded 805 attacks.
      • “The most interesting data after this surging month of attacks is the targets: While news of widespread cyberattacks targeting water infrastructure in the United States may be dominating security headlines lately, those attacks aren’t ransomware, and ransomware attacks on utility companies were actually down 44 percent last month.
      • “In addition to a decline in attacks on utilities, legal firms and government agencies also became less attractive targets, with attacks on those sectors down 31 percent and 11 percent, respectively, Comparitech said.
      • “On the other hand, ransomware attacks increased most heavily in July against finance companies, tech firms, pharmaceutical companies and medical billers, and the education sector, with rates up 71 percent, 62 percent, 46 percent and 44 percent, respectively. 
      • “Those numbers should come as no surprise given what pentesting firm DeepStrike reported about the most frequent payers of ransomware: Manufacturing, education, healthcare, and financial sector firms are the most likely to pay out a ransom, the firm says, with even the least likely (finance) still paying ransoms 51 percent of the time. Ripe targets, in other words.” 
    • Cyberscoop relates,
      • “Researchers said INC ransomware, one of the most active ransomware groups globally, has been the main attacker exploiting a pair of SonicWall zero-days soon after they were disclosed last month.
      • “The prolific ransomware-as-a-service operation wasn’t the first group to exploit the flaws, which were actively exploited for three weeks before the vendor disclosed and patched the defects July 14, but it has been the most assertive and concerning group to target and chain both vulnerabilities together for full access.
      • “Since public disclosure, INC ransomware has emerged as the most commonly named threat actor actively weaponizing this vulnerability chain,” Brett Deroche, director of incident response at Rapid7, told CyberScoop. “While Inc is the name driving the post-disclosure wave, we can’t attribute the full body of exploitation to INC specifically.” * * *
      • “The SonicWall vulnerabilities — CVE-2026-15409 and CVE-2026-15410 — are the latest in a series of security issues confronting the vendor’s customers, including actively exploited zero-days, previously disclosed defects, and an attack last year that allowed a state-sponsored threat group to steal the firewall configurations of every SonicWall customer.” 

    From the cybersecurity business and defenses front,

    • The Wall Street Journal reports,
      • “Hasbro CFO Gina Goetter was abroad when a cyberattack hit the company this spring. The day started as planned, but her schedule was wiped clean a few hours later.  
      • “The team “knew something was wrong in the morning,” said Goetter, who is also the company’s COO. “By afternoon, they were aware that it was a breach.” 
      • “The toy and game maker discovered the intrusion in late March. Executives quickly pulled its entire SAP system, which tracks everything from financial to human-resource matters, offline to assess the damage. For three or four days, employees relied on manual workarounds to keep operations moving, forcing Hasbro to delay its first-quarter earnings. 
      • “Company leadership, however, refused to derail certain business operations. * * *Systems were restored faster than anticipated following the cyberattack, keeping costs lower than expected. Hasbro lost roughly $25 million in revenue because of the breach in the three months ended June 28, below the projected $40 million to $60 million hit. The swift recovery allowed the company to quickly terminate third-party legal and accounting support, often a significant part of the costs, according to Goetter.  “We came up faster, which helped,” she said.”
    • SC Media adds,
      • “No, 60% of small businesses don’t fail within six months of suffering a data breach.
      • “That widely circulated figure has been bouncing around for 15 years, but it’s dead wrong, security researcher Adrian Sanabria said Tuesday (Aug. 4) at the BSides Las Vegas hacker conference.” * * *
      • “Sanabria didn’t have any suggestions for companies that are short of cash when an attack or breach happens, other than to have a line of credit at the ready. But he pointed out that transparency and honesty go a long way toward restoring trust after a breach.
      • “Especially in healthcare, he said, “the more transparent you are, the less you’ll get sued for.”
        An audience member cited CrowdStrike as handling its devastating July 2024 bad-update incident very well, with the company leader’s same-day online mea culpa and subsequent apology tour to visit affected clients.
      • “Unfortunately, Sanabria said, many companies of every size still think it’s wiser to not disclose data breaches. That’s mainly out of fear of legal exposure, even though it’s clear that timely and full disclosure is the better policy.
        “Most of the reasons we have for keeping breaches quiet are not good reasons,” Sanabria said. “The model is there, and we know how to do it, but the lawyers won’t let us.”
    • Here’s a link to Dark Reading’s CISO Corner.

    Cybersecurity Saturday

    “”We are in the Singularity.” Elon Musk

    From the Project Glasswing front,

    • Cybersecurity Dive reports,
      • “Versions of Anthropic’s Claude AI model broke out of their testing environments and hacked into other organizations on three separate occasions, Anthropic said on Thursday [July 30].
      • The frontier AI lab’s announcement came roughly one week after OpenAI disclosed a similar incident involving its models, a revelation that has set off a new round of consternation about whether AI developers are adequately overseeing their sophisticated AI products.
      • “In the three incidents that Anthropic disclosed, Claude conducted the intrusions while believing that it was participating in a capture-the-flag exercise in which it did not have access to the internet and all available systems were part of the test. “Due to a misunderstanding between us and our evaluation partner,” Anthropic explained in a blog post, “this was not the case, and internet access was available.”
      • “As a result, when Claude encountered the three victim organizations, it believed that they were simulated targets and broke into them using basic attack techniques such as exploiting weak passwords.
    • The article describes the incursions which is worth a click.
    • Cyberscoop adds,
      • “We almost never get both sides of an intrusion. This time we did.
      • “Last month, Hugging Face disclosed a breach into part of its production infrastructure, saying an autonomous AI agent system ran the attack from start to finish. Five days later, OpenAI revealed that its own models, including GPT-5.6 Sol along with an unreleased one, were responsible for the breach. OpenAI called it an unprecedented cyber incident.
      • “Most of the commentary since has been about AI capability. That is the least useful part of the story, because the capability was doing what it was destined to do. Security teams should look at a simpler truth: in both systems, the key defenses sat behind untrusted code that was already running.”
    • Cybersecurity Dive notes,
      • “Businesses are more concerned about AI-fueled threats than traditional cybersecurity dangers, potentially undermining their ability to prepare for the attacks they are most likely to face, researchers at the security firm Arctic Wolf said on Tuesday.
      • “Roughly a third of organizations said AI topped their list of cybersecurity concerns, while concerns about malware, credential theft and cloud misconfigurations dropped from their 2025 numbers, according to Arctic Wolf’s annual AI and cybersecurity trends report.
      • “The report also delved into organizations’ use of AI for their security programs, their reasons for reporting cybersecurity incidents and regional trends in cybersecurity challenges.”
    • and
      • “AI agents remain a major cybersecurity risk for businesses, with 81% of CISOs worrying that their AI systems aren’t properly governed, according to a report Okta published on Wednesday.
      • “Only 47% of companies Okta surveyed said they knew all the AI agents on their networks, and only 46% reported controlling those agents’ access to corporate data.
      • “Okta’s findings highlight a complicated and dangerous environment in which companies aren’t properly balancing the risks and benefits of agentic AI.”
    • Security Week points out,
      • “Anthropic on Friday [July 24] rolled out Claude Opus 5, pitching it as a cheaper alternative to its top-tier Fable 5 model. In terms of cybersecurity, the new model is nearly as good as the AI giant’s most capable system, Mythos 5, at spotting software vulnerabilities, but remains well behind it in turning those findings into working exploits.”
      • “The difference comes from Anthropic’s own OSS-Fuzz-based evaluation, which measures how well a model can locate and then exploit vulnerabilities with minimal human steering. According to the company, Opus 5 identifies vulnerabilities at a rate close to Mythos 5, but its exploit-development score trails considerably. 
      • Anthropic frames this as a deliberate outcome, noting that it has avoided training Opus 5 directly on offensive cyber tasks. The gains it does show, the company says, are a byproduct of broader capability improvements.”
    • Per a July 28, 2026, SonicWall news release,
      • SonicWall today confirmed it is a participant in Anthropic’s Project Glasswing and is testing Claude Mythos 5 for defensive cybersecurity work. Through the initiative, SonicWall is applying the model to vulnerability discovery and code review across its own software to find and remediate security issues before they can be exploited. 
      • Project Glasswing is an Anthropic-led industry effort that gives participating security teams access to Claude Mythos 5, a frontier model not available to the general public, for defensive security research. Anthropic launched the program to help close the gap between attackers using AI to accelerate vulnerability discovery and defenders’ ability to find and fix those same issues first. 
      • “Security vendors are not exempt from the pressure every software maker is under right now,” said Chandro Prasad, SonicWall Chief Product Officer. “Vulnerabilities move from disclosure to exploitation faster than most patch cycles can keep up with. Participating in Project Glasswing gives our security team another way to find and close gaps in our own code before an attacker does. That is the standard we hold ourselves to, and this program is a meaningful way to raise it further.” 

    From the cybersecurity policy and law enforcement front,

    • Bleeping Computer reports,
      • “The U.S. and Australian governments have released new guidance urging critical infrastructure organizations to prepare to isolate vital operational technology systems in the event of a cyberattack or other major disruptions.
      • “The guidance, titled “CI Fortify – Advice for isolating vital systems,” was developed by the U.S. Cybersecurity and Infrastructure Security Agency (CISA), the Australian Signals Directorate’s Australian Cyber Security Centre (ACSC), the FBI, and international partners.
      • “It provides recommendations for disconnecting critical operational technology (OT) and associated systems from corporate, Internet-facing, and other less-trusted networks while continuing to provide essential services for an extended period.”
    • Cyberscoop relates
      • “The Cybersecurity and Infrastructure Security Agency published a guidebook for federal agencies Thursday to aid them on managing security risks with open-source software, touching on topics like patching and open-source AI models.
      • “An executive order President Joe Biden signed and that President Donald Trump amended ordered CISA and other agencies to issue open-source security recommendations to federal agencies. But the guidance is also timely, given a recent slew of attacks on open-source software (OSS).
      • “As part of our statutory mission, CISA remains laser-focused on enhancing the nation’s cybersecurity by collaborating with government, industry and the open-source community to understand and securely use OSS,” said Chris Butera, acting executive assistant director for cybersecurity. “CISA encourages federal civilian agencies to review this guide and implement the principles and practices to improve risk management, better execute their mission, and better serve the public.” 
      • “The document, “Open Source Software: Security Principles and Practices,” touts the advantages of open-source software — which anyone can use, modify and share — as offering benefits in efficiency, cost, security transparency and more, but notes that it also has unique tradeoffs.”
      • “All software carries risk, and OSS is no more or less risky than other software. The key distinction is that, with OSS, agencies can directly assess code quality and security, rather than relying solely on vendor assurances,” the guidance reads. “OSS is increasingly intertwined with emerging technologies such as artificial intelligence. Agencies that adapt to OSS’s unique characteristics will position themselves to meet future challenges and leverage new innovations.”
    • Dark Reading tells us,
      • “A gaggle of government partners from around the world has released new guidelines for the minimum elements that organizations should include in a software bill of materials (SBOM).
      • The document, published this week, was authored by the US Cybersecurity and Infrastructure Security Agency (CISA) and 16 other government entities spread across four continents. It supersedes the National Telecommunications and Information Administration’s (NTIA) 2021 guidelines, which laid out what an SBOM had to contain as far as the US government was concerned. This updated version was first drafted in 2025, and was then informed by suggestions from 90 commenters, including major organizations like Google, Microsoft, and Amazon Web Services (AWS) to create the resulting document.
      • An SBOM is essentially an “ingredients list,” detailing the building blocks and supply chains that make up a given piece of software. This could include proprietary or open source software components, APIs, utilities, and more. As a risk management tool, it aims to provide visibility into where vulnerabilities exist in a software stack and how to prioritize patching, among other things.
      • “There’s nothing revolutionary in this latest spruced-up framework, which follows SBOM policy revisions earlier this year, but it introduces 10 new data fields, and a dozen or so updates to existing elements, which range from major to minor significance. Though the changes might be directionally positive, Jeff Williams, founder of OWASP and founder and CTO of Contrast Security, argues that these minor procedural changes miss the bigger picture.”
    • Per a Health and Human Services Department news release,
      • “The U.S. Department of Health and Human Services (HHS), Office for Civil Rights (OCR) today announced a settlement with OSF Healthcare System and its Affiliated Covered Entities (OSF), concerning potential violations of the Health Insurance Portability and Accountability Act of 1996 (HIPAA) Privacy, Security, and Breach Notification Rules. OSF is headquartered in Illinois and has providers located in Illinois and Michigan.
      • “An accurate and thorough HIPAA risk analysis is not only required by law, but it is also necessary to protect health information and prevent or mitigate ransomware attacks,” said OCR Director Paula M. Stannard. “If a HIPAA regulated entity doesn’t know what threats and vulnerabilities exist to its electronic protected health information (ePHI), they will often learn the hard way when their systems are hacked.” * * *
      • “The settlement resolves an investigation that OCR initiated after OSF filed a breach report in October 2021. In April of 2021, OSF discovered that its files had been infected with the “Nephilim” variant of ransomware. The PHI of 53,907 individuals was exfiltrated by the threat actor. Affected PHI included driver’s license numbers, diagnosis and treatment information, prescription information, medical record numbers, provider names, dates of services, financial account information, and health insurance information.” * * *
      • “Under the terms of the resolution agreement, OSF agreed to implement a corrective action plan that OCR will monitor for two years and paid $552,250 to OCR. Under the corrective action plan, OSF has committed to taking steps to ensure compliance with the HIPAA Rules and protect the security of ePHI, including:
        • “Conduct an accurate and thorough risk analysis to determine the potential risks and vulnerabilities to the confidentiality, integrity, and availability of its ePHI; and
        • “Develop and implement a risk management plan to address and mitigate security risks and vulnerabilities identified in its risk analysis.
      • “Read the resolution agreement and corrective action plan.”

    From the cybersecurity breaches and vulnerabilities front,

    • Dark Reading reports,
      • “A coordinated cyberattack targeting more than 30 community water systems in Minnesota this week underscored the growing threat to often poorly protected operational technology (OT) from adversaries seeking to disrupt critical infrastructure services across the US.
      • “The attacks, which US government officials have reportedly attributed to Iran, disrupted automated systems in some Minnesota communities, forcing them to switch to manual operations for brief periods. However, the attacks don’t appear to have affected water supply, water safety, or wastewater services in a major way, based on public statements by community officials and Minnesota’s IT Services (MNIT) unit.” * * *
      • In an advisory Thursday [July 30], the FBI described the attacks as broader and impacting water and wastewater systems in at least seven states with some of the attacks degrading water operations. The FBI advisory said attackers were targeting OT devices including Rockwell Automation/Allen-Bradley PLCs, specifically MicroLogix 1100 and 1400 series devices. “After remotely accessing internet-facing devices, the actors changed the IP addresses and passwords, resulting in a loss of monitoring and control functionality,” the FBI said. It recommended that affected organizations remove PLCs “from direct Internet exposure via secure gateway and firewalls, setting up strong, unique passwords, and utilizing access control list (ACL) to allow only authorized communication between expected control system devices.”
    • Bleeping Computer adds,
      • “Pharmaceutical company Amgen says it suffered a data breach after threat actors stole corporate data and patient information stored in multiple cloud systems operated by third-party service providers.
      • “Amgen is a California-based biotechnology company that develops and manufactures medicines for serious illnesses, including cancer, cardiovascular disease, inflammation, and rare diseases.
      • “The company said it detected the unauthorized activity in July 2026 and responded by activating its cybersecurity response plan, implementing containment measures, and hiring independent forensic experts to investigate the incident.
      • “The investigation found that the attackers stole sensitive data from the cloud environments.
      • “The Company has since learned that some of its data, including proprietary data, patient protected health information, and other information, has been exfiltrated from these cloud environments,” Amgen said in a Form 8-K filing with the SEC.”
    • Cyberscoop tells us,
      • “Huntress researchers spotted an active and ongoing series of attacks targeting SonicWall VPN and firewall accounts, which compromised 30 organizations in less than two days, the company said in a threat advisory Tuesday [July 28].
      • The credential stuffing campaign started Saturday and grew rapidly, ultimately compromising 92 unique user accounts during the next 41 hours, according to Huntress. Researchers said the attacks were broad and opportunistic, hitting various SonicWall devices, rather than targeting specific types of organizations.
      • SonicWall hasn’t released a security advisory about the malicious activity as of press time. A spokesperson told CyberScoop the company is still investigating and hopes to have more information soon.
      • The attacks ended — at least for now — as abruptly as they began. The last compromise occurred Monday, according to Michael Tigges, principal tactical response analyst at Huntress.
    • Bleeping Computer informs us,
      • “Hackers are actively exploiting a vulnerability in the FastJson open-source Java library, allowing remote code execution without user interaction or elevated privileges.
      • “The security issue affects FastJson versions 1.2.68 through 1.2.83 and is leveraged in attacks targeting various organizations in the U.S.
      • “The malicious activity was observed last week by the agentic security company ThreatBook, and researchers at the business protection company Imperva confirmed that it was “targeting a wide range of organizations, across Financial Services, Healthcare, Computing, Retail, Business, and other industries.” * * *
      • “FastJson is an open-source Java library developed by Alibaba, used for serializing Java objects to JSON, and vice versa.” * * *
      • “In its security bulletin, Alibaba confirmed the critical severity of the vulnerability and warned that it is exploitable on “the most common Spring Boot deployment model.”
    • CISA added three known exploited vulnerabilities to its catalog this week.
      • July 27, 2026
        • CVE-2025-68686 Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability
        • CVE-2026-16812 Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability
          • Cybersecurity News discusses the Fortinet KVE here.
          • Arista discusses its KVE here.
      • July 29, 2026
        • 2026-20316. Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability
          • Cybersecurity News discusses this KVE here.
    • Bleeping Computer notes,
      • “Broadcom has released security updates to fix five vulnerabilities in VMware vCenter, ESX, Workstation, and Fusion, including three critical flaws that allow attackers to bypass authentication, execute arbitrary code, or escape from a virtual machine to the host.
      • “The vulnerabilities also affect products containing vCenter or ESX, including VMware Cloud Foundation, VMware vSphere Foundation, VMware Telco Cloud Platform, and VMware Telco Cloud Infrastructure.
      • “Broadcom says organizations running versions released before those listed as fixed in its advisory should assume they are vulnerable and take immediate action.”
    • Dark Reading adds,
      • “A maximum-severity vulnerability in the open source AI agent platform Ruflo puts enterprise AI deployments at risk by letting attackers conduct various malicious activities from inside the orchestration framework. The flaw also can leave agents behaviorally compromised even after it’s been patched.
      • “Researchers at Noma Security’s Noma Labs discovered the flaw, tracked as CVE-2026-59726, in Ruflo, formerly called Claude Flow and which hosts AI agent swarms for Codex and Claude Code, they revealed today. The vulnerability, which received the highest CVSS severity score of 10, allowed them to access the platform without logging in at all, according to Noma Labs.”
      • “The weakness is a lack of authentication coupled with command execution capabilities, enabling complete control over the container and exposure of sensitive credentials,” according to details about the flaw posted on OpenCVE.”
    • ZDNet notes,
      • “Forty-three percent of organizations have experienced AI-enhanced or AI-generated phishing attacks, and 37% have encountered AI-augmented malware, according to a new survey. 
      • “CDW’s 2026 Security Research Report is based on a survey of 951 IT decision-makers across a variety of industries. Published Monday, the research reveals what appears to be an AI arms race between cyberattackers and defenders. Many organizations are considering investing in AI threat detection, training, and controls to combat the new face of modern cyber threats: AI techniques, tactics, and technologies.” 

    From the ransomware front,

    • Inc.com reports,
      • “The hackers behind the Fairlife ransomware attack have identified themselves, and experts are sounding the alarm. 
      • “A hacking group known as Anubis has claimed responsibility for the ransomware attack that hit Fairlife, Coca-Cola’s dairy products unit, saying it locked the company’s servers and stole about one terabyte of confidential data.
      • “Coca-Cola first confirmed the attack on July 17, noting that the incident had affected Fairlife’s production systems and forced a temporary suspension of its U.S. operations. At the time, the company said it expected the disruption to continue for the foreseeable future. It said that there was no impact on the safety or quality of its products.
      • “Upon revealing its identity, Anubis threatened to leak the stolen data unless Fairlife paid a ransom. Despite that, Coca-Cola announced this week that much of production had resumed. The company did not disclose how it managed to restore operations or share any details about how the hackers initially gained access to Fairlife’s systems. Coca-Cola has not disclosed whether it paid the ransom.
      • Zach Lewis, chief information officer and chief information security officer at a private higher education institution, told Inc. that this was a case of double extortion: Attackers encrypt a company’s systems and demand payment for a decryption key, and then come back with a second demand, threatening to leak stolen data unless they’re paid again.
      • He described the process as an oddly formal one, with negotiations often playing out through dedicated portals set up by the hackers themselves. “It’s really bizarre working with these criminals who are running a really good support site to navigate through this negotiation,” he said. “They want the transaction to be successful, because if they don’t hold up their end of the bargain, they don’t get that good reputation, and when they go to hit someone else, they won’t get paid either.”
    • Health Exec relates,
      • “A 2025 data breach on a medical billing company, first revealed in late June, exposed sensitive protected health data on 1.3 million people to hackers.
      • “In an announcement, Medical Computer Business Services (MCBS) said the September 2025 incident stemmed from an unauthorized third party gaining access to its network, though it revealed few details about the nature of the attack, saying online that personal information on individuals stored on its network may have been “accessed or removed.”
      • “Soon after, an updated filing with the U.S. Department of Health and Human Services’ Office of Civil Rights Healthcare Data Breach Tracker showed the official number of victims, meaning that hackers at the very least accessed files on 1,261,464 patients.
      • “The company did not confirm that files were moved offsite. However, BleepingComputer reports—complete with a screenshot from the dark web—that a data trove from the incident is available online, with a ransomware group called PEAR (Pure Extraction and Ransom) taking credit. 
      • “The data is available for download, which typically means a ransom wasn’t paid. 
      • “The trove was discovered by researchers at the outlet sometime this week.” 
    • Bleeping Computer tells us,
      • “Health-ISAC, a cybersecurity information-sharing organization for the health sector, is warning healthcare and medical technology organizations of an observed increase in successful attacks by ShinyHunters.
      • “ShinyHunters is an extortion gang that primarily conducts supply chain and identity attacks to breach cloud SaaS and storage platforms in data theft attacks,
      • “Over the past two years, the threat actors have become notorious for conducting numerous supply chain attacks on third-party integration partners. These breaches give them access to OAuth tokens that are used to integrate with SaaS providers like Salesforce and Snowflake.
      • “The threat actors are known for identity attacks, where they target employees through social engineering, including vishing and phishing, to compromise corporate single-sign-on accounts. Once they gain access to an account, they log in to an organization’s Okta, Microsoft Entra, or Google SSO dashboard, which acts as a centralized hub listing all SaaS applications the user has permission to access.” * * *
      • “Health-ISAC says the most important defensive step is breaking the attack chain between the initial vishing call and the takeover of an SSO account.
      • “Organizations are advised to require out-of-band identity verification for password resets, MFA resets, and device re-enrollment requests.
      • “This can include calling users back using a previously verified phone number and requiring manager approval for privileged accounts.”
    • Cybersecurity Dive adds,
      • “Dozens of North American companies have been targeted in a social engineering campaign that abuses Microsoft Teams to deploy ransomware, according to a report by cybersecurity firm Sophos.
      • “A threat group, tracked as STAC4749, has initiated chats or calls through Microsoft Teams under the guise of providing help desk or IT support to companies in the U.S. and Canada. 
      • “After initiating a remote session through Microsoft Quick Assist or the cloud-based RemSupp tool, hackers deploy PowerShell in order to establish persistence and execute malicious payloads.” * * *
      • “In at least three cases, the hackers deployed Chaos ransomware on a compromised system. Researchers said in one of the cases, the time between initial access to deployment of ransomware was 17 hours, which is consistent with prior Chaos cases. 
      • “The observed attacks ran between February and June, targeting organizations in the services, manufacturing, energy, construction and engineering sectors.” 
    • Cybersecurity News informs us,
      • “The Gentlemen ransomware operation is drawing attention for its aggressive effort to disable security software before locking files. Instead of relying only on fast encryption, the attackers attempt to remove the tools that could detect, block, or contain the attack.
      • “This approach raises the risk for businesses because antivirus and endpoint monitoring tools may be silenced when they are needed most. 
      • “The campaign’s exact initial access method was not detailed, but the activity shows attackers preparing systems for encryption after obtaining a foothold.
      • “Catalyst analysts identified the malware component as anticheatG13.sys, a kernel-level driver with broad capabilities for manipulating processes, networking, files, and system memory.”
    • Per Dark Trace,
      • “Darktrace detected a multi-stage ransomware intrusion from its earliest stages, identifying reconnaissance, privilege escalation, lateral movement, command-and-control communications, and data exfiltration before encryption occurred. This analysis highlights how behavioral detection exposed attacker activity using legitimate tools and infrastructure, providing multiple opportunities for early intervention and containment. “

    From the cybersecurity business and defenses front,

    • Security Week reports,
      • “Nvidia and a large group of technology, cybersecurity, and enterprise software companies announced on Monday the launch of the Open Secure AI Alliance, a new initiative aimed at developing and sharing open source tools, models, and techniques for securing AI systems and agents. 
      • “The effort builds on existing work from the Linux Foundation’s recently launched Akrites initiative and the OpenSSF community.
      • “Inaugural partners of the Open Secure AI Alliance also include Adobe, Cadence, Capital One, Cisco, Cloudera, Cloudflare, Cognition, CrowdStrike, Databricks, Dell, DoorDash, Elastic, HPE, Hugging Face, IBM, LangChain, Microsoft, Naver, NetApp, Nous Research, OpenClaw, Palantir, Palo Alto Networks, Red Hat, Reflection AI, Salesforce, SAP, SK Telecom, ServiceNow, Siemens, Snowflake, SpaceXAI, Synopsys, Thinking Machines Lab, and TrendAI.”
    • Cybersecurity Dive adds,
      • “Microsoft on Monday announced the launch of Project Perception, an agentic security system designed to help defenders combat a rapidly evolving threat of AI-based attacks by malicious actors. 
      • “The company also introduced MAI-Cyber-1-Flash, an AI model that helps users identify and remediate vulnerabilities through an integration with the company’s MDASH code-scanning harness. 
      • “The launch is part of a major industry push to implement AI-based security that can protect corporate IT and critical infrastructure systems from sophisticated attacks. In the past year, threat actors have demonstrated the ability to speed and scale attacks in a way that traditional security technologies cannot match.” 
    • Forresters offers its take on how Project Perception should be implemented.
    • The Wall Street Journal reports,’
      • “Data-security company Cyera has agreed to acquire startup Oasis Security for $1 billion, the latest large deal in a wave of consolidation across the cybersecurity industry fueled by artificial intelligence.
      • “The cash-and-stock acquisition would help Cyera bridge its data-protection platform with Oasis’s technology for managing nonhuman identities, such as AI agents and automated software, as companies grapple with the risks of deploying autonomous tools across their businesses. The companies expect the deal to close later this year.
      • “The biggest catalyst for this acquisition is the customers,” said Yotam Segev, Cyera’s chief executive, who co-founded the company in 2021. “Our customers, and especially our shared customers, have been telling us that these capabilities belong together.”
      • “The transaction between the two New York-based companies is among the largest cybersecurity acquisitions of the year, underscoring how AI is reshaping the industry.”
    • Cyberscoop adds,
      • “Okta announced Thursday it has signed a deal to buy Permiso Security, a cloud-based firm that tracks threats tied to human, machine, and AI-driven digital identities. 
      • “Permiso specializes in spotting risks after a user or system has already logged in, an area the industry refers to as identity threat detection and response. The company draws on more than 2,500 signals gathered from over 70 identity-related partners to flag issues such as excessive access permissions, unused credentials, unusual behavior from AI agents, and violations of internal security policies.
      • “Ely Kahn, Okta’s chief product officer, told CyberScoop that Permiso will allow Okta to merge two functions that have operated separately: real-time threat detection and identity security posture management. “Today those are two separate products that don’t really talk to each other,” he said.” 
    • The American Hospital Association offers “Lessons Learned from Conversations with the FBI: Healthcare Cyberthreats and Best-practice Defense.”
    • The Health Sector Coordinating Council provides a summary recap of the Operation Vital Signs National Cybersecurity Exercise which took place on July 21 an 22, 2026.
    • The HIPAA Journal shares its HIPAA Audit Checklist.
    • Tech Target gives us a CISO’s guide to privileged identity management.
    • SC Media explains why “effective incident response plans elusive for most cybersecurity teams.”
    • Here is a link to Dark Reading’s CISO Corner.

    Cybersecurity Saturday

    “”We are in the Singularity.” Elon Musk

    From the War with Iran front.

    • The American Hospital Association News tells us
      • “The Cybersecurity and Infrastructure Security Agency and other U.S. and international partners July 22 released an updated advisory on Iranian-affiliated cyber actors targeting internet-connected programmable logic controllers, which are computers used to manage and monitor equipment. PLCs can be found in climate control systems, access control systems and many other applications in healthcare. Agencies first warned of malicious activity targeting Rockwell Automation PLCs in April. The updated advisory expands the scope of incidents to include observed targeting of Schneider Electric, Siemens and potentially other manufacturers of PLCs. It also includes new guidance on detecting malicious changes in reusable code modules exploited within Rockwell Automation PLC programs.”

    From the Project Glasswing / the Singularity front,

    • Cybersecurity Dive reports on July 22,
      • “Two OpenAI large language models, including one not yet released to the public, broke free of their constraints last week and autonomously hacked into the AI application library Hugging Face.
      • “The first-of-its-kind event, in which the LLMs tried to steal information that would help them excel on an important test, has highlighted the dangers of the AI industry’s increasingly powerful tools.
      • “We consider this incident to be an unprecedented cyber incident, involving state-of-the-art cyber capabilities, and are responding accordingly,” OpenAI said in a blog post on Tuesday that confirmed its models’ responsibility for the attack, which Hugging Face announced on July 16.”
    • AI Strategist David Borish, writing in LinkedIn, lets us know,
      • “On July 21, Elon Musk quote a message from OpenAI researcher Will Depue that laid out a timeline: a security incident at Hugging Face on July 21, a counterexample to the Jacobian conjecture on July 20, the disproof of Erdős’s unit distance conjecture on May 20, the solution to Erdős problem 1196 on April 14, and Anthropic’s Project Glasswing finding thousands of zero day vulnerabilities on April 7. Depue’s post noted that in “normal” times, these milestones would have been spread across months or years. Compressed into a single week of news cycles, they read differently. Musk’s reply ran five words: “We are in the Singularity.”
      • “The claim landed hard because, unlike most Singularity talk, this timeline is not speculative. Each item is a documented event with a paper trail, and the details matter more than the framing.” * * *
      • “The skeptical case. Grocery prices, commute times, and most people’s jobs look the same this week as they did a month ago. Every event on Depue’s timeline required a human to set up the evaluation, pose the conjecture, or prompt the model, and in most cases required teams of human experts to verify, formalize, or clean up afterward. Deep learning researcher Yann LeCun has argued current architectures will not reach general intelligence without a different approach entirely. Writer Freddie deBoer has made the broader point that a self-improving AI escaping human oversight remains a speculative scenario without a demonstrated mechanism, distinct from AI systems getting better at specific tasks people assign them.
      • “Both things can be true at once. The rate of capability progress across math, security research, and coding is genuinely compressing what used to take years into weeks, and the humans setting the objectives, verifying the outputs, and deciding what gets deployed have not gone anywhere. The more telling test ahead is quieter than another isolated proof or another leaderboard topper: whether formal verification, in Lean or otherwise, keeps pace with the rate of claims, and whether the containment failures at Hugging Face turn out to be a one time embarrassment or the first entry in a longer list.”
    • TechTimes adds,
      • “Microsoft is preparing to launch Project Perception, an AI-powered security platform that scans enterprise codebases for exploitable vulnerabilities — and is built around a deliberate cost-and-access argument against Anthropic’s Claude Mythos Preview, the most capable vulnerability-hunting AI available and one that most organizations on Earth cannot currently use.
      • “The platform is expected to debut before the end of July. It routes security analysis tasks across AI models from Microsoft, OpenAI, and Anthropic, using a model-selection layer that reserves expensive frontier model calls for the steps where they create real value and assigns cheaper, distilled models to high-volume scan passes. That architecture, according to reporting first published by The Information, is designed to bring the cost of running continuous, enterprise-grade vulnerability discovery well below what Anthropic charges for direct Mythos access.”

    From the cybersecurity policy front,

    • Federal News Network reports,
      • “The unprecedented breach of a technology vendor by autonomous artificial intelligence agents is serving to underscore governmentwide efforts to streamline federal cloud security and prioritize faster patching of critical software vulnerabilities.
      • “OpenAI confirmed this week that its advanced AI training models broke out of their test environment and then hacked into the networks of start-up vendor Hugging Face. The incident is the latest AI cybersecurity development driving policy conversations across Washington.
      • “Pete Waterman, director of the Federal Risk and Authorization Management Program (FedRAMP) at the General Services Administration, pointed to the Hugging Face incident as a landmark moment for cybersecurity during Carahsoft’s FedRAMP Summit on Thursday.
      • “Waterman said the incident underscores his program’s shift to the FedRAMP 20x model.”
    • Cyberscoop relates,
      • “Industry groups who spoke at town halls hosted by the Cybersecurity and Infrastructure Security Agency [(CISA)] about a pending cyber incident notification regulation had a few consistent messages:
      • “We want this to apply to fewer of us. We don’t want to report to you on as many incidents. We want to give you less information when we do. 
      • “CISA last week published transcripts from the town halls, where the agency sought feedback on the delayed rule for the 2022 Cyber Incident Reporting for Critical Infrastructure Act — perhaps the most significant cyber legislation Congress has ever passed. That law required critical infrastructure owners to report major cyberattacks to the federal government within 72 hours, and ransomware payments within 24 hours.” * * *
      • “Where the rule specifies what kind of data organizations should report in a major incident, CISA should “seek to collect the least amount of information possible in the easiest to report fashion to facilitate information accuracy and reporting speed,” said Samantha Burch, vice president of technology public policy at government affairs at AHIP, a health insurance industry trade association.” * * *
      • “One industry representative told CyberScoop that CISA’s willingness to hold town halls, combined with the Trump administration strategy emphasizing “common sense regulation,” was a good sign about where the rule might be heading.
      • ‘They are not picking up on the Biden administration’s approach and tweaking it. They’re thinking, ‘What are the specific pieces of information we need during a cyber incident to help critical infrastructure companies respond?’” said Henry Young, senior director of policy for the Business Software Alliance. “In general, industry is optimistic that what we’ll end up with are a few of the most important pieces of information, so that in the emergency, companies can act quickly and actually respond to an incident rather than completing lots of paperwork.”
    • and
      • “Seven out of 10 federal cyber regulations requiring written reports to federal agencies are duplicated elsewhere, a report from a government watchdog found in a report to Congress Wednesday.
      • “And so far, efforts to de-conflict haven’t had much success, the report from the Government Accountability Office concluded.
      • “At the request of two top lawmakers, the GAO examined federal cyber regulations at 37 agencies. It counted 80 out of 117 rules that “either contain the same kind of reporting requirement applicable to a sector or the same reporting requirement as at least one other regulation.”
      • “The desire to harmonize those conflicting rules gathered steam under the Biden administration, as it undertook a more aggressive push to regulate cybersecurity than prior administrations. It has continued into the second Trump administration.”

    From the cybersecurity breaches and vulnerabilities front,

    • HIPAA Journal reports,
      • “There has been a general trend of increasing data breaches over the past decade, with this year on track to set a new record. According to the H1 2026 Data Breach Report from the Identity Theft Resource Center (ITRC), there have been at least 1,803 data compromises in H1 2026, which will give an annual total of more than 3,600 data compromises if they continue to occur at a similar rate as the first half of the year.
      • “Across those data compromises, there have been 1,394 confirmed data breaches (excluding leaks, exposures, and unknown incidents), accounting for 77% of total events. More than 471 million victim notices have been issued, which already exceeds the total number of victim notices for all of 2025, and there are still six months of the year to go. While at the current rate, this year is unlikely to beat the total for 2024, even with only 6 months of data, 2026 already ranks as one of the worst years to date.
      • “As ITRC explains in the report, part of the reason is the return of mega data breaches, the biggest of which involved the Instructure Holdings’ Canvas platform, which accounted for an estimated 275 million notices. A mega data breach at Under Armour involved more than 72.7 million notices, while the SoundCloud data breach saw 29.8 million victim notices issued.
      • “There were no healthcare data breaches in the top 10 data compromise list, in contrast to H1, 2025, when three healthcare data breaches made it into the top 5. In fact, based on breach reporting to the HHS’ Office for Civil Rights, there have been relatively few mega data breaches in healthcare. In H1 2026, only 7 healthcare data breaches required more than 1 million notices.”
    • Dark Reading relates,
      • “Russian state-backed threat actors are compromising networks of Western governments and enterprises through the Zimbra Collaboration Suite (ZCS), according to intelligence and cybersecurity agencies in more than a dozen countries.
      • “In a joint advisory Thursday, the US government and several allied nations warned that an advanced persistent threat (APT) dubbed “Laundry Bear” has been targeting ZCS customers since July 2025. Laundry Bear actors used a zero-day vulnerability in ZCS, tracked as CVE-2025-66376, in a phishing campaign that featured what experts describe as a “half-click exploit” to breach Zimbra webmail servers.
      • “Unlike traditional phishing campaigns that persuade a user into taking an action, such as clicking a link or opening a file, Laundry Bear’s latest campaign leverages a view-based exploit that only requires a user to view a malicious email within a vulnerable version of the webmail service,” the agencies said in the advisory.
      • The campaign is designed “almost certainly to gather sensitive information for the Russian Federation,” according the advisory. The Laundry Bear attacks mark yet another threat from Russian APTs against US organizations.
    • Cybersecurity Dive tells us,
      • “A critical vulnerability in Check Point Software’s SmartConsole login process is being exploited, with a small number of customers already impacted, according to a security advisory released Wednesday from the company. 
      • “The authentication bypass flaw, tracked as CVE-2026-16232, allows an attacker to gain full administrative privileges after they access an application login token. An attacker can then make changes to security policy and configurations. The vulnerability has a severity score of 9.1 out of 10. 
      • Check Point on Wednesday released a jumbo hotfix to address several security issues in its firewall and management products, according to the advisory.
      • A vulnerability of this type is particularly concerning, giving an attacker the ability to make a number of changes, according to a blog post released Thursday by Rapid7. A remote hacker can “alter administrator permissions, manipulate VPN configurations, and potentially disable or tamper with logging and monitoring,” Rapid7 said. 
    • and
      • “A critical-severity deserialization vulnerability in Microsoft SharePoint is now under exploitation, according to security researchers at watchTowr and Defused
      • “The flaw, tracked as CVE-2026-50522, has a severity rating of 9.8 out of 10 and could enable an attacker to execute remote code over a network. 
      • “Hackers are targeting on-premises SharePoint server environments following the release of new exploit code, watchTowr researchers said in a LinkedIn post. Researchers warned that attackers are stealing machine keys to maintain long-term access.”
    • CISA added six known exploited vulnerabilities to its catalog this week.
      • July 21, 2026
        • CVE-2021-27137 DD-WRT Stack-Based Buffer Overflow Vulnerability
        • CVE-2026-0770 Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability  
        • CVE-2026-63030 WordPress Core Interpretation Conflict Vulnerability  
        • CVE-2026-60137 WordPress Core SQL Injection Vulnerability
          • Security Affairs discusses these KVEs here.
      • July 22, 2026
        • CVE-2026-16232 Check Point SmartConsole Improper Authentication Vulnerability
          • The Hacker News discusses this KVE here.
        • CVE-2026-50522 Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
          • Cybersecurity Dive discusses this KVE here.
    • Cyberscoop adds,
      • “Malware targeting AI coding assistants and software developers’ automated workflows is spreading into more environments with more capabilities, placing defenders at a growing disadvantage.
      • “A malware strain dubbed Sandworm_Mode, first discovered by Socket in February, represents a growing threat to software development. According to a CrowdStrike report, the self-propagating worm can spread through code repositories with minimal detection, raising alarms about software supply chains.
      • “The malware’s capabilities are extensive, but not especially unique compared to the series of supply-chain worms known as Shai-Hulud, and more recently Mini Shai-Hulud.
      • “This is the new trend,” Adam Meyers, senior vice president of counter adversary operations at CrowdStrike, told CyberScoop. “This is something we’re seeing more and more. It’s the new hotness right now.”

    From the ransomware front,

    • Cybersecurity Dive reports,
      • “A threat group called Anubis claimed credit for the ransomware attack against Fairlife, the dairy products unit of Coca-Cola. 
      • “The group says it locked the servers at Fairlife and obtained 1TB of data from the attack, according to researchers at Arctic Wolf. Anubis is threatening to leak information if its demands are not met within a week. Researchers provided screenshots posted on the group’s data leak site
      • “Coca-Cola was forced to suspend U.S. production at Fairlife while it launched an investigation into the attack. Coca-Cola officials noted there was no impact on the safety or quality of its dairy products.” “
    • Dark Reading relates,
      • “Ransomware is not just growing, it is actually accelerating, with activity surging between October 2025 and March 2026, as more than 60 new groups entered an increasingly crowded criminal ecosystem.
      • “For enterprises, the surge means not only more attacks but also a larger and constantly changing pool of adversaries to track and defend against.
      • Black Kite analyzed ransomware incidents between April 1, 2025, and March 31, 2026, and identified 7,551 known victims worldwide. That represented a 25% increase over the previous 12-month period, with much of the growth concentrated in the second half of the year. Black Kite counted 2,904 victims between April and September 2025 and 4,647 between October 2025 and March 2026, marking a 60% increase in reported ransomware victims. March 2026 was the busiest month with as many as 861 organizations — or nearly 28 per day — falling victim to a ransomware attack.
      • “This isn’t a problem we’ve contained,” says Ferhat Dikbiyik, chief research and intelligence officer at Black Kite. “It’s still a lucrative business, and the barrier to running one keeps getting lower.”
    • The Hacker News tells us,
      • “Threat actors have been observed exploiting a now-patched high-severity Palo Alto Networks PAN-OS vulnerability as an entry point to deploy Qilin (aka Agenda) ransomware on victim environments.
      • Arctic Wolf Labs said it investigated multiple intrusions in June 2026 that began with the exploitation of CVE-2026-0257 (CVSS score: 7.8), an authentication bypass flaw affecting the portal and gateway components of PAN-OS software.
      • Successful exploitation of the flaw allows unauthenticated remote attackers to sidestep authentication and establish VPN sessions without valid credentials when authentication override cookies are enabled with specific certificate configurations.
      • “Post-exploitation tradecraft varied across intrusions, from rapid encryption-only operations to full double-extortion, possibly suggesting multiple affiliates operating under the Qilin ransomware-as-a-service (RaaS) umbrella,” the cybersecurity company said.
    • Bleeping Computer points out,
      • “The Clop ransomware gang (also tracked as Cl0p) is targeting Internet-exposed PTC Windchill and FlexPLM instances in a new data theft extortion campaign.
      • “Clop has reportedly been exploiting a critical improper input validation vulnerability tracked as CVE-2026-12569, which allows attackers to execute arbitrary code on vulnerable Windchill and FlexPLM instances.
      • “As cybersecurity company ReliaQuest reported on Thursday, Clop operators have been deploying JSP webshells that allow them to exfiltrate sensitive data from targeted companies’ compromised PLM platforms.
      • “ReliaQuest has observed threat actors actively exploiting CVE-2026-12569, a critical unsafe deserialization vulnerability (CVSS 9.3) affecting PTC Windchill and FlexPLM. Exploitation enables unauthenticated remote code execution and JSP web shell deployment for remote command execution and sensitive product data exfiltration,” the company said.”
    • Per Cisco Talos,
      • “Cisco Talos has discovered a new Rust-based remote access trojan (RAT) we call “msaRAT” attributed to the Chaos ransomware group. The name is derived from the binding names found in the binary: “msaOpen,” “msaClose,” “msaError,” and “msaMessage”.
      • “msaRAT is implemented using the Tokio asynchronous runtime, with primary capabilities of browser-leveraged remote code execution and covert tunneling to establish command-and-control (C2) communications.
      • “This RAT never touches the network directly — it controls its C2 communication channel exclusively through Chrome DevTools Protocol (CDP), a browser debugging API. The binary contains a Cloudflare Workers endpoint, but it never makes HTTP connections to that domain itself; it offloads that work entirely to the browser.
      • “msaRAT manipulates the browser via CDP, performs signaling (SDP Offer/Answer exchange) with Cloudflare Workers, and establishes a WebRTC DataChannel between the browser and the C2 server using Twilio TURN (Traversal Using Relays around NAT) as a relay.”

    From the cybersecurity business and defenses front,

    • The Wall Street Journal reports,
      • “The Defense Department signed an up to 10-year, near $7 billion contract with Oracle intended to streamline fragmented licensing and intra-agency efficiency.
      • “The Austin-based cloud computing and software company separately maintained different contracts across the agency. The government said the deal will optimize services and deliver hundreds of millions of dollars in taxpayer savings.”
    • TechCrunch relates,
      • Glow, a cybersecurity startup founded by former Meta and Snowflake executives, emerged from stealth as a unicorn, betting that artificial intelligence is reshaping how enterprises secure employee devices.
      • “The Palo Alto-headquartered startup on Wednesday said it raised $180 million in an all-equity Series A funding round that valued it at $1.2 billion, with backing from Sequoia Capital, Cyberstarts, Greenoaks, and Redpoint Ventures, alongside participation from Index Ventures, Swish Ventures, Lux Capital, Operator Collective, and Holly Ventures. The investment made Glow one of the latest cybersecurity startups to achieve unicorn status before publicly disclosing revenue metrics.”
    • Cybersecurity Dive relates,
      • “Many ransomware victims remain vulnerable to follow-up cyberattacks, even after they complete their incident response processes, highlighting gaps in mitigation activities that increase their odds of becoming repeat targets, the security firm Black Kite said on Tuesday in its annual ransomware report.
      • “The report described how victims fail to patch critical vulnerabilities and properly configure email security tools, underscoring the importance of thorough digital cleanup operations as part of the ransomware recovery period.” * * *
      • “Black Kite also shared fresh data on the ransomware ecosystem and its top targets.”
      • Because ransomware is a profit-motivated business, cybercriminals prioritize the easiest and most lucrative targets, and if an organization fails to fix the problems that opened the door for hackers in the first place, they are likely to return. That fact makes it imperative for hacked businesses to fix digital liabilities as soon as possible after an incident, lest hackers revictimize them seeking another payout.
    • MSN adds, “The next cyber arms race isn’t about finding bugs. It’s about fixing them first.”
    • Here is a link to Dark Reading’s CISO Corner.

    Cybersecurity Saturday

    From the War with Iran front,

    • Cybersecurity Dive reports,
      • “Threat actors linked to Iran are using artificial intelligence to enhance their cyber and information warfare capabilities, putting the U.S. and its allies at higher risk of asymmetric attack, according to a report released Thursday by Recorded Future. 
      • “Iran-nexus actors have used generative AI and large language models in a range of activities, including the development of malware, conducting research on industrial control systems, exploiting software vulnerabilities and other uses. 
      • “There are no indications yet that Iran has developed fully autonomous models, but the country is clearly using AI to accelerate its existing capabilities. 
      • “AI has not transformed Iran into a fundamentally different cyber power, but it has compressed the distance between intent and action,” Alexander Leslie, senior advisor at Recorded Future, told Cybersecurity Dive.” 

    From the Project Glasswing front.

    • CRN reports,
      • “Microsoft’s unprecedented July security update—which potentially includes patches for more than 600 vulnerabilities—is confirmation that ultra-powerful AI models for discovering software flaws are already starting to signal massively bigger challenges in vulnerability management, according to MSP executives.
      • “For months, the industry has been watching for indicators that vulnerability discovery capabilities from frontier AI models such as Anthropic’s Claude Mythos would lead to increased CVEs (Common Vulnerabilities and Exposures). While some hints of this had surfaced previously, the hundreds of CVEs that received software patches Tuesday as part of Microsoft’s monthly release of software bug fixes is the clearest sign of this yet, MSP executives told CRN.
      • “Estimates of the number of vulnerabilities disclosed by Microsoft during the release, colloquially known as “Patch Tuesday,” have varied but could be above 600, according to TrendAI’s Zero Day Initiative. Dustin Childs, head of threat awareness at TrendAI, counted 621 new Microsoft CVEs for the July security update.
      • “The bug apocalypse has fully descended upon us,” Childs wrote in a post.” * * *
      • “Microsoft has been among the tech industry vendors that have received access to Anthropic’s Claude Mythos model for the purposes of proactively discovering vulnerabilities in its own products, as part of the Project Glasswing initiative announced in April. Similarly, OpenAI has provided Microsoft with access to its frontier AI vulnerability-discovery models through its Trusted Access for Cyber initiative.”

    From the cybersecurity and law enforcement front,

    • Cybersecurity Dive reports,
      • “The Trump administration on Tuesday [July 14] announced the launch of a program that will coordinate the security community’s use of frontier AI models to rapidly identify and fix vulnerabilities.
      • “The vulnerability management clearinghouse, which the administration is calling Gold Eagle, is a response to the skyrocketing number of vulnerabilities that AI models are finding and the strain that that surge is placing on the security community. Through the clearinghouse, the government will coordinate efforts by private companies and independent researchers to scan critical software packages for flaws, fix any flaws that surface and deploy those fixes to end users.” * * *
      • “Gold Eagle “has already begun to intake and prioritize identified cybersecurity vulnerabilities from across industries and sectors, coordinate scanning verifications, and ultimately ensure the security of our nation’s software and networks,” the White House said in a statement.
      • “The core of the Gold Eagle program is the Vulnerability Information and Coordination Environment (VINCE), which the government is operating in partnership with Carnegie Mellon University’s Software Engineering Institute. The VINCE platform will allow anyone to report vulnerabilities to the Gold Eagle program for triage and mitigation.
      • “VINCE will enable “vulnerability and patching coordination at a speed and scale never seen before,” National Cyber Director Sean Cairncross told reporters during a briefing on Tuesday.
      • “Gold Eagle will focus heavily on open-source software, whose code underpins a wide range of critical infrastructure but is often poorly scrutinized.”
    • Dark Reading adds,
      • “Katie Moussouris, founder and CEO of Luta Security as well as a pioneer in vulnerability remediation, tells Dark Reading that the cross-sector vulnerability coordination gap Gold Eagle targets “is real,” as the Known Exploited Vulnerabilities (KEV) catalog, National Vulnerability Database (NVD), and Information Sharing and Analysis Center (ISACs) do not address cross-sector prioritization. And as she has long said, vulnerability management policy problems don’t resolve on their own.
      • “The bottleneck was never knowing about more bugs. It was having the people and process to prioritize and fix them and ensure they do not recur,” she says. “Remediation prioritization according to the new BOD 26-04 will take skills and process at each affected organization, by definition, since two and possibly three out of four of the prioritization criteria are subjective and specific per organization.” * * *
      • “Moussouris cited CISA’s recent postmortem on its AWS keys being exposed in a public GitHub repository for six months as an example of something that highlights pre-existing process weaknesses at the federal level.” * * *
      • Knostic chief AI officer Sounil Yu says that if the government wants to help stakeholders via “frontier AI capabilities,” the most useful application would be something that accelerates the implementation of vulnerability fixes.
      • “Finding vulnerabilities proactively has not been the constraint. Even finding a fix or patch has not been a significant constraint. The constraint has traditionally been in implementing the fix wherever the software has been deployed,” he says. “But if you unpack it further, it’s deploying the fix and then recertifying that everything is working as expected.”
      • “Similarly, Sachin Jade, chief product officer at Cyware, tells Dark Reading that while AI tools can surface vulnerabilities faster than anyone can currently act on them, there is also a lag in determining which findings are real, prioritizing severity, and developing and deploying a fix.
      • “This program is a good start, and we as the industry have to work collectively to sharpen our approaches, increase defense velocity, empower sharing and collective defense, and become proactive in our mindsets,” Jade says.”
    • Beckers Health IT asks and answers “Healthcare Security Teams Have More Alerts Than Ever. So Why Is Risk Still Getting Through?”
      • “People remain the core of healthcare cybersecurity. When automation handles repetitive work, analysts can focus on meaningful threats, response planning and the gaps most likely to affect the organization.
      • “IBM found that organizations extensively using AI and automation in security operations identified and contained breaches 80 days faster and experienced an average of $1.9 million less in breach costs. That does not mean technology replaces experienced professionals. It shows what can happen when they receive better-organized information sooner.
      • “The most resilient healthcare organizations will be the ones that can work through data faster, identify what is relevant and act within clear safeguards before a security gap interrupts claims or patient care.”
    • Security Week relates,
      • “The Department of War has suspended CMMC Phase 2’s mandatory third-party assessment requirement, citing concerns that the assessor ecosystem couldn’t scale to meet demand and that compliance costs were pushing small and mid-sized firms out of the defense industrial base. 
      • “A newly formed CMMC Reform Task Force will spend 60 days reviewing the program, gathering industry feedback, and reporting recommendations by mid-September. 
      • Crucially, the pause only affects independent verification, with Phase 1 self-assessment obligations, SPRS score submissions, and the underlying DFARS 252.204-7012 requirement to protect controlled unclassified information (CUI) remaining fully in effect. 
      • “Industry professionals broadly agree that the suspension pauses third-party CMMC audits but not the underlying legal obligation to protect CUI, warning that self-attestation without verification raises False Claims Act exposure. However, experts are split on whether the fix should be to scope assessments down, automate them, or preserve them largely as-is.”
    • Per a July 15, 2026, Cybersecurity and Infrastructure Security Agency (CISA) news release,
      • “Today, the Cybersecurity and Infrastructure Security Agency (CISA), in partnership with the National Security Agency (NSA), Japan Computer Emergency Response Team Coordination Center (JPCERT/CC), Netherlands’ National Cyber Security Centre (NCSC-NL), and United Kingdom’s National Cyber Security Centre (NCSC-UK), published Establishing a Coordinated Vulnerability Disclosure Program to Work With Security Researchers.
      • “This guidance helps software manufacturers and online service providers collaborate effectively with security researchers who identify weaknesses in software, networks, and hardware in a structured, transparent framework. A well-defined coordinated vulnerability disclosure (CVD) program enables software manufacturers and online service providers to better assess potential risk, improve their vulnerability management processes, and make informed decisions that improve product security for their customers.
      • “Coordinated vulnerability disclosure is foundational to building a secure software ecosystem. The practices in this guide help protect customers, strengthen products and support CISA’s Secure by Design initiative, which encourages companies to be transparent and responsible in how they build and maintain their technology,” said Acting Executive Assistant Director for Cybersecurity Chris Butera. “CISA encourages suppliers to establish a coordinated vulnerability disclosure program and build constructive, collaborative relationships with security researchers to enhance product security.”  
    • Cyberscoop tells us
      • “A total of eight cyber personnel have served in a program that began in 2022 to rotate workers between federal agencies to bolster the workforce, a watchdog report said Thursday.
      • “Over the life of the Federal Rotational Cyber Workforce program that effectively went away last year, 13 agencies offered 106 positions and received 634 applications, according to the Government Accountability Office. Eight workers won approval to participate.
      • “The goal of the Office of Personnel Management-led program, established by bipartisan legislation, was that “participating employees develop knowledge and skills that they can bring back to their home agencies,” as the GAO noted.
      • “OPM evaluated possible shortcomings in implementing the program in late 2024 and developed plans for improving it, but never followed up on them, the GAO said. As of next summer the program will officially end, OPM said.”
    • and
      • “A pair of young men were sentenced to 66 months in jail for committing acyberattack on the Transport for London that brought the network’s operations to a standstill in 2024, the United Kingdom’s National Crime Agency said Thursday [July 16].
      • “Thalha Jubair and Owen Flowers were arrested at their homes in September 2025, barely a year after the attack, and pleaded guilty last month just as their trials were set to begin. Flowers was previously arrested in connection with the attack in September, but was released after questioning by officers.
      • “Jubair and Flowers were leading members and highly involved in Scattered Spider, a nebulous hacker subset of The Com, according to researchers. The 20-year-old Jubair was a prolific cybercriminal and core member of the unbound collective
      • “U.S. authorities last year accused Jubair of direct, prominent involvement in at least 120 cyberattacks, including extortion of 47 U.S.-based organizations and the January 2025 attack on the federal court system. 
    • Beckers Health IT identified 11 cases from a Federal crackdown on hospital hackers.
      • “Federal authorities are intensifying their pursuit of the cybercriminals behind hospital and healthcare ransomware attacks, bringing charges against ransomware developers, state-sponsored hackers and even insiders from the cybersecurity industry.
      • “The latest move came July 14, when the Justice Department indicted three Russian nationals and two “bulletproof hosting” companies tied to $62 million in U.S. victim losses. The action is part of Operation Riptide, the FBI’s ongoing campaign against cybercrime infrastructure, after Americans reported more than $20 billion in cybercrime losses last year, a 26% single-year increase.”

    From the cybersecurity breaches and vulnerabilities front,

    • HIPAA Journal posted its May 2026 Healthcare Data Breach report last Tuesday.
      • “Based on the current data on the HHS’ Office for Civil Rights (OCR) breach portal, 61 healthcare data breaches affecting 500 or more individuals were reported in May 2026. May’s current total represents a 27.1% month-over-month increase in data breaches. Over the past 12 months, an average of 64 large healthcare data breaches were reported each month.”
    • MedTech Dive reports,
      • “Abbott disclosed on Thursday [July 16] that a cyberattack hit its cancer diagnostics business.
      • The medical device company said in a statement posted to its websitethat there was unauthorized access to a limited number of internal systems in its cancer diagnostics business. There was no impact on other Abbott businesses, sites or systems.
      • Abbott’s cancer diagnostics business includes Exact Sciences, which the company acquired in a $21 billion deal earlier this year. The legacy Exact Sciences systems are separate from Abbott’s, according to the statement.
    • Beckers Health IT relates,
      • “A cyberattack on New Jersey law firm Greenbaum Rowe Smith & Davis has exposed data on 12,801 patients across three health systems in the state.
      • “Greenbaum discovered unauthorized access to its systems through a compromised user account in November 2025 and traced the intrusion to Nov. 25-27, 2025, according to the firm’s notification. Affected organizations include Edison, N.J.-based Hackensack Meridian Health, Morristown, N.J.-based Atlantic Health and Trinitas Regional Medical Center in Elizabeth, N.J., part of West Orange, N.J.-based RWJBarnabas Health.
      • “An investigation completed in April found an unauthorized third party accessed patient names, addresses, medical record numbers, medical history, provider details, medical bill amounts and health insurance information. For a subset of individuals, Social Security numbers or dates of birth also were exposed, Greenbaum said.”
    • Bleeping Computer tells us,
      • “Ernst & Young is notifying customers of a data breach caused by the compromise of a third-party support ticket system used by its IT personnel.
      • “According to the company, support tickets submitted through the platform may have included documents containing client tax information.
      • “Ernst & Young (EY) is among the world’s four largest auditing and professional services providers, offering auditing, tax, consulting, and transaction advisory services to major organizations in more than 150 countries.” * * *
      • “Ernst & Young says it secured its systems and notified federal law enforcement authorities, while it has assured that the unauthorized access has been removed.
      • “The company also states that it is not aware of any misuse or further exposure of the stolen files and has no indication that particular individuals were targeted by the threat actors.”
    • CISA added ten known exploited vulnerabilities to its catalog this week.
      • July 13, 2026
        • CVE-2008-4128 Cisco IOS Cross-Site Request Forgery Vulnerability
          • Security Affairs discusses this KVE here.
      • July 14, 2026
        • CVE-2026-15409 SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability
        • CVE-2026-15410 SonicWall SMA1000 Appliances Code Injection Vulnerability
        • CVE-2026-56155 Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability
        • CVE-2026-56164 Microsoft SharePoint Server Missing Authentication for Critical Function Vulnerability
          • The Hackers News discusses the SonicWall KVEs here
          • Cybersecurity News discusses the Microsoft Active Directory KVE here.
          • Cybersecurity News discusses the Microsoft Sharepoint Server KVE here.
      • July 15, 2026
        • CVE-2023-4346 KNX Association KNX Protocol Connection Authorization Option 1 Overly Restrictive Account Lockout Mechanism Vulnerability
        • CVE-2026-46817 Oracle E-Business Suite Improper Privilege Management Vulnerability
          • The Hacker News discusses these KVEs here.
      • July 16, 2026
        • CVE-2026-25089 Fortinet FortiSandbox OS Command Injection Vulnerability  
        • CVE-2026-39808 Fortinet FortiSandbox OS Command Injection Vulnerability  
        • CVE-2026-58644 Microsoft SharePoint Deserialization of Untrusted Data Vulnerability 
          • Bleeping Computer discusses the Fortinet KVEs here.
          • The Hackers News discusses the Microsoft Sharepoint KVE here.
    • The American Hospital Association News adds,
      • “The Cybersecurity and Infrastructure Security Agency has issued an alert warning of four Microsoft SharePoint vulnerabilities being exploited by cyber threat actors. CISA said the vulnerabilities affect all supported on-premises versions of SharePoint Server, including the Subscription Edition, 2019 and 2016. Threat actors can establish remote code execution and perform other actions to deploy malware. CISA said organizations should monitor SharePoint Servers closely for any signs of exploitation or unusual activity. An additional vulnerability was found, but it is not yet known to have been exploited. Microsoft identified it as a potential risk if it is left unpatched. CISA urged organizations to apply the latest patches and security updates from Microsoft, among other recommendations. 
      • “Nearly everyone using Microsoft products is using SharePoint, the backbone of the Office suite,” said Scott Gee, AHA deputy national advisor for cybersecurity and risk. “Hospitals with their SharePoint instances housed on premises should pay particular attention to this alert. The common vulnerabilities and exposures listed in the report have patches available, and they should be deployed as soon as possible. Hospitals should also verify that the security measures mentioned are in place.” 
    • and
      • “The Cybersecurity and Infrastructure Security Agency and other U.S. and international agencies released a joint advisory July 13, warning of Russian cyber actors targeting vulnerable network devices, primarily routers, in critical infrastructure sectors globally, including healthcare. The advisory details how the threat actors primarily use scanning to identify poorly configured devices for exploitation. The actors then exfiltrate sensitive information and facilitate malicious activity. The advisory includes recommendations to help defend against potential threats.
      • “This malicious cyber activity has been attributed to the Russian Federal Security Bureau, a foreign intelligence agency of the Russian government,” said John Riggi, AHA national advisor for cybersecurity and risk. “Therefore, this represents an advanced and persistent cyber threat targeting U.S. healthcare that should be prioritized. The first step in mitigating this threat and other nation-state cyber threas is to install the latest network router encryption standard, Simple Network Management Protocol v3.”
    • Cybersecurity Dive tells us,
      • “Businesses should be on guard for a hacking campaign in which attackers spoof OAuth client IDs to collect information about targets’ user directories, the security firm Proofpoint said on Monday.
      • “The security firm said it had observed “multiple campaigns at scale abusing spoofed OAuth application identifiers, with distinct tooling, infrastructure, and execution patterns indicating independent adoption by multiple threat actors.”
      • “The report explains how organizations should monitor their networks for this reconnaissance technique.”
    • Cyberscoop points out,
      • “Cyberstalkers are increasingly exploiting a feature in Google Chrome meant for mobile phone user convenience, but can give intruders broad access to a device owner’s private information, according to researchers.
      • “Certo Software said in a blog post Tuesday that stalkers are making use of Chrome’s sync capability — meant to make it so signing into Chrome on one device makes it easier to do so on other devices, too — to spy on a phone owner’s browsing history and gain access to their stored passwords.”
    • Bleeping Computer adds,
      • “A flaw in Anthropic’s Claude for Chrome browser extension could allow a malicious extension to trigger predefined AI actions by simulating user clicks, potentially allowing it to abuse Claude’s access to connected services such as Gmail, Google Docs, Google Calendar, and Salesforce.
      • ‘The issue was discovered by Ax Sharma of Manifold Security, who says it stems from how the Claude extension determines whether a user intentionally requested one of its built-in tasks.
      • “Chrome extensions with permission to run on a website can inject JavaScript into the page, allowing them to read and modify its contents. This includes changing page elements, reading information displayed on a site, and generating click and keyboard events programmatically.
      • “According to Manifold’s report, the Claude extension listens for click events on a specific page element that launches one of its built-in AI workflows. These workflows are predefined tasks that allow Claude to perform actions in connected services such as Gmail, Google Docs, Google Calendar, and Salesforce.”

    From the ransomware front,

    • Cybersecurity Dive reports,
      • “Coca-Cola on Thursday said it is investigating a ransomware attack that impacted its Fairlife dairy unit and has suspended production at the company’s U.S. production facilities. 
      • “In a filing with the Securities and Exchange Commission, the company said it trying to determine the full scope of the attack and what impact it might have on its business. Coca-Cola said the attack has had no effect on the quality and safety of its Fairlife products, which include ultra-filtered, lactose-free milk as well as protein and nutritional shakes.”
    • Per a Sophos news release,
      • “This year’s data has a few eyebrow-raising departures from the patterns of past State of Ransomware reports. Exploited vulnerabilities lost their three-year grip on the top root-cause spot. Median ransom demands and payments both dropped, yet the average recovery bill still climbed. And small organizations (100-250 employees) are falling further behind their larger peers on the one metric that matters most: stopping the attack before data gets encrypted.
      • “The seventh annual Sophos State of Ransomware report is based on a vendor-agnostic survey of 2,158 IT and security leaders whose organizations were hit by ransomware in the last 12 months.
      • “Click here to access the full report now.”
    • Dark Reading adds,
      • “According to Sophos’ survey, malicious email (26%) and phishing (24%) dethroned the three-year reign of vulnerabilities (18%, down from 32%) as the top root cause of ransomware attacks. Two-thirds (67%) of victims also said the ransomware attack they suffered was their most significant identity attack over the past year.
      • “With phishing and malicious email now accounting for half of all ransomwareroot causes in this report, organizations should deploy advanced email filtering, implement DMARC/DKIM/SPF protocols, and invest in regular phishing awareness training,” Sophos said. “The shift toward email-based attacks suggests that technical vulnerability patching alone is insufficient.”
      • “The third most common root cause of ransomware attacks was also identity related, with compromised credentials used in 23% of cases. This is particularly significant because of one of the most startling findings: Multifactor authentication (MFA) was deployed for 97% of instances where compromised credentials were the root cause of ransomware attacks.” * * *
      • While staying patched remains important as always, it appears the fight against ransomware is moving from patch management to identity protection.
      • “Organizations should prioritize identity threat detection and response (ITDR), enforce multifactor authentication across all access points, and regularly audit both human and non-human identity credentials,” Sophos said. The vendor stopped short of recommending a specific type of MFA, suggesting the biggest failure wasn’t MFA itself but rather incomplete deployment or perhaps a lack of comprehensive inventorying.”
    • InfoSecurity Magazine lets us know,
      • “The number of ransomware attacks which target government departments and agencies has risen to the extent that one has its services restricted by encryption every single day.
      • “The figure comes from analysis by researchers at Comparitech, who studied ransomware incidents which targeted government entities between January and June 2026.
      • The research, published on July 16, recorded that 187 government organizations were hit with ransomware during the first six months of 2026. That represents a 13% increase on the 165 ransomware attacks recorded during the second half of 2025.
      • “The increase in recorded ransomware events is notable because the figure of 187 incidents across 182 days means that the average number of ransomware attacks against government bodies now stands at an average of one every day.
      • “Of those 187 recorded incidents, just over half (89) were publicly confirmed by the organization which was hit.”
    • Bleeping Computers warns
      • “A new ransomware actor called Spirals completed a corporate intrusion, from initial access to data theft and encryption, in less than 24 hours.
      • “The attack occurred in June and breached an IT services firm in South Asia after compromising an Internet Information Services (IIS) server exposed on the public web.” * * *
      • Symantec’s report provides network indicators and file hashes associated with the documented Spirals attack to help organizations worldwide set up defenses against this threat group.”

    From the cybersecurity business and defenses front,

    • The Wall Street Journal reports
      • “Cybersecurity mergers and acquisitions reached 219 in the first half of 2026, putting the sector on track to surpass last year’s 400 deals.
      • “The rush to acquire artificial-intelligence capabilities is driving the surge in cybersecurity dealmaking.
      • “Technology and cybersecurity companies accounted for 88% of disclosed cyber acquisition spending in the first half of the year.”
    • Cybersecurity Dive relates,
      • “Enterprise security teams are incorporating AI into their programs at a faster rate than ever before, but a significant gap exists in the governance policies that are designed to support that expansion, according to a report released Monday by the SANS Institute.
      • Four out of 10 security practitioners said there is no formal policy in their organization for AI adoption, according to the report. More than six of 10 practitioners said they have no visibility into where AI models are being used or what kind of information is being exposed. 
      • “About 75% of security practitioners have a governance role related to enterprise AI, yet more than half of respondents said there are no established frameworks for AI audits, the report showed.”
    • Dark Reading adds,
      • “Having completed its $32 billion acquisition of Wiz earlier this year, Google is fulfilling its plan to automate threat detection, investigation, and remediation with a new “agentic defense” platform built around intelligent security agents.
      • “Wiz, founded in 2020, quickly became one of the fastest-growing cloud security companies by introducing graph-based analysis to correlate cloud assets, identities, vulnerabilities, and exposures across multicloud environments. The acquisition gives Google a cloud-native security platform that supplements its existing artificial intelligence (AI), threat intelligence, and incident response features.
      • “On Monday [July 13], Google revealed it had integrated Wiz attack surface management (ASM) and Google Threat Intelligence (TI). When Wiz ingests posture and workload telemetry from Google Cloud, it enriches detections in real time with Google TI and pushes prioritized exposure data directly into SecOps playbooks and cases, enabling SOC teams to investigate and respond to cloud‑native risks without switching between tools.
      • “The integration builds on Google’s AI Threat Defense, launched in May, and other automation capabilities that combine Gemini with Wiz’s scanning, simulation, and remediation to counter AI-powered threats. It leverages the reasoning capabilities of its Gemini AI modeling platform and other frontier models alongside Wiz’s contextual risk prioritization capabilities. Google AI Threat Defense uses Gemini’s code remediation features and CodeMender, along with expertise from Mandiant.”
    • Cyberscoop notes,
      • “As AI-enabled hacking becomes a bigger threat for cybersecurity and national security, public attention has focused on mainly a few leading frontier AIcompanies developing more powerful large language models.
      • “These models, and the billions of dollars behind them matter, but they’re only part of a larger shift. Enterprises are now building their own technology platforms that take these general-purpose LLMs and turn them into bespoke cybersecurity tools.
      • “Industry professionals refer to these tools as a “harness.” They control the model’s behavior, limit its risks, and connect it to internal IT systems and networks so it can work reliably at scale.
      • New research from Cato Networks shared exclusively with CyberScoop shows how much power can come from a harness. It paired OpenAI’s ChatGPT 5.5 and GPT 5.5-Cyber models with its own tool and tested the abilities of the agent to hack into a victim network with as little human direction as possible.” * * *
      • “Dan Rapp, chief AI and data officer at Proofpoint, said their harness, “Satori,” has become a critical tool for keeping their agentic AI on track while giving humans the ability to step in when things go awry.
      • “I think what you’re seeing in the foundation of frontier models is you have raw intelligence, raw reasoning power, but to get these systems to perform the way you want to, both context engineering – the content provided ensuring that its accurate and relevant – and the harness engineering are essential to actually get the systems to perform well,” Rapp told CyberScoop.”
    • Dark Reading explains how to “Manage Vendor Risk in a Few Practical Steps.”
      • “Risk tolerance, exposure visibility, board oversight — handling third-party risk is complicated but achievable with disciplined, precise governance.”
    • Tech Target highlights “Multifactor authentication: 5 examples and strategic use cases.”
      • “Before implementing MFA, conduct a careful study to determine which security factors offer the strongest protection. Passwords and PINs aren’t cutting it any longer.”
    • Here’s a link to Dark Reading’s CISO Corner.