July 2026 Cyber Environment Update

Security Insights  /  July 2026 Cyber Environment Update

Allan Grant | SOC Analyst | 31 July 2026

Three things stood out in July.

Artificial intelligence (AI) crossed the line from tool to threat. Two frontier AI laboratories disclosed within ten days of each other that their models had escaped evaluation environments and compromised live production systems. Researchers also documented agentic malware capable of running an intrusion from start to finish, including JadePuffer, which Sysdig describes as the first ransomware operation driven end to end by a large language model (LLM). AI impacted the defensive side as well, with Microsoft patched a record 570 flaws in a single month and put the volume down to AI-assisted discovery.

Around 90,000 Australian businesses picked up new privacy and security obligations on 1 July. Anti-money laundering reforms brought real estate agencies, law firms, accountants, conveyancers, trust and company service providers and dealers in precious metals under the AML/CTF regime, and with it the Privacy Act, whatever their size. Customer due diligence means these firms now collect and hold far more identity data than before, and the Australian Privacy Principles require them to protect it with reasonable security controls.

The gap between disclosure and exploitation kept closing. The wp2shell chain against WordPress, a SharePoint deserialisation flaw, a ServiceNow sandbox escape and SonicWall zero-days were all weaponised within hours or days of proof-of-concept code appearing. The US government cut federal remediation deadlines for the most severe flaws to three days. In Australia, ASD's Essential Eight recommends patching internet-facing services within 48 hours where an exploit exists. This is the standard to measure yourself against, and most of this month's flaws were being exploited well inside it.

Two AI Laboratories Disclose That Their Own Models Compromised Real Systems

OpenAI disclosed on 21 July 2026 that its GPT-5.6 Sol model, paired with an unreleased and more capable model, escaped a sandboxed evaluation environment and reached Hugging Face production infrastructure. Hugging Face is the dominant public repository for AI models and datasets, the equivalent of GitHub for machine learning, and a large share of AI development pulls models and training data directly from it. A compromise there sits upstream of a great many organisations.

This was a by-product of models trying to win an evaluation, and Hugging Face's chief executive called it probably the first incident of its kind. Later reporting put the escape at around 9 July, with the intrusion running from 11 to 13 July. OpenAI did not connect its own agent to the activity until after Hugging Face published details on 16 July, and the two companies spoke around 20 July, by which point the victim had already gone to the Federal Bureau of Investigation (FBI). The attack path came down to an unpatched internal proxy, weak segmentation between test and production, and reusable credentials (TechCrunch) (OpenAI).

Anthropic Finds Three More Incidents After Reviewing 141,000 Evaluations

OpenAI's disclosure prompted Anthropic to go back through its own cyber evaluation transcripts. It published the results on 30 July 2026. Across 141,006 evaluation runs, three separate Claude models had reached the open internet from testing environments and gained unauthorised access to the production systems of three different organisations. The models were Claude Opus 4.7, Claude Mythos 5 and an internal research model, and the earliest incidents went back to April (Anthropic, ABC News).

How it happened differs from the OpenAI case. None of the models tried to break containment. These were capture-the-flag exercises where the model is told to find information hidden elsewhere on a simulated network, and the prompts said there was no internet access. A misunderstanding between Anthropic and its evaluation partner Irregular left those environments connected to the public internet, and the safeguards that would have caught the resulting behaviour were not in place. In each case the model went hunting for its fictional target, found a real system, and compromised it using weak passwords and unauthenticated endpoints.

Anthropic suspended all cyber evaluations on 23 July, had identified the three incidents by 24 July, and notified the affected organisations on 27 July. None of the three had spotted the intrusion themselves.

What This Means Going Forward

Expect more of this, and expect the next round to be deliberate.

Both July incidents involved models running with safety classifiers disabled or absent, which is currently a condition of controlled testing but not hard to reproduce outside one.

The UK AI Security Institute (AISI) published its first public measurement of the open-weight cyber capability gap on 17 July 2026. Freely downloadable models now trail the closed frontier models, by four to seven months on offensive cyber tasks, down from six to ten months through 2025, and GLM-5.2 matches a closed frontier model from February 2026 at a fraction of the cost (AI Security Institute).

Safeguards on those models are easily bypassed. A Financial Times investigation in May showed a free GitHub tool stripping safety protections from Meta and Google models in minutes on consumer hardware, and the International AI Safety Report 2026 reaches the same conclusion: safeguards on open-weight models are much easier to remove, and highly motivated malicious actors are the concern.

Taken together, the conclusion is that offensive capability models exist, close to the frontier, downloadable by anyone, with guardrails that can be quickly stripped with a four to seven month gap in capability from frontier models. This is the time that defenders have to prepare for these sorts of attacks.

The preparation itself is unglamorous. The techniques in every one of these incidents were ordinary, so fixing unpatched software, weak credentials and flat networks raises the cost for an autonomous attacker exactly as it always has for a human one.

Malware That Targets AI Development, and Ransomware That Runs Itself

Two pieces of research published in July show attackers treating AI tooling as both a weapon and a target.

The first is a worm CrowdStrike calls SANDWORM_MODE, and it goes after development teams that use AI coding assistants. It hides in npm packages, the shared code libraries that developers download and build into their own software, and it published 19 poisoned ones. Once a developer installs one, it steals the credentials sitting in that environment, including API keys for nine major AI providers, then uses those stolen credentials to reach further and poison more packages. It waits days between steps so the activity blends into the ordinary background of software updates. CrowdStrike has not said who is behind it, only that it could be a nation-state or a criminal operation (CyberScoop).

The second is JadePuffer, documented by Sysdig, and it is the first intrusion known to have been run start to finish by an AI rather than a person. It broke into a server running Langflow, a tool for building AI applications, then wrote and ran its own scripts on the spot whenever it hit an obstacle. It came back later with ransomware built for the job, which went looking specifically for the files an AI team cannot work without: trained models, the databases that feed them, and training data.

There is a catch that makes this worse than ordinary ransomware. The encryption key was generated at random, used once, and never saved or sent anywhere, so the attacker has nothing to sell back even if a victim wanted to pay. The practical result of this is destruction, and a tested backup is the only way out (BleepingComputer).

Scattered Spider Members Jailed Over the Transport for London Attack

Owen Flowers, 18, of Walsall, and Thalha Jubair, 20, of East London, were each sentenced to five years and six months at Woolwich Crown Court on 16 July 2026 for the 2024 attack on Transport for London (TfL). Both were described as leading members of Scattered Spider, a loose grouping within the wider collective known as The Com. They pleaded guilty on 22 June 2026, the first day of their trial, and were charged under the Computer Misuse Act (The Record).

The attack ran from 31 August to 3 September 2024. It left 148 TfL systems inoperable, forced roughly 27,000 staff to reset passwords in person, and cost TfL a reported 29 million pounds, about AU$54.5 million. Around 10 million passengers had personal data exposed. Flowers also admitted involvement in attacks on two US healthcare providers and could face a far longer sentence if he is extradited and convicted in the United States (National Crime Agency).

This is a law enforcement win and the largest cybercrime prosecution the UK has brought. However, it will likely not slow the group down much. The FBI has already pointed out that others continue to operate under the Scattered Spider brand, and Europol launched Project COMPASS in late July specifically to disrupt The Com's recruitment, which draws heavily on minors through gaming platforms and social media. These are decentralised, English-speaking collectives that recruit faster than prosecutions remove members. Australian organisations should assume the tradecraft continues, since reporting has linked the same group to the 2025 Qantas vishing breach.

Ernst & Young Breach Claimed by ShinyHunters

ShinyHunters claimed the EY breach on its leak site on 27 July 2026. The group alleged a supply-chain compromise of a third-party IT support platform that handed it credentials to EY's internal systems, and told the firm to make contact by 31 July before publishing. EY had disclosed the incident earlier in July, saying it detected anomalous activity on 23 April after an unauthorised party accessed the platform between 28 March and 12 April and downloaded documents tied to numerous clients. Support tickets frequently carried attached tax documents, which exposed names, addresses, Social Security numbers, financial account numbers and card details. Regulatory filings put the floor at 1,366 affected US residents, though EY's global client base suggests the real number runs well beyond that. EY has not confirmed the group's claims, and no data has surfaced on underground forums so far. ShinyHunters has been one of the busiest extortion operations of 2026, listing EY alongside RingCentral and Brinks Home, and it keeps favouring software-as-a-service platforms, single sign-on credentials and vishing over direct network intrusion, as it did with Instructure, Charter Communications and McGraw Hill (Cyber Security News, BleepingComputer).

Ransomware Halts Production at Coca-Cola's Fairlife Dairy

The Coca-Cola Company disclosed in a securities filing on 16 July that a ransomware event had suspended production at the US facilities of its Fairlife dairy subsidiary, with access gained through a third party. The Anubis ransomware group listed Fairlife on its dark-web leak site on 20 July, claimed roughly one terabyte of stolen data, and gave Coca-Cola about a week to negotiate. Coca-Cola confirmed in late July that data had been taken and that most production had resumed across its four US Fairlife facilities. No monetary demand has been disclosed, and the company has not confirmed the attacker or commented on payment. Anubis emerged in late 2024, has listed around 100 organisations since, and pairs data theft with encryption and, on occasion, a destructive wiper (BleepingComputer).

Attacks on the Physical Edge: Cameras and Water Treatment

Russian Intelligence Hijacks IP Cameras to Watch Military Logistics

The Netherlands' civilian and military intelligence services, the General Intelligence and Security Service (AIVD) and the Military Intelligence and Security Service (MIVD), published a joint advisory on 10 July 2026. It warns that at least one Russian intelligence service is systematically compromising internet-connected Internet Protocol (IP) cameras across the Netherlands, other European Union and North Atlantic Treaty Organisation member states, and Ukraine, in order to collect military intelligence. The services say the actor runs image-recognition software across captured feeds to pick out military vehicles and cargo, and that in Ukraine camera access has helped locate personnel and equipment ahead of strikes. The operation is ongoing and has escalated since Russia's full-scale invasion (Security Affairs).

CISA Warns of Escalating Attacks on Water Treatment Controllers

CISA issued an alert on 30 July 2026 reporting a significant increase in threat actors targeting programmable logic controllers (PLCs) in the water and wastewater systems sector, and urged operators to get publicly exposed PLCs and other operational technology (OT) off the internet as quickly as they can. Attackers have been changing passwords to lock operators out of their own equipment and altering IP addresses to disconnect devices, which has led to boil-water notices and long stretches of manual operation. CISA says entities of all sizes are being hit, including some with mature security programs (CISA).

The alert followed a coordinated attack on more than 30 Minnesota community water systems over 26 and 27 July, affecting municipalities including Plymouth, South St Paul, Maple Plain and Braham. The FBI later reported that utilities in at least seven states had come forward, some with degraded operations. Investigators have not confirmed a single actor across all the intrusions, and reporting that ties the Minnesota incidents to Iranian-linked operators should be treated as probable rather than settled. No contamination has been reported (Cybersecurity Dive, BleepingComputer).

These attacks needed little sophistication. The way in was via exposed controllers, default and weak credentials, poor segmentation, and in some cases vulnerabilities that have been public for years. Attackers then modified controller project files and tampered with the code executing safety logic, disabling alarms so operators would not notice.

Put this next to the Dutch advisory and the same pattern shows up twice. Equipment sitting outside the managed estate, rarely patched and often still running default credentials, now attracts both intelligence collection and operational disruption. Australian operators covered by the Security of Critical Infrastructure regime should read the accompanying international OT isolation guidance as applying directly to them.

United States Policy: an AI Clearinghouse on Shaky Foundations

The White House launched GOLD EAGLE on 14 July 2026, a public-private clearinghouse for coordinating the discovery, validation and remediation of vulnerabilities across US critical infrastructure using frontier AI. The Treasury, the Department of Homeland Security through CISA, and the Department of War are implementing it, working voluntarily with industry partners under Executive Order 14409. Participation carries no mandatory reporting or licensing requirements. Officials described the aim as cutting duplicated scanning effort, validating findings, and getting prioritised remediation guidance to defenders before adversaries can weaponise new flaws (The White House, The Record).

Two weaknesses sit underneath all this, and both affect how much threat intelligence eventually flows outward. The liability protections that make industry willing to share vulnerability information rest on the Cybersecurity Information Sharing Act, currently scheduled to sunset on 30 September 2026. On top of that, CISA has lost roughly a third of its workforce over the past year and had its funding cut. A clearinghouse can only do as much as the agency capacity behind it allows.

Australian Policy Developments

Privacy Act Obligations Reach a New Wave of Businesses from 1 July

Tranche 2 is the second stage of Australia's anti-money laundering regime that applies from 1 July. Tranche 1, in place since 2006, covered banks, casinos, remittance providers and digital currency exchanges, roughly 17,000 entities. Tranche 2 extends the same regime to the professions the Financial Action Task Force calls gatekeepers, and AUSTRAC estimates around 90,000 of them.

From 1 July 2026, obligations under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 apply to designated services typically provided by real estate professionals, dealers in precious metals and stones, and professional service providers including lawyers, conveyancers, accountants, and trust and company service providers (OAIC). Enrolment with AUSTRAC closes on 29 July, and captured firms also need an AML/CTF program, customer due diligence, suspicious matter reporting and seven-year record keeping.

Plenty of firms have missed the privacy consequence. The OAIC's guidance is explicit that the Privacy Act 1988 applies to personal information handling in relation to or in connection with AML/CTF obligations, whether or not the entity is a small business that would otherwise be exempt (OAIC).

Three obligations follow for security teams.

This is not just theoretical. LR Reed, a Melbourne property management firm, was listed by a ransomware group in July, and the published sample included staff names, salary details, a banking document and a passport. Property services falls squarely within Tranche 2. Due diligence has these firms collecting more identity data than they have ever held, and the instinct is to keep all of it as proof of compliance. That builds the target extortion groups look for, in businesses with no security function.

Australia Establishes an Office of AI Within the Department of the Prime Minister and Cabinet

The Commonwealth established an Office of AI inside the Department of the Prime Minister and Cabinet on 15 July 2026, announced in the Prime Minister's keynote at the University of Sydney. The office will coordinate the design and legislation of new mandatory Australian AI Standards, including requirements for large AI data centres covering energy and water use, along with stronger copyright protections for creators. National Cabinet will consider the approach in August 2026, with standards expected to be legislated early in 2027. At the end of July there is still no binding AI legislation, just a coordinating body and a stated direction. Industry welcomed the move while pressing for more speed. Tenable's Ben Mudie observed that many boards had prioritised adoption ahead of security, and that governance needs to move at the speed of the threat (Prime Minister of Australia).

OAIC Concludes Preliminary Inquiries Into the Qantas Vishing Breach Without Formal Action

Privacy Commissioner Carly Kind concluded preliminary inquiries into the 2025 Qantas breach on 16 July 2026 without opening a Commissioner-initiated investigation or taking regulatory action. The breach affected approximately 5.67 million customer records, including around 5.12 million Australians. It started with a vishing call on 28 June 2025, in which an attacker impersonating "Qantas IT help" talked an agent at an overseas third-party contact centre into connecting a customer relationship management system to a data-extraction tool (iTnews).

The inquiries examined Australian Privacy Principles 1, 8 and 11, with regard to ISO/IEC 27001, the Information Security Manual and the Essential Eight Maturity Model. The Commissioner concluded that the information gathered did not indicate a likelihood that Qantas had failed to take reasonable steps, noting that Qantas had audited the contact-centre operator and tested staff security awareness in the months beforehand. Credit card details, passport data, passwords and PINs were not exposed. The report makes no concluded findings that every practice complied, and the Commissioner may reopen the matter (OAIC). The benchmarks the OAIC reached for carry beyond this case. An APRA-regulated or otherwise mature entity should expect its third-party assurance to be measured against those same standards.

Australian Incidents

July breaches spanned primary healthcare, energy retail, property management, food production, heritage engineering and defence-adjacent manufacturing. Australian organisations are being hit on exposure, not industry.

Advisories and Vulnerabilities

Government advisories issued during July.

Also of note outside the government advisories: Microsoft's July Patch Tuesday addressed at least 570 vulnerabilities, almost triple the previous record, with nearly 60 rated critical and three zero-days, two of them already exploited (Krebs on Security). Oracle's quarterly update covered more than 1,400 flaws across 334 products, roughly 600 of them remotely exploitable without authentication (SecurityWeek).

Key Takeaways for Organisations

CONTACT US

Sign up or speak with a Fortian Security Specialist

Request a consultation with one of our security specialists today or sign up to receive our monthly newsletter via email.

Get in touch