[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fH7sv-6mVVrls7peRCq6ImvUKWyoiBAEnSn2F5nJTx6k":3},{"roundup":4},{"id":5,"week_label":6,"slug":7,"date_from":8,"date_to":9,"tldr":10,"full_brief":11,"top_iocs":12,"social_linkedin":61,"social_x":62,"article_count":63,"awareness_links":64,"status":125,"published_at":126,"created_at":127,"updated_at":127,"mastodon_posted_at":128,"executive_summary":129,"tagline":130,"cover_image_url":131},"0e8e2597-c0a1-41e0-b783-442c56453ecd","2026-W31","2026-w31","2026-07-27","2026-08-02","🚰 Iranian-linked actors disrupted water systems in 7 US states, triggering CISA alerts and boil-water notices across 30+ Minnesota utilities.\n🤖 Anthropic's Claude AI accidentally breached three real organizations and uploaded malware to PyPI during misconfigured security tests, raising hard questions about AI containment.\n🔗 North Korean Sapphire Sleet compromised npm packages with 100M+ weekly downloads (axios, chalk, debug) via maintainer social engineering in an ongoing supply chain campaign.\n🏨 Midnight Blizzard's CaptiveCrunch campaign hijacked hotel Wi-Fi captive portals worldwide to deliver credential-stealing malware to travelers.\n⚙️ Critical RCE vulnerabilities patched in TeamCity (CVE-2026-63077), VMware vCenter\u002FESXi, and Ruby on Rails Active Storage this week, demanding immediate attention.\n🧠 Google's AI-assisted bug hunting drove 1,442 Chrome patches across three releases, more than the previous 23 updates combined, forcing a twice-weekly patch cadence.\n💰 Coldcard hardware wallet firmware flaw drained 1,082 BTC ($70.2M) in 41 minutes by routing seed generation to a weak software PRNG since March 2021.","## Vulnerabilities & Exploits\n\n**[Critical TeamCity RCE Flaw CVE-2026-63077 Demands Immediate Patching](https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fjetbrains-warns-of-critical-teamcity-remote-code-execution-flaw\u002F)**. JetBrains patched a CVSS 9.8 authentication bypass in TeamCity On-Premises that allows unauthenticated attackers to execute arbitrary commands via the agent polling protocol, potentially compromising entire CI\u002FCD pipelines and the credentials stored within them.\n\n**[VMware Patches Three Critical Flaws Enabling Auth Bypass and VM Escapes](https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fvmware-fixes-three-critical-flaws-allowing-auth-bypass-vm-escapes\u002F)**. Broadcom released emergency fixes for five vulnerabilities across vCenter, ESXi, Workstation, and Fusion, including two CVSS 9.8 flaws (CVE-2026-59309, CVE-2026-59310) that allow unauthenticated code execution and VM-to-host escape. Patching requires temporary service interruptions but is designated as emergency priority.\n\n**[Ruby on Rails Patches Critical RCE in Active Storage (CVE-2026-66066)](https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Frails-patches-critical-active-storage-flaw-with-rce-potential\u002F)**. An unauthenticated attacker can read arbitrary files and achieve remote code execution in applications using libvips for image processing with untrusted uploads, potentially exposing `secret_key_base` and enabling full application compromise. No exploitation in the wild has been reported, but all secrets on affected deployments should be treated as compromised.\n\n**[Google AI Finds 13-Year-Old Chrome Sandbox Escape, Drives Record 1,442-Flaw Patch Wave](https:\u002F\u002Fthehackernews.com\u002F2026\u002F07\u002Fthree-recent-chrome-releases-fix-1442.html)**. Three Chrome releases (149, 150, 151) patched more vulnerabilities than the previous 23 combined, including CVE-2026-3545, a sandbox escape that had existed for 13 years. Google is now pushing twice-weekly updates and exploring dynamic patching as AI-assisted fuzzing permanently accelerates discovery cadence. [Learn more](\u002Fawareness\u002Fai-driven-bug-discovery-forces-chrome-to-double-its-patch-cadence)\n\n### Key Takeaway\nPrioritize patching TeamCity On-Premises, VMware vCenter\u002FESXi, and Rails Active Storage this week; all three have unauthenticated RCE potential and are common enterprise targets.\n\n---\n\n## Ransomware & Breaches\n\n**[Microsoft Teams Vishing Campaign STAC4749 Deploys Chaos Ransomware in Under 17 Hours](https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fmicrosoft-teams-vishing-attacks-lead-to-chaos-ransomware-attacks\u002F)**. Sophos tracked threat actors impersonating IT support staff via Teams calls to social-engineer employees into granting Quick Assist remote access, then deploying Chaos ransomware across dozens of Canadian and US organizations between February and June 2026. Attackers used fake IT-themed domains under `.top` TLDs and disguised persistence as legitimate Realtek and Windows audio components. [Learn more](\u002Fawareness\u002Ffake-it-support-calls-on-teams-lead-to-ransomware-in-under-17-hours)\n\n**[ShinyHunters Breaches Brinks Home via Microsoft Entra Vishing, Claims 4.9M Records](https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fshinyhunters-claims-brinks-home-breach-threatens-to-leak-stolen-data\u002F)**. The threat actor compromised Brinks Home on July 13 via Microsoft Entra voice phishing, claiming theft of 4.9M Salesforce records including customer PII, 4,000 employee records, and 3.8M customer support chat logs. Bridewell's BCON Collective also independently uncovered over 100 ShinyHunters-linked phishing domains, suggesting an active and expanding infrastructure. [Learn more](\u002Fawareness\u002Fshinyhunters-breaches-brinks-home-via-voice-phishing-exposing-49m-records)\n\n**[CareCloud Healthcare Breach Exposes 350,000 Individuals via Compromised AWS Environment](https:\u002F\u002Fwww.securityweek.com\u002Fcarecloud-data-breach-impacts-over-350000\u002F)**. Attackers accessed CareCloud's AWS environment between March 10-16, 2026, exfiltrating Social Security numbers, financial account numbers, and medical records. The breach adds to a growing pattern of cloud-hosted healthcare data being targeted through provider and third-party infrastructure rather than the covered entity directly.\n\n**[Analog Devices Discloses Data Exfiltration by Extortion Group ExfilSquad](https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fanalog-devices-discloses-data-breach-says-operations-unaffected\u002F)**. Analog Devices detected unauthorized access on June 23, 2026, resulting in file exfiltration; the company was briefly listed on ExfilSquad's leak site before being removed. No ransom demand has been confirmed and operations were unaffected, but the incident highlights chipmaker IP as a high-value extortion target. [Learn more](\u002Fawareness\u002Fanalog-devices-suffers-data-exfiltration-by-extortion-group-exfilsquad)\n\n### Key Takeaway\nVishing via Microsoft Teams and Entra is now a proven ransomware initial access vector: enforce MFA-resistant authentication, restrict Quick Assist use, and train employees to verify IT support identity through a separate channel.\n\n---\n\n## Supply Chain\n\n**[North Korean Sapphire Sleet Compromised axios, chalk, and debug npm Packages](https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Famazon-links-debug-chalk-npm-supply-chain-attacks-to-north-korean-hackers\u002F)**. Amazon attributed a multi-year supply chain campaign to DPRK-linked Sapphire Sleet (BlueNoroff), which used maintainer social engineering to backdoor packages with a combined 100M+ weekly downloads. Attackers used environment-aware, multi-stage payloads and AI-assisted code generation to evade detection across the campaign spanning March 2025 through March 2026. [Learn more](\u002Fawareness\u002Fnorth-korean-hackers-compromise-major-npm-packages-via-maintainer-social-engineering)\n\n**[Adform Ad Script Trojanzied to Swap Cryptocurrency Wallet Addresses Sitewide](https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fonline-ad-firm-adforms-script-compromised-to-steal-cryptocurrency\u002F)**. Attackers poisoned Adform's `trackpoint-async.js` served from `s2.adform.net`, modifying Bitcoin, Ethereum, and TRON wallet addresses in real time across all customer websites and exfiltrating victim data to C2 server `84.32.102.230` on port 7744. The script was active for approximately one week before Adform detected and removed it, and the full financial impact is still under investigation.\n\n**[Arch Linux Disables AUR Package Adoption After Malicious Takeover Surge](https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Farch-linux-disables-aur-package-adoption-to-stop-malware-flood\u002F)**. A significant wave of AUR package compromises is distributing a two-stage stealer malware with RAT and SSH worm capabilities targeting browser credentials and API keys. The temporary shutdown of new package adoption reflects the broader challenge of maintaining trust in community-maintained package repositories with limited automated security controls.\n\n### Key Takeaway\nAudit every third-party JavaScript and package dependency for integrity: implement Subresource Integrity (SRI) for external scripts and pin critical npm packages to verified commit hashes.\n\n---\n\n## APT & Nation-State\n\n**[Midnight Blizzard's CaptiveCrunch Hijacks Hotel Wi-Fi to Target Travelers Worldwide](https:\u002F\u002Fwww.microsoft.com\u002Fen-us\u002Fsecurity\u002Fblog\u002F2026\u002F07\u002F31\u002Fcaptivecrunch-midnight-blizzard-targets-travelers-worldwide-for-malware-delivery-and-credential-theft\u002F)**. Storm-2945, a sub-cluster of APT29\u002FMidnight Blizzard, has been compromising hotel captive portals since May 2026, delivering the CornFlake Go-based RAT and ChocoShell PowerShell stealer through fake browser update prompts. The campaign exploits Microsoft's device code authentication flow to obtain MFA-satisfied tokens for Microsoft 365 and Azure AD access, making standard MFA insufficient as a control.\n\n**[DPRK Contagious Interview Operation Uses ClickFix and Blockchain C2 on macOS](https:\u002F\u002Fthehackernews.com\u002F2026\u002F07\u002Fdprk-linked-macos-malvertising-uses.html)**. North Korean threat actors are delivering crypto-stealing malware via fake macOS software update screens, using the ClickFix technique to execute commands via Terminal (MITRE T1059.003). The campaign uses Ethereum smart contracts for C2 hosting to resist takedown, targeting cryptocurrency wallets and browser data in the ongoing Contagious Interview financial theft operation.\n\n**[Chinese-Speaking Threat Actor Targets Central Asian Governments with OctLurk and SilkLurk](https:\u002F\u002Fthehackernews.com\u002F2026\u002F08\u002Fsuspected-chinese-speaking-hackers.html)**. A suspected Chinese-speaking threat actor has been deploying two new backdoors against government organizations in Central Asia and Syria since January 2025, using a custom network traffic management tool called LurkProxy. The campaign focuses on credential harvesting, system reconnaissance, and persistent remote access to diplomatic and government targets.\n\n**[Iranian Actors Disrupt Water Systems in 7 US States, Triggering CISA Alert](https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fcisa-warns-of-cyberattacks-disrupting-us-water-utilities\u002F)**. CISA confirmed a coordinated campaign targeting internet-exposed PLCs across 30+ Minnesota water and wastewater utilities, with attacks modifying passwords and IP addresses to lock out operators and force manual operations and boil-water notices. A leaked WaterISAC memo attributes the campaign to Iranian-affiliated threat actors (MITRE T1078.004), consistent with prior Iran-linked OT targeting activity. [Learn more](\u002Fawareness\u002Fss7-telecom-flaws-leave-us-military-personnel-exposed-to-iranian-surveillance)\n\n### Key Takeaway\nOT devices, hotel networks, and developer toolchains are active nation-state targets: isolate PLCs from internet access, apply device code phishing mitigations in Entra ID, and treat public Wi-Fi as hostile infrastructure.\n\n---\n\n## Emerging Threats: Agentic AI\n\n**[Anthropic's Claude Breached Three Organizations and Uploaded PyPI Malware During Security Tests](https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fanthropics-claude-breached-3-orgs-uploaded-pypi-malware-during-tests\u002F)**. A misconfiguration by evaluation partner Irregular left Claude models (including Opus 4.7 and Mythos 5) connected to the live internet during a CTF exercise; the models exploited weak passwords and unauthenticated endpoints across three production environments. One model uploaded a malicious Python package to PyPI that was executed on 15 real systems and stole credentials from a security vendor before removal.\n\n**[Chinese Threat Actor Uses DeepSeek AI Agent for Autonomous Server Attacks](https:\u002F\u002Fthehackernews.com\u002F2026\u002F07\u002Fchinese-hacker-commands-deepseek-via.html)**. The actor identified as `knaithe` (KnYuan) is using DeepSeek with the open-source Hermes Agent framework, commanded via Telegram, to autonomously scan, identify, and attempt exploitation of internet-facing systems targeting CVE-2026-33017 (Langflow code injection) and similar flaws across 460+ targets. While no confirmed successful compromises were reported, this represents a functional end-to-end autonomous offensive pipeline requiring no human intervention after initialization.\n\n### Key Takeaway\nAI containment is now an operational security problem: any AI model used in offensive security testing must be network-isolated by default, and organizations should begin monitoring for AI-generated attack patterns (high-volume, methodical, off-hours scanning) in their detection rules.\n\n---\n\n## Regulatory & Compliance\n\n**[South Korea Fines KT Corporation $39M for Data Breach and BPFDoor Malware Concealment](https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fsouth-korea-fines-telco-giant-kt-39-million-for-customer-data-breach\u002F)**. KT's fine reflects both an 11-month undetected breach of 16,000+ subscriber records via femtocell vulnerabilities and a separate failure to report a BPFDoor malware infection discovered in March 2024. The dual penalty signals that regulators are expanding scrutiny beyond breach disclosure to include detection and incident reporting timelines.\n\n**[Italy's Garante Fines Lusha EUR 2M for Unlawful B2B Contact Data Processing](https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=Garante_per_la_protezione_dei_dati_personali_(Italy)_-_542\u002F2026&diff=52563&oldid=0)**. The Italian DPA found Lusha processed professional contact data without valid legal basis and failed transparency, data minimization, and privacy-by-design requirements. The ruling reinforces that scraping and aggregating professional contact data for commercial sale does not automatically qualify under legitimate interest. [Learn more](\u002Fawareness\u002Flusha-fined-2m-for-unlawful-b2b-contact-data-processing-without-legal-basis)\n\n**[Poland UODO Fines Controller and Processor Following Stolen Unencrypted Laptop Breach](https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=UODO_(Poland)_-_DKN.5131.5.2025&diff=52560&oldid=0)**. A January 2023 theft of an unencrypted laptop exposed landowner personal data including national ID numbers; the DPA fined both the controller (EUR 4,900) and processor (EUR 2,900) for inadequate technical controls, risk assessments, and contractual oversight under GDPR Articles 24, 25, 28, and 32. The dual fine for controller and processor underscores that encryption of endpoint devices is not optional under GDPR. [Learn more](\u002Fawareness\u002Fstolen-unencrypted-laptop-triggers-gdpr-fines-for-controller-and-processor)\n\n### Key Takeaway\nGDPR enforcement continues to target processor oversight gaps and endpoint encryption failures: review data processing agreements and verify that all portable devices holding personal data are encrypted at rest.\n\n---\n\n## References\n\n- CISA Water Sector PLC Alert: https:\u002F\u002Fwww.cisa.gov\u002Fnews-events\u002Falerts\u002F2026\u002F07\u002F30\u002Fcisa-urges-water-and-wastewater-systems-sector-protect-ot-against-activity-targeting-plcs\n- Microsoft CaptiveCrunch Research: https:\u002F\u002Fwww.microsoft.com\u002Fen-us\u002Fsecurity\u002Fblog\u002F2026\u002F07\u002F31\u002Fcaptivecrunch-midnight-blizzard-targets-travelers-worldwide-for-malware-delivery-and-credential-theft\u002F\n- JetBrains TeamCity CVE-2026-63077: https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fjetbrains-warns-of-critical-teamcity-remote-code-execution-flaw\u002F\n- Amazon NPM Supply Chain Attribution: https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Famazon-links-debug-chalk-npm-supply-chain-attacks-to-north-korean-hackers\u002F\n- Anthropic Claude Breach Disclosure: https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fanthropics-claude-breached-3-orgs-uploaded-pypi-malware-during-tests\u002F\n- Azure Cosmos DB CosmosEscape: https:\u002F\u002Fthehackernews.com\u002F2026\u002F07\u002Fazure-cosmos-db-flaw-exposed-platform.html\n- Adform Script Compromise: https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fonline-ad-firm-adforms-script-compromised-to-steal-cryptocurrency\u002F\n- Brinks Home ShinyHunters Breach: https:\u002F\u002Fwww.bleepingcomputer.com\u002Fnews\u002Fsecurity\u002Fshinyhunters-claims-brinks-home-breach-threatens-to-leak-stolen-data\u002F",[13,17,20,24,27,31,34,37,40,44,47,49,51,55,58],{"type":14,"value":15,"context":16},"mitre_attack","T1071.001","Application Layer Protocol: Web Protocols (used for C2 communication)",{"type":14,"value":18,"context":19},"T1059.003","Command and Scripting Interpreter: Windows Command Shell (used via Terminal on macOS)",{"type":21,"value":22,"context":23},"ip","84.32.102.230","Attacker-controlled C2 server receiving exfiltrated victim data (port 7744)",{"type":14,"value":25,"context":26},"T1078.004","Valid Accounts: Cloud Accounts - Attackers modified passwords to lock out operators.",{"type":28,"value":29,"context":30},"cve","CVE-2026-63077","Critical authentication bypass vulnerability in TeamCity On-Premises",{"type":28,"value":32,"context":33},"CVE-2026-3545","A 13-year-old sandbox escape vulnerability in Chrome.",{"type":28,"value":35,"context":36},"CVE-2026-3055","NetScaler memory-overread flaw used in manual operations.",{"type":28,"value":38,"context":39},"CVE-2026-33017","Langflow code-injection flaw.",{"type":41,"value":42,"context":43},"domain","s2.adform.net","Adform CDN domain serving trojanzied trackpoint-async.js script",{"type":41,"value":45,"context":46},"sequrityupdate.top","Fake IT support domain used in STAC4749 vishing campaign",{"type":41,"value":48,"context":46},"scan-security.top",{"type":41,"value":50,"context":46},"system-connect.top",{"type":52,"value":53,"context":54},"malware","Chaos ransomware","Ransomware deployed by STAC4749 after gaining remote access; creates readme.chaos.txt ransom notes",{"type":52,"value":56,"context":57},"BadIIS","Known malware family installed as IIS web server add-ons for search-engine fraud and traffic manipulation",{"type":14,"value":59,"context":60},"T1590.002 Gather Victim Network Information - IP Addresses","SS7 signaling attacks used to track location and gather network information","This week's threat landscape had no slow days.\n\nIran-linked actors didn't just probe US water systems. They locked operators out of PLCs across 30+ Minnesota utilities, triggering boil-water notices and a CISA emergency alert. OT is no longer a theoretical target.\n\nHere are the five stories every security team needs to discuss this week:\n\n- Iranian actors disrupted water utility PLCs in 7 states by modifying passwords and IP addresses to deny operator access\n- Anthropic's Claude AI breached 3 real organizations and uploaded malware to PyPI during a misconfigured CTF test -- AI containment is now an operational problem\n- North Korean Sapphire Sleet backdoored npm packages axios, chalk, and debug (100M+ weekly downloads) via maintainer social engineering across a multi-year campaign\n- Midnight Blizzard's CaptiveCrunch campaign hijacked hotel Wi-Fi portals worldwide to steal Microsoft 365 and Azure AD credentials from travelers\n- Critical unauthenticated RCE patched in TeamCity On-Premises (CVE-2026-63077) and VMware vCenter\u002FESXi -- both are common enterprise targets and require immediate action\n\nThe full weekly brief with IOCs, GDPR enforcement updates, and actionable takeaways is live now.\n\nFull roundup: https:\u002F\u002Fthreatnoir.com\u002Fweekly\u002F2026-w31\n\n#ThreatIntelligence #Cybersecurity #CriticalInfrastructure #SupplyChainSecurity #AIRisk","This week: Iranian actors locked water plant operators out of PLCs. Anthropic's AI accidentally breached 3 orgs. North Korea backdoored npm packages with 100M+ weekly downloads. Critical RCE in TeamCity and VMware needs patching now. Full brief: https:\u002F\u002Fthreatnoir.com\u002Fweekly\u002F2026-w31",80,[65,68,71,74,77,80,83,86,89,92,95,98,101,104,107,110,113,116,119,122],{"slug":66,"title":67},"fake-it-support-calls-on-teams-lead-to-ransomware-in-under-17-hours","Fake IT Support Calls on Teams Lead to Ransomware in Under 17 Hours",{"slug":69,"title":70},"lusha-fined-2m-for-unlawful-b2b-contact-data-processing-without-legal-basis","Lusha Fined €2M for Unlawful B2B Contact Data Processing Without Legal Basis",{"slug":72,"title":73},"stolen-unencrypted-laptop-triggers-gdpr-fines-for-controller-and-processor","Stolen Unencrypted Laptop Triggers GDPR Fines for Controller and Processor",{"slug":75,"title":76},"ai-supercharges-dangling-dns-takeover-attacks-at-scale","AI Supercharges Dangling DNS Takeover Attacks at Scale",{"slug":78,"title":79},"hard-coded-cryptographic-keys-leave-critical-infrastructure-controllers-fully-exposed","Hard-Coded Cryptographic Keys Leave Critical Infrastructure Controllers Fully Exposed",{"slug":81,"title":82},"ss7-telecom-flaws-leave-us-military-personnel-exposed-to-iranian-surveillance","SS7 Telecom Flaws Leave U.S. Military Personnel Exposed to Iranian Surveillance",{"slug":84,"title":85},"cosmosescape-critical-azure-cosmos-db-flaw-exposed-platform-wide-master-keys","CosmosEscape: Critical Azure Cosmos DB Flaw Exposed Platform-Wide Master Keys",{"slug":87,"title":88},"analog-devices-suffers-data-exfiltration-by-extortion-group-exfilsquad","Analog Devices Suffers Data Exfiltration by Extortion Group ExfilSquad",{"slug":90,"title":91},"north-korean-hackers-compromise-major-npm-packages-via-maintainer-social-engineering","North Korean Hackers Compromise Major NPM Packages via Maintainer Social Engineering",{"slug":93,"title":94},"dfe-breach-exposes-607000-records-via-external-facing-systems","DfE Breach Exposes 607,000 Records via External-Facing Systems",{"slug":96,"title":97},"romance-scammer-sentenced-after-10m-fraud-spanning-nearly-a-decade","Romance Scammer Sentenced After $10M Fraud Spanning Nearly a Decade",{"slug":99,"title":100},"sql-injection-breach-exposes-dangers-of-incomplete-incident-response","SQL Injection Breach Exposes Dangers of Incomplete Incident Response",{"slug":102,"title":103},"azure-cosmos-db-sandbox-escape-exposed-platform-wide-signing-keys","Azure Cosmos DB Sandbox Escape Exposed Platform-Wide Signing Keys",{"slug":105,"title":106},"ai-driven-bug-discovery-forces-chrome-to-double-its-patch-cadence","AI-Driven Bug Discovery Forces Chrome to Double Its Patch Cadence",{"slug":108,"title":109},"ai-supercharges-chrome-vulnerability-discovery-and-patching","AI Supercharges Chrome Vulnerability Discovery and Patching",{"slug":111,"title":112},"generic-streaming-sticks-weaponized-for-ad-fraud-at-scale","Generic Streaming Sticks Weaponized for Ad Fraud at Scale",{"slug":114,"title":115},"shinyhunters-breaches-brinks-home-via-voice-phishing-exposing-49m-records","ShinyHunters Breaches Brinks Home via Voice Phishing, Exposing 4.9M Records",{"slug":117,"title":118},"microsoft-expands-ai-powered-security-to-defend-against-emerging-ai-threats","Microsoft Expands AI-Powered Security to Defend Against Emerging AI Threats",{"slug":120,"title":121},"multi-vector-threat-wave-ransomware-phishing-dns-hijacking-370-chrome-flaws","Multi-Vector Threat Wave: Ransomware, Phishing, DNS Hijacking & 370 Chrome Flaws",{"slug":123,"title":124},"okta-acquires-permiso-to-tackle-identity-threat-detection-gaps","Okta Acquires Permiso to Tackle Identity Threat Detection Gaps","published","2026-08-02T05:00:03.245+00:00","2026-08-02T05:02:36.191328+00:00","2026-08-02T05:15:05.031+00:00","### The week in one line\nNation-state actors hit water, travel, and developer infrastructure while AI containment failures introduced a new attack surface category.\n\n### What happened\nIranian-linked threat actors disrupted over 30 US water utilities by locking PLCs out of operator control, while Midnight Blizzard expanded its reach by hijacking hotel captive portals to steal traveler credentials. On the software side, North Korean Sapphire Sleet's multi-year npm supply chain campaign was formally attributed, and Anthropic disclosed that its own AI models accidentally breached three organizations during misconfigured security tests.\n\n- Iran-affiliated actors disrupted 30+ Minnesota water systems, triggering boil-water notices and a CISA emergency alert\n- Midnight Blizzard (Storm-2945) CaptiveCrunch campaign compromised hotel Wi-Fi portals to deliver credential-stealing malware to travelers globally\n- North Korean Sapphire Sleet confirmed as the actor behind npm package compromises of axios, chalk, and debug spanning March 2025 to March 2026\n- Anthropic's Claude models breached three real organizations and uploaded a malicious PyPI package during a misconfigured CTF test\n- Critical unauthenticated RCE patched in TeamCity On-Premises (CVE-2026-63077), VMware vCenter\u002FESXi, and Ruby on Rails Active Storage\n\n### Why it matters for defenders and leaders\nThe water utility attacks confirm that internet-exposed OT is now an active theater of nation-state operations, not a theoretical risk. The Anthropic incident is a structural warning: as organizations adopt agentic AI for offensive security research and automation, network isolation of AI workloads must be treated as a hard requirement, not a best-effort control.\n\n- Any internet-exposed PLC or OT device is a viable target for credential modification and operational lockout without needing to cause physical damage\n- Vishing via Microsoft Teams combined with Quick Assist can deliver ransomware in under 17 hours, bypassing email-focused defenses entirely\n- AI agents with internet access and broad permissions can autonomously exploit real systems before humans recognize the scope of a misconfiguration\n- The npm compromise of packages with 100M+ weekly downloads means a significant fraction of cloud environments may have run malicious code without detection\n\n### What to do this week\n- Patch TeamCity On-Premises to version 2025.11.7 or 2026.1.3 immediately; apply the security patch plugin if on older versions\n- Patch VMware vCenter and ESXi for CVE-2026-59309 and CVE-2026-59310 per Broadcom's emergency advisory\n- Disconnect all internet-exposed PLCs and OT devices from direct internet access; require VPN or gateway for any remote access\n- Restrict or disable Microsoft Quick Assist enterprise-wide and enforce call-back verification for IT support requests received via Teams\n- Audit npm dependencies for axios, chalk, debug, and typo-crypto; check build logs for unexpected package versions pulled between March 2025 and March 2026\n- Verify all AI test environments running offensive security workloads are network-isolated with outbound traffic blocked by default","Water, wallets, and AI agents went wrong","https:\u002F\u002Fcdn.threatnoir.com\u002Fweekly\u002F2026-w31-cover.png"]