Please enjoy our latest podcast, the weekly Security Sprint, on Spotify, Apple, as well as other locations accessible via the Spotify for Podcasters link or wherever you listen to your favorite podcasts.
Today, Dave and Andy examine the growing need for converged, all-hazards security planning; the rapid growth in high-impact vulnerabilities; AI’s role in accelerating both discovery and exploitation; rising hacktivist activity; the continued targeting of Microsoft Teams and business communications; and a ransomware landscape that remains highly active.
Opening:
- Cybersecurity Regulations: Multiple Sectors Are Subject to Potentially Duplicative Reporting Requirements — U.S. Government Accountability Office & 70% of federal cybersecurity reporting rules are duplicated, GAO finds — CyberScoop
- ANCHOR-CI could fix 20 years of broken government-industry collaboration — CyberScoop
- Project Pilot: Can AI models fly drones? — Anthropic —
- OpenAI and Hugging Face partner to address security incident during model evaluation — OpenAI —
- Bluesky Thread: OpenAI and Hugging Face incident demonstrates both autonomous cyber risk and defensive potential — Pwnallthethings
- Hugging Face CISO Post Mortem — Cloud Security Alliance
Main Topics:
1 dead, 16 injured after car ramming at Berlin CSD Pride event — DW — 25 Jul 2026. One person was killed and 16 others were injured after a vehicle was driven into people attending Berlin’s CSD Pride event. Authorities investigated the circumstances and potential motive behind the incident as emergency personnel treated victims and secured the area. The attack underscores the vulnerability of large public gatherings to vehicle-based violence and the potential for mass casualties within seconds. Target is event organizers, law enforcement, emergency services, commercial facilities, and organizations supporting LGBTQ communities. Dig highlights the importance of vehicle barriers, controlled access routes, emergency medical planning, and rapid threat communication at major public events.
- The suspect in the deadly Berlin Pride attack is killed in a confrontation with police
- Car Plows Into Crowd at Berlin Pride Event in Suspected Terror Attack
‘Integrated’ cyber and physical attacks concerned FIFA planners — StateScoop — 20 Jul 2026. Security planners for the 2026 FIFA World Cup prepared for blended attacks combining cyber disruption, physical violence, disinformation, swatting, infrastructure attacks, and interference with emergency communications. The Center for Internet Security reported that more than one billion cyberattacks were blocked during the tournament and supported an information-sharing environment used by approximately 4,000 participants across government and private-sector organizations. Officials identified integrated attacks as a particular concern because simultaneous digital and physical disruptions could overwhelm responders and degrade communications during a major incident. Target is major-event organizers, law enforcement, government agencies, critical infrastructure operators, and private-sector security partners with Dig highlighting the need to integrate cyber, physical, intelligence, and communications planning because adversaries increasingly operate across multiple threat domains simultaneously. (StateScoop)
2026H1 Threat Review: Vulnerabilities Up 51% Year Over Year — Forescout — 20 Jul 2026. Forescout reports a 51 percent year-over-year increase in vulnerabilities during the first half of 2026 as organizations contend with accelerating disclosure volumes across IT, Internet of Things, operational technology, and connected devices. The expanding vulnerability landscape increases pressure on security teams that must identify exposed systems and prioritize remediation based on exploitability and operational importance. Internet-facing systems and infrastructure lacking effective asset visibility remain particularly difficult to protect at scale.
Email threat landscape: Q2 2026 trends and insights — Microsoft Security — 23 Jul 2026. Microsoft detected approximately 7.6 billion email-based phishing threats during the second quarter, while monthly volumes declined modestly from April through June. Phishing linked to the Tycoon2FA service fell 92 percent from pre-disruption averages, demonstrating the potential impact of coordinated infrastructure disruption. Threat actors continued shifting toward Microsoft Teams, where malicious calls reached nearly ten times the mid-2025 baseline, and one automated business email compromise campaign reached more than 67,000 users across 42,000 organizations in under three hours.
Quick Hits:
- Weekly ransomware & data leak landscape — eCrime.ch — 27 Jul 2026. eCrime.ch recorded 236 public ransomware and data-leak claims involving 45 active groups during the seven-day period ending 27 July, with 63 events showing public evidence of data leakage. Qilin led with 37 claims, followed by Gentlemen and Global Secret Group with 31 each, while construction was the most frequently targeted sector with 17 incidents. The United States accounted for 103 claims, and healthcare recorded 10 incidents among the 88 sectors represented.
- Pay up or not? Ransomware surge has victims facing tough choices — Ars Technica
- If you pay a hacker’s ransom, chances are that they’ll come back for more
- Cl0p Exploitation of PTC Windchill & FlexPLM (CVE-2026-12569) — Ransom-ISAC — 22 Jul 2026. Ransom-ISAC, eCrime.ch, and DEFUSED warn that Cl0p ransomware affiliates are actively exploiting internet-exposed PTC Windchill and FlexPLM systems.
- Black Kite’s 2026 Ransomware Report: Ransomware Accelerates 60% in Six Months and Shows No Signs of Slowing as New Ransomware Groups Emerge Weekly


Read more about Gate 15’s full podcast menu at our Podcast page. You can subscribe and enjoy all the Gate 15 Podcasts on Spotify for Podcasters, Apple, Spotify, as well as other locations accessible from the Spotify for Podcasters link. Week-to-week, you can hear and learn more about our all-hazards threats, risks, mitigation and other issues impacting homeland security risk management from our team as well as our regular and special guests. The full podcast menu includes:
- The Security Sprint is our weekly rundown of the week’s notable all-hazards security news, risks and threats and some of the key focus areas for organizations to consider behind the headlines. Gate 15 team members discuss physical security, cybersecurity, natural hazards, health threats and other issues across our environment.
- Nerd Out! Security Panel Discussion, moderated by Dave Pounder, focuses on physical security topics including terrorism, extremism, hostile events, and other pertinent topics.
- The Gate 15 Interview, is a monthly interview between Gate 15’s founder and Managing Director, Andy Jabbour and guests from throughout the homeland security risk management community addressing a wide range of all-hazards topics and issues.
- The Cybersecurity Evangelist, with Jennifer Lyn Walker, is a cybersecurity-focused discussion with Jen and invited guests. This is presently a Gate 15 special podcast and occasionally is updated on our Gate 15 podcast channel.
- Venue Security, The IAVM Podcast Series was a 2024 limited series podcast as Gate 15’s founder and Managing Director, Andy Jabbour hosted a series of short interviews with venue safety and security experts from the International Association of Venue Managers’ (IAVM) Venue Safety and Security Committee (VSSC) and other special guests from the IAVM community.
- The Risk Roundtable, was a monthly discussion among our team and occasional guests exploring the all-hazards threats and risks impacting the United States and internationally. This was suspended in September 2023.
We hope you’ll subscribe, listen and share your ideas and other feedback! Reach out to us on Bluesky, LinkedIn, via email at Gate15@gate15.global.
