Weekly threat intelligence roundup covering major incidents and vulnerabilities from July 13, 2026. Key breaches include AssuranceAmerica (7M people affected via credential compromise), Latvia's state forestry company hit by ransomware exploiting a two-year-old unpatched system, and Injective Labs suffering a supply chain attack via malicious npm packages stealing crypto wallet keys. AI-related threats include JadePuffer, an autonomous LLM-driven ransomware operation exploiting a Langflow CVE, and prompt injection attacks achieving RCE through Claude Code and OpenAI Codex. Notable patches cover a Tenda router authentication backdoor, a critical Linux KVM hypervisor escape vulnerability, U-Boot secure boot bypass flaws, and an Opera GX browser modification injection flaw. Threat intelligence reports highlight Iran-linked Cavern Manticore targeting Israeli organizations, a 33% rise in ransomware incidents in June 2026, and China-linked UAT-7810 compromising networking devices.