All episodes
Week of Jul 20, 2026

Threat Vectr Weekly — week of Jul 20

11 min

Stories covered this week

Transcript

Narrated by two AI anchors. Lightly formatted for reading.

Marcus

Welcome to Threat Vectr Weekly, your briefing on what matters most in cybersecurity right now. I'm Marcus, joined as always by Elena, and this is the episode for the week of July 20th. Coming up: the European Union has formally sanctioned Russian intelligence officers for years of cyber spying and sabotage. The US government is sounding the alarm on two critical website vulnerabilities that are already being exploited in the wild. And a New Jersey medical lab is notifying more than half a million patients that criminals walked off with their most sensitive personal and health data. We have got a full rundown of eight stories, so let's get into it.

Marcus

We start in Brussels, where the European Union has taken formal legal action against a group of Russian intelligence officers and associated entities. The EU says these individuals ran a years-long campaign of digital espionage targeting member-state governments, and went further than just stealing documents. Officials are also accusing the network of sabotage against critical infrastructure, the systems that keep modern societies running: electricity grids, water treatment facilities, railway networks. Disrupting those services can have life-or-death consequences. The sanctions the EU is imposing are travel bans, so the named individuals cannot set foot in any EU country, and asset freezes, meaning any money or property they hold inside the EU is locked. These are not military measures, but they are a formal international statement that this behaviour has consequences. The practical message for European organisations running critical systems: the threat is real, officially acknowledged, and state-sponsored.

Elena

Thanks Marcus. Staying in the world of privacy but shifting to Silicon Valley now, Meta had a rough week. The company that owns Facebook, Instagram, and WhatsApp launched a new artificial intelligence image generation feature tied to public Instagram accounts, and then quietly killed it within days. The tool let any user create AI-generated pictures by drawing on content from other people's public Instagram posts, with no direct consent from those account holders. Privacy advocates pushed back hard. So did a Hollywood union, representing creative workers who have fought for years against their work being fed into AI systems without permission. Meta acknowledged the feature, quote, misses the mark. Here is what matters if you use Instagram: if your account is set to public, meaning anyone on the internet can see your posts, your photos could have been used as raw material for images you had no say in. The lesson is simple but worth saying out loud. Public does not mean you have consented to every possible use of your content.

Marcus

Building on that theme of AI and trust, there is an interesting piece of research worth flagging this week. A team of scientists from Australia, Canada, and the UK is studying whether ordinary people can be trained to reliably spot AI-generated faces. The short answer from Professor Amy Dawel, who directs the Emotions and Faces Lab at Australian National University, is yes, but the old methods no longer work. Telling people to look for an extra finger or a melted ear has run its course, because AI image tools have simply gotten too good to make those mistakes. Fraudsters also cherry-pick images that look clean. The research team is developing more subtle detection techniques, and early results are cautiously encouraging. Why does this matter practically? Fake profile photos are used to build false trust online, in romance scams, job offer fraud, and impersonation attacks. The better people are at spotting them, the harder those attacks become. We will link to the full study in our newsletter this week.

ElenaSponsored

A quick word from our sponsor, Train2Secure. Your people are your biggest cyber risk — and your strongest defence. Train2Secure runs realistic phishing simulations and short, engaging security-awareness training your team will actually finish, with compliance-ready reporting that runs on autopilot. Turn your staff into a human firewall. Start your free trial today at Train2Secure dot com — that's Train, the number two, Secure, dot com.

Elena

Over to Australia now, where the online safety regulator, the eSafety Commissioner, is reporting real progress on age verification for adult websites, along with a new challenge it has not solved yet. Since legally binding codes came into force in March 2025, twenty-seven of the thirty most-visited adult websites used by Australians now show an age verification screen before granting access. The rules cover not just pornography platforms but also AI companion chatbots, apps designed to simulate human relationships, and app stores. The goal is straightforward: stop anyone under eighteen from reaching that material. The regulator is now turning its attention to virtual private networks, or VPNs, which let a device appear to be browsing from a different country, effectively making those age gates invisible. This is the predictable next battle. Any national age restriction faces the same workaround problem, and the eSafety Commissioner has signalled it is actively assessing how to address it.

Marcus

A quick but relevant one for the millions of people who pay for ChatGPT. OpenAI has temporarily removed the rolling five-hour usage limit for subscribers on its Plus, Pro, and Business plans, and reset everyone's usage counter to zero. The trigger was a surge of intense demand over a weekend, driven in part by the fact that ChatGPT and Codex, OpenAI's coding tool, share the same pool of allowed tasks. When one gets busy, the other runs dry fast. OpenAI product lead Tibo confirmed the change publicly. The company is also retuning the underlying model, GPT-5.6 Sol, to use less of each user's allowance per task. The practical takeaway here is more about understanding how these tools work than celebrating a temporary reprieve. If you rely on AI tools for your work, know that usage caps exist, that coding assistants and chat tools can compete for the same resources, and that capacity can disappear quickly during peak periods. Build that into your workflow planning.

Elena

Now to a story that anyone running a website needs to hear. The US Cybersecurity and Infrastructure Security Agency, known as CISA, has added two vulnerabilities in Joomla extensions to its Known Exploited Vulnerabilities catalog. Joomla is a content management system, software used by millions of websites worldwide to manage and publish content. The two affected add-ons are iCagenda, a calendar plugin, and Balbooa, a forms plugin. Both vulnerabilities scored a perfect 10.0 on the CVSS severity scale. That is the worst possible rating. A score of 10 means the flaw requires no login, is trivial to exploit, and gives an attacker deep access to your system. Critically, both were exploited as zero-days, meaning attackers were using them before patches were widely available. Federal civilian agencies in the United States are legally required to patch or stop using these extensions immediately. If you run a Joomla site with either plugin installed, treat this as urgent. Update now, and check your server logs for signs of unauthorised access. Do not wait.

Marcus

Here is a story that cuts to a deeper tension in the security industry. Artificial intelligence is making well-resourced organisations dramatically safer, and some experts worry it is leaving everyone else further behind. Steve Schmidt, chief security officer at Amazon Web Services, told CSO Online that AI has collapsed the time it takes to build defences after a security test from as long as ten months down to roughly fifteen minutes. That is extraordinary. But it is only available to organisations that can afford enterprise-grade AI tools. Security researcher Wendy Nather coined the phrase the security poverty line back in 2011 to describe organisations that simply cannot buy effective security. Rural hospitals, community banks, local utilities. The Trump administration directed federal agencies in 2025 to expand AI-enabled security access to exactly those groups. The concern being raised by several security leaders is this: organisations that cannot afford proper licences may end up sharing sensitive data with providers to access cheaper tools, trading privacy for affordability. Some experts believe open-source alternatives will close the gap within a few years. We will see.

Elena

We close this week with a data breach that is significant both in scale and in the sensitivity of what was taken. Centers Laboratory, a diagnostics company in New Jersey that processes medical tests for healthcare providers, has notified the US Department of Health and Human Services that criminals stole personal and health records belonging to 542,377 people. The attackers were inside the network for six days, between the 9th and 14th of August 2025. What they took includes names, dates of birth, Social Security numbers, passport numbers, driver's licence numbers, health insurance details, and medical records. The criminal group responsible is called WorldLeaks, which grew out of a ransomware operation called Hunters International. WorldLeaks has now claimed attacks against more than 170 organisations worldwide and published over 1.6 million files it says came from Centers Lab. If you are a patient of any New Jersey-based laboratory service, watch for a breach notification letter. Monitor your credit, consider placing a fraud alert on your accounts, and treat any unexpected communication asking for your Social Security number with extreme caution.

Marcus

That is everything for the week of July 20th on Threat Vectr Weekly. Thank you for spending part of your day with us. Every story we covered today, plus links to the original sources and the research we mentioned, is waiting for you at threatvectr dot com slash newsletter. Subscribe there and we will drop next week's briefing straight into your inbox before the episode goes live. Stay sharp, stay patched, and we will see you next week.

© 2026 Threat Vectr