Daily Digest on AI and Emerging Technologies (27 July 2026)

Governance, Regulation, Legislation, Geostrategies

The AI Trust Paradox: Businesses Are Racing Ahead, but Consumers Are Hesitating

(Pierluigi Paganini – Security Affairs) Businesses are rapidly adopting AI, with 93% planning deployment, but consumer trust lags far behind: only 23% trust companies to use AI with their data, revealing a major “AI trust gap.” Research from Thales shows trust depends on transparency and use case, as users favor Artificial intelligence for cybersecurity but resist it in high-risk areas like financial decisions. To close this gap and reduce fears, organizations must clearly communicate how AI is used, where it adds security, and where humans remain in control. Before deploying artificial intelligence in a vacuum of industry stats, businesses would do well to do a social temperature check: do their customers even feel comfortable using it? The Thales Digital Trust Index 2026 report reveals: yes and no. It really depends on what you’re using it for. According to the survey, 93% of IT decision-makers are already deploying or planning to deploy generative AI. But only 23% of consumers trust companies that use artificial intelligence to handle their data. That’s a 70% gap between what companies want and what their customers are saying. Is the answer to just pull back on artificial intelligence? It doesn’t have to be. What we’re finding works is being informed and specific about where you want your AI adoption to lead. The report’s findings boil down to this: trust depends on visibility into the use case and the sensitivity of the task. While customers might be comfortable with artificial intelligence in security scenarios, they may not feel comfortable with it acting on their behalf. To avoid customer recoil, companies need to understand the differences and consider their rollouts accordingly. – https://securityaffairs.com/195915/ai/the-ai-trust-paradox-businesses-are-racing-ahead-but-consumers-are-hesitating.html

EU rail agency adopts AI image labels under AI Act guidance

(DigWatch) The European Union Agency for Railways (ERA) has begun introducing labels for AI-generated images on its website, becoming one of the first EU agencies to visibly implement the European Commission’s new transparency guidance under the AI Act. The European Commission adopted guidelines on 20 July explaining how providers and deployers should comply with the transparency obligations set out in Article 50 of the AI Act. ERA began progressively applying its own measures to new website content the following day. – https://dig.watch/updates/eu-rail-agency-ai-generated-image-labels

Canada launches consultation on AI transparency framework

(DigWatch) The Canadian government has launched a public consultation on new AI transparency measures, seeking views on how people should be informed about AI systems, AI-generated content and increasingly autonomous AI technologies. The consultation examines ways to help people identify synthetic content, notify users when they are interacting with AI and improve access to clear information about how AI systems are developed, what they can do and where their limitations lie. – https://dig.watch/updates/canada-ai-transparency-rules-consultation

Portugal expands cloud adoption across public administration

(DigWatch) Portugal’s public administration has significantly expanded its use of cloud computing, with new research showing rising investment as government organisations prepare for greater AI adoption and future sovereign cloud initiatives. The findings, published by the Agency for State Technological Reform (ARTE) in its Cloud Governance Impact Assessment Report for Public Administration, are based on responses from 262 public sector organisations, including ministries, municipalities, public institutes and schools. – https://dig.watch/updates/portugal-cloud-adoption-public-administration

Argentina proposes blockchain-based capital market reforms

(DigWatch) Argentina has proposed sweeping capital market reforms that would integrate digital assets, blockchain technology and smart contracts into the country’s financial system, reflecting a broader effort to modernise financial regulation and expand the use of decentralised technologies. The draft legislation would allow investment funds to hold digital assets where consistent with their investment policies and subject to regulatory approval. It also establishes a legal framework for the tokenisation of negotiable securities, enabling their issuance, custody, transfer and trading through blockchain-based systems. – https://dig.watch/updates/argentina-blockchain-based-capital-market-reforms

APEC adopts regional AI agenda for connectivity, skills and trust

(DigWatch) Asia-Pacific ministers have adopted a regional agenda on AI, digital connectivity, workforce skills and online safety, positioning AI as part of a broader strategy for economic development and digital resilience across APEC economies. Outlined in the 2026 Digital and AI Ministerial Statement, the APEC AI plan promotes the responsible adoption of AI across sectors, including manufacturing, agriculture and public services. – https://dig.watch/updates/apec-ai-plan-chengdu-statement

Australia’s eSafety study examines children’s digital habits

(DigWatch) Australia’s eSafety Commissioner has published two studies showing that parents are helping children develop safe digital habits from an early age, while highlighting growing gaps in awareness of newer online risks such as generative AI, algorithmic recommendations and online sexual extortion. The research found that Australian parents actively supervise their children’s online activities, establish rules for internet use and regularly discuss online safety. – https://dig.watch/updates/australias-esafety-study-childrens-digital-habits

Associated Press expands AI newsroom guidelines with human oversight

(DigWatch) The Associated Press (AP) has updated its AI newsroom guidelines, expanding the ways journalists may use generative AI while reaffirming that human oversight, verification and editorial accountability remain central to its reporting standards. Approved uses include early-stage research, document summarisation, transcription, translation and assistance with headlines, story summaries and shot lists. AI may also support grammar, spelling and search optimisation. However, all AI-generated outputs must be reviewed and edited by an AP journalist before publication. The technology cannot replace original reporting, source verification, fact-checking or editorial judgement. – https://dig.watch/updates/ap-ai-newsroom-rules

Kazakhstan strengthens workforce skills through digital learning

(DigWatch) Kazakhstan’s employers’ organisation is expanding workplace training through greater use of digital learning, certified trainers and occupational safety programmes as part of efforts to strengthen workforce skills. The initiative follows the completion of an advanced digital learning programme that enables certified trainers to develop online courses, webinars and professional training tailored to employers’ needs. Occupational safety and health will remain at the core of the programme as additional training areas are introduced. – https://dig.watch/updates/kazakhstan-workforce-skills-digital-learning

Security and Surveillance

LockBit5 and Qilin Lead Ransomware Attacks Against Italian Organizations

(Pierluigi Paganini – Security Affairs) Six months, 148 confirmed ransomware claims against Italian targets, and one sector taking the brunt of it. That’s the headline number from a new semi-annual tracker compiled by ransomNews under its RedACT project, which pulls together OSINT and SOCMINT sources to build a manual, deduplicated picture of who’s getting hit and by whom. The pace works out to roughly 25 claims a month, just under six a week. Attackers claim to have exfiltrated over 13,400 GB of data across the period, though that figure only covers 64 of the 148 cases; where a volume is actually disclosed, it averages around 61 GB. Read that gap as a reminder that leak-site numbers are marketing copy from criminals, not audited disclosures. “During the reporting period, 148 confirmed ransomware claims were recorded against Italian organizations, averaging 24.7 per month or 5.7 per week.” reads the report published by ransomNews. “The geographic distribution by NUTS macro-region shows Northwest Italy as the most affected area with 63 victims (42.6%), followed by the Northeast (36), Central Italy (30), Southern Italy (13), and the Islands (5). One claimed victim could not be geographically identified. Attackers claimed to have stolen a total of 13,405.22 GB (approximately 13.4 TB) of data, although data volume was disclosed in only 64 of the 148 cases (43.2%). Where reported, the average amount of exfiltrated data was 61.1 GB.” – https://securityaffairs.com/196045/security/lockbit5-and-qilin-lead-ransomware-attacks-against-italian-organizations.html

Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Credentials

(Pierluigi Paganini – Security Affairs) ReliaQuest’s threat research team just documented attackers compromising the Wi-Fi gateways at hotels and conference centers, then quietly rerouting guests toward fake Microsoft login pages. No phishing email required. No malicious attachment. Just bad luck about which hotel you picked. “Adversaries have been compromising public Wi-Fi gateways at hotels, conference centers, and other shared venues to hijack the accounts of traveling corporate employees.” reads the report published by ReliaQuest. “Once they control the Wi-Fi gateway, they quietly redirect users to attacker-controlled infrastructure to steal credentials, in activity ongoing since at least June 2026”. The mechanism is simple once you see it. These gateways handle DNS for every device that connects, so whoever controls the gateway controls where your traffic actually goes, even when the address bar looks completely normal. ReliaQuest found compromised devices across several US cities plus India and Saudi Arabia, hitting employees from finance, law, healthcare, energy, and retail, which tells you this isn’t aimed at one industry. It’s aimed at anyone who travels for work. – https://securityaffairs.com/196017/security/hackers-hijack-hotel-wi-fi-to-steal-microsoft-365-credentials.html

Australian energy provider Origin Energy disclosed a data breach impacting customer data

(Pierluigi Paganini – Security Affairs) Origin Energy disclosed a cyberattack that exposed customer data after a hacker claimed to have stolen records belonging to 2 million customers and threatened to publish them. An alleged hacker calling themselves “John Doe” claimed responsibility for the Origin Energy breach, saying they accessed the company’s customer systems and stole customers’ personal data. “Most are loyal, long-term customers,” reads an email sent by the hacker to Australian media outlet 7News. “Despite my outreach to their board members, security teams, and customer care departments, Origin hasn’t made a public announcement about the breach or responded to negotiate next steps. “They’ve shown no interest in resolving it before the data goes public.” – https://securityaffairs.com/195973/data-breach/australian-energy-provider-origin-energy-disclosed-a-data-breach-impacting-customer-data.html

Thailand’s Ministry of Finance Targeted With Hermes AI Agent Running Unattended, Hades Implant Staged

(Pierluigi Paganini – Security Affairs) Researchers at Hunt.io have uncovered an intrusion targeting Thailand’s Ministry of Finance that offers a rare look inside a live cyber-espionage operation. Instead of recovering malware after the fact, the team found exposed staging servers containing attack tools, stolen credentials, active session material, AI agent logs, and a previously undocumented implant dubbed Hades. The findings suggest the operation was still unfolding when the infrastructure was discovered. The investigation, conducted jointly by Hunt.io and security researcher Bob Diachenko, traced the activity to three publicly accessible directories exposed between July 9 and July 13 on a Hong Kong-hosted server. Together they contained nearly 600 files, including exploit code, web shells, custom scripts, compiled implants, and credentials targeting Thailand’s Ministry of Finance (MOF). Investigators also found evidence that the operator had already established access to multiple internal systems, although the initial intrusion vector remains unknown. One of the most interesting aspects of the operation is the use of Hermes, an open-source autonomous AI agent. Rather than acting as a chatbot, Hermes functioned as an operator assistant capable of executing commands without waiting for approval. – https://securityaffairs.com/195941/hacking/thailands-ministry-of-finance-targeted-with-hermes-ai-agent-running-unattended-hades-implant-staged.html

UAC-0099 Is Now Hiding Malware Inside a Fake Notepad++ Plugin to Target Ukrainian Organizations

(Pierluigi Paganini – Security Affairs) CERT-UA published a new advisory attributing a phishing campaign to UAC-0099, a Russia-aligned threat actor active since at least mid-2022 and previously known for exploiting WinRAR vulnerabilities and using phishing emails to deliver malware families including LONEPAGE, MATCHBOIL, and DRAGSTARE. The latest campaign, observed earlier this summer, uses a trojanized Notepad++ plugin as the infection mechanism. It’s a meaningful change in delivery method for a group that’s been refining its toolset steadily for three years. The attack starts with a phishing email carrying an image attachment. Clicking it opens a URL hidden behind a link shortener, which redirects to a file-sharing service such as EasySend[.]co where a ZIP archive waits. Inside the ZIP is a VBScript file disguised as a PDF document. – https://securityaffairs.com/195923/cyber-warfare-2/uac-0099-is-now-hiding-malware-inside-a-fake-notepad-plugin-to-target-ukrainian-organizations.html

US Agencies Warn of Laundry Bear Campaign Targeting Unpatched Zimbra Servers

(Pierluigi Paganini – Security Affairs) The Cybersecurity and Infrastructure Security Agency (CISA), National Security Agency (NSA), Federal Bureau of Investigation (FBI) and other U.S. government and international partners published a joint advisory to warn that the Russia-linked APT group Laundry Bear (aka Void Blizzard) is targeting organizations using unpatched Zimbra Collaboration servers. The attackers exploit CVE-2025-66376, an XSS flaw that allows malicious JavaScript embedded in HTML emails to run automatically when viewed, enabling account theft without user interaction. The vulnerability was exploited as a zero-day before being patched and remains under active exploitation against unpatched systems. “Unlike traditional phishing that attempts to persuade a user to take an action, such as clicking a link or downloading a file, LAUNDRY BEAR’s current campaign uses a zero-click exploit that only requires a user to view a malicious email within a vulnerable version of the ZCS webmail service.” reads the advisory. “This campaign uses a custom-developed aggregation and data exfiltration capability called Ulej to exploit a common vulnerabilities and exposures (CVE) in ZCS, CVE-2025-66376, with the potential for adaption to exploit other vulnerabilities as well. This advisory provides several mitigations to protect against this activity and specific remediation actions for organizations that detect indicators of compromise in their environment. “ – https://securityaffairs.com/195901/apt/us-agencies-warn-of-laundry-bear-campaign-targeting-unpatched-zimbra-servers.html

ENISA expands EU healthcare cybersecurity support with new initiative

(DigWatch) ENISA has signed a €6 million agreement with the European Commission to strengthen cybersecurity across Europe’s healthcare sector through new guidance, support services and coordinated capacity-building initiatives. As part of the EU Health Action Plan, ENISA has published updated procurement guidelines to help healthcare organisations integrate cybersecurity requirements into technology purchasing and supplier management. The guidance covers security considerations throughout the procurement lifecycle and recommends measures tailored to different cyber risks. – https://dig.watch/updates/enisa-and-european-commission-cyber-defence-tools

Frontiers

Coinbase prepares crypto infrastructure for quantum computing

(DigWatch) Coinbase has outlined a long-term strategy to prepare both its own infrastructure and the wider cryptocurrency ecosystem for the eventual arrival of fault-tolerant quantum computing, warning that preparations for post-quantum cryptography should begin well before the technology becomes practical. The company’s preparations focus on three areas. Coinbase is developing a post-quantum version of its proprietary key management system, reviewing internal systems that rely on encryption and monitoring developments across Ethereum and Base to ensure future upgrades remain compatible with emerging post-quantum cryptographic standards. – https://dig.watch/updates/coinbase-crypto-infrastructure-quantum-computing