Cyber News Bytes: What’s Happening in Cybersecurity This Week

This week's latest cybersecurity news and industry updates

Before the headlines: if you've ever wondered which cybersecurity roles are actually worth chasing versus which ones get overhyped, I just dropped a new video!

Definitely worth a watch if you’re in the job market right now or looking to make a career move.

Now, four cyber news headlines from this week you need to know. →

1. A Pentagon breach exposed 3 million people's data, and it sat undetected for nine months

The Pentagon's Defense Manpower Data Center confirmed that unauthorized users accessed an unencrypted file-sharing system from October 2025 through July 16, 2026, before anyone caught it. The breach affects roughly 2.76 million living individuals and 294,000 deceased people, with stolen data including Social Security numbers, names, dates of birth, contact information, sex, race, and military personnel details.

DMDC manages identity and personnel records for more than 60 million people connected to the Department of Defense, including active-duty members, veterans, contractors, and family members. Officials say they currently have no indication the stolen data has been misused, and affected individuals are being offered a year of free credit monitoring.

Why it matters: Three million people may be the headline, but nine months of undetected access to highly sensitive, unencrypted data is the real story here. If your organization handles sensitive PII, this is a reminder to check not just who can access a file-sharing system, but whether that data is encrypted at rest in the first place.

Read more at BleepingComputer

2. A Chinese ransomware group is hitting water utilities and telecoms through unpatched SharePoint servers

Symantec reports that Warlock, a ransomware group linked to Chinese threat actor Storm-2603, has expanded its SharePoint exploitation campaign to hit a water utility, a telecom provider, a regional government body, and a university across Europe, Africa, and Latin America. The group exploits the long-known "ToolShell" SharePoint vulnerabilities to deploy web shells, then harvests SharePoint's ASP.NET machine keys to forge signed payloads for full remote code execution.

In one intrusion against a critical infrastructure operator, attackers pushed a security-disabling tool to roughly 40 hosts within about two hours, then deployed the ransomware across at least 33 hosts by staging it in the domain's SYSVOL share, which replicates automatically to every domain controller.

Why it matters: These SharePoint flaws have been publicly known for over a year, yet they keep producing real victims, including a water utility. If your organization runs on-premises SharePoint, confirm you're patched against ToolShell and the newer related CVEs, since "we'll get to it eventually" is exactly how campaigns like this keep working.

Read more at The Hacker News

3. A perfect-10 Dell flaw gives attackers admin credentials for every connected storage array, no login required

Dell patched six critical vulnerabilities in its Container Storage Modules, which connect Kubernetes clusters to Dell's major storage platforms, including PowerStore, PowerScale, PowerFlex, PowerMax, and Unity XT. The worst, CVE-2026-63688, carries a maximum CVSS score of 10.0 and lets an unauthenticated remote attacker pull backend administrator credentials for every storage array registered with the system. A second flaw rated 9.9 lets a low-privilege user escalate to root access on cluster nodes.

Dell said CVE-2026-63688 amounts to a complete bypass of its entire authorization security model, handing an attacker full administrative control over storage infrastructure spanning all five supported product families.

Why it matters: A flaw that hands over admin credentials for your storage backend with zero authentication required is about as close to a master key as it gets. If you run Dell CSM in a Kubernetes environment, patch to version 1.18.0 and rotate every credential Dell's advisory names, since a credential leak like this doesn't get undone by a patch alone.

Read more at The Hacker News

4. AI agents tried basic hacking attempts on US and Canadian government sites while just looking for public data

AI research lab Transluce found that autonomous AI agents, some traced back to OpenAI based on request tags, sent over 200,000 requests to the US Department of Education's Civil Rights Data Collection site in a single day in June while searching for school statistics. Buried in that traffic was a basic SQL injection probe. A similar pattern hit Library and Archives Canada, where 13 of 899 requests carried attack-style payloads while the agents were hunting for century-old divorce records.

Both government agencies confirmed no services were impacted and no data was taken. OpenAI acknowledged unusual agent behavior on some government sites and said it is reviewing the findings.

Why it matters: Nobody instructed these agents to attack anything, they were doing routine data retrieval and still ended up throwing SQL injection probes at government infrastructure along the way. As agentic AI handles more open-ended tasks, this is becoming a pattern worth tracking: agents sometimes default to adversarial techniques even when nobody asked them to.

Read more at SecurityWeek

This week ranged from a nine-month-old breach nobody caught in time, to a ransomware group still cashing in on year-old vulnerabilities, to AI agents defaulting to hacking techniques nobody asked for.

Stay secure out there!

- Sandra | Cyber With Sandra