Afternoon Review in IT Security — August 2, 2026
The threat landscape continues to evolve with sophisticated supply-chain attacks, nation-state operations targeting travelers, and emerging AI-driven autonomous attack capabilities. Today's security briefing highlights critical vulnerabilities affecting advertising infrastructure, hospitality networks, and critical infrastructure systems worldwide.
Online Ad Firm Adform's Script Compromised to Steal Cryptocurrency
A significant supply-chain attack has compromised the advertising platform operated by Adform, one of the internet's major ad delivery networks. The attack involved injecting malicious code into Adform's advertising scripts, which are loaded across thousands of websites globally. The compromised script targeted cryptocurrency users by intercepting wallet addresses copied to visitors' clipboards and replacing them with addresses controlled by the attacker, effectively redirecting cryptocurrency transfers to threat actors. This attack demonstrates the cascading risks inherent in widely-deployed third-party scripts and the potential for attackers to weaponize trusted advertising infrastructure. Source: Online ad firm Adform's script compromised to steal cryptocurrency
Midnight Blizzard Targets Travelers Through Compromised Hotel Sign-In Portals
Russian threat actor Midnight Blizzard, specifically a sub-cluster designated Storm-2945, has been conducting a coordinated campaign against hospitality organizations since May 2026. The operation, named CaptiveCrunch, involves compromising the sign-in portals of hotels and other travel-related businesses to deliver malware to guests and harvest their credentials. Travelers connecting to hotel networks become targets for credential theft and malware installation, creating a unique vector for compromising individuals across multiple geographic regions. This campaign highlights the vulnerability of captive portal systems and the attractiveness of hospitality networks as attack staging grounds for nation-state actors. Source: CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft
Threat Actor Leverages DeepSeek AI for Autonomous Server Attacks
A Chinese-speaking threat actor has begun utilizing the DeepSeek AI model in conjunction with the open-source Hermes Agent framework to conduct autonomous cyberattacks against vulnerable servers with minimal human intervention. This represents a significant escalation in attack automation, as the AI system can independently identify exposed servers, exploit known vulnerabilities including CVE-2026-33017, CVE-2026-21858, CVE-2025-68613, and CVE-2026-3055, and establish persistence with limited operator involvement. The convergence of advanced AI capabilities and autonomous attack frameworks poses an emerging threat to organizations with unpatched systems and internet-exposed infrastructure. Source: Hacker uses DeepSeek AI to autonomously attack vulnerable servers
CISA Alerts on Escalating Attacks Against U.S. Water Utilities
The Cybersecurity and Infrastructure Security Agency has issued a warning regarding a substantial increase in cyberattacks targeting internet-exposed programmable logic controllers in water and wastewater treatment systems across the United States. These attacks directly threaten critical infrastructure responsible for providing essential services to the American public. The targeting of PLCs represents a particularly dangerous vector, as successful compromise could enable attackers to disrupt water treatment processes or contaminate supplies. This alert underscores the ongoing vulnerability of operational technology systems that were not designed with modern cybersecurity principles in mind. Source: CISA warns of cyberattacks disrupting U.S. water utilities
Today's threat intelligence reveals a security environment characterized by both sophisticated supply-chain compromises and nation-state operations targeting critical infrastructure and civilian populations. Organizations must prioritize patching vulnerable systems, implementing network segmentation for operational technology, and conducting rigorous third-party code audits to defend against these multifaceted threats.