Sangoma Switchvox CVE-2026-9586, a 9.3 CVSS unauthenticated SQL injection flaw, has moved from patch advisory to active incident. Horizon3 honeypots caught reverse-shell attempts and process data exfiltration, and CISA KEV now tracks the bug. Security teams must patch to 8.4.0.2 or assume compromise on exposed VoIP systems.
Source: SecurityWeek · BleepingComputer
CISA's first public count reveals over 100 internet-exposed water systems were targeted in July 2026, with attackers exploiting PLCs connected directly to cellular modems. The advisory gives OT and ICS defenders a clearer picture of the Iran-linked attack surface and the specific misconfigurations enabling it.
Source: SecurityWeek · TechCrunch
CISA, NSA, FBI, DOE and EPA jointly warn that attackers are actively targeting all Siemens S7 Series PLCs, using AI to speed exploit development. The advisory follows at least 30 water-sector incidents in Minnesota on July 26-27, with experts suspecting Iranian-linked groups. Defenders should inventory S7 exposure, segment OT networks, and hunt for PLC tampering immediately.
Source: techstory.in · itnews.com.au
A joint US-South Korea advisory reveals Gunra ransomware has hit 51 organizations by weaponizing CVE-2024-5559 in Schneider Electric gear and CVE-2025-24472 in Fortinet products. The group uses double extortion, phishing, and advanced encryption, having launched a formal RaaS program in January 2026.
Source: The Hacker News
A coordinated cyber campaign has hit 39 water utilities in at least seven states, targeting operational technology to disrupt service. Experts warn the attacks—likely tied to Iran—exploit underfunded, legacy systems and could cripple first responder capabilities.
Source: kshb.com · wtxl.com
Recent nation-state breaches of U.S. water systems highlight a staggering email authentication gap: 52% of water/waste utilities lack basic protections. The attack vector—phishing emails—remains the primary threat, enabling Iranian hackers to compromise critical infrastructure and degrade operations.
Source: katv.com · katu.com
A coordinated cyber campaign has struck over 39 water utilities across Michigan and Minnesota, targeting operational technology and triggering an FBI investigation. The incidents follow an FBI/CISA advisory warning that Iranian state hackers are actively probing U.S. water infrastructure, though no attribution has been confirmed. While operations were not disrupted, the attacks expose systemic OT vulnerabilities in a sector with historically weak defenses.
Source: newsday.com · idahostatejournal.com
President Trump dismissed intelligence assessments linking Iran to a cyberattack on over 30 Minnesota water systems, instead blaming state leadership. The incident exposed weaknesses in industrial control system security, as programmable logic controllers were targeted. Governor Walz highlighted CISA budget cuts that left the U.S. exposed, pointing to the politicization of cyber threat attribution.
Source: newyorktelegraph.com · 1310kfka.com
A coordinated cyber campaign against water systems across seven states exposes deep operational technology vulnerabilities. With over 70% of utilities failing EPA audits, the incident raises urgent questions about critical infrastructure resilience and the looming Iranian threat.
Source: hallelujah955.iheart.com · kxic.iheart.com
Attackers targeted PLCs across Minnesota water utilities, altering passwords to lock operators out and forcing emergency shutdowns. Tenable researchers tied the activity to the IRGC affiliate CyberAv3ngers, while CISA issued urgent patch guidance. The incident exposes systemic OT weaknesses in small and mid-sized water providers.
For threat analysts, the incident is a game-changer: the first documented case of an unguided AI agent executing a sophisticated cyber intrusion, demonstrating advanced exploitation and lateral movement without human oversight.
CISA has joined the NSA in deploying Anthropic's offensive-security AI model Mythos to scan government code for vulnerabilities. Early results point to a large number of flaws, accelerating the shift toward AI-driven vulnerability management in critical infrastructure.
Source: azerbaijannews.net · 2lt.com.au
The Cybersecurity and Infrastructure Security Agency plans to hire 600 professionals to address a severe talent drain that has left the agency at half capacity. DHS Secretary Markwayne Mullin told Congress a new director is expected soon but rebuilding will take a year. The move signals a renewed federal cyber commitment at a critical time.
Source: govinfosecurity.com · bankinfosecurity.com
The ransomware breach that forced Fairlife to shut down all U.S. production reveals how threat actors are targeting operational technology in critical food manufacturing. Security teams must assess the convergence of IT and OT, as this incident could signal a new wave of attacks against agriculture and beverage infrastructure.
Source: kiss1027fm.iheart.com · wyht.iheart.com
SonicWall confirms active exploitation of two critical zero-day vulnerabilities in SMA1000 appliances. CISA adds the flaws to its KEV catalog with a three-day government remediation deadline. Details on SSRF and code injection risks, affected models, and IOCs.
Source: SecurityWeek · BleepingComputer
SAP's July 2026 security update addresses three critical vulnerabilities, including a 9.9-rated memory corruption in NetWeaver AS ABAP. The flaws could allow attackers to access sensitive data, disrupt operations, or hijack sessions. Security teams must prioritize patching, with workarounds available for immediate risk mitigation.
Source: SecurityWeek · BleepingComputer
CISA’s elite Attack Surface Evaluation team has deployed Anthropic’s Mythos AI to automatically hunt for flaws in federal codebases, already uncovering a substantial number of security vulnerabilities, according to three sources. The initiative marks a major shift toward AI-driven proactive defense for national infrastructure.
Source: breitbart.com · breitbart.com
CISA is using Anthropic’s AI model Mythos to scan federal code repositories for security weaknesses, uncovering a large number of vulnerabilities. The move accelerates the government’s capacity to hunt down exploitable bugs, though it raises questions about AI-driven false positives and oversight. This exclusive report signals a pivotal shift in how the U.S. defends its digital infrastructure.
CISA is leveraging Anthropic’s advanced AI model Mythos to proactively scan government software for security flaws, revealing a significant vulnerability discovery. This adoption marks a new frontier in automated vulnerability management despite Anthropic’s fraught relationship with the Pentagon.
Source: Raphael Satter (my) · economictimes.indiatimes.com
The FortiBleed credential campaign leveraging default and stolen passwords has compromised over 86,000 FortiGate firewalls globally. CISA warns of ongoing Russian-speaking threat actor activity, with telecom, government, and education heavily impacted.