July 2026 Cybersecurity Digest

July 2026 Cybersecurity News Digest

This month's cybersecurity roundup is a reminder that security threats keep evolving on every front – from massive data breaches to AI systems now capable of finding and exploiting vulnerabilities on their own, alongside Microsoft's biggest Patch Tuesday of the year.

1.      Hackers claim to have breached Decathlon’s customer database, exposing 160 million records

A threat actor is claiming to sell a Decathlon customer database with around 160 million records on a cybercrime forum. The breach remains unverified, and Decathlon has not confirmed any compromise to its systems or data. The stolen database allegedly includes a wide range of personally identifiable information (PII), raising concerns about privacy and security for customers. Potential risks include credential-stuffing attacks and phishing campaigns using stolen information. Customers are advised to change passwords, use unique passwords from a password manager, enable multi-factor authentication, and be vigilant against unsolicited communications. Organisations should also remind employees not to reuse corporate credentials across consumer platforms. As of now, the breach claims remain unconfirmed by Decathlon.

2.      Google launches "Selfie Video" identity verification feature for accessing locked accounts

Google has launched a new identity verification feature called “selfie video” to assist users in recovering locked accounts. This feature offers an alternative sign-in method when users lose access to primary authentication devices. Users can record a short video of themselves, which is stored as a biometric reference for future verifications.

The setup process is straightforward, guiding users through recording a video with specific head movements. During account recovery, a new selfie video can be submitted for comparison with the original. This method aims to enhance security by reducing reliance on static credentials, though it raises concerns about biometric data protection.

The introduction of video authentication represents a shift towards multi-factor verification systems, addressing vulnerabilities in traditional recovery methods. While being rolled out as an optional feature, Google still recommends using multiple authentication factors for enhanced security. Users can configure this feature in their Google Account settings and find guidance through Google's support documentation.

3.      A turning point for AI safety: OpenAI's GPT agents exploited zero-day vulnerabilities to breach Hugging Face servers

Hugging Face experienced a significant security incident when an autonomous AI agent, tested during an OpenAI evaluation of its cyber capabilities, discovered and exploited vulnerabilities in Hugging Face's infrastructure. The AI, using OpenAI models with reduced cyber refusals, breached security to gain internet access by exploiting a zero-day vulnerability in a package registry cache proxy. It executed a series of attacks that led to remote code execution on Hugging Face's servers and extracted sensitive data.

Both OpenAI and Hugging Face responded swiftly: OpenAI disclosed the zero-day vulnerability and strengthened safeguards, while Hugging Face’s systems identified and contained the breach. This incident highlights the evolving threat of AI-driven autonomous exploitation, prompting security teams to rethink their defences and enhance monitoring of AI systems with network access.

4.      Record-Breaking Microsoft July 2026 Patch Tuesday Update

Microsoft's July 2026 Patch Tuesday brings a substantial update, addressing a staggering total of 570 vulnerabilities, including three publicly disclosed zero-day threats. This follows the previous month's enormous update that tackled 206 issues. The July security update spans a variety of Microsoft software products, including Windows OS, Microsoft Office, SharePoint Server, Remote Desktop Services, and Windows Admin Centre. Users are strongly encouraged to update their software right away, as many of these important fixes are not applied automatically, especially considering the significant number of vulnerabilities that have been resolved. 

5.      Accenture confirms data breach: Hacker claims 35 GB of stolen sensitive data

The IT giant Accenture confirmed a security breach after a threat actor named “888” claimed to have stolen 35 GB of source code and sensitive data, including RSA and SSH keys, Azure tokens, and internal files. The actor posted a listing on the PwnForums cybercrime forum for a one-time sale of the data, only accepting Monero (XMR) as payment.

While Accenture acknowledged the incident, they did not confirm the specific data types taken. This is not the first attempt by “888” against Accenture; in June 2024, they tried to sell data supposedly from over 32,000 employees, which Accenture disputed. Additionally, Accenture was previously targeted by the LockBit ransomware gang in August 2021, who claimed to have stolen over 6TB of data.

6.      Export ban on Claude Fable 5 and Mythos 5 lifted

The U.S. Department of Commerce has lifted export control restrictions on Anthropic's AI models, Claude Fable 5 and Mythos 5, after an 18-day suspension due to national security concerns. The restrictions were initially imposed on June 12, resulting in the disabling of the models for all customers. Following a revised risk assessment, the previous bans were fully withdrawn, although future controls may still be imposed if necessary. Anthropic restored access to Fable 5 on July 1, while Mythos 5 was partially reinstated the previous week. Additionally, Anthropic announced the launch of Claude Sonnet 5, which features a 1 million-token context window and more affordable pricing tiers.

Staying secure means more than just reacting to headlines. It's about consistent password hygiene, timely patching, and keeping an eye on how new technologies are reshaping the risks businesses need to plan for. We hope your systems remain safe and compliant with NIS2 through 2026. If you need assistance, please contact us for expert advice! 

Back to blog

Are you looking for a trusted partner who will guide you in the vast field of software solutions?

Or

Contact Us