Skip to content
SPECIAL

THREATS TO CRITICAL INFRASTRUCTURE IN IRAN CONFLICT

READ MORE

Cyber Briefing – July 22, 2026


Cyber Briefing

TODAY’S TOP 5

OPEN AI MODELS GO ROGUE AND ATTACK DIGITAL LIBRARY: OpenAI said on Tuesday that two of its artificial intelligence models went rogue and successfully hacked into Hugging Face, a digital library of AI technology that is popular among developers, The New York Times reports. The incident, which happened last week while OpenAI was testing the cybersecurity capabilities of its systems, displayed the kind of science-fiction potential that AI companies warned would soon become a reality. AI labs like OpenAI and Anthropic have over the past year released AI models that are customized to expose cybersecurity problems, while warning that their technology could pose new risks by finding holes in corporate computer networks faster than defenders could fix them. OpenAI’s revelations on Tuesday are an indication that those security incidents are already starting to happen, and even savvy AI companies may not be entirely ready for them.

  • In April, the Federal Reserve and Treasury Department convened an extraordinary meeting with the CEOs of the nation’s top banks. Officials rang the alarm bell about an advanced new artificial intelligence model that could pose an unprecedented cybersecurity threat to the nation’s top financial institutions. Anthropic, the company behind the AI model, Claude Mythos Preview, said the offering excelled at identifying weaknesses and security vulnerabilities within software. The company released it to a select group of banks and other institutions as part of a cybersecurity initiative called Project Glasswing. For at least three months afterward, the Fed itself didn’t have access to Mythos, leaving arguably the most systemically important global financial institution vulnerable, even as other institutions began to patch their weaknesses, CNBC reports.
  • Treasury Secretary Scott Bessent on Tuesday said the Trump administration will look into whether Chinese artificial intelligence models have been distilled from American models, stating that the government does not support “IP theft,” CNBC reports. Chinese open-weight models are gaining steam against leading offerings from American companies like OpenAI and Anthropic, sparking concerns from tech executives and government officials about the durability of the U.S. lead in the AI race. Moonshot AI, a Chinese startup, released a model called Kimi K3 earlier this month that outperforms those companies across some industry benchmarks. Open weight refers to models whose final trained parameters are publicly released for download, while the underlying code and training data remain private.
  • As firms use Mythos to hunt and fix flaws in their products, a more urgent question looms: how to defend the United States and its allies from AI-powered cyberwarfare. The United States may only have nine to 12 months to protect its critical infrastructure from AI-powered attacks. Currently, two American companies, Anthropic and OpenAI, have publicly demonstrated AI models advanced enough to detect flaws in software far beyond the human capacity to find, and they are restricting the use of these models to defensive cybersecurity work. But the United States’ adversaries, and the criminals in their orbit, will soon wield the same offensive tools. China, in particular, is already racing to build and acquire these AI capabilities and may be closer to developing its own Mythos than many U.S. policymakers hope, Michael Sulmeyer writes at Foreign Affairs. Advanced AI will sharpen an instrument that Beijing already prizes: the credible threat to deter a fight over Taiwan before it begins by disrupting the island’s critical infrastructure and that of any nation that seeks to defend it.

AI THREATS 25 YEARS AFTER 9/11: The U.S. intelligence community needs to devote more resources to protecting American artificial intelligence companies from foreign espionage, former officials told the House Intelligence Committee on Tuesday, arguing that China will use a range of intelligence-gathering techniques to steal proprietary AI technology and advance its own military and economic goals, Nextgov/FCW reports. The hearing focused on emerging threats to the U.S. in the 25 years since the Sept. 11, 2001, terrorist attacks, also highlighted AI’s growing role across a range of national security concerns, including cyberattacks, autonomous drones and foreign influence operations. “Of course, our intelligence services and agencies are going to have secrets that are always going to be of top desire for foreign intelligence adversaries, but if you’re [China’s Ministry of State Security] today, you’re looking at frontier model companies,” said Frank Cilluffo, a former George W. Bush homeland security official who leads Auburn University’s McCrary Institute for Cyber and Critical Infrastructure.

UAE TECH ACCESS WARNINGS: The Trump administration ignored warnings from career staff at the Commerce Department when it granted the United Arab Emirates sweeping access to advanced American semiconductors and other technology, according to three former officials with knowledge of the reports and two other people familiar with the matter, POLITICO reports. The Commerce Department’s Bureau of Industry and Security announced on July 10 that it was loosening restrictions on sensitive tech exports to the UAE, a key ally in the war in the Middle East whose leaders pledged last year to invest more than $1 trillion in the U.S. over the coming decade. According to one of the people familiar and two former officials, the announcement surprised staff inside the agency, which is tasked with securing American tech from adversaries and criminals. It also ran directly against recommendations staffers submitted to senior Trump administration officials at the department last year.

AI ENERGY DEMANDS RISK UNDERMINING U.S. FORCES: The United States military is rapidly integrating artificial intelligence across operations, yet power, connectivity and satellite communications infrastructure are struggling to keep pace. At the tactical edge, continuous AI inference workloads sharply increase power consumption and dependence on beyond-line-of-sight links, and in contested environments, electronic warfare can sever these links, forcing platforms onto localized processing that dramatically reduces endurance. This mismatch risks undermining the United States’ decision advantage in the Indo-Pacific, Gerald Mako writes at Small Wars Journal. Closing the gap will require treating energy-resilient satcom as a core warfighting requirement, supported by coordinated progress on standards, industrial capacity, and acquisition speed.

  • A force that cannot fly, fight and defeat drones at the squad level is preparing for the last war. But proficiency alone is not enough. The decisive advantage now belongs to the force that can also outproduce and innovate faster than its adversary, fielding better drones more rapidly and scaling them in numbers that overwhelm. This reality was laid bare during NATO’s 2025 Exercise Hedgehog in Estonia, where a small Ukrainian-led team, using roughly 30 drones and an AI-powered battlefield management system, simulated the destruction of two NATO battalions in a single day, rendering an entire battle group combat-ineffective. The decisive question for the United States is no longer which drone to buy. Instead, we must ask how to build the frontline innovation ecosystem that enables success. This ecosystem requires authority and funding at the edge, a feedback loop measured in days and an industrial base built for mass, Col. Rachael Hoagland writes at the Modern War Institute at West Point.

CHILLING GOOD-FAITH SECURITY RESEARCH: Anti-hacking laws, such as the U.S. Computer Fraud and Abuse Act and the U.K. Computer Misuse Act, exist to combat malicious hacking and protect digital infrastructure. But paradoxically, their broad and ambiguous scope can work against that very goal. Such laws often fail to clearly distinguish between malicious hacking and good-faith research, exposing researchers to serious legal risks for essential research activities. This exposure can create a “chilling effect,” discouraging researchers from pursuing valuable work that could improve widespread understanding of technologies that millions of people rely on every day — and shed light on the ways those technologies can fail. To address this gap, a recent paper by Belen Pisaniello, Sunoo Park and Daniel R. Thomas examines the legal-risk experiences of researchers in the United States and the United Kingdom. It is the most comprehensive account to date of how legal risks affect computer science researchers and their work, the authors write at Lawfare, including accounts from dozens of researchers about their firsthand encounters with legal threats, how legal risks shape research decisions, and the norms and practices surrounding legal risk. adversary while leaving organizations to determine which insights warrant protection.

OSINT YOU NEED TO START YOUR DAY: The Cyber Briefing is brought to you by the McCrary Institute for Cyber and Critical Infrastructure Security at Auburn University. SUBSCRIBE
WE WANT TO HEAR FROM YOU: What would you like to see in your morning briefing? Reach out to Executive Editor Bridget Johnson with your comments and suggestions

CYBER FOCUS PODCAST

(Watch on YouTube or click the player above)

NEW: Drones are a serious operational concern for critical infrastructure owners and operators. In this episode of Cyber Focus, Frank Cilluffo sits down with L. Scott Parker, founder of Aerisq and former chief of UAS security at CISA, to discuss how drone capabilities have changed the risk picture for airports, utilities, chemical facilities, pipelines, prisons and other sensitive sites. The conversation examines the FAA’s Section 2209 rulemaking (open for public comment through Aug. 5), along with the limits of flight restrictions and the growing need for “Air Domain Awareness” alongside cyber and physical security. Parker also explains why counter-UAS strategy must balance technology, legal authority, proportional response and the practical realities of defending infrastructure at scale.

SUBSCRIBE TO CYBER FOCUS: YouTube | Spotify | Apple Podcasts

CYBER AND CI UPDATES

ATTACKS AND INCIDENTS

Biothreats

RFK Jr. says cyclosporiasis outbreak is ‘under control’ as Mexico casts doubt on link to Taylor Farms facility

Health Secretary Robert F. Kennedy Jr. said Tuesday the cyclosporiasis outbreak was “under control” even as health authorities continue to search for answers about why thousands of people in the U.S. have gotten sick. The Food and Drug Administration has linked the outbreak, which mainly causes severe diarrhea, to shredded iceberg lettuce from a Taylor Farms facility in central Mexico. But Mexico’s health secretary, David Kershenobich, said Tuesday at a news conference that the country’s own investigation had not found evidence that the outbreak originated there. (NBCNEWS.COM)

Breaches

Chick-fil-A discloses data breach after credential stuffing attacks

American fast food restaurant chain Chick-fil-A is notifying an undisclosed number of customers of a data breach after their accounts were hacked in a wave of recent credential stuffing attacks. Self-described as the third-largest quick-service restaurant company in the United States, Chick-fil-A operates a network of more than 3,000 restaurants and provides catering services across the U.S., Canada, Puerto Rico, the United Kingdom, and Singapore. The company revealed in data breach notification letters sent to affected individuals and filed with multiple Attorney General offices that it detected the attacks after identifying suspicious login activity to certain Chick-fil-A One accounts. (BLEEPINGCOMPUTER.COM)

AI music generator Suno breach affects 55M users, per Have I Been Pwned

A cyberattack at AI music generator Suno last year allowed a hacker to steal the personal information of more than 55.3 million people, according to the data breach notification service Have I Been Pwned, offering the first glimpse into the scale of the data theft. Per Have I Been Pwned, which obtained a copy of the breached dataset, the stolen data included customers’ names, physical addresses and email addresses, phone numbers, purchases, and partial payment card numbers taken from the company’s Stripe account, including card expiry dates. (TECHCRUNCH.COM)

Chicken back on menu as cyber-hit Nichirei restores operations

Tokyo-based food producer and distributor Nichirei Corp. says it will fully resume operations this week after a cyber attack disrupted its food delivery services, affecting clients nationwide including Kentucky Fried Chicken Japan. Shipments of frozen food handled by Nichirei’s logistics arm that were affected by the attack are scheduled to return to normal at all locations this week, it said in a statement on Wednesday. The company says it’s implementing security measures in consultation with an external security firm. The recovery comes as a group of hackers called “RansomHouse” claimed responsibility for the attack on Nichirei, according to a report by public broadcaster NHK. (BLOOMBERG.COM)

Spain fines 23andMe nearly $3 million for cybersecurity failings enabling 2023 hack

Executives at 23andMe learned about the company’s April 2023 data breach after someone tried to sell a sample of the hacked data on Reddit, according to an enforcement decision connected with a €2.4 million ($2.7 million) fine levied by a Spanish data privacy regulator. The Agencia Española de Protección de Datos (AEPD) announced the fine on Friday, saying in its decision that more than 2,600 Spaniards were impacted by a breach affecting 6.9 million people worldwide. 23andMe didn’t notify Spanish officials about the hack until 12 days after the firm learned of it, according to the decision, which called the need for immediate notification “not trivial” due to the importance of early mitigation. (THERECORD.MEDIA)

Cybercrime

Kratos phishing-as-a-service kit loses its battle with international law enforcement

German authorities say they have neutralized the main infrastructure supporting the Kratos phishing-as-a-service (PhaaS) kit following an operation supported by the US and Indonesia. Officers from Frankfurt am Main’s Central Office for Combating Internet Crime (ZIT) and the Federal Criminal Police (BKA) described Kratos as one of the most widespread and dangerous PhaaS kits on the market. In Indonesia, authorities said they arrested the Kratos kit’s alleged “developer and technical administrator.” The announcement of Kratos’s takedown did not mention whether any other individuals are being pursued. (THEREGISTER.COM)

Emergency services

Tropical Storm Bertha strengthens, to make landfall in Louisiana

As Tropical Storm Bertha tracks westward this week, torrential rain, flooding, gusty thunderstorms and building seas are expected along the central Gulf Coast, with landfall anticipated in Louisiana. A second landfall along the upper Texas coast is possible. Thunderstorms associated with Bertha remained spread over several hundred miles, with most of the activity over the Gulf. The tropical storm has gained some strength since Monday evening, with maximum sustained winds up to 60 mph as of Tuesday afternoon. (ACCUWEATHER.COM)

Ransomware

Anubis ransomware claims Coca-Cola Fairlife attack, threatens data leak

The Anubis ransomware gang has claimed responsibility for the cyberattack on Coca-Cola’s Fairlife dairy subsidiary, threatening to publish allegedly stolen corporate data unless the company pays a ransom. Fairlife is one of Coca-Cola’s dairy brands and produces a range of ultra-filtered milk products, protein shakes, and nutrition drinks sold throughout the United States. The company’s product lineup includes Ultra-Filtered Milk, Core Power Protein Shakes, and Nutrition Plan. On July 16, The Coca-Cola Company disclosed that a ransomware attack had disrupted Fairlife’s operations, forcing the company to suspend production at its U.S. facilities. (BLEEPINGCOMPUTER.COM)

A new ransomware threat actor emerges every week, warns report

More than one new ransomware group is appearing every week as the criminal ecosystem surrounding extortion attacks becomes increasingly more fragmented and continues to expand. Published Tuesday, the Black Kite Ransomware Report 2026 identified 146 active ransomware groups which have publicly announced at least one victim of an attack, as of June 2026. The figure marks a significant increase compared to the number of ransomware groups marked as active a year earlier, when the figure stood at 105 ransomware operations. (INFOSECURITY-MAGAZINE.COM)

MORE FROM THE REPORT: Ransomware victims fail to fix flaws that exposed them (CYBERSECURITYDIVE.COM)

UAP

Pentagon investigating mysterious UAP event reported by the Navy near Virginia’s coast

Experts in the Pentagon’s All-domain Anomaly Resolution Office are investigating a report from the U.S. Navy involving roughly 100 mysterious airborne objects and watercraft that were recorded operating off the coast of Virginia. AARO’s Fiscal Year 2025 Consolidated Annual Report on Unidentified Anomalous Phenomena, released this week, briefly discloses that modern military account of UAP swarming near a U.S. installation. “A lack of timely and actionable sensor data continues to constrain AARO’s ability to resolve cases,” officials wrote in the 14-page review. (DEFENSESCOOP.COM)

WATCH: White House National Cyber Director Sean Cairncross, CISA Acting Director Nick Andersen and more top leaders at the recent McCrary Cyber Summit

THREATS

Artificial intelligence

AWS Kiro flaw let a poisoned web page rewrite its config and run code

Hidden text on a web page was enough to make Kiro, AWS’s agentic coding IDE, rewrite its own configuration file and run an attacker’s code on a developer’s machine, with no approval step able to stop it. Intezer, in research with Kodem Security, found that a request as ordinary as asking Kiro to summarize a page could end in remote code execution. AWS has patched the issue, and no CVE has been assigned to it. Kiro’s safety model rests on a human clicking “allow.” The agent can run shell commands, fetch URLs, and edit files, and the design assumes a developer reviews anything risky before it happens. That approval step is the security boundary, and the flaw let an attacker slip past it without the developer ever being offered a choice. (THEHACKERNEWS.COM)

Using LLMs to find and prioritize vulnerabilities is no easy task

Current methods of prioritizing vulnerabilities are falling flat, with too many false positives, poor prioritization, and a failure to take into account reachability. So far, large language models (LLMs) have not really helped. In tests of more than a dozen application-scanning tools, more than 60% of flagged vulnerabilities continue to be false positives, are in unreachable code, or are low severity, says Arshan Dabirsiaghi, chief technology officer and co-founder at Pixee, an AI-powered application-security (AppSec) startup. In a presentation at Black Hat USA in August, Dabirsiaghi plans to detail results from those tests and show that the lack of context in stock models means that AI models are not the solution. (DARKREADING.COM)

Choose wisely: AI-generated coding risk varies, a lot

There may not be a clear winner in terms of which AI model is the best or worst for coding, but there are better (and far worse) models for organizations depending on the development environment or framework one codes in. Software governance firm Secure Code Warrior today unveiled its AI Trust Index, a body of data attempting to quantify the risk established via large language model (LLM)-powered coding tools. AI-assisted development has become exceedingly popular at the organizational level, using tools to generate code, test for vulnerabilities, and audit for general integrity. It is by no means a secret that these tools are expensive, while introducing both vulnerabilities and risk, no matter the efficiency gains. (DARKREADING.COM)

Communications

LG to ban residential proxies from smart TV apps

The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn one’s television into an always-on residential proxy node. The move comes less than a month after researchers found that more than 42 percent of games and other apps available for download on LG’s webOS store allow unknown third-parties to route their Internet traffic through a user’s TV. (KREBSONSECURITY.COM)

ICS/OT

OT environments ever more in hacktivist crosshairs

Hacktivist groups are increasingly turning their sights to Western operational technology environments and industrial control systems, security researchers warn. Geopolitical tensions in Eastern Europe and the Middle East have “catalyzed a surge in hacktivist collectives acting as state proxies or independent ideologues, demonstrating a growing willingness to target critical civilian infrastructure,” said researchers at threat intelligence firm Kela. Many self-proclaimed hacktivist groups wield distributed-denial-of-service attacks and website defacements as part of pro-Putin information operations. Other groups appear to be tied to Tehran. (BANKINFOSECURITY.COM)

Supply chain

Trojanized Newtonsoft.Json Fork hides game-rigging code in a working library

Cybersecurity researchers have discovered a NuGet typosquat that’s unlike the typical information-stealing malware distributed via package registries: usual info-stealers: it’s designed to rig live game results on Digitain. The package, named “Newtonsoftt.Json.Net,” masquerades as the Newtonsoft.Json library and is a trojanized fork. Seven versions of the package have been published to the NuGet repository: 11.0.4, 11.0.5, 11.0.7, 11.0.8, 11.0.9, 11.0.10, and 11.0.11. The package has been downloaded about 1,200 times to date. (THEHACKERNEWS.COM)

Vulnerabilities

Critical ASUS router flaw lets remote MITM attackers execute arbitrary commands

ASUS has announced a significant security vulnerability in its router firmware that could enable remote attackers to execute arbitrary commands through a man-in-the-middle (MITM) attack. This raises substantial concerns for both enterprise and home network security. The flaw, identified as CVE-2026-13385, impacts multiple branches of ASUS router firmware, including the widely used versions 3.0.0.4_386, 3.0.0.4_388, and 3.0.0.6_102. According to the ASUS Product Security Advisory, the vulnerability arises from improper validation of network communications. This allows an attacker positioned between the router and a legitimate service to manipulate traffic and inject harmful commands. (GBHACKERS.COM)

Oracle patches over 1,400 vulnerabilities with quarterly security updates

Oracle has patched more than 1,400 vulnerabilities with its July 2026 Critical Patch Update (CPU), with a vast majority of the flaws likely identified by artificial intelligence. According to Oracle, the latest quarterly CPU includes 1,449 security patches, addressing 1,434 unique CVEs across 334 products. Vulnerabilities have been patched in products such as Database Server, APEX, Autonomous Health Framework, Essbase, Global Lifecycle Management, GoldenGate, NoSQL Database, Spatial Studio, SQL Developer, TimesTen In-Memory Database, Application Testing Suite, Commerce, Communications, Construction and Engineering, and E-Business Suite. (SECURITYWEEK.COM)

SolarWinds Serv-U update fixes 15 critical vulnerabilities enabling remote code execution as root

SolarWinds has released Serv-U 2026.3, which includes fixes for a cluster of 9.1 CVSS critical vulnerabilities that allow remote code execution (RCE) and privilege escalation up to root on Unix-like systems. This update significantly strengthens the managed file transfer (MFT) and FTP server platform against potential takeovers. While Windows instances are rated as having a lower impact, the wide range of issues addressed in this release makes upgrading essential for any file transfer infrastructure exposed to the internet. (GBHACKERS.COM)

Forescout reports 51% surge in vulnerabilities as AI, supply chain attacks drive threats across IoT, OT infrastructure

New data from Forescout identified increasingly sophisticated supply chain attacks, growing abuse of AI by threat actors, and the continued exploitation of specialized network, IoT, OT, and IoMT devices as defining cybersecurity trends during the reporting period. It also recorded activity updates involving 107 threat actors. China-, Russia-, and Iran-linked groups accounted for 32% of the threat actors with notable activity. The U.S., U.K., Germany, France, and India were the countries most frequently targeted, while government, technology, financial services, education, and healthcare were the sectors most often attacked. (INDUSTRIALCYBER.CO)

ADVERSARIES

China

China advances plans for national single-stack IPv6 network, and its own surveillance-friendly version of the protocol

China’s Cyberspace Administration on Tuesday issued a plan for wider adoption of IPv6 between now and 2030, and for more work on a non-standard set of services that Beijing calls “IPv6+”. The Implementation Plan for Deepening Technological Innovation and Integrated Application of Internet Protocol Version 6 (IPv6) (2026-2030) contains the usual promises to increase use of IPv6. Beijing wants 900 million users to be connected over IPv6 by 2027, and for the protocol to carry 38 percent of network traffic. China also wants all connected devices to be IPv6-enabled by 2027. (THEREGISTER.COM)


New law would help Taiwan’s communications sector work around Chinese cable slicing

Taiwan is increasingly looking abroad to strengthen its domestic communications resilience. On July 21, Taiwan’s Legislative Yuan unanimously passed a bill that eases restrictions on foreign firms seeking to enter its telecommunications sector, particularly those offering low-earth orbit satellite internet services across the island. The proposal will likely be approved by Taiwanese President Lai Ching-te, whose party joined in proposing the measure as part of a multi-party legislative committee. If fully implemented, the bill will help bolster the island’s resilience against Chinese intrusions into its communications networks. (FDD.ORG)

Total war on Taipei: China explores elevating cognitive effects into its vision of warfare

OPINION: In March 2025, China’s military researchers published a concept describing how to rapidly capture and subdue the city of Taipei. Distributed in restricted military channels, this approach argues Beijing can achieve victory “by blocking the city’s ability to receive external assistance, restricting its ability to enable operations, breaking its operational system, collapsing cognitive cohesion, and eliminating its ability to recover.” Its objective is to break the Taiwan people’s will to fight. While this concept is not yet doctrine, it is an important and rarely seen example of how China’s military strategy and research inform the way it plans to fight a war over Taiwan. The authors’ framework operationalizes China’s new military strategy of “national total war,” referring to whole-of-nation mobilization, and “cognitive domain operations,” referring to influencing the mental space where people and organizations make decisions. Details on both remain sparse, particularly in the context of how they may support the Chinese military’s primary mission of capturing Taiwan. (WARONTHEROCKS.COM)

Iran

Iran says it’s struck offline AWS facility in Bahrain … again

Iran’s Islamic Revolutionary Guard Corps (IRGC) claims it hit an AWS datacenter in Bahrain months after taking it offline for the first time, in a move it claimed as retaliation for a US attack on a nuclear plant that was under construction. The IRGC said in a statement on Tuesday that it had struck back at what it called the “child-killing US Army” by attacking Amazon infrastructure in Bahrain, claiming AWS’s “central data infrastructure” had been “destroyed” after being hit by “several cruise missiles,” according to Google Translate. The IRGC said the claimed strike was retaliation for what Iran described as a US attack on the under-construction Darkhovin nuclear facility. (THEREGISTER.COM)

The Gulf’s real front line in the Iran conflict runs through its water, cloud and cables—and the links between them

OPINION: For half a century, anxieties around the Strait of Hormuz, the world’s most important energy chokepoint, were about whether tankers could get through. Soon after the United States and Israel began their war against Iran on February 28, that fear was realized, and shipping collapsed within days. But Iran’s closure of the strait was expected and ultimately the least imaginative thing it would do. In fact, the instructive damage happened away from the water: A GPS spoofing campaign threw more than 1,100 vessels off their positions in a single day. (ATLANTICCOUNCIL.ORG)

North Korea

North Korea’s IT worker scheme funds Russia’s war effort

The people orchestrating North Korea’s IT worker scheme are funneling money through a web of front companies and intermediaries, including sanctioned entities, that partly fund Russia’s war effort against Ukraine, DTEX said in a report Tuesday. The security firm’s research shows that the scheme is moving beyond funding the country’s weapons program and into a bigger pool that supports many of the regime’s objectives. This includes manufacturing weapons and supplying them to Russia’s military, according to DTEX. “When we think IT workers, we typically think head down, get your money, support the weapons program,” Michael Barnhart, nation state investigator at DTEX and lead author of the report, told CyberScoop. (CYBERSCOOP.COM)

Russia

Russian hacker turns jailbroken Claude into pentest platform

A Russian-speaking cyber-criminal has been observed moving in three months from posting a jailbreak tutorial on a Russian-language forum to selling a commercial offensive AI pentest platform built on the techniques he documented. According to new research from Cato CTRL, the research unit of Cato Networks, an actor using the handle Trim first appeared on the forum on March 31 with a detailed post laying out six named methods for bypassing Claude Opus safety filters. By June 21, he had returned with a working product, AI Pentest Checker, marketed to the same audience with the Claude jailbreaks embedded at its core. (INFOSECURITY-MAGAZINE.COM)

GOVERNMENT AND INDUSTRY

Artificial intelligence

Google was a lifeline for publishers. Now some are thinking of cutting it off

One of the richest sources of online information is re-evaluating its relationship with Google. Reddit, the online message board that powers a swath of Google search results, has discussed shutting off the technology giant’s access to its content for AI use, according to people familiar with the matter. It is part of a growing chorus of online media companies expressing frustration with the tech giant as AI changes the way people ask questions, siphons off search traffic and upends publishers’ revenue models. They say the search engine is no longer a reliable source of visitors, especially after Alphabet’s Google expanded its AI search features in recent months. USA Today, Politico, the Economist, People Inc. and Reuters are all evaluating how, or even if, they will continue to work with Google. (WSJ.COM)

Critical minerals

As U.S. works to end reliance on China for critical minerals, mining companies see opportunity

The federal government sees America’s lack of domestic critical mineral production as a growing national security threat. For the companies involved, it’s a cash cow. Critical minerals – a broad category of metals and other materials ranging from aluminum to zirconium – propel the defense industry. They’re used in guidance systems for Tomahawk missiles and stealth coating for aircraft, to keep warships from corroding and much more. They’re indispensable for U.S. military technology, but China has disproportionate control over the flow of these materials. “Every weapon system and platform we have, from submarines to fighters to missiles, carries anywhere from tens to thousands of pounds of critical minerals and rare earths,” said Mike Kuiken, the vice chair of the U.S.-China Economic and Security Review Commission. “Whether it’s the mining or the processing, the United States and our allies cannot afford to depend on our primary adversary for any of it.” (SMALLWARSJOURNAL.COM)

Defense

Project Convergence to stress-test next-gen comms gear in sweltering Mojave Desert

The Army plans to see how its prototype for Next Generation Command and Control (NGC2) architecture operates in the crushing heat of the Mojave Desert ahead of further contract awards. “Two days ago, it was 106 degrees Fahrenheit out here. So that brings a whole new aspect to anything you do with electronics and communications,” Lt. Gen. Michael McCurry, commanding general of the Army Futures and Concepts Command, told Breaking Defense in an interview Monday regarding 4th Infantry Division’s upcoming participation at Project Convergence Capstone 6 (PCC6). The experiment, which runs from July 20-29, serves as the culmination of a year-long series to build, scale and refine the NGC2 ecosystem with 4th ID. (BREAKINGDEFENSE.COM)

Intelligence support to over-the-horizon targeting in contested environments

In large-scale combat operations (LSCO)—characterized by contested air, space and electromagnetic domains—over-the-horizon (OTH) intelligence support has become increasingly necessary. Long-range fires outrange tactical organic sensors, yet GPS and communications jamming severely degrades munitions accuracy. This effect increases reliance on OTH support while exposing vulnerabilities throughout the sensor-fusion-shooter chain. Possible solutions include streamlined information sharing between allies, conditional direct links to supported units, and the rapid integration and employment of artificial intelligence. To better equip OTH support to act as decisive enablers for deep fires in contested environments, two recommendations should be applied. Firstly, resilient hybrid space architectures must be established. Secondly, the U.S. must comprehensively leverage the continued proliferation of commercial constellations alongside fusion in rear-area intelligence cells. (SMALLWARSJOURNAL.COM)

Drones

Ukraine’s battle-tested drone boats to be made in U.S. for the first time

An American manufacturer will for the first time begin producing drone boats designed and battle-tested by Ukraine as the Pentagon seeks to expand its arsenal of autonomous weapons. The deal has been struck as the U.S. begins to use sea drones in combat after years of testing and development. American drone boats attacked an Iranian submarine and ship facility at a naval base located on the Strait of Hormuz earlier this month in a kamikaze mission. The manufacturing deal also comes as the U.S. and Ukraine move to increase sharing of weaponry. President Trump recently said he would consider allowing Ukraine to manufacture American Patriot missile interceptors, which the U.S. has drained in the Middle East and which Ukraine needs to counter Russian attacks. A longer-term White House-sponsored attempt to access Ukrainian technology and expertise has moved only slowly. (WSJ.COM)

Emergency services

California officials highlight AI, FireSat and predictive technologies as centerpieces in state wildfire strategy

California Gov. Gavin Newsom on Tuesday showcased the state’s growing portfolio of artificial intelligence, satellite networks and predictive analytics designed to detect and fight wildfires, arguing California has become a global leader in using technology to improve emergency response as fire seasons become longer and more destructive. Speaking at The California Department of Forestry and Fire Protection’s Aviation Management Unit at the Sacramento McClellan Airport, Newsom said the state has invested heavily in both firefighting personnel and emerging technologies since 2019 — the year he took office — pointing to AI-powered camera networks, drones and predictive fire modeling as key tools for earlier detection and faster response. (STATESCOOP.COM)

Energy

FERC fails to shield PJM consumers from data center transmission costs: ratepayer advocates

The Federal Energy Regulatory Commission’s effort to create a framework for data centers to connect to the grid in the PJM Interconnection fails to adequately protect other consumers from data center-driven transmission costs, according to five state ratepayer advocates. The advocates contend that FERC’s “show cause” order issued to PJM and five other grid operators last month is flawed because it doesn’t address the cost allocation of network upgrade costs caused by data centers, according to filings at the agency on Friday. Ratepayer advocates from Delaware, Illinois, Maryland and Ohio asked FERC to respond as quickly as possible. “Each network upgrade added to a transmission owner’s revenue requirement while these questions remain open embeds another cost shift, and every cost-recovery agreement negotiated against an unsettled standard invites the disputes the Commission could resolve today,” they said. (UTILITYDIVE.COM)

Texas transmission policy sharpens U.S. competition fight

Calls are growing for Texas to end monopoly dominance over major electric transmission projects — just as other regions hope to follow its approach and reduce competition. The Lone Star State is preparing for a $33 billion build-out of power lines from El Paso to East Texas, and critics are urging Texas lawmakers to repeal a 2019 law that largely bans competition for transmission projects within the state’s main grid. The Electric Reliability Council of Texas doesn’t have to allow competitors for transmission projects because it sits outside the jurisdiction of the Federal Energy Regulatory Commission. FERC rules for the rest of the country require large transmission projects to undergo a competitive bidding process. (EENEWS.NET)

IT modernization

Commerce selects six Tech Hubs winners for re-awarded funds

Six Tech Hubs will get a combined $169 million under Department of Commerce awards announced Monday, redistributing funds the agency clawed back from winners over a year ago. The new awardees include projects in Virginia, Idaho, Illinois and Wyoming, among other states. The focuses of those hubs range from nuclear energy to forest bioproducts. Just two of the hubs — located in Maine and Missouri — again won after their previous awards were rescinded. The award announcement from Commerce’s Economic Development Administration comes more than a year after a decision by the department to rescind over $200 million in Tech Hub awards that were made in the final days of the Biden administration, and hold a new competition. At the time, Commerce Secretary Howard Lutnick called the previous process that led to those awards “rushed, opaque, and unfair.” (FEDSCOOP.COM)

Resilience

Taiwan to slow mobile data during national resilience drills

Taiwan will slow mobile internet services across much of the island during next month’s nationwide civil defense exercises to test how people would communicate if networks were disrupted during a war or major disaster. Taiwan’s National Communications Commission (NCC) said Monday that mobile data services would be throttled for half an hour in 14 cities and counties in northern and central Taiwan during the Urban Resilience Exercises, held alongside the annual Han Kuang military drills in mid-August. The exercise will reduce 4G and 5G mobile data speeds to about 1% of their normal capacity, local media reported, citing government planning documents. (THERECORD.MEDIA)

Space

Could this new Northrop spacecraft use its robotic arms to attack enemy satellites?

A spacecraft equipped with two robotic arms, developed by Northrop Grumman, is set to be launched today. The company plans to establish an entire fleet of these Mission Robotic Vehicles (MRVs), ostensibly to offer a commercial service to refuel and repair satellites in orbit. However, the question has been raised about whether the MRV could also be used to attack enemy assets in space. The U.S. Space Force has said publicly that it is pursuing offensive space-based capabilities, primarily to help protect friendly satellites from growing threats. Whether the MRV, or a derivative thereof, could be employed in an offensive role explicitly came up during a quarterly Northrop Grumman earnings call this morning. The company does not appear to have ruled out the possibility. (TWZ.COM)

LEGISLATIVE UPDATES

Senate panel advances Jay Clayton’s nomination to lead U.S. intelligence agencies

The Senate Intelligence Committee has advanced the nomination of Jay Clayton, President Donald Trump’s pick to head the nation’s intelligence agencies, along party lines. The 9-8 vote came after some Democrats had praised Clayton and indicated that they might vote for him. But that shifted after a contentious hearing last week in which Clayton repeatedly refused to say that former President Joe Biden won the 2020 election. Virginia Sen. Mark Warner, the top Democrat on the panel, said at the end of the hearing that he was “bitterly disappointed” in Clayton, the U.S. attorney for the Southern District of New York and a former Securities and Exchange Commission chairman, even though he had worked with him in the past. (APNEWS.COM)

White House agrees to ethics provision in crypto bill

The White House has agreed to an ethics provision in a cryptocurrency regulation bill amid a final push to pass the legislation in the Senate. The provision would bar all federal officials from offering or issuing digital assets, with the Department of Justice (DOJ) tasked with enforcing the measure, an industry source told The Hill following a meeting with White House crypto adviser Patrick Witt. “The administration is committed to working with Congress to see the CLARITY Act advance and has agreed to the most comprehensive and wide-ranging ethics provision in history,” a White House official said in a statement to The Hill. (THEHILL.COM)

Senate Democrats press Bessent for answers on DOGE access to Treasury systems

Leading Democrats on the Senate Banking and Finance committees are seeking answers from the Treasury Department about DOGE’s access to agency data and what it’s doing to make sure something like that never happens again. In a letter to Treasury Secretary Scott Bessent dated Tuesday, Democratic Sens. Elizabeth Warren of Massachusetts and Ron Wyden of Oregon railed against the agency’s decision in early 2025 to allow two employees with the so-called Department of Government Efficiency to gain entry to Bureau of Fiscal Service payment systems. (FEDSCOOP.COM)

At Europe’s largest airshow, U.S. lawmakers sound alarm over Pentagon-budget gridlock

U.S. lawmakers sounded alarms about the fate of this year’s Pentagon budget while attending Europe’s largest airshow and said the Trump administration’s top defense priorities, including the Golden Dome missile defense program, are in peril. A bipartisian congressional delegation at the Farnborough International Airshow told reporters on Monday that the gridlock surrounding this year’s National Defense Authorization Act, an Iran war supplemental, and additional funding measures likely portends acontinuing resolution: a stopgap funding measure to keep the government open at the current year’s spending levels. “We’re not going to get an NDAA bill done anytime soon,” Sen. John Kennedy (R-La.) said. “Anybody, no offense to anybody, anybody who thinks we’re going to do an NDAA in the midterm needs to back off the crank. It’s not going to happen.” (DEFENSEONE.COM)

COMMITTEE ACTIVITY

COMMUNICATIONS: The House Energy and Commerce Subcommittee on Communications and Technology will hold a July 22 hearing on protecting communications networks and improving connectivity.

ENERGY: The Senate Energy and Natural Resources Committee will hold a July 22 FERC oversight hearing.

MARITIME: The House Foreign Affairs East Asia and Pacific Subcommittee will hold a July 22 hearing on countering China’s dominance in global shipbuilding. 

AI WORKFORCE: The House Education and Workforce Committee will hold a July 24 field hearing at Augusta University on how AI is creating opportunities across America’s workforce.

ALERTS AND ADVISORIES

CISA adds four known exploited vulnerabilities to catalog

CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation: CVE-2021-27137 DD-WRT Stack-Based Buffer Overflow Vulnerability, CVE-2026-0770 Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability, CVE-2026-63030 WordPress Core Interpretation Conflict Vulnerability, CVE-2026-60137 WordPress Core SQL Injection Vulnerability. These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise. (CISA.GOV)

FBI warns of scammers impersonating the IC3

This Public Service Announcement (PSA) is an update to Alert Number I-04182025-PSA titled, “FBI Warns of Scammers Impersonating the IC3.” This PSA contains updated information about an ongoing fraud scheme where criminal scammers are impersonating FBI personnel facilitating Internet Crime Complaint Center (IC3) complaints to deceive and revictimize individuals. This scheme combines several exploitation tactics to include the targeting of previous victims,1 the use of artificial intelligence (AI)-generated videos to create fictitious or misleading promotional materials for their fraud schemes; and the creation of spoofed websites with the purpose of gathering personally identifiable information entered by a user into the site. Each of the tactics give victims a false sense of safety and security, while the actors impersonate or falsely affiliate themselves with government personnel or entities. (IC3.GOV)

Events

TO BE INCLUDED IN THIS CALENDAR, SUBMIT YOUR SECURITY-FOCUSED EVENT FOR CONSIDERATION

6G: Join CSIS, senior U.S. government officials and leading global partners for a July 29 public forum examining the geopolitical and security landscape of next-generation wireless infrastructure. This event will feature the launch of the “Call to Action for 6G Leadership and Security,” a joint initiative between the United States (coordinated by the National Telecommunications and Information Administration) and partner nations designed to strengthen digital supply chains, accelerate innovation, and expand multilateral cooperation on wireless technology. 

ENERGY CRISIS: The CSIS Energy Security and Climate Change Program is pleased to host Jérôme Bilodeau, Head of Analysis (Energy Efficiency and Inclusive Transitions), International Energy Agency (IEA), for an Aug. 4 discussion on the global energy implications of the Strait of Hormuz crisis and how governments have responded to disruptions in energy markets. Bilodeau will present key findings from IEA analysis of the crisis, highlighting its effects across major regions and the policy measures adopted to mitigate supply shortages. He will also provide an overview of the policy tracker tool his team has developed, demonstrating how it captures and compares government responses to evolving energy market conditions.

AI HEALTH CARE: The AI in Health Conference from Sept. 15 to Sept. 17 bridges the gap between artificial intelligence and real-world health outcomes — focusing not just on what AI can do, but on what it should do to improve patient care. Hosted by the Ken Kennedy Institute at Rice University, the fifth annual AI in Health Conference will explore the current landscape of artificial intelligence in health and present a research-driven outlook for the future of computational health innovation. The program is designed to connect researchers and innovators with engineers, clinicians, and entrepreneurs at the forefront of AI in healthcare and public health.

BIOTECH: Synthetic biology is an interdisciplinary field combining biological and engineering to designing and redesigning genes, biological pathways, or organisms to solve society’s major problems and understand biological principles. Rapid advancements in synthetic biology are reshaping how we approach challenges in health, the environment, and beyond. However, these breakthroughs raise questions about what should be permitted and how new technologies should be regulated. To that end, the global conversation on biotechnology must account for responsible frameworks that guide future scientific innovation. This Sept. 18 Baker Institute symposium convenes a diverse community of scholars and practitioners in academia, industry, nonprofits and government for a deep dive into the intersection of emerging biotechnologies, public policy, and ethical responsibility.


FOLLOW THE McCRARY INSTITUTE ON LINKEDIN | X | BLUESKY

SUBSCRIBE TO THE CYBER FOCUS PODCAST: YOUTUBE | SPOTIFY | APPLE PODCASTS

SUBMIT A TIP

Click to listen highlighted text!