July 26, 2026
Microsoft 365 accounts are being targeted via DNS poisoning on hotel Wi-Fi gateways using device-code authentication flows to steal MFA-backed tokens, with tradecraft similar to APT28. Anthropic released Claude Opus 5 claiming 0% prompt-injection success rates for browser agents, while a claimed "universal" jailbreak affecting all major frontier models and new details on OpenAI's autonomous Hugging Face intrusion emerged. Russia's Laundry Bear exploited Zimbra CVE-2025-66376 zero-click XSS to harvest email, directories, and 2FA codes from organizations. Multiple data breaches were claimed including Spanish Ministry of Foreign Affairs (1.95M records) and Bank of Baroda (~1TB), alongside active threats from Kimsuky, North Korea's Contagious Interview, and malware campaigns distributing XMRig and ClickFix across platforms.
July 20, 2026
- Alibaba released open-weight Qwen 3.8 (2.4T-parameter multimodal), claiming it trails only Fable 5, days after Moonshot's Kimi K3 topped the Code Arena frontend rankings and forced Moonshot to suspend new subscriptions amid demand. Kimi still scores ~39% on FrontierMath Tier 4 versus ~90% for OpenAI/Anthropic, underlining an uneven capability profile (The Decoder — Qwen, The Decoder — Kimi) (discussion).
· AI & Model Security
in AI Moves From Threat Model to Threat Actor: Autonomous Intrusions and a Shrinking Cyber Gap
July 17, 2026
- Moonshot's Kimi K3 (2.8T params, 1M context) is topping arenas and closing on GPT-5.6 Sol and Fable 5, with full open weights due by July 27 — reviving open-weights governance questions (jailbreak resistance, pre-clearance) that Ethan Mollick notes remain entirely unsettled for open models (The Decoder, Simon Willison). Separately, Mira Murati's Thinking Machines Lab released Inkling, a 975B open-weights model leading US open models but still trailing top Chinese labs (The Decoder).
· AI & Model Security
in Live SonicWall Exploitation, a New C2 Release, and AI Agents Tricked Into Running Attacker Commands
July 9, 2026
- xAI shipped Grok 4.5, trailing Fable 5 and GPT-5.5 on coding benchmarks but at roughly one-tenth the cost (~$1.51 vs $17.32 per task on CursorBench), with EU availability expected mid-July. The Decoder
· Industry & Policy
in A 15-Year-Old Linux Kernel Bug Hands Root on Every Distro
June 24, 2026
Critical vulnerabilities hit domain controllers as CVE-2026-41089 (Netlogon RCE) and Onelogon (Zerologon bypass) emerge, while FortiBleed credential-harvesting campaign reaches Finnish organizations after compromising 110M+ credentials from 430K+ Fortinet devices. Major supply-chain threats include Klue OAuth attacks affecting LastPass, malicious npm packages impersonating PostCSS, and Cordyceps malicious pull requests targeting Azure/Google/Apache projects; Anthropic's Mythos model discovered Squidbleed (Heartbleed-style flaw in Squid) and vulnerabilities in classified US systems.
June 17, 2026
- GLM-5.2 dropped open weights with a 1M context window and is benchmarking as a top-3 model across open and proprietary — the release coincides with the US export-control directive that forced Anthropic to suspend foreign access to Fable 5 and Mythos 5, fueling bets on Chinese model providers. r/LocalLLaMA, Dark Reading.
· AI & Model Security
in Microsoft 365 Copilot 'SearchLeak' Enables One-Click Data Theft as Novo Nordisk Loses Internal AI Models to Extortionists