Governance, Regulation, Legislation, Geostrategies
Guterres: AI must be shaped by ‘all of humanity’, not a handful of powers
(UN News) UN Secretary-General António Guterres on Friday urged governments and technology companies to work together to ensure artificial intelligence (AI) benefits all countries. He warned that without international cooperation the technology could widen global inequality instead of advancing sustainable development. Speaking at the opening ceremony of the World Artificial Intelligence Conference (WAIC) in Shanghai, Mr. Guterres described AI as “humanity’s greatest opportunity in the 21st century”, but cautioned that it could also become “one of its greatest risks”. “Technology that will shape the future of humanity must be shaped by all of humanity”, he said, stressing that AI governance “cannot be governed by a handful of countries or companies” and that “every nation needs a seat at the table”. – https://news.un.org/en/story/2026/07/1167965
World AI Cooperation Organization established in Shanghai
(DigWatch) Twenty-nine countries signed an agreement in Shanghai on 16 July establishing the World Artificial Intelligence Cooperation Organization (WAICO), an independent intergovernmental international organisation that will be headquartered in Shanghai. Chinese Foreign Minister Wang Yi signed the agreement on behalf of China, while representatives from countries including Kazakhstan, Laos, Pakistan, Russia and Indonesia became founding members. UN Secretary-General António Guterres attended the signing ceremony alongside representatives of other countries and international organisations. – https://dig.watch/updates/world-ai-cooperation-organization-shanghai
Rome Declaration calls for human control over AI and nuclear weapons
(DigWatch) Nobel laureates, scientists, religious leaders and former heads of state and government have signed the Rome Declaration for an Unarmed and Disarming Peace in the Age of Artificial Intelligence, Nuclear and Autonomous Weapons, New Digital Protocols, and Emerging Models of Digital Development. The declaration was adopted on 16 July on Rome’s Capitoline Hill following the Global Nobel Laureates Assembly on Artificial Intelligence and Nuclear War, hosted by the Vatican. The declaration calls for renewed international cooperation to address the challenges posed by AI, nuclear weapons and other emerging technologies. It stresses that decisions concerning life and death, peace and war, and the future of humanity should remain under meaningful human control, while highlighting the importance of ensuring that technological progress is guided by ethics, responsibility and respect for human dignity. – https://www.vaticannews.va/en/world/news/2026-07/global-nobel-laureates-assembly-sign-declaration-on-peace-ai.html
Greece adopts national framework to implement EU AI Act
(DigWatch) The Greek Parliament has approved the national implementing framework for the EU AI Act, making Greece one of the first member states to establish a comprehensive national system for enforcing the regulation. The new law in Greece establishes the institutional framework for supervising AI systems, coordinating enforcement, supporting innovation and ensuring compliance with the EU AI Act. The legislation designates the Hellenic Data Protection Authority (HDPA) as the central market surveillance authority and the Hellenic Telecommunications and Post Commission (EETT) as the notifying authority, while establishing a dedicated AI Coordination and Expertise Centre. – https://dig.watch/updates/greece-national-framework-implement-eu-ai-act
UAE highlights AI-driven labour market strategy at BRICS meeting
(DigWatch) The United Arab Emirates presented its AI-driven labour-market policies at the 2026 BRICS Labour and Employment Ministers’ Meeting in India. The country highlighted public-private cooperation, adaptable legislation and investment in AI as part of its approach to workforce development. UAE Minister of Human Resources and Emiratisation Abdulrahman Al Awar said AI is being used to forecast labour-market needs, identify future skills and support data-based decision-making. – https://dig.watch/updates/uae-ai-driven-labour-market-strategy-at-brics
UK publishes government data breach response framework
(DigWatch) The UK government has published a Model Action Plan establishing a coordinated approach for responding to significant personal data breaches across government departments and arm’s-length bodies. The plan prioritises the wellbeing, privacy, safety and legal rights of people affected by personal data breaches. It also introduces mandatory central reporting to help identify systemic weaknesses, analyse incident trends and share lessons across government. A breach may be considered significant if it creates a risk of serious harm to large numbers of people, affects vulnerable or high-profile individuals, threatens national security or critical infrastructure, involves multiple organisations, or could cause major financial, operational or reputational damage. – https://dig.watch/updates/uk-model-plan-significant-data-breaches
Japan and NVIDIA launch national AI infrastructure
(DigWatch) Japan is moving to build what NVIDIA describes as the world’s first national AI infrastructure for physical AI, in partnership with Noetra and supported by government and industry leaders. The initiative is designed to strengthen Japan’s AI ecosystem across manufacturing, logistics, healthcare, telecommunications and other industrial sectors. Noetra will establish an NVIDIA Vera Rubin AI factory using 13,750 NVIDIA Vera CPUs and 27,500 NVIDIA Rubin GPUs. – https://nvidianews.nvidia.com/news/japan-government-industrial-leaders-and-nvidia-launch-the-worlds-first-national-ai-infrastructure
OpenAI calls for aligned US AI safety framework
(DigWatch) OpenAI has called for closer alignment between US state and federal AI safety efforts, arguing that a common framework is needed to govern frontier AI systems. In a policy blog post, the company said recent frontier AI legislation in California, New York and Illinois shows how states can help create a shared baseline before a single federal framework is in place. OpenAI describes this process as ‘reverse federalism’, where state laws move in similar directions and gradually shape a de facto national standard. – https://dig.watch/updates/openai-calls-for-aligned-us-ai-safety-framework
India approves €13 billion Semicon 2.0 strategy
(DigWatch) The Government of India has approved Semicon 2.0, a long-term strategy worth Rs. 1.275 trillion (approximately €13 billion) to accelerate the development of the country’s semiconductor design and manufacturing ecosystem. Building on Semicon 1.0, the programme aims to strengthen India’s position across the semiconductor value chain through sustained public investment, industrial incentives and workforce development. The strategy is organised around six pillars, such as semiconductor design, manufacturing equipment and materials, fabrication facilities, advanced packaging technologies, research and development, and talent development. – https://dig.watch/updates/india-approves-e13-billion-semicon-2-0-strategy
Federal Reserve note warns of AI import dependence
(DigWatch) A surge in AI infrastructure investment could widen the US current account deficit by increasing demand for imported high-technology equipment, according to a Federal Reserve research note. The note says the US AI buildout depends heavily on imports of advanced inputs, with about 90% of equipment goods used in high-technology sectors sourced from abroad. Suppliers are concentrated in East Asia, where economies specialise in semiconductors and related hardware. – https://dig.watch/updates/federal-reserve-warns-of-ai-import-dependence
Ofcom says age checks expand but more action needed
(DigWatch) Ofcom has published its 2026 Use of Age Assurance Report, finding that age-assurance measures have expanded rapidly over the past year while calling for further action to strengthen online protections for children under the UK’s Online Safety Act. The report examines the first six months after child protection duties took effect in July 2025, covering pornography, social media and online dating services. Ofcom said highly effective age assurance can significantly improve child safety, although no single method can completely prevent circumvention. – https://dig.watch/updates/ofcom-age-checks
Illinois issues AI guidance for schools with AI-assisted drafting disclosed
(DigWatch) The Illinois State Board of Education has published comprehensive guidance on the use of AI in schools, while also disclosing that the 409-page document was itself developed with assistance from multiple AI models alongside human review. The guidance was prepared following legislation adopted in 2025, with contributions from education, technology and public policy experts. Initial drafts drew ChatGPT, Claude and Gemini, while human reviewers edited, verified and refined the final document. – https://dig.watch/updates/illinois-ai-guidance-schools
Canada invests CAD 13.9 million in Quebec AI projects
(DigWatch) The Government of Canada has announced nearly CAD 13.9 million (approximately €8.8 million) in funding for 63 AI projects across Quebec under the Regional Artificial Intelligence Initiative (RAII), aiming to accelerate AI adoption among small and medium-sized enterprises (SMEs). The funding will support projects focused on both developing AI technologies and integrating AI into existing business operations. The government said the initiative will help SMEs improve productivity, develop innovative solutions and strengthen regional economic growth. – https://dig.watch/updates/canada-invests-in-quebec-ai-projects
Companies face new questions over AI control and governance
(DigWatch) Enterprise AI adoption is moving beyond questions of which model to use towards deeper concerns about infrastructure, governance and ownership. A Forbes Technology Council article argues that companies entering production with AI need to ask whether systems can operate securely inside their own environments and who controls the intelligence those systems generate over time. It frames enterprise AI as requiring a new trust layer across the stack. – https://dig.watch/updates/companies-questions-ai-control-and-governance
UK establishes ministerial group to coordinate digital inclusion
(DigWatch) The UK government has published the terms of reference for a new ministerial group created to coordinate digital inclusion policy across departments, aiming to improve access to digital services, technologies and skills. The Ministerial Group for Digital Inclusion will set the government’s strategic direction, agree a shared vision and identify priorities for improving digital inclusion across the UK. Its work will focus on embedding digital inclusion into policy design, public service delivery and existing government governance structures. The group will also monitor progress across departments with support from official-level bodies. – https://dig.watch/updates/uk-ministerial-group-digital-inclusion
Australia unveils AI framework for data centres, copyright and infrastructure
(DigWatch) The Australian government has announced plans for a national AI framework centred on new Australian AI Standards, enforceable rules for large AI data centres and stronger protections for creative works. The framework aims to support AI investment while addressing its impact on energy infrastructure, water resources, local communities, national sovereignty and intellectual property. Under the proposed standards, large AI data centres would be legally required to underwrite their additional power supply and pay the full cost of connecting to the electricity network. The government said this would prevent AI infrastructure expansion from increasing household energy bills. – https://dig.watch/updates/australia-ai-standards-data-centres
South Korea to launch free national AI service
(DigWatch) South Korea’s Ministry of Science and ICT has announced plans to launch the ‘AI for Everyone’ project this year, providing a homegrown AI service that anyone in the country can use free of charge without usage limits. The ministry will select participating companies through an open call for proposals. A beta version is scheduled for late September, followed by the launch of a general-purpose AI chatbot and an AI agent to help users search for and apply for public services. – https://dig.watch/updates/south-korea-to-launch-free-national-ai-service
European Commission expands AI assistant across global DG INTPA network
(DigWatch) The European Commission’s Directorate-General for International Partnerships (DG INTPA) has expanded the use of an AI assistant to support staff across its headquarters and delegations in more than 100 countries. Launched in March 2026 and developed with Accenture, the AI assistant is tailored to DG INTPA’s internal procedures, terminology and policy work. According to Accenture, the platform has more than 2,000 regular users and has processed over 400,000 queries. – https://dig.watch/updates/european-commission-ai-assistant-dg-intpa-network
The AI boom tests the limits of growth
(Amy Harder – Axios) Electricity demand is becoming the clearest measure of the AI industry’s extraordinary expansion — and a test of how long that pace can last. The industry’s pursuit of ever-larger models is fueling debate over whether they will deliver enough value to justify mounting environmental and financial costs. Google, Microsoft and Amazon all highlighted improved energy and water efficiency in sustainability reports released in recent weeks. But those gains are being overwhelmed by overall growth. Google’s electricity consumption rose more than 140% between 2021 and 2025 — already exceeding the outer bounds of projected growth modeled in a 2023 paper by Alex de Vries-Gao, a researcher at VU Amsterdam and founder of online platform Digiconomist. – https://www.axios.com/2026/07/16/ai-boom-tests-limits-growth
South Korea prioritises AI and semiconductor investment in the 2027 budget
(DigWatch) South Korea plans to introduce a record national budget exceeding KRW 800 trillion (around €500 billion) in 2027, with semiconductors, AI and youth employment at the centre of its investment strategy. Announced during the National Fiscal Strategy Meeting, the proposed budget would increase by more than 10% compared with 2026, reflecting the government’s focus on strengthening industrial competitiveness, technological leadership and long-term economic growth. A significant share of the funding will support three flagship initiatives focused on semiconductors, AI data centres and physical AI technologies. – https://dig.watch/updates/south-korea-ai-semiconductors-2027-budget
European Commission approves €659 million for four German chip projects
(DigWatch) The European Commission has approved €659 million in German State aid to support the construction of four first-of-a-kind semiconductor manufacturing facilities, strengthening Europe’s chip supply chain and advancing the objectives of the European Chips Act and the proposed Chips Act 2.0. The projects aim to expand manufacturing capacity across several strategic segments of the semiconductor value chain while reducing the EU’s dependence on external suppliers. The approved funding will support four companies across Germany. – https://dig.watch/updates/european-commission-german-chip-projects
European Parliament committee backs stronger online protections for children
(DigWatch) The European Parliament’s Committee on Culture and Education has adopted a report calling for stronger enforcement of existing EU digital legislation to create a safer online environment, particularly for children and young people. MEPs argue that platforms should be held more accountable for the impact of their services through stronger safeguards, greater algorithmic transparency and stricter protections against addictive digital design. The European Parliament report calls for a ban on the most harmful addictive platform features and supports introducing a dedicated ‘youth mode’ that would disable targeted advertising and reduce minors’ exposure to addictive design practices. – https://dig.watch/updates/eu-parliament-stronger-child-online-protections
Japan reviews legal protection for AI voice imitation
(DigWatch) Japan’s Justice Ministry has prepared a draft report on civil liability for the unauthorised use of people’s voices and images through generative AI. The draft focuses on the protection of famous individuals, including celebrities, singers and voice actors, as AI tools make it easier to imitate real voices and appearances. It was submitted to an expert committee on 13 July, with a final report expected as early as August. – https://dig.watch/updates/japan-legal-protection-for-ai-voice-imitation
Nobel laureates call for urgent AI economic planning
(DigWatch) Sixteen Nobel laureates have joined leading economists and AI researchers in calling for urgent preparation for the economic changes that more powerful AI systems could trigger. The statement, titled We Must Act Now: A Statement on AI’s Transformation of the Economy, was released by the Stanford Digital Economy Lab. – https://dig.watch/updates/nobel-laureates-urgent-ai-economic-planning
UK MPs call for clearer sovereign AI strategy
(DigWatch) UK MPs have called on the government to set out a clearer strategy for building sovereign AI and other critical technology capabilities. A new report from the Science, Innovation and Technology Committee warns that the UK may not be able to rely on allies for access to technologies essential to economic growth and national security. The committee said the government has not clearly defined what sovereign capability means, how it should be measured or what success would look like. – https://dig.watch/updates/uk-mps-call-for-clearer-sovereign-ai-strategy
Meta expands Louisiana AI data centre with $50 billion investment
(DigWatch) Meta has announced plans to expand its data centre in Richland Parish, Louisiana, increasing the site’s AI computing capacity to 5 GW as part of the company’s broader investment in AI infrastructure. Meta said the expansion represents an investment of more than $50 billion and will support more than 1,000 permanent jobs once the facility becomes operational. According to Meta, the project includes more than $1 billion in local infrastructure improvements, covering roads, water and wastewater systems. The company also said it has awarded more than $1.6 billion in contracts to Louisiana businesses since construction began in 2024. – https://dig.watch/updates/meta-expands-louisiana-ai-data-centre-with-50-billion-investment
South Korea links water security to semiconductor expansion
(DigWatch) South Korea’s Ministry of Climate, Energy and Environment has reviewed plans to secure water supplies for the new Honam semiconductor industrial complex, highlighting the growing importance of water infrastructure for advanced chip manufacturing. First Vice Minister Kum Hanseung inspected Naju Lake, Jangheung Dam, Boseong River Dam and Juam Dam as part of a review of the infrastructure needed to support the project and coordination between relevant organisations. The government aims to secure 650,000 tonnes of industrial water per day for the semiconductor complex. Plans include using surplus dam capacity, repurposing part of the water currently allocated for power generation and making use of unused water resources. – https://dig.watch/updates/south-korea-water-semiconductor-expansion
Intel invests €5 billion in Ireland chip expansion
(DigWatch) Intel has announced a €5 billion investment to expand semiconductor manufacturing at its Leixlip campus in Ireland, increasing production capacity for processors used in AI and high-performance computing. The investment is intended to meet growing demand for AI and high-performance computing by expanding production of Intel Xeon 6 and next-generation Intel Xeon processors built on the Intel 3 process node. Intel said the project will also support research and development while making greater use of existing cleanroom capacity. – https://dig.watch/updates/intel-invests-in-ireland-chip-expansion
UAE’s big bet on AI
(Mike Allen – Axios) In Abu Dhabi, the largest emirate in the United Arab Emirates, AI is as much a part of daily life as reporting a pothole or making a doctor’s appointment or paying a parking ticket — because AI does all that for you. Abu Dhabi, the capital of one of the world’s wealthiest and most globalized business hubs, has near-universal adoption of an app that knows when you need to renew your national ID or health insurance or vehicle registration. The app’s “AutoGov” feature goes a step further: It handles the paperwork and pays what’s owed without being asked. The UAE made a massive bet on AI, spending billions on infrastructure and research, backed by long-term thinking and alignment from top leaders. Before the war with Iran, the bet was paying off massively. “People make money here and bring money here,” a UAE resident told Jim VandeHei and me when we visited just before the war. – https://www.axios.com/2026/07/15/uae-ai-government-app-tamm
Google DeepMind’s Demis Hassabis calls for U.S.-led global AI watchdog
(Mike Allen, Zachary Basu, Madison Mills – Axios) Demis Hassabis, Google DeepMind co-founder and CEO, is calling on the U.S. to establish a new AI watchdog with the power to screen the world’s most advanced models — and coordinate an industry-wide slowdown if dangers mount. Hassabis, the Nobel laureate behind Gemini, lays out the plan in a personal manifesto published Tuesday morning, “A Framework for Frontier AI and the Dawning of a New Age”. In an exclusive interview with Axios, Hassabis said the time has come for a more “systematic” approach to AI regulation — funded by the industry, staffed by world-class technical experts, and answerable to the U.S. government. Today’s AI-driven cyber risks are “warning shots,” Hassabis told us from his London base. Within 18 months, he said, those capabilities — plus far graver biological and nuclear threats — could live inside open-source models beyond any government’s control. – https://www.axios.com/2026/07/14/demis-hassabis-ai-regulation-google-deepmind
Greece adds digital passport to Gov.gr Wallet
(DigWatch) The Greek Ministry of Digital Governance and Artificial Intelligence has added the national passport to the Gov.grWallet, allowing citizens with active ordinary passports to store a secure digital version on their mobile devices. The digital passport can be used for identification and as a travel document within Greece. Diplomatic and service passports are not currently supported. The passport becomes the thirteenth document available through the Gov.gr Wallet, joining digital identity cards, driving licences, disability cards, unemployment cards, academic IDs, insurance information, vehicle records, driver penalty points, pet records, the Athens Ring Road permit and the Real Estate File. – https://dig.watch/updates/greece-adds-digital-passport-to-gov-gr-wallet
UNESCO promotes inclusive digital transformation at WSIS Forum 2026
(DigWatch) UNESCO used the WSIS Forum 2026 to promote a vision of digital transformation centred on inclusion, multilingualism, human rights and the public interest, arguing that emerging technologies should remain accessible, ethical and beneficial for everyone. A central theme of UNESCO’s participation was multilingual digital inclusion. The organisation argued that people should be able to access digital services, create knowledge, preserve cultural heritage and participate online using their own languages and writing systems. – https://dig.watch/updates/unesco-digital-transformation-wsis-forum-2026
Saudi Arabia launches AI tool for national data insights
(DigWatch) Saudi Arabia’s Ministry of Economy and Planning has launched the beta version of INSAIGHTS, an agentic AI tool integrated into the Data Saudi Platform. The system is designed to improve how users access, analyse, and interact with national economic and social data. INSAIGHTS allows users to convert questions into instant insights and analytics by drawing on more than 7,500 indicators available through the platform. The tool aims to support decision-makers, researchers, analysts and the public with faster access to reliable information for data-driven decisions. – https://dig.watch/updates/saudi-arabia-launches-ai-tool-for-national-data
Music industry introduces labels for AI-generated songs
(DigWatch) Major music industry organisations have announced a voluntary labelling system to help listeners understand when AI has been used in songs. Groups including the RIAA, IFPI, the Recording Academy, SAG-AFTRA, IMPALA, WIN, A2IM and the Human Artistry Campaign back the initiative. The labels will distinguish between ‘AI-generated’ and ‘AI-assisted’ music. – https://dig.watch/updates/music-industry-labels-for-ai-generated-songs
What the UK government should do on AI and tech policy
(Alex Krasodomski – Chatham House) Britain’s next prime minister faces major policy decisions on tech and AI. They should aim to strengthen the UK’s tech sovereignty by building the national strengths – and the alliances – that give a middle power leverage in a shifting order. – https://www.chathamhouse.org/2026/07/what-uk-government-should-do-ai-and-tech-policy
Philippines uses AI and satellites to strengthen food security
(DigWatch) The Philippine Department of Agriculture and the Philippine Statistics Authority are partnering to use AI and satellite technology to improve agricultural data collection, strengthen national food security and support more informed policymaking. Agriculture Secretary Francisco Tiu Laurel Jr. stated that enhanced data sharing between the two agencies would enable policymakers to make more informed decisions on food production, logistics and supply. – https://dig.watch/updates/philippines-ai-satellites-food-security
Malaysia launches consultations on AI Governance Bill
(DigWatch) Malaysia’s Ministry of Digital has launched public engagement sessions on its proposed AI Governance Bill, marking the next step towards establishing the country’s first dedicated legal framework for AI governance. The sessions, organised by the National AI Office throughout July 2026, aim to explain the proposed framework, encourage dialogue and gather feedback from government agencies, industry, businesses, academia and the public. – https://dig.watch/updates/malaysia-ai-governance-bill-consultation
UNESCO study highlights AI gender gap in South Asia
(DigWatch) UNESCO has published the Outlook Study on Artificial Intelligence and Gender in South Asia, the first regional assessment of women’s participation in AI across Bangladesh, Bhutan, India, Maldives, Nepal and Sri Lanka. Developed by the UNESCO Women for Ethical AI (W4EAI) South Asia Chapter, the report examines women’s representation across the AI ecosystem, from education and research to employment and entrepreneurship, highlighting the structural barriers that limit leadership opportunities. – https://dig.watch/updates/unesco-study-ai-gender-gap-south-asia
EU-Australia Digital Dialogue focuses on AI and online safety
(DigWatch) The EU and Australia have reaffirmed their digital partnership during the third EU-Australia Digital Dialogue, advancing cooperation on AI, cybersecurity, digital policy and secure infrastructure. The online meeting was co-chaired by Renate Nikolay, Deputy Director-General for Communications Networks, Content and Technology at the European Commission, and Helen Wilson, Deputy Secretary of the Science and Technology Group at Australia’s Department of Industry, Science and Resources. – https://dig.watch/updates/eu-australia-digital-dialogue-ai-connectivity
ILO and EU deepen cooperation on AI and jobs
(DigWatch) The International Labour Organization (ILO) and the European Commission have reaffirmed their strategic partnership, agreeing to strengthen cooperation on social justice, quality jobs and the human-centred governance of AI and digital transformation. Against a backdrop of geopolitical uncertainty, climate change, demographic shifts and rapid technological change, the two organisations committed to ensuring that global transitions create inclusive labour markets and resilient economies. – https://dig.watch/updates/ilo-and-eu-deepen-cooperation-on-ai-and-jobs
ITU launches standards group for agentic AI
(DigWatch) The International Telecommunication Union (ITU) has launched a new global initiative to develop international standards for trusted digital identity and agentic AI, responding to the rapid emergence of increasingly autonomous AI systems. Announced at the AI for Good Global Summit, the new Focus Group on Trust and Identity for Humans and Agentic AI will develop frameworks aimed at strengthening accountability while ensuring meaningful human oversight of autonomous AI systems. – https://dig.watch/updates/itu-launches-standards-group-for-agentic-ai
Finland ranks among EU’s digital leaders
(DigWatch) Finland has ranked among the EU’s leading digital economies in the European Commission’s latest State of the Digital Decade report, with the country highlighted for its digital skills, AI leadership, supercomputing capabilities and advanced public services. The report paints a mixed picture across the EU. While digital adoption, connectivity, cloud services and AI continue to advance, the bloc still faces shortages of digital skills and lags in semiconductor production and globally competitive technology companies. According to the Commission, insufficient investment and market fragmentation remain major obstacles. – https://dig.watch/updates/finland-ranks-among-eu-digital-leaders
Security and Surveillance
Ernst & Young (EY) Investigates Data Breach Involving Third-Party Support Tickets
(Pierluigi Paganini – Security Affairs) Ernst & Young (EY) is disclosed a data breach linked to a compromised third-party support ticket system used by its IT teams. The platform stored support requests that may have included documents containing client tax information. “EY uses a third-party information technology service management platform to help EY information technology personnel provide support to EY teams performing tax-related work for clients. Support tickets submitted through the platform may include documents containing client tax information. On April 23, 2026, EY identified anomalous activity within that platform.” reads the data breach notification. ” “EY’s Information Security team immediately initiated its incident response procedure to determine the nature and scope of the incident, contain it, and begin remediation and recovery efforts. EY has worked with an independent cybersecurity firm to investigate the incident and confirm that the unauthorized access has been stopped, and our systems are now secure. Based on EY’s investigation and available evidence, between March 28, 2026, and April 12, 2026, an unauthorized third party accessed the platform referenced above and downloaded documents pertaining to a number of EY clients.” – https://securityaffairs.com/195550/data-breach/ernst-young-ey-investigates-data-breach-involving-third-party-support-tickets.html
A cyberattack hit Nichirei, one of Japan’s largest food companies
(Pierluigi Paganini – Security Affairs) Nichirei is one of Japan’s largest food companies, best known for its frozen food business. Founded in 1942 and headquartered in Tokyo, it operates globally through dozens of subsidiaries. The food giant confirmed that the system outage reported on July 13 resulted from a cyberattack targeting its servers. The company immediately set up an emergency response team to investigate the incident and coordinate recovery efforts. To reduce the risk of further attacks, Nichirei is withholding technical details about the breach while it continues to restore affected systems and assess the full impact. – https://securityaffairs.com/195543/security/a-cyberattack-hit-nichirei-one-of-japans-largest-food-companies.html
New Russian Campaign Uses Fake Webex and Zoom Installers to Deploy Starland RAT
(Pierluigi Paganini – Security Affairs) Cisco Talos researchers published a detailed technical report on July 16 disclosing UAT-11795, a financially motivated, Russian-speaking threat actor that has been running a malware campaign against users in the United States and Europe since at least June 2025. The operation distributes trojanized installers for software that IT professionals and developers actually use: MobaXterm, Cisco Webex, Zoom, DBeaver, and even the gaming platform FACEIT. “Cisco Talos is disclosing UAT-11795, a sophisticated, Russian-speaking, financially motivated adversary that has been conducting a malicious campaign targeting users in the U.S. and Europe since at least June 2025.” reads the report published by Talos. – https://securityaffairs.com/195532/malware/new-russian-campaign-uses-fake-webex-and-zoom-installers-to-deploy-starland-rat.html
White House launches GOLD EAGLE cybersecurity initiative
(DigWatch) The White House has announced the launch of GOLD EAGLE, a cybersecurity vulnerability coordination initiative established under President Donald Trump’s Executive Order 14410, Promoting Advanced Artificial Intelligence Innovation and Security. According to the administration, the initiative brings together federal agencies, open-source software partners and operators of critical infrastructure to accelerate the identification and remediation of cybersecurity vulnerabilities using AI. The initiative is being implemented through collaboration between the White House, the Department of the Treasury, the Department of Homeland Security, including the Cybersecurity and Infrastructure Security Agency (CISA), and the Department of War. The administration said GOLD EAGLE is intended to reduce duplicative vulnerability scanning, improve exploit detection and provide prioritised threat and remediation information to government and private-sector defenders. – https://www.whitehouse.gov/releases/2026/07/white-house-launches-gold-eagle-initiative-for-unprecedented-cybersecurity-vulnerability-coordination/
US and allied Governments’ Recommendations: Securing Network Devices Against Russian APT Groups
(Pierluigi Paganini – Security Affairs) The US and allied governments warn that Russian state-sponsored APT groups are scanning and exploiting poorly secured network devices, especially routers, to access critical infrastructure. Groups linked to FSB Center 16, including Berserk Bear, Energetic Bear, Ghost Blizzard, Crouching Yeti, Dragonfly, and Static Tundra, have targeted organizations in communications, defense, energy, finance, government, and healthcare sectors. “Russian Federal Security Service (FSB) Center 16 cyber actors continue to exploit poorly configured and vulnerable networking devices worldwide, opportunistically compromising multiple critical infrastructure sector networks.” reads the joint advisory”. Russian FSB Center 16 actors mainly target poorly configured network devices, especially routers, by scanning the internet for exposed SNMP services with weak or default credentials. – https://securityaffairs.com/195448/apt/us-and-allied-governments-recommendations-securing-network-devices-against-russian-apt-groups.html
Spain promotes national cybersecurity support helpline
(DigWatch) Spain’s National Cybersecurity Institute (INCIBE) has highlighted its free and confidential 017 helpline, which provides specialist advice on digital security issues for citizens, businesses, professionals and educational institutions. The helpline provides guidance on scams, phishing, identity theft, compromised accounts, social media privacy, cyberbullying, device security and protecting personal information. It also advises on parental controls, online child safety, digital identity management and the safe use of apps and social media platforms. – https://dig.watch/updates/spain-national-cybersecurity-support-helpline
UK to introduce AI for police evidence disclosure
(DigWatch) The UK Home Office has announced major reforms to criminal evidence disclosure that will introduce AI tools to automatically review and summarise police evidence, modernising procedures that have remained largely unchanged since 1996. The reforms respond to the growing volume of digital evidence in criminal investigations. According to the Home Office, a single fraud case can now involve more than four million documents, while some investigations contain digital material equivalent to 500,000 e-books. Existing guidance often requires officers to manually review and summarise potentially relevant material before prosecutors determine whether it is needed. – https://dig.watch/updates/uk-to-introduce-ai-for-police-evidence-disclosure
Compromised Logins Surge as the Most Common Entry Point for Ransomware Attacks
(Danny Palmer – Infosecurity Magazine) Identity-based attacks and abuse of compromised credentials have become the most common method cybercriminals use to hit networks with ransomware, analysis of real-world incidents has revealed. According to a new report by Sophos, 79% of ransomware attacks can be traced back to an initial intrusion which exploited compromised identities and legitimate user logins. In total, malicious emails accounted for the initial entry point for ransomware in 26% of analyzed incidents, up from 19% in 2025. – https://www.infosecurity-magazine.com/news/compromised-logins-ransomware-entry/
Engineering The Internet For Resilience
(Darren Anstee – Infosecurity Magazine) Over the past few months, the news cycle has seen warnings about nation-state hackers targeting critical water and electricity infrastructure, even accompanied by government advice on how to survive a prolonged national blackout. But, while the government focuses on the risks to our electricity and water supplies, we must also consider the availability of an increasingly critical pillar of modern civilization: the Internet. We all use Internet services in every aspect of our lives. Internet infrastructure and the services it supports have grown both exponentially and organically over the past three decades. The architectures and technologies we have used have evolved as user needs – and revenue opportunities – have shifted. The layers of hardware and software that support the services we all consume are often designed, at their foundation, for resilience – but the level of investment in resilience is very variable, based on the risk management decisions and financial realities of individual organizations. As users, we see end-to-end digital services, but the delivery of those services can involve many loosely coupled organizations. – https://www.infosecurity-magazine.com/opinions/engineering-for-resilience/
Government Updates UK’s National Risk Register with Cyber Warnings
(Phil Muncaster – Infosecurity Magazine) The UK government has added several new cyber-related scenarios to its National Risk Register; some of which could theoretically result in mass casualties. The register is based on the government’s internal, classified National Security Risk Assessment, and considers malicious risks like terrorism and cyber-attacks alongside non-malicious risks such as severe weather incidents. In the latest edition, published on July 14, the government added new scenarios anticipating what might happen in the event of cyber-attacks on digital infrastructure, water infrastructure, and police systems, as well as a mass CrowdStrike-style outage impacting IT systems. There’s also a new section devoted to interference in democratic processes, which could come from: “attacks on election infrastructure, deterioration of the online information space, harassment and intimidation towards candidates or voters, the hack and leak of sensitive information relating to a party or a prominent individual, and any element of foreign interference in any of these.” – https://www.infosecurity-magazine.com/news/uk-national-risk-register-cyber/
AI is beginning to carry out live cyberattacks, Check Point warns
(DigWatch) AI is moving beyond assisting cybercriminals to carrying out operational tasks during live intrusions, according to Check Point Research’s Annual AI Security Report 2026. The report argues that AI-enabled cyber operations are entering a new phase in which AI systems can execute parts of an attack rather than simply helping attackers write code, research targets or prepare phishing campaigns. The shift could make cyber operations faster and less dependent on continuous human oversight. Check Point said it observed AI carrying out hands-on tasks during incidents ranging from China-linked campaigns to a criminal breach affecting several Mexican government agencies. According to the company, these capabilities are spreading beyond state-backed actors to financially motivated cybercriminals. – https://dig.watch/updates/check-point-ai-cyberattacks-2026-report
US: Pentagon Suspends CMMC Phase II Requirements for Defense Contractors
(Kevin Poireault – Infosecurity Magazine) The US Department of Defense (DoD) has suspended the Cybersecurity Maturity Model Certification (CMMC) Phase II requirements until it reviews the program to allow for more innovation in the US defense industrial base (DIB). Originally scheduled to come into effect on November 10, 2026, the requirements corresponded to the second stage of the DoD’s phased rollout for the CMMC, a program designed to enhance cyber hygiene for US defense contractors and subcontractors handling federal contract information (FCI) and controlled unclassified information (CUI) for the DoD – also known as the Department of War (DoW). – https://www.infosecurity-magazine.com/news/us-pentagon-suspends-cmmc-2/
Five Charged in “Russian Coms” Fraud Platform Case
(Phil Muncaster – Infosecurity Magazine) Five people from London have been charged as part of a multi-year investigation into a notorious fraud platform thought to be responsible for millions of scam calls. The charge list includes conspiracy to supply articles for use in connection with fraud, acquiring, transferring and converting criminal property, and “failure to comply with a notice relating to not providing phone passcodes”. The arrests relate to Russian Coms, which the National Crime Agency (NCA) described as a “group” but is also the name of a vishing platform used extensively by fraudsters until it was shut down in 2024. – https://www.infosecurity-magazine.com/news/five-charged-in-russian-coms-fraud/
Open Directory Exposes Three Evilginx Phishing Operators
(Alessandro Mascellino – Infosecurity Magazine) A single misconfigured server has exposed the complete toolkit of an active a three-actor phishing ecosystem. According to new research from French security firm Lexfo, the open directory was a Python HTTP server left running on a Budapest virtual private server in late April, with directory listing switched on. Phishing configurations, credential logs, remote management installers and the operator’s own Telegram session files were all readable. Behind it was a threat actor tracked as codemado, running an Evilginx-based adversary-in-the-middle (AiTM) platform against corporate Microsoft 365 accounts. – https://www.infosecurity-magazine.com/news/open-directory-exposes-evilginx/
Pakistani Police Systems Hit by Chinese and Indian Espionage
(Alessandro Mascellino – Infosecurity Magazine) Two rival nation-state cyber espionage operations, one linked to China and the other to India, have converged on the same Pakistani police force. According to new analysis published by SentinelLabs, the research arm of SentinelOne, on July 9, suspected China- and India-nexus actors ran intrusion campaigns against several Pakistani law enforcement bodies between February 2024 and April 2026, concentrating on Balochistan Police, the province’s main force. The compromised assets included servers hosting applications for biometric records, criminal case files and tenant registrations tied to national identity data. One China-nexus actor reportedly planted implants in a portal used by officers and citizens. SentinelLabs grouped the command and control (C2) activity observed into four clusters. PlugX, ShadowPad and Cobalt Strike point to China-nexus operators; a Remcos cluster was tied to a suspected India-nexus actor Recorded Future tracks as TAG-179, overlapping with the group others call Bitter. – https://www.infosecurity-magazine.com/news/chinese-indian-espionage-pakistani/
Attacker Used AI to Build Custom PowerShell Recon Malware
(Pierluigi Paganini – Security Affairs) During an incident response investigation on June 3, 2026, Huntress analyst Jevon Ang recovered a PowerShell script from a compromised Windows Server that the attacker had used to map out the victim’s Active Directory environment. The script hadn’t been downloaded from a public repository or pulled from a known offensive toolkit. It was custom-built, almost certainly by prompting an AI model until the output worked. Huntress researchers reconstructed the full script from PowerShell script block logging, specifically Event ID 4104 in the Microsoft-Windows-PowerShell/Operational log. “The script, enthusiastically titled “100% Working AD Information Gathering Script – FULLY FIXED”, is a highly aggressive, noisy, custom-built AD enumeration tool. It doesn’t try to hide its functions, and has a number of distinct and interesting phases.” reads the report published by Huntress. The attack itself wasn’t particularly novel. The threat actor gained RDP access using pre-compromised credentials, staged tools in C:\ProgramData, ran the custom recon script within minutes of establishing the session, then roughly thirty minutes later deployed s5cmd.exe, a legitimate Amazon S3 command-line tool that Huntress has seen repeatedly abused for data theft. A second pass with SharpShares.exe followed, hunting for additional data repositories. – https://securityaffairs.com/195321/hacking/attacker-used-ai-to-build-custom-powershell-recon-malware.html
Malware Hits Japan’s Largest Taxi Company Nihon Kotsu, Services Temporarily Suspended
(Pierluigi Paganini – Security Affairs) Nihon Kotsu, Japan’s largest taxi company, disclosed on July 13, 2026 that its internal systems suffered an unauthorized external access involving malware infection in the early morning hours of Saturday, July 11. The company immediately shut down systems as an emergency measure to contain the damage. As a result, its online car hire reservation system, telephone-based taxi dispatch service, and several internal systems are currently unavailable. The company’s public notice was direct about the sequence of events. “We have recently discovered that our internal systems were subjected to unauthorized external access (malware infection). We sincerely apologize for the great inconvenience and concern this has caused to our customers, business partners, and all other parties involved.” reads the company’s notice. “Upon detecting the unauthorized access, we immediately took emergency measures, including shutting down systems, to prevent further damage. As a result, our hire car web order and reservation management system, telephone-based taxi dispatch service, and some internal systems are currently temporarily unavailable”. – https://securityaffairs.com/195305/cyber-crime/malware-hits-japans-largest-taxi-company-nihon-kotsu-services-temporarily-suspended.html
CrashStealer: New macOS Infostealer Uses Signed Apps to Evade Gatekeeper
(Pierluigi Paganini – Security Affairs) Jamf Threat Labs first spotted CrashStealer in early May 2026 as a suspicious macOS sample uploaded to VirusTotal. By early July, in-the-wild detections confirmed the malware had moved from development into active deployment. The malware is written in native C++, impersonates Apple’s built-in crash-reporting framework, and encrypts everything it collects before sending it out. Most commodity macOS stealers are thin AppleScript wrappers or lightweight Objective-C tools. This one isn’t. The initial access arrives through a disk image called “Werkbit Setup,” which contains a single application named Werkbit.app. That app is signed with a valid Apple Developer ID, Emil Grigorov (WWB7JA7AQV), and carries a notarization ticket, meaning it clears Gatekeeper on first launch without any warning. – https://securityaffairs.com/195278/malware/crashstealer-new-macos-infostealer-uses-signed-apps-to-evade-gatekeeper.html
Lidl Notified Online Shop Customers in Germany, Belgium, and the Netherlands of a Data Breach
(Pierluigi Paganini – Security Affairs) Lidl contacted customers of its online shop in Germany, Belgium, and the Netherlands last week to inform them that their personal data had been stolen in an attack on an external IT service provider. The discount chain, owned by Schwarz Group, published separate notifications on its customer service websites in Belgium and the Netherlands. The breach was discovered at the beginning of last week. The stolen data covers salutation, first and last name, phone number, email address, date of birth, and customer number for anyone who used Lidl’s online shop. – https://securityaffairs.com/195270/data-breach/lidl-notified-online-shop-customers-in-germany-belgium-and-the-netherlands-of-a-data-breach.html
ENISA introduces cybersecurity assessment tool for SMEs
(DigWatch) The European Union Agency for Cybersecurity (ENISA) has introduced a Cyber Resilience Maturity Assessment Model to help micro, small and medium-sized enterprises (SMEs) strengthen cybersecurity and prepare for the EU’s Cyber Resilience Act (CRA). The framework offers a structured way for organisations to assess their current cyber resilience, identify weaknesses and improve product security over time. Designed primarily for manufacturers of products with digital elements, the framework provides a structured way for organisations to assess their cyber resilience, identify weaknesses and improve product security over time. It evaluates five areas, such as governance, risk management, vulnerability management, product lifecycle management and cybersecurity skills. – https://dig.watch/updates/enisa-cybersecurity-assessment-tool-for-smes
PKI Under Pressure: AI, PQC and Shorter Lifecycles Drive New Security Challenges
(Marcus Silwer – Infosecurity Magazine) In the era of AI and agentic adoption, security and digital trust are more vital than ever before. At the center of digital trust is Public Key Infrastructure (PKI), the framework used to manage digital certificates and public-key encryption to enable secure communication, authentication and data integrity across digital environments. While PKI provides critical digital trust, the IT landscape PKI lives within is changing rapidly. – https://www.infosecurity-magazine.com/blogs/pki-under-pressure-security/
EU Targets FSB-Linked Hackers in New Sanctions Over Cyber Sabotage
(Pierluigi Paganini – Security Affairs) The European Union imposed sanctions on Monday targeting nine individuals and four entities linked to a Russian cyberespionage and sabotage operation that Brussels says has been running since 2010. The targets include Russian military intelligence officers, hackers, and private companies. The European Council said the sanctioned actors helped Russia destabilize the EU and its partners. The cyberespionage campaign affected at least nine countries. The European Council stopped short of publishing their names in its public statement, which is an unusual level of restraint for a sanctions announcement. – https://securityaffairs.com/195242/intelligence/eu-targets-fsb-linked-hackers-in-new-sanctions-over-cyber-sabotage.html
Dutch Nationals Suspected in Odido Hack That Exposed Six Million Customers
(Pierluigi Paganini – Security Affairs) Dutch police have identified strong indications that Dutch nationals were involved in the February 2026 cyberattack on telecom provider Odido, which resulted in data from more than six million customers being stolen and subsequently made public. Odido is a Dutch telecommunications company and one of the largest mobile network operators in the Netherlands. It was formed when T-Mobile Netherlands and Tele2 were rebranded as Odido in 2023 after private equity firms Apax Partners and Warburg Pincus acquired the business. – https://securityaffairs.com/195235/cyber-crime/dutch-nationals-suspected-in-odido-hack-that-exposed-six-million-customers.html
Australia Alerts Organizations to Ongoing CMS Exploitation Attacks
(Pierluigi Paganini – Security Affairs) Australia’s Signals Directorate has issued an alert about a large-scale exploitation campaign actively targeting content management systems (CMS) worldwide, with many small and medium-sized Australian businesses already hit. Attackers are scanning websites for known vulnerabilities, deploying webshells to gain persistent remote access, and using compromised servers as a base for broader attacks. “A large-scale exploitation campaign is targeting various vulnerabilities in content management systems (CMS) globally, including in Australia, with many small to medium sized Australian businesses impacted.” reads the alert published by the Australia’s Signals Directorate. – https://securityaffairs.com/195208/security/australia-alerts-organizations-to-ongoing-cms-exploitation-attacks.html
Ryuk Ransomware Member Pleads Guilty Over Attacks on U.S. Organizations
(Pierluigi Paganini – Security Affairs) Armenian national Karen Serobovich Vardanyan (34) pleaded guilty in the U.S. for his role in Ryuk ransomware attacks targeting American organizations between 2019 and 2020. Extradited from Ukraine after his 2025 arrest, he admitted providing initial access to corporate networks that enabled ransomware deployment. “An Armenian national extradited from Ukraine to the United States pleaded guilty yesterday for his role in Ryuk ransomware attacks and an extortion conspiracy targeting companies throughout the United States, including a technology company operating in Oregon.” reads the press release published by DoJ. “Karen Serobovich Vardanyan, 34, pleaded guilty to conspiracy and computer fraud.” – https://securityaffairs.com/195216/uncategorized/ryuk-ransomware-member-pleads-guilty-over-attacks-on-u-s-organizations.html
Defense, Intelligence, Warfare
Marines eye cloudless networks to keep AI tools running when the cloud goes down
(Patrick Tucker – Defense One) The cloud connectivity that makes big AI models work is also the reason they won’t work in war. As the Marine Corps explores ways to bring AI tools to the battlefield, it is looking at one software company’s proposal to keep troops computing when broader access gets cut off. Ditto will announce Monday that the Marines’ Project Dynamis will evaluate their technology for turning radios, cell phones, even drones, into a local network that can keep data flowing and AI tools running locally when cloud access disappears. “Ditto’s position is that we do not leverage a server-client model,” Eric Hanft, Ditto’s senior vice president for public sector and a former Army infantry officer, said in an interview. “If you continue to architect your data flows around that, you never remove this fundamental dependency that, if two edge nodes need to communicate and have to go to and from a server—and that server is not available—there’s no communication.” – https://www.defenseone.com/defense-systems/2026/07/marines-cloudless-networks-ai-cloud/414716/?oref=d1-featured-river-secondary
Frontiers
Claude for Teachers released for verified US educators
(DigWatch) Anthropic has launched Claude for Teachers, offering verified K-12 educators in the US free access to premium Claude features, teaching skills and curriculum-aligned resources. The product is designed to help teachers plan lessons, adapt materials, differentiate instruction and manage classroom workflows. Claude for Teachers connects to Learning Commons, giving it access to academic standards across all 50 US states and related learning competencies. – https://www.anthropic.com/news/claude-for-teachers
Visa explores hybrid future for AI-driven payments
(DigWatch) Visa has outlined a future in which traditional card networks and stablecoins play complementary roles in AI-driven commerce. A joint report by Visa and blockchain analytics firm Artemis examines how AI agents are beginning to make payments, drawing on live on-chain data and emerging payment protocols. The report divides agentic commerce into two broad categories. In macro-commerce, AI agents act on behalf of people in transactions such as travel bookings, subscriptions or other consumer purchases. Visa says those payments resemble ordinary e-commerce and remain well-suited to card networks. In micro-commerce, software systems make small and frequent payments to other software systems, often for API access or computing resources. – https://dig.watch/updates/visa-explores-hybrid-future-for-ai-payments
Microsoft and 3M partner on AI data centre infrastructure
(DigWatch) Microsoft and 3M have announced a strategic partnership covering AI data centre infrastructure and the deployment of Microsoft AI tools across 3M’s business operations. Microsoft Azure will become the first hyperscale cloud provider to deploy 3M’s Expanded Beam Optical technology, which is designed to improve the physical connectivity needed for expanding cloud and AI workloads. Unlike conventional fibre connectors that rely on direct physical contact, the technology uses an expanded optical beam, making connections more resistant to dust and contamination during installation and maintenance. Microsoft said early deployments suggest the technology could shorten network installation times in some environments while maintaining reliable signal performance under typical data centre conditions. – https://dig.watch/updates/microsoft-3m-ai-data-centre-infrastructure
AI is reshaping physics but raising new questions
(DigWorld) AI is becoming an increasingly important tool in physics, helping researchers analyse large datasets, accelerate simulations and identify patterns that may be difficult to detect through conventional methods. A Physics World feature examines how machine learning is already embedded in particle physics, including work at CERN’s Large Hadron Collider, where researchers have used AI techniques in Higgs boson analyses and searches for new physics. Newer approaches are also being used to detect unexpected anomalies in collider data, potentially helping physicists look beyond predictions based on existing theories. – https://dig.watch/updates/ai-is-reshaping-physics-but-raising-new-questions
MIT develops safer way to detect harmful AI models
(DigWatch) MIT researchers have developed a new auditing method to detect whether generative AI models have been adapted to produce child sexual abuse material without generating illegal content during testing. The technique was developed with Thorn, a child safety nonprofit focused on protecting children from sexual abuse and exploitation online. Traditional AI safety testing often involves prompting a model and checking its outputs, but that approach cannot be used for child sexual abuse material, which is illegal to generate in the US and many other jurisdictions. – https://dig.watch/updates/mit-develops-safer-way-detect-harmful-ai-models