Cyber Briefing: 2026.07.23
Caught between legacy software end-of-life cutoffs and the emergence of autonomous AI exploits, security teams are abandoning traditional perimeters for hybrid, identity-first defense.
Welcome to Cyber Briefing, your daily source for all things cybersecurity. We bring you the latest advisories, alerts, incidents, and news every weekday.
Organizations face growing infrastructure and application risks driven by impending software end-of-support deadlines and emerging AI threats. Microsoft is set to discontinue Extended Security Update support for Exchange Server 2016 and 2019 by October 2025, forcing administrators to upgrade, migrate to cloud solutions, or risk running unpatched systems. Concurrently, autonomous agentic AI poses security risks to confidential computing environments by threatening secure enclaves through prompt injection and unauthorized data access. On the defense side, organizations are shifting away from fully automated AI penetration testing, where reliance dropped sharply from 29% to 9%, and adopting hybrid approaches to combine AI speed with essential human analysis.
Recent security incidents and regulatory developments highlight the critical need for proactive identity verification and workforce readiness. Credential stuffing attacks recently hit Chick-fil-A, compromising user accounts and exposing personal data, payment card details, and loyalty codes. In response to rising access risks, platforms like Google are implementing advanced identity verification tools, such as selfie video authentication, to secure account recovery. On the governance front, upcoming compliance mandates under the EU AI Act are pushing security teams to upskill their workforces to properly manage and secure artificial intelligence operations.
Listen to our podcast here ⏬
⚡THREAT LANDSCAPE
Microsoft ends Exchange 2016/2019 ESU support
Microsoft will discontinue Extended Security Update (ESU) support for Exchange Server 2016 and 2019 in October 2025, ending all security patches for these versions. Organizations still running these servers will no longer receive critical vulnerability fixes after the cutoff date. Administrators must migrate to Exchange Server 2019 Cumulative Update 14 or later, move to Exchange Online, or accept operating unpatched systems with significant security risks. Read More
Agentic AI Challenges Confidential Computing
Confidential computing, which uses secure enclaves to protect data during processing, faces new challenges from agentic AI systems that can autonomously access and manipulate sensitive information. While technical barriers like performance overhead and key management that previously limited adoption are being addressed, AI agents introduce risks around data leakage, prompt injection attacks, and unauthorized access to protected enclaves. Security teams should implement strict access controls for AI agents, monitor enclave interactions, and establish clear policies governing AI access to confidential computing environments. Read More
🚨INCIDENTS & REAL-WORLD IMPACT
Chick-fil-A data breach via credential stuffing
Chick-fil-A is notifying customers that their accounts were compromised through credential stuffing attacks, where attackers used stolen credentials from other breaches to access customer accounts. The breach exposed personal information including names, email addresses, mobile phone numbers, masked payment card details, and Chick-fil-A One membership numbers and mobile pay QR codes. Affected customers should immediately change their passwords, enable multi-factor authentication if available, and monitor their accounts for unauthorized activity. Read More
🔓 EXECUTIVE RISK & CYBERNOMICS
Google adds selfie video authentication
Google has introduced selfie video authentication as a new account recovery method for users locked out of their accounts. The feature requires users to record a short video of their face following onscreen prompts that capture multiple angles, which Google then compares to a previously stored video to verify identity. This option provides an alternative when users cannot access their usual devices, passwords, or two-factor authentication methods. Read More
🛡️ POLICY, REGULATION & LEGAL SIGNALS
EU AI Act Deadline Approaching
The European Union’s AI Act implementation deadline is approaching, requiring organizations to prepare their security teams for new compliance requirements. The legislation establishes rules for artificial intelligence systems operating in the EU, creating new security and risk management obligations. Organizations must assess whether their current workforce has the skills needed to secure AI systems and meet regulatory standards. Read More
💻 CAREER ENABLEMENT
Security teams shift from AI-only to hybrid penetration test
Organizations are abandoning AI-only penetration testing after discovering that automated tools miss critical vulnerabilities and generate false negatives. According to Cobalt’s 2026 survey of 455 cybersecurity professionals, reliance on fully automated AI testing dropped from 29% to just 9% in one year, with 78% of organizations reporting that AI scanners fail to detect important security flaws. Security teams now favor a hybrid approach combining AI reconnaissance with human expertise to identify business logic vulnerabilities and validate findings, particularly for AI-powered applications that produce high-risk findings at three times the rate of conventional software. Read More
Copyright © 2026 CyberMaterial. All Rights Reserved.
Follow CyberMaterial on:
Substack, LinkedIn, Twitter, Reddit, Instagram, Facebook, YouTube, and Medium








