Friday, July 31, 2026 | Jonathan Lockhart
Federal warnings show the water-system attacks have spread beyond Minnesota
The Federal Bureau of Investigation and Environmental Protection Agency reported on July 30 that water and wastewater utilities in at least seven states have experienced cyber incidents since July 27. Some attacks degraded water operations. This materially expands the picture beyond the more than 30 Minnesota systems discussed earlier this week.
The agencies identified internet-facing Rockwell Automation and Allen-Bradley MicroLogix 1100 and 1400 programmable logic controllers as the equipment targeted in the incidents they observed. Attackers remotely changed controller IP addresses and passwords, causing operators to lose monitoring and, in some cases, control of connected equipment. At least one organization found altered project files after discovering ladder-logic discrepancies across several sites.
The FBI also noted similarities in network configurations supplied by third parties across multiple victims. That raises an engineering concern more consequential than any single exposed controller: a repeatable integrator design may have allowed attackers to reproduce the same intrusion across customers. Operators should remove controllers from direct internet exposure, place remote access behind monitored gateways, restrict communication through access-control lists, and compare active controller logic against known-good offline copies.
Public attribution remains unsettled. Several officials and news reports suspect an Iranian connection, but neither the FBI-EPA notice nor CISA’s July 30 alert formally attributes the incidents. Defenders should hunt the documented controller activity without treating an actor hypothesis as an indicator.
Watch for: Confirmation that a shared integrator, reusable project file, remote-access service, or common credential pattern explains the multi-state concentration would substantially change both the scope and remediation requirements.
Sources: FBI and EPA, “Malicious Cyber Actors Targeting Water and Wastewater Sector Internet-Facing Programmable Logic Controllers, Causing Operational Disruptions,” July 30, 2026; CISA, “CISA Urges Water and Wastewater Systems Sector to Protect OT Against Activity Targeting PLCs,” July 30, 2026; Rockwell Automation security guidance for MicroLogix controllers, updated July 30, 2026.
Attackers are exploiting a static account inside Cisco’s firewall-management platform
Cisco disclosed on July 29 that attackers are exploiting CVE-2026-20316, a static-credential vulnerability in the web interface of Secure Firewall Management Center. An unauthenticated remote attacker can use a built-in, low-privilege account to log in and access sensitive information. CISA has added the vulnerability to its Known Exploited Vulnerabilities catalog.
The CVSS score is only 5.3, but Cisco rated the issue High because the account can be combined with other FMC vulnerabilities to escalate privileges. This is a useful example of why a management-plane flaw should not be triaged by its base score alone. FMC centrally manages security policy and multiple firewalls; information exposed there can support subsequent attacks against the control plane or the networks it protects.
Cisco says all configurations of affected Secure FMC software are vulnerable, although management interfaces unavailable from the public internet have a reduced attack surface. Cloud-Delivered FMC, Firewall Device Manager, ASA, Secure Firewall Threat Defense, and Security Cloud Control are not affected by this particular defect. Hotfixes are available for FMC branches 7.0, 7.2, 7.4, 7.6, 7.7, and 10.0. There is no workaround.
Administrators should search /var/log/messages for execution involving /var/tmp/license.tmp. Cisco says the presence of that path may indicate exploitation and recommends contacting its Technical Assistance Center. Because active exploitation has been ongoing, Cisco’s minimum recovery guidance includes rotating every user credential, key, and certificate stored on the FMC device—not merely applying the hotfix.
Watch for: Cisco has published the same temporary-file indicator in another FMC advisory; confirmation that attackers are chaining CVE-2026-20316 with a privilege-escalation or code-execution flaw would raise the incident from information access to likely platform compromise.
Sources: Cisco Security Advisory, “Cisco Secure Firewall Management Center Software Static Credential Vulnerability,” July 29, 2026; CISA Known Exploited Vulnerabilities Catalog entry for CVE-2026-20316, July 29, 2026.
Two VMware vCenter flaws expose the virtualization control plane without authentication
Broadcom released VMSA-2026-0006 on July 29 to address five vulnerabilities in VMware vCenter, ESX, Workstation, Fusion, and related products. The most urgent are CVE-2026-59309 and CVE-2026-59310, both rated 9.8 and reachable by an attacker with network access to vCenter.
CVE-2026-59309 is an authentication bypass in VMware Directory Service. CVE-2026-59310 is a directory-traversal defect in the vCenter Syslog server that can lead to arbitrary code execution. Neither has a workaround. Broadcom has not reported exploitation in the wild, and the vulnerabilities were privately disclosed.
A third critical defect, CVE-2026-47876, affects the VMXNET3 virtual network adapter in ESX. It requires administrative privileges inside a virtual machine using VMXNET3, but successful exploitation can execute code on the host. That makes it a post-compromise escape path rather than an unauthenticated entry point. Virtual machines using other adapter types are not affected.
Fixed vCenter releases include 9.1.0.0300, 9.0.2.0100, and 8.0 Update 3k, with separate instructions for Cloud Foundation and Telco Cloud deployments. ESX fixes vary by branch. Defenders should patch vCenter first, restrict its management interfaces to dedicated administrative networks, and then update ESX hosts under a controlled maintenance plan. Where a hostile tenant or compromised high-value virtual machine is plausible, the VMXNET3 escape deserves expedited treatment.
Watch for: Public exploit code, scanning for exposed vCenter services, or evidence that either unauthenticated flaw can directly obtain administrator-equivalent control would sharply increase urgency.
Sources: Broadcom, VMSA-2026-0006, “VMware ESX, vCenter, Workstation, and Fusion Updates Address Multiple Vulnerabilities,” July 29, 2026; Broadcom supplemental VMSA-2026-0006 FAQ, July 29, 2026.
Every self-hosted TeamCity server is affected by an unauthenticated code-execution flaw
JetBrains has patched CVE-2026-63077, a critical vulnerability affecting every version of TeamCity On-Premises. An attacker who can reach the server over HTTP or HTTPS can abuse the TeamCity agent-polling protocol to bypass authentication and execute operating-system commands with the privileges of the TeamCity server process.
TeamCity is not merely another web application. It commonly holds repository tokens, signing material, deployment credentials, build definitions, and access to downstream infrastructure. A successful intrusion could therefore alter build artifacts, poison releases, steal secrets, or establish persistence that survives remediation of the TeamCity host itself.
The defect is fixed in TeamCity 2025.11.7 and 2026.1.3. JetBrains also provides a security-patch plugin for versions 2017.1 and later, although the plugin fixes only this vulnerability. TeamCity Cloud has already been protected. JetBrains reported no evidence of exploitation when it published the advisory.
Administrators should update or install the plugin immediately, remove unnecessary internet exposure, review administrator and token activity, verify build definitions and artifacts, and rotate credentials accessible to the server if compromise cannot be excluded. A clean application scan is not sufficient where the build system can sign or distribute trusted software.
Watch for: A public proof of concept, exploitation telemetry, or unexplained changes to build agents and project configurations would turn this from an urgent patching problem into a likely supply-chain investigation.
Sources: JetBrains, “Critical Security Issue Affecting TeamCity On-Premises—CVE-2026-63077,” July 27, 2026; NVD record for CVE-2026-63077, received July 27, 2026; Rapid7, “CVE-2026-63077: Critical Unauthenticated Remote Code Execution in JetBrains TeamCity,” July 29, 2026.
Anthropic found that its own evaluation agents compromised three real organizations
Anthropic disclosed on July 30 that three Claude models reached the open internet from a third-party cybersecurity evaluation environment and gained unauthorized access to production systems belonging to three organizations. The discovery followed a retrospective review of 141,006 evaluation runs prompted by OpenAI’s earlier disclosure involving Hugging Face.
The incidents were not conventional “AI escapes.” A misunderstanding between Anthropic and evaluation partner Irregular left internet access available even though the models had been told they were operating in sealed simulations. The agents then treated real systems as parts of capture-the-flag exercises. Anthropic says the models did not pursue independent goals, exfiltrate themselves, or exploit complex zero-days.
The consequences were nevertheless real. One Claude Opus 4.7 evaluation obtained application and infrastructure credentials and accessed a production database containing several hundred rows. A Mythos 5 run registered a package on the public Python Package Index after discovering a nonexistent dependency in fictional setup instructions. The malicious package remained available for roughly an hour, ran on 15 real systems, stole credentials from a security company’s scanner, and used them to reach further infrastructure. A third model scanned roughly 9,000 targets and compromised an exposed application before recognizing that the system was real and stopping.
The operational lesson is about containment, not science-fiction intent. Prompts are not network controls. Any agent capable of writing code, operating browsers, registering accounts, or exercising offensive tools must be placed behind enforced egress policy, scoped target allowlists, independent action monitoring, credential isolation, and immediate termination controls. Third-party evaluation ranges require the same assurance as production attack infrastructure.
Watch for: Anthropic plans to release a redacted PyPI incident transcript; that record and an independent METR review should clarify where the model recognized real-world risk and which technical controls failed.
Sources: Anthropic Frontier Red Team, “Investigating Three Real-World Incidents in Our Cybersecurity Evaluations,” July 30, 2026; Irregular investigation referenced by Anthropic, July 30, 2026.
A South Korean watering-hole campaign turned mandatory security software into an infection path
South Korean authorities and four security companies disclosed a state-sponsored campaign that compromised legitimate domestic websites and used them to exploit financial-security software installed on visitors’ computers. One identified product is AnySign4PC, certificate-based signing software widely encountered when accessing Korean financial and government services.
A visitor using a vulnerable AnySign4PC release could be compromised merely by opening an infected page. The malicious site communicated with the locally installed program over WebSocket, checked its version, delivered corresponding exploit code, and triggered a buffer overflow. The resulting payloads included SIGNBT and COPPERHEDGE backdoors capable of command execution, reconnaissance, file theft, process injection, and additional malware delivery.
AnySign4PC versions 1.1.4.4 through 1.1.4.6 are identified as vulnerable; KISA lists 1.1.5.0 as the corrected release and recommends removing vulnerable installations. AhnLab found 15 legitimate websites used as watering holes and evidence associated with 72 organizations during 2026. That figure should not be read as 72 uniformly confirmed full compromises because the public report does not define its counting methodology.
Some infrastructure, filenames, execution patterns, tooling, and even an SSH-key fingerprint overlapped with Gunra ransomware incidents. Earlier AnySign4PC activity has separately been attributed to Lazarus, but the current joint advisory does not definitively attribute the entire campaign to Lazarus or establish that the espionage and ransomware operators are the same. Shared access, infrastructure reuse, or an access broker remain plausible explanations.
Watch for: Identification of the two still-unnamed security products—and clarification of whether a common access supplier served both espionage and ransomware operators—would significantly broaden the defensive response.
Sources: KISA, National Intelligence Service, National Police Agency, and Financial Security Institute joint advisory on state-sponsored watering-hole attacks, July 30, 2026; AhnLab, “Operation Double Barrel,” July 30, 2026; ENKI Whitehat analysis of AnySign4PC exploitation; Plainbit watering-hole forensic report.
Amazon links four major npm compromises to one North Korean operation
Amazon Threat Intelligence reported on July 29 that the compromises of the axios, debug, chalk, and typo-crypto packages were connected to the North Korean threat group commonly tracked as Sapphire Sleet, BlueNoroff, or Stardust Chollima. Amazon assigns medium confidence to the attribution based on shared infrastructure, command-and-control indicators, code, and operating patterns.
The history shows a progression rather than four isolated package incidents. Amazon believes the group trojanized typo-crypto in March 2025 as a limited test, compromised debug and chalk in September 2025, and then targeted axios in March 2026. Axios receives more than 100 million weekly downloads. In each operation, attackers socially engineered a trusted maintainer and published a malicious update through an account users already trusted.
Amazon also describes a change in supply-chain engineering. Malicious functions are increasingly divided among multiple apparently harmless packages, armed through external configuration, or withheld until the runtime resembles a genuine developer environment. Attackers may spend months accumulating maintainer credibility before using it. A package-level malware scan can therefore miss behavior that appears only across a dependency graph or after a remote service changes state.
Defenders should identify historical exposure to the affected releases, inspect build and developer systems rather than only production servers, review dependency installation telemetry, and restrict package lifecycle scripts from receiving unrestricted credentials or network access. Lockfiles and internal registries reduce accidental movement but do not neutralize a trusted maintainer account that publishes a signed malicious update.
Watch for: Evidence that the compromised packages yielded durable access to CI/CD systems, cloud credentials, or cryptocurrency infrastructure would clarify the campaign’s downstream impact.
Sources: AWS Security Blog, “Amazon Identifies North Korean Hacker Group Behind Open-Source Supply Chain Attacks,” July 29, 2026; Open Source Vulnerabilities record MAL-2026-3400; prior Wiz research on the debug and chalk compromise.
A Microsoft Teams support call can now become ransomware in less than a day
Sophos published details of a campaign it tracks as STAC4749 in which attackers impersonated corporate IT personnel through Microsoft Teams chats and voice calls. The operation targeted dozens of organizations between February and June, with approximately 95 percent of observed targets located in Canada and the United States. Manufacturing, energy, services, construction, and engineering were prominent sectors.
The callers persuaded employees to launch Microsoft Quick Assist or install remote-management software. Attackers later shifted toward RemSupp, potentially because it was less likely to be blocked. Once connected, they used PowerShell, installed a custom backdoor, established registry persistence disguised as Windows or Realtek audio components, and deployed additional access tools such as DWAgent and AnyDesk.
At least three intrusions ended with Chaos ransomware. In one case, fewer than 17 hours separated the Teams contact from encryption. Sophos found no connection between this activity and the separate Iranian MuddyWater operation that used Chaos as a possible cover for espionage. Limited keyboard evidence suggests a Russian-language operator, but Sophos says the evidence is insufficient for attribution.
Organizations should restrict or visibly label external Teams communication, require verification through a separate internal channel before any support session, control Quick Assist and unsanctioned remote-management tools, and alert on external callers asking users to execute software. Helpdesk identity has become an access-control mechanism and must be defended accordingly.
Watch for: Additional ransomware deployments or reuse of STAC4749’s custom loader and backdoor outside the observed Teams campaign would indicate a broader affiliate service.
Sources: Sophos X-Ops, “Chaos in Teams Vishing,” July 28, 2026; Microsoft guidance on protecting users from external Teams social engineering.
A repaired Azure Cosmos DB flaw exposed how one cloud key could cross every tenant
Wiz disclosed CosmosEscape on July 30, a vulnerability chain in the Azure Cosmos DB Gremlin interface that could have provided full read-and-write access to every Cosmos DB account. Microsoft mitigated the initial entry point within 48 hours of receiving the November 2025 report and completed a long-term architectural correction across all regions in July.
The chain began with escape from the Gremlin query sandbox into the multi-tenant database gateway. From there, researchers reached a platform-wide signing secret that could retrieve any account’s primary key. A separate configuration store allowed enumeration and filtering by tenant or subscription identifiers, making targeted cross-tenant compromise theoretically possible. According to Wiz, even private and network-isolated accounts were potentially reachable because the compromised gateway enforced those network boundaries.
Microsoft found no evidence of exploitation beyond the researchers’ activity. The key has been eliminated, additional service-to-service authentication and network protections have been introduced, and no customer action is required.
CosmosEscape matters because it demonstrates why customer-managed isolation cannot compensate for an unsafe provider control plane. Cloud customers should still retain independent audit logs, minimize the authority of data stored in any one service, and maintain response plans for provider-side incidents that cannot be patched from the customer tenant.
Watch for: Microsoft’s detailed account of its key architecture and historical telemetry would help determine how confidently exploitation can be excluded across the pre-remediation period.
Sources: Wiz Research, “CosmosEscape: Taking Over Every Database in Azure Cosmos DB,” July 30, 2026; Microsoft response included in the Wiz disclosure, July 30, 2026.
The FCC has moved connected power equipment and mobile robots onto its national-security list
The Federal Communications Commission added foreign-produced connected power inverters and advanced robotic devices to its Covered List on July 28. New covered models generally cannot receive the equipment authorization required for import, marketing, or sale in the United States.
The inverter designation reaches equipment used in solar generation, battery storage, data centers, and distributed energy systems when it provides remote communication, control, sensing, or monitoring. The national-security determination warns that remote access could support surveillance, data theft, unauthorized shutdown, or disruption of critical infrastructure.
Covered robots include mobile systems such as humanoids and quadrupeds that meet defined weight, sensing, navigation, connectivity, and software criteria. Existing authorized models and already purchased devices are not banned, and the action does not itself prohibit federal use. Manufacturers may seek conditional approval from designated federal departments.
The FCC also issued a waiver allowing qualifying security and compatibility updates for previously authorized equipment through at least January 1, 2029. That detail matters: freezing firmware would have created a new vulnerability-management problem while addressing a supply-chain risk. Operators should treat the policy as a procurement signal, not evidence that installed equipment is compromised, and should continue patching, inventorying remote-management paths, and isolating inverter and robotic control networks.
Watch for: Any FCC action affecting existing authorizations—or technical requirements imposed through conditional approval—will determine whether this remains primarily a future-procurement restriction or becomes an installed-base remediation issue.
Sources: FCC, “FCC Adds Foreign-Produced Power Inverters and Robots to Covered List,” July 28, 2026; FCC Public Notice DA 26-786, July 28, 2026; FCC Office of Engineering and Technology blanket waiver for qualifying firmware and software changes, July 28, 2026.
Jonathan Lockhart is a cybersecurity researcher and investigative journalist at bordercybergroup.com.
If you would like to support our work — useful, well-researched, ad-free cybersecurity intelligence — subscribe, comment, or buy us a coffee! Thanks.
Member discussion: