Daily Digest on AI and Emerging Technologies (22 July 2026)

Governance, Regulation, Legislation, Geostrategies

UNESCO and LG launch free AI ethics course worldwide

(DigWatch) UNESCO and LG AI Research have launched a free AI ethics course designed to help technologists, researchers, policymakers, students, and other professionals apply responsible AI principles in practice. The massive open online course, titled Empowering Minds: Transforming Lives, was launched in Seoul during the Ethics by Design: Industry and Innovation Conference. Hosted on Coursera, it is available free of charge to learners worldwide. The programme is based on UNESCO’s Recommendation on the Ethics of Artificial Intelligence, adopted by its 193 member states in 2021. According to UNESCO, it is intended to move beyond high-level principles by providing practical frameworks for decisions made throughout the AI lifecycle. – https://dig.watch/updates/unesco-lg-free-ai-ethics-course

Portugal launches implementation phase for digital government working groups

(DigWatch) Portugal’s Technical Working Groups under the State Simplification and Technology Network have begun work on initiatives aimed at modernising public administration and accelerating the implementation of digital technologies. The inaugural meeting brought together representatives from public sector organisations to establish priorities, assign responsibilities and agree on the next steps for the programme. – https://dig.watch/updates/portugal-digital-government-working-groups

European Central Bank moves digital euro project into next legislative phase

(DigWatch) The European Central Bank (ECB) says the digital euro project has entered a new phase after the European Parliament adopted its negotiating position, allowing trilogue negotiations with other EU institutions to begin. Speaking in Rome, ECB Executive Board member Piero Cipollone said the digital euro could be introduced in 2029 if the legislative process is completed by the end of 2026. He said the project is intended to complement cash, strengthen Europe’s payments infrastructure and preserve the role of banks in the digital payments ecosystem. – https://dig.watch/updates/ecb-digital-euro-next-legislative-phase

Spain invests in open-source AI design platform Penpot

(DigWatch) The Spanish Ministry for Digital Transformation and Public Service has announced a €1.92 million investment in Kaleidos to accelerate development of its open-source interface design platform, Penpot, as part of a €6.9 million public and private funding round. According to the Ministry, the investment is intended to strengthen European digital sovereignty by supporting an open-source alternative to dominant foreign interface design software. Penpot combines design and software development in a single platform while supporting collaborative workflows and generative AI applications. – https://dig.watch/updates/spain-open-source-ai-design-platform

China expands high-quality datasets to support AI development

(DigWatch) China has built approximately 120,000 high-quality datasets as part of a broader effort to expand the data resources supporting AI development and the digital economy, according to the National Data Administration. By the end of June, these datasets, covering fields such as scientific research, industrial manufacturing and healthcare, totalled more than 1,565 petabytes, an increase of over 60% compared with the end of the first quarter. – https://dig.watch/updates/china-high-quality-datasets-ai-development

Backlash against data centers could cost the US its AI edge

(Jeannie Salo – Atlantic Council) As the United States approaches midterm elections, politicians from both parties are tapping into the grassroots backlash against new data center builds.  As a nationwide protest was being planned for this weekend, Republican governors in Montana, Wyoming, and Missouri joined a White House-brokered Ratepayer Protection Pledge committing data center developers to cover their fair share of energy, water, and grid costs. New York Governor Kathy Hochul went further, signing the nation’s first statewide moratorium on new large-scale data center permits while regulators spend up to a year developing stronger ratepayer and environmental standards—the most consequential policy response yet to community backlash. Media coverage has exploded. The result: digital infrastructure is now visible, controversial, and ripe for weaponization that could hurt US leadership in AI and jeopardize the economic benefits the technology would confer to communities for generations. – https://www.atlanticcouncil.org/blogs/energysource/backlash-against-data-centers-could-cost-the-us-its-ai-edge/

Security and Surveillance

Researchers Uncover North Korean ‘ClickFake’ Campaign Targeting Web3 Pros

(Kevin Poireault – Infosecurity Magazine) A new sophisticated social engineering operation targeting Web3 and cryptocurrency professionals has been identified by researchers at SOCRadar. Attributed to the notorious North Korean-aligned hacking group Famous Chollima, also known as Wagemole, the campaign leverages fraudulent job interviews and highly interactive web portals to trick candidates into installing remote access trojans (RATs) on their personal devices. Instead of relying on broad phishing blasts, researchers at SOCRadar Threat Research Unit (STRU) noted that the threat group is shifting to highly personalized recruitment scams that capitalize on the high mobility of tech talent in the cryptocurrency market. By manufacturing elaborate pretexts, Famous Chollima establishes a high degree of trust with its targets before launching the decisive blow. – https://www.infosecurity-magazine.com/news/north-korean-clickfake-campaign/

FBI Warns of Deepfake Videos Impersonating IC3 Leadership

(Alessandro Mascellino – Infosecurity Magazine) An FBI warning has flagged an escalation in the long-running scheme to impersonate the Bureau’s Internet Crime Complaint Center (IC3), with scammers now deploying deepfake videos of senior FBI officials and spoofed IC3 websites to defraud previous fraud victims a second time. A public service announcement issued on July 20 by the IC3 follows an April 2025 warning about the same core scheme. Nick Tausek, lead security automation architect at security automation vendor Swimlane, said the scheme had become materially more polished since that earlier warning. What used to be text-only recovery pitches, he warned, now resembled “an official government process from start to finish.” – https://www.infosecurity-magazine.com/news/fbi-deepfake-videos-ic3/

A New Ransomware Threat Actor Emerges Every Week, Warns Report

(Danny Palmer – Infosecurity Magazine) More than one new ransomware group is appearing every week as  the criminal ecosystem surrounding extortion attacks becomes increasingly more fragmented and continues to expand. Published on July 21, the Black Kite Ransomware Report 2026 identified 146 active ransomware groups which have publicly announced at least one victim of an attack, as of June 2026. The figure marks a significant increase compared to the number of ransomware groups marked as active a year earlier, when the figure stood at 105 ransomware operations. According to the study, 2026 alone has seen the emergence of 61 new ransomware groups, the equivalent of more than one a week. – https://www.infosecurity-magazine.com/news/new-ransomware-weekly/

Russian Hacker Turns Jailbroken Claude Into Pentest Platform

(Alessandro Mascellino – Infosecurity Magazine) A Russian-speaking cyber-criminal has been observed moving in three months from posting a jailbreak tutorial on a Russian-language forum to selling a commercial offensive AI pentest platform built on the techniques he documented. According to new research from Cato CTRL, the research unit of Cato Networks, an actor using the handle Trim first appeared on the forum on March 31 with a detailed post laying out six named methods for bypassing Claude Opus safety filters. By June 21, he had returned with a working product, AI Pentest Checker, marketed to the same audience with the Claude jailbreaks embedded at its core. Trim said they bought a grey-market Claude API key from a Telegram reseller for $4 and built the tooling around it, an approach Cato characterized as evidence of the leading edge of a broader trend. – https://www.infosecurity-magazine.com/news/trim-jailbroken-claude-ai-pentest/

US Hospital Finance Software Provider Craneware Reports Data Theft

(Beth Maundrill – Infosecurity Magazine) Healthcare finance software provider Craneware has disclosed a cyber incident that resulted in the theft of a significant volume of file names from its data environment. The company confirmed in a July 20 notice that it had identified a cybersecurity incident involving unauthorized access to some of its data environment. A “significant volume” of file names were viewed and exfiltrated in the cyber-attack, a large element of this is said to have been non-sensitive data or already public regulatory data. – https://www.infosecurity-magazine.com/news/craneware-reports-data-theft/

Cruciferra Crypter Uses Process Ghosting to Evade Detection

(Alessandro Mascellino – Infosecurity Magazine) A crypter service used by multiple unrelated cyber-criminal groups has been documented cloaking commodity malware with process ghosting, kernel-driver abuse and more than 90 mix-and-match encryption routines. According to new research from Proofpoint published on July 20, the crypter, marketed as Cruciferra, was first offered for sale on the Exploit forum in autumn 2025 and now underpins dozens of campaigns delivering AsyncRAT, Agent Tesla, Remcos, XWorm, ValleyRAT and Snake Keylogger. Tiered access runs from $450 to $2,000 a month. Proofpoint identified both production and apparent testing samples, suggesting active development. On dark web forums, Cruciferra calls itself “the underground’s most lethal crypter.” – https://www.infosecurity-magazine.com/news/cruciferra-crypter-process-ghosting/

JadePuffer Returns With Ransomware Designed to Wipe AI Models

(Alessandro Mascellino – Infosecurity Magazine) The agentic operator documented as the first ransomware campaign run end-to-end by a large language model (LLM) has returned with a purpose-built locker designed to destroy trained AI model artifacts. According to new research from the Sysdig Threat Research Team (TRT) published one July 20, JadePuffer re-entered the same Langflow instance it hit in its earlier campaign and staged ENCFORGE, a UPX-packed Go ransomware binary that targets roughly 180 file extensions across the modern machine learning stack. The payload’s targeting is deliberate rather than opportunistic. Named formats include PyTorch and TensorFlow checkpoints, HuggingFace SafeTensors weights, llama.cpp GGUF quantized models, FAISS vector indices, Apache Parquet and TFRecord training datasets and NumPy arrays. – https://www.infosecurity-magazine.com/news/jadepuffer-ai-model-ransomware/

New HollowGraph Malware Hijacks Microsoft 365 Calendars for Covert C2 Communications

(Beth Maundrill – Infosecurity Magazine) A newly identified Windows malware sample abuses Microsoft Graph API to transform a compromised Microsoft 365 calendar into a covert two-way command and control (C2) channel. Researchers at Group-IB dubbed the highly sophisticated malware sample HollowGraph and attributed it, with high confidence, to the Cavern backdoor framework. Analysis by Group-IB found that the HollowGraph attack is highly targeted and focuses on Israeli entities. This is because the compromised mailbox identified was associated with an Israeli organization. In addition, the malware files uploaded were from Israel and files associated with the broader Cavern framework were also uploaded from Israel. – https://www.infosecurity-magazine.com/news/hollowgraph-microsoft-calendars/