// daily digest ยท 2026-07-22
Wednesday·22 July 2026

Cyber Digest

A daily roundup of key cybersecurity developments across sectors

20 stories6 sectors6 sourcesGlobal focus

Executive Summary

A busy news cycle driven heavily by AI-security developments: Google DeepMind launched Gemini 3.5 Flash Cyber for AI-assisted vulnerability patching, while new research demonstrated how a poisoned web page could compromise AWS's Kiro coding IDE and how open-source Android AI agent frameworks are vulnerable to invisible-screen-text attacks. On the vulnerability front, CVE-2026-50522 โ€” a critical SharePoint RCE (CVSS 9.8) โ€” is under active exploitation after public PoC release, and CISA has urged SharePoint hardening. The healthcare sector saw Craneware investigating a significant cyberattack impacting a software vendor serving thousands of practices. On the regulatory front, Illinois became the third US state to enact comprehensive AI safety legislation, and the European Commission referred four member states to the CJEU over NIS2 transposition delays.

9
IT / Technology
2
Healthcare
3
Government
4
Legal / Regulatory
1
Energy & Utilities

Incident Map

(static view)
CriticalSevereElevatedGuardeddarker = more incidents
United States
6
China
2
Kenya
1
Spain
1

Pan-regional / not map-pinned: ๐ŸŒ Global: 10

4 countries ยท 20 stories ยท click a country for its stories. Interactive map loads on the hosted site.

๐ŸŽฏ Geo-attribution: 6/20 stories located directly from text (30%). Low-confidence (region-bucket only, check): United States.

๐ŸŽฏ Geo-attribution: 6/20 stories located directly from text (30%). Low-confidence (region-bucket only, check): United States.

IT / Technology 9 stories

1

AWS Kiro Flaw Let a Poisoned Web Page Rewrite Its Config and Run Code

Intezer and Kodem Security found that hidden text on a web page was enough to make AWS's agentic coding IDE, Kiro, rewrite its own MCP configuration file and execute attacker code โ€” bypassing the human approval step entirely. AWS has patched the issue.

The Hacker Newsโ— Tier 2/4 โ€” High2026-07-21
2

Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC

A third SharePoint Server flaw from July Patch Tuesday (CVSS 9.8) is now under active exploitation, per watchTowr. The deserialisation vulnerability allows authenticated Site Owners to execute code remotely. CISA has separately urged organisations to harden SharePoint deployments.

The Hacker Newsโ— Tier 2/4 โ€” High2026-07-21
3

Google Launches Gemini 3.5 Flash Cyber AI to Find and Fix Software Vulnerabilities

DeepMind released Gemini 3.5 Flash Cyber, a specialised AI model for vulnerability discovery, validation, and patching. It will be exclusively available to governments and trusted partners via CodeMender in a limited-access pilot, with red-teaming capabilities planned.

The Hacker Newsโ— Tier 2/4 โ€” High2026-07-21
4

Critical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code Execution

CVE-2026-6875 (CVSS 9.5), a sandbox escape in ServiceNow AI Platform, is being actively exploited in the wild, according to Defused Cyber. ServiceNow released fixes throughout June and is restricting the type of code that can run in sandbox contexts.

The Hacker Newsโ— Tier 2/4 โ€” High2026-07-21
5

Zimbra Patches Critical SNMP Command Injection and Four XSS Vulnerabilities

Zimbra 10.1.20 addresses a critical command injection flaw in the SNMP monitoring component plus four XSS vulnerabilities and a mail forwarding restriction bypass.

The Hacker Newsโ— Tier 2/4 โ€” High2026-07-21
6

New ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attack

Sysdig linked a second attack on the same Langflow server to the JADEPUFFER operator, now deploying ENCFORGE ransomware designed to encrypt model weights, vector indexes, and training datasets. The CVE-2025-3248 Langflow flaw (CVSS 9.8) remains the entry point.

The Hacker Newsโ— Tier 2/4 โ€” High2026-07-21
7

FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware

Island researchers discovered ~7,600 malicious GitHub repositories โ€” over 800 posing as AI skills or MCP servers โ€” delivering the SmartLoader malware, which then pushes StealC infostealer payloads.

The Hacker Newsโ— Tier 2/4 โ€” High2026-07-20
8

Apple Fixes Hide My Email Bug That Exposed Real Addresses in Mail Logs

Apple fixed a flaw in its Hide My Email service that allowed real email addresses behind disposable addresses to be unmasked. The fix was deployed July 3 after more than a year since initial disclosure.

The Hacker Newsโ— Tier 2/4 โ€” High2026-07-21
9

Open-Source Android AI Agents Could Let Invisible Screen Text Run Code on Host PCs

Researchers demonstrated seven attacks against five open-source mobile agent frameworks (AppAgent, AppAgentX, Mobile-Agent-v3, Open-AutoGLM, MobA), showing how invisible on-screen text can slip instructions to AI agents and ultimately run commands on the host PC.

The Hacker Newsโ— Tier 2/4 โ€” High2026-07-21

Healthcare 2 stories

1

Major Healthcare Software Vendor Craneware Investigating Cyberattack

Craneware, a healthcare technology company serving numerous medical practices, confirmed it is investigating a cybersecurity incident and acknowledged that a significant amount of data was compromised.

HIPAA Journalโ— Tier 2/4 โ€” High2026-07-21
2

Abbott Investigating Cyberattack Claims From Two Threat Actors

Healthcare giant Abbott is investigating claims from two threat groups alleging cyberattacks and data theft, including one involving legacy systems.

HIPAA Journalโ— Tier 2/4 โ€” High2026-07-20

Government 3 stories

1

Kenya Probes Hack of President's Website After Bitcoin Ransom Demand

Kenya's government is investigating a breach of the president's official website following a bitcoin ransom demand. The incident raises concerns about state digital infrastructure security in East Africa.

The Recordโ— Tier 2/4 โ€” High2026-07-21
2

DNI Nominee Clayton Wins Senate Panel's Approval

Jay Clayton, the nominee for Director of National Intelligence, secured approval from the Senate Intelligence Committee, advancing his nomination to the full Senate.

The Recordโ— Tier 2/4 โ€” High2026-07-21
3

Taiwan to Slow Mobile Data During National Resilience Drills

Taiwan will throttle mobile data speeds during upcoming national resilience drills as part of cyber and communications preparedness exercises amid ongoing geopolitical tensions.

The Recordโ— Tier 2/4 โ€” High2026-07-21

Energy & Utilities 1 story

1

New Bit2Watt Attack Could Let Cloud Tenants Disrupt Power Grids Without an Exploit

Zhejiang University researchers demonstrated that a cloud tenant using ordinary GPU access can push a data centre's power draw up and down to destabilise the grid โ€” requiring no exploit or system compromise, just a misbehaving workload.

The Hacker Newsโ— Tier 2/4 โ€” High2026-07-21

Defence 1 story

1

Apps Marketed to US Troops Are Shipping Chinese and Russian Code

Wired reports that mobile applications marketed to US military personnel contain embedded code from Chinese and Russian software libraries, raising supply chain and espionage concerns.

Wiredโ— Tier 3/4 โ€” Moderate2026-07-22

Analytics

Sector distribution

IT / Technology
9
Healthcare
2
Government
3
Legal / Regulatory
4
Energy & Utilities
1
Defence
1

Source breakdown

The Hacker News
10
The Record
4
HIPAA Journal
2
Hunton Andrews Kurth Privacy & Cybersecurity Blog
2
WilmerHale Privacy and Cybersecurity Law Blog
1
Wired
1
20stories
IT / Technology 9
Healthcare 2
Government 3
Legal / Regulatory 4
Energy & Utilities 1
Defence 1

Source Reliability Index

TierLabelDescription
โ— Tier 1Very HighOfficial / first-party
โ— Tier 2HighEstablished cyber journalism
โ— Tier 3ModerateGeneral tech/news media
โ— Tier 4LowSocial / unverified