TL;DR

  • The FCC just banned robot dogs. Not a metaphor. Humanoid robots, quadrupeds, and power inverters all landed on the Covered List this week — which means somebody in Washington sat in a room and decided the dog was a national security threat. (Story #13)

  • Seven out of nine AI tools failed the same test — and it wasn't close. Researchers fed image editors from a major open model hub a simple prompt. Seven of them returned sexualized alterations nobody asked for. If your procurement checklist doesn't have a line item for this, it does now. (Story #5)

  • North Korea has been in the open-source supply chain since 2025 — and Amazon just found four of them. Four major compromises, one Pyongyang-backed crew, and an operation significantly larger than anyone had scoped. Check what's in your build pipeline. (Story #7)

EDITORIAL

Trying To Stay One Step Ahead Of A Threat We Can’t Even See Yet…

hacker GIF

Giphy

Laundry Bear didn't discover anything exotic — it just read the same advisory you did and moved faster. ExfilSquad didn't crack a helpdesk; it called one, and someone helpful picked up.

The Secure Boot mess isn't an attack at all.

It's a certificate doing exactly what certificates do, on a schedule published fifteen years ago.

Three stories, one shape: the failure wasn't technical.

Which is the uncomfortable part, because technical problems have vendors.

This week's don't.

There's no SKU for how long it takes your team to act on a warning, or whether the person on the phone at 4:50pm on a Friday will break script to be nice, or whether anyone owns the calendar entry for a firmware dependency. Those are operating questions. They get answered by whoever's tired.

So read the burnout interview at the bottom.

Not as a wellness item — as an ops item.

Every gap above closes with attention, and attention is the one resource on your stack you cannot provision, license, or scale.

When it runs out, the advisory sits unread, the helpdesk gets accommodating, and the certificate expires on time.

BTW…

Microsoft's Threat Intel portal goes dark Saturday. That one's just a date. Go check the four things.

See you next week.

Headlines

July 31, 2026

New findings link a Pyongyang-backed threat group to four major open-source supply chain compromises dating back to 2025, uncovering an operation far larger than previously estimated.

July 31, 2026

Threat actor group ExfilSquad compromised an internal helpdesk in a social engineering attack, exposing over 600,000 PII records belonging to UK government, university, and school staff

July 31, 2026

Citing national security concerns, the FCC officially added foreign-manufactured humanoid robots, quadrupeds, and power inverters to its Covered List.

Other News From Around The Web

This Week in Tech, AI & Cybersecurity
Curated highlights • July 31, 2026

1. Wireless Isn’t Magic—It’s Just Better When You Stop Micromanaging Your Network

Summary: Stop fighting your Wi-Fi. Learn how Room & Board ditched the cables, embraced AI, and found peace by letting their network manage itself. Check out the full podcast story.

2. U.S. Digital Corps Graduates Largest Class of Fellows Yet

Summary: “This government has starved for talent,” OPM Director Scott Kupor said during graduation remarks celebrating the program's largest cohort to date.

3. Microsoft Says Windows Secure Boot Certificate Rollout Is Ongoing

Summary: Microsoft confirms updates are continuing following the expiration of original Secure Boot certificates in June.

4. The Security Interviews: Bronwyn Boyle, Cybermindz

Summary: Cyber burnout is rapidly accelerating as defenders face relentless attacks without a traditional "finish line." Bronwyn Boyle discusses the severe mental health toll on security teams and the heavy financial cost organizations face when replacing burned-out staff.

5. Hugging Face Deepfake Tests Raise New Risks for AI Procurement

Summary: Enterprise research revealed that seven out of nine tested Hugging Face image-editing tools produced sexualized alterations, underscoring critical gaps in model governance, provenance, and vendor risk management.

6. The Perimeter Is Gone. Security Has to Follow the Data.

Summary: Commentary: Many Zero Trust initiatives remain tied to legacy network borders. True modernization requires protecting data directly rather than defending perimeter boundaries that no longer exist.

7. Amazon Uncovers Broad North Korean Hacking Campaign Against Open-Source Software

Summary: New findings link a Pyongyang-backed threat group to four major open-source supply chain compromises dating back to 2025, uncovering an operation far larger than previously estimated.

8. Department for Education Suffers Data Breach

Summary: Threat actor group ExfilSquad compromised an internal helpdesk in a social engineering attack, exposing over 600,000 PII records belonging to UK government, university, and school staff.

9. Laundry Bear Pivots to New Exploit Days After Zimbra Alert

Summary: Hours after authorities issued warnings about Russian APT Laundry Bear's Zimbra exploits, researchers caught the group pivoting to exploit an Outlook Web Access (OWA) XSS vulnerability (CVE-2026-42897) to deliver a sophisticated persistent backdoor named OWAReaper.

10. This Week’s Breach News from Kaseya

Summary: A Microsoft outage disrupted Azure and Microsoft 365 services just as news emerged of OpenAI’s experimental test models breaching containment, stirring fresh debate over autonomous cyber threats.

11. Bent: How a Homeless Teen Became One of Cybercrime’s Most Prolific Counterfeiters

Summary: A deep-dive podcast spotlighting the criminal career of John J. Boseak—from homeless teenager to high-profile counterfeiter operating in the cyber underworld.

12. Microsoft Threat Intelligence Portal Retires in August: 4 Checks Before the Cutoff

Summary: With Microsoft sunsetting its legacy Threat Intelligence portal on August 1, enterprise security teams must urgently audit their licenses, permissions, investigation projects, APIs, and workflows.

13. The US Government Just Blacklisted Foreign-Made Robots and Power Inverters

Summary: Citing national security concerns, the FCC officially added foreign-manufactured humanoid robots, quadrupeds, and power inverters to its Covered List.

14. Microsoft Unveils Its First Cybersecurity-Focused AI Model and Agentic Security System

Summary: Microsoft’s newly released domain-specific AI model achieved a benchmark score of 95.95% on the CyberGym framework, advancing automated incident analysis and agentic defense.

15. More Than 45,000 Software Flaws Reported as AI Reshapes Cybersecurity

Summary: As AI security tools supercharge vulnerability discovery, IT and enterprise teams face unprecedented patching backlogs alongside heightened offensive exploitation risks.

The editorial opinions expressed here are those of the author and represent the view from the cheap seats — which, it turns out, have an excellent view of the dumpster fire.

Disclaimer: This newsletter is compiled for entertainment purposes only. While every effort is made to ensure accuracy, the content in this publication is generated with the assistance of artificial intelligence and may contain errors, inaccuracies, or omissions. Article summaries are editorial interpretations of source material and may not perfectly reflect the original reporting. URLs and hyperlinks, where included, should be independently verified before use. Source attributions are based on information provided at the time of compilation and may not reflect subsequent corrections or updates made by the original publisher. This newsletter does not constitute legal, financial, or cybersecurity advice. Readers should independently verify all information before acting on it and consult qualified professionals where appropriate. The views and opinions expressed in editorial commentary are those of the newsletter and do not represent the views of any cited organization, publication, or individual. Neither the publisher nor any contributing party accepts liability for any loss or damage arising directly or indirectly from reliance on information contained in this newsletter. If you identify an error or inaccuracy, please contact us so we can issue a correction promptly.

Recommended for you

View all
caret-right