Skip to content
SPECIAL

THREATS TO CRITICAL INFRASTRUCTURE IN IRAN CONFLICT

READ MORE

Cyber Briefing – July 21, 2026


Cyber Briefing

TODAY’S TOP 5

AI EXECS SOUND ALARM ON CHINESE MODELS: Silicon Valley and Washington are debating a multibillion-dollar question: Should American companies be able to use Chinese artificial-intelligence models? OpenAI and Anthropic executives are sounding the alarm about the rise of cheap AI, particularly powerful new models produced in China, suggesting they will lead to a “dystopian” AI future and present unacceptable security risks without regulation, The Wall Street Journal reports. Some analysts who study the AI industry say the two companies, which are preparing for public listings in the next year, just want to eliminate the competition. The emergence of highly capable, open autonomous AI systems — including Moonshot AI’s Kimi K3 model and Alibaba’s Qwen 3.8 Max, which were released in recent days and viewed favorably by investors and users — has turned the AI race on its head once again. Kimi K3 also was competitive with U.S. models on some benchmarks.

  • The Trump administration is showing signs it could ban cutting-edge Chinese AI models — a momentous move that could lock in dominance by OpenAI and Anthropic, Axios reports. Parts of the administration have tried to implement de facto bans on foreign open-source models before, knowledgeable sources tell Axios. Last week’s rise of Chinese model Kimi is reigniting those efforts. Pro-competition voices fear the implications. U.S. companies are increasingly using open-source models from China because they’re cheaper and, as seen by the advent of Kimi, just about as good as the domestic technology.
  • Top Trump administration AI safety official Chris Fall has left after just three months on the job, according to a Commerce Department spokesperson, POLITICO reports. Fall, who was director of the Center for AI Standards and Innovation, has been at the center of the federal government’s voluntary review process of frontier AI models. CAISI is a Commerce Department agency that functions as a key point of contact for industry and spearheads commercial AI testing and research. His departure comes as the White House and lawmakers across the country grapple with how to regulate the emerging technology. 

EO TIGHTENS DEFENSE SUPPLY CHAIN: President Donald Trump on Monday signed an executive order making it harder for U.S. defense contractors to obtain waivers allowing them to buy critical minerals and other materials from China and other prohibited foreign suppliers, the administration’s latest effort to reduce reliance on overseas supply chains for weapons production, Reuters reports. The new rules mean defense contractors will have to do much more than simply show that a Chinese supplier is the easiest or cheapest option. Companies seeking a waiver will need to prove they searched for alternatives, explain where their materials come from and lay out a plan to move away from prohibited suppliers. Contractors will face the loss of contracts if they don’t prove they are doing enough to source domestically.

  • There is no question the Defense Department should continue the pursuit of commercial software, but it owes a more critical look at what exactly it should be buying commercially and how it can leverage these capabilities to serve its own internal needs. The department should pursue the commercial procurement of infrastructure, agentic tools and model access for its existing internal software development organizations, Jacob Green writes at War on the Rocks. If done, it could build nearly all its software systems and applications in-house with unheard-of responsiveness, full government ownership and at a fraction of the cost it spends today.

NEW SUPPLY CHAIN FRONT IN IRAN WAR: The Houthis, the Iranian-backed armed faction in Yemen, on Monday said they would impose a blockade on Saudi ships, threatening to open a new front in the Middle East conflict and raising the pressure on volatile global energy markets, The New York Times reports. The announcement was made as many in the region were tensely watching to see if the rounds of bombardment between U.S. and Iranian forces in the Persian Gulf would continue to escalate. The two countries traded new attacks on Monday, with Iran targeting countries that host U.S. military bases, despite efforts by mediators to calm tensions, and the United States then launching strikes on Iran for a 10th consecutive night.

  • At Just Security, U.S. Coast Guard Rear Admiral (ret.) Melissa Bert analyzes the forgotten merchant mariners in this fragile supply chain: By the IMO’s count, at least 14 seafarers have been killed and more than 40 commercial vessels attacked since the war began. During this conflict, the technology provides up-to-date details concerning shipping in the Strait of Hormuz: the stranded seafarers have overwhelmingly been aboard ships of neutral nations, many with third-state crews and owners who have taken no part in any aspect of the U.S.–Iran confrontation. In peacetime, what strands mariners is usually the opposite problem — deliberate opacity. A vessel’s ownership or charter may be falsely broadcast on AIS, or the transponder switched off altogether, a practice known as spoofing. Ships registered by nations with lax safety and security laws are sometimes simply abandoned in bankruptcy. In either case, the crew can be left aboard with no viable recourse for rescue, repatriation, or wages.
  • The Iranian ballistic missile attack on a Jordanian air base that killed two U.S. servicemembers struck prefabricated housing units where troops lived and slept, according to U.S. officials familiar with the matter, The Wall Street Journal reports. The attack on Muwaffaq Salti Air Base was one of three separate missile strikes on the base in 24 hours last week, which killed two soldiers from Army air and missile defense units, according to the officials. The remains of a third person have been found at the location and are being examined. That three missiles were able to slip through U.S. air defenses points to the challenges in protecting the estimated 50,000 troops stationed in the region against an Iranian military that is still equipped with a substantial number of ballistic missiles and drones. 
  • The U.S. Secret Service is examining a video that appears to have been produced by Iranian operatives and aims to identify opportunities to assassinate Trump, including supposed motorcade routes used by his protective details in Florida and New York. The video, which was sent to Nextgov/FCW by a U.S. government official, is titled “Where to Kill Trump?!” with the title written in a blood-stained font alongside a bloody silhouette of the president’s side profile. In high-quality, likely AI-generated red, black and white graphics of people, buildings, vehicles, roads and other infrastructure, it claims to show how the president and his Secret Service detail commute from Palm Beach International Airport in Florida to his Mar-a-Lago estate, and from LaGuardia Airport to Trump Tower in New York City. 

CHINESE RESEARCHERS DEVISE CLOUD GRID TAKEDOWN: AI data centers wreak havoc on the power grid under normal circumstances, so what happens if a bad actor controls all the GPUs and wants to cause harm? Cybersecurity researchers in China have devised a way for malicious tenants to attack their infrastructure provider, potentially causing blackouts or damaging equipment, The Register reports. The attack, dubbed Bit2Watt, imagines an adversary masquerading as a legitimate cloud tenant to launch GPU workloads that have the potential to damage data centers and supporting electrical systems. It’s intended to demonstrate the need to extend cybersecurity defenses to datacenter workload scheduling. “Our results indicate that GPU loads can reach modulation frequencies exceeding 6,000 Hz, compared with only a few hertz observed in conventional household loads such as air conditioners,” the Zhejiang University authors state in their paper. “Such high-frequency modulations can substantially induce voltage excursions, harmonic distortion, and damping degradation.”

  • Data centers in the U.S. will account for about 20% of the nation’s electricity consumption in 2035, up from 5.9% today, according to BloombergNEF. That compares with an estimated 12% in 2030, it said in a report today. In states such as Virginia and Texas where data centers are concentrated, their share of electricity use will be even higher. Given the speed at which soaring demand from artificial intelligence is increasing, BNEF projects data center power needs to reach 194 gigawatts in the country by 2035. That’s a jump of 83% from its December forecast. The gain reflects a growing pipeline of AI facilities poised to be built within the next decade. One gigawatt is equivalent to the capacity of a traditional nuclear reactor. 
  • Data centers sprouting up across the U.S. are facing an emerging environmental challenge: What happens to the wastewater they generate, and what kind of contaminants are in it? Recently, a data center under construction in Cheyenne, Wyoming, was found to have contaminated the sewer system with a rare bacterium. The incident highlights what engineers view as an emerging challenge for the data center industry that is already under scrutiny over its environmental footprint, E&E News reports. As new projects crop up nationwide, experts say it’s not clear whether small utilities have the infrastructure and regulations to ensure the wastewater is properly managed.

SECURING AI ALGORITHMIC INSIGHTS: Algorithmic insights — the techniques, methods, and design know-how that materially improve artificial intelligence (AI) systems — can confer substantial commercial and strategic advantages. Unlike model weights, algorithmic insights generally cannot be isolated as a single digital artifact. They reside across source code, documentation, communications, experimental systems, and human expertise, and some can be conveyed through only a brief conversation or an observed screen. Their unauthorized disclosure could erode technological leads and, in some cases, lower barriers to dangerous AI capabilities. A new RAND report adapts the framework developed in Securing AI Model Weights to algorithmic insights. The authors identify 44 attack vectors across nine categories and propose five cumulative insight security levels (ISLs) matched to five levels of adversary operational capacity. The framework is conditional rather than prescriptive: It describes the security posture likely required to protect a specified insight against a specified class of adversary while leaving organizations to determine which insights warrant protection.

OSINT YOU NEED TO START YOUR DAY: The Cyber Briefing is brought to you by the McCrary Institute for Cyber and Critical Infrastructure Security at Auburn University. SUBSCRIBE
WE WANT TO HEAR FROM YOU: What would you like to see in your morning briefing? Reach out to Executive Editor Bridget Johnson with your comments and suggestions

CYBER FOCUS PODCAST

(Watch on YouTube or click the player above)

National security challenges increasingly cut across technology, economic competitiveness, critical infrastructure, manufacturing and workforce development. Universities have a growing role to play not only in conducting research, but also in translating ideas into practical solutions and preparing students to confront real-world problems. Auburn University President Dr. Chris Roberts, McCrary Institute Chairman Lt. Gen. (Ret) Ron Burgess, Senior Vice President for Research Dr. Steve Taylor and Samuel Ginn College of Engineering Dean Dr. Mario Eden join Frank Cilluffo on the latest episode of Cyber Focus to discuss Auburn’s commitment to national security. The conversation explores the changing threat environment, the university’s expanding research presence in Huntsville, partnerships among academia, government and industry, and how experiential education can prepare students for jobs and technologies that do not yet exist.

SUBSCRIBE TO CYBER FOCUS: YouTube | Spotify | Apple Podcasts

CYBER AND CI UPDATES

ATTACKS AND INCIDENTS

Breaches

Estée Lauder discloses data breach via Oracle E-Business flaw

Cosmetics giant Estée Lauder is notifying customers of a data breach after hackers exploited a flaw in Oracle E-Business Suite that the company used for human resources (HR) operations. The company says that last month it identified an intrusion that had occurred on August 9, 2025, which led to the threat actor obtaining “personal information of certain” individuals. “We became aware of a cybersecurity issue involving a vulnerability in the Oracle E-Business Suite system which is used by the Estee Lauder Companies for HR management purposes,” the notification says. (BLEEPINGCOMPUTER.COM)

Communications

Cyberattack causes widespread internet outage in more than 20 Maine towns

Tidewater Telecom is working to restore internet for residents across Midcoast Maine after detecting a cyber attack on Sunday evening. Residents across Midcoast Maine and beyond are dealing with internet service disruptions after Tidewater Telecom reported a widespread outage impacting 23 Maine towns. Tidewater Telecom and LCI found an external computer-generated attack on their Internet Service systems on Sunday, according to an update on Monday night. They said no consumer data was impacted. (NEWSCENTERMAINE.COM)

Events

‘Integrated’ cyber and physical attacks concerned FIFA planners

Among the events that did not occur during any of this year’s FIFA World Cup matches was a terrorist hijacking a jumbotron. Not during any one of the 78 games hosted in the United States this year was an AI-generated video shown to tens of thousands of startled soccer fans, falsely warning them of an imminent explosion somewhere in the stadium. And although that scenario did not occur this year, it was one of many possible scenarios that event planners prepared for leading up to the global sporting event that concluded on Sunday with fireworks, not bombs, and a 1-0 Spanish victory over Argentina. John Cohen, executive director of the office of strategic programs and initiatives at the Center for Internet Security, an Upstate New York nonprofit that assists state and local governments with their cybersecurity, said it’s a sign of the times that such considerations of digital intrusion were this year put on equal footing with more traditional, physical threats associated with large-scale events. (STATESCOOP.COM)

MORE: More than 1,000 domains illegally streaming World Cup games seized, DOJ says (THERECORD.MEDIA)

Government

Hackers were inside South Korea’s diplomat training system for 9 months

Unidentified hackers compromised an online education system used by South Korea’s diplomatic academy, stealing personal information belonging to former and current employees of the country’s Ministry of Foreign Affairs, the department announced Monday. In a data protection notice, the MoFA said the breach of the Korea National Diplomatic Academy’s e-learning platform occurred from April 2025 to February 2026, when a related government authority notified the ministry of abnormal access to the system. The ministry said it immediately shut the system down and has not restored it since. (THERECORD.MEDIA)

Health care

Clover Health Investments discloses data breach

Healthcare technology company Clover Health Investments has disclosed a data breach impacting customers’ personal and health information. Discovered on July 4, the incident was the result of a social engineering attack that compromised three non-managerial health plan employee accounts. Clover Health Investments says it activated its response plan immediately after discovering the attack, and engaged third-party cybersecurity experts to contain and investigate the intrusion. (SECURITYWEEK.COM)

Nuclear

India says allegedly leaked nuclear plant files pose no safety risk

India’s state-owned nuclear operator said that documents recently posted online and purportedly linked to the country’s largest nuclear power plant contain no information affecting safety or security. The statement came after the media reported last week that the cybercrime group World Leaks had published thousands of files apparently connected to the Kudankulam Nuclear Power Plant (KKNPP). The files appeared to include engineering drawings, supplier information, inspection records and insurance documents related to Units 3 and 4, which are under construction near the southern tip of India. (THERECORD.MEDIA)

Ransomware

Critical Palo Alto VPN bug now exploited by Qilin ransomware gang

The Qilin ransomware gang is exploiting a critical PAN-OS GlobalProtect authentication bypass flaw to breach victims’ networks, according to cybersecurity company Arctic Wolf. Palo Alto Networks addressed the vulnerability (CVE-2026-0257) on May 13 and warned that attackers had begun abusing it to breach corporate networks after Rapid7 reported observing it being exploited against numerous customers starting on May 17. “GlobalProtect portal and gateway of Palo Alto Networks PAN-OS® software allows the attacker to bypass security restrictions and establish an unauthorized VPN connection,” the company warned at the time. “Palo Alto Networks has become aware of limited exploit attempts on unpatched PAN-OS devices without mitigations applied.” (BLEEPINGCOMPUTER.COM)

WATCH: White House National Cyber Director Sean Cairncross, CISA Acting Director Nick Andersen and more top leaders at the recent McCrary Cyber Summit

THREATS

Artificial intelligence

JadePuffer agentic attacks now target AI model data with ransomware

The JadePuffer autonomous AI agent has upgraded with custom malware called EncForge that focuses on encrypting AI assets, such as training datasets, vector databases, and model checkpoints. JadePuffer was disclosed earlier this month as an agentic threat actor (ATA) capable of running autonomously through the stages of a ransomware attack, from initial access to data encryption. Cloud security company Sysdig says that the AI agent adapted to technical difficulties in real time and optimized the intrusion mechanism to find the correct fix in less than a minute. (BLEEPINGCOMPUTER.COM)

Critical ServiceNow AI platform flaw exploited for unauthenticated code execution

Threat actors are now exploiting a recently disclosed critical security flaw impacting ServiceNow AI Platform, according to Defused Cyber. In a post shared on X, the threat intelligence firm said it’s observing in-the-wild exploitation of CVE-2026-6875 (CVSS score: 9.5), a sandbox escape vulnerability that could allow an unauthenticated user to run arbitrary code. Searchlight Cyber, which disclosed additional technical specifics, said it reported the issue on April 1, 2026, adding it allows a complete compromise of the ServiceNow instance as well as all connected proxy servers. (THEHACKERNEWS.COM)

Cursor, Codex, Gemini CLI, Antigravity hit by sandbox escapes

Security researchers broke out of the sandboxes in four widely used AI coding agents, including Cursor, OpenAI’s Codex, Google’s Gemini CLI and Antigravity, without attacking the sandbox head-on. The agent stays inside the box and follows every rule. It just writes a file that a trusted tool outside the box later runs, loads, or scans, and the escape happens on its own. Pillar Security’s research team, Eilon Cohen, Dan Lisichkin and Ariel Fogel, reproduced the bypasses over several months and published them today as a series they call the Week of Sandbox Escapes, one write-up a day. (BLEEPINGCOMPUTER.COM)

Malware

From a single alert to 1,000 files: Inside an exposed WebDAV malware delivery lab

An MDR alert recently led our team to an exposed server that was doing more than hosting payloads. It was functioning as a fully operational malware delivery lab. Containing over 1,000 artifacts, the infrastructure served as a QA hub where attackers systematically tested delivery paths, social engineering lures, and WebDAV execution methods. Analysis reveals an interesting shift in adversary operations: attackers are adopting generative AI to move beyond individual exploits and operate like modern software product teams. By leveraging LLMs for rapid lure generation, detailed README documentation, and automated testing, they are significantly accelerating their development cycle. (RAPID7.COM)

HOLLOWGRAPH malware turns Microsoft 365 calendars into an espionage channel

The malware, which Group-IB calls HOLLOWGRAPH, is one component of a bigger toolkit the company links with high confidence to the Cavern backdoor framework, a modular espionage toolkit built from separate plugins that each handle a different task, previously tied to Iran-linked activity. Group-IB identified 12 infected systems (three actively communicating), all evidence pointing to a narrowly targeted espionage operation against Israeli entities. The earliest recorded contact between a victim and the attacker dates to June 3, 2026, and the most recent to July 9, 2026, a window showing the malware has been in active use since at least early June. (HELPNETSECURITY.COM)

Cruciferra crypter uses process ghosting to evade detection

A crypter service used by multiple unrelated cyber-criminal groups has been documented cloaking commodity malware with process ghosting, kernel-driver abuse and more than 90 mix-and-match encryption routines. According to new research from Proofpoint published on July 20, the crypter, marketed as Cruciferra, was first offered for sale on the Exploit forum in autumn 2025 and now underpins dozens of campaigns delivering AsyncRAT, Agent Tesla, Remcos, XWorm, ValleyRAT and Snake Keylogger. Tiered access runs from $450 to $2,000 a month. (INFOSECURITY-MAGAZINE.COM)

Supply chain

FakeGit campaign abuses 7,600 GitHub repositories to distribute SmartLoader and Lumma stealer malware via open-source supply chain

The FakeGit campaign represents a significant escalation in the abuse of trusted open-source platforms for malware distribution. Leveraging over 7,600 malicious GitHub repositories, threat actors have orchestrated a sophisticated supply chain attack to propagate the SmartLoader malware. These repositories, often indistinguishable from legitimate projects due to the use of AI-generated documentation and code samples, serve as lures for unsuspecting users seeking popular tools, gaming cheats, cracked software, or system utilities. Upon execution, SmartLoader acts as a dropper, deploying secondary payloads such as Lumma Stealer, a notorious infostealer. The campaign’s scale, automation, and exploitation of both human and AI-driven code discovery workflows underscore the urgent need for enhanced vigilance and robust countermeasures across the software supply chain. (RESCANA.COM)

Vulnerabilities

WordPress wp2shell exploitation grows as public exploit fuels mass scanning

Attackers have begun to exploit two critical vulnerabilities in WordPress that, when combined together, enable unauthenticated remote code execution (RCE) and complete compromise of vulnerable websites. The two security flaws, tracked as CVE-2026-63030 and CVE-2026-60137, have been codenamed wp2shell. “By the early hours of Saturday morning (UTC), successful exploitation was already well underway, initially using public exploit code to exfiltrate hashed credentials, with remote code execution following once additional details were made public,” Jake Knott, principal security researcher at watchTowr, told The Hacker News in a statement. (THEHACKERNEWS.COM)

Critical Gitea flaw lets public-only tokens write to private repositories and trigger actions workflows

Gitea administrators are strongly encouraged to upgrade their systems following the discovery of a critical authorization vulnerability. This flaw allows public-only API tokens to modify private pull request branches and potentially trigger Gitea Actions workflows. The vulnerability, tracked as CVE-2026-58443 and GHSA-xxjv-752h-3vp2, affects Gitea versions up to and including 1.26.4. The issue has been resolved in Gitea version 1.27.0. (GBHACKERS.COM)

Zimbra update patches critical vulnerabilities

Zimbra on Monday announced patches for several critical-severity vulnerabilities, including a command injection bug disclosed in late June. The critical command injection impacts the SNMP monitoring component of the collaboration suite if SNMP notifications are enabled and the integrated Swatchdog service is running. An unauthenticated attacker could send crafted payloads to execute arbitrary OS commands in the background and compromise the email server. (SECURITYWEEK.COM)

ADVERSARIES

China

The short-war illusion: What Iran teaches Beijing about Taiwan

OPINION: In a military conflict with Taiwan, China’s cheapest path to victory is a short, decisive one: a decapitating opening strike — that is, a strike targeting leadership — that collapses organized resistance and a rapid seizure of the island, handing Washington a fait accompli. Two recent wars test that bet. Russia’s attempt in 2022 to decapitate Kyiv and force a quick capitulation fell apart within days. The U.S. and Israeli war with Iran in 2026 offers the same verdict. Decapitation strikes did not end the war, the denial of a key chokepoint proved cheap to impose and costly to break, and protraction favored the dispersed defender. None of this should let Taiwan rest easy — Iran spent decades preparing for exactly this kind of war. This piece views the conflict through the lens the People’s Liberation Army (PLA) itself might use — the essential audience whose response Washington and Taipei must anticipate as they design their own defenses. (LAWFAREMEDIA.ORG)

Iran

Iran-linked APT42 uses AI-assisted phishing and TAMECAT backdoor to target defense officials

Iran-linked APT42 is escalating its espionage operations with AI-assisted phishing and an expanded TAMECAT backdoor, enabling long-lived access to defense and government identities rather than just endpoints. Recent activity shows tightly integrated social engineering, cloud abuse, and fileless PowerShell tradecraft that significantly complicate detection and response. APT42, also tracked as TA453 in some reporting, is an Iran-nexus actor focused on credential theft, espionage, and long-horizon social engineering against high‑value targets such as defense officials, diplomats, and nuclear‑adjacent experts. (GBHACKERS.COM)

North Korea

Researchers uncover North Korean ‘ClickFake’ campaign targeting Web3 pros

A new sophisticated social engineering operation targeting Web3 and cryptocurrency professionals has been identified by researchers at SOCRadar. Attributed to the notorious North Korean-aligned hacking group Famous Chollima, also known as Wagemole, the campaign leverages fraudulent job interviews and highly interactive web portals to trick candidates into installing remote access trojans (RATs) on their personal devices. Instead of relying on broad phishing blasts, researchers at SOCRadar Threat Research Unit (STRU) noted that the threat group is shifting to highly personalized recruitment scams that capitalize on the high mobility of tech talent in the cryptocurrency market. (INFOSECURITY-MAGAZINE.COM)

GOVERNMENT AND INDUSTRY

Artificial intelligence

AI platform lets California match model with use case

When California Gov. Gavin Newsom signed Executive Order N-12-23 back in late 2023, few could have guessed that one of the outcomes would be a tailored, state-run AI platform in the hands of every worker. Getting any model up and running in state government is a challenge, let alone a consolidated suite of them. There are privacy, security, governance and appropriate use considerations, and yet the California Department of Technology (CDT) made it happen from pilot to practice in just under a year. Earlier this month, officials pushed send on Poppy, a collection of 10 different models tailored to fit the diverse and challenging work of government. (GOVTECH.COM)

Why blocking AI models won’t stop the cyber threats they create

OPINION: 2026 has turned out to be the year when predictions about AI-powered cyberattacks, long hypothesized as a potential risk associated with AI improvement, seem to be coming true. New models have capabilities on par with the best human hackers, marking a pivotal window of opportunity in both AI and cybersecurity policy. This is a transitional period where new technologies are pushing existing American cybersecurity infrastructure to the brink. The real question isn’t whether cybersecurity still matters, but rather: How will the risks that AI introduces be managed before they outpace defenses, and who will step up to lead this challenge? (CYBERSCOOP.COM)

Defense

Coast Guard issues RFI as it considers arming vessels with high-energy lasers

The U.S. Coast Guard’s Research and Development Center is reaching out to industry for detailed information on vendors’ directed energy systems that could be deployed on vessels or piers and zap adversary drones or other “targets of interest.” The Coast Guard falls under the Department of Homeland Security, but it’s also considered a military service and often deploys its platforms to support the Navy and the joint force. The organization released a request for information Monday as it conducts market research to determine the availability and technical readiness of high-energy laser technologies for maritime applications. (DEFENSESCOOP.COM)

Army recruiters get help from AI-powered chatbot

The U.S. Army has promoted its Sgt. Star artificial intelligence (AI)-powered chatbot to Staff Sgt. Star as the service expands the tool’s capabilities to help recruiters quickly find policy and recruiting guidance. Staff Sgt. Star answers recruiters’ questions about policies, waivers, and recruiting tasks, allowing them to quickly find authoritative guidance without searching manuals or relying on a help desk. The chatbot is trained on authoritative recruiting resources and is continuously updated as policies, regulations, and workflows evolve. Jeffrey Faulkner, deputy product lead for Accessions Information Environment (AIE), the Army’s recruiting IT system, said the chatbot operates within AIE and is available to authorized users. The AIE office developed the tool in less than three months to reduce recruiters’ repetitive administrative work. (MERITALK.COM)

Drones

Marine regiment tests AeroVironment’s JUMP 20-X system for the first time, but faces lack of Group 3 drone operators

A Marine Corps regiment experimented with a new Group 3 unmanned aerial system during a recent training exercise in what officials said marked the first time a drone of that size had been tested by one of the service’s conventional units. However, its troops relied on the system’s vendor to employ the technology because the regiment lacked operators. Because the 2nd Marine Regiment does not have any Marines trained to operate Group 3 drones, contractors with AeroVironment launched the JUMP 20-X uncrewed platform — equipped with the company’s hallmark loitering munition known as the Switchblade — late last week in California alongside troops who were learning how to use it, officials said. (DEFENSESCOOP.COM)

Energy

Data centers drove $6.3B in PJM capacity auction costs: market monitor

Data centers are responsible for $6.3 billion, or 38%, of the $16.4 billion in charges from the PJM Interconnection’s just-held capacity auction, Joseph Bowring, president of Monitoring Analytics, said in an email to Utility Dive. Monitoring Analytics is the grid operator’s independent market monitor. In PJM’s last four base capacity auctions, data center-driven capacity charges totaled $29.4 billion — 46% of the $63.6 billion in total capacity charges in that period, Bowring said. Monitoring Analytics plans to publish its analysis of the most recent auction in a few weeks, he said. PJM isn’t fully grappling with the ramifications of data center development, according to Bowring. “PJM is continuing to act like it’s business as usual,” he said in an interview on Friday. “You have to open your eyes and recognize that it is really a paradigm shift, and failing to do that imposes costs on other customers.” (UTILITYDIVE.COM)

AI data center growth could force U.S. utilities to rethink generation plans, BofA says

Bank of America analysts forecast the United States will need more than 230 GW of new generating capacity over the next five years, but regulated utilities are expected to add only about 93 GW of accredited supply, leaving a gap of more than 100 GW. Data centers alone could add roughly 125 GW of U.S. electric load over the period, pushing overall electricity demand growth to a 4.1% compound annual growth rate from 2026 through 2030, according to the report. With large gas turbines largely sold out through 2030, data center developers are increasingly likely to turn to on-site gas engines while utilities extend coal plant operations, deploy batteries and pursue transmission upgrades, BofA analysts said. (UTILITYDIVE.COM)

Space

The Space Force is now seeking to buy up to $30 billion in rocket launches

It seems as though $5.6 billion wasn’t enough. That was the news from the US Space Force on Friday, when military officials announced they were tripling the maximum value of one of the service’s National Security Space Launch contracts to $17 billion. The expansion of the Space Force’s National Security Space Launch (NSSL) Phase 3 contract comes as the Pentagon signals rising demand for military satellite launches. The NSSL program is set up to allow Space Systems Command, which oversees the Space Force’s launch program, to select from a pool of launch providers for individual missions to deliver the military’s satellites to orbit. (ARSTECHNICA.COM)

U.S. rocket-launch bottleneck worries Sweden, which just launched its first military satellite

Sweden’s military just launched its first satellite in May, but its top space officer is already worried that bottlenecks at U.S. and European launch facilities could slow the development of urgently needed orbital capabilities. The satellite, built by Planet Labs and launched aboard a SpaceX Falcon 9 rocket from Vandenberg AFB, California, went up four years ahead of schedule because of the “severe security situation,” Swedish Armed Forces Rear Adm. Anders Sundeman, the country’s space chief, told reporters during a media event here. “Time is of essence.” As Sweden looks to grow its space assets, it will need to rely on U.S. launch providers which are being overbooked and strained by skyrocketing military and commercial demands for new satellites. (DEFENSEONE.COM)

Surveillance

Flock Safety kills acoustic system designed to detect ‘human distress’

The automated license plate reader company Flock Safety is abandoning plans to sell an acoustic gunshot detection device whose ability to detect screaming and other types of “human distress” sparked an outcry from privacy advocates when it was announced in October. Flock quietly revealed on July 10 that it has decided to “remove” the product, according to a company blog post. “This feature was designed to help identify potential violent incidents in areas where other public safety tools were less effective,” the blog post said. “The feature was only available to a small number of customers as part of a limited trial, and was never broadly released.” (THERECORD.MEDIA)

Transportation

Two airports opt into TSA’s new privatization model

Two airports have opted into the Transportation Security Administration’s new “Gold+” privatization model, becoming the first to do so, with TSA employees at those locations being told they will be offered jobs with a to-be-determined private screening contractor. Des Moines International Airport and Tampa International Airport have each respectively chosen to transition to TSA Gold+, according to emails viewed by Federal News Network. TSA unveiled the Gold+ initiative earlier this year. The agency plans to pay private contractors to manage both airport screening staff and the technology at airport checkpoints, while TSA provides oversight. (FEDERALNEWSNETWORK.COM)

Transportation looks to AI to accelerate its modernization initiatives

The Department of Transportation is ramping up its use of artificial intelligence, according to a top agency official, with the emerging capabilities playing an increasingly important role in the agency’s ongoing modernization efforts. Speaking at GovExec’s Government Efficiency Summit on July 16, Transportation Deputy Secretary Steven Bradbury said internal adoption of the technologies has already helped to accelerate needed software upgrades, with growing workforce use of AI poised to further expand its impact on agency operations. Transportation released its 1DOT IT strategy last September to help guide its digital infrastructure transformation, which includes a focus on modernizing and replacing its outdated systems. (NEXTGOV.COM)

LEGISLATIVE UPDATES

Senators cast doubt on success of new reconciliation bill

A bipartisan group of senators attending the Farnborough Airshow this week forecast a bleak outlook for a third reconciliation bill, warning that appropriators must take action to ensure the Pentagon’s base budget includes all the funds necessary for national security priorities. The House this week is set to debate a budget resolution that would kickstart the reconciliation process and add $60 billion for defense — a number far less than the Pentagon’s $350 billion request. But the lawmakers said even that will be a tough sell with midterm elections quickly approaching. (BREAKINGDEFENSE.COM)

House taking up NDAA, funding patch, budget plan

House Republicans will rush to advance a spate of legislative priorities this week — including the defense policy bill, a government funding measure and a reconciliation blueprint — before leaving town for a five-week recess. The jam-packed agenda will be dominated by House leaders’ attempt to pass the fiscal 2027 National Defense Authorization Act, which includes provisions on electricity bills, critical minerals, nuclear energy and “forever chemicals.” Lawmakers are offering hundreds of amendments, including some on energy and environment issues. The House will also take up a continuing resolution that would keep the government running past the current Sept. 30 funding deadline. It is Speaker Mike Johnson’s (R-La.) bid to get ahead of a September funding fight and put pressure on Democrats to show they want to avoid a shutdown. (EENEWS.NET)

House committee narrows data center energy bill

The House Energy and Commerce Committee has narrowed the scope of its data center energy legislation to focus specifically on the sprawling facilities generating nationwide concern. The Ratepayer Protection Act — H.R. 9340, sponsored by Reps. Gabe Evans (R-Colo.) and Kathy Castor (D-Fla.) — would require states to consider adopting a federal standard directing data centers to pay the full cost of new generation and transmission upgrades needed to serve them. Ahead of a markup that began Monday and will stretch into Tuesday, committee leaders released a substitute amendment that narrows the bill to apply specifically to data centers. Previously, the bill language could be applied to projects with a peak electricity demand of 100 megawatts or more. (EENEWS.NET)

Cruz and Blackburn meet Trump to discuss tech policy

President Donald Trump met Monday at the White House with Republican Sens. Ted Cruz and Marsha Blackburn to discuss tech policy. The huddle came ahead of a highly-anticipated Senate Commerce Committee markup to take place as soon as next week on a roster of kids’ online safety and artificial intelligence bills. In preparation for that markup, Blackburn, a Tennessee Republican, has been working to build support for the Kids Online Safety Act, which would restrict the features and platforms minors could access online. (POLITICO.COM)

COMMITTEE ACTIVITY

COMMUNICATIONS: The House Energy and Commerce Subcommittee on Communications and Technology will hold a July 22 hearing on protecting communications networks and improving connectivity.

ENERGY: The Senate Energy and Natural Resources Committee will hold a July 22 FERC oversight hearing.

MARITIME: The House Foreign Affairs East Asia and Pacific Subcommittee will hold a July 22 hearing on countering China’s dominance in global shipbuilding. 

AI WORKFORCE: The House Education and Workforce Committee will hold a July 24 field hearing at Augusta University on how AI is creating opportunities across America’s workforce.

ALERTS AND ADVISORIES

FBI warns of scammers impersonating the IC3

This Public Service Announcement (PSA) is an update to Alert Number I-04182025-PSA titled, “FBI Warns of Scammers Impersonating the IC3.” This PSA contains updated information about an ongoing fraud scheme where criminal scammers are impersonating FBI personnel facilitating Internet Crime Complaint Center (IC3) complaints to deceive and revictimize individuals. This scheme combines several exploitation tactics to include the targeting of previous victims,1 the use of artificial intelligence (AI)-generated videos to create fictitious or misleading promotional materials for their fraud schemes; and the creation of spoofed websites with the purpose of gathering personally identifiable information entered by a user into the site. Each of the tactics give victims a false sense of safety and security, while the actors impersonate or falsely affiliate themselves with government personnel or entities. (IC3.GOV)

Events

TO BE INCLUDED IN THIS CALENDAR, SUBMIT YOUR SECURITY-FOCUSED EVENT FOR CONSIDERATION

CHINA: Audrye Wong’s new book, Subversion and Seduction: China’s Economic Statecraft, explores an underemphasized aspect of China’s economic influence: positive inducements. Understanding the mechanisms, successes, and limitations of China’s economic statecraft will be critical for leaders in the United States and abroad as they navigate a world where China increasingly wields its economic clout for geopolitical influence. Join AEI’s Robert Doar and Dr. Wong on July 21 for a discussion on this essential new book.

ENERGY OUTLOOK: The CSIS Energy Security and Climate Change Program is pleased to host Dr. Nick Wayth, Chief Executive of the Energy Institute (EI), for a July 21 conversation on the findings of the 2026 Energy Institute Statistical Review of World Energy. Dr. Wayth and Dr. Joseph Majkut, Director of the CSIS Energy Security and Climate Change Program, will discuss the report’s key findings and what they reveal about today’s global energy system. As countries pursue increasingly diverse approaches to energy security, affordability, and decarbonization, the conversation will examine how shifting energy demand, evolving geopolitics, rapid electrification, and the continued growth of renewables are reshaping global energy markets. 

6G: Join CSIS, senior U.S. government officials and leading global partners for a July 29 public forum examining the geopolitical and security landscape of next-generation wireless infrastructure. This event will feature the launch of the “Call to Action for 6G Leadership and Security,” a joint initiative between the United States (coordinated by the National Telecommunications and Information Administration) and partner nations designed to strengthen digital supply chains, accelerate innovation, and expand multilateral cooperation on wireless technology. 

ENERGY CRISIS: The CSIS Energy Security and Climate Change Program is pleased to host Jérôme Bilodeau, Head of Analysis (Energy Efficiency and Inclusive Transitions), International Energy Agency (IEA), for an Aug. 4 discussion on the global energy implications of the Strait of Hormuz crisis and how governments have responded to disruptions in energy markets. Bilodeau will present key findings from IEA analysis of the crisis, highlighting its effects across major regions and the policy measures adopted to mitigate supply shortages. He will also provide an overview of the policy tracker tool his team has developed, demonstrating how it captures and compares government responses to evolving energy market conditions.

AI HEALTH CARE: The AI in Health Conference from Sept. 15 to Sept. 17 bridges the gap between artificial intelligence and real-world health outcomes — focusing not just on what AI can do, but on what it should do to improve patient care. Hosted by the Ken Kennedy Institute at Rice University, the fifth annual AI in Health Conference will explore the current landscape of artificial intelligence in health and present a research-driven outlook for the future of computational health innovation. The program is designed to connect researchers and innovators with engineers, clinicians, and entrepreneurs at the forefront of AI in healthcare and public health.

BIOTECH: Synthetic biology is an interdisciplinary field combining biological and engineering to designing and redesigning genes, biological pathways, or organisms to solve society’s major problems and understand biological principles. Rapid advancements in synthetic biology are reshaping how we approach challenges in health, the environment, and beyond. However, these breakthroughs raise questions about what should be permitted and how new technologies should be regulated. To that end, the global conversation on biotechnology must account for responsible frameworks that guide future scientific innovation. This Sept. 18 Baker Institute symposium convenes a diverse community of scholars and practitioners in academia, industry, nonprofits and government for a deep dive into the intersection of emerging biotechnologies, public policy, and ethical responsibility.


FOLLOW THE McCRARY INSTITUTE ON LINKEDIN | X | BLUESKY

SUBSCRIBE TO THE CYBER FOCUS PODCAST: YOUTUBE | SPOTIFY | APPLE PODCASTS

SUBMIT A TIP

Click to listen highlighted text!