Someone deleted a country's land registry this week. An intruder logged into Romania's national cadastre agency with valid credentials, mapped the systems, and — when the extortion demand went unpaid — wiped the production servers and the backups together, taking the e-Terra platform offline, freezing property transactions nationwide, and, the attacker claims, walking off with citizens' records and the agency's source code first; the whole catastrophe turned not on any exploit but on backups reachable with the same login as the live system. The rest of the week's threats clustered around two uncomfortable truths about trust. One is that the software supply chain keeps betraying it: attackers hijacked long-dormant developer accounts to poison three RubyGems packages — one impersonating Microsoft's own credential manager — a malicious extension in ByteDance's AI coding tool hid its controls on the Ethereum blockchain, and apps marketed to and installed by US troops were found shipping Chinese and Russian code, turning routine software into an intelligence exposure. The other is that patient state espionage is quietly looting the identity layer itself, with Kaspersky detailing a campaign that spent months inside Southeast Asian governments harvesting police complaint systems, biometric databases and national identity registries by moving stolen data across internal shares so it read as ordinary employee traffic, while a Sandworm sub-cluster infecting Ukrainians now hides its command servers in Ethereum smart contracts — the same uncensorable trick the criminals reached for, a convergence that quietly breaks the takedown model Europe's defenders rely on. Against that, the loudest AI-crime story deflated on inspection: a Russian-speaking operator did let a jailbroken Gemini write eighty-nine percent of a botnet for him, and it turned out to control eight computers at a single dental clinic — the barrier that fell was skill, not scale. And the ground kept moving abroad, as Brussels hit Alibaba's AliExpress with a record €550 million fine — the largest yet under its platform rulebook, and its first landed on a Chinese marketplace — while Washington answered with a UN 'free speech' gambit aimed squarely at those same European rules, and Moonshot, days after Kimi K3 upended the AI trade, had to suspend new sign-ups because it had run out of the compute to serve them.
Top Stories
- EU hits China’s Alibaba with €550M record fine over illegal products — Technology – POLITICO · EU & Technology
- Risky Bulletin: Hacker wipes Romania's entire land registry database — Risky Bulletin · Cybersecurity & Threats
- Apps Marketed to US Troops Are Shipping Chinese and Russian Code — WIRED · Threat Intelligence (CTI)
- Alibaba says newest Qwen AI model is second only to Anthropic’s Claude Fable 5 — Tech - South China Morning Post · China & Technology
- Critical ServiceNow code execution flaw now exploited in attacks — BleepingComputer · Cybersecurity & Threats
AI & Power
Silicon Valley is embracing armed robots. Washington is making room. — Technology
Why it matters: Silicon Valley building armed robots with Washington's blessing is the clearest sign the AI-defence merger has moved from software to lethal hardware.
Silicon Valley is embracing armed robots and Washington is making room for them, marking the AI-defence convergence crossing into autonomous lethal systems.
The secret Trump administration battle to fight Chinese AI — Axios
Why it matters: An internal Trump-administration fight over how to counter Chinese open models is where the incoherence of US AI policy is being decided out of view.
A behind-the-scenes battle inside the Trump administration over how to counter Chinese AI reveals a policy with no settled answer to the open-weight surge.
AI memory shortage puts pressure on governments to act — Semafor
Why it matters: A memory shortage severe enough to pull governments in reframes AI's bottleneck as a physical-supply problem, not a software one.
An AI-driven memory shortage is pressuring governments to intervene, exposing hardware supply as the binding constraint on the AI build-out.
The Massive Supply Deals Feeding the AI Frenzy Are No Sure Thing — Technology - WSJ.com
Why it matters: Questioning whether the circular mega-deals underwriting the AI boom will actually be honoured is the sceptic's case against the whole capex cycle.
The Wall Street Journal questions whether the massive interlocking supply deals feeding the AI frenzy are a sure thing, probing the circular financing beneath the boom.
Banning AI Models Doesn’t Add Up to a Policy — Foreign Policy
Why it matters: The argument that banning Chinese models is not a policy is the intellectual rebuttal to the containment reflex driving Washington's China-AI debate.
Foreign Policy argues that banning AI models does not add up to a policy, rebutting the containment instinct as Chinese open weights spread regardless.
Politicians Are Trying to Change What Chatbots Say About Them — NYT > Technology
Why it matters: Politicians pressuring model-makers over what chatbots say about them is the speech-and-power fight moving from platforms to model weights.
Politicians are pressuring AI companies over what chatbots say about them, extending the content-moderation and speech fight down into model outputs.
Big Tech Needs to Prove that AI Spending Is Going Somewhere — Bloomberg Markets
Why it matters: The market demanding proof that AI capex produces returns is the pressure that could deflate the build-out faster than any regulation.
Big Tech faces mounting pressure to prove its enormous AI spending is producing returns, the market scepticism that could bite before regulation does.
AI is more likely than humans to form biases when hiring — MIT Technology Review
Why it matters: Evidence that AI hiring tools form biases more readily than humans undercuts the core efficiency-and-fairness pitch for automating recruitment.
MIT research finds AI is more likely than humans to form biases when hiring, undercutting the fairness case for automating recruitment decisions.
These AI-Native Companies Have Tiny Staffs and Fewer Bosses — Technology - WSJ.com
Why it matters: Firms running on tiny AI-augmented staffs are the concrete labour-displacement case the abstract productivity debate keeps circling.
A wave of AI-native companies is operating with tiny staffs and fewer managers, the tangible edge of the labour displacement the AI economy implies.
EU & Technology
EU hits China’s Alibaba with €550M record fine over illegal products — Technology – POLITICO
Why it matters: A €550m fine against AliExpress — the largest DSA penalty yet — is Brussels proving the platform rulebook has teeth against a Chinese marketplace, not just US ones.
The EU hit Alibaba's AliExpress with a record €550m fine for failing to prevent the sale of illegal goods, the largest DSA penalty to date and its first landed on a Chinese platform.
Trump pushes UN ‘free speech’ declaration in veiled attack on EU tech regulation — Technology – POLITICO
Why it matters: Trump using a UN 'free speech' declaration to attack EU tech rules turns the transatlantic regulatory clash into a multilateral fight over sovereignty itself.
Trump is pushing a UN 'free speech' declaration in a veiled attack on EU tech regulation, escalating the transatlantic fight over the DSA to the multilateral stage.
How the EU is targeting Big Tech’s AI monopoly — Tech Archives | Euractiv
Why it matters: Mapping how the EU is aiming its antitrust and platform tools at Big Tech's AI layer shows the enforcement front moving from search and social to models.
Analysis of how the EU is targeting Big Tech's AI monopoly shows Brussels extending its competition and platform tools into the model layer.
CuspAI lands $450m round to accelerate AI materials discovery — Sifted
Why it matters: A $450m round for a European AI-materials lab, backed by Bezos and sovereign funds, is the continent attracting frontier capital into a strategic niche.
Cambridge-based CuspAI landed a $450m round backed by Jeff Bezos and sovereign AI funds to accelerate AI-driven materials discovery, a rare European frontier bet at scale.
Auditors tell UK government to do the math before banking on £45B AI savings — www.theregister.com - Articles
Why it matters: Auditors warning the UK to check its arithmetic before booking £45bn in AI savings is the reality check on government AI-productivity promises.
UK auditors told the government to do the math before banking on £45bn in AI savings, puncturing the headline productivity claims driving public-sector AI adoption.
The European Parliament’s answer to its AI worries: More AI — Technology – POLITICO
Why it matters: The European Parliament answering its AI anxieties with more AI captures the bloc's contradiction — regulate the technology while deploying it internally.
The European Parliament's response to its own AI worries is to adopt more AI, a telling contradiction as it simultaneously moves to regulate the technology.
How Daniel Ek is building his ‘new European dream’ — Sifted
Why it matters: Daniel Ek building a 'new European dream' across defence and deep tech is the Spotify founder betting his capital on European strategic autonomy.
Spotify's Daniel Ek is building what he calls a 'new European dream', channelling his capital into European defence and deep-tech sovereignty plays.
Burnham sparks backlash over reported plans to ditch DSIT — Sifted
Why it matters: Burnham reportedly dismantling the UK's dedicated science-and-tech department would fold digital policy back into a general ministry just as it matters most.
Incoming UK prime minister Andy Burnham sparked backlash over reported plans to scrap DSIT, folding science and technology back into a broader department.
Airbus takes flight from AWS. What happens next is critical — www.theregister.com - Articles
Why it matters: Airbus migrating off AWS to a French sovereign cloud is the test case for whether European sovereignty rhetoric survives contact with operational reality.
Airbus is migrating critical workloads off AWS to a French sovereign cloud, and whether the move actually holds is the real test of European cloud sovereignty.
US & Technology
Why Silicon Valley Can’t Stop Looking Over Its Shoulder at China — NYT > Technology
Why it matters: Silicon Valley's China anxiety becoming the organising frame of the moment is itself the story — the Kimi shock has rewired how the Valley sees the race.
Silicon Valley cannot stop looking over its shoulder at China, the anxiety now organising how the Valley reads the AI race after the Kimi K3 shock.
Capital One Open Sources AI-Powered ‘VulnHunter’ Security Tool — SecurityWeek
Why it matters: A major bank open-sourcing an AI vulnerability-hunting tool is the defensive-AI counter-move to the week's steady drumbeat of AI-enabled offence.
Capital One open-sourced VulnHunter, an AI-powered security tool, a defensive-AI contribution against the rising tide of AI-enabled offence.
The ‘Bad Blood’ Between Polymarket’s Shayne Coplan and Kalshi’s Tarek Mansour — NYT > Technology
Why it matters: The Coplan-Mansour feud is the prediction-market industry's power struggle spilling into public just as these venues gain political weight.
The 'bad blood' between Polymarket's Shayne Coplan and Kalshi's Tarek Mansour exposes a power struggle atop the prediction markets now shaping political information.
Trump's DOJ turns to a never-used court for its next deportation fight — Axios
Why it matters: The DOJ reaching for a never-used court to speed deportations is the administration engineering novel legal machinery around existing checks.
Trump's DOJ is turning to a never-used court for its next deportation fight, engineering novel legal machinery to route around existing judicial checks.
US Marshals arrest the Tate brothers in Miami — The Verge
Why it matters: The Tate brothers' US arrest amid new UK trafficking charges is the transatlantic law-enforcement action against a major online-influence operation.
US Marshals arrested the Tate brothers in Miami as Britain unveiled new rape and trafficking charges, a transatlantic move against a major online-influence figure.
Lego Strikes Back Against Screens—With Chips in Bricks — Technology - WSJ.com
Why it matters: Lego embedding chips in bricks to fight screen time is the analog-toy industry's hardware answer to childhood's migration onto devices.
Lego is fighting screen time by embedding chips in physical bricks, the toymaker's hardware bet against childhood's migration onto screens.
China & Technology
Alibaba says newest Qwen AI model is second only to Anthropic’s Claude Fable 5 — Tech - South China Morning Post
Why it matters: Alibaba claiming its newest Qwen model trails only Anthropic's top system puts a Chinese lab within one rung of the global frontier by its own benchmark.
Alibaba says its newest Qwen model is second only to Anthropic's Claude Fable 5, a claim that places a Chinese open lab one rung below the global frontier.
Kimi K3 developer suspends new subscriptions amid compute constraints — Tech - South China Morning Post
Why it matters: Moonshot halting new sign-ups days after Kimi K3's launch shows the open-weight insurgency is now constrained by the same compute scarcity as its Western rivals.
Moonshot suspended new Kimi K3 consumer subscriptions days after launch as demand overwhelmed compute capacity, exposing the hardware limit behind the open-weight surge.
China’s daily AI token calls reach 140 trillion, up more than 1,000-fold since early 2024 — TechNode
Why it matters: A thousand-fold rise in daily AI token calls since 2024 is the raw measure of how deeply inference has been absorbed into China's economy.
China's daily AI token calls have reached 140 trillion, up more than a thousand-fold since early 2024, a measure of how fast inference has scaled into the economy.
Kimi K3 48-Hour Chip Design Experiment: Why Moonshot AI Autonomous EDA Pipeline Has the Entire Semiconductor Industry Nervous — Pandaily - China Tech News, AI & Electric Vehicle Insights
Why it matters: A Chinese model running an autonomous 48-hour chip-design pipeline is the AI-designs-the-hardware loop the whole industry has been nervous about.
Moonshot's Kimi K3 ran a 48-hour autonomous chip-design experiment via an EDA pipeline, a demonstration of AI closing the loop on semiconductor design.
Chinese President Xi Jinping wants emergency response systems to keep AI in check — www.theregister.com - Articles
Why it matters: Xi calling for emergency mechanisms to keep AI in check is Beijing pairing its open-weight push abroad with a control narrative at home.
Xi Jinping called for emergency-response systems to keep AI in check, pairing China's global open-weight push with a domestic control-and-safety narrative.
China develops more than 400 humanoid robot products, accounting for over half of the global total — TechNode
Why it matters: China holding over half the world's humanoid-robot product lines is the embodied-AI manufacturing lead translating into sheer catalogue dominance.
China has developed more than 400 humanoid robot products, over half the global total, translating its embodied-AI push into manufacturing scale.
Threat Intelligence (CTI)
[P2] Apps Marketed to US Troops Are Shipping Chinese and Russian Code — WIRED
Why it matters: Apps sold to and installed by US military personnel found shipping Chinese and Russian code, turning routine software into a foreign-intelligence exposure.
WIRED reports that apps marketed to and used by US troops are shipping Chinese and Russian code, extending a documented pattern in which Russian-built components (such as Pushwoosh and Elfsight) have been embedded in US Army and federal apps under the appearance of American software; a related case saw a $1.4m White House app containing Russian-built Elfsight code pushed onto FAA and federal government-issued devices, and prior analysis found hundreds of domains and IPs inside Russian military apps largely hosted on US cloud providers.
severity high · exploited in the wild · EU: NIS2, CRA, FIRRMA
[P2] SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines — The Hacker News
Why it matters: Attackers hijacked long-dormant developer accounts to slip a backdoor into three RubyGems packages — one impersonating Microsoft's own credential manager.
Between 18 and 19 July, malicious versions of three RubyGems packages — git_credential_manager (impersonating Microsoft's Git Credential Manager), Dendreo, and fastlane-plugin-run_tests_firebase_testlab — were published in a campaign named SleeperGem; each release is a loader that fetches a second stage from an attacker-controlled Forgejo host, checks roughly 30 CI-related environment variables and deliberately skips ephemeral build runners to ensure it runs on a developer machine, where it drops a native daemon and installs persistence. The name reflects the takeover of real, long-dormant (six-to-seven-year-quiet) accounts rather than freshly planted ones.
severity high · exploited in the wild · EU: NIS2, CRA
[P2] GoSerpent campaign used coordinated malware chain to steal government files — Biometric Update
Why it matters: A patient espionage operation looting police, biometric and national-identity databases across Southeast Asia — undetected for stretches by riding trusted internal traffic.
Kaspersky's GReAT detailed GoSerpent, a previously undocumented backdoor used against Southeast Asian government and diplomatic entities since late 2025: the operators establish GoSerpent as the foothold, deploy file-collection and credential-dumping utilities, and in May 2026 returned with an evolved toolset including the Stowaway RAT and a dedicated TmcLoader/TmcPayload exfiltration chain, using credentials stolen months earlier to move data across internal network shares so the traffic reads as authorised employee access. Targets include police complaint-management systems, biometric databases, criminal case files, hotel and tenant records linked to national identity registries, and diplomatic networks.
severity high · exploited in the wild · EU: NIS2, CER Directive · actor TetrisPhantom (overlap) (50%)
[P2] UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices wih Malware — The Hacker News
Why it matters: A Sandworm sub-cluster is hiding its command-and-control addresses inside Ethereum smart contracts — a state actor adopting the criminals' uncensorable infrastructure.
CERT-UA attributes a ClickFix campaign to UAC-0145, a sub-cluster of the GRU's Sandworm: fake CAPTCHA checks on more than ten compromised websites (June-July 2026) instruct Ukrainian visitors to paste a PowerShell command that drops a VBS autorun file (GHETTOVIBE) and runs reconnaissance (SCOUTCURL); a bespoke tool, SMARTAXE, dynamically alters page content per visitor, and the CAPTCHA content uses the EtherHiding technique — retrieving the C2 domain from an Ethereum smart contract via an address in the page source. CERT-UA also observed Android APK backdoors distributed via messaging apps disguised as security tools.
severity high · exploited in the wild · EU: NIS2, CER Directive · actor Sandworm (UAC-0145 sub-cluster, GRU) (85%)
[P3] Police Chiefs Cite TfL Hack in Push for Cybercrime Risk Orders — Infosecurity Magazine
Why it matters: British police chiefs are citing the Transport for London attack to argue for new court orders that would restrict convicted cyber offenders' access to computers.
Following the sentencing of two Scattered Spider members over the £29m Transport for London attack, UK police chiefs are pushing for 'cybercrime risk orders' — court-imposed restrictions (analogous to existing preventive orders) that would constrain convicted or suspected cyber offenders' access to computers, tools or infrastructure — citing the TfL case and the youth of its perpetrators as justification.
severity medium · EU: NIS2
[P3] Threat Intelligence | On-Chain Backdoor in a Malicious TRAE Extension — Threat Intelligence on Medium
Why it matters: A malicious extension in ByteDance's AI coding IDE hides its command-and-control on the Ethereum blockchain — the same uncensorable technique a GRU cluster used this week.
SlowMist analysed a malicious extension (package name juannegro.solidity, impersonating a Solidity language plugin) still downloadable from the TRAE IDE marketplace — ByteDance's AI-native IDE — as of 18 July despite removal from Open VSX; it is a cross-platform (Windows, macOS, Linux) malware dropper that runs on IDE startup, installs user-level persistence, and retrieves its next-stage payload address from an Ethereum smart contract (EtherHiding) or connects directly to a remote shell, with the operator observed updating the on-chain payload and shell addresses after publication.
severity medium · exploited in the wild · EU: NIS2, CRA
Defence & National Security
Russia Hits Kyiv With Largest Ballistic Missile Barrage — Bloomberg Politics
Why it matters: Russia hitting Kyiv with its largest ballistic barrage of the war signals an escalation in the air campaign as Western attention splits toward the Gulf.
Russia hit Kyiv with the largest ballistic missile barrage of the war, escalating the air campaign as Western attention is pulled toward the widening Gulf conflict.
US service member killed in northern Iraq, US Central Command says — Defense News
Why it matters: A US service member killed in northern Iraq widens the American casualty toll beyond Jordan and pulls Washington deeper into the Iran war.
A US service member was killed in northern Iraq per CENTCOM, widening the American casualty toll and deepening US involvement in the Iran conflict.
The Pentagon Is Finally Buying (Some) Weapons From Startups — Technology - WSJ.com
Why it matters: The Pentagon actually buying weapons from startups is the procurement reform the defence-tech boom has been promising, finally showing in contracts.
The Pentagon is finally buying some weapons from startups, an early sign the defence-tech procurement reforms are translating from rhetoric into contracts.
Lockheed to build cheaper Patriot missile to counter drone threat — myFT following
Why it matters: Lockheed building a cheaper Patriot interceptor to counter drones is the West adapting to the cost-exchange problem cheap drones have imposed.
Lockheed will build a cheaper Patriot missile to counter the drone threat, an answer to the ruinous cost-exchange ratio of shooting down cheap drones.
US Bombs Iran for Ninth Day in Campaign to Reopen Hormuz — Bloomberg Politics
Why it matters: A ninth day of US strikes to reopen Hormuz is a sustained campaign with global energy consequences already showing at the pump.
US forces bombed Iran for a ninth day in a campaign to reopen the Strait of Hormuz, a sustained operation already lifting global oil and fuel prices.
Sweden eyes additional batch of Gripen E jets to replace Ukraine-bound aircraft — Breaking Defense
Why it matters: Sweden ordering more Gripens to backfill Ukraine-bound aircraft is European industry sustaining its own arsenal while arming Kyiv.
Sweden is eyeing an additional batch of Gripen E jets to replace Ukraine-bound aircraft, European industry backfilling its own fleet while supplying Kyiv.
Digital Sovereignty & Identity
The EU is about to sell our most sensitive data to the US for visa-free travel — European Digital Rights (EDRi)
Why it matters: EDRi warning that the EU would hand the US its citizens' most sensitive data for visa-free travel is the sovereignty contradiction at the border, in plain terms.
EDRi warns the EU is about to give the US access to citizens' most sensitive data in exchange for visa-free travel, trading privacy for border convenience.
The ACLU Is Arming Lawyers to Expose State Surveillance Secrets — WIRED
Why it matters: The ACLU equipping lawyers to prise open state surveillance secrets is the litigation front against the data-broker and biometric build-out.
The ACLU is arming lawyers to expose state surveillance secrets, opening a litigation front against the opaque data-broker and biometric systems police now use.
Grocery Outlet stores deploy SAFR facial recognition to ID suspected shoplifters — Biometric Update
Why it matters: A grocery chain running facial recognition to flag suspected shoplifters is the normalisation of biometric surveillance into everyday retail.
Grocery Outlet is deploying SAFR facial recognition to identify suspected shoplifters, pushing biometric surveillance into routine retail settings.
The FBI reportedly won’t investigate ICE anymore — The Verge
Why it matters: The FBI reportedly declining to investigate ICE removes a federal check on the agency at the centre of the surveillance-and-enforcement expansion.
The FBI reportedly will no longer investigate ICE, removing a federal oversight check on the agency driving much of the domestic surveillance build-out.
Within line of sight – personal issue police drones are on the horizon — Biometric Update
Why it matters: Personal-issue police drones moving within line of sight is aerial surveillance becoming standard-issue kit rather than a special capability.
Personal-issue police drones are on the horizon, normalising aerial surveillance as standard equipment for individual officers.
The Future of Age Verification: Your Face Never Leaves Your Device — BleepingComputer
Why it matters: On-device face-based age verification is the privacy-preserving compromise the age-assurance fight has been circling, if it works as claimed.
Vendors are pitching on-device facial age verification — 'your face never leaves your device' — as the privacy-preserving answer to age-assurance mandates.
Quantum & Cryptography
Before Q-Day: The Race to Quantum First — War on the Rocks
Why it matters: Framing the post-quantum transition as a race to 'quantum first' is the strategic case for treating cryptographic migration as national-security urgency.
A War on the Rocks analysis frames the pre-Q-Day period as a race to quantum first, arguing the cryptographic transition is a strategic contest, not just an IT upgrade.
Australia issues guidance on evaluating third-party quantum readiness — PQShield
Why it matters: Australia issuing guidance on judging suppliers' quantum readiness is a government pushing post-quantum migration down the supply chain, not just its own systems.
Australia issued guidance on evaluating third-party quantum readiness, extending post-quantum migration obligations to suppliers and the wider supply chain.
Crypto-Agility as an Operational Capability — KuppingerCole Analysts
Why it matters: Reframing crypto-agility as an operational capability rather than a one-off migration is the maturing of how organisations approach the quantum threat.
Analysts argue crypto-agility must become a standing operational capability, not a single post-quantum migration project, to keep pace with cryptographic change.
Cybersecurity & Threats
[P1] Risky Bulletin: Hacker wipes Romania's entire land registry database — Risky Bulletin
Why it matters: A national land registry wiped off its own servers — systems and backups both — after a failed extortion, freezing property transactions across a country.
A threat actor using the alias ByteToBreach logged into Romania's National Agency for Cadastre and Land Registration (ANCPI) with valid credentials, mapped the internal systems, and wiped both systems and backups after failing to extort the agency, taking the e-Terra land-registry platform offline and freezing property transactions; the actor also claims to have copied citizen data and the agency's GitLab source repositories and to have deployed ransomware, and is advertising the data for sale.
severity critical · exploited in the wild · EU: NIS2, GDPR, CER Directive · actor ByteToBreach (60%), escalation
[P1] Critical ServiceNow code execution flaw now exploited in attacks — BleepingComputer
Why it matters: An unauthenticated remote-code-execution flaw in the AI layer of a platform that runs enterprise IT workflows — now being exploited in the wild.
CVE-2026-6875 is a sandbox escape in the ServiceNow AI Platform — the layer running across most of the company's IT service management and workflow tools — allowing unauthenticated remote code execution under certain conditions; reported by Adam Kues of Assetnote, rated CVSS 9.5, disclosed 13 July, and now reported by threat-intel firm Defused to be under active exploitation, enabling data theft, workflow manipulation, credential and token theft, and lateral movement into connected enterprise applications.
severity critical (CVSS 9.5) · exploited in the wild · CVE-2026-6875 · EU: NIS2, DORA, GDPR
[P2] Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution — The Hacker News
Why it matters: A fifteen-year-old flaw in NGINX's script engine that a single unauthenticated request can turn into a worker crash — and, under the right conditions, code execution.
CVE-2026-42533 is a pre-authentication heap buffer overflow in NGINX's internal script engine, latent since the map directive gained regex support in March 2011; it surfaces only in a specific configuration (a regex-based map whose output variable is referenced in a string expression after an earlier regex capture), where a crafted HTTP request can crash or restart the worker for denial of service and, where ASLR is disabled or bypassed, may allow remote code execution — a single unauthenticated GET can recover the addresses a payload needs on a default Ubuntu 24.04 build.
severity high · CVE-2026-42533 · EU: NIS2, CRA
[P3] Russian-Speaking Hacker Uses Google Gemini CLI to Control Botnet of Eight Dental Clinic PCs — The Hacker News
Why it matters: A Russian-speaking criminal used a jailbroken Gemini CLI to build and run a botnet — which turned out to be eight PCs at a single dental clinic.
A Russian-speaking actor known as bandcampro used Google's open-source Gemini CLI as a hacking agent across more than 200 sessions between 19 March and 21 April 2026 to deploy and operate command-and-control infrastructure controlling eight computers at a dental clinic and access their OpenDental database; posing as an authorised penetration tester, the operator instructed Gemini to suppress safety disclaimers and auto-save any credentials it encountered, persisting those instructions in Gemini's memory file, and the AI produced roughly 89% of the text and handled the C2 migration — architecture, coding, VPS deployment and debugging — in about six minutes.
severity medium · exploited in the wild · EU: NIS2, GDPR · actor bandcampro (70%)
[P2] New 7-Zip Vulnerability Could Let Crafted XZ Archives Run Code During Extraction — The Hacker News
Why it matters: A heap overflow in how 7-Zip parses XZ archives that can run code when a booby-trapped archive is merely opened.
CVE-2026-14266 is a heap-based buffer overflow in how 7-Zip processes XZ chunked data: when an XZ stream runs its output through a filter, the decoder was handed the full output-buffer length on each pass rather than the space remaining, producing an out-of-bounds write; opening a crafted XZ archive can run code in the context of the current process. Detailed by Trend Micro's Zero Day Initiative (rated 7.0), reported 5 June by Landon Peng of Lunbun LLC, and fixed 25 June in 7-Zip 26.02.
severity high · CVE-2026-14266 · EU: NIS2, CRA
[P3] Federal audit finds major gaps in US aviation cybersecurity oversight — Biometric Update
Why it matters: Federal auditors warn that the agencies overseeing US aviation are running on outdated standards and unclear responsibility, leaving the national airspace exposed.
A Department of Transportation Inspector General audit of the FAA's 45 high-impact systems and a parallel GAO review found the FAA adhering to outdated NIST baselines, producing inadequate documentation, and failing to track known vulnerabilities, having fully implemented only three of seven network-protection objectives; the TSA still relies on a 2018 cybersecurity roadmap that no longer aligns with DHS strategy and does not clearly assign responsibility for securing airlines and airports.
severity medium · EU: NIS2, CER Directive