
The defense against the AI arts.
Trump's latest AI leader resigns. The Army burns through its AI tokens. Scammers impersonate IC3 personnel.HollowGraph malware uses a compromised Microsoft 365 calendar for C2. Qilin ransomware targets a critical Palo Alto Networks flaw. A North Korean campaign targets Web3 and cryptocurrency professionals through fake job recruitment scams. Zimbra patches multiple critical bugs. Shadow AI creates regulatory headaches. Hackers wipe Romania’s land registry database. Our guest is Errol Weiss, Chief Security Officer at Health-ISAC, setting the record straight on ransomware trends. Patching the automotive security system you didn’t know you had.
Today is Tuesday July 21st 2026. I’m Dave Bittner. And this is your CyberWire Intel Briefing.
Trump's latest AI leader resigns.
Chris Fall has resigned as director of the Center for AI Standards and Innovation (CAISI) after just three months, continuing a period of leadership instability at the National Institute of Standards and Technology office. No reason was given for his departure. CAISI is responsible for developing AI testing standards and assessing cybersecurity risks, but it has recently appeared less central to the Trump administration’s AI strategy. The Commerce Department’s temporary restriction on Anthropic’s AI models and the White House’s new “Gold Eagle” AI safety initiative both proceeded without a prominent role for CAISI. Meanwhile, industry leaders, including Google DeepMind CEO Demis Hassabis, have called for an independent AI standards body. Questions also remain about CAISI’s evaluation methods for Chinese open-weight AI models, with federal agencies declining to provide details.
With another quick departure, the job is starting to look a bit like Hogwarts’ Defense Against the Dark Arts professorship, an important role that never seems to keep the same occupant for long.
The Army burns through its AI tokens.
Just weeks after the Department of Defense announced that nearly half of its 3.5 million employees were using artificial intelligence at work, the Army began warning personnel to conserve their AI usage after exhausting a shared pool of tokens. According to an internal email obtained by WIRED, the Army’s Chief Information Office had to reinstate limits despite previously offering unlimited access, and future funding beyond October remains uncertain. The Army uses the Ask Sage platform to access large language models from OpenAI, Google, and Meta for administrative and operational tasks. Employees had been encouraged to increase AI use, with additional tokens automatically allocated as needed. The episode mirrors similar pullbacks at companies including Meta and Uber after unexpectedly high AI usage. One Army employee questioned the tools’ reliability, saying they sometimes produced inaccurate results and argued that broader deployment should be more deliberate and focused on appropriate use cases.
Scammers impersonate IC3 personnel.
The FBI is warning that scammers are impersonating agency personnel and the Internet Crime Complaint Center (IC3) to target people who have already been victims of fraud. The schemes use fake emails, phone calls, social media accounts, AI-generated videos, and spoofed websites that closely resemble IC3.gov. Victims are often directed to fraudulent complaint forms or messaging platforms, where scammers attempt to steal additional personal and financial information or demand payment to recover stolen funds. The FBI emphasizes that IC3 has no social media presence and does not contact complainants through messaging apps, phone calls, or online chats. Legitimate follow-up comes only through FBI personnel or other law enforcement officers. The agency also stresses that it never charges fees or requests cryptocurrency, gift cards, or wire transfers to recover stolen money.
HollowGraph malware uses a compromised Microsoft 365 calendar for C2.
Researchers at Group-IB have identified a new malware strain, dubbed HollowGraph, that uses a compromised Microsoft 365 calendar as a covert command-and-control channel. Instead of communicating with attacker-controlled servers, the malware leverages the Microsoft Graph API to receive instructions through calendar events and exfiltrate stolen data by creating its own encrypted calendar entries, blending malicious activity with legitimate Microsoft 365 traffic. It also uses DNS tunneling as a secondary channel to refresh configuration data and authentication credentials. Group-IB identified 12 victims, with evidence suggesting the campaign has been active since early June and primarily targets Israeli organizations. Researchers believe HollowGraph is part of a broader malware framework and note technical similarities to the Iran-linked threat group Lyceum, although they say the current evidence is insufficient for a high-confidence attribution.
Qilin ransomware targets a critical Palo Alto Networks flaw.
Arctic Wolf warns that affiliates of the Qilin ransomware operation are actively exploiting a critical Palo Alto Networks PAN-OS GlobalProtect authentication bypass vulnerability, tracked as CVE-2026-0257, to breach corporate networks. The flaw, patched in May, allows attackers to establish unauthorized VPN connections on unpatched systems. Investigations into multiple June incidents found the vulnerability led directly to Qilin ransomware deployments, ranging from rapid encryption attacks to double-extortion campaigns. Researchers believe exploitation is ongoing, urging organizations to patch affected GlobalProtect appliances immediately, particularly given the large number of internet-exposed VPN instances.
A North Korean campaign targets Web3 and cryptocurrency professionals through fake job recruitment scams.
Researchers at SOCRadar have uncovered a North Korean campaign, dubbed “ClickFake Interview,” targeting Web3 and cryptocurrency professionals through fake job recruitment scams. Attributed to the Famous Chollima threat group, the operation uses fraudulent recruiters on LinkedIn, Telegram, Discord, and email to lure candidates into fake online interviews. During a staged technical assessment, victims are prompted to run a “diagnostic” command to fix a fabricated camera or microphone issue, installing malware instead. Windows users receive the PylangGhost remote access trojan, while macOS users are infected with GolangGhost and, in some cases, a credential-stealing application. The malware targets browser-based cryptocurrency wallets, password managers, and sensitive credentials. Researchers warn the campaign also threatens organizations by potentially giving attackers access to corporate systems and digital assets through compromised employees.
Zimbra patches multiple critical bugs.
Zimbra has updated their Collaboration Suite to address multiple critical and high-severity vulnerabilities, including a command injection flaw that could allow unauthenticated attackers to execute operating system commands on vulnerable email servers. The update also fixes four cross-site scripting vulnerabilities, a mail forwarding restriction bypass, access control and authorization flaws, and a server-side request forgery issue in the Nextcloud integration. While Zimbra has not reported any of the vulnerabilities being exploited in the wild, it is urging customers to upgrade to version 10.1.20 as soon as possible.
Shadow AI creates regulatory headaches.
Security and legal experts are warning that unauthorized use of artificial intelligence, often called “shadow AI,” is creating significant regulatory and litigation risks for organizations. The issue gained attention after Community Bank in Pennsylvania disclosed that an employee used an unauthorized AI tool to process sensitive customer information, triggering SEC cybersecurity reporting requirements despite no external breach or system compromise. Experts say AI-related incidents increasingly center on unauthorized data exposure rather than traditional hacking, with companies potentially facing state breach notifications, regulatory scrutiny, lawsuits, and reputational damage. They recommend integrating AI governance into cybersecurity, data governance, and incident response programs, while involving legal, finance, and business leaders early when assessing materiality. Organizations should also improve visibility into AI use, provide approved alternatives to shadow AI tools, and train employees on responsible AI practices, as evolving state laws and litigation risks are expected to persist regardless of future federal regulatory changes.
Hackers wipe Romania’s land registry database.
Romania’s National Agency for Cadastre and Real Estate Advertising (ANCPI) is rebuilding its systems after a hacker allegedly breached the agency, failed to extort it, and wiped its land registry database. The attack has disrupted Romania’s real estate market for more than a week, leaving notaries unable to process property transactions and preventing citizens from accessing land ownership records. According to reports, the attacker used valid credentials to access the network, mapped internal systems, and deleted data and backups after the extortion attempt failed. Stolen employee credentials, internal documents, and IT network information were later offered for sale online. Officials say they are rebuilding the agency’s infrastructure from scratch and appear to have retained offline backups, allowing recovery despite the destructive attack.
Patching the automotive security system you didn’t know you had.
Modern cars increasingly need software updates, but UC San Diego researchers have discovered an unusual twist: millions of drivers may need to patch a security device they never knew they had. The culprit is the aftermarket KARR Security System, often installed by dealerships before a car is sold, even when buyers decline the feature. Researchers found a flaw that lets anyone within Bluetooth range unlock doors, disable alarms, honk horns, flash lights, or even prevent a vehicle from starting. The vulnerability stems from a shared authentication key embedded across all devices. Acrisure Protection Group has released a firmware update, but owners must install it themselves, assuming they know the device exists. Researchers estimate more than two million vehicles are affected, calling it one of the broadest automotive security risks to date. And for fans of Knight Rider, there’s an ironic footnote here. KARR was the show’s rogue, malfunctioning counterpart to KITT. It seems this KARR has also developed a knack for making drivers’ lives unnecessarily interesting.
And that’s the CyberWire.
For links to all of today’s stories, check out our Daily Briefing at the cyberwire dot com.
We’d love to know what you think of this podcast. Your feedback ensures we deliver the insights that keep you a step ahead in the rapidly changing world of cybersecurity. If you like the show, please share a rating and review in your podcast app. Please also fill out the survey in the show notes or send an email to cyberwire@n2k.com
We’re proud that N2K CyberWire is part of the daily routine of the most influential leaders and operators in the public and private sector, from the Fortune 500 to many of the world’s preeminent intelligence and law enforcement agencies.
N2K helps cybersecurity professionals and organizations grow, learn, and stay ahead. We’re the nexus for discovering the people, tech, and ideas shaping the industry. Learn how at n2k.com.
N2K’s lead producer is Liz Stokes. We’re mixed by Tré Hester, with original music by and sound design Elliott Peltzman. Our contributing host is Maria Varmazis. Our executive producer is Jennifer Eiben. Peter Kilpe is our publisher. And I’m Dave Bittner. Thanks for listening.
