Cyber Briefing: 2026.07.20
Over 2,000 hospitals hit in a major billing software breach, while a sophisticated new malware strain evades EDR tools by routing stolen corporate data through Microsoft 365 calendars.
Welcome to Cyber Briefing, your daily source for all things cybersecurity. We bring you the latest advisories, alerts, incidents, and news every weekday.
The provided headlines highlight several operational challenges and tool releases across the tech and cybersecurity sectors. Microsoft is currently addressing a week-long synchronization issue affecting Windows Server Update Services (WSUS) administrators, while healthcare software provider Craneware is investigating a data breach that compromised part of its environment and impacted over 2,000 U.S. hospitals. On the tool and resource side, Capital One has open-sourced “VulnHunter,” an AI-driven tool designed to map attack paths and prioritize exploitable code fixes, while Microsoft launched “Dusseldorf,” an open-source out-of-band application security testing platform to help researchers detect external network vulnerabilities without building custom infrastructure.
In threat and policy updates, researchers discovered a sophisticated new malware strain named “HOLLOWGRAPH”, attributed with high confidence to the Iranian-linked Cavern backdoor framework, which evades detection by hiding command-and-control traffic and stolen data inside Microsoft 365 calendar invites dated out to the year 2050. Meanwhile, a major policy shift occurred as the Department of Justice authorized federal employees to download TikTok on government-issued devices, reversing a 2022 ban following a restructuring deal that transitioned TikTok’s U.S. operations to a joint venture backed by Oracle, Silver Lake, and MGX.
Listen to our podcast here ⏬
⚡THREAT LANDSCAPE
Microsoft fixes WSUS sync delays
Microsoft is addressing a known issue affecting Windows Server Update Services (WSUS) servers that has caused synchronization problems for over a week. WSUS administrators have experienced delays or failures when attempting to sync updates from Microsoft’s servers. Organizations relying on WSUS for centralized patch management should monitor their sync status and consider temporary workarounds until Microsoft releases a permanent fix. Read More
HOLLOWGRAPH malware hides in M365 calendar invites
A new Windows malware strain called HOLLOWGRAPH uses Microsoft 365 calendar invites to hide command-and-control communications and data theft, creating calendar events dated to May 2050 with encrypted attachments containing stolen files. Group-IB attributes the malware with high confidence to the Cavern backdoor framework, previously linked to Iranian threat activity, and has identified at least 12 infected systems using a compromised Israeli Microsoft 365 account. The malware uses DNS tunneling to refresh authentication credentials and encrypts exfiltrated data with RSA and AES-256-GCM, making detection difficult since all traffic appears as legitimate Microsoft cloud activity. Read More
🚨INCIDENTS & REAL-WORLD IMPACT
Craneware data breach affects 2,000+ US hospitals
Craneware, a healthcare software provider based in Edinburgh, disclosed unauthorized access to part of its data environment that affects over 2,000 US hospitals. The company has engaged external forensic investigators to assess the breach and is working to determine what data was compromised. Healthcare organizations using Craneware’s services should monitor for potential data exposure and await further guidance from the vendor. Read More
🔓 EXECUTIVE RISK & CYBERNOMICS
Microsoft releases Dusseldorf OAST platform
Microsoft has released Dusseldorf, an open-source out-of-band application security testing (OAST) platform designed to detect vulnerabilities where applications make external network connections during attacks. The platform captures inbound traffic across multiple protocols and allows security researchers to create automated response workflows for validation. Dusseldorf is intended to run in private environments, eliminating the need for researchers to build custom infrastructure for testing out-of-band vulnerabilities. Read More
🛡️ POLICY, REGULATION & LEGAL SIGNALS
Federal employees can download TikTok on work phones
The Department of Justice has authorized federal employees to download TikTok on government-issued devices, reversing a 2022 ban. The policy change follows a deal that transferred TikTok’s U.S. operations to a joint venture backed by Oracle, Silver Lake, and MGX, with Oracle serving as security partner and ByteDance retaining a 19.9% stake. President Trump has cleared executive branch employees to install the app on official devices, subject to individual agency approval and workplace policies. Read More
💻 CAREER ENABLEMENT
Capital One Open Sources AI VulnHunter Tool
Capital One has open-sourced VulnHunter, an AI-powered security tool that automatically identifies exploitable code vulnerabilities, maps potential attack paths, and suggests specific fixes. The agentic tool aims to help security teams prioritize remediation efforts by focusing on flaws that attackers could actually exploit rather than all reported vulnerabilities. Organizations can now integrate VulnHunter into their security workflows to improve vulnerability management efficiency. Read More
Copyright © 2026 CyberMaterial. All Rights Reserved.
Follow CyberMaterial on:
Substack, LinkedIn, Twitter, Reddit, Instagram, Facebook, YouTube, and Medium








