By security practitioners, for security practitioners novacoast federal | Apex Program | novacoast | about innovate
By security practitioners, for security practitioners

Top 10 Cybersecurity News (August 03, 2026): Minnesota Water Utilities Hit In Coordinated Attack, DeepSeek Model Drives Autonomous Attacks On Servers, and More

WEEKLY TOP TEN: August 03, 2026, 16:00 GMT

  1. Minnesota Water Utilities Hit In Coordinated Attack

    Minnesota IT Services activated statewide cybersecurity incident response after hackers targeted more than 30 community water systems in a coordinated attack. The intrusions struck operational technology on July 26 and 27, and although officials have not attributCISed the activity, researchers have pointed to patterns consistent with Iran-linked targeting of small water utilities. Affected communities included Braham, Plymouth, South St. Paul, and Maple Plain. Officials said drinking water safety was never compromised, but automated control functions were disrupted and contingency procedures were activated. The case shows how small municipal utilities running OT through consumer remote-access tools or exposed controller interfaces present a soft target with outsized public consequences.
  2. CISA Alerts Water Sector To Surge In PLC Attacks

    CISA warned on July 30 that it is observing a significant increase in threat actors targeting programmable logic controllers in the Water and Wastewater Systems Sector, urging owners, operators, and integrators to remove publicly exposed PLCs and other operational technology from the internet as soon as possible. Attackers have modified passwords to lock out operators and disconnected PLCs by changing IP addresses, producing boil water notices and sustained manual operations, and they are targeting water entities of all sizes. Utilities in at least seven states have reported related incidents to the FBI. Cellular modems outside asset inventories are a noted blind spot.
  3. Russian Group Exploits Exchange OWA Zero-Day For Access

    The Russian state-sponsored group Laundry Bear, also tracked as Void Blizzard, is exploiting an Exchange Outlook Web Access vulnerability in email campaigns to deliver a sophisticated backdoor called OWAReaper, giving the actors long-term mailbox access. The campaign extends the same actor’s documented pattern of pursuing webmail as a durable espionage foothold rather than a one-time collection opportunity. Because the backdoor targets the mail platform directly, organizations should not assume that patching alone evicts the intruder. Security teams running on-premises Exchange should hunt for anomalous OWA sessions, review application passwords and mail forwarding rules, and rotate credentials for any account showing suspicious access.
  4. Amgen Cloud Breach Exposes Patient And Proprietary Data

    Pharmaceutical company Amgen disclosed a data breach after threat actors stole corporate data and patient information stored in multiple cloud systems operated by third-party service providers. The incident continues a run of 2026 breaches in which the compromised environment was not the victim’s own infrastructure but cloud tenancies managed by vendors, making detection and forensic scope dependent on providers. For life sciences organizations, the exposure spans two distinct risk categories at once: regulated patient health information carrying notification obligations, and proprietary research data with competitive and intellectual property value. Security leaders should map which vendor-hosted cloud systems hold both categories and confirm logging access under contract. 
  5. Teams Vishing Calls Lead To Chaos Ransomware Attacks

    Threat actors are impersonating IT support staff in Microsoft Teams calls to gain remote access to corporate devices and deploy Chaos ransomware in attacks targeting North American organizations. The technique bypasses email security entirely by initiating contact inside a trusted collaboration platform, where external participants often appear with minimal visual distinction from colleagues. Because the victim grants remote access voluntarily, endpoint controls frequently register the session as legitimate administrative activity. Mitigations include restricting external Teams federation and inbound calls from untrusted tenants, blocking unsanctioned remote access tooling, and training staff that legitimate IT support will never cold-call requesting screen control.
  6. Adform Ad Script Compromised To Steal Cryptocurrency

    Online advertising firm Adform suffered a supply-chain attack that delivered cryptocurrency-stealing scripts to websites using its ad platform, replacing wallet addresses copied to visitors’ clipboards with attacker-controlled ones. The company detected the incident on July 27, removed the malicious code, notified affected clients, and reported it to authorities, warning that anyone who visited an affected site that day and copied a Bitcoin, Ethereum, or Tron address may have pasted a substituted one. Users are advised to clear browser caches because the altered file may persist, and to verify wallet addresses before sending funds. Third-party ad tags remain an under-governed execution path on production sites. 
  7. ShinyHunters Claims Brinks Home Breach And Leak Threat

    Residential security company Brinks Home disclosed that hackers breached some of its systems and are threatening to leak allegedly stolen data, with ShinyHunters claiming responsibility. A physical security provider holds customer addresses, alarm configurations, service schedules, and account credentials, a combination that raises harm potential well beyond typical consumer records if published. The listing continues the group’s high-tempo 2026 extortion campaign, which has relied on public victim naming and deadlines to force negotiation. Organizations that resell or integrate monitoring services should determine what subscriber data they share with the provider and prepare customer communications ahead of any publication.
  8. VMware Fixes Auth Bypass And Virtual Machine Escapes

    Broadcom released security updates addressing five vulnerabilities in VMware vCenter, ESX, Workstation, and Fusion, including three critical flaws that allow attackers to bypass authentication, execute arbitrary code, or escape from a virtual machine to the host. Hypervisor escape collapses the isolation boundary that most segmentation designs depend on, meaning a single compromised guest can reach every workload sharing the host. vCenter compromise is equally consequential, granting administrative reach across entire clusters. Given how consistently virtualization management has been targeted by ransomware operators seeking mass encryption leverage, organizations should treat these updates as emergency change candidates rather than routine quarterly patching. 
  9. DeepSeek Model Drives Autonomous Attacks On Servers

    A Chinese-speaking threat actor is using the DeepSeek AI model and the open-source Hermes Agent to conduct autonomous cyberattacks on exposed servers with limited human involvement. The operator, tracked through the aliases knaithe and KnYuan, launched exploitation attempts against more than 460 targets across seven exploit tracks spanning eight CVEs, with researchers reporting data exfiltration from three organizations through a NetScaler memory-overread flaw and command execution on additional hosts. Failures occurred where target configurations did not match exploit prerequisites. The volume achieved by a single operator is the central finding for defenders planning detection capacity.
  10. LeakNet Claims 11TB Theft From NYC Health And Hospitals

    A data-extortion operation using the name LeakNet claims it stole an 11TB archive from NYC Health + Hospitals containing information linked to more than 12 million people, a figure not confirmed by the health system, regulators, or independent forensic review. The group published a preview on July 27 with screenshots of databases, medical spreadsheets, internal messages, and a directory listing, and threatened to publish the remainder later. Several screenshots contain visible patient names, addresses, Social Security numbers, dates of birth, and medical information. The system previously disclosed a breach in March affecting at least 1.8 million people.

Our Threat Operations and Intelligence team compiles a daily digest of the most recent online cybersecurity risks. The previous 10 stories were determined to be most significant during the course of the week, ranked by highest risk, and using multiple sources when available.

Previous Post

Innovator Series S2 Episode 4: Dan Shiebler of Artemis Security

Innovate uses cookies to give you the best online experience. If you continue to use this site, you agree to the use of cookies. Please see our privacy policy for details.