< back to blog

Security briefing: July 2026

Crystal Morin
Security briefing: July 2026
Published by:
Crystal Morin
Security briefing: July 2026
Sr. Cybersecurity Strategist
@
Security briefing: July 2026
Published:
August 4, 2026
falco feeds by sysdig

Falco Feeds extends the power of Falco by giving open source-focused companies access to expert-written rules that are continuously updated as new threats are discovered.

learn more
Green background with a circular icon on the left and three bullet points listing: Automatically detect threats, Eliminate rule maintenance, Stay compliant, with three black and white cursor arrows pointing at the text.

When the whole world shows up

Every four years, the world comes together. It doesn’t matter if you actually like soccer, or football, or whatever you want to call it; you plant yourself in front of the TV anyway because that’s what everyone else is doing. I know almost nothing about the sport but I still watched nearly every game. For a few weeks, everything that keeps us apart gets put on pause, and the whole planet agrees to care about the same ball for 90 minutes at a time.

The security world needs to behave more like FIFA season, but every single day.  While the world united around a tournament, the threats in July didn’t take a break. An AI model went rogue, ransomware dropped a new playbook, and the US government stood up a new body to referee the threat landscape.  

If FIFA can get the whole world to show up for the same 90 minutes, security should be able to get an industry to show up for the same fight.

Here’s what happened last month:

July 1: JADEPUFFER drops an agentic ransomware operation

  • The Sysdig Threat Research Team (TRT) documented the first agentic threat actor (ATA) to run a complete extortion operation with no human at the keyboard. 
  • JADEPUFFER’s payloads are self-narrating, a telltale sign of LLM-generated code with natural language reasoning and target-prioritization breadcrumbs that humans wouldn’t normally code in.
  • When it hit a failed login, it refined the code and retried the steps within 31 seconds. 
  • The targeted production database was destroyed, but there was no indication the data was exfiltrated as the ransom note suggested. The encryption key was also ephemeral and never stored, so payment couldn’t recover it. Also, the Bitcoin address matched a well-known documentation example, so it may have been hallucinated.
  • Although this ransom operation had its flaws, it moved fast and proved that it no longer takes a skilled operator to run an attack.

July 14: White House launches GOLD EAGLE

  • On June 2, 2026, Executive Order 14409 established GOLD EAGLE, a new federal clearinghouse for vulnerability coordination. 
  • It consists of Treasury, DHS/CISA, and the Department of War working with the cybersecurity industry to intake, prioritize, and coordinate vulnerability patching faster than the current model of doing so with one agency at a time.

July 16: Hugging Face disclosed ATA breach

  • Over the course of a weekend, Hugging Face discovered an intrusion in their production infrastructure using AI-assisted detection — an anomaly-detection pipeline with LLM-based triage to separate real signals from noise. 
  • They collected more than 17,000 recorded events and reconstructed the attack using LLM-driven analysis agents. 
  • Only the attacking agents didn’t have malicious intent, per se. According to researchers, these were agents belonging to OpenAI with their safeguards intentionally reduced, and they escaped their sandbox and broke into Hugging Face’s infrastructure to steal the answers to the test they were being evaluated on. 
  • Now Hugging Face and OpenAI are working together to improve detection and response in the age of ATAs and improve safety and guardrails when deploying AI models.

Additional Sysdig TRT findings

Azure permission takeover

  • On July 14, the Sysdig TRT reported an attack that started with one service-principal credential and ended with tenant takeover. 
  • The attacker was able to move through five different, disconnected Azure permission systems — Entra directory roles, Azure RBAC, Key Vault access policies, bearer keys, and Graph API application permissions — and went from unauthenticated to tenant owner in about one hour. 
  • You cannot change the fragmented permission model, but you can be proactive. Turn on the diagnostic logging, which is off by default, and watch the bridges between the five planes, especially elevateAccess.

Ransomware built to target AI/ML infrastructure

  • Three weeks after the Sysdig TRT first reported on JADEPUFFER, they released a second blog on the operator.
  • JADEPUFFER launched ENCFORGE against a target: a purpose-built Go ransomware binary targeting 180 files, including model checkpoints, vector databases, and training data. 
  • Standard business files come back from a backup, but many organizations are not backing up production models the same way. Once a model is destroyed, rebuilding one costs $75,000 to $500,000 per model. 

Also in the news

  • FastJson, the open source Java library, had a zero-day remote code execution vulnerability (CVE-2026-16723) first seen actively exploited in the US on July 20. Many business sectors were being targeted, and no fix was available for the affected versions 1.2.68 through 1.2.83 until July 29. Vulnerable organizations should patch immediately and hunt for the two known malicious strings: @type":"jar:file: or @type":"jar:http:.
  • Abbott Laboratories stated on July 16 that its Cancer Diagnostics business and LabCentral customer portal were compromised. ShinyHunters and ShadowByt3$ are claiming responsibility. ShinyHunters gained access through a voice phishing campaign that compromised a corporate Microsoft Entra SSO account, and stole tens of millions of records.
  • Accenture, a consulting firm that serves the Fortune 500, was breached in early July by a threat actor called “888.” The attacker claims to have stolen 35 GB of source code, Azure personal access tokens, RSA keys, and SSH keys, but the means of initial access are unknown. If the claims are legitimate, stolen source code could have serious downstream consequences on Accenture clients. 
  • Fairlife, the Coca-Cola-owned dairy subsidiary, halted US production for 11 days after a ransomware attack on July 16. The Anubis ransomware-as-a-service gang claimed responsibility and said they stole one TB of data. Unverified reporting points to CitrixBleed 2 as the mechanism for initial access. 

Closing thoughts

Historically, security hasn’t gotten the same global consensus as FIFA. It’s possible that in July, agentic threats like JADEPUFFER and the Hugging Face incident were the triggers that might finally bring the industry together. GOLD EAGLE is an early sign of what that could look like: government, industry, and defenders agreeing to coordinate faster instead of patching one agency at a time. Whether this collaboration holds will be the real test.

About the author

Cloud Security
Security for AI
featured resources

Test drive the right way to defend the cloud
with a security expert