This Week in Cybersecurity
Each week at Applied Tech we recap the biggest cybersecurity news headlines from the week to keep you informed and ready to face the latest threats. Here’s your breakdown for the week of July 25th – July 31st!
CareCloud's Breach Toll Climbs Past 345,000 as Details Emerge
New regulatory filings show the March breach at health tech giant CareCloud, which stores patient data for more than 45,000 U.S. providers, has affected at least 345,000 people so far. Hackers had access to one of the company’s AWS-hosted electronic health record stores for six days in March and claimed to have exfiltrated data, though no ransomware or extortion group has publicly claimed the attack.
Stolen data spans Social Security numbers, government IDs, financial account details, and medical information. The disclosed count is expected to grow as more state notifications are filed, and CareCloud has not responded to requests for comment.
Source: TechCrunch
Read More
Google Says AI Tools Drove a Record Wave of Chrome Patches
Google says it patched 1,072 security bugs across Chrome’s two June releases, more than the 1,036 fixes issued over the previous 23 versions combined during the past two years. The company credits its internal AI tools, including Gemini, for the jump, calling vulnerability discovery an “automated, industrial-scale operation.”
Microsoft reported a similar AI-driven surge this month with a record 570 patched flaws, while Apple’s patch volume has stayed roughly flat by comparison. The trend affirms warnings from security researchers that AI is accelerating bug discovery on both the offensive and defensive sides.
Source: TechCrunch
Read More
Teams Impersonation Scheme Moves From Access to Encryption in Under a Day
Sophos is tracking a vishing campaign, dubbed STAC4749, in which attackers pose as IT helpdesk staff over Microsoft Teams calls to trick employees into granting remote access, then deploy Chaos ransomware. The campaign hit dozens of organizations across the U.S. and Canada between February and June, with one intrusion moving from initial contact to full encryption in under 17 hours. Attackers used Quick Assist and remote management tools to gain footholds, disguised persistence mechanisms as legitimate audio drivers, and in at least one case stole data before encrypting systems.
Sophos links the Chaos ransomware-as-a-service operation to former members of the BlackSuit and Royal gangs, both Conti offshoots, though it found no connection to the similarly Teams-based MuddyWater campaign.
Source: BleepingComputer
Read More
New FCC Rule Blocks Import Approval for Foreign Robots, Inverters
Federal agencies updated an advisory warning that Iran-linked hackers are targeting industrial control systems from Siemens, Schneider The FCC added foreign-produced mobile robots and networked power inverters to its Covered List on July 28, blocking new models from receiving the equipment authorization needed for U.S. sale, though previously authorized devices and existing owners are unaffected. The robot determination cites prior research on exposed camera feeds and Bluetooth exploits affecting quadruped robots, while the inverter determination points to a documented case of a foreign manufacturer remotely disabling units after a business dispute.
Manufacturers can seek Conditional Approval through the Department of War or Homeland Security by January 1, 2028. It’s the FCC’s third such category-wide action, following similar bans on foreign drones and routers, and notably does not name specific manufacturers or claim an active exploitation campaign.Electric, and Rockwell Automation. The attackers gain access through internet-exposed programmable logic controllers, then alter the underlying logic to disable safety alarms and shutdown protections without alerting operators.
Source: The Hacker News
Read More

About Applied Tech, An HBS Brand
Applied Tech is a leading IT and cybersecurity services provider dedicated to helping organizations protect their digital assets and scale their IT capabilities. Our proactive services span cloud management, security, productivity, and IT growth strategy—delivered by an experienced team with solutions built around your goals.
As part of Heartland Business Systems, we now bring greater resources, broader capabilities, and deeper technical expertise to every client relationship.
Get in Touch with Us


