Everything Old is New Again, Again
7–21–2026 (Tuesday)
Hello, and welcome to The Intentional Brief - your weekly video update on the one big thing in cybersecurity for middle market companies, their investors, and executive teams.
I’m your host, Shay Colson, Managing Partner at Intentional Cybersecurity, and you can find us online at intentionalcyber.com.
Today is Tuesday, July 21, 2026, the Strait of Hormuz is closed once again.
Everything Old Is New Again, Part 2
On the cyber side, we’ve got a bit of an “I told you so” episode.
Last week, we talked about how Microsoft was foreshadowing both that they’d be pushing out bigger patches in their famous “Patch Tuesday” window, and the need for more frequent patching. Now we know why they telegraphed this message.
July’s Patch Tuesday fixes a record 570 vulnerabilities, including two “zero days,” and 59 "Critical" vulnerabilities, 48 of which are remote code execution, 9 are elevation of privilege, 1 is a security bypass, and 1 is a spoofing.
They weren’t the only ones doing a patch dump, either, as we saw updates from Adobe, BeyondTrust, Cisco, Fortinet, Ivanti, NVIDIA, Process Software, Ubiquity, SAP, VMWare and others.
At the same time, we saw some new research out of Orca Security claiming that 99.9% of AI vulnerability alerts with an available fix remain unpatched. Some other stats that jumped out are that Orca finds the majority (51%) of organizations they surveyed are using AI to build custom software, and “found that 81.2% of companies running AI packages have at least one known vulnerability.” Of those, “74.1% have at least one critical CVE.” Again, patching is not glamorous, but it’s tremendously important, and - at least according to Orca - we’re still struggling with it.
Speaking of struggling, more information about the recent DHS breach was reported last week, and it notes that:
Between May 15 and May 24, the infiltration was detected by analysts inside FEMA, where they observed the hackers had altered files on testing and live servers, used a legitimate web-server program to run malicious code and deleted activity logs that could have exposed their movements, according to the readout. The activity was ruled a false positive.
Between May 25 and June 3, the hackers used similar methods aiming to leave scant trace of their activity, setting off more alerts that were again dismissed as benign. On June 4, they installed hidden backdoors and stole credential data — typically employed to verify users’ identities and grant access to accounts or systems — where personnel then declared a breach was active.
The report concludes: “It’s not clear why the intrusion was deemed benign two times over such a wide timeframe.”
To go back to an overused trope, the Target breach had similar constructs, where alerts were firing but either being dismissed or ignored. Everything old is new again.
If you’ve got tools giving you alerts that things aren’t great, please do enough diligence to make an accurate call. You’ve done the hard work of procuring, and deploying these things - and, yes, maybe they still need some tuning - but don’t throw the baby out with the bathwater here. DHS did, and paid the price.
Fundraising
From a fundraising perspective, another good week, with just shy of $15B in newly committed capital raised across more than a dozen funds.
Meanwhile, in public markets, SpaceX has fallen more than 20% below it’s IPO price as we await long-rumored IPOs from both Anthropic and OpenAI.
A reminder that you can find links to all the articles we covered below, find back issues of these videos and the written transcripts at intentionalcyber.com.
We’ll see you next week for another edition of the Intentional Brief.
Links
https://www.helpnetsecurity.com/2026/07/13/ai-infrastructure-security-risks-report/