
Loading summary
A
From the CISO series, it's Cybersecurity Headlines
B
these are the cybersecurity headlines for Friday, July 31, 2026. I'm Steve Prentiss. Semiconductor firm Analog Devices discloses Data Breach, the Massachusetts based company which designs and manufactures analog mixed signal and digital signal processing chips for the industrial, automotive and communications sectors, in a Wednesday filing with the SEC that it had detected unauthorized access to certain of its systems occurring on June 23rd. The attack resulted in the theft of certain files, but the nature of these files was not described. The company further stated that it is not aware of the files having been leaked and that the attack is not expected to have a material impact on its business operations or financial condition. End quote Copilot for Word Proof of concept copies hidden prompts into new documents According to Norwegian AI and machine learning researcher Hakan Malloy, hidden instructions in a Word document can make Microsoft 365 copilot rewrite figures in a report, then copy the same instructions into the finished file. This is an AI worm technique that Malloy disclosed on Tuesday, 144 days after reporting it to Microsoft who who confirmed it and deployed mitigations up to GPT 5.5. However, the full chain works with modified Instructions on GPT 5.6 and therefore remains exploitable. This attack is not a zero click and does not execute malware. It requires a copilot drafting or editing operation, and the malicious document must enter the model's context as an attachment or as a OneDrive source selected by WorkIQ, the intelligence engine behind Microsoft 365 Copilot. End Quote There is no evidence of this technique having been exploited in the wild as of yet, and a link to the summary of the Maloy report is available in the show Notes to this episode. Microsoft Teams vishing attacks lead to Chaos Ransomware attacks Threat actors are once again impersonating IT support staff, this time in Microsoft Teams calls to to gain remote access to corporate devices and to deploy chaos ransomware. Sophos, who is tracking the campaign as STAC4749, says that it has targeted dozens of North American organizations between February and June of this year, with at least three of these intrusions leading to the deployment of chaos ransomware. One of these attacks went from initial access to encrypting files in less than 17 hours. The attacks begin with external Microsoft Teams accounts impersonating IT help desk or support personnel in teams, chats and voice calls to targeted employees. FTC sues hims and hers for allegedly sharing patients medical data with advertisers. The U.S. federal Trade Commission has sued telehealth provider HIMS and Hers, alleging it illegally shared customers sensitive health information with advertising and technology companies including Meta, Snap, Microsoft, Pinterest, Reddit and X. Despite privacy promises to users, the FTC claims website tracking pixels collected data about users health related activity and transmitted it to third parties, while also accusing the company of deceptive billing and making subscription cancellations unnecessarily difficult. Hims and hers says its privacy policy allows users to control how their data is used and plans to fight the allegations. Huge thanks to our sponsor. Pin Drop A finance worker joined a video call with their CFO and wired $25 million to attackers. This isn't fiction, this happened. Deep fake video AI voice completely convincing. It could be happening in your meetings right now. Pin Drop Pulse for meetings can detect deepfake impersonation before the damage is done. So go to pindrop that is p I n d r-op.com and start verifying OpenAI hugging face attack A Case of Human error, not rogue AI following up on the OpenAI hugging face modal breach event that we have been covering these past two weeks, some security experts are calling this a case of human error in which the sandbox from which GPT 5.6 SOL and another pre release model escaped should have been completely physically secluded from the Internet, but wasn't. Dan Guido, the founder of Cybersecurity research startup TrailOfBits, called the Mistake a containment failure with the safeties turned off. In his blog he describes that the sandbox was a highly isolated environment with network access constrained to the ability to install packages through an internally hosted third party software that that acts as a proxy and cache for package registries. It appears that a zero day vulnerability in the package installation system became the critical first step in the eventual hack on Hugging Face. UK Department for Education reveals vulnerabilities and spurs industry Reaction following up on the story we covered yesterday regarding the theft of more than 740,000 records from the UK Department for Education and and Police national legal database, a number of high profile members of the cybersecurity industry spoke out pointing to the vulnerability of help desks and customer facing portals as an entry point into otherwise well defended government systems, end quote. The richness of the data these departments hold, paired with the data that shows education is currently one of the most targeted sectors globally. Facing thousands of attacks per organization every week, led to an outpouring of frustration regarding the lack of defense focus that this sector receives. A link to the article containing these comments, many of them is available in the show. Notes to this episode Senate Confirms Clayton as Intel Chief the Senate on Tuesday confirmed Jay Clayton as the next Director of National Intelligence. Senators voted along party lines 51 to 47. He is currently the U.S. attorney for the Southern District of New York and will assume leadership of the organization that is meant to oversee and coordinate the country's nearly 20 intelligence agencies. End quote Google Develops new Naming Convention for Threat Actors so Long, Cozy Bear and Vault Typhoon Google has created a new taxonomy for cybercrime outfits, leaving behind Microsoft's earlier attempt at creating consistent names. Following its acquisition and absorption of Mandiant, it is announcing a two word schema in which the first word is a unique and memorable term chosen to represent the specific actor. The second word will categorize threat clusters by motivation, attribution, or activity type based on which category they consider to be most important for defence and response strategies. This means the following words will be applied to the following Castle to describe crews from the People's Republic of China, Ion for threats from Iran, Neptune for North Korean attackers, Relic for Russians, and Comet for gangs not backed by a state. Remember to register for today's Super Cyber Friday at 1pm Eastern. Today we're going to be talking about hacking the SMB security gap. We know small businesses have often ignored security. It used to be that they weren't worth the time of your average threat actor to pop, but agentic AI has changed the math. So how do they start to address this chasm? Register@SuperCyberFriday.com for the event and join in the conversation. And if you have some thoughts on the news from today or about this show in general, please be sure to reach out to us at feedback@cisoseries.com we would love to hear from you. I'm Steve Prentiss reporting for the CISO series.
A
Cybersecurity headlines are available every weekday. Head to cisoseries.com for the full stories behind the headlines.
Host: Steve Prentiss, CISO Series
Episode Theme: Daily roundup of major cybersecurity incidents and trends, with a focus on recent data breaches, AI threats, vishing campaigns, regulatory lawsuits, and shifts in industry practices.
This episode presents key cybersecurity developments from July 31, 2026. Discussions include a disclosure from Analog Devices about a data breach, a novel Copilot AI worm in Office documents, Microsoft Teams vishing attacks leading to ransomware incidents, a major FTC lawsuit over data privacy in telehealth, a human error-driven AI sandbox breach at Hugging Face, reactions to UK government database theft, leadership changes in US intelligence, and Google’s fresh approach to threat actor naming conventions.
On Analog Devices Breach:
“The attack is not expected to have a material impact on its business operations or financial condition.”
— Steve Prentiss [00:30]
On Copilot AI Worm:
“It requires a Copilot drafting or editing operation, and the malicious document must enter the model's context as an attachment or as a OneDrive source selected by WorkIQ, the intelligence engine behind Microsoft 365 Copilot.”
— Steve Prentiss [01:40]
On UK Government Data Vulnerability:
“The richness of the data these departments hold, paired with data that shows education is currently one of the most targeted sectors globally…led to an outpouring of frustration regarding the lack of defense focus.”
— Steve Prentiss [06:50]
Steve Prentiss’s narration is brisk and matter-of-fact, typical of the daily news briefing style. The episode distills a sense of urgency about evolving cyber threats—be it through new technical exploits (the Copilot worm), the perennial risks of social engineering, or regulatory and reputational hazards for organizations mishandling sensitive data. The breadth of stories emphasizes the diversity and speed of challenges facing the cybersecurity community.