← Back to Blog

The Tuesday Briefing — Jul 21, 2026

6 min readAtypical Tech
Illustration for The Tuesday Briefing — Jul 21, 2026

The Big Picture

This week, an AI agent broke into a company, stole passwords, and locked up the network — without a single human giving it instructions after launch. Around the same time, an urgent, actively-exploited flaw in a widely used business software platform (ServiceNow) let attackers break in with no login required at all. The theme this week: AI tools are now both the target and the weapon, and the businesses getting hit hardest are the ones running common tools without a patching plan.

This Week's Top 5

1. An AI Program Broke Into a Company and Locked Its Files — With Zero Human Help

What happened: Security researchers documented a case where an AI agent found an unpatched flaw in a workflow automation tool called Langflow, broke in on its own, stole login credentials, and encrypted the company's files — the entire attack ran without a person directing any of it.

Why it matters to your business: If your business uses any workflow automation, chatbot, or "AI helper" tools connected to your network, an outdated version can now be found and exploited automatically, at any hour, with nobody behind the keyboard.

What to do: Ask whoever manages your automation or AI tools (even a simple chatbot plugin) for a list of every one connected to your systems, and confirm each is running its latest version.

2. A Widely Used Business Platform (ServiceNow) Has a Break-In Flaw With No Login Needed

What happened: A serious security flaw in ServiceNow's AI platform — a tool many mid-size companies use for IT tickets, HR requests, and workflow management — is being actively exploited by attackers who don't even need a password to get in.

Why it matters to your business: If your business or an outsourced IT provider uses ServiceNow, this is not a "someday" risk — attackers are using it right now to break into systems.

What to do: If your business uses ServiceNow, contact your IT provider today (not this week — today) and ask them to confirm the emergency patch has been applied.

3. A New Attack Tool Is Scanning the Internet Specifically for Small Business AI Setups

What happened: Researchers found a new automated attack tool roaming the internet looking for exposed AI and automation tools (things like chatbot builders and workflow platforms) that businesses left accessible without proper security, then stealing the cloud passwords stored inside them.

Why it matters to your business: Many small businesses set up AI tools quickly through a developer or freelancer, and it's easy to accidentally leave them open to the public internet without realizing it.

What to do: Ask your developer or IT contractor: "Is our AI or automation tool accessible from the open internet, or only from inside our network?" It should be the second one unless there's a specific reason otherwise.

4. A Popular Free Security Tool Had a Flaw That Let Secrets Leak Out

What happened: Gitleaks, a free tool many developers use to catch accidentally-exposed passwords and keys in code, was found to have its own flaw — a rigged file could trick it into leaking those same secrets to an attacker.

Why it matters to your business: If your business has custom software or an in-house developer, tools meant to protect your secrets can themselves become a leak point if not kept current.

What to do: If you have an in-house or contract developer, ask if they use Gitleaks, and if so, confirm they've updated to version 8.30.1 or later.

5. Ransomware Can Now Fully Lock Down a Small Business Network in Under 24 Hours

What happened: A new ransomware group nicknamed "The Gentlemen" and a fast-moving ransomware strain called "Spirals" are hitting small and mid-size businesses hard, with Spirals able to fully encrypt an entire network within 24 hours of breaking in through an unpatched web server.

Why it matters to your business: A day used to feel like a safety cushion between "something's wrong" and "everything's locked." That cushion is basically gone now — detection speed matters as much as prevention.

What to do: Ask your IT provider whether you have any tool actively monitoring for suspicious activity in real time (not just antivirus that scans occasionally) — if not, this is the week to set that up.

Quick Hits

  • A researcher found that a private tool used by developers to catch AI mistakes (Claude Code) had six separate bugs letting it run commands it shouldn't — Anthropic issued emergency fixes; if developers on your team use it, confirm it's updated.

  • A survey found 64% of companies in South Africa have employees using AI tools nobody approved or reviewed — likely true everywhere, and a good excuse to ask your team what AI tools they're actually using day to day.

  • GitHub is starting to require older automation "runner" software be updated by a set deadline this summer — worth a quick check if your business has any custom code pipelines.

  • A report found 81% of ransomware attacks now start with a stolen login, not a virus — reinforcing that strong, unique passwords and a second login step matter more than antivirus software alone.

  • An academic study found that hacking tricks that work against one AI tool often work against several others — meaning a flaw found in one popular AI product can spread risk to many similar tools.

  • Security company Sophos found that legitimate AI coding assistants can trigger the same alarms as actual hackers, causing IT teams to get flooded with false alarms — a heads-up if your IT provider mentions unusual alert volume.

One Thing to Do This Week

Find out if any software your business runs is reachable from the public internet without a login — especially anything related to AI, automation, or chatbots. Attackers are actively scanning the internet right now specifically for these kinds of exposed tools, as seen in two separate stories this week. Ask your IT provider or developer one direct question: "Can you check what's accessible from the open internet, and confirm anything sensitive requires a login?" This is usually a same-day fix once someone checks — the hard part is remembering to ask.

Worth Reading

Related Posts