Ticker feed
More than 30 Minnesota community water systems were hit in a coordinated cyberattack on July 26–27, targeting operational technology (OT) systems across cities including Plymouth, Braham, South St. Paul, and Maple Plain. Automated control functions were disrupted, and Braham briefly took its water plant offline after attackers shut down its well and operating controls.
State and federal agencies are investigating, though no group has been officially blamed. Iran-linked threat actors remain suspects given recent US warnings about attacks on industrial control systems.
Plymouth said its problems were limited to equipment connected via cellular communications — and that lines up with a known blind spot. Denis Calderone, CTO of Suzu Labs, notes that water towers, lift stations and pump stations often reach SCADA systems over cellular modems, and those secondary links are "frequently overlooked during risk analysis."
Drinking water remains safe across all affected cities. But BreachLock CEO Seemant Sehgal's warning applies well beyond Minnesota: whatever common weakness the attackers found here almost certainly exists in water infrastructure elsewhere.
Updated 11 Aug 2026: The FBI has since confirmed the campaign targeted water systems in at least seven states, including Michigan and Georgia.
Source: SecurityWeek
More than 30 Minnesota community water systems were hit in a coordinated cyberattack on July 26–27, targeting operational technology (OT) systems across cities including Plymouth, Braham, South St. Paul, and Maple Plain. Automated control functions were disrupted, and Braham briefly took its water plant offline after attackers shut down its well and operating controls.
State and federal agencies are investigating, though no group has been officially blamed. Iran-linked threat actors remain suspects given recent US warnings about attacks on industrial control systems.
Plymouth said its problems were limited to equipment connected via cellular communications — and that lines up with a known blind spot. Denis Calderone, CTO of Suzu Labs, notes that water towers, lift stations and pump stations often reach SCADA systems over cellular modems, and those secondary links are "frequently overlooked during risk analysis."
Drinking water remains safe across all affected cities. But BreachLock CEO Seemant Sehgal's warning applies well beyond Minnesota: whatever common weakness the attackers found here almost certainly exists in water infrastructure elsewhere.
Updated 11 Aug 2026: The FBI has since confirmed the campaign targeted water systems in at least seven states, including Michigan and Georgia.
Source: SecurityWeek
A Russian state-backed hacking group called "Laundry Bear" has been quietly breaching Zimbra webmail servers since July 2025, targeting US government agencies, defense contractors, and Ukrainian government entities. A joint advisory from 15 countries revealed the group exploited CVE-2025-66376, a zero-day that only required victims to open or preview an email — no clicking required.
The haul was substantial: victims' last 90 days of email, addresses and passwords, the organization's email directory including its Global Address List, two-factor authentication tokens, and newly created application passcodes.
Zimbra patched the flaw in version 10.1.13 in November 2025, but the campaign ran undetected for months, and CISA only added it to its Known Exploited Vulnerabilities catalog in March 2026. Proofpoint, which tracks the group as TA488, has seen no activity since February — after researchers at Seqrite went public and the group tore down its own infrastructure.
Organizations still running unpatched Zimbra remain at risk. Update, review authentication logs, and revoke any unauthorized application passcodes — especially ones named "ZimbraWeb."
Source: Dark Reading
A Russian state-backed hacking group called "Laundry Bear" has been quietly breaching Zimbra webmail servers since July 2025, targeting US government agencies, defense contractors, and Ukrainian government entities. A joint advisory from 15 countries revealed the group exploited CVE-2025-66376, a zero-day that only required victims to open or preview an email — no clicking required.
The haul was substantial: victims' last 90 days of email, addresses and passwords, the organization's email directory including its Global Address List, two-factor authentication tokens, and newly created application passcodes.
Zimbra patched the flaw in version 10.1.13 in November 2025, but the campaign ran undetected for months, and CISA only added it to its Known Exploited Vulnerabilities catalog in March 2026. Proofpoint, which tracks the group as TA488, has seen no activity since February — after researchers at Seqrite went public and the group tore down its own infrastructure.
Organizations still running unpatched Zimbra remain at risk. Update, review authentication logs, and revoke any unauthorized application passcodes — especially ones named "ZimbraWeb."
Source: Dark Reading
Security researcher Justin O'Leary found serious "confused deputy" flaws in both Microsoft Azure and Google Cloud Platform — disclosing the Azure bug on 12 May and the GCP one on 18 June — and neither company properly acknowledged them.
The Azure bug lets an attacker escalate from Backup Contributor, with zero Kubernetes permissions, to full cluster-admin access via the AKS backup service. O'Leary rates it CVSS 9.9. The GCP flaw sits in Config Connector, the open source Kubernetes add-on for managing GCP resources, and lets someone with basic namespace access silently crown themselves GCP Organization Owner — with the attack hidden from audit logs, since it looks like service account activity.
Microsoft appears to have quietly patched its flaw without disclosure or a CVE. Google's bug bounty panel told O'Leary the report "didn't qualify," arguing customers are responsible for their own permission settings, though it said it might fix the issue anyway. Anyone running Config Connector should review who holds namespace access in the meantime.
O'Leary details both at Black Hat USA 2026, in a talk called "Trust No Deputy: Breaking Azure and GCP Through Managed Identity Chains."
Source: Dark Reading
Security researcher Justin O'Leary found serious "confused deputy" flaws in both Microsoft Azure and Google Cloud Platform — disclosing the Azure bug on 12 May and the GCP one on 18 June — and neither company properly acknowledged them.
The Azure bug lets an attacker escalate from Backup Contributor, with zero Kubernetes permissions, to full cluster-admin access via the AKS backup service. O'Leary rates it CVSS 9.9. The GCP flaw sits in Config Connector, the open source Kubernetes add-on for managing GCP resources, and lets someone with basic namespace access silently crown themselves GCP Organization Owner — with the attack hidden from audit logs, since it looks like service account activity.
Microsoft appears to have quietly patched its flaw without disclosure or a CVE. Google's bug bounty panel told O'Leary the report "didn't qualify," arguing customers are responsible for their own permission settings, though it said it might fix the issue anyway. Anyone running Config Connector should review who holds namespace access in the meantime.
O'Leary details both at Black Hat USA 2026, in a talk called "Trust No Deputy: Breaking Azure and GCP Through Managed Identity Chains."
Source: Dark Reading
Coca-Cola has confirmed a data breach tied to a ransomware attack on its dairy subsidiary Fairlife. The company initially disclosed the intrusion on July 16, suspending production at four U.S. Fairlife facilities. Most production has since resumed, and Fairlife product availability remains largely unaffected thanks to existing inventory.
The Anubis ransomware group claimed responsibility on July 20, alleging it stole 1 TB of confidential data — a figure Coca-Cola has not confirmed. The company acknowledges data was taken but hasn't said what, and says the incident won't materially affect its financial condition or results of operations.
Anubis has been active since December 2024, runs a double-extortion model, and unusually also carries a wiper mode for permanently destroying files. It has threatened to publish the stolen Fairlife data if no ransom is paid.
Source: SecurityWeek
Coca-Cola has confirmed a data breach tied to a ransomware attack on its dairy subsidiary Fairlife. The company initially disclosed the intrusion on July 16, suspending production at four U.S. Fairlife facilities. Most production has since resumed, and Fairlife product availability remains largely unaffected thanks to existing inventory.
The Anubis ransomware group claimed responsibility on July 20, alleging it stole 1 TB of confidential data — a figure Coca-Cola has not confirmed. The company acknowledges data was taken but hasn't said what, and says the incident won't materially affect its financial condition or results of operations.
Anubis has been active since December 2024, runs a double-extortion model, and unusually also carries a wiper mode for permanently destroying files. It has threatened to publish the stolen Fairlife data if no ransom is paid.
Source: SecurityWeek
CISA added six actively exploited Microsoft zero-days to its Known Exploited Vulnerabilities Catalog on 10 February 2026: CVE-2026-21510 (Windows Shell), CVE-2026-21513 (MSHTML), CVE-2026-21514 (Office Word), CVE-2026-21519 (Desktop Window Manager), CVE-2026-21525 (Remote Access Connection Manager) and CVE-2026-21533 (Remote Desktop Services).
Between them they cover privilege escalation, security feature bypasses and denial of service. Microsoft shipped fixes in its February 2026 Patch Tuesday, so anyone current on updates is covered — the risk sits with organisations that deferred that cycle.
Federal remediation deadlines have since changed. CISA replaced Binding Operational Directive 22-01 with BOD 26-04 on 10 June 2026, swapping flat timelines for a tiered model running from three days to 60 days depending on risk.
Nation-state groups, including China's Salt Typhoon, are among those exploiting similar flaws. All organisations should confirm the February patches are applied and audit exposure across Office, RDS and remote access tools.
Source: Cybersecurity News
CISA added six actively exploited Microsoft zero-days to its Known Exploited Vulnerabilities Catalog on 10 February 2026: CVE-2026-21510 (Windows Shell), CVE-2026-21513 (MSHTML), CVE-2026-21514 (Office Word), CVE-2026-21519 (Desktop Window Manager), CVE-2026-21525 (Remote Access Connection Manager) and CVE-2026-21533 (Remote Desktop Services).
Between them they cover privilege escalation, security feature bypasses and denial of service. Microsoft shipped fixes in its February 2026 Patch Tuesday, so anyone current on updates is covered — the risk sits with organisations that deferred that cycle.
Federal remediation deadlines have since changed. CISA replaced Binding Operational Directive 22-01 with BOD 26-04 on 10 June 2026, swapping flat timelines for a tiered model running from three days to 60 days depending on risk.
Nation-state groups, including China's Salt Typhoon, are among those exploiting similar flaws. All organisations should confirm the February patches are applied and audit exposure across Office, RDS and remote access tools.
Source: Cybersecurity News
A supply chain attack hit Jscrambler's popular NPM package on July 11, after a threat actor used a compromised publishing credential to push malicious versions containing hidden malware. Jscrambler versions 8.16, 8.17, 8.18 and 8.20 were affected — 8.19 was not — along with jscrambler-webpack-plugin 8.6.2, gulp-jscrambler 8.6.2, grunt-jscrambler 8.5.2 and jscrambler-metro-plugin 9.0.2. The tainted versions were downloaded 1,479 times before being deprecated.
The malware, written in Rust, steals credentials, crypto wallet seed phrases, browser data and cloud API keys — and reaches further than most, pulling in AI coding assistant and MCP configurations, OS keyrings, messaging apps and Steam sessions. It exfiltrates everything over TLS and tries stolen credentials against cloud APIs.
Jscrambler has deprecated the malicious versions and released clean version 8.22. If you installed any affected version, remove it immediately, scan for malware, and rotate all secrets and API keys.
Source: SecurityWeek
A supply chain attack hit Jscrambler's popular NPM package on July 11, after a threat actor used a compromised publishing credential to push malicious versions containing hidden malware. Jscrambler versions 8.16, 8.17, 8.18 and 8.20 were affected — 8.19 was not — along with jscrambler-webpack-plugin 8.6.2, gulp-jscrambler 8.6.2, grunt-jscrambler 8.5.2 and jscrambler-metro-plugin 9.0.2. The tainted versions were downloaded 1,479 times before being deprecated.
The malware, written in Rust, steals credentials, crypto wallet seed phrases, browser data and cloud API keys — and reaches further than most, pulling in AI coding assistant and MCP configurations, OS keyrings, messaging apps and Steam sessions. It exfiltrates everything over TLS and tries stolen credentials against cloud APIs.
Jscrambler has deprecated the malicious versions and released clean version 8.22. If you installed any affected version, remove it immediately, scan for malware, and rotate all secrets and API keys.
Source: SecurityWeek
A misconfigured Python HTTP server in Budapest with directory listing enabled handed researchers a full look inside three active phishing campaigns. The exposed server at 185.163.204.7 contained credential logs, phishing configs, RMM installers, combolists, and even the operator's own Telegram session files.
Three distinct threat actors were identified: codemado, an Egyptian operator whose Microsoft 365 AiTM campaign ran from January to May 2026; mail-argenta, a Nigerian operator undone by his own reused password, hardcoded in a public GitHub repo and later found in infostealer logs; and saroula01, whose Device Code Flow campaign quietly accumulated 218 victims across 12 countries over a year — 94% of them corporate accounts.
All three built their MFA-bypassing infrastructure from customised Evilginx forks pulled straight off public GitHub repositories, with minimal modification. The barrier to running these attacks is effectively zero.
Source: Lexfo Security Blog
A misconfigured Python HTTP server in Budapest with directory listing enabled handed researchers a full look inside three active phishing campaigns. The exposed server at 185.163.204.7 contained credential logs, phishing configs, RMM installers, combolists, and even the operator's own Telegram session files.
Three distinct threat actors were identified: codemado, an Egyptian operator whose Microsoft 365 AiTM campaign ran from January to May 2026; mail-argenta, a Nigerian operator undone by his own reused password, hardcoded in a public GitHub repo and later found in infostealer logs; and saroula01, whose Device Code Flow campaign quietly accumulated 218 victims across 12 countries over a year — 94% of them corporate accounts.
All three built their MFA-bypassing infrastructure from customised Evilginx forks pulled straight off public GitHub repositories, with minimal modification. The barrier to running these attacks is effectively zero.
Source: Lexfo Security Blog
Security firm Socket has uncovered "Operation Muck and Load" — a campaign using 222 GitHub repositories across 190 accounts to distribute Windows malware. Active since January 24, 2026, the threat actor published over 1,200 package versions, 700 of which are malicious.
The attack disguises a Go module as a legitimate DNS scanning tool, impersonating the real open source project dnsub. Hidden PowerShell code then pulls encrypted payloads from dead-drop platforms including Pastebin, YouTube, Instagram, Telegram, and Google Docs — making it harder to shut down.
Final payloads include AsyncRAT, Quasar RAT, Vidar infostealer, and XMRig cryptominers. Anyone who has pulled a DNS or subdomain scanning module from GitHub should check what they actually installed — go.mod and go.sum are the place to start.
Source: SecurityWeek
Security firm Socket has uncovered "Operation Muck and Load" — a campaign using 222 GitHub repositories across 190 accounts to distribute Windows malware. Active since January 24, 2026, the threat actor published over 1,200 package versions, 700 of which are malicious.
The attack disguises a Go module as a legitimate DNS scanning tool, impersonating the real open source project dnsub. Hidden PowerShell code then pulls encrypted payloads from dead-drop platforms including Pastebin, YouTube, Instagram, Telegram, and Google Docs — making it harder to shut down.
Final payloads include AsyncRAT, Quasar RAT, Vidar infostealer, and XMRig cryptominers. Anyone who has pulled a DNS or subdomain scanning module from GitHub should check what they actually installed — go.mod and go.sum are the place to start.
Source: SecurityWeek
Accenture has confirmed a security incident after a hacker posted on PwnForums claiming to have stolen 35 gigabytes of internal data — including Azure access keys, tokens, SSH and RSA keys, configuration files, and source code. The threat actor posted a screenshot of a private Azure DevOps repository on an accenture.com domain as proof, and listed the data for sale.
Accenture called it "this isolated matter," said it had "remediated its source," and reported no impact to operations or service delivery. It did not confirm what was taken, whether personal or client data was involved, or how the attacker got in.
Ross Filipek, CISO at Corsica Technologies, warns the stolen data could serve as "a playbook for future attacks" — exposing code vulnerabilities, credentials and infrastructure detail. Consulting firms make attractive targets precisely because of how deep their access runs into client systems.
Source: SecurityWeek
Accenture has confirmed a security incident after a hacker posted on PwnForums claiming to have stolen 35 gigabytes of internal data — including Azure access keys, tokens, SSH and RSA keys, configuration files, and source code. The threat actor posted a screenshot of a private Azure DevOps repository on an accenture.com domain as proof, and listed the data for sale.
Accenture called it "this isolated matter," said it had "remediated its source," and reported no impact to operations or service delivery. It did not confirm what was taken, whether personal or client data was involved, or how the attacker got in.
Ross Filipek, CISO at Corsica Technologies, warns the stolen data could serve as "a playbook for future attacks" — exposing code vulnerabilities, credentials and infrastructure detail. Consulting firms make attractive targets precisely because of how deep their access runs into client systems.
Source: SecurityWeek
A massive global cybercrime sweep has wrapped up with 5,811 arrests and $293 million in intercepted illicit assets. Operation First Light 2026 ran from January 15 to April 30, 2026, pulling in law enforcement from 97 countries under Interpol's coordination — with funding from China's Ministry of Public Security.
The operation targeted social engineering scams like romance fraud and business email compromise schemes. Authorities blocked or froze 31,014 bank accounts, seized cryptocurrency wallets, identified 15,606 suspects, and uncovered more than 142,000 victims worldwide.
One standout bust in Eswatini took down a network posing as Brazilian Federal Police over video calls, talking victims into transferring money for "safekeeping." Officers seized 240 electronic devices and a full replica Brazilian police station — fake uniforms, signage and all.
Source: Infosecurity Magazine
A massive global cybercrime sweep has wrapped up with 5,811 arrests and $293 million in intercepted illicit assets. Operation First Light 2026 ran from January 15 to April 30, 2026, pulling in law enforcement from 97 countries under Interpol's coordination — with funding from China's Ministry of Public Security.
The operation targeted social engineering scams like romance fraud and business email compromise schemes. Authorities blocked or froze 31,014 bank accounts, seized cryptocurrency wallets, identified 15,606 suspects, and uncovered more than 142,000 victims worldwide.
One standout bust in Eswatini took down a network posing as Brazilian Federal Police over video calls, talking victims into transferring money for "safekeeping." Officers seized 240 electronic devices and a full replica Brazilian police station — fake uniforms, signage and all.
Source: Infosecurity Magazine