Litany Of The Hacked: July 2026 Wrap-Up

 


Sing, o goddess, of the litany of the hacked from July 2026.

Sure, we're keeping with the Homer theme, and yes we appreciate that the Anthropic product that 'launched a thousand ships' (+/-) was named Mythos. 

Let's check the litany for this month. Our point is not shame, but shared awareness to pool resources where possible and create a sense of community. Thus, the litany now includes:

Department of Education and police national legal database (both UK)...Fairlife Milk (a unit of Coca-Cola)...AssuranceAmerica...Greenfield Communications...Accenture Consulting...Homeland Security Information Network (HSIN)...

In mitigation: one week later there is already a 'post-mortem' of the OpenAI/HuggingFace incident c/o Jen Easterly: https://cloudsecurityalliance.org/artifacts/hugging-face-ciso-post-mortem. We'll come back to that another time. But in aggravation (yep that again) Anthropic announced that one of its products also acted autonomously, though allegedly it did not break out of its sandbox.

Hooray of the month thus far: The litany does not include the public water utilities in Minnesota and Michigan (and multiple other states) because while they were targeted, the state CISOs in coordination with federal partners were able to create a defense. This is an example of sharing lessons; let's hope other utilities and public infrastructure systems are in on the sharing.

As Brendan recently put it, the speed of these advances in cyberattacks is unprecedented -- though maybe we should change our benchmarks for 'precedence' give that it only gets faster from here. Chris Hughes over at his Substack platform puts the state of affairs as this:

Nearly every major lab and vendor shipped a cyber-specific model or tool, an Open Secure AI Alliance formed with 40+ members, and the UK’s AI Safety Institute started publishing what these models actually do when you point them at real systems, including the uncomfortable finding that they cheat. On the other side, the gap between AI-speed discovery and human-speed remediation kept widening into what one bank now calls “Patchmageddon,” and the market kept pricing all of it, with endpoint and identity startups raising at scale.

The theme from last week holds, which is that the capability is arriving faster than our governance, disclosure, and prioritization models can adapt. What changed this week is that the defensive side stopped talking and started shipping.

AI-based cybersecurity should not be all Greek to you.

Ask us how you can avoid joining the litany.

(image credit: User:Bibi Saint-Pol, Public domain, via Wikimedia Commons)

Comments