| ~7 MIN READ |
|
Nothing in this edition is the biggest breach of the year. What it is: a hospital billing vendor, a dev-tool backdoor, a fake IT helpdesk, and an AI agent that broke into a company on its own, none of them enormous alone, all of them proof the attack surface keeps getting weirder in the same direction. Buckle in.
This week wasn't about one big headline, it was about how many different doors attackers are trying now: enterprise software, open source packages, passkey enrollment, and, for the first time in a documented way, an AI agent acting on its own. Here's what happened, what's still unresolved, and one deadline worth checking today. PS: Was this forwarded to you? Subscribe free at exzeccyber.com/subscribe → |
|
In this edition
|
ACTIVE EXPLOITATION
🔓 ServiceNow's AI Platform Has a 9.5-Severity Hole, and Attackers Keep Finding New Ways Through It
Intro
ServiceNow runs the IT and HR backbone of a huge share of the Fortune 500, and right now it has a hole attackers are actively climbing through.
What Happened
CVE-2026-6875 is an unauthenticated code-injection flaw in ServiceNow's AI Platform, CVSS 9.5, that lets an attacker escape the platform's script sandbox and execute code remotely. It was publicly disclosed July 13. By July 20, a threat intelligence firm confirmed active in-the-wild exploitation, using a different sandbox-escape technique than the one in the original proof-of-concept.
Why It's Important
Defenses tuned to the published exploit are already being bypassed by a second method, which means patching alone isn't the finish line here.
The Other Side
ServiceNow pushed the fix fast, hosted instances were patched same-week, and self-hosted customers have had access to the update since the disclosure.
TL;DR: A 9.5-severity ServiceNow flaw is being actively exploited through multiple methods, one week after disclosure.
Further reading: Help Net Security
|
|
Live webinar, July 22: see how native SSP automation runs on real billing data — audit-ready under ASC 606, no spreadsheets required. Save your spot.
|
|
|
Same AI software. Wildly different results.
Every company in this dataset bought the same AI capabilities. The difference in results came down to one thing: whether someone inside CX owned it.
One beauty retailer made 202 workflow updates in 30 days — refining as policies changed and new questions came in. Companies without a named owner saw performance stall or decline.
Read the data on what separates AI deployments that work from the ones that stall, and the four questions worth asking before your next AI investment.
Strange but real
📍 This Ransomware Gang Checks Your GPS Before It Extorts You (and Only Asks for $200)
Intro
This one happened back in April, but it's too good to leave on the shelf: a ransomware strain that refuses to run unless you're standing in Turkey.
What Happened
JanaWare, discovered by researchers investigating a wave of attacks on Turkish citizens, checks the victim's system locale and external IP geolocation before it will even execute. It spreads through phishing emails carrying malicious Java archive files via Outlook, and once it does run, it demands a strikingly modest $200 to $400, a fraction of typical ransomware demands.
Why It's Important
It's a real data point in a bigger shift: the ransomware ecosystem is splintering into smaller, cheaper, more targeted operations instead of consolidating around a few big-name gangs.
The Other Side
Low-value, high-volume ransomware is still ransomware. Just because the ask is small doesn't mean the intrusion or the encryption is.
TL;DR: A ransomware strain won't even run outside Turkey, and asks for as little as $200 when it does.
Further reading: The Record
|
Wrong keywords. Weak product descriptions. Missing metadata. StoreClaw automatically audits your Shopify and Amazon stores and uncovers every SEO issue costing you traffic and sales. Get FREE SEO report today

