AI and IT News Recap: July 22, 2026: Google Ships a Cheaper Gemini Flash, Qilin Ransomware Rides a Palo Alto VPN Bug, and Estée Lauder's Oracle Breach Surfaces

By Noah Smith, Owner & Consultant, KeyChange Technologies · July 22, 2026

Pen-and-ink illustration of a bakery: a baker hands out trays of small fresh rolls to an eager line of customers out the door, while a tall tiered showpiece cake sits unfinished under a draped cloth on the back bench.

Welcome to your AI and IT news recap for July 22, 2026. It was a busy 24 hours: Google quietly shipped a cheaper, faster Gemini Flash while its flagship stayed in the oven, the AI labs broke their own lobbying records, and a run of nasty exploitation news hit Palo Alto VPNs, ServiceNow, and a cosmetics giant's HR system. Here is what matters and why.

📌 The AI and IT news at a glance

  • Google ships Gemini 3.6 Flash (and a Cyber variant), but the flagship Pro is a no-show again.
  • Anthropic and OpenAI break Q2 lobbying records, with Anthropic outspending Nvidia.
  • Qilin ransomware is riding a Palo Alto GlobalProtect VPN bug into corporate networks.
  • A critical ServiceNow AI Platform flaw is now under active attack.
  • Estée Lauder discloses an Oracle E-Business Suite breach that exposed SSNs and passport numbers.
  • CISA flags four more actively exploited bugs, including two in WordPress core and one in the Langflow AI tool.

🔝 Top story: Google ships a cheaper, leaner Gemini Flash while the flagship stalls

On July 21, Google released a trio of Gemini models: Gemini 3.6 Flash, a smaller Gemini 3.5 Flash-Lite, and Gemini 3.5 Flash Cyber, a security-tuned variant that Google is restricting to governments and trusted partners. The headline is price and efficiency. Gemini 3.6 Flash lands at

.50 per million input tokens and $7.50 per million output tokens, undercutting the $9 output price of the 3.5 Flash it replaces, keeps the 1 million token context window, and uses roughly 17% fewer output tokens on the Artificial Analysis Index. Flash-Lite drops to $0.30 in and .50 out. All of it carries a knowledge cutoff of March 2026.

What is conspicuously missing is Gemini 3.5 Pro, the flagship that has now slipped past its target more than once, even as Google teases a future Gemini 4. The pattern says a lot about where the frontier labs are competing right now: not on the single biggest, smartest model, but on cheap, fast, token-efficient models tuned for agentic workloads that run thousands of calls at a time. When your AI bill is a function of tokens, a 17% reduction plus a lower sticker price compounds fast.

In short: Google launched Gemini 3.6 Flash and a Flash-Lite tier that are cheaper and more token-efficient than their predecessors, while the flagship Gemini 3.5 Pro again failed to appear.

What it means for your business: If you or your vendors run anything on Gemini Flash, the new tier can cut your per-task AI costs without a model migration headache. The bigger signal for buyers is that the affordable "workhorse" tier is where the real progress and price war is happening, so build your automations around it rather than waiting on flagship models.

My take: The quiet Flash release is more useful to most businesses than another flagship would have been. Model launches are getting boring in the best way: cheaper, leaner, good enough. The one thing I would watch is that "Cyber" variant being gated to governments and trusted partners, because security tooling that only the well-connected can buy tends to widen the gap between big defenders and everyone else.

Source: MarkTechPost: Google Releases Gemini 3.6 Flash, 3.5 Flash-Lite, and 3.5 Flash Cyber


🤖 AI: The labs break their lobbying records, and Anthropic outspends Nvidia

Fresh Q2 2026 federal lobbying disclosures show the AI labs are spending like incumbents. Anthropic reported nearly million (

.97 million) for the quarter, OpenAI reported
.2 million, and together the two spent
.17 million, up about 23% from the first quarter. Anthropic outspent Nvidia and came within a whisker of Oracle's million total. It has already spent more than
.5 million in the first half of 2026, more than the
.1 million it spent in all of 2025.

The line items tell you what each company is worried about. Anthropic's disclosures center on export controls, cybersecurity, and AI safety standards, which tracks with the recent saga of its Fable and Mythos models being pulled offline and then restored. OpenAI's focus is copyright, cloud computing and infrastructure, cybersecurity, and privacy. This is the AI industry graduating from "move fast" to "shape the rules," and the rules being written now will define what these tools can and cannot do for years.

In short: Anthropic and OpenAI set new lobbying-spend records in Q2 2026, with Anthropic's nearly million topping Nvidia and approaching Oracle.

What it means for your business: The regulatory environment for the AI tools you depend on is being actively negotiated in Washington, and the vendors are the ones at the table. Expect the compliance, data-handling, and export rules around AI to keep shifting, so favor vendors who are transparent about how policy changes could affect your access and pricing.

My take: Record lobbying spend is not sinister on its own, but it is a tell. When a company spends more to influence policy than it did a year ago, it is bracing for rules that could reshape its business, and those same rules land on you as the customer. Worth keeping an eye on rather than losing sleep over.

Source: CNBC: OpenAI, Anthropic boost lobbying as legacy tech and defense spending slips


🛡️ IT and security

Qilin ransomware is exploiting a Palo Alto GlobalProtect VPN bug for initial access

Arctic Wolf reports that affiliates of the Qilin ransomware operation are exploiting CVE-2026-0257, an authentication bypass in Palo Alto Networks PAN-OS GlobalProtect portals and gateways, to get their first foothold in victim networks. The flaw (CVSS 7.8) lets an unauthenticated attacker establish a VPN session without valid credentials when authentication override cookies are enabled with certain certificate configurations. Palo Alto patched it back on May 13 and CISA added it to its Known Exploited Vulnerabilities catalog on May 29, but plenty of appliances are still exposed.

The playbook once they are in is grim and familiar: dump credentials from LSASS and Active Directory, move laterally with PsExec and RDP, drop remote-access tools like AnyDesk and Ngrok, exfiltrate data to MEGA using Rclone for double extortion, wipe the Windows event logs, and then encrypt. Arctic Wolf assesses with moderate confidence that these intrusions are ongoing, driven by heavy internet scanning and the ransomware-as-a-service model spreading the exploit across many affiliates.

In short: The Qilin ransomware gang is abusing a known Palo Alto GlobalProtect authentication bypass (CVE-2026-0257) to break into networks and deploy ransomware.

What it means for your business: If your company uses a Palo Alto GlobalProtect VPN, confirm with whoever runs it that the May patch is applied, because this is a fully patched flaw still being weaponized against stragglers. A remote-access VPN is the front door to your whole network, and this is exactly the kind of bug that turns into a weekend-ruining ransomware event.

My take: The uncomfortable lesson here is not that a new bug dropped, it is that a two-month-old patched one is still paying off for criminals. Patching your edge devices fast is unglamorous and it is the single highest-leverage thing most small businesses are not doing. Ask your IT provider point blank when your VPN was last updated.

Source: The Hacker News: Qilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial Access


A critical ServiceNow AI Platform flaw is now under active attack

CVE-2026-6875, a critical pre-authentication code-execution flaw in the ServiceNow AI Platform, is now being exploited in the wild, according to threat-intelligence firm Defused. The bug lets an unauthenticated attacker escape ServiceNow's script sandbox and run code remotely on a targeted instance, with no credentials, no phishing, and no prior foothold required. Researchers at Searchlight Cyber found it and reported it in early April; it was publicly disclosed on July 13, and ServiceNow shipped patches on July 14.

The wrinkle is that attackers have already found a second sandbox-escape gadget chain that gets around defenses tuned to the original proof of concept, which raises the pressure to patch rather than rely on stopgap filtering. ServiceNow says its hosted instances were updated automatically, but self-hosted customers have to apply the fix themselves, and those are the ones most at risk right now.

In short: A critical, pre-auth remote code execution bug in the ServiceNow AI Platform (CVE-2026-6875) is being actively exploited, with a second exploit variant already bypassing early defenses.

What it means for your business: ServiceNow runs a lot of enterprise IT and HR workflows, and a self-hosted instance sitting on this flaw is a direct path in for an attacker. If your organization runs ServiceNow, this is a "patch this week, not this month" item, and confirm whether your instance is hosted or self-managed.

My take: Pre-auth RCE with a working exploit is about as bad as vulnerability news gets, and the fact that attackers already have a second variant tells you they are paying close attention. The AI-platform angle is a reminder that bolting AI onto core business systems adds new attack surface, not just new features.

Source: BleepingComputer: Critical ServiceNow code execution flaw now exploited in attacks


Estée Lauder discloses an Oracle E-Business Suite breach that sat undetected for months

Cosmetics giant Estée Lauder has disclosed a data breach after attackers exploited a flaw in the Oracle E-Business Suite software it used for HR operations. The exposed data is sensitive: Social Security numbers, passport numbers, and financial and health information. The timeline is the alarming part. The intrusion happened on or around August 9, 2025, but the company did not detect it until June 19, 2026, a gap of roughly ten months before disclosure this week.

The incident is tied to the broader Oracle E-Business Suite exploitation campaign that surfaced last year and was later attributed to the Clop ransomware gang, which abused a flaw in the BI Publisher Integration component affecting EBS versions 12.2.3 through 12.2.14. Estée Lauder says it has brought in outside specialists, notified law enforcement, and is offering affected people 24 months of free identity monitoring through Kroll, with an enrollment deadline of October 31, 2026.

In short: Estée Lauder disclosed that attackers exploited an Oracle E-Business Suite flaw to steal SSNs, passport numbers, and health data, with the breach going undetected for about ten months.

What it means for your business: A ten-month detection gap is the real story for owners. The tools you buy will have bugs, but not knowing you were breached for the better part of a year is a monitoring failure any business can fall into. This is the case for having logging, alerting, and someone actually watching, especially around systems that hold employee personal data.

My take: Big-vendor software is not automatically safe software, and "we run Oracle" is not a security strategy. What separates a bad day from a catastrophe is how fast you notice. If you cannot say with confidence how you would detect an intrusion in your own systems, that is the gap to close before the next flashy zero-day.

Source: BleepingComputer: Estée Lauder discloses data breach via Oracle E-Business flaw


CISA adds four more actively exploited bugs, including two in WordPress core

On July 21, CISA added four vulnerabilities to its Known Exploited Vulnerabilities catalog, its running list of bugs confirmed to be under active attack. Two of them are in WordPress core: CVE-2026-63030, an interpretation-conflict flaw, and CVE-2026-60137, a SQL injection flaw. The other two are CVE-2021-27137, a years-old buffer overflow in DD-WRT router firmware, and CVE-2026-0770 in Langflow, a popular open-source tool for building AI workflows.

The mix is a useful snapshot of where attackers actually spend their time: content management systems that run a huge share of the web, aging network gear that rarely gets updated, and now AI developer tooling that is being adopted faster than it is being secured. A KEV listing is a strong signal, because federal agencies are given a hard deadline to patch these, and private organizations should treat the list as a prioritized to-do.

In short: CISA flagged four actively exploited vulnerabilities on July 21, including two in WordPress core, one in DD-WRT router firmware, and one in the Langflow AI tool.

What it means for your business: If your website runs on WordPress, this is a nudge to confirm core and plugins are on auto-update or are being patched promptly, since WordPress is the most-attacked platform on the web for a reason. And if your team has quietly started using AI-workflow tools like Langflow, they now carry the same patching responsibility as any other software.

My take: The CISA KEV list is the closest thing security has to a "fix these first" cheat sheet, and it is free. WordPress showing up twice is routine, but Langflow on the list is the interesting one: AI tools are now mainstream enough that criminals are exploiting them, and casual adoption without patching is going to bite someone.

Source: CISA: CISA Adds Four Known Exploited Vulnerabilities to Catalog


That is the AI and IT news for July 22, 2026. For yesterday's edition, see our July 21, 2026 recap. Stay patched, stay skeptical, and we will see you tomorrow.