
Loading summary
A
From the CISO series. It's Cybersecurity Headlines
B
these are the cybersecurity headlines for Tuesday, July 28, 2026 I'm Sarah Lane. Nvidia opens the AI security tent Nvidia is leading a new open secure AI alliance with more than 30 founding members, including Microsoft, CrowdStrike, Hugging Face I, IBM, Cisco and the Linux Foundation. The group plans to build and share open models and tools and techniques for securing AI software and agents. Nvidia tied the launch to the recent Hugging Face intrusion, where commercial models blocked real exploit code during the investigation and an open weight model helped reconstruct more than 17,000 attacker actions. The alliance argues that open models can be defensive assets, not just security risks, especially when defenders need to run them locally with fewer restrictions. Microsoft puts a cyber sprinter in M dash Microsoft introduced Mai CyberOne Flash, its first security focused model inside the company's EM Dash Multi Agent vulnerability hunting system. Microsoft says the smaller model can handle about 90% of M Dash tasks, while the hardest 10% get routed to GPT 5.4. That mix scored 96% on the Cybergem benchmark, 12 points above Mythos, while cutting costs in half compared with Microsoft's previous M Dash model lineup, the system uses more than 100 agents to find, validate and help remediate software flaws with sandbox execution and no Internet access. Fairlife ransomware spills data Coca Cola confirmed that hackers stole data during the ransomware attack on its Fairlife Dairy subsidiary. The incident temporarily shut down production at four US Facilities, but the company says most production has resumed existing inventory, covered shortages and product quality and safety were never affected. The Anubis gang claimed it encrypted Fairlife's Nutanix Systems and stole 1 terabyte of data, although that amount has not been independently verified. Coca Cola says some systems are still being restored while the gang's deadline has expired and the stolen files are now available for download. Telegram phishers make it personal Researchers at resident NGO uncovered a highly personalized Telegram phishing campaign targeting an exiled Belarusian activist and users in Belarus, Russia and Kazakhstan. The attackers sent fake security alerts through Telegram secret chats and built a unique link for each target, including that person's phone number. Victims who entered Telegram's one time login code could have their accounts taken over immediately. The infrastructure checked each visitor's device and browser, redirected security tools to harmless pages and then followed up with messages that included the victim's device, the visit time and their Internet provider. Researchers found 64 phone numbers in those links, but couldn't confirm that every single person received the lure or that any account was actually compromised. Huge thanks to our sponsor Pindrop. A finance worker joined a video call with their cfo and wired $20 million to attackers. This isn't fiction. It happened. Deep fake video AI voice completely convincing. It could be happening in your meetings right now. Pin drop pulse per meetings can detect deepfake impersonation before the damage is done. Go to pindrop.com and start verifying V Bulletin exploit goes public an unnamed researcher appears to have released public exploit details for a critical V bulletin flaw that lets an unauthenticated attacker reject run PHP code on a forum server. The bug sits in the template engine and can be triggered with a specially crafted page nav parameter. Versions 6.2.1 and earlier, along with 6.1.6 and earlier are affected. Vbulletin issued patches at the end of June and released version 6.2.2 on July 1, almost four weeks before the exploit became public. Administrators should patch now and check for signs of compromise. Claude's shared chats escape the group Chat Some Claude conversations shared through public links were indexed by Google, making them searchable by anybody who knew the right site query. The indexed chats reportedly included API credentials, crypto wallet information, resumes, legal strategy, and other personal data. No evidence that private but unshared Claude conversations were exposed. They had to be public. Google results for the shared pages have disappeared, but removing a search result doesn't disable the underlying link. Users can review and unshare old links under their settings, then privacy, then shared chats. Clop rides a Windchill flaw A CLOP ransomware affiliate is exploiting a critical ptc, Windchill AS and Flex PLM flaw to break into organizations without authentication. The vulnerability lets attackers execute code, remotely, deploy web shells, search file systems, and stage data for extortion. PTC patched it on June 17 and reported exploitation the next day, but the current campaign began July 20 and has hit aerospace, automotive, manufacturing and and retail and apparel organizations. Attackers have also sent extortion emails to hundreds of users inside affected companies. Organizations should apply PTC's fixes and hunt with the published indicators of compromise. Wyden wants legacy VPNs shown the door Oregon Senator Ron Wyden wants federal agencies to retire old VPN servers that sit directly on the public Internet, saying those systems have become a repeat entry point in attacks involving Cisco, Fortinet, Avanti and Checkpoint appliances, leaving CISA stuck issuing emergency patch orders. Wyden is asking CISA to give agencies two years to remove legacy public facing remote access systems and shift to zero trust tools that don't advertise an exposed front door. He also wants National Institute of Standards and Technology implementation standards and and procurement rules that block agencies and defense contractors from buying remote access products that don't meet federal zero trust requirements. Remember to register for this Friday's Super Cyber Friday at 1pm Eastern Time. This Friday we're gonna be talking about hacking the SMB security gap. We know small businesses have always ignored security. It used to be that they weren't worth the time of your average threat actor to pop, but agentic AI has changed that math. So how do they start to address this chasm? Register@supercyper Friday.com for the event and join in on the conversation. And if you have thoughts on the news from today or about our show in general, be sure to reach out to us feedbackisoseries.com we always want to hear from you. I am Sarah Lane reporting for the CISO series. You stay classy out there. Planet Earth
A
cybersecurity headlines are available every weekday. Head to cisoseries.com for the full stories. Behind the headlines.
Host: Sarah Lane, CISO Series
Main Theme: Top daily stories in information security, focusing on new alliances for AI security, major ransomware incidents, critical vulnerabilities, phishing campaigns, and regulatory calls for updated remote access standards.
This episode covers a broad spectrum of urgent cybersecurity topics:
“Open models can be defensive assets, not just security risks, especially when defenders need to run them locally with fewer restrictions.” (Sarah Lane, 00:27)
“That mix scored 96% on the Cybergem benchmark, 12 points above Mythos, while cutting costs in half compared with Microsoft’s previous M Dash model lineup.” (Sarah Lane, 01:32)
page nav parameter“Administrators should patch now and check for signs of compromise.” (Sarah Lane, 04:30)
“Users can review and unshare old links under their settings, then privacy, then shared chats.” (Sarah Lane, 05:03)
“…those systems have become a repeat entry point in attacks…leaving CISA stuck issuing emergency patch orders.” (Sarah Lane, 06:23)
On AI models as defensive assets:
“The alliance argues that open models can be defensive assets, not just security risks…” (00:27)
Microsoft’s vulnerability hunting breakthrough:
“…scored 96% on the Cybergem benchmark, 12 points above Mythos, while cutting costs in half…” (01:32)
Fairlife ransomware aftermath:
“Product quality and safety were never affected.” (02:23)
Telegram phishing sophistication:
“The infrastructure checked each visitor’s device and browser, redirected security tools to harmless pages, and then followed up with messages that included the victim’s device, the visit time and their Internet provider.” (03:21)
VBulletin exploit warning:
“Administrators should patch now and check for signs of compromise.” (04:30)
Senator Wyden on VPN risk:
“…repeat entry point in attacks involving Cisco, Fortinet, Avanti and Checkpoint appliances, leaving CISA stuck issuing emergency patch orders.” (06:23)
For deeper dives into any story, visit CISOseries.com.