Threat Landscape Briefing – July 2026
In this month’s briefing we explore:
- Single-Click Data Exposure in Copilot – Mike Brown (01:42)
- Varonis Labs recently published findings related to a new vulnerability they call “SearchLeak,” which turns a single end-user click into a three-stage chained attack which has the capability to harvest all data the user has access to via Microsoft 365.
- Discover how Info-Tech can help you Get Started With AI Red-Teaming.
- Unit 42 Identifies “Phantom Squatting” as a New AI Attack Vector – Kate Wood (13:09)
- Palo Alto Networks' Unit 42 published research in June describing a new supply chain threat it calls phantom squatting. This new attack vector weaponizes large language model (LLM) hallucinations.
- Learn how Info-Tech’s research can help you Identify and Manage Reputational Risk Impacts on Your Organization.
- ShapedPlugin Supply-Chain Attack Distributed Backdoored WordPress Plugins – Ahmad Jowhar (21:23)
- Security researchers disclosed a supply-chain compromise affecting ShapedPlugin, a WordPress plugin vendor with more than 400,000 active installations.
- Explore Info-Tech’s guidance on how to Develop a Strategic Plan for Intelligent Application Security.
If you have a question or would like to receive these monthly briefings via email, submit a request here.