AI and IT News Recap: July 3, 2026: A SharePoint Zero-Day Under Active Attack, Washington's AI Rulebook Nears, and Together AI's $800M Round

By Noah Smith, Owner & Consultant, KeyChange Technologies · July 3, 2026

Pen-and-ink cutaway of an office building where an opened parcel in the mailroom sends dark tendrils up through the floors to seize rows of file cabinets, symbolizing untrusted data taking over a server.

Here is the AI and IT news for July 3, 2026, a fast and no-spin read for business owners. Today leans security-heavy: a Microsoft SharePoint flaw is under active attack with a holiday-weekend patch deadline, while Washington closes in on its rulebook for the most powerful AI models. Most useful items sit right at the top.

📌 The AI and IT news at a glance

  • A SharePoint flaw is under active attack (CVE-2026-45659), and CISA set a July 4 patch deadline.
  • The White House races to finalize voluntary rules for releasing the most powerful AI models.
  • Together AI banks $800M at an $8.3B valuation as demand for open-model infrastructure surges.
  • Cisco confirms attackers are exploiting a Unified CM server flaw (CVE-2026-20230).
  • Medtronic starts notifying customers caught in a ShinyHunters-linked breach.
  • Claude in Chrome goes generally available, with background agents that commit their own work.
  • Google launches Gemini Spark for Mac and a 2.0 agent toolkit for developers.

🔝🛡️ Top story: A SharePoint flaw is under active attack, with a July 4 patch deadline

CISA added CVE-2026-45659, a remote code execution flaw in on-premises Microsoft SharePoint Server, to its Known Exploited Vulnerabilities catalog after confirming it is being exploited in the wild. The bug (CVSS 8.8) stems from insecure deserialization of untrusted data and affects SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Enterprise Server 2016. Microsoft shipped patches back in May and, notably, rated exploitation as "less likely" at the time, an assessment that has now aged poorly.

The practical risk is high because the bar to abuse it is low. An attacker only needs valid credentials with basic Site Member permissions to run arbitrary code on an unpatched server. Federal civilian agencies were ordered to patch by July 4, which is a good target date for everyone else too, especially heading into a long weekend when IT coverage is thin.

In short: CISA confirmed active exploitation of a SharePoint remote code execution flaw (CVE-2026-45659) and set a July 4 patch deadline for federal agencies.

What it means for your business: If you run SharePoint on-premises, this is a patch-now item, because a single low-privilege user account is enough for an attacker to take over the server.

My take: The "exploitation less likely" label is exactly why you patch on a schedule rather than on a vendor's mood. If you have on-prem SharePoint, confirm the May update is applied today, not after the holiday weekend when attackers know everyone has clocked out.

Source: The Hacker News


🤖 AI generally

🤖 The White House races to finalize its playbook for powerful AI models

The administration is moving fast to write the rulebook for how the most capable AI models get released. Technical teams from OpenAI, Google, and Anthropic have been meeting repeatedly with White House officials to finalize a voluntary framework, with a public rollout expected as soon as next week. The framework builds on the June executive order that lets developers hand the government early access to a "covered frontier model" for up to 30 days before a wider release, and lets the government help pick which trusted partners get in first.

The muscle behind it sits with two agencies. The Center for AI Standards and Innovation (CAISI) and the National Security Agency are set to build a classified benchmarking process that measures a model's advanced cyber capabilities, with the NSA director making the call on whether a model crosses the "covered frontier" threshold. It is a notable shift: national-security machinery moving directly into the AI release pipeline. This is the same policy track that recently saw export controls lifted on Anthropic's top models, as we covered in the July 2 recap.

In short: The White House is close to publishing voluntary standards, co-developed with the big AI labs, for vetting and releasing the most powerful models.

What it means for your business: Expect the timing and availability of the newest frontier models to increasingly hinge on government review, which can add lag between a launch announcement and when you can actually use it.

My take: Voluntary today has a way of becoming expected tomorrow. This will not touch everyday business AI use, but it does mean the cutting edge may arrive on a government-shaped schedule. Plan roadmaps around models that are already generally available, not ones pending review.

Source: The White House


🤖 Together AI raises $800M at an $8.3B valuation

Together AI announced an $800 million Series C at an $8.3 billion post-money valuation, more than doubling its worth from the

.3 billion it carried about 16 months ago. The round was led by Aramco Ventures, with Nvidia, Vista Equity Partners, General Catalyst, and others joining. The company runs a cloud built for training and deploying AI on open-source models such as DeepSeek, MiniMax, and Kimi, pitching itself as the cheaper alternative to closed systems from OpenAI and Anthropic. It says annual bookings topped
.15 billion as of its last quarter.

In short: Together AI raised an $800M Series C at an $8.3B valuation to scale its open-model cloud infrastructure.

What it means for your business: The open-model ecosystem is getting better funded, which over time means more competition and potentially lower prices for the AI capacity your vendors buy and pass along.

My take: The interesting signal is not the dollar figure, it is where the money is betting: that open models on cost-efficient infrastructure are a real alternative to the big closed labs. For buyers, more credible options is a good thing.

Source: TechCrunch


🛡️ IT and security

🛡️ Cisco confirms attackers are exploiting a Unified CM server flaw

Cisco confirmed in-the-wild exploitation of CVE-2026-20230, a server-side request forgery flaw in Unified Communications Manager and its Session Management Edition. Rated 8.6, the bug comes from improper validation of certain HTTP requests and can let an unauthenticated attacker write files to the underlying operating system, opening a path to privilege escalation and root access. Cisco disclosed the issue in early June and shipped fixes then, but active exploitation was detected later in the month, prompting the confirmation and fresh urgency around patching.

In short: Cisco confirmed that a Unified CM SSRF flaw (CVE-2026-20230, CVSS 8.6) is being actively exploited, after patching it in early June.

What it means for your business: If your phone or communications backbone runs on Cisco Unified CM, unpatched servers are now a live target, not a theoretical one.

My take: Communications infrastructure is easy to forget because it "just works," which is exactly why it gets skipped on patch day. If you run Unified CM, verify the June update is in place before the weekend.

Source: SecurityWeek


🛡️ Medtronic notifies customers of a ShinyHunters-linked breach

Medical device maker Medtronic has begun notifying customers that their personal data was exposed to an unauthorized third party in a breach tied to the ShinyHunters extortion group. Details on the full scope are still emerging, but the notification is the latest in a run of incidents linked to the same crew, which has made a habit of hitting large enterprises and pressuring them over stolen data.

In short: Medtronic is notifying affected customers of a data breach connected to the ShinyHunters group.

What it means for your business: Even well-resourced companies get caught in these campaigns, and the fallout often reaches customers and partners, so watch for breach notices from vendors you share data with.

My take: ShinyHunters keeps showing up because the playbook works: grab data, then squeeze. The takeaway for smaller businesses is to minimize what data you hand to vendors in the first place, because you inherit their breaches.

Source: BleepingComputer


🧰 New tools for builders and businesses

🧰 Claude in Chrome goes generally available, with background agents that commit their own work

Anthropic pushed Claude Code to version 2.1.198, and the headline is that Claude in Chrome is now generally available, giving direct browser access to Claude sessions and agents with no install required. The update also changes how background work behaves: subagents now run in the background by default so the main session keeps going, and background agents launched from the agents interface will commit, push, and open a draft pull request when they finish a coding task, rather than stopping to ask. There is also a new /dataviz skill for building charts and dashboards, complete with a runnable color-palette validator.

In short: Claude Code 2.1.198 makes Claude in Chrome generally available and lets background agents finish coding work by opening a draft pull request on their own.

What it means for your business: If your team uses Claude for development, the friction of running and reviewing AI-assisted work just dropped, though self-committing agents are worth setting guardrails around.

My take: Agents that open their own pull requests are a genuine productivity jump and a genuine review-discipline test. Great for velocity, as long as a human still signs off before anything merges.

Source: Claude Code changelog


🧰 Google launches Gemini Spark for Mac and a 2.0 agent toolkit

Google rolled out Gemini Spark for the Gemini app on macOS, in beta for US Google AI Ultra subscribers, bringing its assistant more natively onto the desktop. Alongside it, Google shipped Agent Development Kit 2.0, aimed at pushing production-grade agentic workflows toward tighter integration with real applications. Together, the two moves continue Google's push to make Gemini both an everyday desktop companion and a serious foundation for developers building automated workflows.

In short: Google launched Gemini Spark on macOS in beta and released Agent Development Kit 2.0 for building production agent workflows.

What it means for your business: More capable desktop AI and better agent-building tools mean the practical options for automating routine work keep expanding across vendors, not just one.

My take: The desktop assistant race is heating up, which is good for buyers. If you are already in Google's ecosystem, Spark is worth a look, but treat beta as beta before wiring it into anything critical.

Source: Tech Startups


That is the AI and IT news for July 3, 2026. For yesterday's edition, see our July 2 recap, and browse practical how-tos in our Knowledge Base. Have a safe and happy Fourth.