Cyber security news July 2026

This posting is here to collect cyber security news in July 2026.

I post links to security vulnerability news to comments of this article.

You are also free to post related links to comments.

66 Comments

  1. Tomi Engdahl says:

    Microsoft Adds New Teams Controls to Block Unauthorized AI Bots From Meetings

    Microsoft’s new Teams admin policy requires organizer approval for external AI bots, giving organizations greater visibility and control over automated participants in sensitive meetings.

    https://www.securityweek.com/microsoft-adds-new-teams-controls-to-block-unauthorized-ai-bots-from-meetings/

    Reply
  2. Tomi Engdahl says:

    Frontier AI: Six Questions Every Enterprise Should Ask Security Vendors

    From model selection and automation to validation and measurable results, the right questions can help enterprises separate genuine AI capabilities from marketing hype.

    https://www.securityweek.com/frontier-ai-six-questions-every-enterprise-should-ask-security-vendors/

    Reply
  3. Tomi Engdahl says:

    Artificial Intelligence
    The AI Token Costs That Can Break Cybersecurity

    As cybersecurity platforms embrace agentic AI, organizations must balance detection performance against the escalating costs of token consumption, deployment architecture, and AI credits.

    https://www.securityweek.com/the-ai-token-costs-that-can-break-cybersecurity/

    Reply
  4. Tomi Engdahl says:

    Reuters:
    Alibaba and its US payment processor AUS agree to pay $600M to resolve DOJ allegations that they failed to prevent illegal sales of drugs and other products — Chinese technology and e-commerce giant Alibaba (9988.HK) and its U.S.-based payment processor have agreed to pay $600 million …

    Alibaba to pay $600 million to resolve US drug sales probe
    https://www.reuters.com/world/alibaba-aus-merchant-services-pay-600-million-resolve-alleged-illegal-2026-07-01/

    Reply
  5. Tomi Engdahl says:

    Pew Research Center:NEW
    A survey of US adults finds 56% support banning social media for under-16s, while 21% oppose; majorities across demographic and partisan groups support a ban — Nearly six-in-ten U.S. adults support banning anyone under the age of 16 from using social media sites, according to a new Pew Research Center survey.

    Majority of Americans support banning social media for kids under 16
    https://www.pewresearch.org/short-reads/2026/07/01/majority-of-americans-support-banning-social-media-for-kids-under-16/

    Nearly six-in-ten U.S. adults support banning anyone under the age of 16 from using social media sites, according to a new Pew Research Center survey. The survey comes as governments around the world weigh new restrictions on teens’ use of social media.

    About one-in-five adults oppose banning those under 16 from using social media. And roughly a quarter are unsure, according to the survey conducted May 26-June 1, 2026.

    Australia, Canada and the United Kingdom are among the countries that have set or are considering a minimum age of 16 for social media use. In the United States, lawmakers in California are considering similar legislation.

    Many social media platforms currently require users to be at least 13 to create an account.

    Reply
  6. Tomi Engdahl says:

    Joe Warminsky / The Record:
    The US DOJ says Peter Stokes, a 19-year-old dual US-Estonian citizen, was extradited from Finland to face charges of participating in Scattered Spider hacks
    https://therecord.media/teen-suspect-in-scattered-spider-hacks-extradited-to-us

    Reply
  7. Tomi Engdahl says:

    A top Democrat on the Senate’s Intelligence Committee warned that the information accessed on a Homeland Security intelligence-sharing network may risk national security.

    US government says it got hacked — again
    https://techcrunch.com/2026/07/02/us-government-says-it-got-hacked-again/?utm_medium=organic_social&utm_source=FBPAGE&fbclid=IwVERDUASzfb5leHRuA2FlbQIxMABzcnRjBmFwcF9pZAwzNTA2ODU1MzE3MjgAAR66mNJPAdoABjwfjHgfnN5ZsabPMz2R6ZzHKHcjVS9MnsjeGyS5RaAarjM9tg_aem_oH7pWvPcMeWl5_TVAiKCRw

    The Department of Homeland Security is investigating a breach of its platform, which federal, state, and local governments and law enforcement use to share intelligence, with one senior lawmaker warning that the information spill could risk national security.

    News sites Nextgov, which first broke news of the incident, and Bleeping Computer report that DHS officials are probing a cyberattack on its Homeland Security Information Network, or HSIN, which allows government agencies and local officials to plan, coordinate, and share information and intelligence about major events and respond to emergencies.

    Reply
  8. Tomi Engdahl says:

    US Department of Homeland Security says it is probing a cyber breach at information-sharing network
    https://www.reuters.com/legal/litigation/us-department-homeland-security-says-it-is-probing-cyber-breach-information-2026-07-02/?fbclid=IwdGRjcAS08pNjbGNrBLTyd2V4dG4DYWVtAjExAHNydGMGYXBwX2lkDDM1MDY4NTUzMTcyOAABHi2EsHKWIgtsPd3kbsqk0LDp5I8006oR7-nxIhsN3EXnTumt1cI-Z2zEBIWL_aem_dmHDCZ_ByH0tI9zSwmEVuA

    WASHINGTON, July 2 (Reuters) – The Department of Homeland Security said on Thursday it ​was investigating a breach in an ‌unnamed information-sharing network.
    In a statement, DHS said there had been a “recent cyber incident” involving ​an “unclassified legacy information sharing environment” but ​did not provide further details and ⁠did not respond to follow-up questions.

    Reply
  9. Tomi Engdahl says:

    A report by the International Institute for Strategic Studies (IISS) assesses that it is ‘highly likely’ many of recent drone incidents throughout Europe were ordered by Moscow as part of a wider hybrid campaign against NATO.

    Read the full story before commenting here: https://theaviationist.com/2026/07/03/europe-drone-incursions-russia-shadow-fleet/

    Reply
  10. Tomi Engdahl says:

    Kysely: Suomalaiset eivät luota yritysten tietoturvaan – asiantuntija antaa vinkit, miten tarkistaa palvelun luotettavuus
    Suomalaisten mielestä yritysten pitäisi kantaa paremmin vastuunsa tietoturvasta. Tätä mieltä oli yli 80 prosenttia vastaajista DNA:n teettämässä Digitaalinen elämä -kyselytutkimuksessa. Asiantuntija muistuttaa, että myös kuluttajilla on vastuu, mitä palveluita he käyttävät. Jokainen voi kuitenkin tarkistaa, että digipalvelussa on huomioitu tietoturva.
    https://corporate.dna.fi/lehdistotiedotteet?type=stt2&id=72161269&scrollTo=UJpEOgFgPw1f&status=all&returnUrl=https%3A%2F%2Fcorporate.dna.fi%2Flehdistotiedotteet%3FscrollTo%3DUJpEOgFgPw1f&fbclid=Iwb21leASux6pleHRuA2FlbQEwAGFkaWQBqzRSX0qmq3NydGMGYXBwX2lkDDM1MDY4NTUzMTcyOAABHnq_Su0zUcB8Ls_I4EXkIJ7UTVO-lqxzhQR28NFP7H8nAjDOxtBATxJjFyAy_aem_yif4UQgGeGsbqZdv7S8qhQ&utm_medium=paid&utm_source=fb&utm_id=120247342377740587&utm_content=120247342377750587&utm_term=120247342377730587&utm_campaign=120247342377740587

    Reply
  11. Tomi Engdahl says:

    Russian hackers have infiltrated the email accounts of British government officials and overseas Foreign Office staff in a major national security breach.

    Dark web forums are now trading access to the sensitive logins for as much as $60,000 (£44,000).

    The breach included emails and coinciding passwords, allowing hackers – and anyone willing to pay for them – the potential ability to infiltrate sensitive Whitehall systems
    https://www.telegraph.co.uk/news/2026/07/05/russian-hackers-steal-government-logins/?WT.mc_id=tmgoff_fb_photo

    Reply
  12. design a custom wordpress plugin says:

    Thank you very much for your hard work! We design a custom wordpress plugin, let me know how can i help in your site.

    Reply
  13. Tomi Engdahl says:

    Maksupäätteillä vaanii uusi vaara: Tästä on kyse relay-hyökkäyksessä
    Relay-hyökkäyksiä on havaittu enenevässä määrin eri puolilla Eurooppaa.
    Maksupäätteillä vaanii uusi vaara: Tästä on kyse relay-hyökkäyksessä
    https://www.is.fi/digitoday/tietoturva/art-2000012123688.html

    Asiakas asettaa maksukorttinsa lukijaan. Sitten hän näpyttelee pin-koodinsa koneeseen, ja kortinlukija varmentaa asiakkaan maksukortin käytön.

    Samassa kortinlukijaan asennettu laite tai ohjelmisto sieppaa tapahtuman varmenteen ja ohjaa sen eteenpäin rikollisen käsissä olevalle korttipäätteelle. Rikollinen pystyy seuraavaksi tekemään esimerkiksi verkkokauppaoston tai käteisnoston – ja maksu veloitetaan kokonaan kuluttajan tililtä.

    Näin toimii niin kutsuttu relay-hyökkäys. Kyseisenkaltaisia hyökkäyksiä on viime syksyn jälkeen havaittu eri puolilla Eurooppaa, ja hyökkäysten kohteeksi on joutunut myös pohjoismaalaisia turisteja.

    Nordea kertoi asiakkaisiinsa kohdistuneista relay-hyökkäyksistä viime keskiviikkona. Tiedotteen mukaan ”kourallinen” sen pohjoismaalaisista asiakkaista on joutunut viime syksyn jälkeen kyseisenkaltaisten hyökkäysten kohteeksi.

    Hyökkäysten yleistyminen on sidottu osaltaan lähimaksutoiminnon leviämiseen. Lähimaksutoiminto mahdollistaa esimerkiksi sen, että maksupäätteeseen asennettavan haittaohjelman sijaan rikollinen kaappaakin maksuvarmennesignaalin ulkoisen NFC-signaaleja kaappaava laitteen avulla.

    NFC-signaalien kaappaamiseksi on kehitetty myös puhelinsovelluksia. Teknologiauutisiin keskittyvä Bleeping Computer -julkaisu kertoi viime vuonna sadoista Android-sovelluksista, jotka hyödynsivät Androidin Host Card Emulation -toimintoa maksukorttien lähimaksudatan emuloimiseen tai varastamiseen.

    Idea muistuttaa autovarkauksista tuttua relay-hyökkäystä, jossa rikollinen ikään kuin onkii auton avaimen lähettämän signaalin ja välittää sen autolle erillisten laitteiden avulla saaden auton ovet avautumaan.

    Relay-hyökkäysten kehittymisen seurauksena niiltä suojautuminen ei ole yksinkertaista. Joillain puhelimilla lähimaksutoiminto on mahdollista kytkeä pois päältä, mutta tämäkään ei auta, jos korttia käyttää haitallisen ohjelmiston varustamassa laitteessa.

    Nordean Annukka Multasen mukaan käyttörajoituksilla ja maakohtaisilla korttirajoituksilla pääsee kuitenkin jo pitkälle

    Reply
  14. Tomi Engdahl says:

    WARNING – Several Tenda firmware builds embed an undocumented auth backdoor in /bin/httpd.

    CVE-2026-11405 checks sys.rzadmin.password after normal login fails. If the supplied password matches, it creates an admin session.

    Still unpatched.

    Read: https://thehackernews.com/2026/07/certcc-warns-of-hidden-admin-backdoor.html

    Reply
  15. Tomi Engdahl says:

    Meta faces $1.4 trillion in penalties. It’s worth $1.5 trillion.

    Four US states are taking the company to trial in August.

    They allege its apps were designed to keep young users engaged.

    The trial opens on August 18 in California.

    Parents can review the safety settings on their kids’ accounts now.

    Meta says a penalty this large has never existed before.

    Read more on TNW: https://thenextweb.com/news/meta-states-1-4-trillion-youth-safety-trial

    Reply
  16. Tomi Engdahl says:

    Fourth Order
    US Air Force Engineer Charged With Sawing Down Flock Surveillance Cameras Receives Thousands of Dollars from Supporters Across the Country
    “There has been community support for me that I humbly welcome.”
    https://futurism.com/future-society/air-force-engineer-flock-surveillance-support-legal-gofundme?fbclid=IwdGRjcAS8M8NjbGNrBLwzq2V4dG4DYWVtAjExAHNydGMGYXBwX2lkDDM1MDY4NTUzMTcyOAABHoeytsalI3XPr1-qJYix9f4L-B-dqA0Z8Bv_AIjym38ARwCfiWK2uU_LAuqs_aem_DX4YtpBf3p5GjjQ9dc4LBQ

    Hundreds of freedom lovers are rallying behind a US Air Force engineer accused of chopping down over a dozen AI-integrated surveillance cameras last year.

    the destruction of Flock license plate cameras.

    Like AI data centers, they’ve become a hot political issue at the local level, fueling public outrage and organized campaigns from coast to coast.

    There’s also no shortage of citizens who prefer a more direct-action approach. Armed with garbage bags, spray paint, and even chainsaws, a not insignificant number of privacy vigilantes have taken the fight to Flock, using any means to free their neighborhoods of the ominous surveillance poles.

    Sovern kicked off the campaign late in December of 2025, where he encouraged his supporters to “reach out to the local governments and demand that these systems are taken down.”

    Reply
  17. Tomi Engdahl says:

    Massavalvonta
    Europarlamentti antaa alusta­yhtiöille luvan kansalaisten viestien skannaamiseen – näin suomalais­mepit äänestivät
    Europarlamentti hyväksyi lain, joka sallii alustayhtiöiden skannata viestejä.
    Parlamentin puheenjohtaja Roberta Metsola toi maaliskuussa hylätyn esityksen poikkeuksellisella tavalla uuteen äänestykseen.
    Menettely sai kovaa kritiikkiä, ja jäsenmaiden on vielä hyväksyttävä parlamentin vaatimat muutokset.
    https://www.hs.fi/politiikka/art-2000012130814.html?fbclid=IwdGRjcAS9njtleHRuA2FlbQIxMQBzcnRjBmFwcF9pZAwzNTA2ODU1MzE3MjgAAR7t0OYn2t9Rior8MkMXGH4P09la516W30Rkszcg4Mdgx0Px3E9f26a4lySgzw_aem_Q8bOhh5ox28PQAjjI5d74w

    Reply
  18. Tomi Engdahl says:

    Europarlamentti antaa alusta­yhtiöille luvan kansalaisten viestien skannaamiseen – näin suomalais­mepit äänestivät
    Europarlamentti hyväksyi lain, joka sallii alustayhtiöiden skannata viestejä.
    Parlamentin puheenjohtaja Roberta Metsola toi maaliskuussa hylätyn esityksen poikkeuksellisella tavalla uuteen äänestykseen.
    Menettely sai kovaa kritiikkiä, ja jäsenmaiden on vielä hyväksyttävä parlamentin vaatimat muutokset.
    https://www.hs.fi/politiikka/art-2000012130814.html?fbclid=IwdGRjcAS9s2NleHRuA2FlbQIxMQBzcnRjBmFwcF9pZAwzNTA2ODU1MzE3MjgAAR62Q3fPAp1ujlsl9HzB9u0WGa5E-3nVy6RrKzZraCS6hzNL7TQdXenT0uwEpw_aem_VEmao7JgWnzSd5f1XhbFNw

    Reply
  19. Tomi Engdahl says:

    The case is among the first in Japan to involve the use of generative AI as a tool in a cyberattack

    Japanese teen arrested for using ChatGPT to delete 46,000 anime streaming accounts
    Attack triggers mass de-registration of 46,812 accounts on company’s Bandai Channel streaming service
    https://www.independent.co.uk/asia/japan/japanese-teen-chatgpt-anime-berattack-bandai-namco-subsidiary-b3011876.html?fbclid=IwdGRjcAS94BZjbGNrBL3f9mV4dG4DYWVtAjExAHNydGMGYXBwX2lkDDM1MDY4NTUzMTcyOAABHpkw8FAoalHNMoG0XIuFu26Z63nPSAWkgi0THf4L-g7cr6vmFUAqjqxDa9PF_aem_i6J39Mz-IaMM3CIQRW1Bxg

    A 15-year-old boy in Japan has been arrested for using artificial intelligence to help him build a programme that forcibly deleted tens of thousands of accounts on an anime streaming service.

    Police described the incident as a deliberate and persistent cyberattack that forced a month-long service suspension

    The high school student from Tokorozawa, near Tokyo, was accused of fraudulent obstruction of business after sending false commands to the servers of Bandai Namco Filmworks, a subsidiary of Japan’s largest toymaker Bandai Namco Holdings, on 4 November 2025.

    The attack triggered the mass de-registration of 46,812 accounts on the company’s Bandai Channel streaming service without the knowledge or consent of those users, Tokyo’s Metropolitan Police Department said.

    The student admitted to the allegations, telling investigators he had written the initial source code himself before turning to ChatGPT to refine and complete it.

    Reply
  20. Tomi Engdahl says:

    https://www.facebook.com/share/p/18rXShd3Jo/

    “DON’T TRACK ME, BRO…” Exposed without a single login screen, Flock’s AI-powered Condor cameras were broadcasting live footage and full admin controls to anyone who looked, according to an investigation highlighted by the Independent Institute. The organization warned this “unnecessarily exposed Americans’ secretly tracking users‘ sensitive personal data to theft by hackers and foreign spies.” Condor’s own product specifications confirm automated human tracking — the whistleblower’s concern about cameras that follow people is not hypothetical.

    While Flock insists data-sharing decisions belong to local agencies, cities like Santa Cruz and Flagstaff discovered their camera data had already reached federal entities before anyone tightened policies or canceled contracts, per NPR. The officer’s reported experience — professional consequences for speaking up — fits a well-documented pattern of institutional resistance to surveillance app criticism, even if the specific case awaits independent confirmation.

    If your city is among those 5,000-plus jurisdictions, your movements have very likely already been logged. The question worth asking your local officials: do they actually understand what they purchased? For those seeking alternatives, home security systems offer privacy-respecting options that keep data under your own control.

    Reply
  21. Tomi Engdahl says:

    Volt and Salt Typhoon have set up the entire country to be shutdown in the event we go to war with China. This isn’t IF they hack us, they already have, and set the stage.

    https://www.wired.com/story/what-happens-if-china-hacks-the-us-water-supply-war-game-volt-typhoon/

    #2600net #irc #secnews #salt #volt #typhoon #cybersecurity

    Reply
  22. Tomi Engdahl says:

    China offered to help Russia destroy Elon Musk’s Starlink constellation
    Unspecified “low-cost” weapons are being considered.
    Read more
    https://cnews.link/china-russia-starlink/

    Key takeaways:
    China and Russia discussed legal, electronic, cyber, and physical measures targeting SpaceX’s Starlink satellite network.
    The plans appeared in 2023 military forum materials obtained by The Insider, Der Spiegel, and Le Monde.
    Starlink matters because it supports Ukrainian military and civilian communications during Russia’s war in Ukraine.
    The proposals could escalate tensions in orbit and raise risks for global satellite communications and space security.

    Reply
  23. Tomi Engdahl says:

    “More relational work on the ground, not remote drones in the air.” https://trib.al/LePy5xz

    Surveil Me Not
    Americans Are Raging About Autonomous Police Drones Swarming the Skies
    “More relational work on the ground, not remote drones in the air.”
    https://futurism.com/future-society/americans-raging-police-drones?fbclid=IwdGRjcATAvSZjbGNrBMC88WV4dG4DYWVtAjExAHNydGMGYXBwX2lkDDM1MDY4NTUzMTcyOAABHj02NJJWO5HGPw2CmDoxXqNSTh5PiEcsNcB529gG6qb0_idw06jj62YeY8qD_aem_OCRZnW8ZrInSo5gudUhzxA

    There’s a hot new phrase bouncing around police departments across the United States: “drone-as-first-responder.”

    From small-town Indiana to New York City, cops around the country are embracing autonomous surveillance drones as the latest innovation in policing. While you might hear about the occasional puppy found in the woods with a police drone, those feel-good stories provide excellent cover for their true purposes: gathering intelligence on peaceful protests, surveilling minority communities, and intimidating activists.

    Reply
  24. Tomi Engdahl says:

    Confidential computing’s core trust mechanism is broken. The fix may not exist
    Attested TLS: the handshake that can’t prove who’s on the other end
    https://www.theregister.com/security/2026/07/04/confidential-computings-core-trust-mechanism-is-broken-the-fix-may-not-exist/5266056

    Reply
  25. Tomi Engdahl says:

    https://www.iltalehti.fi/digiuutiset/a/3823eb8a-225b-472b-95cc-c3bf564651b6
    Tutkijat järkyttyivät: Tekoäly teki jotain odottamatonta
    Tekoälyn tekemä kuvanparannusohjelma sisälsi haitallista koodia, joka pääsi käsiksi puhelimen kuvakansioon. Tietoja voitaisiin käyttää esimerkiksi kiristämiseen.

    Reply
  26. Tomi Engdahl says:

    “”This contract is not being renewed because of serious concerns around civil liberties and civil rights issues.” https://trib.al/VhLDJcL

    Goose Chase
    LAPD Abandons Flock Contract After Making a Horrifying Discovery
    “This contract is not being renewed because of serious concerns around civil liberties and civil rights issues.”
    https://futurism.com/future-society/lapd-abandons-flock-contract-false-alarm?fbclid=IwdGRjcATC1HljbGNrBMLUaWV4dG4DYWVtAjExAHNydGMGYXBwX2lkDDM1MDY4NTUzMTcyOAABHhIdwlZOh0uDp7Il63m2lUUyKZSpnVc-MdJiErKnevCW1uD7mpBamSkYJb2L_aem_Pqp2s7cvlc7FrvtXDcBuUw

    Reply

Leave a Comment

Your email address will not be published. Required fields are marked *

*

*