The CyberWire Daily Podcast 7.20.26
Ep 2596 | 7.20.26

Behind the friendly face.

Transcript

Hugging Face reports an autonomous AI-powered breach. Ernst & Young discloses a client data breach. Attackers are actively exploiting a critical ServiceNow flaw. Ransomware gangs sharpen their tactics against law firms. Capital One open-sources an AI security tool. Text salting fools AI email filters. Hidden gambling apps slip into Apple’s App Store. And federal agents arrest a Florida man accused of spreading malware through video games. Monday business briefing. Tim Starks from CyberScoop discusses election integrity. Fake feathers lead to faulty findings.

Today is Monday July 20th 2026. I’m Dave Bittner. And this is your CyberWire Intel Briefing.

Hugging Face discloses an autonomous agentic breach. 

Hugging Face disclosed that an autonomous AI agent breached part of its production infrastructure, gaining unauthorized access to a limited number of internal datasets and service credentials. The attack began when a malicious dataset exploited two code execution vulnerabilities in the company’s data-processing pipeline, allowing attackers to compromise a processing worker, escalate privileges, steal cloud and cluster credentials, and move laterally through internal systems. The company said it found no evidence that public AI models, datasets, Spaces, or its software supply chain were altered. Hugging Face contained the incident, closed the vulnerabilities, rebuilt affected systems, rotated compromised credentials, and is investigating with external forensic experts while notifying law enforcement. Users are advised to rotate access tokens and review account activity. During the response, Hugging Face also found that safety guardrails in commercial AI models hindered forensic analysis, leading it to rely on an open-weight model running on its own infrastructure to investigate the attack more effectively.

Ernst & Young is notifying clients of a data breach. 

Ernst & Young (EY) is notifying clients that personal and financial information was exposed in a data breach involving a third-party service management platform used for tax-related work. Attackers accessed the platform between March 28 and April 12 and downloaded client documents containing sensitive information, including Social Security numbers, account details, and tax records. EY discovered the incident on April 23, launched an investigation with an external cybersecurity firm, and says there is no evidence of misuse. Affected clients are being offered two years of identity and credit monitoring services.

A critical ServiceNow AI Platform vulnerability is under active exploitation. 

Attackers have begun exploiting a critical ServiceNow AI Platform vulnerability, tracked as CVE-2026-6875, just days after security updates were released. The flaw, discovered by Searchlight Cyber, allows unauthenticated attackers to escape the platform’s sandbox and achieve remote code execution in complex attacks. ServiceNow patched hosted instances and released fixes for self-hosted deployments on July 13. Threat intelligence firm Defused reported observing active exploitation in the wild, noting attackers are using a different technique than the published proof of concept to reach the same code execution path. Although ServiceNow’s advisory still states it is unaware of active exploitation, the company urges customers to apply patches immediately. The platform supports more than 100 billion workflows annually and is widely used across Fortune 500 organizations.

Ransomware attacks targeting law firms grow more sophisticated. 

Ransomware attacks targeting law firms are becoming more sophisticated, with attackers increasingly impersonating IT staff, bypassing multi-factor authentication, and stealing sensitive data instead of encrypting it. Experts warn that criminals are also compromising backup systems, abusing trusted third-party vendors, and using remote access tools and screen-sharing platforms to gain persistent access. Artificial intelligence has made phishing and voice scams more convincing while increasing the volume of security vulnerabilities firms must address. Security professionals recommend employee training, strict access controls, disabling unauthorized USB devices, limiting screen sharing, and conducting regular ransomware response exercises. They also caution that paying a ransom offers no guarantee stolen data will be deleted and could create legal risks. Ultimately, experts stress that firms of all sizes are potential targets and should prioritize preparation over assuming they are too small to be attacked.

Capital One has open-sourced an internally developed AI-powered security tool. 

Capital One has open-sourced VulnHunter, an internally developed AI-powered security tool designed to identify and remediate software vulnerabilities at the code level. Unlike traditional vulnerability scanners, the tool uses an agentic reasoning workflow to identify exploitable flaws, map potential attack paths, and recommend targeted fixes while reducing false positives. Available on GitHub, VulnHunter currently requires Anthropic’s Claude Opus 4.8 and a Claude Code environment. Capital One says the tool has helped identify and remediate vulnerabilities across thousands of internal code repositories and hopes open-sourcing it will strengthen software supply chain security across the industry.

Text salting  bypasses AI-powered email security. 

Cybercriminals are increasingly using a technique called text salting to bypass AI-powered email security, according to Barracuda, which has detected more than one million retail-themed phishing emails using the method since April. Text salting hides benign words within emails to confuse machine learning and large language model (LLM) filters while keeping the phishing message unchanged for human recipients. Attackers conceal the extra text using techniques such as CSS cropping, off-screen text placement, and zero-font formatting. Barracuda warns that many AI-driven content analysis tools process all text equally and may not distinguish between visible and hidden content, leading to misclassification. The company recommends a layered email security strategy that evaluates sender reputation, authentication, URLs, HTML rendering, and discrepancies between visible and hidden content, rather than relying solely on AI or keyword detection.

Gambling apps hide in Apple’s App Store. 

A 9to5Mac investigation has uncovered more than 60 App Store apps that allegedly conceal online gambling platforms behind simple games and utility apps. The apps behave normally for users outside Brazil, but when opened from a Brazilian IP address, they transform into betting platforms. Researchers found many of the apps share common traits, including single-use developer accounts, nearly identical privacy policies, few or no updates, and small file sizes. The investigation also uncovered a public GitHub repository with instructions for creating these “jacket apps,” including how to remotely switch functionality, use generic branding, and avoid detection during Apple’s App Store review process. The findings come as Brazilian regulators pressure Apple and Google to explain how they detect apps that hide gambling features and ensure only authorized betting services are available, adding to growing scrutiny of deceptive apps on major mobile marketplaces.

Feds arrest a Florida man for allegedly distributing malware through video games. 

Federal authorities have arrested 21-year-old Florida resident Zyaire Wilkins for allegedly helping distribute malware through video games that infected roughly 8,000 computers and stole at least $220,000 in cryptocurrency. Prosecutors say Wilkins financed malware development and promoted infected games on platforms including Discord, Telegram, X, and LinkedIn, often targeting cryptocurrency holders. Once installed, the malware stole passwords, browser data, account tokens, and other sensitive information used to access victims’ crypto wallets. Investigators linked the campaign to several games distributed through what court records describe as a popular digital game platform. Evidence allegedly included encrypted messages, blockchain transactions, and cryptocurrency-funded gift card purchases that helped identify Wilkins. He has been charged with conspiracy to obtain information from computers for financial gain. 

Monday business briefing. 

Cybersecurity companies continue to attract strong investment, led by Israeli identity management startup Oak, which emerged from stealth with a $60 million seed round to expand its security and AI platform. UK-based Valarian raised $50 million to accelerate its sovereign infrastructure offerings, while Israel’s QIZ Security secured $17 million to advance its post-quantum cryptography platform. AI fraud prevention startup Reken disclosed a $10 million seed round, Savi Security raised $7 million to develop AI-powered family cybersecurity tools, and Spain’s 8Layers added €1 million to expand its identity security platform across Europe. The sector also saw several acquisitions, including Barracuda Networks buying identity security firm Evo Security, Cribl acquiring detection engineering company CardinalOps, CompassMSP purchasing The Logic Group, The 20 MSP acquiring Sundance Networks, and Presidio completing its acquisition of managed security provider LookingPoint to strengthen its AI-driven security capabilities.

 

Fake feathers lead to faulty findings. 

For birdwatchers, spotting a rare visitor far from its normal habitat is a badge of honor. Unfortunately, artificial intelligence is proving to be an unwelcome addition to the flock. Researchers are warning that AI-generated and AI-enhanced wildlife photos could undermine citizen science platforms such as iNaturalist and the Macaulay Library, which scientists rely on to track species distributions and environmental change. While obvious fakes, like a toucan in Siberia, are easy to dismiss, subtler edits are causing concern. In one case, an AI-enhanced photo of a common bird in Brazil mistakenly acquired features of a North American red-winged blackbird, creating a false sighting. Scientists say many photographers simply want prettier images, but even minor AI edits can introduce misleading details. With hundreds of questionable images already identified, researchers are urging nature enthusiasts to keep their editing light, because conservation science works best when the birds are the only ones embellishing their feathers.

And that’s the CyberWire.

For links to all of today’s stories, check out our Daily Briefing at the cyberwire dot com.

 

 

We’d love to know what you think of this podcast. Your feedback ensures we deliver the insights that keep you a step ahead in the rapidly changing world of cybersecurity. If you like the show, please share a rating and review in your podcast app. Please also fill out the survey in the show notes or send an email to cyberwire@n2k.com

We’re proud that N2K CyberWire is part of the daily routine of the most influential leaders and operators in the public and private sector, from the Fortune 500 to many of the world’s preeminent intelligence and law enforcement agencies.

N2K helps cybersecurity professionals and organizations grow, learn, and stay ahead. We’re the nexus for discovering the people, tech, and ideas shaping the industry.  Learn how at n2k.com.

 

N2K’s lead producer is Liz Stokes. We’re mixed by  Tré Hester, with original music by and sound design Elliott Peltzman. Our contributing host is Maria Varmazis. Our executive producer is Jennifer Eiben. Peter Kilpe is our publisher. And I’m Dave Bittner. Thanks for listening.