Cybersecurity Headlines

Nvidia opens AI security tent, Microsoft adds cyber sprinter to MDASH, Fairlife ransomware spills data

8 min
Jul 28, 202627 days ago
Listen to Episode
Summary

This episode covers NVIDIA's new Open Secure AI alliance for AI security, Microsoft's smaller security-focused AI model integrated into its vulnerability hunting system, and a ransomware attack on Coca-Cola's Fairlife subsidiary. Additional stories include personalized Telegram phishing campaigns, public exploit releases for vBulletin, Claude chat data exposure, and CLOP ransomware exploiting PTC Windchill vulnerabilities.

Insights
  • Open-source AI models are emerging as defensive security assets, not just risks, particularly when defenders can run them locally without restrictions
  • Smaller, specialized AI models can handle 90% of security tasks cost-effectively while routing complex cases to larger models, improving ROI
  • Legacy VPN infrastructure remains a critical vulnerability vector, prompting federal policy intervention toward zero-trust architecture
  • Agentic AI is changing the threat landscape for small businesses, making them economically viable targets for attackers
  • Public disclosure of exploit code significantly accelerates real-world attacks, with CLOP ransomware beginning campaigns within days of vulnerability disclosure
Trends
Open-source AI models gaining acceptance as security tools in enterprise defense strategiesHybrid AI model architectures combining smaller specialized models with larger general-purpose models for cost optimizationIncreased regulatory pressure on federal agencies to modernize remote access infrastructure and adopt zero-trust principlesRansomware gangs exploiting unpatched enterprise software within weeks of public exploit disclosureHighly personalized phishing campaigns using device fingerprinting and personal data to increase compromise ratesSupply chain attacks targeting manufacturing and aerospace sectors through software vulnerabilitiesData exposure risks in AI chatbot shared links indexed by search enginesDeepfake video and voice technology enabling financial fraud at scale
Companies
NVIDIA
Leading new Open Secure AI alliance with 30+ founding members to build open models and tools for securing AI software
Microsoft
Introduced MAI Cyber One Flash security model in M-Dash vulnerability hunting system; founding member of NVIDIA alliance
Coca-Cola
Confirmed data theft during ransomware attack on Fairlife dairy subsidiary; production temporarily halted at four U.S...
CrowdStrike
Founding member of NVIDIA's Open Secure AI alliance for AI security collaboration
Hugging Face
Experienced intrusion where commercial models blocked exploit code; founding member of NVIDIA alliance
IBM
Founding member of NVIDIA's Open Secure AI alliance for AI security initiatives
Cisco
Founding member of NVIDIA alliance; legacy VPN appliances cited as repeat attack entry points by Senator Wyden
Linux Foundation
Founding member of NVIDIA's Open Secure AI alliance supporting open AI security models and tools
Anubis Gang
Claimed responsibility for Fairlife ransomware attack, encrypting Nutanix systems and stealing one terabyte of data
PTC
Windchill and Flex PLM vulnerability exploited by CLOP ransomware affiliate; patched June 17, exploitation began July 20
Fortinet
Legacy VPN appliances cited by Senator Wyden as repeat attack entry point for federal agencies
Checkpoint
Remote access appliances mentioned as repeat vulnerability vector in federal agency attacks
Palo Alto Networks
Evante remote access products cited as repeat attack entry points in federal agency breaches
Anthropic
Claude shared chats indexed by Google, exposing API credentials, crypto wallets, and personal data publicly
Google
Search engine indexed Claude shared chats containing sensitive data; results removed but underlying links remain acce...
Nutanix
Systems encrypted by Anubis gang during Fairlife ransomware attack
People
Sarah Lane
Host reporting on cybersecurity headlines for the CISO series podcast
Ron Wyden
Advocating for federal agencies to retire legacy VPN servers and adopt zero-trust architecture
Quotes
"Open models can be defensive assets, not just security risks, especially when defenders need to run them locally with fewer restrictions"
NVIDIA (via alliance statement)Opening segment
"The smaller model can handle about 90% of M-Dash tasks, while the hardest 10% get routed to GPT 5.4"
Microsoft (via product announcement)Microsoft segment
"Agentic AI has changed that math. So how do they start to address this chasm?"
Sarah LaneSuper Cyber Friday promotion
Full Transcript
From the CISO series, it's Cybersecurity Headlines. These are the Cybersecurity Headlines for Tuesday, July 28, 2026. I'm Sarah Lane. NVIDIA opens the AI security tent. NVIDIA is leading a new Open Secure AI alliance with more than 30 founding members, including Microsoft, CrowdStrike, Hugging Face, IBM, Cisco, and the Linux Foundation. The group plans to build and share open models and tools and techniques for securing AI software and agents. NVIDIA tied the launch to the recent Hugging Face intrusion, where commercial models blocked real exploit code during the investigation, and an open-weight model helped reconstruct more than 17,000 attacker actions. The alliance argues that open models can be defensive assets, not just security risks, especially when defenders need to run them locally with fewer restrictions. Microsoft puts a cyber sprinter in M-Dash. Microsoft introduced MAI Cyber One Flash, its first security-focused model, inside the company's M-Dash multi-agent vulnerability hunting system. Microsoft says the smaller model can handle about 90% of M-Dash tasks, while the hardest 10% get routed to GPT 5.4. That mix scored 96% on the Cyber Gym benchmark, 12 points above Mythos, while cutting costs in half compared with Microsoft's previous M-Model lineup. The system uses more than 100 agents to find, validate, and help remediate software flaws with sandbox execution and no internet access. Fairlife ransomware spills data. Coca-Cola confirmed that hackers stole data during the ransomware attack on its Fairlife dairy subsidiary. The incident temporarily shut down production at four U facilities but the company says most production has resumed Existing inventory covered shortages and product quality and safety were never affected. The Anubis gang claimed it encrypted Fairlife's Nutanix systems and stole one terabyte of data, although that amount has not been independently verified. Coca-Cola says some systems are still being restored, while the gang's deadline has expired, and the stolen files are now available for downloads. Telegram phishers make it personal. Researchers at Resident NGO uncovered a highly personalized telegram phishing campaign targeting an exiled Belarusian activist and users in Belarus, Russia, and Kazakhstan. The attackers sent fake security alerts through Telegram's secret chats and built a unique link for each target, including that person's phone number. victims who entered telegram's one-time login code could have their accounts taken over immediately the infrastructure checked each visitor's device and browser redirected security tools to harmless pages and then followed up with messages that included the victim's device the visit time and their internet provider researchers found 64 phone numbers in those links but couldn't confirm that every single person received the lure or that any account was actually compromised Huge thanks to our sponsor, Pindrop. A finance worker joined a video call with their CFO and wired $20 million to attackers. This isn't fiction. It happened. Deep fake video. AI voice. Completely convincing. It could be happening in your meetings right now. Pindrop polls for meetings can detect deep fake impersonation before the damage is done. Go to Pindrop.com and start verifying. The Bulletin Exploit Goes Public An unnamed researcher appears to have released public exploit details for a critical vBulletin flaw that lets an unauthenticated attacker run PHP code on a forum server The bug sits in the template engine and can be triggered with a specially crafted page nav parameter. Versions 6.2.1 and earlier, along with 6.1.6 and earlier, are affected. The Bulletin issued patches at the end of June and released version 6.2.2 on July 1st, almost four weeks before the exploit became public. Administrators should patch now and check for signs of compromise. Claude's shared chats escape the group chat. Some Claude conversations shared through public links were indexed by Google, making them searchable by anybody who knew the right site query. The indexed chats reportedly included API credentials, crypto wallet information, resumes, legal strategy, and other personal data. No evidence that private but unshared clawed conversations were exposed. They had to be public. Google results for the shared pages have disappeared, but removing a search result doesn't disable the underlying link. Users can review and unshare old links under their settings, then privacy, then shared chats. CLOP rides a windchill flaw. A CLOP ransomware affiliate is exploiting a critical PTC windchill and flex PLM flaw to break into organizations without authentication. The vulnerability lets attackers execute code remotely, deploy web shells, search file systems, and stage data for extortion. PTC patched it on June 17th and reported exploitation the next day, but the current campaign began July 20th and has hit aerospace, automotive, manufacturing, and retail and apparel organizations Attackers have also sent extortion emails to hundreds of users inside affected companies Organizations should apply PTC fixes and hunt with the published indicators of compromise Wyden wants legacy VPNs shown the door. Oregon Senator Ron Wyden wants federal agencies to retire old VPN servers that sit directly on the public internet, saying those systems have become a repeat entry point in attacks involving Cisco, Fortinet, Evante, and Checkpoint appliances, leaving CISA stuck issuing emergency patch orders. Wyden is asking CISA to give agencies two years to remove legacy public-facing remote access systems and shift to zero-trust tools that don't advertise an exposed front door. He also wants National Institute of Standards and Technology Implementation Standards and procurement rules that block agencies and defense contractors from buying remote access products that don't meet federal zero trust requirements. Remember to register for this Friday's Super Cyber Friday. At 1 p.m. Eastern time this Friday, we're going to be talking about hacking the SMB security gap. We know small businesses have always ignored security. It used to be that they weren't worth the time of your average threat actor to pop. But agentic AI has changed that math. So how do they start to address this chasm? Register at supercyberfriday.com for the events and join in on the conversation. And if you have thoughts on the news from today or about our show in general, be sure to reach out to us, feedback at cisoseries.com. We always want to hear from you. I am Sarah Lane reporting for the CISO series. You stay classy out there, planet Earth. Cybersecurity headlines are available every weekday. Head to CISOseries.com for the full stories behind the headlines.