AI and IT News Recap: July 3, 2026: A SharePoint Zero-Day Under Active Attack, Washington's AI Rulebook Nears, and Together AI's $800M Round
By Noah Smith, Owner & Consultant, KeyChange Technologies · July 3, 2026

Here is the AI and IT news for July 3, 2026, a fast and no-spin read for business owners. Today leans security-heavy: a Microsoft SharePoint flaw is under active attack with a holiday-weekend patch deadline, while Washington closes in on its rulebook for the most powerful AI models. Most useful items sit right at the top.
📌 The AI and IT news at a glance
- A SharePoint flaw is under active attack (CVE-2026-45659), and CISA set a July 4 patch deadline.
- The White House races to finalize voluntary rules for releasing the most powerful AI models.
- Together AI banks $800M at an $8.3B valuation as demand for open-model infrastructure surges.
- Cisco confirms attackers are exploiting a Unified CM server flaw (CVE-2026-20230).
- Medtronic starts notifying customers caught in a ShinyHunters-linked breach.
- Claude in Chrome goes generally available, with background agents that commit their own work.
- Google launches Gemini Spark for Mac and a 2.0 agent toolkit for developers.
🔝🛡️ Top story: A SharePoint flaw is under active attack, with a July 4 patch deadline
CISA added CVE-2026-45659, a remote code execution flaw in on-premises Microsoft SharePoint Server, to its Known Exploited Vulnerabilities catalog after confirming it is being exploited in the wild. The bug (CVSS 8.8) stems from insecure deserialization of untrusted data and affects SharePoint Server Subscription Edition, SharePoint Server 2019, and SharePoint Enterprise Server 2016. Microsoft shipped patches back in May and, notably, rated exploitation as "less likely" at the time, an assessment that has now aged poorly.
The practical risk is high because the bar to abuse it is low. An attacker only needs valid credentials with basic Site Member permissions to run arbitrary code on an unpatched server. Federal civilian agencies were ordered to patch by July 4, which is a good target date for everyone else too, especially heading into a long weekend when IT coverage is thin.
In short: CISA confirmed active exploitation of a SharePoint remote code execution flaw (CVE-2026-45659) and set a July 4 patch deadline for federal agencies.
What it means for your business: If you run SharePoint on-premises, this is a patch-now item, because a single low-privilege user account is enough for an attacker to take over the server.
My take: The "exploitation less likely" label is exactly why you patch on a schedule rather than on a vendor's mood. If you have on-prem SharePoint, confirm the May update is applied today, not after the holiday weekend when attackers know everyone has clocked out.
Source: The Hacker News
🤖 AI generally
🤖 The White House races to finalize its playbook for powerful AI models
The administration is moving fast to write the rulebook for how the most capable AI models get released. Technical teams from OpenAI, Google, and Anthropic have been meeting repeatedly with White House officials to finalize a voluntary framework, with a public rollout expected as soon as next week. The framework builds on the June executive order that lets developers hand the government early access to a "covered frontier model" for up to 30 days before a wider release, and lets the government help pick which trusted partners get in first.
The muscle behind it sits with two agencies. The Center for AI Standards and Innovation (CAISI) and the National Security Agency are set to build a classified benchmarking process that measures a model's advanced cyber capabilities, with the NSA director making the call on whether a model crosses the "covered frontier" threshold. It is a notable shift: national-security machinery moving directly into the AI release pipeline. This is the same policy track that recently saw export controls lifted on Anthropic's top models, as we covered in the July 2 recap.
In short: The White House is close to publishing voluntary standards, co-developed with the big AI labs, for vetting and releasing the most powerful models.
What it means for your business: Expect the timing and availability of the newest frontier models to increasingly hinge on government review, which can add lag between a launch announcement and when you can actually use it.
My take: Voluntary today has a way of becoming expected tomorrow. This will not touch everyday business AI use, but it does mean the cutting edge may arrive on a government-shaped schedule. Plan roadmaps around models that are already generally available, not ones pending review.
Source: The White House
🤖 Together AI raises $800M at an $8.3B valuation
Together AI announced an $800 million Series C at an $8.3 billion post-money valuation, more than doubling its worth from the