In partnership with

~7 MIN READ
Fact Ransomware is fragmenting, not shrinking: 93 new ransomware variants emerged in 2025, a 94% jump from 2024, even as total ransomware payments fell from $1.9 billion to $1.3 billion over the same period. More gangs, smaller paydays. (Industry ransomware tracking research via The Record, April 2026)
The Signal
 
Nothing in this edition is the biggest breach of the year. What it is: a hospital billing vendor, a dev-tool backdoor, a fake IT helpdesk, and an AI agent that broke into a company on its own, none of them enormous alone, all of them proof the attack surface keeps getting weirder in the same direction. Buckle in.

This week wasn't about one big headline, it was about how many different doors attackers are trying now: enterprise software, open source packages, passkey enrollment, and, for the first time in a documented way, an AI agent acting on its own. Here's what happened, what's still unresolved, and one deadline worth checking today.

PS: Was this forwarded to you? Subscribe free at exzeccyber.com/subscribe

In this edition
  📌 Big Cyber News
  🚨 Can't Miss
  🤖 AI in Cyber
  🏛️ Privacy, Power & Policy
  🛠️ Tools & Tactics
  🧪 Strange Cyber
📌 Big Cyber News
 
ACTIVE EXPLOITATION
🔓 ServiceNow's AI Platform Has a 9.5-Severity Hole, and Attackers Keep Finding New Ways Through It
Intro
ServiceNow runs the IT and HR backbone of a huge share of the Fortune 500, and right now it has a hole attackers are actively climbing through.
What Happened
CVE-2026-6875 is an unauthenticated code-injection flaw in ServiceNow's AI Platform, CVSS 9.5, that lets an attacker escape the platform's script sandbox and execute code remotely. It was publicly disclosed July 13. By July 20, a threat intelligence firm confirmed active in-the-wild exploitation, using a different sandbox-escape technique than the one in the original proof-of-concept.
Why It's Important
Defenses tuned to the published exploit are already being bypassed by a second method, which means patching alone isn't the finish line here.
The Other Side
ServiceNow pushed the fix fast, hosted instances were patched same-week, and self-hosted customers have had access to the update since the disclosure.
 
👉 Takeaway
If you run ServiceNow and haven't confirmed this patch is live everywhere, including self-hosted instances, do that today, not this week.
TL;DR: A 9.5-severity ServiceNow flaw is being actively exploited through multiple methods, one week after disclosure.
Further reading: Help Net Security
🚨 Can't Miss
 
 
DATA BREACH
Craneware, whose billing software underpins pricing and revenue operations at more than 2,000 US hospitals and 10,000 clinics and pharmacies, confirmed attackers exfiltrated employee data and a subset of customer records. Operations weren't disrupted, and whether patient data was touched is still being determined. A reminder that the scariest healthcare breaches aren't at the hospital, they're at the vendor nobody outside billing has heard of.
Ask your healthcare vendors who their vendors are. This is where breaches actually start.
 
SUPPLY CHAIN
Attackers used a GitHub Actions misconfiguration and a flood of decoy pull requests to sneak malicious code into four AsyncAPI npm packages pulling 2.25 million weekly downloads. The payload steals credentials, poisons AI coding tools, spreads worm-style, and phones home over six channels at once, including IPFS, BitTorrent, and Ethereum. Malicious versions are pulled, but if your project touched these packages, rotate credentials now.
Supply-chain attacks are getting more resilient by design. Assume compromise, don't just assume patched.
 
SOCIAL ENGINEERING
An extortion group is cold-calling employees across six industries, posing as internal IT support, and walking targets through what looks like routine Microsoft passkey enrollment, while quietly registering the attacker's own passkey for permanent access. Passkeys are supposed to be the phishing-resistant answer, this campaign specifically targets the enrollment step instead of the login.
Train employees that "IT" asking you to enroll a new passkey over the phone is a red flag, not a routine request.

Live webinar, July 22: see how native SSP automation runs on real billing data — audit-ready under ASC 606, no spreadsheets required. Save your spot.

🤖 AI in Cyber
 
 
AI OFFENSE
An attacker deployed an autonomous AI agent that independently exploited two code-execution flaws in Hugging Face's dataset pipeline, escalated its own privileges, moved across internal systems, and stole credentials, logging over 17,000 actions with minimal human direction. Hugging Face says no public models were tampered with, and is still investigating impact to partner data. This isn't AI assisting an attacker anymore, it's AI running the operation.
If your threat model still assumes a human is pacing every step of an attack, it's already out of date.
🏛️ Privacy, Power & Policy
 
 
FTC ENFORCEMENT
RentGrow will pay $2.25 million to settle FTC allegations that it let duplicate criminal and eviction entries appear on tenant screening reports and mishandled consumer disputes about their own records. A wrong line on one of these reports can cost someone an apartment, and the FTC's settlement raises the accuracy bar for the whole tenant-screening industry.
If you've ever been denied housing over a background check, you now have a concrete precedent to point to.
 
COURT RULING
The Seventh Circuit vacated a settlement that would have paid facial-recognition victims in Clearview AI equity instead of cash, ruling the deal replaced all eight original class representatives with members from "favored" states and created unequal payouts. The five-year biometric privacy case, a bellwether for how courts treat face-scraping companies, is back open.
Watch this case. How it resolves will shape what "compensation" means for the next facial-recognition privacy fight.
🛠️ Tools & Tactics
 
 
Practical play
CISA added CVE-2026-58644, a critical unauthenticated SharePoint Server RCE (CVSS 9.8), to its Known Exploited Vulnerabilities catalog after it was weaponized as a zero-day ahead of Microsoft's July fix. Federal agencies had until July 19 to patch, everyone else should treat that as their deadline too. If you run on-prem SharePoint Server, confirm the update is applied and check logs for exploitation attempts predating your patch, since this one was used before a fix existed.
Patch now if you haven't, this SharePoint bug was actively exploited before Microsoft even shipped the fix.

Same AI software. Wildly different results.

Every company in this dataset bought the same AI capabilities. The difference in results came down to one thing: whether someone inside CX owned it.

One beauty retailer made 202 workflow updates in 30 days — refining as policies changed and new questions came in. Companies without a named owner saw performance stall or decline.

Read the data on what separates AI deployments that work from the ones that stall, and the four questions worth asking before your next AI investment.

🧪 Strange Cyber
 
Strange but real
📍 This Ransomware Gang Checks Your GPS Before It Extorts You (and Only Asks for $200)
Intro
This one happened back in April, but it's too good to leave on the shelf: a ransomware strain that refuses to run unless you're standing in Turkey.
What Happened
JanaWare, discovered by researchers investigating a wave of attacks on Turkish citizens, checks the victim's system locale and external IP geolocation before it will even execute. It spreads through phishing emails carrying malicious Java archive files via Outlook, and once it does run, it demands a strikingly modest $200 to $400, a fraction of typical ransomware demands.
Why It's Important
It's a real data point in a bigger shift: the ransomware ecosystem is splintering into smaller, cheaper, more targeted operations instead of consolidating around a few big-name gangs.
The Other Side
Low-value, high-volume ransomware is still ransomware. Just because the ask is small doesn't mean the intrusion or the encryption is.
 
👉 Takeaway
Don't calibrate your ransomware defenses around "we're not big enough to be a target." Volume-based gangs are explicitly hunting for exactly that assumption.
TL;DR: A ransomware strain won't even run outside Turkey, and asks for as little as $200 when it does.
Further reading: The Record

Wrong keywords. Weak product descriptions. Missing metadata. StoreClaw automatically audits your Shopify and Amazon stores and uncovers every SEO issue costing you traffic and sales. Get FREE SEO report today

Keep Reading