News Jul 7, 2026 ๐Ÿ‘ 22

IT News Roundup: SharePoint RCE, Custom AI Chips, and Five Eyes Cyber Warning - July 7, 2026

This week in IT: CISA flags actively exploited SharePoint vulnerability, Anthropic pursues custom silicon with Samsung, Five Eyes agencies issue rare joint warning on AI-powered cyber threats, and a 24-billion-record credential dump surfaces online.

The past week in technology has been defined by urgent security alerts, a bold push toward custom AI silicon, and an unprecedented joint warning from the world's leading intelligence agencies. From a SharePoint flaw now on CISA's Known Exploited Vulnerabilities list to Big Tech's staggering $650 billion infrastructure investment, IT professionals have plenty to monitor and act on.

CISA Adds SharePoint RCE Vulnerability to KEV After Active Exploitation

CISA has added CVE-2026-45659, a remote code execution vulnerability in Microsoft SharePoint Server, to its Known Exploited Vulnerabilities (KEV) catalog, confirming that the flaw is being actively exploited in the wild. The vulnerability involves the deserialization of untrusted data and allows an authenticated attacker with Site Member permissions to execute arbitrary code on the server.

The patch was released during Microsoft's May 2026 Patch Tuesday but the company initially classified exploitation as "less likely." CISA's Bureau of Industry and Security issued Directive 26-04, mandating that U.S. federal agencies remediate the vulnerability within three days of its KEV listing on July 1, 2026, with a deadline of July 4.

Organizations running on-premises SharePoint deployments should verify that the May 2026 security update has been applied immediately. Even environments that assumed the risk was theoretical now face confirmed exploitation attempts. Source: The Hacker News, CybelAngel

24 Billion Credentials Exposed in One of the Largest Data Dumps Ever Discovered

Security researchers at Cybernews uncovered an exposed Elasticsearch database containing approximately 24 billion stolen records, including usernames, passwords, and login URLs stored in plaintext. The roughly 8-terabyte database was compiled from 36 different sources, including Telegram channels, previous breach collections, and data exported from live servers โ€” likely aggregating infostealer malware logs.

The database was discovered on June 12 and has since been taken offline, but the scale of the exposure is staggering. The records span years of credential harvesting from multiple data breaches and malware campaigns. Anyone whose credentials may be in the dump should change passwords immediately and ensure multi-factor authentication is enabled across all accounts.

This incident underscores the compounding risk of credential reuse โ€” many of the 24 billion records are likely duplicates from earlier breaches, meaning a single compromised password could appear across dozens of unrelated services. Source: Malwarebytes, Cybernews

Five Eyes Agencies Issue Rare Joint Warning on AI-Powered Cyber Attacks

In an unusually public and coordinated statement, the cyber security agencies of the Five Eyes alliance (the United States, United Kingdom, Canada, Australia, and New Zealand) have warned that frontier AI models capable of devastating cyber attacks on governments and businesses are "mere months away."

The joint statement, issued by the NSA, GCHQ, Canadian Centre for Cyber Security, Australian Signals Directorate, and Government Communications Security Bureau, said that AI "accelerates the speed, scale and sophistication of cyber threats." The agencies urged leaders to invest in cyber defenses, upgrade legacy systems, patch vulnerable software, and limit access to critical infrastructure.

The rarity of a public, unified Five Eyes statement on this topic signals a significant escalation in perceived risk. For IT teams, the message is clear: the window to harden defenses before AI-automated attacks become mainstream is closing rapidly. Source: NSA, The Guardian

Anthropic Enters Talks with Samsung to Build Custom AI Chip on 2nm Process

Anthropic, the developer of the Claude AI model family, is reportedly in early-stage discussions with Samsung Electronics to manufacture a custom AI accelerator chip targeting Samsung's 2-nanometer SF2 process. The chip would use Gate-All-Around nanosheet transistors, a significant architectural advance over the FinFET transistors used in the previous generation.

The move follows Anthropic hiring specialized silicon engineers in recent months. The company is still defining chip specifications, power requirements, and integration plans for its server clusters. A custom silicon strategy would follow the path pioneered by Google (TPUs), Amazon (Trainium/Inferentia), and Microsoft (Maia), reducing dependence on Nvidia's GPU supply and potentially lowering inference costs at scale.

For homelabbers and infrastructure planners, the trend of AI companies designing their own silicon suggests that the GPU-centric model may evolve in the coming years, with custom accelerators becoming more common and potentially more accessible. Source: TechTimes, TrendForce

Big Tech Plans Combined $650 Billion AI Infrastructure Spending in 2026

Amazon, Alphabet, Meta, and Microsoft are collectively projected to spend approximately $650 billion on AI-related infrastructure in 2026, according to analysis by Bridgewater Associates and reporting from Bloomberg and Reuters. Amazon leads with roughly $200 billion, followed by Alphabet at $175โ€“185 billion, Meta at $115โ€“135 billion, and Microsoft at approximately $130 billion.

This represents the largest single-year corporate investment cycle in technology history. The spending is funding massive data center buildouts, GPU procurement, custom chip development, and even nuclear energy partnerships to power the growing compute demand. The ripple effects extend across the entire IT supply chain โ€” from semiconductor manufacturers and network equipment vendors to cooling systems and power infrastructure.

For smaller IT shops and homelab enthusiasts, this spending wave is driving down the cost of older-generation GPUs and servers on the secondary market, creating opportunities for budget-conscious compute projects. Source: Reuters, Tech Insider

Google Cloud Next 2026: Gemini Enterprise Agent Platform and 8th-Gen TPUs

Google's Cloud Next 2026 conference showcased the Gemini Enterprise Agent Platform, a unified system for building, scaling, and governing AI agents at enterprise scale. The platform combines Vertex AI capabilities with new tools for agent orchestration, governance, observability, and identity management, including an Agent Designer, activity Inbox, and support for long-running agents.

On the infrastructure side, Google announced two eighth-generation Tensor Processing Unit chips, a new AI networking fabric, and the "Agentic Data Cloud" architecture โ€” a new approach to organizing data so AI agents can act on it in real time. The Knowledge Catalog component acts as a dynamic map of an organization's entire data ecosystem.

These announcements signal Google's push to position itself as the infrastructure layer for the agentic AI era, competing directly with AWS and Azure in the enterprise AI deployment space. Source: Google Cloud Blog, Virtualization Review


โ† Back to Blog