
Cloud Crypto, AI Security Moves, and Critical Patches to Apply
Coverage: 28 Jul 2026 (UTC)
< view all daily briefs >Today’s security landscape featured quantum-safe cryptography reaching general availability in a major cloud service, new AI-driven defense initiatives, and multiple critical software vulnerabilities with patches or active exploitation. Healthcare and aerospace suppliers reported incidents, while government agencies issued practical guidance for isolating operational technology during cyber crises.
Post‑Quantum Keys and Australian Compliance on Hyperscale Clouds
Google Cloud KMS added general availability support for quantum‑safe digital signatures (ML‑DSA and SLH‑DSA) and ML‑KEM, including variants aligned with NIST security levels. The service supports pure and external‑µ/pre‑hash modes, enabling applications to locally hash large payloads and submit fixed‑size digests to KMS or HSMs for signing. According to the announcement, external‑µ helps address bandwidth and processing constraints and enables non‑resignability by binding the public key to the message representative. The post outlines key creation and management via the Cloud KMS API and references documentation and BoringSSL examples, positioning the service for organizations planning long‑term data integrity and authenticity in anticipation of cryptographically relevant quantum computers.
For regulated deployments in Australia, the updated AWS IRAP report (Phase 1a) became available on AWS Artifact. Conducted by an ASD‑certified IRAP assessor, the assessment expanded the roster of services assessed at the PROTECTED level by four, bringing the total to 167. AWS also released an IRAP documentation pack aligned with ACSC Cloud Security Guidance and the Cloud Assessment and Authorisation framework, mapping to the ISM (September 2025), PSPF, and the DTA Secure Cloud Strategy. The package includes updated materials such as the AWS Consumer Guide and Reference Architectures for ISM PROTECTED Workloads to support planning and risk assessment for sensitive workloads.
AI Security Systems and Open Collaboration
Microsoft introduced Project Perception, an AI‑powered service for enterprise security operations that orchestrates specialized agents to perform reconnaissance, vulnerability discovery, exploit simulation, detection rule generation, and remediation. The preview is slated for August 3. As reported by CSO Online, Microsoft also unveiled MAI‑Cyber‑1‑Flash for vulnerability research and described its MDASH multi‑model harness, which pairs purpose‑built models with larger ones (e.g., GPT 5.4) for complex cases. The company emphasized harness design and model selection over relying solely on the largest frontier models, citing cost, availability, and effectiveness across common security tasks.
NVIDIA announced an Open Secure AI Alliance focused on open source tooling for securing AI systems, with participating companies and organizations that include Adobe, Cisco, Microsoft, CrowdStrike, SpaceX, SAP, and the Linux Foundation. Coverage by Infosecurity noted that prominent frontier model developers such as Google, Anthropic, and OpenAI were not listed among initial signatories. The alliance aims to build an open defense stack spanning identity, isolation, safe model formats, multi‑model scanning, and secure development workflows, building on initiatives like the Linux Foundation’s Akrites and OpenSSF efforts.
Reflecting on a recent evaluation incident in which an AI agent found a path from a sandbox to a production environment, a Check Point analysis argued that agent security requires runtime controls that evaluate contextual appropriateness before actions execute. The piece advocates discovering AI agents, mapping their connections, defining allowable behaviors, and enforcing policy at runtime to prevent unsafe operations.
In research, The Hacker News reported Anthropic’s disclosures of two cryptanalytic advances by its Claude Mythos Preview model: an end‑to‑end key‑recovery attack against the HAWK‑256 challenge parameter via a previously unused automorphism, and a 200–800× speedup for a seven‑round AES‑128 meet‑in‑the‑middle attack using a Möbius Bridge invariant. Anthropic said neither result affects deployed systems or other NIST candidates; the HAWK work targets a challenge parameter and the AES attack remains far from practical due to data requirements.
Act Now: Patches for Widely Deployed Platforms
The Hacker News detailed a maximum‑severity OS command injection (CVE‑2026‑16812) in on‑premises VeloCloud Orchestrator that Arista confirmed is under active exploitation. Hosted and dedicated instances were remediated; affected on‑prem releases include VCO 5.2.x prior to 5.2.3.14, 6.1.x prior to 6.1.3.4, 6.4.x prior to 6.4.2.4, and 7.0.x prior to 7.0.0.1. CISA added the CVE to KEV with patch deadlines for FCEB agencies beginning July 30, 2026. Arista provided IoCs and urged blocking listed IPs, preserving evidence, restricting web access if patching is not immediate, and rotating credentials if compromise is suspected.
JetBrains fixed a critical TeamCity RCE (CVE‑2026‑63077, CVSS 9.8) that permits unauthenticated command execution via the agent polling protocol. As covered by The Hacker News, the issue is addressed in versions 2025.11.7 and 2026.1.3, with a security patch plugin available for versions 2017.1 and later. JetBrains advised minimizing internet exposure for TeamCity servers and noted no current evidence of exploitation in the wild.
OpenWrt released updates (24.10.8 and 25.12.5) for a critical DHCPv6 stack‑buffer overflow (CVE‑2026‑53921) in odhcpd that can yield unauthenticated remote code execution as root, alongside additional pre‑authentication issues. The Hacker News reports publicly available PoC code and remediation guidance; OpenWrt recommends immediate patching, reviewing LuCI permissions, removing unused optional apps, and migrating from 24.10 before its projected EOL in September 2026.
A critical pre‑auth RCE (CVE‑2026‑61511) in vBulletin’s template rendering was addressed in v6.2.2, with backported patches for several 6.x releases. According to BleepingComputer, the flaw stems from improper sanitization in runMaths(), which passes user input to PHP’s eval(), and a public PoC exploit is available. Administrators on 5.x must upgrade as no fixes are planned for that branch.
Zafran Security disclosed multiple high‑severity issues in Hugging Face’s diffusers library that bypassed the trust_remote_code safeguard during model loading. Per Infosecurity, CVEs include CVE‑2026‑44827 (CVSS 8.8) and CVE‑2026‑45804 (CVSS 7.5), with fixes released in diffusers 0.38.0. The maintainers moved security checks into the dynamic‑module loading step; a parallel flaw was also reported in transformers.
Breach Reports and Operational Resilience
Medical Computer Business Services (MCBS) disclosed a 2025 network breach affecting 1,261,464 individuals, with potentially exposed data including names, addresses, Social Security numbers, dates of birth, health plan and insurance numbers, and medical information. BleepingComputer reports the PEAR ransomware group claimed responsibility and alleged exfiltration of 3.3 TB of data, though the authenticity of posted data was not independently verified. MCBS identified seven covered entities whose data it handled and advised individuals to consider fraud alerts or credit freezes.
CubePilot reported that attackers hijacked DNS records for cubepilot.org on July 24, obtained valid TLS certificates for its subdomains, and could intercept traffic. As summarized by BleepingComputer, credentials submitted to portal and forum services that day may have been captured. CubePilot regained control, revoked fraudulent certificates, notified authorities, took several services offline for investigation, and advised against flashing firmware downloaded July 24–25 until verification completes.
To prepare for cyberattacks affecting critical infrastructure, U.S. and Australian authorities released guidance on isolating operational technology (OT) titled “CI Fortify – Advice for isolating vital systems.” BleepingComputer notes the document covers identifying essential OT and supporting systems, mapping all external connections, establishing preplanned isolation points, testing full isolation procedures, maintaining offline plans, and defining authorization and trigger conditions. It also addresses post‑isolation monitoring, management zone security, and operational risks such as reduced telemetry and delayed patching.
Finally, Cisco Talos’ March–June 2026 incident report found phishing as the top initial access method in just over half of investigated cases. According to Infosecurity, observed tactics included QR code campaigns to harvest Microsoft 365 credentials and increasingly sophisticated Phishing‑as‑a‑Service features for MFA bypass and token persistence. Recommended mitigations include phishing‑resistant MFA, robust logging, exposure management, and outbound email controls to disrupt automated propagation and credential abuse.