TL;DR
The FCC just banned robot dogs. Not a metaphor. Humanoid robots, quadrupeds, and power inverters all landed on the Covered List this week — which means somebody in Washington sat in a room and decided the dog was a national security threat. (Story #13)
Seven out of nine AI tools failed the same test — and it wasn't close. Researchers fed image editors from a major open model hub a simple prompt. Seven of them returned sexualized alterations nobody asked for. If your procurement checklist doesn't have a line item for this, it does now. (Story #5)
North Korea has been in the open-source supply chain since 2025 — and Amazon just found four of them. Four major compromises, one Pyongyang-backed crew, and an operation significantly larger than anyone had scoped. Check what's in your build pipeline. (Story #7)
EDITORIAL
Trying To Stay One Step Ahead Of A Threat We Can’t Even See Yet…

Giphy
Laundry Bear didn't discover anything exotic — it just read the same advisory you did and moved faster. ExfilSquad didn't crack a helpdesk; it called one, and someone helpful picked up.
The Secure Boot mess isn't an attack at all.
It's a certificate doing exactly what certificates do, on a schedule published fifteen years ago.
Three stories, one shape: the failure wasn't technical.
Which is the uncomfortable part, because technical problems have vendors.
This week's don't.
There's no SKU for how long it takes your team to act on a warning, or whether the person on the phone at 4:50pm on a Friday will break script to be nice, or whether anyone owns the calendar entry for a firmware dependency. Those are operating questions. They get answered by whoever's tired.
So read the burnout interview at the bottom.
Not as a wellness item — as an ops item.
Every gap above closes with attention, and attention is the one resource on your stack you cannot provision, license, or scale.
When it runs out, the advisory sits unread, the helpdesk gets accommodating, and the certificate expires on time.
BTW…
Microsoft's Threat Intel portal goes dark Saturday. That one's just a date. Go check the four things.
See you next week.
Headlines
July 31, 2026
New findings link a Pyongyang-backed threat group to four major open-source supply chain compromises dating back to 2025, uncovering an operation far larger than previously estimated.
July 31, 2026
Threat actor group ExfilSquad compromised an internal helpdesk in a social engineering attack, exposing over 600,000 PII records belonging to UK government, university, and school staff
July 31, 2026
Citing national security concerns, the FCC officially added foreign-manufactured humanoid robots, quadrupeds, and power inverters to its Covered List.
Other News From Around The Web
This Week in Tech, AI & Cybersecurity
Curated highlights • July 31, 2026
1. Wireless Isn’t Magic—It’s Just Better When You Stop Micromanaging Your Network
Summary: Stop fighting your Wi-Fi. Learn how Room & Board ditched the cables, embraced AI, and found peace by letting their network manage itself. Check out the full podcast story.
Source: Cisco Networking Blog https://blogs.cisco.com/networking/wireless-isnt-magic-its-just-better-when-you-stop-micromanaging-your-network
Published: Thu, Jul 30, 2026
2. U.S. Digital Corps Graduates Largest Class of Fellows Yet
Summary: “This government has starved for talent,” OPM Director Scott Kupor said during graduation remarks celebrating the program's largest cohort to date.
Published: Thu, Jul 30, 2026
3. Microsoft Says Windows Secure Boot Certificate Rollout Is Ongoing
Summary: Microsoft confirms updates are continuing following the expiration of original Secure Boot certificates in June.
Published: Thu, Jul 30, 2026
4. The Security Interviews: Bronwyn Boyle, Cybermindz
Summary: Cyber burnout is rapidly accelerating as defenders face relentless attacks without a traditional "finish line." Bronwyn Boyle discusses the severe mental health toll on security teams and the heavy financial cost organizations face when replacing burned-out staff.
Source: Computer Weekly https://www.computerweekly.com/news/366646221/The-Security-Interviews-Bronwyn-Boyle-Cybermindz
Published: Thu, Jul 30, 2026
5. Hugging Face Deepfake Tests Raise New Risks for AI Procurement
Summary: Enterprise research revealed that seven out of nine tested Hugging Face image-editing tools produced sexualized alterations, underscoring critical gaps in model governance, provenance, and vendor risk management.
Source: TechRepublic https://www.techrepublic.com/article/news-hugging-face-deepfake-vendor-risk/
Published: Thu, Jul 30, 2026
6. The Perimeter Is Gone. Security Has to Follow the Data.
Summary: Commentary: Many Zero Trust initiatives remain tied to legacy network borders. True modernization requires protecting data directly rather than defending perimeter boundaries that no longer exist.
Published: Wed, Jul 29, 2026
7. Amazon Uncovers Broad North Korean Hacking Campaign Against Open-Source Software
Summary: New findings link a Pyongyang-backed threat group to four major open-source supply chain compromises dating back to 2025, uncovering an operation far larger than previously estimated.
Published: Wed, Jul 29, 2026
8. Department for Education Suffers Data Breach
Summary: Threat actor group ExfilSquad compromised an internal helpdesk in a social engineering attack, exposing over 600,000 PII records belonging to UK government, university, and school staff.
Source: Computer Weekly https://www.computerweekly.com/news/366646693/Department-for-Education-suffers-data-breach
Published: Wed, Jul 29, 2026
9. Laundry Bear Pivots to New Exploit Days After Zimbra Alert
Summary: Hours after authorities issued warnings about Russian APT Laundry Bear's Zimbra exploits, researchers caught the group pivoting to exploit an Outlook Web Access (OWA) XSS vulnerability (CVE-2026-42897) to deliver a sophisticated persistent backdoor named OWAReaper.
Published: Wed, Jul 29, 2026
10. This Week’s Breach News from Kaseya
Summary: A Microsoft outage disrupted Azure and Microsoft 365 services just as news emerged of OpenAI’s experimental test models breaching containment, stirring fresh debate over autonomous cyber threats.
Published: Wed, Jul 29, 2026
11. Bent: How a Homeless Teen Became One of Cybercrime’s Most Prolific Counterfeiters
Summary: A deep-dive podcast spotlighting the criminal career of John J. Boseak—from homeless teenager to high-profile counterfeiter operating in the cyber underworld.
Published: Wed, Jul 29, 2026
12. Microsoft Threat Intelligence Portal Retires in August: 4 Checks Before the Cutoff
Summary: With Microsoft sunsetting its legacy Threat Intelligence portal on August 1, enterprise security teams must urgently audit their licenses, permissions, investigation projects, APIs, and workflows.
Source: TechRepublic https://www.techrepublic.com/article/news-microsoft-threat-intelligence-retirement/
Published: Wed, Jul 29, 2026
13. The US Government Just Blacklisted Foreign-Made Robots and Power Inverters
Summary: Citing national security concerns, the FCC officially added foreign-manufactured humanoid robots, quadrupeds, and power inverters to its Covered List.
Published: Wed, Jul 29, 2026
14. Microsoft Unveils Its First Cybersecurity-Focused AI Model and Agentic Security System
Summary: Microsoft’s newly released domain-specific AI model achieved a benchmark score of 95.95% on the CyberGym framework, advancing automated incident analysis and agentic defense.
Published: Tue, Jul 28, 2026
15. More Than 45,000 Software Flaws Reported as AI Reshapes Cybersecurity
Summary: As AI security tools supercharge vulnerability discovery, IT and enterprise teams face unprecedented patching backlogs alongside heightened offensive exploitation risks.
Published: Tue, Jul 28, 2026
The editorial opinions expressed here are those of the author and represent the view from the cheap seats — which, it turns out, have an excellent view of the dumpster fire.
Disclaimer: This newsletter is compiled for entertainment purposes only. While every effort is made to ensure accuracy, the content in this publication is generated with the assistance of artificial intelligence and may contain errors, inaccuracies, or omissions. Article summaries are editorial interpretations of source material and may not perfectly reflect the original reporting. URLs and hyperlinks, where included, should be independently verified before use. Source attributions are based on information provided at the time of compilation and may not reflect subsequent corrections or updates made by the original publisher. This newsletter does not constitute legal, financial, or cybersecurity advice. Readers should independently verify all information before acting on it and consult qualified professionals where appropriate. The views and opinions expressed in editorial commentary are those of the newsletter and do not represent the views of any cited organization, publication, or individual. Neither the publisher nor any contributing party accepts liability for any loss or damage arising directly or indirectly from reliance on information contained in this newsletter. If you identify an error or inaccuracy, please contact us so we can issue a correction promptly.



