11 min read

this week in security — july 19 2026 edition

U.S. police buying vans with spy tech, Scattered Spider hackers jailed, Russia called out on European cyberattacks, Iran tapped phone networks to track U.S. troops, WordPress bugs under attack, fitness bands are a privacy hot mess, and more.
~ ~

Spy vans equipped with cell-site simulators — or 'stingrays' — are coming to America
Forbes ($): Excellent reporting by @thomasbrewster exploring how U.S. police departments are snapping up vans and trucks equipped with cell-site simulators (often known as "stingrays"). These suitcase-sized devices trick nearby phones into connecting to the device rather than the nearest cell tower, allowing police and feds to track people's devices over a large geographic area. Police departments in New Mexico, New York, and Texas already have these "spy vans," with Texas State Police spending over $4.5 million to equip several vehicles with snoop tech. Stingrays are controversial because they collect data about innocent people's nearby devices, but the agencies seeking to use stingrays don't always get an easy pass. As first flagged by Forbes, one Ohio judge recently denied [PDF] to issue an unnamed federal agency with a warrant to identify a suspect's phone, but would have also allowed the feds "unbridled discretion to examine the movements" of innocent people across Ohio for a month. In a blog post, I wrote up more about the warrant and how these cell-site simulators work. 
More: The Drive | ~this week in security~ | @thomasbrewster

Scattered Spider hackers jailed for 5+ years for London transit hack
BBC News ($): Two members of the Scattered Spider hacking group, Thalha Jubair and Owen Flowers, were sentenced to more than five years in prison for their central roles in hacking Transport for London, the U.K. capital's transit system. The hackers pleaded guilty, though they didn't really get much choice since they live streamed the cyberattack while doing it, including the two bickering about the hack itself. The breach sparked considerable disruption (though the transit system kept largely running) but prompted every one of the 27,000 staff to reset their passwords in person. The hack saw millions of people's personal data stolen, but underscored how much damage can be done from the disruption caused by a hack independent of an extortion effort. Police seem to believe that "Scattered Spider" as a group is over, though its remaining members have splintered to different hacking groups. One senior U.K. cop called the hackers a "nest of wasps," but warned the nest is "still there."
More: Sky News | London Centric | Reuters ($) | The Guardian | The Telegraph ($) | @dcuthbert

Microsoft's Patch Tuesday fixes record number of security flaws, citing its use of AI
Krebs on Security: If you wondered why the list of Windows security updates is as massive as it is this month, it's because Microsoft is blaming (or thanking, depending on your viewpoint) the use of AI in the aiding of new security flaws. In total, Microsoft fixed around 620-or-so vulnerabilities in this month's so-called Patch Tuesday. Microsoft said last week that it was expecting a "large volume" of bugs as it doubles-down on the use of AI to hunt for security bugs that might have gone undiscovered for decades. This bumper, record-breaking number of bug fixes may continue for some time. Microsoft said that two of the bugs it fixed have been actively abused in ongoing hacking campaigns, including a particularly bad SharePoint bug that's easy to exploit.
More: Microsoft | Zero Day Initiative | Cyberscoop | TechCrunch ($) 

EU sanctions Russia over European cyberattacks, including hack on Polish power plants
Associated Press: The European Council, made up of the leaders of Europe's 27 member states, have sanctioned a number of accused intelligence officers with Russia's FSB spy agency, as well as other Russia-linked cybercriminals and hacktivists, as part of sweeping measures aimed at slapping back snooping and malicious cyber activity across the continent. The EU accused Russia of carrying out "disruptive sabotage" against a Polish heat and power plant, which officials said at the time came "very close" to causing a power outage. The EU also blamed Russia for targeting its governments to "sow chaos," a classic Putin tactic. Russia has also targeted several other countries across Europe. The sanctions mostly focus on asset freezes and travel bans, given that the bloc can't really do much else, since Russia continues to shield its top hackers from the West.
More: European Council | EUEA | The Record | WSJ ($) | Reuters ($)

a screenshot from Europe's strategic communications on its Russia sanctions, which reads: "Today's action marks a significant step in the EU's response to Russia's malicious cyber activities. By exposing and targeting Russia's entire malicious cyber ecosystem, a network of state actors, proxies and enablers that support Russia’s objective to destabilise the EU, its Member States and international partners, the EU is significantly raising the costs of Russia's malicious behaviour."

Russian state hackers are hacking consumer routers to hide malicious web traffic
CISA: Let's stick with Russia for a hot second… because Russian state hackers are also breaking into poorly secured routers as part of efforts to run botnets that conceal their malicious traffic from Western spies. CISA, FBI, the NSA, and a bunch of other countries called out Russia's router hacks, and advised on how you can secure your routers. (Ars Technica has more.) This comes in the same week that the U.S. Justice Department unsealed and released a 2024 indictment, accusing three Russians of running a "bulletproof" web host, which allegedly shielded state hackers and criminals from law enforcement demands and takedowns. The bulletproof hosts, MediaLand and ML.Cloud, were sanctioned last year, and both Reuters ($) and CNN ($) have more.

Two new bugs in WordPress bugs under attack backdoor servers
Bleeping Computer: Shields up, folks: Hackers are actively attacking two vulnerabilities in WordPress' core code, so get patching and checking your logs for potential intrusions. Per the good folks at IFIN who track cyber threats, the two bugs dubbed WP2Shell allow hackers to pop backdoors on servers running WordPress versions 6.9 and later. Cyber firm Searchlight found the bugs. WordPress' maker said users should update today to version 7.0.2.

Finnish hacker behind therapy breach wanted by police after appeal rejected
Helsinki Times: Police in Finland have issued an arrest warrant for Aleksanteri Kivimäki (aka Zeekill), who was convicted for a 2018 breach of one of the country's top therapy apps, spilling highly sensitive therapy notes to the web. Finland's appeals court denied Kivimäki's appeal and ordered that he serve the rest of his sentence behind bars — assuming the cops can find him.

A post on Bluesky by realhackhistory.org, which reads: "@joetidy.bsky.social ,  Zeekill appears to be on the run (again). Finnish authorities have been finding it hard to keep a handle on him for what a decade at least now?"

Iran steps up cyberattacks by tracking U.S. military personnel
Financial Times ($): Iran is stepping up its cyberattacks on U.S. military staff by abusing access to the global mobile phone networks (which most governments have by nature) to tap into the location data of foreign phones operating on its cell network. This exploitation relies on abusing bugs in the SS7 protocol that allows cell networks to talk to each other, per The New York Times ($), which also covered the story. This tracking comes after the Pentagon told Sen. Ron Wyden in May that U.S. military staff had been targeted in the battlefield using their location data, but in that case the data had been derived from apps and games on their phones and sold on to data brokers.

U.K. has no plans to regulate VPNs (for now), as plan for digital ID to be scrapped
BBC News ($): The U.K. government said it has no plans to regulate the use of VPNs following its recent introduction of age verification laws. Ministers said only about 5% of kids are using VPNs to bypass age checks, per @johnperrino, who has a good thread on Bluesky. Also: The U.K. will on Monday get its seventh (by my count) prime minister in a decade. The incoming PM Andy Burnham has already ruled out the introduction of digital ID cards, which last year sparked the U.K.'s top parliamentary petition in opposition with 3 million signatures.

John Perrino post on Bluesky, which reads: "There are no mentions of VPNs in the announcement or report summary page, but more than 60 mentions in the full report. These mostly reference UK government findings that only 5% of children report using VPNs to circumvent age restrictions."

A long-read on how a crew in London pulled off a records heist by breaking into a datacenter
The New York Times Magazine ($): This is an incredible story about how a London crew of thieves pulled off a successful heist of a Verizon datacenter in 2007 by stealing racks of servers containing (allegedly) information of criminal wrongdoing. Brilliant reporting here, plus a cameo from a dog called Buster. 

Most smart fitness bands and trackers lack key privacy features
Electronic Frontier Foundation: Earlier this year, I confirmed that wearable fitness tracker maker Oura receives government demands for users' private information after revealing that the company does not end-to-end encrypt users' health data stored on its servers. That got the EFF's @thorinklosowski digging around to see how other fitness trackers scramble their users' data so that they can't access it or dig it up for governments. Turns out, not many! Only the Apple Watch fully scrambles data out of sight of cops, plods, and feds, and publishes a transparency report detailing what data it hands over, if any. Also: Solid research from Mozilla digging into security and privacy issues with period trackers. By running network traffic tests, Mozilla caught one app, Stardust, sharing health data with a third-party company. Only one app, Euki, got a recommendation as being "squeaky clean." BBC News ($) dives into the findings.

Lidl customer data pinched: Supermarket giant Lidl said (in Dutch) it had a data breach, affecting reams of personal data from customers across Germany, Belgium, and the Netherlands. The data included names, dates of birth, phone numbers, email addresses, and more. It's not yet known who's behind the hack. (via NLTimes, HelpNetSecurity)

Third time's the charm, DHS edition: Sources tell @ddimolfetta that Homeland Security dismissed alerts on two separate occasions that suggested hackers were in its HSIN intelligence sharing system, but only nuked the hackers' access on the third go after staff finally saw a bunch of backdoors planted on its system. Makes you wonder how much this would've been detected sooner had CISA not had its workforce decimated over the past year... (via Nextgov)

Japan builds intel agency: Japan is building its first intelligence agency since World War II, and is asking the U.S., Germany, and Australia for help. Japan has a complicated history with spying as Imperial Japan, but the country's relatively new leader, prime minister Sanae Takaichi, recognizes that Japan today faces increased threats from China, Russia, and North Korea. (via The New York Times ($), @livcaisley)

A tweet by Olivia Caisley, which reads: "NYT: Japan is building a centralised intelligence agency for the first time since WW2 and it is turning to partners in the West for help. Aus officials, including ambassador to Japan, Andrew Shearer, have been providing advice around tech and coordination."

New AI threat clearinghouse: The White House has launched a clearinghouse for sharing AI cyber threat information between the government and the private sector. The program, dubbed "Gold Eagle" (for some reason), aims to help identify, fix, and patch security flaws discovered with frontier AI models, like Mythos. The clearinghouse has already started receiving information about security flaws, but lots of questions about the program remain. (via Cyberscoop, Politico)

Hugging Face breach: Hugging Face, a company that allows people to share their AI models online, said Friday that it experienced a breach earlier in the week, and that internal databases and several credentials it uses for third-party services had been compromised. The company is still figuring out if any customer data was taken. (via Hugging Face, @jkirk) 

Climate hack whodunnit: A group of U.S. climate activists and Exxon critics may learn who hacked them with phishing lures a decade ago. Court docs allege that a law firm representing Exxon ordered the hack, which the firm and Exxon deny. An indictment unsealed earlier this year pointed to a much larger hacking operation than first known. (via The Guardian, Grist, @hilarybeaumont)

$18M settlement after 23andMe breach: Several U.S. attorneys general have secured a settlement that will see about $18 million dispersed to 6.9 million victims across several states whose ancestry and genetic data was stolen in the 23andMe data breach in 2023. The genetic testing company filed for bankruptcy protection in 2025 following the breach. (via New York AG, DataBreaches.net)

Welcome back to the happy corner, your sprinkling of good things and more to round out the busy week of news. Aaaaand breathe.

I loved this report from Bangor Daily News exploring how libraries across Maine are helping visitors and patrons resist AI and large tech platforms. This effort aims to help people escape the clutches of Big Tech by learning how to better control and handle their own information. Above all, it's a great way to give people better agency over the tech they use. This is very encouraging to see, especially for the very many(!) who eschew AI as much as possible. Also, another very important reminder that libraries and librarians are awesome. (Thanks to Jamie for flagging this story!)

A screenshot of two paragraphs from the Bangor Daily News story, which reads: "Despite breathless reporting on AI and how it is going to change the world, [Maine librarian Hannah] Cyrus said that in her experience, most average library patrons aren’t finding it helpful.  “People are frustrated with auto-complete on steroids,” she said. “These things are trying to finish their sentences for them. They just want to turn it off.”"

Now this is really cool: getjailbroken by Chris Binnie is a fun way to test your AI hacking skills with an educational quiz by letting you try to hack an AI agent using prompt injections. This is a really fun way to think outside the box by tricking a virtual AI agent into breaking through its guardrails. 

And lastly, a little nugget from ~yesteryear~. Let's skip back a few years to 2019 where @AshwinRamaswami finally drops the details of how he accidentally breached Stanford University's admissions record system containing students' highly sensitive information, making front-page headlines. The bug he found was a classic IDOR, which governments have since warned are simple flaws that can be easily abused. This was a solid post-mortem of the incident, featuring some wise words from Alex Stamos.

Got good news to share? Get in touch! this@weekinsecurity.com.

This week's cyber cat is Mr Garfield. He doesn't want any of your lasagna, but would definitely "borrow" your passwords. Thanks so much to Kenn W. for sending in!

Mr. Garfield is a very handsome ginger kitty who can be seen sitting on some blankets and looking into the camera.

🐈 Keeping sending in your cyber cats (or non-feline friends)! 🐈‍⬛ Send me an email with their photo and name and they will be featured in an upcoming newsletter!

That's all there is from this week's very busy newsletter. Thanks for reading! I'll be back next week with your usual round-up of all the cyber news you need to know, plus more.

If you liked this newsletter, please share it on your socials — and feel free to tag me on Bluesky, Mastodon, or LinkedIn.

As always, please get in touch if you have anything you want to share for the newsletter. It's a real joy hearing from you, what you're interested in, and what you're working on — from tools to research to news stories! And if you have a moment to send in a cyber-cat (or friend!), I'd be over the moon if you sent in a snap.

In the meantime, I have a blog post that I expect to publish later this week on ~this week in security~, so do keep watch out for that. I think you'll like this deep-dive!

Catch you next,
@zackwhittaker