Skip to content
SPECIAL

THREATS TO CRITICAL INFRASTRUCTURE IN IRAN CONFLICT

READ MORE

Cyber Briefing – July 20, 2026


Cyber Briefing

TODAY’S TOP 5

‘UNFORGETTABLE LESSONS’ THREATENED NEXT IN IRAN’S CYBERWAR: After an April cessation in kinetic hostilities was announced in the United States’ conflict with Iran, a key state-connected Iranian hacking group similarly dialed back its mounting public threats against critical infrastructure and declared that it had “currently postponed overt confrontation” with the United States per “highest leadership” orders. Now, as the ceasefire has collapsed and strikes have resumed, Handala has circled back to ominous critical infrastructure threats that reflect those made earlier in the war yet aren’t as detailed, Threat Beat reports. On Thursday, the group posted on its Telegram channel an image of various critical infrastructure sectors — pumps at a gas station, an aisle at a supermarket, an electricity substation and a water treatment facility — accompanied by the text “YOU WILL REALIZE.”

  • The United States conducted a new round of airstrikes early today targeting Iran after announcing the death of another American service member, hitting around a northwestern city believed to be home to underground missile bases. Iran responded by launching an attack targeting Bahrain, the home of the U.S. Navy’s 5th Fleet, and Kuwait, The Associated Press reports. The latest attacks again showed how, step by step, the U.S. and Iran have inched closer to all-out war as last month’s interim deal meant to permanently end the fighting has crumbled and shipping traffic in the Strait of Hormuz has largely stalled. Both sides have targeted civilian infrastructure relied on by millions of people.
  • Reports of Russia-Iran collaboration in the U.S.-Iran conflict are a real and live source of concern. Russia has shared intelligence with Iran that purportedly led to the targeting of U.S. soldiers in the Middle East, as well as drone technologies that have given Iran a substantive asymmetric edge in targeting regional adversaries. However, collaboration on cyber operations has been repeatedly misread and misunderstood, including claims that Russia has supplied Iran with cyber support and that pro-Russia actors have formed a coalition with Iranian hackers, both of which have only a thin evidence base, Nikita Shah and Justin Sherman write at CSIS.
  • From missile warning to satellite communications for drones, the Space Force has played a key, if often unseen, role in the U.S. conflict with Iran, the head of the service’s Combat Forces Command said Friday, Air and Space Forces Magazine reports. And one area in particular has seen Guardians be especially active: the electromagnetic spectrum. “What you are seeing in these operations isn’t just extremely proficient space operations. What you’re seeing from U.S. forces is extremely proficient joint operations,” Lt. Gen. Gregory J. Gagnon said at a virtual event with AFA’s Mitchell Institute for Aerospace Studies. The Space Force’s combat contributions are often hidden behind a veil of classification, but officials have offered more and more hints about those efforts in recent months. 

APPS MARKETED TO U.S. TROOPS ARE SHIPPING CHINESE AND RUSSIAN CODE: A recent examination of hundreds of mobile apps marketed toward U.S. military personnel found more than one in eight contained software built by companies in China, Russia or other foreign nations, raising fresh concerns that adversary governments could harvest data revealing where service members live, work and deploy, WIRED reports. According to researchers at Purdue University, the U.S. Military Academy at West Point, and Florida International University, one popular app used by service members to rate living conditions on their own bases include code from Huawei, the Chinese telecom that U.S. regulators flagged as a national security threat in 2020. Two others were built by Russian companies and incorporate the Russian ad service Yandex.

  • The Pentagon wants to move quickly with its review of the Cybersecurity Maturity Model Certification program, but plenty of questions swirl around what defense officials can do differently this time to balance compliance concerns for small businesses with the need to enforce cybersecurity requirements, Federal News Network reports. The CMMC review team met for the first time on Thursday, Defense Department Chief Information Officer Kirsten Davies told reporters that same day following a tour of the factory floor at Kform, a small defense manufacturer based in Sterling, Va. Davies was joined on the tour by Small Business Administrator Kelly Loeffler and Under Secretary of Defense for Acquisition and Sustainment Michael Duffey.
  • More than 1,000 participants from 44 states and territories, along with military and civilian cyber professionals from 23 partner nations, are participating in Cyber Shield 2026, the Department of Defense’s longest-running and largest unclassified cyber defense exercise, the 382nd Public Affairs Detachment reports. Participants will work together in close quarters to gain advanced cyber knowledge and test their ability to defend against cyberattacks through real-world scenarios, strengthening overall National Cybersecurity. Held July 12-25 at the Professional Education Center in Little Rock, Cyber Shield 2026 brings together National Guard, active-duty, Reserve, civilian and international participants to strengthen cyber defense capabilities through realistic, scenario-based training. This exercise develops participants’ ability to detect, respond to and defend against cyber threats while reinforcing partnerships that support national and global cybersecurity.

CHINESE OPEN-WEIGHT MODEL MORE MEMORY THAN COMPUTE?: When DeepSeek’s R1 debuted in early 2025, almost $600 billion was wiped out from Nvidia Corp.’s market value in a single day on fears that artificial intelligence would require less computing power than previously expected. Moonshot AI’s release of Kimi K3 on Friday triggered a similar reaction, helping push semiconductor stocks sharply lower. The comparison, however, may overlook an important distinction, Bloomberg reports. While models such as Kimi K3 are designed to use computing resources more efficiently, they still require enormous amounts of memory to operate, a dynamic that could continue to support demand for companies including SK Hynix Inc., Taiwan Semiconductor Manufacturing Co. and Nvidia Corp. Kimi K3 contains 2.8 trillion parameters, China’s largest model yet, pushing the sparsity ratio — a measure of computing efficiency — to a record, according to data compiled by Bloomberg from disclosures from model producers. A higher ratio means fewer parameters are activated for each task relative to the model’s total size.

OTA TECH CREATES ROUGH ROAD FOR TRANSPORTATION SECTOR: The automotive industry’s increasing use of over-the-air technology to update vehicle systems makes it more susceptible to cyberattacks, analysts say, urging more intervention in the sector. OTA technology is wireless tech that can deliver new software, firmware, fixes and data to internet-connected devices. Tesla began deploying over-the-air updates to its Model S vehicles in 2012. This helped normalize the tech, according to Jason Van der Schyff, a fellow of cyber, technology and security at the Australian Strategic Policy Institute, who noted it is now embedded across much of the automotive sector. “The technology is increasingly welcomed as it is a quick and cost-effective way to manage systems on vehicles, over traditional methods which may have required a recall or update at routine maintenance,” Siraj Ahmed Shaikh, professor in systems security at Swansea University in the U.K, told CNBC.

  • The responsibility for ensuring Italy’s flagship Formula 1 team is prepared to defend against evolving cyberattacks is Luca Pierro, head of enterprise cybersecurity at Ferrari. In this conversation, which took place at Ferrari’s Maranello headquarters, Pierro detailed to Infosecurity Magazine how the team implements a cybersecurity strategy that ensures staff are protected from cyber threats while also operating at speed.

THE RACE TO QUANTUM FIRST: Skeptics have long called quantum computing decades away. Nvidia’s Jensen Huang told analysts in January 2025 that very useful quantum machines were 15 to 30 years away. By March he was walking that back. Within a year, Google had unveiled its Willow processor, Amazon its Ocelot, IBM its Nighthawk and Loon, and Quantinuum, now on the Nasdaq, delivered Helios, a machine already running error-corrected logical qubits, the reliable building blocks a full-scale computer needs. Road maps that were once vague now come with dates, climbing toward the million-qubit scale most vendors assume a fault-tolerant machine will need to run long calculations without errors piling up. The most detailed of them aims at fault tolerance before the decade is out, backed by IBM’s commitment of more than $10 billion. Yet the United States is preparing for the quantum era one office at a time, while the threat is arriving all at once, Mauritz Kop and Joe Federici write at War on the Rocks. Cryptography, artificial intelligence, networks, sensing and the supply chain are being handled as five separate problems on five separate schedules. They share one deadline and one prize: “Quantum First,” before China. Responsibility should sit with the National Security Council, with the first year of work inexpensive and concrete, and allies offered a stake in the science.ors — rapidly and deliberately take steps to enable the widespread, safe deployment of these tools.

OSINT YOU NEED TO START YOUR DAY: The Cyber Briefing is brought to you by the McCrary Institute for Cyber and Critical Infrastructure Security at Auburn University. SUBSCRIBE
WE WANT TO HEAR FROM YOU: What would you like to see in your morning briefing? Reach out to Executive Editor Bridget Johnson with your comments and suggestions

CYBER FOCUS PODCAST

(Watch on YouTube or click the player above)

National security challenges increasingly cut across technology, economic competitiveness, critical infrastructure, manufacturing and workforce development. Universities have a growing role to play not only in conducting research, but also in translating ideas into practical solutions and preparing students to confront real-world problems. Auburn University President Dr. Chris Roberts, McCrary Institute Chairman Lt. Gen. (Ret) Ron Burgess, Senior Vice President for Research Dr. Steve Taylor and Samuel Ginn College of Engineering Dean Dr. Mario Eden join Frank Cilluffo on the latest episode of Cyber Focus to discuss Auburn’s commitment to national security. The conversation explores the changing threat environment, the university’s expanding research presence in Huntsville, partnerships among academia, government and industry, and how experiential education can prepare students for jobs and technologies that do not yet exist.

SUBSCRIBE TO CYBER FOCUS: YouTube | Spotify | Apple Podcasts

CYBER AND CI UPDATES

ATTACKS AND INCIDENTS

Artificial intelligence

AI-driven cyberattack compromises Hugging Face production infrastructure via autonomous agent

On July 16, Hugging Face, the world’s largest AI model repository, publicly disclosed a breach of its production infrastructure. The intrusion was executed entirely by an autonomous AI agent, marking a significant escalation in the operational use of AI-driven cyberattacks. Attackers exploited two code-execution vulnerabilities in the dataset processing pipeline, enabling remote code execution, privilege escalation, credential harvesting, and lateral movement across internal clusters. The breach resulted in unauthorized access to a limited set of internal datasets and several service credentials. There is no evidence of tampering with public models, datasets, Spaces, or the software supply chain. The incident was detected and contained using Hugging Face’s own AI-based forensic analysis pipeline. The company has advised users to rotate access tokens and review recent account activity as a precaution. This event highlights a new asymmetry in cyber defense: attackers can leverage unrestricted AI agents, while defenders may be constrained by commercial model guardrails. The breach underscores the urgent need for organizations to deploy self-hosted, vetted AI models for both defense and forensic response. (RESCANA.COM)

Biothreats

FDA walks back finding of cyclospora parasite as outbreak probe continues

Taylor Farms said that the Food and Drug Administration has apologized after the agency walked back an earlier statement that the parasite linked to an outbreak affecting thousands of people had been detected on a sample of its lettuce. The FDA on Sunday said it has yet to identify the presence of cyclospora on samples of lettuce from the company despite recent tests. The agency now deems the detection that it reported Saturday a false positive after laboratory experts reviewed the sample results. Taylor Farms, which supplies some of the country’s biggest retailers and restaurants, makes a range of products from salad kits to vegetable blends. (WSJ.COM)

AI takes on the cyclospora outbreak

It’s been the most explosive U.S. public health crisis so far this summer: An outbreak of extreme intestinal illness for thousands of people across dozens of states caused by cyclospora, a microscopic parasite that health officials say they’ve traced to iceberg lettuce served at some fast-food restaurants. With nearly 6,000 suspected cases and growing, researchers are leaning into artificial intelligence to respond to the largest multistate outbreak in years. While experts don’t expect AI to solve thecCyclospora problem, some clinical laboratories are using AI tools for diagnostics to dramatically accelerate the processing of sick patients’ feces samples for testing and diagnosis. (HEALTHCAREINFOSECURITY.COM)

Breaches

Ernst & Young discloses data breach after support system hack

Ernst & Young is notifying customers of a data breach caused by the compromise of a third-party support ticket system used by its IT personnel. According to the company, support tickets submitted through the platform may have included documents containing client tax information. Ernst & Young (EY) is among the world’s four largest auditing and professional services providers, offering auditing, tax, consulting, and transaction advisory services to major organizations in more than 150 countries. (BLEEPINGCOMPUTER.COM)

Cybercrime

Police chiefs cite TfL hack in push for cybercrime risk orders

Following the sentencing of two young men for the 2024 Transport for London (TfL) hack, senior police officers have said the case makes a compelling argument for tougher legal powers in the UK, namely Cybercrime Risk Orders (CCROs). Owen Flowers, 19, and Thalha Jubair, 20, were sentenced to five and a half years in prison each for committing unauthorised acts against TfL under Section 3ZA the UK’s Computer Misuse Act (CMA) 1990. Both men are believed to be part of Scattered Spider, a cybercriminal group that has been linked to major cyber-attacks over the past few years, including the Marks & Spencer and Co-op incidents in 2025. (INFOSECURITY-MAGAZINE.COM)

Government

Kenya restores presidential website after cyberattack

Kenya’s official presidential website, president.go.ke, is back online after hackers defaced its homepage and demanded a ransom of five Bitcoin, worth approximately KSh41.3 million (about $320,000), in an attack detected on 18 July 2026. The attackers replaced the site’s homepage with messages targeting President William Ruto directly, alongside a cryptocurrency wallet address, and threatened to leak unspecified information about the president if payment was not made by 6pm the same day. (ITWEB.AFRICA)

Health care

Abbott probes two cyber incidents amid extortion claims

Abbott Laboratories is investigating two separate cybersecurity incidents after confirming unauthorized access to internal legacy Exact Sciences systems in its Cancer Diagnostics business, while also investigating a separate claim that attackers breached its LabCentral portal and stole company data. The company confirmed the Cancer Diagnostics incident after the ShinyHunters extortion gang added Abbott to its data leak site, initially threatening to publish allegedly stolen data after July 18 unless the company negotiated with the group, before later extending the deadline to July 21. (BLEEPINGCOMPUTER.COM

Health tech firm Craneware says customer and staff data stolen in cyberattack

Healthcare technology firm Craneware said it has been hit by a cyber attack with hackers stealing some customer and employee data. The Edinburgh-based company provides software to the US healthcare industry, including thousands of hospitals, clinics and pharmacies. Craneware, which is listed on London’s Alternative Investment Market (AIM), said it was responding to and investigating a cyber incident through which a significant volume of file names were viewed and exfiltrated. (UK.FINANCE.YAHOO.COM)

Ransomware

Inc ransomware exploits SonicWall SMA zero-days

Two newly reported vulnerabilities in SonicWall’s Secure Mobile Access (SMA) appliances have been exploited as zero-days by a major ransomware group. On July 14, the cybersecurity vendor SonicWall published a security advisory regarding two vulnerabilities in its SMA 1000 Series appliances, CVE-2026-15409 and CVE-2026-15410. Together they could allow any random, unauthenticated attacker to gain remote code execution (RCE) powers and then run commands on the box at the root level. (DARKREADING.COM)

Government agencies falling victim to ransomware daily, warns study

The number of ransomware attacks which target government departments and agencies has risen to the extent that one has its services restricted by encryption every single day. The figure comes from analysis by researchers at Comparitech, who studied ransomware incidents which targeted government entities between January and June 2026. The research, published on July 16, recorded that 187 government organizations were hit with ransomware during the first six months of 2026. That represents a 13% increase on the 165 ransomware attacks recorded during the second half of 2025. (INFOSECURITY-MAGAZINE.COM)

WATCH: White House National Cyber Director Sean Cairncross, CISA Acting Director Nick Andersen and more top leaders at the recent McCrary Cyber Summit

THREATS

Supply chain

SleeperGem: RubyGems supply chain attack targets dormant maintainer accounts

The package immediately stood out because it simply downloaded binaries from a Git repository hosted at https://git.disroot[.]org/git-ecosystem/. Pulling the four versions apart, you can watch the delivery mechanism get built in real time over about nine hours, in two sittings. Version 2.8.0 was already a fully working dropper on day one: build a URL against that hardcoded Forgejo host, fetch it with certificate verification explicitly switched off, and hand the payload straight to a shell or PowerShell. (AIKIDO.DEV)

Vulnerabilities

New 7-Zip vulnerability could let crafted XZ archives run code during extraction

Opening a crafted XZ archive in 7-Zip could let an attacker run code on the machine. The flaw, CVE-2026-14266, is a heap-based buffer overflow in how the archiver processes XZ chunked data, and Trend Micro’s Zero Day Initiative (ZDI) detailed it on July 15. A fix shipped on June 25 in 7-Zip 26.02. The overflow lets an attacker “execute code in the context of the current process,” per the advisory. The code runs with the token 7-Zip itself holds and gains no privileges of its own. On Windows, a normally launched 7-Zip runs under a filtered standard-user token even on an administrator account, so the attacker inherits those limited rights unless the program was started elevated. The bug came in from Landon Peng of Lunbun LLC, who reported it to 7-Zip on June 5. (THEHACKERNEWS.COM)

OpenSSL fixes HollowByte memory exhaustion bug

Okta’s Red Team disclosed a denial-of-service vulnerability in OpenSSL they named HollowByte, and the attack payload is exactly 11 bytes. A remote, unauthenticated attacker sends that payload and the server allocates up to 131 KB of memory before the TLS handshake even begins, then blocks a worker thread waiting for data that never arrives. No credentials required, no prior access, no exploit chain. “When a rogue header lands, the state machine triggers an unvalidated allocation.” reads the advisory. “When the malicious 11-byte payload arrives, the TLS state machine reads the 4-byte handshake header and triggers an unvalidated pre-allocation based on the header’s 3-byte length declaration. (SECURITYAFFAIRS.COM

ADVERSARIES

China

GoldenEyeDog hackers group behind DigiCert breach that hijacks code-signing certificates

GoldenEyeDog, a Chinese cybercrime group linked to the Golden Gh0st malware family, is back in focus after an intrusion at DigiCert exposed the risks around code-signing certificates. The attackers used the access to intercept customer certificate activation codes and sign their own malicious files. The operation relied on a simple but effective route into a sensitive environment. Malicious files were disguised as screenshots, delivered through phishing emails or support-ticket submissions, and opened by staff who believed they were reviewing customer content. (CYBERSECURITYNEWS.COM)

People in many countries now view China more positively than the U.S.

Global views of the United States worsened last year as President Donald Trump’s second term began, though most people still had a more positive opinion of the U.S. than China. This year, that is no longer the case. Views of China have improved in recent years while opinions of the U.S. have worsened, to the point where China is now seen more positively than the U.S. in most of 36 countries surveyed. Confidence in these countries’ respective leaders to do the right thing regarding world affairs has followed a similar pattern. (PEWRESEARCH.ORG)

North Korea

North Korean Contagious Interview campaign hides OTTERCOOKIE malware in SVG images

A sophisticated North Korean threat campaign dubbed “Contagious Interview” has resurfaced with new delivery techniques, leveraging weaponized SVG image files to deploy the OTTERCOOKIE malware while coinciding with a separate supply chain intrusion targeting the Ruby ecosystem. Security researchers tracking DPRK-linked activity note that the campaign continues to impersonate recruiters and job interview workflows, luring developers into executing seemingly benign files. (GBHACKERS.COM)

MetaMask code was open to a North Korea-linked contractor for a month before Consensys halted releases

A contractor brought in through a third-party provider worked on MetaMask code from March 9 until Consensys cut off access in April. Consensys later described the person as linked to North Korea. Consensys said its investigation found no misappropriation of assets or data, no malicious code deployment and no impact to user safety or security. General counsel Matt Corva said the company identified the threat quickly, terminated access, launched a comprehensive investigation and notified law enforcement. (CRYPTORANK.IO)

Russia

Russian cybercriminal used jailbroken Gemini CLI to rebuild botnet infrastructure in six minutes

A Russian-speaking threat actor known as “bandcampro” used a jailbroken Gemini CLI, Google’s open-source terminal-based AI agent, to deploy and operate a small command-and-control (C2) botnet, according to TrendAI. In more than 200 sessions between March 19 and April 21, 2026, the threat actor worked with Gemini to deploy and operate infrastructure that controlled eight computers inside a dental clinic and gain access to the clinic’s OpenDental database. Posing as an “authorized penetration tester,” he instructed Gemini to suppress safety disclaimers and automatically save any credentials it encountered. Both instructions were placed in Gemini’s memory file, which reloads at the start of each session, allowing them to persist across subsequent conversations. (HELPNETSECURITY.COM)

UAC-0145 uses ClickFix CAPTCHAs to infect Ukrainian devices with malware

Russian state-sponsored threat actors have been observed leveraging the infamous ClickFix strategy to trick Ukrainian targets into infecting their own machines with data-stealing malware. According to the Computer Emergency Response Team of Ukraine (CERT-UA), the activity has been attributed to UAC-0145, a sub-cluster within Sandworm, an advanced hacking unit affiliated with GRU, Russia’s primary foreign military intelligence agency. In these attacks, threat actors have been found to leverage fake CAPTCHA checks on compromised websites that instruct prospective targets to execute a PowerShell command in the terminal. (THEHACKERNEWS.COM)

Ukraine’s Unmanned Systems Forces strike 13 more Russian shadow fleet vessels

Ukraine’s Unmanned Systems Forces (USF) struck an additional 13 vessels linked to Russia’s shadow fleet in the Black and Azov Seas on July 18. The targeted maritime assets included eight dry cargo vessels, one oil tanker, one gas carrier, one tugboat, and two floating cranes. According to a statement by USF Commander Robert “Madyar” Brovdi, this latest attack brings the total number of vessels hit during the ongoing campaign, designated Operation “Molochka,” to 172. (KYIVPOST.COM)

Russia’s virtual retreat in war against Ukraine is accelerating

Perceptions of Russia’s war against Ukraine are shifting, as the impression of stalemate gives way to Ukraine’s growing military-technological edge and Moscow’s visible strategic drift. The North Atlantic Treaty Organization (NATO) summit in Ankara, U.S. President Trump’s silence toward Russian President Vladimir Putin, and Türkiye’s alignment with allied deterrence have compounded Russian setbacks in Crimea and the deepening fuel crisis. Elite discontent, spreading repression against business magnates, and public fatigue in Russia suggest that mobilization, strategically necessary to sustain the war, could instead trigger a domestic meltdown. (JAMESTOWN.ORG)

GOVERNMENT AND INDUSTRY

Artificial intelligence

Google and Apple are clashing with the EU over the future of AI assistants

Google and Apple have a big leg up in the AI race: their control of billions of smartphones around the world. That’s according to the European Commission, which is now cracking down on what that means for AI assistants. Apple and Google have long dominated the smartphone market, combining for roughly 5 billion active Android phones and iPhones worldwide, according to market research firm Omdia. And as AI continues to become more ubiquitous and specialized, the two tech giants are enabling their AI assistants to help complete tasks rather than just answer questions. (CNN.COM)

Labor Department eyes AI curriculum akin to China’s teachings

The Department of Labor is working closely with two other agencies to develop AI education for U.S. students that mirrors China’s curriculum for teaching the emerging technology, its acting secretary told lawmakers Thursday. During his confirmation hearing to be the permanent DOL secretary, Keith Sonderling told members of the Senate Health, Education, Labor & Pensions Committee that the Trump administration is taking AI education “very seriously” from a “national competitive” and workforce development perspective. In an exchange with Sen. Josh Hawley, R-Mo., Sonderling said the DOL has partnered with the National Science Foundation and the Department of Education to “develop that AI curriculum that China has.” (FEDSCOOP.COM)

Homeland Security’s updated AI inventory raises more questions than it answers

The Department of Homeland Security posted an updated AI inventory this week, reflecting its implemented risk management practices for high-impact use cases and other changes. The inventory comes months past the April 3 deadline set by the Office of Management and Budget. While sources said it’s better late than never, some of the changes outlined raised more questions than they answered. “DHS deserves credit for revisiting its AI inventory rather than just letting it gather dust for a year,” said Tom Bowman, policy counsel for the Center for Democracy & Technology’s Security and Surveillance Project. “But the revisions themselves are puzzling and uneven.” (FEDSCOOP.COM)

Data centers

Data centers want to build their own gas turbines. Would that skirt state renewable energy laws?

Virginia’s surging energy demands require more power generation infrastructure to be built, a slow process that’s delaying new data centers waiting to be connected to the grid. Dominion Energy, the state’s largest utility, has an estimated 70 gigawatts worth of projects in their queue that need more power sources online before they can link to the energy network. The company is able to connect about 10 large-load customers a year. Tech companies are responding by creating their own power to try to skip the line. (VIRGINIAMERCURY.COM)

Defense

The Pentagon is finally buying (some) weapons from startups

Since taking the top job at the Pentagon, Defense Secretary Pete Hegseth has rewritten rules and upended traditions that had for decades steered how the U.S. military buys weapons. More than a year into his tenure, he is keeping his promise to shower money on high-tech defense startups — while also unloading ever-larger sums of cash on the traditional vendors he has publicly disparaged as slow and bloated. Venture capitalists and startup founders have been salivating at what they hope is a true defense reformation that hands power — and billions of dollars — to defense-tech startups that have been excluded from the inner circle of weapons procurement. (WSJ.COM)

Navy, Army risk wasting money, time without unified hypersonic missile strategy: GAO

The Pentagon doesn’t have a unified strategy for investing in a key hypersonic missile capability for the Navy and the Army — and failing to figure one out could result in additional program delays and inefficient use of funds, a new watchdog report warns. The Navy and the Army are both developing their own versions of what the Navy calls its Conventional Prompt Strike (CPS) capability, with the services collectively aiming to invest more than $50 billion into the hypersonic effort. The Navy is updating its Zumwalt-class destroyers with a vertical launch system to accommodate the CPS missiles, and plans to include the system onto some Virginia-class submarines. (BREAKINGDEFENSE.COM)

DoD selects Accenture to investigate ‘existential supply chain vulnerability’ threatening military medicine

The U.S. military’s medical supply chain is dangerously reliant on foreign entities, prompting the Pentagon to take “an immediate, urgent action” to pinpoint and assess domestic pharmaceutical manufacturing solutions and diversify options for the joint force. According to procurement justification materials published Thursday, the Assistant Secretary of Defense for Health Affairs, in partnership with the Defense Health Agency and Defense Logistics Agency, selected Accenture Federal Services for a firm-fixed-price, sole-source contract to provide supply chain mapping reports and due diligence evaluations, and enable domestic onshoring. (DEFENSESCOOP.COM)

Australian Army unveils Abrams disguised as Chinese tank

The Australian Army has shared photos showing one of its M1A2 Abrams outfitted as a surrogate enemy platform, specifically to represent a People’s Liberation Army main battle tank. Vehicles meant to visually reflect an adversarial platform are a regular feature of exercises involving an Opposing Force (OPFOR). The depiction also reflects Australia’s growing emphasis on preparing for high-end conflict in the Indo-Pacific, and an Australian Defense Force that’s increasingly focusing its training and force structure on the challenges posed by China’s rapidly expanding military capabilities. The photos were published on the Facebook account of the Australian Army’s School of Armor. Located at the Puckapunyal Military Area in Victoria, southeastern Australia, this serves as the army’s center of excellence for mounted combat and armored fighting vehicle training. (TWZ.COM)

IT modernization

IARPA launches new acquisition marketplace

The Intelligence Advanced Research Projects Activity announced on Friday that it has launched a new platform to help rapidly onboard innovative capabilities from the private sector. The IARPA Solutions Marketplace is designed to streamline the procurement process by providing vendors with a pathway to showcase their solutions through short video pitches and then receive feedback from relevant agencies. IARPA, which serves as the Office of the Director of National Intelligence’s research and development unit, also posted a solution notice on SAM.gov. Interested companies can submit their videos through the platform beginning on August 1. (NEXTGOV.COM)

GSA to take its Emerging Tech Showcase governmentwide

As the General Services Administration closes in on achieving its 2026 moonshot goal to save and automate 1 million hours of work for its employees, the agency will showcase and share those internal efforts — and a host of other proven tech efforts — with a governmentwide audience on July 30. Registration for the Emerging Technology Showcase is open to all federal employees, and though the event will be held in person at the Interior Department’s Yates Auditorium, it will be livestreamed for a virtual audience likely in the tens of thousands. “The administration has looked at GSA to lead” on approaches that make government more efficient, effective and responsive, GSA Deputy Administrator Mike Lynch said Thursday at the Government Efficiency Summit. (NEXTGOV.COM)

Nuclear

Nuclear energy could be in for a big decade

The global nuclear energy industry has been muted since 2011, when the Fukushima Daiichi disaster unfolded in Japan. Some new reactors have been built — especially in China — but a lot of old nuclear power plants have been retired as well. That means nuclear energy has been “running in place” for well over a decade, as a new report from BloombergNEF puts it. But now, the market is changing — and BNEF’s analysts predict that the sector is poised to break out in a sprint. BNEF forecasts that global nuclear energy capacity will rise to 535 gigawatts by 2036, a 44% increase from last year’s installed capacity of 372 GW. (CANARYMEDIA.COM)

Resilience

Cyberattack can be like the Hiroshima nuke: The man who got Shin Bet to be serious on cyber

When Dr. Harel Menashri pushed the Shin Bet to take computers seriously in the 1990s, the agency, which was built around Arabic-speaking case officers, dismissed the subject as “mumbo jumbo.” Speaking with the Jerusalem Post senior military analyst Yonah Jeremy Bob, Menashri recalled the demonstration that changed officials’ minds. Menashri, a founder of the Shin Bet’s cyber arm who spent 25 years in the service and now heads the cyber program at the Holon Institute of Technology, used a “tiny Trojan” taken from the internet. He said it could have caused Hiroshima-scale damage, killing nearly everyone in the Haifa Bay area. Three decades later, his warnings have only grown more urgent. Menashri explained how malicious code can kill by manipulating SCADA sensors. SCADA is a system of software and hardware that allows industries to monitor and control utilities and industrial equipment from a central location. (JPOST.COM)

Social media

TikTok is no longer banned on U.S. government devices

The Department of Justice has announced that federal employees can now download and install TikTok on electronics provided by the government, explaining that its current version doesn’t pose the risks the previous one did. However, it’s still up to individual agencies to decide whether or not to allow their employees to download TikTok on federal phones. In 2022, TikTok was outlawed on almost all devices issues by the US federal government due to national security concerns. Chris Wray, the FBI director at the time, warned that China could use the app to collect data on users via its parent company ByteDance. (ENGADGET.COM)

Space

Space Force welcomes first part-time guardians

The Space Force welcomed its first part-time troops on Wednesday, bringing in 18 Air Force Reservists as the service rolls out a more flexible personnel model designed to help recruit and retain experienced staff. The Space Force is the first military branch to let troops move between full-time and part-time work without transferring to the National Guard or Reserves, instead keeping both under a single chain of command. The new approach will test how far military service can go to accommodate members’ needs without compromising critical national security missions. (FEDERALNEWSNETWORK.COM)

The Pentagon’s Space Development Agency hasn’t moved as fast as anyone would like

The Space Development Agency was established in 2019 to help speed up the deployment of US military space systems by sidestepping the Pentagon’s traditional sluggish bureaucracy. Seven years later, SDA is finally launching its first batches of operational satellites, just as the Pentagon plans to shutter the semi-autonomous agency and fold it back into the Space Force’s procurement pipeline, newly reorganized under several program acquisition executives in a bid to streamline weapons buying. SDA’s fate is not a surprise, and lawmakers in both houses of Congress have backed the agency’s closure in drafts of this year’s National Defense Authorization Act. (ARSTECHNICA.COM)

DIU seeking ‘near-term’ power-beaming satellite demo

The Defense Innovation Unit (DIU) wants to loft a prototype satellite to low Earth orbit for beaming electrical power, both to other spacecraft and to the ground, within the next several years, according to a new solicitation to prospective commercial vendors. Space power beaming (SPB) “could enable a number of applications of interest to the Department of War such as edge computing, in-space manufacturing, and power delivery to forward operating locations and unmanned systems,” explained DIU’s “Commercial Solutions Opening” announcement, using the Department of Defense’s secondary name. DIU notes that while ultimately envisioned as a “multi-orbit” capability extending into deep space beyond Earth, “Joint Force desires a near-term LEO-based prototype and demonstration to evaluate the military utility of the capability.” (BREAKINGDEFENSE.COM)

LEGISLATIVE UPDATES

Senate committee advances WRDA 2026, expanding cybersecurity support for critical water infrastructure

The Senate Environment and Public Works Committee unanimously approved the bipartisan Water Resources Development Act of 2026 on Wednesday, advancing legislation that authorizes 61 feasibility studies and 15 new or modified U.S. Army Corps of Engineers construction projects focused on flood risk management, navigation and ecosystem restoration. The measure also reauthorizes the EPA (Environmental Protection Agency)’s drinking water and wastewater infrastructure programs, including the State Revolving Funds, and includes provisions to strengthen cybersecurity for critical water systems. (INDUSTRIALCYBER.CO)

Senators to question FERC members on grid, data centers

Senators will have a chance to question all five Federal Energy Regulatory Commission members this week as the agency takes on a prominent role in addressing rising power demand from data centers. The Senate Energy and Natural Resources Committee hearing comes as the commission has garnered bipartisan praise for its initial step last month addressing how to connect massive data centers onto the electric grid. Instead of issuing one uniform rule, the commission sent show-cause orders to six regional grid operators, telling them to examine how large loads and co-located loads connect to the transmission system amid queue backlogs, cost-allocation disputes and affordability concerns. (EENEWS.NET)

Critics mount offensive against change to federal grant rules

Opposition is building to a sweeping government-wide crackdown on federal grant awards, with opponents threatening litigation over a proposed rule that would put the grant approval process into the hands of political appointees. A request for public comment on the rule by the Office of Management and Budget triggered almost half a million responses, most of them opposed to the changes. Stand Up for Science, a nonprofit advocacy group that organized opposition to the proposed rule, said it was “prepping with our partners for the legal battles to fight OMB in the federal court system” and “doubling down on the pressure it will take to get this Congress to stand up and stop the OMB rule from being implemented.” (ROLLCALL.COM)

Kids online safety push faces First Amendment hurdles

As Congress considers competing House and Senate proposals meant to protect kids online, lawmakers have only to look to their states to understand the challenges in seeking to regulate kids’ social media usage without running afoul of the First Amendment. States have already tried some of the same strategies Congress is considering, only to see those laws stopped by injunctions granted over free speech objections. At issue in many of the court conflicts over age verification laws is the definition of the social media platforms themselves, with courts determining that by making exceptions for certain websites, states have shown their hand in restricting speech based on its content and the people authoring it. (ROLLCALL.COM)

COMMITTEE ACTIVITY

COMMUNICATIONS: The House Energy and Commerce Subcommittee on Communications and Technology will hold a July 22 hearing on protecting communications networks and improving connectivity.

ENERGY: The Senate Energy and Natural Resources Committee will hold a July 22 FERC oversight hearing.

MARITIME: The House Foreign Affairs East Asia and Pacific Subcommittee will hold a July 22 hearing on countering China’s dominance in global shipbuilding. 

AI WORKFORCE: The House Education and Workforce Committee will hold a July 24 field hearing at Augusta University on how AI is creating opportunities across America’s workforce.

ALERTS AND ADVISORIES

CISA adds three known exploited vulnerabilities to catalog

CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation: CVE-2026-25089 Fortinet FortiSandbox OS Command Injection Vulnerability, CVE-2026-39808 Fortinet FortiSandbox OS Command Injection Vulnerability, CVE-2026-58644 Microsoft SharePoint Deserialization of Untrusted Data Vulnerability. These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise. (CISA.GOV)

Events

TO BE INCLUDED IN THIS CALENDAR, SUBMIT YOUR SECURITY-FOCUSED EVENT FOR CONSIDERATION

EU: On July 20 the Atlantic Council’s Europe Center will host a conversation with European Commissioner for Democracy, Justice, the Rule of Law and Consumer Protection Michael McGrath on Europe’s digital future. As the European Union navigates a rapidly evolving global digital landscape while pursuing its own vision of a trusted digital ecosystem, policymakers face difficult questions about innovation, regulation, and consumer protection. McGrath will share his perspective on how Europe can promote innovation and competitiveness while building a safer and more trusted digital environment for citizens and businesses alike.

CHINA: Audrye Wong’s new book, Subversion and Seduction: China’s Economic Statecraft, explores an underemphasized aspect of China’s economic influence: positive inducements. Understanding the mechanisms, successes, and limitations of China’s economic statecraft will be critical for leaders in the United States and abroad as they navigate a world where China increasingly wields its economic clout for geopolitical influence. Join AEI’s Robert Doar and Dr. Wong on July 21 for a discussion on this essential new book.

ENERGY OUTLOOK: The CSIS Energy Security and Climate Change Program is pleased to host Dr. Nick Wayth, Chief Executive of the Energy Institute (EI), for a July 21 conversation on the findings of the 2026 Energy Institute Statistical Review of World Energy. Dr. Wayth and Dr. Joseph Majkut, Director of the CSIS Energy Security and Climate Change Program, will discuss the report’s key findings and what they reveal about today’s global energy system. As countries pursue increasingly diverse approaches to energy security, affordability, and decarbonization, the conversation will examine how shifting energy demand, evolving geopolitics, rapid electrification, and the continued growth of renewables are reshaping global energy markets. 

6G: Join CSIS, senior U.S. government officials and leading global partners for a July 29 public forum examining the geopolitical and security landscape of next-generation wireless infrastructure. This event will feature the launch of the “Call to Action for 6G Leadership and Security,” a joint initiative between the United States (coordinated by the National Telecommunications and Information Administration) and partner nations designed to strengthen digital supply chains, accelerate innovation, and expand multilateral cooperation on wireless technology. 

ENERGY CRISIS: The CSIS Energy Security and Climate Change Program is pleased to host Jérôme Bilodeau, Head of Analysis (Energy Efficiency and Inclusive Transitions), International Energy Agency (IEA), for an Aug. 4 discussion on the global energy implications of the Strait of Hormuz crisis and how governments have responded to disruptions in energy markets. Bilodeau will present key findings from IEA analysis of the crisis, highlighting its effects across major regions and the policy measures adopted to mitigate supply shortages. He will also provide an overview of the policy tracker tool his team has developed, demonstrating how it captures and compares government responses to evolving energy market conditions.

AI HEALTH CARE: The AI in Health Conference from Sept. 15 to Sept. 17 bridges the gap between artificial intelligence and real-world health outcomes — focusing not just on what AI can do, but on what it should do to improve patient care. Hosted by the Ken Kennedy Institute at Rice University, the fifth annual AI in Health Conference will explore the current landscape of artificial intelligence in health and present a research-driven outlook for the future of computational health innovation. The program is designed to connect researchers and innovators with engineers, clinicians, and entrepreneurs at the forefront of AI in healthcare and public health.

BIOTECH: Synthetic biology is an interdisciplinary field combining biological and engineering to designing and redesigning genes, biological pathways, or organisms to solve society’s major problems and understand biological principles. Rapid advancements in synthetic biology are reshaping how we approach challenges in health, the environment, and beyond. However, these breakthroughs raise questions about what should be permitted and how new technologies should be regulated. To that end, the global conversation on biotechnology must account for responsible frameworks that guide future scientific innovation. This Sept. 18 Baker Institute symposium convenes a diverse community of scholars and practitioners in academia, industry, nonprofits and government for a deep dive into the intersection of emerging biotechnologies, public policy, and ethical responsibility.


FOLLOW THE McCRARY INSTITUTE ON LINKEDIN | X | BLUESKY

SUBSCRIBE TO THE CYBER FOCUS PODCAST: YOUTUBE | SPOTIFY | APPLE PODCASTS

SUBMIT A TIP

Click to listen highlighted text!