AI and IT News Recap: July 14, 2026: Two Perfect-10 Joomla Zero-Days Web-Shell the Web, Europe Names Russia’s Hackers, and Claude Fable 5 Gets Another Reprieve

By Noah Smith, Owner & Consultant, KeyChange Technologies · July 14, 2026

Pen-and-ink cutaway illustration of a small shop: a queue of anonymous figures posts envelopes through a slot in the front door while the envelopes pile up inside and an arm reaches out of one toward the till, as the shopkeeper sweeps, unaware.

Quiet Monday? Not really. Here is your AI and IT news for July 14, 2026: two perfect-10 flaws are being used to plant web shells on ordinary business websites, Europe just put names and faces to Russia's hacking machine, and Anthropic keeps kicking the Fable 5 can down the road.

📌 The AI and IT news at a glance

  • Two max-severity Joomla zero-days are being exploited right now, and Australia says the wider campaign against website CMS platforms is global.
  • The EU and UK dropped their first joint cyber sanctions package, naming GRU and FSB officers and a company that recruits hackers out of universities.
  • Lidl told online shop customers in three countries their data was stolen from an IT service provider.
  • CrashStealer, a new Mac infostealer, sailed straight through Gatekeeper with a valid Apple notarization.
  • Anthropic extended free Claude Fable 5 access again, this time through July 19.
  • Claude finally has rupee pricing in India, its second-biggest market.
  • Monzo co-founder Tom Blomfield joined Anthropic's compute team.
  • A poisoned npm release of jscrambler went hunting for cloud keys and AI coding assistant credentials.

🔝 Top story: two perfect-10 Joomla flaws are quietly turning small business websites into attacker infrastructure

CISA added two maximum-severity flaws to its Known Exploited Vulnerabilities catalog after both were confirmed exploited as zero-days. CVE-2026-48939 sits in iCagenda, a popular Joomla events calendar extension, and lives in the "Submit an Event" form: the attachment upload accepted whatever a visitor handed it, including PHP. CVE-2026-56291 does the same thing in Balbooa Forms, where the frontend upload took a file from any anonymous visitor with no login, no CSRF token, and no file type check. Both score a flat 10.0. Both give an unauthenticated stranger remote code execution on your web server.

The exploitation is not theoretical or targeted. According to mySites.guru, which found both, CVE-2026-48939 has been hit by automated scanners since June 15, one identifying itself in access logs as "icagenda-batch/1.0" that grabbed a token, posted a malicious upload, then fetched the planted shell at the exact path the component writes attachments to. Patches exist: iCagenda 4.0.8 and 3.9.15, Balbooa Forms 2.4.1. Federal agencies had until yesterday to fix it. On the same day, Australia's ACSC warned of a broad global campaign scanning websites for any CMS or plugin flaw that allows file upload or remote code execution, listing bugs in WordPress plugins, Craft CMS, MetInfo, and more, with a pointed note that AI is "accelerating the speed and scale of cyber operations, reducing the time between vulnerability disclosure and exploitation."

In short: Two maximum-severity file upload flaws in common Joomla extensions are being exploited in automated attacks to plant web shells, and CISA has added both to its KEV catalog.

What it means for your business: If your marketing site runs Joomla or WordPress with third-party form, calendar, or booking plugins, that site is a live target this week, and a web shell on it becomes a foothold, a phishing host, or a data leak on your domain. Patch the extensions, then go look in the upload folders for PHP files that should not be there.

My take: The uncomfortable part is not the CVEs, it is who owns the website. In most companies the marketing site was built by an agency three years ago, nobody has logged into the admin panel since, and it is not on anyone's patch list because it is "just the brochure site." That is exactly the asset getting web-shelled here. The bots are not choosing you, they are choosing everyone. Find out today who owns that box and when it was last updated.

Source: The Hacker News: iCagenda and Balbooa Forms Joomla Flaws Reportedly Exploited as Zero-Days


🤖 AI

Anthropic extends Claude Fable 5 access again, days after OpenAI's Sol landed

Anthropic announced on Sunday, via X, email, and an updated support page, that Claude Fable 5 stays available to subscribers at no extra cost through July 19. That is the second extension in a week: the original promotion launched July 7 and let Claude users spend up to half their weekly subscription limits on the model. Users who burn through the expanded allowance can still buy usage credits and pay by consumption.

The timing is not subtle. It came three days after OpenAI launched GPT-5.6, headlined by its flagship Sol model, which OpenAI claims hits state-of-the-art results in coding, knowledge work, cybersecurity, and science at a lower cost, and which it says beat Fable on coding tasks. Fable's own debut was rocky: it launched in June as a safety-restricted variant of the more powerful Mythos, the Commerce Department forced Anthropic to pull it days later, and access was only restored at the start of this month. Mythos itself is still limited to roughly 150 organizations across more than 15 countries.

In short: Anthropic extended free Fable 5 access for Claude subscribers through July 19, its second extension in a week, following OpenAI's GPT-5.6 launch.

What it means for your business: If you are evaluating frontier models, you have a free window until July 19 to test Fable on your real workloads, which is a better basis for a decision than anybody's benchmark chart.

My take: A week-by-week access extension is a competitive reflex, not a roadmap. Handy if you are experimenting, risky if you are building on it. Do not put Fable in a production workflow on the strength of a promotional window that has already moved twice.

Source: Forbes: AI Model Wars: Anthropic Extends Fable Access Again After OpenAI's Sol Release


Claude gets rupee pricing in India, its biggest market after the US

Anthropic has started showing Indian rupee pricing on Claude's website and mobile apps in India, which accounts for 5.8% of global Claude usage and is the second-largest market after the US. Claude Pro is listed at ₹2,000 a month billed annually (roughly 1, against

7 in the US), Max starts at ₹11,999 (about
25, against
00), and Team starts at ₹2,399 per seat (about 5, against 0). Indian prices include local taxes.

Notably, Anthropic has not enabled UPI, India's instant payments rail, so users still pay by card or through Apple and Google app store billing. OpenAI shipped rupee pricing with UPI support last August. The move fits a broader India push: a Bengaluru office opened in February, former Microsoft India MD Irina Ghose is running the country business, and there are partnerships with Infosys and TCS. It also follows a bruise, when Anthropic abruptly suspended non-US access to Fable 5 and Mythos 5 in June and sent Indian developers shopping for alternatives.

In short: Anthropic began rolling out rupee-denominated Claude subscriptions in India, though without UPI payment support.

What it means for your business: If you have engineering or support teams in India, local billing removes a real friction point from seat expansion, though the local price is still above US dollar pricing.

My take: Localized pricing that comes in above the US price and skips the payment method everyone actually uses is a half-step. It signals India matters commercially, but the pricing is not aggressive and the omission of UPI is going to keep conversion soft.

Source: TechCrunch: Anthropic starts localizing Claude pricing for India, its biggest market after the US


Monzo co-founder Tom Blomfield joins Anthropic's compute team

Tom Blomfield, who co-founded GoCardless in 2011 and Monzo in 2015 and ran the bank as CEO until 2020, said Monday he is taking a leave of absence from Y Combinator to join Anthropic. He will work on the compute team alongside Anthropic co-founder and chief compute officer Tom Brown, on the infrastructure underneath the Claude model family.

It is an unusual hire. Blomfield is a consumer fintech operator and, since 2023, a full YC partner who mentored founders across four batches, not an infrastructure engineer. Anthropic has spent 2026 collecting marquee names, and the destination team says something: compute, not product, not research.

In short: Monzo and GoCardless co-founder Tom Blomfield is taking leave from Y Combinator to join Anthropic's compute team.

What it means for your business: Nothing operationally, but it is a useful signal about where the frontier labs think the constraint is right now, and it is not model quality.

My take: When an AI lab recruits a scaling operator instead of another researcher, they are telling you their bottleneck is chips, power, and buildout. Keep that in mind the next time a vendor promises you unlimited capacity at a fixed price.

Source: Sifted: Anthropic recruits Monzo cofounder Tom Blomfield for AI compute team


🛡️ IT and security

The EU and UK hit Russia with their first joint cyber sanctions package

Brussels and London moved together on Monday for the first time on cyber sanctions, and the naming was specific. The Council of the EU sanctioned nine individuals and four entities, centered on the 16th Center of Russia's FSB, over an espionage network the bloc says has targeted governments and run sabotage operations against critical infrastructure like heating and power plants since 2010. The UK went further, sanctioning 24 individuals and entities, including senior GRU figures Vyacheslav Stafeyev, Ivan Senin, and Ivan Kasyanenko, whom officials say directed cyber and hybrid operations.

Two of the UK designations matter for ordinary businesses more than the GRU names do. Britain sanctioned members of IMPULS, a company accused of recruiting hackers straight out of Russian universities, and individuals tied to the Lumma Stealer infostealer operation, which UK authorities link to at least 2,100 domestic victims in six months. Lumma is not spycraft, it is the commodity malware that harvests your employees' saved browser passwords and session cookies.

In short: The EU sanctioned nine individuals and four entities and the UK sanctioned 24, in the first joint EU-UK cyber sanctions package, targeting FSB and GRU units plus the Lumma Stealer operation.

What it means for your business: Sanctions do not patch anything, but the Lumma detail is the actionable part: infostealers remain the cheapest route into most companies, and they arrive through your staff's browsers, not your firewall.

My take: Naming FSB officers is symbolic. Naming the people behind an infostealer that has hit thousands of small businesses is not. The practical lesson is unchanged and unglamorous: kill saved passwords in browsers, enforce phishing-resistant MFA, and treat session cookie theft as the primary threat it now is.

Source: BleepingComputer: EU and UK hit Russia with first joint cyber sanctions package


Lidl tells shoppers in three countries their data was taken from an IT supplier

Lidl notified online shop customers in Germany, Belgium, and the Netherlands that their personal information was stolen in a security incident at one of its IT service providers. The stolen data covers names, telephone numbers, email addresses, dates of birth, customer numbers, and salutations. Lidl says attackers did not get into the online shop's own systems and rules out exposure of passwords, payment information, and addresses.

The company has not named the provider or said how many people are affected. It notified the Dutch data protection authority, brought in forensics, and told customers to expect phishing that uses the stolen details. That is the right warning: a list of verified names, birthdays, phone numbers, and email addresses tied to a known retailer is exactly the raw material for convincing "there is a problem with your order" scams.

In short: Lidl disclosed that customer contact details from its online shop were stolen in a breach at a third-party IT service provider.

What it means for your business: Your vendors' security is your breach notification. If you cannot name which suppliers hold your customer data and what happens when one of them is hit, you do not have a third-party risk program, you have a hope.

My take: No passwords, no payment data, so it will be written off as minor. It is not. Name plus birthday plus phone plus email plus a real retailer relationship is a phishing kit with a 100% accurate mailing list, and it will be used for months.

Source: Help Net Security: Hackers breach Lidl's IT service provider, steal customer data


CrashStealer: Mac malware that Apple itself notarized

Jamf Threat Labs published analysis of a new macOS infostealer called CrashStealer, which disguises itself as Apple's own crash reporting tool. It installs as CrashReporter.app with the real tool's icon and metadata and persists via a LaunchAgent named com.apple.crashreporter.helper. Researchers first saw it in May while it was still in development and observed it in actual attacks in early July.

The delivery is the alarming part. The first stage, an app called Werkbit, was signed with a valid Apple Developer ID and successfully notarized, so it passed Gatekeeper with no unidentified-developer warning at all. Apple has since revoked the signing credentials. The payload targets roughly 80 crypto wallet extensions, 14 password managers including 1Password, Bitwarden, and LastPass, plus Chrome, Edge, Brave, Firefox, Opera, and Vivaldi, and the macOS keychain, with control-flow flattening and layered anti-debugging to slow analysis.

In short: A new macOS infostealer, CrashStealer, impersonates Apple's crash reporter and reached victims through an Apple-notarized first-stage app that bypassed Gatekeeper cleanly.

What it means for your business: "It is a Mac, and macOS would have warned me if it were dangerous" is not a control. If your team keeps company passwords in a browser or password manager on an unmanaged Mac, that is now a single-hop compromise.

My take: Notarization is a spam filter, not a guarantee, and this is not the first reminder. The fix is boring and works: managed endpoints, EDR on Macs too, and no long-lived credentials sitting in a browser profile.

Source: BleepingComputer: New CrashStealer malware poses as Apple crash reporting tool


🧰 New software and AI tooling

A poisoned jscrambler npm release went straight for AI coding assistant credentials

Someone used a stolen npm publishing credential to push a malicious 8.14.0 release of jscrambler, a JavaScript protection package pulling roughly 15,800 downloads a week. Socket's research team caught it six minutes after publication on July 11. The release added an undocumented preinstall hook that ran hidden native binaries for Linux, macOS, and Windows during npm install, before a single line of your application code executed. The attacker then pushed four more poisoned versions, 8.16.0, 8.17.0, 8.18.0, and 8.20.0, over about three hours while remediation was underway. From 8.18.0 onward they dropped the install hook entirely and hid the dropper inside dist/index.js, which defeats scanners that only check install scripts and neatly sidesteps npm install --ignore-scripts.

Look at what it stole: AWS, GCP, and Azure credentials, crypto wallets, Discord, Slack, and Telegram tokens, browser data, OS keyrings, and, tellingly, credentials for Claude Desktop, Cursor, Windsurf, Zed, Factory, and VS Code. Jscrambler confirmed the compromise, revoked and rotated its credentials, and hardened publishing.

In short: Attackers published five malicious releases of the jscrambler npm package that stole cloud credentials, crypto wallets, and AI coding assistant tokens during install.

What it means for your business: If your developers or your vibe-coding stack pulled jscrambler between July 11 and 13, assume every credential on that machine is burned and rotate it. More broadly, npm install is code execution on a developer laptop that usually holds production keys.

My take: The AI coding assistant tokens in the target list are the part to sit with. Attackers now understand that a developer's Cursor or Claude Desktop credentials are a doorway into repos, cloud, and internal context, which makes the AI dev laptop the highest-value box in most companies. Pin your dependencies, use lockfiles, and stop letting laptops hold long-lived cloud keys.

Source: Socket: jscrambler npm Package Compromised in Supply Chain Attack


Missed yesterday's edition? Catch up with the July 13, 2026 AI and IT news recap.