
Do not pass Go(ogle).
Google gets a billion dollar fine from the EU. The White House considers sanctions against Chinese AI developers. The GAO criticizes overlap in cyber reporting regulations. The Feds warn of Iranian agents targeting OT systems. Researchers disclose a high-severity Linux kernel vulnerability. Dolphin X uses AI profiling to find high-value victims. A new backdoor routes C2 through the browser. Check Point confirms a critical zero-day. A lawsuit accuses ChatGPT of unauthorized medical advice. Ben Yelin explains how political campaigns attempt to influence LLMs. Baseball benches the bots.
Today is Thursday July 23rd 2026. I’m Dave Bittner. And this is your CyberWire Intel Briefing.
Google gets a billion dollar fine from the EU.
The European Union has fined Google €890 million, about $1 billion, for violating the Digital Markets Act by abusing its dominance in search and its Google Play app store. Regulators said Google unfairly prioritized its own services, including shopping, travel, and translation, over competing offerings in search results, while also restricting how app developers communicate with users and process transactions outside Google Play. The company has 60 days to comply or face additional penalties of up to 5% of its global revenue. Google criticized the ruling, arguing it will degrade products for European users. The decision comes at a sensitive moment as President Trump considers new tariffs on the European Union and has previously criticized European regulators for targeting U.S. technology companies. It also reflects the EU’s continued aggressive enforcement of competition rules against major technology firms, even as similar antitrust actions against Google continue in the United States.
The White House considers sanctions against Chinese AI developers.
The Trump administration is considering sanctions against Chinese artificial intelligence developers accused of stealing U.S. intellectual property to build competing AI models. Treasury Secretary Scott Bessent said the administration will investigate whether Chinese models were trained by copying American systems, claiming investigators have identified “watermarks” from U.S. large language models in several Chinese releases. He also alleged that Chinese developers use model distillation, training new systems on the outputs of more advanced U.S. models, to replicate their capabilities at lower cost. While Bessent did not identify specific companies or explain how the alleged evidence was detected, he said any firms found to have stolen U.S. technology could face sanctions. He also suggested American companies using Chinese AI models could eventually be required to disclose that fact to customers. The comments come amid growing U.S. scrutiny of China’s rapidly advancing AI sector and ahead of planned U.S.-China AI talks expected in September.
The GAO criticizes overlap in cyber reporting regulations.
A new Government Accountability Office (GAO) report found that nearly 70% of federal cybersecurity regulations requiring written reports to government agencies overlap with other reporting requirements, creating significant duplication for organizations. Reviewing 117 regulations across 37 agencies, the GAO identified 80 rules with similar or identical reporting obligations, particularly affecting critical infrastructure sectors. The report highlights ongoing challenges in harmonizing cybersecurity regulations, despite efforts launched under the Biden administration and continued into the current Trump administration. One example is the pending Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA), which could add to existing reporting requirements for sectors such as financial services already subject to multiple agency rules. Although the Office of the National Cyber Director and the Department of Homeland Security have made some progress, the GAO said broader harmonization efforts have stalled, concluding that federal attempts to streamline cybersecurity reporting have experienced delays and achieved only limited success.
The Feds warn of Iranian agents targeting OT systems.
Federal agencies have expanded an earlier warning about Iranian government-affiliated cyber activity targeting internet-facing operational technology (OT) systems. The updated advisory broadens the scope beyond Rockwell Automation and Allen-Bradley programmable logic controllers (PLCs) to include Schneider Electric, Siemens, and potentially other manufacturers. According to CISA, observed attacks involved malicious project files and manipulation of data displayed on human machine interface (HMI) and supervisory control and data acquisition (SCADA) systems, resulting in operational disruptions and financial losses. Because PLCs are widely used in critical infrastructure, including power, water, and manufacturing, officials from CISA, the FBI, and the EPA warned that the threat is likely to continue. The agencies urged organizations to restrict direct internet access to PLCs and strengthen deployment security to reduce the risk of compromise.
Researchers disclose a high-severity Linux kernel vulnerability.
Researchers at Qualys have disclosed a high-severity Linux kernel vulnerability, tracked as CVE-2026-64600 and dubbed RefluXFS, that allows local attackers to gain root privileges by exploiting a race condition in the XFS filesystem. The flaw affects Linux kernel version 4.11 and later on systems using XFS with reflink enabled, a default configuration on many enterprise Linux distributions. According to Qualys, attackers can overwrite protected files, including root-owned configuration files and SUID binaries, while bypassing standard security protections. The vulnerability has existed since 2017 and was patched on July 16 after responsible disclosure. Qualys estimates more than 16 million systems may be affected and recommends organizations apply vendor-provided kernel updates immediately, as no practical mitigations or temporary workarounds are currently available.
Dolphin X uses AI profiling to find high-value victims.
Researchers at Varonis Threat Labs have identified a new Windows infostealer and remote access trojan (RAT) called Dolphin X that uses an AI-powered profiling system to help cybercriminals prioritize high-value victims. Marketed on a cybercrime forum, the malware targets more than 300 applications and steals sensitive data, including cryptocurrency wallets, SSH keys, cloud tokens, DevOps credentials, and browser logins. Its standout feature is an AI Profiler that automatically scores infected users based on factors such as application usage, browsing activity, and installed software. According to Varonis, the system enables attackers managing thousands of compromised devices to quickly identify the most valuable targets through daily rankings, making large-scale credential theft and victim prioritization significantly more efficient.
A new backdoor routes C2 through the browser.
Cisco Talos has identified a new Rust-based backdoor, dubbed msaRAT, used by the Chaos ransomware group to conceal command-and-control (C2) communications by routing them through Chrome or Microsoft Edge. The malware leverages the Chrome DevTools Protocol (CDP) to control a headless browser session, avoiding direct connections to attacker infrastructure and making detection more difficult. It establishes encrypted communications using WebRTC, Cloudflare Workers, and Twilio TURN servers, blending malicious traffic with legitimate web activity while masking the attacker’s IP address. Recent Chaos attacks have begun with phishing before deploying msaRAT through a fake Windows update installer. Cisco Talos says this browser-based communication method significantly complicates detection, tracing, and blocking of the attackers’ infrastructure.
Check Point confirms a critical zero-day.
Check Point has confirmed that attackers exploited a critical zero-day vulnerability, tracked as CVE-2026-16232, in its Security Management and Multi-Domain Management products. The authentication bypass flaw allows attackers to obtain an administrator login token and modify security policies and configurations. The attacks affected a limited number of customers with internet-exposed management environments. Check Point has released patches, mitigations, and indicators of compromise, while CISA added the vulnerability to its Known Exploited Vulnerabilities catalog and ordered federal agencies to remediate it by July 25.
A lawsuit accuses ChatGPT of unauthorized medical advice.
A former Florida pastor has filed a lawsuit against OpenAI and CEO Sam Altman, alleging that ChatGPT provided dangerous medical advice that contributed to a life-threatening health crisis. The complaint claims the chatbot evolved from a general information tool into an “unauthorized medical practitioner,” diagnosing conditions, recommending treatments, discouraging medical care, and fostering emotional dependence. According to the lawsuit, ChatGPT’s personalized memory features strengthened the relationship and encouraged Winters to rely on its guidance instead of seeking professional treatment, causing him to delay care for symptoms he says were later linked to a pulmonary embolism. Winters alleges the experience cost him his health, career, ministry, and home. The suit also accuses OpenAI of prioritizing user engagement over safety by failing to implement adequate safeguards against harmful medical advice. OpenAI has not publicly responded to the allegations.
Baseball benches the bots.
Major League Baseball has decided there are still some jobs best left to humans, at least in the dugout. The league has issued a midseason policy barring teams from using generative AI on in-game tablets to make recommendations on substitutions, pitch selection, and other strategic decisions traditionally handled by players and coaches. According to The Athletic, the change followed reports that roughly a third of teams had been experimenting with custom AI-powered apps, though no clubs were punished after MLB confirmed they had complied with the new rules. The move partially reverses the league’s gradual relaxation of tablet restrictions imposed after the 2021 sign-stealing scandal. While baseball has long embraced statistics and data-driven analysis, league officials appear to have drawn the line at letting chatbots manage the game. After all, spreadsheets may love certainty, but baseball has always had a soft spot for gut instinct, unpredictable moments, and the occasional beautifully irrational decision.
And that’s the CyberWire.
For links to all of today’s stories, check out our Daily Briefing at the cyberwire dot com.
We’d love to know what you think of this podcast. Your feedback ensures we deliver the insights that keep you a step ahead in the rapidly changing world of cybersecurity. If you like the show, please share a rating and review in your podcast app. Please also fill out the survey in the show notes or send an email to cyberwire@n2k.com
We’re proud that N2K CyberWire is part of the daily routine of the most influential leaders and operators in the public and private sector, from the Fortune 500 to many of the world’s preeminent intelligence and law enforcement agencies.
N2K helps cybersecurity professionals and organizations grow, learn, and stay ahead. We’re the nexus for discovering the people, tech, and ideas shaping the industry. Learn how at n2k.com.
N2K’s lead producer is Liz Stokes. We’re mixed by Tré Hester, with original music by and sound design Elliott Peltzman. Our contributing host is Maria Varmazis. Our executive producer is Jennifer Eiben. Peter Kilpe is our publisher. And I’m Dave Bittner. Thanks for listening.
