On this week's Security Sprint, Dave and Andy covered the following topics:
Opening:
• Cybersecurity Regulations: Multiple Sectors Are Subject to Potentially Duplicative Reporting Requirements — U.S. Government Accountability Office & 70% of federal cybersecurity reporting rules are duplicated, GAO finds — CyberScoop
• ANCHOR-CI could fix 20 years of broken government-industry collaboration — CyberScoop
• Project Pilot: Can AI models fly drones? — Anthropic —
• OpenAI and Hugging Face partner to address security incident during model evaluation — OpenAI —
• Bluesky Thread: OpenAI and Hugging Face incident demonstrates both autonomous cyber risk and defensive potential — Pwnallthethings
• Hugging Face CISO Post Mortem — Cloud Security Alliance
Main Topics:
1 dead, 16 injured after car ramming at Berlin CSD Pride event — DW — 25 Jul 2026. One person was killed and 16 others were injured after a vehicle was driven into people attending Berlin’s CSD Pride event. Authorities investigated the circumstances and potential motive behind the incident as emergency personnel treated victims and secured the area. The attack underscores the vulnerability of large public gatherings to vehicle-based violence and the potential for mass casualties within seconds.
• The suspect in the deadly Berlin Pride attack is killed in a confrontation with police
• Car Plows Into Crowd at Berlin Pride Event in Suspected Terror Attack
‘Integrated’ cyber and physical attacks concerned FIFA planners — StateScoop — 20 Jul 2026. Security planners for the 2026 FIFA World Cup prepared for blended attacks combining cyber disruption, physical violence, disinformation, swatting, infrastructure attacks, and interference with emergency communications.
• The Gate 15 Interview EP 60 – Sasha Larkin: “I like the chaos, chaos makes sense to me.”
2026H1 Threat Review: Vulnerabilities Up 51% Year Over Year — Forescout — 20 Jul 2026. Forescout reports a 51 percent year-over-year increase in vulnerabilities during the first half of 2026 as organizations contend with accelerating disclosure volumes across IT, Internet of Things, operational technology, and connected devices.
Email threat landscape: Q2 2026 trends and insights — Microsoft Security — 23 Jul 2026. Microsoft detected approximately 7.6 billion email-based phishing threats during the second quarter, while monthly volumes declined modestly from April through June.
Quick Hits:
• Weekly ransomware & data leak landscape — eCrime.ch — 27 Jul 2026. eCrime.ch recorded 236 public ransomware and data-leak claims involving 45 active groups during the seven-day period ending 27 July, with 63 events showing public evidence of data leakage. Qilin led with 37 claims, followed by Gentlemen and Global Secret Group with 31 each, while construction was the most frequently targeted sector with 17 incidents. The United States accounted for 103 claims, and healthcare recorded 10 incidents among the 88 sectors represented.
• Pay up or not? Ransomware surge has victims facing tough choices — Ars Technica
• If you pay a hacker’s ransom, chances are that they’ll come back for more
• Cl0p Exploitation of PTC Windchill & FlexPLM (CVE-2026-12569) — Ransom-ISAC — 22 Jul 2026. Ransom-ISAC, eCrime.ch, and DEFUSED warn that Cl0p ransomware affiliates are actively exploiting internet-exposed PTC Windchill and FlexPLM systems.
• Black Kite’s 2026 Ransomware Report: Ransomware Accelerates 60% in Six Months and Shows No Signs of Slowing as New Ransomware Groups Emerge Weekly