Anthropic Ships Claude Opus 5, 50 Tech Companies Sign an Open-Weights Letter, and OpenAI Launches Health in ChatGPT

This brief covers the trailing ~72 hours (July 23–26, 2026). Every item below was confirmed on the originating organization’s own page, with a published date inside the window. Anthropic had a busy stretch, shipping Claude Opus 5 and upgrading voice mode, while 50 American tech companies — including OpenAI, Google, Meta, Microsoft, and NVIDIA — signed a joint open-weights policy letter, and OpenAI began rolling out connected health records in ChatGPT.

Anthropic launches Claude Opus 5, claiming near-Fable intelligence at half the price

Anthropic · July 24, 2026

Anthropic released Claude Opus 5, positioning it as the new state of the art on coding and knowledge-work evaluations like Frontier-Bench and GDPval-AA, while remaining behind Mythos 5 on cybersecurity tasks. Priced unchanged from Opus 4.8 at $5/$25 per million tokens, it becomes the default model on Claude Max and ships alongside a Fast mode (~2.5× speed at twice the price), mid-conversation tool changes on the Claude Platform, and automatic safety-classifier fallbacks on the API. Anthropic says its automated behavioral audit found Opus 5 to be its most aligned model to date, and its cyber classifiers are expected to intervene around 85% less often than Fable 5’s.

“Claude Opus 5 is available today. It’s a thoughtful and proactive model that comes close to the frontier intelligence of Claude Fable 5 at half the price.” — Anthropic

Source: Introducing Claude Opus 5

Fifty tech companies sign “Open Weights and American AI Leadership” letter; Anthropic and Amazon absent

Coalition letter (hosted by NVIDIA) · July 24, 2026

A coalition letter dated July 24 urges U.S. policymakers to avoid premature restrictions on open-weight models, arguing openness expands access, strengthens competition, and may be “one of the most important paths to AI safety and security.” It also defends distillation as a legitimate model-development technique. Signatories span NVIDIA, Microsoft, Meta, Google, OpenAI, AMD, IBM, Mistral, Hugging Face, Andreessen Horowitz, Palantir, and dozens more — with Anthropic and Amazon notably absent from the list.

“Our AI leadership will be judged not by one frontier AI model, but by whether the United States builds a strong, open ecosystem that diffuses into every sector.” — Open Weights and American AI Leadership

Source: Open Weights and American AI Leadership (PDF)

OpenAI launches Health in ChatGPT with connected medical records and Apple Health

OpenAI · July 23, 2026

OpenAI began rolling out Health in ChatGPT to logged-in U.S. users 18 and older across Free, Go, Plus, and Pro plans. Users can connect Apple Health, supported hospital-system medical records, One Medical, or Function Health, and ChatGPT can then draw on that context in everyday conversations — with permission prompts by default. OpenAI says connected health information and the conversations that use it are not used to train its foundation models or target ads, and data from disconnected sources is deleted from its systems within 30 days.

“Every week, more than 300 million people turn to ChatGPT with health-related questions—from understanding a lab result and preparing for an appointment to making sense of what a doctor said and building a healthier routine.” — OpenAI

Source: Launching Health in ChatGPT

Claude voice mode gains Opus and Sonnet, connected tools, and 11 languages

Anthropic · July 23, 2026

Anthropic upgraded Claude’s voice mode beyond the speed-focused Haiku model: paid users can now run voice conversations on Claude Opus or Sonnet and switch models mid-conversation. Voice mode can also reach connected tools like Gmail, Google Calendar, and Slack (asking permission before acting), and supports 11 languages with mid-conversation switching. The update is in beta for all chat users on mobile, desktop, and web.

“Claude Opus and Sonnet, models designed for hard problem-solving, are now available in voice mode. You can switch models mid-conversation from the model picker.” — Anthropic

Source: Think through hard problems in voice mode

Still developing

Three notable items landed just before this window opened:

AMD and Anthropic strategic partnership (July 22). Anthropic will deploy up to 2 gigawatts of AMD Instinct MI450 Series GPUs in Helios rack-scale systems starting in the first half of 2027, and AMD committed a strategic equity investment of up to $5 billion tied to deployment milestones. Source: AMD Newsroom

Alphabet Q2 2026 earnings (July 22). Sundar Pichai said Google has “started our most ambitious pre-training run yet, for Gemini 4,” with Cloud revenue up 82%, a $514 billion Cloud backlog, and the Gemini app at 950 million monthly active users. Source: Q2 2026 earnings call: Remarks from our CEO

Microsoft–Mistral expanded partnership (July 21). Microsoft signed a multibillion-dollar agreement to use Mistral’s expanding European GPU infrastructure and offer Mistral’s models across its cloud. Source: Microsoft Source


This brief covers the trailing ~72 hours (July 23–26, 2026).

Primary sources:

GitLab Notebook-Diff RCE PoC, AD CS “Certighost” DC Impersonation, and Actively Exploited Fastjson 1.x RCE

This brief covers the trailing ~48 hours (July 24–26, 2026). Every item below was checked against its primary advisory, vendor PSIRT, original research write-up, or the CISA KEV catalog, and the disclosure or publication date was confirmed to fall within (or, for the “Still developing” section, just outside) the window.

Researchers publish working GitLab RCE chain from two five-year-old Oj memory-corruption bugs

depthfirst · July 24, 2026

depthfirst detailed — and released proof-of-concept code for — a remote code execution chain against default self-managed GitLab, built by combining two memory-safety flaws in Oj, the native-C Ruby JSON parser used by GitLab’s Jupyter notebook diff renderer. An authenticated user who can push to a project commits a crafted .ipynb file and opens its commit diff, driving repository-controlled bytes into Oj inside a Puma worker; an out-of-bounds write plus a heap-pointer disclosure are chained to hijack a callback pointer and reach system(), executing commands as the git account. The chain affects GitLab CE/EE 15.2.0 through 18.10.7, 18.11.0 through 18.11.4, and 19.0.0 through 19.0.1 (fixed in 18.10.8, 18.11.5, and 19.0.2 by upgrading to Oj 3.17.3, shipped June 10). GitLab did not file the underlying fix as a security fix, so there is no CVE or CVSS for the chain itself; the broader Oj review produced nine published advisories including CVE-2026-54502, CVE-2026-54896, and CVE-2026-54903. No in-the-wild exploitation was reported at publication.

“A normal authenticated user who could push to a project and view its commit diff could reach this path from their own project. Exploitation required no administrator privileges, CI or runner access, victim interaction, or access to another user’s project.” — Yuhang Wu, depthfirst

Source: depthfirst research · GitLab 19.0.2 patch release · The Hacker News

“Certighost” exploit lets a low-privileged AD user impersonate a Domain Controller (CVE-2026-54121)

Microsoft MSRC / independent researchers · July 24, 2026

Researchers H0j3n and Aniq Fakhrul published a working exploit for an Active Directory Certificate Services flaw they codenamed Certighost, tracked as CVE-2026-54121 (CVSS 8.8, improper authorization), which Microsoft patched on July 14. The bug lives in the AD CS enrollment “chase” fallback: an Enterprise CA follows a requester-supplied Domain Controller host over SMB and LDAP without first proving it is a real DC, letting a normal domain account obtain a certificate for a Domain Controller and authenticate as that machine via PKINIT. Because DC accounts carry directory-replication rights, the resulting Kerberos credential can retrieve the krbtgt secret through DCSync. Exploitation needs only network access and a domain account (no admin rights, no user interaction), and the full PoC is public. The flaw was not on CISA’s KEV catalog as of July 24, and no primary source reviewed reported in-the-wild exploitation.

“As of July 24, no primary source reviewed by The Hacker News reported exploitation in the wild, but the full proof-of-concept was public. That absence of reporting does not prove that exploitation has not occurred.” — The Hacker News

Source: Microsoft MSRC advisory · NVD · The Hacker News

Fastjson 1.x RCE (CVE-2026-16723) reported under active attack with no 1.x patch available

Alibaba advisory / ThreatBook / Imperva · advisory July 21, exploitation reported July 22–25, 2026

Alibaba published an advisory for CVE-2026-16723 (Alibaba-assigned CVSS 9.0), a critical RCE in the Fastjson 1.x Java JSON library affecting versions 1.2.68 through 1.2.83. In a Spring Boot executable fat-JAR application, an attacker-controlled @type value can be turned into a class-resource lookup that fetches attacker-controlled bytecode, yielding unauthenticated code execution with the privileges of the Java process; the maintainers confirmed the chain requires no AutoType enablement and no classpath gadget. ThreatBook reported capturing in-the-wild exploitation on July 22, and Imperva reported activity against U.S. financial-services, healthcare, and retail organizations. As of July 25 no fixed Fastjson 1.x artifact was available — mitigations are enabling SafeMode (-Dfastjson.parser.safeMode=true) or using the 1.2.83_noneautotype build, with migration to Fastjson2 as the long-term fix. Note: a July 23 CISA-ADP assessment marked exploitation as “none,” and the flaw was absent from CISA’s KEV catalog on July 25.

“As of July 25, Alibaba had not released a fixed Fastjson 1.x version.” — The Hacker News

Source: Alibaba advisory · NVD · The Hacker News

Still developing

Cl0p-linked actors chain unauthenticated RCE against internet-exposed PTC Windchill / FlexPLM (CVE-2026-12569)

Ransom-ISAC / PTC · July 25, 2026

A coordinated advisory from Ransom-ISAC, eCrime.ch, and DEFUSED describes a data-extortion campaign, with tradecraft attributed to Cl0p (aka FIN11 / Graceful Spider / Lace Tempest), against internet-exposed PTC Windchill and FlexPLM. Attackers chain a pre-authentication information disclosure in the FlexPLM WSDL endpoint (CVSS 7.5) with a server-side flaw in the Windchill login servlet, CVE-2026-12569 (CVSS 9.3), which CISA added to its KEV catalog in late June. Successful exploitation yields unauthenticated RCE and hex-named JSP web shells under /Windchill/login/, followed by staging and double-extortion theft of engineering and design data across manufacturing, automotive, aerospace, and retail targets.

“Attackers chain a pre-authentication information disclosure in the FlexPLM WSDL endpoint with a server-side flaw in the Windchill login servlet, enabling unauthenticated remote code execution and deployment of hex-named JSP web shells under /Windchill/login/.” — Ransom-ISAC / eCrime.ch / DEFUSED advisory

Source: Ransom-ISAC advisory · The Hacker News


This brief covers the trailing ~48 hours (July 24–26, 2026).

Primary sources:

wp2shell Pre-Auth RCE in WordPress Core Forces Emergency Updates; CISA Adds Fortinet FortiSandbox Command Injection and SharePoint Deserialization Flaws to KEV

This brief covers the trailing ~48 hours (July 16–18, 2026). Every item below was verified against its primary source — vendor advisory, researcher writeup, or CISA KEV entry — before inclusion.

wp2shell: pre-authentication RCE in WordPress core, emergency releases 6.9.5 and 7.0.2 pushed as forced updates

Searchlight Cyber / WordPress.org · July 17, 2026

Searchlight Cyber’s Assetnote research team (Adam Kues) disclosed wp2shell, a pre-authentication remote code execution flaw in WordPress core that chains a REST API batch-route confusion with SQL injection — a default install with zero plugins is exploitable by an anonymous HTTP request. Affected versions are 6.9.0–6.9.4 and 7.0.0–7.0.1; WordPress shipped 6.9.5 and 7.0.2 on July 17 and enabled forced automatic updates, while 6.8.6 backports a fix for the SQL injection component on the 6.8 branch. No CVE ID or CVSS score had been assigned at publication, technical details are being withheld, and no in-the-wild exploitation had been reported as of July 18. If you cannot update immediately, block both /wp-json/batch/v1 and ?rest_route=/batch/v1 at the WAF or disable anonymous REST access.

“The attack has no preconditions and can be exploited by an anonymous user in a stock install of WordPress with no plugins.” — Searchlight Cyber security advisory

Source: Searchlight Cyber advisory · WordPress 7.0.2 release post · The Hacker News

CISA adds two actively exploited Fortinet FortiSandbox command injection flaws to KEV

CISA · July 16, 2026

CISA added CVE-2026-25089 (CVSS 9.8) and CVE-2026-39808, both OS command injection vulnerabilities in Fortinet FortiSandbox, to the Known Exploited Vulnerabilities catalog on evidence of active exploitation. CVE-2026-25089 allows a remote, unauthenticated attacker to execute arbitrary commands via specially crafted HTTP requests. Fortinet published fixes in its June advisories, so patches are available; federal agencies are on a short remediation clock under BOD 22-01.

“These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise.” — CISA, KEV catalog alert

Source: CISA alert · SecurityWeek

SharePoint deserialization RCE CVE-2026-58644 lands in KEV two days after Patch Tuesday

CISA / Microsoft · July 16, 2026

CVE-2026-58644 (CVSS 9.8), a critical deserialization-of-untrusted-data vulnerability in Microsoft SharePoint Server that allows an unauthorized attacker to execute arbitrary code, was added to the KEV catalog in the same July 16 update. Microsoft patched it in the July 14 Patch Tuesday release and had initially flagged it only as an attractive target with no known exploitation — the KEV addition confirms exploitation evidence emerged within roughly 48 hours of the patch. Federal agencies have until July 19 to remediate. This lands on top of an already rough month for on-prem SharePoint: CISA is separately tracking active exploitation of CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164, with Shadowserver counting roughly 10,000 internet-exposed SharePoint servers.

Source: CISA alert · BleepingComputer

Still developing

SonicWall SMA1000 zero-days under active exploitationSonicWall / Rapid7 · July 14, 2026. SonicWall confirmed two zero-days in SMA1000-series secure remote-access appliances: CVE-2026-15409 (CVSS 10.0), an SSRF in the Work Place interface, and CVE-2026-15410 (CVSS 7.2), a post-authentication code injection in the Appliance Management Console. Rapid7 has observed targeted zero-day exploitation of internet-facing appliances since at least late June. Patches are available. Source: BleepingComputer · The Hacker News

Microsoft’s record July Patch Tuesday: 570+ fixes, two exploited zero-daysMicrosoft · July 14, 2026. The July update fixed CVE-2026-56155, an actively exploited AD FS elevation-of-privilege flaw, and CVE-2026-56164, an actively exploited SharePoint Server elevation-of-privilege flaw that CISA added to KEV the same day with a July 17 federal deadline. Source: BleepingComputer · CISA alert

LegacyHive Windows zero-day PoC published, no patch availableJuly 15, 2026. A researcher going by “Nightmare Eclipse” released a proof-of-concept exploit abusing the Windows User Profile Service for local privilege escalation to admin-level access, hours after Patch Tuesday. It affects supported Windows desktop and Server versions including fully patched systems, and has no CVE ID yet. Source: BleepingComputer


This brief covers the trailing ~48 hours (July 16–18, 2026).
Primary sources: Searchlight Cyber — wp2shell advisory · WordPress.org — 7.0.2 release · CISA — July 16 KEV additions · CISA — July 14 KEV additions · CISA KEV catalog

Moonshot’s Kimi K3 Becomes the Largest Open Model, Thinking Machines Debuts Inkling, and OpenAI Details GPT-Red Adversarial Safety Training

This brief covers the trailing ~72 hours (July 15–18, 2026). Every item below was confirmed on the originating organization’s own page, with a published date inside the window. It was a heavyweight stretch for open-weight models: Moonshot shipped the largest open model ever announced, and Mira Murati’s Thinking Machines Lab released its first model, while OpenAI published three posts spanning safety research, teen policy, and AI economics, and Google DeepMind and Isomorphic Labs laid out a joint biosecurity strategy.

Moonshot AI launches Kimi K3, a 2.8-trillion-parameter model it calls the first open 3T-class model

Moonshot AI · July 16, 2026

Moonshot introduced Kimi K3, a 2.8T-parameter Mixture-of-Experts model (16 of 896 experts active) built on its Kimi Delta Attention and Attention Residuals architectures, with native vision and a 1-million-token context window. Moonshot says K3 trails only Claude Fable 5 and GPT-5.6 Sol overall while consistently outperforming other tested models, and it is priced at $3/$15 per million tokens — the most expensive Chinese-lab model to date. K3 is live on Kimi.com, Kimi Work, Kimi Code, and the Kimi API, with full open weights promised by July 27, 2026.

“Today, we are introducing Kimi K3 — our most capable model. Kimi K3 is a 2.8T-parameter model built on our Kimi Delta Attention and Attention Residuals, with native vision capabilities and a 1-million-token context window. It is the world’s first open 3T-class model.” — Moonshot AI

Source: Kimi K3: Open Frontier Intelligence

Thinking Machines Lab releases Inkling, its first open-weights model

Thinking Machines Lab · July 15, 2026

Mira Murati’s Thinking Machines Lab released Inkling, a 975B-parameter Mixture-of-Experts model (41B active) trained from scratch on 45 trillion tokens of text, images, audio, and video, with a 1M-token context window and controllable thinking effort. The lab positions Inkling not as a benchmark leader but as a broad, balanced base for customization via its Tinker fine-tuning platform, and it trained the model specifically for calibration, instruction following, and resistance to censorship. Full weights are on Hugging Face, and a lighter Inkling-Small (12B active) is previewed.

“Inkling is not the strongest overall model available today, open or closed. Instead, a combination of qualities makes it a good open-weights base for customization: multimodal capabilities, efficient thinking, and availability on Tinker for fine-tuning.” — Thinking Machines Lab

Source: Inkling: Our open-weights model

OpenAI reveals GPT-Red, an internal red-teaming model trained via self-play to harden GPT-5.6

OpenAI · July 15, 2026

OpenAI detailed GPT-Red, an internal-only automated red-teaming model trained with self-play reinforcement learning at the compute scale of some of its largest post-training runs. GPT-Red found successful prompt-injection attacks in 84% of held-out scenarios versus 13% for human red-teamers, and even broke a live Andon Labs vending-machine agent in OpenAI’s office. Used adversarially during GPT-5.6’s training, it helped drive the model’s failure rate on GPT-Red’s direct prompt injections down to 0.05%, with a pre-print promised the following week.

“We believe automated red-teaming unlocks a crucial form of self-improvement for safety: using today’s models to directly help make future models safer.” — OpenAI

Source: GPT-Red: Unlocking Self-Improvement for Robustness

Google DeepMind and Isomorphic Labs publish a joint approach to bioresilience

Google DeepMind · July 16, 2026

Google DeepMind and Isomorphic Labs published a joint bioresilience framework organized around prevention, detection, and response: adapting SynthID watermarking to biological sequences for DNA-synthesis screening, using AlphaEvolve to cut the cost of metagenomic pathogen surveillance, and granting trusted researchers access to frontier systems to accelerate vaccine and countermeasure design. Isomorphic Labs has stood up a dedicated unit to rapidly deploy its Drug Design Engine during novel outbreaks, and the pair report more than 15 partnerships with governments and biosecurity organizations over the past 12 months.

“Our work is twofold – to prevent threat actors from misusing our models, and to ensure that governments, scientists, biosecurity experts and our teams can harness these technologies to build a more resilient world.” — Google DeepMind and Isomorphic Labs

Source: Our approach to bioresilience

OpenAI argues teens deserve access to safe AI, expands Study Mode parental controls

OpenAI · July 16, 2026

OpenAI published its case for teen access to AI paired with age-appropriate protections, citing that nearly 9 in 10 teens on ChatGPT use it weekly for learning or productivity. New measures include letting parents enable Study Mode by default from Parental Controls, education-focused starter prompts, more frequent break reminders for teens, and expanded parent notifications — now covering account deactivations for violent-threat policy violations, developed with violence-prevention firm Moonshot (unrelated to Moonshot AI). OpenAI also announced it has joined the Family Online Safety Institute.

“Keeping teens from using it until adulthood would be like asking a previous generation to avoid the internet or search engines until they turned 18, leaving them less prepared to use one of the defining technologies of their time.” — OpenAI

Source: Why teens deserve access to safe AI

OpenAI CFO Sarah Friar proposes a four-part “scorecard for the AI age”

OpenAI · July 17, 2026

In a follow-up to last week’s enterprise spend playbook, OpenAI CFO Sarah Friar proposed measuring AI ROI as “Useful Intelligence per Dollar” across four questions: how much useful work gets done, what a successful task costs, how dependable the results are, and whether each AI dollar buys more work at scale. The post frames GPT-5.6’s three tiers (Sol, Terra, Luna) as levers in that equation and claims GPT-5.6 Sol set a new state of the art on the Artificial Analysis Coding Agent Index while using 54% fewer output tokens than another leading model.

“The ultimate scorecard for the age of AI could be looked at as ‘Useful Intelligence per Dollar.’” — Sarah Friar, CFO, OpenAI

Source: A scorecard for the AI age


This brief covers the trailing ~72 hours (July 15–18, 2026).

Primary sources:

Record Microsoft Patch Tuesday With Two Exploited Zero-Days, SonicWall SMA1000 Under Active Attack, and AsyncAPI npm Supply-Chain Compromise

This brief covers cyber security developments from the trailing ~48 hours (July 14–16, 2026). Every item below was verified against its primary source — vendor advisory, CISA KEV entry, or original researcher publication — and dated within the window.

Microsoft’s record 570-flaw Patch Tuesday fixes two actively exploited zero-days in AD FS and SharePoint

Microsoft MSRC / Zero Day Initiative · July 14, 2026

Microsoft’s July 2026 Patch Tuesday shipped fixes for a record 570 vulnerabilities, including 59 rated Critical and two zero-days under active exploitation: CVE-2026-56155 (CVSS 7.8), an elevation-of-privilege flaw in Active Directory Federation Services stemming from insufficient access-control granularity, and CVE-2026-56164 (CVSS 5.3), an unauthenticated, network-reachable elevation-of-privilege bug in Microsoft SharePoint Server credited to Mandiant and Google Cloud researchers. Both were added to CISA’s KEV catalog on July 14, and CISA issued a companion alert urging SharePoint hardening. A third zero-day, the publicly disclosed BitLocker security-feature bypass CVE-2026-50661 (CVSS 6.1), was also patched but is not known to be exploited.

“It’s a missing-authentication flaw, meaning an unauthenticated attacker can hit it over the network with no user interaction required. When something this reachable is being actively abused, patch it now and worry about the score later.” — Trend Micro Zero Day Initiative, on CVE-2026-56164

Source: Microsoft MSRC (CVE-2026-56155) · Microsoft MSRC (CVE-2026-56164) · ZDI July 2026 review · BleepingComputer

SonicWall SMA1000 zero-days exploited in the wild — CVSS 10.0 SSRF plus admin-console code injection

SonicWall PSIRT · July 14, 2026

SonicWall confirmed active zero-day exploitation of two SMA1000 appliance vulnerabilities: CVE-2026-15409 (CVSS 10.0), an unauthenticated server-side request forgery in the Work Place interface, and CVE-2026-15410 (CVSS 7.2), a post-authentication OS command injection in the Appliance Management Console. Affected models 6210, 7210, and 8200v are fixed in platform-hotfix versions 12.4.3-03453 and 12.5.0-02835; SonicWall says there are no workarounds other than patching and published IOCs including rogue /__api__/login routes. CISA added both CVEs to the KEV catalog on July 14 with a federal remediation deadline of July 17.

“SonicWall PSIRT has investigated multiple cases indicating the active exploitation of the vulnerabilities described in this advisory.” — SonicWall advisory SNWLID-2026-0008

Source: SonicWall PSIRT SNWLID-2026-0008 · CISA KEV alert · BleepingComputer

AsyncAPI npm packages with 3M+ weekly downloads compromised via stolen GitHub Actions token

Datadog Security Labs · July 14, 2026

Four packages in the @asyncapi npm namespace — @asyncapi/generator 3.3.1, generator-components 0.7.1, generator-helpers 1.1.1, and specs 6.11.2/6.11.2-alpha.1 — were published with malicious code after an attacker exploited a misconfigured GitHub Actions workflow to steal a privileged bot personal access token. The implant chains a first-stage downloader to an IPFS-hosted second stage and a modular framework that steals browser credentials, SSH keys, npm/GitHub tokens, AWS credentials, and crypto wallets, with command-and-control over HTTP, Nostr relays, Ethereum smart contracts, and a libp2p mesh. Affected versions have been removed; teams should audit lockfiles and rotate any credentials present on machines that installed them.

“A commit to the AsyncAPI generator GitHub repository injected obfuscated JavaScript into four npm packages with a combined weekly download volume of over 3 million.” — Datadog Security Labs

Source: Datadog Security Labs · The Hacker News

CISA adds actively exploited Oracle E-Business Suite takeover flaw to KEV

CISA · July 15, 2026

CISA added CVE-2026-46817 (CVSS 9.8), an improper privilege management flaw in the Oracle Payments component of Oracle E-Business Suite versions 12.2.3–12.2.15, to the Known Exploited Vulnerabilities catalog with a federal remediation deadline of July 18. The bug allows an unauthenticated attacker with HTTP access to fully take over Oracle Payments; in-the-wild exploitation was observed before any public proof-of-concept existed. Oracle patched the flaw in last month’s Critical Patch Update — organizations should confirm the CPU is applied and check whether EBS instances are internet-exposed. The same KEV update also added CVE-2023-4346, a KNX protocol authorization weakness affecting building-automation deployments.

Source: CISA KEV alert · SecurityWeek · BleepingComputer

Progress confirms zero-day path traversal behind emergency ShareFile Storage Zone shutdown, ships patches

Progress Software · July 14, 2026

Progress confirmed that last week’s emergency shutdown of ShareFile Storage Zone Controllers was driven by a high-severity path traversal vulnerability affecting all 5.x and 6.x versions, disclosed to the company via a “credible external security threat” warning. An authenticated administrator can read arbitrary files accessible to the service account, write attacker-controlled content to arbitrary directories, or enumerate the filesystem. Fixed versions 5.12.5 and 6.0.2 are available now; a reserved CVE will be published in about two weeks. Progress says it has found no evidence of customer compromise.

“Currently, we have no indication of unauthorized access to any ShareFile customer account or data, and we have not identified any active threat.” — Progress Software

Source: Progress ShareFile downloads/advisory · BleepingComputer


This brief covers the trailing ~48 hours (July 14–16, 2026).
Primary sources: CISA KEV alert (July 14) · CISA KEV alert (July 15) · CISA SharePoint hardening alert · Microsoft MSRC · SonicWall PSIRT · Datadog Security Labs · Zero Day Initiative

Anthropic Launches Claude for Teachers and a $10M Canadian Research Commitment, While OpenAI Publishes an Agentic-Era Spend Playbook

This brief covers the trailing ~72 hours (July 12–15, 2026). Every item below was confirmed on the originating organization’s own page, with a published date inside the window. After one of the busiest weeks in recent memory (GPT-5.6, ChatGPT Work, Muse Spark 1.1, and Grok 4.5 all landed July 8–9), this window was notably quiet: the verified news is concentrated on a single day, July 14, led by two Anthropic announcements.

Anthropic launches Claude for Teachers, free for verified US K-12 educators

Anthropic · July 14, 2026

Anthropic introduced Claude for Teachers, giving verified US K-12 educators free access to premium Claude capabilities, a library of teaching skills grounded in learning science, and connections to evidence-based curricula mapped to academic standards in all 50 states via Learning Commons. The product connects to an ecosystem of K-12 tools (ASSISTments, Brisk Teaching, Canva Education, MagicSchool, and others), includes Claude Code and Cowork for tasks like analyzing class data and scheduling recurring work, and ships with K-12-specific privacy terms written to comply with FERPA — teacher data is not used for model training. Anthropic will pilot an evaluation in the Detroit Public Schools Community District, is open-sourcing the teaching skills, and is working with the American Federation of Teachers on privacy standards. Educators who sign up by June 30, 2027 get a full year of free access.

“We’re introducing Claude for Teachers, providing verified K-12 educators in the US free access to premium Claude capabilities, a library of teaching skills, and a direct connection to evidence-based curricula, mapped to academic standards in all 50 states.” — Anthropic

Source: Introducing Claude for Teachers

Anthropic commits $10 million CAD to Canadian AI research

Anthropic · July 14, 2026

Anthropic announced a $10 million CAD commitment to Canadian research institutions, with partnerships spanning the country’s three regional AI institutes — Amii (Edmonton), Mila (Montréal), and the Vector Institute (Toronto) — plus CHEO, CAMH, Université Laval, the University of Toronto, and the University of Saskatchewan. The funding targets beneficial and responsible AI applications from reinforcement learning and AI safety to children’s health and low-resource languages like Quebec French and Indigenous languages. Anthropic also published its first Canadian country brief from the Anthropic Economic Index, finding Canada ranks eighth worldwide in Claude.ai use and second in per-capita adoption among the top ten countries.

“Some of the foundations of modern AI came out of Toronto, Montréal, and Edmonton— and so, strikingly, did many of the researchers most committed to making it safe. I was formed by that culture, and I’m proud Anthropic can support the next chapter.” — Chris Olah, Co-Founder, Anthropic

Source: Anthropic commits $10 million to Canadian AI research

OpenAI publishes an enterprise playbook for managing AI spend in the agentic era

OpenAI · July 14, 2026

Following last week’s GPT-5.6 and ChatGPT Work launches, OpenAI published guidance for enterprise leaders on managing AI investments as agents take on longer-running work. The five-step framework centers on measuring “useful work per dollar” rather than token price, tracking cost per accepted outcome, and governing agentic workflows before they scale. The post also highlights updated usage analytics and spend controls in the ChatGPT Admin Console — adoption, credit usage, and spend broken down by user, product, and model — and notes that token prices fell 97% from GPT-4 to GPT-5.4, with GPT-5.6 completing coding-agent tasks with 54% fewer output tokens.

“But token price alone does not show whether AI is creating value. Leaders should look at useful work per dollar: tasks completed, time saved, decisions improved, and workflows ready to scale.” — OpenAI

Source: How to manage AI investments in the agentic era


This brief covers the trailing ~72 hours (July 12–15, 2026).

Primary sources: