2026.07.21 News You Should Know

- 6 mins read

Series: News You Should Know 2026

Microsoft

Windows 0-day drops the same day Microsoft releases record number of patches - Ars Technica - In a post, he said that “the ability of a non-admin user to be able to modify the classes registry hive of an admin user is a pretty powerful primitive. Clever attackers or people who want to accomplish something will easily be able to figure out how to do things that are more interesting and/or don’t even require user interaction.” Additional Reading: Microsoft’s serial tormentor drops LegacyHive 0-day

Microsoft 365 calendars become spy drop boxes in HOLLOWGRAPH campaign - Every event created by HOLLOWGRAPH is dated May 13, 2050, an otherwise empty corner of the diary where encrypted attachments are less likely to attract attention. Instead of reaching out to attacker-controlled infrastructure for instructions, the implant rummages through calendar events, picks up encrypted tasking, and drops stolen files into new appointments for its operators to collect later.

Microsoft’s Secure Boot has been broken for a decade and no one noticed until now - Ars Technica - The threat extends to Windows and Linux users alike, since the shim can be installed on devices running both operating systems. From there, an attacker can subvert the mandated chain of digitally signed firmware to install malicious firmware that loads early in the boot process and persists after either the OS is reinstalled or a hard drive is replaced.

Hugging Face

Hugging Face confirms breach affected internal datasets and credentials, urges users to take action | TechCrunch -Hugging Face blamed the breach on an external AI agent, which executed “many thousands of individual actions across a swarm of short-lived sandboxes, with self-migrating command-and-control staged on public services.”

Frontier LLMs couldn’t help Hugging Face fight off evil agents - Additionally, after unsuccessfully using unnamed frontier models to start the forensic analysis, the Hugging Face security team ultimately ran the log analysis on GLM 5.2, an open-weight model developed by Chinese AI firm Z.ai, on the platform’s own infrastructure.

AI

OpenAI admits GPT-5.6 occasionally deletes files – but it’s an ‘honest mistake’ - OpenAI has confirmed reports that GPT-5.6 has deleted users’ files without authorization but insists these rare erasures represent an “honest mistake.” “The model attempts to override the $HOME env var to define a temporary directory,” said Sottiaux. “The model makes an honest mistake and mistakenly deletes $HOME instead.”

Open-Source Android AI Agents Could Let Invisible Screen Text Run Code on Host PCs - An Android app that can draw over other windows and write to shared storage can slip instructions to the AI agent driving that phone, in text no human eye will ever see. Two more steps, and the same app is running commands on the PC driving the agent.

Cursor Flaw Lets Malicious Cloned Repositories Trigger Windows Code Execution - Open a repository in Cursor on Windows and, if a file named git.exe is sitting in the project root, Cursor runs it. No click, no approval dialog, no warning that anything in the folder is about to execute. No prompt injection, no agent, no model in the loop, and no prior access to the machine: opening the folder is the entire exploit, and the result is arbitrary code execution as the logged-in user. AI security firm Mindgard reported the flaw to Cursor on December 15, 2025. There is still no patch, and Cursor has published no advisory for the issue.

AI Companies Are Buying Tons of Old Books Because They’re Free of AI Slop - As AI companies search for more training data to improve their models, one company is offering old, printed books as an ideal source because they are guaranteed to be free of the very AI slop AI companies are producing.

Bit2Watt

New Bit2Watt Attack Could Let Cloud Tenants Disrupt Power Grids Without an Exploit - That is the claim behind Bit2Watt, described by three Zhejiang University researchers in a paper accepted to CHES 2026, the IACR’s hardware-security conference, and the evidence splits in two: they measured the power modulation on real GPUs and simulated the grid destabilization it could cause. The technique inverts the usual grid-attack model: no compromised sensors, no malware on control systems, no stolen operator credentials, just a workload built to misbehave on purpose.

(1037) Staged cyber attack reveals vulnerability in power grid - YouTube - 2007 Boise National Lab

Errata

Iran abused mobile networks’ vulnerabilities to locate US military in the Middle East, report says | TechCrunch - The Iranian government exploited Signaling System 7, or SS7, a set of protocols for 2G and 3G networks that has long been the backbone of how cellular networks connect to each other to route subscribers’ calls and texts around the world, the newspaper reported, citing research by the Mobile Surveillance Monitor, as well as anonymous government officials with knowledge of the spy campaign. Apart from SS7, Iran also abused advertising technology used to serve tailored ads to cellphone users, another well-known surveillance technique that relies on everyday technology.

Tech support scam caused massive data breach at Australian airline Qantas - Qantas has previously admitted the incident was the result of a social engineering attack on a contact center. The Commissioner’s report goes deeper, explaining a crook who claimed to represent “Qantas IT help” made the call and told a contact center agent to access a CRM system and perform certain actions needed to close a support ticket. Those actions instead connected the CRM to a data extraction tool which the crooks used to siphon off customer records.

BUT

Australia’s Privacy Commissioner has revealed a tech support scam was the cause of the massive 2025 data breach at Australian airline Qantas and found the carrier didn’t breach its privacy obligations despite leaking personally identifiable information for 5.7 million customers.

Zoom Patches Critical Windows Flaw That Could Enable Account Takeover - “Improper Input Validation in Zoom Desktop Client for Windows and Zoom VDI Client for Windows may allow an unauthenticated user to conduct an account takeover via network access,” Zoom said in an advisory released this week.

New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code - An anonymous HTTP request can run code on a WordPress site. The bug is in core, so a bare install with zero plugins is exploitable. Every 6.9 and 7.0 site was in range until Friday, when WordPress shipped 6.9.5 and 7.0.2 and enabled what it calls forced updates through its auto-update system.

SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines - “Each malicious release is a loader,” StepSecurity said in an analysis. “It fetches a second stage from an attacker controlled Forgejo host, checks whether it is running in a build system and skips if it is, and on a developer machine it drops a native daemon and installs persistence.”

I’m an experienced home cook, security engineer, people leader, and dedicated father and husband. I can be found on Mastodon at @IAintShootinMis@DigitalDarkAge.cc and on Signal at DigitalDarkAge.98. An RSS Feed of this blog is available here and a copy of my current OPML file is here.