Cyber Briefing – July 28, 2026
TODAY’S TOP 5
TECH LEADERS WARNS AGAINST OPEN-WEIGHT AI CRACKDOWN: Silicon Valley leaders from Anthropic PBC’s Dario Amodei to Nvidia Corp.’s Jensen Huang warned against a U.S. crackdown on open-weight artificial intelligence systems, deepening a debate about how Washington should respond to a surprise breakthrough from Chinese startup Moonshot, Bloomberg reports. In a blog post released Monday, Amodei sought to dispel claims that Anthropic supports a ban on open-weight models, which allow users to download and customize the technology. At the same time, he called for the U.S. to adopt policy interventions to slow China’s AI development and said that all models — both open and closed — should go through mandatory safety testing before release.
- Chinese AI startup Moonshot AI, creators of the increasingly famous “Kimi K” family of powerful, open AI models, on Monday released the full weights for its largest and most performant version yet — Kimi K3. But enterprises evaluating the model should read the attached custom Kimi K3 usage license as carefully as the benchmark charts, Venture Beat reports.
- The National Institute of Standards and Technology launched a new program on Monday granting researchers access to an isolated testbed environment to safely evaluate artificial intelligence models against various commands, Nextgov/FCW reports. The AI Technology Evaluation, or AITE, is a voluntary testing vehicle focused on AI model safety analysis. It provides blind data for models to process when completing tasks to gain objective insights and conduct evaluations of model capabilities. Notably, the evaluation data is not intended to serve as training data for the models.
- Anthropic and the U.S. Department of Defense are set to face off Thursday in San Francisco federal court before a judge who already called the Pentagon’s effort to ban the artificial intelligence firm’s models almost certainly retaliatory and “Orwellian,” Gov Info Security reports. Each side has asked District Court for the District of Northern California Judge Rita F. Lin to end Anthropic’s lawsuit in their favor and either permanently undo the department’s blacklisting of the firm.
AFTER THE ROGUE OPENAI HACK: The boss of the startup hacked by an OpenAI agent has called for the investigation into the incident to show “radical transparency,” The Guardian reports. Clément Delangue, the chief executive of Hugging Face, said the “unprecedented” attack on his business required a similar response. Writing on X after OpenAI revealed that its technology had gone rogue during a cybersecurity test, Delangue also called on the company to provide $100m (£75m) worth of computing power to help build defences against such attacks. “The first autonomous agent cyber-attack is an unprecedented event. It deserves an unprecedented response!” he wrote.
- OpenAI CEO Sam Altman will meet with senior Trump administration officials, lawmakers and economists in Washington, D.C., this week to preview the capabilities of the company’s upcoming family of artificial intelligence models, CNBC reports. Altman has maintained a regular presence on Capitol Hill this year as he’s tried to alleviate policymakers’ concerns about the rapidly advancing technology and help shape their views about what regulation should look like.
- OpenAI sent shock waves across Silicon Valley last week when it revealed that two of its artificial intelligence technologies had gone rogue and hacked into a popular internet library. The incident showed the unpredictable power of new AI systems and the growing importance of technology that can be used against AI attacks. On Monday, Microsoft added to the widening assortment of AI security tools with the release of systems designed to help businesses protect their computer networks, The New York Times reports.
WATCH: McCrary Institute Director Frank Cilluffo is a guest on Ahead of the Threat: The FBI Cyber Podcast with host FBI Assistant Director Brett Leatherman.
STAFFING STRAINS IMPACT UNDERSEA SURVEILLANCE: The Pentagon’s Office of Inspector General urged the U.S. Navy to establish a more permanent workforce with specialized skillsets to meet serious current and emerging demands associated with a vital underwater network that combines seabed technologies with data-processing assets to monitor and classify submarines. According to a heavily redacted IG report, which was distributed internally in January and recently obtained by DefenseScoop through the Freedom of Information Act (FOIA) process, a fragile talent pipeline and unstable staffing for the Integrated Undersea Surveillance System (IUSS) has proven to be a perpetual challenge for the service. “The IUSS does not have a sustainable workforce with sufficient expertise to effectively accomplish existing and future mission requirements,” officials wrote in the watchdog review. “The decline in IUSS enlisted acoustic analysts’ skills is attributed to the Navy not prioritizing repeat IUSS tours.”
- The Oregon Department of State Lands is proposing for the first time to charge multinational telecommunications and tech companies for using the seafloor off the state’s Pacific Coast for fiber-optic cables used to transmit internet data and international calls, Oregon Capital Chronicle reports. Since 1989, when Oregon got its first trans-Pacific fiber optic cable spanning from Pacific City to Alaska to Japan, the state lands department has only mandated companies pay an application fee that, since 2001, has been frozen at $5,000. Now, Oregon could join its West Coast neighbors in California and Washington in requiring companies also pay compensation fees based in part on the amount of cable extending along the states’ near-coast seabed.
DATA CENTER REGISTRY WITH TEETH?: The nation’s largest grid operator plans to create a registry of data centers and other large energy users whose electricity may be curtailed during a power shortage, E&E News reports. PJM Interconnection announced the move Monday, along with plans for an extra capacity auction in September. The Reliability Backstop Procurement, as that auction is called, aims to cover the system’s peak demand after PJM’s most recent capacity auction fell about 60 gigawatts short. The pair of decisions comes at a moment of existential crisis for PJM, which manages a power grid serving 13 states in the mid-Atlantic and Midwest. The grid operator faces bipartisan pressure from states as well as the Federal Energy Regulatory Commission to prove that it can manage unprecedented load growth across a sprawling region.
- Power sources providing electricity only to data centers and not the public grid may not be subject to federal pollution laws, the U.S. Environmental Protection Agency said on Monday, Reuters reports. The EPA said if the power plants are not supplying electricity to the grid then they would not be subject to the federal Clean Air Act’s Acid Rain Program, which has been key to the dramatic reduction of smog and soot pollution from industrial facilities. “The EPA believes that, considering the plain text of these definitions, the Acid Rain Program does not apply to power generation facilities that are not connected in any way to the larger electricity grid,” EPA Assistant Administrator Aaron Szabo wrote in a July 16 letter.
- The Justice Department’s bid to nix a Clean Air Act suit against xAI’s turbines shows how security claims reshape energy permitting, James W. Coleman writes at Lawfare.
- Satellite imagery shows damage to two Amazon.com Inc. data centers in Bahrain, supporting Iran’s claims last week that it struck the sites with missiles, Bloomberg reports. The Islamic Revolutionary Guard Corps, through state-backed news agency Tasnim, released high-resolution satellite images showing significant damage to two data centers in the towns of Zallaq and Askar, alleging that they were targeted because of Amazon’s support for U.S. military operations. Independent, lower-resolution images from the European Space Agency’s Sentinel-2 satellite constellation reviewed by Bloomberg News show damage at both facilities.
MINNESOTA WATER SECTOR HIT BY ATTACKS: At least three Minnesota cities reported cyberattacks Monday that have impacted water facilities and prompted a response from state authorities, FOX 9 reports. Officials in Plymouth, South St. Paul and Braham announced they were dealing with cyberattacks at their respective water facilities. In Plymouth, the attacks, which started Sunday overnight, targeted their water towers and lift stations. In South St. Paul, its water utility system was hit. In Braham, the city’s water plant was knocked offline for a brief period. In a news release, Plymouth city officials said the issue seemed to be impacting a number of other cities. ges.
| OSINT YOU NEED TO START YOUR DAY: The Cyber Briefing is brought to you by the McCrary Institute for Cyber and Critical Infrastructure Security at Auburn University. SUBSCRIBE |
| WE WANT TO HEAR FROM YOU: What would you like to see in your morning briefing? Reach out to Executive Editor Bridget Johnson with your comments and suggestions |
CYBER FOCUS PODCAST
(Watch on YouTube or click the player above)
Drones are a serious operational concern for critical infrastructure owners and operators. In this episode of Cyber Focus, Frank Cilluffo sits down with L. Scott Parker, founder of Aerisq and former chief of UAS security at CISA, to discuss how drone capabilities have changed the risk picture for airports, utilities, chemical facilities, pipelines, prisons and other sensitive sites. The conversation examines the FAA’s Section 2209 rulemaking (open for public comment through Aug. 5), along with the limits of flight restrictions and the growing need for “Air Domain Awareness” alongside cyber and physical security. Parker also explains why counter-UAS strategy must balance technology, legal authority, proportional response and the practical realities of defending infrastructure at scale.
SUBSCRIBE TO CYBER FOCUS: YouTube | Spotify | Apple Podcasts
CYBER AND CI UPDATES
ATTACKS AND INCIDENTS
Cybercrime
FBI: Breaking affiliate trust sped along LockBit’s takedown
Undermining affiliates’ trust and strong international partnerships were the keys to dismantling LockBit, one the most successful ransomware-as-a-service (RaaS) groups of its time, which at its peak was responsible for a quarter of all ransomware attacks. LockBit operated primarily between 2020 and 2024, and Brett Leatherman, assistant director of the FBI’s Cyber Division, tells Dark Reading that during its time it victimized more than 2,500 organizations across at least 120 countries, with more than 1,800 of these attacks occurring in the US. Overall, the group collected more than $500 million in ransom payments, and the group and its leader, a Russian national named Dmitry Yuryevich Khoroshev, seemed invincible. (DARKREADING.COM)
Drones
Aussie UAS supplier warns of cyberattack
A maker of unmanned guidance hardware supplied to Ukraine says some systems have been taken offline, and the incident is under investigation. Australia-based CubePilot, which supplies hardware and embedded software for the civilian unmanned systems industry, has warned its customers that some of its systems are offline while it investigates a security incident. “We are currently investigating a security incident affecting certain CubePilot systems,” the company’s CEO, Philip Rowse, shared in a post to LinkedIn. (AUSTRALIANAVIATION.COM.AU)
Phishing
Telegram phishing campaign targeted exiled Belarusian activist, Russians and Kazakhstanis
Researchers have uncovered a highly personalized phishing campaign that used Telegram to try to hijack the account of an exiled Belarusian activist, as well as users in Russia and Kazakhstan. Two reports released last week by digital security organization Resident NGO document how the operation targeted at least one Belarusian activist living in Lithuania and appears to be part of a broader Telegram phishing campaign against users in Belarus, Russia, and Kazakhstan since at least October 2024. The attack began with a fake Telegram security alert sent through the app’s end-to-end encrypted secret chat feature from an unfamiliar account registered to a Kazakhstani phone number. The message falsely claimed the victim had violated Telegram’s rules and warned their account would be blocked unless they clicked a link to verify it. (THERECORD.MEDIA)
WATCH: White House National Cyber Director Sean Cairncross, CISA Acting Director Nick Andersen and more top leaders at the recent McCrary Cyber Summit
THREATS
Artificial intelligence
Uh-oh: Some Claude shared conversations and Artifacts appear to be indexed and publicly accessible on Google Search
Over the weekend, Reddit user -void1 posted an alarming discovery on the r/ClaudeAI subreddit: some conversations that users of Anthropic’s Claude AI chatbot had made “shareable” via a link were being indexed by Google Search, and could be clicked on and accessed by seemingly anyone. The conversation took off on the social networks X and Reddit, the latter with thousands of upvotes and comments, many expressing concern about user privacy and information security, and the additional finding by users that shared Claude Artifacts — including interactive applications, dashboards, documents and other AI-generated work products — were also appearing in Google Search results. (VENTUREBEAT.COM)
Botnets
New Dysphoria DDoS botnet spreads to 200k devices worldwide
A botnet called Dysphoria has compromised around 200,000 devices across the world and is using them for distributed denial of service (DDoS) attacks and traffic relay operations. According to QiAnXin XLab cybersecurity researchers, Dysphoria evolved from the ‘jackskid’ and ‘fbot’ malware by adding a covert blockchain-based command-and-control (C2) resolution mechanism. Specifically, the botnet uses Ethereum ENS and Solana SNS domains to retrieve infrastructure information, while C2 addresses are concealed inside fake IPv6 strings and recovered using a custom byte-transformation algorithm. (BLEEPINGCOMPUTER.COM)
Tengu Mirai botnet uses watchdog reboots and binary bricking to resist removal
Tengu, a newly observed Mirai-derived botnet, is demonstrating how modern IoT malware is rapidly evolving beyond traditional distributed denial-of-service (DDoS) operations by integrating persistence, evasion, and multi-functional attack capabilities. Unlike legacy Mirai variants, Tengu employs a hybrid C2 model that blends plaintext and encrypted communications. Initial registration and heartbeat messages are transmitted in cleartext, while command execution and updates are protected using an AEAD scheme resembling ChaCha20-Poly1305. (GBHACKERS.COM)
Critical infrastructure
Hackers target U.S. firms in FastJson RCE zero-day attacks
Hackers are actively exploiting a vulnerability in the FastJson open-source Java library, allowing remote code execution without user interaction or elevated privileges. The security issue affects FastJson versions 1.2.68 through 1.2.83 and is leveraged in attacks targeting various organizations in the U.S. The malicious activity was observed last week by the agentic security company ThreatBook, and researchers at the business protection company Imperva confirmed that it was “targeting a wide range of organizations, across Financial Services, Healthcare, Computing, Retail, Business, and other industries.” (BLEEPINGCOMPUTER.COM)
Malware
MedusaHVNC malware uses hidden Windows desktops to evade detection
MedusaHVNC is a remote access trojan (RAT) being sold as malware-as-a-service (MaaS). It is promoted through its own website and a Telegram channel. It was found and analyzed by BlackFog, with the analysis finding a hidden virtual network computing (HVNC) module that opens a legitimate browser on a separate hidden Windows desktop, Since it operates from a hidden desktop, its operation is invisible to the user. The malware uses a 5-stage infection chain. It starts when the legitimate wscript.exe executes a JScript launcher. The script waits for just over 7.5 seconds and then builds its embedded files under %TEMP%\Nx2981Okkr2\. (SECURITYWEEK.COM)
Tactics
Hackers pose as IT helpdesk on Microsoft Teams to deploy GoGRPC backdoor
There is an evolving intrusion campaign in which threat actors impersonate IT helpdesk personnel via Microsoft Teams to gain initial access and deploy a custom Go-based backdoor dubbed “GoGRPC.” Active since January 2026, the activity is assessed to be linked to an initial access broker (IAB) operation that likely facilitates downstream ransomware attacks. It aligns with tactics observed in campaigns such as Payouts King and Microsoft-documented cross-tenant helpdesk impersonation intrusions. (GBHACKERS.COM)
Vulnerabilities
Microsoft fixes Certighost flaw that allowed domain controller impersonation
Microsoft has patched a high-severity vulnerability in Active Directory Certificate Services that allowed a user with basic domain access to obtain a valid certificate identifying them as a Domain Controller. Tracked as CVE-2026-54121 and named Certighost, the flaw received a CVSS score of 8.8. Researchers H0j3n and Aniq Fakhrul reported it to Microsoft in May 2026, and the company released a fix on July 14, 2026. Full technical details and a working proof of concept followed ten days later. Active Directory Certificate Services, commonly called AD CS, issues certificates that act as trusted digital identities inside company networks. Computers and users can present these certificates when requesting access to services, including Kerberos authentication. (HACKREAD.COM)
Critical TeamCity flaw could let attackers run OS commands without logging in
JetBrains is urging customers of on-premise versions of TeamCity to update to the latest version following the discovery of a critical security issue that could result in arbitrary code execution. The vulnerability, assigned CVE-2026-63077 (CVSS score: 9.8), affects all TeamCity On-Premises versions. It has been addressed in versions 2025.11.7 and 2026.1.3. TeamCity Cloud instances have already been updated. JetBrains has credited Antoni Tremblay with discovering and reporting the flaw on July 10. “If exploited, this flaw may enable an unauthenticated attacker with HTTP(S) access to a TeamCity server to bypass authentication checks and execute arbitrary operating system commands with the privileges of the TeamCity server process,” JetBrains said. (THEHACKERNEWS.COM)
‘Confused deputy’ flaws persist in Google Cloud, Microsoft Azure
Significant cracks in the managed identity trust chains of the world’s biggest cloud platforms could put enterprise and government resources at risk. That’s according to Justin O’Leary, independent security researcher, who discovered two “confused deputy” vulnerabilities in both Microsoft Azure and the Google Cloud Platform (GCP) earlier this year. Despite reporting them to the cloud giants, neither company acknowledged the vulnerabilities or paid a bug-bounty reward, even though Microsoft appears to have silently patched its flaw. Confused deputy issues arise when a product or service receives a request from an upstream entity but fails to preserve the original source of request and even allows it to be forwarded to external parties. (DARKREADING.COM)
Critical Arista VeloCloud Orchestrator vulnerability exploited as zero-day
Arista Networks on Monday released patches for a critical-severity OS injection vulnerability in the VeloCloud Orchestrator (VCO) centralized management platform, warning that it has been exploited in the wild as a zero-day. The security defect is tracked as CVE-2026-16812, has a maximum CVSS score of 10, and could be exploited remotely to access privileged functionality intended for internal use only. “Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator,” Arista Networks notes in its advisory. (SECURITYWEEK.COM)
Public exploit released for patched vBulletin pre-auth code execution flaw
Public exploit details released on July 27 show how an unauthenticated request can reach PHP’s eval() function inside vBulletin and execute code on an unpatched forum server. The attack requires no account, administrative access, or interaction from another user. SSD Secure Disclosure lists vBulletin 6.2.1 and earlier, and 6.1.6 and earlier, as affected, but does not give a lower version boundary. vBulletin issued security patches for 6.2.1, 6.2.0, and 6.1.6 at the end of June and released the fixed version 6.2.2 on July 1, nearly four weeks before the exploit went public. (THEHACKERNEWS.COM)
LegacyHive exploit abuses Windows profile loading to hijack user registry hives
LegacyHive is a newly discovered proof-of-concept (PoC) for Windows that exploits profile initialization and offline registry hive manipulation to redirect user-level registry paths, potentially allowing access to resources associated with another account. This technique was published by the Nightmare-Eclipse disclosure actor shortly after Microsoft’s July 2026 Patch Tuesday. Unlike traditional software vulnerabilities, LegacyHive chains legitimate Windows features in an unusual manner. Researchers from LevelBlue SpiderLabs successfully reproduced the PoC on fully updated Windows systems, demonstrating that the exploit remains viable even after current updates. (GBHACKERS.COM)
n8n sandbox escape lets workflow editors run OS commands as the n8n process
n8n has patched a high-severity expression-sandbox escape that could let an authenticated workflow editor execute operating-system commands on the server running the automation platform. Security Joes found the flaw while probing n8n’s February fix for CVE-2026-27577 for another bypass. The affected ranges are <2.31.5 and >=2.32.0,<2.32.1. n8n fixed the flaw in versions 2.31.5 and 2.32.1. It tracks the issue as GHSA-gv7g-jm28-cr3m, rates it High with a CVSS 4.0 score of 8.7, and no CVE had been assigned as of July 27. Administrators should update rather than rely on n8n’s interim guidance to restrict instance access and workflow editing to fully trusted users. The advisory describes those controls as incomplete, short-term mitigations. It lists no patched 1.x release and does not say whether n8n Cloud was affected. (THEHACKERNEWS.COM)

ADVERSARIES
China
Nvidia staff detained by Taiwan in China chip smuggling case
On Tuesday, Taiwan’s Keelung Prosecutors Office said investigators searched the residence and office of a man surnamed Chang last week in connection with a chip smuggling investigation that they first announced in May. Chang has been detained, prosecutors said, without naming the person in full or identifying his company affiliations. They haven’t accused Nvidia or any other company of wrongdoing. The move may be the first known instance of government authorities taking legal action against an employee of Nvidia in a chip smuggling case. The Taiwan effort is one of at least eight semiconductor diversion probes across four jurisdictions, as officials from Washington to Singapore crack down on a shadow trade that Nvidia Chief Executive Officer Jensen Huang once denied exists. (BLOOMBERG.COM)
Researchers link Chinese cyber vendor to PLA’s RedRelay covert attack network
Researchers have linked Guangdong Chanming Technology Co., Ltd., a little-known Chinese cybersecurity vendor, to RedRelay, a covert relay network allegedly used by China-linked threat actors. The findings connect company records, software artifacts, patent filings, and PLA procurement documents to a wider cyber-espionage ecosystem. Guangdong Chanming maintains almost no visible public presence. The company has no obvious marketing site, public product catalog, or consumer-facing security portfolio. (CYBERPRESS.ORG)
Russia
What the latest U.S. sanctions bill means for Russia — and for China, India and Iran
OPINION: Championed by late US Senator Lindsey Graham, the bipartisan Sanctioning Russia Act is gaining new momentum in Congress, where more than sixty U.S. senators have cosponsored a newly revised version. The legislation aims to reduce the Kremlin’s oil revenues by placing tougher sanctions on Russia’s energy and financial sectors. It also imposes additional sanctions on Russian President Vladimir Putin and other senior Russian officials. But if passed, it would also affect several major countries that currently trade with Russia, and those effects should be factored into U.S. planning. (ATLANTICCOUNCIL.ORG)

GOVERNMENT AND INDUSTRY
Artificial intelligence
Secret Service wants more AI robots for target practice
The Secret Service is planning to spend up to $20 million on AI robots for target practice as part of a contract it expects to award in the fourth quarter of fiscal 2026, per recently published acquisition planning documents. The Department of Homeland Security unit wants to add one autonomous robotic system that will include eight all-terrain infantry targets, one vehicle target and four other infantry targets. The Secret Service will require its robotic training squad to wear ballistic protection for various ammunition calibers. The agency has been building up its autonomous training tools with Marathon Targets, starting back in 2023. (FEDSCOOP.COM)
Police AI platform uses ‘Easter eggs’ to verify human review
As artificial intelligence-powered tools become increasingly common across law enforcement, experts have warned that they need built-in safeguards to ensure that AI-generated content is reviewed by a human before it’s used in the criminal justice process. One AI company, Code Four, has taken an unusual approach: inserting hidden “Easter eggs” into AI-generated draft documents to confirm officers have actually read them. Code Four was co-founded by George Cheng and Dylan Nguyen, who both dropped out of the Massachusetts Institute of Technology to run the company last year. With seed funding secured through the startup accelerator Y Combinator — and ongoing support through a startup fellowship program run by the software company Palantir Technologies — the pair have added more capabilities, and their company counts nearly 140 law enforcement agencies as customers. (STATESCOOP.COM)
Two-thirds of workers are so fed up with ‘AI slop’ that they ‘feel nostalgic for pre-AI work’
Knowledge workers are secretly yearning for the days before AI entered the mix, with three-in-ten saying they preferred work before adoption of the technology. In a survey of office workers by digital transformation firm Adaptavist, 65% said they preferred the pre-AI era and 38% would remove generative AI tools from the world entirely if they had the chance. Younger workers in particular are among those most frustrated by AI, with 40% of Gen Z and Millennials saying they would scrap generative AI tools, compared with 32% of Gen X and 29% of Boomers. (ITPRO.COM)
Defense
Western power race to bring the production of explosives back home
The business of explosives is booming as Western governments unleash spending to bring production home. At least 24 new projects are under way for propellants or explosives across NATO countries, according to information assembled by The Wall Street Journal. Three new factories are set for just Arkansas, a center of U.S. weapons production. Russia’s invasion of Ukraine four years ago exposed the West’s struggle to churn out ammunition. Although artillery-shell output has increased, producers still rely on constricted supplies of dangerous chemicals manufactured in a globe-spanning supply chain with lots of chokepoints. (WSJ.COM)
French wildfires threaten nuclear deterrence industry, Rafale assembly
Wildfires raging west of the French city of Bordeaux are threatening a number of France’s key defense-industrial sites, including an ArianeGroup facility that produces propulsion components for the M51 submarine-launched ballistic missile, Dassault Aviation’s final assembly line for the Rafale fighter jet, and one of Roxel’s main manufacturing sites for solid rocket motors used in MBDA missiles. Dassault Aviation said it was moving sensitive equipment from a site closest to the wildfires to one nearer Bordeaux, with most workers staying home in line with instructions issued by the authorities. ArianeGroup had evacuated its affected sites, while the French Atomic Energy Commission CEA closed its military nuclear research site near Bordeaux as the wildfires approached. (DEFENSENEWS.COM)
Pentagon’s special ops office hosts first Shark Tank-style Accelerator Event
Select members of industry gathered on Friday in a scenic conference venue overlooking the Potomac River and the Washington skyline to pitch capabilities in a Shark Tank-type exercise to solve some of the toughest problems for the special operations world. The first-ever Accelerator Event, sponsored by the office of the Assistant Secretary of Defense for Special Operations and Low-Intensity Conflict (SO/LIC), billed itself as “a different kind of industry day,” according to SO/LIC Assistant Secretary Derrick Anderson. “It’s the direct manifestation of acquisition reform and our priority of pioneering for SOF and serving as a pathfinder for the department,” Anderson said in opening remarks to attendees. “Advances in technology reinforce the simple, hard truth: The time for action is now. We cannot afford to wait. We cannot afford to let legacy bureaucratic acquisition process dictate our readiness.” (BREAKINGDEFENSE.COM)
Drones
Navy’s GARC kamikaze drone boat blew a hole in ex-USS Peleliu during sinking exercise
Just weeks after the U.S. military publicly acknowledged using kamikaze drone boats in combat for the first time, the Navy has confirmed that its Global Autonomous Reconnaissance Craft (GARC) uncrewed surface vessel (USV) took part in its first live-fire training exercise. The kamikaze drone boat was employed during RIMPAC 2026, attacking the ex-USS Peleliu in one of the operation’s high-profile sinking exercises (SINKEX). On July 24, the Navy released a video showing USVs taking part in the SINKEX in the Pacific Ocean, which targeted the decommissioned Tarawa class amphibious assault ship, but it was hard to tell what the USV in question was. The event itself had taken place on July 17 and saw the former USS Peleliu pummeled by multiple U.S. and allied assets. The video shows significant damage already inflicted on the assault ship, especially around the waterline, and water already being taken onboard. The footage was captured by the second drone boat, as it inspected the damage done by all the fires. (TWZ.COM)
After Valiant Shield exercise, PACAF commander says he’s ‘impressed’ with Australia’s Ghost Bat drone program
On the heels of a large multinational exercise, the commander of U.S. Pacific Air Forces said he’s “impressed” with the Royal Australian Air Force’s collaborative combat aircraft program. A production representative MQ-28 Ghost Bat drone, built by Boeing, was integrated into the recently concluded Valiant Shield 26 event in the Pacific, which was led by the United States and included participation from Australia, Canada, Japan and New Zealand. “For the first time in a major international exercise, the Boeing Defence Australia MQ-28A Ghost Bat demonstrated how collaborative combat aircraft can integrate, enhance and complement other platforms,” officials wrote in an Australian Defence Department press release. (DEFENSESCOOP.COM)
Emergency services
NOAA will shift critical weather forecasting services to public cloud in modernization push
The National Oceanic and Atmospheric Administration (NOAA) has announced plans to modernize critical weather prediction capabilities as part of a deal with Google Cloud. Under the terms of the deal, Google Cloud will serve as the primary high-performance computing (HPC) infrastructure provider for NOAA’s Weather and Climate Operational Supercomputing System (WCOSS). This will see WCOSS move from traditional, on-premises hosting to a fully public cloud approach. The scientific agency said this will deliver a weather modelling system that is “more flexible and easy to update.” (ITPRO.COM)
Gray zone
Cognitive warfare below the threshold: AI, decision speed and the future of competition
OPINION: The cognitive warfare lessons from Iran and Ukraine are typically framed around high-intensity conventional conflict: AI-enabled targeting at scale, decision-loop compression in contested fires environments, human-machine authority in autonomous engagement. These are the right problems to study. They are not the only problems the cognitive warfare framework illuminates. (SMALLWARSJOURNAL.COM)
Leadership
Power grid guru Peter Lake to leave Trump’s Energy Dominance Council
Peter Lake, a key architect of President Donald Trump’s effort to to grow electricity production for artificial intelligence, is leaving his position at the White House’s National Energy Dominance Council at the end of this month. Lake, a former chair of the Public Utility Commission of Texas, served as senior director of power for the NEDC, where he helped drive the White House proposals designed to enable data centers to quickly connect to the power grid while establishing measures to help protect ratepayers from additional costs. (POLITICO.COM)
Clayton on verge of confirmation as intel chief
Jay Clayton is on the verge of becoming President Donald Trump’s next director of national intelligence — though Democrats won’t be helping him get there. The Senate on Monday voted 51-43 in a party line vote to move forward with Clayton’s nomination, teeing up a final vote as soon as Tuesday to confirm him as the next head of the Office of the Director of National Intelligence. No Democrats joined their GOP counterparts in support of Clayton. (POLITICO.COM)
Colorado names first principal director of AI architecture
Jane Yang has been named the Colorado Governor’s Office of Information Technology (OIT)’s first-ever principal director of AI architecture, bringing her public- and private-sector technology experience to the new position. Colorado’s IT office has recently undergone changes amid a significant restructuring as the state shifts to a product-oriented delivery model. Among the changes, David Edinger stepped down as CIO in June, handing the reins to Sarah Tuneberg. Tuneberg was most recently deputy executive director for digital and delivery, and before that she led the Colorado Digital Service. (GOVTECH.COM)
Nuclear
Leaked document reveals White House nuclear waste plan
The White House is pushing Congress to break a decades-long impasse around the handling of nuclear waste and entice states to get on board, according to a document obtained by POLITICO. The Trump administration is seeking changes to federal law to allow the Department of Energy to partner with states willing to store waste generated at the nation’s nuclear reactors, according to the document laying out “legislative principles.” It has been circulating on Capitol Hill and among nuclear industry leaders. When asked about the document, a White House official said Monday that the administration “is always looking for ways to advance our civil nuclear energy sector.” (POLITICO.COM)
Quantum
Enterprises aren’t moving fast enough on post-quantum cryptography preparations
Organizations could face a ticking quantum time-bomb, according to new research from DigiCert, with the vast majority aware that they aren’t properly prepared. An overwhelming 85% of IT and security leaders believe that quantum computing advances will break existing security standards within a decade, yet only 7% have deployed quantum-safe certificates so far. A key worry among survey respondents lies in the risk of ‘harvest now, decrypt later’ (HDNL) attacks. This refers to a method whereby threat actors steal and save encrypted data with the goal of cracking it later on using quantum computers. (ITPRO.COM)
Social media
Meta is fighting a mountain of social-media lawsuits — at just the wrong time
Meta Platforms is facing one of the most serious legal threats of its 22-year history—and it couldn’t come at a worse time for the company as it navigates a tricky and costly transition to the artificial-intelligence era. In March, the company suffered defeats in landmark court cases in California and New Mexico that accused it of giving priority to growth over the safety of its underage users. Thousands more lawsuits by individuals, school districts and more than 40 state attorneys general are pending in state and federal courts. Together, they could put the company on the hook for many billions of dollars in damages and weaken the federal protections that have historically shielded it from liability for harmful content on its platform. (WSJ.COM)
Space
Trump admin exempts SpaceX’s Starlink from FCC ban on foreign-made routers
The Trump administration on Monday exempted SpaceX’s Starlink routers from the Federal Communications Commission ban on foreign-made routers. A public notice issued by the FCC said Starlink routers received approval from the Department of War (also known as the Department of Defense). SpaceX’s exemption is good until February 1, 2028. The FCC kicked off an industry-wide scramble when it updated the Covered List to include all consumer-grade routers made at least partly outside the US, except those that are granted exemptions. The Covered List includes devices deemed to pose an unacceptable risk to national security. Given that routers are generally built outside the U.S. or at least contain foreign-made components, all major vendors need exemptions. (ARSTECHNICA.COM)
LEGISLATIVE UPDATES
Bipartisan funding bill could drop this week
Senators say they are making headway in talks on a bipartisan bill funding the government through the election, even as rank-and-file Republicans doubt that Democratic leaders will go for it. Senate Appropriations Chair Susan Collins (R-Maine) said that text of the stopgap funding bill could be released this week, and that she’s been working with Democrats on it. Her Democratic counterpart, Sen. Patty Murray of Washington, said “we’re working on it.” (SEMAFOR.COM)
Sen. Wyden urges feds to discard older, insecure, public-facing VPNs
Sen. Ron Wyden implored a trio of federal leaders Monday to lead a comprehensive campaign to purge older, insecure virtual private networks that are directly accessible via the public internet from federal agencies. “For too long, federal agencies and government contractors have suffered devastating cyberattacks due to their reliance on legacy, insecure, internet-facing VPN servers to grant employees remote access,” Wyden (D-Ore.) wrote in his missive to top officials at the Office of Management and Budget, Cybersecurity and Infrastructure Security Agency and National Institute of Standards and Technology. They should coordinate “require the adoption of modern, secure remote-access technology across the federal government,” he said. (CYBERSCOOP.COM)
House NDAA proposes major acquisition workforce reforms
The fiscal 2026 defense policy bill was touted as a piece of legislation that would deliver “the most significant acquisition reforms in a generation.” And while the bill made some significant changes to defense acquisition processes, it barely addressed the workforce — a gap some experts warned could undermine those reforms. Plus, the department’s acquisition workforce has long been stretched thin, and recent efforts to reduce the size of its civilian workforce have only exacerbated those challenges. Meanwhile, the Defense Department’s acquisition budgets have grown significantly in recent years. (FEDERALNEWSNETWORK.COM)
COMMITTEE ACTIVITY
AI LABOR: The Senate Health, Education, Labor, and Pensions Subcommittee on Employment and Workplace Safety will hold a July 29 hearing to examine the impact of AI on the workplace.
AI FRAUD: The Senate Committee on Aging will hold a July 29 hearing on deepfakes, chatbots and the new frontier of senior fraud.
COMMUNICATIONS: The Senate Commerce, Science and Transportation Subcommittee on Telecommunications and Media will hold a July 30 hearing to examine intelligent networks, focusing on powering artificial intelligence and transforming communications.
ALERTS AND ADVISORIES
CISA adds two known exploited vulnerabilities to catalog
CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2025-68686 Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability and CVE-2026-16812 Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability. These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise. (CISA.GOV)
Events
TO BE INCLUDED IN THIS CALENDAR, SUBMIT YOUR SECURITY-FOCUSED EVENT FOR CONSIDERATION
SUPPLY CHAIN: The Iran war is disrupting the balance of power across the Middle East while underscoring the need to rethink the flow of energy and goods across the region. The India-Middle East-Europe Economic Corridor (IMEC) initiative has the potential to facilitate new trade corridors, but to do so it must adapt to a changing Middle East and overcome both political and practical hurdles. On July 28, the Atlantic Council’s Project on Middle East Integration will host a panel discussion on how the Iran war and its associated threats have highlighted the need for new trade alternatives and corridors.
6G: Join CSIS, senior U.S. government officials and leading global partners for a July 29 public forum examining the geopolitical and security landscape of next-generation wireless infrastructure. This event will feature the launch of the “Call to Action for 6G Leadership and Security,” a joint initiative between the United States (coordinated by the National Telecommunications and Information Administration) and partner nations designed to strengthen digital supply chains, accelerate innovation, and expand multilateral cooperation on wireless technology.
DEFENSE: Conflicts in Ukraine and the Middle East have accelerated global efforts to develop lethal and affordable drone systems. Taiwan’s lawmakers, however, have already passed on one opportunity to fund a domestic drone industrial base. So lawmakers are once again debating the best way to fund a new effort and deter the People’s Liberation Army. Senior Fellow Can Kasapoğlu recently explored this issue in a Hudson policy memo, which drew upon the Russia-Ukraine War and operations in the Strait of Hormuz. Join Hudson Institute for an Aug. 4 discussion on Taiwan’s rapidly changing security and defense industry.
ENERGY CRISIS: The CSIS Energy Security and Climate Change Program is pleased to host Jérôme Bilodeau, Head of Analysis (Energy Efficiency and Inclusive Transitions), International Energy Agency (IEA), for an Aug. 4 discussion on the global energy implications of the Strait of Hormuz crisis and how governments have responded to disruptions in energy markets. Bilodeau will present key findings from IEA analysis of the crisis, highlighting its effects across major regions and the policy measures adopted to mitigate supply shortages. He will also provide an overview of the policy tracker tool his team has developed, demonstrating how it captures and compares government responses to evolving energy market conditions.
ENERGY: The CSIS Energy Security and Climate Change Program is pleased to host Jérôme Bilodeau, Head of Analysis (Energy Efficiency and Inclusive Transitions), International Energy Agency (IEA), for an Aug. 4 discussion on the global energy implications of the Strait of Hormuz crisis and how governments have responded to disruptions in energy markets. Bilodeau will present key findings from IEA analysis of the crisis, highlighting its effects across major regions and the policy measures adopted to mitigate supply shortages. (CSIS.ORG)
AI HEALTH CARE: The AI in Health Conference from Sept. 15 to Sept. 17 bridges the gap between artificial intelligence and real-world health outcomes — focusing not just on what AI can do, but on what it should do to improve patient care. Hosted by the Ken Kennedy Institute at Rice University, the fifth annual AI in Health Conference will explore the current landscape of artificial intelligence in health and present a research-driven outlook for the future of computational health innovation. The program is designed to connect researchers and innovators with engineers, clinicians, and entrepreneurs at the forefront of AI in healthcare and public health.
BIOTECH: Synthetic biology is an interdisciplinary field combining biological and engineering to designing and redesigning genes, biological pathways, or organisms to solve society’s major problems and understand biological principles. Rapid advancements in synthetic biology are reshaping how we approach challenges in health, the environment, and beyond. However, these breakthroughs raise questions about what should be permitted and how new technologies should be regulated. To that end, the global conversation on biotechnology must account for responsible frameworks that guide future scientific innovation. This Sept. 18 Baker Institute symposium convenes a diverse community of scholars and practitioners in academia, industry, nonprofits and government for a deep dive into the intersection of emerging biotechnologies, public policy, and ethical responsibility.
FOLLOW THE McCRARY INSTITUTE ON LINKEDIN | X | BLUESKY
SUBSCRIBE TO THE CYBER FOCUS PODCAST: YOUTUBE | SPOTIFY | APPLE PODCASTS