Cyber Briefing: 2026.07.21
The social engineering surge meets the supply chain blind spot: why lagging security audits and vendor operational disruptions are putting healthcare and cloud assets in the crosshairs.
Welcome to Cyber Briefing, your daily source for all things cybersecurity. We bring you the latest advisories, alerts, incidents, and news every weekday.
Recent security alerts highlight sophisticated social engineering campaigns, including scammers using AI-generated videos and fake IC3 sites to re-target past fraud victims, as well as North Korean threat actors using fake recruitment offers to trick Web3 professionals into executing malicious commands that deploy crypto-stealing trojans. Meanwhile, operational reliance on single-datacenter dependencies was exposed during a 15-hour Google Cloud outage in Europe, and consumer frustration mounted over LG’s Monitor App Installer silently pushing unwanted McAfee ads onto Windows PCs without explicit consent.
On the policy front, HHS opened a public comment period to update CLIA regulations to enforce stricter cybersecurity controls and AI guidelines across clinical laboratories to better safeguard sensitive patient data. Concurrently, a Synack survey revealed that 95% of enterprise security teams uncover critical vulnerabilities outside scheduled testing windows, underscoring a severe disconnect between rapid infrastructure changes and infrequent, non-continuous testing practices.
Listen to our podcast here ⏬
⚡THREAT LANDSCAPE
FBI Impersonation Scam Targets Previous Victims
Scammers are impersonating FBI personnel from the Internet Crime Complaint Center (IC3) to target people who previously lost money to fraud. The FBI issued an updated alert on July 20, 2026, warning that attackers now use AI-generated videos of FBI officials and fake IC3 websites to appear legitimate. Victims should verify any FBI contact through official channels and report suspicious communications directly to the real IC3. Read More
North Korean ClickFake Campaign Targets Web3 Professionals
North Korean hacking group Famous Chollima (also known as Wagemole) is conducting targeted social engineering attacks against Web3 and cryptocurrency professionals through fake job recruitment campaigns. The attackers pose as recruiters on LinkedIn, Telegram, and Discord, luring victims to fraudulent assessment portals that use ClickFix techniques to trick candidates into running malicious commands that install remote access trojans (PylangGhost for Windows, GolangGhost for macOS). These modular malware tools steal credentials and private keys from over 80 browser extensions, targeting cryptocurrency wallets like MetaMask and Phantom, potentially compromising millions in digital assets. Read More
🚨INCIDENTS & REAL-WORLD IMPACT
Google Cloud 15-hour outage hits three services
Google Cloud suffered a 15-hour outage affecting VMware Engine, NetApp Volumes, and Bare Metal Solutions after an electrical fault on the utility grid caused cooling failures at a single datacenter serving the europe-west4-a zone. The incident revealed that some Google Cloud managed services depend on single datacenters within availability zones, contradicting typical assumptions about cloud redundancy. Organizations using specialized cloud services should verify whether providers maintain facility-level redundancy for those specific offerings, as standard multi-zone architectures may not apply to all managed services. Read More
🔓 EXECUTIVE RISK & CYBERNOMICS
LG Monitor App Installer Criticized for McAfee Ads
LG’s Monitor App Installer automatically installs software when compatible monitors connect to Windows PCs, and includes unwanted McAfee advertisements according to YouTube channel Gamers Nexus. The installer runs without explicit user consent when LG monitors are plugged in. Users can prevent automatic installation by disabling Windows driver updates or uninstalling the software after connection. Read More
🛡️ POLICY, REGULATION & LEGAL SIGNALS
HHS Seeks Input on CLIA Cybersecurity Updates
The Department of Health and Human Services has issued a request for information on updating the Clinical Laboratory Improvement Amendments (CLIA) of 1988, with a focus on cybersecurity and artificial intelligence use in clinical laboratories. The request seeks input on current lab cybersecurity practices, including protection of patient data, access controls, and incident response plans, as well as the use of AI tools in test result interpretation. Comments are being accepted through September 14, 2026, and will inform future rulemaking to address gaps in current HIPAA Security Rule protections and emerging threats from connected laboratory systems. Read More
💻 CAREER ENABLEMENT
95% of Security Teams Miss Vulnerabilities Between Tests
A Synack survey of enterprise security leaders found that 95% discovered high or critical vulnerabilities outside scheduled testing windows in the past year, with 42% experiencing this at least monthly. The research identified three key problems: 38% of organizations left at least a quarter of their critical attack surface untested for over 90 days, 79% would not act on AI-generated findings without human validation, and only 15% have continuous testing programs despite rapid environment changes. Security teams face a widening gap between how quickly their systems evolve and how often they actually test them. Read More
Copyright © 2026 CyberMaterial. All Rights Reserved.
Follow CyberMaterial on:
Substack, LinkedIn, Twitter, Reddit, Instagram, Facebook, YouTube, and Medium








