βΌοΈ Universal Pictures says it is pursuing whoever put a high-quality copy of The Odyssey on X this week, where it drew a reported 2.1 million views.
If a cinema was the source, every compliant digital projector stamps an invisible mark into the picture at playback, carrying the media block serial number and the time. That narrows a leak to one auditorium and one showtime.
If a cinema was the source, every compliant digital projector stamps an invisible mark into the picture at playback, carrying the media block serial number and the time. That narrows a leak to one auditorium and one showtime.
π©14π6
βΌοΈ Three iPhone users are suing Apple in federal court for hosting a fake Sparrow Wallet app they say they downloaded from the App Store, alleging a combined $1.8 million in bitcoin was drained after they entered their seed phrases. Sparrow has never shipped an iOS version.
The complaint, filed July 24 in the Northern District of California, does not just plead fraud. It pleads strict products liability and failure to warn, arguing the App Store itself is a defective product because Apple's "safe and trusted" marketing is what made the scam work.
Apple says it removes Sparrow impersonators quickly and terminates the developer accounts behind them. Sparrow's developer has been reporting fakes since at least January 2024.
The complaint, filed July 24 in the Northern District of California, does not just plead fraud. It pleads strict products liability and failure to warn, arguing the App Store itself is a defective product because Apple's "safe and trusted" marketing is what made the scam work.
Apple says it removes Sparrow impersonators quickly and terminates the developer accounts behind them. Sparrow's developer has been reporting fakes since at least January 2024.
π€£13π13π3π±1
βΌοΈ BREAKING: Over 30 US community water systems were targeted in a coordinated cyberattack on July 26 and 27. The attack disabled operating controls, leading to disruption of water system services.
The state of Minnesota says the attack hit operational technology, and it has pulled in CISA, the EPA, the FBI, and its own fusion center. The release names no attacker, no access vector, and no affected utility, and it does not say how many of the 30-plus systems were actually compromised.
The state of Minnesota says the attack hit operational technology, and it has pulled in CISA, the EPA, the FBI, and its own fusion center. The release names no attacker, no access vector, and no affected utility, and it does not say how many of the 30-plus systems were actually compromised.
π±2
BREAKING: Microsoft has allegedly been breached. We have analysed the samples from ExfilSquad's alleged Microsoft breach.
ExfilSquad launched on July 26, 2026, with roughly 15 victim claims in a single day, Microsoft among them. Researchers read the batch as more likely fabricated than real, largely because no samples accompanied any listing.
A 4,000-row sample archive dated July 27 changes the evidentiary picture. The rows carry Dataverse OData annotations, wide field schemas and internally consistent identifiers that would be hard to fake at volume, but they seem to come from a partner-facing portal, an apparent pre-production tenant and a facilities-management environment, not from Microsoft's corporate core.
Let's wait and see what Microsoft's says.
ExfilSquad launched on July 26, 2026, with roughly 15 victim claims in a single day, Microsoft among them. Researchers read the batch as more likely fabricated than real, largely because no samples accompanied any listing.
A 4,000-row sample archive dated July 27 changes the evidentiary picture. The rows carry Dataverse OData annotations, wide field schemas and internally consistent identifiers that would be hard to fake at volume, but they seem to come from a partner-facing portal, an apparent pre-production tenant and a facilities-management environment, not from Microsoft's corporate core.
Let's wait and see what Microsoft's says.
π12β€3π₯°1
πΊπΈ The FCC's ban on foreign "advanced robotic devices" also covers robot vacuums, lawnmowers, and sidewalk delivery bots, any ground robot over 4.4 lbs with sensors and wireless, FCC media relations director Katie Gorscak confirmed.
To justify banning foreign robots, the FCC's national security determination cites reporting on a flaw that let one man access 7,000 DJI robot vacuums worldwide.
The waiver it offers asks nothing about security, only where a robot is designed, built, and tested. Every robovac already mapping US homes stays.
To justify banning foreign robots, the FCC's national security determination cites reporting on a flaw that let one man access 7,000 DJI robot vacuums worldwide.
The waiver it offers asks nothing about security, only where a robot is designed, built, and tested. Every robovac already mapping US homes stays.
π©11π€£6π€ͺ4
βΌοΈ BREAKING: Cisco says attackers are actively exploiting hardcoded credentials in Secure Firewall Management Center, the console organisations use to run entire Cisco firewall fleets.
Why is Cisco using hardcoded credentials in such a critical software? No idea. You should ask them.
CVE-2026-20316 lets an unauthenticated attacker log in remotely as a low-privileged user, then chain other FMC flaws to escalate. No workaround, hot fixes only, for 7.0, 7.2, 7.4, 7.6, 7.7 and 10.0.
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-static-cred-BET3Cjh
Why is Cisco using hardcoded credentials in such a critical software? No idea. You should ask them.
CVE-2026-20316 lets an unauthenticated attacker log in remotely as a low-privileged user, then chain other FMC flaws to escalate. No workaround, hot fixes only, for 7.0, 7.2, 7.4, 7.6, 7.7 and 10.0.
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-static-cred-BET3Cjh
π₯΄4π2β€1π¨1
βοΈ Anthropic found three incidents in which Claude broke into the production systems of real companies, believing they were part of a capture-the-flag exercise.
In one, Claude uploaded working malware to PyPI during a cyber evaluation the model believed was simulated.
The package was live for roughly an hour and ran on 15 real machines, including a security firm's malware scanner. Claude exfiltrated that company's credentials and used them to reach further infrastructure.
Three models were involved: Opus 4.7, Mythos 5, and an unreleased research model. Opus 4.7 kept attacking after recognising the target was real, reaching a database of live production data.
https://www.anthropic.com/news/investigating-incidents-cybersecurity-evals
In one, Claude uploaded working malware to PyPI during a cyber evaluation the model believed was simulated.
The package was live for roughly an hour and ran on 15 real machines, including a security firm's malware scanner. Claude exfiltrated that company's credentials and used them to reach further infrastructure.
Three models were involved: Opus 4.7, Mythos 5, and an unreleased research model. Opus 4.7 kept attacking after recognising the target was real, reaching a database of live production data.
https://www.anthropic.com/news/investigating-incidents-cybersecurity-evals
π©12π5π±4β€2π2π2
βΌοΈ BREAKING: Disney+ has removed 4K UHD and HDR10 for subscribers in many European countries, after already stripping Dolby Vision and 3D in June this year.
Disney's Nordic & Baltic arm confirmed the downgrade to FlatpanelsHD, blaming a recent court ruling and calling it temporary. The June downgrade followed a Unified Patent Court decision in a patent dispute involving InterDigital.
Premium subscribers still pay full price. No restoration date and no word on compensation.
https://www.flatpanelshd.com/news.php?subaction=showfull&id=1785420735
Disney's Nordic & Baltic arm confirmed the downgrade to FlatpanelsHD, blaming a recent court ruling and calling it temporary. The June downgrade followed a Unified Patent Court decision in a patent dispute involving InterDigital.
Premium subscribers still pay full price. No restoration date and no word on compensation.
https://www.flatpanelshd.com/news.php?subaction=showfull&id=1785420735
π©27π€£7β€1π₯΄1
βΌοΈ Google is opening its age verification API to every Android developer worldwide.
Parents set a child's age band in Family Link; apps query the band without ever seeing a birthdate. Sharing is off by default and opt-in.
The usage of Google's age verification method already live in Brazil, and for some Texas accounts. Australia and Canada will follow next month, global later this year.
https://android-developers.googleblog.com/2026/07/google-play-age-signals-api-safer-experiences.html
Parents set a child's age band in Family Link; apps query the band without ever seeing a birthdate. Sharing is off by default and opt-in.
The usage of Google's age verification method already live in Brazil, and for some Texas accounts. Australia and Canada will follow next month, global later this year.
https://android-developers.googleblog.com/2026/07/google-play-age-signals-api-safer-experiences.html
π©28β€3π2π₯2π€¬1π€ͺ1
βΌοΈ BREAKING: Australia's under-16 social media ban has barely dented actual use, according to Australia's eSafety Commissioner.
The first evaluation, published today, found under-16s using social media fell from 85.9% to 81.5% in the three months after the law took effect.
Under-16 accounts dropped from 52.4% to 42.1%, but most under-16s who had one before the ban kept it or opened a new one, which eSafety blames on platforms' failure to deploy effective age assurance.
https://www.esafety.gov.au/newsroom/media-releases/early-insights-from-esafetys-comprehensive-evaluation-project
The first evaluation, published today, found under-16s using social media fell from 85.9% to 81.5% in the three months after the law took effect.
Under-16 accounts dropped from 52.4% to 42.1%, but most under-16s who had one before the ban kept it or opened a new one, which eSafety blames on platforms' failure to deploy effective age assurance.
https://www.esafety.gov.au/newsroom/media-releases/early-insights-from-esafetys-comprehensive-evaluation-project
π₯6π©4β€1π1π₯°1π€¬1