Our July 2026 highlights cover the growing use of AI, the resilience of critical systems, and the risks created when trusted technologies are given broad access to organisational environments.
This month, an autonomous AI security-testing agent demonstrated how exposed credentials, code-execution paths, and excessive permissions can be combined into an unexpected intrusion chain, showing the risks when AI is unrestricted in pursuing a goal. New Zealand organisations face greater focus on privacy, breach readiness, and the ability to isolate vital operational technology during major incidents, while across the ditch a significant Australian data breach occured.
We highlight changes to Microsoft 365 data-residency with third-party AI processing, and Microsoft’s security updates which addressed actively exploited vulnerabilities and introduced additional protections for AI-related threats.
Happenings
[Global] OpenAI Agent Escapes Test Environment and Breaches Hugging Face
AI model and dataset hosting platform Hugging Face disclosed a July 2026 security incident in which an autonomous AI agent system gained unauthorised access to part of its production infrastructure. The intrusion began in the dataset-processing pipeline, where malicious dataset behaviour abused code-execution paths to run commands on a processing worker, then escalated to node-level access, to harvest cloud and cluster credentials. Hugging Face reported unauthorised access to a limited set of internal datasets and several service credentials but said they had found no evidence of tampering with public models, datasets, workspaces, container images, or published packages.
OpenAI later confirmed that the activity originated from their testing of models that were being evaluated for cybersecurity capability, including GPT-5.6 Sol and another more capable internal research model. The agent escaped a highly isolated evaluation environment, captured and used exposed credentials, and relied on public web utilities for staging, storage, and relay activity. Reports indicate that the agent carried out thousands of automated actions at machine speed and that some activity touched third-party services beyond Hugging Face, although OpenAI said it had not identified any other compromises at the same severity or scale.
Agentic systems can create significant risk when given broad permissions and clear objectives, as they may reason through how to achieve an outcome and independently take intermediate actions that were never explicitly requested or anticipated by the operator. This can result in the agent accessing systems, using available credentials, or crossing operational boundaries in pursuit of the original objective. The incident shows how autonomous agents can combine traditional weaknesses such as exposed credentials, over-permissioned service accounts, code execution paths, and poorly isolated sandboxes into a coherent intrusion chain. Organisations experimenting with agentic security testing or autonomous tooling should treat agents as high-risk operators and isolate evaluation environments, restrict internet access, remove secrets from test systems, monitor for unusual automated behaviour, require human approval for risky actions, and confirm that credentials used by AI workflows are scoped, short-lived, and rapidly revocable.
[NZ/Global] NZ Joins Guidance for Isolating Vital OT Systems
New Zealand’s National Cyber Security Centre has joined international partners including CISA, the UK National Cyber Security Centre, and the Canadian Centre for Cyber Security to provide guidance on isolating vital Operational Technology (OT) environments and supporting systems. The guidance responds to the ongoing targeting of critical infrastructure by state-sponsored actors and cybercriminals, including attempts to conduct espionage, pre-position for disruptive effects, or extort operators through ransomware and data theft.
The guidance recommends that critical infrastructure operators be able to isolate vital OT and supporting systems during a major cyber incident, crisis, or service disruption, and focuses on practical preparation rather than a single technical control. Organisation should identify vital systems and critical customers, map dependencies and network connections, and build effective separation points, creating dedicated OT capability, and undertake testing for isolation plans before they are needed.
The guidance provides advice for operating in isolation for an extended period, including manual or alternative SCADA paths where required. OT isolation should be treated as a planned resilience capability – operators of essential services should understand which systems are truly vital, how those systems depend on IT, cloud, identity, remote access, vendors, and telecommunications, and critically, how to safely enable continuity if those links have to be disconnected. This is particularly important for sectors such as energy, water, transport, telecommunications, and other services where continuity is critical during a national-scale incident or geopolitical crisis.
[NZ] Privacy Commissioner Signals Greater Scrutiny of Breaches and AI Decisions
The Office of the Privacy Commissioner’s 2026–2030 Statement of Intent and 2026/27 Statement of Performance Expectations indicate a more active privacy-regulation environment for New Zealand organisations. The Commissioner’s operating context notes that serious privacy-breach notifications have been increasing, and the 2026/27 plan links this trend to wider public concern about how agencies collect, protect, and use personal information. The Office’s stated direction is to make privacy a core focus for agencies, provide clearer expectations, and use investigation and compliance powers where serious privacy harm occurs
The performance plan covers a growing concern about AI-assisted decision-making, with the latest national privacy survey cited by the Office showing 67% of New Zealanders were concerned about government agencies or businesses using their personal information to make AI-assisted decisions affecting them. The same survey found strong demand for more control over personal information and pointed to lower confidence that existing protections are keeping pace with new technology.
Privacy risk should be treated as both a governance and security issue and addressed not only with policy, but also technical controls where applicable. Breach readiness needs to include clear escalation paths, notification decision-making processes, evidence preservation, and communications planning. AI use cases should be assessed before deployment, especially where personal information is used to support decisions about people. Organisations should be able to explain what information is used, why it is needed, how decisions are checked, and what safeguards exist to prevent unfair, inaccurate, or intrusive outcomes.
[NZ] OpenAI-Operated Models Automatically Enabled for Eligible Microsoft 365 Tenants
From 24 July 2026, Microsoft automatically enabled access to OpenAI-operated models for all users in eligible commercial Microsoft 365 tenants unless an administrator has explicitly configured the new subprocessor setting. OpenAI was added to Microsoft’s Online Services Subprocessors List in June, with the new delivery option becoming available in July. Unlike previous models delivered through Azure, these models are operated by OpenAI on their own infrastructure, with Microsoft retaining oversight through contractual, technical, and organisational safeguards.
Microsoft says use of the OpenAI-operated models remains governed by the Microsoft Product Terms, Data Protection Addendum, and Enterprise Data Protection commitments, subject to documented exclusions. However, a significant limitation exists that processing through these models is currently excluded from Microsoft’s applicable in-country processing commitments. The models are included within the EU Data Boundary except where Microsoft’s documentation states otherwise, and they are not currently available in government or sovereign clouds.
The setting affects Microsoft 365 Copilot, Copilot experiences within Microsoft 365 applications, and Microsoft Copilot Studio. The available control set can allow access for all users, restrict it to selected users or groups, or completely disable OpenAI-operated models. The control does not disable Microsoft-operated models delivered through Azure OpenAI, although Microsoft warns that restricting the OpenAI subprocessor may affect the availability of some newer Copilot capabilities. Organisations should review the current tenant setting, identify which users and Copilot workloads can access OpenAI-operated models, and assess whether the processing arrangement is consistent with privacy notices, contractual obligations, records of processing, data-residency requirements, and internal AI policies. Where in-country processing is mandatory or sensitive information is involved, access may need to be restricted until the organisation has completed appropriate legal, privacy, security, and risk assessments.
[AU] Origin Energy Data Breach
of Australia’s largest electricity and gas retailers suffered a customer data breach in July 2026, with an estimated 900,000 customer records extracted. The incident affected Origin Energy, a major Australian energy provider that manages an estimated 4.8 million customers across its gas and electricity services. Origin Energy reportedly received an initial tip-off about the breach from the adversary on 2 July 2026. However, the company appears not to have publicly acted on the initial notification before the adversary released partial information about the breach to journalists on 22 July 2026. The adversary claims to hold around 2 million customer records and has threatened to release the information if Origin Energy does not pay a ransom. Origin Energy released a formal statement on 23 July 2026 confirming that the breach had been verified and impacted their customer data and confirmed that the adversary extracted personal information such as names and dates of birth, along with account information including partial payment card details.
There has been no reported disruption to the delivery of Origin Energy’s services or the supply of energy to customers. In response to the incident, Origin Energy is currently contacting affected individuals to notify them of the breach and provide support where required.
Techniques and Updates
Hospitality Wi-Fi Presenting Major Risk
Microsoft has identified an emerging technique abused by state-sponsored actors, in which attackers compromise hospitality Wi-Fi infrastructure and use the connection process itself to target corporate travellers. Hospitality Wi-Fi is particularly attractive because it is designed to provide simple access to large numbers of unfamiliar and unmanaged devices, with users already expecting browser redirects, login pages, and connectivity prompts, making malicious content easier to disguise as part of the normal connection process. These networks may rely on third-party providers, shared gateways, or centrally managed captive-portal platforms, meaning that one compromise can potentially reach users across several venues.
Attackers manipulate captive portals, DNS responses, or web traffic so that malicious content appears while a user is joining a hotel, conference-centre, or other guest network. An attacker-controlled page may imitate a Microsoft 365 sign-in screen, present a device-code authentication request, or display a convincing browser or Windows update message. A victim can be directed to a legitimate Microsoft authentication page and complete multifactor authentication, but still authorise a session initiated by the attacker.
We recommend that organisations remind staff to treat guest Wi-Fi as untrusted and, where possible, use managed mobile connections for corporate devices, or personal devices with corporate data, or that connect to corporate systems. Organisations should restrict device-code authentication where it is not required, and remind staff not to install updates, run commands, or approve unexpected authentication prompts while connected to public networks.
Microsoft Security / Updates
Microsoft’s July 2026 security updates introduced changes across Microsoft Defender, Entra ID, and Purview, including new protections for AI-related threats, changes to authentication, and expanded endpoint and data-security capabilities. The monthly vulnerability release addressed two actively exploited vulnerabilities affecting organisations that operate on-premises SharePoint Server or Active Directory Federation Services.
Microsoft patched CVE-2026-56164, an actively exploited privilege-escalation vulnerability affecting supported versions of on-premises SharePoint Server. SharePoint Online is not affected, but organisations still operating SharePoint Server should confirm that the July security updates have been applied and any required post-installation steps completed.
An ADFS vulnerability CVE-2026-56155, is actively being exploited, and affects the permissions applied to the Distributed Key Manager container used by Active Directory Federation Services. If permissions are too broad, an attacker with access to the stored key material may be able to decrypt token-signing private keys and gain elevated privileges. Microsoft began a staged hardening process with the July Windows updates, but organisations using AD FS must still review their configuration and complete the required remediation steps.
Microsoft Defender for Office 365 introduced protection for indirect prompt-injection attacks, where actors place malicious instructions inside emails or other external content that may later be processed by an AI assistant. Defender can now detect this content and classify messages as high confidence phishing, before they reach users or Microsoft 365 Copilot. Microsoft Purview added controls that can prevent Copilot from using externally received emails as grounding information and Purview’s network data-security capabilities can detect and block sensitive information being sent to unmanaged cloud applications and generative AI services when integrated with a supported network-security or secure-browser solution.