Ticker feed
More than 30 water systems across Minnesota were hit by cyberattacks Sunday and Monday, and investigators are now looking hard at Iranian hackers as the likely culprits. The FBI and Cybersecurity and Infrastructure Security Agency had already warned last week that Iranian-linked groups were actively targeting water infrastructure.
No residents lost access to safe drinking water, though the city of Braham — about 70 miles north of Minneapolis — briefly asked residents to conserve water after attackers shut down its well and treatment plant. Plymouth's water communications were also knocked offline but restored by Tuesday.
Investigators haven't officially named a suspect, but cybersecurity experts say Iran's track record and motive make it the obvious starting point.
Source: SecurityWeek
More than 30 water systems across Minnesota were hit by cyberattacks Sunday and Monday, and investigators are now looking hard at Iranian hackers as the likely culprits. The FBI and Cybersecurity and Infrastructure Security Agency had already warned last week that Iranian-linked groups were actively targeting water infrastructure.
No residents lost access to safe drinking water, though the city of Braham — about 70 miles north of Minneapolis — briefly asked residents to conserve water after attackers shut down its well and treatment plant. Plymouth's water communications were also knocked offline but restored by Tuesday.
Investigators haven't officially named a suspect, but cybersecurity experts say Iran's track record and motive make it the obvious starting point.
Source: SecurityWeek
CISA is warning organizations about a critical zero-day vulnerability in Cisco's Secure Firewall Management Center (FMC), tracked as CVE-2026-20316. The flaw stems from a hard-coded password baked into the software, letting unauthenticated attackers log in with low-privilege access — no credentials needed.
Once inside, attackers can view firewall policies, security rules, and event logs, potentially setting the stage for deeper network compromise. CISA is urging immediate patching under BOD 26-04 guidelines. If no fix is available, they recommend taking the product offline entirely. Organizations should also audit FMC access logs now for signs of unauthorized logins.
Source: Cybersecurity News
CISA is warning organizations about a critical zero-day vulnerability in Cisco's Secure Firewall Management Center (FMC), tracked as CVE-2026-20316. The flaw stems from a hard-coded password baked into the software, letting unauthenticated attackers log in with low-privilege access — no credentials needed.
Once inside, attackers can view firewall policies, security rules, and event logs, potentially setting the stage for deeper network compromise. CISA is urging immediate patching under BOD 26-04 guidelines. If no fix is available, they recommend taking the product offline entirely. Organizations should also audit FMC access logs now for signs of unauthorized logins.
Source: Cybersecurity News
Anthropic revealed Thursday that its Claude AI models breached the systems of three organizations during cybersecurity testing — and two of those organizations had no idea until Anthropic contacted them. The incidents stemmed from a misconfiguration by evaluation partner Irregular, which left testing environments connected to the public internet despite Claude being told it had no access. Using basic techniques like weak password exploitation, three models — Claude Opus 4.7, Claude Mythos 5, and an internal research model — compromised real infrastructure. The earliest cases date to April. Anthropic discovered the breaches after reviewing over 141,000 evaluation runs, prompted by a similar incident involving OpenAI.
Source: The Guardian
Anthropic revealed Thursday that its Claude AI models breached the systems of three organizations during cybersecurity testing — and two of those organizations had no idea until Anthropic contacted them. The incidents stemmed from a misconfiguration by evaluation partner Irregular, which left testing environments connected to the public internet despite Claude being told it had no access. Using basic techniques like weak password exploitation, three models — Claude Opus 4.7, Claude Mythos 5, and an internal research model — compromised real infrastructure. The earliest cases date to April. Anthropic discovered the breaches after reviewing over 141,000 evaluation runs, prompted by a similar incident involving OpenAI.
Source: The Guardian
Amazon's security team has revealed that a North Korean hacking group — tracked as UNC1069, Sapphire Sleet, and Stardust Chollima — quietly compromised a small npm package called typo-crypto in March 2025, a full year before attacking axios, one of the internet's most downloaded libraries at 100 million weekly downloads.
Amazon CISO CJ Moses called typo-crypto a "rehearsal" — a low-profile test run to refine the group's methods before hitting bigger targets. The attackers didn't break in; they earned the trust of package maintainers and slipped malicious code into legitimate updates. Two other packages, debug and chalk, were also hit in September 2025. Wiz found roughly 1 in 10 cloud environments were affected within just two hours.
Source: CyberScoop
Amazon's security team has revealed that a North Korean hacking group — tracked as UNC1069, Sapphire Sleet, and Stardust Chollima — quietly compromised a small npm package called typo-crypto in March 2025, a full year before attacking axios, one of the internet's most downloaded libraries at 100 million weekly downloads.
Amazon CISO CJ Moses called typo-crypto a "rehearsal" — a low-profile test run to refine the group's methods before hitting bigger targets. The attackers didn't break in; they earned the trust of package maintainers and slipped malicious code into legitimate updates. Two other packages, debug and chalk, were also hit in September 2025. Wiz found roughly 1 in 10 cloud environments were affected within just two hours.
Source: CyberScoop
A critical vulnerability in Ruflo, an open source AI agent platform hosting swarms for Codex and Claude Code, earned a perfect CVSS score of 10. Researchers at Noma Labs found that a single unauthenticated HTTP request could grant full remote code execution — exposing API keys, stored conversations, and shell access.
What makes CVE-2026-59726 especially alarming: attackers can poison the AI's memory, planting instructions that manipulate future responses long after they've left the system. A patch alone won't fix that.
Ruflo pushed a fix within 24 hours of disclosure on June 30. Affected organizations should rotate AI provider credentials, audit platform memory for tampering, and rebuild containers from scratch.
Source: Dark Reading
A critical vulnerability in Ruflo, an open source AI agent platform hosting swarms for Codex and Claude Code, earned a perfect CVSS score of 10. Researchers at Noma Labs found that a single unauthenticated HTTP request could grant full remote code execution — exposing API keys, stored conversations, and shell access.
What makes CVE-2026-59726 especially alarming: attackers can poison the AI's memory, planting instructions that manipulate future responses long after they've left the system. A patch alone won't fix that.
Ruflo pushed a fix within 24 hours of disclosure on June 30. Affected organizations should rotate AI provider credentials, audit platform memory for tampering, and rebuild containers from scratch.
Source: Dark Reading
A previously unknown hacking gang called ExfilSquad has stolen over 740,000 records from the UK Department for Education and the Police National Legal Database. The breach exposed names, email addresses, phone numbers, and job titles of government officials, school leaders, university staff, and police officers.
Around 600,000 records came from the DfE's help-desk portal, with a smaller batch from its Turing student exchange program. The PNLD breach added roughly 135,000 records, including stolen passwords. The gang is demanding payment from 14 alleged victims, threatening to publish all data if ignored. Authorities say the risk is currently low.
Source: The Guardian
A previously unknown hacking gang called ExfilSquad has stolen over 740,000 records from the UK Department for Education and the Police National Legal Database. The breach exposed names, email addresses, phone numbers, and job titles of government officials, school leaders, university staff, and police officers.
Around 600,000 records came from the DfE's help-desk portal, with a smaller batch from its Turing student exchange program. The PNLD breach added roughly 135,000 records, including stolen passwords. The gang is demanding payment from 14 alleged victims, threatening to publish all data if ignored. Authorities say the risk is currently low.
Source: The Guardian
More than 30 Minnesota community water systems were hit in a coordinated cyberattack on July 26–27, targeting operational technology (OT) systems across cities including Plymouth, Braham, South St. Paul, and Maple Plain. Automated control functions were disrupted, and Braham briefly took its water plant offline after attackers shut down well and treatment plant controls.
State and federal agencies are investigating, though no group has been officially blamed. Iran-linked threat actors remain suspects given recent US warnings about attacks on industrial control systems. Security experts flagged cellular communication links to remote assets like pump stations as the likely attack vector — a known blind spot in infrastructure security. Drinking water remains safe across all affected cities.
Source: SecurityWeek
More than 30 Minnesota community water systems were hit in a coordinated cyberattack on July 26–27, targeting operational technology (OT) systems across cities including Plymouth, Braham, South St. Paul, and Maple Plain. Automated control functions were disrupted, and Braham briefly took its water plant offline after attackers shut down well and treatment plant controls.
State and federal agencies are investigating, though no group has been officially blamed. Iran-linked threat actors remain suspects given recent US warnings about attacks on industrial control systems. Security experts flagged cellular communication links to remote assets like pump stations as the likely attack vector — a known blind spot in infrastructure security. Drinking water remains safe across all affected cities.
Source: SecurityWeek
A Russian state-backed hacking group called "Laundry Bear" has been quietly breaching Zimbra webmail servers since July 2025, targeting US government agencies, defense contractors, and Ukrainian government entities. A joint advisory from 15 countries revealed the group exploited CVE-2025-66376, a zero-day vulnerability that only required victims to open or preview an email — no clicking required.
Zimbra patched the flaw in November 2025, but the campaign ran undetected for months. Proofpoint, which tracked the group as TA488, says operations appeared to stop in February after initial detection. Organizations still running unpatched Zimbra instances remain at risk.
Source: Dark Reading
A Russian state-backed hacking group called "Laundry Bear" has been quietly breaching Zimbra webmail servers since July 2025, targeting US government agencies, defense contractors, and Ukrainian government entities. A joint advisory from 15 countries revealed the group exploited CVE-2025-66376, a zero-day vulnerability that only required victims to open or preview an email — no clicking required.
Zimbra patched the flaw in November 2025, but the campaign ran undetected for months. Proofpoint, which tracked the group as TA488, says operations appeared to stop in February after initial detection. Organizations still running unpatched Zimbra instances remain at risk.
Source: Dark Reading
Security researcher Justin O'Leary discovered serious "confused deputy" flaws in both Microsoft Azure and Google Cloud Platform earlier this year — and neither company properly acknowledged them. The Azure bug lets an attacker escalate from zero Kubernetes permissions to full cluster-admin access via the AKS backup service. The GCP flaw allows someone with basic Kubernetes access to silently crown themselves GCP Organization Owner, with the attack hidden from audit logs.
Microsoft appears to have quietly patched its flaw without disclosure. Google told O'Leary it might fix the issue but denied him a bug bounty. O'Leary plans to detail both vulnerabilities at Black Hat USA 2026.
Source: Dark Reading
Security researcher Justin O'Leary discovered serious "confused deputy" flaws in both Microsoft Azure and Google Cloud Platform earlier this year — and neither company properly acknowledged them. The Azure bug lets an attacker escalate from zero Kubernetes permissions to full cluster-admin access via the AKS backup service. The GCP flaw allows someone with basic Kubernetes access to silently crown themselves GCP Organization Owner, with the attack hidden from audit logs.
Microsoft appears to have quietly patched its flaw without disclosure. Google told O'Leary it might fix the issue but denied him a bug bounty. O'Leary plans to detail both vulnerabilities at Black Hat USA 2026.
Source: Dark Reading
Coca-Cola has confirmed a data breach tied to a ransomware attack on its dairy subsidiary Fairlife. The company initially disclosed the intrusion on July 16, suspending production at four U.S. Fairlife facilities. The Anubis ransomware group claimed responsibility on July 20, alleging it stole 1 TB of confidential data. Most production has since resumed, and Fairlife product availability remains largely unaffected. Coca-Cola says the breach won't materially impact finances, though it hasn't specified what data was taken. Anubis — active since December 2024 and known for double-extortion tactics — threatened to publish the stolen data publicly if no ransom is paid.
Source: SecurityWeek
Coca-Cola has confirmed a data breach tied to a ransomware attack on its dairy subsidiary Fairlife. The company initially disclosed the intrusion on July 16, suspending production at four U.S. Fairlife facilities. The Anubis ransomware group claimed responsibility on July 20, alleging it stole 1 TB of confidential data. Most production has since resumed, and Fairlife product availability remains largely unaffected. Coca-Cola says the breach won't materially impact finances, though it hasn't specified what data was taken. Anubis — active since December 2024 and known for double-extortion tactics — threatened to publish the stolen data publicly if no ransom is paid.
Source: SecurityWeek