Skip to content
SPECIAL

THREATS TO CRITICAL INFRASTRUCTURE IN IRAN CONFLICT

READ MORE

Cyber Briefing – July 24, 2026


Cyber Briefing

DIRECTOR’S NOTE: Read here

TODAY’S TOP 5

AI KILL SWITCH LEGISLATION LANDS: Two members of Congress have introduced bipartisan legislation that would require developers of the most advanced artificial-intelligence systems to maintain the ability to slow down, suspend or shut down their models if they pose serious risks, The Wall Street Journal reports. The AI Kill Switch Act would give the Homeland Security Department authority to order companies to take emergency action against AI systems that could cause catastrophic harm, in consultation with the Commerce secretary and the director of national intelligence. The bill from House Representatives Ted Lieu (D-Calif.) and Nathaniel Moran (R-Texas) comes days after OpenAI disclosed that two of its AI models escaped a testing environment, accessed the internet and compromised systems at Hugging Face, an AI platform company. OpenAI described the incident as an “unprecedented cyber incident” involving state-of-the-art cyber capabilities, the Wall Street Journal reported.

  • Hugging Face co-founder and chief science officer Thomas Wolf sensed that something was off the minute he first looked at his company’s logs of the weekend attack. “This is making no sense. This guy is just looking at cybersecurity data sets,” he remembers thinking. “Human attackers, they don’t want that. They want something they could sell.” Hugging Face put an end to the attack two days later, with help from a model from China, Wolf said. It was only early this week that Hugging Face learned from OpenAI that its models were behind the hack. Nearly two weeks later, OpenAI is still piecing together what happened, The Wall Street Journal reports.
  • Giving more resources to the government’s Center for AI Standards and Innovation has support from President Donald Trump’s top science and technology official, FedScoop reports. “I think CAISI can certainly benefit from more resources,” Office of Science and Technology Policy Director Michael Kratsios told Rep. Jay Obernolte (R-Calif.) on Wednesday at a House hearing. Obernolte sponsored the bill to codify the standards-setting body into law and asked the director about whether the Commerce Department component has adequate resources. It’s difficult to recruit people to work in government and even harder when it comes to the experts needed for testing and evaluation who would work for the private sector and easily make more money, Kratsios explained.
  • If a widespread AI attack were to occur against one or more of the 16 U.S. critical infrastructure sectors, it could prove devastating to the daily life and security for Americans and have massive economic implications. If the United States wants to survive the initial onslaught of a major AI cyberattack, it must seek to improve its whole-of-society partnerships and communication. Specifically, the U.S. federal government should focus its efforts on this framework, Andrew Faulhaber writes at CSIS.

INSIDE THE WHITE HOUSE DEBATE OVER CHINESE AI: The Trump administration is wrestling with how to respond to the possibility that leading Chinese tech firm Moonshot AI stole American intellectual property to create its latest artificial intelligence model, POLITICO reports. The company’s Kimi K3 model – released last week – is nearly as powerful as the U.S.’s most advanced efforts but far less costly. That creates a confounding dynamic inside the administration where President Donald Trump’s science and technology adviser and Treasury Secretary Scott Bessent are taking a hardline approach aimed at protecting American IP, while Commerce Secretary Howard Lutnick has a more modest approach, concerned with companies’ access to cheaper, effective technology. The debate inside the White House underscores the competitive uncertainty and potential threats that Chinese firms represent to American tech companies and the degree to which the Trump administration has failed to coalesce around a response.

  • Last summer, top Chinese chip developer Huawei Technologies held a closed-door briefing for the country’s technology czar to introduce its latest artificial-intelligence chips. The company laid out a plan for rivaling American behemoth Nvidia and said China could become self-sufficient in some critical areas of AI within three years, The Wall Street Journal reports. It was just what Ding Xuexiang, a confidant of Chinese leader Xi Jinping, wanted to hear. Three years earlier, Washington had squeezed China’s access to cutting-edge AI chips and the tools required to manufacture them — a potentially crippling blow to the country’s ambitions as a tech power. With Xi’s blessing, Vice Premier Ding started a fevered effort to forge domestic alternatives. Ding dusted off the same all-out approach China had used to produce its first atomic bombs, hydrogen bombs and satellites in the 1960s during a rift with the Soviet Union. He set up a committee that drew from the country’s best companies and labs to form specialized teams and directed them to master the different elements of the chip supply chain.
  • China defended the country’s development of artificial intelligence, stating it comes from “greater self-reliance and strength” after a top White House official accused a Chinese startup of improperly using Anthropic’s latest model and accessing restricted Nvidia chips, The Hill reports. Lin Jian, China’s Foreign Ministry spokesperson, told reporters on Wednesday the country “opposes politicizing and instrumentalizing trade and tech issues,” as the startup Moonshot AI faces allegations of distilling technology and stealing intellectual property (IP) from U.S. frontier labs to develop its latest model, Kimi K3.
  • An IT researcher said he found a total of 19 zero-day vulnerabilities in the then-current version 8.8.0 of the redis database in 90 minutes using the AI from the Chinese start-up Moonshot AI, Heise reports. Kimi K3 also created proof-of-concept code (PoC) to demonstrate the exploitation of the vulnerabilities.

RUSSIAN PHISH WITHOUT A CLICK: A group of Russian state-supported cyber actors has been targeting and compromising various Western government and commercial organizations using the Zimbra Collaboration Suite (ZCS) software since at least July 2025, according to a new joint cybersecurity advisory. The Russian state-supported advanced persistent threat (APT) group’s activity is tracked in the cybersecurity community under several names (see Cybersecurity industry tracking), primarily as “LAUNDRY BEAR,” a name initially coined by the Netherlands General Intelligence and Security Service (AIVD) and Defence Intelligence and Security Service (MIVD). The group’s targeting is almost certainly to gather sensitive information for the Russian Federation, with these actors primarily focusing on the covert acquisition of email data. Unlike traditional phishing campaigns that persuade a user into taking an action, such as clicking a link or opening a file, LAUNDRY BEAR’s latest campaign leverages a view-based exploit that only requires a user to view a malicious email within a vulnerable version of the webmail service.

  • Slovakia has become a target of cyber operations linked to the Russian security services. Although the Slovak authorities confirmed, following media inquiries, that the attacks had affected targets inside the country, Robert Fico’s government did not initially informed the public about the incident. According to available information, the attacks targeted critical infrastructure, the energy sector, the defence industry and the automotive sector, Balkan Insight reports.

PRO-IRAN HACKERS TAKE ANOTHER SWIPE AT MICROSOFT: Pro-Iran hackers who claimed to have disrupted Microsoft 365 in the early days of the war said Thursday that they came back for another round of “targeting systems managed by the West that are actively used to serve the enemy by processing data and assisting in carrying out attacks,” Threat Beat reports. Reports of problems with Microsoft 365 began climbing at Downdetector at 10:25 a.m. on Thursday, peaking just after 11 a.m. and persisting throughout the afternoon. Users reported inability to access SharePoint and OneDrive, and issues with services including Microsoft Teams. “We’ve confirmed some users in North America are experiencing issues accessing or using various Microsoft 365 services,” Microsoft posted on X at 11:56 a.m. “We’re analyzing service telemetry and diagnostic data to isolate the source of impact.”

  • Iran has quickly rebuilt infrastructure damaged during the U.S. and Israeli bombing campaign over recent months, from missile bases nestled deep inside mountains to bridges, ports and production facilities, according to Israeli and Western officials and a review of satellite imagery, The Wall Street Journal reports. The faster-than-expected progress worries some Israeli officials. It helps explain Iran’s continued resilience despite an air campaign that involved more than 20,000 strikes at the height of the war and that continues along Iran’s coast in an effort to break Tehran’s grip on the Strait of Hormuz. Near Kangavar, in western Iran, satellite imagery from Planet Labs in March showed two tunnel entrances and an access road damaged by airstrikes aimed at blocking access to an Iranian missile base. Within weeks, imagery from Airbus revealed a neatly paved road leading to freshly excavated entrances. 

BEFORE A CYBER FORCE, FIX CYBER GOVERNANCE: “Two years ago, I was a career submariner being detailed to U.S. Cyber Command to pay my joint penance, unsure how a non-cyber officer could support. Seeing the successes but also cyber’s unrealized potential, I left the command equal parts Cyber Force acolyte and skeptic,” Justin Hardy writes at War on the Rocks. “I won’t relitigate whether the force-generation model is broken because smarter and more experienced professionals have documented that failure, and on the man-train-equip problems, they are certainly right. But before the cyber community starts to debate what to call these new Cyber Force warriors, the department should answer the question the Senate was one vote away from skipping. The debate should answer the question of who will govern cyberspace.” and military challenges. 

OSINT YOU NEED TO START YOUR DAY: The Cyber Briefing is brought to you by the McCrary Institute for Cyber and Critical Infrastructure Security at Auburn University. SUBSCRIBE
WE WANT TO HEAR FROM YOU: What would you like to see in your morning briefing? Reach out to Executive Editor Bridget Johnson with your comments and suggestions

CYBER FOCUS PODCAST

(Watch on YouTube or click the player above)

Drones are a serious operational concern for critical infrastructure owners and operators. In this episode of Cyber Focus, Frank Cilluffo sits down with L. Scott Parker, founder of Aerisq and former chief of UAS security at CISA, to discuss how drone capabilities have changed the risk picture for airports, utilities, chemical facilities, pipelines, prisons and other sensitive sites. The conversation examines the FAA’s Section 2209 rulemaking (open for public comment through Aug. 5), along with the limits of flight restrictions and the growing need for “Air Domain Awareness” alongside cyber and physical security. Parker also explains why counter-UAS strategy must balance technology, legal authority, proportional response and the practical realities of defending infrastructure at scale.

SUBSCRIBE TO CYBER FOCUS: YouTube | Spotify | Apple Podcasts

CYBER AND CI UPDATES

ATTACKS AND INCIDENTS

Cybercrime

Illinois man sentenced for hacking Snapchat accounts to steal nude photos

An Illinois man was sentenced on Tuesday to more than six years in prison after admitting he hacked the Snapchat accounts of ‌hundreds of women in order to steal any nude or semi-nude photos they had, ‌which he then kept, sold or traded on the internet. Kyle Svara, 27, was sentenced by U.S. District Judge Brian Murphy in Boston to 76 months in prison after pleading guilty to charges arising out of an earlier prosecution of a former Northeastern University track-and-field coach who paid him to hack the accounts of student athletes and other women. The sentence was confirmed by a spokesperson for U.S. Attorney Leah Foley, ‌whose office prosecuted Svara. (REUTERS VIA YAHOO.COM)

Rubio unveils visa restrictions targeting cybercrime networks

Secretary of State Marco Rubio announced on Thursday a new visa restriction policy targeting foreign nationals responsible for or complicit in cybercrime and cyber-enabled crime. “This policy targets individuals responsible for, or complicit in, cybercrime and cyber-enabled crime, such as those involved in cyberscams, and sextortion,” Rubio said in a statement. Certain immediate family members of people covered by the policy may also be subject to the State Department’s new visa restrictions, according to Rubio. (FOXNEWS.COM)

Education

Ransomware attacks targeting universities on the rise

Universities have found themselves in the firing line of cybercriminals, as ransomware attacks against higher education institutions have increased, analysis of recent incidents has revealed. According to the Comparitech’s Education Ransomware Roundup for the first half of 2026, the number of attacks against higher education providers between January and June increased by 8% when compared with the previous six months. The report, published on July 23, pointed to the rise of The Gentlemen ransomware operation as a key factor in the surge of attacks against the sector. (INFOSECURITY-MAGAZINE.COM)

Government

Cyberattack behind monthlong outage in St. Louis suburb

A cyberattack is behind the monthlong outage that knocked out some University City online services, including bill payments and building permits, officials acknowledged Wednesday. For weeks, the city attributed the disruption to “server issues.” On Wednesday, communications manager Jared Jones told the St. Louis Post-Dispatch that UCity’s network was targeted with “malicious” intent. “The cyberattack disrupted network connections and prevented access to several essential city systems and online services,” Jones said in an email. “Once the activity was identified, the city worked with its technology and cybersecurity partners to stop the attack and begin rebuilding and restoring the affected systems.” (GOVTECH.COM)

Hacker runs Hermes AI agent unattended for post-exploitation at Thai Finance Ministry

Someone installed a popular AI assistant on a rented server, switched off the setting that makes it ask permission before running risky commands, and pointed it at Thailand’s Ministry of Finance, which runs the country’s treasury and tax collection. The agent then worked through the ministry’s network on its own, checking hosts for ways to gain root access, hunting through file systems, and crawling a folder of staff personnel records going back to 2012. The operator left the agent’s own logs sitting on a web server with directory listing switched on, where threat intelligence firm Hunt.io and researcher Bob Diachenko found them, along with 585 files and 470 MB of attack tooling. (THEHACKERNEWS.COM)

Tactics

Hotel Wi-Fi DNS poisoning attacks hijack Microsoft 365 accounts without phishing

Adversaries are silently hijacking Microsoft 365 accounts by compromising hotel and conference-center Wi-Fi gateways and poisoning DNS no phishing emails, malicious attachments, or endpoint malware required. ReliaQuest assesses that the tradecraft closely mirrors prior APT28-linked router campaigns, extending them into captive-portal infrastructure used by traveling corporate staff. Since at least June 2026, threat actors have been compromising captive-portal appliances at hotels, conference centers, and other public Wi-Fi venues and using them to redirect all web traffic through attacker-controlled infrastructure. (GBHACKERS.COM)

WATCH: White House National Cyber Director Sean Cairncross, CISA Acting Director Nick Andersen and more top leaders at the recent McCrary Cyber Summit

THREATS

Artificial intelligence

Europe’s multilingual reality exposes AI security gaps

Not all languages are treated equally when it comes to AI model function and safety, and European organizations face a particular risk when it comes to this reality. The modern large language model (LLM) ecosystem relies heavily on natural language, whether a user is speaking to a chatbot, issuing specific instructions for software development, generating emails, or performing large-scale data analysis. This reliance is further illustrated through the wide range of prompt injection attacks that rely on language-based trickery. While leading models can process text in dozens to hundreds of languages, performance and safety capabilities vary dramatically between languages. (DARKREADING.COM)

AI agents now enterprises’ fastest-growing exposed attack surface

The rapid adoption of enterprise AI tools is the fastest-growing source of new exposure for businesses, and it puts them at risk to additional cyber threats, a new report has warned. Published on July 22, the Sophos AI Security 2026 Report, warned that AI identities have become a new attack surface as AI agents and assistants are adopted in the workplace. Employees have deployed coding agents, agentic AI assistants, LLMs and other tools to help them with their work. It has become common for the agents to receive privileged access to core systems to aid with their efficiency. (INFOSECURITY-MAGAZINE.COM)

Malware

Golden Chickens resurfaces with four new malware families and modular implants

The threat actors behind the Golden Chickens malware-as-a-service (MaaS) ecosystem have resurfaced with four new malware families, indicating that the operators are showing no signs of stopping despite extensive public disclosures into their inner workings. The malware families in question are: TinyEgg, ChonkyChicken, a modularized variant of ChonkyChicken, and a modified web browser credential theft utility codenamed ChromEggscalator. Recorded Future’s Insikt Group is tracking the group under the moniker TAG-195. TAG-195 is a financially motivated malware-as-a-service (MaaS) developer whose tooling has been previously linked to TAG-127 as an operator and customer. The threat intelligence company said it has also observed TAG-127 deploying TinyEgg via ClickFix-style social engineering campaigns that trick unsuspecting users into manually executing malicious commands. (THEHACKERNEWS.COM)

SourTrade browser-assembled malware defeats hash-based detection by design

SourTrade turns the browser itself into a malware build system, deliberately sidestepping the industry’s reliance on hash-based file fingerprints and traditional network-centric detection. SourTrade has been active since late 2024, abusing programmatic ads to reach retail traders and crypto investors in 12 geographies across APAC, LATAM, Africa, and Western markets, including Japan, Thailand, South Korea, Taiwan, Hong Kong, Bolivia, Brazil, Nigeria, Türkiye, South Africa, Australia, and Great Britain. Landing pages deploy a cloaking kit that fingerprints visitors and cleanly separates analysts, bots, and automated scanners from human victims. (GBHACKERS.COM)

Hackers abuse Notepad++ plugins to stealthily install malware

Ukraine’s CERT has uncovered attacks distributing an archive containing the legitimate Notepad++ application and a malicious utility called LunchPoke disguised as a plugin to establish persistence. The campaign has been attributed to a threat cluster tracked as UAC-0099, which primarily targets organizations in Ukraine and has previously been linked to providing initial access for attacks carried out by APT44, also known as Sandworm. The attackers do not exploit any vulnerability or a supply-chain compromise impacting the popular software. (BLEEPINGCOMPUTER.COM)

Chaos ransomware’s msaRAT: Living off the browser to build a covert C2 channel

Cisco Talos has discovered a new Rust-based remote access trojan (RAT) we call “msaRAT” attributed to the Chaos ransomware group. The name is derived from the binding names found in the binary: “msaOpen,” “msaClose,” “msaError,” and “msaMessage”. msaRAT is implemented using the Tokio asynchronous runtime, with primary capabilities of browser-leveraged remote code execution and covert tunneling to establish command-and-control (C2) communications. This RAT never touches the network directly — it controls its C2 communication channel exclusively through Chrome DevTools Protocol (CDP), a browser debugging API. The binary contains a Cloudflare Workers endpoint, but it never makes HTTP connections to that domain itself; it offloads that work entirely to the browser. (BLOG.TALOSINTELLIGENCE.COM

New Dolphin X malware uses AI to rank high-value targets

A new Dolphin X remote access trojan claims to use an AI-powered profiling feature to score and rank infected users, helping cybercriminals identify which victims should be targeted first. The malware was analyzed by Varonis Threat Labs researcher Daniel Kelley, who spotted it being advertised on a cybercrime forum by a vendor using the alias “Kontraktnik,” promoting it as an all-in-one remote access trojan. According to Varonis, the operator panel lists 329 features across ten categories, including a credential-stealing feature that claims to target more than 300 applications. (BLEEPINGCOMPUTER.COM)

Phishing

ChatGPT among top 10 most impersonated brands in phishing attacks, says Check Point

Open AI’s ChatGPT entered the top 10 of the most impersonated brands in phishing attacks for the first time in the second quarter of 2026, according to a Check Point study. This included a fake “ChatGPT Plus payment failed” email the cybersecurity company observed in June. The malicious email was dressed up to look exactly like an OpenAI billing notice and led victims to a page built purely to steal full credit card details. The inclusion of OpenAI’s top customer-focused tool is “a strong signal of where attacker attention is heading next,” said Check Point. (INFOSECURITY-MAGAZINE.COM)

Vulnerabilities

Finding eight high-severity vulnerabilities in NodeBB in six hours

Aikido ran a whitebox assessment on NodeBB, a forum software powered by NodeJS. The result? Eight high-severity vulnerabilities that would all be exploitable on default instances of NodeBB. This includes Cross-Site Scripting (XSS), two of which require interaction with a custom Federation server that the AI agent had to set up itself. Another affects practically every input on NodeBB due to a template injection. Apart from these issues, there were clever authorization bypasses to hijack and read various data that shouldn’t be public. (AIKIDO.DEV)

Apache Syncope flaws let users gain admin roles and execute remote code

Apache Syncope has released versions 4.1.24.1, 4.1.24.1.2, and 4.0.74.0.7 to address six security vulnerabilities affecting the 4.1, 4.0, and 3.0 release branches. These vulnerabilities include a self-service privilege escalation bug, multiple post-authentication remote code execution (RCE) pathways, authenticated server-side request forgery (SSRF), and SQL injection issues. CVE-2026-62183 affects deployments that utilize the all-Java user workflow adapter or the Flowable workflow adapter with BPMN definitions that do not require administrator approval for registration or self-update actions. (GBHACKERS.COM)

ADVERSARIES

China

China-nexus hackers breached hospital X-rays, embassy and Honduran congress with new malware loader

A China-linked espionage operation compromised a Vietnamese public hospital’s X-ray and MRI imaging system, tunneled through Malaysia’s Ministry of Foreign Affairs network, and sent malware to Honduras’s National Congress — all using a custom Windows loader that none of the major endpoint security vendors had previously documented, according to Group-IB’s full technical breakdown published on July 23, 2026. Cybersecurity firm Group-IB stumbled onto the operation through an unusual stroke of luck: the hackers forgot to disable directory listings on their own command server. (TECHTIMES.COM)

Is China a peaked power? And so what if it is?

OPINION: Previous U.S. foreign, security, and defense policies toward the People’s Republic of China (PRC) and the Chinese Communist Party (CCP) have failed. Contrary to the decades-long hopes and expectations of Western policymakers, the PRC’s rapid economic development via quasi-capitalistic mechanisms did not foster internal democratic norms. While the “opening up” dictates of the post-Deng Xiaoping era brought spectacular economic growth, they failed to transform the CCP into a responsible stakeholder in the U.S.-led international community. Unrealistic expectations that the PRC would cooperate as a stable security partner in the Indo-Pacific never materialized; in fact, the opposite occurred. The CCP has emerged as a revisionist adversary, systematically challenging U.S. and allied security sector dominance not only in the Indo-Pacific but globally. (SMALLWARSJOURNAL.COM)

North Korea

Facing the North Korea-Russia alliance: EU-ROK strategies for deterrence and cooperation

OPINION: North Korea’s large-scale military support for Russia has transformed what began as a European war into a broader Eurasian security challenge, with direct implications for the Indo-Pacific and the Korean Peninsula. Pyongyang’s troop deployment and ammunition transfers to Russia mark a decisive shift from diplomatic alignment to direct military collaboration, creating the basis for a deeper Russia-North Korea security relationship. Although China, Russia and North Korea are not permanent ideological allies, their shared interest in weakening the US-led international order could sustain pragmatic and interest-based military cooperation. (REALINSTITUTOELCANO.ORG)

GOVERNMENT AND INDUSTRY

Data centers

As AI backlash grows, Trump says firms should pay more for electricity

More than 200 companies and politicians, including some of the country’s largest utilities, have signed a voluntary pledge to prevent AI data centers from driving up electricity costs for millions of Americans, President Trump said on Thursday. The pledge is largely symbolic, and experts have said it could be difficult to enforce because power prices are often determined by state regulators. But it underscored the extent to which rising energy bills have become a top concern for voters — and a potential liability for Republicans — ahead of the midterm elections. Trump first announced the initiative, which he called a “ratepayer protection pledge,” during his State of the Union speech in February. The following month, the White House secured promises from tech companies like Amazon, Google and Microsoft to pay a greater share of the enormous costs associated with delivering electricity to new data centers. (NYTIMES.COM)

Google meets the neighbors and gets both barrels over its new UK data center

Google invited residents living near its newly built datacenter north of London to meet the team at the local council offices on Wednesday evening – and was met with a barrage of complaints about poor consultation, noise, and light pollution. The Waltham Cross Datacenter (WXT), which was officially opened last year, sits on a 33-acre (133,546 m²) site north of the M25 motorway that encircles London. It is expected to provide up to 77 MW of IT capacity when full, but it is currently nowhere near this level, according to Google.(THEREGISTER.COM)

Defense

Pentagon willing to work with industry over critical mineral EO concerns

Amidst industry concerns that a new executive order on critical minerals has an unrealistic timeframe, a key Pentagon official is saying the department is prepared to work with companies — as long as they are making a good-faith effort to comply with the order. “What we need to do is commit to companies to say, ‘Look, how are you going to go ahead and resolve this problem through friendshoring, through domestic shoring, through changes in suppliers?” Michael Cadenazzi, the assistant secretary of defense for industrial base policy, told Breaking Defense Wednesday on the sidelines of the Farnborough Airshow. (BREAKINGDEFENSE.COM)

ONR launching ‘research by AI’ initiative as it looks to speed the delivery of cutting-edge tech to the fleet

The Office of Naval Research plans to lean more heavily into artificial intelligence as a tool that can help the office perform its work, according to the organization’s new science-and-technology strategy. “Strategy, and especially strategy in innovation organizations, requires placing informed bets — and sometimes big ones. Resource allocation is much of what we do. Therefore, ensuring that we are allocating our portfolios to the highest and best uses at any given time (and adjusting as new data emerges) is the core of what we must do well to accomplish our mission,” Chief of Naval Research Dr. Rachel Riley wrote in an introductory letter to the new S&T strategy that was released Wednesday. (DEFENSESCOOP.COM)

Energy

FERC eyes ‘grid-enhancing technology’ incentives: Chairman Swett

The Federal Energy Regulatory Commission has created a task force on “grid-enhancing technologies” to see how the agency can support them, possibly with incentives, FERC Chairman Laura Swett said Wednesday. Utilities have proactively started using GETs — which include dynamic line ratings, advanced power flow controllers and high-performance conductors — and their cost-saving data is now available, Swett told the U.S. Senate’s Energy and Natural Resources Committee during an oversight hearing. The Federal Power Act bars FERC from requiring utilities to use GETs, but the agency can direct transmission owners to analyze them, which can show what the most economic option is when considering new transmission infrastructure, according to Swett. (UTIILITYDIVE.COM)

Intelligence

Why Japan is creating its first modern spy agency since World War II

Chinese spies stealing trade secrets from Japanese companies. Japanese soldiers unknowingly using USB drives infected with Chinese malware. A cyberattack on Japan’s space agency by hacking groups linked to the Chinese military. For decades, Japan has struggled to crack down on other countries taking advantage of its weak intelligence apparatus, and to respond in kind. Now, in a major break from historical taboos linking intelligence-gathering to wartime activities, the Japanese government is looking to undertake systematic spying of its own, overhauling its intelligence capabilities for the first time since World War II, in a move current and former Western officials said their governments would welcome. (WASHINGTONPOST.COM)

U.S. intelligence agency quietly cut about 200 jobs since June 1

The Office of the Director of National Intelligence has shrunk more than is publicly known in recent weeks, losing about 200 personnel to firings and reassignments since June 1, according to data the Trump administration shared with Congress this week. The cuts are the latest to hit ODNI, which was created to oversee and coordinate all U.S. spy agencies but has been targeted by President Donald Trump and many Republicans in Congress. They, and some former U.S. intelligence officials, say it has expanded far beyond what lawmakers intended when it was created two decades ago. The ODNI had about 2,000 employees at the start of Trump’s second term. It is now little more than half that size, according to congressional aides. (WASHINGTONPOST.COM)

IT modernization

Technology Modernization Fund: Small savings achieved so far, but substantial future savings expected

The Technology Modernization Fund (TMF) invests funding in agency projects to, among other things, modernize aging federal information technology (IT) systems. From fiscal years 2018 through 2025, the TMF received over $1 billion in net appropriations, of which the Technology Modernization Board invested about $1.03 billion in 68 unclassified projects. As of June 2025 (the latest data available at the time of this analysis), 24 TMF projects expected to achieve total savings of about $1.06 billion. Eleven of these projects had collectively realized savings of about $13.5 million, and 13 had not yet begun to achieve savings. While savings thus far have been small, the amount is not unexpected given that 21 projects—with expected savings of about $1.04 billion, or 98.3 percent of the total—anticipate achieving their savings in fiscal year 2027 or later. Thirty-seven projects did not expect any cost savings, but are intended to provide other value, such as mitigating security risks. Seven other projects were cancelled prior to June 2025 and no longer expect savings. (GAO.GOV)

Regulations

EU hits Google with $1 billion fine over its Play app store and search

The European Union on Thursday hit Google with a fine of 890 million euros ($1 billion) after it said the technology behemoth broke digital antitrust regulations by setting up Google Play and its ubiquitous search engine to corral consumers towards its own services and apps to the detriment of competitors. It was the latest major crackdown on Big Tech by Brussels, which has led the world in reining in some of the world’s largest companies from Silicon Valley to Beijing. It has done so despite the risk of incurring the wrath of President Donald Trump, who has lashed out at the 27-nation bloc’s digital regulations amid a broader campaign against Europe: imposing high tariffs, making threats to seize Greenland from Denmark by force, and rattling trust within the NATO military alliance. (APNEWS.COM)

Space

Begun the new Star Wars: How the U.S. must capture AI-cyber and space warfare

OPINION: The Empire has struck first. While Washington debates budgets and scandals, the People’s Republic of China, a revanchist Russia, and their North Korean ally have launched a new arms race in the ultimate high ground: space fused with artificial intelligence and cyber dominance. This is not science fiction. It is the strategic reality of the 21st century. What Ronald Reagan understood with the Strategic Defense Initiative — that control of space and advanced technology decides the fate of free nations — must now be reborn at exponential speed. The new Star Wars has begun. America must win it decisively, or we will lose the Republic. (REALCLEARDEFENSE.COM)

Vulnerabilities

After Hugging Face breach, FedRAMP chief tells slow-to-patch vendors to stay out of government

Technology companies that cannot quickly fix dangerous vulnerabilities should not be allowed to sell their products to federal agencies, the head of the government’s bedrock cloud security program said Thursday. Pete Waterman, director of the General Services Administration’s Federal Risk and Authorization Management Program, known as FedRAMP, delivered the blunt warning while discussing resistance from companies that say they lack the resources to address a known, exploitable vulnerability exposed to the internet within a matter of days. (NEXTGOV.COM)

GitHub slashes public bug bounty payouts as AI report flood buries its security team

GitHub has decided that, if everyone with an AI chatbot can file a bug bounty report, it may as well stop paying them like seasoned security researchers. Starting July 27, the Microsoft-owned code forge is overhauling its bug bounty program with a two-tier system that cuts rewards for public submissions while dangling much fatter payouts to a new invite-only group of researchers with proven track records. At the same time, newcomers will find themselves capped on how many reports they can submit until they’ve demonstrated they can produce something worth reading. (THEREGISTER.COM)

LEGISLATIVE UPDATES

The Pentagon wants to build data centers. Congress would like a word

The Department of Defense’s leasing of land to private companies for artificial intelligence server farms is drawing bipartisan scrutiny from lawmakers worried about the impact on military installations and surrounding communities. The Pentagon is building data centers to supercharge its war tactics with drone swarms and other technologies powered by AI. Members of Congress — including a senior Republican appropriator — are trying to check that effort before it accelerates any further. “As we enter the period of AI, which requires very serious data centers, data facilities, that are extraordinary consumers of both energy and water, the question arises as to whether they should be on military bases,” Rep. John Garamendi (D-Calif.) said last month after proposing a sweeping amendment to the House’s version of the fiscal 2027 National Defense Authorization Act. (EENEWS.NET)

GOP Financial Services report cites AI as both fraud accelerator and preventer

Top Republicans on the House Financial Services Committee released a staff report on Wednesday outlining policy approaches for combating financial fraud and scams, with the document citing artificial intelligence as a key driver of financial fraud and also an important tool for countering more sophisticated criminal schemes. The report was compiled following a year-long investigation conducted by the panel, which included holding a series of fraud-focused hearings. The final document appears to have been released without any input from the committee’s Democrats. (NEXTGOV.COM)

Ratepayer bill gains momentum in House amid data center backlash

A bill that seeks to mitigate data centers’ impacts on Americans’ electric bills is gaining steam in the House, as lawmakers face pressure to act in the face of sharp backlash to the sprawling AI infrastructure. The bipartisan Ratepayer Protection Act would require states to “consider” standards that put the costs on tech companies, rather than individuals. Its supporters say it could help alleviate potential price spikes caused by power-hungry data centers, but critics say it doesn’t go far enough to solve the problem. (THEHILL.COM)

COMMITTEE ACTIVITY

AI WORKFORCE: The House Education and Workforce Committee will hold a July 24 field hearing at Augusta University on how AI is creating opportunities across America’s workforce.

ALERTS AND ADVISORIES

CISA, NSA, FBI and partners warn Zimbra collaboration suite users of ongoing Russian state-supported malicious threat activity

Known primarily as LAUNDRY BEAR, the Russian advanced persistent threat (APT) group’s ongoing covert efforts appear focused on targeting Western government and commercial organizations to gather email data possibly for espionage. The advisory shares mitigations, indicators of compromise, and remediation to harden networks that use ZCS webmail against this ongoing threat activity. Unlike traditional phishing that attempts to persuade a user to take an action, such as clicking a link or downloading a file, LAUNDRY BEAR’s current campaign uses a zero-click exploit that only requires a user to view a malicious email within a vulnerable version of the ZCS webmail service. This campaign uses a custom-developed aggregation and data exfiltration capability called Ulej to exploit a common vulnerabilities and exposures (CVE) in ZCS, CVE-2025-66376, with the potential for adaption to exploit other vulnerabilities as well. This advisory provides several mitigations to protect against this activity and specific remediation actions for organizations that detect indicators of compromise in their environment. (CISA.GOV)

Events

TO BE INCLUDED IN THIS CALENDAR, SUBMIT YOUR SECURITY-FOCUSED EVENT FOR CONSIDERATION

6G: Join CSIS, senior U.S. government officials and leading global partners for a July 29 public forum examining the geopolitical and security landscape of next-generation wireless infrastructure. This event will feature the launch of the “Call to Action for 6G Leadership and Security,” a joint initiative between the United States (coordinated by the National Telecommunications and Information Administration) and partner nations designed to strengthen digital supply chains, accelerate innovation, and expand multilateral cooperation on wireless technology. 

ENERGY CRISIS: The CSIS Energy Security and Climate Change Program is pleased to host Jérôme Bilodeau, Head of Analysis (Energy Efficiency and Inclusive Transitions), International Energy Agency (IEA), for an Aug. 4 discussion on the global energy implications of the Strait of Hormuz crisis and how governments have responded to disruptions in energy markets. Bilodeau will present key findings from IEA analysis of the crisis, highlighting its effects across major regions and the policy measures adopted to mitigate supply shortages. He will also provide an overview of the policy tracker tool his team has developed, demonstrating how it captures and compares government responses to evolving energy market conditions.

AI HEALTH CARE: The AI in Health Conference from Sept. 15 to Sept. 17 bridges the gap between artificial intelligence and real-world health outcomes — focusing not just on what AI can do, but on what it should do to improve patient care. Hosted by the Ken Kennedy Institute at Rice University, the fifth annual AI in Health Conference will explore the current landscape of artificial intelligence in health and present a research-driven outlook for the future of computational health innovation. The program is designed to connect researchers and innovators with engineers, clinicians, and entrepreneurs at the forefront of AI in healthcare and public health.

BIOTECH: Synthetic biology is an interdisciplinary field combining biological and engineering to designing and redesigning genes, biological pathways, or organisms to solve society’s major problems and understand biological principles. Rapid advancements in synthetic biology are reshaping how we approach challenges in health, the environment, and beyond. However, these breakthroughs raise questions about what should be permitted and how new technologies should be regulated. To that end, the global conversation on biotechnology must account for responsible frameworks that guide future scientific innovation. This Sept. 18 Baker Institute symposium convenes a diverse community of scholars and practitioners in academia, industry, nonprofits and government for a deep dive into the intersection of emerging biotechnologies, public policy, and ethical responsibility.


FOLLOW THE McCRARY INSTITUTE ON LINKEDIN | X | BLUESKY

SUBSCRIBE TO THE CYBER FOCUS PODCAST: YOUTUBE | SPOTIFY | APPLE PODCASTS

SUBMIT A TIP

Click to listen highlighted text!