
Loading summary
A
From the CISO series, it's Cybersecurity Headlines
B
these are the cybersecurity headlines for Thursday, July 9, 2026. I'm Sarah Lane. Mexico's first cyber test gets tested Mexico's new National Cybersecurity plan is getting an early stress test as the country co hosts the FIFA World cup, per perhaps you've heard of it. This was adopted back in November and calls for updated cyber laws. A national cybersecurity strategy by the end of the third quarter of this year, a new national cybersecurity center to monitor threats and closer coordination between government, industry and universities. Recorded Future says the tournament has raised the risk from ransomware gangs, hacktivists, fraud, crime, credential theft, disinformation and nation state activity. New York University adjunct professor Jose Felipe Otero says the plan is still falling short on protecting operational technology, supply chains and third party software risks. Snoops break into Round Cube mail servers proofpoint shared new details with the Register about a suspected China linked espionage campaign it tracks as Unkmasstraction, which has been targeting U.S. and Canadian universities since May by exploiting unpatched Roundcube webmail servers. The campaign focuses on physics, engineering and other departments tied to national security research, using phishing emails to steal credentials, deploy web shells and maintain long term access. Proofpoint notes it observed fewer than 10 universities that were being targeted, but estimates the campaign may have reached a few dozen institutions and also may still be ongoing. Cash App owner paying up for lacks security Block, the company behind Cash App as well as other apps, agreed to pay $45 million to settle allegations from 46 different states that it overstated the app security and failed to adequately protect users from fraud. State attorneys general say Cash App lacked basic safeguards, including live phone support until 2021, allowed scammers to create large networks of fake accounts and left many victims unable to recover stolen money. The settlement also requires block to maintain 24. 7 customer support and reinforces an earlier federal agreement with requiring up to $120 million in consumer restitution. Mount Royal confirms breach and now we're going back to Canadian university news. Mount Royal University in Calgary, Alberta, says hackers stole data from a shared file storage drive and then deleted files from multiple campus drives after a cyber attack disrupted university systems back in June. The university is still trying to determine what was exposed and warns recovery could take weeks or even months. The ransomware group CMD organization has claimed responsibility, has demanded a 30 bitcoin ransom and has published samples of what it says is the stolen data Mount Royal is offering two years of credit monitoring and identity theft protection to anyone who's worked there within the past five years. Huge thanks to our sponsor Vanta. Your team just added its 67th AI tool and unfortunately also your 67th security blind spot. The good news? The Vanta Agent works like a GRC engineer in the background, finding every app your team uses, scoring that risk and drafting fixes for you. Vanta is the platform used by over 16,000 fast moving companies like Ramp Cursor and Harvey who are shaping the future with AI and staying ahead of AI risk. Get started today at Vanta.com headlines Attacker breaches AWS in 3 days A single attacker used AI assisted workflows to breach a large AWS environment in about 72 hours and extort an unnamed global enterprise incident response firm. Signia Stock says the attacker did not rely on a single flaw, but did chain together weaknesses across cloud services, source code repositories, CICD pipelines, stolen credentials and data stores Using AI to speed up reconnaissance, tool development and adapting to the victim's environment A good reminder that defenders need to automate detection and response because AI is letting attackers move faster than traditional security operations can keep up. Paris Peace Forum takes on AI threats French nonprofit Paris Peace Forum is launching a new global hub to study AI powered cyber threats and coordinate international responses. It's called the Integrated Network for Trusted AI in Cyberspace and it's meant to bring together governments, researchers and organizations like Microsoft, organizations Orange Cyber Defense and the Cyber Threat Alliance. One of its biggest goals is building a rapid response coalition to respond more quickly as cyber threats keep evolving. Coding agents trigger endpoint security rules Claude code cursor and OpenAI codecs are starting to trigger the same endpoint security alerts that defenders use to catch real attackers. Security firm Sophos says the agents aren't malicious, but they're performing attacker like actions more often, like accessing browser credentials, enumerating Windows credential stores, downloading files with built in system tools and creating startup scripts, all as part of legitimate development tasks. The researchers say it's a clear sign that security teams need to rethink how they distinguish between trusted AI assistants and and actual intruders. IBM and Red Hat Launch Lightwell well, they claimed, and they delivered. IBM and Red Hat have launched Project Lightwell into two commercial services designed to help enterprises defend open source software from AI powered attacks. Lightwell uses AI to find, validate and backport security fixes directly into the versions of open source software or organizations are already running. Instead of forcing major upgrades. The launch comes as IBM, Red Hat, the Linux foundation, and Chainguard's Athena Coalition are all taking different approaches to solving the same problem. AI is finding and weaponizing open source vulnerabilities faster than traditional patching can keep up. We have a theme going on here, guys. If you have any thoughts on the news from today or about our show in general, be sure to reach out to us. Feedbackisoseries.com we'd love to hear from you. I am Sarah Lane, reporting for the CISO series. Stay cool out there and as always, stay safe.
A
Cybersecurity headlines are available every weekday. Head to cisoseries.com for the full stories. Behind the headlines.
Host: Sarah Lane | Podcast: CISO Series
Episode Theme:
A fast-paced rundown of the most pressing cybersecurity news stories, from Mexico’s national “cyber test” during the FIFA World Cup, to AI’s growing role in both attacks and defenses, and the evolving challenges in endpoint security and open source protection.
Sarah Lane covers globally significant cybersecurity stories, highlighting mounting threats during Mexico’s FIFA World Cup preparations, an ongoing espionage campaign targeting Roundcube mail servers in North American universities, a major settlement involving Cash App’s security practices, a ransomware attack on Mount Royal University, rapid AWS compromise using AI, coordinated efforts to address AI-powered threats, and new tools to defend open source software.
[00:20]
“The plan is still falling short on protecting operational technology, supply chains and third party software risks.” [00:56]
[01:13]
[01:53]
[02:36]
“Mount Royal is offering two years of credit monitoring and identity theft protection to anyone who's worked there within the past five years.” [03:05]
[04:14]
“Defenders need to automate detection and response because AI is letting attackers move faster than traditional security operations can keep up.” [04:44]
[05:02]
[05:34]
“Security teams need to rethink how they distinguish between trusted AI assistants and actual intruders.” [05:52]
[06:07]
“The plan is still falling short on protecting operational technology, supply chains and third party software risks.” [00:56]
“Cash App lacked basic safeguards, including live phone support until 2021, allowed scammers to create large networks of fake accounts and left many victims unable to recover stolen money.” [02:02]
“Defenders need to automate detection and response because AI is letting attackers move faster than traditional security operations can keep up.” [04:44]
“It’s a clear sign that security teams need to rethink how they distinguish between trusted AI assistants and actual intruders.” [05:52]
Sarah Lane maintains a brisk, factual, and at times lightly conversational tone, guiding listeners through a global perspective on the fast-evolving cybersecurity landscape. The episode emphasizes the growing sophistication of both threats and defenses, with an undercurrent of urgency about bridging gaps, from global event security to the open source software supply chain.