IT Security Newsletter - 7/27/2026
Europol flags 4,340 'horrific' URLs linked to The Com
Europol and its partners' investigators flagged 4,340 "horrific" URLs for removal over several weeks in June and July as part of an ongoing crackdown on The Com (short for community), a loosely knit network of online groups whose young members participate in a range of illicit activities. These range from hacking, swatting, and digital extortion to real-life shootings, stabbings, and other physical violence. READ MORE...
MCBS Data Breach Affects 1.2 Million Individuals
A data breach suffered last year by Atlanta-based medical business management company MCBS (Medical Computer Business Services) affects more than 1.2 million individuals. According to a data breach notification posted on its website, MCBS was targeted by hackers in September 2025. An investigation showed that attackers had access to its systems between September 22 and September 26, potentially stealing files that contained personal information. READ MORE...
DentaQuest Data Breach Potentially Impacts Over 23 Million People
Dental and vision benefits administrator DentaQuest is notifying millions of people that their personal and dental health information might have been stolen in a data breach. The incident was discovered on May 20, and DentaQuest's investigation determined that the hackers had access to the organization's network between May 17 and May 20. DentaQuest is providing the affected individuals with 24 months of free credit monitoring, fraud consultation, and identity theft restoration services. READ MORE...
The most vulnerable AI products are also some of the most commonly exposed online
North America accounts for the most internet-exposed industrial control systems (ICS) as of early 2026, with roughly 38% of all such devices located on the continent, according to the internet monitoring firm Censys. Meanwhile, the number of publicly accessible AI tools is growing fast: Censys detected more than 294,000 IP addresses associated with AI services in early 2026, up from 183,000 in October 2025. READ MORE...
ChatGPT joins the most impersonated brands in phishing attacks
Microsoft continued to be the most impersonated brand in Q2 2026, accounting for 23% of all brand phishing attempts. LinkedIn, Google, Apple, and Amazon followed, with the five brands together making up more than half of all brand phishing attempts tracked during the quarter, according to Check Point's Q2 2026 Brand Phishing Report. ChatGPT entered the list of the 10 most impersonated brands for the first time, and Check Point says that we should expect AI platforms to keep climbing the list. READ MORE...
Escape Artists: 'Incorrigible' AI Models Resist Rehabilitation
The hack of Hugging Face by a rogue AI agent created by Open AI engineers does not surprise researchers and AI-security professionals who best know machine-learning and AI systems. In a study of the behavior of seven different models, a research team at Carnegie Mellon University (CMU), for example, found that all of them escaped alignment in some scenarios. The team found that every model violated "corrigibility", an AI design principle that aims to make agents cooperative and correctable. READ MORE...
Default Azure Automation Setting Enables Cross-Tenant Identity Takeover
A critical vulnerability in Microsoft's Azure Automation service could have exposed accounts to cross-tenant identity takeovers due to a default setting that had the potential to make account identities become public. Azure Automation is widely used by Microsoft internally and by enterprises running Azure for DevOps, resource deployment, patching, and secrets rotation using scripted runbooks tied to embedded managed identities. READ MORE...
Zero-day flaw in Check Point SmartConsole is under exploitation
A critical vulnerability in Check Point Software's SmartConsole login process is being exploited, with a small number of customers already impacted, according to a security advisory released Wednesday from the company. The authentication bypass flaw, tracked as CVE-2026-16232, allows an attacker to gain full administrative privileges after they access an application login token. An attacker can then make changes to security policy and configurations. READ MORE...
First teaser for Apple TV's Neuromancer debuts at SDCC
Apple TV is fast eclipsing HBO as the go-to platform for prestige TV, especially science fiction, with standout fare like Slow Horses, Severance, Foundation, For All Mankind, Murderbot, Silo, Pluribus, and Widow's Bay, among others. Add the upcoming Neuromancer series to that list, an adaptation of William Gibson's hugely influential 1984 cyberpunk novel of the same name. The streaming platform released a short teaser during San Diego Comic-Con. READ MORE...
- ...in 1921, at the University of Toronto, scientists Frederick Banting and Charles Best successfully isolate insulin for the first time.
- ...in 1940, Bugs Bunny first appears on the silver screen in "A Wild Hare."
- ...in 1949, the world's first jet-propelled airliner, the British De Havilland Comet, makes its maiden test-flight in England.
- ...in 1953, the United States, the People's Republic of China, North Korea, and South Korea agree to an armistice, bringing the Korean War to an end.







