Weekly review

ThreatNoir Morning Brief — July 31

2026-07-31Morning4 articles
Audio
Listen to the episode

Morning Review in IT Security — July 31, 2026

Critical infrastructure and software supply chains face mounting threats as nation-state actors intensify campaigns against water utilities and developers. This morning's briefing covers coordinated attacks on operational technology, a severe vulnerability in enterprise build tools, and sophisticated malware campaigns targeting macOS users.

CISA Urges Water Sector to Protect OT After Coordinated Attacks on PLCs

The Cybersecurity and Infrastructure Security Agency has issued an urgent call for water and wastewater utilities to secure internet-exposed programmable logic controllers following a wave of intrusions affecting dozens of systems in Minnesota. The coordinated attacks demonstrate the vulnerability of operational technology infrastructure when exposed to the public internet without adequate access controls. Source: CISA Urges Water Sector to Protect OT After Coordinated Attacks on PLCs

The advisory underscores the critical need for water utilities to implement network segmentation and restrict remote access to control systems. Organizations in this sector should prioritize inventory of all internet-facing devices and implement authentication mechanisms to prevent unauthorized access to PLCs and related infrastructure.

JetBrains Warns of Critical TeamCity Remote Code Execution Flaw

JetBrains has disclosed a critical authentication bypass vulnerability in TeamCity On-Premises that could allow attackers to achieve remote code execution. The flaw, tracked as CVE-2026-63077, represents a significant risk to development environments relying on TeamCity for continuous integration and deployment pipelines. Source: JetBrains warns of critical TeamCity remote code execution flaw

Organizations operating TeamCity On-Premises deployments should prioritize patching this vulnerability immediately, as successful exploitation could grant attackers control over build systems and access to source code repositories. The supply chain implications are substantial, as compromised build infrastructure can be leveraged to inject malicious code into distributed software.

A Leaked Memo Ties Cyberattacks on Minnesota Water Utilities to Iran

A confidential memo obtained by WIRED and issued by WaterISAC, the water sector's information sharing organization, attributes dozens of cyberattacks against Minnesota water utilities to Iranian threat actors. The attribution links Tehran-based operations to the coordinated intrusions that prompted CISA's recent advisory. Source: A Leaked Memo Ties Cyberattacks on Minnesota Water Utilities to Iran

The memo documents sophisticated reconnaissance and lateral movement techniques consistent with nation-state activity, indicating a sustained campaign against critical water infrastructure. This attribution elevates the incident from isolated network compromises to a geopolitical concern with implications for national security and public safety.

DPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto-Stealing Malware

North Korean threat actors have launched a sophisticated malvertising campaign targeting macOS users through fake software update screens as part of an evolution of the Contagious Interview malware family. The attack redirects users to fraudulent web pages displaying convincing but non-existent update sequences, tricking victims into executing malware designed to steal cryptocurrency. Source: DPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto-Stealing Malware

The campaign leverages malicious domains including rg-telemetry.sbs and th-updates.sbs to deliver the payload. Users should remain vigilant when encountering unexpected software update prompts and verify updates through official application channels rather than clicking on unsolicited notifications. This campaign demonstrates the continued sophistication of North Korean cyber operations in targeting individual users and their digital assets.

Threats spanning critical infrastructure, enterprise software, and individual endpoints underscore the breadth of the current threat landscape. Organizations and users should prioritize patching, network hardening, and user awareness training to mitigate these converging risks.

Sources & IOCs

Source articles and extracted indicators (defanged where appropriate).

DPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto-Stealing Malware
MITRE ATT&CK3
  • Command and Scripting Interpreter: Windows Command Shell (used via Terminal on macOS)
  • Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder (Persistence via LaunchAgent)
  • Application Layer Protocol: Web Protocols (used for C2 communication)
Malware1
  • Contagious Interview
    Name of the ongoing malware campaign
Domain2
  • rg-telemetry.sbs
    C2 server domain for malware communication
  • th-updates.sbs
    C2 server domain for malware communication