Cyber Briefing – July 23, 2026
TODAY’S TOP 5
CHINESE TECH REINS IN ROGUE OPENAI: A New York startup’s use of a Chinese AI model to rein in a rogue agent built with OpenAI technology is stoking fears that guradrails restricting U.S. AI firms from doing cybersecurity work could drive customers toward their Beijing-based rivals, Reuters reports. The affected startup, Hugging Face, said it had turned to Zhipu AI’s open-source GLM-5.2 model last week to analyze data from the hack after leading U.S. AI models declined the task, unable to distinguish between a defender and an attacker. While the breach was caused by an autonomous agent that escaped containment, it highlighted how U.S. companies facing AI-driven cyberattacks can be limited by American AI labs that either restrict access to their most advanced models or design them to refuse hacking-related tasks out of safety concerns.
- When OpenAI’s advanced artificial intelligence models breached AI startup Hugging Face’s internal systems last week, they spent mere hours carrying out a hack that would have taken a skilled human far longer, people familiar with the matter said, Bloomberg reports. Typically, even a talented hacker would need a couple of weeks to complete an attack like this, said the people, who asked not to be named in order to discuss details that have not been publicly released. OpenAI has been in contact with the US government since learning the breach occurred, one of the people added. An OpenAI spokesperson said the company communicated with law enforcement and other government authorities about the incident, and that it has been transparent with them about its findings.
- The alarming cybersecurity incident involving OpenAI’s newest and most advanced artificial intelligence technology has lawmakers hurrying to advance legislation that they say is needed to prevent AI from spinning dangerously outside human control, POLITICO reports. “This is precisely why we need secure testing with government agencies engaged and having visibility throughout the process,” Sen. Mark Warner (D-Va.), ranking member of the Senate Intelligence Committee, said in a statement. Warner this week outlined a slate of legislative priorities for AI, including the Secure AI Development Act, which would establish a mandatory testing framework for frontier models before they are granted broader public access.
- White House Office of Science and Technology Policy Director Michael Kratsios accused China’s Moonshot AI on Wednesday of stealing from Anthropic’s Fable model and acquiring banned Nvidia chips to build its Kimi K3 system, Quartz reports. According to a post Kratsios published on X, Moonshot “developed a sophisticated internal platform to conduct large scale distillation against U.S. models, allowing them to quickly switch between multiple methods of access to avoid detection.” Distillation is a process in which researchers train smaller AI models using outputs from larger ones to replicate some of their capabilities at lower cost.
- The United States should close a critical gap by creating a statutory AI security review agency, paired with new, purpose-built legal authority for emergency remedies, anti-capture safeguards, real resourcing, and a path toward allied mutual recognition, Martijn Rasser writes at War on the Rocks. The predictable objection is that any such agency would be captured by industry or politicized by whoever holds power. The June episode illustrates why this view gets the problem backwards. Left without a structured institution, we are vulnerable to a system where private, unvalidated corporate claims dictate public outcomes, the very definition of capture. The design challenge is not whether to build one, but how to build one more insulated from those pressures than the status quo. This is not an argument for adopting Anthropic’s preferred policy position, nor for treating its mitigation claims as presumptively correct. The same process should apply to OpenAI, Google, xAI, Amazon, Meta, and any other developer whose frontier model raises comparable national security questions.
IRAN OT THREAT ADVISORY: In a joint cybersecurity advisory, agencies urgently warn U.S. organizations of ongoing Iranian-affiliated cyber targeting of internet-connected operational technology (OT) devices, including programmable logic controllers (PLCs). These actions disrupted PLCs across several U.S. critical infrastructure sectors through malicious project file interactions and manipulation of data on human machine interface (HMI) and supervisory control and data acquisition (SCADA) displays, resulting in operational disruption and financial loss. This update adds new guidance on detecting malicious changes in reusable code modules exploited within Rockwell Automation PLC programs. It also expands scope to include observed targeting of Schneider Electric, Siemens, and potentially other branded/manufactured PLCs, emphasizing the importance of restricting direct internet access and providing best practices for secure deployment.
- Pro-Iran hackers claimed responsibility for a United Airlines website outage Wednesday night that left users reporting an inability to log in, check in or change flights, Threat Beat reports.
- The Iran-backed Houthis claimed their first attack on commercial ships in recent months, opening a new front in the U.S.-Iran war that has already disrupted global energy supplies and rattled bond markets, Bloomberg reports. The militant group, based in Yemen, said it targeted two Saudi Arabian oil tankers in the Red Sea with missiles and drones. The Saudi government confirmed an attack on one refined-products tanker, called the Encelia. The British navy also said a tanker was struck near the Saudi town of Al Shuqaiq in the southern part of the sea. The Houthis said the second vessel was named Layla, which is a crude-oil carrier.
NDDA AND MORE PRE-RECESS HILL ACTION: House Republicans passed $1.1 trillion in funding for the military on Wednesday in a final flurry of activity before leaving Washington for a more than month-long recess, NPR reports. The funding, an annual military policy bill called the National Defense Authorization Act, or NDAA, passed by a vote of 216 to 212, with six Democrats joining Republicans to support the bill. It now heads to the Senate, where it faces an uncertain path forward. The bill — typically advanced with broad bipartisan majorities — has become a largely party-line effort this year. Republicans call the bill “a generational investment in America’s national defense” that “builds the fighting force of the future by prioritizing innovation, lethality, and readiness.”
- A provision to extend the 2015 Cybersecurity and Information Sharing Act was included in the chamber’s version of the NDAA, The Record reports. The Widespread Information Management for the Welfare of Infrastructure and Government Act would reauthorize CISA 2015, which provides legal protections that allow the private sector and federal government to swap data on criminal and nation-state hacking threats.
- The House Science, Space and Technology Committee passed legislation Tuesday that would support new federal collaboration with private entities to study and improve pipeline infrastructure, E&E News reports. The “Next Generation Pipelines Research and Development Act,” H.R. 2613, from Reps. Randy Weber (R-Texas) and Deborah Ross (D-N.C.), would authorize close to $250 million. The bill cleared the panel in a unanimous voice vote. “This bill demonstrates that Republicans and Democrats can set aside our differences and promote meaningful legislation that enhances our leadership and energy research capabilities, and ensures a strong and safe return on the investment of American taxpayers,” said Weber.
- The Senate Commerce, Science and Transportation Committee approved a series of six nominations and seven bills on Wednesday, including a measure to limit the use of vehicles and vehicle technologies developed by foreign entities of concern on American roadways, Roll Call reports. The bill, introduced by Sen. Bernie Moreno (R-Ohio) and co-sponsored by Sen. Elissa Slotkin (D-Mich.), would ban the import, sale and operation of vehicles manufactured by companies deemed “foreign entities of concern,” based in certain adversarial nations such as China. It would also ban the use of technologies developed by such countries, including Chinese-developed connected vehicle technologies, in the U.S.
MOST FEDERAL CYBER REPORTING RULES DUPLICATIVE, GAO FINDS: Seven out of 10 federal cyber regulations requiring written reports to federal agencies are duplicated elsewhere, a report from a government watchdog found in a report to Congress Wednesday, CyberScoop reports. And so far, efforts to de-conflict haven’t had much success, the report from the Government Accountability Office concluded. At the request of two top lawmakers, the GAO examined federal cyber regulations at 37 agencies. It counted 80 out of 117 rules that “either contain the same kind of reporting requirement applicable to a sector or the same reporting requirement as at least one other regulation.”
- These regulations included sector-specific and cross-sector reporting requirements for private-sector entities that may be required to report similar or different cybersecurity information to multiple agencies, the GAO report said. For example, a proposed rule from the Department of Homeland Security related to cybersecurity incident reporting by critical infrastructure sectors acknowledged that it may be potentially duplicative with one or more of the 15 existing financial sector regulations that also require such incident reporting. Additionally, cross-sector regulations may duplicate or conflict with regulations focused on a specific sector. One from the Securities and Exchange Commission that requires publicly traded companies across different sectors to provide cybersecurity plans may duplicate or conflict with regulations focused on a specific sector. GAO has ongoing work to obtain additional industry perspectives on federal cybersecurity regulations, including where they perceive overlap and duplication within selected critical infrastructure sectors.
HOW DRONES ARE BRINGING BACK CHEMICAL WARFARE: Since Russia’s full-scale invasion of Ukraine on February 24, 2022, unmanned aerial vehicles (UAVs) have revolutionized modern warfare. These small consumer-grade and home-made drones have been adapted to drop munitions, crash into targets, or supply cut-off units. Simultaneously, the war has also been shaped by significant trench warfare when opposing sides face each other from well-protected positions, and the frontline moves relatively little. In combination, both these developments have given rise to the use of UAVs to deliver chemical munitions on the battlefield as both sides struggle to dislodge entrenched enemy units. Notably, since the early 2000s, various defense contractors have worked on delivering irritant agents via drones for domestic riot control, and police forces in India and Israel have been documented using such UAVs to disperse protestors. However, the war in Ukraine appears to be the first time UAVs have been used to deliver chemical agents as weapons on the battlefield at a significant scale. At Small Wars Journal, Patrick Senft examines the role of drones in deploying chemical munitions in Ukraine, drawing on open-source images and Telegram posts from military bloggers as well as publicly available sources. The phenomenon is underreported but poses significant legal, ethical, and military challenges.
| OSINT YOU NEED TO START YOUR DAY: The Cyber Briefing is brought to you by the McCrary Institute for Cyber and Critical Infrastructure Security at Auburn University. SUBSCRIBE |
| WE WANT TO HEAR FROM YOU: What would you like to see in your morning briefing? Reach out to Executive Editor Bridget Johnson with your comments and suggestions |
CYBER FOCUS PODCAST
(Watch on YouTube or click the player above)
Drones are a serious operational concern for critical infrastructure owners and operators. In this episode of Cyber Focus, Frank Cilluffo sits down with L. Scott Parker, founder of Aerisq and former chief of UAS security at CISA, to discuss how drone capabilities have changed the risk picture for airports, utilities, chemical facilities, pipelines, prisons and other sensitive sites. The conversation examines the FAA’s Section 2209 rulemaking (open for public comment through Aug. 5), along with the limits of flight restrictions and the growing need for “Air Domain Awareness” alongside cyber and physical security. Parker also explains why counter-UAS strategy must balance technology, legal authority, proportional response and the practical realities of defending infrastructure at scale.
SUBSCRIBE TO CYBER FOCUS: YouTube | Spotify | Apple Podcasts
CYBER AND CI UPDATES
ATTACKS AND INCIDENTS
Breaches
Paidwork breach exposes sensitive data of 23 million users
Paidwork markets itself as a way to earn money through simple tasks like watching ads, testing apps, and completing surveys, with most jobs paying only a few cents at a time. For its users, many of whom are drawn to the platform for small, incremental earnings, the fallout from this breach could end up costing far more than they ever made. According to Have I Been Pwned, which added the breach to its database on July 19, the leaked data covers 23,272,765 users and stems from an intrusion that occurred in March 2026. (HELPNETSECURITY.COM)
Education
Instructure incident driving 58 percent of breach notices in 2026
The mega breach is back in 2026, according to a new report from the Identity Theft Resource Center (ITRC). The nonprofit group, which works to prevent and reduce incidences of identify theft, found that 1,029 data compromises generated 471 million breach notices in the first half of the year, with one incident — the breach involving Instructure’s Canvas platform — accounting for 275 million of those notices, or about 58 percent of the total. The report, released Wednesday by the ITRC, also points to a surge in insider threats, shrinking transparency and escalating zero-day attacks. (GOVTECH.COM)
Energy
Australia’s Origin Energy confirms customer data breach
Australian power producer Origin Energy said on Thursday that a security incident had resulted in the unauthorised access and disclosure of some customer data. The confirmation comes a day after the country’s top electricity and gas retailer said it was investigating a potential security incident. The data includes personal information such as names, addresses, contact numbers and account information, as well as affected customers’ financial information including the last few digits of a credit card or a bank account, Origin said on Thursday. (REUTERS VIA FINANCE.YAHOO.COM)
Financial
Upbound says hack caused $13 million in fraudulent Acima leases
The Upbound Group fintech company disclosed that threat actors who stole data from its systems leveraged it to create $13 million in Acima leases. In a filing with the U.S. Securities and Exchange Commission (SEC), the company says that it “experienced cybersecurity incidents in which certain non-sensitive customer information and other documents were obtained without authorization.” The threat actor used the information to commit fraud in lease-to-own agreements, resulting in financial losses of about $13 million in the Acima segment in the second quarter of this year. (BLEEPINGCOMPUTER.COM)
Government
Ransomware attack leads to major data breach in Kootenai County, Idaho
County officials advised the public on Wednesday that a ransomware attack on March 30 resulted in cyber criminals stealing significant personal information from the county’s network. According to the press release, the impacted information included names, addresses, dates of birth, Social Security numbers, individual taxpayer identification numbers, driver’s license or state identification card numbers, medical information, health insurance identification numbers, as well as financial account and payment card information. (KHQ.COM)
Ransomware
Two-thirds of ransomware victims say AI boosted attack effectiveness
The rise of AI tooling as part of the attacker playbook has become a significant factor in why ransomware attacks have become harder to detect until it is too late. According to a global survey of cybersecurity professionals by Proofpoint, of those organizations which have been hit by a ransomware attack, almost two thirds (65%) said that AI increased the effectiveness of the attack. The AI tools did this by helping cybercriminals to produce more convincing phishing emails, impersonation attacks and credential theft campaigns. (INFOSECURITY-MAGAZINE.COM)
Transportation
Stadler refuses to pay cyberattack ransom
Stadler Rail has confirmed that it was targeted in a cyberattack in mid-July, with the Everest hacker group claiming to have stolen technical data and demanding SFr10m not to exploit it. “Under no circumstances will Stadler pay a ransom,” the Swiss manufacturer said. The attackers obtained compromised login credentials for a data-exchange platform used with one of Stadler’s suppliers, allowing them to access technical information belonging to that supplier. Stadler said its own IT systems “were not compromised and remain intact,” and no data had been lost from its systems. (RAILWAYGAZETTE.COM)
WATCH: White House National Cyber Director Sean Cairncross, CISA Acting Director Nick Andersen and more top leaders at the recent McCrary Cyber Summit
THREATS
Artificial intelligence
Vibe-coded apps riddled with exploitable security flaws
Vibe coding, the use of AI to assist or perform code generation, is increasing dramatically. In May 2026, Hostinger reported, “90% of developers regularly use at least one AI tool at work as of January 2026.” This is likely to increase through the basic business pressure that applies to everything: we need more, faster and cheaper. But while vibe coding is increasing in volume, so are concerns over the security of vibe-developed apps. Xint.io, the web platform that delivers Theori’s AI driven autonomous pentest code (Xint), decided to analyze vibe-coded apps to quantify what, where, why and how often vibe coding introduces security weaknesses into the apps it touches. (SECURITYWEEK.COM)
Malware is targeting AI tools in software development environments
Malware targeting AI coding assistants and software developers’ automated workflows is spreading into more environments with more capabilities, placing defenders at a growing disadvantage. A malware strain dubbed Sandworm_Mode, first discovered by Socket in February, represents a growing threat to software development. According to a CrowdStrike report, the self-propagating worm can spread through code repositories with minimal detection, raising alarms about software supply chains. The malware’s capabilities are extensive, but not especially unique compared to the series of supply-chain worms known as Shai-Hulud, and more recently Mini Shai-Hulud. (CYBERSCOOP.COM)
Emergency services
Fake Bahrain alert app deploys Android surveillance malware
An emerging threat campaign is taking advantage of users’ implicit trust in government emergency alert notifications to target them with devastating Android malware. Researchers from Dream, a cybersecurity vendor focused on national defense and critical infrastructure, published a research blog on July 20 concerning a malicious Android application named “BH Alert,” posing as a Bahraini civil-defense emergency alert application. Threat actors distribute this app as Bahrain, Kuwait, and other Gulf states are activating civil-defense protocols following Iranian missile strikes. (DARKREADING.COM)
Government
Secret Service has investigated 10,000 threats in 2026
U.S. Secret Service Director Sean Curran on Wednesday said the agency has opened more than 10,000 investigations this year into threats against protectees. Curren told reporters about the 40 percent rise, and when compared to last year, that the threat number is “off the charts.” The environment “has become very volatile, and that’s just across the board,” Curran said. “The threat picture and environment is as large as I’ve ever seen it.” (THEHILL.COM)
Malware
Brazilian banking trojan actively spreading in Portugal
An old Brazilian banking malware is still making rounds today, in ongoing attacks against Portuguese organizations. “Lampion” — named after Japanese-style paper lamps — is a banking Trojan believed to have originated in Brazil, where banking Trojans are as culturally native as samba music. It was first discovered around the 2019 holiday season, and Portuguese organizations haven’t given hackers all that much reason to modify it. Researchers at Acronis found that it’s still being used in attacks today, largely in the same form it came in years ago. (DARKREADING.COM)
TrickBot ditches HTTP for DNS tunneling in latest variant
A TrickBot variant has been observed swapping the HTTP command-and-control (C2) channel the malware has used for the better part of a decade for a bespoke DNS tunneling scheme that hides beacons and payloads inside malformed DNS queries. According to new research from Fortinet’s FortiGuard Labs published on July 22, the samples reveal a modular architecture consistent with earlier TrickBot campaigns but with the transport layer redesigned around encrypted data smuggled through DNS packets to a public resolver. The redesign is significant given the family’s history. (INFOSECURITY-MAGAZINE.COM)
New msaRAT malware uses Chrome, Edge browsers to route C2 traffic
The Chaos ransomware gang is using a new backdoor dubbed msaRAT that hides command-and-control (C2) communication by routing it through the Chrome or Edge browsers. The malware is written in Rust and uses the Chrome DevTools Protocol (CDP) to control a headless browser session and establish a connection to the attacker’s server. Since the malware routes all communication through the browser, it does not make any direct connection to the C2 infrastructure, significantly lowering the risk of detection. (BLEEPINGCOMPUTER.COM)
Transportation
KARR Bluetooth vulnerability lets nearby attackers unlock and immobilize over 2 million cars
A critical Bluetooth vulnerability in dealer-installed KARR Security Systems is putting over 2 million vehicles at risk of unauthorized access and immobilization. This situation has prompted urgent calls for drivers to update affected devices. Researchers at the University of California, San Diego, revealed that the flaw allows attackers within Bluetooth range to issue commands such as locking or unlocking doors, disabling alarms, triggering horns and lights, and even preventing a vehicle from starting. Although the vulnerability does not allow for remote driving or control of a moving vehicle, it significantly lowers the barrier for physical theft by enabling silent entry into targeted cars. (GBHACKERS.COM)
Vulnerabilities
New Check Point zero-day vulnerability exploited in the wild
The exploited vulnerability is tracked as CVE-2026-16232 and it affects the cybersecurity company’s Security Management and Multi-Domain Management products. The flaw has been described as an authentication bypass issue that allows an attacker to obtain an application login token. The token can then be used to log in via the SmartConsole with full administrator privileges, and make changes to the security policy and configuration. “Check Point confirmed that this vulnerability has been observed in the wild, affecting a limited number of customers whose Management environments were directly exposed to the Internet without IP restrictions,” Check Point said. (SECURITYWEEK.COM)
Ubuntu snap-confine vulnerability enables local root access
A newly disclosed vulnerability in the Ubuntu component that isolates snap applications has been found to hand full root access to any local user on default installations of Ubuntu Desktop 24.04, 25.10 and 26.04. According to new research from the Qualys Threat Research Unit (TRU) published on July 21, the flaw sits in snap-confine, the enforcement component that builds the execution environment for snap applications. It is tracked as CVE-2026-8933 and rated high severity. It follows a separate snap-confine root-escalation flaw the same team disclosed in the tool four months earlier. (INFOSECURITY-MAGAZINE.COM)
Hackers exploit Windmill flaw to read arbitrary server files without authentication
A high-severity security flaw impacting open-source developer platform Windmill has come under active exploitation in the wild, per VulnCheck. The vulnerability in question is CVE-2026-29059 (CVSS score: 7.5), a case of unauthenticated path traversal impacting Windmill’s “get_log_file” endpoint (“/api/w/{workspace}/jobs_u/get_log_file/{filename}”). “The filename parameter is concatenated into a file path without sanitization, allowing an attacker to read arbitrary files on the server using ../ sequences,” according to an advisory published by Windmill in March 2026. (THEHACKERNEWS.COM)
Flaw in Adobe extension with 300M installs enabled WhatsApp data theft
A highly popular Chrome extension made by Adobe was affected by a vulnerability that could have been exploited to silently steal a user’s WhatsApp chats and contacts. According to web and browser security firm Guardio, whose researchers discovered and reported the vulnerability to Adobe, an attacker could have stolen users’ WhatsApp data simply by tricking them into visiting a seemingly harmless webpage. The exploit did not involve a WhatsApp vulnerability, malware deployment, compromised credentials, or access to the targeted device. (SECURITYWEEK.COM)

ADVERSARIES
China
China’s strategic petroleum reserve as a geoeconomic tool
China’s Strategic Petroleum Reserve (SPR) was established in March 2004, with the aim of constructing China’s first oil base to protect the country’s energy security. Since then, China’s SPR has evolved from a small coastal network into a nationwide system of large-scale storage facilities combining central government, commercial and provincial reserves. While the Chinese SPR is primarily designed to mitigate risks from oil supply chain disruptions, its size compared to that of other countries could give China a large potential leverage on international energy markets and, by extension, in the global economy. In other words, China’s SPR could evolve from an economic policy device to a geoeconomic tool allowing the country to achieve goals such as exercising leverage on other nations, protecting national security, influencing alliances, punishing adversaries and affecting global supply chains. (RAND.ORG)
EU Huawei ban could cost €40bn, far exceeding original estimate
The European Union’s plan to remove telecom equipment from suppliers “high-risk” including Huawei, could cost significantly more than the bloc’s original estimate, new research has revealed. According to industry group GSMA, that replacing equipment from so-called high-risk vendors could cost between €30 billion and €40 billion, far above the EU’s projection of €3.4 billion to €4.3 billion per year over three years. As a result, this amounts to roughly €10 billion to €13 billion overall. (MOBILEEUROPE.CO.UK)
North Korea
New Kimsuky campaign compromised South Korean software vendors
North Korean hackers successfully targeted South Korean collaborative-work software vendors before breaching the suppliers’ customers, threat researchers have found. The campaign by the Kimsuky group, also known as APT43, was carried out in 2025 and early 2026. The group has in the past gone after the corporate infrastructure of South Korean companies, as well as government entities. In one case observed by researchers at the South Korean cybersecurity company ENKI WhiteHat, the hackers compromised a groupware vendor through an externally accessible mail server by installing malware through a remote code execution vulnerability. (THERECORD.MEDIA)

GOVERNMENT AND INDUSTRY
Critical minerals
Reducing U.S. import reliance on critical minerals with substitution and recycling technologies
The U.S. relies on imports for many critical minerals that are essential to the battery and semiconductor industries. But their supply chains are vulnerable to disruptions. GAO looked at how substitution and recycling technologies might reduce reliance on imports. Battery recycling — extracting minerals from batteries for reuse — could reduce imports in 2 to 3 years. Policy options that could help reach this goal include establishing infrastructure for collecting and recycling materials. By contrast, substitution and recycling may not reduce short-term import reliance in the semiconductor industry. (GAO.GOV)
Data
AI-driven data inferencing is outpacing state privacy protections, watchdogs warn
While many states have enacted data privacy laws, some experts warned this week that those protections are being outpaced by advances in artificial intelligence, which can be used to infer sensitive traits — such as sexual orientation, health conditions or political beliefs — from seemingly unrelated data points. Those concerns were the topic of a virtual panel hosted Tuesday by LGBT Tech and the Justice Education Project, where privacy experts warned that AI can infer sensitive traits from seemingly ordinary data, including app usage, search history, location data and online activity. Those data points, when combined and analyzed by AI, can reveal information such as a person’s sexual orientation, health status or other sensitive characteristics, even if they never disclosed them. These risks are especially pronounced for LGBTQ+ people, abortion seekers, protesters and other marginalized groups, as this data can exacerbate systems of surveillance and inequality, panelists said. (STATESCOOP.COM)
Defense
Pentagon’s next APFIT round will prioritize tech that ‘can be made cheaply at scale’
The Pentagon will soon start its selection cycle for the next cohort of companies with production-ready capabilities that the military can quickly operationalize for real-world use via the Accelerate the Procurement and Fielding of Innovative Technologies, or APFIT program. Lawmakers and a team led by Under Secretary of Defense for Research and Engineering Emil Michael hosted an event that filled a large caucus room in the Cannon House Office Building on Tuesday, where APFIT awardees showcased their products and spotlighted recent milestones for U.S. military and government officials, a small group of reporters, and bipartisan members and staff from both chambers of Congress. (DEFENSESCOOP.COM)
Australia whips together a hybrid air defense weapon
Australia successfully tested a “Frankenstein” medium-range air defense system last month, harnessing existing and new capabilities in a way nobody has tried before. After dawdling over the need to improve its ground-based air defense (GBAD) capabilities, Australia — with American assistance — is prioritizing a hybrid solution that takes sensors, software and weapons already in the Australian inventory. This first-of-type integration, which successfully fired an SM-2 interceptor missile, offers an alternative to buying expensive Patriot-type air defense systems, for example. (DEFENSENEWS.COM)
Naval Postgraduate School launches AI supercomputer in first for military
The Naval Postgraduate School announced Wednesday it has deployed the Nvidia DGX GB300 AI supercomputer to expand its computational capabilities and help students learn how to use AI for weather modeling, oceanic and operations research, cybersecurity, resilience planning and response planning. “By supporting the Naval Postgraduate School and placing one of the world’s most advanced AI supercomputers in the hands of the men and women who defend our nation, we are empowering them to train on it, build with it, and lead America’s fighting force with the decisive advantages our Sailors, Marines and Joint Force deserve,” said Nvidia president and CEO Jensen Huang in a press release. Nvidia donated the AI supercomputer to the Naval Postgraduate School Foundation, making it the first in the military to launch the technology. Teams from technology companies Vertiv, DDN and VAST Data provided infrastructure, storage and technical expertise to help speed up the deployment, according to the release. (NEXTGOV.COM)
Drones
Pentagon adds ‘bombers’ to Drone Dominance Program
The Defense Department is adding a new element to its billion-dollar Drone Dominance Program by incorporating unmanned aerial systems that are reusable and can drop bombs on enemy targets. Since its inception last year, the program has been focused on evaluating and procuring large quantities of low-cost, one-way attack drones for the military, with the goal of rapidly fielding them across the force. Now, that portfolio is expanding, the Pentagon announced this week. The bomber drones won’t be like the large, manned bombers in the Air Force’s inventory. For this initiative, the department is seeking man-packable or light-duty combat vehicle-transportable UAS with a mission range of 15-30 kilometers. (DEFENSESCOOP.COM)
An early look at the Air Force’s new counter-drone units
The Air Force has stood up the first rapidly deployable units of Airmen designed to protect air bases in the Pacific or other potential hotspots from aerial attack. These point defense flights are typically made up of roughly 20 enlisted Airmen with aviation and battle management backgrounds and could protect permanent installations in the United States, but they are specially trained to defend remote airfields, such as those set up for agile combat employment missions, from drone attack. “It’s an expeditionary capability, so we want it to be light and lean,” Michael Sheehy, director of future operations under the Air Force deputy chief of staff for operations, told Air & Space Forces Magazine. (AIRANDSPACEFORCES.COM)
Czech government to expand anti-drone powers to protect critical infrastructure
Interior Minister Lubomír Metnar (ANO) and Transport Minister Ivan Bednárik (SPD) on Tuesday presented draft legislation expanding the use of anti-drone measures to protect critical infrastructure. The proposal responds to a growing number of incidents involving unauthorized drones near protected sites and would strengthen the authorities’ powers to counter them. Under the proposed amendment employees of companies operating critical infrastructure should be allowed to disable or destroy drones they identify as dangerous. (ENGLISH.RADIO.CZ)
Resilience
NASA, DOD and others join Energy Department-led Genesis Mission
The Genesis Mission is expanding beyond the Department of Energy to include 20 federal agencies that are bringing a combined commitment of more than $5 billion and a range of challenges to tackle. The Genesis Mission is a DOE-led effort to combine the advancements in AI, quantum and high-performance computing to stand up supercomputers, launch a national platform and double the productivity of the country’s research-and-development budget. The federal agencies enlisting in the initiative include the departments of Defense, Health and Human Services, Transportation, and Interior, as well as NASA and the National Science Foundation. The expansion was announced Wednesday at the Genesis Mission 2026 Summit in Washington, D.C., with several agency leads in attendance. (FEDSCOOP.COM)
Social media
French Parliament greenlights social media ban for under-15s
Both houses of the French Parliament voted Tuesday to block social media access for children under 15, making France the first European country to enact a ban amid a broadening global crackdown. The law will take effect on September 1, when users under 15 will no longer be able to create new social media accounts. Enforcement of the ban on existing accounts will begin in January 2027. The legislation also outlaws the use of cell phones in high schools. The devices are already banned from elementary and middle schools. (THERECORD.MEDIA)
Space
Space Force launch program sees demand surge from 60 missions to 170
The Space Force is tripling the size of one of its main launch procurement contracts from $5.6 billion to $17 billion to accommodate growing demand from government customers. The service on July 17 announced an increase in the ceiling value for Lane 1 of its National Security Space Launch program, the contract mechanism the Space Force uses to launch government payloads with less stringent mission assurance requirements. The scope of the effort has grown from earlier estimates of around 30 to 60 missions to roughly 170 over a five-year ordering period, a Space Systems Command spokesperson told Air & Space Forces Magazine. (AIRANDSPACEFORCES.COM)
FCC approves satellite spectrum license streamlining
The Federal Communications Commission (FCC) approved a sweeping overhaul of its licensing process for spectrum usage by satellites — a move that will cut red tape for operators across the military, civil and commercial sectors, as well as ease the path to orbit for new types of missions. The reforms have been widely lauded by the space industry. While the FCC does not license satellites owned by the Defense Department, operators providing commercial services to the US military and national security agencies must obtain a commission license. (BREAKINGDEFENSE.COM)
Next Space Force chief throws cold water on the idea of space privateers
In the early years of the United States, when the nascent US Navy was still getting its sea legs, several presidents used privateers to capture or destroy enemy warships when armed naval vessels were unable to do so. President John Adams was one of the most vigorous proponents of commissioning private vessels for national ends. His administration issued letters of marque and reprisal during the so-called “Quasi-War” with France in the final years of the 18th century. These letters created the legal distinction between privateering and piracy. One of the letters signed by Adams, dated November 1799, authorized the use of a merchant ship to “subdue, seize, and take any armed French vessel” found near US coastal waters of “elsewhere on the high seas.” France also routinely used privateers against US shipping at the time. (ARSTECHNICA.COM)
When commercial satellites become wartime intelligence
OPINION: Recent reports allege that MizarVision, a Chinese geospatial artificial intelligence (AI) company, published AI-enhanced imagery of U.S. military assets in the Middle East, raising concerns that commercial imagery could aid targeting during active hostilities. At the same time, companies such as Planet Labs have reportedly restricted access to images from conflict zones at the request of the U.S. government. One case involves exposure, the other restraint, but both highlight the same reality: Governments now view commercial satellite imagery as a strategic asset. (LAWFAREMEDIA.ORG)
Transportation
Hanover is testing the cybersecurity of its light rail power supply
A substation on the Hanover light rail network will host one of the four pilot projects of the European PREVENT programme, designed to increase the cyber resilience of transport power systems. According to the International Association of Public Transport – UITP, a partner in the project, an automated power supply system, equipped with backup batteries, will be tested in Hanover to withstand potential cyber-attacks. The tests will focus on the points through which attackers could penetrate the system, the security of data exchange, and the effects that unauthorised commands could have on physical components. (RAILWAYPRO.COM)
LEGISLATIVE UPDATES
Lawmakers get taste of AI-enabled cyberattacks in China-Taiwan war game
Members and staffers from the House Homeland Security Committee and the House China Select Committee were put through a simulated Taiwan crisis Tuesday that tested how U.S. officials might respond to AI-backed cyberattacks targeting transportation and logistics networks needed to deploy American forces. The Center for Strategic and International Studies hosted the event to give lawmakers a window into the trade-offs and uncertainty that would shape the U.S. response to a fast-moving conflict involving China and its implications in American cyberspace. Among those participating were Republican Reps. Eli Crane of Arizona, Michael Guest of Mississippi and Michael McCaul of Texas, along with Democratic Rep. Shri Thanedar of Michigan and Puerto Rico Resident Commissioner Pablo José Hernández, also a Democrat. (NEXTGOV.COM)
AI, audits and OSINT featured in House intel bill
An annual spy authorization bill seeks to boost the intelligence community’s use of artificial intelligence and takes another whack at advancing reforms to open source intelligence (OSINT), among numerous other provisions. The House Permanent Select Committee on Intelligence passed its version of the fiscal 2027 intelligence authorization act on Monday in a closed-door markup. The annual bill includes a sweeping set of provisions that impact the management and operations of the 18 U.S. intelligence agencies. The committee typically writes and debates most of the bill behind closed doors, before releasing an unclassified version of its markup. (FEDERALNEWSNETWORK.COM)
COMMITTEE ACTIVITY
AI WORKFORCE: The House Education and Workforce Committee will hold a July 24 field hearing at Augusta University on how AI is creating opportunities across America’s workforce.
ALERTS AND ADVISORIES
Iranian-affiliated cyber actors exploit programmable logic controllers across U.S. critical infrastructure
The Federal Bureau of Investigation (FBI), Cybersecurity and Infrastructure Security Agency (CISA), National Security Agency (NSA), Environmental Protection Agency (EPA), Department of Energy (DOE), United States Cyber Command – Cyber National Mission Force (CNMF), and Department of the Treasury (Treasury) (hereafter referred to as the “authoring agencies”) are urgently warning U.S. organizations of ongoing cyber exploitation of internet-connected OT devices — including PLCs manufactured by Rockwell Automation/AllenBradley, Schneider Electric, Siemens, and potentially other manufactured PLCs — across multiple U.S. critical infrastructure sectors. As a result of this activity, organizations from multiple U.S. critical infrastructure sectors experienced disruptions through malicious interactions with PLC project files and the manipulation of data displayed on human machine interface (HMI) and supervisory control and data acquisition (SCADA) displays. In a few cases, this activity caused operational disruption and financial loss. (IC3.GOV)
CISA adds two known exploited vulnerabilities to catalog
CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation: CVE-2026-16232 Check Point SmartConsole Improper Authentication Vulnerability and CVE-2026-50522 Microsoft SharePoint Deserialization of Untrusted Data Vulnerability. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise. (CISA.GOV)
Events
TO BE INCLUDED IN THIS CALENDAR, SUBMIT YOUR SECURITY-FOCUSED EVENT FOR CONSIDERATION
6G: Join CSIS, senior U.S. government officials and leading global partners for a July 29 public forum examining the geopolitical and security landscape of next-generation wireless infrastructure. This event will feature the launch of the “Call to Action for 6G Leadership and Security,” a joint initiative between the United States (coordinated by the National Telecommunications and Information Administration) and partner nations designed to strengthen digital supply chains, accelerate innovation, and expand multilateral cooperation on wireless technology.
ENERGY CRISIS: The CSIS Energy Security and Climate Change Program is pleased to host Jérôme Bilodeau, Head of Analysis (Energy Efficiency and Inclusive Transitions), International Energy Agency (IEA), for an Aug. 4 discussion on the global energy implications of the Strait of Hormuz crisis and how governments have responded to disruptions in energy markets. Bilodeau will present key findings from IEA analysis of the crisis, highlighting its effects across major regions and the policy measures adopted to mitigate supply shortages. He will also provide an overview of the policy tracker tool his team has developed, demonstrating how it captures and compares government responses to evolving energy market conditions.
AI HEALTH CARE: The AI in Health Conference from Sept. 15 to Sept. 17 bridges the gap between artificial intelligence and real-world health outcomes — focusing not just on what AI can do, but on what it should do to improve patient care. Hosted by the Ken Kennedy Institute at Rice University, the fifth annual AI in Health Conference will explore the current landscape of artificial intelligence in health and present a research-driven outlook for the future of computational health innovation. The program is designed to connect researchers and innovators with engineers, clinicians, and entrepreneurs at the forefront of AI in healthcare and public health.
BIOTECH: Synthetic biology is an interdisciplinary field combining biological and engineering to designing and redesigning genes, biological pathways, or organisms to solve society’s major problems and understand biological principles. Rapid advancements in synthetic biology are reshaping how we approach challenges in health, the environment, and beyond. However, these breakthroughs raise questions about what should be permitted and how new technologies should be regulated. To that end, the global conversation on biotechnology must account for responsible frameworks that guide future scientific innovation. This Sept. 18 Baker Institute symposium convenes a diverse community of scholars and practitioners in academia, industry, nonprofits and government for a deep dive into the intersection of emerging biotechnologies, public policy, and ethical responsibility.
FOLLOW THE McCRARY INSTITUTE ON LINKEDIN | X | BLUESKY
SUBSCRIBE TO THE CYBER FOCUS PODCAST: YOUTUBE | SPOTIFY | APPLE PODCASTS