2026-08-03
- ot ics
US Water Cyberattacks Extend Beyond Minnesota to at Least 6 Other States
Water systems in Michigan, South Dakota, Georgia, and at least three other U.S. states have been targeted by Iran-linked hackers, extending beyond the Minnesota water system incidents previously reported. The attacks underscore a growing threat to critical water infrastructure across multiple regions.
Why it matters: Water utility operators and state officials in targeted states need to assess their systems for compromise and coordinate incident response, as nation-state actors are actively targeting this critical infrastructure sector.
- threat intel
OpenAI reveals how criminals used ChatGPT to run scams
OpenAI banned a coordinated network of ChatGPT accounts operating from Preah Sihanouk province in Cambodia that used the platform to generate fake personas, craft messages for scam targets, produce promotional content for fraudulent schemes, and manage daily operations. A WhatsApp tip earlier this year led the company to investigate and disrupt the operation. The region has been previously associated with online scam compounds and human trafficking networks.
Why it matters: Security teams and trust and safety professionals should monitor for generative AI abuse in scam operations; this case shows how threat actors use ChatGPT to scale fraud and phishing at efficiency that outpaces manual detection.
- vulnerabilitiesCVE-2026-17583
Thermo Fisher Patches Flaw That Could Make DNA File Tampering Nearly Undetectable
Thermo Fisher Scientific released a patch on July 31 for a vulnerability in Applied Biosystems human identification software that could enable undetectable tampering with DNA analysis data files (.fsa and .hid formats) if laboratory controls are bypassed. The flaw, tracked as CVE-2026-17583, affects the integrity of forensic and genetic data before analysis tools process them.
Why it matters: DNA forensics labs, law enforcement agencies, and diagnostic facilities using this software face risks of altered genetic evidence or test results that could undermine investigations, trials, or patient care; apply this patch immediately to validate data integrity controls.
- industry
Rapid7 Expands UK and Ireland Channel Presence Through Strategic Partnership with Exclusive Networks
Rapid7 announced a strategic distribution partnership with Exclusive Networks to expand its presence in the United Kingdom and Ireland cybersecurity market. The partnership aims to empower channel partners with technical expertise and go-to-market support while helping organizations adopt integrated security operations platforms that combine exposure management, threat detection, and automation.
Why it matters: UK and Ireland resellers and system integrators can now access Rapid7's platform and enablement resources through Exclusive Networks to better serve customers modernizing their security operations; organizations evaluating security vendors benefit from expanded local channel support.
- threat intel
CrowdStrike: AI is now both the weapon and the target in cyberattacks
CrowdStrike's annual threat hunting report reveals that AI-driven malicious activity surged 89% over the past year, with attackers using frontier AI models to discover vulnerabilities, generate attack tools, and automate operations at scale. The company found that 88% of vulnerabilities were weaponized within 48 hours through AI, compressing the traditional patch window to 24-48 hours, while AI supply chain attacks like TeamPCP's compromise of over 300 software dependencies demonstrate a new attack surface that most organizations have failed to adequately secure.
Why it matters: Security teams must urgently reassess their patch timelines, vulnerability management processes, and AI tool governance, as the weaponization of AI has fundamentally shortened response windows and expanded attack surfaces across enterprise infrastructure.
- vulnerabilitiesCVE-2026-18577
N-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incomplete
N-able disclosed that attackers exploited an authentication bypass vulnerability (CVE-2026-18577) in N-central to obtain remote administrative access to the platform and systems managed through it. An initial patch released on August 2, 2026 proved incomplete, allowing continued exploitation. The vulnerability affects N-central builds prior to version 2026.3.1.7.
Why it matters: Managed service providers and their customers face potential compromise of monitored infrastructure; practitioners managing N-central deployments must verify they have deployed the complete fix and audit for unauthorized administrative access.
- ai security
Hugging Face Diffusers Flaws Could Let Model Repositories Execute Arbitrary Code
Three high-severity vulnerabilities in Hugging Face's Diffusers library allow malicious model repositories to execute arbitrary code by circumventing the trust_remote_code safety mechanism. These flaws expose the AI supply chain to unauthorized code execution when users load affected models.
Why it matters: ML practitioners and organizations using Hugging Face models face remote code execution risk; patching and code review of model sources are now critical to prevent supply chain compromise.
- threat intel
Mapping the malware blast radius a single alert won’t show you
Stairwell's Backstory AI agent analyzes a single malware alert and maps the full scope of a campaign by identifying related variants and undocumented samples. Research indicates that each published malware sample conceals an average of 2.4 undocumented variants, highlighting significant blind spots in standard alert triage.
Why it matters: Security teams relying on individual alerts miss the broader malware campaign scope; practitioners should evaluate whether their current detection covers variant families and related executables across endpoints.
- ai security
SkillSpector: NVIDIA’s open-source security scanner for AI agent skills
NVIDIA released SkillSpector, an open-source security scanner designed to evaluate AI agent skills before installation. The tool analyzes directories, zip files, markdown files, or Git URLs and provides risk scores, findings, and recommendations. Skills in this context are markdown-based instructions that may include Python scripts with shell access and environment permissions.
Why it matters: Security teams and AI practitioners deploying autonomous agents need to assess third-party skills for malicious or unsafe code execution before integration, as skills can execute arbitrary commands with full system permissions.
- threat intel
AI cut phishing from hours to seconds, which is where DMARC and BIMI come in
A video discussion explores the evolution of email security standards from early spam filtering through modern protocols like SPF, DMARC (Domain-based Message Authentication, Reporting and Conformance), and BIMI (Brand Indicators for Message Identification), examining why organizations continue to face email security challenges. The speakers highlight how artificial intelligence has accelerated phishing detection timelines and discuss the role of email authentication in maintaining business trust.
Why it matters: Organizations responsible for email security and brand protection need to understand current authentication standards (DMARC and BIMI) to combat phishing attacks that AI now detects in seconds rather than hours, affecting customer trust and incident response timelines.
- cloud saas
Product showcase: Guardio Mobile Security turns breach alerts into a recovery plan
Guardio Mobile Security is a multi-platform application that monitors for exposed personal information, detects phishing attempts, and alerts users to emerging threats across smartphones, tablets, and web browsers. The app guides new users through onboarding to explain its security features and initiate threat scanning.
Why it matters: Mobile users and device owners need visibility into whether their credentials or personal data have leaked and require accessible tooling to respond to breach notifications.
- threat intel
Risky Bulletin: Russia is behind the recent hotel WiFi hacks
Microsoft attributes a widespread campaign targeting hotel WiFi gateways globally to a Russian state-sponsored hacking group. The attacks manipulate DNS traffic to redirect users to phishing sites and malware downloads, often using ClickFix pages as a delivery mechanism. The campaign is larger and more complex than initially reported by ReliaQuest two weeks ago.
Why it matters: Hotel guests, IT staff managing hospitality networks, and organizations with employees traveling face credential theft and malware infection risks from compromised WiFi; network administrators should audit DNS configurations and implement traffic monitoring on hotel networks.
- threat intel
Buying TikTok followers can expose users to scams and account theft
Services that sell TikTok followers, likes, and views often employ deceptive practices that put customers at risk of account theft, financial fraud, and other scams. Malwarebytes researchers found that these engagement-buying platforms create security vulnerabilities affecting both purchasers and other platform users. The artificial engagement market presents itself as legitimate marketing but frequently operates through fraudulent mechanisms.
Why it matters: Any user or content creator considering engagement-buying services needs to understand the account takeover and financial loss risks involved, and security teams should be aware that compromised creator accounts can become vectors for broader platform attacks.
- research
Cybersecurity, Then & Now
Dark Reading reflects on nearly two decades of cybersecurity coverage since its launch in 2006, noting that fundamental challenges in the field persist despite technological evolution. The piece observes that while tactics and tools have shifted, core security concerns remain relatively constant.
Why it matters: Practitioners benefit from understanding that historical security patterns and lessons apply to current threats, helping inform strategy and avoid repeated mistakes.