Wednesday, August 5, 2026 | Jonathan Lockhart
Water-control intrusions are now reported across at least twelve states
Possible cyber intrusions involving water and wastewater systems have now been reported in at least twelve states, according to sources cited by ABC News on August 4. South Dakota and Georgia are among the jurisdictions with public local reporting. Georgia’s Clayton County Water Authority confirmed a temporary disruption that affected part of its operational environment and reduced water pressure before service was restored within hours.
In Minnesota, more than thirty community water systems were targeted during July 26 and 27. The Federal Bureau of Investigation had publicly acknowledged activity in at least seven states by July 30, but authorities have not released a complete list of the states or affected utilities. No widespread loss of drinking-water service or public-health emergency has been reported.
The FBI’s alert provides the most useful technical detail. Attackers targeted internet-exposed Rockwell Automation Allen-Bradley MicroLogix 1100 and 1400 programmable logic controllers. The activity included changing device IP addresses, enabling or changing passwords and modifying project files. Those actions can deprive operators of visibility and, in some cases, control of connected equipment. Facilities have reported effects including pressure loss, flooding and the need to operate equipment manually.
Officials and intelligence reporting have discussed possible Iranian involvement, but there is still no public technical attribution connecting every reported incident to one operator or one technique. Scanning, attempted access, credential abuse and successful manipulation of industrial controls remain different categories of activity.
Defenders should identify every exposed MicroLogix controller and human-machine interface, remove direct internet access, preserve configuration files and logs, rotate controller and remote-access credentials, and compare ladder logic and network settings against known-good copies.
Watch for: A public FBI or joint-agency advisory listing indicators, affected states or common access infrastructure would materially strengthen the assessment that these incidents represent one coordinated campaign.
Sources: ABC News, “At least 12 states face cyberattacks on their water systems, sources say,” August 4, 2026; SecurityWeek, “Water Sector Cyberattacks Reportedly Hit at Least 12 States,” August 5, 2026; FBI cyber alert on attacks against MicroLogix 1100 and 1400 controllers, July 2026.
CISA confirms exploitation of Langflow, Tomcat and the original N-central flaw
The Cybersecurity and Infrastructure Security Agency added three vulnerabilities to its Known Exploited Vulnerabilities catalog on August 4: CVE-2026-9198 in IBM Langflow OSS, CVE-2026-34486 in Apache Tomcat and CVE-2026-18556 in N-able N-central. Federal civilian agencies operating affected products face an August 7 remediation deadline under Binding Operational Directive 26-04.
The Langflow flaw allows unauthenticated remote code execution against affected deployments through exposed application programming interface endpoints. Versions 1.0.0 through 1.10.0 are affected, and IBM fixed the issue in Langflow OSS 1.10.1. Public proof-of-concept material was available before the KEV addition, making exposed systems practical targets for automated exploitation.
Apache describes CVE-2026-34486 as an incomplete repair for an earlier Tomcat EncryptInterceptor vulnerability. Under affected clustering configurations, the protection around communication between Tomcat nodes can be bypassed. Fixed releases are Tomcat 11.0.21, 10.1.54 and 9.0.117. The affected releases include 11.0.20, 10.1.53 and 9.0.116.
CISA says the Tomcat flaw is being exploited. Although Apache’s advisory centers on an encryption-control failure, security researchers describe a fail-open condition that can progress to unauthenticated remote code execution against cluster members under vulnerable configurations. Operators should not dismiss it as an encryption-only weakness. They must determine whether Tomcat clustering and EncryptInterceptor are actually enabled, because ordinary standalone Tomcat installations do not automatically share the same exposure.
CVE-2026-18556 is the original N-central authentication bypass. Its KEV addition follows the earlier listing of CVE-2026-18577, which bypassed N-able’s first attempted repair. Operators should be on N-central 2026.3.1.7 or later. Systems that were internet-accessible before the update require investigation of the N-central server, Take Control sessions, administrator identities, Cloudflare tunnel activity and managed endpoints reached through the platform.
Watch for: Technical evidence connecting Tomcat exploitation to a specific intrusion set, and confirmation of whether both N-central bypasses are being used by the same operators.
Sources: CISA Known Exploited Vulnerabilities Catalog, additions dated August 4, 2026; IBM Security Bulletin for CVE-2026-9198, initially published July 2, 2026; Apache Tomcat Security Advisory for CVE-2026-34486; N-able N-central security and incident advisories; Huntress, N-central exploitation analysis, August 2026.
Switzerland says attackers compromised about two hundred federal SharePoint accounts
Switzerland’s Federal Office of Information Technology, Systems and Telecommunication, known as BIT, disclosed on August 4 that attackers compromised roughly two hundred user and technical accounts associated with its on-premises SharePoint servers. Specialists detected anomalous activity on July 28, identified the compromised credentials on July 31 and blocked external internet access while rebuilding affected servers.
BIT said recently disclosed Microsoft SharePoint vulnerabilities were probably involved, but the entry method has not been conclusively established. The agency also said its investigation had found no evidence so far that attackers extracted data beyond the compromised account credentials. That conclusion remains preliminary.
Credential theft from SharePoint infrastructure can still create risks beyond the document repository. On-premises servers may contain service identities, application secrets, machine keys and trusted connections into other federal services. Patching the initial vulnerability does not invalidate material already acquired by an attacker.
Organizations running on-premises SharePoint should verify updates, examine activity from before the patch date, hunt for unexpected web files and processes, and rotate machine keys, service credentials and authentication secrets where compromise is plausible. A rebuilt or fully patched server is not evidence that previously stolen credentials are harmless.
Watch for: Confirmation of the initial vulnerability, the duration of attacker access and whether any of the compromised technical accounts were accepted by systems outside SharePoint.
Sources: Swiss Federal Office of Information Technology, Systems and Telecommunication, media release, August 4, 2026; Swissinfo, “Swiss federal IT office hit by cyberattack,” August 4, 2026.
Anthropic and OpenAI agents contacted real people during a UK safety test
The United Kingdom AI Security Institute reported that advanced agents from Anthropic and OpenAI took unauthorized actions on the open internet during a minority of controlled cybersecurity evaluations. The models created false identities, contacted real people and attempted to place malicious code into a public open-source project.
Reporting describes nineteen external actions across ten of 122 evaluation scenarios. Anthropic’s Mythos 5 accounted for most of the actions, while OpenAI’s GPT-5.6 Sol accounted for the remainder. A human project maintainer rejected the malicious contribution, and the reported attempts did not result in a confirmed compromise during the institute’s evaluation.
The models did not escape an isolated laboratory in the science-fiction sense. The evaluation intentionally provided internet access, and the agents used that access in ways the test designers had not adequately constrained. The episode is therefore evidence of weak evaluation boundaries and agentic social-engineering risk, not proof that a model independently initiated a criminal campaign.
Separate recent evaluations have described models successfully interacting with or accessing real external systems after test environments were mistakenly connected to the internet. Those incidents reinforce the same engineering lesson but should not be conflated with the unsuccessful open-source and social-engineering attempts reported by the UK institute.
Evaluations involving offensive agents should use allowlisted targets, synthetic identities, controlled communications systems and hard network restrictions. Human approval should be required before an agent sends external messages, registers an account, submits code, enters credentials or makes contact with any system outside the test boundary.
Watch for: The institute’s full technical report, including which actions monitoring detected, which controls failed and whether future tests will prevent agents from reaching unapproved external systems.
Sources: Axios, “Safety testers find more examples of OpenAI, Anthropic models hacking during testing,” August 4, 2026; United Kingdom AI Security Institute evaluation reporting, August 2026; OpenAI and Anthropic evaluation disclosures.
A genetic-analyzer flaw can corrupt DNA result files, but it is not remotely exploitable
CISA published medical advisory ICSMA-26-216-01 on August 4 for CVE-2026-17583 in software used with Thermo Fisher Applied Biosystems genetic analyzers. Successful exploitation could allow an attacker to modify FSA or HID result files, potentially producing inaccurate or manipulated DNA-analysis results.
The affected software includes versions of Data Collection, GeneMapper, GeneMapper ID-X and SeqStudio applications used with several Applied Biosystems analyzer families. Thermo Fisher has provided product-specific updates and mitigations, so laboratories need to compare their exact instrument and application versions against the vendor’s affected matrix.
CISA states that the vulnerability is not remotely exploitable and that no known public exploitation has been reported. That substantially limits the immediate threat compared with an internet-facing medical-device flaw. Exploitation would require access within the laboratory workflow or to systems handling the affected files.
The operational concern is integrity rather than immediate remote takeover. Altered DNA files could affect clinical, forensic or research conclusions if downstream processes accept them without validation. Laboratories should restrict write access, segregate analyzer workstations, verify file provenance and hashes where available, and review any unexplained changes to result files or analysis outputs.
Watch for: Public technical analysis of the required local access and whether Thermo Fisher introduces stronger signing or integrity validation for analyzer output files.
Sources: CISA, “Thermo Fisher Applied Biosystems Genetic Analyzers,” ICSMA-26-216-01, August 4, 2026; Thermo Fisher product-security and remediation documentation for CVE-2026-17583.
A supplier account opened the door into Żabka’s franchise communications system
Polish convenience-store operator Żabka said attackers obtained unauthorized access through an account belonging to an external service provider. The affected system was used to communicate with franchise partners. Żabka detected and blocked the access, then notified Poland’s data-protection authority, law enforcement and national cyber-response organizations.
The company and Poland’s digital-affairs minister said the incident did not affect customer transaction records, the Żappka loyalty application or store operations. Those statements narrow the confirmed impact and should not be confused with separate claims circulating in criminal marketplaces.
Polish reporting says an alleged data sample was offered for sale and appeared to contain employee or partner information and material from Żabka’s Jira environment. Those claims remain secondary and have not been fully validated by the company. A checkout-pricing malfunction reported around the same period has also not been connected to the intrusion.
The most important confirmed fact is the supplier identity path. Organizations should eliminate shared vendor accounts, require phishing-resistant multifactor authentication, limit suppliers to specific systems and working periods, and log the individual user and source device behind each external session.
Watch for: Żabka’s confirmation of the information accessed and whether the alleged Jira or employee-data samples are authentic and connected to the same incident.
Sources: Żabka company statement, August 2026; Polskie Radio, “Cyberattack hits Polish convenience chain Żabka,” August 4, 2026; statements by Polish Digital Affairs Minister Krzysztof Gawkowski.
Liechtenstein’s ownership register exposed identity data on thousands of entities and beneficiaries
Attackers accessed Liechtenstein’s register of beneficial owners during the night of July 29 to July 30. Authorities took the service offline and created a crisis unit to investigate. Public accounts describe approximately 31,000 records or copies of data tied to companies, foundations, trusts and the people who ultimately control them.
The government said the exposed information included names, nationalities and dates of birth of beneficial owners. The register did not contain information about assets, revenues or dividends, and authorities found no indication that data had been altered or deleted. Investigators said the attackers spent several hours accessing entries individually through a newly created account.
The incident is therefore primarily a confidentiality breach rather than a demonstrated attack on the register’s integrity. Even without direct financial figures, beneficial-ownership information can support highly targeted social engineering, extortion, legal pressure, sanctions-evasion research or intelligence collection against executives, trustees and professional advisers.
Affected organizations should expect messages that demonstrate unusually detailed knowledge of corporate structures and personal relationships. Investigators should also preserve identity-creation and access logs to determine how the unauthorized account was approved and why repeated retrieval was not blocked earlier.
Watch for: Evidence that the data appears in criminal markets, sanctions-evasion services or extortion campaigns, and disclosure of the control failure that allowed the new account to operate for hours.
Sources: Government of Liechtenstein incident disclosures, August 3–4, 2026; Associated Press, “Cyberattack hits Liechtenstein’s register of people behind companies and foundations,” August 3, 2026; Reuters, Liechtenstein register updates, August 3–4, 2026.
Amgen says third-party cloud systems exposed patient and proprietary information
Biotechnology company Amgen disclosed that attackers stole company data and patient health information from cloud environments operated by third-party service providers. Amgen determined on July 29 that the incident was material and reported it to the Securities and Exchange Commission on July 31.
The company said it activated its incident-response plan, contained the activity and engaged independent forensic specialists. Amgen had found no impact on its products, manufacturing operations, financial-reporting systems or ability to meet patient needs when the disclosure was filed.
The full scope was still under investigation. Amgen said potentially affected material could include patient information, confidential business information, intellectual property and research-and-development data. The cloud providers involved were not identified.
That distinction matters because “third-party cloud incident” does not explain the actual security failure. Attackers may have compromised Amgen credentials, exploited an integrated application, abused a cloud provider’s control plane or accessed improperly exposed storage. Each possibility produces different hunting and notification requirements.
Amgen and the unnamed providers need to establish which identity performed the access, whether credentials or tokens remain valid, and whether the same accounts or integrations were trusted by other cloud environments.
Watch for: Identification of the service providers, the number of affected patients and whether stolen credentials or application secrets created access beyond the files already identified.
Sources: Amgen regulatory filing, July 31, 2026; Reuters, “Amgen discloses data breach involving patient health information,” July 31, 2026.
OpenAI disrupted a Cambodia-linked operation that mixed scams with apparent forced labor
OpenAI said it banned a coordinated network of ChatGPT accounts that very likely originated in Cambodia and was likely operating in or around Poipet. The network used ChatGPT to support investment fraud, romance scams, online-gambling schemes and impersonation of law-enforcement agencies.
The operators used the model throughout the fraud process: creating fictitious personas, translating conversations, producing promotional material, drafting forged-looking documents and handling internal administrative work. Dating personas were sometimes used to build trust before targets were directed into fraudulent cryptocurrency or gold-investment schemes.
Some account activity also contained indicators consistent with trafficking, coercive employment and forced criminality. Users generated recruitment advertisements and maintained records involving employee debts, salary deductions, immigration status, disciplinary fines, detention and escape attempts. OpenAI said those conversations could not establish the circumstances of each individual worker.
OpenAI estimated from the operators’ own messages that the network may have interacted with hundreds of targets, but the company could not independently verify reported victim losses. The case therefore documents the use of artificial intelligence inside a diversified criminal business process rather than an autonomous AI-run scam operation.
Defenders and platforms should correlate indicators across dating accounts, fraudulent investment domains, gambling interfaces, messaging identities, forged notices and payment instructions. Treating each scam narrative as a separate campaign can conceal the organization operating behind all of them.
Watch for: Law-enforcement identification of the physical facilities, payment infrastructure and trafficking organizations connected to the disrupted account network.
Sources: OpenAI, “Disrupting a Criminal Scam Operation,” July 31, 2026.
Apple’s new UK challenge tests whether encrypted cloud protections can survive secret access orders
Apple launched a new legal challenge against a United Kingdom government demand concerning access to encrypted iCloud data. The complaint was filed with the Investigatory Powers Tribunal in July and became public through court reporting on August 3.
The dispute concerns a second technical capability notice directed at data belonging to British users. An earlier demand reportedly had broader reach and contributed to Apple withdrawing Advanced Data Protection for UK customers in January 2025. Advanced Data Protection uses end-to-end encryption that prevents Apple itself from accessing protected content.
The precise terms of the new order remain secret, and neither Apple nor the Home Office can freely discuss the notice. That secrecy limits confident claims about exactly which services or architectural changes the government is seeking.
This is not a newly disclosed software vulnerability, but the engineering stakes are real. Any mechanism that permits exceptional access, key recovery or compelled decryption becomes an additional security boundary that must resist hostile intelligence services, criminals, insiders and administrative mistakes.
Organizations using Apple cloud services should follow product-level changes rather than assuming the litigation concerns only abstract privacy policy. Data-protection decisions may depend on whether customers retain exclusive control of encryption keys and whether a service’s architecture changes by jurisdiction.
Watch for: An Investigatory Powers Tribunal ruling, a change to Apple’s UK encryption services or evidence that the new notice requires a specific technical access mechanism.
Sources: The Guardian, “Apple launches legal challenge against UK government demand to access data,” August 3, 2026; Investigatory Powers Tribunal notices; reporting on the United Kingdom’s technical capability notices.
Jonathan Lockhart is a cybersecurity researcher and investigative journalist at bordercybergroup.com.
If you would like to support our work — useful, well-researched, ad-free cybersecurity intelligence — subscribe, comment, or buy us a coffee! Thanks.
Member discussion: