
Loading summary
A
From the CISO series, it's Cybersecurity Headlines
B
these are the cybersecurity headlines for Tuesday, July 14, 2026. I'm Sarah Lane. Russia's Router access routes, the United States and 12 additional countries said in a joint cybersecurity advisory Monday that Russia's Federal Security Service, or fsb, linked hackers are going after network devices, especially older Cisco gear that still exposes smart install or legacy snmp. The advisory points to older weaknesses that let attackers pull configuration files, modify settings, and quietly use routers and switches as footholds. This obviously matters because the boxes sit in front of the network, often get patched late or never, and can give an intelligence service a map of how an organization is built before any real intrusion even begins. Europe Sanctions Russia's long game in more Russia related news, the EU is sanctioning Russian cyber spies over a long running hacking campaign tied to the country's intelligence services. The action targets people and entities accused of helping Russian operations against European governments and critical infrastructure, including activity linked to the FSB and Gruff. The bigger message is that Europe is treating these intrusions as part of Russia's broader pressure campaign, not isolated hacks, but years of spying disruption and positioning inside networks of importance. MEM Ghost Haunts AI Memory Researchers published a paper called When Claws Remember but Do Not Tell on the open access archive called Archive with an X. About MemGhost A Word, a one shot attack framework that tries to poison an AI agent's long term memory through a single email. The target isn't just getting the agent to read bad instructions once, but getting it to save false facts or preferences and then act on them later as if they were trusted. History in tests across 56 held out cases, MemGhost reached an 87.5% N2N success rate on OpenClaw with GPT 5.4 and 71.4% on Claude Code SDK with with Sonnet 4.6. So persistent memory apparently needs its own security controls, not just better prompts. DHS alert got waved off twice A Department of Homeland Security network intrusion reportedly made it through two early reviews because the alerts were dismissed as false positives before the breach was finally confirmed, according to an internal readout c seen by NexGov. The big problem is not just getting alerts, it's deciding which signal deserves escalation before an attacker has more time inside the network. It's a good reminder that detection, engineering and incident response matters just as much as the tool itself, especially inside agencies where a missed internal compromise can turn into a much bigger national security problem. Huge. Thanks to our sponsor, ThreatLocker, every security leader is being asked the same question right now. How do we enable innovation without creating unnecessary risk? That's the challenge behind cloud adoption, behind AI, behind automation, and behind every major technology decision. ThreatLocker helps organizations take a zero trust approach to that challenge, giving them greater control over what can execute, what can access their environment, and what users and applications are allowed to do. That's why ThreatLocker is proud to support cybersecurity headlines, because security works when innovation and control move together. Joomla bugs hit CISA's must patch list CISA added two actively exploited remote code execution bugs in Joomla. Extensions to its known exploited vulnerabilities catalog with maximum priority. That gives federal agencies a patch deadline of July 13th to apply security updates and mitigations within three days. Extension flaws are especially risky because site owners may keep the core CMS updated while older plugins quietly stay exposed. Once attackers get remote code execution on a public facing site, the next step can be Web shells, credential theft redirects, or using that server as a foothold for more attacks. Pakistan's police systems draw spies Researchers say police systems in Pakistan have been targeted by cyber espionage activity linked to both Chinese and Indian interests, which makes the story not just about cybercrime but about regional intelligence collection. Police networks can hold identity records, investigations, case files, informant details, and communications that are valuable well beyond law enforcement. In that context, a compromise can become a way to track people, map government operations or gather leverage intense geopolitical environments. LIDL breach hits online shoppers German supermarket chain at Lidl is warning online shop customers in Germany, Belgium and the Netherlands that attackers retrieved access to their personal information through a hacked IT service provider. The exposed data included names, phone numbers, email addresses, dates of birth, and registered customer numbers, Lidl says. Passwords and payment information not affected. But the stolen contact data is still useful for phishing, especially if scammers pretend to be following up on the breach. Crash Stealer slips past Gatekeeper Researchers from JAMF Threat Labs are warning about Crash Stealer, a macOS malware campaign using a notarized dropper to get past Apple's Gatekeeper checks. Notarization is supposed to give users and security teams more confidence that an app has cleared Apple's automated screening. But if attackers can get the first stage dropper notarized, they can make the infection look less suspicious at the exact moment the a user is deciding whether to run it. Once installed stealers typically go after browser data, credentials, crypto wallets and other high value local information. If you have any thoughts on the news from today or about our show in general, be sure to reach out to us feedbackisoseries.com we really want to hear from you. I am Sarah Lane reporting for the CISO series. Stay Safe out There. Planet Earth
A
cybersecurity headlines are available every weekday. Head to cisoseries. Com for the full stories behind the headlines.
Main Theme:
The episode provides a concise roundup of the day's most pressing cybersecurity stories, spotlighting state-sponsored attacks, vulnerabilities in widely used hardware and software, evolving malware threats, and the persistent challenge of distinguishing real incidents from false alarms.
"This obviously matters because the boxes sit in front of the network, often get patched late or never, and can give an intelligence service a map of how an organization is built before any real intrusion even begins."
(Sarah Lane, 00:41)
"...Europe is treating these intrusions as part of Russia's broader pressure campaign, not isolated hacks, but years of spying disruption and positioning inside networks of importance."
(Sarah Lane, 01:22)
"So persistent memory apparently needs its own security controls, not just better prompts."
(Sarah Lane, 02:09)
"It's a good reminder that detection, engineering and incident response matters just as much as the tool itself, especially inside agencies where a missed internal compromise can turn into a much bigger national security problem."
(Sarah Lane, 02:45)
"...site owners may keep the core CMS updated while older plugins quietly stay exposed."
(Sarah Lane, 04:00)
"...a compromise can become a way to track people, map government operations or gather leverage intense geopolitical environments."
(Sarah Lane, 04:38)
"But the stolen contact data is still useful for phishing, especially if scammers pretend to be following up on the breach."
(Sarah Lane, 05:19)
"But if attackers can get the first stage dropper notarized, they can make the infection look less suspicious at the exact moment the user is deciding whether to run it."
(Sarah Lane, 05:59)
Sarah Lane’s delivery is brisk, clear, and nuanced—balancing the urgency of rapidly evolving risks with practical analysis for industry professionals.
This episode underscores the pervasiveness and escalating sophistication of both state-backed and criminal cyber threats—reminding listeners of the crucial importance of timely patching, vigilant incident response, and the changing attack landscape, especially as AI and other emerging technologies introduce new vulnerabilities.
For deeper dives on any headline, visit CISOseries.com.