Cybersecurity Saturday

Cybersecurity Saturday

“”We are in the Singularity.” Elon Musk

From the Project Glasswing front,

  • Cybersecurity Dive reports,
    • “Versions of Anthropic’s Claude AI model broke out of their testing environments and hacked into other organizations on three separate occasions, Anthropic said on Thursday [July 30].
    • The frontier AI lab’s announcement came roughly one week after OpenAI disclosed a similar incident involving its models, a revelation that has set off a new round of consternation about whether AI developers are adequately overseeing their sophisticated AI products.
    • “In the three incidents that Anthropic disclosed, Claude conducted the intrusions while believing that it was participating in a capture-the-flag exercise in which it did not have access to the internet and all available systems were part of the test. “Due to a misunderstanding between us and our evaluation partner,” Anthropic explained in a blog post, “this was not the case, and internet access was available.”
    • “As a result, when Claude encountered the three victim organizations, it believed that they were simulated targets and broke into them using basic attack techniques such as exploiting weak passwords.
  • The article describes the incursions which is worth a click.
  • Cyberscoop adds,
    • “We almost never get both sides of an intrusion. This time we did.
    • “Last month, Hugging Face disclosed a breach into part of its production infrastructure, saying an autonomous AI agent system ran the attack from start to finish. Five days later, OpenAI revealed that its own models, including GPT-5.6 Sol along with an unreleased one, were responsible for the breach. OpenAI called it an unprecedented cyber incident.
    • “Most of the commentary since has been about AI capability. That is the least useful part of the story, because the capability was doing what it was destined to do. Security teams should look at a simpler truth: in both systems, the key defenses sat behind untrusted code that was already running.”
  • Cybersecurity Dive notes,
    • “Businesses are more concerned about AI-fueled threats than traditional cybersecurity dangers, potentially undermining their ability to prepare for the attacks they are most likely to face, researchers at the security firm Arctic Wolf said on Tuesday.
    • “Roughly a third of organizations said AI topped their list of cybersecurity concerns, while concerns about malware, credential theft and cloud misconfigurations dropped from their 2025 numbers, according to Arctic Wolf’s annual AI and cybersecurity trends report.
    • “The report also delved into organizations’ use of AI for their security programs, their reasons for reporting cybersecurity incidents and regional trends in cybersecurity challenges.”
  • and
    • “AI agents remain a major cybersecurity risk for businesses, with 81% of CISOs worrying that their AI systems aren’t properly governed, according to a report Okta published on Wednesday.
    • “Only 47% of companies Okta surveyed said they knew all the AI agents on their networks, and only 46% reported controlling those agents’ access to corporate data.
    • “Okta’s findings highlight a complicated and dangerous environment in which companies aren’t properly balancing the risks and benefits of agentic AI.”
  • Security Week points out,
    • “Anthropic on Friday [July 24] rolled out Claude Opus 5, pitching it as a cheaper alternative to its top-tier Fable 5 model. In terms of cybersecurity, the new model is nearly as good as the AI giant’s most capable system, Mythos 5, at spotting software vulnerabilities, but remains well behind it in turning those findings into working exploits.”
    • “The difference comes from Anthropic’s own OSS-Fuzz-based evaluation, which measures how well a model can locate and then exploit vulnerabilities with minimal human steering. According to the company, Opus 5 identifies vulnerabilities at a rate close to Mythos 5, but its exploit-development score trails considerably. 
    • Anthropic frames this as a deliberate outcome, noting that it has avoided training Opus 5 directly on offensive cyber tasks. The gains it does show, the company says, are a byproduct of broader capability improvements.”
  • Per a July 28, 2026, SonicWall news release,
    • SonicWall today confirmed it is a participant in Anthropic’s Project Glasswing and is testing Claude Mythos 5 for defensive cybersecurity work. Through the initiative, SonicWall is applying the model to vulnerability discovery and code review across its own software to find and remediate security issues before they can be exploited. 
    • Project Glasswing is an Anthropic-led industry effort that gives participating security teams access to Claude Mythos 5, a frontier model not available to the general public, for defensive security research. Anthropic launched the program to help close the gap between attackers using AI to accelerate vulnerability discovery and defenders’ ability to find and fix those same issues first. 
    • “Security vendors are not exempt from the pressure every software maker is under right now,” said Chandro Prasad, SonicWall Chief Product Officer. “Vulnerabilities move from disclosure to exploitation faster than most patch cycles can keep up with. Participating in Project Glasswing gives our security team another way to find and close gaps in our own code before an attacker does. That is the standard we hold ourselves to, and this program is a meaningful way to raise it further.” 

From the cybersecurity policy and law enforcement front,

  • Bleeping Computer reports,
    • “The U.S. and Australian governments have released new guidance urging critical infrastructure organizations to prepare to isolate vital operational technology systems in the event of a cyberattack or other major disruptions.
    • “The guidance, titled “CI Fortify – Advice for isolating vital systems,” was developed by the U.S. Cybersecurity and Infrastructure Security Agency (CISA), the Australian Signals Directorate’s Australian Cyber Security Centre (ACSC), the FBI, and international partners.
    • “It provides recommendations for disconnecting critical operational technology (OT) and associated systems from corporate, Internet-facing, and other less-trusted networks while continuing to provide essential services for an extended period.”
  • Cyberscoop relates
    • “The Cybersecurity and Infrastructure Security Agency published a guidebook for federal agencies Thursday to aid them on managing security risks with open-source software, touching on topics like patching and open-source AI models.
    • “An executive order President Joe Biden signed and that President Donald Trump amended ordered CISA and other agencies to issue open-source security recommendations to federal agencies. But the guidance is also timely, given a recent slew of attacks on open-source software (OSS).
    • “As part of our statutory mission, CISA remains laser-focused on enhancing the nation’s cybersecurity by collaborating with government, industry and the open-source community to understand and securely use OSS,” said Chris Butera, acting executive assistant director for cybersecurity. “CISA encourages federal civilian agencies to review this guide and implement the principles and practices to improve risk management, better execute their mission, and better serve the public.” 
    • “The document, “Open Source Software: Security Principles and Practices,” touts the advantages of open-source software — which anyone can use, modify and share — as offering benefits in efficiency, cost, security transparency and more, but notes that it also has unique tradeoffs.”
    • “All software carries risk, and OSS is no more or less risky than other software. The key distinction is that, with OSS, agencies can directly assess code quality and security, rather than relying solely on vendor assurances,” the guidance reads. “OSS is increasingly intertwined with emerging technologies such as artificial intelligence. Agencies that adapt to OSS’s unique characteristics will position themselves to meet future challenges and leverage new innovations.”
  • Dark Reading tells us,
    • “A gaggle of government partners from around the world has released new guidelines for the minimum elements that organizations should include in a software bill of materials (SBOM).
    • The document, published this week, was authored by the US Cybersecurity and Infrastructure Security Agency (CISA) and 16 other government entities spread across four continents. It supersedes the National Telecommunications and Information Administration’s (NTIA) 2021 guidelines, which laid out what an SBOM had to contain as far as the US government was concerned. This updated version was first drafted in 2025, and was then informed by suggestions from 90 commenters, including major organizations like Google, Microsoft, and Amazon Web Services (AWS) to create the resulting document.
    • An SBOM is essentially an “ingredients list,” detailing the building blocks and supply chains that make up a given piece of software. This could include proprietary or open source software components, APIs, utilities, and more. As a risk management tool, it aims to provide visibility into where vulnerabilities exist in a software stack and how to prioritize patching, among other things.
    • “There’s nothing revolutionary in this latest spruced-up framework, which follows SBOM policy revisions earlier this year, but it introduces 10 new data fields, and a dozen or so updates to existing elements, which range from major to minor significance. Though the changes might be directionally positive, Jeff Williams, founder of OWASP and founder and CTO of Contrast Security, argues that these minor procedural changes miss the bigger picture.”
  • Per a Health and Human Services Department news release,
    • “The U.S. Department of Health and Human Services (HHS), Office for Civil Rights (OCR) today announced a settlement with OSF Healthcare System and its Affiliated Covered Entities (OSF), concerning potential violations of the Health Insurance Portability and Accountability Act of 1996 (HIPAA) Privacy, Security, and Breach Notification Rules. OSF is headquartered in Illinois and has providers located in Illinois and Michigan.
    • “An accurate and thorough HIPAA risk analysis is not only required by law, but it is also necessary to protect health information and prevent or mitigate ransomware attacks,” said OCR Director Paula M. Stannard. “If a HIPAA regulated entity doesn’t know what threats and vulnerabilities exist to its electronic protected health information (ePHI), they will often learn the hard way when their systems are hacked.” * * *
    • “The settlement resolves an investigation that OCR initiated after OSF filed a breach report in October 2021. In April of 2021, OSF discovered that its files had been infected with the “Nephilim” variant of ransomware. The PHI of 53,907 individuals was exfiltrated by the threat actor. Affected PHI included driver’s license numbers, diagnosis and treatment information, prescription information, medical record numbers, provider names, dates of services, financial account information, and health insurance information.” * * *
    • “Under the terms of the resolution agreement, OSF agreed to implement a corrective action plan that OCR will monitor for two years and paid $552,250 to OCR. Under the corrective action plan, OSF has committed to taking steps to ensure compliance with the HIPAA Rules and protect the security of ePHI, including:
      • “Conduct an accurate and thorough risk analysis to determine the potential risks and vulnerabilities to the confidentiality, integrity, and availability of its ePHI; and
      • “Develop and implement a risk management plan to address and mitigate security risks and vulnerabilities identified in its risk analysis.
    • “Read the resolution agreement and corrective action plan.”

From the cybersecurity breaches and vulnerabilities front,

  • Dark Reading reports,
    • “A coordinated cyberattack targeting more than 30 community water systems in Minnesota this week underscored the growing threat to often poorly protected operational technology (OT) from adversaries seeking to disrupt critical infrastructure services across the US.
    • “The attacks, which US government officials have reportedly attributed to Iran, disrupted automated systems in some Minnesota communities, forcing them to switch to manual operations for brief periods. However, the attacks don’t appear to have affected water supply, water safety, or wastewater services in a major way, based on public statements by community officials and Minnesota’s IT Services (MNIT) unit.” * * *
    • In an advisory Thursday [July 30], the FBI described the attacks as broader and impacting water and wastewater systems in at least seven states with some of the attacks degrading water operations. The FBI advisory said attackers were targeting OT devices including Rockwell Automation/Allen-Bradley PLCs, specifically MicroLogix 1100 and 1400 series devices. “After remotely accessing internet-facing devices, the actors changed the IP addresses and passwords, resulting in a loss of monitoring and control functionality,” the FBI said. It recommended that affected organizations remove PLCs “from direct Internet exposure via secure gateway and firewalls, setting up strong, unique passwords, and utilizing access control list (ACL) to allow only authorized communication between expected control system devices.”
  • Bleeping Computer adds,
    • “Pharmaceutical company Amgen says it suffered a data breach after threat actors stole corporate data and patient information stored in multiple cloud systems operated by third-party service providers.
    • “Amgen is a California-based biotechnology company that develops and manufactures medicines for serious illnesses, including cancer, cardiovascular disease, inflammation, and rare diseases.
    • “The company said it detected the unauthorized activity in July 2026 and responded by activating its cybersecurity response plan, implementing containment measures, and hiring independent forensic experts to investigate the incident.
    • “The investigation found that the attackers stole sensitive data from the cloud environments.
    • “The Company has since learned that some of its data, including proprietary data, patient protected health information, and other information, has been exfiltrated from these cloud environments,” Amgen said in a Form 8-K filing with the SEC.”
  • Cyberscoop tells us,
    • “Huntress researchers spotted an active and ongoing series of attacks targeting SonicWall VPN and firewall accounts, which compromised 30 organizations in less than two days, the company said in a threat advisory Tuesday [July 28].
    • The credential stuffing campaign started Saturday and grew rapidly, ultimately compromising 92 unique user accounts during the next 41 hours, according to Huntress. Researchers said the attacks were broad and opportunistic, hitting various SonicWall devices, rather than targeting specific types of organizations.
    • SonicWall hasn’t released a security advisory about the malicious activity as of press time. A spokesperson told CyberScoop the company is still investigating and hopes to have more information soon.
    • The attacks ended — at least for now — as abruptly as they began. The last compromise occurred Monday, according to Michael Tigges, principal tactical response analyst at Huntress.
  • Bleeping Computer informs us,
    • “Hackers are actively exploiting a vulnerability in the FastJson open-source Java library, allowing remote code execution without user interaction or elevated privileges.
    • “The security issue affects FastJson versions 1.2.68 through 1.2.83 and is leveraged in attacks targeting various organizations in the U.S.
    • “The malicious activity was observed last week by the agentic security company ThreatBook, and researchers at the business protection company Imperva confirmed that it was “targeting a wide range of organizations, across Financial Services, Healthcare, Computing, Retail, Business, and other industries.” * * *
    • “FastJson is an open-source Java library developed by Alibaba, used for serializing Java objects to JSON, and vice versa.” * * *
    • “In its security bulletin, Alibaba confirmed the critical severity of the vulnerability and warned that it is exploitable on “the most common Spring Boot deployment model.”
  • CISA added three known exploited vulnerabilities to its catalog this week.
    • July 27, 2026
      • CVE-2025-68686 Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability
      • CVE-2026-16812 Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability
        • Cybersecurity News discusses the Fortinet KVE here.
        • Arista discusses its KVE here.
    • July 29, 2026
      • 2026-20316. Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability
        • Cybersecurity News discusses this KVE here.
  • Bleeping Computer notes,
    • “Broadcom has released security updates to fix five vulnerabilities in VMware vCenter, ESX, Workstation, and Fusion, including three critical flaws that allow attackers to bypass authentication, execute arbitrary code, or escape from a virtual machine to the host.
    • “The vulnerabilities also affect products containing vCenter or ESX, including VMware Cloud Foundation, VMware vSphere Foundation, VMware Telco Cloud Platform, and VMware Telco Cloud Infrastructure.
    • “Broadcom says organizations running versions released before those listed as fixed in its advisory should assume they are vulnerable and take immediate action.”
  • Dark Reading adds,
    • “A maximum-severity vulnerability in the open source AI agent platform Ruflo puts enterprise AI deployments at risk by letting attackers conduct various malicious activities from inside the orchestration framework. The flaw also can leave agents behaviorally compromised even after it’s been patched.
    • “Researchers at Noma Security’s Noma Labs discovered the flaw, tracked as CVE-2026-59726, in Ruflo, formerly called Claude Flow and which hosts AI agent swarms for Codex and Claude Code, they revealed today. The vulnerability, which received the highest CVSS severity score of 10, allowed them to access the platform without logging in at all, according to Noma Labs.”
    • “The weakness is a lack of authentication coupled with command execution capabilities, enabling complete control over the container and exposure of sensitive credentials,” according to details about the flaw posted on OpenCVE.”
  • ZDNet notes,
    • “Forty-three percent of organizations have experienced AI-enhanced or AI-generated phishing attacks, and 37% have encountered AI-augmented malware, according to a new survey. 
    • “CDW’s 2026 Security Research Report is based on a survey of 951 IT decision-makers across a variety of industries. Published Monday, the research reveals what appears to be an AI arms race between cyberattackers and defenders. Many organizations are considering investing in AI threat detection, training, and controls to combat the new face of modern cyber threats: AI techniques, tactics, and technologies.” 

From the ransomware front,

  • Inc.com reports,
    • “The hackers behind the Fairlife ransomware attack have identified themselves, and experts are sounding the alarm. 
    • “A hacking group known as Anubis has claimed responsibility for the ransomware attack that hit Fairlife, Coca-Cola’s dairy products unit, saying it locked the company’s servers and stole about one terabyte of confidential data.
    • “Coca-Cola first confirmed the attack on July 17, noting that the incident had affected Fairlife’s production systems and forced a temporary suspension of its U.S. operations. At the time, the company said it expected the disruption to continue for the foreseeable future. It said that there was no impact on the safety or quality of its products.
    • “Upon revealing its identity, Anubis threatened to leak the stolen data unless Fairlife paid a ransom. Despite that, Coca-Cola announced this week that much of production had resumed. The company did not disclose how it managed to restore operations or share any details about how the hackers initially gained access to Fairlife’s systems. Coca-Cola has not disclosed whether it paid the ransom.
    • Zach Lewis, chief information officer and chief information security officer at a private higher education institution, told Inc. that this was a case of double extortion: Attackers encrypt a company’s systems and demand payment for a decryption key, and then come back with a second demand, threatening to leak stolen data unless they’re paid again.
    • He described the process as an oddly formal one, with negotiations often playing out through dedicated portals set up by the hackers themselves. “It’s really bizarre working with these criminals who are running a really good support site to navigate through this negotiation,” he said. “They want the transaction to be successful, because if they don’t hold up their end of the bargain, they don’t get that good reputation, and when they go to hit someone else, they won’t get paid either.”
  • Health Exec relates,
    • “A 2025 data breach on a medical billing company, first revealed in late June, exposed sensitive protected health data on 1.3 million people to hackers.
    • “In an announcement, Medical Computer Business Services (MCBS) said the September 2025 incident stemmed from an unauthorized third party gaining access to its network, though it revealed few details about the nature of the attack, saying online that personal information on individuals stored on its network may have been “accessed or removed.”
    • “Soon after, an updated filing with the U.S. Department of Health and Human Services’ Office of Civil Rights Healthcare Data Breach Tracker showed the official number of victims, meaning that hackers at the very least accessed files on 1,261,464 patients.
    • “The company did not confirm that files were moved offsite. However, BleepingComputer reports—complete with a screenshot from the dark web—that a data trove from the incident is available online, with a ransomware group called PEAR (Pure Extraction and Ransom) taking credit. 
    • “The data is available for download, which typically means a ransom wasn’t paid. 
    • “The trove was discovered by researchers at the outlet sometime this week.” 
  • Bleeping Computer tells us,
    • “Health-ISAC, a cybersecurity information-sharing organization for the health sector, is warning healthcare and medical technology organizations of an observed increase in successful attacks by ShinyHunters.
    • “ShinyHunters is an extortion gang that primarily conducts supply chain and identity attacks to breach cloud SaaS and storage platforms in data theft attacks,
    • “Over the past two years, the threat actors have become notorious for conducting numerous supply chain attacks on third-party integration partners. These breaches give them access to OAuth tokens that are used to integrate with SaaS providers like Salesforce and Snowflake.
    • “The threat actors are known for identity attacks, where they target employees through social engineering, including vishing and phishing, to compromise corporate single-sign-on accounts. Once they gain access to an account, they log in to an organization’s Okta, Microsoft Entra, or Google SSO dashboard, which acts as a centralized hub listing all SaaS applications the user has permission to access.” * * *
    • “Health-ISAC says the most important defensive step is breaking the attack chain between the initial vishing call and the takeover of an SSO account.
    • “Organizations are advised to require out-of-band identity verification for password resets, MFA resets, and device re-enrollment requests.
    • “This can include calling users back using a previously verified phone number and requiring manager approval for privileged accounts.”
  • Cybersecurity Dive adds,
    • “Dozens of North American companies have been targeted in a social engineering campaign that abuses Microsoft Teams to deploy ransomware, according to a report by cybersecurity firm Sophos.
    • “A threat group, tracked as STAC4749, has initiated chats or calls through Microsoft Teams under the guise of providing help desk or IT support to companies in the U.S. and Canada. 
    • “After initiating a remote session through Microsoft Quick Assist or the cloud-based RemSupp tool, hackers deploy PowerShell in order to establish persistence and execute malicious payloads.” * * *
    • “In at least three cases, the hackers deployed Chaos ransomware on a compromised system. Researchers said in one of the cases, the time between initial access to deployment of ransomware was 17 hours, which is consistent with prior Chaos cases. 
    • “The observed attacks ran between February and June, targeting organizations in the services, manufacturing, energy, construction and engineering sectors.” 
  • Cybersecurity News informs us,
    • “The Gentlemen ransomware operation is drawing attention for its aggressive effort to disable security software before locking files. Instead of relying only on fast encryption, the attackers attempt to remove the tools that could detect, block, or contain the attack.
    • “This approach raises the risk for businesses because antivirus and endpoint monitoring tools may be silenced when they are needed most. 
    • “The campaign’s exact initial access method was not detailed, but the activity shows attackers preparing systems for encryption after obtaining a foothold.
    • “Catalyst analysts identified the malware component as anticheatG13.sys, a kernel-level driver with broad capabilities for manipulating processes, networking, files, and system memory.”
  • Per Dark Trace,
    • “Darktrace detected a multi-stage ransomware intrusion from its earliest stages, identifying reconnaissance, privilege escalation, lateral movement, command-and-control communications, and data exfiltration before encryption occurred. This analysis highlights how behavioral detection exposed attacker activity using legitimate tools and infrastructure, providing multiple opportunities for early intervention and containment. “

From the cybersecurity business and defenses front,

  • Security Week reports,
    • “Nvidia and a large group of technology, cybersecurity, and enterprise software companies announced on Monday the launch of the Open Secure AI Alliance, a new initiative aimed at developing and sharing open source tools, models, and techniques for securing AI systems and agents. 
    • “The effort builds on existing work from the Linux Foundation’s recently launched Akrites initiative and the OpenSSF community.
    • “Inaugural partners of the Open Secure AI Alliance also include Adobe, Cadence, Capital One, Cisco, Cloudera, Cloudflare, Cognition, CrowdStrike, Databricks, Dell, DoorDash, Elastic, HPE, Hugging Face, IBM, LangChain, Microsoft, Naver, NetApp, Nous Research, OpenClaw, Palantir, Palo Alto Networks, Red Hat, Reflection AI, Salesforce, SAP, SK Telecom, ServiceNow, Siemens, Snowflake, SpaceXAI, Synopsys, Thinking Machines Lab, and TrendAI.”
  • Cybersecurity Dive adds,
    • “Microsoft on Monday announced the launch of Project Perception, an agentic security system designed to help defenders combat a rapidly evolving threat of AI-based attacks by malicious actors. 
    • “The company also introduced MAI-Cyber-1-Flash, an AI model that helps users identify and remediate vulnerabilities through an integration with the company’s MDASH code-scanning harness. 
    • “The launch is part of a major industry push to implement AI-based security that can protect corporate IT and critical infrastructure systems from sophisticated attacks. In the past year, threat actors have demonstrated the ability to speed and scale attacks in a way that traditional security technologies cannot match.” 
  • Forresters offers its take on how Project Perception should be implemented.
  • The Wall Street Journal reports,’
    • “Data-security company Cyera has agreed to acquire startup Oasis Security for $1 billion, the latest large deal in a wave of consolidation across the cybersecurity industry fueled by artificial intelligence.
    • “The cash-and-stock acquisition would help Cyera bridge its data-protection platform with Oasis’s technology for managing nonhuman identities, such as AI agents and automated software, as companies grapple with the risks of deploying autonomous tools across their businesses. The companies expect the deal to close later this year.
    • “The biggest catalyst for this acquisition is the customers,” said Yotam Segev, Cyera’s chief executive, who co-founded the company in 2021. “Our customers, and especially our shared customers, have been telling us that these capabilities belong together.”
    • “The transaction between the two New York-based companies is among the largest cybersecurity acquisitions of the year, underscoring how AI is reshaping the industry.”
  • Cyberscoop adds,
    • “Okta announced Thursday it has signed a deal to buy Permiso Security, a cloud-based firm that tracks threats tied to human, machine, and AI-driven digital identities. 
    • “Permiso specializes in spotting risks after a user or system has already logged in, an area the industry refers to as identity threat detection and response. The company draws on more than 2,500 signals gathered from over 70 identity-related partners to flag issues such as excessive access permissions, unused credentials, unusual behavior from AI agents, and violations of internal security policies.
    • “Ely Kahn, Okta’s chief product officer, told CyberScoop that Permiso will allow Okta to merge two functions that have operated separately: real-time threat detection and identity security posture management. “Today those are two separate products that don’t really talk to each other,” he said.” 
  • The American Hospital Association offers “Lessons Learned from Conversations with the FBI: Healthcare Cyberthreats and Best-practice Defense.”
  • The Health Sector Coordinating Council provides a summary recap of the Operation Vital Signs National Cybersecurity Exercise which took place on July 21 an 22, 2026.
  • The HIPAA Journal shares its HIPAA Audit Checklist.
  • Tech Target gives us a CISO’s guide to privileged identity management.
  • SC Media explains why “effective incident response plans elusive for most cybersecurity teams.”
  • Here is a link to Dark Reading’s CISO Corner.

Cybersecurity Saturday

“”We are in the Singularity.” Elon Musk

From the War with Iran front.

  • The American Hospital Association News tells us
    • “The Cybersecurity and Infrastructure Security Agency and other U.S. and international partners July 22 released an updated advisory on Iranian-affiliated cyber actors targeting internet-connected programmable logic controllers, which are computers used to manage and monitor equipment. PLCs can be found in climate control systems, access control systems and many other applications in healthcare. Agencies first warned of malicious activity targeting Rockwell Automation PLCs in April. The updated advisory expands the scope of incidents to include observed targeting of Schneider Electric, Siemens and potentially other manufacturers of PLCs. It also includes new guidance on detecting malicious changes in reusable code modules exploited within Rockwell Automation PLC programs.”

From the Project Glasswing / the Singularity front,

  • Cybersecurity Dive reports on July 22,
    • “Two OpenAI large language models, including one not yet released to the public, broke free of their constraints last week and autonomously hacked into the AI application library Hugging Face.
    • “The first-of-its-kind event, in which the LLMs tried to steal information that would help them excel on an important test, has highlighted the dangers of the AI industry’s increasingly powerful tools.
    • “We consider this incident to be an unprecedented cyber incident, involving state-of-the-art cyber capabilities, and are responding accordingly,” OpenAI said in a blog post on Tuesday that confirmed its models’ responsibility for the attack, which Hugging Face announced on July 16.”
  • AI Strategist David Borish, writing in LinkedIn, lets us know,
    • “On July 21, Elon Musk quote a message from OpenAI researcher Will Depue that laid out a timeline: a security incident at Hugging Face on July 21, a counterexample to the Jacobian conjecture on July 20, the disproof of Erdős’s unit distance conjecture on May 20, the solution to Erdős problem 1196 on April 14, and Anthropic’s Project Glasswing finding thousands of zero day vulnerabilities on April 7. Depue’s post noted that in “normal” times, these milestones would have been spread across months or years. Compressed into a single week of news cycles, they read differently. Musk’s reply ran five words: “We are in the Singularity.”
    • “The claim landed hard because, unlike most Singularity talk, this timeline is not speculative. Each item is a documented event with a paper trail, and the details matter more than the framing.” * * *
    • “The skeptical case. Grocery prices, commute times, and most people’s jobs look the same this week as they did a month ago. Every event on Depue’s timeline required a human to set up the evaluation, pose the conjecture, or prompt the model, and in most cases required teams of human experts to verify, formalize, or clean up afterward. Deep learning researcher Yann LeCun has argued current architectures will not reach general intelligence without a different approach entirely. Writer Freddie deBoer has made the broader point that a self-improving AI escaping human oversight remains a speculative scenario without a demonstrated mechanism, distinct from AI systems getting better at specific tasks people assign them.
    • “Both things can be true at once. The rate of capability progress across math, security research, and coding is genuinely compressing what used to take years into weeks, and the humans setting the objectives, verifying the outputs, and deciding what gets deployed have not gone anywhere. The more telling test ahead is quieter than another isolated proof or another leaderboard topper: whether formal verification, in Lean or otherwise, keeps pace with the rate of claims, and whether the containment failures at Hugging Face turn out to be a one time embarrassment or the first entry in a longer list.”
  • TechTimes adds,
    • “Microsoft is preparing to launch Project Perception, an AI-powered security platform that scans enterprise codebases for exploitable vulnerabilities — and is built around a deliberate cost-and-access argument against Anthropic’s Claude Mythos Preview, the most capable vulnerability-hunting AI available and one that most organizations on Earth cannot currently use.
    • “The platform is expected to debut before the end of July. It routes security analysis tasks across AI models from Microsoft, OpenAI, and Anthropic, using a model-selection layer that reserves expensive frontier model calls for the steps where they create real value and assigns cheaper, distilled models to high-volume scan passes. That architecture, according to reporting first published by The Information, is designed to bring the cost of running continuous, enterprise-grade vulnerability discovery well below what Anthropic charges for direct Mythos access.”

From the cybersecurity policy front,

  • Federal News Network reports,
    • “The unprecedented breach of a technology vendor by autonomous artificial intelligence agents is serving to underscore governmentwide efforts to streamline federal cloud security and prioritize faster patching of critical software vulnerabilities.
    • “OpenAI confirmed this week that its advanced AI training models broke out of their test environment and then hacked into the networks of start-up vendor Hugging Face. The incident is the latest AI cybersecurity development driving policy conversations across Washington.
    • “Pete Waterman, director of the Federal Risk and Authorization Management Program (FedRAMP) at the General Services Administration, pointed to the Hugging Face incident as a landmark moment for cybersecurity during Carahsoft’s FedRAMP Summit on Thursday.
    • “Waterman said the incident underscores his program’s shift to the FedRAMP 20x model.”
  • Cyberscoop relates,
    • “Industry groups who spoke at town halls hosted by the Cybersecurity and Infrastructure Security Agency [(CISA)] about a pending cyber incident notification regulation had a few consistent messages:
    • “We want this to apply to fewer of us. We don’t want to report to you on as many incidents. We want to give you less information when we do. 
    • “CISA last week published transcripts from the town halls, where the agency sought feedback on the delayed rule for the 2022 Cyber Incident Reporting for Critical Infrastructure Act — perhaps the most significant cyber legislation Congress has ever passed. That law required critical infrastructure owners to report major cyberattacks to the federal government within 72 hours, and ransomware payments within 24 hours.” * * *
    • “Where the rule specifies what kind of data organizations should report in a major incident, CISA should “seek to collect the least amount of information possible in the easiest to report fashion to facilitate information accuracy and reporting speed,” said Samantha Burch, vice president of technology public policy at government affairs at AHIP, a health insurance industry trade association.” * * *
    • “One industry representative told CyberScoop that CISA’s willingness to hold town halls, combined with the Trump administration strategy emphasizing “common sense regulation,” was a good sign about where the rule might be heading.
    • ‘They are not picking up on the Biden administration’s approach and tweaking it. They’re thinking, ‘What are the specific pieces of information we need during a cyber incident to help critical infrastructure companies respond?’” said Henry Young, senior director of policy for the Business Software Alliance. “In general, industry is optimistic that what we’ll end up with are a few of the most important pieces of information, so that in the emergency, companies can act quickly and actually respond to an incident rather than completing lots of paperwork.”
  • and
    • “Seven out of 10 federal cyber regulations requiring written reports to federal agencies are duplicated elsewhere, a report from a government watchdog found in a report to Congress Wednesday.
    • “And so far, efforts to de-conflict haven’t had much success, the report from the Government Accountability Office concluded.
    • “At the request of two top lawmakers, the GAO examined federal cyber regulations at 37 agencies. It counted 80 out of 117 rules that “either contain the same kind of reporting requirement applicable to a sector or the same reporting requirement as at least one other regulation.”
    • “The desire to harmonize those conflicting rules gathered steam under the Biden administration, as it undertook a more aggressive push to regulate cybersecurity than prior administrations. It has continued into the second Trump administration.”

From the cybersecurity breaches and vulnerabilities front,

  • HIPAA Journal reports,
    • “There has been a general trend of increasing data breaches over the past decade, with this year on track to set a new record. According to the H1 2026 Data Breach Report from the Identity Theft Resource Center (ITRC), there have been at least 1,803 data compromises in H1 2026, which will give an annual total of more than 3,600 data compromises if they continue to occur at a similar rate as the first half of the year.
    • “Across those data compromises, there have been 1,394 confirmed data breaches (excluding leaks, exposures, and unknown incidents), accounting for 77% of total events. More than 471 million victim notices have been issued, which already exceeds the total number of victim notices for all of 2025, and there are still six months of the year to go. While at the current rate, this year is unlikely to beat the total for 2024, even with only 6 months of data, 2026 already ranks as one of the worst years to date.
    • “As ITRC explains in the report, part of the reason is the return of mega data breaches, the biggest of which involved the Instructure Holdings’ Canvas platform, which accounted for an estimated 275 million notices. A mega data breach at Under Armour involved more than 72.7 million notices, while the SoundCloud data breach saw 29.8 million victim notices issued.
    • “There were no healthcare data breaches in the top 10 data compromise list, in contrast to H1, 2025, when three healthcare data breaches made it into the top 5. In fact, based on breach reporting to the HHS’ Office for Civil Rights, there have been relatively few mega data breaches in healthcare. In H1 2026, only 7 healthcare data breaches required more than 1 million notices.”
  • Dark Reading relates,
    • “Russian state-backed threat actors are compromising networks of Western governments and enterprises through the Zimbra Collaboration Suite (ZCS), according to intelligence and cybersecurity agencies in more than a dozen countries.
    • “In a joint advisory Thursday, the US government and several allied nations warned that an advanced persistent threat (APT) dubbed “Laundry Bear” has been targeting ZCS customers since July 2025. Laundry Bear actors used a zero-day vulnerability in ZCS, tracked as CVE-2025-66376, in a phishing campaign that featured what experts describe as a “half-click exploit” to breach Zimbra webmail servers.
    • “Unlike traditional phishing campaigns that persuade a user into taking an action, such as clicking a link or opening a file, Laundry Bear’s latest campaign leverages a view-based exploit that only requires a user to view a malicious email within a vulnerable version of the webmail service,” the agencies said in the advisory.
    • The campaign is designed “almost certainly to gather sensitive information for the Russian Federation,” according the advisory. The Laundry Bear attacks mark yet another threat from Russian APTs against US organizations.
  • Cybersecurity Dive tells us,
    • “A critical vulnerability in Check Point Software’s SmartConsole login process is being exploited, with a small number of customers already impacted, according to a security advisory released Wednesday from the company. 
    • “The authentication bypass flaw, tracked as CVE-2026-16232, allows an attacker to gain full administrative privileges after they access an application login token. An attacker can then make changes to security policy and configurations. The vulnerability has a severity score of 9.1 out of 10. 
    • Check Point on Wednesday released a jumbo hotfix to address several security issues in its firewall and management products, according to the advisory.
    • A vulnerability of this type is particularly concerning, giving an attacker the ability to make a number of changes, according to a blog post released Thursday by Rapid7. A remote hacker can “alter administrator permissions, manipulate VPN configurations, and potentially disable or tamper with logging and monitoring,” Rapid7 said. 
  • and
    • “A critical-severity deserialization vulnerability in Microsoft SharePoint is now under exploitation, according to security researchers at watchTowr and Defused
    • “The flaw, tracked as CVE-2026-50522, has a severity rating of 9.8 out of 10 and could enable an attacker to execute remote code over a network. 
    • “Hackers are targeting on-premises SharePoint server environments following the release of new exploit code, watchTowr researchers said in a LinkedIn post. Researchers warned that attackers are stealing machine keys to maintain long-term access.”
  • CISA added six known exploited vulnerabilities to its catalog this week.
    • July 21, 2026
      • CVE-2021-27137 DD-WRT Stack-Based Buffer Overflow Vulnerability
      • CVE-2026-0770 Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability  
      • CVE-2026-63030 WordPress Core Interpretation Conflict Vulnerability  
      • CVE-2026-60137 WordPress Core SQL Injection Vulnerability
        • Security Affairs discusses these KVEs here.
    • July 22, 2026
      • CVE-2026-16232 Check Point SmartConsole Improper Authentication Vulnerability
        • The Hacker News discusses this KVE here.
      • CVE-2026-50522 Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
        • Cybersecurity Dive discusses this KVE here.
  • Cyberscoop adds,
    • “Malware targeting AI coding assistants and software developers’ automated workflows is spreading into more environments with more capabilities, placing defenders at a growing disadvantage.
    • “A malware strain dubbed Sandworm_Mode, first discovered by Socket in February, represents a growing threat to software development. According to a CrowdStrike report, the self-propagating worm can spread through code repositories with minimal detection, raising alarms about software supply chains.
    • “The malware’s capabilities are extensive, but not especially unique compared to the series of supply-chain worms known as Shai-Hulud, and more recently Mini Shai-Hulud.
    • “This is the new trend,” Adam Meyers, senior vice president of counter adversary operations at CrowdStrike, told CyberScoop. “This is something we’re seeing more and more. It’s the new hotness right now.”

From the ransomware front,

  • Cybersecurity Dive reports,
    • “A threat group called Anubis claimed credit for the ransomware attack against Fairlife, the dairy products unit of Coca-Cola. 
    • “The group says it locked the servers at Fairlife and obtained 1TB of data from the attack, according to researchers at Arctic Wolf. Anubis is threatening to leak information if its demands are not met within a week. Researchers provided screenshots posted on the group’s data leak site
    • “Coca-Cola was forced to suspend U.S. production at Fairlife while it launched an investigation into the attack. Coca-Cola officials noted there was no impact on the safety or quality of its dairy products.” “
  • Dark Reading relates,
    • “Ransomware is not just growing, it is actually accelerating, with activity surging between October 2025 and March 2026, as more than 60 new groups entered an increasingly crowded criminal ecosystem.
    • “For enterprises, the surge means not only more attacks but also a larger and constantly changing pool of adversaries to track and defend against.
    • Black Kite analyzed ransomware incidents between April 1, 2025, and March 31, 2026, and identified 7,551 known victims worldwide. That represented a 25% increase over the previous 12-month period, with much of the growth concentrated in the second half of the year. Black Kite counted 2,904 victims between April and September 2025 and 4,647 between October 2025 and March 2026, marking a 60% increase in reported ransomware victims. March 2026 was the busiest month with as many as 861 organizations — or nearly 28 per day — falling victim to a ransomware attack.
    • “This isn’t a problem we’ve contained,” says Ferhat Dikbiyik, chief research and intelligence officer at Black Kite. “It’s still a lucrative business, and the barrier to running one keeps getting lower.”
  • The Hacker News tells us,
    • “Threat actors have been observed exploiting a now-patched high-severity Palo Alto Networks PAN-OS vulnerability as an entry point to deploy Qilin (aka Agenda) ransomware on victim environments.
    • Arctic Wolf Labs said it investigated multiple intrusions in June 2026 that began with the exploitation of CVE-2026-0257 (CVSS score: 7.8), an authentication bypass flaw affecting the portal and gateway components of PAN-OS software.
    • Successful exploitation of the flaw allows unauthenticated remote attackers to sidestep authentication and establish VPN sessions without valid credentials when authentication override cookies are enabled with specific certificate configurations.
    • “Post-exploitation tradecraft varied across intrusions, from rapid encryption-only operations to full double-extortion, possibly suggesting multiple affiliates operating under the Qilin ransomware-as-a-service (RaaS) umbrella,” the cybersecurity company said.
  • Bleeping Computer points out,
    • “The Clop ransomware gang (also tracked as Cl0p) is targeting Internet-exposed PTC Windchill and FlexPLM instances in a new data theft extortion campaign.
    • “Clop has reportedly been exploiting a critical improper input validation vulnerability tracked as CVE-2026-12569, which allows attackers to execute arbitrary code on vulnerable Windchill and FlexPLM instances.
    • “As cybersecurity company ReliaQuest reported on Thursday, Clop operators have been deploying JSP webshells that allow them to exfiltrate sensitive data from targeted companies’ compromised PLM platforms.
    • “ReliaQuest has observed threat actors actively exploiting CVE-2026-12569, a critical unsafe deserialization vulnerability (CVSS 9.3) affecting PTC Windchill and FlexPLM. Exploitation enables unauthenticated remote code execution and JSP web shell deployment for remote command execution and sensitive product data exfiltration,” the company said.”
  • Per Cisco Talos,
    • “Cisco Talos has discovered a new Rust-based remote access trojan (RAT) we call “msaRAT” attributed to the Chaos ransomware group. The name is derived from the binding names found in the binary: “msaOpen,” “msaClose,” “msaError,” and “msaMessage”.
    • “msaRAT is implemented using the Tokio asynchronous runtime, with primary capabilities of browser-leveraged remote code execution and covert tunneling to establish command-and-control (C2) communications.
    • “This RAT never touches the network directly — it controls its C2 communication channel exclusively through Chrome DevTools Protocol (CDP), a browser debugging API. The binary contains a Cloudflare Workers endpoint, but it never makes HTTP connections to that domain itself; it offloads that work entirely to the browser.
    • “msaRAT manipulates the browser via CDP, performs signaling (SDP Offer/Answer exchange) with Cloudflare Workers, and establishes a WebRTC DataChannel between the browser and the C2 server using Twilio TURN (Traversal Using Relays around NAT) as a relay.”

From the cybersecurity business and defenses front,

  • The Wall Street Journal reports,
    • “The Defense Department signed an up to 10-year, near $7 billion contract with Oracle intended to streamline fragmented licensing and intra-agency efficiency.
    • “The Austin-based cloud computing and software company separately maintained different contracts across the agency. The government said the deal will optimize services and deliver hundreds of millions of dollars in taxpayer savings.”
  • TechCrunch relates,
    • Glow, a cybersecurity startup founded by former Meta and Snowflake executives, emerged from stealth as a unicorn, betting that artificial intelligence is reshaping how enterprises secure employee devices.
    • “The Palo Alto-headquartered startup on Wednesday said it raised $180 million in an all-equity Series A funding round that valued it at $1.2 billion, with backing from Sequoia Capital, Cyberstarts, Greenoaks, and Redpoint Ventures, alongside participation from Index Ventures, Swish Ventures, Lux Capital, Operator Collective, and Holly Ventures. The investment made Glow one of the latest cybersecurity startups to achieve unicorn status before publicly disclosing revenue metrics.”
  • Cybersecurity Dive relates,
    • “Many ransomware victims remain vulnerable to follow-up cyberattacks, even after they complete their incident response processes, highlighting gaps in mitigation activities that increase their odds of becoming repeat targets, the security firm Black Kite said on Tuesday in its annual ransomware report.
    • “The report described how victims fail to patch critical vulnerabilities and properly configure email security tools, underscoring the importance of thorough digital cleanup operations as part of the ransomware recovery period.” * * *
    • “Black Kite also shared fresh data on the ransomware ecosystem and its top targets.”
    • Because ransomware is a profit-motivated business, cybercriminals prioritize the easiest and most lucrative targets, and if an organization fails to fix the problems that opened the door for hackers in the first place, they are likely to return. That fact makes it imperative for hacked businesses to fix digital liabilities as soon as possible after an incident, lest hackers revictimize them seeking another payout.
  • MSN adds, “The next cyber arms race isn’t about finding bugs. It’s about fixing them first.”
  • Here is a link to Dark Reading’s CISO Corner.

Cybersecurity Saturday

From the War with Iran front,

  • Cybersecurity Dive reports,
    • “Threat actors linked to Iran are using artificial intelligence to enhance their cyber and information warfare capabilities, putting the U.S. and its allies at higher risk of asymmetric attack, according to a report released Thursday by Recorded Future. 
    • “Iran-nexus actors have used generative AI and large language models in a range of activities, including the development of malware, conducting research on industrial control systems, exploiting software vulnerabilities and other uses. 
    • “There are no indications yet that Iran has developed fully autonomous models, but the country is clearly using AI to accelerate its existing capabilities. 
    • “AI has not transformed Iran into a fundamentally different cyber power, but it has compressed the distance between intent and action,” Alexander Leslie, senior advisor at Recorded Future, told Cybersecurity Dive.” 

From the Project Glasswing front.

  • CRN reports,
    • “Microsoft’s unprecedented July security update—which potentially includes patches for more than 600 vulnerabilities—is confirmation that ultra-powerful AI models for discovering software flaws are already starting to signal massively bigger challenges in vulnerability management, according to MSP executives.
    • “For months, the industry has been watching for indicators that vulnerability discovery capabilities from frontier AI models such as Anthropic’s Claude Mythos would lead to increased CVEs (Common Vulnerabilities and Exposures). While some hints of this had surfaced previously, the hundreds of CVEs that received software patches Tuesday as part of Microsoft’s monthly release of software bug fixes is the clearest sign of this yet, MSP executives told CRN.
    • “Estimates of the number of vulnerabilities disclosed by Microsoft during the release, colloquially known as “Patch Tuesday,” have varied but could be above 600, according to TrendAI’s Zero Day Initiative. Dustin Childs, head of threat awareness at TrendAI, counted 621 new Microsoft CVEs for the July security update.
    • “The bug apocalypse has fully descended upon us,” Childs wrote in a post.” * * *
    • “Microsoft has been among the tech industry vendors that have received access to Anthropic’s Claude Mythos model for the purposes of proactively discovering vulnerabilities in its own products, as part of the Project Glasswing initiative announced in April. Similarly, OpenAI has provided Microsoft with access to its frontier AI vulnerability-discovery models through its Trusted Access for Cyber initiative.”

From the cybersecurity and law enforcement front,

  • Cybersecurity Dive reports,
    • “The Trump administration on Tuesday [July 14] announced the launch of a program that will coordinate the security community’s use of frontier AI models to rapidly identify and fix vulnerabilities.
    • “The vulnerability management clearinghouse, which the administration is calling Gold Eagle, is a response to the skyrocketing number of vulnerabilities that AI models are finding and the strain that that surge is placing on the security community. Through the clearinghouse, the government will coordinate efforts by private companies and independent researchers to scan critical software packages for flaws, fix any flaws that surface and deploy those fixes to end users.” * * *
    • “Gold Eagle “has already begun to intake and prioritize identified cybersecurity vulnerabilities from across industries and sectors, coordinate scanning verifications, and ultimately ensure the security of our nation’s software and networks,” the White House said in a statement.
    • “The core of the Gold Eagle program is the Vulnerability Information and Coordination Environment (VINCE), which the government is operating in partnership with Carnegie Mellon University’s Software Engineering Institute. The VINCE platform will allow anyone to report vulnerabilities to the Gold Eagle program for triage and mitigation.
    • “VINCE will enable “vulnerability and patching coordination at a speed and scale never seen before,” National Cyber Director Sean Cairncross told reporters during a briefing on Tuesday.
    • “Gold Eagle will focus heavily on open-source software, whose code underpins a wide range of critical infrastructure but is often poorly scrutinized.”
  • Dark Reading adds,
    • “Katie Moussouris, founder and CEO of Luta Security as well as a pioneer in vulnerability remediation, tells Dark Reading that the cross-sector vulnerability coordination gap Gold Eagle targets “is real,” as the Known Exploited Vulnerabilities (KEV) catalog, National Vulnerability Database (NVD), and Information Sharing and Analysis Center (ISACs) do not address cross-sector prioritization. And as she has long said, vulnerability management policy problems don’t resolve on their own.
    • “The bottleneck was never knowing about more bugs. It was having the people and process to prioritize and fix them and ensure they do not recur,” she says. “Remediation prioritization according to the new BOD 26-04 will take skills and process at each affected organization, by definition, since two and possibly three out of four of the prioritization criteria are subjective and specific per organization.” * * *
    • “Moussouris cited CISA’s recent postmortem on its AWS keys being exposed in a public GitHub repository for six months as an example of something that highlights pre-existing process weaknesses at the federal level.” * * *
    • Knostic chief AI officer Sounil Yu says that if the government wants to help stakeholders via “frontier AI capabilities,” the most useful application would be something that accelerates the implementation of vulnerability fixes.
    • “Finding vulnerabilities proactively has not been the constraint. Even finding a fix or patch has not been a significant constraint. The constraint has traditionally been in implementing the fix wherever the software has been deployed,” he says. “But if you unpack it further, it’s deploying the fix and then recertifying that everything is working as expected.”
    • “Similarly, Sachin Jade, chief product officer at Cyware, tells Dark Reading that while AI tools can surface vulnerabilities faster than anyone can currently act on them, there is also a lag in determining which findings are real, prioritizing severity, and developing and deploying a fix.
    • “This program is a good start, and we as the industry have to work collectively to sharpen our approaches, increase defense velocity, empower sharing and collective defense, and become proactive in our mindsets,” Jade says.”
  • Beckers Health IT asks and answers “Healthcare Security Teams Have More Alerts Than Ever. So Why Is Risk Still Getting Through?”
    • “People remain the core of healthcare cybersecurity. When automation handles repetitive work, analysts can focus on meaningful threats, response planning and the gaps most likely to affect the organization.
    • “IBM found that organizations extensively using AI and automation in security operations identified and contained breaches 80 days faster and experienced an average of $1.9 million less in breach costs. That does not mean technology replaces experienced professionals. It shows what can happen when they receive better-organized information sooner.
    • “The most resilient healthcare organizations will be the ones that can work through data faster, identify what is relevant and act within clear safeguards before a security gap interrupts claims or patient care.”
  • Security Week relates,
    • “The Department of War has suspended CMMC Phase 2’s mandatory third-party assessment requirement, citing concerns that the assessor ecosystem couldn’t scale to meet demand and that compliance costs were pushing small and mid-sized firms out of the defense industrial base. 
    • “A newly formed CMMC Reform Task Force will spend 60 days reviewing the program, gathering industry feedback, and reporting recommendations by mid-September. 
    • Crucially, the pause only affects independent verification, with Phase 1 self-assessment obligations, SPRS score submissions, and the underlying DFARS 252.204-7012 requirement to protect controlled unclassified information (CUI) remaining fully in effect. 
    • “Industry professionals broadly agree that the suspension pauses third-party CMMC audits but not the underlying legal obligation to protect CUI, warning that self-attestation without verification raises False Claims Act exposure. However, experts are split on whether the fix should be to scope assessments down, automate them, or preserve them largely as-is.”
  • Per a July 15, 2026, Cybersecurity and Infrastructure Security Agency (CISA) news release,
    • “Today, the Cybersecurity and Infrastructure Security Agency (CISA), in partnership with the National Security Agency (NSA), Japan Computer Emergency Response Team Coordination Center (JPCERT/CC), Netherlands’ National Cyber Security Centre (NCSC-NL), and United Kingdom’s National Cyber Security Centre (NCSC-UK), published Establishing a Coordinated Vulnerability Disclosure Program to Work With Security Researchers.
    • “This guidance helps software manufacturers and online service providers collaborate effectively with security researchers who identify weaknesses in software, networks, and hardware in a structured, transparent framework. A well-defined coordinated vulnerability disclosure (CVD) program enables software manufacturers and online service providers to better assess potential risk, improve their vulnerability management processes, and make informed decisions that improve product security for their customers.
    • “Coordinated vulnerability disclosure is foundational to building a secure software ecosystem. The practices in this guide help protect customers, strengthen products and support CISA’s Secure by Design initiative, which encourages companies to be transparent and responsible in how they build and maintain their technology,” said Acting Executive Assistant Director for Cybersecurity Chris Butera. “CISA encourages suppliers to establish a coordinated vulnerability disclosure program and build constructive, collaborative relationships with security researchers to enhance product security.”  
  • Cyberscoop tells us
    • “A total of eight cyber personnel have served in a program that began in 2022 to rotate workers between federal agencies to bolster the workforce, a watchdog report said Thursday.
    • “Over the life of the Federal Rotational Cyber Workforce program that effectively went away last year, 13 agencies offered 106 positions and received 634 applications, according to the Government Accountability Office. Eight workers won approval to participate.
    • “The goal of the Office of Personnel Management-led program, established by bipartisan legislation, was that “participating employees develop knowledge and skills that they can bring back to their home agencies,” as the GAO noted.
    • “OPM evaluated possible shortcomings in implementing the program in late 2024 and developed plans for improving it, but never followed up on them, the GAO said. As of next summer the program will officially end, OPM said.”
  • and
    • “A pair of young men were sentenced to 66 months in jail for committing acyberattack on the Transport for London that brought the network’s operations to a standstill in 2024, the United Kingdom’s National Crime Agency said Thursday [July 16].
    • “Thalha Jubair and Owen Flowers were arrested at their homes in September 2025, barely a year after the attack, and pleaded guilty last month just as their trials were set to begin. Flowers was previously arrested in connection with the attack in September, but was released after questioning by officers.
    • “Jubair and Flowers were leading members and highly involved in Scattered Spider, a nebulous hacker subset of The Com, according to researchers. The 20-year-old Jubair was a prolific cybercriminal and core member of the unbound collective
    • “U.S. authorities last year accused Jubair of direct, prominent involvement in at least 120 cyberattacks, including extortion of 47 U.S.-based organizations and the January 2025 attack on the federal court system. 
  • Beckers Health IT identified 11 cases from a Federal crackdown on hospital hackers.
    • “Federal authorities are intensifying their pursuit of the cybercriminals behind hospital and healthcare ransomware attacks, bringing charges against ransomware developers, state-sponsored hackers and even insiders from the cybersecurity industry.
    • “The latest move came July 14, when the Justice Department indicted three Russian nationals and two “bulletproof hosting” companies tied to $62 million in U.S. victim losses. The action is part of Operation Riptide, the FBI’s ongoing campaign against cybercrime infrastructure, after Americans reported more than $20 billion in cybercrime losses last year, a 26% single-year increase.”

From the cybersecurity breaches and vulnerabilities front,

  • HIPAA Journal posted its May 2026 Healthcare Data Breach report last Tuesday.
    • “Based on the current data on the HHS’ Office for Civil Rights (OCR) breach portal, 61 healthcare data breaches affecting 500 or more individuals were reported in May 2026. May’s current total represents a 27.1% month-over-month increase in data breaches. Over the past 12 months, an average of 64 large healthcare data breaches were reported each month.”
  • MedTech Dive reports,
    • “Abbott disclosed on Thursday [July 16] that a cyberattack hit its cancer diagnostics business.
    • The medical device company said in a statement posted to its websitethat there was unauthorized access to a limited number of internal systems in its cancer diagnostics business. There was no impact on other Abbott businesses, sites or systems.
    • Abbott’s cancer diagnostics business includes Exact Sciences, which the company acquired in a $21 billion deal earlier this year. The legacy Exact Sciences systems are separate from Abbott’s, according to the statement.
  • Beckers Health IT relates,
    • “A cyberattack on New Jersey law firm Greenbaum Rowe Smith & Davis has exposed data on 12,801 patients across three health systems in the state.
    • “Greenbaum discovered unauthorized access to its systems through a compromised user account in November 2025 and traced the intrusion to Nov. 25-27, 2025, according to the firm’s notification. Affected organizations include Edison, N.J.-based Hackensack Meridian Health, Morristown, N.J.-based Atlantic Health and Trinitas Regional Medical Center in Elizabeth, N.J., part of West Orange, N.J.-based RWJBarnabas Health.
    • “An investigation completed in April found an unauthorized third party accessed patient names, addresses, medical record numbers, medical history, provider details, medical bill amounts and health insurance information. For a subset of individuals, Social Security numbers or dates of birth also were exposed, Greenbaum said.”
  • Bleeping Computer tells us,
    • “Ernst & Young is notifying customers of a data breach caused by the compromise of a third-party support ticket system used by its IT personnel.
    • “According to the company, support tickets submitted through the platform may have included documents containing client tax information.
    • “Ernst & Young (EY) is among the world’s four largest auditing and professional services providers, offering auditing, tax, consulting, and transaction advisory services to major organizations in more than 150 countries.” * * *
    • “Ernst & Young says it secured its systems and notified federal law enforcement authorities, while it has assured that the unauthorized access has been removed.
    • “The company also states that it is not aware of any misuse or further exposure of the stolen files and has no indication that particular individuals were targeted by the threat actors.”
  • CISA added ten known exploited vulnerabilities to its catalog this week.
    • July 13, 2026
      • CVE-2008-4128 Cisco IOS Cross-Site Request Forgery Vulnerability
        • Security Affairs discusses this KVE here.
    • July 14, 2026
      • CVE-2026-15409 SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability
      • CVE-2026-15410 SonicWall SMA1000 Appliances Code Injection Vulnerability
      • CVE-2026-56155 Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability
      • CVE-2026-56164 Microsoft SharePoint Server Missing Authentication for Critical Function Vulnerability
        • The Hackers News discusses the SonicWall KVEs here
        • Cybersecurity News discusses the Microsoft Active Directory KVE here.
        • Cybersecurity News discusses the Microsoft Sharepoint Server KVE here.
    • July 15, 2026
      • CVE-2023-4346 KNX Association KNX Protocol Connection Authorization Option 1 Overly Restrictive Account Lockout Mechanism Vulnerability
      • CVE-2026-46817 Oracle E-Business Suite Improper Privilege Management Vulnerability
        • The Hacker News discusses these KVEs here.
    • July 16, 2026
      • CVE-2026-25089 Fortinet FortiSandbox OS Command Injection Vulnerability  
      • CVE-2026-39808 Fortinet FortiSandbox OS Command Injection Vulnerability  
      • CVE-2026-58644 Microsoft SharePoint Deserialization of Untrusted Data Vulnerability 
        • Bleeping Computer discusses the Fortinet KVEs here.
        • The Hackers News discusses the Microsoft Sharepoint KVE here.
  • The American Hospital Association News adds,
    • “The Cybersecurity and Infrastructure Security Agency has issued an alert warning of four Microsoft SharePoint vulnerabilities being exploited by cyber threat actors. CISA said the vulnerabilities affect all supported on-premises versions of SharePoint Server, including the Subscription Edition, 2019 and 2016. Threat actors can establish remote code execution and perform other actions to deploy malware. CISA said organizations should monitor SharePoint Servers closely for any signs of exploitation or unusual activity. An additional vulnerability was found, but it is not yet known to have been exploited. Microsoft identified it as a potential risk if it is left unpatched. CISA urged organizations to apply the latest patches and security updates from Microsoft, among other recommendations. 
    • “Nearly everyone using Microsoft products is using SharePoint, the backbone of the Office suite,” said Scott Gee, AHA deputy national advisor for cybersecurity and risk. “Hospitals with their SharePoint instances housed on premises should pay particular attention to this alert. The common vulnerabilities and exposures listed in the report have patches available, and they should be deployed as soon as possible. Hospitals should also verify that the security measures mentioned are in place.” 
  • and
    • “The Cybersecurity and Infrastructure Security Agency and other U.S. and international agencies released a joint advisory July 13, warning of Russian cyber actors targeting vulnerable network devices, primarily routers, in critical infrastructure sectors globally, including healthcare. The advisory details how the threat actors primarily use scanning to identify poorly configured devices for exploitation. The actors then exfiltrate sensitive information and facilitate malicious activity. The advisory includes recommendations to help defend against potential threats.
    • “This malicious cyber activity has been attributed to the Russian Federal Security Bureau, a foreign intelligence agency of the Russian government,” said John Riggi, AHA national advisor for cybersecurity and risk. “Therefore, this represents an advanced and persistent cyber threat targeting U.S. healthcare that should be prioritized. The first step in mitigating this threat and other nation-state cyber threas is to install the latest network router encryption standard, Simple Network Management Protocol v3.”
  • Cybersecurity Dive tells us,
    • “Businesses should be on guard for a hacking campaign in which attackers spoof OAuth client IDs to collect information about targets’ user directories, the security firm Proofpoint said on Monday.
    • “The security firm said it had observed “multiple campaigns at scale abusing spoofed OAuth application identifiers, with distinct tooling, infrastructure, and execution patterns indicating independent adoption by multiple threat actors.”
    • “The report explains how organizations should monitor their networks for this reconnaissance technique.”
  • Cyberscoop points out,
    • “Cyberstalkers are increasingly exploiting a feature in Google Chrome meant for mobile phone user convenience, but can give intruders broad access to a device owner’s private information, according to researchers.
    • “Certo Software said in a blog post Tuesday that stalkers are making use of Chrome’s sync capability — meant to make it so signing into Chrome on one device makes it easier to do so on other devices, too — to spy on a phone owner’s browsing history and gain access to their stored passwords.”
  • Bleeping Computer adds,
    • “A flaw in Anthropic’s Claude for Chrome browser extension could allow a malicious extension to trigger predefined AI actions by simulating user clicks, potentially allowing it to abuse Claude’s access to connected services such as Gmail, Google Docs, Google Calendar, and Salesforce.
    • ‘The issue was discovered by Ax Sharma of Manifold Security, who says it stems from how the Claude extension determines whether a user intentionally requested one of its built-in tasks.
    • “Chrome extensions with permission to run on a website can inject JavaScript into the page, allowing them to read and modify its contents. This includes changing page elements, reading information displayed on a site, and generating click and keyboard events programmatically.
    • “According to Manifold’s report, the Claude extension listens for click events on a specific page element that launches one of its built-in AI workflows. These workflows are predefined tasks that allow Claude to perform actions in connected services such as Gmail, Google Docs, Google Calendar, and Salesforce.”

From the ransomware front,

  • Cybersecurity Dive reports,
    • “Coca-Cola on Thursday said it is investigating a ransomware attack that impacted its Fairlife dairy unit and has suspended production at the company’s U.S. production facilities. 
    • “In a filing with the Securities and Exchange Commission, the company said it trying to determine the full scope of the attack and what impact it might have on its business. Coca-Cola said the attack has had no effect on the quality and safety of its Fairlife products, which include ultra-filtered, lactose-free milk as well as protein and nutritional shakes.”
  • Per a Sophos news release,
    • “This year’s data has a few eyebrow-raising departures from the patterns of past State of Ransomware reports. Exploited vulnerabilities lost their three-year grip on the top root-cause spot. Median ransom demands and payments both dropped, yet the average recovery bill still climbed. And small organizations (100-250 employees) are falling further behind their larger peers on the one metric that matters most: stopping the attack before data gets encrypted.
    • “The seventh annual Sophos State of Ransomware report is based on a vendor-agnostic survey of 2,158 IT and security leaders whose organizations were hit by ransomware in the last 12 months.
    • “Click here to access the full report now.”
  • Dark Reading adds,
    • “According to Sophos’ survey, malicious email (26%) and phishing (24%) dethroned the three-year reign of vulnerabilities (18%, down from 32%) as the top root cause of ransomware attacks. Two-thirds (67%) of victims also said the ransomware attack they suffered was their most significant identity attack over the past year.
    • “With phishing and malicious email now accounting for half of all ransomwareroot causes in this report, organizations should deploy advanced email filtering, implement DMARC/DKIM/SPF protocols, and invest in regular phishing awareness training,” Sophos said. “The shift toward email-based attacks suggests that technical vulnerability patching alone is insufficient.”
    • “The third most common root cause of ransomware attacks was also identity related, with compromised credentials used in 23% of cases. This is particularly significant because of one of the most startling findings: Multifactor authentication (MFA) was deployed for 97% of instances where compromised credentials were the root cause of ransomware attacks.” * * *
    • While staying patched remains important as always, it appears the fight against ransomware is moving from patch management to identity protection.
    • “Organizations should prioritize identity threat detection and response (ITDR), enforce multifactor authentication across all access points, and regularly audit both human and non-human identity credentials,” Sophos said. The vendor stopped short of recommending a specific type of MFA, suggesting the biggest failure wasn’t MFA itself but rather incomplete deployment or perhaps a lack of comprehensive inventorying.”
  • InfoSecurity Magazine lets us know,
    • “The number of ransomware attacks which target government departments and agencies has risen to the extent that one has its services restricted by encryption every single day.
    • “The figure comes from analysis by researchers at Comparitech, who studied ransomware incidents which targeted government entities between January and June 2026.
    • The research, published on July 16, recorded that 187 government organizations were hit with ransomware during the first six months of 2026. That represents a 13% increase on the 165 ransomware attacks recorded during the second half of 2025.
    • “The increase in recorded ransomware events is notable because the figure of 187 incidents across 182 days means that the average number of ransomware attacks against government bodies now stands at an average of one every day.
    • “Of those 187 recorded incidents, just over half (89) were publicly confirmed by the organization which was hit.”
  • Bleeping Computers warns
    • “A new ransomware actor called Spirals completed a corporate intrusion, from initial access to data theft and encryption, in less than 24 hours.
    • “The attack occurred in June and breached an IT services firm in South Asia after compromising an Internet Information Services (IIS) server exposed on the public web.” * * *
    • Symantec’s report provides network indicators and file hashes associated with the documented Spirals attack to help organizations worldwide set up defenses against this threat group.”

From the cybersecurity business and defenses front,

  • The Wall Street Journal reports
    • “Cybersecurity mergers and acquisitions reached 219 in the first half of 2026, putting the sector on track to surpass last year’s 400 deals.
    • “The rush to acquire artificial-intelligence capabilities is driving the surge in cybersecurity dealmaking.
    • “Technology and cybersecurity companies accounted for 88% of disclosed cyber acquisition spending in the first half of the year.”
  • Cybersecurity Dive relates,
    • “Enterprise security teams are incorporating AI into their programs at a faster rate than ever before, but a significant gap exists in the governance policies that are designed to support that expansion, according to a report released Monday by the SANS Institute.
    • Four out of 10 security practitioners said there is no formal policy in their organization for AI adoption, according to the report. More than six of 10 practitioners said they have no visibility into where AI models are being used or what kind of information is being exposed. 
    • “About 75% of security practitioners have a governance role related to enterprise AI, yet more than half of respondents said there are no established frameworks for AI audits, the report showed.”
  • Dark Reading adds,
    • “Having completed its $32 billion acquisition of Wiz earlier this year, Google is fulfilling its plan to automate threat detection, investigation, and remediation with a new “agentic defense” platform built around intelligent security agents.
    • “Wiz, founded in 2020, quickly became one of the fastest-growing cloud security companies by introducing graph-based analysis to correlate cloud assets, identities, vulnerabilities, and exposures across multicloud environments. The acquisition gives Google a cloud-native security platform that supplements its existing artificial intelligence (AI), threat intelligence, and incident response features.
    • “On Monday [July 13], Google revealed it had integrated Wiz attack surface management (ASM) and Google Threat Intelligence (TI). When Wiz ingests posture and workload telemetry from Google Cloud, it enriches detections in real time with Google TI and pushes prioritized exposure data directly into SecOps playbooks and cases, enabling SOC teams to investigate and respond to cloud‑native risks without switching between tools.
    • “The integration builds on Google’s AI Threat Defense, launched in May, and other automation capabilities that combine Gemini with Wiz’s scanning, simulation, and remediation to counter AI-powered threats. It leverages the reasoning capabilities of its Gemini AI modeling platform and other frontier models alongside Wiz’s contextual risk prioritization capabilities. Google AI Threat Defense uses Gemini’s code remediation features and CodeMender, along with expertise from Mandiant.”
  • Cyberscoop notes,
    • “As AI-enabled hacking becomes a bigger threat for cybersecurity and national security, public attention has focused on mainly a few leading frontier AIcompanies developing more powerful large language models.
    • “These models, and the billions of dollars behind them matter, but they’re only part of a larger shift. Enterprises are now building their own technology platforms that take these general-purpose LLMs and turn them into bespoke cybersecurity tools.
    • “Industry professionals refer to these tools as a “harness.” They control the model’s behavior, limit its risks, and connect it to internal IT systems and networks so it can work reliably at scale.
    • New research from Cato Networks shared exclusively with CyberScoop shows how much power can come from a harness. It paired OpenAI’s ChatGPT 5.5 and GPT 5.5-Cyber models with its own tool and tested the abilities of the agent to hack into a victim network with as little human direction as possible.” * * *
    • “Dan Rapp, chief AI and data officer at Proofpoint, said their harness, “Satori,” has become a critical tool for keeping their agentic AI on track while giving humans the ability to step in when things go awry.
    • “I think what you’re seeing in the foundation of frontier models is you have raw intelligence, raw reasoning power, but to get these systems to perform the way you want to, both context engineering – the content provided ensuring that its accurate and relevant – and the harness engineering are essential to actually get the systems to perform well,” Rapp told CyberScoop.”
  • Dark Reading explains how to “Manage Vendor Risk in a Few Practical Steps.”
    • “Risk tolerance, exposure visibility, board oversight — handling third-party risk is complicated but achievable with disciplined, precise governance.”
  • Tech Target highlights “Multifactor authentication: 5 examples and strategic use cases.”
    • “Before implementing MFA, conduct a careful study to determine which security factors offer the strongest protection. Passwords and PINs aren’t cutting it any longer.”
  • Here’s a link to Dark Reading’s CISO Corner.

Cybersecurity Saturday

From the renewed war with Iran front,

  • Dark Reading offers an opinion piece explaining that “Iran’s Cyber Crosshairs Focus Beyond Critical Infrastructure.”
    • “Obscurity isn’t a defense. If your company has any Internet-facing vulnerability, you’re at risk from multiple threats.” * * *
    • “The groups behind recent attacks, including Handala, Ababil of Minab, and others operating within Iran’s cyber-influence ecosystem, cloak themselves in the mask of cyber activism, or “hacktivism.” They are largely opportunistic. They aren’t specifically hunting targets; they are on “Shodan Safaris” hunting easily exploited vulnerabilities or insecure systems. A law firm or logistics hub with an exposed programmable logic controller or an unpatched VPN is an easy, appealing target.
    • “Many companies don’t realize how much of their infrastructure is externally accessible, or how little it takes to exploit what’s exposed. Handala, which the US Justice Department has attributed to Iran’s Ministry of Intelligence and Security, remotely wiped over 200,000 hosts in an attack on Stryker, a medical device manufacturer, in March. The incident disrupted manufacturing and impacted their first-quarter earnings. More recently, Ababil of Minab compromised Vyncs, a GPS tracking platform used across the logistics sector, taking systems offline and defacing its website. In the Stryker incident, the attack was likely made possible through credentials stolen via commodity malware and provided for sale via illicit channels — emphasizing the opportunistic nature of these events.”
  • Security Week adds,
    • “An Iran-linked advanced persistent threat (APT) actor has been using a modular command-and-control (C&C) framework in recent attacks targeting organizations in Israel, Check Point reports.
    • “Tracked as Cavern Manticore, the APT focuses on government entities and IT providers, and appears linked to Iran’s MOIS (Ministry of Intelligence and Security), with possible ties to the OilRig subgroup Lyceum (also known as Hexane and SiameseKitten).
    • ‘Cavern Manticore’s C&C framework includes an adaptable toolset built using .NET, with various compilation formats used across components, used as an anti-analysis layer.”

From the Project Glasswing front,

  • Crypto Briefing reports,
    • “The U.S. government has begun utilizing AI technology developed by Anthropic to identify vulnerabilities in its software systems. This initiative, part of Project Glasswing, leverages Anthropic’s Mythos model to detect bugs within hours, a significant improvement over traditional methods. Despite previous concerns over security risks associated with the Mythos model, its deployment underscores the government’s commitment to strengthening cybersecurity measures. The move is seen as a strategic effort to protect critical infrastructure and enhance national security.”
  • Bleeping Computer adds,
    • Microsoft says Windows users should expect to see an increase in security updates as the company increasingly relies on artificial intelligence to discover vulnerabilities in its codebase.
    • In a blog post published today, Microsoft said advances in AI have significantly accelerated vulnerability discovery, allowing engineers to identify more security issues before they can be exploited in zero-day attacks.
    • “The pace of vulnerability discovery is changing with advances in AI making it possible to find more issues, faster, across more code, with new mechanisms that can accelerate both discovery and analysis,”  Microsoft said. * * *
    • “This announcement comes two days [July 8] after Reuters reported that the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has begun using Anthropic’s Fable AI model to scan government software for vulnerabilities that cybercriminals or foreign intelligence services could exploit.
    • “According to the report, the AI-assisted code audits have already uncovered numerous vulnerabilities, though officials did not disclose how many or provide details on their severity.”
  • SC Media lets us know “what our industry learned the past 90 days since the Mythos announcement.”
    • “For years, security leaders have discussed the possibility that AI would eventually accelerate offensive cyber operations. Mythos transformed that discussion from a future-looking hypothesis into an immediate operational concern.
    • “Over the past three months, the industry has begun adjusting to a new reality. We no longer view AI simply as a productivity tool that helps developers write code or assists analysts with investigations. It’s emerged as a force multiplier for vulnerability discovery, capable of identifying weaknesses at a pace that challenges traditional security workflows. As the time between vulnerability discovery and exploitation shrinks, organizations are now forced to rethink long-standing assumptions about patch management, vulnerability prioritization, and cyber defense.
    • “This shift extends well beyond one AI model or one vendor. Whether organizations use commercial frontier models, open-weight alternatives, or internally developed AI systems, the underlying trend remains the same: AI has dramatically compressed the window defenders have to identify, validate, and remediate software flaws before attackers can weaponize them. In many ways, the security industry has entered an era in which the speed of decision-making may become just as important as the quality of detection.”

From the cybersecurity policy and law enforcement front,

  • On July 3, the Office of Management and Budget’s Office for Information and Regulatory Affairs posted the federal government’s 2026 unified regulatory agenda.
    • Fierce Healthcare tells us,
      • “Federal regulators have delayed a major overhaul of the Health Insurance Portability and Accountability Act (HIPAA) Security Rule, pushing back final action on the rule by a year.
      • “The Department of Health and Human Services (HHS) had proposed a May 2026 release for a final rule that makes significant changes to the HIPAA Security Rule and marks the first major update to the 23-year-old rule in more than 10 years.
      • “The U.S. Office of Management and Budget (OMB) website was updated and indicates that the final rule was pushed back to July 2027.”
    • Federal News Network lets us know,
      • “[The unified agenda] shows that the Cybersecurity and Infrastructure Security Agency expects to issue a final rule for the Cyber Incident Reporting for Critical Infrastructure Act in September 2026. Earlier this summer, CISA held a series of townhalls to get some final feedback on the regulations.” * * *
      • “Meanwhile, the Unified Agenda also shows that a federal contracting rule that standardizes cybersecurity requirements for unclassified IT systems will also be finalized in September 2026.
      • “The rule “will ensure federal information systems are better positioned to protect from cybersecurity threats by standardizing common cybersecurity contractual requirements across agencies for unclassified federal information systems,” according to the regulatory preview.
      • “And another federal contracting rule on “cyber threat and incident reporting and information sharing” is also projected to be finalized in September, the Unified Agenda shows.
      • “Both the CUI rule and the incident reporting rule have been long anticipated, with proposed rules dating back to 2023. They each represent landmark rules for the government contracting community, which is also grappling with the roll out of the Defense Department’s Cybersecurity Maturity Model Certification (CMMC) requirements.
      • “The CMMC regulations went into effect late last year, but DoD has been slowly ramping up the requirements for third-party audits. This November, however, the requirement for a third-party CMMC assessment is expected to become standard in all applicable contracts.
      • “DoD also expects to shortly issue more details on how the cybersecurity standards that underpin CMMC will be updated.
      • “The Unified Agenda shows that this month, DoD will adopt an interim final rule for the CMMC program that details the deadline for shifting to the National Institute of Standards and Technology Special Publication 800-171 Revision 3. Currently, CMMC assessments are tied to Revision 2 of the NIST standards.”
  • Fedscoop informs us,
    • “Greg Barbaccia is stepping down as federal CIO and leaving government at the end of August, he said in an email to the CIO Council Tuesday [June 7, 026].
    • “I’m writing to share that I’ve made the difficult decision to leave government, and my time as Federal CIO is coming to an end,” Barbaccia wrote to CIOs on the council in his email, obtained by FedScoop. 
    • “Barbaccia, who joined the Trump administration as its top IT official in January 2025, said his last day in the role will be Aug. 31.
    • “Barbaccia’s departure comes just months after he brought on former Department of Education CIO Thomas Flagg to be his deputy. Flagg would be the default acting official with Barbaccia’s departure, a government chief information officer told FedScoop on the condition of anonymity to be more candid.”
  • Cyberscoop observes,
    • “The AI-focused executive order President Donald Trump signed last monthgave the Treasury Department, the National Security Agency, and the Cybersecurity and Infrastructure Security Agency (CISA) 30 days to establish a new “AI cybersecurity clearinghouse.” The deadline passed last week.
    • “The clearinghouse is meant to coordinate the scanning, discovery, and validation of software vulnerabilities in critical infrastructure, and then prioritize how those vulnerabilities get patched and distributed.
    • “It’s the right problem to solve. The question now is whether what is created will actually solve it.”
  • and
    • “A major credential leak spurred the Cybersecurity and Infrastructure Security Agency to strengthen protections for its sensitive materials, improve how researchers can report agency vulnerabilities and develop plans for similar incidents, the agency said in a forensic report released Thursday.
    • The blog post outlines CISA’s response to the leak that the researcher who discovered it in May called one of the worst he had ever seen, which also drew congressional scrutiny.”
  • Cyberscoop adds,
    • “”A former ransomware negotiator for DigitalMint was sentenced to 70 months in jail for deceiving his employer’s clients and conspiring with ransomware affiliates to extort a combined $75.3 million from five U.S. companies he was entrusted to aid during their moments of extreme crisis, the Justice Department said Thursday. 
    • Angelo John Martino III shared confidential information he gained from his work as a ransomware negotiator, including victim organizations’ negotiating positions and insurance policy limits, to extract the maximum payment for himself and other BlackCat affiliates he colluded with in backchannels.”
  • and
    • “An Armenian national who was extradited from Ukraine to the United States last year pleaded guilty to participating in a series of attacks in 2019 and 2020 involving Ryuk ransomware, the Justice Department said Thursday.
    • “Karen Serobovich Vardanyan pleaded guilty to computer fraud and conspiracy to commit fraud and extortion. He agreed to pay nearly $1.2 million million in restitution and faces up to 15 years in jail.
    • “The 34-year-old admitted to participating in cybercrime from November 2019 to April 2020 when he and his co-conspirators deployed Ryuk ransomware against three U.S.-based organizations while living in Ukraine and Russia.”

From the cybersecurity breaches and vulnerabilities front,

  • Dark Reading reports,
    • “In February, a ransomware attack against the University of Mississippi Medical Center disrupted operations for more than two weeks. In March, a cyberattack on German medical-billing provider Unimed, which services 95% of the nation’s university hospitals and more than half of large clinics, resulted in the theft of sensitive health data for tens of thousands of patients.
    • “In the first half of 2026, cyberattacks on the healthcare sector jumped 14%, slightly more than the overall increase of 11% across all industries, according to data from technology research firm Comparitech. While healthcare providers — such as hospitals and doctors’ offices — saw a moderate rise in attacks, healthcare businesses suffered a significant increase of 35% compared with the second half of 2025 and 110% compared with the same six months from the previous year.
    • “Much of the shift in focus is likely because attackers have recognized that compromising a single provider can provide access to multiple hospitals, says Rebecca Moody, head of data research at Comparitech.”
  • Cybersecurity Dive relates,
    • “A threat actor claims to have stolen a vast trove of sensitive data from the consulting giant Accenture in a recent cyberattack.
    • “The compromised data includes source code, Microsoft Azure personal access tokens, RSA encryption keys and SSH keys, a hacker calling themselves “888” said in a dark-web post shared by Bleeping Computer.
    • “The actor says they hacked roughly 35GB of data from Accenture during the intrusion, which occurred in early July.
    • “Accenture downplayed the incident in a statement to Cybersecurity Dive.
    • “We are aware of this isolated matter and we have remediated its source,” spokesperson Peter Soh said. “There is no impact to Accenture operations and service delivery.”
    • “The stolen data could put Accenture and its clients at significant risk of further attacks. “Source code can help attackers understand internal application logic, identify weak implementation patterns, and search for hardcoded secrets or exploitable paths in custom systems,” the threat intelligence firm SOCRadar said in an analysis of the incident. Meanwhile, the exposed access keys could let hackers roam freely through code repositories and cloud storage services.”
  • and
    • “AssuranceAmerica, a closely held provider of auto and renters insurance, was the target of a cyberattack earlier this year that impacted more than 6.9 million customers, according to state regulatory filings. 
    • “The Atlanta-based firm said the incident was detected on March 17, stemming from an attack that targeted one of its employees a day earlier, according to a filing with the California Attorney General’s office. 
    • “An investigation found an unauthorized party gained access to the company’s IT department and copied a number of data files. The company said it notified law enforcement about the attack. 
    • “According to a filing with the Maine Attorney General’s office, the breach involved more than 6.9 million people. This included nearly 880 people within the state of Maine. The Maine AG discontinued posting new notices on its public site in June after its breach reporting system was the target of an attack.”
  • and
    • “An initial access broker weaponized a critical vulnerability known as CitrixBleed 2 in a series of attacks during the first half of 2026 across multiple organizations, according to a report released Thursday [July 9] by the security company Huntress. 
    • “After exploiting the vulnerability, the hackers escalated privileges, created rogue local administrator accounts and established persistence with legitimate remote access tools, including ScreenConnect and Zoho Assist. 
    • “About a half-dozen cases between January and June followed a consistent playbook. In the most advanced case, the attackers deployed DragonForce ransomware, Huntress researchers said.”
  • Healthcare Dive adds,
    • “AdaptHealth disclosed last week that a recent cyberattack resulted in patient data being stolen.
    • “A threat actor gained unauthorized access to company systems through a social engineering attack and exfiltrated data, including certain personally identifiable information, protected health information of patients and stored password files associated with insurance billing, according to a July 2 filing with the Securities and Exchange Commission.
    • “Based on information obtained to date, AdaptHealth believes that the threat actor gained unauthorized access to certain cloud-based business applications, including internal patient management systems and document storage platforms. The company also confirmed that certain external electronic health record system portals were accessed.”
  • CISA added six known exploited vulnerabilities to its catalog this week.
    • July 7, 2026 (two releases; “Per BOD 26-04, federal agencies are required to patch all four security weaknesses by July 10.”)
      • CVE-2026-48282 Adobe ColdFusion Path Traversal Vulnerability
      • CVE-2026-48908 JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability
      • CVE-2026-55255 Langflow Authorization Bypass Through User-Controlled Key Vulnerability  
      • CVE-2026-56290 Joomlack Page Builder Improper Access Control Vulnerability
        • Security Week discusses these KVEs here.
    • July 10, 2026
      • CVE-2026-48939 iCagenda Unrestricted Upload of File with Dangerous Type Vulnerability
      • CVE-2026-56291 Balbooa Forms Unrestricted Upload of File with Dangerous Type Vulnerability
        • Mallory discusses these KVEs here.
  • Dark Reading adds,
    • “Microsoft has tackled yet another zero-day vulnerability published by a disgruntled security researcher with a vendetta against the software giant.
    • “On Wednesday, Microsoft issued an out-of-band patch for RoguePlanet, an elevation-of-privilege vulnerability in Windows Defender, tracked as CVE-2026-50656. The high-severity flaw, which received a 7.8 CVSS score from Microsoft, could allow an attacker to escalate privileges on a Windows device from a basic user to the highest SYSTEM-level access, which would give them complete control over the device.” * * *
      “Despite a public exploit being available for RoguePlanet, it’s unclear if the vulnerability has been exploited in the wild. Microsoft’s updated advisory states the flaw has not been exploited, and CISA has not added CVE-2026-50656 to its Known Exploited Vulnerabilities (KEV) catalog. Qualys, meanwhile, published a threat report on June 18 stating that RoguePlanet has been “exploited in attacks,” though no details were provided.”
  • Security Week relates,
    • “Organizations across multiple sectors have been targeted in a vishing campaign aimed at harvesting Microsoft 365 credentials, Okta warns.
    • “The campaign started in April and has involved voice calls directing the victims to fake Microsoft Entra ID login pages under the pretense that they need to register a new passkey.
    • “Tracked as O-UNC-066 and also known as CL-CRI-1147 and Pink, the hacking group has been targeting automotive, aviation, construction, food and beverage, healthcare, and technology organizations, mainly for data extortion.
    • “As part of the observed attacks, the threat actor has been registering domains incorporating the word ‘passkey’, and has been directing victims to pages that closely mirror the Microsoft passkey enrollment process.
    • “It appears engineered to convince a targeted user they are in the process of enrolling a passkey with Microsoft, while the threat actor simultaneously registers their own passkey in the targeted user’s Microsoft account,” Okta says.”
  • and
    • “A critical prompt injection vulnerability in GitHub Agentic Workflows could allow unauthenticated attackers to leak private repository data, Noma Labs warns.
    • “GitHub Agentic Workflows allows users to write workflows in natural language using markdown files that an AI agent will use as GitHub Actions, thus automating the interaction with code repositories.
    • “Because of the security defect, named GitLost, unauthenticated attackers can hide indirect prompts in crafted GitHub Issues posted on the public repositories of an organization that also maintains private repositories, and the AI agent will follow the instructions.”

From the ransomware front,

  • Cybersecurity Dive reports,
    • “Ransomware activity grew slightly between the first and second quarters of 2026 but significantly year over year, and there were more hacker groups active during April, May and June than in any previous quarter, researchers said on Thursday [July 9].
    • “Cybercrime actors claimed breaches of 2,279 victims in Q2 2026, a 7% increase over Q1 2026 but a 43% year-over-year increase compared with Q2 2025, GuidePoint Security said in a quarterly report.
    • “The Qilin ransomware gang led the quarter, accounting for 13% of attacks, but the relatively new group The Gentlemen has grown quickly and now accounts for almost as much activity, GuidePoint said.” * * *
    • “Qilin, The Gentlemen, Akira and DragonForce compromise what GuidePoint calls the “four-headed monster” of high-volume ransomware groups. The lack of a “singular monolithic figure” could make the ransomware community more resilient to law-enforcement takedowns, the security firm said, because there are now “multiple franchises poised to absorb displaced affiliates if another were to disappear overnight.”
  • Tech Crunch relates,
    • “Last week, researchers at cloud security firm Sysdig said they’d documented the first known case of “agentic ransomware.” It was an extortion operation, dubbed JadePuffer, in which an AI agent — not a human — handled the technical execution of a real-world cyberattack from start to finish. The agent broke into a vulnerable server, stole credentials, moved through the target’s network, encrypted files, and even wrote its own ransom note, adapting to obstacles along the way like a human hacker would. Coverage of the operation described it as run “without any human oversight,” with “no human at the keyboard.”
    • “That’s not quite the full picture. In an interview on Monday with CyberScoop, Sysdig’s Michael Clark, the company’s senior director of threat research, clarified that a human was still very much involved — just not in the technical execution. “A human still set up and pointed the operation and provisioned the infrastructure behind it, the command-and-control server, the staging server used for the stolen data and chose a victim,” Clark said. The credentials used to break into the victim’s database, he added, weren’t harvested by the AI agent itself; someone obtained them separately, through a prior compromise, and handed them to the operation.
    • “None of this contradicts Sysdig’s original claim, and the technical details of the attack remain notable on their own — wild, even. The agent got in through a known bug in Langflow, a popular open source tool for building LLM apps, then moved on to a production MySQL server and exploited another known flaw to gain admin access. It encrypted over 1,300 configuration records and not only left behind a ransom note that it wrote itself but it left a Bitcoin address where the ransom could be sent. Sysdig hasn’t disclosed who was targeted.”
  • Dark Reading tells us,
    • “A newly rebranded ransomware outfit is sneaking malware into American organizations using a malicious yet Microsoft-approved driver.
    • “Researchers at Symantec recently observed a cyberattack from a group known as “Hyadina.” Hyadina is a 4-year-old ransomware-as-a-service (RaaS) operation with a new locker, “GodDamn,” an iteration on its previous lockers, “Beast” and “Monster.” It typically attacks American organizations, and it also has a distinct distaste for former Soviet countries. Its targets have spanned sectors that include healthcare, manufacturing, education, and wherever else it finds opportunity.
    • In a recent case against an unidentified organization, Hyadina used a smorgasbord of dual-use hacking tools, including legitimate remote monitoring and management (RMM) software, and more than a dozen penetration testing programs. The real kicker, though, was a malicious program with kernel access on Windows, capable of killing any and all processes, including security software.

From the cybersecurity business and defenses front,

  • Cybersecurity Dive reports,
    • “U.S. companies are merging cyber risk issues into their overall enterprise risk strategy, at a time when AI adoption and business resilience are leading to significant shifts in business priorities, according to a report released Tuesday [July 7] by Information Services Group, a technology research and advisory firm.
    • “Cybersecurity is increasingly seen as a business-critical concern, as companies accelerate their adoption of agentic AI and transform much of their technology and data infrastructure to hybrid or multicloud environments. 
    • “Enterprise leaders are closely integrating cyber spending decisions with overall IT strategy. In addition, C-suite and board members are taking greater accountability for business continuity, financial exposure and regulatory compliance.”
  • Info-Security Magazine relates,
    • “Chris Betz has officially taken the helm as the new CISO of Google Cloud. Transitioning from his previous role as Google’s VP of infrastructure security, Betz is stepping up to lead the company’s security posture at a critical turning point in the industry.
    • “In his very first interview since assuming the CISO title [which is found in the article], he shared his vision on the role generative AI will play in defending global enterprises.
    • “Coinciding with his transition, Betz published a key blog post on the Google Cloud blog titled Cloud CISO Perspectives: The 4 lessons that guided AI threat defense. In the article, he lays out Google’s playbook for using AI to defend against AI, advocating for a multi-model approach, robust security harnesses and the irreplaceable value of human expertise in modern cyber defense.”
  • Tech Target offers “a roadmap to zero trust maturity.”
    • “Transforming an organization to take on a zero-trust posture is no small affair. A phased, thoughtful approach can bolster security while supporting business outcomes.”
    • “Zero trust is not a product, control or single technology deployment; it’s a strategic architecture and operating model designed to reduce risk and improve the security posture of organizations that have traditional, perimeter-based security models. Perimeter-based models — which assume clearly defined “inside” and “outside” boundaries — fail to address modern threats because they were designed for a world that no longer exists.
    • “Zero trust relies on three foundational principles:
      • “Explicit verification. Every access request is authenticated and authorized using components such as user identity, device health, location and behavior.
      • Least-privilege access enforcement. Users and devices receive only the minimum access required, and only for as long as needed.
      • Assume breach. Security operates under the assumption that attackers are already present, with controls designed to limit access and damage.”
  • and sugggests an approach for “evaluating secure enterprise browsers vs. security plugins
    • “Malicious actors have long targeted and exploited browser vulnerabilities. The widespread adoption of AI increases the risk, forcing CISOs to reevaluate browser security options.” * * *
    • “In this moment of renewed attention to browser security and the risks of it failing, CISOs face two options for improving browser security: deploying secure enterprise browsers and deploying browser security plugins.”
  • Here is a link to Dark Reading’s CISO Corner.

Cybersecurity Saturday

From the Project Glasswing front,

  • Cybersecurity Dive reports,
    • “Anthropic on Wednesday [July 1, 2026] unfroze access to its advanced Fable and Mythos AI models after the Trump administration lifted an export-control ban.
    • The return of the two models — with Fable 5 available for general use and the more powerful Mythos 5 limited to a coalition of trusted partners, as it was prior to the ban — represents significant progress in ongoing talks between President Donald Trump’s administration and AI firms over the responsible deployment of frontier AI models, an issue the U.S. government and the tech industry have sparred over in recent months.
    • “In a Tuesday statement announcing a resolution to one of the AI race’s most intense clashes, Anthropic insisted that its models had always been safe and that the government had blown the situation out of proportion — suggesting that tense conversations still lie ahead about the balance between offering advanced capabilities to defenders and keeping them out of the hands of U.S. adversaries.”
  • Bleeping Computer adds,
    • “Anthropic says Claude Fable 5 won’t be accessible via Claude subscriptions after July 7, but it’s not a permanent change, and the company expects the model to return outside the usage-based plan soon.
    • “Fable 5 was recently restored after the US government lifted export controls on Anthropic’s most powerful models, Fable 5 and Mythos 5.
    • “As part of the redeployment, Anthropic said Fable 5 would be available globally on Claude.ai, Claude Code, Claude Cowork, and the Claude Platform.”
  • and
    • “Claude Fable, the company’s most powerful model, is now available to all users, but early impressions are disappointing, as it appears to be nowhere near the original release.” * * *
    • “[T]he real gut punch is the degraded performance, or as famously used in the AI community, the “nerfed” performance.
    • “On Reddit, users are reporting that the restored Fable 5 feels weaker, or is simply being routed through stricter safety systems more often than before.
    • “The new guardrails are kicking in on way too many tasks and falling back to Opus 4.8,” one user wrote in a Reddit post. “This is not the model that got banned.”
    • “The problem is not just limited to Claude desktop, as Claude Code is also struggling with similar issues.”
  • Observer interviews CrowdStrike president Michael Sentonas who “discusses Anthropic’s Claude Mythos and how A.I. could speed up vulnerability discovery and exploitation.”

From the cybersecurity policy and law enforcement front,

  • Cyberscoop reports,
    • “The Department of Homeland Security is bringing back a key cybersecurity information sharing effort with critical infrastructure, more than a year after the Trump administration shuttered an existing nerve center between government and private sector.
    • “The Alliance of National Councils for Homeland Operational Resilience – Critical Infrastructure program, first reported by CyberScoop in January, is meant to replace the function of the Critical Infrastructure Partnership Advisory Council.
    • “CIPAC was a federal advisory body that allowed agencies like the FBI, the Cybersecurity and Infrastructure Security Agency and the intelligence community to interact with key owners and operators of water, power, internet and telecommunications to coordinate on cyberattacks and digital vulnerabilities. ANCHOR will fulfill a similar role.
    • “ANCHOR-CI will provide forums through which cybersecurity, law enforcement, intelligence, national security, and other government representatives at the federal, state, local, tribal, and territorial levels may engage representatives of private sector entities and critical infrastructure owners and operators in reviewing the current threat environment, discussing potential vulnerabilities, and forming recommendations on securing a more resilient critical infrastructure and cyberspace,” DHS wrote in a federal register notice set to publish July 1.
    • “ANCHOR-CI will be managed by CISA, which will appoint members to the council from industry, trade associations, state and local governments and other sources.
    • “The body will consist of four types of different councils: one focused on federally designated critical infrastructure sectors, cross-sector councils to deal with emerging threats like cyber attacks or zero-day vulnerabilities, critical infrastructure industry councils and regional coordinating councils.”
  • and
    • “Trump administration budget chief Russell Vought told lawmakers Tuesday that he’s willing to work with Department of Homeland Security Secretary Markwayne Mullin on re-staffing up the Cybersecurity and Infrastructure Security Agency, following deep personnel cuts and further proposed reductions in the fiscal 2027 budget blueprint.
    • “Mullin said last week at a House Appropriations Subcommittee on Homeland Security hearing that he would like to hire 600 more people at CISA, similar to remarks he made earlier this month at another House hearing. President Donald Trump has cut or lost more than 1,000 from an agency that stood around 3,400-strong at the end of the Biden administration — cuts criticized by lawmakers in both parties.”
  • Federal News Network relates,
    • “The National Institute of Standards and Technology expects to advance high profile standards work around a “Cyber AI Profile” and securing artificial intelligence agents this summer, amid a flurry of federal activity aimed at addressing both the risks and opportunities for AI and cybersecurity.
    • “NIST’s National Cybersecurity Center of Excellence (NCCoE) is now running six distinct projects focused on the intersection of AI and cyber. But Cherilyn Pascoe, director of the NCCoE, said AI is popping up across the center’s work, which focuses on practical guidance to advance secure technologies in collaboration with government agencies, industry and academia.
    • “I think AI is going to be part, if not a leading part, of every project going forward at the center,” Pascoe said in an interview. “It is becoming so foundational to cybersecurity.”
    • “Recent advancements in AI models like Anthropic’s Claude Mythos have shown the ability to quickly find software vulnerabilities and create cyber exploits much faster than humans.”
  • Security Week tells us,
    • “Google, the FBI, and other organizations coordinated in a joint effort to dismantle NetNut, a massive residential proxy network.
    • “Also known as Popa, NetNut is believed to consist of more than 2 million Android devices such as smart TVs and streaming boxes, that have been infected through trojanized applications and malware such as Badbox 2.0.
    • ‘The network’s operator, linked to the publicly-traded Israeli firm Alarum Technologies Ltd, rented the residential proxies to various threat actors, including cybercriminal and espionage groups.
    • “In a single week in June, Google observed 316 distinct threat clusters using NetNut to hide their locations in password-spray attacks and to access victim environments.
    • “We believe our coordinated actions have caused significant degradation to NetNut’s proxy network and its business operations, reducing the available pool of devices for the proxy operator by millions,” Google said.
    • “As part of the operation, the internet giant disabled Google accounts and associated services used for command-and-control (C&C), dismantling the botnet’s backend infrastructure.”
  • Cyberscoop informs us,
    • “19-year-old alleged member of the Scattered Spider extortion crew was extradited to the United States last week and remains in federal custody awaiting several cybercrime charges, the Justice Department said Wednesday. 
    • “Peter Stokes, a dual citizen of the United States and Estonia, was allegedly involved in Scattered Spider since it formed in 2022 and boasted on social media about the luxurious globetrotting life he enjoyed while he was still a child. 
    • “The cybercrime ring of young, native English-speaking people has infiltrated more than 100 businesses since 2022, and extorted more than $100 million from its victims around the world, officials said.” 

From the cybersecurity breaches and vulnerabilities front,

  • HIPAA Journal reports,
    • “Verizon Business has released the findings from its inaugural Breach Impact Study, which focuses on the financial impact of data breaches. The BIS report is from the same authoring team as the Verizon Data Breach Investigations Report and was produced in partnership with CyberAcuView. The report is based on an analysis of around 70,000 U.S. cyber insurance claims, including 38,000 claims where the policies paid out. The data spans from January 2019 to October 2025.
    • “In contrast to many data breach cost reports, the report is based on median claim amounts rather than averages, which are susceptible to skewing. In 2019, the median financial impact was around $60,000, rising by 80% to $110,000 in 2025, with data breach costs outpacing inflation, which was around 23% over the period of the study. More than half of paid-out claims exceeded $83,000, with 10% having an impact of $920,000 or more. The most extreme 2.5% of cases exceeded $5 million in losses.
    • “The report shows that data breach costs almost doubled between 2019 and 2025, with business interruption the single largest loss driver, followed by loss to threat actor and response and recovery.”
  • MedTech Dive relates,
    • “Medtronic has begun to notify people who may have been affected by a cyberattack that was disclosed more than two months ago.
    • “Medtronic provided the update in a statement posted to its website on Monday [June 29, 2026]. At this time, Medtronic has no evidence the data that was accessed has been publicly posted or exposed to the internet, according to the statement.
    • “The company is providing 24 months of complimentary credit monitoring, dark web monitoring and identity theft restoration services. It is also setting up a dedicated call center to address questions for those affected.”
  • Bleeping Computer tells us,
    • “The Department of Homeland Security is investigating a cyberattack that compromised the Homeland Security Information Network (HSIN), a sensitive information-sharing platform used by federal, state, local, and private-sector partners.
    • “The intrusion, first reported by Nextgov, was carried out by an unknown threat actor in recent weeks and is believed to have occurred sometime between late May and early June, according to two people familiar with the matter who spoke on the condition of anonymity.
    • “DHS is currently investigating the attack and has reportedly not attributed it to any specific threat actor or foreign governments. Whether any documents were stolen from the system also remains unclear.”
  • Cyberscoop informs us,
    • “Toolkits to wage phishing campaigns are a now-venerable instrument for cybercriminals, but researchers recently turned up details on something like a full-fledged “business email compromise-as-a-service” platform.
    • “Cisco Talos said Wednesday that it had found an operator panel dubbed ARToken, which shares infrastructure and other things in common with, and as an affiliate to, the EvilTokens phishing-as-a-service operation built to bypass multi-factor authentication and compromise Microsoft 365 accounts. EvilTokens has reportedly seen a dramatic increase in its phishing attacks — by 1,380% early this year compared to the same period last year — with an assist from artificial intelligence integration.
    • “ARToken is notable, though, for the capabilities that go beyond what’s been made public about EvilTokens so far by companies like Sekoia and Microsoft itself, such as inbox rule manipulation and shared access links.
    • “These features indicate the platform is more mature than a simple device code phishing kit — it is a complete BEC operations environment,” wrote Michael Kelley, security research engineer at Cisco Talos, in a blog post, referring to business email compromise scams that involve sending fake emails to solicit fraudulent payments.”
  • and
    • “Citrix published a security bulletin Tuesday [June 30] disclosing six vulnerabilities in NetScaler ADC and NetScaler Gateway appliances, including a high-severity memory disclosure flaw that researchers say belongs to a vulnerability class first identified in the 2023 incident known as CitrixBleed.
    • “The company rated the overall bulletin severity as high and assigned CVSS scores ranging from 6.9 to 8.8 across the six CVEs. Citrix said customers should install the updated builds and, in one case, manually adjust a configuration parameter even after patching.
    • “The most closely scrutinized of the vulnerabilities, CVE-2026-8451, was discovered by researchers at watchTowr, a cybersecurity firm that has published several prior analyses of issues in NetScaler products. According to a technical writeup the firm released alongside Tuesday’s disclosure, the vulnerability stems from how NetScaler parses SAML authentication requests when an appliance is configured as a SAML identity provider, a deployment mode commonly used for single sign-on.”
  • CISA added two known exploited exploits (KVE) to its catalog this week.
  • Bleeping Computer adds,
    • “CISA confirmed on Monday that ransomware gangs have begun exploiting a high-severity Microsoft Defender privilege escalation vulnerability that has previously been abused in zero-day attacks.
    • “Dubbed BlueHammer, the security flaw (CVE-2026-33825) was leaked by a security researcher known as “Nightmare Eclipse” in early April, together with proof-of-concept exploit code, in protest at how the Microsoft Security Response Center (MSRC) handles the disclosure process.
    • “Insufficient granularity of access control in Microsoft Defender allows an authorized attacker to elevate privileges locally,” Microsoft explains in a security advisory.”
  • Dark Reading notes,
    • “NIST has reduced the number of CVEs receiving enrichment in the National Vulnerability Database since April due to a growing backlog, impacting the data available to security teams.
    • “Research from Volerion found that, between April 15 and June 15, only 6,759 out of 13,441 non-rejected CVEs published to the NVD received NIST enrichment, causing coverage gaps, delayed analysis, and reliance on inconsistent CVSS scores provided by over 500 CVE Numbering Authorities (CNAs).
    • “Volerion’s analysis identified issues with timeliness, enrichment quality, and scoring discrepancies—especially in critical metrics such as attack complexity—potentially causing organizations to misjudge vulnerability severity and prioritize incorrectly.
    • “The report urges organizations not to rely solely on NIST or CNA CVSS scores for risk assessment, recommending the use of diverse metrics and independent analysis for more accurate prioritization.”
  • Security Week points out,
    • “Cisco confirmed that a recently patched vulnerability in its Unified Communications Manager (Unified CM) and Unified Communications Manager Session Management Edition (Unified CM SME) has been exploited in the wild.
    • “Tracked as CVE-2026-20230 (CVSS score of 8.6), the security defect is described as the improper validation of specific HTTP requests, which could allow attackers to mount SSRF attacks.
    • “Successful exploitation of the bug could lead to arbitrary files being dropped to the underlying operating system, which could then be used to gain root access.
    • “Only appliances with the WebDialer service enabled are vulnerable, Cisco says. The service is disabled by default.”
  • Cybersecurity Dive adds,
    • “Researchers say a critical vulnerability in Oracle E-Business Suite is facing exploitation attempts by a threat actor. 
    • “The vulnerability, tracked as CVE-2026-46817, is a flaw in the Oracle Payments, and has a severity score of 9.8. 
    • “If successfully exploited, an unauthenticated attacker with network access via HTTP would be able to compromise the product. 
    • “Researchers at Defused observed a hacker exploiting the flaw on its Oracle E-Business honeypots, according to a post on X. The activity was observed on June 27 from a French IP address, but researchers said the threat actor was using a VPN. 
    • “There has been no prior known exploitation activity or any release of a proof of concept, researchers said.” * * *
    • “Oracle previously addressed the vulnerability as part of a larger series of security patch updates in May.”

From the ransomware front,

  • Dark Reading reports,
    • The initial access broker (IAB) operation behind the credential-harvesting FortiBleed campaign is working in concert with ransomware actors, indicating the victims of the massive operation are now facing an even greater threat.
    • Research published by SOCRadar this week connects FortiBleed actors with two ransomware-as-a-service (RaaS) gangs, Inc Ransom and Lynx. SOCRadar researchers discovered an operator behind the campaign’s infrastructure that was actively logged into the ransom negotiation panels for both groups, and “engaging directly with ransom demands.”
    • “Finding a single operator working both panels, using infrastructure traceable back to FortiBleed, is the clearest evidence yet that FortiGate credentials harvested through this campaign are being handed off, or used directly, for ransomware deployment,” according to the SOCRadar blog post
    • “The connection to ransomware gangs marks the latest development in this saga. The attacks against insecure Fortinet FortiGate firewalls were initially discovered last month by security consultant Volodymyr “Bob” Diachenko. SOCRadar then later found that the attacks were part of a global campaign it dubbed “FortiBleed,” which had compromised thousands of devices and used a Golang-based sniffer to turn firewalls into credential stealers.”
  • and
    • “An emerging ransomware campaign is targeting small businesses across multiple regions with fake Interpol notices designed to trick victims into downloading malware disguised as evidence of alleged criminal activity.
    • “The campaign has so far has targeted businesses in multiple sectors, including pharmaceuticals, food, agriculture, technology, media, and legal services in the US, Europe, Asia, and the Middle East.
    • “Besides its focus on small businesses, the campaign is notable because it highlights how attackers no longer need sophisticated ransomware or the resources of a major cybercrime operation to launch disruptive attacks, Bitdefender said in a report this week. “Even relatively simple malware can become a serious threat when paired with convincing social engineering,” Bitdefender security analyst Alina Bizga wrote.”
  • The Hacker News relates,
    • “Security firm Sysdig says it has found what it believes is the first ransomware attack run from start to finish by an AI agent.
    • “Its Threat Research Team calls the operator JADEPUFFER and says a large language model handled the whole job: breaking in, stealing credentials, moving deeper into the network, then encrypting and wiping a company’s production database.
    • “Ransomware has always needed a skilled person somewhere in the loop, either at the keyboard or writing the script the malware follows. If a model can chain those steps on its own, the skill needed to run an attack drops to whatever it costs to rent an AI agent.”
    • “The way in was an old, already-patched bug. JADEPUFFER exploited CVE-2025-3248, a missing-authentication flaw in Langflow, an open-source tool for building AI apps and agent workflows. The flaw lets anyone who can reach the server run their own Python code on it, no login needed.” * * *
    • “The fixes are familiar. Patch Langflow and never expose its code-running endpoints to the internet. Do not run AI tools with cloud keys and provider credentials sitting in their environment; keep secrets in a proper manager, away from anything the web can reach.
    • “Harden Nacos: change the default signing key, keep it off the public internet, and never let it connect to its database as root. Never expose a database’s admin account to the internet, and lock down outbound traffic so a hacked server cannot phone home.”
  • Cyberscoop explains,
    • “How ransomware syndicates weaponize corporate-style organization
      • “From outsourced labor to tiered pricing models, an inside look at how today’s top ransomware threats operate less like rogue hackers and more like Fortune 500 companies.”
  • Cybersecurity Dive informs us,
    • “A massive credential-harvesting campaign, dubbed FortiBleed, is linked to two ransomware-as-a-service operations, tracked as INC ransom and Lynx, according to a blog post Wednesday [July 2, 2026] by cybersecurity firm SOCRadar. 
    • An operator with access to FortiBleed infrastructure was found to be logged into negotiation panels for INC as well as Lynx, researchers said. 
    • In certain cases, the attacks may have involved exploitation of a vulnerability in a content collaboration platform called Nextcloud. The analysis is still ongoing, so a public advisory or common vulnerabilities and exposures number has not yet been assigned. 
    • “The Nextcloud issue appears to have been used as part of the attackers’ broader operational workflow, likely for expansion or infrastructure access after initial compromise,” Ensar Seker, CISO at SOCRadar, told Cybersecurity Dive.
    • “Not all cases involved Nextcloud, nor was compromise fully dependent on exploitation of the zero day.” 

From the cybersecurity business and defenses front,

  • The Wall Street Journal reports,
    • “Chinese artificial-intelligence systems have matched the performance of Anthropic’s powerful model Mythos in some cybersecurity scenarios, a development poised to reset the global tech race and pressure the White House in its overhaul of U.S. AI policy.
    • “Security researchers said that a new AI model, released this month by China’s Zhipu AI, also known as Z.ai, can match the latest U.S. models when it comes to finding security bugs, although it still lags behind Anthropic’s and OpenAI’s products in other tasks.
    • “Overall, the capability gap between top U.S. models and those built by Chinese companies has narrowed significantly, and use of Chinese AI systems has surged as businesses seek to rein in runaway costs. A host of companies, including Microsoft, are weighing how they can offer Chinese models on their platforms, a development that is set to alter the balance of power among tech companies.
    • “China is making sure that the gap becomes smaller and smaller over time,” said Lior Div, chief executive officer of the cybersecurity company 7AI.”
  • Dark Reading relates,
    • “Red Hat and its parent IBM have committed an eye-popping $5 billion to Project Lightwell, a new subscription-based patching service for enterprises running business-critical systems that can’t risk the disruption of updating open-source software in production. It is the largest known commitment specifically targeting open-source software supply chain security — dwarfed only by Google’s broader $10 billion cybersecurity pledge in 2021, which also covered zero-trust and workforce training.”
  • and
    • “Apple is changing its approach to security patching, in response to the growing threat of accelerated artificial intelligence (AI) attacks.
    • “The company has historically saved big, bundled sets of bug fixes for new versions of its operating system (OS). That’s set to change. The company released a variety of security updates June 29 for iPhones, iPads, Macbooks, and the Safari browser, untethered to any major version releases. It’s hardly the first time it’s released security updates out-of-band, but the motivation was different this time. According to Reuters, the company said “it was adapting to the reality that, given the ability of artificial intelligence to speed the development of malicious hacking tools, it ⁠needed to reduce the time between when updates were first made public and when they were put into customers’ hands.”
  • Tech Target discusses “The agentic AI ‘lethal trifecta’: What CISOs should know.”
    • “The very capabilities that make an AI agent useful also make it dangerous. Here’s what CISOs should know about the agentic AI lethal trifecta, and what they should do about it.”
  • Security Week explains “How to Conduct a Successful Audit of AI-Driven Software Development.”
    • “As AI-generated code becomes commonplace, CISOs need new audit strategies to measure developer practices, govern AI tool usage, and identify software risks before they reach production.”
  • Here’s a link to Dark Reading’s CISO Corner.

Cybersecurity Saturday

From the Project Glasswing front,

  • CNBC reports,
    • “A U.S. official told The Associated Press on Tuesday [June 23] that one of Anthropic’s artificial intelligence models had identified vulnerabilities in highly sensitive and secure U.S. government computer systems during a testing exercise.
    • “The official, who spoke on the condition of anonymity to discuss the matter, said Anthropic had teamed up with U.S. intelligence agencies to conduct tests using the company’s Mythos model. It had identified certain vulnerabilities within hours, but that does not mean the model was able to exploit them within that time, the official said.
    • “The official said the testing was done through an Anthropic initiative called Project Glasswing, which brought together tech giants and other companies in hopes of securing the world’s critical software from “severe” fallout that the Mythos model could pose to public safety, national security and the economy.”
  • NextGov/FCW relates,
    • “OpenAI is offering a limited preview of its new GPT-5.6 model series to select partners, part of an “ongoing engagement with the U.S. government” as Washington and leading artificial intelligence developers try to strike a balance between tech innovation and safety.
    • Three models in the company’s GPT-5.6 series — Sol, Terra and Luna — will initially be available to select partners following conversations and previews with government officials, OpenAI said in its Friday [June 26] announcement
    • “That initially limited rollout follows a request made by the federal government. During the narrow preview period, OpenAI will test model capabilities and coordinate with collaborating partners before making it more broadly available. General access to the models will be available “in the coming weeks,” a similar structure to Anthropic’s Project Glasswing that was set up to test its Mythos Preview model.
    • “OpenAI made it clear that it primarily believes in broad, open access to AI models and that limited previews for government partners are short-term.” * * *
    • “OpenAI’s announcement follows Trump’s signing of an executive order earlier this month that calls for leading AI developers to share model access before market release for safety analyses. Signed following last-minute industry pushback regarding overregulation concerns, the order and OpenAI’s choice to voluntarily share its new model with the government signal the priority the White House is placing on AI safety despite trying to thread the needle between a light-tough regulatory posture and ensuring companies are unencumbered enough to innovate.”
  • The Wall Street Journal informs us,
    • “The Trump administration is allowing Anthropic to reoffer one of its banned AI models to trusted companies and government partners, a key step toward rolling back restrictions that fueled industry concern about ad hoc federal regulation of artificial intelligence.
    • “Anthropic can allow dozens of companies and partners trusted by the government to access Mythos 5, one of the two models that the administration banned for foreign use two weeks ago, Commerce Secretary Howard Lutnick said in a Friday letter to Anthropic Chief Compute Officer Tom Brown, a copy of which was viewed by The Wall Street Journal. 
    • “Fable 5, a general-purpose version of Anthropic’s powerful Mythos model that was also banned, remains restricted, and restrictions on Mythos 5 still apply to entities that aren’t trusted partners.
    • “The olive branch from the administration is the result of two weeks of talks led by Lutnick and Brown to address the government’s security concerns, which were sparked by Amazon researchers who found a way to evade Fable’s safeguards.” * * *
    • “An Anthropic spokesman said the company was working to restore access to Mythos 5 for the partners as soon as possible. “We are pleased to see this progress and continue to work with the government to expand access to Mythos 5 and make Fable 5 available for general use again,” he said.” 

From the cybersecurity policy and law enforcement front,

  • Cybersecurity Dive reports,
    • “President Donald Trump on Monday [June 22] set ambitious deadlines for how quickly federal agencies and government contractors must adopt quantum-resistant encryption algorithms, aiming to prevent U.S. adversaries from using quantum computers to decrypt sensitive data in the coming decades.
    • “The United States must take steps to strengthen cryptographic protections for the Nation’s sensitive data, critical infrastructure, and digital economy,” Trump said in a new executive order.
    • “The directive requires the Office of Management and Budget to issue guidance setting two major deadlines for agencies’ adoption of post-quantum cryptography (PQC) in their high-value assets: Dec. 31, 2030, for key establishment, and Dec. 31, 2031, for digital signatures.”
    • “By accelerating the U.S. Government’s PQC migration timeline, this Order ensures that American cybersecurity keeps pace with emerging technology and recognizes the reality of the accelerating quantum industry,” the White House said in a fact sheet about the new order.”
  • Dark Reading adds,
    • “Organizations will face major challenges — and even greater costs — on the road to becoming quantum-ready over the next five years.” * * *
    • “Jonathan Nguyen-Duy, chief technology officer (CTO) at quantum security vendor Arqit, tells Dark Reading that many organizations underestimate the scale of this challenge, viewing post-quantum migration as a technology upgrade.
    • “Cryptography sits everywhere from applications, networks, cloud environments, and software libraries to connected devices and third-party systems,” he says. “That’s why post-quantum migration is much more than swapping one algorithm for another. Every update needs to be tested and implemented without disrupting the business. It requires long-term funding, cross-functional ownership and a level of persistence that many organizations will find challenging.”
    • “Garfield Jones, SVP of research and strategy at post-quantum cryptography vendor QuSecure, says that many agencies are in the inventorying stage, and some have designated PQC leads. “But substantial work remains on implementation and testing of NIST standardized algorithms within agency environments,” he explains. “Smaller agencies may be able to meet these accelerated deadlines, but larger and federated agencies face a more difficult path as previously unaccounted IT and OT assets continue to surface through manual counting processes.”
  • The American Hospital Association News relates,
    • “Leaders of the Five Eyes cybersecurity agencies, consisting of Australia, Canada, New Zealand, the United Kingdom and the United States, released a joint statement June 22 urging resilience as the evolution of artificial intelligence has been rapidly transforming cyber risk. The alert recommends leaders and organizations to understand and assess risk, readiness and accountability; prioritize foundational cybersecurity practices and controls; empower leaders with authority and resources; and remain engaged as threats and guidance evolve. The agencies recommended additional actions to reduce operational, financial and reputational exposure. Specific tactical recommendations include reducing attack surface, accelerating patching processes, addressing legacy systems, reviewing and strengthening identity and access controls, and preparing for incidents before they happen. 
    • “This important advisory from leaders of the world’s most trusted domestic and international cybersecurity agencies amounts to a clear and stark warning for the private sector,” said John Riggi, AHA national advisor for cybersecurity and risk. “Cyber adversaries are using AI to increase the speed, sophistication and severity of cyberattacks. Within months, not years, the rapid development of frontier AI models will accelerate cyber risk. It is recommended that organizations treat cyber risk as an enterprise risk, use AI to bolster network defenses, and mitigate potential risk to patient care and safety by preparing in-depth cyber resiliency and extended clinical continuity plans. It is especially important for hospitals and health systems to prioritize cyber resiliency for mission-critical and life-critical services.” 
       
  • Homeland Security Today informs us,
    • “The Cybersecurity and Infrastructure Security Agency (CISA) published a guide [on June 24] that helps federal civilian agencies advance their zero trust capabilities and adopt modern architectures supported under the Trusted Internet Connections (TIC) 3.0 Initiative. Part of CISA’s Journey to Zero Trust seriesthis guide helps agencies transition away from the limitations of using TIC 2.0 and capitalize on TIC 3.0 flexibilities to employ Secure Access Service Edge (SASE) solutions. Federal agencies will better understand, plan and mature to zero trust architecture to improve user experience, increase visibility and control, and enable telemetry sharing with CISA services.
    • “Many legacy architectures rely on perimeter-based security models such as TIC 2.0 that routes all traffic through centralized controls. Today’s rapidly evolving threat landscape and organizations’ shift to more distributed business models with cloud capabilities and remote workforces reveal shortcomings in legacy perimeter-based paradigms. Based on CISA’s work with federal agencies, this guide helps technical leaders and enterprise architects implement a SASE solution to replace their existing managed trusted internet protocol services (MTIPS) connectivity. The transformation to SASE solution improves network performance, reduces latency, and increases visibility and control.”
  • Per a General Accounting Office news release,
    • “Cloud computing services allow access to resources like networks, storage, and software. It can cost federal agencies less to use these services than to create their own. But using cloud computing services can pose cybersecurity risks.
    • “We looked at how some agencies protect data in the cloud. Agencies we reviewed varied in implementing key cloud computing security practices. For example, some agencies didn’t fully continuously monitor security controls. Also, some agencies didn’t document how to respond to or recover from cybersecurity incidents.
    • “Our recommendations address these issues and more to ensure cloud services are safe.”
  • Security Week points out,
    • “The National Institute of Standards and Technology (NIST) announced Wednesday that it’s seeking public feedback on updated Internet of Things (IoT) security guidelines.
    • “Updated to reflect current security needs, the guidance provides general considerations on the impact of IoT products on risk assessments and aims to establish cybersecurity requirements to support security controls.
    • “The initial public draft (IPD) of SP 800-213 Revision 1, titled ‘IoT Product Cybersecurity Guidelines for the Federal Government: Establishing IoT Product Cybersecurity Requirements’, is available for download on NIST’s website (PDF), with the public comment period ending August 24.
    • “As organizations increasingly rely on IoT products, they need to understand that these products are system elements and must be taken into account in the risk management process, NIST argues.
    • “The updated guidelines build on SP 800-213A, which provides a catalog of IoT product cybersecurity capabilities and non-technical capabilities for both manufacturers and consumers.”
  • Cybersecurity Dive notes,
    • “Microsoft on Wednesday announced a coordinated operation with Europol and other international partners to disrupt Amadey and StealC — tools used as infostealers to conduct ransomware, financial fraud and other digital crimes. 
    • “Amadey is a specialized tool used by cybercriminals to infect computers, while StealC is used to steal passwords and other sensitive data after the computers are infected. The tools are used widely around the globe, with Microsoft finding more than 140,000 computers worldwide infected with the tools during the first two weeks of May. 
    • “Microsoft identified more than 200 malicious Amadey and StealC command-and-control domains and IPs and shut them down using a combination of court-ordered actions, domain seizures and related actions. 
    • “In a filing with the U.S. District Court in Miami, Microsoft accused a series of unnamed defendants of operating a malware-as-a-service enterprise. Microsoft asked the court to disable and transfer control of related internet domains to the company. 
    • “Microsoft, in a blog post Wednesday, said investigators used AI to help analyze how Amadey and StealC were being used in the infostealing operation.” 

From the cybersecurity breaches and vulnerabilities front,

  • HealthExec reports,
    • “Last week, HealthExec reported on a data breach at a healthcare AI company that resulted in personal data from its hospital and payer clients being exposed to hackers. This week, a filing with the federal government provided details on how many patients were impacted. 
    • “According to the U.S. Department of Health and Human Services’ (HHS) Office of Civil Rights healthcare data breach tracker, the number of individuals impacted by the hack on Xsolis was determined to be 1,396,519.
    • “Stolen data was determined to include protected health information, including details on medical treatments that patients received. Names, dates of birth, contacts, Social Security numbers and health insurance information were also compromised. 
    • “Xsolis, a company that uses artificial intelligence to improve patient care utilization, posted a notice earlier this month that contained many of the details of the data security incident, said to have stemmed from a “targeted phishing attack” that resulted in an unauthorized third party accessing its network.” 
  • Cybersecurity Dive relates,
    • “Klue, a provider of a market intelligence platform, is investigating a supply chain attack that led to the mass exfiltration of Salesforce customer relationship management data belonging to hundreds of customers, including several prominent cybersecurity firms. 
    • “A threat actor used a compromised Klue Battlecards app to gain access to OAuth tokens for connecting Klue with third-party integrations, including Salesforce, according to information from Klue and security researchers at Reliaquest, which warned about the attack in a recent blog post. 
    • “Salesforce, which disabled connections through the Klue Battlecards appuntil further notice, said there is no indication of a vulnerability within its own platform. 
    • “A threat actor tracked as Icarus posted stolen data from several victims on its website, according to a Monday [June 22] blog post from Huntress. Itself a victim of the attack, Huntress said none of its internal systems were impacted.
    • “The threat group has begun reaching out to companies whose customer data was compromised in the attack, said Charles Carmakal, CTO at Mandiant Consulting.” 
  • Bleeping Computer tells us,
    • “The FBI and CISA are warning that a phishing campaign targeting Signal users tied to Russian intelligence services has evolved to steal Signal Backup Recovery Keys, allowing attackers to access victims’ historical messages.
    • “The updated public service announcement is an update to a March 2026 advisory that warned the threat actors were targeting users of commercial messaging applications, particularly Signal, through phishing campaigns designed to hijack accounts rather than break end-to-end encryption.
    • “RIS cyber threat actors continue to masquerade as automated CMA support accounts in updated phishing messages but have evolved their tactics to attempt to elicit victims’ Backup Recovery Keys,” warns an FBI PSA published today [June 26].
  • CISA added six known exploited vulnerabilities (KVEs) to its catalog this week.
    • June 23, 2026
      • CVE-2025-67038 Lantronix EDS5000 Code Injection Vulnerability
      • CVE-2026-34908 Ubiquiti UniFi OS Improper Access Control Vulnerability
      • CVE-2026-34909 Ubiquiti UniFi OS Path Traversal Vulnerability
      • CVE-2026-34910 Ubiquiti UniFi OS Improper Input Validation Vulnerability
        • The Hacker News discusses these KVEs all of which required patching within three days.
    • June 25, 2026
      • CVE-2026-12569 PTC Windchill and FlexPLM Improper Input Validation Vulnerability
      • CVE-2026-20230 Cisco Unified Communications Manager Server-Side Request Forgery (SSRF) Vulnerability
        • Bleeping Computer discusses these KVEs. CISA set the same June 28 deadline for federal agencies to patch both KVEs.
  • Cyberscoop adds,
    • “An attacker exploited a previously unknown and unpatched Cisco vulnerability earlier this year to infiltrate a communications service provider and gain the highest level of access possible, Mandiant said Wednesday [June 24].
    • “Cisco has since patched the flaw, one of seven actively exploited zero-day vulnerabilities this year in its SD-WAN (software-defined wide area network) software used to manage internet traffic within organizations, typically those that are widely distributed, such as banks with numerous branches.
    • “But Google-owned cybersecurity firm Mandiant said the attacker (or attackers) could have used its root-level access to obtain broad and undetected visibility into the internal traffic throughout the provider’s entire corporate network. In a caveat, Mandiant also said it could not fully assess how far the compromise actually went because of how cleverly the perpetrators hid their activity.
    • “The attack illustrated hackers’ ongoing targeting of edge devices, Mandiant said. Attacks on such devices have been very common and involved in some of the most consequential breaches in recent years, prompting the Cybersecurity and Infrastructure Agency to direct federal agencies to give them special attention this year.
  • Cyberscoop observes,
    • “When CISA issues an emergency directive, the message to every federal agency and every security team paying attention is to patch now. For CVE-2026-50751, a CVSS 9.3 authentication bypass in Check Point Remote Access VPN, that directive landed on June 21. despite exploitation beginning in early May. That, six-week active intrusion gap is not a footnote. It is the entire story.
    • “The flaw itself is straightforward in the worst possible way. A logic error in the certificate-validation process, triggered when the deprecated IKEv1 key-exchange protocol is enabled, allows a remote attacker to establish a fully authenticated VPN session without a valid password. No phishing. No credential theft. No lateral movement required to reach the perimeter. The attacker walks through the front door, and the door logs it as a legitimate entry.
    • “By the time Check Point disclosed the vulnerability on June 8, a Qilin ransomware. affiliate had already used it to compromise a few dozen organizations worldwide. The post-access playbook was efficient, including Rclone for data exfiltration, the Tox protocol for command-and-control communication routed through disposable VPS infrastructure. Quiet, fast, and designed to complete the job before detection had a chance to matter.” * * *
    • “CISA will issue another emergency directive. There will be another authentication bypass, another perimeter device turned attack vector, another financially motivated threat actor with a head start measured in weeks. The patch-and-detect cycle will play out again, and organizations that had their exposure managed entirely at the perimeter will find themselves in the same position.
    • “The lesson here is not that Check Point failed or that VPNs are over. It is that any architecture where a single authentication bypass gives an attacker operating authority over the entire environment has a structural problem that no patch resolves. Closing the door is necessary. Making sure the ransomware cannot detonate even after the attacker is inside is the part the industry still has not solved at scale.
    • “That is the conversation the CISA directive should be starting, and mostly is not.”
  • Security Week points out,
    • “Researchers at Wiz have disclosed a high-severity vulnerability in the Amazon Q Developer extension for Visual Studio Code that could allow attackers to steal developers’ cloud credentials by luring them into opening a booby-trapped code repository.
    • “Amazon Q Developer is an AI-powered coding assistant that offers developers features such as code suggestions, automated refactoring, and access to external tools and services via integrations with local processes.
    • “AWS was notified about the issue on April 20 and a patch was released on May 12. The cloud giant published a security advisory this week.
    • “The root cause of the vulnerability was that the extension would automatically act on configuration files embedded in a workspace without first asking the user for permission.

From the ransomware front,

  • Cybersecurity Dive reports,
    • “The number of ransomware attacks that hackers claimed on dark-web leak sites rose by nearly one-fifth in 2025, to 6,883, while the total number of leak sites increased by roughly one-third, to 115, the security firm Bitsight said in its annual “State of the Underground” report.
    • “Ten groups — five of them associated with Russia — were responsible for roughly 58% of attacks, according to the report, suggesting a remarkable concentration of activity.
    • “Roughly 60% of ransomware victims were in the U.S., with the manufacturing sector topping the list.”
  • Dark Reading adds,
    • “A specter is haunting Europe — the specter of ransomware.
    • “After a global lull in 2024 and 2025, the ransomware-as-a-service (RaaS) ecosystem appears to be back to form, at least in Europe. Researchers from Black Kite tracked 684 ransomware attacks across the continent through the first four months of 2026. That’s 55% more than the 441 recorded in the first four months of 2025, even more than the 643 recorded through the first half of 2025.
    • “Globally, the US absorbs almost half of all ransomware victims. Canada and the UK have traded second place. Europe was a step behind. Now that’s shifting,” Ferhat Dikbiyik, chief research and intelligence officer at Black Kite, tells Dark Reading. He believes that at least a couple of factors are at play. 
    • “First, an oversaturation of ransomware activity in the US is leading some to seek opportunities elsewhere. And “second, and this is my read: [Attackers’] own artificial intelligence (AI)-assisted target research is starting to point them at Europe,” he says. “The stealer logs are there. The unpatched vulnerabilities are there. The money is there. Smaller countries may run weaker defenses, but the big economies offer the full package: wealth and exposure together. The question isn’t why ransomware groups target the major EU powers; it’s why would you not?”
  • HelpNetSecurity tells us,
    • “A relatively new backdoor called Mistic has been deployed in multiple attacks since April 2026 targeting organizations in the insurance, education, IT, and professional services sectors, according to Symantec.
    • “The malware appears to be associated with Woodgnat, also known as KongTuke, a financially motivated initial access broker (IAB) active since at least May 2024 that has been connected to ransomware operations including QilinInterlock, Rhysida, Akira8Base, and Black Basta.
    • “Woodgnat reportedly functions primarily as an IAB. Its goal is not to deliver the final payload, but to establish highly durable remote access within an enterprise and sell this high-level access to ransomware affiliates and other attackers for a fee,” the researchers said.”
  • CSO Online shares an “Anatomy of a retail ransomware attack: Tabletop simulates modern mayhem methods.”

From the cybersecurity business and defenses front,

  • Cybersecurity Dive reports
    • “A coalition of technology companies, including Anthropic, AWS, IBM and Microsoft, announced a joint effort to find, disclose and remediate security flaws in open-source software. 
    • “The group, called Akrites, will establish a shared security incident response team as well as a coordinated vulnerability disclosure process.
    • “The founding members, led by the Linux Foundation, will commit extensive resources to the effort, including funding, engineers and cybersecurity expertise. 
    • “Officials said the plan was mainly driven by the emergence of frontier AI models that radically accelerated the ability to discover vulnerabilities in critical software applications. In recent months, malicious actors have demonstrated the ability to weaponize AI for use in sophisticated attacks.” 
  • and
    • “AWS launched agentic tools AWS Continuum, which flags and helps remediate security risks, and AWS Context, a search layer that uses a company’s data to make better informed agents, at its AWS Summit in New York City on June 17.
    • “The company rolled out the tools as the rise in AI agents is rapidly changing the way enterprises operate, reshaping the cybersecurity landscape and necessitating tools that connect siloed data.
    • “AWS rolled out new capabilities for AI tools Kiro, AWS DevOps Agent, AWS Transform for modernization and Amazon Bedrock AgentCore to build and deploy agents. It also updated Amazon Quick, an agentic assistant-modeled AI application, which was released as Quick Suite last year.”
  • Dark Reading adds,
    • “In 2025, nearly 3 in 10 security professionals thought that fully autonomous AI systems could satisfy their companies’ security-testing needs. But after a year of testing and experimentation, that optimism has largely gone away.
    • “Instead, chief information security officers (CISOs) and other security practitioners have more realistic expectations of the AI-based systems, which often have significant blind spots, are prone to false positives, and can blow through AI budgets, according to a June 25 report released by Cobalt, a penetration-testing-as-a-service firm. The number of organizations willing to rely on AI-powered penetration testing for their security needs fell to 9% in 2026, down from 29% a year earlier. The vast majority of companies preferred a hybrid, human-in-the-loop approach or relegating only non-critical tasks to automation.
    • “Security practitioners are experimenting to find the sweet spot of what can be automated reliably and responsibly, says Gunter Ollmann, chief technology officer for Cobalt.”
  • HIPAA Journal informs us,
    • “Cybersecurity risk is growing, and healthcare organizations are struggling to defend a rapidly increasing attack surface. AI tools are being implemented without the secure infrastructure to support them. Most healthcare practices have meaningful gaps in cyberattack recovery readiness, face ongoing and regular third-party vendor disruptions, and there is growing concern that a cyberattack will result in a patient fatality. The current state of cybersecurity in healthcare is far from rosy.
    • “These were some of the findings from the 2026 Healthcare IT Landscape Report from Omega Systems, a leading provider of managed IT and security services to the healthcare and financial services industries. The report is based on a survey of 200 healthcare business leaders in the United States, including CEOs, CISOs, CIOs, CFOs, and COOs, at healthcare organizations with between 50 and 600 employees. The healthcare organizations represented in the report include medical practices, clinics, ambulatory care centers, specialty services, and long-term care facilities.”
  • Tech Target offers “A CISO’s guide to infostealers: Prevention and detection.”
    • “Infostealers aren’t new. But what is new is that almost anyone — regardless of skill — can now deploy the malware. Update incident response plans to safeguard your operations.”
  • Security Week notes,
    • “AI agents go beyond answering questions. They can autonomously browse websites, read emails, search company files, query software tools, and more. AI models producing incorrect answers is hardly a threat, until agents encounter information that’s maliciously designed to influence what it sees, believes, remembers, or executes.
    • “An agent leverages webpages, document stores, wikis, images, emails, or tools to produce intended outputs. But what happens when these sources mask malicious instructions? These trap AI agents into making a wrong interpretation or taking unintended action. Scientists from Google DeepMind categorized these “traps” into six categories, including content injection, semantic manipulation, cognitive state, behavioral control, systemic, and human-in-the-loop traps. The last two are more theoretical and expected to become more relevant as AI agent use grows. It helps to understand these traps to determine the necessary mitigations.”
  • Per Cybersecurity Dive,
    • “As cyber risk evolves, the insurance industry tightens guardrails.”
    • “C-suite executives are concerned about resilience, but claims are increasingly tied to strict underwriting standards.”
  • Here is a link to Dark Reading’s CISO Corner.

Cybersecurity Saturday

From the Project Glasswing front,

  • Politico reports on June 18,
    • “The White House and Anthropic are working on a framework that would assess the severity of security flaws in new AI models and guide potential government intervention, according to a senior White House official and an administration official familiar with the matter granted anonymity to discuss it.
    • “The effort comes after the White House imposed export controls on Anthropic, which forced the company to suspend access for all users to Fable 5 and Mythos 5, its latest powerful AI models over a perceived security flaw, known in the industry as a jailbreak.
    • Administration officials and Anthropic CEO Dario Amodei disagreed over the severity of the jailbreak, POLITICO previously reported, but the technology has outpaced the government infrastructure to define and assess such disputes.
    • “The attempt to create a standardized method to evaluate this and future such incidents underscores how the administration is racing to establish guardrails for new and powerful models that some fear can, if left unchecked, threaten economic and national security.
    • “The negotiations between Anthropic and the administration also reflect an understanding that no AI model can be completely immune to hacking — part of Anthropic’s initial defense of its model — and that government should lay out the rules for companies to measure security risks by, a sentiment relayed by other leading AI companies and country leaders at G7 meetings earlier this week in France.”
  • Bloomberg adds also on June 18,
    • “Some firms have preserved their access to a preview version of the Mythos AI model through Project Glasswing, despite a US government order.
    • “Businesses including banks and technology firms are accessing Mythos Preview to hunt for cyber vulnerabilities, with companies like Dragos Inc. and Cisco Systems Inc. confirming they have access.
    • “The US government order led to the shutdown of other versions of the Mythos AI model, but it didn’t explicitly address the Preview version, and Anthropic hasn’t directly addressed its availability.”
  • Cyberscoop points out,
    • “While Washington D.C. frets over the potential impact of Anthropic’s Claude Fable 5, security researchers continue to track how the integration of frontier AI tools are transforming the digital security landscape for malicious hackers and defenders alike.
    • “The breakneck speed of model releases may be creating short, silent security gaps for developers who must choose between performance and security, according to a new report.”
  • Cybersecurity Dive notes
    • “More than one-fifth of organizations running macOS networks have lost money or experienced a cyberattack because of their use of AI tools, according to a report that network management vendor Jamf released on Tuesday.
    • “Roughly six in 10 macOS-based organizations expect an AI-related incident in the near future, the survey found.
    • “The report, based on interviews with 687 IT and security leaders managing MacOS network environments, also describes system administrators’ AI implementation priorities, the largest areas of risk they face and Jamf’s recommendations for mitigating those risks.”

From the cybersecurity policy and law enforcement front,

  • Cybersecurity Dive reports,
    • “U.S. cybersecurity resilience in the face of sophisticated threats from China and other adversaries will increasingly depend on critical infrastructure’s ability to weather major disruptions, a top U.S. cyber official said Wednesday.
    • “Each and every one of us is operating right now on the front lines of a war that is never going to be cleared,” Nick Andersen, the acting director of the Cybersecurity and Infrastructure Security Agency (CISA), said at ICS Village and the Institute for Security and Technology’s Critical Effect conference.
    • “We are going to see an adversarial disruption of our critical infrastructure,” Andersen said. “It’s going to have significant not just technical impact, it’s going to have a significant psychological impact on the safety of the American people. … We need to start operating like that’s the reality of where we’re at — that we’re not going to be able to keep everything persistently online and available as much as we would like.”
    • “CISA’s emphasis on resilience marks a shift from earlier government cybersecurity doctrines that focused on preventing intrusions. In recent years, advanced nation-state hacking campaigns — especially Beijing’s Volt Typhoon espionage operation — have increasingly convinced government and industry strategists that their primary goal should be ensuring that infrastructure can continue operating during an attack.”
  • Federal News Network adds,
    • “A new White House memo aims to strengthen the cybersecurity of sensitive government systems by centralizing oversight of those systems, while also setting aggressive deadlines for updating incident response procedures and other policies.
    • “In a national security presidential memorandum signed out Friday, President Donald Trump re-establishes and updates the Committee on National Security Systems (CNSS), a decades-old interagency body that sets security policies for military and intelligence systems, as well as systems that process classified information. It charges the committee with leading a policy aimed at fostering “a proactive, adaptive, and resilient cybersecurity ecosystem for all NSS to better safeguard the nation against persistent cyber threats from sophisticated adversaries.”
    • “The memo gives the committee the power to establish “baseline cybersecurity requirements” for all national security systems. It formalizes the director of the National Security Agency’s role as the “national manager” for national security systems. That role involves identifying emerging threats and providing minimum security protections, including through emergency directives.
    • “The memo includes the federal chief information officer on the reconstituted CNSS body, along with the deputy national manager at the NSA and the CIOs at the Defense Department and the intelligence community, respectively.
    • “It also mandates that national security systems should meet or exceed the level of cybersecurity standards issued by the National Institute of Standards and Technology.”
  • Cyberscoop relates,
    • “Authorities on Thursday [June 18] disrupted a botnet, a malware framework and seized infrastructure that Evil Corp and other cybercrime groups used to steal data and break into various networks.
    • “The globally coordinated effort targeted SocGholish, multi-stage malware that has compromised websites, redirected users to traffic distribution systems (TDS) and slipped malware into their networks since 2017.
    • “The malware establishes an initial foothold into victim computers, collectively known as a botnet, and is then used by threat actors for further targeting with ransomware campaigns and espionage,” the FBI’s cyber division said in a statement. 
    • “Cybersecurity firms, researchers and officials from the United States, Canada, Germany, the Netherlands and Europol took down 106 servers and remediated nearly 15,000 sites that were infected with the malware. Officials also disabled the botnet and notified victims.
    • “Sites infected with SocGholish, which are primarily hosted on WordPress, were widespread and provided everyday services including restaurants and auto repair shops, according to the Dutch National Police
    • “The botnet, also known as “FakeUpdates,” is linked to the Russian cybercrime group Evil Corp. It also provided initial access to other ransomware variants, including DoppelPaymer, WastedLoocker, Hades Ransomware, LockBit, RansomHub and others, according to Infoblox, which participated in the takedown.” 
  • Per an HHS news release,
    • “The U.S. Department of Health and Human Services (HHS), Office for Civil Rights (OCR) today announced a settlement with Spencer Gifts LLC Flexible Benefits and Welfare Benefit Plans (the Plan), the employer-sponsored group health plan of Spencer Gifts LLC, a national retail company, over potential violations of the Health Insurance Portability and Accountability Act of 1996 (HIPAA) Privacy and Security Rules.” * * *
    • “The settlement resolves an investigation that OCR initiated after the Plan filed a breach report on January 24, 2022. The Plan had received employee complaints that employees were unable to connect to the virtual private network. The Plan discovered that in November 2021, an unauthorized actor accessed the company’s network and deployed ransomware, encrypting data on the company’s systems, including servers storing the Plan’s PHI, and demanding a ransom. The PHI of 10,023 individuals was potentially affected by the breach, including health plan members’ names, addresses, zip codes, phone numbers, email addresses, and Social Security numbers.” * * *
    • “The resolution agreement and corrective action plan can be found at: https://www.hhs.gov/sites/default/files/ocr-ra-cap-spencer.pdf [PDF, 654 KB].”
  • Security Week tells us,
    • “A Ukrainian national pleaded guilty in a US court to his role in the notorious Conti ransomware group, the Department of Justice announced.
    • “The man, Oleksii Oleksiyovych Lytvynenko, 44, of Cork, Ireland, was arrested in Ireland in 2023 and was extradited to the US in October 2025 to face Conti-related charges.
    • “Lytvynenko admitted in court to joining the Conti operation in September 2021 and working on the development of a malware loader for the group. He also admitted to possessing data from 12 victims, including eight in the US.
    • “Authorities in the US believe that the Ukrainian national continued to engage in cybercriminal activities after the Conti operation shut down.
    • “Lytvynenko pleaded guilty to wire fraud conspiracy and faces up to 20 years in prison. He is scheduled for sentencing on September 10, 2026.
    • “One of the most prolific ransomware groups half a decade ago, Conti was used in attacks against over 1,000 organizations in the US and abroad between 2020 and 2022.”

From the cybersecurity breaches and vulnerabilities front,

  • Tech Target identifies the largest healthcare data breaches so far reported to HHS OCR this year.
  • Dark Reading reports,
    • “A recent — and likely massive — breach at Novo Nordisk, where attackers reportedly gained an initial foothold using a single GitHub access token, underscores how code repositories and developer environments have become ground zero for attackers seeking intellectual property, credentials, and software supply chain assets.
    • “Novo Nordisk, the Danish pharmaceutical giant behind blockbuster drugs Ozempic and Wegovy, disclosed the breach June 11 after detecting unauthorized access to what it claimed were a “limited number of its internal IT systems.” 
  • Bleeping Computer relates on June 19,
    • “The Texas Parks and Wildlife Department (TPWD) disclosed a data breach at its license system vendor that exposed personal information for more than three million individuals.
    • “The Texas Cyber Command discovered the intrusion and launched an investigation to determine the extent and impact of the unauthorized access. The state authority found that Social Security Numbers (SSNs), dates of birth, or any financial information, such as credit cards, have not been impacted.
    • “However, the threat actor may have obtained personally identifiable information that includes the data types [identified in the article] associated with 3,087,721 Texas hunting and fishing license customers,
  • and
    • “The U.S. Cybersecurity and Infrastructure Security Agency (CISA) urged Fortinet customers to secure their devices after nearly 74,000 firewall and VPN credentials were exposed in a data leak dubbed “FortiBleed.”
    • “This warning comes after threat actors used compromised credentials to target internet-accessible Fortinet devices across government and private-sector organizations worldwide.
    • “CISA is aware of global reports that malicious cyber actors have targeted internet-accessible Fortinet devices across government and private sector organizations using compromised credentials,” it said.
    • “This activity, referred to as FortiBleed, involves the exposure of leaked credentials associated with approximately 74,000 Fortinet devices, including firewalls and virtual private network (VPN) gateways.”
    • ‘The agency called on affected FortiGate appliance owners to terminate all SSL VPN and administrative sessions, reset all VPN and administrative passwords, enable phishing-resistant multifactor authentication, and review logs for signs of unauthorized access or lateral movement.
    • “CISA also advised Fortinet customers to store admin credentials using the modern Password-Based Key Derivation Function 2 (PBKDF2) hashing algorithm, and to restrict firewall management interfaces from public internet access and remove any unauthorized accounts to reduce the attack surface as much as possible.”
  • CISA added four known exploited vulnerabilities to its catalog this week.
    • June 15, 2026
      • CVE-2026-20262 Cisco Catalyst SD-WAN Manager Directory or Path Traversal Vulnerability
      • CVE-2026-54420 LiteSpeed cPanel Plugin UNIX Symbolic Link (Symlink) Following Vulnerability
        • Security Affairs discusses these KVE here.
    • June 16, 2026
      • CVE-2026-48907 Widget Factory Joomla Content Editor Improper Access Control Vulnerability
        • Bleeping Computer discusses this “patch by Sunday June 21” KVE here.
    • June 18, 2026
      • CVE-2026-20253 Splunk Enterprise Missing Authentication for Critical Function Vulnerability
        • Bleeping Computer discusses this “patch by Sunday June 21” KVE here.
  • Security Week informs us,
    • Microsoft on Wednesday published an advisory acknowledging the public disclosure of a vulnerability in Defender that could lead to privilege escalation.
    • The security defect, now tracked as CVE-2026-50656 (CVSS score of 7.8), was dropped last week by security researcher Nightmare Eclipse (also known as Chaotic Eclipse).
    • “Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as ‘RoguePlanet’,” the tech giant’s advisory reads.
    • “We are working to provide a high-quality security update that addresses this vulnerability. We will provide information in this CVE when the update is available,” Microsoft adds.
    • RoguePlanet, Nightmare Eclipse explained last week, targets a race condition in Microsoft Defender and allows attackers to gain System privileges.
    • The researcher released a proof-of-concept (PoC) exploit that demonstrates local privilege escalation (LPE) on Windows 11 and Windows 10 systems with the June 2026 patches installed.
  • and
    • “Cybersecurity firms Huntress and Recorded Future have disclosed the impact of a supply chain attack that hit market intelligence platform Klue.
    • “The attack started on June 11 and affected systems associated with software platform integrations. The hackers connected to Klue’s backend servers and executed unauthorized commands, pushing a code update to harvest OAuth tokens for customers’ Klue integrations.
    • “Klue notified customers of the incident on June 12, warning that it had deactivated OAuth tokens for all customers and disabled integrations with Salesforce, HubSpot, SharePoint, Zoom, Gong, Chorus, Clari, Google Drive, and Slack.
    • According to ReliaQuest, the hackers abused the Salesforce REST API to exfiltrate large volumes of customer relationship management (CRM) data over a 24-hour window, “including a concentrated burst of nearly a thousand queries in 15 minutes and sustained extraction windows lasting over 6 hours”. * * *
    • “On Thursday [June 18], both Huntress and Recorded Future confirmed that they were among the companies affected by the supply chain attack.”
  • The Wall Street Journal reports,
    • “Millions of digital home devices in the U.S. have pre-installed backdoor software, creating residential proxy networks used by nation-state hackers to mask cyberattacks.
    • “Government agencies from nine countries warned that Chinese state-sponsored hackers use these networks to conduct operations, making attribution challenging.
    • “Midnight Blizzard, a Russian hacking group that broke into Microsoft, used residential proxy networks to steal Microsoft 365 credentials by logging in from U.S. home networks.” * * *
    • “This is a bigger problem because of the sheer numbers,” said Noopur Davis, Comcast’s head of information security. It is one of the most worrying problems the telecommunications company has seen, she said.
    • “[This story explains how to protect yourself from a sneaky back door that can let hackers into your home.]”

From the ransomware front,

  • Industrial Cyber reports,
    • “CYFIRMA reported that healthcare organizations are facing an increasingly hostile cyber threat environment, with ransomware emerging as the sector’s most significant risk. Over the past 90 days, healthcare accounted for 216 verified ransomware victims, representing 9.05% of ransomware victims globally and ranking the sector third among 14 industries. The report found that ransomware attacks against healthcare increased 8.5% quarter over quarter, with April alone recording 90 victims, well above the sector’s previous six-month average. 
    • “In a new report, CYFIRMA identified healthcare victims in 42 countries, up from 33 in the prior period, while 50 of 81 active ransomware gangs targeted healthcare organizations, highlighting broad criminal interest in hospitals, pharmaceutical firms, and specialized medicine providers. The report also warned that nation-state activity and supply chain risks are compounding the threat landscape. Healthcare organizations appeared in 10 of 33 observed advanced persistent threat (APT) campaigns, up from three of 19 campaigns in the previous reporting period. North Korea-linked Lazarus Group led observed activity, while Russia-, China-, and Iran-linked actors also targeted the sector. 
    • “The researchers further noted that web applications, operating systems, web portals, and access management platforms remain key targets as attackers pursue credential theft and patient data. The company further identified supply chain concentration as a defining structural risk, warning that breaches involving specialized healthcare IT providers can cascade across multiple hospitals and healthcare networks simultaneously, amplifying operational disruption and cyber exposure.” 
  • Security Week relates,
    • “Commercial printing and imaging technologies company Kodak has confirmed suffering a data breach after the ShinyHunters cybercrime group claimed to have stolen information from its systems. 
    • “Kodak was named on the ShinyHunters website on June 15, with the hackers claiming to have obtained more than 2.2 million records of customer personal information and other corporate data. 
    • “The hackers threatened to leak the stolen data on June 18 unless the company pays a ransom.
    • Contacted by SecurityWeek, Kodak said it’s conducting an investigation with the aid of external cybersecurity experts and promised to share additional information “as appropriate”.
    • “Kodak recently discovered that an unauthorized third party illegally gained access to a limited amount of company data,” said a spokesperson for Kodak.
    • “Although our investigation is ongoing, we are confident the incident was limited in scope and has been contained and that there is no threat to our systems or operations as a result of the incident,” the spokesperson added. “We have also notified law enforcement and are continuing to support their investigation.”
  • Dark Reading tells us,
    • “INC is a ransomware group that has excelled in the ransomware-as-a-service (RaaS) space through doing the basics effectively — alongside a bit of good timing.
    • “Researchers with security vendor Acronis today published a blog post covering RaaS gang INC, a group that emerged in 2023 and has claimed more than 800 victims to date. INC is a ransomware actor that greatly benefited from the shutdown of ALPHV/BlackCat and the disruption of LockBit; this is an attribute shared with other ascendant gangs, such as The Gentlemen.”
    • “And according to the Acronis Threat Research Unit (TRU), the group is one of the most active of its kind right now. On the surface, INC doesn’t stand out so much. It’s a double extortion ransomware actor (meaning it uses encryptionand data leaking to get victims to pay up), drawing victims from manufacturing, legal services, healthcare, technology, construction, and educational sectors, among others. The group appears to have a certain preference for organizations with especially sensitive data to add extra extortion pressure.” 
       
  • Bleeping Computer adds,
    • “The Gentlemen ransomware-as-a-service (RaaS) is actively developing and maintaining a suite of endpoint detection and response (EDR) killers to help affiliates evade detection in attacks.
    • “The gang employs a collection of EDR-killing tools, most notably a utility that researchers dubbed GentleKiller. The tool has at least eight variants and impersonates various legitimate security products, including Kaspersky, Valorant, Javelin, and WatchDog.
    • “The gang is using a suite of EDR killers, the most frequently used being a custom tool that researchers named GentleKiller, which has at least eight variants impersonating various legitimate products.
    • The Gentlemen ransomware-as-a-service (RaaS) is actively developing and maintaining a suite of endpoint detection and response (EDR) killers to help affiliates evade detection in attacks.
    • “An EDR killer is typically used to disable defenses in the early phases of an attack, and in ransomware incidents, they ensure that data theft or encryption processes run unencumbered.
    • “These tools work by leveraging the ‘bring your own vulnerable driver’ (BYOVD) technique to elevate privileges and disable security engines.”
  • and
    • “DragonForce ransomware used a custom malware named ‘Backdoor.Turn’ to hide command-and-control traffic inside Microsoft Teams relay infrastructure.
    • “The backdoor abuses the Traversal Using Relays around NAT (TURN) protocol used by Microsoft Teams to distribute messages when a direct connection to the client is unavailable (e.g., clients on a private network).
    • “DragonForce is a ransomware operation active since at least 2023, that adopted a cartel-style organizational structure and has been linked to the infamous Scattered Spider threat group.

From the cybersecurity business and defenses front,

  • Cyberscoop reports,
    • “Accenture announced Thursday it would acquire a majority stake in industrial cybersecurity firm Dragos for $3.25 billion and purchase two smaller security companies outright, essentially making a $4.18 billion bet that defending the IT networks of power grids, pipelines, factories and critical infrastructure sectors will become one of the defining challenges of the AI era.
    • “The deals — which also include two Austin, Texas-based companies, runZero and NetRise —  represent a significant strategic pivot for Accenture toward operational technology (OT) security,  a segment of the cybersecurity market that has long been underfunded relative to traditional IT defenses. The announcement comes as the consulting giant faces pressure on its core business from the same AI tools reshaping the threat environment it is now moving to address.”
  • HIPAA Journal adds,
    • “Compliancy Group has acquired Healthicity in a deal that combines two healthcare compliance software companies and expands Compliancy Group’s platform to include healthcare compliance, workforce compliance, risk assessment, third-party risk management, incident management, provider auditing, coding auditing, and documentation auditing.
    • “The acquisition was announced on June 17, 2026. Financial terms of the transaction were not disclosed. Compliancy Group said the combined organization will serve more than 3,000 healthcare organizations across the United States and selected global markets.”
  • Dark Reading advises,
    • “Get Out of Security Debt by Tackling the Exposure Problem.
      • “Teams digging out of security debt need to answer only two simple questions: Which vulnerabilities in our systems are exposed, and how long should they stay that way?”
  • Tech Target adds,
    • “It’s time to update incident response for the AI era”
    • “Your latest cybersecurity incident might not be a threat actor, but an internal AI agent doing what it’s authorized to do. Incident response must evolve to accommodate AI.”
  • ZDNet offers
    • “10 signs that someone is monitoring or accessing your accounts – how to stop them
      • “Learn how to spot the signs of account monitoring and compromise – and take back control.”
  • and
    • “5 steps to ensure HIPAA compliance on mobile devices
      • “HIPAA compliance on mobile devices depends on governing access to PHI across both managed and personal endpoints. Here are five steps to achieving compliance in clinical settings.”
  • Security Week lets us know about
    • “AI and Cybersecurity – Everything You Wanted to Know, But Were Afraid to Ask
      • “From defending networks to enabling attacks, artificial intelligence is changing every aspect of cybersecurity. Here’s what dozens of experts say security leaders need to understand now.”
  • Here’s a link to Dark Readings’s CISO Corner.

Cybersecurity Saturday

From the Project Glasswing front,

  • Tech Crunch reports,
    • “The U.S. government on Friday ordered Anthropic to immediately shut off access to two of its most powerful AI models — Claude Fable 5 and Claude Mythos 5 — citing national security concerns. Anthropic announced on X that it has complied, but it made clear it thinks the government got this one wrong.
    • “The directive, which Anthropic said it received on Friday [June 12] at 5:21 pm ET, forces the company to disable both models for all users worldwide — not just the foreign nationals the government’s export control order was nominally aimed at. Access to Anthropic’s other models isn’t affected.” * * *
    • “Fable 5, released just three days ago, was Anthropic’s answer to the obvious commercial pressure: a version of Mythos fitted with guardrails that block responses in high-risk areas like cybersecurity and biology, making it safe enough for general release, the company argued. It was immediately the most capable AI model available to the public, according to benchmark tests from Vals AI, a company that tracks AI tech performance.” * * *
    • “Anthropic is widely expected to pursue an IPO this year and has staked much of its public identity on being the safety-conscious alternative to its rivals. The irony isn’t lost on observers that the very caution Anthropic displayed in restricting Mythos — which it promoted as a model so dangerous it couldn’t be released publicly — has now apparently attracted exactly the kind of government scrutiny that could disrupt its business most.”

From the cybersecurity policy and law enforcement front,

  • Federal News Network reminds us,
    • “The Cybersecurity and Infrastructure Security Agency is restarting public engagements on delayed cyber incident reporting rules that will likely cover tens of thousands of critical infrastructure organizations.
    • “The meetings come as CISA faces pressure to issue the final regulations quickly, while some lawmakers and industry groups also want the agency to amend the draft rules to be less broad and burdensome.
    • “Starting Monday, CISA will host a series of virtual town halls to get feedback on the draft regulations to implement the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA). The meetings will run through Wednesday.”
  • Cyberscoop reports,
    • “The Cybersecurity and Infrastructure Security Agency on Wednesday [June 10] ordered federal agencies to prioritize vulnerabilities based on four criteria, as part of push to “patch smarter, not harder.”
    • “Federal agencies should emphasize patches for vulnerabilities that affect a publicly exposed asset, allow an attacker to fully automate exploitation, give attackers the ability to take over control of a system or relate to evidence of active, real-world exploitation, CISA declared.
    • “CISA acting director Nick Andersen previewed the binding operational directive (BOD) Tuesday [June 9], framing it as a rethinking of vulnerability management more broadly.” * * *
    • BOD 26-04 sets forth timelines for how quickly agencies must fix a vulnerability based on how many of the four criteria it meets. If it meets all four, for example, agencies need to fix it within three days and carry out a “forensic triage” to assess whether their systems were compromised. 
    • “More generally, agencies must immediately update their vulnerability management policies, including establishing a process for ongoing remediation of known, exploited vulnerabilities (KEVs) on CISA’s “must-patch” list. Within 60 days, agencies need to update their processes for remediating common vulnerabilities, and within 180 days, agencies must meet the order’s remediation timelines.
    • “The directive is motivated in part by how artificial intelligence is shifting the window from vulnerability discovery to weaponization, and CISA said it reflects priorities in an executive order on AI that President Donald Trump signed last week.”
  • and
    • “The FBI, along with Google and Lumen Technologies, took down a major cybercrime network based in China that was responsible for an estimated $1.9 billion in losses, officials said Friday. 
    • “Outsider, which provided phishing kits and hosted infrastructure for cybercriminals since July 2023, facilitated a wave of phishing attacks against people and businesses in 55 countries, including the United States, the FBI said in a LinkedIn post.
    • “The jointly coordinated effort dubbed “Operation Ghost Hook” netted the seizure of several domains of the group’s core admin servers, a Shopify storefront, roughly $100,000 from Outsider payment wallets and thousands of domains registered through U.S.-based providers, officials said.
    • “The FBI said it also used an Outsider Telegram bot to access information on the cybercrime network’s customers.”
  • and
    • “A longtime former member of Conti, a ransomware group that attacked more than 1,000 organizations globally before it disbanded in 2022, pleaded guilty to participating in some of those attacks in federal court Wednesday [June 10], the Justice Department said.
    • “Oleksii Oleksiyovych Lytvynenko, also known as Alexsey Alexseevich Litvinenko, admitted he joined the prolific cybercrime group in September 2021 and held data on 12 victims, including eight based in the United States. The 44-year-old told the court he developed malware that Conti used in some of its attacks, according to officials.” 
  • Bleeping Computer adds,
    • “Law enforcement has dismantled the “AudiA6” cryptocurrency service allegedly used by ransomware actors and other cybercriminals to launder more than $380 million.
    • “Europol says that the service has been linked to more than 15 distinct international investigations of ransomware attacks.
    • “It is believed that the platform acted as a central money laundering hub between 2022 and 2025.”

From the cybersecurity breaches and vulnerabilities front,

  • Bleeping Computer reports,
    • “Danish pharmaceutical giant Novo Nordisk, the world’s largest producer of insulin, disclosed a data breach affecting patient information from some clinical trials.
    • “Founded in 1923, Novo Nordisk now employs around 67,900 people across 80 offices worldwide and is the maker of viral GLP-1 receptor agonist drugs Wegovy and Ozempic.
    • “The company revealed on Thursday [June 11] that attackers gained access to its internal IT systems and data related to patients participating in some clinical trials, including their patient IDs (random alphanumeric strings) and information on trial participation, sex, year of birth, biomarkers, health/immunogenicity data, and lifestyle factors (e.g., smoking, alcohol use, BMI).
    • “However, Novo Nordisk said that this data was pseudonymized and that the attackers can’t use it to identify any affected patients by name.
    • “While our investigation and response are ongoing, we have discovered that certain non-public data, including personal data, was copied externally without authorisation. We are informing the impacted parties as appropriate,” the company said.”
  • HIPAA Journal tells us,
    • “Episource, a provider of medical coding, risk adjustment services, and software solutions, experienced a cyberattack in early 2025, in which files containing patient data were exfiltrated from its network. In June 2025, the forensic investigation had progressed, and it was confirmed that 5.4 million individuals had been affected.
    • “The investigation has since revealed the data breach was more extensive, involving unauthorized access to the electronic protected health information of 6,725,572 individuals, according to updated figures provided to the HHS’ Office for Civil Rights. With more than 6.7 million affected individuals, the data breach currently ranks as the third-largest healthcare data breach of 2025, behind the 13.9 million-record data breach at Aflac and the 62.2 million-record data breach at Conduent Business Services, and ranks as the 16th-largest healthcare data breach of all time. The threat group behind the incident remains unknown.”
  • Industrial Cyber relates,
    • “Global cyberattack activity eased in May 2026 following April’s sharp rebound, but the broader threat landscape remained volatile, according to research from Check Point Research. Organizations experienced an average of 2,055 weekly cyberattacks during the month, representing a 2% increase year-over-year despite a 7% decline from April. Education remained the most targeted sector, averaging 4,641 weekly attacks per organization, while government and telecommunications also continued to face elevated attack volumes. 
    • “The report noted notable year-over-year increases in attacks targeting agriculture, hospitality, travel, recreation, and construction sectors as digitalization expands across these industries. The most significant trend was a sharp rise in ransomware activity. Check Point recorded 698 ransomware attacks globally in May, a 48% increase compared to the same month last year and the highest year-over-year growth rate recorded in 2026. Business services accounted for 35% of all ransomware victims, while consumer goods and industrial manufacturing also experienced substantial increases. 
    • “The report found that ransomware activity has become increasingly fragmented, with 61 active groups operating during the month. Qilin emerged as the most active ransomware group, responsible for 14% of published attacks, followed by The Gentlemen and DragonForce.”
  • Dark Reading adds,
    • “Phishing attacks are down across most industries, yet researchers argue the phishing threat is higher today than ever, as the fewer attacks that are perpetrated are becoming more dangerous.
    • “In its 2026 annual phishing report, Zscaler researchers framed the trend not as a drop but as a “rebalancing” — threat actors moving from wide spray-and-pray campaigns to more focused attacks with higher conversion rates.”
  • CISA added seven known exploited vulnerabilities to its catalog this week.
    • June 8, 2026
      • CVE-2026-42271 BerriAI LiteLLM Command Injection Vulnerability
      • CVE-2026-50751 Check Point Security Gateway Improper Authentication Vulnerability
        • Infosec discusses the BerriAI KVE here.
        • Cybersecurity Dive discusses the Check Point KVE here.
    • June 9, 2026
      • CVE-2026-7473 Arista Extensible Operating System Incomplete Comparison with Missing Factors Vulnerability
      • CVE-2026-11645 Google Chromium V8 Out-of-Bounds Read and Write Vulnerability
      • CVE-2026-20245 Cisco Catalyst SD-WAN Manager Improper Encoding or Escaping of Output Vulnerability
        • Scorifya discusses the Arista KVE here.
        • Cybersecurity News discusses the Google KVE here.
        • Cybersecurity Dive discusses the Cisco KVE here.
    • June 11, 2026
      • CVE-2026-10520. Ivanti Sentry OS Command Injection Vulnerability
        • Dark Reading discusses this KVE here.
    • June 12, 2026
      • CVE-2026-35273 Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function Vulnerability
        • Cybersscoop discusses this KVE here.
  • Info Security Magazine informs us,
    • “Cybersecurity software regularly fails to detect and prevent the cyber-attacks they are designed to protect organizations from, especially within the bowser layer, research by Menlo Security has warned.
    • “Published on June 9, Menlo Security’s 2026 Browser Threat Report found that one in five phishing attacks which target the enterprise browser users go completely undetected by the tools which are supposed to protect the network and its users from attacks.
    • “Based on platform telemetry across millions of active browser sessions in enterprise customer environments between January 1 and March 31 2026, the research warned that threat actors are gaining entry to enterprise environments through the browser session layer.
    • “The problem, the paper said, is that attacks via the browser target areas which many traditional enterprise cybersecurity products are not designed to identify or prevent suspicious activity in.
  • Cybersecurity Dive points out,
    • “Financial services organizations are widely using AI agents for common business operations, but many of them aren’t sure whether their AI tools have opened the door for hackers, according to a new report.
    • “Sixty-two percent of financial services firms have deployed AI agents, and 93% of those firms have given them some level of autonomy, the Cloud Security Alliance (CSA) said in its Tuesday report.
    • “The report’s authors said the main conclusion from their survey, which consisted of interviews with 340 global IT and security professionals between Jan. 15 and March 1, is that “financial institutions have deployed AI faster than they have secured it.”
  • Per Security Week,
    • Palo Alto Networks drew attention to a high-severity security flaw in the Cortex XSOAR and Cortex XSIAM platforms that could allow attackers to access and modify restricted resources.
    • “Tracked as CVE-2026-0274, the issue is described as the improper validation of credentials in the CommvaultSecurityIQ integration of the affected products and does not require a special configuration to be triggered.
    • “The company also rolled out patches for eight medium and low-severity security defects in PAN-OS, Prisma Access Agent, Cortex XSOAR, and GlobalProtect App.
    • “Palo Alto Networks says it is not aware of any of these vulnerabilities being exploited in the wild.
    • “On Wednesday [June 10], Splunk published a dozen advisories detailing security weaknesses in its products and third-party libraries they use.”

From the ransomware front,

  • Health Exec reports,
    • “A health system in Mississippi has revealed a December 2025 data breach of its network resulted in records on 53,888 patients being stolen by hackers. Meanwhile an infamous cybercrime cell has claimed credit for the attack, posting proof on the dark web.
    • “Last month Singing River Health System reported official numbers from the incident to the U.S. Department of Health and Human Services’ Office for Civil Rights, which operates a data breach tracker. This came after an investigation into what it called a “cybersecurity incident” that staff at Singing River discovered a few days after cybercriminals were already inside its network.
    • “According to the health system, which said it worked with a third-party cybersecurity firm on its investigation, its network was compromised from Dec. 19 to 21, 2025, before the unauthorized access was discovered and containment protocols were deployed.” * * *
    • “Researchers at Comparitech released a report last week showing that Anubis—a cybercrime syndicate known for its ransomware attacks against healthcare entities—had claimed credit for the data breach in a post on its own dark web leak site.
    • “The group claims to have 293 GB of data from Singing River, much of it containing sensitive patient information. It posted samples to prove it had the goods, including what Comparitech described as “intimate images of surgeries and injuries.”
  • The Hacker News relates,
    • “A new analysis of The Gentlemen operation has revealed that the financially motivated threat group initially operated as an affiliate responsible for conducting double extortion attacks, while leveraging resources from various ransomware-as-a-service (RaaS) schemes like LockBit (aka Tenacious Mantis), Qilin (aka Pestilent Mantis), and Medusa (aka Venomous Mantis).
    • “According to a detailed report published by PRODAFT, the group, which it tracks as Phantom Mantis, is led by a Russian-speaking cybercriminal it calls LARVA-368, who goes by the online aliases hastalamuerte, ArmCorp, zeta88, nobody0, and santamuerte. The Gentlemen is known to be active since March 2025, claiming a total of 478 victims to date, per data from Ransomware.Live.”
  • Cybersecurity Insiders tells us,
    • “In recent years, ransomware has evolved from simple file-encrypting malware into highly sophisticated cyber weapons capable of disrupting entire organizations. Among these emerging threats, Time Bomb Ransomware has gained significant attention due to its ability to remain dormant within systems before launching a coordinated attack. This delayed-execution strategy makes it particularly dangerous for backup engines, which serve as the last line of defense against data loss and cyber incidents.
    • “Time Bomb Ransomware operates by infiltrating an organization’s network and remaining undetected for an extended period. Instead of immediately encrypting files, the malware silently spreads across systems, identifies critical assets, and waits for a predetermined trigger date or condition. 
    • “During this dormant phase, it can infect data backup repositories, storage servers, and disaster recovery environments without raising suspicion. As a result, organizations may unknowingly back up infected data for weeks or even months- depending on the backup engine configuration that can range on weekly to monthly time intervals.
    • “The primary danger lies in the ransomware’s ability to compromise backup engines before activating its payload. Traditional backup solutions are designed to create multiple copies of data to ensure business continuity. However, when ransomware infiltrates these backup systems, it can encrypt, corrupt, or delete backup copies along with the primary data. Consequently, organizations lose their ability to recover information, forcing them to either pay the ransom or suffer significant operational disruptions.”

From the Cybersecurity defenses front,

  • The Wall Street Journal reports,
    • “Frontier artificial intelligence models, like Anthropic’s Mythos, are forcing organizations to rethink cybersecurity by rapidly identifying attack chains.
    • “Visa developed a “Mean Time to Adapt” metric and the VVAH framework to automate vulnerability fixing and testing.
    • “Mean Time to Adapt,” measures how quickly an organization identifies, triages and fixes vulnerabilities once discovered.
    • “The rapid AI-driven discovery of flaws creates pressure on organizations, especially smaller vendors and the public sector, to automate defenses.”
  • JP Morgan Chase suggests ten actions to take now for AI-ready cyber resilience.
    • Run the Latest Software Versions
    • Manage Assets and Software Components with Reference Data
    • Build and Operate a Robust Vulnerability Management Program
    • Stress Test Incident Response and Resiliency Plans
    • Know Your Major SaaS and Outsourced Dependencies
    • Optimize Change Management for Speed
    • Aggressively Filter Outbound Traffic from Production Systems
    • Remove Standing Privileges from Employee Entitlements
    • Manage Remote Access and Segment Where Possible
    • Embed Security into the AI Development and Deployment Lifecycle
  • Bleeping Computer adds,
    • “AI is transforming the speed and scale of cybercrime in ways traditional security operations were never designed to handle.
    • Gartner predicts AI agents will cut the time it takes to exploit account exposures by 50% by 2027. Phishing campaigns that once took days to craft can now be generated in minutes, free of the telltale errors that once gave them away, while vulnerabilities that once required manual reconnaissance can now be identified and exploited automatically.
    • “For MSPs, the stakes are clear. Those still relying on a fragmented security stack will not just be slower to respond but will also struggle to prove to clients that their environments are fully protected.
    • “Keeping pace with AI-driven threats requires a more unified, AI-powered approach that strengthens security, simplifies operations and delivers greater value without putting additional pressure on margins.’
  • CSO raises “15 tough cybersecurity questions every CISO must answer.”
  • Here is a link to Dark Reading’s CISO Corner.

Cybersecurity Saturday

From the War with Iran front,

  • Cybersecurity Dive reports,
    • “The Cybersecurity and Infrastructure Security Agency, FBI and other federal authorities warned Tuesday [June 2] that hackers have targeted automatic tank gauge systems in threat activity across multiple industry sectors.
    • “Tank gauge, or ATG, systems are used to measure temperature, check fuel or other liquid levels and detect leaks, according to guidance released by the agencies. Hackers have targeted internet-exposed devices and used command execution to disable alerts or otherwise obscure the monitoring of these devices.” * * *
    • “Federal authorities have not attributed the attacks to any specific group, but CNN previously reported an investigation into the hack of ATG systems that serve gas stations in multiple U.S. states. The threat activity is suspected to be connected to Iran-linked hackers, but federal officials are not publicly making that link. 
    • “OT security experts cautioned there are limits to how a hacker might manipulate these devices. 
    • “A malicious actor could take control of an ATG and disrupt its functions, including leak detection, but they cannot cause a leak with an ATG,” said Markus Mueller, field CISO at Nozomi Networks. “Similarly, a malicious actor could disrupt the ability to fill or use a tank to fill a vehicle.” 

From the Project Glasswing front,

  • Cybersecurity Dive reports,
    • “Anthropic is significantly expanding the number of organizations that have access to its powerful Claude Mythos Preview AI model, a move that reflects growing interest in Mythos’s vulnerability-hunting capabilities within government agencies and critical infrastructure sectors.
    • “Following several weeks of close collaboration with our Project Glasswing partners, the security industry, open-source software maintainers, and the U.S. government, we’re extending the partnership to approximately 150 new organizations,” Anthropic said in a statement on Tuesday [June 2].
    • “The new organizations, which are based in more than 15 countries, include infrastructure operators in sectors that weren’t represented in Project Glasswing’s membership, such as power, water, healthcare and telecommunications. Other new members include hardware vendors and critical software maintainers, including nonprofit groups.”
  • Beckers Hospital Review adds,
    • “Health system leaders told Becker’s they’re encouraged by AI developer Anthropic opening up its Project Glasswing cybersecurity initiative to healthcare.”
  • Cybersecurity Dive notes,
    • One of the most important jobs for CISOs in the AI era is to stay calm and carefully assess their organizations’ risk exposure, experts said this week at the annual Gartner Security & Risk Management Summit here.
    • “Don’t panic,” Katell Thielemann, a VP analyst at Gartner, said during a talk on Tuesday about AI’s impact on the security of cyber-physical systems such as industrial control equipment.
    • “Yes, things are changing fast,” Thielemann said, “but there are some low-hanging fruit” that CISOs can tackle, such as disconnecting critical devices from the internet and monitoring remote access to the remaining infrastructure.

From the cybersecurity policy front,

  • Cyberscoop reports,
    • “The Trump administration issued a revised executive order Tuesday [June 2] focused on artificial intelligence, offering a significantly pared-back vision for the federal government’s role vetting AI systems compared with a draft version that was spiked weeks ago.
    • “The order keeps in place the administration’s largely voluntary framework for companies to engage with the federal government around testing new models before release, but appears to considerably weaken or loosen provisions that had been opposed by industry.
    • “Under the order, AI companies would voluntarily provide the federal government access to frontier models before release, but now it will be for “up to” 30 days instead of the 90-day timeline included in previous drafts.
    • “It also explicitly states that nothing in the program will be construed as mandatory or part of a federal licensing or permitting regime, and gives AI companies significant influence to help define what models would and would not be covered under for testing.
    • “It also states that all federal testing and access to the models would be subject to “confidentiality, cybersecurity, insider-risk, and intellectual-property protection, use, and nondisclosure requirements.”
  • Federal News Network relates,
    • During a House Homeland Security Committee hearing on Wednesday June 3, Homeland Security Secretary Markwayne Mullin “said the Cybersecurity and Infrastructure Security Agency needs to hire hundreds of additional staff. CISA’s staff has gone from roughly 3,400 people to 2,200 under the Trump administration, with many taking deferred resignations or early retirements.
    • “We probably need somewhere around [2,800] if we can actually have the partnerships we need with states and to be able to use the grants, the monies that stayed with CISA to be able to invest with local and state municipalities,” Mullin said. “We’re not going to fail on the mission that we have in front of us, and cyber attacks are only getting stronger, and they’re attacking our private partnership the most.”
    • “Mullin’s comments somewhat conflict with the Trump administration’s fiscal 2027 budget request for CISA, which would reduce the agency’s budget by $707 million compared to 2025 spending levels.” * * *
    • “Mullin also teased that Trump may be close to naming a new CISA director nominee. Former DHS official Sean Plankey’s nomination for CISA director was rescinded earlier this year after facing lengthy delays in the Senate.
    • “We’ve got a person soon to be nominated that will be running CISA that has the ability to recruit and focus on the authorities we have,” Mullin said. “We want CISA to be the leader in cybersecurity. They should be, and they will be.”
  • The American Hospital Association News tells us,
    • “The Health Sector Coordinating Council’s Cybersecurity Working Group has released a guide to help healthcare organizations establish cyber governance frameworks for secure artificial intelligence implementation. The guide addresses challenges in identifying and mitigating AI-specific cyber risks, including data poisoning, model drift and adversarial attacks, while ensuring compliance with current regulations. It also explores a spectrum of AI technologies used in healthcare, including traditional machine learning models, generative AI and agentic AI systems capable of autonomous action. 
    • “This comprehensive guide is a must-read for all healthcare organizations, vendors and suppliers as the development and implementation of various forms of AI into healthcare settings has become widespread at tremendous speed and scale,” said John Riggi, AHA national advisor for cybersecurity and risk. “The secure-by-design and implementation recommendations offered in this guide will help mitigate unintended cybersecurity risk and consequences of AI use in healthcare and help prevent adversarial exploitation of AI-related technical flaws. Mitigating AI cybersecurity risk is part of cyber safety, and cyber safety is patient safety.” 

From the cybersecurity vulnerabilities and breaches front,

  • Bleeping Computer reports,
    • “A data breach at the dental benefits administrator DentaQuest has reportedly exposed the sensitive data of 2.6 million accounts.
    • “The security incident came to light last month, when the infamous extortion group ShinyHunters listed the company on its data leak site and claimed to have stolen more than 234 GB of data.
    • “Following what the threat actor describes as a failure to reach an agreement with the company, the data was publicly leaked.” * * *
    • “On June 2, DentaQuest confirmed on its website that its networks had been breached and the incident caused “limited disruption” in customer service.
    • “DentaQuest is actively managing a cybersecurity incident involving unauthorized access to a limited portion of our network,” reads the statement.” * * *
    • “Yesterday, [June 3], data breach alerting service Have I Been Pwned (HIBP) analyzed the leaked information and found that it contained records for 2.6 million accounts.”
  • The HIPAA Journal has been keeping track of all healthcare data breaches since 2009.
    • “There was a sharp increase in data breaches between 2018 and 2021, with data breaches doubling in just three years as cybercriminals aggressively adopted ransomware and actively targeted the healthcare sector. The large annual increases in data breaches came to an end in 2021, increasing by around 4% between 2022 and 2023, and again by around 4% from 2024 to 2025, when a new annual record was set with 772 large data breaches reported.”
  • CISA added five known exploited vulnerabilities to its catalog this week.
  • Cybersecurity Dive adds,
    • “Cisco on Thursday [June 4] warned of a zero-day vulnerability in its Catalyst SD-WAN product that could allow an attacker to execute arbitrary commands as root. 
    • “The vulnerability, tracked as CVE-2026-20245, is the result of insufficient validation of user-supplied input. The flaw, which has a severity score of 7.8, could allow an attacker to conduct command-injection attacks and elevate privileges as the root user. 
    • “The company said it has confirmed a limited number of cases where the flaw was exploited, leading to a configuration change being pushed to edge devices.”
    • “Cisco has thus far not released any patches and has no current workarounds. 
    • “The vulnerability was disclosed by Mandiant.” 
  • and
    • “Researchers on Monday [June 1] warned that more than 30 Red Hat npm packages have been compromised in a supply-chain attack that used a credential-stealing worm. 
    • A total of 96 versions across 32 packages have been identified as compromised, according to researchers at Aikido Security. The accumulated downloads exceed 116,000, according to researchers. 
    • “The packages were published through the GitHub Actions OIDC, which indicates the compromise was linked to the continuous integration/continuous delivery pipeline, instead of a npm token, researchers noted.” 
  • The American Hospital Association News informs us,
    • “The FBI and international agencies have released an alert on Chinese military intelligence services using professional networking sites and online job platforms to target government, military and any other personnel with access to classified or privileged information. The agencies said intelligence officers or affiliates pose as employees of private consultancies, research institutions or human resources firms, and post job advertisements online for foreign policy and defense analysts. Successful candidates are then pressured to provide “non-public” information for unspecified clients associated with the Chinese government.
    • “This alert is important for healthcare since many individuals in the sector have current or former access to classified information,” said John Riggi, AHA national advisor for cybersecurity and risk. “Many healthcare organizations are also engaged in highly sensitive, taxpayer-funded medical research, innovation and clinical trials. For decades, the Chinese government has been engaged in an aggressive campaign to legitimately acquire, steal or hack the results of this research and innovation for their own strategic national security priorities, economic advantage or weaponization. Use of social media platforms to engage and compromise individuals with access to classified or unclassified, but sensitive information is one of their most effective tactics. As such, we should remain wary of connecting with unknown individuals on these platforms seeking to discuss research, or provide unusually lucrative offers for employment, speaking engagements, opinions or research — especially those which may involve foreign contacts or travel.”
  • Dark Reading identifies “4 Critical Threats Where Attackers Have the Advantage
    • “Gartner analysts issued a call to action to bolster defenses against several emerging critical threats, such as deepfakes and prompt injections.”

From the ransomware front,

  • Industrial Cyber reports,
    • “Microsoft Threat Intelligence detailed a growing RaaS (ransomware-as-a-service) operation known as The Gentlemen, tracked by Microsoft as Storm-2697, warning that the threat combines strong file encryption with aggressive self-propagation capabilities that can compromise entire enterprise networks. The analysis disclosed that the Go-based ransomware uses per-file ephemeral key encryption built on Curve25519 and XChaCha20, while simultaneously leveraging multiple lateral movement techniques to spread across connected systems, significantly increasing the speed and impact of attacks once initial access is obtained. 
    • “Researchers mentioned that The Gentlemen emerged in mid-2025 before evolving into a RaaS platform that recruits affiliates to conduct attacks at scale. The company noted that the malware’s self-propagation module enables broad network compromise, making it more dangerous than conventional ransomware focused solely on file encryption. The operation has been linked to widespread attacks across multiple sectors and regions, with threat actors using the ransomware alongside data theft and extortion tactics to maximize pressure on victims. 
    • “In addition to using per-file ephemeral Curve25519 keys with XChaCha20 stream cipher, The Gentlemen ransomware attempts to spread across an environment using a series of simultaneous, distinct lateral movement methods, increasing likelihood of widespread impact once initial access is achieved. Microsoft has observed The Gentlemen ransomware impacting organizations across education, transportation, healthcare, and financial industries in North America, South America, Europe, Africa, and Asia.”
  • Bleeping Computer relates,
    • “A threat actor is using an AI-built ransomware attack toolkit that automates Active Directory discovery and helps evade endpoint detection and response (EDR) solutions.
    • “Tool and payload development was assisted by Cursor and Claude Opus agents in various stages, including initial coding, analysis, and revisioning. Additionally, some agents were tasked with checking security research posts for various bypass techniques.
    • “Some of the malware created this way was tested in virtual environments against EDR tools from Sophos, CrowdStrike, and Microsoft.
    • “Despite the malware research and development orchestrated using AI technology, the researchers note that the workflow is entirely human-driven.”
  • Cybersecurity Insiders informs us,
    • “The traditional pattern of ransomware attacks appears to be changing, according to a recent analysis published by Ransomnews. For years, cybersecurity experts observed that many ransomware groups preferred launching attacks during weekends, particularly on Fridays and Sundays, when organizations often operated with reduced staffing levels.
    • “However, new data suggests that cybercriminals have shifted their tactics and are now focusing more heavily on weekdays, especially between Monday and Friday.
    • “The research indicates that ransomware incidents are increasingly occurring during standard European business hours rather than late at night or during weekends. This marks a significant departure from previous attack strategies, which were designed to exploit periods when IT teams and security personnel were less likely to be available to respond quickly.
    • “According to the findings, Sunday has become the least active day for ransomware-related activity. In contrast, October stands out as the busiest month of the year, recording the highest number of ransomware attacks. While the reasons behind the October surge are not entirely clear, experts believe that threat actors may take advantage of increased business activity during the final quarter of the year, when organizations are often focused on meeting annual targets and may have less time to dedicate to cybersecurity preparedness.”

From the cybersecurity business and defenses front,

  • Cybersecurity Dive reports,
    • “CrowdStrike reported better-than-expected earnings during the fiscal first quarter, as accelerating demand for AI is pushing more enterprises to focus on tighter cybersecurity controls. 
    • “CrowdStrike CEO George Kurtz said demand for AI and the introduction of Anthropic’s Mythos created an inflection point that demonstrated to the market that cybersecurity is an essential part of the AI ecosystem. 
    • “AI has now directly entered the world of cybersecurity across two dimensions,” Kurtz said during the company earnings call Wednesday. “First, you need cybersecurity to secure AI itself. Deploying AI across the enterprise is simply too risky without cybersecurity from the start.” * * *
    • The company said revenue increased 26%, to $1.39 billion, during the fiscal first quarter ended April 30, compared with year-ago revenue of $1.1 billion. * * *
    • “On Tuesday, CrowdStrike rival Palo Alto Networks reported a 31% increase in revenue, to $3 billion, during the company’s fiscal third quarter. 
    • “These results are materializing as AI fundamentally redefines the enterprise tech stack, elevating cybersecurity to a mission-critical priority for every organization,” Nikesh Arora, chairman and CEO of Palo Alto Networks, said during his company conference call on Tuesday.”
  • Dark Reading points out “Cyber Insurance Rates Are Dropping, but Exclusions Widen.”
    • “Cyber insurance coverage is slowly changing, and some policies may not provide coverage for social engineering attacks like ClickFix.”
  • Tech Target calls attention to “Lost in translation: Cybersecurity board reporting for CISOs.”
    • “Cybersecurity board reports don’t always land. At the Security and Risk Management Summit 2026, Gartner analysts suggested a novel way to communicate cyber-risk to corporate directors.”
  • A Cybersecurity Dive commentator delves into “Turning tension into collaboration: How CIOs and CISOs can lead together.”
    • If properly managed and channeled, age-old friction between IT and cybersecurity can create a more resilient organization.
  • Here is a link to Dark Reading’s CISO Corner.

Cybersecurity Saturday

From the War with Iran front

  • SC Media reports,
    • The Iran state-sponsored threat group Nimbus Manticore conducted attacks during the U.S.-Israel military campaign Operation Epic Fury targeting the U.S. aviation industry and others for deployment of a new AI-assisted backdoor called “MiniFast,” Check Point Research reported Friday [May 22].
    • The attacks, seen throughout the 2026 Iran war in March, followed previous campaigns throughout February using an older backdoor called MiniJunk. Both waves of attacks utilized career-themed phishing lures for initial access and AppDomain hijacking techniques to execute malicious payloads. * * *
    • Check Point said Nimbus Manticore has shifted tactics in its most recent attacks, seen after the Iran war ceasefire in April, using search engine optimization (SEO) poisoning to impersonate the software Oracle SQL Developer and spread MiniFast.
    • “MiniFast, the successor of MiniJunk, enables extensive control of the victim’s machine through API-based communications with the attacker’s command-and-control (C2) server. As in previous attacks, Nimbus Manticore used career-themed phishing lures to spread MiniFast during Operation Epic Fury, specifically impersonating a U.S. domestic airline.”
  • Cybersecurity Dive adds,
    • “Iranian government-linked hackers sabotaged the computer infrastructure of Los Angeles’s transit system by using access to a virtual machine to delete critical operating-system data, the Israeli cybersecurity firm Gambit Security said in a report published on Tuesday.
    • “The same threat actor also conducted data-wiping attacks on the South Florida Regional Transportation Authority, the connected-vehicle technology firm Agnik and a Saudi Arabian construction company that handles critical infrastructure projects, according to the report.
    • “Gambit dismissed the hackers’ claims of being a new pro-Iranian hacktivist gang, instead attributing their operations to Black Shadow, a group that the Israeli government and private security firms have linked to Iran’s Ministry of Intelligence and Security.”

From the Project Glasswing front,

  • Bleeping Computer reports,
    • “Anthropic has confirmed that it plans to bring Mythos-class models to the general public after delaying the rollout due to security risks to public and private software.” * * *
    • In a blog post, Anthropic confirmed that it plans to release Mythos-class models to the public in the coming weeks, but it has not committed to a specific timeframe.
    • “We’re making swift progress on developing these safeguards and expect to be able to bring Mythos-class models to all our customers in the coming weeks,” Anthropic said in a blog post.
    • “Anthropic says it is already allowing a small number of organizations to use Claude Mythos preview for cybersecurity work, but it is unclear if the same model will be rolled out to the public.
    • “According to the company, the Mythos model shows major improvements in code reasoning and autonomy, far above Claude’s current flagship model, Opus 4.8.”

From the cybersecurity policy and law enforcement front,

  • Beckers Health IT reports,
    • “House Republican leaders are calling on FBI Director Kash Patel to act aggressively to stop cybercriminal groups targeting the healthcare industry.
    • “In a May 28 letter to Mr. Patel, the lawmakers pointed to the sharp increase in healthcare ransomware attacks and data breaches over the past several years that jeopardize patient safety and cost hospitals and health systems millions of dollars.
    • “We strongly encourage continued collaboration between the FBI and healthcare stakeholders, including through public-private partnerships, streamlined reporting mechanisms, and clear guidance that enables hospitals — large and small — to participate effectively in information-sharing initiatives without undue burden,” the legislators wrote.”
  • Cyberscoop relates,
    • “House subcommittee will hold an open hearing next week on how frontier artificial intelligence models are shaping the cybersecurity landscape, for good and for ill.
    • “The June 4 hearing will be the second the Homeland Security Subcommittee on Cybersecurity and Infrastructure Protection has held that was focused at least in part on the subject, following a similar hearing held in December. But unlike at that joint subcommittee hearing, where members also examined other emerging technologies, AI takes center stage next week. * * *
    • “The witnesses will be Sandra Joyce, vice president of Google Threat Intelligence; Chris Meserole, executive director of the Frontier Model Forum; Jack Cable, a former top official at the Cybersecurity and Infrastructure Security Agency and now chief executive officer and co-founder of Corridor Security; and Matthew Guariglia, senior policy analyst at the Electronic Frontier Foundation.”
  • and
    • “The White House has updated rules for federal agencies to keep logs of significant cyber activities in their networks, touting it as a measure to cut back on red tape and focus on how cybersecurity risks have evolved.
    • “The Office of Management and Budget memorandum, released Friday, replaces a 2021 memo signed by then-President Joe Biden. It continues revisions that President Donald Trump has made to federal cybersecurity guidance under his predecessor.
    • “The new memo, M-26-14, nods at the intentions of the earlier memo, M-21-31, saying that “Implementation of that memorandum improved foundational capabilities across agencies” to establish standards for logging and improve agencies’ record-keeping for the purposes of detecting and responding to cyberattacks.” * * *
    • There have been calls for the idea of updating the 2021 memo, and one observer praised the new version to CyberScoop. Another analyst, however, questioned how much harm the Trump administration might do by rescinding the earlier memo before having all of the new memo’s directives in place.
    • “One directive is for the Cybersecurity and Infrastructure Security Agency to develop a “logging reference architecture” within 90 days that prioritizes the objectives of conducting continuous event monitoring and enabling investigations of forensic analysis after a known or suspected compromise.
    • “Agencies would have another 90 days to submit a logging plan that adheres to those principles. The memo also establishes a new model for measuring agency progress in implementation. Multiple government watchdogs have concluded that agencies weren’t meeting the prior memo’s benchmarks.”
  • Federal News Network adds,
    • “Acting Federal Chief Information Security Officer Mike Duffy wrote on LinkedIn that the new policy “focuses agencies on what matters most: continuous visibility, rapid detection, effective threat hunting and actionable response capabilities.”
    • “And given the recent discovery by Claude’s Mythos of thousands of zero day vulnerabilities in systems that were previously known or not addressed, agencies and industry are being forced to figure out how best to strengthen their partnership against these AI-fueled attacks.
    • “Nick Andersen, the acting director of the Cybersecurity and Infrastructure Security Agency, said he has deep concerns specifically about one type of technology when it comes to cybersecurity vulnerabilities.
    • “The open source community is one that I’m particularly worried about when we start to think about the rapid escalation of vulnerability discovery. But it is going to result in us having to make some really, really hard decisions on the level of investment that’s going to be required,” Andersen said on May 21 at the Cyber Innovation Summit sponsored by the National Security Institute at George Mason University’s Antonin Scalia Law School.”
  • Cyberscoop cautions,
    • “A Department of Commerce inspector general report released Thursday [May 28] found that the National Institute of Standards and Technology has mismanaged a critical cybersecurity vulnerability database through poor planning, inefficient operations, duplicate federal programs, and failure to communicate with users.
    • “The National Vulnerability Database, maintained by NIST since 2005, collects information about computer security flaws and adds details like severity ratings and affected products. This information helps cybersecurity professionals across government and the private sector decide which security problems to fix first. In February 2024, the database’s enrichment contract lapsed, creating a backlog of unprocessed security flaws that has only grown worse.
    • “The report identified the lack of strategic planning as a core problem. NIST leaders admitted they had no long-term plan for clearing the backlog, even as it grew from about 13,000 unprocessed security flaws in June 2024 to over 27,000 by the end of 2025.
  • The American Hospital Association lets us know,
    • “The Cybersecurity and Infrastructure Security Agency May 26 announced a revised schedule for its series of virtual town hall meetings for public input on proposed rulemaking for the Cyber Incident Reporting for Critical Infrastructure Act of 2022. The meetings will now begin June 15. They were originally scheduled for March and April but were not held due to the partial shutdown of the Department of Homeland Security. CISA seeks input to finalize a proposed rule originally issued in March 2024. The proposed rule would require critical infrastructure organizations, including hospitals and health systems, to report certain cyber incidents to CISA within 72 hours and ransom payments within 24 hours, among other mandates. The AHA commented on the rule, calling certain proposed requirements redundant to those from other federal agencies and saying that they may add unnecessary burden to hospitals working to ensure access to needed services during cybersecurity incident response.”
  • CISA notes,
    • “The revised [town hall meeting] schedule is available in the Federal Register. Interested stakeholders may register for the town hall meetings at www.cisa.gov/circia. Any changes or updates to the town halls will be available on www.cisa.gov/circia
  • Cybersecurity Dive tells us,
    • “The Cybersecurity and Infrastructure Security Agency on Thursday [May 28] warned that hackers targeted software development pipelines in recent weeks and urged security teams to check for potential compromise of their environments. 
    • “CISA referenced two recent campaigns, including the “Megalodon” supply chain attack and a GitHub compromise through a malicious Nx Console Visual Studio Code extension.” * * *
    • “CISA is urging security teams to monitor and conduct audits on their workflow files and activity from contributors. Attention should be paid to suspicious pull requests or direct commits, specifically any coming from an automated account. 
    • “Security teams should revert any unauthorized changes, CISA advised, and check for anything that came in after May 18. 
    • ‘If a compromise is found in connection with a previously compromised Nx Console or GitHub account, CISA suggests the following:
      • “Undertake a forensics review of continuous integration/continuous delivery logs, impacted developer machines and cloud audit trails. 
      • “Rotate or revoke secrets, including credentials, tokens and secrets related to CI/CD pipelines.”
  • The Wall Street Journal informs us,
    • “The FBI’s latest report on internet crime complaints shows cybercriminals are using AI, causing $893 million in losses.
    • “Cryptocurrency investment fraud was the largest source of financial losses, totaling $7.2 billion last year.
    • “Government-impersonation scams increased to over 32,000 complaints last year, aided by AI for sophistication.”
  • Bleeping Computer points out,
    • “A North Carolina man was sentenced to more than 10 years in prison for selling the personal information of over 7 million elderly Americans to Jamaican scammers.
    • “57-year-old Troy Murray (who used the Steve Dixon pseudonym) pleaded guilty in January 2026 to one count of conspiracy to commit wire fraud and was sentenced Thursday to 121 months in prison, three years of supervised release, and ordered to forfeit $5,2 million.
    • ‘Prosecutors said that Murray’s alias was so widely known among Jamaican scammers that it was referenced in a 2022 song lyric by a Jamaican musical artist.
  • and
    • A Romanian national was sentenced this week to 56 months in federal prison for breaking into an Oregon state government computer network and fr cyberattacks targeting dozens of other U.S. victims.
    • 46-year-old Catalin Dragomir (who used the online handle “inthematrixl”) of Constanta, Romania, pleaded guilty on February 19 to one count of aggravated identity theft and one count of obtaining information from a protected computer.
    • The charges carried a maximum of five years in prison for the computer intrusion count, followed by a mandatory consecutive two-year term for the identity theft count, a fine of $250,000, and three years’ supervised release. The court also ordered Dragomir to forfeit approximately 23 Monero (XMR), a cryptocurrency, valued at roughly $8,500.

From the cybersecurity breaches and vulnerabilities front,

  • Bleeping Computer reports,
    • “The ShinyHunters extortion gang stole personal information from 4.9 million accounts after hacking the U.S. telecom giant Charter Communications in early April, according to data breach notification service Have I Been Pwned.
      “Charter has over 92,000 employees and provides internet, mobile, video, and voice services to more than 32 million customers and over 57 million homes in 41 states across the U.S. through its Spectrum brand.
      “The company confirmed the breach earlier this week, saying that the attackers did not steal sensitive personal customer information and that it had alerted authorities about the incident.”
    • * * * “After the company refused to pay the ransom demanded by ShinyHunters to have the stolen data returned and destroyed, the cybercrime group leaked the documents stolen from Charter’s Salesforce instance on their dark web leak site.
    • “Have I Been Pwned analyzed the leaked data and confirmed that the incident affected 4.9 million accounts, whose names, email addresses, job titles, phone numbers, and physical addresses were stolen.
    • “The group later published the data, which exposed 4.9M unique email addresses along with names, phone numbers and physical addresses,” Have I Been Pwned said. “A subset of approximately 85k records originating from an internal employee directory also included job titles.”
    • “The FBI has recently advised ShinyHunters’ victims not to give in to the gang’s ransom demands, after previously warning that doing so cannot guarantee that threat actors won’t attempt to sell the stolen data to other cybercriminals or extort them again.
  • and
    • “Threat actors are abusing ChatGPT’s content-sharing feature to display fake OpenAI outage pages that direct users to download malware disguised as the ChatGPT desktop application.
    • “The “LLMShare” campaign, discovered by Push Security, uses Google ads to direct users searching for ChatGPT to a malicious shared ChatGPT page hosted on chatgpt.com, allowing the attack to be delivered through a legitimate OpenAI domain.
    • “Users who click the advertisement are taken to a legitimate ChatGPT shared page, but instead of seeing a chat conversation, they are presented with a rendered outage notice claiming the web version is unavailable and that they should download the desktop application instead.”
  • Security Week relates,
    • “The infamous extortion gang Silent Ransom Group (SRG) has been impersonating IT support in a fresh campaign targeting law firms, the FBI warns.
    • “Active since at least 2022, SRG has been targeting law firms in the US since at least 2023, mainly through callback phishing emails and social engineering calls, claiming to aid victims in canceling subscription fees.
    • In a May 2025 alert, the FBI warned of SRG’s phishing emails containing links to remote access software that allowed the attackers to quickly exfiltrate data from the victims’ systems.
    • “In attacks observed this year, the threat actor has updated its tactics, now posing as an employee from the victim’s IT department.” * * *
    • “To prevent SRG attacks, organizations are advised to verify the credentials of all individuals with access to company assets, limit access to sensitive data, train employees to identify phishing attempts, and establish clear policies for IT support communication and authentication.
    • “Backing up all company data, implementing phishing-resistant multi-factor authentication (MFA), blocking access to commonly exploited ports, and disabling remote access and permissions for external drive installation should also prevent intrusions and the loss of sensitive and confidential data.”
  • Cybersecurity Dive tells us,
    • “Nearly all executives are confident their employees are using AI responsibly, but shadow AI is creeping its way into organizations, an Okta survey released Wednesday found. More than half of employeesreported they’re using personal AI tools without approval, the security platform provider learned in surveying nearly 300 tech executives and 500 knowledge workers along with market research firm Apprize360.
    • “Workers reported using unapproved AI tools for productivity reasons, saying they allow the tools access to internal messages, HR-related information and confidential company documents. The practice is heightening security risks, as 58% of executives said their organization had an AI-related security incident or a close call last year, according to the report. 
    • “Lack of clarity in AI usage policies or banning personal AI tools can actually increase shadow AI use, said Harish Peri, Okta’s SVP and GM for AI security, in an email. “By taking a more collaborative approach with employees, leaders can offer sanctioned, enterprise-grade alternatives to the unapproved tools that teams are using.”

From the ransomware front,

  • Industrial Cyber reports,
    • “The Federal Bureau of Investigation (FBI) disclosed that about 25 ransomware groups used a criminal VPN service known as ‘First VPN Service’ to conduct network intrusions, scanning operations, botnets, denial-of-service attacks, and scams. The service has been active since around 2014 across 32 exit nodes in 27 countries. It affects organizations by enabling ransomware groups and other cybercriminal actors to conduct network intrusions, reconnaissance, credential abuse, denial-of-service attacks, and broader malicious operations.
    • “At least 25 ransomware groups, such as Avaddon Ransomware, have used First VPN Service infrastructure to perform network reconnaissance and intrusions,” the FBI wrotein a recent FLASH advisory. “First VPN Service IP addresses have been used for scanning activity, botnets, denial of service attacks, scams, and hacking. First VPN Service was almost exclusively advertised in known criminal dark web forums such as Exploit[.]in and XSS[.]is, two of the most prominent Russian-language online forums which provide marketplaces for cyber criminals to buy and sell unauthorized access to computer systems, stolen personal identifying information, hacking tools, and contraband. This reporting applies solely to the First VPN Service and does not extend to other VPN providers with similar naming.” 
    • “The revelation came alongside a coordinated international takedown of the service, led by French and Dutch cybercrime units with support from Ukraine, the U.K., Switzerland, and Luxembourg. It follows from the findings that the VPN was marketed almost exclusively on prominent Russian-language dark web forums used by cybercriminals to trade stolen data, hacking tools, and unauthorized access to systems.”
  • Morphisec tells us “How AI is Changing Ransomware — and Why It’s Faster, Smarter, and Harder to Detect.” 
    • “AI-driven ransomware is still in its early stages, but the direction is clear. Threats are becoming:   
      • “faster  
      • “more adaptive
      • “more autonomous  
      • “harder to observe  
      • “increasingly resistant to detection    
    • “Organizations that continue relying solely on reactive security models will face growing exposure as attack timelines shrink, and visibility gaps expand. The future of cybersecurity will not be defined by who can detect threats fastest. It will be defined by who can prevent them from executing at all.”   
  • Tech Radar adds,
    • “There is a glaring misconception at the heart of cybersecurity that cyber-attacks are targeted at specific organizations or sectors. But while certain sectors do receive more than their fair share of attacks, this isn’t due to deliberate targeting; like any business, it’s driven by money.
    • “Threat groups are largely driven by financial gain, with actors looking to get the most ‘bang for their buck’. Targeting vulnerabilities that don’t just give them access to one organization, but multiple, to grow their potential revenue opportunities.
    • “And at the moment, organizations are leaving far too many of these vulnerabilities open for exploitation.”

Cybersecurity business and defenses front,

  • Cybersecurity Dive reports,
    • “IBM will spend $5 billion to help find and fix vulnerabilities in open-source software packages used throughout the business world, the company announced on Thursday [May 28].
    • “Through Project Lightwell, IBM will create “a trusted enterprise clearinghouse combined with a global force of engineers to identify and fix vulnerabilities at scale,” using AI to validate and test the patches before deployment, the company said. Businesses will be able to subscribe to the patching program for automated deployment of fixes that integrates with their existing life cycle management processes.
    • “Open source is the backbone of today’s digital economy and the foundation of modern AI, and we are at an inflection point in how it is built, secured, and scaled,” IBM CEO Arvind Krishna said in a statement. “This is about strengthening trust in the systems that power business, government, and society.”
  • Security Week relates,
    • “Google Cloud this week announced an always-on autonomous platform designed to protect enterprises from the rising wave of AI-powered cyberattacks.
    • “The new Google AI Threat Defense cybersecurity solution leverages AI to identify machine-powered threats faster and stop them before they can do harm.
    • “According to Google, the platform continuously prioritizes critical real-world risks and can help organizations implement defenses that predict attack paths and proactively deploy remediation.
    • “Google AI Threat Defense combines Mandiant’s frontline and incident response experience with Wiz’s cloud security platform (recently acquired by Google) and Gemini’s reasoning and code remediation capabilities powered by Gemini and CodeMender.
    • “By connecting real-world exposure directly to autonomously creating and prioritizing patching, AI Threat Defense helps organizations actively predict attack paths, prioritize the most significant threats, and deploy verified fixes faster than adversaries can exploit them,” Google says.”
  • and
    • “Anthropic has announced two new security features for its Claude AI: a self-hosted sandbox and a new security guidance plugin.
    • “The sandbox, currently in public beta, was announced at Anthorpic’s Code w/ Claude event in London this week.
    • “According to the company, Claude Managed Agents can now operate in a user-controlled sandbox connected to the user’s private MPC servers. 
    • “Tool execution moves to an environment you configure—your own infrastructure or a managed provider like Cloudflare, Daytona, Modal, or Vercel—while the agent loop that handles orchestration, context management, and error recovery stays on Anthropic’s infrastructure,” Anthropic explained. 
    • “It added, “Your network policies, audit logging, and security tooling apply, files and repositories don’t leave your perimeter, and you control compute sizing and the runtime image for compute-heavy work.”
    • “Separately, the company unveiled a security guidance plugin for Claude Code, designed to help developers detect and fix vulnerabilities as they write code.”
  • Cyberscoop informs us,
    • “CrowdStrike has dismantled the Glassworm botnet in an operation aided by Google and Shadowserver, stripping the operators’ access to infrastructure that helped threat actors infect hundreds of pieces of open-source software with malware since early 2025, the company said Tuesday [May 26]. 
    • “The coordinated effort involved the simultaneous takedown of four attacker-controlled servers that were designed to obscure the botnet’s operations and remain resilient against disruptions.
    • “CrowdStrike and partners took down infrastructure, severed access to the botnet’s most critical services, impeded operation momentum and slowed the attackers’ ability to scale, Adam Meyers, senior vice president of counter adversary operations at CrowdStrike, told CyberScoop.”
  • and
    • “Security researchers chained together five separate weaknesses in the popular workflow automation service Zapier that, if first discovered by a malicious actor, could have granted access to millions of user accounts and the systems those accounts connect to.
    • :The flaws, disclosed by security firm Token Security, did not require malware or insider access. The only prerequisite, according to the company’s report, was a free Zapier account. From there, researchers chained together weaknesses that, if taken individually, would have looked routine, but together opened a path to one of the most widely used services of the modern internet.
    • “Zapier’s software can be configured to move data between email, customer-relationship tools, payment processors, calendars, code repositories and thousands of other applications. Zapier says it supports more than 8,000 third-party integrations and has millions of users, which means breaking into Zapier could escalate into a wide-ranging supply-chain attack.” * * *
    • “The episode lands at a moment when automation platforms and artificial-intelligence tools are increasingly being granted the standing authority to act on behalf of users across dozens of services at once. Token Security’s researchers argued that the weaknesses they found were not unique to Zapier. Each link in the chain, they said, was a well-documented kind of mistake. The vulnerability was the chain itself, and the same pattern, they warned, almost certainly exists at other companies that have not yet looked.
    • “Zapier says the issues have been fixed and no further action is required. But the researchers suggested organizations with heightened sensitivity review their automation logs for anything they did not create, and consider reauthorizing Zapier connections to particularly sensitive systems.
    • “You can read the full research report on Token Security’s website.” 
  • Tech Target points out
    • “The unified platform versus best-of-breed tools debate continues as security teams struggle with integration challenges, alert fatigue and limited resources. Does buying software from individual vendors still make sense, or does that approach only further complicate today’s distributed networks? The pressure is prompting a fresh look at unified security platforms as a way to reduce complexity and costs, improve visibility and regain control.”
  • An SC Media commentator identifies “seven identity security best practices for the Agentic AI era.”
    • “Execute regular identity security risk assessments: Leverage tools that can clearly show what AI agents operate in our environment, including those that are operating as shadow IT. This analysis should put risks in clear context, including agent security posture, and potential escalation paths.
    • Encrypt credentials: Put them in a secure vault, with automatic key rotation to make it harder to steal or reuse valid credentials.
    • Restrict remote access to systems: Use leverage tooling that can perform automated credential injection from the company’s vaults to prevent adversary-in-the-middle attacks.
    • Use workload identity to avoid long-lived tokens: Also use scoped permissions, whether OAuth-based or otherwise, to reduce the “blast radius” of stolen credentials.
    • Limit permissions on endpoints with endpoint privilege management tools: Default permissions to “standard user” and set up policies that limit what local agents can do on those systems. Remove standing policies and replace them with JIT or time-limited policies and permissions.
    • “Implement IP allowlisting: This will reject AI agent requests coming from non-authorized locations.
    • Log and audit all privileged behavior: Do this in all systems, whether that’s through tools such as session logs, shipping event logs to a SIEM, or using anomalous behavior analysis tools in the SOC.”
  • Here is a link to Dark Reading’s CISO Corner.