ThreatNoir Morning Brief — July 31
Morning Review in IT Security — July 31, 2026
Critical infrastructure and software supply chains face mounting threats as nation-state actors intensify campaigns against water utilities and developers. This morning's briefing covers coordinated attacks on operational technology, a severe vulnerability in enterprise build tools, and sophisticated malware campaigns targeting macOS users.
CISA Urges Water Sector to Protect OT After Coordinated Attacks on PLCs
The Cybersecurity and Infrastructure Security Agency has issued an urgent call for water and wastewater utilities to secure internet-exposed programmable logic controllers following a wave of intrusions affecting dozens of systems in Minnesota. The coordinated attacks demonstrate the vulnerability of operational technology infrastructure when exposed to the public internet without adequate access controls. Source: CISA Urges Water Sector to Protect OT After Coordinated Attacks on PLCs
The advisory underscores the critical need for water utilities to implement network segmentation and restrict remote access to control systems. Organizations in this sector should prioritize inventory of all internet-facing devices and implement authentication mechanisms to prevent unauthorized access to PLCs and related infrastructure.
JetBrains Warns of Critical TeamCity Remote Code Execution Flaw
JetBrains has disclosed a critical authentication bypass vulnerability in TeamCity On-Premises that could allow attackers to achieve remote code execution. The flaw, tracked as CVE-2026-63077, represents a significant risk to development environments relying on TeamCity for continuous integration and deployment pipelines. Source: JetBrains warns of critical TeamCity remote code execution flaw
Organizations operating TeamCity On-Premises deployments should prioritize patching this vulnerability immediately, as successful exploitation could grant attackers control over build systems and access to source code repositories. The supply chain implications are substantial, as compromised build infrastructure can be leveraged to inject malicious code into distributed software.
A Leaked Memo Ties Cyberattacks on Minnesota Water Utilities to Iran
A confidential memo obtained by WIRED and issued by WaterISAC, the water sector's information sharing organization, attributes dozens of cyberattacks against Minnesota water utilities to Iranian threat actors. The attribution links Tehran-based operations to the coordinated intrusions that prompted CISA's recent advisory. Source: A Leaked Memo Ties Cyberattacks on Minnesota Water Utilities to Iran
The memo documents sophisticated reconnaissance and lateral movement techniques consistent with nation-state activity, indicating a sustained campaign against critical water infrastructure. This attribution elevates the incident from isolated network compromises to a geopolitical concern with implications for national security and public safety.
DPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto-Stealing Malware
North Korean threat actors have launched a sophisticated malvertising campaign targeting macOS users through fake software update screens as part of an evolution of the Contagious Interview malware family. The attack redirects users to fraudulent web pages displaying convincing but non-existent update sequences, tricking victims into executing malware designed to steal cryptocurrency. Source: DPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto-Stealing Malware
The campaign leverages malicious domains including rg-telemetry.sbs and th-updates.sbs to deliver the payload. Users should remain vigilant when encountering unexpected software update prompts and verify updates through official application channels rather than clicking on unsolicited notifications. This campaign demonstrates the continued sophistication of North Korean cyber operations in targeting individual users and their digital assets.
Threats spanning critical infrastructure, enterprise software, and individual endpoints underscore the breadth of the current threat landscape. Organizations and users should prioritize patching, network hardening, and user awareness training to mitigate these converging risks.
Sources & IOCs
Source articles and extracted indicators (defanged where appropriate).
- Critical authentication bypass vulnerability in TeamCity On-Premises
- Indicator removal on host (clear logs or other data).
- Disabling or modifying safety and protection parameters in critical infrastructure.
- Account discovery (local system).
- Command and scripting interpreter: Windows Command Shell.
- Application layer protocol: Web protocols (HTTP/HTTPS).
- Non-standard port.
- Command and Scripting Interpreter: Windows Command Shell (used via Terminal on macOS)
- Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder (Persistence via LaunchAgent)
- Application Layer Protocol: Web Protocols (used for C2 communication)
- Contagious InterviewName of the ongoing malware campaign
rg-telemetry.sbsC2 server domain for malware communicationth-updates.sbsC2 server domain for malware communication